RotoSuite — General terms and conditions Version 1.0 · 17 September 2026 https://rotosuite.com/en/terms Company details are being completed. The fields in square brackets will be replaced with the legal company name, registered address and Chamber of Commerce number. Dutch law applies. These terms are intended for business contracts for RotoSuite. Together with the accepted quotation or order and any data processing agreement, SLA and project schedules, they form the contractual framework. Visiting this website or requesting a demonstration does not create a subscription. 1. Parties and definitions Provider: [COMPANY_NAME], located at [REGISTERED_ADDRESS], Netherlands Chamber of Commerce number [KVK_NUMBER], providing RotoSuite. Customer: the legal entity or individual acting in a professional or business capacity that enters the agreement. User: a person authorised to access the service for the customer. Service: agreed access to RotoSuite and activated modules, including agreed support. Customer data: information supplied by or for the customer and content generated for the customer. Agreement: the accepted order and documents incorporated into it. Writing includes email and other durable electronic communications. An SLA contains only expressly agreed service levels. 2. Application and contract formation These terms apply when made available and incorporated before or when the agreement is concluded. They are for business use, not consumer subscriptions. Departures apply when agreed in writing by authorised representatives. An agreement arises through written acceptance of a sufficiently definite offer or a mutually confirmed order. The order identifies at least the parties, modules, scope, price, start date and duration. A quotation remains open for its stated period; without a stated period, separate confirmation by RotoSuite is required. The customer warrants its representative’s authority. Customer purchasing terms apply only if expressly accepted in writing by RotoSuite. A website link does not replace the applicable obligation to provide terms at contract formation. 3. Document priority and interpretation Mandatory law always prevails. For personal data, mandatory transfer provisions take priority, followed by the specific data processing agreement. For other conflicts, priority is: the signed or accepted order and express departures; the applicable SLA or project schedule for its subject; and these terms. The privacy notice explains processing and does not authorise new processing. Marketing, screenshots, demonstrations and roadmaps do not promise unagreed functionality, outcomes or service levels. The order’s designated contract language prevails between translations; otherwise the Dutch version prevails insofar as legally permitted. 4. Scope of the SaaS service Customers receive access to agreed modules and capacity for the agreed term. Users, organisations, sites, storage, transactions, AI consumption, integrations and limits are specified in the order or service description. Not every advertised feature is included in every subscription. RotoSuite performs agreed work with appropriate care and professional skill. Work without an expressly agreed result is subject to a reasonable-efforts obligation. The service supports operations; customers remain responsible for operating their business, decisions, statutory records and physical processes. 5. Use rights and access management RotoSuite grants a non-exclusive, non-transferable right to use the service for agreed internal business purposes and authorised users during the term. Affiliates, external parties and third-party service delivery are permitted within the agreed scope. Customers acquire neither ownership of the software nor source-code rights. Customers appoint authorised administrators, assign appropriate roles and promptly revoke access after departure or role changes. Users keep credentials confidential, use suitable additional authentication where available and promptly report suspected misuse. Shared accounts and circumventing licence limits are prohibited unless expressly agreed as functional accounts. Customers are responsible for authorised users within their control. This does not remove RotoSuite’s responsibility for its own access security, errors or attributable unauthorised access. 6. Implementation, migration and cooperation Configuration, migration, custom work, training and integrations are included only as agreed. Parties document assumptions, dependencies, responsibilities, planning, acceptance criteria and any fixed milestones. Customers provide accurate source data, authorised contacts, access and decisions on time. Customers determine which data may lawfully be migrated and retain usable source copies. Parties coordinate validation and go-live. Outdated files, missing documentation or scope changes may affect price and timing; RotoSuite explains consequences before additional work. Extra work requires written agreement on scope and price or calculation method. Customer delay does not permit unlimited charges. Expressly agreed final deadlines remain binding; other schedules are estimates, with an obligation to communicate material delay. 7. Delivery and acceptance For a project or custom deliverable with an acceptance procedure, the customer carries out agreed checks and reports specific departures from acceptance criteria. Without an agreed period, the customer has ten working days after a clear delivery notice to report them. Acceptance and outstanding items are documented. Silence does not automatically accept a material defect. Minor issues that do not materially prevent normal use need not block go-live where reasonable correction arrangements exist. Acceptance does not waive latent-defect claims or continuing obligations. 8. Support and service levels Support channels, hours, priorities, availability, response times, recovery targets and credits apply as specified in the order or SLA. Without a specific SLA, there is no promise of round-the-clock support, complete availability or guaranteed resolution times. RotoSuite handles reported incidents with care and prioritises by urgency and impact. Customers provide sufficient diagnostic information without unnecessary sensitive data. A response target does not guarantee resolution within that time. An SLA should specify measurement, maintenance windows, exclusions and escalation. Credits limit other remedies only where expressly and validly agreed. A supplier outage is not automatically force majeure. 9. Maintenance and service changes RotoSuite may maintain, secure and develop the service. Planned maintenance with noticeable effects is announced in advance where reasonably possible, with regard to business operations. Urgent security issues may require immediate action and notification as soon as appropriate. Changes must not materially reduce agreed core functionality or security without an appropriate solution. RotoSuite gives timely notice of significant changes, consequences and alternatives. If a material deterioration is not resolved within a reasonable time, customers may terminate the affected part and request a proportionate refund of unused prepaid charges. Customers maintain supported browsers, devices and suitable connectivity. Customer-managed integrations may need adjustment; substantial additional work is agreed beforehand. 10. Acceptable use and security research Customers and users must act lawfully and respect third-party rights. Malicious code, unauthorised access, circumventing security or limits, disruption of other environments, unlawful spam and unlawful content are prohibited. Reverse engineering, copying or reuse of software components is permitted only under a non-excludable statutory right or RotoSuite’s permission. Security testing affecting availability or other parties’ information requires prior written coordination. Vulnerabilities may be reported confidentially; researchers must not unnecessarily collect, alter or disclose information. RotoSuite investigates misuse proportionately. Where possible, measures target the affected user, function or information, with an explanation where law and security permit. 11. Customer data and content rights Rights in customer data remain with the customer or relevant third parties. RotoSuite receives only the permissions necessary to provide, secure and support the agreed service, not a general licence to sell, publish or independently commercialise content. Customers ensure lawful sources, an appropriate lawful basis, required notices and authority to instruct processing. They determine the accuracy and completeness of their business records. RotoSuite remains responsible for correctly following instructions and implementing its agreed measures. Aggregated information is anonymous only where individuals and confidential customer content cannot reasonably be identified. Pseudonymisation does not automatically anonymise personal data. Reuse outside the agreement requires a separate lawful arrangement. 12. Privacy and processing arrangements Before processing personal data for the customer, the parties conclude an Article 28 GDPR processing agreement specifying subject, duration, nature, purpose, data categories, individuals, instructions, security, subprocessors, locations, transfers and termination. These terms do not replace that operational specification. RotoSuite processes only on documented instructions unless legally required otherwise. It informs the customer before legally required processing unless prohibited, and flags instructions it considers contrary to applicable data protection law so a lawful solution can be agreed. Authorised personnel are bound by confidentiality. RotoSuite provides agreed and legally required assistance with rights requests, security, breaches, impact assessments and supervisory consultations. At the end, information is returned or deleted at the customer’s choice, subject to statutory exceptions and agreed backup expiry. Customers may obtain information and reasonable audits to assess compliance. Planning, confidentiality and protection of other customers may be arranged, but statutory audit and supervisory rights cannot be made ineffective. Charges must not obstruct mandatory cooperation. 13. Subprocessors and international processing Subprocessors require the specific or general written authorisation set out in the processing agreement. Under general authorisation, RotoSuite gives advance notice of additions or replacements, allowing reasonable data-protection objections. Parties seek a workable solution before the processing concerned begins. Appropriate equivalent data protection obligations bind subprocessors. RotoSuite remains responsible to the customer for their obligations as required by the GDPR. A provider independently contracted by the customer does not become RotoSuite’s subprocessor merely through an integration. Transfers outside the EEA require a lawful mechanism and, where necessary, safeguards, assessment and supplementary measures. Parties, locations and transfer mechanisms are documented. These terms make no unverified promise that every module processes data exclusively within one country or region. 14. Security responsibilities RotoSuite implements appropriate technical and organisational measures, taking account of risk, available technology, and the service’s nature and scope. The service-specific security schedule describes measures and additional customer requirements. Certifications and standards are contractual promises only where expressly agreed. Customers secure their devices, networks, identities, integrations and permissions and appropriately use available security features. Both parties promptly report relevant vulnerabilities and incidents and help mitigate impact. Absolute security cannot be guaranteed; appropriate security obligations remain. 15. Incidents and personal data breaches RotoSuite informs the customer without undue delay after becoming aware of a personal data breach affecting processing on its behalf. The initial notice contains available relevant facts, followed by further information where necessary. Operational contacts and any shorter reporting periods are agreed in the processing agreement. RotoSuite assists investigation, mitigation and documentation. The customer, as controller, assesses notification to authorities and individuals. Internal investigation must not unnecessarily delay mandatory notification. Communications concerning the other party are coordinated unless legal duties or necessary urgency prevent this. 16. Backups, recovery and continuity Backup scope, frequency, retention and recovery capabilities are specified in the service description or SLA. Recovery time and recovery point objectives apply only if expressly agreed. Infrastructure backup does not automatically provide an individual archive or restoration of every deleted file. Customers identify continuity and statutory archiving requirements before use. Parties agree exports, restoration exercises and contingency arrangements where needed. RotoSuite’s agreed backup and recovery duties remain. Both parties assist recovery and prevent further damage following loss or corruption. 17. AI and generated results AI features are provided for the agreed use and configuration. Outputs may contain errors, omissions or incorrect citations and may not be unique. Customers organise human review before important business, employment, safety or quality decisions. Prohibited AI practices are not permitted. Uses subject to additional legal requirements, including certain employment, biometric or safety functions, require prior assessment of intended use, roles, documentation and obligations. A generic feature is not confirmation that every use is lawful. Where relevant, parties specify the model provider, transferred data, retention and applicable terms. Customer content must not train general-purpose models without a separate lawful, documented arrangement. Output rights depend on law and agreed provider terms; RotoSuite does not guarantee exclusive copyright in every output. The party with the relevant statutory role organises required transparency and appropriate user competence. Obligations imposed directly on RotoSuite are not shifted exclusively to the customer. 18. Production, safety and employee monitoring RotoSuite supports processes and information. Without a specific written agreement and appropriate assessment, it is not a certified machine safeguard, emergency-stop system, medical device or autonomous safety system. Customers must maintain appropriate physical safeguards, checks, maintenance and emergency procedures. Customers ensure lawful, proportionate configuration of cameras, meeting recordings, phishing exercises, staff assessments and monitoring. This may require notices, employee representation procedures, impact assessment, access restrictions and retention rules. A technical capability does not replace required permission or legal authority. Machine integrations must identify the information read and whether control is affected. Deployments affecting physical processes require controlled validation with responsible specialists. 19. External services and integrations Providers contracted directly by customers retain their own terms and privacy arrangements. Customers obtain required licences, access and permissions. RotoSuite explains the agreed integration’s boundaries and does not guarantee third-party functions beyond its control. If a third-party API, price or service changes, parties discuss effects and alternatives. Additional charges require a contractual basis or prior agreement. RotoSuite remains responsible under the agreement and law for suppliers it engages to fulfil its own obligations. 20. Prices, consumption and price changes The order specifies prices, currency, billing intervals, included consumption and one-off charges. Business prices exclude VAT and applicable taxes unless stated otherwise. Usage-based AI, storage or external messaging requires an agreed rate or transparent calculation method. RotoSuite communicates foreseeable limit overruns where reasonably possible. Additional consumption does not authorise unlimited charges. Fixed prices during a fixed term change only under previously agreed indexation or a new written agreement. New prices for a subsequent term may be proposed at least sixty days in advance, allowing genuine review and cancellation before they apply. Without an agreed adjustment mechanism, there is no unrestricted right to increase prices during the current term. 21. Invoices and payment Unless the order states otherwise, invoices are payable within thirty days. Customers promptly explain invoice disputes. Undisputed amounts remain payable. A short complaint period does not automatically extinguish statutory rights. After written reminder and a reasonable cure period, applicable statutory commercial interest and reasonable legally permitted collection charges may be claimed. Service suspension additionally requires the procedure and assessment in the suspension clause. Inability to pay is not itself force majeure. 22. Duration, renewal and ordinary termination The order specifies the start and initial term. Without an express fixed term, the agreement is indefinite and terminable in writing on one month’s notice. Trials do not silently become paid subscriptions without prior agreement. Automatic renewal of a fixed term requires the order to state the renewal duration and notice period expressly. Otherwise the fixed term expires unless continuation is agreed. Notice may be sent to the designated contract contact or our contact addresses and will be acknowledged. Mandatory rights to switch data processing services remain available despite longer commercial terms. Early termination charges require transparent, lawful advance agreement and must not undermine statutory switching rights. 23. Temporary suspension RotoSuite may proportionately restrict access where necessary for a serious security risk, unlawful use, legal duty or material breach continuing after written warning and a reasonable cure period. Immediate threats may require action first, with explanation as soon as appropriate. Where possible, restrictions target the affected part. Parties cooperate in recovery and mitigation. Suspension does not automatically permit destruction of customer data or obstruction of statutory export rights. Access is restored without unnecessary delay once the cause is resolved. 24. Termination for breach Either party may terminate all or part of the agreement for a sufficiently serious attributable breach after written notice and a reasonable cure period, unless performance is permanently impossible or notice is not legally required. The extent of termination must be proportionate. Insolvency, cessation and similar events are subject to statutory rights and restrictions. Mandatory insolvency or continuity rules cannot be excluded. Following termination for RotoSuite’s breach, prepaid undelivered parts are refunded proportionately without prejudice to other valid claims. 25. Switching, export and the EU Data Act Where Chapter VI of the EU Data Act applies, these arrangements override conflicting terms. Customers may switch to another provider or their own infrastructure, or request deletion. Notice to start switching is no more than two months; the following transition normally lasts no more than thirty calendar days. If technically infeasible, RotoSuite supplies reasons within fourteen working days of the request and an alternative transition of no more than seven months. Customers have the right to extend once for a period they consider appropriate for their purposes. RotoSuite provides reasonable assistance, protects security and continuity and explains known risks. At least thirty calendar days are available for retrieval after transition. Until 12 January 2027, advance-disclosed switching charges may not exceed legally permitted actual costs. From that date, switching charges, including necessary data egress, do not apply. Regular service fees and separately ordered extras are distinguished; mandatory assistance cannot be relabelled optional work. Statutory exceptions for certain custom or non-production services apply only where their conditions are met and customers receive appropriate advance information. 26. Export and deletion arrangements Exit arrangements specify exportable inputs, outputs, metadata and digital assets, formats, access methods, dependencies, responsibilities and technical limits. Before contracting, RotoSuite provides legally required service information, including the applicable online register of data structures and export formats. A module description does not promise one-to-one portability of every screen or external integration. Protected internal software, trade secrets and other customers’ information need not be supplied where statutory exceptions permit, without obstructing effective switching. Common machine-readable formats and required interfaces are provided where mandated. Parties coordinate authorisation and secure transfer. For a statutory switch, the affected agreement ends on successful completion of switching; if the customer chooses deletion only, it ends when the applicable notice period expires. RotoSuite notifies the customer of termination. Other endings follow the order. After the retrieval period, relevant customer data is deleted except for necessary statutory retention. Backup expiry, deletion confirmation and continuing services are documented. Confidentiality and security continue throughout exit and for remaining copies. 27. Intellectual property and infringement claims RotoSuite, software, documentation, designs and generic improvements remain owned by RotoSuite or licensors. Payment for custom work alone does not transfer ownership; assignment or broader licensing requires a separate written agreement. Customers retain rights in their content and supplied materials. For a substantiated claim that the unchanged, agreed service infringes intellectual property, parties notify and reasonably assist one another. RotoSuite may secure usage rights, provide a functionally suitable alternative or terminate the affected part and refund unused prepaid charges. The liability provisions remain applicable. This remediation does not apply insofar as claims result from unlawful customer content, unagreed modifications or out-of-scope use. Neither party may settle claims imposing admissions, payments or duties on the other without consent. 28. Confidentiality and references Parties protect information designated confidential or confidential by nature, use it only to perform the agreement, and share it only with people or advisers needing access and subject to suitable confidentiality duties. Exceptions cover information demonstrably already lawfully known, publicly available without breach, independently developed or lawfully received from a third party. Legally required disclosure remains possible, limited to necessity and with prior notice where permitted. Confidentiality survives while information remains confidential; statutory and processing duties also apply to personal data. RotoSuite will not use the customer’s name, logo or case study as a public reference without prior permission. 29. Liability and mitigation Each party is liable for damage legally attributable to its breach or unlawful act. Where performance remains possible, the party first receives a reasonable opportunity to remedy following sufficiently clear written notice. Unless otherwise agreed in writing, RotoSuite’s total contractual liability per contract year is capped at twelve months of fees paid or payable for the affected service. If less time has elapsed, agreed recurring fees are annualised. Related events count as one event in the year of the first occurrence. The cap includes reasonable direct investigation, remediation, data reconstruction, mitigation and temporary replacement costs. Lost profits, missed savings and purely consequential damage are excluded insofar as lawful. Labelling a loss cannot exclude it contrary to mandatory law. Limits do not apply to management’s intentional misconduct or conscious recklessness, death or personal injury for which liability exists, or other legally non-limitable liability. GDPR compensation rights of individuals and authorities’ powers are unaffected. Parties reasonably mitigate damage and notify claims promptly; statutory limitation periods remain applicable. 30. Force majeure Performance is excused only insofar as a non-attributable event beyond reasonable control actually prevents it. The affected party explains cause, impact and expected duration and reasonably mitigates consequences. A cyberattack, supplier outage or staff shortage alone does not establish force majeure; precautions and contractual risk allocation matter. After sixty days of material prevention, either party may terminate the affected part in writing unless another reasonable arrangement was agreed. Undelivered prepaid parts are refunded proportionately. Payment for properly delivered services, confidentiality, data protection and necessary exit cooperation remain applicable insofar as feasible. 31. Demonstrations, trials and beta features Trial or beta duration, scope and restrictions are disclosed in advance. Prefer fictional or adequately anonymised information. Personal data requires suitable agreements and security. Betas may change or stop and are not the sole basis for business-critical processes without separate agreement. Confidentiality and privacy duties remain. Paid continuation, automatic conversion and retention or deletion of trial data must be expressly agreed. 32. Changes to terms and contract transfers New terms govern new contracts when validly agreed. Material changes to existing contracts are proposed with explanations at least sixty days beforehand and apply only through a valid agreed change mechanism or acceptance. Replacing this webpage alone does not amend existing contracts. A valid mechanism introducing materially adverse changes must give customers a reasonable opportunity to terminate the affected part before implementation. Necessary legal changes are explained with as much preparation time as possible. Contract transfers require legally necessary cooperation. Transfers must not circumvent data protection, agreed service levels or existing rights. Parties give timely notice of changes materially affecting performance. 33. Governing law, disputes and final provisions Dutch law applies, without excluding overriding mandatory rules. The UN Convention on Contracts for the International Sale of Goods is excluded where relevant. Authorised contacts first seek to resolve disputes within thirty days; urgent measures and statutory deadlines need not wait. Unless otherwise agreed, disputes go to the competent court for the provider’s registered office, insofar as such jurisdiction agreement is lawful. Individuals’ statutory rights and supervisory powers remain unaffected. If a provision is invalid or unenforceable, independent remaining provisions survive. Parties replace it with a lawful arrangement reflecting its purpose without circumventing mandatory law. Not immediately exercising a right does not automatically waive it. 34. Arrangements required before go-live An enterprise implementation requires specific arrangements alongside general terms. Applicable items must be documented before the relevant processing or service starts. Open matters are not silently agreed guarantees. - Order: legal parties, modules, users, sites, limits, charges, taxes, start date, duration, renewal and termination. - Implementation: migration, roles, dependencies, training, planning, acceptance and additional-work approval. - SLA: support hours, measurable availability, maintenance, escalation, credits if agreed and recovery objectives. - Processing agreement: instructions, data and individual categories, locations, security measures, subprocessors, transfers, audits, incident contacts and retention. - AI and integrations: providers, permitted information, purposes, human review, provider terms and usage prices. - Exit: exportable information and metadata, formats and interfaces, switching schedule, statutory periods, deletion and backup expiry. Questions about privacy or contracts? Contact Sander or Marthijn. For a privacy request, identify the organisation and processing concerned. Do not send passwords or a complete copy of an identity document. s.staal@pentas.nl / m.koorn@pentas.nl