Document architecture and order of precedence
This framework is designed so that one core set of General Terms applies to both custom software and SaaS offerings, while transaction-specific information is completed in the relevant schedules. An Order Form may activate one or more schedules.
| Document | Role | Priority |
|---|---|---|
| Order Form / Proposal | Commercial selections, product, fees, term, customer and option elections | 1 |
| Data Processing Addendum | Personal-data processing terms | 2 for data-protection matters |
| Custom Software Statement of Work | Scope, milestones, acceptance and licence for project deliverables | 2 for custom-project matters |
| SaaS Service Schedule | Subscription, uptime, support, data regions and exit | 2 for SaaS matters |
| Security and Technical Measures | Baseline security controls | 3 |
| Acceptable Use Policy | Prohibited and controlled use | 3 |
| These General Terms | Core legal and commercial terms | 4 |
If two documents conflict, the higher-priority document controls only to the extent of the conflict. A negotiated change in an Order Form must expressly identify the clause being changed. Mandatory law prevails over all documents.
General Terms and Conditions
1. Identity, applicability and formation
1.1Supplier. These General Terms apply to software, cloud, development, implementation, consulting, support and related services supplied by DQ Solutions B.V., a Curaçao limited liability company registered with the Curaçao Chamber of Commerce under number 160193 and having its registered address at Groot Kwartierweg 2 A, Curaçao ("DQ").
1.2Agreement. The agreement between DQ and the person or entity purchasing or using the Services consists of the documents listed in the architecture section (the "Agreement"). The person or entity is the "Customer". A natural person acting mainly outside a trade, business, craft or profession is a "Consumer".
1.3Acceptance. The Agreement is formed when the Customer signs or electronically accepts an Order Form, accepts these General Terms during registration, uses a paid Service after having had a reasonable opportunity to review them, or otherwise unequivocally accepts DQ’s offer. Where mandatory law requires a particular form, information or separate consent, that requirement applies.
1.4Customer terms excluded. Customer purchase terms do not apply unless DQ expressly accepts them in a signed writing that identifies the accepted provisions. This clause does not restrict mandatory Consumer rights.
1.5Authority. A person accepting for an organization warrants that they are authorized to bind it. A Consumer contracts personally.
1.6Availability. The current version will be posted at [WEBSITE URL]. DQ will provide a durable copy where required by law.
2. Definitions and interpretation
| Term | Meaning |
|---|---|
| Authorized User | A person whom Customer permits to access a Service under Customer’s account. |
| Customer Data | Data, content, files, instructions, credentials and personal data submitted by or for Customer. |
| Deliverables | Work product expressly identified as deliverable in a Statement of Work, excluding DQ Materials and Third-Party Materials. |
| DQ Materials | Software, code, tools, libraries, templates, methods, know-how, models, documentation and other materials owned, licensed or developed by DQ, including reusable or generic components. |
| Documentation | User, technical or operational documentation DQ makes available for a Service. |
| Fees | Charges stated in an Order Form or Statement of Work. |
| Order Form | A proposal, order, quotation or online checkout record accepted by the parties. |
| SaaS Service | Hosted software made available by DQ on a subscription basis. |
| Services | SaaS Services, custom software services, implementation, support and other services ordered by Customer. |
| Statement of Work or SOW | A written project schedule describing custom or professional services. |
| Third-Party Materials | Software, services, data, APIs, open-source components or content supplied by third parties. |
Headings are for convenience. “Including” means “including without limitation”. The singular includes the plural. A reference to written notice includes email where the Agreement permits it.
3. Services and changes
3.1Performance. DQ will provide the Services with reasonable skill and care and materially in accordance with the applicable Order Form, SOW, Documentation and Service Schedule. Unless an express result is identified, implementation, development, consulting and support are performed on a reasonable-efforts basis.
3.2Dependencies. Customer will timely provide accurate information, decisions, access, personnel, infrastructure, test data and cooperation reasonably needed. DQ is not responsible for delay, rework or failure caused by Customer delay, inaccurate inputs, third-party systems or a dependency outside DQ’s reasonable control. Reasonable resulting costs may be charged after notice.
3.3Personnel and subcontractors. DQ may use qualified personnel, affiliates and subcontractors and remains responsible for their performance to the extent required by the Agreement and applicable law.
3.4Change control. Either party may request a change. A change affecting scope, assumptions, Fees, timing, architecture, security, data location or acceptance criteria takes effect only through a written change order. DQ may charge for analysis of a material change request if disclosed in advance.
3.5Beta and preview features. Beta, trial, proof-of-concept and preview features may be changed or withdrawn and are provided without service levels, unless the Order Form states otherwise. DQ will identify them as such.
4. Accounts, access and acceptable use
4.1Access right. Subject to payment and compliance, DQ grants Customer during the applicable term a limited, non-exclusive, non-transferable and non-sublicensable right for Authorized Users to access and use the Services for Customer’s internal purposes, or for the approved consumer purpose stated in the Order Form.
4.2Account responsibility. Customer is responsible for Authorized Users, secure credentials, user administration, lawful instructions and activity under its accounts, except to the extent caused by DQ. Customer must promptly notify DQ of suspected compromise.
4.3Restrictions. Customer must not, except where mandatory law expressly permits: copy or modify the Services outside the licence; reverse engineer or attempt to discover source code; bypass access or usage controls; rent, resell or provide a service bureau using the Services; interfere with security or availability; upload malicious code; unlawfully scrape, benchmark for publication, or use the Services to build a competing product; or use the Services for unlawful, deceptive, infringing or harmful purposes.
4.4Suspension. DQ may suspend affected access where reasonably necessary to address a security incident, unlawful use, material breach, non-payment after notice, risk to the Service or users, or a legal requirement. Where practicable, DQ will give notice and limit suspension to the affected part. Consumer remedies under mandatory law remain unaffected.
5. Fees, invoicing and taxes
5.1Fees. Customer will pay the Fees stated in the Order Form or SOW. Unless stated otherwise, Fees are exclusive of taxes, bank charges, duties and withholding. A Consumer price presented as tax-inclusive remains tax-inclusive to the extent required by law.
5.2Currency and invoicing. The default currency is USD. An Order Form may state XCG, EUR or another currency. SaaS subscriptions are invoiced annually in advance unless stated otherwise. Project Fees are invoiced by milestone, monthly in arrears for time and materials, or as stated in the SOW.
5.3Payment. Undisputed invoices are due within thirty (30) calendar days of the invoice date. DQ may require advance payment, a deposit or automated payment for a Consumer or where reasonably justified by credit risk.
5.4Invoice disputes. Customer must notify DQ of a good-faith invoice dispute within fifteen (15) days after receipt, describing the disputed amount and reasons. Customer will pay the undisputed portion on time. A shorter objection period will not defeat mandatory Consumer rights.
5.5Late payment. Overdue undisputed amounts accrue interest at 1.5% per month, calculated daily, or the maximum lawful rate if lower, plus reasonable collection costs recoverable by law. DQ will issue any legally required notice or cure period before suspension or acceleration.
5.6No set-off. A business Customer may not set off or withhold payment except for a finally adjudicated claim or DQ’s written consent. This restriction does not apply where prohibited for Consumers.
5.7Price adjustment. At each renewal DQ may adjust recurring Fees on at least sixty (60) days’ notice by the greater of (a) 3% and (b) the percentage increase in a generally recognized consumer-price index reasonably selected for the invoicing currency or Curaçao, but not more than 8%. This cap does not apply to changes in usage, scope, tiers, taxes, exchange rates agreed as pass-through, third-party licence or infrastructure costs, security or regulatory requirements, or Customer-requested changes. If a Consumer faces a material unilateral increase not required by law or directly linked to an agreed objective index, the Consumer may terminate the affected Service before the increase takes effect without an early-termination charge.
6. Intellectual property and licences
6.1DQ ownership. DQ and its licensors retain all right, title and interest in the Services, Deliverables, DQ Materials, Documentation, improvements, configurations, derivative works and all related intellectual-property rights. No ownership transfers to Customer.
6.2Custom Deliverables licence. Upon full payment, DQ grants Customer a perpetual, worldwide, non-exclusive, non-transferable licence to use the final Deliverables identified in the applicable SOW for Customer’s internal business or personal purposes. The licence does not include source code unless expressly stated, and does not permit resale, sublicensing, commercial distribution or creation of a competing offering unless the SOW expressly allows it.
6.3Embedded DQ Materials. DQ Materials embedded in Deliverables are licensed only as necessary to use the Deliverables within the licence scope. DQ may reuse skills, ideas, know-how, generic code, tools, frameworks and non-confidential techniques in other work.
6.4Customer Data and materials. Customer retains ownership of Customer Data and customer-owned materials. Customer grants DQ and its subcontractors a non-exclusive, worldwide licence during the Agreement to host, copy, transmit, transform, display and otherwise process them only as needed to provide, secure, support and improve the Services, comply with law and enforce the Agreement.
6.5Feedback and analytics. Customer grants DQ a perpetual, irrevocable, royalty-free right to use feedback without identifying Customer. DQ may create and use aggregated or de-identified analytics that do not reasonably identify Customer, an Authorized User or a data subject.
6.6Third-Party Materials. Third-Party Materials are subject to applicable third-party terms. DQ will identify material third-party or open-source licensing restrictions relevant to the Deliverables where reasonably practicable.
6.7IP claim remedy. If a third party claims that a paid Service or DQ-authored Deliverable infringes its intellectual-property right, DQ may procure continued use, modify or replace the affected item, or terminate it and refund prepaid Fees for the unused period. This is Customer’s exclusive contractual remedy for such a claim, except where law does not permit limitation. The remedy does not apply to claims caused by Customer Data, Customer specifications, unauthorized combinations or modifications, or use after notice to stop.
7. Customer Data, privacy and security
7.1Customer responsibility. Customer is responsible for the lawfulness, accuracy, quality and required notices, permissions and legal bases for Customer Data and instructions. Customer must not submit special-category, highly regulated or children’s data unless the Order Form and DPA expressly permit it.
7.2DPA. Where DQ processes personal data for Customer as processor or service provider, Schedule 4 applies. Where DQ processes account, billing, security, marketing or relationship data for its own purposes, DQ acts as controller under its privacy notice at [PRIVACY POLICY URL].
7.3Security. DQ will maintain appropriate technical and organizational measures described in Schedule 5, taking account of risk, state of the art and implementation cost. No system is entirely secure, and DQ does not warrant absolute security.
7.4Data regions. Unless the Order Form states otherwise, production Customer Data may be hosted or processed in the European Economic Area and North America, with support or subprocessors potentially located in other regions subject to contractual, technical and legal safeguards described in the DPA. Customer may purchase a stricter region option if offered.
7.5Security incident. DQ will notify Customer without undue delay after confirming a breach of security affecting Customer personal data and will provide reasonably available information and cooperation consistent with the DPA.
8. Confidentiality
8.1Confidential Information means non-public business, technical, financial, security, product, personal or other information disclosed in connection with the Agreement that is marked confidential or should reasonably be understood as confidential. Customer Data, source code, security materials, pricing and product roadmaps are Confidential Information.
8.2The receiving party will use Confidential Information only for the Agreement, protect it with at least reasonable care, and disclose it only to personnel, professional advisers and subcontractors who need to know and are bound by confidentiality obligations.
8.3Confidential Information excludes information the receiving party proves was lawfully known without restriction, independently developed, lawfully received from another source without duty, or public without breach.
8.4Required disclosure is permitted to the extent legally required, provided the receiving party gives advance notice where lawful and reasonably assists with protective measures. On request or termination, Confidential Information will be returned or destroyed, subject to legal retention, backups and the DPA.
8.5These duties continue for five years after disclosure, and indefinitely for trade secrets and personal data for so long as protected by law.
9. Warranties and disclaimers
9.1Mutual. Each party warrants that it has authority to enter the Agreement.
9.2DQ warranty. DQ warrants that paid Services will be performed with reasonable skill and care and that SaaS Services will materially conform to Documentation. Customer must report a reproducible material nonconformity promptly. DQ will use reasonable efforts to correct it, reperform the affected Service or, if not reasonably possible, terminate the affected Service and refund prepaid Fees for the unused period.
9.3Customer warranty. Customer warrants that Customer Data, specifications and instructions may lawfully be provided and used as contemplated, and that Customer’s use complies with the Agreement and law.
9.4Disclaimer. Except for express warranties and mandatory rights, the Services and Deliverables are provided “as is” and “as available”. DQ disclaims implied warranties of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, uninterrupted operation and error-free results to the maximum lawful extent. Outputs must be independently reviewed before use in legal, financial, medical, safety-critical or regulatory decisions.
9.5Consumers. Nothing in the Agreement excludes a statutory guarantee, conformity remedy, cooling-off right or other mandatory protection available to a Consumer.
10. Indemnities
10.1Customer indemnity. A business Customer will defend and indemnify DQ against third-party claims, damages, fines and reasonable costs arising from Customer Data, Customer specifications, unlawful use, breach of clause 4 or violation of third-party rights, except to the extent caused by DQ. This clause does not apply to a Consumer beyond liability imposed by mandatory law.
10.2Procedure. The indemnified party must promptly notify the indemnifying party, allow control of the defence and settlement, and reasonably cooperate at the indemnifying party’s expense. No settlement may admit fault or impose non-monetary obligations on the indemnified party without consent, not to be unreasonably withheld.
11. Limitation of liability
11.1Excluded loss. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, exemplary, punitive or consequential loss, or for loss of profit, revenue, anticipated savings, goodwill, business opportunity or data, even if foreseeable. Costs of restoring Customer Data are direct loss only to the extent caused by DQ’s breach and not avoidable through Customer’s reasonable backup duties or the SaaS backup commitment.
11.2General cap. Each party’s aggregate liability arising from the Agreement in any rolling twelve-month period will not exceed the Fees paid or payable for the affected Services during the twelve months immediately before the event giving rise to liability. For a free Service, DQ’s aggregate liability is USD 100.
11.3Elevated cap. DQ’s aggregate liability for breach of confidentiality, data-protection obligations, security obligations or its IP defence obligation will not exceed two times the general cap.
11.4Uncapped or non-excludable matters. Nothing limits liability that cannot lawfully be limited, including liability for fraud or wilful misconduct, death or personal injury caused by negligence where applicable, or Customer’s obligation to pay Fees. Gross negligence and mandatory Consumer liability are excluded from a cap only to the extent required by applicable law.
11.5Allocation. The exclusions and caps apply in contract, tort, statute, indemnity and otherwise, are cumulative across the Agreement and reflect the Fees and risk allocation. Each party will take reasonable steps to mitigate loss.
12. Term, renewal, termination and exit
12.1Subscription term. Unless the Order Form states otherwise, a SaaS subscription begins on the Effective Date and continues for twelve (12) months. It automatically renews for successive twelve-month periods unless either party gives at least sixty (60) days’ written non-renewal notice before the current term ends.
12.2Consumer renewal notice. Where required by law, DQ will send a Consumer a clear renewal reminder and provide any required cancellation mechanism or right. Mandatory rights override the notice period above.
12.3Project term. A SOW continues until completion or earlier termination. Termination for convenience is permitted only if stated in the SOW. Customer remains liable for completed work, committed non-cancellable costs and reasonable wind-down costs.
12.4Termination for cause. Either party may terminate an affected Order Form for a material breach not cured within thirty (30) days after written notice. DQ may use a ten-day cure period for undisputed non-payment after the due date, subject to required Consumer notices. Either party may terminate immediately for insolvency or unlawful performance, to the extent permitted by law.
12.5Effect. On termination, access and licences ending with the term cease, accrued payment obligations become due, and each party will return or destroy Confidential Information as required. Perpetual Deliverable licences survive if fully paid. Clauses intended by nature to survive remain in effect.
12.6Data export and deletion. Customer may export available Customer Data using standard features before termination. On written request within sixty (60) days after termination, DQ will make a standard export available where technically feasible. DQ may charge reasonable costs for special assistance. DQ will delete Customer Data from active systems within thirty (30) days after the export window, subject to law, disputes and backup rotation. Schedule 4 controls for personal data.
13. Service changes and changes to terms
13.1Service evolution. DQ may update the Services to improve security, functionality, legal compliance or performance, provided it does not materially reduce the core paid functionality during a committed term without offering a commercially reasonable alternative or termination right for the affected Service.
13.2Terms changes. DQ may amend these General Terms on at least sixty (60) days’ notice for future renewals. Material changes during a committed term require Customer consent, except changes needed for law, security, abuse prevention or third-party requirements where delay is not reasonably possible. A Consumer may terminate before a materially adverse unilateral change takes effect, unless the change is legally required and termination is not required by law.
14. Compliance, export and third-party services
14.1Each party will comply with applicable law. Customer must not use the Services in violation of sanctions, export-control, anti-bribery or anti-money-laundering laws. DQ may request information reasonably needed for compliance screening.
14.2Third-party services and integrations are governed by their own terms. DQ is not responsible for third-party services, changes or data handling outside DQ’s control, but DQ remains responsible for its selected subprocessors as provided in the DPA.
14.3Customer is responsible for deciding whether the Services are suitable for regulated or high-risk use and for obtaining required approvals. The Order Form must identify any specific regulatory requirement DQ has agreed to support.
15. Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disasters, epidemic, war, civil disorder, labour disruption, governmental action, widespread internet or utility failure, cyberattack not caused by failure to maintain agreed security, or critical supplier failure. The affected party will notify the other, mitigate and resume performance. Payment for Services already provided is not excused. If material force majeure continues for sixty (60) days, either party may terminate the affected Service on written notice.
16. Notices
Contractual notices must be in writing. Notices to DQ must be sent to [LEGAL-NOTICE EMAIL] and, for formal service where required, to Groot Kwartierweg 2 A, Curaçao. Notices to Customer may be sent to the legal, administrative or billing contact in the Order Form. Email notices are deemed received on the next business day if no delivery failure is received. Termination, claims and dispute notices should clearly state their purpose.
17. Governing law and disputes
17.1Governing law. The Agreement is governed by the laws of Curaçao, without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
17.2Good-faith escalation. Before filing proceedings, the parties will attempt in good faith for thirty (30) days to resolve a dispute through representatives authorized to settle. A party may seek urgent interim relief at any time.
17.3Default forum: Curaçao courts. Unless the Order Form validly selects arbitration, the courts of Curaçao have exclusive jurisdiction. Nothing deprives a Consumer of a mandatory right to bring or defend proceedings in another competent court.
17.4Optional arbitration. If the Order Form expressly selects “NAI Arbitration”, and arbitration is enforceable against the relevant Customer, all disputes arising out of or relating to the Agreement will be finally resolved under the Arbitration Rules of the Netherlands Arbitration Institute. The seat is Willemstad, Curaçao; the tribunal consists of one arbitrator; the language is English; and hearings may be remote. Consumer disputes will not be arbitrated unless the Consumer validly agrees after the dispute arises or applicable mandatory law clearly permits the pre-dispute clause.
18. General provisions
18.1Assignment. Customer may not assign the Agreement without DQ’s consent, not to be unreasonably withheld for a bona fide business reorganization. DQ may assign to an affiliate or in connection with a merger, financing, reorganization or sale of substantially all relevant business assets, subject to continued performance and applicable Consumer law.
18.2No agency. The parties are independent contractors. The Agreement creates no partnership, joint venture, fiduciary, employment or agency relationship.
18.3Entire agreement. The Agreement is the entire agreement about its subject and supersedes prior proposals and communications. Fraudulent misrepresentation and mandatory rights are unaffected.
18.4Severability. An invalid provision will be limited or replaced to the minimum extent necessary to make it enforceable while preserving intent, and the remainder continues.
18.5Waiver. A waiver must be in writing and is limited to the specific instance. Delay is not a waiver.
18.6Electronic contracting. Signatures, check-box acceptance and electronically stored records may be used to form and evidence the Agreement to the extent permitted by law.
18.7Language. The controlling language is English. A translated version is for convenience unless mandatory law states otherwise.
Order Form and Commercial Elections
| Field | Details |
|---|---|
| Customer legal name / Consumer name | [INSERT] |
| Registration or ID information | [INSERT OR NOT APPLICABLE] |
| Address and country | [INSERT] |
| Billing contact and email | [INSERT] |
| Legal-notice email | [INSERT] |
| Service / product | [INSERT] |
| Effective date | [INSERT] |
| Currency | ☐ USD ☐ XCG ☐ EUR ☐ Other: ____ |
| Initial subscription term | 12 months, unless stated: ____ |
| Renewal | Automatic 12-month renewal |
| Non-renewal notice | 60 days |
| Invoicing | ☐ Annual advance ☐ Monthly advance ☐ Milestone ☐ T&M monthly arrears |
| Payment term | 30 calendar days |
| Hosting region option | ☐ EEA + North America ☐ EEA primary ☐ Other agreed region: ____ |
| Service tier | ☐ Standard ☐ Enhanced ☐ Enterprise |
| Dispute forum | ☐ Curaçao courts (default) ☐ NAI arbitration, Willemstad, where legally valid |
| Consumer status | ☐ Business ☐ Consumer |
| Schedules activated | ☐ SaaS ☐ Custom Software SOW ☐ DPA ☐ Security/TOMs ☐ AUP |
| Special terms / deviations | [Identify clause and replacement wording] |
Acceptance: By signing or electronically accepting this Order Form, Customer confirms that it received or could access the Agreement documents before acceptance and agrees to them, subject to mandatory law.
| For DQ Solutions B.V. | For Customer |
|---|---|
| Name: ____________________ | Name: ____________________ |
| Title: _____________________ | Title: _____________________ |
| Date/signature: ____________ | Date/signature: ____________ |
SaaS Service, SLA and Support
1. SaaS scope and licence
The SaaS Service, modules, usage metrics, tenant, Authorized User limits, integrations and Documentation are stated in the Order Form. Customer receives the access right in clause 4 of the General Terms. Usage above purchased limits may be blocked or invoiced at the then-current overage rate after reasonable notice.
2. Availability commitment
DQ targets 99.0% Monthly Uptime for production SaaS Services. “Monthly Uptime” means total minutes in a calendar month minus Excluded Downtime, divided by total minutes minus Excluded Downtime, multiplied by 100.
Excluded Downtime includes: announced maintenance; emergency maintenance; Customer systems, actions or credentials; third-party integration failure not under DQ’s control; internet or telecommunications failure outside DQ’s boundary; force majeure; suspension permitted by the Agreement; beta features; and failure caused by Customer’s failure to meet documented technical requirements.
DQ will ordinarily give at least forty-eight (48) hours’ notice for planned maintenance expected to materially affect availability and will schedule it outside normal business hours where reasonably practicable.
3. Service credits
| Monthly Uptime | Credit on affected monthly recurring SaaS Fee |
|---|---|
| 99.0% or above | No credit |
| 98.0% to <99.0% | 5% |
| 95.0% to <98.0% | 10% |
| Below 95.0% | 20% |
Customer must request a credit within thirty (30) days after the affected month and provide reasonably sufficient details. Credits apply to future invoices, are not cash refunds, and are the sole contractual remedy for uptime failure, except for termination rights, Consumer rights, wilful misconduct or liability that cannot be limited. Total credits for a month cannot exceed 20% of the affected monthly recurring Fee.
4. Support levels
| Priority | Description | Initial response target | Update target |
|---|---|---|---|
| P1 Critical | Production unavailable for most users, material security event, or critical data integrity issue with no workaround | 12 business hours, with commercially reasonable continuous efforts during support hours | At least daily |
| P2 High | Material function unavailable for multiple users; significant degradation; workaround limited | 1 business day | Every 2 business days |
| P3 Standard | Non-critical defect, configuration, usability or integration issue | 2 business days | As reasonably available |
| P4 Request | How-to, enhancement or general inquiry | 2 business days | As reasonably available |
Standard support is provided by email and chat during DQ’s published business hours, excluding Curaçao public holidays. Enhanced or 24x7 options apply only if purchased. Response targets are objectives, not guaranteed resolution times.
5. Backup, recovery and continuity
DQ will maintain routine backups appropriate to the Service. For a confirmed data-loss incident within DQ’s control, DQ targets restoration of available backup data within thirty-six (36) hours after remediation makes restoration safe and technically feasible. This is a recovery target, not a guarantee. Customer remains responsible for exporting and retaining records required for its legal or business continuity needs.
6. Data regions and subprocessors
Default processing regions are the EEA and North America. Support access and subprocessors may involve other countries under the DPA. Current material hosting providers, subprocessors and locations will be listed at [SUBPROCESSOR URL] or in the Order Form. DQ will provide change notice and an objection process under Schedule 4.
7. Exit
Standard export formats will be described in Documentation. Special migration, transformation, validation or extended retention is professional services charged at current rates. Customer should complete exports before access ends.
Custom Software Statement of Work Template
| Project field | Project-specific entry |
|---|---|
| Project name | [INSERT] |
| Business objective | [INSERT] |
| Deliverables | [INSERT] |
| Out of scope | [INSERT] |
| Customer dependencies | [INSERT] |
| Milestones and target dates | [INSERT] |
| Project method | ☐ Agile ☐ Phased ☐ Other: ____ |
| Fees and invoicing | [INSERT] |
| Acceptance criteria | [OBJECTIVE, TESTABLE CRITERIA] |
| Acceptance period | 10 business days after delivery |
| Warranty period | 30 days after acceptance for material conformity defects |
| Source-code delivery | ☐ No ☐ Yes, limited to: ____ |
| Licence purpose / entities / users | [INSERT] |
| Third-Party Materials | [INSERT OR LINK TO BILL OF MATERIALS] |
| Support after acceptance | [INSERT OR SaaS/SUPPORT ORDER] |
| Special security or data requirements | [INSERT] |
1. Project governance
Each party will appoint a project lead. The leads will manage decisions, risks, dependencies and status. A project lead cannot amend Fees, liability, ownership or licence scope unless expressly authorized.
2. Delivery and acceptance
DQ will notify Customer when a Deliverable is ready for acceptance testing. Customer will test it against the stated criteria within ten (10) business days and either accept it or provide one consolidated written rejection identifying reproducible material nonconformities. DQ will correct verified nonconformities and resubmit. The Deliverable is accepted when Customer accepts in writing, uses it in production other than for testing, or fails to provide a valid rejection within the acceptance period. Deemed acceptance does not remove mandatory Consumer remedies.
Minor defects that do not materially prevent intended use do not delay acceptance and will be addressed through an agreed remediation plan.
3. Agile work
For agile work, approved backlog items, sprint goals, demonstrations and written product-owner decisions form part of the scope record. Estimates are not fixed commitments unless the SOW expressly states a fixed price and fixed acceptance criteria.
4. Change requests
A change request must describe the requested change, reason, priority and desired date. DQ will assess impact on Fees, timing, architecture, security and dependencies. Work begins after written approval, except emergency work needed to prevent material harm.
5. IP and licence
DQ retains ownership under clause 6 of the General Terms. The SOW may expand the Customer licence by expressly stating distribution, affiliate use, source-code access, escrow, white-labelling or sublicensing rights. Silence means the standard internal-use licence applies.
6. Maintenance and warranty
During the stated warranty period, DQ will correct at no additional charge reproducible material defects causing a Deliverable not to meet accepted criteria. The warranty excludes changes in Customer or third-party systems, unauthorized modifications, misuse, unsupported environments and new requirements. Ongoing maintenance requires a support or SaaS order.
Data Processing Addendum
This DPA applies when DQ processes Personal Data on behalf of Customer. Capitalized privacy terms have the meanings assigned by Applicable Data Protection Law.
1. Roles, scope and instructions
Customer is controller, or processor for its own controller; DQ is processor or subprocessor. DQ will process Personal Data only on documented Customer instructions, including the Agreement and Annex A, unless law requires otherwise. DQ will notify Customer if an instruction appears to violate Applicable Data Protection Law, unless prohibited by law.
2. Compliance and confidentiality
Each party will comply with its applicable obligations. DQ will ensure persons authorized to process Personal Data are bound by confidentiality and have access only as needed.
3. Security
DQ will implement and maintain the measures in Schedule 5. DQ may update measures if the overall level of security is not materially reduced. Customer is responsible for secure configuration, access administration, lawful data, endpoints and instructions.
4. Subprocessors
Customer generally authorizes DQ to use subprocessors. DQ will impose materially equivalent data-protection obligations and remains responsible for their performance to the extent required by law. DQ will maintain a current list at [SUBPROCESSOR URL] and give at least thirty (30) days’ notice of a new material subprocessor where practicable. Customer may object on reasonable data-protection grounds during that period. The parties will seek a reasonable solution. If none is available, Customer may terminate only the affected Service without penalty before the new subprocessor begins processing, and DQ will refund prepaid Fees for the unused affected period.
5. International transfers and data regions
Personal Data may be processed in the EEA and North America and, through support or subprocessors, in other locations listed in Annex C. DQ will use a lawful transfer mechanism required by Applicable Data Protection Law, which may include adequacy decisions, approved standard contractual clauses, binding corporate rules or another valid safeguard. Where Customer is subject to GDPR or UK GDPR, the applicable approved clauses are incorporated by reference if needed for a restricted transfer.
6. Data-subject rights and assistance
DQ will promptly forward a request received from a data subject relating to Customer-controlled Personal Data and will not respond except on documented instruction or as legally required. Taking account of processing nature, DQ will provide reasonable assistance with rights requests, impact assessments, prior consultation and compliance information. DQ may charge reasonable costs for assistance beyond standard functionality unless caused by DQ’s breach.
7. Security incidents
DQ will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice will include information reasonably available about nature, likely consequences, affected data and subjects, mitigation and contact details. DQ’s notice is not an admission of fault. DQ will take reasonable containment and remediation measures and assist Customer with legally required notifications.
8. Deletion and return
During the Service, Customer may use standard export functions. After termination, DQ will return or make Personal Data available for export as described in clause 12.6 and will delete it from active systems within the stated period, unless law requires retention. Backup copies will be protected and deleted through ordinary rotation.
9. Audit
DQ will provide available certifications, summaries or reports reasonably sufficient to demonstrate compliance. If legally required and those materials are insufficient, Customer may conduct one audit per year on at least thirty (30) business days’ notice, during business hours, without disrupting operations and subject to confidentiality and security restrictions. Customer bears audit costs unless the audit identifies DQ’s material breach.
10. Liability and precedence
Liability under this DPA is governed by clause 11 of the General Terms and counts toward the same caps. This DPA prevails for data-protection matters. Mandatory data-protection law prevails where inconsistent.
Annex A | Processing details
| Item | Description |
|---|---|
| Subject matter | Provision, hosting, support, security, maintenance and improvement of the ordered Services |
| Duration | For the Agreement term plus return, deletion and retention period |
| Nature and purpose | Collection, hosting, organization, retrieval, transmission, support, security, backup, analytics and deletion as instructed |
| Data subjects | Customer personnel, Authorized Users, Customer clients, suppliers, contractors, website/app users, and other persons whose data Customer submits |
| Personal Data | Identity, contact, account, authentication, usage, device, support, transaction, financial and other data configured by Customer |
| Special categories | Not permitted unless expressly stated in the Order Form and supported by additional safeguards |
| Customer instructions | Agreement, configuration, support requests and other documented lawful instructions |
| DQ privacy contact | [PRIVACY / DPO EMAIL] |
Security and Technical & Organizational Measures
| Control area | Baseline commitment |
|---|---|
| Governance | Documented security responsibilities, risk-based policies and periodic review. |
| Personnel | Confidentiality obligations, role-appropriate screening where lawful, awareness training and access termination. |
| Access control | Unique accounts, least privilege, privileged-access restriction, authentication controls and periodic access review. |
| Encryption | Encryption in transit using industry-standard protocols; encryption at rest where supported and appropriate to risk. |
| Development | Change control, code review or equivalent quality controls, dependency management and separation of environments where appropriate. |
| Vulnerability management | Reasonable scanning, patching, remediation prioritization and security testing based on risk. |
| Logging and monitoring | Security-relevant logging and monitoring appropriate to the Service, with retention aligned to operational and legal needs. |
| Availability | Backups, restoration procedures, redundancy or recovery measures appropriate to the purchased Service. |
| Incident response | Documented assessment, containment, remediation and notification process. |
| Supplier security | Risk-based diligence and contracts for material subprocessors. |
| Physical security | Reliance on hosting providers’ controlled facilities for cloud infrastructure; reasonable controls for DQ offices and devices. |
| Data lifecycle | Retention, export and deletion controls consistent with the Agreement and DPA. |
| Testing and assurance | Periodic review of control effectiveness; certifications or independent reports where DQ elects or the Order Form requires. |
Customer-specific controls, certifications, recovery objectives, penetration-test reports, encryption-key ownership, dedicated tenancy or regulated-industry requirements apply only if expressly included in the Order Form.
Acceptable Use Policy
Customer and Authorized Users must not use the Services to:
violate law, sanctions, export controls, privacy rights or intellectual-property rights;
upload malware, ransomware, destructive code or content designed to disrupt systems;
gain unauthorized access, probe or test vulnerabilities without written permission, or bypass security controls;
send spam, phishing, deceptive communications or unlawful marketing;
process content that is unlawful, fraudulent, defamatory or infringing;
perform high-volume scraping, denial-of-service activity or usage that materially harms other users;
misrepresent identity or authority, share accounts, or disclose credentials;
use outputs as the sole basis for high-impact legal, credit, employment, insurance, medical or safety decisions without qualified human review and a lawful basis;
permit access by competitors for competitive analysis, copy product elements or build a substitute service; or
use a beta or AI-enabled feature contrary to its Documentation or any stated prohibited-use rule.
DQ may investigate credible misuse, preserve evidence, remove or restrict affected content or access, and cooperate with lawful authorities. Where practicable, DQ will provide notice and an opportunity to remedy. Measures will be proportionate to risk and subject to mandatory Consumer rights.
Consumer Information and Cancellation Form
This Schedule supplements, and does not replace, mandatory Consumer law. It applies only to a Customer who is a Consumer.
1. Pre-contract information
Before acceptance, DQ will provide clear information on DQ’s identity and contact details, the main characteristics and compatibility of the Service, total price and billing frequency, term and renewal, functionality and technical protection measures where relevant, complaint handling, cancellation method and any statutory withdrawal right that applies.
2. Digital performance and withdrawal
If a Consumer asks DQ to begin supplying digital content or services during a statutory withdrawal period, DQ will obtain any consent and acknowledgment required by law. If mandatory law grants a withdrawal right, the Consumer may exercise it within the legally prescribed period. Any lawful charge for performance before withdrawal will be proportionate and disclosed.
3. Conformity and remedies
DQ will provide all mandatory conformity, repair, replacement, price reduction, termination or refund remedies. Contractual limits do not reduce these rights.
4. Complaints
Complaints may be sent to [SUPPORT EMAIL] and legal notices to [LEGAL-NOTICE EMAIL]. DQ will acknowledge and address complaints within a reasonable period. A Consumer remains free to use any competent authority, court or mandatory dispute process.
5. Model cancellation / withdrawal notice
| To: DQ Solutions B.V., Groot Kwartierweg 2 A, Curaçao, [LEGAL-NOTICE EMAIL] I hereby give notice that I cancel / withdraw from my contract for: __________________________ Ordered / activated on: __________________________ Consumer name: _________________________________ Consumer address: _______________________________ Account email: __________________________________ Date: __________________ Signature, if on paper: __________________ |
|---|