Supplier's Terms and Conditions
The Supplier (HarfangLab SAS – Trade and Companies Register (RCS) No. 839 045 697) has developed software for the detection, investigation and remediation of cyberattacks (the “Software”). The solution consists of software agents (the “Agents”) deployed on the endpoints (servers and/or workstations) of the client’s IT system. The Agents communicate with a central manager (the “Manager”) which issues commands and stores the data transmitted by the Agents. The Manager enables the operation of the detection, investigation, and remediation modules. Algorithms and detection engines and rules, integrated into the Software and updated by the Supplier, identify suspicious behaviors and artefacts and generate alerts where applicable. The Software also includes remediation features to neutralise the threat and prevent its spread. The Manager can interface with other software via connectors (APIs). In view of the foregoing, the parties agree as follows:
1. Definition
Terms beginning with a capital letter have either the definition given to them in the text or the following meaning:
- Administrator(s): means the Client’s employee(s) who act as the Supplier‘s point(s) of contact for Maintenance or Support activities.
- Anomaly: means any reproducible failure, crash, malfunction or incident whose correction is necessary because it prevents or restricts normal use of the Software, according to the following levels:
- An Anomaly is classified as “Blocking” when the Manager is unavailable, an Agent fails to start, or an Agent causes a critical operating system error on the endpoint.
- An Anomaly is classified as “Non‑Blocking” when it causes a disruption in the use of the Software without preventing security monitoring.
- Client: means the legal entity for whose benefit the Software is used and within which the Agents are installed.
- Deployment Mode: means the environment on which the Manager is installed and the manner in which the Software is deployed, namely (i) either from the Supplier’s cloud or (ii) on‑premises, whether within the infrastructure of the Partner, the Client or the Client’s third‑party service provider.
- Documentation: means the installation, user and administration manuals, in any medium, describing the operation and/or implementation of the Software, provided or made available by the Supplier and subject to updates by the Supplier.
- Endpoints: means the Client’s servers and/or workstations on which the Agents are installed.
- Fee: means the amount payable for the Licence to Use the Software, Maintenance and Support for a period of twelve (12) months.
- IPR (Intellectual Property Rights): means, without limitation, any intellectual property right or right of any kind and all components thereof, as well as any subject matter of such rights, including in particular any patent, invention, trademark, trade name, topography, designs, models, database, copyright, sui generis right, and know‑how, whether such rights are registered or not, together with any applications or filings therefor.
- Maintenance: means the provision by the Supplier of corrections of Anomalies and updates to the Software, under the terms set out herein.
- Open Source: means software developments included in the Software’s libraries that are made available to the Client under an “Open Source” licence.
- Operator: means the legal entity responsible for operating the Software, namely (i) the Partner, if the Partner provides a CSIRT or SOC service in addition to distributing the Software; or (ii) the Client, where the Client operates the Software directly; or (iii) the Client’s security service provider.
- Partner: means the legal entity that has entered into a partnership agreement with the Supplier for the distribution of the Software.
- Prerequisites: means the minimum hardware, software and connectivity configuration of the Client’s information system, and the information to be provided to the Supplier, necessary for the installation, configuration and proper functioning of the Software.
- Production Incident: means a situation in which the Software is no longer accessible under normal conditions due to (i) a configuration error of the Software and/or its dependencies; (ii) non‑compliance with the Prerequisites; (iii) a lack of monitoring and management of the resources used by the Software; or (iv) a hardware failure, a network device failure or a server failure.
- Software: means the Agents and the Manager in object code form, together with all patches, fixes, evolutions, updates or versions supplied by the Supplier.
- Support: means the Supplier’s technical support service, intended to respond to problems encountered by Users in using the Software, to assist them and to provide a knowledge base, under the terms set out herein.
- User: means the employee(s) of the Operator who uses all or part of the Software in the course of their security monitoring and/or incident response activities.
2. Purpose of the General Terms and Conditions
These Supplier’s General Terms and Conditions (“GTC”) are intended, in particular, to set out the terms applicable to (i) the types of licences (each a “Licence”) that may be granted by the Supplier for the Software; and (ii) the provision of Support and Maintenance and, where applicable, hosting on the Supplier’s cloud.
3. Rights granted by License type
Depending on the type of Licence provided and/or selected by the Client and agreed with the Supplier, the latter grants the Client the following rights, subject to the limitations set out in this Article:
Licence to Use
The Supplier grants the Client a non‑exclusive, personal and non‑transferable right to use the Software for internal purposes and for the scope and duration agreed in the relevant agreement. The Operator is authorised to access and use the Software on the Client’s behalf when it provides the Client with a security monitoring (SOC) service, under the above terms and conditions. The Manager may be installed, according to the Deployment Mode, (i) in the Supplier’s cloud or (ii) on‑premises.
CSIRT Licence
The Supplier grants the Client a non‑exclusive, personal and non‑transferable right to use the Software for the sole purpose of resolving security incidents affecting the Client, and for no other purpose, for the contract scope and for a period of three (3) months. The Operator is authorised to access and use the Software on a non‑exclusive, personal and non‑transferable basis, for internal use and for a period of three (3) months from the date it is made available. If the incident‑response engagement has not been completed by the end of the initial three (3) month period, the usage rights are extended for an additional one (1) month.
Evaluation Licence
Prior to entering into a licence agreement for use of the Software, and solely to enable the Client to assess the suitability of the Software for its needs (“Evaluation”), the Supplier grants the Client a non‑exclusive, personal and non‑transferable right to use the Software for Evaluation purposes, for internal use, for up to 200 Endpoints and for a period of two (2) months from the date it is made available, in the country where the Client is domiciled (i.e., the place where the Agents are installed).
Depending on the type of Licence provided and/or selected by the Partner and agreed with the Supplier, the latter grants the Partner the following rights, subject to the limitations set out in this Article:
Evaluation Licence
Prior to entering into a partnership agreement, and solely to enable the Partner to assess the suitability of the Software for the needs of its customers and/or prospects (“Evaluation”), the Supplier grants the Partner a non‑exclusive, personal and non‑transferable right to use the Software for Evaluation purposes, for up to 200 Endpoints and for a period of two (2) months from the date it is made available, in the country where the Partner is domiciled (i.e., the place where the Agents are installed).
Demonstration Licence
In connection with the distribution of the Software, the Partner may present Software usage scenarios to prospects (“Demonstration”). The Supplier grants the Partner a non‑exclusive, personal and non‑transferable licence solely to carry out demonstrations for the benefit of its customers and prospects, for up to 200 Endpoints and for the term of the agreement.
Under the Evaluation Licence and the Demonstration Licence, and to the extent permitted by applicable law, the Software, the Documentation and the services are provided “as is” without any warranties, including those set out herein.
Restrictions
Whatever the type of licence granted, the Client, the Partner and, as the case may be, the Operator acknowledge that the Supplier grants no ownership rights in the Software, the IPR or the Open Source, but only the right to use them in accordance with the Licence granted to them. The right to use any Open Source arises from the open‑source licence applicable to the relevant software. Information relating to the Open Source may be provided upon the Client’s or Partner’s written request.
Accordingly, the Client, the Partner and, as the case may be, the Operator undertake not to infringe the related IPR and shall refrain, without limitation, unless they have obtained the Supplier’s express authorisation, from the following:
- Decompiling, disassembling or reverse‑engineering the Software except for interoperability purposes and under the conditions set out in Article L.122‑6‑1 of the French Intellectual Property Code, only after having first requested in writing from the Supplier the necessary information and only if the Supplier has refused to provide it;
- Attempting to discover the source‑code structure or any other operational mechanism of the Software;
- Reproducing the Software other than to make a single identical copy for back‑up and security purposes in accordance with the provisions of the French Intellectual Property Code;
- Modifying, correcting, translating, arranging or adapting all or part of the Software, creating derivative works from the Software, or extracting and re-using a qualitatively or quantitatively substantial part of the Software;
- Marketing, sublicensing, distributing, transferring, assigning rights in, renting, pledging, broadcasting or making the Software available by any means whatsoever, or copying all or part of the Software onto any public or private network whatsoever, other than under the conditions set out in this Agreement;
- Removing or deleting any notice relating to the Supplier’s IPR on the Software or on any packaging or physical medium of the Software or the Documentation, or on any element comprising the Software;
- Using the Software for any purpose other than those expressly authorised, or on any system or at any operating location other than those agreed;
- Reproducing the Documentation in more copies than authorised, which by default is one (1) copy.
Under an Evaluation Licence, the Client, the Partner and the Operator, and under a Demonstration Licence, the Partner, shall not: (i) use the Software in a production environment or for production purposes, unless expressly authorised in advance by the Supplier; or (ii) charge, directly or through a third party, for any third‑party access to or use of the Software, or use the Software, directly or indirectly, to generate revenue or otherwise commercially exploit the Software in any way.
Expiry of Granted Rights
At the end of the duration of the rights granted as set out in the agreement (the “Commitment Term”), the Client may renew its Licence to Use. If the Evaluation or the incident‑response engagement results in an order for a Licence to Use, the rights are extended for a period of one (1) additional month to avoid any service interruption. In the absence of an order or renewal, the Client undertakes to cease all access to, and to cease all use of, the Software, and to uninstall the Agents or have the Operator uninstall them.
If the Software is hosted in the Supplier’s cloud, the Supplier will deactivate the access rights enjoyed by the Operator within ten (10) business days from the end of the Licence. The Software will then become inaccessible to Users, and, after a period of one (1) month from the end of the Licence, the Supplier will permanently delete the stored data. For other Deployment Modes, uninstallation of the Manager is carried out by the Client or the Operator within fifteen (15) days from the Licence end date. The Client or the Partner undertakes to delete, or have deleted, any copy of the Software integrated into any other program or stored on any storage medium, and all information, including the Supplier’s Confidential Information, as defined in Article 7.
4. Provision of the Software
General terms of provision: The Software is made available to the Operator by the Supplier according to the Deployment Mode agreed between the Parties:
- If the Software is installed on the Supplier’s cloud, the Supplier is responsible for installing the Manager in accordance with the information provided in the order or the agreement, including, without limitation, the number of Agents and the retention period for stored data. The Operator, or the Partner where applicable, must inform the Supplier in writing prior to the order if any special conditions are likely to impact the sizing of the Supplier’s cloud. The Software is made available to the Client and the Operator by providing access credentials to the Manager.
- In the other Deployment Modes, the Software and the associated Documentation will be made available in digital form via a download link. The Software and the Documentation are deemed delivered on the date they are made available.
The Software and Documentation are deemed delivered on the date they are made available.
Specific terms for CSIRT, Demonstration and Evaluation Licences
The Manager is installed in the Supplier’s cloud. For an Evaluation, the Supplier sizes the Supplier’s cloud for 200 Endpoints with no data retention.
- Installation Procedure
Upon delivery of the Software, the Operator is solely responsible for deploying the Software on its information system, namely:
- the Agents when the Software is deployed in the Supplier’s cloud; and
- the Manager and the Agents in all other cases.
The infrastructure on which the Software is deployed must at all times comply with the Prerequisites. The Prerequisites are available on the Supplier’s support portal and may be updated by the Supplier at any time, to reflect changes to the Software.
6. Hosting of the Manager in the Supplier’s Cloud
Where the Software is deployed in the Supplier’s cloud, the Supplier provides a hosting service for the Manager accessible via the Internet (the “Supplier’s Cloud”). The Client acknowledges that hosting of the Software and the data generated by its use is entrusted to a subcontractor of the Supplier (the “Cloud Provider”). Consequently, hosting is provided under the following conditions.
Availability of the Software
The Software is accessible 24 hours a day, 7 days a week, except during the periods of unavailability defined below. The Supplier’s availability commitments are subject to compliance with the conditions set out in the agreement. The Client is aware of the technical hazards inherent on the Internet and the access interruptions that may result. The Supplier cannot be held liable for any resulting total or partial unavailability of, or malfunctions in, the Software. In cooperation with the Cloud Provider, the Supplier takes the necessary measures to enable access to and use of the Software under the best possible technical conditions.
The Software availability rate is 99.5%. This percentage indicator measures the annual availability of the Software in the Supplier’s Cloud. It is calculated using the following formula: total number of minutes in the year minus the number of minutes of unavailability in the year, divided by the total number of minutes in the year.
The duration of unavailability excluded from calculation of the availability rate corresponds to the sum of unavailabilities related in particular to the following cases:
- planned interruptions by mutual agreement with the Operator (in particular, database reorganisation, maintenance windows, cold backups, etc.);
- interruptions at the Operator’s request or made necessary to safeguard the Operator’s information system or the hosting environment;
- application failures caused by the Operator or a third party;
- malfunction of the Client’s hardware or local network, total or partial interruption of the Internet or of the private WAN used by the Client to access the Software;
- time required, where applicable, to carry out the physical transfer of stored data;
- interruptions related to services provided by a third party other than the Cloud Provider;
- maintenance operations on the hosting infrastructure or on the Software;
- malfunction resulting from failure to implement a recommendation issued by the Cloud Provider or the Supplier to maintain service quality, or occurring during a Maintenance operation;
- any period during which the Operator does not provide the necessary information or access, or fails to cooperate in resolving a Production Incident;
- any interruptions related to malfunctions on the Operator’s side or its failure to comply with its obligations;
- force majeure events, notably within the meaning of Article 1218 of the French Civil Code and as defined by French case law.
The Operator is responsible for the means of accessing the Software as well as for administering rights and Users (including defining credentials). The Client is responsible for protecting access to the Manager.
Security and Backup
The security measures implemented by the Cloud Provider are available at the following address: PS–I – OVH. Backups of stored data are performed in accordance with the Supplier’s business continuity and disaster recovery plan.
Reversibility
Under a Licence to Use, upon the Client’s express request, the Supplier will return to the Client any data for which the Client itself does not hold a copy at the end of the agreement. The request for return must be made to the Supplier no later than fifteen (15) days before the last day of the Licence term. Database data will be provided via a download link in a binary format as supported by the Elastic/OpenSearch backup mechanism; configuration items will be provided in YAML format. Any other assistance in connection with reversibility or the portability of such data will be invoiced separately to the Client on the basis of the Supplier’s then current price list.
7. Warranties
Conformity Warranty: The Supplier warrants that, for a period of thirty (30) days from the date the Software is made available (the “Warranty Period”), and subject to use in accordance with the provisions of the agreement, the Software will operate in conformity with the Documentation. If the Supplier receives a written claim during the Warranty Period describing the non-conformities observed, the Supplier will use best efforts, at its discretion, to remedy the non-conformity either by means of a fix or a workaround. If the Supplier is unable to correct the non‑conformity within thirty (30) days of receipt of the claim, the parties may terminate the agreement, in which case the Client may request from the Partner or the Supplier, as applicable depending on who sold the Licence, a pro rata refund of the Fee paid. This Conformity Warranty will not apply if the non‑conformity is not reproducible or results (i) from use of the Software that does not comply with the provisions of the agreement; (ii) from a malfunction of the Operator’s or the Client’s information system; or (iii) from the Software becoming inoperative for reasons beyond the Supplier’s control.
IP Non‑Infringement Warranty
The Supplier warrants that the Software does not infringe any copyright or other intellectual property rights of a third party. Accordingly, the Supplier undertakes to bear all damages that may be awarded against the Partner and/or the Client by a final court decision for breach of this warranty.
This warranty applies only provided that the Partner or the Client: (i) notifies the Supplier in writing of any claim, demand or legal action brought by a third party without delay upon receiving such notice; (ii) allows the Supplier to assume control of the defense and of any negotiations for settlement, it being understood that the Partner or the Client may also have counsel of its choice to defend its interests; (iii) does not enforce any judgment or agree to any settlement without the Supplier’s written consent; and (iv) provides the Supplier with all information and assistance necessary to defend its interests.
Where this non‑infringement warranty is invoked, the Supplier may, at its option: (i) obtain for the Partner or the Client the right to continue using the disputed elements; (ii) modify any disputed elements so that the Software ceases to infringe the third party’s intellectual property rights while remaining compliant with the agreement; (iii) provide an alternative solution of equivalent scope; or (iv) terminate the agreement and refund to the Partner or the Client, as the case may be, the Fee paid, less the amount corresponding to the period during which the Software was used.
The Supplier will have no liability under this warranty if the third‑party claim results from: (i) use of all or part of the Software in combination with any software, hardware, products or other equipment or materials not supplied or approved by the Supplier; (ii) use of the Software that is not in accordance with the Supplier’s Documentation; or (iii) any modification, maintenance intervention or alteration of the Software not performed or authorised by the Supplier.
The provisions of this Article set out the Supplier’s sole and exclusive obligations and liabilities in the event of infringement of a third party’s IPR. The parties agree that, as necessary, this Article will survive termination or expiry of the agreement.
Information Warranty: The Software generates alerts indicating potential security risks to the information system. It is not a solution that guarantees the security of an information system, the resolution or identification of every security incident, or that satisfies any particular needs of the Client. The Client remains at all times responsible for implementing all other measures necessary to ensure the cybersecurity of its infrastructure, in particular backing up its data and training its employees in this regard. The Supplier shall in no event be liable if the Software is used in the context of incident response at the Client, and the Client or the Operator ultimately fails to bring the incident to an end.
Operator Warranties: In connection with use of the Software, the Operator represents and warrants, throughout the period of use of the Software:
- That it complies and will comply with all laws applicable to its use of the Software, including its obligations towards its personnel in relation to the processing of their Personal Data (as defined below);
- That it will comply with the Prerequisites and the Documentation and will refrain from using any off-the-shelf software, other software or operating systems not identified as compatible with the Software;
- That any materials provided or collected via the Software do not infringe any copyright, trademark or other intellectual property right or other right of a third party;
- That it acknowledges the Software is not intended to be used to monitor staff activity, in particular during employee evaluations. The Supplier shall bear no liability for any decision taken by the Client on the basis of information reported by the Software. Any disputes between the Client and its employees or third parties arising from decisions taken on the basis of information reported by the Software shall be resolved directly between the Client, the persons concerned and, where applicable, the Partner, and the Supplier shall not be involved in resolving such disputes;
- As regards the Client, that it will inform Users that it uses the Software and that the information reported via the Agents installed on Endpoints may give access, solely for the purposes of managing the security of the information system, to all information and documents contained on the Endpoints, including information, data, files or directories identified as personal by the Users or containing Personal Data.
8. Termination
The Licence to Use may be terminated automatically by either Party in the event of a breach by the other Party of its obligations that is not remedied, where capable of remedy, within thirty (30) days following formal notice to remedy, it being specified that such notice must refer to this provision.
For the purposes of this Article, the Client’s obligations are as follows: (i) compliance with the conditions of access to and use of the Software; (ii) compliance with the Supplier’s intellectual property rights and the terms of the granted licence; (iii) compliance with the warranties and the Prerequisites; (iv) compliance with confidentiality undertakings; and (v) payment of amounts owed to the Supplier.
For the purposes of this Article, the Supplier’s obligations are as follows: (i) meeting the Software’s annual availability rate; (ii) compliance with confidentiality undertakings; (iii) compliance with the Conformity and IP Non‑Infringement (Quiet Enjoyment) Warranty; and (iv) compliance with its obligations regarding the protection of personal data.
Where the breach is not capable of remedy, the thirty (30)‑day period shall operate as a notice period prior to termination.
9. Confidentiality
Each Party undertakes to keep confidential all of the other Party’s confidential information as defined below (“Confidential Information”) to which it has access or of which it may become aware in the course of negotiating and performing the agreement, throughout the term of the agreement and for five (5) years after its termination for any reason whatsoever (except with respect to Personal Data, which may be retained for a longer or shorter period).
The Parties agree that the following shall be deemed Confidential Information:
- all information, analyses, studies and other documents, in whatever form, relating to the content of the discussions between the Parties or to the agreement;
- methodologies, products, tools and IT developments, hardware, industrial models, know-how and ethical, financial, economic, technical, commercial or other data, including in particular all information relating to business, accounts, management, commercial operations and administrative, financial and marketing activities;
- other information identified in writing as confidential by either Party; and
- the Software and the Documentation.
The Parties undertake to treat the other Party’s Confidential Information in the same manner as their own confidential information and not to disclose Confidential Information to any third party in any way. Notwithstanding the foregoing, to the extent strictly necessary, the Parties are authorised to disclose such Confidential Information as is essential to their respective agents, advisers and/or subcontractors (“Authorised Third Parties”). In any event, the Parties agree that the use and/or disclosure of Confidential Information to an Authorised Third Party is conditional upon such party entering into a confidentiality undertaking reflecting this provision. The Parties warrant, within the meaning of Article 1204 of the French Civil Code, compliance with this confidentiality obligation by their Authorised Third Parties.
The obligations set out in this Article do not apply to Confidential Information:
- that was known to a Party before the date the agreement was signed;
- that was in the public domain on the date of its disclosure;
- that has been or may be disclosed to a Party by a third person without breach of any confidentiality obligation;
- that becomes publicly available by publication or any other means of communication, except where this results from a breach of this confidentiality obligation;
- the disclosure of which is required by law or by an administrative or judicial decision; or
- that must be brought to the Client’s attention for the purposes of making the Software available or for its use for the Client’s benefit.
All tangible media containing Confidential Information are and shall remain the property of the Party that discloses them. No reproduction or use is authorised without the prior written consent of the relevant Party.
Notwithstanding this Article, the Client, the Operator and, where applicable, the Partner are hereby informed that the Supplier may disclose any information in its possession that is lawfully requested by, or upon the authorisation of, a judicial or administrative authority, without any liability attaching to the Supplier as a result.
For the purposes of implementing an Evaluation Licence, the Client will be required to enter into with the Supplier a confidentiality agreement separate from these Supplier’s General Terms and Conditions. In that event, and in the event of any inconsistency between the provisions of such confidentiality agreement and this confidentiality clause, the Parties agree that the provisions of the confidentiality agreement shall prevail.
10. Personal Data
Each Party mutually undertakes to comply with the applicable personal data regulations as derived from Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons (the “GDPR”), the French Data Protection Act No. 78‑17 of 6 January 1978 as amended, and any relevant CNIL recommendations relating to their activities (the “Data Protection Regulations”). For the purposes of this Article, the terms “Personal Data”, “Processing”, “Data Subject”, “Controller” and “Processor” have the meanings given to them in the Data Protection Regulations.
Roles of the Parties
The Parties’ roles with respect to the Processing carried out under the agreement are as follows:
- In connection with use of the Software, the Client shall always act as Controller, and the Operator, if different from the Client, shall always act as Processor on behalf of and on the documented instructions of the Client.
- Where the Software is deployed in the Supplier’s Cloud, the Supplier is responsible for hosting the Software and, in this respect, acts as the Client’s Processor.
- For the Processing relating to the provision of Support and Maintenance services (“Maintenance Processing”) and the Processing relating to improving the Software’s features (“Detection‑Improvement Processing”), the Supplier acts as Controller.
Supplier’s undertakings as Processor
In accordance with the Data Protection Regulations, when acting as the Client’s Processor, the Supplier undertakes to:
- process Personal Data only on the Client’s written instructions and inform the Client if an instruction infringes the Data Protection Regulations, including with respect to any transfers of Personal Data to a third country, unless required to do so by Union or Member State law to which the Supplier is subject; in that case, the Supplier will inform the Client of that legal requirement before Processing, unless the relevant law prohibits such information on important grounds of public interest;
- ensure that persons authorised to process Personal Data at the Supplier are subject to appropriate confidentiality undertakings or statutory confidentiality obligations;
- implement the measures necessary to ensure the security and integrity of Personal Data and its Processing as described in the Supplier’s security assurance plan;
- provide reasonable assistance to the Client, through appropriate technical and organisational measures, insofar as possible, to enable the Client to respond to Data Subject requests to exercise their rights (access, erasure, etc.) by forwarding the request to the Client without responding to it, unless expressly instructed otherwise; and provide the same assistance in relation to the Client’s conduct of prior consultations or data protection impact assessments with respect to the Processing and strictly within that scope;
- provide reasonable assistance to the Client to ensure compliance with its security obligations, considering the nature of the Processing and the information available to the Supplier in accordance with these terms;
- delete all retained Personal Data unless Union or Member State law requires the retention of Personal Data;
- make available to the Client within a reasonable time all information necessary to demonstrate compliance with this Article and allow one audit per year, including inspections by the Client, and contribute to such audits, it being understood that any audit or penetration test shall be subject to prior written agreement on its modalities and scope;
- inform the Client without undue delay and, where possible, within 48 hours after becoming aware of a Personal Data Breach resulting from a confirmed security incident at the Supplier or the host of the Personal Data;
- cooperate reasonably with the CNIL (French administrative regulatory body – responsible for protecting personal data and ensuring privacy rights) where necessary, and cooperate with the Client in the event of a CNIL request regarding the Processing, which includes: (i) if the request is addressed to the Supplier, informing the Client as soon as possible unless such information is prohibited by applicable law; and (ii) if the request is addressed by the CNIL to the Client, providing reasonable assistance to enable the Client to respond to the CNIL; and
- cease all Processing of Personal Data upon termination or expiry of the agreement, save as necessary to perform the reversibility commitments regarding Personal Data set out herein.
Maintenance and Detection Improvement Processing
The Maintenance Processing and the Detection‑Improvement Processing are described in the privacy policy relating to use of the Software available upon request. These Processings are carried out by the Supplier as Controller. In this capacity, the Client acknowledges having taken note of the characteristics of these Processings. The Supplier states that the Processings are compatible with the original purposes of the Processing and undertakes to comply with its obligations as Controller under the Data Protection Regulations.
Subprocessing by the Supplier
The Client acknowledges that the Supplier engages Sub‑processors, including the Cloud Provider, to enable it to meet certain obligations under these terms. The full list of Sub‑processors as at the signing date appears below. Signature of the agreement constitutes the Client’s express acceptance of the Sub‑processors engaged by the Supplier for the performance of the services listed below. If this list changes, the Supplier undertakes to provide the Client and the Partner with the updated list of Sub‑processors to enable them to raise objections to the designation of a Sub‑processor only on legitimate, substantiated grounds (e.g., a competitor, a provider with whom the Partner has an ongoing dispute), which must be communicated to the Supplier in writing. In the absence of any reservation by the Client or the Partner within ten (10) days from the date the information is sent, the Client and the Partner shall be deemed to have accepted the new Sub‑processors. If the Partner or the Client refuses a Sub‑processor, the Supplier reserves the right to apply pricing different from that initially agreed to reflect such refusal.
Characteristics of the Processing subject to subprocessing:
- Purpose of the Processing: Hosting
- Nature of the Processing: Hosting and storage of Data
- Duration of the Processing: Commitment Term
- Purposes of the Processing: Hosting
- Categories of Data: Telemetry data and first name/last name, email address, browsing data
- Categories of special categories of data: N/A
- Categories of Data Subjects: Users of the Client’s information system
- Sub‑processor: OVH, located in France
The Client may request that additional information be provided.
In the case of a managed service and in the event of transfers to a recipient or authorised third party located in a country outside the European Union (EU), the Client hereby authorises the Supplier, if necessary, to execute on the Client’s behalf the standard contractual clauses with Sub‑processors processing the Client’s Personal Data outside the EU.
11. Support
Support is provided via an online service available at the following address: www.harfanglab.io. It is intended to assist the Operator in resolving issues and is not a substitute for Administrator training, through:
- A knowledge base, generally available 24/7/365 except during maintenance windows of the platform hosting the knowledge base, offering answers to recurring issues that an Administrator may encounter;
- Various technical documentation on installing and using the Software;
- A ticketing system enabling Administrators to contact the Supplier’s teams. Tickets will be handled by the Help Center team from 9:30 a.m. to 5:30 p.m. Central European Time (CET/UTC+1), Monday to Friday inclusive, excluding public holidays.
If the support portal is unavailable, requests should be sent to: support@harfanglab.fr.
Support is organised according to the following three levels:
|
|
Definition |
Actions |
|
Level 1 (N1) |
Requests for information about the Software or requests relating to a malfunction that can be resolved easily. |
• Logging the request (date, time, reason); • Performing an initial assessment/triage of the request, establishing a diagnosis, and proposing recommendations based on quick‑reference guides/runbooks. |
|
Level 2 (N2) |
Requests relating to a malfunction that may require the Supplier to access the Manager. |
Access to the console to: • Diagnose the fault (if the diagnosis was not performed at Level 1 (N1)); • Guide the User via videoconference to resolve the complex issue. |
|
Level 3 (N3) |
Requests relating to an Anomaly requiring a high level of expertise in the Software. |
• Handling of the request by the maintenance service for the Software; • Support and best practices for operating the Software, together with feedback (lessons learned). |
Where it acts as Operator, the Partner is responsible for providing Level 1 (N1) and Level 2 (N2) Support; otherwise, the Supplier will provide Support at all levels.
12. Maintenance
General provisions
Any fix or update to the Software is made available to the Operator in the same manner as delivery. A description of the changes is available in the Documentation. New Software versions are made available on a monthly basis, and bug fixes are provided on a weekly basis as “hotfixes” where necessary. These cadences are provided for information purposes only and may be subject to change.
To benefit from Maintenance, the following conditions must be met:
- The Operator must designate at least one Administrator and provide the Supplier with the Administrator’s name, telephone number and email address, and promptly notify the Supplier of any subsequent changes, so this information remains up to date. The Operator must designate a replacement Administrator in the event of absence, leave or departure of the current Administrator so that there is always an Administrator in charge;
- The Client and the Operator must use the Support portal, unless otherwise instructed by the Supplier, to report Anomalies;
- The Client or, as applicable, the Partner must be current with their payment obligations to the Supplier;
- If the Software is not deployed in the Supplier’s Cloud, the Operator must provide the Supplier with remote access to the Manager via the Software’s “EDR Update” module;
- The Client and/or Operator must be using a version of the Software that remains under Maintenance at the time the Support request is made.
Installation of updates
Installation of Manager updates is performed by the Supplier via the “EDR Update” module. If the Client or the Operator has disabled the “EDR Update” module, updating the Manager is the Operator’s responsibility. Installation of Agent updates is the Operator’s responsibility.
Evolutionary Maintenance
As part of evolutionary maintenance, the Supplier makes available to the Client, improvements to the functions and modules covered by the subscribed licence. Evolutionary maintenance does not extend to new modules that may be offered by the Supplier in the future. The Client and the Partner accept that the Supplier may include any useful technical protection measures to control use of the Software in strict compliance with the granted licence.
Furthermore, the Client and the Operator may request that the Supplier carry out improvements to the Software, including developing new features or APIs. The Parties agree that the Supplier has no obligation to perform such developments, which constitute additional services, nor to integrate them into the Software.
Correction of Anomalies
Once a ticket for an Anomaly has been opened on the Support portal, the intervention timeframes are as follows:
- For an Evaluation or Demonstration licence: recorded Anomalies are corrected as soon as reasonably practicable;
- For a Licence to Use, Software Anomalies are then handled within the following timeframes:
|
|
Ticket acknowledgement |
Qualification of the Anomaly upon receipt of the ticket |
Proposal for a fix or, where available, a workaround after qualification when available |
Correction |
|
Blocking Anomaly |
1 hour* |
1 business day* |
5 business days* |
Correction in the next hotfix |
|
Non-blocking Anomaly |
1 hour* |
Best efforts |
10 working days* |
Correction in the next minor version of the Software |
*During Support opening hours, i.e. 9:30 – 17:30 CEST, excluding public holidays in France
The Operator and the Client undertake to cooperate with the Supplier in resolving Anomalies and Production Incidents, in particular by:
- providing sufficient information to enable the Supplier to reproduce the Anomaly, including: (i) a clear and precise description of the Anomaly ; (ii) the Software component concerned; (iii) the function being used when the Anomaly occurred and/or the sequence of instructions that led to it; (iv) the error message displayed when the Anomaly occurred, where applicable; (v) sufficient detail to allow the Supplier to qualify the Anomaly, determine its severity and assess its impact on the Client’s activities; and (vi) any other information regarding hosting, the Software or the Anomaly, including, in particular, a copy of the data contained in the database included in the Software;
- answering questions and requests for information and ensuring the necessary access to their premises, equipment and to any required information and/or Documentation, as well as, where applicable, the availability of the relevant Users, in order to facilitate the performance of Support and Maintenance interventions.
The Supplier shall not be required to correct an Anomaly in the following cases: (i) lack of cooperation by the Operator and/or the Client in resolving Anomalies, including failure to answer questions and requests for information; (ii) use of the Software not in accordance with its intended purpose or with the Documentation; (iii) unauthorised modification of, or attempt to modify, the Software by the Partner, the Client or a third party; (iv) failure to comply with the Prerequisites; (v) use of any off‑the‑shelf software, other software or operating system not compatible with the Software; (vi) failure of communication networks.
If the Supplier agrees, or is required by the Client, to intervene where the Anomaly results directly or indirectly from a breach by the Partner or the Client of their obligations hereunder, the Operator undertakes to pay the Supplier the costs incurred, as applicable, corresponding to the time spent by the Supplier’s personnel or its subcontractors.
13. Additional services
The Operator may order from the Supplier the provision of additional services not included under the agreement, such as (the following list being non‑exhaustive):
- installation and/or update support for the Manager when installed on‑premises;
- support for specific configurations in accordance with specifications;
- configuration of connectors to third‑party solutions;
- additional training;
- development work such as new features, connectors or APIs.
These services will be subject to a quotation submitted for the Operator’s acceptance and a separate purchase order signed by the Parties.