General terms & conditions - Open GI

NOTE: The contract is made up of the Terms and Conditions of Business for the Supply of Software and Services (“Section 1”) and these General Terms and Conditions (“Section 2”).

The specific Parts in Section 1, which apply, will be dependent upon the service that Open GI provides to the Client and shall be specified on an Order Form.

In the case of any conflict or inconsistency between documents, then the following order of priority shall apply:

(1) the most recent Order Form,

(2) the Supplementary Terms,

(3) Section 1,

(4) Section 2, and

(5) the Acceptable Use Policy.

1. Duration

1.1. This Agreement shall come into effect from the date it is signed by both parties and shall continue thereafter until terminated by either party in accordance with the provisions of this Agreement.

2. Initial Period

2.1. Each of the Services taken by the Client is subject to an Initial Period which is calculated as the period commencing on the date specified on the applicable Order Form andending on the date stated in the applicable Order Form for all services taken under this Agreement save that where no end date is specified in the applicable Order Form, the Initial Period shall be thirty-six (36) months.  In the event a Service is adjusted or varied, and a new Order Form is issued for that Service the Initial Period shall re-start and run for the period set out in the Order Form.

3. Client Obligations

3.1. The Client shall provide access to its own systems and premises, as reasonably necessary, to enable Open GI to comply with its obligations relating to delivery, installation, implementation and testing.

3.2. The Client shall fulfil any dependencies which are described in an Order Form or project plan as may be agreed between the parties.

3.3. The Client shall not directly or indirectly permit any third party to access, use or have the use of the Services or the output from the Services nor use them on behalfof or for the benefit of any third party without the prior written authorisation of Open GI.

3.4. The Client warrants on a continuing basis that all Content, Client Data and other information provided by it or its Users through the Software or the Services:

3.4.1. is correct and up to date at all times;

3.4.2. does not breach any laws or regulations including but not limited to, advertising, privacy or consumer protection law and laws relating to privacy, data protection and use of systems and communications;

3.4.3. is not defamatory or offensive or an infringement of any third party’s rights, including any third party’s Intellectual Property Rights;

3.4.4. complies with the Acceptable Use Policy.

3.5. The Client will, at its cost, promptly obtain and provide to Open GI all required consents necessary for Open GI to provide the Services. A “required consent” means any consents or approvals required from the Client or a third party to give Open GI the right or license to access, use, configure, install or modify (including creating derivative works) of the Software, Private Cloud Services, Public Cloud Services and other products that the Client uses, without infringing the ownership or license rights (including patent and copyright) of the providers or owners of such products.

4. Attendance On Site

4.1. Where the parties have agreed that it is necessary for Open GI to perform Services at the Client’s premises:

4.1.1. the Client shall provide Open GI’s staff with such office accommodation, computer resources, support facilities and other facilities as may be reasonably required for them to perform Open GI’s obligations hereunder; and

4.1.2. the Client shall supply to Open GI a copy of all rules and regulations with which Open GI’s personnel should comply whilst on the Client’s premises.  Open GI shall use its reasonable endeavours to procure that personnel shall comply with such rules and regulations whenever they are at the Client’s premises.  The Client shall take all reasonable precautions to ensure the health and safety of Open GI’s personnel while they are on the Client’s premises.

4.2. Where Open GI, its subcontractor or its agent, visits the Client’s premises to carry out Services and is prevented from performing the Services due to any act or omission on the part of the Client or its agents, Open GI shall be entitled to payment for making the visit, and any re-scheduled visit, at its usual and prevailing Professional Day Rate for the Service, plus reasonable travel costs, in addition to the sums already contracted for that visit.

5. Fees and Payment

5.1. In consideration for any licence or access granted under this Agreement and the Services provided, the Client agrees to pay the Fees set out in the applicable Order Forms and other charges, which Open GI shall be entitled to make under the Agreement plus any applicable taxes and duties.

5.2. In addition to the Fees specified on the Order Forms, Open GI shall be entitled to charge reasonable travelling, delivery, subsistence and other out of pocket expenses. For the avoidance of doubt, travelling time is taken into consideration and is part of the Professional Days when Open GI estimates the number of Professional Days required to complete Services.

5.3. All Fees payable by the Client to Open GI are owed irrespective of whether an invoice is issued. Fees are due for payment:

5.3.1. for licences for Software, on delivery and thereafter in advance for a specified period and at the frequency indicated on the Order Form unless otherwise agreed in writing between Open GI and the Client; and

5.3.2. for Services, on delivery or on the date and frequency indicated on the Order Form unless otherwise agreed in writing between Open GI and the Client.

5.4. The Fees may be increased by Open GI by up to the increase in the Index plus 10% per annum.  

5.5. Notwithstanding any Fee increase under clause 5.4, Open GI reserves the right to increase the Fees at any time to the extent that it experiences increased third party costs (in connection with the provision of the Software and Services) materially in excess of the increase applied pursuant to clause 5.4.

5.6. Save where the Client has terminated the Private Cloud Services or Public Cloud Services as a result of the circumstances outlined in clause 6.3 of Part D and clause 7.3 of Part F of Section 1, the Client shall not be entitled to a refund of any Fees paid in advance, or any part of them, upon termination of this Agreement due to a default on the part of the Client or where there exists a Force Majeure Event.

5.7. The Client shall not be entitled to make any deduction from any amount due from it to Open GI nor shall the Client be entitled to exercise any right of set‐off except that in the event that the Client has a bona fide dispute as to the amount of any invoice issued by Open GI which it has notified to Open GI in writing within fourteen (14) days of the date of invoice, then the Client shall be entitled to withhold payment of the amount which it genuinely disputes only pending resolution of that dispute. Following resolution of such dispute, the Client shall pay to Open GI within seven (7) days the full amount which it agrees or is ordered to pay including, if applicable, interest calculated in accordance with clause 5.8.2.

5.8. In the absence of any date for payment being specified on an invoice or in any Order Form, the Client will pay on receipt of an invoice, Order Form or installation whichever is the earlier.  If the Client fails to pay any invoice by the due date, Open GI shall be entitled without prejudice to any other right or remedy to:

5.8.1. suspend or withhold performance of its Services, further work or deliveries to the Client without thereby incurring any liability to the Client; and/or

5.8.2. charge interest on such overdue sum on a day to day basis from the original due date until payment is received in full as well after as before any judgment and independent of such judgment at a rate of four per cent (4%) per annum above the base lending rate of Lloyds Bank in force from time to time; and/or

5.8.3. terminate this Agreement pursuant to clause 14.2.3; and/or

5.8.4. instruct a debt collection agency or law firm to collect payment (including any interest and/or late payment charges) on its behalf. In such circumstances the Client will be liable to pay an additional sum to Open GI which will not exceed the reasonable costs that it may incur to pay the debt collection agency or law firm, who will add the sum to the outstanding debt.

5.9. Open GI may at its sole discretion from time to time update the Documentation provided with its Services and the Software and provide Upgrades.  Open GI reserves theright to levy an administration charge in respect of the provision of Upgrades and Documentation.

5.10. The Service Fees are calculated as reasonable estimates of the number of Professional Days required to carry out the Services based on information in Open GI’s possession at the date of providing the estimates.  Open GI shall be entitled to charge at its prevailing Professional Day rates from time to time for further Professional Days which are reasonably required by Open GI to carry out its obligations hereunder where in the reasonable opinion of Open GI the amount ornature of the work to be carried out exceeds that estimated (provided that such extra days are not required as a consequence of any failure by Open GI to carry out the work associated with the provision of the Services with reasonable skill and care).

5.11. Where Open GI, its subcontractor or its agent visits the Client’s premises to fix an Incident reported by the Client and subsequently discovers that there is no error or fault found on that visit, Open GI reserves the right to charge the then prevailing on-call hourly rate for the time spent in addition to its usual Fees.

5.12. Where a Policy in Force Fee is agreed and detailed on an Order Form:

5.12.1. the Client will be charged a Policy in Force Fee for the applicable Software and Services listed on the Order Form.

5.12.2. the Client shall be required to make a written declaration in good faith of the TPIF on the last day of each calendar month to Open GI by the third working day of the following month. On the basis of such good faith declaration, Open GI shall calculate the PIF Fee for the relevant month. The PIF Fee may be subject to a monthly minimum which will be specified on an Order Form and shall be calculated by Open GI at the end of each month as: (the greater of Monthly Minimum PIF or TPIF) x PIF Rate.

5.12.3. the number of Users which the Client shall be entitled to have access to shall not exceed the Maximum Number of Users specified on the Order Form. If the Client wishes to increase the Maximum Number of Users it may do so at any time by notifying Open GI in writing, and Open GI shall adjust the Policy in Force Fee to reflect the increased number of Users and confirm this in writing to the Client.

5.12.4. Open GI shall be relying on the Client’s declaration of the TPIF to calculate the Policy in Force Fee and the Client agrees that Open GI shall be entitled to access the Back Office to monitor and report on the number of Policies in Force at anytime to validate and calculate the Policy in Force Fee due each month.

5.12.5. in the event of any dispute between the parties as to the number of Policies in Force, Open GI shall have the right to audit the Client’s records to verify the number of Policies in Force and the Client shall, on reasonable notice, make available to Open GI such records and other documentary evidence (including the last back up of the Back Office) as may be reasonably necessary for Open GI to perform an audit and verify the numbers of Policies in Force.

5.12.6. in the event that the outcome of any audit shows that the Client under or over declared the number of PIFs in the audit period, then Open GI shall re-calculate the applicable Policy in Force Fees that should have been charged to the Client and a charge or credit of the Policy in Force Fees shall be made to the Client as appropriate. Without prejudice to any other remedy that may be available to Open GI, if an audit reveals a material under-reporting of the TPIF by the Client, then Open GI reserves the right to charge the Client the reasonable and necessary costs incurred in conducting the audit.

5.12.7. the PIF Rate has been calculated based on both the current type and volume of insurance policies that the Client administers and shall be specified on an Order Form. Should there be a difference in the volume of policies or if the Client wish to add to or remove the type of insurance policies which it administers in the Back Office then this will require the parties to agree new Fees to accommodate the changes in volume or new line of business.

6. Open GI Warranty

6.1. Open GI warrants that:

6.1.1. the Software (excludingany Updates) shall perform substantially in accordance with the relevantDocumentation applicable at the date of installation or deployment of theSoftware and be free from material defects for a period of ninety (90) daysfollowing acceptance under clause 3.2 of Part A of Section 1 or under clause4.1of Part F of Section 1;

6.1.2. It has used reasonable commercial endeavours to eliminate security vulnerabilities from the Software, the Private Cloud Services and the Public Cloud Services;

6.1.3. the Professional Services are performed by suitably qualified and experienced staff in accordance with Good Industry Practice;

6.1.4. it has the right to grant the Client a licence of the Software;

6.1.5. subject to the provisions of clause 6.3, all Services performed by Open GI under this Agreement shall be performed in compliance with all Applicable Laws in line with Good Industry Practice.

6.2. The Client shall provide timely written notice to Open GI of any failure to comply with the warranty given under clause 6.1.1 in order to enable Open GI to take remediation measures. Open GI’s obligation and the Client’s exclusive remedy for a breach of the warranty given in clause 6.1.1 is limited to replacing defective Software notified to Open GI and, at Open GI’s option either repair (by way of Maintenance Release) within a reasonable period of time, or replace the Software in whole or in part.

6.3. Open GI does not warrant that the Software, the Services or the Database will satisfy any particular purpose of the Client. The Client is solely responsible for ensuring that its business and services (including its use of the Services and the Software and any requests for changes or Professional Services) comply with the laws, rules, regulations and codes of conduct which may apply to its business and no warranty is given by Open GI in this respect.

6.4. Open GI cannot warrant that the Services will be completely secure, error free or without interruption and it cannot be held responsible for delays and the loss of data arising from the use of communication networks and facilities including via the internet. The Client acknowledges that due to the nature of the internet there are inherent risks associated with using the Private Cloud Services and the Public Cloud Services, which could result in loss of confidential information or data. In the unlikely event that there is a loss, destruction or alteration of Client Data held by Open GI (where this has been specified as a service provided by Open GI on the Order Form) then Open GI shall use its reasonable endeavours to try to restore such Client Data from its backup files. Open GI cannot be held liable for the acts or omissions of third parties who are not under its direct control including providers of Third Party Software.

6.5. The warranties provided in clause 6.1 shall not apply if:

6.5.1. the condition of the Software or the Services is as a result of use by the Client not permitted under the terms of this Agreement; or

6.5.2. the Software, the Services or the Database supplied has been modified by any party other than Open GI; or

6.5.3. the Software or the Services have not been used in accordance with the Documentation; or

6.5.4. the Software or Services has been used or accessed on equipment or software which is incompatible with the Software or Services or not in accordance with the requirements specified by Open GI; or

6.5.5. the Licence Fees and all other Fees are not paid up to date by the Client; or

6.5.6. notification of a breach of warranty is not made as soon as reasonably possible and in anyevent within twenty (20) Business Days of the Client becoming aware of the breach.

6.6. In the event of a breach of the warranty given under clause 6.1.4, the provisions of clause 8 shall apply and this shall be the sole remedy available to the Client for such breach.

6.7. The warranties contained in this clause 6 are limited warranties and are the only warranties made by Open GI in relation to the subject matter of this Agreement.  Open GI makes and the Client receives no additional warranty, express, implied, or statutory, including (but not limited to) all warranties of satisfactory quality or fitness for particular purpose to the extent permitted by the Applicable Laws.

7. Intellectual Property

7.1. The Client acknowledges that the Intellectual Property Rights created, developed, subsisting and used in and/ or in connection with the supply of the Licensed Materials and Services (including any images, and text incorporated into the Licensed Materials or Services and any subsequent Upgrades, amendments, variations or improvements made by Open GI or the Client to the Licensed Materials or Services), and any report, documentation, and information, on whatever media, prepared or created by Open GI pursuant to this Agreement shall remain or become the sole and exclusive property of Open GI, its assignors or licensors, regardless of whether the Licensed Materials (or any part thereof), Services or Professional Services have been developed solely by Open GI or jointly with the Client excepting components supplied under licence to Open GI by third parties which are the exclusive property of those third parties.  The Client shall not at any time or in anyway question or dispute the ownership of the Intellectual Property Rights of Open GI in respect of the Licensed Materials and Services. The Client shall neither derive nor assert any title or interest in the Licensed Materials or Services, except to the extent of the licence granted under this Agreement.

7.2. In the event that new software, inventions, designs or processes evolve in performance of or as a result of this Agreement, the Client acknowledges that the same shall be the property of Open GI and the Client agrees, at Open GI’s expense, to do all things and execute all documents that may be required to vest title in Open GI.

7.3. Nothing in this Agreement shall serve to transfer from the Client to Open GI any of the Intellectual Property Rights owned by the Client in relation to its Client Data and all right, title and interest in and to the existing Intellectual Property Rights owned by the Client in the Client Data will remain exclusively with the Client.

8.  Intellectual Property Indemnity

8.1. Open GI agrees:

8.1.1. to defend and/or manage (at its own expense) any claim or action brought against the Client in the event and to the extent that such claim or action is based upon an allegation that the Client’s use of the Licensed Materials in accordance with the licence to use granted by the Agreement infringes, violates or in any manner contravenes or breaches any Intellectual Property Rights of any third party; and

8.1.2. to indemnify the Client and hold it harmless from and against all liabilities, costs, damages (excluding consequential or indirect loss and damage) and expenses (including reasonable legal fees) associated with such claim or action, PROVIDED ALWAYS THAT:

8.1.2.1. Open GI is promptly notified in writing of such claim or action;

8.1.2.2. Open GI shall have the exclusive right to control the defence of such claim or action;

8.1.2.3. the Client at Open GI’s request and costs provides Open GI with all reasonable assistance in connection with such defence; and

8.1.2.4. the Client under no circumstances settles such claim or action without Open GI’s prior written consent.

8.2. In the event of any such claim, action, or threat thereof, Open GI (at its sole option, expense and promptly providing as much notice to the Client as reasonably possible) may (a) procure for the Client the right to continue to use the Licensed Materials; or (b) replace or modify the Licensed Materials with functionally compatible, non-infringing software or documentation provided that Client’s use of the replaced or modified Licensed Materials is not adversely affected; or (c) if Open GI determines that none of the foregoing remedies are reasonably available, terminate the Agreement and refund to Client the Licence Fees paid by the Client to Open GI during the immediately preceding twelve (12) months. The foregoing shall be Open GI’s sole obligation and the Client’s sole remedy in respect of the indemnity obligations of Open GI pursuant to this clause 8.

8.3. Open GI shall be under no liability whatsoever under the terms of this clause 8 to the extent that the alleged infringement arises as a result of:

8.3.1. use of the Licensed Materials in combination with any software not licensed to the Client by Open GI or previously approved by Open GI; or

8.3.2. use of the Licensed Materials with any equipment not previously approved by Open GI;

8.3.3. use by the Client of the Licensed Materials in breach of any provision of this Agreement; or

8.3.4. where the Client refuses any reasonable solution proposed pursuant to clause 8.2.

9. Content Indemnity

9.1. The Client indemnifies Open GI against any losses, damages, costs (including legal fees) and expenses incurred by Open GI, whether foreseeable or not, arising from any claim or allegation by a third party that the Content infringes the Intellectual Property Rights of a third party (“Content IPR Claim”), provided that Open GI:

9.1.1. promptly notifies the Client in writing of any Content IPR claim of which it has notice;

9.1.2. does not make any admission as to liability or agree to any settlement of or compromise any Content IPR Claim without the prior written consent of the Client.

9.2. The Client will, at Open GI’s request, and at the Client’s expense, be entitled to have the conduct of and/or settle all negotiations and litigation arising from any Content IPR Claim and Open GI will, at the Client’s request and expense, give the Client all reasonable assistance in connection with such negotiations and litigation.

9.3. If any Content IPR Claim is made, or in the Client’s reasonable opinion is likely to be made, against Open GI, the Client may at its own expense, either:

9.3.1. procure for Open GI the right to continue providing access to the relevant Content; or

9.3.2. modify or replace the infringing part(s) of the Content IPR Claim so as to avoid the infringement or alleged infringement.

10. Confidentiality

10.1. The Documentation, object codes and all other material, ideas, expressions or information relating to or forming part of the Licensed Material and the Services is confidential and the property of Open GI. The Client agrees to keep all such information, together with any information relating to Open GI’s business, secret and confidential (except for information already in the public domain other than through a breach of this Agreement or information to the extent required to be disclosed by law) and to respect Open GI’s proprietary rights in all such information disclosing it only to those of its employees, agents and/or sub-contractors to whom disclosure is necessary.  The Client shall ensure that all such employees, agents and/or sub-contractors are made aware of its obligations of confidentiality under this Agreement.

10.2. Open GI acknowledges that in performing its obligations under this Agreement that it and its advisers (whether external or in associated companies), employees, agents and/or sub-contractors may have access to confidential information belonging to the Client being information not in the public domain (other than through a breach of this Agreement). Open GI undertakes not to make use of such confidential information or disclose it to any party other than as required in performing its obligations under this Agreement.  Open GI shall ensure that all such advisers (whether external or in associated companies), employees, agents and/or sub-contractors are made aware of its obligations of confidentiality under this Agreement.

11. Data Protection and Security

11.1. Both parties shall comply with all applicable requirements of the Data Protection Legislation and the provisions of Schedule A.

11.2. Open GI will use reasonable commercial endeavours to maintain and comply with its security measures detailed in Schedule A during the term of this Agreement and to establish and maintain reasonable safeguards against the destruction, loss or unauthorised alteration of the Client’s Data, and shall institute reasonable security procedures to restrict the destruction, corruption or unauthorised access to the Private Cloud Services or the Public Cloud Services.

11.3. The Client acknowledges that Open GI’s security procedures represent an industry standard of security, and that nevertheless, any service operating in a cloudenvironment is subject to risks associated with such industry level of security utilised in the Private Cloud Services and Public Cloud Services.  In addition, the Client acknowledges that the Private Cloud Services and Public Cloud Services may be subject to intrusion through the “hacking” or unauthorised use of the Client’s logins and passwords, which are the sole responsibility of the Client and its Users.  If, where this is feasible, the Client wishes to add redundancies or more advanced security measurers or technologies, additional fees will be charged.  Such upgraded measures will not be undertaken unless confirmed in an Order Form.

12. Limitation of Liability

12.1. Nothing in this Agreement shall limit or exclude either party’s liability for:

12.1.1. death or personal injury caused by its negligence;

12.1.2. fraud or fraudulent misrepresentation; or

12.1.3. any other actor omission, liability for which cannot be limited or excluded by Applicable Laws.

12.2. Subject to clause 12.1, Open GI shall not be liable to the Client, whether in contract, tort (including negligence), for a breach of statutory duty, or otherwise, including under any indemnity, arising under or in connection with this Agreement for Indirect Losses.

12.3. Subject to clauses 12.1 and 12.2, Open GI’s total liability to the Client in any Year, whether in contract, tort (including negligence), for breach of statutory duty, or otherwise, including under any indemnity, arising under or in connection with this Agreement shall not exceed 115% of the Fees paid by the Client in the Year in which the loss or damage arose. In the case of loss or damage arising as a result of acts or omissions on the part of a Third Party Service Provider Open GI’s liability shall be limited to the lower of the amount which Open GI recovers from such Third Party and the fees paid by the Client to Open GI for the Third Party Services..

12.4. The terms implied by sections 3 to 5 of the Supply of Goods and Services Act 1982 are, to the fullest extent permitted by law, excluded from this Agreement.

12.5. Open GI is not in the business of providing (and has not agreed to provide under this Agreement) general consultancy or advisory services by way of an expert to the Client, and Open GI is under no duty of care in respect of the words, actions or deeds of its employees, its subcontractors agents or servants in this respect.

13. Force Majeure Event

13.1. Neither party shall be liable for delay in performing its obligations or for the failure to perform its obligations if the delay or fault results from a Force Majeure Event. For the avoidance of doubt, nothing in this clause 13 shall excuse the Client from any payment obligations under this Agreement. A party relying upon this clause shall promptly notify the other of such reliance and provide as much detail as possible of the circumstances surrounding the Force Majeure Event including likely duration and what steps the Party is taking to remedy any non-performance or delay. A party relying on this clause shall use all reasonable endeavours to remove or mitigate such causes of non-performance (including by implementing its business continuation plans) and shall continue performance under the Agreement as soon as reasonably practicable after such cause(s) is removed or sufficiently diminished in order to do so.

13.2. In the event that the Force Majeure Event continues for more than 60 Business Days, and provided performance continues to be substantially impeded, either party may terminate the Agreement with immediate effect upon giving written notice to the other party.

14. Termination

14.1. This Agreement may be terminated by either party (without prejudice to any of its rights or remedies) under the following circumstances:

14.1.1. where there is a Force Majeure Event, in accordance with the provisions of clause 13;

14.1.2. at the non-defaulting party’s option by notice in writing to the other party (to have immediate effect unless otherwise stated) if:

14.1.2.1. the other party commits any material breach of this Agreement which is not capable of remedy or (in the case of a breach capable of being remedied) shall have failed to remedy any such breach within thirty (30) days after the receipt of a request in writing so to do;

14.1.2.2. the other party has a receiver, manager, administrator, administrative receiver or liquidator appointed or shall pass a resolution for winding-up or if a petition is presented to any court for its winding up or if it shall enter into any composition or arrangement with its creditors or if any proceedings are commenced relating to its insolvency or possible insolvency;

14.1.2.3. a receiver or administrator is appointed, or an encumbrancer takes possession of the undertaking or assets (or any part thereof) of the other party;

14.1.2.4. the otherparty is unable to pay its debts (within the meaning of the Insolvency Act 1986 or any statutory re-enactment or modification thereof) or ceases or threatens to cease to carry on its business or substantially the whole of its business; or

14.1.3. the entire Agreement by giving the other party the applicable Notice Period in writing at any time on or after the expiry of the last applicable Initial Period (where there is more than one Service taken by the Client).

14.2. This Agreement may be terminated by Open GI under the following circumstances:

14.2.1. If the Client is in breach of the terms of the software licence contained in Part A of Section 1, the terms of the right to access and use contained in part F of Section 1, or the Acceptable Use Policy;

14.2.2. if the Client being a sole trader has a receiver appointed under the Mental Health Act 1998 or dies;

14.2.3. without prejudice to clause 14.1.2.1, by Open GI giving the Client fourteen (14) days’ notice in writing in the event that the Client fails to pay any Fees due under the terms of the Agreement; or

14.2.4. by Open GI giving twelve (12) months’ notice to the Client at any time that it wishes to terminate either any of the Services under this Agreement or the whole of the Agreement.  This right is without prejudice to all other rights hereunder to suspend or withdraw services or supplies.

14.3. In addition to the termination rights set out in clause 14.1, either party may terminate an individual Service by giving the other party notice in writing equal to the applicable Notice Period to terminate that Service to expire on or after the expiry of the relevant Initial Period.

14.4. On termination of this Agreement for any reason other than material breach by Open GI, Open GI will, where applicable, send to the Client disable programs designed to disable the Software.  The Client undertakes to run the disable programs and then return them to Open GI, to cease using and return any Equipment which has not been paid in full and the Software.  Further, the Client shall delete all copies and partial copies of the Software from all Computer Devices and from any other storage  and return to Open GI all copies and all part copies of Documentation relating to the Software and the Services and certify to Open GI that it has run the disable programs (where applicable) and that all copies and partial copies have been deleted and that the Client no longer retains any copies or partial copies of the Software whatsoever. Where the Client is receiving the Private Cloud Services or the Public Cloud Services, the Client’s access to such services shall be terminated immediately.

14.5. Where disable programs are required in accordance with clause 14.4, the Client agrees to pay all Fees set out in the Order Form after termination of this Agreement until the Client has certified to Open GI that it has run the disable programs.  If the Client has given notice to terminate and does not certify that it has disabled the Software within any applicable Notice Period, the Client agrees to pay to Open GI the Fees at Open GI’s current and then standard prices for use of the Software and its continued support.  If Open GI has given notice to terminate and the Client does not certify that it has run the disable programs within any applicable Notice Period, Open GI may,at the Client’s expense, apply for a court order restraining the Client from continued use of the Software and delivery up of a certificate indicating that the Client has stopped use of the Software.

14.6. Any termination or expiry of this Agreement howsoever arising shall not affect any accrued rights or liabilities of either party nor shall it affect the coming into force or the continuance in force on or after such termination of any provision hereof which is expressly or by implication intended to come into or continue in force on or after such termination being, for the avoidance of doubt (without limitation) provisions relating to liability, confidentiality, payments and termination.

14.7. Open GI shall provide assistance on termination to include Open GI providing such documentation as may be reasonably necessary for the procurement of replacement services, transition of the Services to a new provider and returning all data and confidential information to the Client in a form agreed between the parties.  All such services shall be chargeable at the then current Open GI list price.  Both parties shall take action to mitigate such costs.

14.8. Within 30 (thirty) days of the termination, cancellation or expiration of the Agreement, the Client shall:

14.8.1. instruct Open GI to either return or destroy the Client Data held by Open GI. In the event that no instructions are received by Open GI within 30 (thirty) days, Open GI shall have no obligation to maintain or provide any Client Data to the Client and shall thereafter (unless legally prohibited), delete all Client Data in its systems or otherwise in its possession or under its control in such a manner as prevents recovery; and

14.8.2. securely delete all copies of Open GI proprietary data (including data supplied by third parties such as providers of data enrichment services) made available to the Client via the Software and Services from its systems and destroy any hard copies of such data in its possession or control, except that the Client will be entitled to retain records that are strictly required for its own regulatory compliance or legal purposes.

15. Assignment and Subcontracting

15.1. The Client may not assign, sub-contract, sub-licence or otherwise transfer its rights or obligations hereunder without the prior written consent of Open GI.  Open GI may assign or otherwise transfer its rights or obligations under this Agreement to an Associated Company (or to a third party for the purposes of securing finance) without the requirement to obtain the consent of the Client.

15.2. Open GI may employ sub-contractors (including any Associated Company) and consultants to perform its obligations under this Agreement and it may sub-licence, without the consent of the Client, to the extent necessary for it to comply with its obligations hereunder, provided that Open GI shall be responsible for the acts, omissions and consequences of its sub-contractors, consultants and sub-licensees.

16. Non-solicitation

16.1. The Client shall not, without the prior written consent of Open GI,  during the period of this Agreement and for a period of 12 months thereafter solicit or attempt to solicit either directly or indirectly through a third party or otherwise any employee, sub-contractor, representative or agent of Open GI and any Associated Company where such person was involved in the development, management or provision of the Services or product development for Open GI or any Associated Company. “Solicit” in this context shall not include general solicitations such as advertisements in newspapers, trade publications or on the internet.

17. Disentanglement

17.1. Commencing upon receipt by Open GI of notice of termination under this Agreement or intention not to renew any of the Services, the following shall occur within thirty (30) days of receipt of such duly served notice:

17.1.1. the parties shall cooperate fully with one another to facilitate a smooth transition of the Services being terminated from Open GI to the Client or to the Client’s designated replacement provider with minimal interruption of the Services pursuant to a written Disentanglement Plan to be approved in writing by each party; and

17.1.2. the parties shall diligently cooperate to complete and agree such plan and the Client will pay Open GI the fees and reasonable out-of-pocket expenses of Open GI as provided in the written Disentanglement Plan.

17.2. If the parties are unable to agree on a Disentanglement Plan, Open GI shall provide a backup of the Client Data from the Cloud Environment in a customary format at charges to be agreed between the parties and supply the same to the Client.

18. Time not of the Essence

18.1. Notwithstanding that Open GI shall use reasonable endeavours to meet any dates and/or times for performance of its obligations under this Agreement, any such date or time to meet such obligations is given in good faith as a reasonable estimate and time is not of the essence of this Agreement for the performance of any such obligation.

19. Dispute Resolution

19.1. Open GI and the Client are committed to resolving all disputes arising under this Agreement (and whether such dispute arises before or after termination of the Agreement) without the need for litigation and to allow, as far as possible, for commercial relationships to remain unaffected by disputes. In the event of a dispute between the parties, either party may invoke this dispute resolution provision by notifying the other party in writing. Following the issue of such notice, Open GI and the Client shall procure that they will:

19.1.1. attempt in good faith to resolve any dispute or claim promptly through negotiations between the respective senior management of the parties (or their nominated representatives) who have authority to settle the same; and

19.1.2. attempt in good faith, if the matter is not resolved through negotiation within three months of the dispute arising, to resolve the dispute or claim through mediation with the assistance of a mediator agreed between the parties or as recommended to the parties by the Centre for Effective Dispute Resolution or such similar organisation that the parties may agree.

19.2. If the matter has not been resolved in accordance with clause 19.1 within six months of the dispute arising, either party may commence court proceedings in respect of such unresolved dispute or issue.

19.3. Notwithstanding the provisions of this clause 19 neither party shall be precluded from seeking injunctive relief to temporarily secure rights and to avoid loss of rights, including (but not limited to) Intellectual Property Rights.

20. Notices

20.1. Notices may be served by either party on the other by recorded delivery or email (subject to confirmation by post) to the registered or principal office (from time to time) of the other or the email address notified by the other party. Notices shall be deemed to be served, if sent by recorded delivery, on the day that the recorded delivery is signed for by the recipient, and, if sent by email, immediately upon receipt of a delivery receipt email from the correct email address.

21. Entire Agreement and Amendments/Waivers

21.1. The Agreement constitutes the complete and exclusive statement of the Agreement between the parties as relates to the subject matter and supersedes all proposals, oral or written, and all other representations, statements, negotiations and undertakings relating to the subject matter.

21.2. This Agreement supersedes and terminates all previous agreements between the parties relating to the Software and provision of Services and the Client expressly agrees that Open GI has fulfilled all of its obligations under any previous agreements for the supply of said Software and Services.

21.3. Acceptance by Open GI of any Order Form for Software or Services is conditional upon acceptance by the Client of these terms and conditions which shall override all other terms and conditions inconsistent herewith, whether express, implied or otherwise including but not limited to terms, conditions or stipulations contained in any purchase order or other form of writing or otherwise stipulated or supplied by the Client and which are at variance with or additional to this Agreement.  Open GI shall not be under any obligation to provide any Services unless it issues a written confirmation to the Client that an Order Form has been accepted.

21.4. In entering into this Agreement both parties agree that they have not relied on any representation, warranty, collateral contract or warranty, contract or other assurance (except those set out in this Agreement) made by or on behalf of any party before the signature of this Agreement and each of the parties waives all rights and remedies which but for this sub-clause, might otherwise be available to it in respect of any such representation, warranty, collateral contract or warranty, contract or other assurance. This clause shall not exclude any liability which one party would otherwise have to the other in respect of any statements made fraudulently by that party.

21.5. From time to time it may be necessary to update this Agreement to reflect changes in the Services that Open GI provides to the Client. The latest version of the Agreement shall be published on https://supportcentre.opengi.co.uk/ and the Client shall be responsible for ensuring that it is familiar with the up to date version.

21.6. No waiver ofany of the provisions of the Agreement shall be binding upon either party unless in writing signed by an authorised representative of such party.  No waiver by either party of any breach by the other party of any of the provisions of the Agreement shall be construed as a waiver of that or any other provision on any other occasion.

21.7. No forbearance, delay or indulgence by either party in enforcing the provisions of this Agreement shall prejudice or restrict the rights of that party nor shall any waiver of its rights operate as a waiver of any subsequent breach.

22. Survival and Invalidity

22.1. Any term contained in the Agreement that could by its nature reasonably be construed to survive the expiration or termination of the Agreement shall so survive and enforcement thereof shall not be subject to any conditions precedent.

22.2. If any provision of the Agreement is held by any competent authority to be invalid or unenforceable in whole or in part the validity of the other provisions of the Agreement and the remainder of the provision in question shall not be affected thereby.

23. Jurisdiction and Governing Law

23.1. The Agreement shall be governed by, construed and applied in accordance with the laws of England and Wales and the parties hereby submit to the exclusive jurisdiction of the courts of England and Wales.

Definitions

In this Agreement including all of the Parts, the following words shall have the following meanings:

Acceptable Use Policy” means Open GI’s policy on acceptable use of the Services (as updated  from time to time)

“Additional Software” means the information technology programs licensed to the Client under this Agreement as detailed in an Order Form which have been specifically written, adapted and/or  developed for the Client by Open GI together with related documentation supplied to the Client;

“Agreement” means the agreement between the parties which is made up of (i) the Open GI Terms and Conditions of Business for the Supply of Software, Services and Equipment, (ii) the Open GI General Terms and Conditions, (iii) the applicable Supplementary Terms (iv) any Order  Form(s) signed by the Client and confirmed as accepted by Open GI) and (v) the Acceptable Use Policy (all as may be amended and  updated from time to time and published on  https://supportcentre.opengi.co.uk/ );

“Applicable Laws” means the laws of England and Wales and any other laws or regulations, regulatory policies, guidelines or industry codes which apply to the operation of the Services including but not limited to, the Data Protection Legislation, the Bribery Act, 2010 and the Modern Slavery Act, 2015;

“Associated Company” means any subsidiary or holding company from time to time of Open GI Limited and any subsidiary from time to time of a holding company of Open GI (for the purposes of this definition a reference to a “holding company” or a “subsidiary company” shall have the meanings given in section 1159 and Schedule 6 of the Companies Act 2006);

“Back Office” means the virtual or physical infrastructure appliance containing the Open GI Software components that form the core of the Open GI policy administration system;

“Business Day” means a day other than a Saturday, Sunday or bank holiday in England and Wales;

“Client” means [Insert Client Name and (company registration no. nnnnnnn)] of [Insert Client  registered address and post code];

“Client Data” means all data, information and material including information relating to its Customers or potential Customers and Personal Data supplied by a Client and held on the Database;

“Cloud Environment” means Open GI’s hardware, network server(s) and data centres or those of a third party under lease or license to Open GI used to provide the Client with access to the Content  webpages, Database, Services and Software;

“Computer Device” means one connected device (including desktop and laptop computers, thin client devices or smartphones/tablets as applicable) accessing or comprising of any of the  Software installed by Open GI or the Client in accordance with Open GI’s standard installation procedures;

“Content” means all data, information, images, graphics and materials either supplied by the Client or specified by the Client, including free format text entered by the Client and Users on data entry fields, registered trademarks and unregistered service marks belonging to the Client and third parties, programs and plug-ins belonging to third parties, hyperlinks and other connections to third party services, systems and websites (including credit checking agencies, merchant services, third party enrichments, news feed and price suppliers and third party news pages);

“Customer” means the person or entity receiving services or products from the Client;

“Database” means the underlying datastore supplied either on the Software or on the Public Cloud Services that will contain the Client Data. The copyright in the datastore vests in the third party supplier of the datastore or Open GI (as applicable) and associated software and the copyright in the structure and format vests in Open GI;

“Data Controller” has the same meaning as is given to that term in the Data Protection Legislation;

“Data Processor” has the same meaning as is given to that term in the Data Protection Legislation;

“Data Processing Instructions” means the instructions given by the Client to Open GI for the processing of Personal Data under this Agreement and which are set out in Appendix A to Schedule A;

“Data Transfer Services” means the transfer of data from the Client onto the Software, the Database or the Public Cloud Services as more particularly described on an Order Form;

“Documentation” means the operating manuals, online guides, user instructions, technical literature, scope, process definitions and procedures and other related materials Open GI supplies to the Client in any form under this Agreement for aiding the use of the Software and the Services, including any part or copy of them or in the course of providing the Support;

“Data Protection  Legislation” means (i) the General Data Protection Regulation ((EU) 2016/679) as it forms part of domestic law in the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018 (including as further amended or modified by the laws of the United  Kingdom or of a part of the United Kingdom from time to time) (“GDPR”), (ii) the Data Protection Act 2018, as amended or updated from time to time, in the United Kingdom and (iii) any successor legislation to the GDPR or the Data Protection Act 2018;

“Data Subject” shall have the same meaning as is given to that term in the Data Protection  Legislation and shall, for the purposes of this Agreement, include prospective and live policyholders and customers and their dependents, business contacts and third party suppliers of the Client and such other individuals as the Client may instruct Open GI to accept;

“Disentanglement” means the transition process described in clause 17;

“Disentanglement Plan” means the plan agreed by the parties to facilitate a Disentanglement;

“EDI Services” means the facility which enables the Client to transact electronic data interchange;

“Emergency Maintenance” means urgent emergency unplanned maintenance such as to avoid an imminent threat or to resolve a service outage. Advance notification of such maintenance shall be provided to the Client by Open GI wherever possible;

“Fees” means all of the fees and charges payable under this Agreement by the Client including the Initial Licence Fee, the Recurring Licence Fee, the Service Fees and Policy in Force Fee;

“Force Majeure Event” means any event which is beyond the reasonable control of either party whereby it is prevented from or delayed in the carrying on of its business including, without limitation, acts of God, governmental actions, war or national emergency, acts of terrorism, protests, riot, civil commotion, fire, explosion, extreme weather conditions, flood, epidemic, pandemic, lock‐outs, strikes or other labour disputes (excluding those relating to either party’s  workforce), or restraints or delays affecting carriers or inability or delay in obtaining supplies of adequate or suitable materials;

“Good Industry Practice” means the exercise of that degree of professionalism, and skill, diligence, prudence and foresight which would reasonably and ordinarily be expected from a reasonably skilled and experienced person engaged in the provision of services similar to or the  same as the Services;

“Indirect Losses” means (a) loss of profits, loss of sales or business, loss of agreements or contracts, loss of revenue, loss of anticipated earnings or savings, loss of or damage to goodwill; (b) loss of use or value of, or corruption of, any data, software, equipment or information, including wasted management, operation or other time; (c) any loss, damage or cost incurred as a result of any Planned Maintenance or Emergency Maintenance; or (d) any indirect, incidental or consequential losses of any kind or nature whatsoever, in each case irrespective of whether the offending party has been advised, knew or should have known of the possibility of such loss or damage;

”Index” means the most recent Retail Prices Index figures published by the Office of National Statistics or its successor;

“Initial Licence Fee” means the licence fee paid on the commencement of the licence for Software and which is specified on an Order Form;

“Initial Period” means the minimum duration for a Service which is set out in the most up to date applicable Order Form relating to that Service;

“Intellectual Property Rights” means all industrial and intellectual property rights including without limitation patents, trademarks, know how, registered designs, unregistered design rights,  database rights (including rights in the design or structure of any database), copyright, confidential know-how and applications for any of the foregoing together with the right to make such applications (including without limitation all such rights in any data drawings specifications  manuals instructions plans designs and computer programs) together also with all information of a confidential nature;

“Licence Fee” means the Initial Licence Fees and the Recurring Licence Fees;

“Licensed Materials” means the Software, Database, Documentation, Updates, Upgrades and any other material supplied to the Client under this Agreement;

“Maintenance Release” means any release of the Software or Services which corrects faults, adds functionality or otherwise amends or upgrades the Software or Services, but which does not constitute an Update or Upgrade;

“Maximum Number of Users” means the maximum number of Users permitted to use the Software as specified in the applicable Order Form;

“Monthly Minimum PIF” means the minimum number of deemed Policies in Force in the Back Office on the last day of each month as set out in the applicable Order Form;

“Monthly Minimum PIF Fee” means the amount calculated by multiplying the Monthly Minimum PIF by the PIF Rate;

“Notice Period” means the period of notice required to terminate either a Service or the entire Agreement as specified on an Order Form or if no Notice Period is specified, the notice period shall be three (3) months’;

“Open GI” means Open GI Limited (company registration no. 1519547) of Buckholt Drive, Warndon, Worcester WR4 9SR acting by itself or through one of its Associated Companies appointed to act as its subcontractor;

“Order Form” means the document of that name which expressly incorporates the terms and conditions of this Agreement and through which the Client requests and Open GI agrees to supply products and services (the first Order Form sets out the products and services that the Client has initially ordered, subsequent Order Forms may vary, add or delete services and products as agreed between the parties);

“Personal Data” has the same meaning as is given to that term in the Data Protection Legislation.  The categories of Personal Data for the purposes of this Agreement shall include data required to quote for and issue and manage insurance policies including policyholders’ and policy  beneficiaries’ names, date of birth, address, contact details, nationality, country of residence and gender and such other categories as the Client may instruct Open GI to process;

“Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, any Personal Data;

“PIF Rate” means the monthly charge for each Policy in Force as set out in an Order Form;

“Planned Maintenance” means scheduled maintenance, which is undertaken by Open GI, and which is notified to the Client in advance;

“Policy(ies) in Force” or “PIF” means a primary insurance policy that is in force on the last day of each month but shall exclude any add-on or ancillary covers or products linked to or associated with that primary policy provided that each such add-on or ancillary cover has a cost to the policyholder of not more than 25% of the premium of the primary policy. Any policy which expires or is cancelled during a month shall not be considered “in force” at the end of that month;

“Policy(ies) in Force Fee” or “PIF Fee” means the Recurring Licence Fee charged to the Client for Policies in Force which shall be calculated by multiplying the PIF Rate by the TPIF.

“Private Cloud Services” means the service provisioned via Open GI’s private Cloud Environment to access and use the Database and Software;

“Professional Day” and “Professional Day Rate” means any weekday between the hours of 9.00am and 5.30pm (with one hour for lunch) excluding Saturdays, Sundays and bank and public holidays in the jurisdiction in which the Services will be performed and the “Professional Day Rate” shall be the rate charged by Open GI for a Professional Day;

“Professional Services” means implementation, consultancy, training, development or other services provided by Open GI in accordance with an Order Form and this Agreement;

“Public Cloud Services” means the service provided by Open GI which gives the Client access to the Software, the Database and Approved APIs via a public Cloud Environment;

“Recurring Licence Fees” means the fee payable annually, or as otherwise agreed, by the Client for a licence to use the Software;

“Regulatory Authority” means any government, quasi-governmental, statutory or regulatory, administrative, fiscal or judicial body, department, authority, tribunal, stock exchange, or any other  competent authority or entity created and regulated by statute in the United Kingdom from which having responsibility for the regulation or governance of the Services (or any part therefor) and/or having legal jurisdiction over the parties;

“Service Fees” means the fees to be paid by the Client to Open GI in relation to the provision of Services;

“Services” means Professional Services, Data Transfer Services, Private Cloud Services, Public Cloud Services, EDI Services, Support and Updates provided by Open GI under this Agreement;

“Software” means, where specified on an Order Form, either (i) the information technology programs licensed to the Client under this Agreement which shall incorporate any Updates, Upgrades and Maintenance Releases, (ii) any Additional Software that may be developed as part of the Professional Services or (iii) the software program developed by Open GI which the Client  may access and use as part of the Public Cloud Services, and in all cases excludes Third Party Software;

“Supplementary Terms” means the terms and conditions which apply to additional services and products purchased by the Client and which can be found at https://opengi.co.uk/supplementary-sales-and-product-terms using the password On8)mRkZU2fIqH# ;  

“Support” means the provision of support and maintenance services by Open GI;

“Term” means the period of this Agreement as calculated in accordance with clause 1.1;

“Third Party Services” means a service provided by a third party including providers of Third Party Software which is procured by the Client through Open GI acting either as a reseller or a subcontractor of the third party;

“Third Party Service Providers” means a provider of a Third Party Service;

“Third Party Software” means software, hosting and services provided by a third party which is used in the Public Cloud Services;

“TPIF” means the total number of Policies in Force in the Back Office on the last day of the relevant month;

“UK Transfer” means a transfer of Personal Data to a country which does not have in place an adequacy decision under Article 45 of GDPR;

“Update” means the periodic supply of third party insurance rate data and guides by Open GI to the Client for use with the Software;

“Upgrade” means any new version of the Software or the Services that Open GI makes available to the Client as part of its Services and which becomes part of the Software on acceptance or installation, whichever is the earlier;

“User” means an employee or agent of the Client who is authorised by the Client to access the Licensed Materials for the sole purpose of the Client’s insurance broking business;

“Year” means a 365 day period (or a 366 day period if that period encompasses 29th February)  commencing either on the effective date of this Agreement or on any anniversary thereof.

The parties have agreed that the Terms and Conditions of Business for the Supply of Software and Services (Section 1) and the General Terms and Conditions (Section 2) shall apply to the supply of any Software and Services ordered by the Client and detailed in an Order Form. All Order Form(s) are expressly made subject to the Terms and Conditions of Business for the Supply of Software and Services and the General Terms and Conditions.

Schedule A: Personal Data Processing and Security

INTRODUCTION:

1. The parties shall comply with all applicable requirements of the Data Protection Legislation.

2. For the purposes of the Data Protection Legislation, the Client is the Data Controller in respect of all Client Data which is Personal Data and appoints Open GI to act as a Data Processor in respect of such Personal Data for the purposes of performing its obligations under this Agreement. The Client hereby warrants that it has due authority and a lawful basis to appoint Open GI as a Data Processor and to process the Personal Data in accordance with its written instructions set out in Appendix A and this Agreement.

3. The parties acknowledge and agree that the Client, as Data Controller of the Personal Data, retains control of the Personal Data and remains responsible for its compliance obligations under the Data Protection Legislation, including (but not limited to), providing any required notices and obtaining any required consents, and for the written processing instructions it gives to Open GI.

OPEN GI OBLIGATIONS:

4. Without prejudice to the generality of clause 1 of Schedule A, in relation to any Personal Data processed in connection with the performance by Open GI of its obligations under this Agreement:

4.1. Open GI shall process the Personal Data only in accordance with the Client’s written instructions and this Agreement, including as set out in the Data Processing Instructions.

4.2. Open GI shall promptly notify the Client if, in its opinion, the Client’s instructions do not comply with the Data Protection Legislation provided that to the maximum extent permitted by law, Open GI shall have no liability howsoever arising (whether in contract, tort (including negligence) or otherwise) for any losses, costs, expenses or liabilities arising from or in connection with processing the Personal Data in accordance with the Data Processing Instructions.

5. Open GI shall comply (and shall ensure that its employees, agents, contractors and sub-contractors comply) with its obligations under Data Protection Legislation and with any Client written instructions requiring Open GI to amend, transfer or delete the Personal Data, or to stop, mitigate or remedy any unauthorised processing unless required by Applicable Law to store the Personal Data in which case Open GI shall notify the Client of such requirement.

6. Open GI will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to any third-party unless the Client or this Agreement specifically authorises the disclosure, or as required by Applicable Law or where it is requested to disclose Personal Data by a law enforcement agency for crime prevention or investigation purposes. If an Applicable Law requires Open GI to process or disclose the Personal Data to a third-party, Open GI shall to the extent practicable, first inform the Client of such legal or regulatory requirement and give the Client an opportunity to object or challenge the requirement, unless the Applicable Law prohibits the giving of such notice.

7. Open GI is authorised by the Client to depersonalise and anonymise Personal Data and Client Data which, once depersonalised and anonymised, may be used by Open GI for its business purposes.

8. In addition, the Client specifically authorises Open GI to access and use the Client Data and Personal Data for the purposes of managing the Client’s account with Open GI and performing the Services including passing such data to insurers and other third parties to enable such insurers and third parties to undertake insurance transactions and other directly related services on behalf of the Client and its Customers;

9. Open GI will ensure that its employees:

9.1. are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations in respect of the Personal Data; and

9.2. have undertaken training on the Data Protection Legislation and how it relates to their handling of the Personal Data and how it applies to their particular duties.

10. Open GI will reasonably assist the Client, at the Client’s reasonable cost, with meeting the Client’s compliance obligations under the Data Protection Legislation, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the relevant Regulatory Authority under the Data Protection Legislation.

SECURITY:

11. Open GI shall ensure that it has in place appropriate technical and organisational measures to protect against unauthorised or unlawful processing of Personal Data and against accidental loss or destruction of, or damage to, Personal Data, appropriate to the harm that might result from the unauthorised or unlawful processing or accidental loss, destruction or damage and the nature of the data to be protected, having regard to the state of technological development and the cost of implementing any measures which shall include, at a minimum, the security measures set out in Appendix B;

12. Open GI shall implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:

12.1. the pseudonymisation and encryption of Personal Data;

12.2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

12.3. the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and

12.4. a protocol for regularly testing, assessing, and evaluating the effectiveness of the security measures.

PERSONAL DATA BREACH:

13. Open GI shall notify the Client without undue delay, and in any event within 48 hours, on becoming aware of any Personal Data Breach and will provide the Client with the following written information upon request:

13.1. a description of the nature of the Personal Data Breach, including where possible, the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned;

13.2. its assessment of the likely consequence of the Personal Data Breach; and

13.3. a description of the measures taken or proposed to be taken to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

14. The information described in clause 13 of Schedule A may be provided in phases where investigations may still be underway.

15. The parties acknowledge and agree that the Client shall have the sole responsibility and discretion to provide notice of any Personal Data Breach to any Data Subjects or any Regulatory Authority unless such notice is required to be given by Open GI by Applicable Law.

TRANSFERS OF PERSONAL DATA:

16. Open GI shall not transfer or otherwise process the Personal Data outside the collective area of the UK and the EEA without first taking appropriate safeguards in relation to the transfer. The Client shall be notified of any such transfer including the measures set out in clauses 17 to 19 below as applicable.

DATA TRANSFERS OUTSIDE UK:

17. Int he event of a UK Transfer from either the Client to Open GI or Open GI to the Client, the parties shall enter into a UK International Data Transfer Agreement which shall be incorporated into and form part of this Agreement.

18. To the extent that any additional measures are required to ensure the compliance of the UK Transfer with Data Protection Legislation, the parties shall cooperate to promptly put in place such measures.

19. Open GI shall, on request by the Client, undertake a transfer risk assessment or contribute to such assessment undertaken by the Client in respect of any planned UK Transfer from either party to the other under this Agreement.

20. The Client acknowledges that due to the nature of Public Cloud Services, Personal Data may be transferred to recipients or other geographical locations in connection with use of the Services further to access and/or computerised instructions initiated by Users. The Client acknowledges that Open GI does not control such processing and the Client shall ensure that Users (and all others acting on its behalf) only initiate the transfer of Personal Data to recipients or other geographical locations if lawful safeguards as required under GDPR are in place and that such transfer is in compliance with all Applicable Laws.

SUBPROCESSORS:

21. Open GI may authorise third party processors to process the Personal Data under this Agreement. The third party processors utilised by Open GI as at the commencement of this Agreement are set out in the Open GI Privacy Notice which can be found at https://www.opengi.co.uk/legals/privacy-notice. Should Open GI propose to add to or replace a third party processor, it shall first notify the Client in writing and provide the Client with an opportunity to object to the appointment of the third party processor within 10 Business Days. Should the Client object to the appointment of the third party processor on reasonable grounds then Open GI shall not appoint the proposed third party processor until reasonable steps have been taken to address the objections raised by the Client and the Client has been provided with reasonable written explanation of the steps taken.

22. Open GI shall enter into a written agreement with each third party processor to ensure that each third party processor is obliged to comply with obligations which are no less onerous than the obligations set out in this Agreement.

23. Open GI shall remain fully liable to the Client for the subcontractor’s performance of its obligations as a Data Processor under this Agreement.

DATA SUBJECT REQUESTS:

24. Open GI shall provide such information to the Client as the Client may reasonably require, to enable the Client to comply with:

24.1. the rights of Data Subjects under the Data Protection Legislation, including, but not limited to, Data Subject access rights, the rights to rectify, port and erase Personal Data, object to the processing and automated processing of Personal Data, and restrict the processing of Personal Data; and

24.2. information or assessment notices served on the Client by the supervisory authority or other relevant regulator under the Data Protection Legislation.

25. Open GI shall promptly notify the Client if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party’s compliance with the Data Protection Legislation.

26. Open GI shall promptly notify the Client if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Data Protection Legislation. The Client shall be responsible for responding to all Data Subject requests.

27. Open GI shall provide the Client with its reasonable co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.

DATA RETURN AND DESTRUCTION:

28. At the Client’s request, Open GI will provide the Client with a copy of (or access to for a limited period) all or part of the Clients’ Personal Data in its possession or control in a format and media type as reasonably agreed by the parties. This shall usually be free of charge however where the Client request is such that Open GI is required to prioritise the work, provide copies of data in specific formats or similar extra work is involved, Open GI reserves the right to charge its reasonable fees which will be notified in advance to the Client.

29. Within 40 Business Days of the termination of the Agreement for any reason or expiry of its Term, Open GI will securely delete or destroy all or any of the Personal Data related to this Agreement in its possession or control. Should the Client require a copy of any Personal Data it shall notify Open GI in writing before expiry of this 40 Business Day period, failing which Open GI shall irreversibly and securely delete or destroy all or any Personal Data and shall have no further liability to the Client in relation to any deleted or destroyed Personal Data.

30. If any Applicable Law requires Open GI to retain any documents, materials or Personal Data that the Client would otherwise be required to return or destroy, it will notify the Client in writing of that retention requirement where it is permitted to do so.

RECORDS:

31. Open GI will maintain written records regarding any processing carried out on behalf of the Client of the Personal Data, as reasonably necessary to demonstrate its compliance with this clause including but not limited to the categories of processing carried out on behalf of the Client, any transfers of data to a third country or an international organisation and, where possible, a general description of the technical and organisational security measures (“Records”).

32. Open GI will ensure that the Records are sufficient to enable the Client to verify Open GI’s compliance with its obligations under this Agreement.

AUDIT:

33. Upon reasonable request from the Client, Open GI will allow for, and provide reasonable assistance in relation to, any audits conducted by the Client or a Regulatory Authority of Open GI’s information technology and information security controls used in complying with its obligations under this Agreement and will make available to the Client such information as is reasonably necessary to demonstrate its compliance with the obligations under Article 28 of the UK GDPR. The Client may not carry out more than one audit in any rolling twelve-month period unless such audit is required as a result of (i) a Personal Data Breach caused by Open GI; (ii) any request made by a Regulatory Authority which concerns Open GI’s conduct; or (iii) any other actual or suspected breach of security or related emergency attributable to OGI. Open GI reserves the right to charge Fees at its prevailing Professional Day Rate where, in its reasonable opinion, the Client’s audit requirements are disproportionate. The Client shall procure undertakings from any appointed auditor or Regulatory Authority that it will, treat all records discussed or inspected pursuant to this clause as confidential information of Open GI which shall be subject to the existing confidentiality undertakings between the parties.

Appendix A

Data Subjects

The Client’s prospective, past and live policyholders and policy beneficiaries, the Client’s employees and such other individuals who the Client may instruct Open GI to accept.

Categories of Data

Shall include data required to quote for and issue and manage insurance policies which may include policyholders’ and policy beneficiaries’ names, date of birth, full address, contact details, vehicle registration numbers, license numbers, driving conviction details, and gender and such other categories as the Client may instruct Open GI to process.

Categories of Special Category Data

Special Category Data to be processed will be determined by the Client and may include motoring and criminal conviction details of policyholders and policy beneficiaries.

Nature and Purpose of Processing

Providing services or fulfilling contractual obligations to the Client as described in the Agreement which may include such processing activities as storage, retrieval, analysing, anonymising, data collection and data transfer.

Duration of the Processing

For as long as is necessary for Open GI to comply with its obligations under the Agreement or as otherwise permitted by the Agreement.

Appendix B

SECURITY

This Appendix contains a description of the security processes and procedures operated by Open GI in respect of the Services. These processes and procedures will be reviewed by Open GI on a regular basis to ensure they remain fit for purpose and shall be updated, amended or replaced as, Open GI, acting reasonably, consider necessary. 

1. Definitions

In this Appendix, the following words shall have the following meanings:  

1.1. “Good Industry Practice” means the exercise of that degree of professionalism, and skill, diligence, prudence and foresight which would reasonably and ordinarily be expected from a reasonably skilled and experienced person engaged in the provision of services similar to or the same as the Services. 

1.2. “In-Scope Systems” means any system, hardware, equipment or infrastructure used by Open GI to provide the Services to the Client. 

2. Information Security Policies 

With respect to the In-Scope Systems, Open GI shall: 

2.1. ensure that it has in place a set of information security policies approved by senior management that are defined, published and communicated to employees and contractors who are engaged in the provision of the Services;

2.2. review the policies at planned and regular intervals or if significant changes occur to ensure their continuing suitability, adequacy and effectiveness;

2.3. ensure that the policies are aligned with national or international information security standards as Open GI considers appropriate for the Services; and

2.4. upon request, and where reasonably relevant and appropriate, share copies of its information security policies with the Client. The Client shall treat any information and policies shared by Open GI as Confidential Information.  

3. Organisational Measures 

With respect to the In-Scope Systems, Open GI shall: 

3.1. maintain a management framework to oversee the implementation and operation of information security within the organisation and treat this framework as a business-critical function;

3.2. define information security roles and responsibilities;

3.3. carry out ongoing risk assessments and continual framework improvements;

3.4. ensure appropriate segregation of duties;

3.5. where appropriate, maintain contact with relevant authorities and other such special interest groups; and

3.6. address information security in project management and software development. 

4. Human Resource Security 

With respect to the In-Scope Systems, Open GI shall: 

4.1. ensure that employees and contractors providing the Services to the Client have undergone appropriate background checks in accordance with relevant laws, regulations, and ethics, and as a minimum, it shall perform the following checks: 

4.1.1. employee right to work; 

4.1.2. employment history; 

4.1.3. identification and residency checks; and

4.1.4. driving licence check (where relevant to the role);

4.2. establishcontractual agreements with its employees and contractors engaged in theprovision of the Services which impose obligations on such employees andcontractors to comply with information security practices in accordance withthe established policies and procedures;

4.3. ensure that all employees, and where relevant, contractors engaged in the provision of the Services, receive appropriate information security awareness training relevant to their role and performed to a set programme with regular updates;

4.4. maintain a central record of training attendance and continually monitor levels of attendance; and

4.5. maintain a formal disciplinary process to take appropriate action against employees who have intentionally or maliciously caused an information security incident. 

5. Asset Management 

With respect to the In-Scope Systems, Open GI shall: 

5.1. Identify and maintain a register of assets and information processing facilities. 

5.2. Maintain policies and procedures for asset management, which include: 

5.2.1. The acceptable use of assets used for the processing of information for the provision of the Services;  

5.2.2. Where appropriate, a process for the lifecycle of an asset, which includes initial allocation through to the return or disposal of assets. 

6. Access Control 

With respect to the In-Scope Systems, Open GI shall: 

6.1. maintain an access control policy approved by senior management that is defined, published, and communicated to employees and contractors engaged in the provision of the Services. The access control policy shall address: 

6.1.1. the security requirements of the business and business applications;

6.1.2. the access rights required to perform the role; 

6.1.3. relevant legislation and contractual obligations; 

6.1.4. segregation of access controls and access rights; 

6.1.5. the denial of use of generic or shared user ID’s for access purposes; 

6.1.6. the use of unique and identifiable user ID’s; 

6.1.7. enhanced attention to roles with privileged access rights such as system administrators; and

6.1.8. a process to authorise changes to access controls and perform reviews of access rights at regular intervals;

6.2. ensure that users are provided with access only to the systems and networks that they are specifically authorised to use as part of their defined role;

6.3. maintain a formal user registration and de-registration process to enable appropriate assignment of access rights; and

6.4. only grant access rights with elevated privileges on a need-to-use basis. 

7. Cryptography 

With respect to the In-Scope Systems, Open GI shall: 

7.1. maintain a policy on the use of cryptographic controls approved by senior management and published and communicated to employees and contractors engaged in providing the Services.;

7.2. where appropriate, use encryption in accordance with Good Industry Practice;

7.3. manage the lifetime of cryptographic keys which include generating, storing, accessing, distributing, and destroying cryptographic keys as appropriate; and

7.4. maintain a process for managing incidents following the unauthorised loss or misuse of cryptographic keys. 

8. Physical and Environmental Security 

With respect to the In-Scope Systems, Open GI shall, where appropriate: 

8.1. ensure that security perimeters to protect areas that contain sensitive or critical information are in place, which includes data processed on behalf of the Client;

8.2. ensure physical and environmental security controls are covered, throughout its information security management system. As a minimum, these controls shall include measures to: 

8.2.1. protect power or communications cabling infrastructure from tampering or unauthorised access, including interception of data; 

8.2.2. protect equipment from power failures or disruption; 

8.2.3. protect equipment from external or environmental disruption of contamination, including fire; 

8.2.4. protect premises by appropriate entry controls; and

8.2.5. locate equipment in such a manner to reduce the risk of damage or theft; 

8.3. ensure that equipment and physical measures are correctly maintained; and

8.4. maintain policies for the protection of physical assets and environmental threats. 

9. Operational Security 

With respect to the In-Scope Systems, Open GI shall: 

9.1. document security controls and operating procedures in line with Good Industry Practice and make them available to all employees to whom they apply. Operating procedures shall address, where applicable: 

9.1.1. the installation and configuration of systems; 

9.1.2. maintaining appropriate system backups and testing the effectiveness of those backups; 

9.1.3. monitoring procedures; 

9.1.4. identification and management of malware; and

9.1.5. the support and escalation contacts related to unexpected or operational difficulties or events; 

9.2. document and implement a change management process to control changes to the organisation, business processes, information processing facilities, systems, and software that affect information security. The change management process shall include: 

9.2.1. upgrades and modifications to application software; 

9.2.2. changes to users or authentication or authorisation processes or systems; 

9.2.3. a process for the approval and testing of changes prior to their application in a live environment; 

9.2.4. separation of development, testing, and operational environments; 

9.2.5. a risks assessment of the proposed change; 

9.2.6. fall-back procedures, including procedures and responsibilities for aborting or recovering from unsuccessful changes or unforeseen circumstances; and

9.2.7. clear communications to all relevant stakeholders regarding the change and its status; 

9.3. monitor and test In-Scope Systems for security vulnerabilities with consideration to: 

9.3.1. having testing frequencies appropriate to the risk profile of the In-Scope System including considering the scale of changes to that system;

9.3.2. managing security vulnerabilities across computer equipment, applications, operating systems and network components, including the identification of roles, responsibilities and reporting requirements; and

9.3.3. assessing the exposure to such vulnerabilities and implementing appropriate mitigation measures to address the associated risk in a timely manner. 

10. Communications Security 

With respect to In-Scope Systems, Open GI shall: 

10.1. manage networks to protect those systems and Client Data ensuring network traffic is routed through securely configured, managed, and monitored firewalls; 

10.2. maintain appropriate controls to ensure the security of information in networks and systems to protect connected services from unauthorised access;

10.3. ensure that Personal Data is only transmitted within the UK and the EEA unless there are suitable safeguards in place in relation to the transfer;

10.4. maintain appropriate controls to safeguard the confidentiality and integrity of data over public networks or wireless networks;

10.5. maintain appropriate logging and monitoring to enable recording and detection of actions that may affect, or are relevant to, information security; and

10.6. maintain appropriate policies and procedures to protect the transfer of information through the use of communication facilities. These shall include: 

10.6.1. measures to reduce the risk of interception, copying, modification, mis-routing and unauthorised destruction;

10.6.2. procedures for the detection of and protection against malware that may be transmitted using electronic communications;

10.6.3. procedures for protecting communicated sensitive electronic information that is in the form of an attachment; and

10.6.4. outline the acceptable use of communication facilities. 

11. Software Development Security

With respect to In-Scope Systems, Open GI shall: 

11.1. ensure that information security is an integral part of the software development lifecycle which shall include:

11.1.1. the implementation and adherence to a software development lifecycle process (SDLC), including a secure coding methodology;

11.1.2. consideration given to security at the early stages of a project and is designed into that project;

11.1.3. conducting security testing at appropriate stages throughout the development lifecycle;

11.1.4. software developers have the appropriate skills and training to maintain security during development;

11.1.5. Software development is carried out in a secure environment protected against internal and external threats; and

11.1.6. appropriate change control processes are implemented to ensure all changes are tested and logged.

12. Incident Management 

With respect to In-Scope Systems, Open GI shall: 

12.1. maintain procedures and management responsibilities to ensure a quick, effective and orderly response to information security events. Incident management procedures shall include: 

12.1.1. incident response planning and preparation;  

12.1.2. procedures and systems for monitoring, detecting, logging, and reporting security events;

12.1.3. procedures for handling forensic evidence; 

12.1.4. procedures for risk assessing and prioritising security events and incidents; and 

12.1.5. procedures and responsibilities for incident response and timely sharing of information to all stakeholders; and

12.2. maintain policies and procedures to identify and react to security events and incidents where a breach or suspected breach of personal data has occurred. 

13. Business Continuity 

With respect to In-Scope Systems, Open GI shall: 

13.1. maintain a business continuity policy and procedures; 

13.2. maintain business continuity and disaster recovery plans; 

13.3. determine its requirements for information security and the continuity of information security management in situations that would trigger its business continuity plan, and establish, document, implement, maintain and regularly verify procedures to ensure the required level of continuity for information security can be achieved; 

13.4. verify the established and implemented information security continuity controls at regular intervals to ensure that they are valid and effective during adverse situations; 

13.5. ensure that processing facilities are implemented with redundancy sufficient to meet availability requirements; and

13.6. maintain response plans for business continuity events.