top of page

General Terms & Conditions

These Cinco General Terms and Conditions (“General Terms and Conditions”) shall apply by and between:

​​

  • Cinco inc. (9118-2162 Quebec)/Cinco AI, a corporation existing under the laws of Québec/Canada, having its principal place of business at 139 Saint-Paul West, Suite 5, Montreal, Quebec, H2Y 1Z5 (“Cinco”), and

  • The client entity named in the applicable Statement of Work to which these Terms and Conditions apply (“Client”).
     

Cinco and the Client may be individually referred to hereinafter as a “Party” or, collectively, as the “Parties”.
 

BACKGROUND


A: WHEREAS, Cinco is a marketing, sponsorship management, brand activation, content, AI, digital, and experiential company operating its own internal innovation lab called “CincoLab”;
B: WHEREAS, the Client desires to engage Cinco, on a case-by-case basis, to provide services within Cinco’s areas of expertise;
C: WHEREAS, the Parties wish to establish in this document the general terms and conditions governing the performance of services by Cinco for the Client, subject to additional service specific terms that may be set out under any relevant Statement of Work.
 

Defined terms used in this Background section are set out hereinafter.

OPERATIONAL PROVISIONS

NOW, THEREFORE, in consideration of the mutual covenants, terms, and conditions hereinafter set forth, and intending to be legally bound hereby, the Parties agree as follows:

1. DEFINED TERMS

1.1     The following definitions shall apply under these General Terms and Conditions:

“Acceptable Use Policy” or “AUP” means Cinco’s acceptable use policy applicable to the Services, as in effect as of the Effective Date, or as updated upon renewal of the applicable Statement of Work or upon at least thirty (30) days’ prior written notice to Client, available at: (wearecinco.com/appterms) (or such other URL as Cinco may notify to Client in writing). The AUP is incorporated into the Agreement by reference.


“Additional Services” means services, features, or capabilities that are not included in the base service package purchased by Client and that are expressly agreed by the Parties in a Statement of Work or an approved Change Request. Additional Services may include, without limitation, Capacity Extensions, Scaling Packages, multi-market or multi-language deployments, integrations (including CRM, ecommerce or analytics), amplification services, or other scoped add-ons.

Additional Services are not usage-based, consumption-based, or volume-based unless expressly stated in the applicable Statement of Work, and are purchasable only on a pre-agreed, scoped basis at the prices and terms set out in the applicable Statement of Work or Change Request. “Affiliate” means any entity directly or indirectly controlled by, controlling, or under common control with a Party, and where “control” means the power to direct or cause the direction in the management or decision making of that entity, and whether by way of share ownership, under contract or otherwise. “Agreement” for any relevant Services, means these General Terms and Conditions, together with its relevant Appendices, and any applicable Statement of Work, and any other documents incorporated by reference herein or under the relevant Statement of Work. “Applicable Laws” means all laws and regulations in force and applicable to a Party to the Agreement in respect of its rights and obligations under the Agreement, and/or applicable to the supply or receipt of Services (including, where relevant, the EU AI Act or other applicable laws where Services use or deploy artificial intelligence), including Data Protection Laws (as defined in the DPA), and any order of a court of competent jurisdiction and the rules or directions of any competent regulatory authority.

“Applicable Taxes” means any sales, use, consumption, goods and services, or value-added taxes or withholding taxes applicable to the Services or payments made in respect of the Services, except taxes imposed on Cinco’s income.

“Authorized User” means any employee or contractor of Client or other individual or entity who is authorized by Client to access and use the Services. Authorized Users will be identified by Client to Cinco.

“Capacity” means the predefined commercial and technical scope applicable to a servicea package, including without limitation interaction limits, content volume, data retention window, supported features, and performance parameters, as set out in the applicable Statement of Work.

“Capacity Extension” means a pre-purchased, time-limited extension to one or more elements of the Capacity envelope, including without limitation data retention, interaction capacity, or feature availability, as expressly set out in the applicable Statement of Work or approved Change Request.
 

“Change Request” or “CR” means a written document agreed to by Cinco describing a modification to the Services.

“Client Customer” means any existing or prospective customer of Client products and/or services in any relevant territory.


“Client Customer Data” means any data or content (in any medium or format) transmitted by or on behalf of Client Customer to Client and/or Cinco in connection with Client Customer access to and use of the Client Experience Platform.“Client Customer Terms” means the terms and conditions governing Client Customer access to, and use of, the Client Experience Platform, and consisting of (1) the Terms of Use and (2) Client Privacy Policy. The Client Customer Terms constitute a binding agreement only between the Client and the Users of the Client Experience Platform.

“Client Data” means any data or content (in any medium or format) transmitted by or on behalf of Client to Cinco in connection with Client use of Services, and whether in respect of Professional Services implementation of the Client Experience Platform, or Operational Services use by the Client following the Operational Services Commencement Date.

“Client Experience Platform” means the Cinco owned and operated online platform (also known as the “Cinco AI Experience”) provided as a fully white-labelled solution for Client with certain AI Technology capabilities, permitting Client via a Client branded and content led version of the platform, to promote, showcase and advertise Client product and service offerings, and/or link to its own proprietary, transactional websites where Client product and service offerings may be purchased by Client Customers in relevant territories.

“Client Privacy Policy” means the policy maintained at URL: wearecinco.com/privacypolicy, and which provides the default, standard privacy policy and part of the Client Customer Terms for the Client Experience Platform as hereinafter described.

“Client Side Software” means a specific piece of software that, if provided as part of the Services, and whether in respect of Client use of the Client Experience Platform or otherwise, Client may download for use on a non-transferable, non-exclusive, subscription basis in conjunction with and for the duration of the subscription for use of the Services.“

"Cloud Services” means any element of the Services delivered using cloud computing technology.

“Commencement Date” is a several reference to the date(s) on which one or more relevant Services may commence under any applicable Statement of Work and as set out therein.

“Confidential Information” means any information disclosed by one party (“Disclosing Party”) to the other party (“Receiving Party”) which: (i) is marked as proprietary and/or confidential by Disclosing Party; or (ii) Receiving Party should reasonably understand to be confidential.

“Contract Year” means each consecutive twelve (12) month period commencing on the Commencement Date (and each anniversary thereof) during which Operational Services are continuously provided under an applicable Statement of Work. For Operational Services terms shorter than twelve (12) months, references to ‘Contract Year’ mean the duration of the applicable Operational Services term.

“Data Protection Laws” has the meaning set out in the DPA (Appendix 1).

“Default Event” means the occurrence of any one of the following in respect a Party:- (i) (Client only) failure to pay Fees when due; (ii) that Party fails to perform any material term or condition of the Agreement and such failure is not cured within 30 days of written notice from the other Party; (iii) that Party ceases the conduct of active business; (iv) any proceedings under any Applicable Law bankruptcy code or other insolvency laws are instituted by or against that Party, or if a receiver shall be appointed for that Party or any of its assets; or (v) that Party makes an assignment for the benefit of creditors, or admit in writing its inability to pay its debts as they come due.

“Documentation” means the written user documentation provided or made available by Cinco to Client under the Agreement relating to the Services.

“DPA” means the Data Processing Agreement set out in Appendix 1 to these General Terms and Conditions.

“EU AI Act” means the European Union´s Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence.


“Infringement Claim” means claims, suits, actions, or proceedings brought against Client in a court of competent jurisdiction by a third-party that allege an infringement by the Services of a third-party’s patent, copyright, or trade secret.


“Intellectual Property Rights” means all patents, trademarks, service marks, copyright and related rights, domain names, rights in get-up, design rights, database rights, topography rights, and all other similar proprietary rights, in each case whether registered or unregistered and including all applications (or rights to apply) for, and renewals or extensions of, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world.


“Operational Services” is a several or collective reference, as the context permits, to the provision of the Client Experience Platform, Cloud Services, AI Technology and Support.
 

“Person” means, as the context requires, any natural person or legal entity, including bodies corporate, unincorporated associations and partnerships.

“Professional Services” means any Client Experience Platform customization, implementation and training services agreed under any implementation project detailed in any relevant Statement of Work.

“Scaling Package” means a bundled set of Capacity Extensions or Additional Services designed to support increased scale, reach, or duration of the Services, as expressly defined and priced in the applicable Statement of Work.


“Services” is a several or collective reference to Operational Services and Professional Services (and as more specifically described in a relevant Statement of Work).


“Statement of Work” means a document agreed upon by the Parties, describing (i) the provision of relevant Services, (ii) applicable timeline for commencement and duration of Professional Services and/or Operational Services, and (iii) Fees, and (iv) any other additional terms and conditions (if any). A Statement of Work may be agreed in physical or electronic form, incorporates these General Terms and Conditions, and may include other documents which are incorporated by reference into the applicable Statement of Work.

“Support” means the operational and technical support services applicable to the Services, as defined in any part of the Agreement, including these General Terms and Conditions, Statement of Work or any Documentation.


“Terms of Use” or “TOU” means those terms and conditions governing the access to, and use of, the Client Experience Platform by Client Customers and which are part of the  Client Customer Terms. The TOU are maintained at URL: wearecinco.com/appterms


2. TERM OF AGREEMENT

 

​2.1     These General Terms and Conditions take effect and will be binding upon Client and Cinco from its Effective Date, and will apply to all Statements of Work entered into under and subject to these General Terms and Conditions (or which incorporate these General Terms and Conditions by reference).

2.2     The term of any Agreement for applicable Professional Services will begin on the Commencement Date indicated in the relevant Statement of Work, and continue until the end of the period referenced in the Statement of Work.
 

Operational Services Term and Renewal
 

2.3     The term of any Agreement for applicable Operational Services shall commence on the Commencement Date specified in the applicable Statement of Work and shall continue for the duration expressly stated in such Statement of Work (the “Initial Term”).

The Agreement for Operational Services shall automatically renew for successive renewal terms of the duration specified in the Statement of Work (each a “Renewal Term”), unless either Party provides written notice of non-renewal in accordance with this Section.

Either Party may prevent the automatic renewal by providing written notice of non-renewal to the other Party at least thirty (30) days prior to the expiration of the then-current term for the terms, unless a different notice period is expressly stated in the applicable Statement of Work.

2.4     For clarity, short-term time-bound engagements, including,  without limitation,  Pilots, or similar offerings, shall not automatically renew and shall expire at the end of the Initial Term stated in the applicable Statement of Work, unless expressly renewed in writing by the Parties.

3. AGREEMENT FOR SERVICES


3.1     Cinco will provide Client the Client Experience Platform together with other relevant, agreed Services pursuant to the Agreement (and more particularly described in a relevant Statement of Work).

3.2     In the event of any conflict or inconsistency among the documents that constitute the Agreement, the documents will be interpreted in the following descending order of precedence: (i) the applicable Statement of Work (including any Change Request issued thereunder); (ii) these General Terms and Conditions (including its Appendices); and (iii) any other documents incorporated by reference in these General Terms and Conditions or any applicable Statement of Work.

3.3     As necessary to reflect changes in its business, technology and service offerings, Cinco may change its rules of operation, access procedures, software, the Services, or the Documentation. Cinco will endeavour to ensure that any such changes will not result in any material reduction of included functionality/capacity for the paid package during the Term, except for security/legal reasons, and subject to equivalent replacement where commercially and legally viable.

3.4     Cinco may employ its Affiliates and third parties in the performance of the Services, and Cinco shall remain primarily responsible to Client in respect thereof.

3.5     Client’s failure to adhere to schedules or complete tasks within Client’s control, or failure to provide timely access to programs, files, data, or other materials, or failure to provide complete and accurate information in a timely manner, may impact Cinco’s performance of the Services. Cinco shall not be liable for any delays or defects in performing the Services to the extent caused by such Client failure. 

4. IMPLEMENTATION AND OPERATION OF THE CLIENT EXPERIENCE PLATFORM

Implementation Period

4.1     If a Statement of Work specifies an acceptance test for any Professional Service deliverables, Cinco will notify Client when a deliverable is ready for acceptance. Client and Cinco will then perform an agreed acceptance test (“Acceptance Test”) within an agreed time period with respect to each deliverable (“Acceptance Period”) to verify that the deliverable functions materially in accordance with any written specifications as stated in the Statement of Work. Acceptance occurs when the deliverable meets all material requirements of the Acceptance Test. Client will notify Cinco promptly in writing of Client’s acceptance. If Client does not conduct the Acceptance Test and notify within the Acceptance Period or, if no Acceptance Period is specified, then within five (5) business days after delivery of the deliverable, the deliverable will be deemed accepted.

4.2     If Client notifies Cinco in writing within the Acceptance Period that the deliverable does not function in all material respects with the written specifications stated in the Statement of Work, and further describes the deficiencies in sufficient detail for Cinco to identify or reproduce them, Cinco will work diligently to correct and redeliver the affected deliverable.

Operational Services Period

4.3     Client acknowledges and agrees that the Client Experience Platform may only be operated and made available to Client Customers by Client on the basis of the Client Customer Terms, and any other terms that Cinco may reasonably require (and notify in writing to Client) from time to time. Client understands that the use of the Client Customer Terms is mandatory (and describes the minimum requirements as stipulated by Cinco, regarding access and use of the Client Experience Platform, and the Client and Client Customer corresponding rights and obligations in respect thereof). For the avoidance of doubt, Cinco is not a party to, nor will assume any obligations or liability, under the Client Customer Terms, which shall remain solely legally binding commitments as between the Client and the applicable Client Customer(s).

4.4     Client Customer Terms must be displayed in the Client Experience Platform in the designated area agreed with Cinco, and be capable of clear and unequivocal Client Customer acceptance (through use of the “I accept” button or similar functionality provided in the Client Experience Platform) or confirmed acceptance whenever Client Customer visits the Client Experience Platform.

4.5     Client undertakes to ensure that the Client Customer Terms will at all times remain consistent, in all material respects, with the terms and conditions of this Agreement. Client will not seek or attempt to, modify or agree changes to any of the Client Customer Terms provisions which are inconsistent with this Agreement, not will Client behave in any manner in its dealings with Client Customers that would harm or limit any rights that Cinco has under this Agreement, or impose any obligation or liability on Cinco in conflict with the Agreement.

4.6     Client acknowledges that Cinco may require certain acknowledgements and attribution to appear within the Client Experience Platform, including certain Cinco trade and service marks and copyright, and/or identifying Cinco as the entity powering the Client Experience Platform (without presenting Cinco at any time as a party to the Client Customer Terms or in any way identifiable as a part of the Client´s organization (and not an independent, underlying service provider)).

4.7     For the avoidance of doubt, to the maximum extent permitted by Applicable Law, nothing in the Client Customer Terms shall operate or be interpreted as between the Parties to this Agreement, to limit, reduce or override any of Cinco´s rights under the Agreement, or result in any increase in Cinco liability or obligations under the Agreement.

5. SERVICE RESTRICTIONS

5.1     Client and its Authorized Users shall only use the Services for Client’s business operations contemplated and authorized under the Agreement. Only Client’s Authorized Users may access and use the Services, and permit Client Customers access to the Client Experience Platform as described in Section 4 above.

5.2     Client shall not: (i) resell the Services to third parties without Cinco’s prior express written agreement; (ii) create multiple free accounts under different or fake identities or otherwise that enables Client to exceed the usage limits, if any, associated with the Services; (iii) modify, reverse engineer, decompile, or otherwise attempt to discover the source code of the Client Experience Platform, Client Side Software or any of Cinco’s or its third-party providers’ software that may be included in the Services.

5.3     Client does not have any rights to the Client Experience Platform, Client Side Software or to any of Cinco’s or its third-party providers’ software that are included in the Services, other than the use and access thereof on a subscription basis as part of and for the duration of receiving the Services.
 

5.4     If Client Side Software is provided as part of the Services, Client may use the Client Side Software, and make copies thereof, for the sole purpose of facilitating Client’s use of the Services in accordance with the Agreement. Each copy of the Client Side Software made by Client must contain the same copyright and other notices specified by Cinco.

6. AI ENABLED SERVICE

6.1     The Services (and in particular the Client Experience Platform) may include and/or enable the use of predictive algorithms, generative artificial intelligence, machine learning, and/or other artificial intelligence technologies (collectively, “AI Technology”). Where any component of the AI Technology is or incorporates a foundation model or large language model provided by a Third Party Provider, Cinco shall identify this in the documentation provided to Client and shall use reasonable endeavours to ensure that its contractual arrangements with that Third Party Provider support Cinco's ability to fulfil its obligations to Client under this Agreement. Certain AI Technology components may be provided by or supported through Third Party Providers.


6.2     The Client Experience Platform may be white-labeled or co-branded, such that Client Customers primarily perceive the Client Experience Platform as provided by Client, even though the Client Experience Platform, Services and related AI Technology are developed, operated and provided by Cinco.

 

To the extent that: 

(1)  any AI Technology utilized in any part of the Services and/or Client Experience Platform is marketed, deployed, placed on the market, or otherwise made available within the European Economic Area (“EEA”) and considered an AI System (as defined in the EU AI Act), and 
(2)  such white-labeling or co-branding causes Client, under the EU AI Act, to be treated as acting in the capacity of a provider of such AI System (in addition to its role as a user or deployer), 


THEN, Client shall assume relevant roles and responsibilities under the EU AI Act both in its capacity as a “deployer” as well as a deemed “provider”.
 

In any event, where the EU AI Act does apply to any AI Technology provided to Client in the Services and/or Client Experience Platform, it is acknowledged and agreed that the EEA Service Addendum (as described below) will apply as a core contractual element of this Agreement – in order to ensure the Parties respective rights and obligations are appropriately identified and acknowledge in respect of the application of the EU AI Act.


6.3     In respect of any access to, use of, or deployment of AI Technology as part of the Services (including as experienced by Client Customers through interactions on the Client Experience Platform), Client acknowledges and agrees as follows:
 

1.   Inputs, Parameters, and Outputs. AI Technology may process or analyze Client Data and/or Client Customer Data based on parameters, configurations, rules, content, prompts, sources, and other inputs determined, provided, controlled, or approved by Client, or otherwise agreed with Cinco (collectively, “Inputs”). Inputs may contain assumptions, biases, errors, or limitations that can affect the relevance, quality, completeness, and accuracy of the results, responses, or outputs produced by the AI Technology (collectively, “Outputs”).

​​

2.   Client Responsibility for Inputs and Use. Client is solely responsible for (i) the selection, quality, legality, and appropriateness of Inputs, (ii) ensuring that Client has all necessary rights, permissions, and lawful bases to provide Inputs and make them available for processing through the Services, and (iii) the use of Outputs in Client’s business, products, services, and interactions with Client Customers. Client shall use the AI Technology and Outputs in compliance with any instructions, documentation, or intended purpose as provided by Cinco. Client shall ensure that Client Customers agree and comply with this Section 6.3.

3.   No Replacement for Human Judgment. AI Technology is intended to support, not replace, human decision-making and professional judgment. Client remains solely responsible for all decisions, actions, advice, representations, and outcomes arising from its use of Outputs, including any decisions or actions taken by Client Customers. Client is responsible for implementing appropriate human oversight, review, and safeguards for any use of Outputs that could affect individuals, consumers, or regulated activities. Where Applicable Laws impose specific human oversight requirements on Client in connection with its deployment or use of AI Technology, Client shall implement and maintain such measures in accordance with those requirements. Cinco shall design the AI Technology in a manner that enables, and does not frustrate, such oversight.


4.   Accuracy; Output Limitations. Client acknowledges that, by their nature, AI-generated outputs may be incomplete, inaccurate, misleading, or inappropriate in certain contexts. Without limiting Cinco’s obligations under the Agreement (including the DPA), except as expressly stated in this Agreement and subject to mandatory Applicable Laws, Cinco does not warrant that Outputs will be error-free, complete, or fit for any particular purpose, and Client is responsible for independently evaluating Outputs before relying on them. 

5.   Prohibited and High-Risk Uses. Client shall not use the Services or AI Technology for any prohibited, unlawful or unacceptable-risk AI practices, including any uses that would cause the Services or AI Technology to be classified or treated as a “high-risk” AI system under the EU AI Act (where relevant) or other Applicable Laws or mandatory industry standards, unless expressly agreed by Cinco in writing. Client shall not attempt to modify, circumvent, reconfigure, or deploy the Services or AI Technology (including any related disclosures, notices, or branding) in any manner that would (i) reclassify the AI Technology or cause it to be effectively treated as a different or high-risk category when compared with the intended purpose(s) and technical documentation of Cinco, or (ii) impose additional regulatory obligations on Cinco or any Third Party Provider, except to the extent contemplated in, and the result of, the EEA Service Addendum, becoming a necessary part of this Agreement (as described below).

6.   Third Party Providers. Where AI Technology functionality relies on Third Party Provider technologies (including large language models or other generative AI components, including “GPAI models” as referenced in the EU AI Act, where relevant), Client acknowledges that such technologies may have technical constraints and may be subject to Third Party Provider terms applicable to Cinco’s upstream use. No Third Party Provider terms shall apply directly to Client unless expressly incorporated in the applicable Statement of Work. Cinco remains responsible to Client for the Services in accordance with the Agreement.
 

7.   Compliance with Law. Applicable Laws may impose additional requirements concerning the use of AI Technology in certain contexts (particular use cases, industries or deployment scenarios). Each Party shall be responsible for compliance with Applicable Laws as they apply to such Party’s role in connection with the Services and AI Technology - including where that role changes as a result of the manner in which a Party deploys, brands, or makes available the AI Technology. Where a Party's regulatory role changes, the Parties shall cooperate in good faith to reflect the revised allocation of responsibilities, including by reference to any applicable regulatory addendum.

Client is responsible for determining the legal and regulatory requirements applicable to Client’s intended use of AI Technology and Outputs in its own products, services, marketing, ecommerce flows, and interactions with Client Customers, and for ensuring ongoing compliance with such requirements.


8.   EEA Service Addendum. For Services, AI Technology and Client Experience Platform usage, marketing, or deployment within the European Economic Area (“EEA”), the Parties agree to be bound by the terms of the EEA Service Addendum, which sets out additional obligations and responsibilities consistent with the EU AI Act and related regulations, including but not limited to provider and deployer obligations, transparency, human oversight, risk management, and post-market monitoring. The EEA Service Addendum is incorporated by reference into this Agreement and shall apply automatically (and only) to any AI Technology which constitutes an AI System under the EU AI Act, and is deployed or made available within the EEA, without requiring separate execution. The EEA Service Addendum shall govern to the extent of any conflict or inconsistency with this Clause 6.


9.   End-User Notices and Transparency. Client shall ensure that all disclosures, notices, instructions, and user-facing transparency measures required under Applicable Laws in connection with Client Customers’ interaction with AI Technology (including any required notice that Client Customers are interacting with an AI system, and any required labeling of AI-generated content where applicable) are presented within the Client Experience Platform in a clear and accessible manner, and that Client obtains any required consents or acknowledgements. Cinco shall provide Client with reasonable guidance and template disclosure language to support Client's compliance with such transparency obligations across the jurisdictions in which the Services are deployed.

10.   Data Protection. Any processing of Personal Data in connection with AI Technology is governed by the DPA and the Agreement. Nothing in this Section limits Cinco’s obligations under the DPA.
 

7.  USE OF THIRD PARTIES
 

7.1     Cinco may use third-party providers (each a “Third Party Provider”) to provide or support any element of the Services (including, for example, cloud infrastructure or hosting for the Client Experience Platform or functionality utilizing artificial intelligence). In some cases, certain obligations related to data security may be fulfilled by the applicable Third Party Provider (for example, as permitted by the Third Party Provider, Cinco may provide copies of the Third Party Provider’s summary security reports or certifications to Client regarding the portions of the Services they provide). Any access to such reports or audit activities requested by Client (or any data protection authority having jurisdiction over Client) shall, to the extent permitted by the relevant Third Party Provider, be limited in scope to that allowed by such Third Party Provider and may be subject to additional charges, which shall be the responsibility of Client.

7.2     If Client intends to utilize a third-party auditor where such audit activities are permitted by the Third Party Provider, Cinco or the Third Party Provider may object in writing to such auditor where such auditor is: (i) not reasonably qualified; (ii) not independent; or (iii) a competitor of Cinco or the applicable Third Party Provider. Where Client requires functionality that depends on an additional processing service offered by a Third Party Provider (e.g., online language translation services), such additional processing services may be subject to the additional terms and restrictions of the relevant Third Party Provider, provided that no such third-party terms shall apply directly to Client unless expressly agreed in the applicable Statement of Work, and in all cases Cinco remains responsible to Client for the Services in accordance with the Agreement.7.3. A Third Party Provider shall be considered a sub-processor where applicable, and Cinco will appoint and manage such sub-processors in accordance with the DPA. A Third Party Provider may utilize subcontractors provided that such Third Party Provider remains responsible for any subcontracted obligations to the same extent it has committed to Cinco. Client acknowledges that access to stored Client Data may be subject to availability constraints imposed by Third Party Providers.

Data deletion timelines and any post-termination backup/archival deletion lag are governed by the “Data Retention Window” provisions in the Agreement and by the DPA (including its “Return and Deletion of Client Data” section).

8. CLIENT RESPONSIBILITIES

8.1     Client is responsible for:- (i) obtaining, installing, and maintaining the equipment, communication lines, and related support services necessary to access the Services; and (ii) ensuring that its Internet and telecommunications connections (if applicable), hardware, devices, and software are secure and compatible with the Services. If Client elects to use a third-party contractor to perform work interfacing with the Services, such work shall be subject to Cinco’s prior written consent. Client is solely responsible for any work performed by, and any acts or omissions of, such third-party contractor, as well as any defect or issue with the Services to the extent resulting from third-party contractor’s work.

8.2     Client shall be liable for:- (i) acts or omissions by its Authorized Users; (ii) maintaining the confidentiality of access credentials (including usernames, passwords, and keys) used by Client or its Authorized Users; (iii) ensuring compliance with the Agreement by each Authorized User, including compliance with Cinco’s AUP; and (iv) ensuring compliance with Applicable Laws in connection with the use of the Services, including, but not limited to, those related to: (a) laws and regulations pertaining to telemarketing, commercial e-mail, spam, use of artificial intelligence systems; (b) export compliance; and (c) data privacy. 
 

9.  CLIENT DATA AND CLIENT CUSTOMER DATA
 

9.1     Client represents and warrants to Cinco that Client is the owner of all rights to the Client Data, or that Client has the right to reproduce, distribute, and transfer the Client Data to Cinco or otherwise permit Cinco use and access thereof, for the purposes of the Agreement and Services provision. Client further represents and warrants that it will at all times have the right to reproduce, distribute, and transfer, make available to and authorise the processing by  Cinco, any relevant Client Customer Data for the purposes of the Agreement, and provision of Services (including by means of ensuring Client secures such rights through its TOU with Client Customers). Client further represents and warrants that it has established and will maintain a valid lawful basis under Applicable Data Protection Law for the processing of Client Data and Client Customer Data contemplated by the Agreement. Client represents and warrants that Cinco is entitled, in accordance with Client´s ownership or licences (as the case may be), to access, modify, re-arrange and maintain Client Data and Client Customer Data provided to Cinco by or on behalf of Client or Client operation of the Client Experience Platform (consistent with the agreed Statement of Work) and other Services, and (B) in the case of Client Customer Data in the operation, delivery and improvement of Services and in particular the Client Experience Platform.
 

9.2     Client acknowledges that the performance of the Services may include transmission of Client Data and Client Customer Data to third parties in the course of the performance of the Services (e.g. transmission of Client Data and/or Client Customer Data to third party partners as part of Cloud Services consisting of electronic data interchange services), and that Cinco is responsible for ensuring any onwards disclosure of Client Data or Client Customer Data to such third parties is consistent with this Agreement,  the DPA, and Applicable Data Protection Law, including through the use of appropriate written agreements with such third parties where required. 


9.3     Client remains responsible for the Client Data and use of the Services in compliance with the Agreement and with all legal and regulatory obligations applicable to the Client, in its role as controller or business, as applicable, without prejudice to Cinco’s obligations under Applicable Data Protection Law in its role as processor or service provider. Client remains responsible for ensuring it procures that Client Customer Data provided by Client Customers is compliant with Applicable Law, to the maximum extent possible. Client shall be responsible: (i) for the correctness and completeness of the Client Data; (ii) for the Client Data being free from viruses, worms, trojan horses, and any other malicious code; and (iii) for storing and maintaining back-up copies of the Client Data, unless such is included in the Services. Client undertakes to pass through or impose on Client Customers terms substantially similar to those in this Section 9.3 in respect of the accuracy, integrity and lawfulness of Client Customer Data. Notwithstanding the foregoing, if any portion of the Client Data or any Client Customer Data contains material that is harmful to Cinco’s systems (e.g., a virus) or otherwise places Cinco in breach, or at risk, of breaching Applicable Law, Cinco reserves the right to protect Cinco’s systems and mitigate/prevent Cinco harm or liability, by suspending or limiting Client’s access and/or use of the Services (or the Client Customer use of the Client Experience Platform) until the matter is rectified to Cinco´s satisfaction, acting reasonably.


9.4     Client agrees that Cinco may use Client Data and Client Customer Data to (i) perform its obligations under the Agreement and (ii) develop, improve, and operate Cinco’s Services, Client Experience Portal and AI Technology using only data that has been aggregated and/or irreversibly anonymized in accordance with Applicable Data Protection Law such that it no longer constitutes Personal Data, and provided that Cinco shall not attempt to re-identify any such data, in accordance with the DPA.


9.5     If any Client Data or Client Customer Data may be subject to governmental regulation or may require security measures beyond those specified by Cinco for the Services, Client will not provide, allow access to, or input such Client Data or Client Customer Data into the Services for processing or allow Cinco access to such Client Data to provide the Services, unless (i) expressly permitted in the applicable Statement of Work, or (ii) Cinco has expressly agreed in writing to implement additional security measures with respect to such Client Data or Client Customer Data, and any associated costs have been agreed in writing.

9.6     The applicable data retention period, any data return services, and any associated fees shall be specified in the applicable Statement of Work.

To the extent Client Data or Client Customer Data constitutes Personal Data, Cinco shall, upon expiration or termination of the Agreement or the applicable Statement of Work and at Client’s written election, delete or return such Data, in accordance with the DPA and Applicable Data Protection Law.
Notwithstanding the foregoing, Cinco may retain Client Data and Client Customer Data in archival or back-up systems as required by Applicable Law following termination, provided that (i) such data remains subject to the confidentiality, security, and data protection obligations set forth in the Agreement and DPA, and (ii) such data is not actively processed except as required for security, integrity, legal compliance, or disaster recovery purposes.
 

9.7     In order to protect Client Data and Client Customer Data, Cinco will (i) implement and maintain adequate technical and organizational measures (as more fully described in the DPA) appropriate to the nature of the Client Data and Client Customer Data including without limitation, technical, physical, administrative and organizational controls, and will maintain the confidentiality, security and integrity of such Client Data and Client Customer Data; (ii) implement and maintain industry standard systems and procedures for detecting, preventing and responding to attacks, intrusions, or other systems failures and regularly test or otherwise monitor the effectiveness of the safeguards’ key controls, systems, and procedures; (iii) designate an employee or employees to coordinate implementation and maintenance of its security measures; and (iv) identify reasonably foreseeable internal and external risks to the security, confidentiality and integrity of Client Data and Client Customer Data that could result in the unauthorized disclosure, misuse, alteration, destruction or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks.


Data Retention Window


9.8     For the purposes of the Agreement, “Data Retention Window” means the period during which Client Data and Client Customer Data are retained and made accessible within the Client Experience Platform, as determined by the applicable service package, Capacity, and any purchased Capacity Extensions or add-ons, as expressly set out in the applicable Statement of Work.


The Data Retention Window forms part of the commercial scope of the Services. Any extension of the Data Retention Window shall require the purchase of an applicable Capacity Extension or add-on as set out in the Statement of Work or an approved Change Request.


Following expiration or termination of the Agreement or the applicable Statement of Work, Client acknowledges that deletion of Client Data and Client Customer Data from archival systems, back-ups, or systems operated by Cinco or its Third Party Providers may be subject to technical or operational delays of up to one hundred eighty (180) days, during which time all confidentiality, security, and data protection obligations under the Agreement shall continue to apply. During such period, such data shall remain subject to restricted access controls and shall not be actively processed except as required for security, integrity, or legal compliance purposes.


10. FEES, PAYMENT AND TAXES


10.1     Client shall pay Cinco the service fees and charges (the “Fees”) as expressly set out in the applicable Statement of Work (“SOW”). Fees are determined on a value-based basis and consist of the agreed asset package fees together with any expressly approved add-ons, Scaling Packages, Capacity Extensions, or other Additional Services described in the SOW or an approved Change Request.
 

10.2     Unless expressly stated otherwise in the applicable SOW, Cinco does not bill on a usage-based, consumption-based, or metered basis. No fees shall be payable by reference to system usage, volume, or activity levels unless such usage-based pricing is explicitly defined and agreed in writing in the SOW.
 

10.3     Cinco shall invoice Client in accordance with the invoicing schedule set out in the applicable SOW for: (a) Professional Services, and (b) the ongoing provision of Operational Services, as applicable.
 

Annual Price Adjustment
 

10.4     Unless otherwise expressly stated in the applicable SOW, any annual price adjustment of up to five percent (5%) (the “Annual Price Adjustment” or “APA”) shall apply only to Renewal Terms of Operational Services with a continuous subscription term of twelve (12) months or more.
 

10.5     For clarity:

  • The APA shall not apply during the Initial Term, unless the Initial Term is expressly defined in the SOW as a term of twelve (12) months or longer;
     

  • The APA shall not apply to one-time fees, including without limitation build, implementation, customization, configuration, or other Professional Services fees;
     

  • The APA shall not apply to short-term engagements, including Pilots, Activations, Campaigns, or other time-bound services with an Initial Term of less than twelve (12) months, unless expressly stated in the applicable SOW; and
     

  • Fees applicable to add-ons, capacity extensions, scaling packages, or additional services shall be as expressly set out in the SOW or approved Change Request and shall not be subject to automatic adjustment.

Any Annual Price Adjustment shall take effect only at the commencement of the applicable Renewal Term.


Payment Terms
 

10.6     Unless otherwise specified in the applicable SOW, all invoices are due and payable within thirty (30) days from the date of invoice. Fees not paid when due shall accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by applicable law.
 

10.7     If Client disputes any portion of an invoice in good faith, Client shall timely pay all undisputed amounts and promptly notify Cinco in writing of the disputed portion, and the Parties shall use commercially reasonable efforts to resolve such dispute promptly.
 

10.8     If any invoiced amounts not subject to a bona fide dispute remain unpaid following ten (10) days’ written notice from Cinco, Cinco may, without prejudice to any other rights or remedies: (i) suspend the Services until payment is received; and (ii) if such amounts remain unpaid for thirty (30) days after such notice, terminate the Agreement or the applicable SOW upon written notice.
 

10.9     Client shall be responsible for all reasonable costs incurred by Cinco in connection with the collection of overdue amounts, including reasonable attorneys’ fees. All Fees are non-refundable except as expressly stated in the Agreement.
 

Taxes and Currency
 

10.10     All Fees are stated and payable in United States dollars (USD) and are exclusive of all Applicable Taxes. Client shall be responsible for and shall pay all Applicable Taxes in accordance with Applicable Law, other than taxes imposed on Cinco’s net income.

11. INTELLECTUAL PROPERTY AND LICENCES


11.1     As between Cinco and Client, Cinco owns all right, title, and interest, including all related Intellectual Property Rights in and to (i) the Client Experience Platform (including modifications, improvements, upgrades, derivative works and all other intellectual property rights embodied therein) and all other Services, (ii) the Documentation, (iii) Client Side Software, and (iv) any suggestions, ideas, requests, feedback, recommendations or other information provided by Client or any other party relating to the foregoing (other than Client Data), and Cinco reserves all rights to use, modify, and allow others to use such materials. Client may not remove Cinco’s copyright or other proprietary notices from the Documentation or any part of the Services save that in the case of the Client Experience Platform Client will be entitled to present its own Client branding as the prominent branding in the form and manner expressly agreed with Cinco (without diluting any of Client obligations or Cinco rights in respect of Cinco underlying proprietary rights and interest (including Intellectual Property Rights in) the Client Experience Platform).
 

11.2     As between Client and Cinco, the Client Data belongs to Client of Client authorised licensors, and Cinco makes no claim to any right of ownership in the Client Data. However, Client grants Cinco a non-exclusive, fully paid up, worldwide right and licence to access, display, modify and make use of the Client Data for the purpose of Cinco performing is obligations and providing the Services (including delivery of the Client Experience Platform in the form and with the data content and functionality (including AI-Enabled Service elements) agreed with Client pursuant to any Statement of Work which forms part of the overall Agreement).
 

12. LIMITED WARRANTY
 

12.1     Cinco warrants that the Services will be rendered in a professional and workmanlike manner and will function in all material respects in accordance with the Agreement.
 

12.2     THE FOREGOING IS A LIMITED WARRANTY, AND EXCEPT AS EXPRESSLY PROVIDED IN THE AGREEMENT, THE SERVICES ARE PROVIDED WITHOUT EXPRESS OR IMPLIED WARRANTIES OR CONDITIONS OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, Cinco DISCLAIMS ALL OTHER WARRANTIES AND CONDITIONS, INCLUDING ANY IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY, OF SATISFACTORY QUALITY, OR OF FITNESS FOR A PARTICULAR PURPOSE, OR THOSE ARISING BY LAW, STATUTE, USAGE OF TRADE OR COURSE OF DEALING. Cinco DOES NOT WARRANT THAT THE SERVICES WILL BE ERROR FREE OR WILL OPERATE WITHOUT INTERRUPTION. CLIENT ASSUMES THE RESPONSIBILITY TO TAKE ADEQUATE PRECAUTIONS AGAINST DAMAGE TO ITS CLIENT DATA OR OPERATIONS THAT COULD BE CAUSED BY SERVICES DEFECTS, INTERRUPTIONS, OR MALFUNCTIONS.

12.3     Cinco’s sole obligation and Client’s sole remedy under the foregoing limited warranty are strictly and exclusively limited to either the correction of any errors in the affected Services which are made known to Cinco by written notice from Client describing such errors in detail or, at the election of Cinco, a pro rata refund of the Fees paid by Client for the particular portion of the Services which is in error.

13. INDEMNITIES


13.1     Provided Client is not in material breach of the Agreement and is current with payment obligations, Cinco will defend Client from any Infringement Claim, to the extent it arises solely from Client’s use of the Services in accordance with the provisions of the Agreement. This defense will not apply to an Infringement Claim to the extent caused by: (i) modification of the Services by any party other than Cinco or no expressly authorised by Cinco; or (ii) the combination or use of the Services with software, hardware, firmware, data, or technology not provided by Cinco to Client; or (iii) the Client Data. As to any such Infringement Claim referenced under the preceding items (i) or (ii) or (iii), Cinco assumes no liability for infringement and Client will hold Cinco harmless against any infringement claims arising therefrom.
 

13.2     Cinco’s obligations in this Section are conditioned upon: (i) Client notifying Cinco in writing within 10 days of Client becoming aware of an Infringement Claim; (ii) Client’s not making an admission against Cinco’s interests; (iii) Client’s not agreeing to any settlement of the Infringement Claim without the prior written consent of Cinco; (iv) Client providing reasonable assistance to Cinco in connection with the defense, litigation, and settlement by Cinco of the Infringement Claim; and (v) Cinco’s maintaining sole control over legal counsel, litigation, and settlement of the Infringement Claim. Cinco will indemnify Client from any judgment finally awarded, or payments made in settlement of, the Infringement Claim where all the conditions of this Section are satisfied.
 

13.3     If the Services become, or in Cinco’s opinion may become, the subject of an Infringement Claim, Cinco will, at no expense to Client: (i) obtain an authorization for Client to continue using the Services; (ii) modify the Services so they become non-infringing but still provide substantially the same functionality as the infringing Services; or (iii) terminate the Services and refund the unused portion of any prepaid fees received by Cinco from Client. Cinco’s entire liability and Client’s sole and exclusive remedy with respect to any Infringement Claim shall be limited to the remedies set forth in this Section 13.
 

13.4     Client shall defend, indemnify, and hold harmless Cinco, its Affiliates, directors, employees and subcontractors from any damages, losses, claims, and expenses arising from any claim or other legal action related to: (i) Client Data that Cinco uses, processes and/or manages in connection with the Services; (ii) Client’s or any Authorized User’s use of the Services; and/or (iii) Client’s or any Authorized User’s breach of the Agreement.


14. LIABILITY


14.1        Exclusion. Subject to Sections 14.3 and 14.4, neither Party nor its Affiliates will be liable for: (i) indirect, incidental, special, consequential, aggravated, exemplary, or punitive damages; or (ii) damages, compensation or reimbursement for lost sales, lost revenue, lost profits, loss of anticipated savings, downtime costs, lost or corrupted data, cost of substitute services or products or facilities, re-procurement amounts, or due to Force Majeure under Section 19.13 below.
 

14.2        Limitation. Subject to Sections 14.1, 14.3 and 14.4, the maximum aggregate liability of Cinco and its Affiliates taken together:
 

14.2.1     for all claims in the aggregate arising from or relating to the Agreement or the Services during or in relation to an individual Contract Year, is limited to the total Fees paid by Client for the Services for the applicable Contract Year; and
 

14.2.2     for all claims in the aggregate arising from or relating to the Agreement or the Services during or in relation to an Agreement Term that is longer than two (2) Contract Years, is limited to an amount equal to the sum of the total Fees paid by Client for the Services in the first two (2) Contract Years, with such amount being inclusive of and not in addition to the total liability determined under Section 14.2.1.
 

14.3.       Exceptions. Nothing in the Agreement shall exclude or limit liability for: (i) death or personal injury caused by negligence; (ii) fraud; (iii) gross negligence, (iv) wilful misconduct, or (v) any other liability that cannot be excluded under Applicable Law.
 

14.4        Disclaimer. The limitations and exclusions in the Agreement apply in regard to any and all claims arising out of or relating to the Agreement or the Services, in tort, equity, at law, strict product liability, or otherwise, including claims of negligence, breach of contract or warranty, regardless of the form of action, or whether any such claim relates to acts or omissions of the party claimed against or any other Person or entity (including, without limitation, such party’s subcontractors), and even if: (i) a party is advised of the possibility of such damages or claims; (ii) such damages or claims were foreseeable; or (iii) a party’s remedies fail in their essential purpose. Except as otherwise provided under Applicable Law, the remedies specified in the Agreement are exclusive.

​​​​

15. CONFIDENTIALITY


15.1        Each Disclosing Party may disclose to the Receiving Party Confidential Information pursuant to the Agreement. 

15.2        Each Receiving Party agrees, for the Agreement Term and for three (3) years thereafter, to hold Disclosing Party’s Confidential Information in strict confidence, not to disclose such Confidential Information to third parties (other than to Affiliates, (or Third Party Providers in Cinco´s case) and to professional advisers who are bound by appropriate written obligations of confidentiality) unless authorized to do so by Disclosing Party, and not to use  such Confidential Information for any purpose except as expressly permitted hereunder. Each Receiving Party agrees to take reasonable steps to protect Disclosing Party’s Confidential Information from being disclosed, distributed or used in violation of the provisions of this Section.

15.3        The foregoing prohibition on disclosure of Confidential Information shall not apply to any information that: (i) is or becomes a part of the public domain through no act or omission of Receiving Party; (ii) was in Receiving Party’s lawful possession without confidentiality obligation prior to disclosure by the Disclosing Party; (iii) is lawfully disclosed to Receiving Party by a third party without restriction on disclosure; (iv) subsequently becomes publicly available through no fault of the Recipient Party; (v) is Client Data, which is governed by Section 9 (Client Data) above; (vi) is independently developed by Receiving Party or its employees or agents without use of Disclosing Party’s Confidential Information; or (vii) is required to be disclosed by Receiving Party as a matter of law or by order of a court or by a regulatory body, provided that Receiving Party promptly notifies Disclosing Party (where lawfully permitted to do so) so that Disclosing Party may intervene to contest such disclosure requirement and/or seek a protective order or waive compliance with this Section. Each Receiving Party is responsible for any actions of its Affiliates, employees and agents in breach of this Section.

15.4        The Recipient Party shall, upon the expiry or termination of the Agreement or on demand of the Disclosing Party, use reasonable endeavours to:

15.4.1     return to the Disclosing Party, or destroy (as the disclosing party may direct), all of the Confidential Information and not retain any copies, extracts or other reproductions in whole or in part of the Confidential Information (except to the extent required by Applicable Law);

15.4.2     destroy all documents, memoranda, notes and other writings whatsoever prepared by it or for it or in its possession which incorporate any of the Confidential Information (except to the extent required by any Applicable Law); and

15.4.3     within thirty (30) days following a written request by the Disclosing Party, provide a certificate executed by a duly authorised officer of the Recipient Party confirming that the Recipient Party has complied with all of its obligations under this Section 15.4.
​​

16. DATA PROTECTION


16.1     Data Processing Agreement (Appendix 1 to these General Terms and Conditions). Cinco will provide the Services in accordance with applicable Data Protection Law requirements described under the DPA (Appendix 1). The DPA describes the Parties´ specific roles and responsibilities under applicable Data Protection Law in regards to the Services and Client Customers, and their specific roles as data processor (Cinco) and data controller (Client) (as such terms are defined in the DPA). It also describes the technical and organisational security measures and standards applied by Cinco and/or its Third Party Providers in respect of the processing of relevant data to which the DPA applies.
 

16.2     Client Privacy Policy (Client Customers). The Client Privacy Policy will appear on, be readily accessible to, and apply to all Client Customer access and use of the Client Experience Platform. Such Client Privacy Policy identifies Client as the data controller of Client Customer personal data, and that Client makes use of third data processors such as Cinco to carry out relevant personal data processing). Client acknowledges and agrees that it is responsible for reviewing, approving, and adopting the Client Privacy Policy for its use of the Client Experience Platform and for ensuring its accuracy with respect to Client’s role as data controller. Client shall include in its Terms of Use a clause making clear that CINCO is acting solely as a data processor and that CINCO bears no responsibility for compliance or end-user data obligations.
 

17. TERMINATION AND SUSPENSION
 

17.1     Services Suspension. Cinco may suspend the Services without Cinco incurring liability for such suspension in order to support compliance with Applicable Laws or to prevent damage, liability, risk or other harm to Cinco, Cinco Affiliates, suppliers/service providers, Client, Client Customers or to Cinco’s other clients. Upon written notice to Client, Cinco may require Client’s assistance in verifying usage of the Services in compliance with the terms of the Agreement. Cinco will be entitled to terminate the Agreement if Cinco reasonably believes that the circumstances causing suspension are not likely to be resolved in a timely manner.
 

17.2     Client Default Event. Upon occurrence of any Client Default Event, Cinco may terminate the Agreement and/or cease or suspend the performance of Services. In addition, in the event of any Client Default Event all accrued Fees will become immediately due and payable. Any such termination shall be without prejudice to any other rights or remedies which Cinco may have against Client with respect to such default, and shall not entitle Client to a refund, in whole or in part, any fees or charges. No remedy referred to in this Section is intended to be exclusive, but shall be cumulative and in addition to any other remedy referred to herein or available to Cinco at law or in equity.
 

17.3     Cinco Default Event. Upon occurrence of any Cinco Default Event, Client may terminate the Agreement. Any such termination shall be without prejudice to any other rights or remedies which Client may have against Cinco with respect to such default. Upon such termination, Cinco shall refund to Client a prorated amount of any fees prepaid by Client for a period following the effective date of such termination. No remedy referred to in this Section is intended to be exclusive, but shall be cumulative and in addition to any other remedy referred to herein or available to Client at law or in equity.
 

17.4     Termination For Cause. If either Party is in material breach of this Agreement, the other Party may terminate this Agreement at the end of a written 30-day notice/cure period, if the breach has not been cured.


For material breaches relating to the rights granted or restrictions in Sections 5 (Restrictions on use); 8 (Client Responsibilities); 9 (Client Data); 10 (Fees, payment and taxes); 11 (Intellectual Property and Licences); 15 (Confidentiality); or 16 (Data Protection), no such cure period will be granted and such termination may be immediate. Except in the event of a material breach or as specifically provided in the Agreement, neither Party will be permitted to terminate the Agreement prior to the end of the Agreement Term. Actions upon termination. Upon any termination of the Agreement: (i) Cinco shall cease to perform the Services; (ii) Client shall immediately pay all accrued Fees; (iii) Client will immediately either return to Cinco or destroy all copies of (a) Documentation, and (b) Client Side Software; (iv) each Party shall destroy or promptly return all copies, partial copies, and any documentation or materials evidencing the other party’s Confidential Information; and (v) return of Client Data shall be governed by Section 9 (Client Data) above. Survival. The following provisions shall survive termination or expiration of the Agreement: Sections 5 (Restrictions on use); 8 (Client Responsibilities); 9 (Client Data); 10 (Fees, payment and taxes); 11 (Intellectual Property and Licences); 13 (Indemnities); 14 (Liability); 15 (Confidentiality); or 16 (Data Protection), and any provisions that by their nature should survive termination.

18. ADDITIONAL SERVICES

 

18.1     Additional Services may be requested by Client in the Statement of Work, or via an amendment or Change Request to the Statement of Work.

​​

18.2     With respect to the materials produced for Client as a result of Additional Services, Cinco provides to Client a non-exclusive, non-transferable subscription to access and use such materials solely in connection with Client’s use of the Services. All rights, title, and interest in such materials remain with Cinco.

 

19. GENERAL

 

19.1        Entire agreement; amendment; waiver. The Agreement represents the entire agreement of the parties, and supersedes any prior or current understandings, whether written or oral with respect to the subject matter of the Agreement. It is expressly agreed that if Client issues a purchase order or other document in connection with the Agreement, such document will be deemed to be for Client’s internal administrative convenience only, any provisions contained therein shall not amend or be used in interpreting the Agreement, and not providing a purchase order does not relieve Client from the responsibility to make timely payments as set forth in the Agreement. Any amendment of the Agreement must be in writing and signed by both parties. Neither party will be deemed to have waived any of its rights under the Agreement by lapse of time or by any statement other than by a written waiver signed by a duly authorized representative. No waiver constitutes a waiver of any prior or subsequent breach. Section headings are for convenience only and will not be construed as a part of this Agreement.

19.2        Right to notify. Notwithstanding any other term of the Agreement, Client agrees that Cinco shall have a right to notify law enforcement if, during the performance of the Services, Cinco: (a) observes information that, in the opinion of Cinco, may be unlawful or constitute a criminal offence; believes in its reasonable opinion that continued performance of the Services will commit or aid and abet any crime. In such an event, Cinco may notify Client of such evidence, and Client agrees that Cinco has a right to discontinue performance of the Services and/or terminate the affected Statement of Work, without liability or penalty.


19.3        No solicitation. During the Agreement Term and for a period of one (1) year after its termination, Client agrees not to solicit the employment of, nor hire or retain as a contractor or consultant, any individuals who are or were Cinco employees, or contractors performing the Services under the Agreement. The foregoing restriction shall not apply in the event Client employs a current or former Cinco employee who responds to an employment position opening made public by Client via a major newspaper, industry publication, or Internet job posting site.
 

19.4        Relationship of the Parties. The relationship of the parties created by the Agreement is that of independent contractor and not that of employer/employee, principal/agent, partnership, joint venture or representative of the other. Neither party is authorized to make any representation, contract or commitment on behalf of the other party. The establishment of the terms of any commercial or legal relationship between Client and any third-party by means of the use of the Services provided hereunder is the sole responsibility of Client. The provision of such Services by Cinco will not be interpreted as conferring any authority or responsibility on Cinco with respect to such relationships or the establishment, continuation or binding effect of such terms.
 

19.5        Services Statistics. Cinco shall be entitled to use, develop or share its experience and knowledge (including processes, ideas, statistical and other information) acquired by it in connection with the services and/or products (“Services Statistics”), provided that any such use of the Services Statistics by Cinco is in a manner or form whereby: (i) the Client is not identified as a source of any such Services Statistics; and (ii) any data arising from the Services Statistics is anonymized.


19.6        Third party rights. No term of the Agreement is intended to confer a benefit on, or to be enforceable by, any person or entity which is not a party to the Agreement; provided that either party’s Affiliate which is defined as an Authorized User under a Statement of Work shall be deemed a party to the Agreement for the purposes of that Statement of Work.


19.7        Assignment. Client may not assign or otherwise transfer any of its rights or obligations under the Agreement, in whole or in part, without the prior written consent of Cinco. Any assignment in breach of this Section is null and void. Except to the extent identified in this Section, the Agreement will be binding upon and inure to the benefit of the respective successors and permitted assigns of the parties.


19.8        Publicity. Client shall not use in any advertising, publicity, promotion, marketing, or other similar activity, any name, trade name, trademark, or other designation including any abbreviation, contraction, or simulation of Cinco, without Cinco’s prior written consent.


19.9        Export laws. The Services (which for purposes of this Section include any Client Side Software, Documentation and technical data stored or transmitted via the Services) may be subject to export and import control laws of Canada, the United States, the European Union, or other countries. Client agrees to comply strictly with all applicable export and import regulations, including, but not limited to (i) the Export Administration Regulations maintained by the U.S. Department of Commerce, and (ii) the trade and economic sanctions maintained by the U.S. Department of Treasury Office of Foreign Assets Control, and will not allow use of the Services in a manner that breaches or facilitates the breach of such regulations. Client has the responsibility to obtain any licenses required to export, re-export, or import the Services, including deemed exports. The Services shall not be provided to nor used by anyone: (a) located in any applicable embargoed or sanctioned countries or by any Foreign National of a U.S. embargoed country; or (b) included on the U.S. Treasury Department’s list of Specially Designated Nationals; (c) the U.S. Department of Commerce’s Denied Persons or Entity List; or (d) subject to trade control sanctions or blocking measures. By using the Services, Client represents and warrants that neither Client nor any Person provided access to the Service by Client is located in any such country or on any such list.

19.10        Force Majeure. At times, the action or inaction of parties or systems not controlled by Cinco or other events beyond Cinco’s control can impair, disrupt or delay Cinco’s ability to provide the Services or Client’s ability to access the Services. Cinco disclaims, and Client shall not hold Cinco responsible for, any and all liability resulting from or related to such actions or events, including acts of God, acts of governmental authority, unavailability of third-party communication facilities or energy sources, fires, transportation delays, or pandemics, or any cause beyond Cinco´s reasonable control (collectively “Force Majeure”).

19.11        Notices. Any notice under the Agreement that must be given by a Party in writing is to be sent either (i) via certified or registered mail, postage prepaid, or (ii) via express mail or nationally recognized courier service to the other Party’s address specified in the Agreement or on the most recent Statement of Work, and shall be effective when received.


19.12        Severability. If any provision of the Agreement is held by a court of competent jurisdiction to be contrary to law, the provision shall be modified so as best to accomplish the objectives of the original provision to the fullest extent permitted by law, and the remaining provisions of the Agreement shall remain in effect.
 

19.13        Governing Law and Jurisdiction. This Agreement shall be governed by and construed in accordance with the laws of the Province of Québec and the federal laws of Canada applicable therein, without regard to conflict of laws principles. The Parties irrevocably attorn to the exclusive jurisdiction of the courts located in Montréal, Québec, Canada for any dispute arising out of or relating to this Agreement.


19.14        Language. The Parties have expressly requested that this Agreement and any notice or other document in connection therewith (including SOW and PO) be prepared in the English language. Les parties ont demandé spécifiquement que cette convention ainsi que tous les avis et autres documents y afférents (y compris tout devis ou bon de commande) soient rédigés en anglais.

19.15        Execution. This Agreement may be executed in counterparts, each of which so executed shall be deemed to be an original, and together which shall be deemed to be but one and the same instrument. Delivery or acceptance of this Agreement or any portion thereof by facsimile transmission or digitally, or in any electronic fashion, shall have the same effect as if delivered personally and any such transmission signature, initial, or notation, shall have the same effect as if it were an original and shall be binding upon the maker thereof.

List of Appendices

Appendix 1: Data Processing Agreement

Appendix 2: EEA Service Addendum
 

______________________________

​​

 

APPENDIX 1 - DATA PROCESSING AGREEMENT (DPA)


This Data Processing Agreement, including its Schedules, ("DPA”) forms part of the Agreement between Cinco and you ("Client” or "you”) for the purchase of the Services (the “Agreement”) to reflect the Parties’ agreement with regard to the Processing of Personal Data.

Client enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws and Regulations, in the name and on behalf of its Authorized Affiliates. For the purposes of this DPA only, and except where indicated otherwise, the term "Client” shall include Client and Authorized Affiliates All capitalized terms not defined herein shall have the meaning set forth in the Agreement.

In the course of providing the Services to Client pursuant to the Agreement, Cinco may Process Personal Data on behalf of Client and the Parties agree to comply with the following provisions with respect to any Personal Data, each acting reasonably and in good faith.

If the Client entity signing this DPA has executed a Statement of Work (“SOW”) or Services Order with Cinco or its Affiliate pursuant to the Agreement, but is not itself a party to the Agreement, this DPA is an addendum to that SOW and applicable renewal SOW, and the Cinco entity that is party to such SOW is party to this DPA.

1. Definition
 

1.1     Unless otherwise defined herein, the terms used in this DPA shall have the same meaning than the terms used in the Agreement.

 

"Authorized Affiliate'' means any of Client’s Affiliate(s) which  is permitted to use the Services pursuant to the Agreement between Client and Cinco, but has not signed its own SOW with Cinco and is not a ‘‘Client’’ as defined under this DPA.

"CCPA'' means the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended by the California Privacy Rights Act, and its implementing regulations.

“Cinco” means Cinco inc., a company incorporated in the Province of Quebec, Canada, incorporated under the number 9118-2162 Quebec Inc.

“Client Customer” means any existing or prospective customer of Client products and/or services in any relevant territory.

“Client Customer Data” means any data or content  (in any medium or format) transmitted by or on behalf of Client Customer to Client and/or CINCO in connection with Client Customer access to and use of the Services.

"Controller" means the entity which determines the purposes and means of the Processing of Personal Data.

“Cookies” means cookies, pixel tags and other similar technologies.

"Client" means the entity that executed the Agreement together with its Affiliates (for so long as they remain Affiliates) which have signed SOW.

"Client Data" means any electronic data or materials provided or submitted by or for Client to or through the Services. This DPA does not apply to non-Cinco applications.

"Client Data Incident” means the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Data, including Personal Data, transmitted, stored or otherwise Processed by Cinco or its Sub-processors.

“Cross-Context Behavioral Advertising” means the targeting of advertising to a Consumer based on the Consumer’s personal information obtained from the consumer’s activity across businesses, distinctly-branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the consumer intentionally interacts.

"Data Protection Laws and Regulations'' means all laws and regulations applicable to the Processing of Personal Data under the Agreement and the placement of Cookies, including those of the European Economic Area, Switzerland, the United Kingdom and the United States and its states.

"Data Subject" means the identified or identifiable person to whom Personal Data relates.

“Data Subject Request” means, a Data Subject's legal right of access, right to rectification, restriction of Processing, erasure (“right to be forgotten”), data portability, object to the Processing, or its right not to be subject to an automated individual decision making as set out in applicable Data Protection Laws and Regulations.

“Europe" means the European Economic Area, Switzerland and the United Kingdom.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), including as implemented or adopted under the laws of the United Kingdom.

“Operational Services” is a several or collective reference, as the context permits, to the provision of the Client Experience Platform, Cloud Services, AI Technology and Support (as defined in the Agreement).

“Personal Data” means any information relating to (i) an identified or identifiable natural person and, (ii) an identified or identifiable legal entity (where such information is protected similarly as Personal Data or personally identifiable information under applicable Data Protection Laws and Regulations), where for each (i) or (ii), such data is Client Data.

“Processing’’ or “Process" means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

“Processor” means the entity which Processes Personal Data on behalf of the Controller, including as applicable any “service provider” as that term is defined by the CCPA.

“Professional Services” means any Client Experience Platform customization, implementation and training services agreed under any implementation project detailed in any relevant SOW.

“Public Authority” means a government agency or law enforcement authority, including judicial authorities.

“Reasonable Security Procedures and Practices” means security measures appropriate to the nature of the Personal Information that are implemented and maintained to prevent the unauthorized access and exfiltration, theft, or disclosure of nonencrypted or nonredacted Personal Information.

“Sale of Data” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Consumer’s Personal Data by a business to another business or a third party for monetary or other valuable consideration.

“Services” means the Professional Services and Operational Services specifically described in a SOW.

"Standard Contractual Clauses” means Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en

“Sub-processor" means any Sub-processor engaged by Cinco for the provision of the Services.

“UK GDPR” means the Data Protection Act 2018, as well as the GDPR as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 (SI 2019/419).
 


2. PROCESSING OF PERSONAL DATA

2.1     Roles of the Parties. Unless otherwise provided in this DPA, the parties acknowledge and agree that with regard to the Processing of Personal Data, Client is a Controller or a Processor, Cinco is a Processor and that Cinco will engage Sub-processors pursuant to the requirements set forth in section 6 “Sub-processors” below.


2.2     Client’s Personal Data Obligations. Cinco will not Process any Personal Data on behalf of Client except upon its documented instructions and consistent with the stated nature and purpose of the processing (as set forth in the attached Schedule 1 – Description of Processing/Transfer), or as required by applicable law Data Protection Laws and Regulations and following reasonable notice to Client (where legally permitted). Client hereby instructs Cinco to Process Personal Data to provide Services in accordance with the Agreement and this DPA. Client shall promptly confirm oral instructions in writing. CINCO shall inform Client immediately if Cinco has a good faith belief that an instruction violates applicable Data Protection Laws and Regulations. Cinco shall then be entitled to suspend execution of the relevant instructions until Client confirms or changes them to comply with applicable law. 
 

2.3     Details of the Processing. The subject-matter of Processing of Personal Data by Cinco is the performance of the Services pursuant to the Agreement. The duration of the Processing, the nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects Processed under this DPA are further specified in Schedule 1 (“Description of Processing/Transfer”) to this DPA.


3. RIGHTS OF DATA SUBJECTS

3.1     Cinco will rectify, erase, or restrict the Processing of data that is being processed on behalf of Client on Client’s documented instructions to the extent Client is unable to do it on his account.


3.2     To the extent legally permitted, if a Client’s Data Subject contacts Cinco directly concerning a rectification, erasure, or restriction of Processing, or complaint, Cinco will immediately, and in all cases within five (5) business days, forward the Data Subject’s request to the Client.
 

3.3     Cinco will assist Client in fulfilling Data Subject requests to exercise rights of rectification, erasure, restriction, objection, data portability, or access in accordance with documented instructions from Client, or with dealing with a complaint from a Data Subject,  without undue delay to the extent commercially practicable. Cinco may charge a reasonable fee to assist Client in the fulfilling of its obligations under this DPA.


4. CINCO PERSONNEL


4.1     Confidentiality. Cinco shall ensure that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data, have received appropriate training on their responsibilities and have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Cinco shall ensure that such confidentiality commitments survive the termination of the personnel engagement.
 

4.2     Reliability. Cinco shall take commercially reasonable steps to ensure the reliability of any Cinco personnel engaged in the Processing of Personal Data.
 

4.3     Limitation of Access. Cinco shall ensure that Cinco' access to Personal Data is limited to those personnel performing Services in accordance with the Agreement.
 

5. ARTIFICIAL INTELLIGENCE


5.1     CINCO uses AI Technology to enhance the functioning and quality of the  Services it provides to Client. Client agrees that CINCO may use and store Client Data and Client Customer Data that is submitted to, or generated by, any AI Technology (and whether Inputs or Outputs) to (i) perform its obligations and Services under the Agreement and (ii) to develop, train and improve CINCO's AI Technology, and (iii) develop best practices, benchmarking and data analytics, but only on the basis that Client Data and Client Customer Data used for such purposes is aggregated or anonymized in accordance and will not be disclosed to any third-party in a manner that would allow them to identify Client, Client Customers or Client personal data.
 

5.2     Cinco is committed to ensuring that the use of  AI Technology in connection with the Services complies with applicable data protection laws.
 

5.3     Should Cinco wish to use Client’s Personal Data in the future for training its algorithms in any AI technology, it will do so only with Client’s explicit consent (when legally required). 
 

6. SUB-PROCESSORS


6.1     Appointment of Sub-processors. Client acknowledges and agrees that (a) Cinco’ Affiliates may be retained as Sub-processors; and (b) Cinco and Cinco’ Affiliates respectively may engage third-party Sub-processors in connection with the provision of the Services. In this case, Cinco or a Cinco’s Affiliate shall enter into a written agreement with each Sub-processor containing, in substance, the same data protection obligations than those in the Agreement with respect to the protection of Client Data to the extent applicable to the nature of the Services provided by such Sub-processor.
 

6.2     List of Current Sub-processors and Notification of New Sub-processors. The current list of Sub-processors     engaged in Processing Personal Data for the performance of each applicable purchased Services, including a description of their processing activities and countries of location, is listed in a link in Schedule 1 attached. Clients hereby consent to the use of these Sub-processors, as it pertains to their Personal Data. Client is responsible for re-checking the sub-processor URL to obtain notice of future changes.
 

6.3     Objection Right for New Sub-processors. Client may reasonably object to Cinco’ use of a new Sub-processor by notifying Cinco promptly in writing within thirty (30) days Cinco’ s written notice on the Sub-processor page, but shall  make reasonable efforts to make available to Client a change in the Services or recommend a commercially reasonable change to Client’s configuration or use of the Services to avoid Processing of Personal Data by the objected-to new Sub-processor. If Cinco is unable to resolve Client's objections, Client may terminate the applicable SOW with respect only to the Services which cannot be provided by Cinco without the use of the objected-to new Sub-processor by providing written notice to Cinco. Cinco will refund Client any prepaid but unused Fees covering the remainder of the term of such SOW following the effective date of termination with respect to such terminated Services, without imposing a penalty for such termination on Client.
 

7. SECURITY
 

7.1     Controls for the Protection of Client Data. Cinco shall maintain appropriate technical and organizational measures for protection of the security (including protection against unauthorized or unlawful Processing and against accidental or unlawful destruction, loss or alteration or damage, unauthorized disclosure of, or access to, Client Data), confidentiality and integrity of Client Data, as set forth in Schedule 2 attached. Cinco regularly monitors compliance with these measures. Cinco will not materially decrease the overall security of the Services as a result of change(s) to its security measures.
 

7.2     Audit. Cinco shall maintain an audit program to help ensure compliance with the obligations set out in this DPA and shall make available to Client information to demonstrate compliance with the obligations set out in this DPA, including those obligations required by applicable Data Protection Laws and Regulations, as set forth in this section 7.2.
 

7.3      Third-Party Certifications and Audits: Cinco has obtained certifications or third-party audit reports related to data security. Upon written request from Client, Cinco shall provide a copy of the latest audit report and/or third-party audit reports or information to demonstrate Cinco’s compliance with its obligations under this DPA.  Client shall accept the findings of such certification or third-party audit report in lieu of carrying its own audit with respect to the areas covered by such certification or audit report Client acknowledges that any information provided under this Section 7.3 shall be considered Confidential Information.


7.4     Legally Mandated On-Site Audits: Where applicable Data Protection Laws and Regulations mandate that Cinco must be subject to an audit by the Client, Cinco will permit Client (or its Third-Party Auditor) to conduct documentary  audit of the Processing undertaken by Cinco in respect of the provision of the Services. Such documentary audits shall take place on reasonable notice and no more than annually, or more frequently if there are indications of non-compliance with this DPA.


8. DATA PROTECTION IMPACT ASSESSMENT


8.1     Upon Client’s request, Cinco shall provide Client with reasonable cooperation and assistance needed to fulfill Client’s obligation under Data Protection Laws and Regulations to carry out a data protection impact assessment related to Client's use of the Services, to the extent Client does not otherwise have access to the relevant information, and to the extent such information is available to Cinco.


9. CLIENT DATA INCIDENT MANAGEMENT AND NOTIFICATION


9.1     Notification. Cinco maintains security incident management policies and procedures. Cinco shall notify Client without undue delay (not to exceed 72 hours) after becoming aware of a “Client Data Incident”.


9.2     Cinco Responsibilities. In respect of such Client Data Incident, Cinco shall: (i) make reasonable efforts to identify the cause; (ii) take such steps as Cinco deems necessary and reasonable to remediate the cause to the extent the remediation is within Cinco' reasonable control; (iii) cooperate reasonably with the Client and provide Client with the information needed to fulfil its data breach obligations under Data Protection Laws and Regulations; (iv) take other further measures and actions that Cinco determines are necessary to remedy or mitigate the effects of the security incident, and (v) except as required by law, Cinco will not take action to notify Data Subjects of any security incident.


9.3     Exclusions. The obligations imposed on Cinco and set out in section 9.2, shall not apply to incidents that are caused by Client or Client’s users.
 

10. RETURN AND DELETION OF CLIENT DATA
 

10.1     Cinco may not create copies or duplicates of the Client Personal Data without Client’s knowledge and consent, except (i) as required to provide Services, (ii) for back-up copies to the extent necessary to ensure orderly data processing and disaster recovery, or (iii) to the extent required by applicable law or regulatory requirements to retain data.
 

10.2     Upon Client’s written request within 30 days after termination or expiration of the Agreement, Cinco will make Client Personal Data available to Client in an industry standard format.  After such a 30-day period, Cinco has no obligation to maintain the Client Data and will destroy it; provided that Cinco may maintain the Client Data to the extent required for legitimate business purposes, including to comply with legal obligations, resolve disputes and conduct audits.

11. DATA TRANSFERS
 

11.1     Should Client Personal Data originates from and/or be processed within the United Kingdom (“UK”), a Member State of the European Union (“EU”) or within a Member State of the European Economic Area (“EEA”), any subsequent transfer of Such Personal Data to Cinco in a country that is not the UK, a Member State of either the EU or the EEA, such transfer shall occur only if the specific conditions of Article 44 et seq GDPR or the UK GDPR, as applicable, have been fulfilled. For the avoidance of doubt, signature of the DPA shall be deemed to constitute signature and acceptance of the EU Standard Contractual Clauses (if applicable), including it applicable module (The EU C-to-P Transfer Clauses or EU P-to-P Transfer Clauses, as applicable), unless  Client wishes to separately execute the Standard Contractual Clauses with Cinco.


Where Client and/or its Authorized Affiliate is a Controller and a data exporter of Personal Data and Cinco is a Processor and data importer in respect of that Personal Data, then the Parties shall comply with the EU C-to-P Transfer Clauses.


Where Client and/or its Authorized Affiliate is a Processor and a data exporter of Personal Data and Cinco is a Processor and data importer in respect of that Personal Data, then the Parties shall comply with the EU P-to-P Transfer Clause.


"EU C-to-P Transfer Clauses" means Standard Contractual Clauses sections I, II, III and IV (as applicable) to the extent they reference Module Two (Controller-to-Processor).


”EU P-to-P Transfer Clauses" means Standard Contractual Clauses sections I, II, III and IV (as applicable) to the extent they reference Module Three (Processor-to-Processor).
 

11.2     For any transfer of Client Data not subject to the GDPR or UK GDPR, then the transfer conditions set out by the applicable Data Protection Laws and Regulations shall apply.


12. AUTHORIZED AFFILIATES

​​

12.1     Contractual Relationship. The parties acknowledge and agree that, by executing the Agreement, Client enters into this DPA on behalf of itself and, as applicable, in the name and on behalf of its Authorized Affiliates, thereby establishing a separate DPA between Cinco and each such Authorized Affiliate. Each Authorized Affiliate agrees to be bound by the obligations under this DPA and, to the extent applicable, the Agreement. For the avoidance of doubt, an Authorized Affiliate is not and does not become a party to the Agreement, and is a party only to this DPA. All access to and use of the Services by Authorized Affiliates must comply with the terms and conditions of the Agreement and any violation of the terms and conditions of the Agreement by an Authorized Affiliate shall be deemed a violation by Client.

12.2     Communication. The Client that is the contracting party to the Agreement shall remain responsible for coordinating all communication with Cinco under this DPA and be entitled to make and receive any communication in relation to this DPA on behalf of its Authorized Affiliates.

12.3     Rights of Authorized Affiliates. Where an Authorized Affiliate becomes a party to this DPA with Cinco, it shall to the extent required under applicable Data Protection Laws and Regulations be entitled to exercise the rights and seek remedies under this DPA, subject to the following: Except where applicable Data Protection Laws and Regulations require the Authorized Affiliate to exercise a right or seek any remedy under this DPA against Cinco directly by itself, the parties agree that (i) solely the Client that is the contracting party to the Agreement shall exercise any such right or seek any such remedy on behalf of the Authorized Affiliate, and (ii) the Client that is the contracting party to the Agreement shall exercise any such rights under this DPA, not separately for each Authorized Affiliate individually, but in a combined manner for itself and all of its Authorized Affiliates together.


13. LIMITATION OF LIABILITY

 

13.1     Limitations. Each party’s and all of its Affiliates’ liability, taken together in the aggregate, arising out of or related to this DPA, and all DPAs between Authorized Affiliates and Cinco, whether in contract, tort or under any other theory of liability, is subject to the 'Limitation of Liability' section of the Agreement, and any reference in such section to the liability of a party means the aggregate liability of that party and all of its Affiliates under the Agreement and all DPAs together.

13.2     Aggregate and Several Liability. For the avoidance of doubt, Cinco’ and its Affiliates' total liability for all claims from Client and all of its Authorized Affiliates arising out of or related to the Agreement and all DPAs shall apply in the aggregate for all claims under both the Agreement and all DPAs established under the Agreement, including by Client and all Authorized Affiliates, and, in particular, shall not be understood to apply individually and severally to Client and/or to any Authorized Affiliate that is a contractual party to any such DPA.


14. COMPLIANCE WITH CCPA

 

  • Processor will not Process any Personal Data on behalf of Controller except consistent with the stated nature and purpose of the Processing (as set forth in the attached Appendix A), which the parties agree constitutes a Business Purpose. 
     

  • Processor will not engage in the Sale of Data unless otherwise permitted under the Agreement or the DPA without the prior express written consent of Controller, and, when required, the persons to whom such Personal Data relates. 
     

  • Processor will maintain the Technical and Organizational Security Measures in Appendix B, which the parties agree constitute Reasonable Security Procedures and Practices. 
     

  • Processor will not use any Personal Data it receives from Controller for CrossContext Behavioral Advertising. 
     

  • Processor shall provide reasonable assistance to Controller for the fulfilment of Controller’s obligation to respond to and address requests of Consumers relating to rights provided by CCPA provided that Controller cannot reasonably perform fulfil such obligation independently with information available to the Controller. Controller shall be responsible for any costs arising from Processor’s provision of such assistance. Processor shall not be required to delete any of the Personal Data to comply with a request to exercise CCPA rights directed by Controller if it is necessary to maintain such information in accordance with Cal. Civ. Code 1798.105(d), in which case Processor shall promptly inform Controller of the exceptions relied upon under Cal. Civ. Code 1798.105(d) and Processor shall not use the Personal Data retained for any other purpose than provided for by that exception.
     

List of Schedules


Schedule 1: Description of Processing/Transfer


Schedule 2: Technology and Organizational Security Controls

SCHEDULE 1 - DESCRIPTION OF PROCESSING/TRANSFER
 

SUBJECT MATTER OF PROCESSING OF CONTROLLER’S PERSONAL DATA BY PROCESSOR. 

The subject matter of the Processing of Controller Personal Data is the digital marketing software as a service (“SaaS”) and related services provided by Processor to Controller pursuant to the terms and conditions of the Agreement. 

DURATION OF PROCESSING. The duration of processing is during the term of the Agreement and for limited periods thereafter as specifically contemplated under the Agreement.

CATEGORIES OF DATA SUBJECTS WHOSE PERSONAL DATA IS TRANSFERRED


Client may submit Personal Data to the Services, the extent of which is determined and controlled by Client in its sole discretion, and which may include, but is not limited to Personal Data relating to the following categories of data subjects:

 

  • Prospects, Clients, and business partners of Client (who are natural persons)

  • Employees or contact persons of Client’s prospects, Clients, and business partners

  • Employees, agents, advisors, freelancers of Client (who are natural persons)

  • Client’s users authorized by Client to use the Services

CATEGORIES OF PERSONAL DATA TRANSFERRED


Client may submit Personal Data to the Services, the extent of which is determined and controlled by Client in its sole discretion, and which may include, but is not limited to, the following categories of Personal Data:

 

  • First and last name

  • Title

  • Position

  • Employer

  • Contact information (company, email, phone, physical business address)

  • ID data

  • Geolocation data


SENSITIVE DATA TRANSFERRED (IF APPLICABLE)


Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures:


None.


NATURE OF THE PROCESSING


The nature of the Processing is the performance of the Services pursuant to the Agreement.


PURPOSE OF PROCESSING, THE DATA TRANSFER, AND FURTHER PROCESSING


Cinco will Process Personal Data as necessary to perform the Services pursuant to the Agreement, as further specified in the Documentation, and as further instructed by Client in its use of the Services.


SUBPROCESSOR TRANSFERS


For transfers to subprocessors, also specify subject matter, nature, and duration of the processing:

As per above, the subprocessor will Process Personal Data as necessary to perform the Services pursuant to the Agreement.


Subject to sectionabove of this DPA, the Sub-processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.


Identities of the Sub-processors used for the provision of the Services and their country of location are listed in this link: wearecinco.com/sub-processors


TECHNICAL AND ORGANIZATIONAL MEASURES


Data importer will maintain administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Personal Data uploaded to the Services, as described in Schedule 2 applicable to the specific Services purchased by data exporter. Data Importer will not materially decrease the overall security of the Services during a subscription term. Data Subject Requests shall be handled in accordance with section above of the DPA.


CONTACT

 

For Data Protection related matters: please send an email to CINCO at [email protected]

_______________

 

SCHEDULE 2 - TECHNOLOGY AND ORGANIZATIONAL SECURITY CONTROLS

Cinco shall undertake appropriate technical and organizational measures for the availability and security of Client Personal Data and to protect it against unauthorized or unlawful Processing and against accidental or unlawful loss, destruction, alteration or damage, and against unauthorized disclosure or access. These measures, listed below, shall take into account the nature, scope, context, and purposes of the Processing, available technology as well as the costs of implementing the specific measures, and shall ensure a level of security appropriate to the harm that might result from a Security Incident.
 

Access Control: Access to Personal Data is limited to employees with a "need-to-know." Cinco uses unique IDs and mandates Multi-Factor Authentication (MFA) for all production systems.
 

Data Encryption and Integrity: Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Cinco uses cryptographic hashing to ensure data integrity during transfer.
 

Physical Security: Cinco utilizes Tier III data centers and relies on their physical safeguards, including 24/7 security and biometric access.
 

Organizational Security: Employees sign confidentiality agreements and receive annual security and data privacy awareness training. A formal "Security Officer" is appointed.
 

Incident Response: Cinco has an internal procedure to identify and report data breaches to the Controller without undue delay.
 

Data Minimization: Cinco only collects and processes the categories of data explicitly defined in the DPA.
 

Vulnerability Management: Cinco undergoes an annual third-party penetration test.
 

Governance and Accountability: Cinco maintains a formal register of all sub-processors. Cinco leverages the sub-processors listed herein for data processing, each of whom employs appropriate physical and information security procedures.

​​​​
______________________________

APPENDIX 2 - EEA SERVICE ADDENDUM

 

This EEA Service Addendum ("Addendum") supplements the Cinco General Terms and Conditions and its appendices ("Agreement") between Cinco and Client.

 

This Addendum sets out relevant provisions which apply to any provision, deployment, and use of an AI System provided to Client by Cinco through the

Services and Client Experience Platform or otherwise within the European Economic Area ("EEA"), and which AI System may accordingly become subject to the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) ("AI Act"), and other Applicable Laws.

To the extent of any conflict or inconsistency between this Addendum and the main Agreement, this Addendum shall prevail in respect of its subject matter.


1. Definitions

 

Defined terms used in this Addendum shall take the meaning set out in the Agreement, unless expressly set out herein.

 

For purposes of this Addendum:

 

"AI System" means the AI Technology and any associated software, models, and components provided by Cinco under the Agreement.

"Deemed Provider" means a Client who, by regulatory determination or otherwise (e.g. as a result of Client's own conduct), is considered to act as a Provider under Applicable Laws.

"Deployer" means the natural or legal person who uses an AI System within the EEA, other than the Provider (per Article 3(11) of the AI Act).

"GPAI Model" means a general-purpose AI model as defined under Article 3(63) of the AI Act, including any large language model or foundation model underpinning the AI System.

"High-Risk AI System" means an AI System identified as high-risk under Annex III of the AI Act (or any successor legislation or amendment thereto).

"Intended Purpose" means the use or purpose for which the AI System is developed and made available by Cinco, as described in the relevant Cinco documentation, as further set out in Schedule 1 to this Addendum.

"Provider" means the natural or legal person who develops an AI System or has it developed and places it on the EEA market or puts it into service under its own name or trademark (per Article 3(10) of the AI Act).

"Risk Classification" means the risk tier assigned to the AI System under the AI Act (being unacceptable risk, high-risk, limited-risk, or minimal risk) and, separately, whether the AI System incorporates or constitutes a GPAI Model, as determined by Cinco and set out in Schedule 1 to this Addendum. 

2. Roles and Responsibilities
 

2.1 Provider Role - Cinco


Cinco is the Provider of the AI System within the meaning of the AI Act and Applicable Laws.


Cinco is responsible for ensuring the AI System complies with all Provider obligations under the AI Act, including but not limited to: 
 

  • Conformity assessment and CE marking (if applicable);

  • Risk management system implementation;

  • Data governance and quality management for training, validation, and testing data;

  • Technical documentation and record-keeping;

  • Transparency and provision of instructions for use;

  • Human oversight design and enabling in a manner consistent with Section 6.3(3) of the General Terms and Conditions;

  • Post-market monitoring and reporting of serious incidents or malfunctioning;

  • Cooperation with competent authorities and provision of information on request;

  • Appointment and maintenance of an EU authorised representative, if required.

  • Compliance with GPAI Model obligations under Title III, Chapter V of the AI Act, including technical documentation, transparency disclosures, and copyright policy, to the extent the AI System incorporates or constitutes a GPAI Model.

  • Registration of the AI System in the EU database under Article 71 of the AI Act, where required by the applicable Risk Classification, including providing Client with all information necessary for Client to fulfil any associated Deployer registration obligations.

 

2.2 Client Role - Deployer
 

Client is the Deployer of the AI System within the EEA when using or making the AI System available to Client Customers.
 

Client shall: 
 

  • Use the AI System strictly within the Intended Purpose as described in Schedule 1 of this Addendum and as may be further defined in applicable Cinco documentation;

  • Implement appropriate human oversight and monitoring measures, including those specified in Cinco's instructions for use provided pursuant to Article 13 of the AI Act, and consistent with Client's obligations under Section 6.3(3) of the General Terms and Conditions;

  • Inform Cinco promptly of any serious incidents, malfunctions, or suspected non-compliance;

  • Ensure compliance with Data Protection Laws, consumer protection laws, and sector-specific regulations;

  • Refrain from using the AI System for High-Risk AI System purposes without prior written agreement and additional compliance measures.

  • Maintain logs of the AI System's operation for a minimum of six (6) months, or such longer period as required by the applicable Risk Classification, sector-specific rules, or Applicable Laws; and provide such logs to Cinco or competent authorities upon request.

  • Subject to its obligations, and the agreed restrictions under Section 3 of this Addendum, where relevant, conduct and document a fundamental rights impact assessment prior to deploying the AI System in any High-Risk use case, in accordance with Article 27 of the AI Act.

  • Promptly notify Cinco (and in any event within forty-eight (48) hours) upon receiving any inquiry, investigation notice, or enforcement action from a competent authority relating to the AI System, and cooperate with Cinco in formulating any response.

 

2.3 Client as Deemed Provider


The Parties confirm that it is their shared intention that the commercial arrangement between them, including the white-label nature of the Client Experience Platform and Client's use of its own branding in respect of Client Customers, is structured and intended to operate such that Cinco acts as Provider and Client acts as Deployer of the AI System for the purposes of the AI Act. The Parties do not intend that the white-label arrangement or Client's use of its own brand within the Client Experience Platform will, of itself, trigger Article 25 of the AI Act or cause Client to be treated as a Provider. 
 

However, the Parties acknowledge that the application of Article 25 is subject to regulatory determination and that neither Party can guarantee how a competent authority may characterise the arrangement in practice. The following provisions therefore set out the agreed allocation of responsibilities for EEA purposes in the event that, notwithstanding the Parties' intentions, Client is treated as a Deemed Provider.
 

In the event that, whether by regulatory determination or as a result of Client's own actions or omissions beyond the scope of the permitted arrangement, Client is treated as a Provider under Article 25 of the AI Act (including by placing the AI System on the market under its own name other than as expressly contemplated under Section 3.1 of this Addendum and Section 6.2 of the General Terms and Conditions, making a substantial modification, or changing the Intended Purpose), Client shall:
 

a) promptly notify Cinco;

b) cooperate with Cinco in fulfilling Provider obligations, including providing information, implementing human oversight, and assisting with post-market monitoring;

c) assume responsibility for any obligations I assumes as a Deemed Provider whether arising solely from its own actions or omission or from regulatory determination that Client is a Deemed Provider; and

d) indemnify and hold harmless Cinco to the extent liabilities, fines, or obligations arise solely from Client's own actions or omissions as Deemed Provider. For the avoidance of doubt: (i) this indemnity does not apply to the extent that Deemed Provider status arises solely from regulatory determination in respect of the white-label arrangement as permitted and structured by the Parties under this Addendum and the General Terms and Conditions, as opposed to Client's own conduct beyond that permitted arrangement; (ii) where Deemed Provider status arises from regulatory determination rather than Client's own conduct, the Parties shall cooperate in good faith to address the consequences and allocate any resulting obligations and costs fairly having regard to their respective roles; (iii) to the extent this indemnity does apply, it operates outside and in addition to any aggregate liability cap set out in Section 14 of the General Terms and Conditions; and (iv) the carve-out in (iii) applies solely in respect of AI Act regulatory fines and obligations arising from EEA deployments and does not otherwise modify the liability regime under the General Terms and Conditions.
 

To the extent that Client assumes Provider obligations as a Deemed Provider under Article 25 of the AI Act, Cinco's corresponding obligations under the AI Act shall be modified accordingly and by operation of law. In all other respects, and to the extent Cinco retains Provider status under the AI Act, nothing in this Section 2.3 shall be construed as limiting or reducing Cinco's obligations as Provider under the AI Act and Applicable Laws.

2.4 Joint Responsibilities

 

Both Parties shall cooperate in good faith to fulfil their respective compliance obligations, including sharing information and documentation as needed.
 

Each Party shall grant the other reasonable audit rights, on not less than ten (10) business days' written notice, to inspect records and systems relevant to compliance with this Addendum and Applicable Laws. Notwithstanding the foregoing, in the event of a suspected serious incident, a regulatory investigation, or any imminent enforcement action relating to the AI System, Cinco may exercise audit rights on not less than forty-eight (48) hours' written notice.
 

3. Intended Purpose and Restrictions


3.1 White-Label Model

 

Client is permitted to brand the Client Experience Platform with its own brands and trademarks as part of the agreed white-labelling model under the General Terms and Conditions, and in particular in accordance with Sections 6.2 and 4.6 thereof. However:
 

a) such branding permission does not extend to Client representing or marketing the AI System as an AI system developed or owned by Client, or presenting AI outputs as originating from a separate AI product developed by Client; and
 

b) as a condition of this permission, Client shall ensure that Cinco is identified as the entity powering the AI System in all customer-facing terms and at the point of AI interaction, in accordance with Section 4 of this Addendum and Section 4.6 of the General Terms and Conditions, it being acknowledged that such attribution is a key element of the structure the Parties have adopted to maintain the intended Provider/Deployer allocation of roles under the AI Act.
 

The Parties' shared intention regarding the effect of this white-label arrangement on the allocation of Provider and Deployer roles under the AI Act, and the consequences if a competent authority determines otherwise, are addressed in Section 2.3 of this Addendum.

3.2 Intended Purpose and Classification

 

Cinco provides a description of the Intended Purpose of the AI System in documentation supplied to Client, as further particularised in Schedule 1.
 

The AI System is currently classified as limited-risk under and in respect of the AI Act. Cinco shall notify Client in writing if the risk classification changes, including if such a change would impose additional obligations on Client as Deployer or would require Client to conduct a fundamental rights impact assessment under Article 27 of the AI Act.
 

Client shall not materially modify or repurpose the AI System beyond the Intended Purpose without prior written consent from Cinco.
 

Client shall not represent the AI System as an AI system developed or owned by Client, or market AI outputs as originating from a separate AI product

developed by Client, without explicit written authorization.
 

Client shall not engage in activities that would cause the AI System to be classified as a High-Risk AI System under the AI Act or other Applicable Laws without explicit written agreement and adherence to additional regulatory requirements.

3.3  Prohibited Uses

 

Client shall not use the AI System, and shall ensure that Client Customers do not use the AI System, for any purpose that is prohibited under Article 5 of the AI Act or any other purpose that becomes prohibited under the AI Act or Applicable Laws from time to time.
 

Any breach of this Section 3.3 shall constitute a material breach of the Agreement, entitling Cinco to terminate immediately on written notice.
 

4. Transparency and User Information

 

Client shall ensure that Client Customers are informed, in clear and accessible terms, that they are interacting with an AI System, including any required disclosures under the AI Act.
 

Without limiting the foregoing, Client shall: (i) display a clear and prominent notice to Client Customers that they are engaging with an AI system; (ii) not suppress, obscure, or delay such notice; and (iii) ensure the notice complies with Article 50 of the AI Act and any guidance issued by competent authorities thereunder.
 

Client shall further ensure that: (1) all customer-facing terms and conditions identify Cinco as the provider of the AI System; and (2) Client maintains mechanisms for human oversight as necessary to comply with transparency and accountability obligations. 
 

Cinco shall provide Client with template disclosure language and instructions for use sufficient to enable Client to comply with its transparency obligations under this Section 4. Such template disclosure language shall expressly identify Cinco as the provider of the AI System and shall be approved by Client prior to use (such approval not to be unreasonably withheld or delayed).

5. Data Governance and Privacy

 

Each Party remains responsible for compliance with applicable Data Protection Laws (including GDPR) for data processed in connection with the Services.
 

For the purposes of GDPR and applicable data protection laws: (i) each Party acts as an independent data controller in respect of personal data it determines to process for its own purposes; (ii) to the extent Cinco processes Client Customer personal data on behalf of Client in connection with the Services, Cinco does so as a data processor, and the terms of the Data Processing Addendum (the "DPA") executed between the Parties (or, if not yet executed, to be executed within thirty (30) days of this Addendum) shall govern such processing.
 

Where personal data is transferred outside the EEA in connection with the Services, the Parties shall ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR (including, where applicable, Standard Contractual Clauses).
 

Client shall ensure it has all necessary consents and lawful bases for processing Client Data and Client Customer Data.

 

Cinco shall process data in accordance with the Agreement and any applicable Data Processing Addendum.

6. Post-Market Monitoring and Reporting

 

Client shall promptly notify Cinco of any serious incidents, malfunctions, or potential risks identified during the deployment or use of the AI System in the EEA.


"Promptly" for purposes of this Section 6 means within twenty four (24) hours of Client becoming aware of a serious incident or malfunction, and within seventy two (72) hours of becoming aware of a potential risk.
 

Cinco shall maintain and execute a post-market monitoring system, including incident reporting to competent authorities as required by Applicable Laws.
 

Cinco shall notify Client of any reports made to competent authorities in connection with the AI System within five (5) business days of making such a report, to the extent permitted by Applicable Laws.

7. Governing Law and Jurisdiction

This Addendum shall be governed by and construed in accordance with the laws governing the main Agreement.
 

Notwithstanding the governing law of the main Agreement, the mandatory provisions of the AI Act and other applicable EU and EEA laws shall apply to this Addendum to the extent required by law.
 

The Parties submit to the exclusive jurisdiction of the courts as set forth in the Agreement.
 

8. General

 

This Addendum supplements but does not replace any other provisions of the Agreement unless explicitly stated.
 

Terms of this Addendum apply exclusively to the extent any CINCO AI System is marketed, deployed, or used within the EEA in respect of the Client.
 

This Addendum is incorporated by reference into the Agreement.

 

_______________

 

 

SCHEDULE 1 — RISK CLASSIFICATION AND INTENDED PURPOSE


AI ACT DISCLOSURE & CLASSIFICATION STATEMENT
 

(EU Regulation 2024/1689 – Artificial Intelligence Act)
 

This Schedule forms part of the Agreement between Cinco (“Provider”) and Client (“Deployer”).
 

1. AI System Identification


System Name: AI Experience Room

Provider: Cinco

Nature of System: Brand-owned adaptive marketing and sponsorship asset delivered as a configured AI-enabled experience.
 

2. Risk Tier Classification


Based on its Intended Purpose and current configuration, the AI Experience Room is classified as a:


Limited Risk AI System under Regulation (EU) 2024/1689 (AI Act).

 

The limited-risk classification has been determined by Cinco on the basis of an assessment conducted in accordance with Article 6 of the AI Act, having regard to the Intended Purpose of the AI Experience Room as set out in clause 4 of this Schedule. 
 

The AI Experience Room is a commercial, informational, and experiential AI system deployed for brand engagement and marketing purposes. It does not fall within any category of high-risk AI system under Annex III of the AI Act as currently in force, does not engage in any practice prohibited under Article 5, and does not perform biometric identification or automated decision-making producing legal or similarly significant effects. 
 

Appropriate transparency measures to support compliance with Article 50 of the AI Act are incorporated into the system. This classification is subject to ongoing review by Cinco in accordance with clause 7 of this Schedule.
 

3. GPAI Model Status
 

The AI Experience Room may incorporate or rely on third-party General-Purpose AI (GPAI) models, including large language models and speech models, as underlying components.


However:

 

  • The AI Experience Room is not itself a GPAI model.

  • Cinco does not develop or place GPAI foundation models on the market.

  • The AI Experience Room is a configured, domain-specific application layer built on top of such models.


Cinco has contractual arrangements in place with the providers of any GPAI models incorporated into the AI Experience Room. Nothing in this Schedule constitutes a representation by Cinco as to the sufficiency or enforceability of those arrangements.
 

4. Intended Purpose


The Intended Purpose of the AI Experience Room is to:

 

  • Deliver interactive, adaptive brand experiences;

  • Enable guided conversational exploration of brand, product, or sponsorship content;

  • Capture real-time engagement, intent, friction, and readiness signals;

  • Support conversion pathways (e.g., ecommerce redirection, CRM triggers, contact forms);

  • Generate decision-grade marketing and sponsorship performance insight.

The AI Experience Room is commercial, informational, and experiential in nature.


It is not intended to:

 

  • Make automated decisions with legal or similarly significant effects;

  • Evaluate creditworthiness;

  • Conduct employment screening or performance evaluation;

  • Perform medical or health diagnosis;

  • Conduct biometric identification or surveillance;

  • Be deployed in law enforcement or other regulated high-risk domains.

 

The limited-risk classification set out in clause 2 of this Schedule has been assessed by reference to the core commercial and marketing use cases described above. Any material change to this Intended Purpose will require formal reassessment by Cinco prior to deployment. Client shall not deploy the AI Experience Room in any regulated sector, including without limitation financial services, healthcare, employment screening, or law enforcement contexts, without prior written agreement with Cinco and a formal reassessment of the applicable risk classification. The limited-risk classification in clause 2 does not extend to deployments in regulated sectors that have not been separately assessed and approved in writing by Cinco.
 

5. Deployer Role & Permitted Customisations


The Client acts as Deployer within the meaning of the AI Act.

The following customisations are those which the Parties intend to fall within the scope of the Client’s Deployer role and are not intended to trigger “Deemed Provider” status under Article 25 of the AI Act, consistent with Section 2.3 of this Addendum. Whether Article 25 is triggered in any particular case remains subject to regulatory determination and cannot be guaranteed by either Party. Customisations within this intended scope include:
 

  • Configure brand narrative, tone, and conversational content;

  • Upload and structure proprietary brand or product knowledge;

  • Select scenes, 3D elements, and content modules;

  • Define calls-to-action and conversion pathways;

  • Configure language and market deployment;

  • Connect CRM, ecommerce, or analytics integrations via defined interfaces;

  • Select Asset Package scope and Capacity Envelopes.

 

The Client may not, without prior written agreement and formal reassessment:

 

  • Modify the underlying AI model architecture;

  • Retrain or fine-tune foundation models independently;

  • Remove or bypass governance, safety, or transparency controls;

  • Alter the system in a way that changes its Intended Purpose;

  • Repurpose the system for a High-Risk AI use case.

 

If such modifications occur, the Client may assume “Deemed Provider” obligations under Article 25 of the AI Act.
 

6. Sector-Specific Regulatory Considerations


The AI Experience Room is sector-agnostic and may be deployed across industries including:

 

  • Automotive & Transport

  • Luxury Brands

  • Consumer Brands

  • Travel & Hospitality

  • Sports & Rights Holders

  • B2B & Industrial

 

Depending on the sector and context in which Client deploys the AI Experience Room, sector-specific regulatory obligations may apply. Identification of and compliance with all such obligations is solely the responsibility of Client as Deployer and Data Controller. Cinco makes no representation or provides any advice or guidance to Client as to the regulatory requirements applicable to any particular Client deployment, or Client’s obligations under the Ai Act or otherwise.

7. Ongoing Compliance & Change Management

  • Cinco shall use reasonable efforts to monitor regulatory developments related to the AI Act, and shall promptly notify Client in writing, and update this Schedule accordingly if:The AI Experience Room’s  limited-risk AI System classification changes;

  • The Intended Purpose materially evolves; or

  • New or newly applicable AI Act obligations relevant to the AI Experience Room become applicable,

 

Client shall promptly notify Cinco in writing if it becomes aware of any changes to its deployment context, Client Customer base, business activities, or intended use that may affect the AI System’s risk classification or give rise to new regulatory obligations, including any intended deployment in a regulated sector not previously disclosed to Cinco. Client remains fully responsible for complying with all deployer obligations under the EU AI Act and must keep itself informed of any new or updated deployer obligations applicable to its deployment of the AI System.


The notification obligations under this clause are ongoing and reflect the parties’ respective roles:- Cinco monitors regulatory developments, while Client monitors deployment and business changes. Client’s continued reliance on the risk classification set forth in clause 2 of this Schedule is conditional upon Client having promptly notified Cinco of any changes in deployment context, customer base, business activities, or intended use that may affect such classification.


Failure by Client to fulfill its notification obligations under this clause shall entitle Cinco to suspend or limit its services related to the AI System, and Client shall indemnify Cinco against any resulting regulatory penalties, liabilities, or damages. Furthermore, Cinco may seek to renegotiate this Schedule or, in cases of material breach, terminate the Agreement with appropriate notice.

bottom of page