This is a click-through agreement. It takes effect when the Partner accepts it electronically during onboarding.
THIS AGREEMENT TAKES EFFECT ON THE DATE ON WHICH THE PARTNER ACCEPTS IT ELECTRONICALLY
BETWEEN
1. TRACED LTD incorporated and registered in England and Wales with company number 12194411 whose registered office is at 1b Blackfriars House, Parsonage, Manchester, Greater Manchester, England, M3 2JA (“Traced“); and
2. the business entity identified during the electronic onboarding process that accepts this agreement (the “Partner“).
By selecting the acceptance control presented during onboarding (for example, a button or checkbox labelled “I Agree”), the individual accepting this agreement confirms that they are authorised to bind the Partner and that the Partner agrees to be bound by this agreement.
BACKGROUND
Traced wishes to appoint the Partner as its non-exclusive partner to manage and license the Traced Product (as defined below) to end user customers both directly and via its reseller channel in conjunction with the Managed Service (as defined below) subject to the terms and conditions of this agreement
AGREED TERMS
1.INTERPRETATION
1.1. The definitions and rules of interpretation in this clause apply in this agreement.
| “Business Day”: | a day other than a Saturday, Sunday or public holiday in England when banks in London are open for business. |
|---|---|
| “Confidential Information”: | information that is proprietary or confidential and is either (i) clearly labelled as such or (ii) otherwise identified as Confidential Information or (iii) would be considered to be confidential by a reasonable business person. |
| “Control”: | the beneficial ownership of more than 50% of the issued share capital of a company or the legal power to direct or cause the direction of the general management of the company, and controls, controlled and the expression change of control shall be construed accordingly. |
| “Data Protection Legislation”: | (i) the UK GDPR (as defined in section 3(10) of the Data Protection Act 2018, supplemented by section 205(4)), the Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003; (ii) where applicable to the processing, Regulation (EU) 2016/679 (the EU GDPR) and any national implementing legislation; and (iii) any other data protection laws and regulations, orders and any codes of practice, guidelines and recommendations issued by the Information Commissioner’s Office or any other competent supervisory authority, in each case as amended and in force from time to time. |
| “Effective Date”: | the date on which the Partner accepts this agreement electronically. |
| “EULA”: | the end user licence agreement in the form set out in Schedule 2. |
| “Intellectual Property Rights”: | patents, rights to inventions, copyright and neighbouring and related rights, trade marks and service marks, business names and domain names, rights in get-up and trade dress, goodwill and the right to sue for passing off or unfair competition, rights in designs, database rights, rights to use, and protect the confidentiality of, confidential information (including know-how and trade secrets) and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim priority from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world. |
| “Legislation”: | any statute, statutory provision or subordinate legislation or any mandatory rules issued by any regulatory body having jurisdiction over the applicable party. |
| “Managed Service”: | the managed service referred to in Part 2 of Schedule 1 in respect of the Traced Product. |
| “Mandatory Policies”: | Traced’s following business policies as amended by notification to the Partner from time to time: (i) Privacy Policy; (ii) Anti-Slavery and Human Trafficking Policy; and (iii) Anti-Corruption and Anti-Bribery Policy. |
| “Privacy Policy”: | The Privacy Policy hosted at the following location: https://traced.app/traced-privacy-policy/ |
| “Traced Product”: | the platform specified in Part 1 of Schedule 1 and the associated documentation (if any). |
| “Trade Marks”: | UK trade mark registration 3466787 for “TRACED”, UK trade mark registration 4344118 for “TRUSTD MOBILE” and UK trade mark registration 3762652 for “TRUSTD”. |
1.2. Clause, Schedule and paragraph headings shall not affect the interpretation of this agreement.
1.3. A person includes a natural person, corporate or unincorporated body (whether or not having separate legal personality).
1.4. Unless the context otherwise requires, words in the singular shall include the plural and in the plural include the singular.
1.5. A reference to writing or written includes email.
1.6. References to clauses and Schedules are to the clauses and Schedules of this agreement and references to paragraphs are to paragraphs of the relevant Schedule.
2.APPOINTMENT
2.1. Traced appoints the Partner as its non-exclusive worldwide reseller to provide the Managed Service and resell the Traced Product on the terms of this agreement both to the Partner’s customers, in respect of which the Partner will obtain a licence for the Traced Product.
2.2. The Partner shall be entitled to describe itself as an “Authorised Partner” of the Traced Product but shall not represent itself as an agent of Traced for any purpose, nor pledge Traced’s credit or give any condition or warranty or make any representation on Traced’s behalf or commit Traced to any contracts. Further, the Partner shall not without Traced’s prior written consent make any representations, warranties, guarantees or other commitments with respect to the specifications, features or capabilities of the Traced Product which are inconsistent with those contained in the promotional material supplied by Traced (including, without limitation, the EULA) or otherwise incur any liability on behalf of Traced howsoever arising.
2.3. The Partner’s appointment under this clause 2 only grants to the Partner a licence to resell Traced Product either as part of the Managed Service or as a standalone product (where the customer manages the Traced Product itself), and does not transfer any right, title or interest to any such Traced Product to the Partner or its customers. Use of the terms “sell”, “license”, “purchase”, “licence fees” and “price” will be interpreted in accordance with this clause.
2.4. Traced reserves the right to sell the Traced Product directly to customers and other resellers.
3.PARTNER’S UNDERTAKINGS
3.1. The Partner undertakes and agrees with Traced to:
3.1.1. The Partner expressly represents and warrants, on the Effective Date and throughout the Term, that its primary business function is one or more of the following: (a) an IT Managed Service Provider; (b) a Managed Security Service Provider; or (c) an IT Reseller.
3.1.2. use its best endeavours to promote the distribution and sale of the Managed Service worldwide or Traced Product in the UK and to expand the sale of the Traced Product by all reasonable and proper means and not to do anything which may hinder or interfere with such sales and, without limitation;
3.1.2.1. to demonstrate to customers the features and capabilities of the Managed Service; and
3.1.2.2. actively to solicit orders for the Managed Service or Traced Product from customers and prospective customers;
3.1.3. take all reasonable steps to ensure that customers of the Managed Service or Traced Product are aware of and accept the terms and conditions of the EULA before using the Traced Product;
3.1.4. refrain from amending or varying the terms of the EULA;
3.1.5. inform Traced immediately of any changes in ownership or Control of the Partner and of any change in its organisation or method of doing business which might affect the performance of the Partner’s duties in this agreement.
4.SUPPLY OF TRACED PRODUCT
4.1. During the Term, Traced shall make available to the Partner and its customers online access and device-specific downloadable copies of the Traced Product.
4.2. Traced is entitled to make changes to the description in Schedule 1 Part 1 which do not adversely affect either the Traced Product or the Managed Service and shall give written notice of such changes to the Partner as soon as reasonably practicable.
5.TRACED’S UNDERTAKINGS
5.1. Traced undertakes:
5.1.1. to provide such information and support as may be reasonably requested by the Partner to enable it properly and efficiently to discharge its duties under this agreement; and
5.1.2. to approve or reject any promotional information or material submitted by the Partner within 14 days of receipt.
6.COMMISSION AND PAYMENT
6.1. The commission rates to be paid by the Partner to Traced for Traced Product are as shown in Schedule 3, and as amended by the parties from time to time.
6.2. The Partner will bear its own costs and expenses in the performance of its obligations under this agreement.
6.3. Traced will invoice the Partner monthly for Commission due.
6.4. The Partner shall pay the full amount invoiced to it by Traced in pounds sterling within 30 days of the date of invoice.
6.5. All amounts due under this agreement shall be paid by the Partner to Traced in full without any set-off, counterclaim, deduction or withholding (other than any deduction or withholding of tax as required by law).
6.6. As between Traced and the Partner, the Partner shall be responsible for the collection, remittance and payment of any or all taxes, charges, levies, assessments and other fees of any kind imposed by governmental or other authority in respect of the purchase, importation, sale, resale or other exploitation of the Traced Product or the Managed Service.
6.7. If the Partner fails to make any payment due to Traced under this agreement by the due date for payment, then, without limiting Traced’s remedies under clause 14, the Partner shall pay interest on the overdue amount at the rate of 4% per annum above Barclays Bank Plc’s base rate from time to time. Such interest shall accrue on a daily basis from the due date until actual payment of the overdue amount, whether before or after judgment. The Partner shall pay the interest together with the overdue amount.
7.ADVERTISING AND PROMOTION
7.1. The Partner shall:
7.1.1. be responsible for the advertising and promotion of the Managed Service or Traced Product provided that the use by the Partner of any advertising materials and promotional literature containing the Trade Marks or other references to Traced Product shall be subject to the prior written consent of Traced;
7.1.2. observe all reasonable directions and instructions given to it by Traced in relation to the promotion and advertisement of the Traced Product or Managed Service to the extent that such promotions or advertisements refer to Traced Product or otherwise use the Trade Marks, and shall not make any written statement as to the quality of Traced Product without the prior written approval of Traced;
7.1.3. conduct its business in a manner that reflects favourably at all times on Traced and the good name, goodwill and reputation of Traced and not enter into any contract or engage in any practice that is or may be detrimental to the interests of Traced in Traced Product; and
7.1.4. avoid deceptive, misleading or unethical practices that are, or might be, detrimental to Traced, Traced Product or the public and shall not publish or employ, or co-operate in the publication or employment of, any false, misleading or deceptive advertising material or other representations with regard to Traced or Traced Product.
8.COMPLIANCE
8.1. In performing its obligations under this agreement, the Partner shall comply with the Mandatory Policies.
8.2. The Partner shall comply with all applicable laws, regulations and sanctions relating to anti-bribery and anti-corruption including but not limited to the Bribery Act 2010.
9.INTELLECTUAL PROPERTY RIGHTS
9.1. Unless otherwise agreed between the parties, all Intellectual Property Rights in and to Traced Product belong, and shall belong, to Traced and/or its licensors.
9.2. The Partner shall, at the expense of Traced, take all such steps as Traced may reasonably require to assist Traced in maintaining the validity and enforceability of the Intellectual Property Rights of Traced during the term of this agreement.
9.3. Without prejudice to the right of the Partner or any third party to challenge the validity of any Intellectual Property Rights of Traced, the Partner shall not do or authorise any third party to do any act which would or might invalidate or be inconsistent with any Intellectual Property Rights of Traced and shall not omit or authorise any third party to omit to do any act which, by its omission, would have that effect or character.
9.4. Traced makes no representation or warranty as to the validity or enforceability of the Intellectual Property Rights in Traced Product and the Trade Marks.
9.5. Traced grants to the Partner a non-exclusive, revocable, personal licence (subject to the terms and conditions of this agreement and during its term and solely for the purposes of performing the Partner’s obligations under this agreement) to use the Trade Marks on or in relation to the Managed Service or Traced Product for the purpose of the promotion, advertisement and sale of the Managed Service.
9.6. The Partner shall not:
9.6.1. copy Traced Product or any part of any of them except to the extent and for the purposes expressly permitted by this agreement; or
9.6.2. modify, adapt, develop, create any derivative work, reverse engineer, decompile, disassemble or carry out any act otherwise restricted by copyright or other Intellectual Property Rights in Traced Product except and only to the extent that it is expressly permitted by applicable law.
9.7. The Partner shall ensure that each reference to, and use of, any of the Trade Marks by the Partner is in a manner approved from time to time by Traced and accompanied by an acknowledgement in a form approved by Traced that the same is a trade mark (or registered trade mark) of Traced.
9.8. The Partner shall not:
9.8.1. use any of the Trade Marks in any way which might prejudice their distinctiveness or validity or the goodwill of Traced therein;
9.8.2. use in relation to Traced Product any trade marks other than the Trade Marks without obtaining the prior written consent of Traced; or
9.8.3. use any trade marks or trade names so resembling any trade mark or trade names of Traced as to be likely to cause confusion or deception.
9.9. Other than the licences expressly granted under this agreement, neither party grants any licence of, right in or makes any assignment of any of its Intellectual Property Rights. In particular, except as expressly provided in this agreement, the Partner shall have no rights in respect of any trade names or trade marks used by Traced in relation to Traced Product or their associated goodwill, and the Partner hereby acknowledges that all such rights and goodwill shall inure for the benefit of and are (and shall remain) vested in, Traced.
9.10. At the request of Traced, the Partner shall do or procure to be done all such further acts and things (including the execution of documents) as Traced shall reasonably require to give Traced the full benefit of this agreement.
9.11. The Partner shall promptly give notice in writing to Traced in the event that it becomes aware of:
9.11.1. any infringement or suspected infringement of the Trade Marks or any other Intellectual Property Rights in or relating to the Traced Product; and
9.11.2. any claim that the Traced Product or the use, sale, license or other exploitation of the Traced Product, whether or not under the Trade Marks, infringes the rights of any third party.
9.12. In the case of any matter falling within clause 9.11.1:
9.12.1. Traced shall, in its absolute discretion, determine what action if any shall be taken in respect of the matter; and
9.12.2. Traced shall have sole control over and shall conduct any consequent action as it shall deem necessary; and
9.12.3. Traced shall pay all costs in connection with that action and shall be entitled to all damages and other sums which may be paid or awarded as a result of any such action.
9.13. In the case of any matter falling within clause 9.11.2:
9.13.1. Traced shall defend the Partner, its officers, directors and employees against any claims that the marketing, advertising or distribution of Traced Product in accordance with this agreement infringes any Intellectual Property Right and shall indemnify the Partner on demand for and against any amounts awarded against the Partner in judgment or settlement of such claims, provided that:
9.13.1.1. Traced is given prompt notice of such claim;
9.13.1.2. the Partner provides reasonable co-operation to Traced in the defence and settlement of such claim, at Traced’s expense; and
9.13.1.3. Traced is given sole authority to defend or settle the claim.
9.13.2. In the defence or settlement of the claim, Traced may obtain for the Partner the right to continue distributing Traced Product in the manner contemplated by this agreement, replace or modify Traced Product so that it becomes non-infringing or, if such remedies are not reasonably available, terminate this agreement forthwith by notice in writing and without liability to the Partner. Traced shall not in any circumstances have any liability if the alleged infringement is based on:
9.13.2.1. the Managed Service;
9.13.2.2. a modification of Traced Product by anyone other than Traced;
9.13.2.3. the Partner’s marketing, advertising, distribution or use of Traced Product in a manner contrary to the instructions given to the Partner by Traced;
9.13.2.4. the Partner’s marketing, advertising, distribution or use of Traced Product after notice of the alleged or actual infringement from Traced or any appropriate authority; or
9.13.2.5. use or combination of Traced Product with the Managed Service in circumstances where, but for such combination, no infringement would have occurred.
9.13.3. The foregoing states the Partner’s sole and exclusive rights and remedies, and Traced’s entire obligations and liability, in the case of any matter falling under clause 9.11.2.
9.14. Each party shall, at the request and expense of the other, provide all reasonable assistance to the other (including, but not limited to, the use of its name in, or being joined as a party to, proceedings) in connection with any action to be taken by the other party, provided that that party is given such indemnity as it may reasonably require against any damage to its name.
10.CONFIDENTIALITY
10.1. Each party may have access to Confidential Information of the other party under this agreement. A party’s Confidential Information shall not include information that:
10.1.1. is or becomes publicly known through no act or omission of the receiving party; or
10.1.2. was in the other party’s lawful possession prior to the disclosure; or
10.1.3. is lawfully disclosed to the receiving party by a third party without restriction on disclosure; or
10.1.4. is independently developed by the receiving party, which independent development can be shown by written evidence.
10.2. Subject to clause 10.4, each party shall hold the other’s Confidential Information in confidence and, unless required by law, not make the other’s Confidential Information available to any third party or use the other’s Confidential Information for any purpose other than the implementation of this agreement.
10.3. Each party agrees to take all reasonable steps to ensure that the other’s Confidential Information to which it has access is not disclosed or distributed by its employees or agents in violation of the terms of this agreement.
10.4. A party may disclose Confidential Information to the extent such Confidential Information is required to be disclosed by law, by any governmental or other regulatory authority or by a court or other authority of competent jurisdiction, provided that, to the extent it is legally permitted to do so, it gives the other party as much notice of such disclosure as possible and, where notice of disclosure is not prohibited and is given in accordance with this clause 10.4, it takes into account the reasonable requests of the other party in relation to the content of such disclosure.
10.5. This clause 10 shall survive termination of this agreement for any reason.
11.PROTECTION AND PROCESSING OF PERSONAL DATA
11.1. Both parties will comply with all applicable requirements of data protection laws. This clause 11.1 is in addition to, and does not relieve, remove or replace, a party’s obligations or rights under applicable data protection laws.
11.2. The parties acknowledge that:
11.2.1. the personal data processed under this agreement may be processed under different relationships, namely:
(a) Traced acts as a processor on behalf of the Partner (or, where applicable, the Partner’s customer as controller) in respect of personal data processed solely on documented instructions to deliver the Traced Product to authorised users, such processing being further described in Schedule 4 (Data Processing Particulars); and
(b) Traced acts as a separate and independent controller in respect of personal data it processes for its own purposes, including (without limitation) service security, threat intelligence, product improvement, fraud prevention, the operation of automated risk-scoring features of Trustd MTD, billing, and meeting Traced’s own legal obligations.
Each party shall, in respect of the personal data for which it is controller, comply with its own obligations under the Data Protection Legislation.
11.2.2. the details of the processing carried out by Traced as processor, including the subject-matter, duration, nature and purpose of the processing, the types of personal data, the categories of data subjects, and the obligations and rights of the controller, are set out in Schedule 4 (Data Processing Particulars), which is incorporated into this agreement and which the parties shall keep under review.
11.2.3. the personal data may be transferred to or stored in a country outside the United Kingdom and the European Economic Area, or outside the country where the Partner, its customers, authorised users or device users are located, in order to fulfil Traced’s obligations under this agreement, provided that any such transfer is made in accordance with clause 11.4.2 and an appropriate transfer mechanism under Article 46 UK GDPR (and, where applicable, Article 46 EU GDPR).
11.3. Without prejudice to the generality of clause 11.1, the Partner will ensure that it has a valid lawful basis under Article 6 UK GDPR (and, where applicable, Article 9 UK GDPR for special category data) and has provided all required transparency information to data subjects in accordance with Articles 13 and 14 UK GDPR in order to enable the lawful transfer of the personal data to Traced for the duration and purposes of this agreement so that Traced may lawfully use, process and transfer the personal data in accordance with this agreement.
11.4. Without prejudice to the generality of clause 11.1, Traced shall, in relation to any personal data processed in connection with the performance by Traced of its obligations under this agreement:
11.4.1. process that personal data only on the documented written instructions of the Partner (which shall include the instructions contained in this agreement and Schedule 4 (Data Processing Particulars)), unless Traced is required by applicable Data Protection Legislation or other applicable law to process personal data otherwise. Where Traced is relying on such law as the basis for processing personal data, Traced shall promptly notify the Partner of this before performing the processing required by applicable Data Protection Legislation, unless those applicable laws prohibit Traced from so notifying the Partner;
11.4.2. not transfer any personal data outside the United Kingdom and the European Economic Area unless at least one of the following conditions is fulfilled:
11.4.2.1 the transfer is to a third country, territory or sector covered by adequacy regulations issued under Article 45 UK GDPR (or, where applicable, an adequacy decision under Article 45 EU GDPR);
11.4.2.2 the parties have entered into the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses (and where the EU GDPR applies to the transfer, the EU Standard Contractual Clauses (Decision 2021/914));
11.4.2.3 another transfer mechanism authorised under Article 46 UK GDPR (or, where applicable, Article 46 EU GDPR) is in place and a transfer risk assessment has been completed; or
11.4.2.4 a derogation under Article 49 UK GDPR (and, where applicable, Article 49 EU GDPR) applies;
and in each case Traced shall comply with reasonable instructions notified to it in advance by the Partner with respect to the processing of the personal data.
11.4.3. taking into account the nature of the processing and the information available to Traced, assist the Partner by appropriate technical and organisational measures, insofar as this is possible, in responding to any request from a data subject exercising rights under Chapter III UK GDPR, and in ensuring compliance with the Partner’s obligations under Articles 32 to 36 UK GDPR with respect to security, breach notifications, data protection impact assessments and prior consultations with supervisory authorities or regulators; the costs of such assistance shall be borne by the Partner save where the need for such assistance arises from Traced’s breach of this agreement or the Data Protection Legislation, in which case Traced shall bear its own costs;
11.4.4. notify the Partner without undue delay, and in any event within 48 hours, on becoming aware of a personal data breach affecting personal data processed under this agreement, and provide the Partner with such information as is reasonably required to enable the Partner to comply with its obligations under Articles 33 and 34 UK GDPR, including (to the extent known): (a) the nature of the personal data breach, including the categories and approximate number of data subjects and personal data records concerned; (b) the likely consequences of the breach; and (c) the measures taken or proposed to address the breach and mitigate its possible adverse effects;
11.4.5. at the written direction of the Partner, delete or return personal data and copies thereof to the Partner on termination of the agreement unless required by applicable Data Protection Legislation to store the personal data (and for these purposes the term “delete” shall mean to put such data beyond use);
11.4.6. maintain complete and accurate records and information necessary to demonstrate its compliance with this clause 11 and Article 28 UK GDPR, and make such records available to the Partner on reasonable written request. The Partner (or an independent third-party auditor mandated by the Partner and reasonably acceptable to Traced) may, on not less than 30 days’ written notice and no more than once in any 12-month period (save where required by a supervisory authority or following a personal data breach), conduct audits or inspections of Traced’s processing activities to the extent strictly necessary to verify compliance with this clause 11. Audits shall be conducted during business hours, in a manner that does not unreasonably disrupt Traced’s business, and subject to appropriate confidentiality undertakings. Traced shall immediately inform the Partner if, in the opinion of Traced, an instruction infringes the Data Protection Legislation; and
11.4.7. ensure that all persons authorised by Traced to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
11.5. Each party shall implement appropriate technical and organisational measures in accordance with Article 32 UK GDPR to ensure a level of security appropriate to the risk, including, where appropriate, the measures referred to in Article 32(1)(a) to (d). Traced’s current technical and organisational measures are set out in Schedule 4 (Data Processing Particulars). Each party shall, on reasonable request, provide the other with information about the measures it has implemented.
11.6. The Partner provides general written authorisation to Traced to engage the sub-processors listed in Schedule 4 (Data Processing Particulars). Traced shall maintain an up-to-date list of sub-processors and shall notify the Partner of any intended addition or replacement of a sub-processor at least 30 days in advance, thereby giving the Partner the opportunity to object to such changes. If the Partner objects on reasonable data protection grounds, Traced shall use reasonable endeavours to make available a change in service to avoid processing by the proposed sub-processor; failing which the Partner may terminate the affected services on notice without penalty.
11.7. Traced shall enter into a written contract with each sub-processor imposing on the sub-processor the same data protection obligations as those imposed on Traced under this agreement, in particular providing sufficient guarantees to implement appropriate technical and organisational measures to meet the requirements of Article 28 UK GDPR.
11.8. Where the sub-processor fails to fulfil its data protection obligations, Traced shall remain fully liable to the Partner for the performance of the sub-processor’s obligations.
11.9. The parties shall, on the reasonable request of either party (such request not to be unreasonably refused), negotiate in good faith to revise this clause 11 to reflect changes in applicable Data Protection Legislation, any guidance issued by the ICO or other competent supervisory authority, or any applicable controller-to-processor standard clauses or certification scheme. Any revision shall take effect only when signed in writing by both parties.
12.WARRANTIES
12.1. Each party represents, warrants and undertakes that:
12.1.1. it has full capacity and authority and all necessary consents to enter into and to perform this agreement and to grant the rights and licences referred to in this agreement and that this agreement is accepted electronically by its duly authorised representative and represents a binding commitment on it; and
12.1.2. without affecting its other obligations under this agreement, it shall comply with all applicable laws in the performance of its obligations under this agreement.
12.2. Traced warrants to the Partner that Traced Product supplied or licensed by it under this agreement will operate substantially in accordance with, and perform, the material functions and features as set out in Schedule 1Part 1.
13.LIMITATION OF LIABILITY
13.1. Except as expressly and specifically provided in this agreement, all warranties, conditions and other terms implied by statute, common law or otherwise are, to the fullest extent permitted by law, excluded from this agreement.
13.2. Nothing in this agreement excludes the liability of Traced:
13.2.1. for death or personal injury caused by Traced’s negligence; or
13.2.2. for fraud or fraudulent misrepresentation.
13.3. Subject to clause 13.2 Traced shall not in any circumstances be liable, whether in tort (including for negligence or breach of statutory duty howsoever arising), contract, misrepresentation (whether innocent or negligent) or otherwise for:
13.3.1. loss of profits; or
13.3.2. loss of business; or
13.3.3. depletion of goodwill or similar losses; or
13.3.4. loss of anticipated savings; or
13.3.5. loss of goods; or
13.3.6. loss of use; or
13.3.7. loss or corruption of data or information; or
13.3.8. any special, indirect, consequential or pure economic loss, costs, damages, charges or expenses.
13.4. Traced’s total aggregate liability in contract, tort (including without limitation negligence or breach of statutory duty howsoever arising), misrepresentation (whether innocent or negligent), restitution or otherwise, arising in connection with the performance or contemplated performance of this agreement shall in all circumstances be limited to the amount actually paid by the Partner to Traced under this agreement in the 12 months preceding the date on which the claim arose.
13.5. In the event of any breach of Traced’s warranty in clause 12.2 (whether by reason of defective materials, production faults or otherwise) the Partner’s sole remedy and Traced’s only obligation and liability to the Partner shall be for Traced to:
13.5.1. replace Traced Product in question; or
13.5.2. at Traced’s option, repay any price paid for Traced Product.
14.TERM AND TERMINATION
14.1. This agreement shall commence on the Effective Date. Unless terminated earlier in accordance with clause 14.2 or clause 14.3 or this clause 14.1, this agreement shall continue for one year (“Initial Term“) and shall automatically extend for one-year periods (“Extended Term“) at the end of the Initial Term and at the end of each Extended Term. Either party may give written notice to the other party, not later than 90 days before the end of the Initial Term or the relevant Extended Term, to terminate this agreement at the end of the Initial Term or the relevant Extended Term, as the case may be.
14.2. Without affecting any other right or remedy available to it, either party may terminate this agreement with immediate effect by giving written notice to the other party if:
14.2.1. the other party fails to pay any amount due under this agreement on the due date for payment and remains in default not less than 14 days after being notified in writing to make such payment; or
14.2.2. the other party commits a material breach of any term of this agreement which breach is irremediable or (if such breach is remediable) fails to remedy that breach within a period of 30 days after being notified in writing to do so; or
14.2.3. the other party suspends, or threatens to suspend, payment of its debts or is unable to pay its debts as they fall due or admits inability to pay its debts or is deemed unable to pay its debts within the meaning of section 123 of the Insolvency Act 1986; or
14.2.4. the other party commences negotiations with all or any class of its creditors with a view to rescheduling any of its debts, or makes a proposal for or enters into any compromise or arrangement with its creditors; or
14.2.5. the other party applies to court for, or obtains, a moratorium under Part A1 of the Insolvency Act 1986;
14.2.6. a petition is filed, a notice is given, a resolution is passed, or an order is made, for or in connection with the winding up of that other party; or
14.2.7. an application is made to court, or an order is made, for the appointment of an administrator, or if a notice of intention to appoint an administrator is given or if an administrator is appointed, over the other party, (being a company, partnership or limited liability partnership); or
14.2.8. the holder of a qualifying floating charge over the assets of that other party (being a company or limited liability partnership) has become entitled to appoint or has appointed an administrative receiver; or
14.2.9. a person becomes entitled to appoint a receiver over the assets of the other party or a receiver is appointed over the assets of the other party; or
14.2.10. a creditor or encumbrancer of the other party attaches or takes possession of, or a distress, execution, sequestration or other such process is levied or enforced on or sued against, the whole or any part of the other party’s assets and such attachment or process is not discharged within 14 days; or
14.2.11. any event occurs, or proceeding is taken, with respect to the other party in any jurisdiction to which it is subject that has an effect equivalent or similar to any of the events mentioned in clause 14.2.2 to clause 14.2.9 (inclusive); or
14.2.12. the other party suspends or ceases, or threatens to suspend or cease, carrying on all or a substantial part of its business; or
14.2.13. the other party’s financial position deteriorates so far as to reasonably justify the opinion that its ability to give effect to the terms of this agreement is in jeopardy.
14.3. Without prejudice to any other rights or remedies to which Traced may be entitled, Traced may terminate the agreement without liability to the Partner if:
14.3.1. if the Partner commits a breach of its obligation in clause 8.1;
14.3.2. if Traced determines that the Partner’s primary business function is not one of the business functions listed in clause 3.1;
14.3.3. there is a change of control of the Partner or Traced; or
14.3.4. the Partner purports to assign any of its rights or obligations under this agreement.
15.EFFECTS OF TERMINATION
15.1. On termination or expiry of this agreement for any reason:
15.1.1. access to the Traced Product by the Partner will cease, and, access to the Traced Product by its customer will cease at the end of the customers’ licensed billing term unless the customer approaches Traced directly to maintain its access, in which case that customer will become a direct customer of Traced;
15.1.2. the Partner shall (at its sole cost) return (or at Traced’s option, destroy) all media on which Traced Product are held and the Partner shall stop selling the Managed Service;
15.1.3. the accrued rights of the parties as at termination or the continuation after termination of any provision expressly stated to survive or implicitly surviving termination shall not be affected or prejudiced;
15.1.4. subject to the foregoing provisions of this clause 15.1, all rights and licences of the Partner under this agreement shall terminate.
15.2. The termination of this agreement shall not of itself give rise to any liability on the part of Traced to pay any compensation to the Partner for loss of profits or goodwill, to reimburse the Partner for any costs relating to or resulting from such termination, or for any other loss or damage.
16.FORCE MAJEURE
Neither party shall in any circumstances be in breach of this agreement nor liable for delay in performing, or failure to perform, any of its obligations under this agreement if such delay or failure results from events, circumstances or causes beyond its reasonable control, including, without limitation, strikes, lock-outs or other industrial disputes (whether involving the workforce of the Partner or any other party), failure of a utility service or transport or telecommunications network, act of God, war, riot, civil commotion, malicious damage, compliance with any law or governmental order, rule, regulation or direction, accident, breakdown of plant or machinery, fire, flood, storm or default of suppliers or sub-contractors. In such circumstances the affected party shall be entitled to a reasonable extension of the time for performing such obligations, provided that if the period of delay or non-performance continues for six months, the party not affected may terminate this agreement by giving 30 days’ written notice to the other party.
17.WAIVER
No failure or delay by a party to exercise any right or remedy provided under this agreement or by law shall constitute a waiver of that or any other right or remedy, nor shall it prevent or restrict the further exercise of that or any other right or remedy. No single or partial exercise of such right or remedy shall prevent or restrict the further exercise of that or any other right or remedy.
18.SEVERANCE
18.1. If any provision or part-provision of this agreement is or becomes invalid, illegal or unenforceable, it shall be deemed deleted, but that shall not affect the validity and enforceability of the rest of this agreement.
18.2. If any provision or part-provision of this agreement is deemed deleted under clause 18.1 the parties shall negotiate in good faith to agree a replacement provision that, to the greatest extent possible, achieves the intended commercial result of the original provision.
19.ENTIRE AGREEMENT
19.1. This agreement constitutes the entire agreement between the parties and supersedes and extinguishes all previous agreements, promises, assurances, warranties, representations and understandings between them, whether written or oral, relating to its subject matter.
19.2. Each party acknowledges that in entering into this agreement it does not rely on, and shall have no remedies in respect of, any statement, representation, assurance or warranty (whether made innocently or negligently) that is not set out in this agreement.
19.3. Each party agrees that it shall have no claim for innocent or negligent misrepresentation or negligent misstatement based on any statement in this agreement.
19.4. Nothing in this clause shall limit or exclude any liability for fraud.
20.VARIATION
No variation of this agreement shall be effective unless it is in writing and signed by the parties (or their authorised representatives).
21.ASSIGNMENT
21.1. The Partner shall not, without the prior written consent of Traced, assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this agreement.
21.2. Traced may at any time assign, transfer, charge, sub-contract or deal in any other manner with all or any of its rights or obligations under this agreement.
22.NO PARTNERSHIP OR AGENCY
22.1. Nothing in this agreement is intended to, or shall be deemed to, establish any partnership or joint venture between any of the parties, constitute any party the agent of another party, nor authorise any party to make or enter into any commitments for or on behalf of any other party except as expressly provided in clause 2.
22.2. Each party confirms it is acting on its own behalf and not for the benefit of any other person.
23.THIRD PARTY RIGHTS
No one other than a party to this agreement, their successors and permitted assignees, shall have any right to enforce any of its terms.
24.RIGHTS AND REMEDIES
The rights and remedies provided under this agreement are in addition to, and not exclusive of, any rights or remedies provided by law.
25.NOTICES
25.1. Any notice or other communication given to a party under or in connection with this contract shall be in writing and shall be:
25.1.1. delivered by hand or by pre-paid first-class post or other next working day delivery service at its registered office (if a company) or its principal place of business (in any other case); or
25.1.2. sent by email to the email address previously used or notified by a party.
25.2. Any notice or communication shall be deemed to have been received:
25.2.1. if delivered by hand, at the time the notice is left at the proper address;
25.2.2. if sent by pre-paid first-class post or other next working day delivery service, at 9.00 am on the second Business Day after posting.
25.2.3. if sent by email, at the time it was sent provided no out-of-office or undeliverable receipt was received back.
25.3. This clause does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.
26.GOVERNING LAW
This agreement and any disputes or claims arising out of or in connection with it or its subject matter or formation (including non-contractual disputes or claims) are governed by and construed in accordance with the laws of England and Wales.
27.JURISDICTION
The parties irrevocably agree that the courts of England have exclusive jurisdiction to settle any disputes or claims arising out of or in connection with this agreement, its subject matter or its formation (including non-contractual disputes or claims).
Schedule 1 – PRODUCTS
1. TRACED PRODUCT
The Traced Product – Trustd MTD – is a Mobile Threat Defence solution which combines AI-powered protection technologies and end-user privacy to protect businesses against mobile-borne cyber threats. Trustd MTD consists of combining the Trustd Mobile Security app for Android, the Trustd Mobile Security app for iOS, the Trustd Mobile Security app for iOS and/or the Trustd Mobile Security Chrome Extension; with either:
the Trustd MTD web-based management platform, and/or,
the Trustd MTD web-based MSP Platform.
2. MANAGED SERVICE
Partners are permitted to issue licenses to and manage the Traced Product on behalf of a Customer via the Traced MSP Platform. Partners are also authorised to provide and charge independently for managed mobile security services using the Traced Product. Such services would typically include management, security monitoring, compliance auditing, threat response, support, integration and professional services.
Schedule 2 – EULA
https://traced.app/traced-control-end-user-license-agreement-eula
Schedule 3 – COMMISSION
Deal Registration – Margin protection during pre-sales consultation
To protect the Partner in their pre-sale consultation of the Traced Product to each customer, Traced honours a Deal Registration process. This process ensures that the Partner receives higher discounts than other Partners who may attempt to provide licenses to the same customer.
The Deal Registration process entails sending an email with the customers’ name and contact details to sales@traced.app during consultation with that customer. Traced will review each Deal Registration submission and provide prompt response with approval providing that:
1. there is ample proof that the Partner is actively engaged with that Customer in relation to the Vendor Service;
2. there are no existing licenses issued to that customer; and
3. there are no active Deal Registrations for that customer.
An approved Deal Registration will automatically expire after 6 months from the date of approval, however, an extension for Deal Registrations can be granted at Traced’s discretion.
Incumbency – Margin protection at renewal
To protect the Partner at renewal of the Traced Product to each customer, Traced honours an incumbency process. This process ensures that the incumbent Partner receives higher discounts than other Partners who may attempt to provide quotation to the same customer at renewal.
The Partner who provided existing licenses of the Traced Product to a customer will automatically hold incumbency to that customer at renewal unless that customer explicitly provides in writing that they no longer wish to renew through The Partner.
Recommended Retail Price (RRP) :
The Recommended Retail Price (RRP) for licenses of the Traced Product is £2 per device per month. This is defined by the “Device Limit” amount set by the Partner for each customer’s account.
Commission Rates:
For licenses issued by the Partner to a customer with whom that Partner holds an active Deal Registration or existing incumbency, the commission rate will be the RRP with an applied discount of 25%
For licenses issued by the Partner to a customer with whom that Partner does not hold an active Deal Registration or existing incumbency, the commission rate will be the RRP with an applied discount of 15%.
NFR Device Subscriptions
Traced may, at its sole discretion, provide the Partner with up to five not-for-resale (“NFR”) device licenses. The Partner may use the NFR device licenses solely within its own organisation for internal testing and demonstration purposes and must not resell, transfer or otherwise make them available to any third party. Traced may change the number of NFR device licenses provided, or withdraw them without prior written notice to the Partner.
Changes to Commercial Terms
Traced may change the RRP and commission rates by giving the Partner at least 60 days’ prior written notice. Unless otherwise stated in the notice, any change will take effect upon expiry of that notice period and will apply to all subscriptions, including existing subscriptions.
Schedule 4 – DATA PROCESSING PARTICULARS
This Schedule 4 sets out the particulars of processing required by Article 28(3) UK GDPR, the list of sub-processors engaged by Traced, and a summary of the technical and organisational measures implemented by Traced in accordance with Article 32 UK GDPR. It is incorporated into, and forms part of, this agreement. In the event of any conflict between this Schedule 4 and the body of this agreement, the body of this agreement shall prevail.
PART 1 – DATA PROCESSING PARTICULARS (ARTICLE 28(3))
| Particular (Article 28(3) UK GDPR) | Details |
| 1. Subject-matter of the processing | The provision by Traced of the Traced Product (the Trustd MTD Mobile Threat Defence platform and associated mobile applications) and the Managed Service to the Partner and, where applicable, the Partner’s customers, in accordance with this agreement. |
| 2. Duration of the processing | For the term of this agreement, and thereafter until Traced has returned or deleted the personal data in accordance with clause 11.4 of this agreement.Retention periods for specific categories of personal data are as follows: • Device telemetry and threat detection events (live): 24 months from date of collection, thereafter anonymised for threat intelligence and product improvement purposes; • Threat detection logs tied to a customer account: deleted on closure of the customer account. • Administrator audit logs (admin actions in the MTD console): 12 months. • Customer master record (B2B account: company name, contact, billing): 6 years post-account closure. • Customer admin user accounts and credentials: 30 days post-removal (audit grace); deleted on account closure. • Support tickets and correspondence: 3 years from ticket closure. • Backup snapshots: 90 days rolling; long-term archives 12 months. • Engineer access audit logs: 12 months (extended to 6 years for any access touching UK or EU personal data).Retention is applied in accordance with Traced’s Data Retention and Erasure Schedule, as updated from time to time. In the event of a personal data breach, litigation hold, or regulatory investigation, retention will be extended for the duration of the relevant matter. |
| 3. Nature and purpose of the processing | Nature: automated and (where necessary) manual processing of personal data to deliver, operate, maintain, secure and support the Traced Product and the Managed Service.Purposes include: • provisioning and managing licences and authorised users of the Traced Product; • detecting, analysing, preventing and responding to mobile-borne cyber threats affecting enrolled devices; • generating device compliance status (including red / amber / green risk-scoring within Trustd MTD) and reporting this to authorised administrators; • providing platform functionality including reporting, alerting, integrations, and management via the Trustd MTD web-based management platform or the Trustd MTD MSP platform; • providing support, troubleshooting and incident response to the Partner and its customers; • billing the Partner in respect of licences issued; and • meeting Traced’s legal, regulatory and security obligations. Note: the processing described at (b), (c), (g) and certain aspects of (d) above may be carried out by Traced as an independent controller in accordance with clause 11.2.1(b) of this agreement. |
| 4. Types of personal data | Device and end-user data: • device identifiers (device ID, hardware serial number, IMEI where available); • device metadata (make, model, operating system, OS version, patch level, language, timezone); • enrolment identifiers (email address used to enrol the device); • network information (IP address, network operator, connection type); • security telemetry (installed applications, application permissions, network connections, security configuration, jailbreak / root status); • threat and compliance events (detections, URL requests to known malicious infrastructure, policy violations, device compliance status); Administrator and operator data: • name, business email address, business phone number (where provided); • account credentials and authentication data; • role, permissions and organisation; • audit and activity logs (actions taken in the platform, IP address, timestamps); Partner contact and billing data: • name, business email address, business address, business phone number of the Partner’s commercial and finance contacts; • licence and invoicing records. Special category data: Traced does not knowingly process special category data (Article 9 UK GDPR) or criminal convictions data (Article 10 UK GDPR) as processor under this agreement. Children’s data: The Traced Product is designed for use by business end-users. Traced does not knowingly process children’s personal data as processor under this agreement. |
| 5. Categories of data subjects | • end-users of mobile devices enrolled in the Traced Product by the Partner or the Partner’s customers (typically the Partner’s or customer’s employees, contractors and other authorised personnel); • administrators and operators of the Traced Product acting on behalf of the Partner or the Partner’s customers; • commercial, technical and finance contacts of the Partner (and, where applicable, of the Partner’s customers). |
| 6. Obligations and rights of the controller (the Partner) | The Partner (or, where applicable, its customer) shall in its capacity as controller: • determine the purposes and means of the processing carried out on its behalf; • ensure it has a valid lawful basis under Article 6 UK GDPR (and, where applicable, Article 9) for the processing; • provide all required transparency information to data subjects under Articles 13 and 14 UK GDPR, including making them aware that Traced acts as processor and, in respect of the controller-level processing described in clause 11.2.1(b), as a separate and independent controller; • respond to data subject requests under Chapter III UK GDPR, with the assistance of Traced as provided under clause 11.4; • assess and, where required, notify personal data breaches to the ICO under Article 33 and to affected data subjects under Article 34, with the assistance of Traced as provided under clause 11.4; • carry out data protection impact assessments where required under Article 35, with the assistance of Traced as provided under clause 11.4; • give lawful and reasonable documented instructions to Traced in respect of the processing; • maintain its own records of processing under Article 30 UK GDPR. |
PART 2 – LIST OF SUB-PROCESSORS
The Partner authorises Traced to engage the sub-processors listed in the table below in accordance with clause 11.6 of this agreement. Traced shall maintain an up-to-date version of this list and shall notify the Partner of any intended addition or replacement in accordance with clause 11.6.
| Sub-processor | Purpose of processing | Location of processing | Transfer mechanism (if outside UK/EEA) |
| Amazon Web Services EMEA SARL (AWS) | Hosting of the Trustd MTD platform, databases (DynamoDB, OpenSearch), storage and application infrastructure, including CloudWatch logging and Cognito authentication. | United Kingdom (eu-west-2, London — production); Ireland; United States (secondary services). | Adequacy (UK / Ireland); AWS DPA including EU Standard Contractual Clauses / UK Addendum for US-hosted services. |
| Sophos Ltd (Sophos Intelix) | Threat intelligence: URL, file and APK-hash reputation lookups to support detection of malicious content on enrolled devices. Anonymous at point of transfer. Optional sub-processor. | United Kingdom / European Union / United States. | Sophos DPA including EU Standard Contractual Clauses / UK Addendum. |
| Google LLC (VirusTotal) | Threat intelligence: file, URL and domain reputation lookups. Anonymous at point of transfer. Optional sub-processor. | United States. | Google EU–US Data Privacy Framework and UK Extension; EU Standard Contractual Clauses where required |
| Google LLC (Firebase Crashlytics) | Crash reporting and diagnostics for the Trustd Mobile Security applications for iOS and Android. | United States (globally distributed Google Cloud infrastructure). | Google DPA; Firebase Data Processing and Security Terms including EU Standard Contractual Clauses / UK supplementary transfer terms. |
| PostHog Inc. | In-app product analytics (CyberSmart-branded instances only). | United Kingdom / European Union / United States. | PostHog Clickthrough DPA including EU Standard Contractual Clauses / UK Addendum; EU–US Data Privacy Framework and UK Extension. |
| Microsoft Corporation (Intune / Microsoft Graph API) | Integration with the customer’s Microsoft Entra ID and Intune environment to support MDM enrolment, compliance signalling and Trustd MTD integration. | United States / European Union (depending on customer tenant region). | Microsoft DPA including EU Standard Contractual Clauses / UK Addendum. |
| browserless.io, Inc. (Browserless) | Dynamic analysis of suspicious URLs using remote browser sessions to support Trustd MTD’s URL reputation service. URLs are anonymous at the point of transfer and contain no user or device identifiers. | United Kingdom—London regional fleet for browser execution. United States may process account, operational or session metadata; confirmation requested from Browserless. | No restricted transfer where submitted URLs are irreversibly anonymous and contain no personal data. |
PART 3 – TECHNICAL AND ORGANISATIONAL MEASURES
The measures set out in this Part 3 summarise the technical and organisational measures implemented by Traced in accordance with Article 32 UK GDPR to ensure a level of security appropriate to the risk. This Part 3 is a summary only and does not constitute an exhaustive list of controls. Traced reserves the right to update the measures from time to time, provided that the level of security is not materially diminished.
| Control area | Measures |
| A. Encryption | • encryption of personal data in transit using industry-standard TLS (minimum TLS 1.2); • encryption of personal data at rest using AWS-native encryption services (AES-256) for databases (DynamoDB, OpenSearch), storage volumes and backup snapshots; • encryption of authentication credentials using industry-standard salted hashing algorithms; • AWS Secrets Manager used for storage and rotation of API keys, client secrets and other sensitive credentials. |
| B. Access control and authentication | • role-based access control (RBAC) for administrator and operator accounts, with least-privilege principles applied; • multi-factor authentication enforced for all Traced personnel access to production systems and administrative interfaces; • AWS Cognito used for authentication of Trustd MTD platform users; • regular review of user access rights and prompt revocation on role change or termination; • segregation of duties between production, testing and development environments. |
| C. Network and infrastructure security | • hosting within Amazon Web Services (production region: eu-west-2, London), with network segmentation and virtual private cloud (VPC) controls; • AWS Web Application Firewall (WAF) protecting API endpoints; • vulnerability scanning of internet-facing infrastructure and remediation in accordance with defined SLAs; • regular penetration testing of the Trustd MTD platform. |
| D. Logging and monitoring | • centralised logging of security-relevant events across the platform; • monitoring of administrator activity and privileged account use; • alerting on anomalous behaviour and security events with defined response procedures. |
| E. Personnel | • personnel authorised to access personal data are subject to written confidentiality obligations that survive termination of their engagement; • engineer access to production personal data is anonymised or redacted where reasonably possible; • background checks appropriate to role prior to engagement; • mandatory information security and data protection training on induction and annually thereafter, delivered via CyberSmart Learn; • endpoint protection deployed on company devices (Sentinel One EDR; CyberSmart Active Protect and/or Trustd MTD) and on contractor / personal devices used for company work (CyberSmart Active Protect and/or Trustd MTD); Egress Defend phishing protection on corporate email. |
| F. Software development lifecycle | • secure development practices including peer code review and dependency vulnerability scanning; • separation of development, testing and production environments; • change management controls for production releases. |
| G. Business continuity and resilience | • regular backups of production data with defined retention and restoration procedures; • documented business continuity and disaster recovery plans, tested periodically; • monitoring of platform availability against defined targets. |
| H. Incident and personal data breach response | • documented incident response procedure covering identification, containment, eradication, recovery and post-incident review; • personal data breach notification to the Partner in accordance with clause 11.4 of this agreement (within 48 hours of becoming aware); • engagement with law enforcement, regulators and, where appropriate, the National Cyber Security Centre in respect of serious incidents. |
| I. Supplier and sub-processor management | • written contracts with all sub-processors imposing equivalent data protection obligations to those in clause 11 of this agreement; • assessment of sub-processors’ security and data protection posture prior to engagement and periodically thereafter; • maintenance of an up-to-date sub-processor register in Part 2 above. |
| J. Governance and assurance | • designated point of contact for data protection matters: Traced’s external Data Protection Officer service, Cybercy Group (DPO@cybercygroup.com); operational data subject rights mailbox: dsar@traced.app; • maintenance of a Record of Processing Activities under Article 30 UK GDPR; • external assurance and certifications: Cyber Essentials Plus certified; • regular internal review of the effectiveness of the measures set out in this Part 3. |
