scormPROXY TERMS AND CONDITIONS
The scormPROXY service covers the content hosting, changing, management and distribution needs in SCORM & xApi format for those companies or organisations wishing to offer their content online in a safe and centralised way.
scormPROXY provides its services through WelcomeNext S.L., whose details are listed below:
Name/Company name: WelcomeNext S.L.
Commercial name: scormPROXY
VAT ID: ES-B86432325
Address: Avenida de Europa 26, ATICA 5, 2nd floor. Pozuelo de Alarcon. Madrid (28224) Spain
Email: in**@*********xt.com
These General Conditions of Use and Contracting (hereinafter the “Conditions”) regulate the acquisition and use of the products and services that WelcomeNext makes available to its users and/or clients.
CLAUSES
1.- SUBJECT-MATTER OF THE AGREEMENT AND TERRITORIAL SCOPE
1.1 This Agreement seeks to establish the grounds according to which WELCOMENEXT is to provide the following services to the CLIENT:
- Implementation, at WELCOMENEXT’s cloud-based servers, of an instance of the technological platform scormPROXY, owned by WELCOMENEXT, to be used by the CLIENT.
- Technical support and maintenance service of the technological platform scormPROXY, in accordance with the terms and conditions set forth in this Agreement.
1.2 The territorial scope of this Agreement will be at the international level.
1.3 Definitions
For the purposes of this Agreement, capitalized terms shall have the following meanings (unless otherwise stated):
- “Availability” means the percentage of total time during which the scormPROXY Service is available to the Client as measured on a monthly basis, excluding (i) planned Maintenance Windows, (ii) events of Force Majeure, and (iii) emergency maintenance that is necessary to safeguard the security or performance of the Service.
- “Confidential Information” means all non-public information, in any form, disclosed by one party (“Disclosing Party”) to the other party (“Receiving Party”) that is either identified as confidential or should reasonably be understood to be confidential given the nature of the information or the circumstances of disclosure, including, but not limited to, business, financial, technical, operational, and customer information.
- “Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by WELCOMENEXT under this Agreement.
- “Force Majeure” means any cause beyond the reasonable control of a party, which may include acts of God, natural disasters, fire, pandemics, governmental actions, and internet disturbances outside of WELCOMENEXT’s reasonable control.
- “Maintenance Window” means the period of time scheduled by WELCOMENEXT to perform maintenance, upgrades, or updates to the scormPROXY Service.
- “Personal Data” means any information relating to an identified or identifiable natural person that is subject to protection under applicable data protection laws.
- “SLA” or “Service Level Agreement” means the specific commitments WELCOMENEXT makes regarding support response times, Availability, and resolution times, as further described in Clause 8 of this Agreement.
2.- TRIAL PERIOD
2.1 WELCOMENEXT won’t start billing the CLIENT for the scormPROXY service until the CLIENT has more than 10 activated licenses in a month or more than 10 connected users in a month (This promotion is limited to a maximum of 4 months from the date of signing).
3.- AGREEMENT PERIOD
3.1 This Agreement shall be effective as of the signing date and its initial term shall be from that date until the end of the following calendar month.
3.2 Once the due date has been reached, the Agreement shall be automatically extended for subsequent periods of 1 month, unless both parties agree to change the duration of the extensions.
3.3 If the CLIENT does not wish to renew this Agreement, they shall notify WELCOMENEXT in writing at least 15 days prior to the expiration of the Agreement.
3.4 In any case, WELCOMENEXT will not be liable for the consequences resulting from the service interruption, or from the lack of maintenance after the Agreement has been terminated.
4.- DATA PROTECTION POLICY
The parties, following the current laws on Personal Data Protection and pursuant to article 28 of the GDPR agree as follows:
4.1 For the provision of the Services, WELCOMENEXT may process Personal Data relating to employees, representatives and authorised users of the CLIENT, and end users / learners of the CLIENT and of the CLIENT’s customers.
Such Personal Data may include administrative user identification data, usernames/user IDs, user full names, optional email addresses, technical access and log data (including IP address, timestamp and browser information), learning activity and course-tracking data, including completion status, progress, scores and SCORM/xAPI tracking information, business identification data of Client’s customers and data transmitted by end users via the platform (e.g., support requests, satisfaction surveys and messages).
The processing may include receipt, collection, recording, organisation, storage, retrieval, consultation, transmission, learning activity tracking, reporting, deletion and other operations necessary for the provision, maintenance and support of the scormPROXY Service.
WELCOMENEXT does not intentionally process special categories of Personal Data pursuant to Article 9(1) GDPR in connection with the Services.
WELCOMENEXT does not embed platform-generated learner account data, learning-tracking data, email addresses, IP addresses or other platform-generated Personal Data within course files or other content assets. However, content and assets uploaded by the CLIENT may themselves contain Personal Data if the CLIENT chooses to include such information.
4.2 WELCOMENEXT, acting as data processor or, where applicable, as another processor engaged pursuant to Article 28(4) GDPR, represents and warrants to the CLIENT the following:
- It has enough technical capacity to meet the obligations of the Agreement in full compliance with the laws regarding personal data protection, being able to commit itself, insofar as is required for the provision of the Services, to comply with the requirements of the GDPR.
- It will maintain the secrecy and confidentiality of the Personal Data processed under the Services to which access is provided.
- It will process the personal data to which access is provided exclusively on behalf of the CLIENT and, in any case, in accordance with the instructions given by the CLIENT. Similarly, it must use such data only for the provision of the Services and, consequently, cannot use them or implement them in any way exceeding such purpose, unless WELCOMENEXT is required to process such Personal Data by Union or Member State law. In such case, WELCOMENEXT shall inform the CLIENT of that legal requirement before processing, unless such law prohibits such information on important grounds of public interest.
- It shall not provide third parties, not even for safekeeping, data to which access is provided pursuant to the provision of the Services, or similar developments, assessments or processes carried out with such data, or duplicate or reproduce all or part of the information, results or relations on such data, except to sub-processors engaged in accordance with this Agreement or where otherwise required by law.
- Application-level Personal Data processed by scormPROXY, including learner account and learning-tracking data, together with database backups, is hosted within the European Union in the Frankfurt region. Content and assets uploaded by the CLIENT may be stored and served through content delivery infrastructure located in Germany, USA, Brazil and Singapore. WELCOMENEXT does not embed platform-generated learner account, tracking, email or IP data within such content files. However, where the CLIENT itself includes Personal Data within a course, PDF, video or other uploaded asset, such Personal Data may consequently be stored and distributed through that content delivery infrastructure. The CLIENT is responsible for ensuring that any Personal Data intentionally included in uploaded content is processed and distributed lawfully. Any resulting international transfer shall be subject to Clause 4.2(xx).The CLIENT shall not intentionally include special categories of Personal Data pursuant to Article 9(1) GDPR within uploaded content or assets unless expressly agreed in writing with WELCOMENEXT and appropriate safeguards have been agreed.
- It shall provide the CLIENT with the necessary information to prove compliance of its obligations, and for audits or inspections carried out by the CLIENT, or an auditor on its behalf.
- WELCOMENEXT has appointed a Data Protection Officer (DPO) and will communicate the relevant contact information to the CLIENT. For all matters relating to data protection or privacy, the DPO can be contacted through the email address pr********@*********xt.com, which is actively monitored and managed for this purpose.
- It shall guarantee that the persons authorised to process personal data commit themselves, expressly and in writing, to respect confidentiality and comply with the corresponding security measures, of which they shall inform accordingly. To that end, WELCOMENEXT shall keep available to the CLIENT all documents evidencing compliance with the obligation set forth in this paragraph.
- It shall guarantee the necessary training, in the field of personal data protection, of those persons authorised to process personal data for which it is responsible.
- It shall give support to the CLIENT in the carrying-out of impact assessments with regard to personal data to which access is provided, as appropriate and requested by the CLIENT.
- It shall give support to the CLIENT in the prior consultations held with the control authority, where applicable.
- If WELCOMENEXT considers that the fulfilment of any particular instruction given by the CLIENT might entail a breach of the GDPR or any other applicable regulations modifying or supplementing it, WELCOMENEXT must immediately inform the CLIENT and ask it to withdraw, amend or confirm such instruction. WELCOMENEXT may suspend the implementation of the relevant instruction while awaiting the CLIENT’s decision with regard to the withdrawal, amendment or confirmation of the corresponding instruction.
- Upon termination of the Services, WELCOMENEXT shall handle the return or deletion of Personal Data in accordance with Clause 4.7.5.
- It shall implement mechanisms to: (i) ensure permanent confidentiality, integrity, availability and resilience of processing systems and services (ii) restore data availability and access in a quick way in case of physical or technical incidents; (iii) constantly verify, assess and value the effectiveness of technical and organisational measures implemented to ensure security of processing; and (iv) pseudonymise and encrypt data, where appropriate.
- As data processor it shall notify the CLIENT, without undue delay, via email: ___________________, after WELCOMENEXT becomes aware of the breach on data protection, of any unlawful or unauthorised data, of any loss, destruction or damage to personal data within the area of responsibility of WELCOMENEXT (caused by WELCOMENEXT, its staff, agents or subcontractors) and of any incident that may be considered to be a security breach of data, along with all relevant information for the documentation and communication of the incident to the authorities or affected parties. In this sense, if available, at least the following information is to be provided:
- Description of the nature of the breach of data security, including, where possible, the categories and approximate number of affected parties, and the categories and approximate number of affected personal data registries;
- Name and contact details of the data protection officer or of another point of contact from which detailed information can be obtained;
- Description of the possible consequences of the breach of data security; and
- Description of the adopted or proposed measures to remedy the breach of data security, including, where appropriate, the measures adopted to mitigate the potential negative effects.
Additionally, WELCOMENEXT shall immediately open a full investigation on the circumstances associated with such incident and shall submit its report or comments on it to the CLIENT, and it shall fully cooperate with the investigation that may be performed by the CLIENT, providing the CLIENT with the assistance required to investigate such incident.
Likewise, it shall assist the CLIENT, in the event of a breach of personal data security, so as to ensure compliance with the reporting obligations of a breach of personal data security in accordance with the GDPR (in particular, arts. 33 and 34 of the GDPR) and any other applicable regulations amending, complementing or that may be enacted in the future.
- It shall assist the CLIENT, at its request, upon simple application, delivering any kind of information or documents needed to provide a proper response to the exercise of the rights of access, rectification, erasure, opposition, limits to processing or data portability that it may receive from the interested parties, it all within reasonable deadlines and, in any case, sufficiently in advance for the CLIENT to be able to comply with legally established deadlines for the provision of the aforementioned rights.
- In those cases where it receives a direct request of access, rectification, erasure, opposition, limits to processing or portability from the affected party, holder of the processed data, it undertakes to immediately transfer such request to the CLIENT so that it can be addressed within the legally established deadlines.
- WELCOMENEXT is generally authorised by the CLIENT to engage sub-processors where necessary for the provision of the Services. WELCOMENEXT shall inform the CLIENT in writing of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, thereby giving the CLIENT sufficient time to object to such changes before the engagement of the relevant sub-processor.
The subprocessor will also be subject to the obligations imposed upon WELCOMENEXT under this Agreement and to the instructions given by the CLIENT at any given time. In this sense, WELCOMENEXT must capture the subprocessing and the obligations of the subprocessor in an Agreement signed by WELCOMENEXT and the subprocessor, which fulfils the formal requirements contained in this clause. In the case of failure on the part of the subprocessor to fulfil its obligations on data protection, WELCOMENEXT will undertake responsibility to the CLIENT with respect to such failures, as if such failure had been committed by WELCOMENEXT.
The sub-processors currently engaged by WELCOMENEXT in connection with the Services are: Oracle Cloud Infrastructure, which provides cloud hosting, static content hosting and OCI Email Delivery; BroadPin (formerly Quistor), which provides infrastructure support and Oracle Cloud administration; and Cloudflare, which provides geographic traffic routing, CDN, caching and content delivery services.
Oracle and BroadPin are not granted application-level or database-level credentials and do not have direct logical access to the scormPROXY application database. Cloudflare processes IP addresses, technical request/traffic metadata and, where applicable, CLIENT-provided content for geographic routing, caching and delivery purposes, but has no direct logical access to the scormPROXY application database.
- It shall maintain a written record of all categories of processing activities carried out in accordance with this Agreement, containing:
- The name and contact details of WELCOMENEXT and, where appropriate, of the CLIENT’s representative or of WELCOMENEXT’s representative and of the data protection officer;
- The categories of processing carried out in accordance with the Agreement; and
- Where applicable, details of transfers to third countries or international organisations and documentation of the applicable safeguards.
- Application-level Personal Data stored in the scormPROXY application database and its backups is hosted within the EU/EEA. Certain limited Personal Data may be processed outside the EU/EEA by authorised sub-processors or through the content delivery infrastructure described in this Agreement. Any such international transfer shall take place only in accordance with Chapter V GDPR and, where required, the documented instructions of the CLIENT. Where the UK GDPR applies to the processing, references in this DPA to applicable data protection law shall include the UK GDPR and the UK Data Protection Act 2018. Any restricted transfer subject to the UK GDPR shall be carried out in accordance with applicable UK international transfer requirements and, where required, using an appropriate lawful transfer mechanism, which may include the UK International Data Transfer Agreement (IDTA) or the UK International Data Transfer Addendum, as applicable.
- It shall have a general description of the technical and organisational security measures regarding: (i) pseudonomisation and encryption of personal data, where appropriate; (ii) the capacity to ensure permanent confidentiality, integrity, availability and resilience of processing systems and services (iii) the capacity to restore personal data availability and access in a quick way in case of physical or technical incidents; and (iv) the process of constant verification, assessment and valuation of technical and organisational measures implemented to ensure security of processing.
Additionally, WELCOMENEXT undertakes to implement all technical and organisational security measures that may be applicable in accordance with the GDPR (namely, those laid down in article 32) and any other applicable regulations that amend, complement or replace it. In the particular context of this relationship, following the relevant risk analysis, both parties have agreed that the specific security measures that WELCOMENEXT must implement in connection with the data processed under this Agreement are those referred to in clause 4.6 below.
Such security measures, and any others that may be implemented can be amended at the request of the CLIENT so as to accommodate them to regulatory changes or variations in the type of personal data to which WELCOMENEXT is to have access to.
- Where WELCOMENEXT receives a legally binding request from a public authority, court or regulatory body requiring disclosure of Personal Data processed on behalf of the CLIENT, WELCOMENEXT shall, where legally permitted and reasonably practicable, notify the CLIENT before disclosure, or otherwise as soon as legally permitted. WELCOMENEXT shall review the validity and scope of the request with its Data Protection Officer and, where appropriate, legal counsel, and shall disclose only the Personal Data that it is legally required to disclose.
4.3 In accordance with the provision of the data protection law, WELCOMENEXT shall be considered as a data controller should it use the data for another purpose, disclose or use them in breach of the stipulations of this Agreement, answering for the breaches it has personally caused.
4.4 Pursuant to that set forth in the applicable regulations on Personal Data Protection, the CLIENT and WELCOMENEXT inform the signatories acting in the name and on behalf of each of the parties in this Agreement (“Representatives“) that the personal data laid down in this Agreement and those arising out of the relationship, shall be processed by each of the parties, as data controllers, on the basis of the legitimate interests of each party in maintaining, complying with, developing, controlling and executing that provided for in this Agreement.
To all appropriate effects, the parties inform the Representatives that their data will not be disclosed to third parties except in the cases provided by the law and access to such data will only be given to service providers of the parties in the systems, technology and administrative management sectors.
If the Representatives wish to exercise their rights to access, rectification, erasure, restriction of processing and, in those situations where it is possible, objection, they may do so by way of a written request addressed to the addresses specified in the Agreement’s appearance clause or to the following addresses, attaching a copy of a personal identification document:
- Data Protection Officer of the CLIENT: ________________________
- Data Protection Officer of WELCOMENEXT: pr********@*********xt.com
They may also address the Spanish Data Protection Agency to claim their rights.
4.5 DATA RETENTION POLICY
During the term of the Contract, WELCOMENEXT shall retain Personal Data processed on behalf of the CLIENT unless otherwise instructed by the CLIENT. The CLIENT may delete user data at any time through the available scormPROXY functionalities.
The standard automated retention period for inactive user data is currently three (3) years. This automated retention period is not configurable on a per-CLIENT basis and shall in any event never exceed five (5) years of inactivity. The five-year period therefore constitutes a maximum retention period and does not prevent the CLIENT from deleting user data earlier.
Upon termination of the Contract, Personal Data shall be handled in accordance with Clause 4.7.5. Database backups will be retained for a maximum of 30 additional days before being irreversibly destroyed.
4.6 SECURITY MEASURES
This article lays down the security measures of information and personal data systems used during the provision of the scormPROXY service to the CLIENT.
For the purposes of Personal Data processed through scormPROXY, the CLIENT may act as Controller or Processor depending on the relevant processing activity.
Where the CLIENT acts as Controller, WELCOMENEXT shall act as Processor.
Where the CLIENT acts as Processor on behalf of a third-party Controller, WELCOMENEXT shall act as another processor engaged by the CLIENT pursuant to Article 28(4) GDPR.
Where the CLIENT acts as Processor, the CLIENT is responsible for ensuring that the terms of this Agreement are sufficient to meet its obligations towards the relevant third-party Controller. Any additional obligations arising from an agreement between the CLIENT and a third-party Controller shall bind WELCOMENEXT only where expressly agreed by WELCOMENEXT in writing.
In all cases, WELCOMENEXT shall process Personal Data solely for the provision of the Services and in accordance with the documented instructions of the CLIENT, subject to applicable law.
The CLIENT is solely responsible for determining the legal basis and capacity under which it processes Personal Data through the Service and, where it acts as Processor, for obtaining any instructions or authorisations required from the relevant Controller. WELCOMENEXT shall not be required to verify the contractual or legal relationship between the CLIENT and any third party. While executing its maintenance duties, WELCOMENEXT shall limit its access to personal data to that necessary for the execution of the Agreement and will strictly comply with the current personal data protection regulations.
WELCOMENEXT may engage the infrastructure, content delivery, email delivery and support sub-processors identified in Clause 4.2(xviii), subject to the conditions set out in that Clause.
Functions and duties of the staff of WELCOMENEXT
Access to the scormPROXY system is granted to authorized staff of WELCOMENEXT, including analysts, programmers, and system technicians, for the purpose of performing the following tasks:
- Incident management
- Maintenance of hardware and software systems
- Execution of security-related operations
- System and data backups
- Production readiness and deployment of programming code
- Coding and testing tasks
These activities are carried out without routine access to personal data. However, in order to provide effective customer support and resolve specific incidents or usage queries, authorized support personnel may access the CLIENT’s account and view personal data on an occasional and limited basis, strictly for the purpose of assisting the CLIENT. Such access is controlled, logged, and conducted in accordance with applicable data protection policies.
Security copies
Backup copies of all the scormPROXY system used by the CLIENT will be made on a daily basis, as well as of its specific configuration. This will also include copies of all information stored in the system (databases, documents, etc.).
Backup files shall be transported through a communications network with certain security measures and secure protocols.
Backup files shall be made every day from ZERO HOURS (00:00) and FIVE HOURS (05:00) in the morning, during which the service may run at below normal service level.
WELCOMENEXT shall store daily backups for a maximum of 30 days.
4.7 ADDITIONAL DATA PROTECTION AND SECURITY COMMITMENTS
4.7.1. Secure Processing: WELCOMENEXT will implement and maintain industry-standard technical and organizational measures to protect Personal Data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, and other unlawful forms of Processing.
4.7.2. Data Minimization: scormPROXY applies data minimisation principles and processes only the Personal Data necessary for the provision of the Services, which may include the categories described in Clause 4.1. Where requested by the CLIENT, scormPROXY can implement measures to anonymise or pseudonymise learner identification data (e.g., learner ID and learner full name), where applicable.
4.7.3. Data Breach Notification: In the event WELCOMENEXT confirms a Data Breach involving the CLIENT’s Personal Data, WELCOMENEXT shall notify the CLIENT without undue delay after becoming aware of the Personal Data Breach and provide sufficient details regarding the nature and scope of the incident and steps taken to mitigate further impact.
4.7.4. Compliance with Applicable Laws: Both Parties shall comply with all applicable data protection and privacy laws, including the EU GDPR and UK GDPR where applicable, the UK Data Protection Act 2018, and other applicable local data protection laws.
4.7.5. Return or Deletion of Data: By entering into this Agreement, the CLIENT instructs WELCOMENEXT to securely delete the Personal Data processed under the Services upon termination of the Agreement.
Prior to termination, the CLIENT may retrieve the information available through the export and reporting functionalities provided by scormPROXY, including user tracking data, activated licence reports, learner survey responses, active/connected user lists and scormPROXY event logs.
The CLIENT may change its above instruction and request the return of Personal Data instead of deletion by notifying WELCOMENEXT in writing before termination of the Services. In such case, the Parties shall agree on a reasonable electronic method for returning the relevant Personal Data processed on behalf of the CLIENT that is not otherwise available through the Service’s export functionalities.
Following completion of the applicable deletion or return process, WELCOMENEXT shall securely delete the CLIENT’s account and dedicated database, unless Union or Member State law requires further retention. Backup copies shall be automatically deleted within a maximum of 30 days.
4.7.6. Security Audits: WELCOMENEXT shall make available to the CLIENT, upon reasonable written request, information reasonably necessary to demonstrate compliance with its applicable data protection obligations.
Where the requested scope is adequately addressed by an independent certification, audit report or other third-party assurance available to WELCOMENEXT, such documentation may be provided as evidence of compliance in lieu of an audit of the same controls.
Where such information is not reasonably sufficient, the CLIENT may request an audit of the relevant Personal Data processing activities, subject to reasonable prior notice, appropriate confidentiality obligations, an agreed scope, and reasonable measures to avoid disruption to WELCOMENEXT’s operations and protect the security and confidentiality of WELCOMENEXT and its other customers.
Any audit shall be limited to processing activities relevant to the CLIENT’s Personal Data.
Penetration testing, vulnerability scanning, source-code review, network or infrastructure testing, or other intrusive technical testing shall not form part of an audit and may only be carried out with WELCOMENEXT’s prior written authorisation.
Unless required by applicable law, a competent supervisory authority, or where there are reasonable indications of non-compliance, audits may not be requested more than once in any twelve-month period.
Nothing in this clause grants the CLIENT any right of physical access to facilities or infrastructure operated by WELCOMENEXT’s infrastructure or sub-processing providers.
5.- TECHNICAL SUPPORT
5.1 WELCOMENEXT offers technical support via e-mail su*****@*********xt.com and via telephone for major incidents. This shall be available to the CLIENT over the life of the Agreement. The CLIENT may appoint a person to act as contact point so as to give notice to WELCOMENEXT about technical problems.
6.- RATES AND FORM OF PAYMENT
6.1 Official rates for the scormPROXY service are those shown on scormPROXY website:
https://welcomenext.com/scormproxy/en/scormnext-price-rates/
6.2 The CLIENT can choose between the available rate models when contracting the service and can also modify the chosen price plan once per year. For this purpose, on the first business day of each month, WELCOMENEXT will elaborate a report with the count of active users or the number of new license activations for the previous month. Likewise, it will issue an invoice for the corresponding amount according to the corresponding price table.
6.3 The amount of such invoice can be paid via bank transfer or by credit card within a maximum period of 15 days after its issuance.
7.- EARLY TERMINATION CONDITIONS
7.1 WELCOMENEXT may terminate this Agreement if one (1) monthly invoice is not paid, or any other amount that is to be paid by the CLIENT. To do this, it must specifically request the CLIENT to pay and give him at least 5 calendar days to do so.
7.2 The CLIENT may terminate, upon request, this Agreement if WELCOMENEXT fails to comply with the services agreed, if, within fifteen (15) calendar days of the request it has not been corrected. Termination may be used if, as a result of a regulatory change, it is determined that it is impossible to continue providing the contracted services.
7.3 If any misconduct or illegal activity is detected, WELCOMENEXT reserves the right to withhold or cease the contracted services without notice. Possible illegal activities or misconducts of the CLIENT, which would entail the withholding or cessation of the contracted services, are listed below:
- The platform scormPROXY may not be changed, adapted or hacked, or falsely indicate that another website is associated with it.
- It may not create sessions or send private messages to disturb or interfere in the development of the system activity.
- The platform may not be used for the transmission, installation or publication of any kind of virus, malicious code or any other kind of file or program detrimental to the development of the service and platform.
- Sign up at the Platform using a false identity, impersonate third parties or carry out any other action that may confuse the rest of the system users.
- Use the Platform in order to get information from another user.
- Break or try to break the security or authentication measures of the Platform or any system connected to it, or any security measure included within the Platform’s contents.
- Upload content if you are not the named holder or do not have the necessary authorisation.
- Use the Platform illegally, contrary to good faith, morality or public order.
- Hinder the normal development of the processes carried out in the Platform.
- Any other activity or conduct that may be detrimental to the development of the system.
7.4 Termination for Breach: If either party commits a material breach of this Agreement and fails to cure such breach within fifteen (15) days of receiving written notice specifying the breach in detail, the non-breaching party may terminate this Agreement immediately upon written notice.
7.5 In the hypothetical case that WELCOMENEXT were to cancel the service provided without the CLIENT having contravened any of the terms described herein, WELCOMENEXT shall notify the CLIENT with at least two (2) months’ notice. Otherwise, WELCOMENEXT shall reimburse the CLIENT for all amounts invoiced to the CLIENT during the preceding two (2) months.
7.6 In any case, WELCOMENEXT will not be liable for the consequences resulting from the service interruption after the Agreement has been terminated.
8.- GUARANTEE FOR THE SERVICE PROVIDED (SLA)
8.1 Service Availability
WELCOMENEXT guarantees a monthly service availability of 99.9% for the scormPROXY platform, measured over each calendar month. This corresponds to a maximum allowable downtime of approximately 44 minutes per month.
If the accumulated unavailability within a calendar month exceeds this threshold, WELCOMENEXT shall apply a proportional service credit to the CLIENT’s next invoice, based on the duration of the excess downtime.
This service credit is the CLIENT’s sole and exclusive remedy for failure to meet the availability guarantee.
Measurement: Availability is measured 24×7 and calculated per calendar month.
Exclusions: The Target Availability excludes any downtime due to (i) scheduled Maintenance Windows announced at least 24 hours in advance, (ii) emergency maintenance needed to protect the security or stability of scormPROXY, (iii) Client-caused outages or disruptions, or (iv) Force Majeure events.
Reporting: WELCOMENEXT will maintain records of system uptime and supply monthly reports of any outages upon the Client’s written request.
8.2 Incident Response and Resolution Times
WELCOMENEXT shall address Client-reported incidents in accordance with the severity levels below:
Severity 1 (Critical): scormPROXY is completely unavailable, or the Client cannot access the Service at all.
Response Time: within 2 hours.
Resolution Goal: best efforts to resolve or provide a workaround within 4 hours.
Severity 2 (Major): Partial disruption or substantial reduction in functionality, but the Service is still accessible.
Response Time: within 4 hours.
Resolution Goal: best efforts to resolve within 8 hours.
Severity 3 (Moderate): Specific disruption or specific issue, but the rest of the Service is accessible.
Response Time: within 8 business hours.
Resolution Goal: best efforts to resolve within 16 business hours.
Severity 4 (Minor): Non-critical problems or cosmetic issues that do not significantly affect functionality (e.g., text errors, UI misalignments).
Response Time: within 2 business days.
Resolution Goal: best efforts to resolve in the next scheduled update or maintenance release.
8.3 Remedies
In the event WELCOMENEXT fails to meet Target Availability in two (2) consecutive months and such failure is solely attributable to WELCOMENEXT, the Client may request service credits up to a maximum of 10% of that month’s fees. Service credits constitute the sole and exclusive financial remedy for proven unavailability claims under this Clause 8.
8.4 Scheduled Maintenance
WELCOMENEXT shall provide at least 24 hours’ notice prior to any scheduled downtime. Whenever possible, such maintenance shall be conducted during low-traffic periods to minimize Client impact.
8.5 Contact Channels
The Client may report issues via the designated support email [su*****@*********xt.com] or phone line.
8.6 Disclaimer
Except as set forth in this Clause 8, WELCOMENEXT makes no additional performance guarantees beyond commercially reasonable efforts for maintaining the scormPROXY Service.
9.- RESPONSIBILITIES
9.1 WELCOMENEXT shall not be liable for the loss of profits and damage resulting from the use, functioning or performance of the software, and shall only be liable for the acts carried out that are necessary to comply with its obligations in accordance with this Agreement.
9.2 Indemnification
- By WELCOMENEXT: WELCOMENEXT shall defend and indemnify the Client against all reasonable and direct damages, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising from third-party claims alleging that the scormPROXY Service infringes intellectual property rights of such third party. The Client shall promptly notify WELCOMENEXT in writing of any claim, grant WELCOMENEXT sole control of the defense and settlement thereof and reasonably cooperate with WELCOMENEXT.
- By the Client: The Client shall defend and indemnify WELCOMENEXT against all reasonable and direct damages, liabilities, costs, and expenses arising from the Client’s or its users’ misuse of the Service or data provided to WELCOMENEXT that violates applicable law or infringes third-party rights.
9.3 Limitation of Liability
- Except for (i) breaches of confidentiality or data protection obligations, (ii) indemnification obligations under Clause 9.2, or (iii) liability arising from wilful misconduct or gross negligence, each party’s total liability shall be limited to the fees paid (or payable) by the Client to WELCOMENEXT under this Agreement in the twelve (12) months preceding the event giving rise to the claim.
- For the cases listed in (i) above, each party’s total liability shall be limited to an amount equal to two (2) times the fees paid (or payable) by the Client to WELCOMENEXT under this Agreement in the twelve (12) months preceding the event giving rise to the claim.
- Nothing in this Agreement shall exclude or limit liability where such limitation is not permitted by applicable law.
9.4 Mitigation
In the event the Service becomes subject to a claim of infringement, WELCOMENEXT may, at its option and expense, (i) procure for the Client the right to continue using the Service, (ii) replace or modify the Service so that it becomes non-infringing while maintaining substantially equivalent functionality, or (iii) if neither (i) nor (ii) is commercially feasible, terminate the relevant portions of the Service and refund any prepaid fees related to the affected Service period.
10.- INTELLECTUAL AND INDUSTRIAL PROPERTY
10.1 The terms and conditions agreed in this Agreement do not involve, implicitly or explicitly, the transfer of any of the intellectual or industrial rights of the Software, its manuals or data model. The knowledge and know-how inherent to the Software, along with the knowledge used for its configuration, are also WELCOMENEXT’s own and confidential information.
10.2 The CLIENT shall take responsibility for the actual damages to WELCOMENEXT arising directly from the fraudulent use or illegal copy of programs or this information by the CLIENT’s own employees, having to take all necessary measures to ensure that only authorised persons have access to such protected information.
10.3 The CLIENT must respect the copyright notices appearing in the programme or in the original documentation.
10.4 The CLIENT is responsible for ensuring that the content stored in the platform respects the applicable industrial and intellectual rights. WELCOMENEXT shall in no case be held liable for infringements of industrial or intellectual property concerning materials, elements, videos, photos, documents or any other element uploaded to the platform by users.
10.5 The content stored in the platform, along with any industrial and intellectual property, shall be held by its respective authors. As a result, WELCOMENEXT may not under any circumstances carry out a disposal, sale, lease, transfer or others of the data collected.
11.- CONFIDENTIALITY
11.1. Definition of Confidential Information: “Confidential Information” shall include, but not be limited to, any technical, financial, business, or marketing information disclosed by one party to the other which is identified as confidential or would reasonably be understood to be confidential given its nature and the circumstances of disclosure.
11.2. Exclusions: Confidential Information does not include any information that (i) is or becomes publicly available without breach of this Agreement; (ii) was lawfully in the receiving party’s possession before its disclosure; (iii) is lawfully disclosed by a third party without confidentiality restrictions; or (iv) is independently developed by the receiving party without reference to the disclosing party’s information.
11.3. Use of Confidential Information: Each party shall use the Confidential Information of the other party solely for the purposes of fulfilling its obligations under this Agreement. Neither party shall disclose the Confidential Information to any third party other than to its employees or authorized subcontractors who have a need to know and who are bound by confidentiality obligations at least as restrictive as those in this Clause 11.
11.4. Protection: Each party agrees to employ the same degree of care to protect the Confidential Information of the other party as it uses to protect its own confidential or proprietary information, but in no event less than reasonable care.
11.5. Return or Destruction: Upon written request by the disclosing party, or upon termination of this Agreement, each party shall promptly return or destroy all Confidential Information of the other party and certify such destruction in writing, except where retention is required by law.
11.6. Remedies: The parties agree that a breach of this Clause 11 may cause irreparable harm for which monetary damages may be inadequate and, in the event of a breach or threatened breach, the non-breaching party shall be entitled to seek immediate injunctive relief in addition to any other remedies available at law or equity.
12.- COMPLIANCE WITH APPLICABLE LAWS
WELCOMENEXT and the Client each agree to comply with all applicable laws and regulations in performing their respective obligations under this Agreement, including, without limitation, data protection laws, anti-corruption laws, and export control regulations. Neither party shall take any action that would cause the other party to be in violation of applicable law.
13.- APPLICABLE LAW AND JURISDICTION
The drafting and interpretation language of this Agreement shall be English.
This Agreement shall be interpreted in accordance with the Spanish law. In the event of a dispute over the whole or part of this Agreement, the parties shall be subject to the jurisdiction of the Courts and Tribunals of the city of Madrid (Spain).
In witness whereof the appearing parties, within the scope of their powers of representation, sign this Agreement in duplicate, on the date and place indicated at the heading of this document.
