Product License Terms & Conditions

Controller

The “controller” as defined in Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:

Alias Robotics S.L.
Calle Venta de la Estrella, 6 Pab. 130
Vitoria-Gasteiz 01006
Álava, Spain

Contact data:

Phone: (+34) 945 19 85 15
E-mail: support@aliasrobotics.com
Our Data Protection Point of Contact (PoC) can be reached at support@aliasrobotics.com.

1. CONTRACTING PARTIES

This document establishes the Terms and Conditions of the license to use the product (“Terms”) between:
ALIAS ROBOTICS, S.L., with registered office at CALLE VENTA DE LA ESTRELLA 6, PAB 130, 01006, Vitoria-Gasteiz (Álava), Spain, and tax ID B01561752 (hereinafter, “ALIAS”), and The Client or entity acquiring a license for the product (hereinafter, the “Licensee”).

2. DEFINITIONS

Product: Refers to the set of cybersecurity solutions developed by ALIAS, including but not limited to models, language models (LLMs), agents, software (open or closed source), technical documentation, and associated technologies.
Confidential Information: Any non-public information made available by ALIAS to the Licensee that is of a confidential nature, as detailed in clause 6.

3. PURPOSE OF THE LICENSE

ALIAS grants the Licensee a non-exclusive, non-transferable, and limited license to use the Product solely and exclusively for the purposes previously agreed upon by both parties.
The license does not transfer intellectual property rights of the Product nor does it grant any right to sublicense, sell, rent, modify, or create derivative works from the Product without written consent from ALIAS.

4. INTELLECTUAL PROPERTY

All intellectual property rights over the Product remain at all times with ALIAS. The use of the Product by the Licensee does not imply any transfer of rights.
The Licensee is expressly prohibited from:
- Performing reverse engineering, decompilation, or disassembly of the Product;
- Copying, distributing, reproducing, or creating derivative works;
- Attempting to discover the source code of the Product.

5. CONFIDENTIALITY

During and after the contractual relationship, the Licensee is obligated to maintain strict confidentiality regarding all Confidential Information disclosed by ALIAS, including but not limited to:
- Software, algorithms, technical documentation;
- Business strategies, pricing, financial plans;
- Licensing terms.
- Disclosure to third parties is prohibited without prior written consent from ALIAS. The confidentiality obligation will survive for a period of five (5) years following the end of the contractual relationship.

6. LIMITATION OF LIABILITY

The Product is provided “as is”, without any kind of express or implied warranties. ALIAS shall not be liable for any indirect, incidental, or consequential damages arising from the use of the Product.

7. TERM AND TERMINATION

The license shall be valid for the period agreed upon by the parties and may be terminated due to:
- Breach of the Terms by the Licensee;
- Improper use of the Product or Confidential Information;
- Conclusion of the project or commercial relationship.
Upon termination, the Licensee must cease using the Product and return or destroy all related materials, including Confidential Information.

8. GOVERNING LAW AND JURISDICTION

These Terms shall be governed by the laws of Spain. Any dispute shall be resolved by the Courts of Vitoria-Gasteiz (Álava), Spain.

9. MISCELLANEOUS

Non-transferability: The Licensee may not assign these Terms without written consent from ALIAS.
Severability: If any provision is found to be invalid, the remaining provisions shall remain in effect.
Modifications: Any changes must be made in writing and signed by both parties.

10. PRODUCT AND COMMERCIAL COMMUNICATIONS

ALIAS may contact the Licensee using the contact details provided during the licensing or contractual process for purposes related to the operation and evolution of the Product. Such communications may include product updates, security notifications, research insights, service improvements, training opportunities, events, and information about related products or services offered by ALIAS.

These communications are based on the existing contractual relationship between the parties and ALIAS' legitimate interest in maintaining and improving the service relationship with its customers.

The Licensee may object to receiving such communications at any time by contacting ALIAS or using the opt-out mechanisms provided in the communication itself.

TERMS OF SERVICE
CSI PRO

Product License Terms & Conditions — CSI PRO · version of 20 April 2026

Controller

The “controller” as defined in Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:

Alias Robotics S.L.
Calle Venta de la Estrella, 6 Pab. 130
Vitoria-Gasteiz 01006
Álava, Spain

1. GENERAL INFORMATION

Please read the terms and conditions set out below (the “Terms”) carefully, as they contain relevant information for users and customers of CSI PRO. These Terms apply to all natural and legal persons who access, subscribe to, or otherwise use the Service, whether on their own behalf or on behalf of an organization.

Alias Robotics may make changes to the Terms from time to time, at its sole discretion. In such event, Alias Robotics will provide notice of such changes by sending an email or by posting a notice on its main website at www.aliasrobotics.com.

These Terms are drafted in English, which shall be the governing language for all purposes.

If you have any questions, please contact us at the address indicated in Clause 2 below.

2. CONTACT DATA

Company Alias Robotics S.L.
Address Venta de la Estrella, 6 Pab. 130, Vitoria-Gasteiz 01006 — Álava, Spain
Phone (+34) 945 19 85 15
E-mail and Data Protection Point of Contact support@aliasrobotics.com

3. SUMMARY

This is a non-binding summary to help you understand our full terms. The complete legal document set out below shall prevail.

- Our product: We offer you a non-exclusive license to use CSI PRO, a framework and set of Artificial Intelligence (AI) tools for professionals. You may use our available AI models (“alias-mini”) or connect those from other providers.

- Your responsibility: You are a professional and must use the tool responsibly and ethically, according to the terms and conditions of Alias Robotics. You are responsible for any AI agent you create and for how you use it. Do not use CSI PRO for illegal activities or to attack systems without authorization.

- AI is not perfect: Artificial intelligence may make mistakes, exhibit bias, or generate incorrect information. You must not make critical decisions based solely on Generated Output without qualified human oversight. As a professional, you remain ultimately responsible for reviewing and validating any results produced by the Service.

- Intellectual Property: We own CSI PRO and our models, and no intellectual property rights are transferred under these Terms. You receive a limited, non-exclusive, non-transferable, revocable license to use the Service. You retain ownership of the data you input (“Input”) and the results the AI generates for you (“Output”). You grant us permission to use your data solely in anonymized and aggregated form to improve our services.

- Risks and Liability: We provide the service “as is.” To the maximum extent permitted by law, we disclaim liability for damages arising from the use of CSI PRO. The Company's total aggregate liability arising from or related to the Service shall in no event exceed the amount actually paid by the User to the Company for the Service during the twelve (12) months immediately preceding the event giving rise to the claim. If the User has maintained a subscription for less than twelve (12) months, the Company's maximum liability shall be limited to the amounts actually paid during such period.

- Jurisdiction: Any dispute shall be resolved before the courts of Vitoria-Gasteiz, Álava, Spain.

4. KEY DEFINITIONS

- “Company,” “We,” “Our”: Refers to Alias Robotics S.L., with registered office in Vitoria-Gasteiz, Álava, Spain.

- “CSI PRO” or “Service”: Refers to Cybersecurity Superintelligence, our artificial intelligence service for cybersecurity, which may constitute an AI system within the meaning of Regulation (EU) 2024/1689 on Artificial Intelligence, including the API, code, architecture, documentation, and our proprietary AI models (the “alias” series).

- “User,” “You,” “Your”: Refers to the customer, person or entity that subscribes to and uses our Service.

- “User Content” or “Input”: Refers to any data, text, prompt, or information that the User submits, uploads, or provides to the Service.

- “Generated Output”: Refers to any data, text, code, AI agent, or other result generated by the Service in response to the User Content.

- “Third-Party Models”: Refers to any large language model (LLM), general-purpose AI model within the meaning of Article 3(63) of Regulation (EU) 2024/1689, or other AI model not developed by the Company that may be accessed or connected through CSI PRO.

- “Host Scaffold”: Refers to any third-party compatible AI scaffold, agentic framework, integrated development environment or coding agent within which, alongside which or through which CSI PRO may be deployed, invoked or used, including without limitation Anthropic's Claude Code (interfaced via CSI::Claude), OpenAI's Codex CLI (interfaced via CSI::Codex) and equivalent or comparable products. Each Host Scaffold is operated by its respective provider under such provider's own terms of service and privacy policy, over which the Company has no control. For the purposes of these Terms, the following characteristics are attributed to Host Scaffolds: (a) the Service is designed to interoperate, at user criteria, with Host Scaffolds but does not, in itself, redistribute, modify or sub-license any Host Scaffold or any component thereof (Clause 4.1); (b) the Company does not acquire or claim any intellectual-property right over any Host Scaffold by virtue of such interoperability (Clause 4.3); (c) any User Content, prompts, outputs, code, files or other data exchanged with a Host Scaffold will be transmitted to, and processed by, the relevant Host Scaffold provider under its own terms, and the Company assumes no responsibility in respect of such processing (Clause 4.8); (d) the Company may, at its sole discretion, discontinue interoperability with any Host Scaffold at any time, without giving rise to any refund or liability (Clause 4.5); (e) the User is solely responsible for procuring and maintaining any credentials, subscriptions or authorisations required by the relevant Host Scaffold provider and for complying with such provider's terms of service and acceptable use policies (Clause 6.2); and (f) the Company does not warrant the availability, accuracy, security, legality or fitness for any particular purpose of any Host Scaffold (Clause 6.6).

- “Open Source Components”: Refers to the third-party software components incorporated into, distributed with, or otherwise used in connection with the Service that are licensed under open-source licenses.

- “CSI Backends”: Refers, collectively, to the execution modules through which CSI dispatches requests, namely (i) CSI::Claude, which interfaces with Anthropic's Claude Code (a Host Scaffold); (ii) CSI::Codex, which interfaces with OpenAI's Codex CLI (a Host Scaffold); (iii) CSI::CAI, which interfaces with the Company's proprietary cai-framework; (iv) CSI::GCAI, which interfaces with the Company's proprietary generative AI module; and (v) CSI::CC, which interfaces with the Company's custom construct CC. CSI::Claude and CSI::Codex are deemed Host Scaffolds for the purposes of these Terms; CSI::CAI, CSI::GCAI and CSI::CC are proprietary to the Company.

- “Subscription Plans”: Refers to the different levels of access and pricing for use of the Service, as described on our website.

- “Applicable Laws”: Refers to the laws of Spain and the regulations of the European Union applicable to the Service, including, without limitation, the General Data Protection Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018, of December 5, on Personal Data Protection (LOPDGDD), and Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act).

FULL TERMS AND CONDITIONS

1. ACCEPTANCE OF TERMS

1.1. By accessing or using the Service, You confirm that You have read, understood, and agreed to be legally bound by these Terms and Conditions (“Terms”), as well as our Privacy Policy and all other applicable contractual and legal notices that We may approve in connection with the Service. If You do not agree to these Terms, You must not use the Service. If You use the Service on behalf of an organization, You represent and warrant that You have the authority to bind such organization to these terms.

2. DESCRIPTION OF THE SERVICE

2.1. CSI PRO is an artificial intelligence framework designed for cybersecurity professionals to build and deploy AI agents for a variety of use cases, both offensive (with proper authorization) and defensive. The Service allows use of the Company's proprietary AI models (alias and the rest of the series) and also enables connection with Third-Party Models. CSI is interoperable by design and operates as a wrapper-of-wrappers: it may be used as a stand-alone scaffold or be integrated within, deployed inside, or invoked from third-party AI scaffolds, agentic frameworks, integrated development environments or coding agents (each, a “Host Scaffold”), including by way of example Anthropic's Claude Code and OpenAI's Codex CLI. CSI is internally organised in modules that dispatch to different execution backends, including (i) CSI::Claude (interfacing with Claude Code), (ii) CSI::Codex (interfacing with OpenAI's Codex CLI), (iii) CSI::CAI (interfacing with the Company's proprietary cai-framework), (iv) CSI::GCAI (interfacing with the Company's proprietary generative AI module) and (v) CSI::CC. The Service further incorporates open-source software components, in each case subject to and used in compliance with their respective open-source license terms.

3. SUBSCRIPTION, FEES AND PAYMENTS

- 3.1. Subscription Plans: Access to the Service requires an active subscription. Plan details, including fees (e.g., EUR 350/month), features, and usage limits are published on our official website. While CSI PRO provides extensive capabilities in an unlimited setting capability, usage is subject to the following rate restrictions to ensure responsible use: maximum of 500,000 Tokens Per Minute (TPM) and 60 Requests Per Minute (RPM). Custom enterprise plans are available on request. All enterprise offerings require a minimum term of twelve (12) months.

- 3.2. Billing and Payment: Fees will be billed in advance on a monthly or annual basis, depending on the selected plan. All payments are non-refundable, except where required by law.

Payment Processing. All payments in connection with the Service are processed through a third-party payment gateway provider. The Company does not directly collect, store or process any payment card data, bank account details or other financial instrument information provided by the User. The User acknowledges and agrees that: (i) the processing of payments is subject to the terms of service and privacy policy of the applicable third-party payment gateway provider, in addition to these Terms; (ii) the Company shall not be liable for any act, omission, error, delay or security breach attributable to such third-party payment gateway provider; and (iii) the User is solely responsible for ensuring the accuracy and completeness of the payment information submitted through the payment gateway. The Company shall implement reasonable measures to ensure that any third-party payment gateway provider engaged in connection with the Service complies with the applicable Payment Card Industry Data Security Standards (PCI DSS) and with the Applicable Laws, including Regulation (EU) 2016/679 (GDPR).

- 3.3. Automatic Renewal: Your subscription will automatically renew at the end of each billing cycle unless You cancel by contacting our support team before the renewal date.

- 3.4. Price Changes: We reserve the right to modify our fees. We will notify You of any price change at least thirty (30) days in advance. Continued use of the Service after the effective date of the price change constitutes your agreement to pay the new amount.

- 3.5. Changes to Terms: In order to improve Our services and adapt to customer demand, these Terms are available at https://aliasrobotics.com/cybersecurityai-terms.php. We reserve the right, at our sole discretion, to modify or replace these Terms at any time. Modifications will be binding and effective thirty (30) days after publication at the aforementioned web address. Continued use of the Service after modifications take effect constitutes acceptance of the new Terms.

- 3.6. Service Levels: The Company shall provide support and maintenance services in connection with the Service in accordance with the service levels, response times, availability commitments, escalation procedures, and performance metrics as published on the Company's official website or otherwise made available to the User through the Service's documentation portal. The Company reserves the right to update such service levels from time to time, subject to prior written notice to the User of no less than thirty (30) days.

4. LICENSE AND INTELLECTUAL PROPERTY

- 4.1. Our Intellectual Property: You acknowledge and agree that, when using the Service, no intellectual property rights of CSI PRO shall be transferred, assigned or licensed to You or to any other party or person, in any manner. For the purpose of this clause, “Intellectual Property Rights” means patents, trademarks, service marks, logos, trade names, brand names, copyrights (including rights in computer software), rights in know-how and other intellectual property rights derived from CSI PRO, in each case whether registered (including applications for registration) or unregistered. We are the exclusive owners of the Intellectual Property Rights, title, and interest in and to CSI PRO, including the API, code, architecture, documentation, and our proprietary AI models “alias.” We grant You a limited, non-exclusive, non-transferable, revocable license to use the Service in accordance with these Terms and your Subscription Plan.

The foregoing is without prejudice to any Open Source Components incorporated into the Service, which remain governed by their respective open-source license terms. The Company complies with the attribution, notice, source-availability and other obligations applicable to such Open Source Components. Nothing in these Terms shall be construed as restricting any rights that the User or any third party may have under the applicable open-source licenses with respect to such Open Source Components.

Interoperability with User-installed third-party tools. The User acknowledges that the Service is designed to interoperate with third-party command-line tools and agents that are publicly distributed by their respective providers and that the User obtains and installs from such providers' official distribution channels or from any other source of the User's own choosing. The Service does not, in itself, redistribute these third-party tools (i.e. Claude Code, Codex CLI or any other such third-party tool); thus, the User remains solely responsible for the lawful acquisition, installation, configuration and ongoing use of such tools in accordance with the terms made available by the respective providers.

- 4.2. Local adjustments to User-installed Third-Party Tools: Where the User elects to do so, the Service may apply local configuration adjustments to the User's own installed instance of third-party tools. Such adjustments are initiated solely by the User and may include, without limitation, the minimisation of telemetry and the routing of network requests through the Service's local routing proxy. All adjustments are performed on the User's own copy of the relevant software at the User's express request, and in furtherance of the principles of data minimisation (Article 5(1)(c) GDPR), data protection by design (Article 25 GDPR) and interoperability (Article 100.5 of the Spanish Intellectual Property Act). For the avoidance of doubt, the adjustments described in this clause are strictly limited in scope and shall not entail the modification, alteration, reverse-engineering or decompilation of the source code, object code or binary files of any third-party software installed by the User. All such adjustments are carried out in accordance with generally accepted industry practices and standards for software interoperability and system administration.

- 4.3. No claim of rights over Third-Party Tools: The Company does not claim, and shall not be construed as claiming, any right of redistribution, modification for redistribution or sub-licensing in respect of any third-party tool that has not been released by its author under an open-source license authorising such acts. Furthermore, the Company does not acquire or claim any intellectual-property right over any third-party tool by virtue of the interoperability provided by the Service. In respect of any third-party components that have been released by their authors under permissive open-source licenses and that may be incorporated into the Service, the Company shall comply with the attribution and notice obligations applicable to such components, as further described in Clause 4.1 above.

- 4.4. Trademarks: The User acknowledges that “Anthropic”, “Claude”, “Claude Code”, “OpenAI”, “Codex” and any other names of third-party products or services referred to in the Service or in these Terms are trademarks or registered trademarks of their respective owners. Any reference to such trademarks in the Service and in these Terms is made solely for descriptive and interoperability purposes, in accordance with applicable trademark laws, and shall not be construed as implying any sponsorship, endorsement, affiliation or commercial partnership between the Company and the respective trademark owners. For the avoidance of doubt, CSI, alias, alias1, alias2-mini, alias2, and the alias series are exclusively owned by the Company.

- 4.5. Right to discontinue interoperability with any Third-Party Component: The Company reserves the right, at its sole discretion and at any time, to disable, remove, limit, replace or otherwise discontinue the interoperability of the Service with any Third-Party Component (including any Host Scaffold, Third-Party Aggregator, User-installed third-party tool or Open Source Component). Such right may be exercised, in particular, and without limitation, in any of the following circumstances: (a) where the relevant third-party provider so requests; (b) where the Company receives a cease-and-desist notice, take-down request, formal objection or comparable communication from such third-party provider or its representatives; or (c) where the Company reasonably considers that continued interoperability is, or may become, inconsistent with the applicable third-party terms or with the Applicable Laws. The Company shall use reasonable efforts to notify Users of any such discontinuance with reasonable advance notice where practicable. The discontinuance of interoperability with any Third-Party Component pursuant to this clause shall not give rise to any refund, credit, indemnity or other liability of the Company towards the User. The User expressly acknowledges and accepts that: (i) the availability of any specific Third-Party Component is not a material term of these Terms; (ii) the User has assessed and assumed the operational risk of relying on any given Third-Party Component; and (iii) no fees previously paid to the Company shall be refundable on account of any such discontinuance.

- 4.6. User Content (Input): You retain all ownership rights over your User Content. You represent and warrant that You have all necessary rights to provide your Input to the Service and that it does not infringe any laws or third-party rights. By using the Service, You grant us a worldwide, non-exclusive, royalty-free license to use, reproduce, modify, and process your Input solely for the purpose of providing and maintaining the Service. To the extent that any User Content contains personal data, such data shall be processed exclusively in accordance with the Applicable Laws and the Data Processing Agreement set out in these Terms, and the license granted herein shall not be construed as authorizing any processing of personal data beyond what is strictly necessary for the provision of the Service.

- 4.7. Generated Output: You own the Generated Output. Subject to this section, You hereby grant us a perpetual, worldwide, non-exclusive, royalty-free license to use, copy, modify, and create derivative works from User Content and Generated Output, only in anonymized and aggregated form (whereby anonymization shall be carried out in accordance with the standards and guidance issued by the data protection authorities under the GDPR, ensuring that re-identification of data subjects is not reasonably possible), in order to improve, develop, and commercialize our products and services. For the avoidance of doubt, no personal data shall be retained or used under this license beyond what is permitted by the data protection regulations.

- 4.8. Use of Data; Exclusion from model training: The Company may collect, record and process User Content, Generated Output and Service-related telemetry and metadata, including, without limitation, prompts and inputs submitted by the User, outputs returned by the alias series of models, by any Third-Party Models accessed through the Service and by any Host Scaffold within which CSI PRO is operated, code, files or other artefacts generated during a session, tool invocations, execution logs, error traces and performance metrics (collectively, “Usage Data”), for the following purposes: (i) the provision, operation, maintenance and security of the Service; (ii) the training, fine-tuning and improvement of the Company's proprietary AI models (the alias series), of CSI::CAI, CSI::CC and of CSI::GCAI; (iii) benchmarking, quality assurance and comparative evaluation of CSI against Host Scaffolds and Third-Party Models; and (iv) research and development in the field of cybersecurity, including the production of academic or industry publications and the responsible disclosure of vulnerabilities. Zero-Data for training applies exclusively to certain Enterprise subscriptions, which will be provided upon request. For such subscriptions, the Company will not collect, record or process Usage Data for the purposes set out in subsections (ii), (iii) and (iv) above, and will process Usage Data solely to the extent strictly necessary for the provision, operation, maintenance and security of the Service (subsection (i)). All other plans, including monthly and individual subscriptions, remain subject to the collection and processing of Usage Data as described in this Clause. Usage Data processed for purposes (ii), (iii) and (iv) shall be used solely in anonymised and aggregated form, in accordance with the anonymisation standards referenced in Clause 4.3 above and with applicable European regulations, including the GDPR and Regulation (EU) 2024/1689 (AI Act).

All data is collected, retained and recorded in compliance with applicable European regulations, including the AI Act, and any use thereof shall be conducted with due consideration of any limitations or preferences communicated by the User.

Exclusion from training. Users may request that their Usage Data be excluded from training or model-improvement activities by notifying Alias Robotics at the contact address set out in Clause 2. For the avoidance of doubt, such exclusion right is not available to Users on PRO, monthly, individual or other non-Enterprise subscription plans. Any such exclusion shall not affect the use of Usage Data to the extent strictly necessary for the provision, operation, maintenance and security of the Service.

5. USE

- 5.1. Purpose of CSI: The intended purpose of the Service is to enable Users to build, deploy and manage AI-driven agents for cybersecurity use cases, including, without limitation, authorized penetration testing, vulnerability assessment, threat detection, incident response automation, and network defence.

Professional use. CSI PRO is not intended for use by consumers or non-professional end users, nor for any purpose unrelated to cybersecurity. The Service may be used in conjunction with the Company's proprietary AI models (alias series) or with Third-Party Models connected through the platform.

Additional information. Further information on the general characteristics, capabilities, limitations, and level of accuracy of the AI models used in the Service shall be made available by the Company in accordance with Clause 6.2 of these Terms.

- 5.2. User's personal data obligations as Data Controller: The User guarantees that they have the necessary legal basis to input personal data into the Service and undertakes to comply with the applicable data protection legislation. In particular, the User shall be responsible for: (a) informing data subjects in accordance with Articles 13 and 14 of the GDPR; (b) obtaining the relevant consents or establishing an appropriate legal basis under Article 6 (and, where applicable, Article 9) of the GDPR; (c) responding to requests for the exercise of data subject rights under Articles 15 to 22 of the GDPR; (d) carrying out, where required, a data protection impact assessment pursuant to Article 35 of the GDPR as regards the processing of personal data when using CSI PRO; and (e) refraining from entering special categories of data within the meaning of Article 9 of the GDPR without a valid legal basis and appropriate safeguards.

- 5.3. Acceptable use: You agree to use CSI in a professional, ethical manner and in compliance with these Terms and all Applicable Laws. Acceptable use includes, among others, carrying out authorized penetration testing, automating security tasks, and defending your network.

- 5.4. Prohibited use: You agree not to use the Service to:

  • Engage in any illegal, fraudulent, or malicious activity.
  • Perform attacks or penetration tests on systems for which you do not have explicit written authorization.
  • Develop or distribute malware, viruses, or any other harmful code.
  • Infringe the intellectual property rights, privacy, or any other rights of third parties.
  • Generate defamatory, obscene, hateful, or discriminatory content.
  • Attempt to reverse-engineer, decompile, or discover the source code of CSI or the “alias” models.
  • Use the Service in a way that could damage, disable, or overload our infrastructure.
  • Use the Service for any purpose that constitutes a prohibited practice within the meaning of Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act).

6. THIRD-PARTY MODELS

- 6.1. Third-Party Models: As a cybersecurity framework, CSI PRO allows you to connect and use Third-Party Models (other LLMs). By doing so, You acknowledge and agree that the same acknowledgements and allocations of responsibility apply, mutatis mutandis, to any Host Scaffold within which the User chooses to operate CSI PRO, including without limitation Anthropic's Claude Code (interfaced via CSI::Claude) and OpenAI's Codex CLI (interfaced via CSI::Codex). In particular, the User acknowledges and agrees that the use of any Host Scaffold is governed by such Host Scaffold provider's own terms of service and privacy policy.

- 6.2. API credentials, upstream authorisation and User liability: Where access to a Third-Party Model or a Host Scaffold requires API credentials, subscription, account or authorisation issued by the relevant third-party provider (such as, by way of example, an Anthropic API key for CSI::Claude or an OpenAI API key for CSI::Codex), the User shall be solely responsible for procuring, providing and maintaining such valid credentials with its own legal title. The User represents, warrants and undertakes that: (i) it has lawfully obtained and is duly authorised to use any such credentials in connection with the Service; (ii) its use of the Service in combination with any Third-Party Model or Host Scaffold complies at all times with the applicable terms of service, acceptable use policies and other contractual requirements of the corresponding upstream provider; (iii) it shall not use the Service to share, resell, redistribute or otherwise extend access to a third-party subscription beyond the perimeter authorised by such upstream provider; and (iv) it shall be solely liable vis-Ă -vis the relevant upstream provider for any breach of such terms attributable to the User's use of the Service. The Company makes no representation or warranty as to whether any given upstream provider permits the use of the Service with its products, nor shall the Company be liable for any termination, suspension, throttling, rate-limiting or other adverse action taken by any upstream provider against the User.

- 6.3. Third-Party Aggregator Services: The User acknowledges that, where the Service is configured to access a Third-Party Model or Host Scaffold through a third-party aggregation, routing or marketplace service (such as, by way of example, OpenRouter or comparable products) (each, a “Third-Party Aggregator”), the data flow and contractual chain involve multiple consecutive third parties, namely (a) the Third-Party Aggregator itself, and (b) the underlying model provider to which the Aggregator relays the request. The User acknowledges and agrees that: (i) the use of any Third-Party Aggregator is governed by such Aggregator's own terms of service and privacy policy; (ii) the User must independently comply with the terms of service of both the Aggregator and the underlying model provider, including any restrictions on downstream redistribution or commercial exploitation; (iii) the Company makes no representation as to which underlying model provider, jurisdiction or data-handling regime applies in connection with any given request routed through a Third-Party Aggregator; and (iv) the Company shall not be liable for any act or omission of any Third-Party Aggregator or of any underlying model provider accessed thereby.

- 6.4. User-Supplied Custom Backends: The User may, at its sole discretion and risk, configure the Service to dispatch requests to a custom or self-hosted backend endpoint (including, by way of example, locally-hosted models, models served via a User-operated inference server or any other endpoint not operated by the Company) (each, a “Custom Backend”). The Service is provided in this configuration strictly “as is”, and the Company: (i) does not control, audit, validate or endorse any Custom Backend, including with respect to its security, accuracy, legality, intellectual-property status or compliance with any third-party rights; (ii) shall not be liable for any act, omission, defect, vulnerability or breach attributable to any Custom Backend or to the model or data hosted thereon; and (iii) shall not be obliged to provide support, troubleshooting or warranty in respect of any failure of the Service caused or contributed to by any Custom Backend. The User shall be solely responsible for ensuring that any Custom Backend is operated in compliance with all Applicable Laws and with all licenses applicable to the models, weights, datasets or software used in or made available through such Custom Backend.

- 6.5. Catch-all, Third-Party Components, Operational Architecture and Future Configurations: The User acknowledges and agrees that the Service is an interoperable framework that may, at present or at any time in the future, (i) interface with, dispatch to, or operate within or alongside any third-party artificial-intelligence model, scaffold, agentic framework, integrated development environment, coding agent, aggregator, marketplace, routing service, model hub, inference provider or any other third-party software or service (including any successor, fork or analogue thereof and regardless of whether such third party is specifically identified in these Terms); (ii) incorporate, redistribute or otherwise make use of third-party software components, including those licensed under open-source licenses; (iii) operate a local routing proxy, telemetry-filtering mechanism, cost-accounting ledger, configuration framework, observability layer or other operational instrumentation that mediates, observes, filters, translates, logs or otherwise modifies the technical interactions between the Service and any such component; and (iv) permit the User to configure custom, self-hosted or User-supplied backend endpoints (each of the foregoing, individually and collectively, a “Third-Party Component”).

- 6.6. Third-Party Components: In respect of any and all Third-Party Components (including any Third-Party Model, Host Scaffold, Third-Party Aggregator, Custom Backend and any other future component of analogous nature), the following provisions shall apply at all times and shall supplement, and not derogate from, the more specific provisions of these Terms, including without limitation the provisions of Clause 4:

(a) Governing terms. The use of any Third-Party Component is governed by the terms of service, acceptable use policies, license terms and privacy policies of the relevant third-party provider, in addition to these Terms. The User is solely responsible for reviewing, accepting and complying with such third-party terms.

(b) Credentials and access. Where access to a Third-Party Component requires credentials, subscriptions, authorisations or accounts issued by the relevant third-party provider, the User shall procure, hold and use such items in its own name and shall not use the Service to share, resell or redistribute access in any manner not authorised by such provider.

(c) Data transmission. Any User Content, prompts, completions, code, files or other data exchanged with a Third-Party Component will be transmitted to, and processed by, the relevant third party in accordance with its own terms. The Company makes no representation and assumes no responsibility in respect of such processing.

(d) No warranty or liability. The Company does not control any Third-Party Component and does not warrant its availability, accuracy, security, legality or fitness for any particular purpose. The Company shall not be liable for any act, omission, defect, change, suspension, termination, rate-limiting or other adverse measure attributable to any Third-Party Component or to its provider.

(e) Routing and filtering mechanism. The Company is entitled to operate the routing, filtering, logging, cost-accounting, translation and configuration mechanisms referred to above for the legitimate purposes of providing, maintaining, securing, optimising and improving the Service, in accordance with the principles of data minimization (Article 5(1)(c) GDPR) and data protection by design (Article 25 GDPR), without prejudice to the User's own obligations under the terms of any Third-Party Component.

(f) Indemnification. Without prejudice to Clause 16, the User shall indemnify, defend and hold harmless the Company against any claim, complaint or proceeding brought by any provider of a Third-Party Component arising from or in connection with the User's failure to comply with the requirements set out in this clause.

(g) Future components. This clause shall apply, mutatis mutandis, to any model, scaffold, aggregator, service, technology, configuration or operational mechanism that may be incorporated into, made accessible through, or developed in connection with the Service after the date of these Terms, with the same allocation of responsibilities and risks as set out above, regardless of whether such item is specifically identified herein.

- 6.7. The use of Third-Party Models is governed by such third parties' terms and conditions and privacy policies. In accordance with the provisions of Clause 4.3 of these Terms, the Company does not acquire or claim any intellectual property right over any Third-Party Component by virtue of the interoperability provided by the Service.

- 6.8. The Company does not control and is not responsible for the performance, security, accuracy, availability, legality, results, or data use of Third-Party Models.

- 6.9. Any User Content you submit to a Third-Party Model is shared at Your own risk. You are solely responsible for reviewing and complying with the contractual and legal requirements applicable to any Third-Party Model that You may use.

- 6.10. Model Transparency: In compliance with the transparency obligations set out in Regulation (EU) 2024/1689 on Artificial Intelligence, the Company shall publish and keep up to date, at least on an annual basis or upon any material update to the AI models used in the Service, information in relation to the AI models produced by Alias Robotics (alias series) and used in CSI PRO. Such information shall be made available at www.aliasrobotics.com and, where applicable, through the Service's documentation portal.

In particular, as regards CSI PRO, we offer you the following information:

(a) General Characteristics

The Service consists of artificial intelligence (AI) models designed to support cybersecurity professionals in both defensive and offensive operations. These systems assist users by analyzing security-related data, identifying patterns, and generating recommendations to improve security decision-making.

Typical use cases include threat analysis, vulnerability assessment, security testing, incident investigation, and operational decision support. The Service is intended as an assistive tool and not as a fully autonomous decision-making system.

(b) Capabilities and Known Limitations

The AI models can process security-related information, detect patterns, generate insights, and support technical analysis in cybersecurity workflows.

However, all AI systems have inherent limitations. Outputs may contain inaccuracies, incomplete reasoning, false positives, false negatives, or context-dependent errors. Performance depends heavily on the quality of the data and instructions provided by users.

These systems have been tested in representative cybersecurity scenarios, but no AI model can guarantee complete accuracy, robustness, or reliability in all operational conditions.

(c) Foreseeable Risks

Foreseeable risks include incorrect analysis, misleading recommendations, overreliance on automated outputs, or misuse resulting from insufficient contextual input.

Improper use may negatively affect security operations, confidentiality, privacy, or produce adverse effects if outputs are applied without adequate validation.

Users are responsible for clearly defining objectives, constraints, and acceptable risk boundaries when interacting with the Service.

(d) Human Oversight Measures

Human oversight is essential for the safe and effective use of the Product.

All outputs generated by the AI must be reviewed and validated by qualified human operators before being used in operational or strategic decisions. Users must apply professional judgment and explicitly communicate relevant constraints, assumptions, and risk tolerances through prompts and instructions.

As with any AI system, cybersecurity AI is inherently imperfect and must operate under continuous human supervision. Final responsibility for risk management and decision-making remains with the human operator.

The Company shall notify Users of any material update to the information published under this Clause by means of a notice on its official website or by email.

- 6.11. Traceability and Activity Logging: For systems classified as high-risk under Regulation (EU) 2024/1689 on Artificial Intelligence, the Company will maintain appropriate log records, enabling traceability of system functioning, human oversight, and auditing by competent authorities. Such records shall be retained for a minimum period of six (6) months from the date of generation, or for such longer period as may be required by applicable law, and shall be protected with appropriate technical and organizational measures ensuring their integrity, availability, and confidentiality.

- 6.12. Risk Classification and Obligations under the EU AI Act: The Company will periodically assess the classification of its services under Regulation (EU) 2024/1689 on Artificial Intelligence. For systems categorized as high-risk, the Company shall: (a) carry out a conformity assessment; (b) implement a risk management system; (c) maintain activity logs and retain usage data; (d) prepare and keep up to date technical documentation; (e) adopt measures for human oversight; (f) ensure data quality; and (g) implement appropriate cybersecurity measures. Any use that contravenes the prohibited AI practices identified in said Regulation shall be strictly prohibited.

7. DATA PRIVACY AND CYBERSECURITY

The protection of your data is fundamental to us. Our collection and use of personal and other information is described in our Privacy Policy. Within the meaning of the General Data Protection Regulation (GDPR), you act as the “Data Controller” of your User Content, and the Company acts as the “Data Processor”.

The User acknowledges that the Service operates a local routing proxy that intermediates the requests issued by each execution backend of CSI (including CSI::Claude, CSI::Codex, CSI::CAI and CSI::GCAI) for the purposes of:

  • unified telemetry and audit logging;
  • cost accounting and rate-limit management;
  • translation between the wire protocols of the relevant Third-Party Models and the alias API; and
  • homogenising the user experience across backends.

To the extent that User Content, Generated Output or other Usage Data are processed through such proxy, such processing shall be subject to the Data Processing Agreement set out in Schedule I and to the security measures described in this Clause.

Telemetry filtering. The User acknowledges that the Service applies a multi-layered filtering mechanism — consisting of environment-variable configuration, application-level filtering and proxy-level allow-listing — that removes operational telemetry signals (such as version, error and analytics call-home traffic) emitted by certain upstream binaries distributed as Open Source Components (in particular, the patched Claude Code and Codex CLI components) before such signals leave the User's local environment. Such filtering is implemented in furtherance of the principles of data minimization (Article 5(1)(c) GDPR) and data protection by design (Article 25 GDPR), and shall not be construed as an attempt to conceal from any upstream provider any User Content, prompts, completions or other data that the User chooses to submit to such provider through the Service. For the avoidance of doubt: (i) all User Content and Generated Output that the User submits to a Third-Party Model or Host Scaffold through the Service continues to be transmitted to, and processed by, the corresponding upstream provider in accordance with such provider's own terms of service and privacy policy, as further set out in the NOTICE contained in Clause 4.4; and (ii) the User remains solely responsible, under Clause 6 of these Terms, for ensuring that its use of the Service complies with the acceptable use policy, the usage policy and any other applicable terms of the corresponding upstream provider. The Company will, where technically feasible, expose configuration options enabling the User to adjust or disable the telemetry-filtering mechanism.

7.1. Processing of personal data of signers and contact persons for the execution of the Service

Both parties (the Company and the User) are aware of and obliged to comply with Regulation (EU) 2016/679, of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter, the “GDPR”), regarding the processing of personal data.

The Company shall process Your contact data — including contact and professional data — for the execution of the Services.

You undertake to inform Your own staff that their personal data may be processed for the purpose of performing these Terms. The legal basis for such processing is the performance of the contractual relationship between the parties and the provision of the Service.

The Company shall retain Your data for the duration of the contractual relationship and, thereafter, for a period of five (5) years to address any liability that may arise in connection with the provision of the Service.

You, Your legal representative, as well as any person whose personal data may be processed for the execution of these Terms, may exercise their rights of access, rectification, deletion, opposition, data portability and limitation of processing before the Company, by means of written notification, or through the following email address: support@aliasrobotics.com, specifying the reason to which the request is referred. In the event that the request is not satisfied, the data subject shall have the right to file a complaint before the relevant data protection authorities.

7.2. Access to personal data by the Company as Data Processor

As regards the processing of personal data where You are the data controller and the Company is the data processor, the parties shall duly enter into a data processing agreement (“Data Processing Agreement” or “DPA”), as an integrated element of this agreement between the parties. You agree that the processing of personal data will be subject to the provisions of the DPA annexed to these Terms.

7.3. Cybersecurity

Nature of the Service and allocation of responsibilities. The Service comprises the provision by the Company of an artificial intelligence framework and set of tools for cybersecurity professionals, including the Company's proprietary AI models (alias series) and the ability to connect Third-Party Models. The Company acts as the provider of the platform infrastructure, AI models, and related services, which determines the following model of responsibility in relation to cybersecurity:

  • The Company is responsible for the security of its own systems, platforms, and internal processes used for the provision and operation of the Service, as well as for the security controls described in this Clause that fall within its competence as service provider. The Company shall not be liable for the acts or omissions of Third-Party Model providers, third-party infrastructure providers, or other third parties outside its sphere of control.
  • The User is responsible for the security of its own systems, networks, devices, and infrastructure that interact with or connect to the Service. In particular, the User shall be responsible for: (i) ensuring the security and integrity of any User Content submitted to the Service; (ii) the selection, configuration, and use of any Third-Party Models connected through the platform, including compliance with the security requirements applicable thereto; (iii) the implementation and maintenance of adequate security measures on the systems and environments under its management or control; (iv) the proper management of user access rights and permissions within its organisation; and (v) compliance with all Applicable Laws in relation to the cybersecurity aspects of its use of the Service. The Company shall not be liable for any security incident, data breach, or loss arising from the User's failure to comply with the obligations set out in this paragraph.

Risk management measures. The Company has implemented appropriate and proportionate technical, operational, and organisational measures to manage the risks posed to the security of the network and information systems used in the provision of the Service. Such measures include, among others: (i) information security policies and risk analysis; (ii) incident handling; (iii) business continuity, including backup management, disaster recovery, and crisis management; (iv) supply chain security; (v) security in the acquisition, development, and maintenance of network and information systems; (vi) policies and procedures to assess the effectiveness of cybersecurity risk-management measures; (vii) basic cyber hygiene practices and cybersecurity training; (viii) policies and procedures relating to the use of cryptography and, where appropriate, encryption; (ix) human resources security, access control policies, and asset management; and (x) the use of multi-factor authentication or continuous authentication solutions, where appropriate.

Incident notification. The Company shall notify, without undue delay, the competent CSIRT or authority of any incident that has a significant impact on the provision of the Service. For these purposes, an incident shall be deemed to have a significant impact where it has caused or is capable of causing serious operational disruption to the Service or significant financial loss to the Company, or where it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

Communication to the User. Where a significant incident is likely to adversely affect the provision of the Service, the Company shall notify the User without undue delay. Likewise, where a significant cyber threat exists that may affect the User, the Company shall communicate, without delay, the measures or remedies that the User may adopt in response to such threat and, where appropriate, the cyber threat itself. Such communication shall be provided free of charge and in plain, intelligible language.

Where a security incident also constitutes a personal data breach, the Company shall notify the User without undue delay, providing the information necessary for the User to comply with its own notification obligations under data protection legislation. The Parties acknowledge that the cybersecurity incident notification flows provided for in this Clause and those relating to personal data breaches may coexist and shall be coordinated in order to comply with the different deadlines and content requirements imposed by each regulatory framework.

User cooperation. The User shall cooperate with the Company to the extent necessary to enable the proper implementation of the cybersecurity measures affecting the systems or equipment under the User's management or control, in particular where the Service requires interaction with the User's own infrastructure. The User shall notify the Company, without undue delay, of any incident or vulnerability of which it becomes aware that could affect the security of the Service.

Cooperation with competent authorities. The Company shall cooperate with the competent national authorities and the designated CSIRT in the performance of their supervisory and enforcement functions under applicable cybersecurity regulations. The mere act of notifying an incident to the competent authority or CSIRT shall not increase the liability of the Company towards Users or third parties in respect of the notified incident.

Update of measures. The security measures described in this Clause may be updated by the Company at any time in order to adapt to the evolving threat landscape and to applicable regulatory changes, in particular those arising from the national legislation transposing Directive (EU) 2022/2555 and from the implementing acts adopted thereunder. The Company shall communicate to the User any material modification of such measures that may affect the level of security of the Service.

8. RESPONSIBLE USE OF AI AND LIMITATIONS

- 8.1. Nature of AI: You acknowledge that artificial intelligence models are probabilistic in nature and may generate incorrect, biased, or incomplete information (“hallucinations”). Generated Output does not constitute professional advice and should not be relied upon as such.

- 8.2. Warning on Critical Decisions: The Service is not designed or intended to be used in making critical, high-risk, or automated decisions that may have significant legal, financial, or physical impacts without independent, qualified human oversight.

- 8.3. Human Oversight Obligation: As a cybersecurity professional, you are obliged to independently review, validate, and supervise any Generated Output before relying on it or acting upon it. You are solely responsible for the consequences of your use of the Service.

9. DISCLAIMER OF WARRANTIES

- 9.1. Disclaimer: To the maximum extent permitted by law, the Service is provided “as is” and “as available.” The Company expressly disclaims all warranties of any kind, whether express, implied, or statutory, including, without limitation, the implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant that the Service will be uninterrupted, secure, accurate, reliable, or error-free.

- 9.2. Exclusion of Liability for Cloud Availability: The Company, as the Licensor, will make reasonable efforts to keep online services available. However, the User acknowledges that access to the software and associated cloud services may be interrupted by causes beyond the Licensor's control, including, but not limited to, third-party failures, power outages, cyberattacks, maintenance updates, technical incidents, or force majeure. Accordingly, the Licensor shall not be liable for unavailability, data loss, delays, transmission errors, or for indirect, incidental, or consequential damages resulting from such interruptions.

10. LIMITATION OF LIABILITY

- 10.1. To the maximum extent permitted by law, in no event shall the Company, its affiliates, directors, employees, or agents be liable for any indirect, incidental, special, consequential, or punitive damages, including, without limitation, loss of profits, data, use, goodwill, or other intangible losses, resulting from:

  • Your access to or use of, or inability to access or use, the Service;
  • Any conduct or content of third parties on the Service;
  • Any content obtained from the Service; and
  • Unauthorized access to, use of, or alteration of your transmissions or content.

- 10.2. The Company's total aggregate liability arising from or related to the Service shall in no event exceed the amount actually paid by the User to the Company for the Service during the twelve (12) months immediately preceding the event giving rise to the claim. If the User has maintained a subscription for less than twelve (12) months, the Company's maximum liability shall be limited to the amounts actually paid during such period.

11. MODIFICATION OF TERMS

11.1. We reserve the right, at our sole discretion, to modify or replace these Terms at any time. If a revision is material, we will provide notice at least thirty (30) days prior to the new terms taking effect. What constitutes a material change will be determined at our sole discretion. Your continued use of the Service after the effective date of such changes constitutes acceptance of the new Terms.

12. TERMINATION

- 12.1. Termination by User: You may cancel your subscription and stop using the Service at any time by accessing the CSI PRO subscription management portal or enquiring at support@aliasrobotics.com.

- 12.2. Termination by Company: We may suspend or terminate your access to the Service immediately, without prior notice or liability, if you materially breach these Terms. Upon termination, your right to use the Service will cease immediately.

13. GOVERNING LAW AND JURISDICTION

13.1. These Terms shall be governed by and construed in accordance with the laws of Spain and the European Union, without regard to its conflict of law provisions. You agree to submit to the exclusive jurisdiction of the courts of Vitoria-Gasteiz, Spain, to resolve any dispute arising out of or in connection with these Terms or the Service.

14. GENERAL PROVISIONS

- 14.1. Entire Agreement: These Terms, together with our Privacy Policy and any other legal notices that We may publish in connection with the Service, constitute the entire agreement between You and the Company with respect to the Service.

- 14.2. Severability: If any provision of these Terms is held to be invalid or unenforceable, that provision shall be limited or eliminated to the minimum extent necessary, and the remaining provisions shall remain in full force and effect.

- 14.3. No Waiver: The Company's failure to enforce any right or provision of these Terms shall not be deemed a waiver of such rights.

- 14.4. Force Majeure: Neither party shall be liable for delays or failures caused by force majeure, including, but not limited to, natural disasters, armed conflicts, acts of terrorism, widespread failures of telecommunications or power providers, large-scale cyberattacks, or any other event beyond the reasonable control of the affected party, provided that such party promptly notifies the other party of the circumstance without undue delay.

15. INCIDENTS AND CLAIMS

15.1. A procedure will be made available for Users, authorities, or third parties to report security incidents, errors, biases, or any potential violation. The Company will investigate such reports and, where appropriate, take corrective measures and communicate results to affected parties and, when applicable, take the measures and make the communications in accordance with Clause 7.3 of the present Terms.

16. INDEMNIFICATION

- 16.1. You agree to indemnify, defend, and hold harmless the Company, its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, liabilities, losses, costs, and expenses (including reasonable attorneys' fees) arising out of or related to:

  • Your misuse of the Service;
  • Your violation of these Terms or of Applicable Laws (including data protection laws);
  • Any User Content or Generated Output you submit, create, or distribute through the Service;
  • Any third-party claim alleging that your use of the Service infringes or violates their rights;
  • Any claim, complaint or proceeding brought by any provider of a Third-Party Model or Host Scaffold (including, by way of example, Anthropic, Inc. or OpenAI, OpCo. LLC) arising from or in connection with the User's failure to comply with the applicable terms of service, acceptable use policies or other contractual requirements of such upstream provider in connection with the User's use of the Service, including, without limitation, any unauthorised sharing of credentials, any use of the Service to bypass restrictions imposed by such upstream provider, or any use of Generated Output in a manner that contravenes such upstream provider's terms.

- 16.2. The Company reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you agree to cooperate fully with such defense.

17. CONTACT

If you have any questions about these Terms, please contact us at support@aliasrobotics.com.

SCHEDULE I
Data Processing Agreement

1. BACKGROUND AND DETAILS OF THE DATA PROCESSING

- 1.1. This Data Processing Agreement (the “DPA” or the “Agreement”) applies only to the extent Alias Robotics, S.L. (the “Data Processor”) accesses and processes personal data on behalf of a customer (“Customer” or “Data Controller”) under the Terms and Conditions of the CSI PRO Services (the “Services”).

To the extent applicable, this DPA (including its Appendix) shall form part of and shall continue in force for as long as Alias Robotics accesses and processes personal data on behalf of the Customer in the context of the provision of the Services. This shall include in particular, but not be limited to, the processing of the categories of Personal Data relating to the data subjects and for the purposes listed in Appendix 1 to this DPA.

- 1.2. The present DPA shall be governed in accordance with data protection regulations and, in particular, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter, the “GDPR”), as well as the Spanish Organic Law 3/2018 of 5 December, on the Protection of Personal Data and Guarantee of Digital Rights (“LOPDGDD”).

2. DEFINITIONS

- 2.1. In this Exhibit, the following terms will have the meanings set out below:

  • “Personal data”, “process/processing”, “controller” and “data subject” shall have the same meaning as in the GDPR.
  • “Personal Data” refers to the data categories controlled by the Controller, identified hereto in Appendix 1 of this Schedule, the content of which shall be processed by the Data Processor.
  • “Data sub-processor” means any processor engaged by the Data Processor or by any other sub-processor of the data who agrees to receive from the Controller or from any other sub-processor of the Controller data exclusively intended for processing activities to be carried out on behalf of the Controller and in accordance with its instructions, on the terms set out herein.
  • “Technical and organizational security measures” means those measures intended for protecting personal data against accidental or unlawful destruction or accidental loss, alteration, unauthorised disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing.

3. INSTRUCTIONS

- 3.1. According to Article 28 of the GDPR, the Customer allows the Data Processor to access and process the personal data that is necessary to provide the Service. This is without prejudice to the provisions on personal data included in the principal Terms governing the CSI PRO Service.

- 3.2. In particular, the Data Processor shall have access to and process the Personal Data contained in Appendix 1 of this DPA.

- 3.3. Additional instructions with regard to the processing of Personal Data may be issued by the Data Controller. Such instructions should be provided in advance and in writing by the Customer, subject to the Data Processor's right to charge additional sums at its current rates should the scope of the agreed offerings be exceeded.

- 3.4. If the Data Processor considers that the instructions given by the Data Controller infringe the rules established by the GDPR or any other data protection legislation, the Data Processor shall immediately inform the Customer about the infringement.

4. DATA PROCESSOR'S OBLIGATIONS

- 4.1. According to the obligations set forth in Article 28.3 GDPR, the Data Processor shall fulfil the obligations and the security measures to guarantee the data protection standards legally required. In particular, the Data Processor shall comply with the following obligations:

  • (a) Comply with all applicable data protection regulations in the processing of the Data Controller's personal data.
  • (b) Handle and process the personal data only following the instructions given by the Data Controller.
  • (c) Refrain from using the Personal Data for any purpose other than described in the Agreement and the fulfilment of its obligations under this DPA. In particular, the Data Processor shall not retain, use, share, sell or disclose the Data Controller's personal data for any purpose other than the provision of the CSI PRO Service.
  • (d) Refrain from disclosing, assigning, transferring or communicating the data in any way to third parties, whether orally or in writing, through electronic media, paper or IT access, without the express authorization of the Controller. In order to communicate personal data to another Data Processor acting on behalf of the same Data Controller, the Data Processor must follow the instructions given by the Controller, who has to previously identify, in writing, the destination, categories of data and the security measures required in order to conduct the communication.
  • (e) The Data Processor shall only allow access to the data by its employees when strictly necessary to render the services set forth in this DPA and provided the employees are subject to the same confidentiality and personal data protection obligations as those set forth in this provision.
  • (f) The Data Processor shall maintain, in writing and when applicable, a record of processing activities carried out on behalf of the Controller.
  • (g) The Data Processor guarantees the Data Controller that there is full compliance with the security measures related to the type of data accessed.
  • (h) Assist the Data Controller by appropriate technical and organisational measures for the fulfilment of the Controller's obligation to respond to requests for exercising the data subjects' rights, such as the right to access, rectification, deletion, limitation of processing, data portability and right to object to automated individual decision-making. If the Data Processor is required to comply with any of the data subjects' rights, it shall inform the Controller immediately, including any relevant information in order to respond to the request.
  • (i) The Controller shall provide data subjects with all the information regarding the processing activities that are going to be carried out.
  • (j) The Data Processor shall ensure appropriate training on data protection for employees who have permanent or regular access to personal data, who are involved in the development of tools used to process personal data or who are involved in the collection or processing of personal data.
  • (k) Assist the Controller in the implementation of a data protection impact assessment.
  • (l) Assist the Controller in the consultations with the supervisory authority.
  • (m) Make available to the Controller all information necessary to demonstrate compliance with the obligations established by data protection legislation and allow for and contribute to audits, including inspections conducted by the Controller or another auditor mandated by the Controller.
  • (n) The Data Processor shall designate a data protection officer in the situations established in Article 37 of the GDPR and communicate his/her contact information to the Controller.
  • (o) Upon termination of this Agreement and after ceasing the use of CSI PRO, the Data Processor shall return the data to the Controller or destroy it, unless there is a legal provision requiring that it be kept, as well as any copy or support on which such data was contained, and shall duly certify such return or destruction in writing to the Controller.

5. TECHNICAL AND ORGANIZATIONAL MEASURES

- 5.1. In accordance with Article 32 of the GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Data Controller shall implement the appropriate technical and organizational measures set out in Appendix 1 of this DPA.

- 5.2. Upon the Data Controller's request, the Data Processor will provide evidence of such technical and organizational measures, being liable for any sanctions, fines or damages which might be imposed for non-compliance with the obligations undertaken in this Agreement or for those set forth in the applicable law on data protection.

6. SUBPROCESSING

- 6.1. The Data Processor may hire third parties to provide certain limited or ancillary services on its behalf, including those in Appendix 1. The Customer consents to the engagement of these third parties and of the Data Processor's affiliates and subprocessors.

- 6.2. From time to time, the Data Processor may engage new subprocessors. In this case, the Data Processor shall impose on any subprocessor the same data protection obligations as the ones set out in this Agreement, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements established in the GDPR. Where that subprocessor fails to fulfil its data protection obligations, the Data Processor shall remain fully liable to the Controller for the performance of that subprocessor's obligations.

7. PERSONAL DATA BREACH NOTIFICATION

- 7.1. The Data Processor shall inform the Customer without undue delay and in any case not later than 72 hours of the personal data breaches of which it has become aware, along with all relevant information for the appropriate documentation and notification of the incident.

- 7.2. Notification shall not be required when a breach of security is unlikely to result in a high risk to the rights and freedoms of natural persons.

- 7.3. If available, the following information must be provided: (i) description of the nature of the personal data breach including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned; (ii) the name and contact details of the data protection officer, the privacy manager, or other point of contact where additional information can be obtained; (iii) description of the potential effects of the personal data breach; (iv) description of the measures taken by the Processor to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

If it is not possible to provide the information simultaneously, the information shall be provided in a phased manner without undue delay.

8. DATA CONTROLLER'S OBLIGATIONS

- 8.1. The Customer shall ensure that the Data Processor guarantees the effective implementation of the GDPR and the LOPDGDD.

- 8.2. The Customer shall implement a data protection impact assessment regarding the processing activities carried out by the Data Processor.

- 8.3. The Customer will be responsible for providing the information right at the time when personal data are obtained.

- 8.4. The Customer shall consult the supervisory authority prior to processing when necessary.

- 8.5. The Customer is entitled to carry out monitoring controls and audits to check that the Data Processor is complying with its obligations. In this regard, the Data Processor, if requested, shall provide the documentation or information to the Customer so that such compliance can be verified. The Customer may, therefore, request from the Data Processor, in a timely manner sufficient for their preparation (which shall be at least ten (10) days in advance), a certificate of compliance on data protection, a copy of the last audit report or the implementation of any action that may be required to prove that the Data Processor fully fulfils the applicable laws on data protection.

9. LIABILITY

- 9.1. The Parties agree that, notwithstanding any investigation conducted by or on behalf of the Data Controller or any knowledge acquired by the Controller at any time, whether before or after the execution and completion of this DPA or on the date hereof, the Data Processor shall be liable and shall indemnify and hold the Controller harmless for any sanctions, fines and damages arising directly from or in connection with any breach, falsehood, inaccuracy, incompleteness, error or omission of any of its legal obligations as data processor or included in this DPA, whether voluntarily or not, attributable to ordinary negligence or fraud (“fault, negligence or dole”) (the “Damages”).

10. TERM AND TERMINATION

- 10.1. The term of this DPA is subject to the term of the Terms and Conditions of the CSI PRO Services. Consequently, once the CSI PRO Services are terminated or expired, this DPA shall automatically terminate.

11. GOVERNING LAW AND JURISDICTION

- 11.1. This DPA shall be governed by and shall be construed in accordance with Spanish law.

- 11.2. Any dispute arising from this DPA, or concerning the validity, interpretation and/or enforcement of this DPA, shall be referred to the Courts of the city of Vitoria-Gasteiz, whose award shall be binding on both Parties, as final and conclusive.

APPENDIX 1
to Schedule I

1. PERSONAL DATA

The Personal Data to which the Processor may have access are detailed below, including the categories of data subjects and processing activities:

Processing to perform Collection · Registration · Storage · Modification · Adaptation · Structuring · Organisation · Consultation · Retrieval · Combination · Restriction · Erasure · Destruction
Purpose of processing The processing shall consist of the provision and management of the CSI PRO Service, including: (i) the creation and administration of User accounts; (ii) the operation, maintenance and support of the platform; (iii) the management and execution of the contractual relationship between the parties; and (iv) any ancillary processing activities strictly necessary for the performance of the CSI PRO Service.
Categories of data
  • Personal data provided by users (including but not limited to identification data, professional data, contact data)
  • Connection and access data (IP addresses, access logs, timestamps, authentication credentials)
  • Network traffic and activity logs (network metadata, system event records)
  • Device and browser data (device identifiers, operating system, browser type)
Data subjects
  • Customer
  • Employees
  • Business partners and collaborators

2. SECURITY MEASURES

The Data Processor, with regard to the Personal Data to which it has access during the provision of the Service, shall comply with the appropriate security measures, including those organisational, technical, physical and administrative measures required to guarantee an adequate level of security according to the risk that may arise from the processing.

In addition, the above-mentioned measures shall guarantee the security, integrity and availability of the Personal Data and avoid its alteration, loss, accidental or illicit destruction, processing, disclosure or unauthorised access at all times, taking into account the state of the art, the costs of implementation, the categories of the data stored, the scope of the processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons.

The planning of security measures shall include the implementation of mechanisms that ensure the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident.

The Data Processor shall implement, at least, the following technical and organisational security measures:

  • Appointment of a data protection officer or a privacy manager, who shall ensure compliance with applicable law.
  • Establishing functions and responsibilities of staff dealing with Personal Data.
  • Creating communication channels between staff involved in data protection, in order to ensure compliance with data protection legislation.
  • Definition of roles and profiles for users of applications and information systems, especially those where data is processed according to the above-mentioned functions and responsibilities, so as to avoid unauthorised access to data or resources. This access control system should guarantee appropriate mechanisms for the identification and authentication of users, such as, for example, the use of passwords which must be renewed periodically, the use of biometric data, automatic blocking of the user account in the event of repeated failed access attempts, and so on.
  • Automated measures in order to limit access to information for unauthorised users or at the end of the specified retention period, such as deletion techniques or pseudonymisation of data.
  • Implement procedures intended to limit physical access to facilities where information systems or physical media are located.
  • Implement control and access registers on supports containing Personal Data.
  • Implement procedures intended to recover Personal Data in the event of its possible destruction, loss or alteration, with the supervision and approval of the person responsible for data protection.
  • Implement procedures in order to ensure the detection, evaluation and notification of security incidents that may affect the rights and freedoms of natural persons.
  • Implementation of compliance regular meetings, defining and executing action plans for the mitigation of detected risks.

If sensitive Personal Data is going to be processed, the Data Processor shall additionally implement the following measures:

  • Providing an access log to sensitive data, identifying the user and the date of access.
  • Data encryption or a similar technique on physical media and portable devices containing sensitive data which are going to be sent or used outside the company's facilities.
  • Encryption of communications containing sensitive data through electronic networks.
  • Implement measures to prevent non-authorised access to sensitive data on physical media (e.g. documentation) during the transportation of the information from the company's facilities to its storage location, which must have appropriate access control security measures.

3. SUBPROCESSORS

The Customer acknowledges and consents to the Data Processor engaging the following subprocessors:

None.