NTT DATA Global Assets standard Terms and Conditions
Effective as of 1 October 2025
These Terms & Conditions ("Terms") govern the access to and use of NTT DATA software assets and related services ("Global Assets"), whether provided on an on-premises basis or as Software-as-a-Service ("SaaS").
1. Definitions
1.1"Affiliate" means an entity which controls, is controlled by, or is jointly controlled with, a Party, where "control" means, at least, a 50% holding in that entity, or the ability to direct the management of that entity, whether through the ownership of securities carrying voting rights or by way of contract or in any other way.
1.2"Authorised User" means a specific person authorised by the Client (for example, employees or collaborators of the Client) to access and use the Software Asset on behalf of and for the benefit of the Client, whether or not these persons are actively using the Software Asset. The Fees will be associated with the number of Authorised Users requested by the Client.
1.3"Client Data" means any data, information or other material (which is owned exclusively, and which is subject of copyright or other rights) which is uploaded, introduced, created or provided in any other way by the Client, or created by NTT DATA based on Client data, while the Software Asset is used, including, among others, any third-party data obtained by the Client and any personal data. For the avoidance of doubt, Client Data does not include comments and improvements.
1.4"Confidential Information" means, among others, technical, commercial or financial documentation relating to the Software Assets and services of NTT DATA, or any other information exchanged by the Parties and its Affiliates in the framework of these Terms and which, given its nature and the circumstances of its disclosure, should be treated as confidential. Confidential Information does not include information which is (a) which is in the public domain, but not as a result of disclosure by the Receiving Party or by any of its representatives in breach of these Terms; (b) which is in the possession of the Receiving Party before its disclosure by the Disclosing Party; (c) which is acquired by the Receiving Party from a third party without any confidentiality obligation; or (d) which is developed independently by the Receiving Party without reference to the Confidential Information received from the Disclosing Party. The Party concerned shall provide evidence of the aforementioned reasons.
1.5"Fees" means the financial amount which NTT DATA will receive as consideration for the use by the Client of the Software Asset in any distribution modality, and/or for the provision of Specialized Services by NTT DATA or its Affiliates to the Client, in accordance with the provisions of the relevant Order Form.
1.6"Implementation Services" or "Implementation" means services consisting in deploying and configuring the Software Asset for the Client.
1.7"Intellectual Property Rights" means each and all of the following: (a) registered patents, designs, trademarks, utility models, copyrights, know-how and rights over databases; (b) any other intellectual property right and similar or equivalent rights in any part of the world, which exist now or in the future; (c) applications for registration, extensions and renewals relating to any of the aforementioned rights and (d) the expression of any original work or creation, in any format, whether tangible or intangible, including, among others, computer programmes, source codes, object codes, technical documentation, instructions manuals, training materials, technical specification documents, plans, moulds, technical codes or references and/or parts thereof, data formats, sketches, designs, logos, as well as the result of any transformation, amendment, update, adaptation, new versions or alterations of such works or creations.
1.8"Licence" means the right granted by NTT DATA to the Client to use the On-Premise Software Asset while these Terms are in force and in accordance with its relevant provisions.
1.9"On-Premise" means the Software Assets or components of a Software Asset which are provided on premise pursuant to a Licence, and the corresponding Technical Documentation, excluding the Third-Party Content.
1.10"Personal Data" means any information about an identified or identifiable natural person, as defined in the Applicable Data Protection Laws (hereinafter "ADPL").
1.11"Pre-existing IP" means any technology and information, elements to be delivered, methodologies, data, designs, ideas, concepts, know-how, techniques, interfaces, templates, documentation, software, hardware, modules, development tools and any other tangible or intangible technical material or information which NTT DATA possessed before these Terms enters into force or which it develops independently of the activities subject of these Terms, as well as any by-product, modification or improvement of any of the foregoing.
1.12"Specialized Services" cover all the activities required to ensure the proper functioning of the software asset, including, among others, Implementation and Support.
1.13"SaaS" means a model of distributing and granting user rights used for delivering the Software Asset by Internet, that is, like a subscription mode service.
1.14"Service Level Agreement" means the level of availability or operation of the Software Assets and Specialized Services for the Client available here: https://trustcenter.syntphony.com/trust-center/support-model/service-level-agreements.
1.15"Software Asset" means the software developed or licensed by NTT DATA, as identified in the Order Form, including its components and related Technical Documentation.
1.16"Subscription" means the right to use the Software Asset in a Software as a Service mode.
1.17"Support Services" or "Support" means the services provided with the purpose of maintaining the Software Asset, including its operation, in accordance with the support level contracted by Client available here:https://trustcenter.syntphony.com/trust-center/support-model/customer-support-policy/support-plans
1.18"Technical Documentation" means the technical help and user documentation (in any form) for the Software Assets which is provided and/or made available by NTT DATA. In particular, it does not include the source code.
1.19"Territory" means the Territory specified in each case in the Order Form.
1.20"Third Party Content" means the components, standards, rules and good practices of third parties, which have been obtained by NTT DATA from publicly available sources or from their legitimate owners and which are governed by their own terms and conditions.
2. Scope of these Terms
2.1Subject to payment of the Fees, NTT DATA grants the Client, who unconditionally accepts, (i) a Licence to install, access and use the Software Asset On-Premise or (ii) a Subscription to the Software Asset in SaaS mode, in the Territory and during the term specified in the Order Form.
2.2This Licence/Subscription is non-exclusive, non-transferable, revocable and non-assignable (unless otherwise expressly provided in these Terms), and is granted solely for the Client's internal business operations in the Territory on the terms and conditions established herein and in the relevant Order Form.
2.3To the extent that Third Party Content is made available to the Client as part of the Software Assets, the Client acknowledges and accepts that it shall not copy, publish or distribute any Third-Party Content independently from its use of the Software Assets, nor transfer it to any third party, unless otherwise provided in the terms and conditions governing the Third-Party Content. The Client shall not grant licences or sell the Third-Party Content and shall not eliminate or alter any notice relating to copyright, trademarks or other notice of property appearing in the Third-Party Content or within the same. The Client acknowledges and accepts that (a) the Third-Party Content may be added to, modified or eliminated at any time by NTT DATA; and (b) NTT DATA is not responsible for nor has any control over Third Party Content, other than making it available in relation to the Software Assets.
2.4To the extent that the Technical Documentation is necessary for the proper use of the Software Assets, NTT DATA grants the Client a non-exclusive, non-transferable, non-assignable and royalty-free licence in the Territory to use and show hard or electronic copies of the Technical Documentation solely for the purposes of reading and using it exclusively to the extent that the Technical Documentation is necessary for the use of the Software Assets. The reproduction, re-labelling, distribution, offer, importation, sale, translation, modification and making derived works from the Technical Documentation are strictly prohibited. The relevant Technical Documentation shall be delivered to the Client upon execution of the applicable Order Form or activation of access, as applicable.
3. Acceptable uses and restrictions on the use of the Software Assets
3.1These Terms allow the use of the Software Assets exclusively for the use for which they were designed, as provided in the Technical Documentation supplied by NTT DATA. The Licence or Subscription granted to the Client only allows the use of the Software Assets for the purposes described in these Terms. The terms of these Terms shall also apply to any update or modification of the Software Assets, unless otherwise provided in the relevant Order Form.
3.2Notwithstanding that the Software Assets may be subject to particular licensing and operating terms and conditions which will be described in the Order Form or in its Annexes, the Parties agree that the following common conditions shall apply to all of them:
3.2.1The use is restricted to the number of Authorised Users or the number of Licenses/Subscriptions acquired by the Client, as provided in the Order Form.
3.2.2The Client shall be responsible for determining the number of Licences or Subscriptions and for notifying the Authorised Users of the conditions for the use of the Software Assets and ensuring the compliance thereof.
3.2.3The Client shall provide accurate, up-to-date and complete information when activating its Licence or Subscription account for a Software Asset. NTT DATA shall not be responsible for any problems which the Client may have in using the Software Assets as a result of not fulfilling this obligation. The Client shall keep confidential all the identifiers of the Authorised Users, the passwords and other account information. The Client will keep the registration of Authorised Users up to date, shall follow the principle of the least privilege when assigning access permits for the Software Assets, and shall require its Authorised Users to change their passwords periodically. The Client shall be responsible for all activity in its Authorised User accounts, and for any complaint, problem or dispute arising as a result of the actions or omissions of its Authorised Users. The Client shall inform NTT DATA immediately upon becoming aware of any unauthorised use of any Software Asset or account information and if such unauthorised use is by an Authorised User, the Client shall take the necessary measures to prevent such use and minimise its consequences.
3.2.4NTT DATA acknowledges that the Authorised Users of the Client may, subject to the terms and conditions of these Terms, include third party providers of services, independent contractors and consultants of the Client, provided that (a) the Client has informed NTT DATA of the name of that third party, the need for access and the security mechanism that the Client will implement to protect the Confidential Information and the Intellectual Property Rights of NTT DATA; (b) the third party is not a direct competitor of NTT DATA and NTT DATA does not oppose such access in the fifteen (15) business days following the date on which the Client has communicated the identity of such third party; (c) the third party agrees to comply with the terms and conditions of these Terms and notifies its Authorised Users thereof (ensuring its compliance); and (d) such third party uses the Software Assets exclusively for the benefit of the internal commercial transactions of the Client. The Client shall provide a list of any third parties which are using a Software Asset in accordance with this clause for the purposes of managing the Licences/Subscriptions granted and the Software Assets. The Client shall be directly responsible before NTT DATA for the appropriate use of the Software Assets by such third parties in accordance with these Terms.
3.2.5Handling security breaches: Both Parties will have a procedure for handling security breaches. NTT DATA will implement appropriate technical and organizational measures which will include measures for handling security breaches. If the Client has indications or knowledge that there has been a security breach relating to a Software Asset or which could potentially affect a Software Asset, it will notify NTT DATA without undue delay and cooperate with NTT DATA as necessary. In the case of a security breach, NTT DATA shall investigate the security breach and provide the Client with sufficient information about the security breach take and shall take steps it deems necessary to mitigate the effects and minimize any damage resulting from the security breach.
3.3The Client shall only use the Software Assets in accordance with these Terms and shall not (i) use them in breach of applicable laws, regulations, or third-party rights (including privacy rights); (ii) introduce or transmit any content, code, or activity that may harm, disrupt, or compromise their integrity, performance, or security, including malware or viruses; (iii) attempt to gain unauthorised access to the Software Assets, related systems, or data, including through automated tools or scraping; (iv) test, analyse, or disclose their performance, source code, or technical documentation without NTT DATA's prior written consent, nor decompile, reverse engineer, disassemble, or create derivative works from them, except as expressly permitted by law; (v) use them to develop or provide competing products or services; (vi) lease, rent, lend, sublicense, distribute, or otherwise make them available to third parties outside the Client's organisation, except as expressly authorised; (vii) tamper with or circumvent any security or usage controls implemented by NTT DATA or its licensors; or (viii) combine them with other software in a manner that subjects them to "copyleft" or similar obligations under FOSS licences. NTT DATA reserves the right to suspend use of the Software Assets or adopt corrective measures in the event of any actual or suspected breach of this clause.
4. Specialized Services
4.1The Client may contract Specialized Services offered by NTT DATA in relation to the Software Assets, depending on its needs and requirements. Such services shall, by default, be governed by the same terms and conditions (if applicable) set forth in these Terms for the licensing or subscription of the Software Assets, without prejudice to any additional technical or financial terms that may be agreed between the parties. Details of the Specialized Services are included in the Order Form.
5. Warranty
5.1NTT DATA warrants that the Software Assets will work or be available (as appropriate) while the Licence or Subscription is in force in accordance with the essential functionalities included in the Order Form and in the Technical Documentation applicable to the Software Asset. NTT DATA does not guarantee that the use of the Software Assets will be uninterrupted or free from errors. If the essential functionalities of a Software Asset do not match with the Order Form or its Technical Documentation, the Client shall notify this in writing so that NTT DATA can, at its sole discretion, take such steps as are reasonably possible from a commercial point of view to quickly repair or replace the Software Asset or part of it or any other remedy envisaged in these Terms.
5.2This warranty shall not apply and, therefore, NTT DATA shall have no obligation to carry out corrections or repairs, or to replace the Software Assets or part of it, in the event of (i) fault or negligence of the Client; (ii) the use of the Software Asset in a manner not specified in the Technical Documentation; (iii) causes not relating to the Software Asset; or (iv) its inability to function with other systems or applications of the Client.
5.3EXCEPT FOR THE EXPRESS WARRANTIES CONTAINED IN THESE TERMS, THE SOFTWARE ASSETS, TECHNICAL DOCUMENTATION, THIRD-PARTY CONTENT AND ANY OTHER SERVICES PROVIDED PURSUANT TO THESE TERMS ARE PROVIDED "AS IS" AND ARE NOT GUARANTEED TO BE FREE FROM ERRORS, AND THE CLIENT ACCEPTS ALL RISK IN RELATION TO QUALITY, PERFORMANCE, RELIABILITY, ACCURACY AND RESULTS OF THEIR USE.
6. Audits
6.1NTT DATA shall be authorised to carry out audits (at least once a year and in accordance with NTT DATA's standard procedures, which may include audits in the Client's facilities and/or remote audits) of the use of the Software Assets and of the Technical Documentation. The Client must provide reasonable cooperation in the performance of such audits. If an audit discloses that (i) the Client has paid less Fees than those due and/or that (ii) the Client has made a use of the Software that exceeds the amount of Licences or Subscriptions or the levels specified in the offer, the Client shall pay the shortfall in Fees and/or the excess use based on the offered Fees, and shall sign an additional Order Form to include the necessary Licences or Subscription for any additional amount or level. The Client shall pay the reasonable costs of the NTT DATA audit if the results of the audit show that the use or levels permitted by the Licence or Subscription have been exceeded. NTT DATA reserves all rights to claim the payment of shortfalls in Fees and the excess of quantities or levels of use permitted by the Licence or Subscription by the Client.
6.2NTT DATA reserves the right to incorporate software security mechanisms in the Software Assets to supervise its use with the aim of ensuring compliance of these Terms and its ownership of the Software Assets. The Client shall not take any measure to avoid or invalidate the purpose of any of such measures.
6.3At the Client's written request, NTT DATA will provide the Client with evidence of any certifications or audit reports applicable to the Software Asset. Any evidence provided by NTT DATA is Confidential Information and is subject to non-disclosure and distribution limitations of NTT DATA. Any audit, test, inspection, pen-test, vulnerability assessment, reverse engineering activity, or other form of technical or security review of the Software Assets, the Technical Documentation, the source code, or NTT DATA's systems, networks, or infrastructure by the Client or any third party on its behalf is strictly prohibited. The Client will only be permitted to audit the Software Assets, the Technical Documentation, the source code, or NTT DATA's systems, networks, or infrastructure where (i) the Client is granted direct audit rights under applicable laws; (ii) NTT DATA has not provided sufficient evidence of the applicable certifications or audit reports; and (iii) expressly authorised in advance by NTT DATA. Where authorised, audits shall be at the Client's cost and expense, subject to NTT DATA's sole discretion, specific conditions, and supervision and shall be limited to once per year. The Client will request current certifications or other audit reports to avoid or minimize repetitive audits. Under no circumstances shall the Client or any third party acting on its behalf be permitted to access, test, or interfere with the source code, security mechanisms, or operational environment of the Software Assets.
7. Intellectual Property Rights
7.1All Intellectual Property Rights over or in relation to the Software Assets, the Technical Documentation and the Pre-existing IP of NTT DATA shall continue to be Intellectual Property Rights or trade secrets exclusively owned by NTT DATA. NTT DATA may incorporate such measures it deems appropriate in a Software Asset or resource to avoid its unauthorised use. The Client shall be responsible for any breach of Intellectual Property Rights arising as a result of a breach of these Terms. In particular, the Client is not authorised to access the source code of the Software Asset.
7.2NTT DATA reserves all the Intellectual Property Rights and the other rights not expressly granted to the Client in these Terms. Consequently, no provision of these Terms shall limit in any way the right of NTT DATA to develop, use, license, improve, modify, create derivative works or use the Software Assets in any other way, or to allow third parties authorised by NTT DATA to do so.
7.3NTT DATA shall not be prevented in any way from using its general knowledge, skills and experience, as well as any ideas, concepts, know-how and techniques acquired or used during the course of these Terms, or from re-using any general knowledge which is public and common to different companies in the same sector.
7.4The Client shall not attempt to apply, register or claim by any mean as its own, in any jurisdiction, the Intellectual Property Rights owned by NTT DATA or third parties, whether not protected in the Territory or in any other country at any time.
7.5The Client shall not suppress or alter in any way copyright or trademark notices or other notices of ownership of NTT DATA in the Software Assets and Technical Documentation.
7.6The Parties shall not use any registered trademark, logo, trade name, Internet domain name or other distinctive sign of the other Party, without its prior express consent in writing. This consent will not be necessary for NTT DATA to use the aforementioned of the Client in any proposal and/or presentation to third parties, as a mere commercial reference, or on NTT DATA's internal Intranet, which only employees' access, provided there is no breach of the confidentiality obligations contained in these Terms.
7.7If Third-Party Content is licensed under a Free Open Source (FOSS) Licence, the applicable terms and conditions of the FOSS licence will prevail over any other terms and conditions covering the Software Asset and, therefore, such components may only be used in accordance with the applicable licence and not in accordance with the terms and conditions of these Terms. All Third-Party Content subject to a FOSS licence will be provided with the Software Asset (together with their respective licence) are listed in the applicable Order Form.
7.8The Client may at any time provide suggestions, requests for improvements or characteristics or other comments to NTT DATA with respect to the Software Assets, services or related documentation (notwithstanding such products, services or documentation are being disclosed or delivered by NTT DATA to the Client under these Terms or not) (together, the "Comments"). The Client accepts that all Comments are voluntary and delivered to NTT DATA in an entirely voluntary manner. NTT DATA may use, disclose, reproduce, license or distribute and exploit the Comments at its discretion, with no restrictions or obligations of any type or nature. The Comments shall, even if they are designated confidential by the Client, not create any confidentiality obligation for NTT DATA unless NTT DATA expressly agrees in writing. To the extent that the Client, or any Authorised User, makes any suggestion in relation to any characteristic, functionality or performance which NTT DATA adopts for any of its Software Assets (expressly excluding the Confidential Information of the Client), the Client and such Authorised User hereby grant to NTT DATA a non-exclusive, royalty-free, worldwide, perpetual and irrevocable right and licence to freely copy, use, make use, publish, adapt, distribute, sell, licence, create derivative works and exploit in any other manner such suggestions, including incorporating them in future versions of the Software Assets or services.
7.9The Client is authorised to print and make a reasonable number of copies of the Technical Documentation for its internal use in accordance with these Terms, provided that the Client reproduces in such copies all the copyright and other ownership notices found in the original copy of such Technical Documentation.
7.10If the Software Asset consists, in whole or in part, of a database, the Client shall not be entitled to extract and/or re-use the whole or a substantial part (evaluated qualitatively and/or quantitatively) of such database. This exclusion shall only affect the original data provided by NTT DATA and shall not prevent the Client from using the results of using the Software Asset.
7.11If the Software Asset includes features that employ Artificial Intelligence (AI) technologies, they will be governed by the terms and conditions set forth in Annex B - Artificial Intelligence Features in the Licensed Software, as well as the terms established in the Order Form, which is an integral part of these Terms.
8. Confidential Information and the processing of personal data
8.1Each Party may have access to Confidential Information relating to the Software Asset, the needs of the Client or these Terms. Each Party recognises that Confidential Information is private and valuable to the Disclosing Party and that any unauthorised disclosure or use of the same will cause irreparable loss and damage to the Disclosing Party. The Receiving Party undertakes to keep the Confidential Information belonging to the Disclosing Party confidential while these Terms are in force until the Receiving Party returns or destroys all Confidential Information in its possession or under its control. Without prejudice to the foregoing, the Parties undertake that all Confidential Information exchanged for the purposes of these Terms before entering into it shall be subject to the confidentiality provisions contained in this clause.
In addition, the confidentiality obligation assumed by the Parties pursuant to these Terms shall remain in force for a period of five (5) years following termination of these Terms.
No Party shall disclose Confidential Information belonging to the other Party to any third party or use such Confidential Information for any purpose other than the performance of these Terms, except to the extent required by law, governmental order or valid court order in accordance with Clause 8.2 below. The Receiving Party shall be liable, together with its employees, agents and third parties for whom it is responsible, for any loss or damage arising as a result of the breach of the confidentiality obligation, without prejudice to any action that the Disclosing Party may take against the Receiving Party or against third parties under any applicable legislation. The Receiving Party undertakes to use the Confidential Information solely for the purpose of complying with these Terms, unless otherwise agreed by the Parties in writing.
8.2Each Party undertakes, moreover, to adopt reasonable security measures when sending Confidential Information. If the applicable law or any legal proceedings demand or require the Receiving Party to disclose any Confidential Information belonging to the Disclosing Party, the Receiving Party, shall, before such compulsory disclosure, inform the Disclosing Party (to the extent legally permitted to do so) and shall reasonably assist the Disclosing Party, at the expense of the latter, if the Disclosing Party wishes to oppose the disclosure. Any disclosure of this kind shall be limited to the required extent and shall be subject to confidentiality protections to the extent reasonably feasible. Disclosure of Confidential Information required by applicable legislation or by legal proceedings shall not constitute a breach of these Terms.
8.3NTT DATA will comply with applicable laws, including data protection legislation, and its applicable privacy statements when using and processing the personal data of the representatives, collaborators or employees of the Customer.
8.4Where the Client's use of the Software Assets involves the processing of the Client's Personal Data, Annex A – Data Processing Agreement shall apply, and the Parties shall specify the details of such processing in the relevant Order Form.
9. Client Data
9.1The Client has and shall maintain the ownership and control of all Client Data. The Client shall not introduce, upload, process or store Client Data in or with a Software Asset, unless the Client has obtained them legally and complied with all applicable laws regarding its use of such Data. NTT DATA shall have no obligation or responsibility in respect of the Data introduced, uploaded, processed or stored by the Client in the Software Asset(s).
9.2NTT DATA may collect, use, process and store technical data relating to the use of computers, mobile telephones or other devices which the Client uses to download, install and access the Software Assets, for its improvement, for the purpose of providing assistance and in order to verify the Software Assets. The foregoing may include, among others, IP addresses and other information such as Internet service, location, browser type and modules used and/or accessed ("Usage Data"). The Client accepts that NTT DATA may process Usage Data to create and compile collections of anonymous and aggregated data and/or statistics about the Software Assets, for the purposes of maintaining, supervising and improving the performance and integrity of NTT DATA's Software Assets.
9.3NTT DATA may use the Client Data, and the Usage Data generated and obtained during the use of the Software Assets by the Client for the purpose of analysing and identifying possible areas for improvement of the Software Assets. NTT DATA will comply with applicable laws, including data protection legislation and its applicable privacy statements.
10. Fees and Payment
10.1The Client shall pay the Fees set out in each Order Form. Unless otherwise provided in the relevant Order Form, the Fees shall be paid no later than thirty (30) days following the date of the invoice and may not be cancelled or reimbursed.
10.2All applicable taxes (excluding taxes on net income of NTT DATA), rights or other governmental levies are additional and payable by the Client and are based on the delivery address specified in the Order Form. If the Client is obliged to pay any mandatory withholding, charge or duty in relation to any payment owing to NTT DATA pursuant to these Terms, the Client shall calculate the payments to be made in such a way that NTT DATA receives the amounts due in accordance with these Terms in full and free from any deduction by way of withholding, charge or duty. NTT DATA shall not charge any tax from which the Client is exempt if the Client is an institution or entity exempt from taxes and the Client provides evidence thereof by way of the relevant tax exemption certificate. The Client recognises that the Order Form contains its invoicing and delivery addresses.
10.3If any payment of Fees is delayed by more than (30) days, NTT DATA may, without limiting any other rights and actions available to it, suspend or finalise access to and use of the Software Assets by the Client, or of related services, in respect of which payment of the Fees is outstanding until such amounts have been paid in full. NTT DATA shall provide at least seven (7) days' notice that payment of the Fees is outstanding before any suspension, and shall not exercise such right if the Client, reasonably and in good faith, disagrees and has complained about the applicable Fees, and is cooperating diligently to find a solution to these Terms. Furthermore, if payment has not been made within the thirty (30) days following the issue date of the invoice, NTT DATA may invoice delay charges which will be calculated by applying a monthly 3% on the delayed amount during the days of delay, unless otherwise provided by law. Such charges shall not limit any other claim which may be available to NTT DATA.
10.4NTT DATA reserves the right to change, update or modify the Fees set out in each Order Form upon prior notice in writing of such price modification to the Client (i) in the case of Order Forms with a duration of more than one (1) year, with at least two (2) months' notice before applying such change and, (ii) in the case of Order Forms with a duration of one (1) year or less, when renewing such Order Form.
11. Duration and Renewal
11.1These Terms shall enter into force on the day on which they are accepted by the Client, including by execution of an applicable Order Form, and shall have an initial duration of twelve (12) months counting from such date, and shall be tacitly and automatically renewed for successive periods of identical duration, unless either Party expresses its will not to renew by way of ninety (90) days' written notice prior to the initial termination date or the termination date of any of its annual renewals. Termination of these Terms shall not take effect as long as there are Order Forms in force pending execution.
11.2A Licence or Subscription of the Client for a Software Asset, whether an On-Premise or a SaaS, shall have the duration set out in the relevant Order Form. If no duration is specified in the Order Form, the Licence or Subscription shall have a duration of one (1) year starting on the date of the Order Form.
11.3The Licence, Subscription and/or Specialized Services regulated in each Order Form shall be renewed at the end of each term for a new term of one (1) year unless either Party expresses its will not to renew by way of ninety (90) days' written notice.
12. Termination of These Terms and Order Forms
12.1Either Party may terminate these Terms and/or Order Form immediately if the other Party materially fails to comply with its obligations under these Terms and, within thirty (30) days following receipt of written notice from the other Party, the Party in breach does not remedy the breach, or does not make significant progress, reasonably satisfactory to the other Party.
12.2NTT DATA may, as well as suspending access to the Software Asset and/or interrupting the provision of Specialized Services, choose to terminate these Terms and/or the Order Form immediately if the Client fails to comply with any of its obligations in the following cases: (i) use of the Software Asset by the Client contrary to the content of the Order Form and its Technical Documentation, (ii) failure to pay the Fees, (iii) breach of any representation or warranty by the Client in relation to its obligations or its Compliance Programme. If NTT DATA terminates these Terms due to any such breach by the Client, without prejudice to any compensation for loss or damage which may by due, the Client shall continue to be liable for all outstanding Fees which must be paid during the term of the Licence, the Subscription, and the Specialized Services. If the Client terminates these Terms due to a breach by NTT DATA, NTT DATA shall reimburse any Fee paid in advance calculated from the effective termination date until the end of the paid term.
12.3Termination of these Terms or any Order Form for convenience by the Client shall not be permitted, unless expressly agreed in writing by NTT DATA. Where termination for convenience is approved, it shall require (i) reasonable prior written notice of at least ninety (90) days, and (ii) full compensation of NTT DATA for any unamortised investments, bespoke developments, or specific resources allocated to the Client under the affected Order Form.
12.4Upon termination of an Order Form, Licence, Subscription or these Terms, access to and use of the Software Assets by the Client shall cease and the Client shall destroy or delete the original and all copies of such Software Assets and of the Technical Documentation that are in its possession or controlled by it. In case of an On-Premise installation, the Client shall certify in writing to NTT DATA, no later than thirty (30) days following such request, that the original and all copies of the Software Assets and the Technical Documentation have been destroyed or returned to NTT DATA.
12.5Each Party shall immediately return to the other Party all Confidential Information belonging to the other Party that is in its possession or controlled by it. If the Client is responsible for erasing all Client Data from the SaaS following termination of the Subscription, NTT DATA shall allow the Client to access the SaaS for a period of thirty (30) days following termination to allow the Client to make such erasure. In the event that the Client has not such obligation, NTT DATA shall erase all Client Data provided under these Terms.
12.6Termination of these Terms shall not constitute a waiver of any of the Fees, amounts or charges owed by the Client, nor shall such termination limit or compromise in any way any other rights of either Party under these Terms. Notwithstanding the termination of these Terms for any reason, the Parties agree that certain provisions, given their nature, shall remain in force following termination of these Terms including, among others, those relating to Confidential Information, personal data protection and Intellectual Property Rights.
13. Liability
13.1EXCEPT AS EXPRESSLY WARRANTED IN THESE TERMS, NTT DATA AND ITS LICENSORS DISCLAIM ALL OTHER REPRESENTATIONS, WARRANTIES OR CONDITIONS, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, DURABILITY AND NON-INFRINGEMENT. NO ORAL OR WRITTEN INFORMATION PROVIDED BY NTT DATA OR ITS REPRESENTATIVES SHALL CREATE ANY ADDITIONAL WARRANTY.
13.2THE TOTAL AGGREGATE LIABILITY OF NTT DATA AND ITS LICENSORS, AFFILIATES OR REPRESENTATIVES FOR ANY CLAIM ARISING UNDER THESE TERMS SHALL BE LIMITED TO DIRECT, PROVEN LOSSES ATTRIBUTABLE TO NTT DATA AND SHALL NOT EXCEED THE FEES PAID BY THE CLIENT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THIS LIMITATION APPLIES TO ALL LIABILITIES, INCLUDING BREACHES OF CONFIDENTIALITY, DATA PROTECTION OBLIGATIONS AND THIRD-PARTY INTELLECTUAL PROPERTY RIGHTS. INDIRECT, INCIDENTAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, INCOME, BUSINESS, DATA OR REPLACEMENT COSTS, ARE EXPRESSLY EXCLUDED.
13.3USE OF THIRD-PARTY CONTENT IS SUBJECT TO ITS OWN TERMS AND CONDITIONS. THE CLIENT SHALL HOLD NTT DATA AND ITS LICENSORS HARMLESS FROM ANY LIABILITY ARISING FROM SUCH USE, AND NTT DATA SHALL HAVE NO LIABILITY FOR THIRD-PARTY CONTENT PROVIDED UNDER FOSS LICENCES.
13.4NO LIQUIDATED DAMAGES, PENALTIES, OR SIMILAR CHARGES SHALL APPLY UNDER THESE TERMS OR ANY ORDER FORM UNLESS (I) THEY ARE OBJECTIVELY MEASURABLE, (II) DIRECTLY LINKED TO SPECIFIC AND DEFINED SERVICE LEVEL AGREEMENTS (SLAS), (III) SUBJECT TO FINANCIAL CAPS AGREED IN ADVANCE, AND (IV) ALIGNED WITH THE SLA FRAMEWORK PUBLISHED BY NTT DATA AT
13.5NTT DATA shall defend and indemnify the Client against any third-party claim in the Territory alleging that authorised use of a Software Asset infringes intellectual property rights, covering actual damages and reasonable legal fees, provided that (i) the Client promptly notifies NTT DATA of the claim, (ii) NTT DATA retains exclusive control of the defence and settlement, and (iii) the Client provides reasonable cooperation. This obligation shall not apply to claims arising from (a) use of outdated versions when a non-infringing version is available, (b) unauthorised combinations with other products or services, (c) misuse or disclosure of Client Data, or (d) use in breach of these Terms or outside the applicable Technical Documentation.
13.6If such a claim is made or likely to be made, NTT DATA may, at its discretion and expense, (i) secure the Client's continued right to use the Software Asset, (ii) replace or modify it with a functionally equivalent non-infringing version, or (iii) terminate the affected Order Form on thirty (30) days' written notice and refund the Client any prepaid but unused Fees corresponding to the twelve (12) months preceding the claim.
13.7The Client shall defend and indemnify NTT DATA, its group companies, Affiliates, and personnel against any claim, loss, or damage arising from (i) the Client's collection or use of Client Data, or (ii) failure to comply with obligations regarding Third-Party Content or use restrictions. Such indemnity covers damages and reasonable legal fees, provided that (i) NTT DATA promptly notifies the Client, (ii) the Client retains exclusive control of the defence and settlement, and (iii) NTT DATA provides reasonable cooperation. This indemnity shall not apply where the claim arises exclusively from the Software Asset itself or from NTT DATA's breach of these Terms.
13.8Neither party shall be liable for any delay or failure to perform caused by force majeure, unforeseeable circumstances or beyond its reasonable control.
14. Notices
14.1Any notice, request, requirement, instruction, notification or other type of communication given or sent in the context of these Terms must be in writing and sent by ordinary mail (with acknowledgment of receipt), by email or delivered to the relevant Party at the address appearing in each Order Form at the time of subscription or renewal of the Licence or Subscription. Notices shall be deemed to have been validly received, if delivered personally, at the time of such delivery, if delivered by ordinary mail, at the time proof of such delivery to the addressee is obtained; and, if delivered by email, when express acknowledgment of receipt of the same is obtained or when non-repudiation is technically feasible. Reasonable notice of any change in address for the purposes of notices must be given to the other Party in accordance with this clause.
15. Governing law and jurisdiction
15.1These Terms and the applicable Order Forms shall be governed by, and construed in accordance with, the laws in force at the place of the Client's registered office or principal place of business.
15.2Any conflict, dispute or claim arising from or in connection with these Terms and the applicable Order Forms, or with the breach, termination or invalidity of these Terms, shall be submitted to the exclusive jurisdiction of the courts having jurisdiction over the Client's registered office or principal place of business.
16. Compliance Programme.
16.1The Parties undertake to comply with all legislation in force (including international legislation) which may be applicable to these Terms while it is in force, in particular anticorruption law, anti-money laundering law, labour law, environmental law and competition law.
16.2Each Party represents that it has implemented a Compliance Programme which involves carrying on professional activity in accordance with certain ethical parameters, contained in its own Ethical Code, the essential purpose of which is to identify risks relating to legislative compliance in the organisation, as well as their prevention and control.
16.3Each Party undertakes to comply in full with the provisions of its Compliance Programme, including, among other things, observing the values, principles and guidelines for conduct contained in its Code of Conduct, as well as its other internal policies and procedures. In particular, both Parties agree to prohibit any action or conduct which could directly or indirectly involve corruption or bribery of any kind, in both the public and the private sector.
16.4In addition, in the framework of this contractual relationship, the Parties agree to avoid any conflicts of interest, whether personal or professional.
16.5Any breach of this clause, provided there is due evidence thereof, shall entitle the Party not in breach to automatically terminate these Terms, as well as to make any claims to which it is legally entitled if affected by such breach.
17. Miscellaneous
17.1Entire agreement. These Terms includes all the obligations, representations and warranties arising from the agreement between the Parties with respect to the use of the Software Assets and the Specialized Services, and replaces any previous conversation or agreement, verbal or written, between the Parties, with the express exclusion of any order terms and conditions of the Client or any general terms and conditions of the Client, which shall not bind the Parties and shall not be construed so as to modify these Terms. Any amendment of these Terms shall take place in writing and shall be accepted by authorised representatives of both Parties.
17.2Partial invalidity. If any of the clauses of these Terms is declared invalid or unenforceable, such clause shall be deemed to be excluded from these Terms, without implying the invalidity of these Terms. In this case the Parties shall use their best efforts to find an equivalent solution which is valid, and which duly reflects their intentions.
17.3Waiver. No failure by a Party to exercise any right under these Terms shall be construed as a waiver of such right.
17.4Assignment of contractual position. NTT DATA may assign its contractual position under these Terms by giving one (1) month's written notice to the Client. The Client shall not be entitled to assign these Terms without the prior written consent of NTT DATA, except to a corporate successor due to a merger, purchase of assets and assumption of liabilities, acquisition, reorganisation, or other means, provided that the Client gives prior notice thereof to NTT DATA and such corporate successor agrees to be bound by these Terms. Furthermore, the Client may only assign these Terms if the assignee is not a competitor of NTT DATA, the Client ceases to use the Software Assets, and the use does not exceed the number of Licenses or Subscriptions purchased by the Client. These Terms shall be for the benefit of the Parties and shall be binding upon their respective successors, executors, heirs and authorised assignees.
17.5Hierarchy. In the event of any inconsistency or conflict between the provisions of these Terms, any Annexes, and any Order Form, the documents shall prevail in the following order of precedence: (i) proposal, (ii) the relevant Order Form; (iii) the applicable Annexes; and (iv) these Terms.
17.6Absence of third-party beneficiaries. Unless otherwise expressly provided in these Terms, no person other than a Party to these Terms shall be entitled to demand compliance with any provision of these Terms.
17.7Mutual respect. The Parties undertake to act in good faith and with utmost consideration for each other's interests in the performance of these Terms, and undertake to respect their respective Intellectual Property Rights, goodwill, directors, workforce and all assets and securities which make up market value.
Annex A - Data processing agreement
1. Introduction
1.1This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the NTT DATA Global Assets standard Terms & Conditions (the "Terms") and applicable Order Form between NTT DATA and Client ("These Terms") under which NTT DATA provides certain software assets, products and/or services ("Services") to Client as set out in the Order Form.
1.2To the extent NTT DATA may be required to process personal data on behalf of Client under these Terms, NTT DATA will do so in accordance with the terms set out in this DPA.
1.3NTT DATA will sign this DPA in its own name and on behalf of its Affiliates. The Client acknowledges and agrees that NTT DATA will be the sole point of contact on behalf of the Affiliates of Personal Data. As other Affiliates may have certain direct rights against the Client, NTT DATA shall use its reasonable endeavours to bring all claims or actions against the Client for itself and on behalf of any other Affiliates to the extent possible. The Client shall be discharged of its obligations to inform or notify other Affiliates when the Client has provided such information or notice to NTT DATA.
2. Defined Terms
2.1"Affiliate" means an entity which controls, is controlled by, or is jointly controlled with, a Party, where "control" means, at least, a 50% holding in that entity, or the ability to direct the management of that entity, whether through the ownership of securities carrying voting rights or by way of contract or in any other way.
2.2"CCPA" means the California Consumer Privacy Act of 2018, as amended (Cal. Civ. Code §§ 1798.100 to 1798.199).
2.3"China or PRC" means the People's Republic of China, excluding for the purposes of this DPA, Hong Kong SAR, Macau SAR and Taiwan.
2.4"China Data Protection Laws" means the Cybersecurity Law of the PRC, Data Security Law of the PRC, Personal Information Protection Law of the PRC and other laws, regulations, administrative rules and compulsory national standards of the PRC.
2.5"Data Exporter" means a party that is transferring Personal Data directly or via onward transfer to a country that triggers additional requirements for the protection of Personal Data being transferred under applicable Data Protection Laws.
2.6"Data Importer" means a party that receives Personal Data directly from a Data Exporter, or via onward transfer, and that is located in a country that triggers additional requirements for the protection of Personal Data being transferred under applicable Data Protection Laws.
2.7"Data Protection Laws" means any data protection and/or privacy related laws, statutes, directives, or regulations (and any amendments or successors thereto) to which a Party is subject and which are applicable to the Software Asset and Specialized Services provided, including where applicable, the EU Data Protection Laws, UK Data Protection Laws, Swiss FDPA, CPRA, China Data Protection Laws, LGPD and other similar laws.
2.8"Data Subject" means an identified or identifiable person. An identifiable person is one who can be identified either directly, or indirectly. To the extent that a legal person is a Data Subject under Data Protection Laws, such legal person shall be considered as a Data Subject for purposes of this DPA.
2.9"EU" means the European Union.
2.10"EU Data Protection Laws" means the GDPR, any successor thereto, and any other law relating to the data protection or privacy of individuals that applies in the European Economic Area.
2.11"EU SCCs" means Sections I, II, III and IV (as applicable) in so far as they relate to Module Two (Controller-to-Processor), Module Three (Processor-to-Processor) and Module Four (Processor-to-Controller), as applicable, within the Standard Contractual Clauses for the transfer of Personal Data to third countries under Regulation (EU) 2016/679 of the European Parliament and the Council approved by EC Commission Decision of 4 June 2021, as set out in Attachment D.
2.12"GDPR" means the General Data Protection Regulation (EU) 2016/679.
2.13"LGPD" means the General Personal Data Protection Law of Brazil.
2.14"Personal Data" means any information relating to a Data Subject that is received, accessed and/or Processed by Processor in its capacity as a "processor" acting on behalf of controller in connection with the performance of processor"s obligations under this DPA.
2.15"Personal Data Breach" means a breach of NTT DATA"s security leading to the actual accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed by NTT DATA.
2.16"Privacy Statement" means any applicable privacy statement describing NTT DATA"s treatment of Personal Data in its general business administration, management, and operations, or related to the Services.
2.17"Restricted Transfer" means a transfer of Personal Data from a Data Exporter to a Data Importer.
2.18"Standard Contractual Clauses" or "SCCs" means any pre-approved standard contractual clauses for the international transfer of personal data under applicable Data Protection Laws, including the EU SCCs, the Swiss Addendum and UK Addendum, as may be updated, supplemented, or replaced from time to time under applicable Data Protection Laws, as a recognized transfer or processing mechanism (as applicable)
2.19"Standard Contract" or "China SCCs" means the Standard Contract For Personal Information Exports for the transfer of Personal Data from a Data Exporter in China to a Data Importer located outside of China issued by the Cyberspace Administration of China ("CAC") or alternative standard contract clauses as may be approved by the CAC from time to time. An English translation of the Standard Contract is available here.
2.20"sub-processor" means any processor engaged by NTT DATA or any Affiliate that processes Personal Data pursuant to these Terms. Sub-processors may include third parties (external processor) or any NTT DATA Affiliate.
2.21"Swiss Addendum" means the EU SCCs as amended by 0.
2.22"UK" means the United Kingdom of Great Britain and Northern Ireland.
2.23"UK Addendum" means the template Addendum B.1.0 issued by the Information Commissioner's Office and laid before Parliament under s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of the Mandatory Clauses of the Addendum. The UK Addendum is set out in Attachment E.
2.24"UK Data Protection Laws" means all laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.
2.25"UK GDPR" means the GDPR as implemented in the UK.
2.26Lower case terms. The following lower case terms used but not defined in this DPA, such as "controller", "processor" and "processing" will have the same meaning as set forth in Article 4 of the GDPR, or where not specifically defined under Data Protection Laws, the same meaning as analogous terms in those Data Protection Laws.
3. Purpose And Scope
3.1NTT DATA may be required to process Personal Data on behalf of Client under any applicable Data Protection Laws.
3.2If NTT DATA is processing Personal Data within the scope of the CCPA, the CCPA Terms contained in Attachment F govern the processing of Personal Data. The CCPA Terms do not limit or reduce any data protection commitments NTT DATA makes to Client in the DPA, these Terms or other terms between NTT DATA and Client.
4. Duration And Termination
4.1This DPA will remain in force so long as these Terms remain in effect or NTT DATA retains any Personal Data related to these Terms in its possession or control.
4.2NTT DATA will process Personal Data until the date of expiration or termination of these Terms, unless instructed otherwise by Client in writing, or until such Personal Data is returned or destroyed on the written instructions of Client or to the extent that NTT DATA is required to retain such Personal Data to comply with applicable laws.
5. Personal Data Types And Processing Purposes
5.1For purposes of this DPA, the Client and NTT DATA acknowledge that the Client is the controller and NTT DATA is the processor or sub-processor of Personal Data.
5.2The details of the processing operations, in particular the categories of Personal Data and the purposes of processing for which the Personal Data is processed concerning the Services as described on each Order Form ("Business Purposes"), are specified in 0 and where appropriate, the Order Form.
6. NTT DATA Obligations
6.1Client instructions. When NTT DATA acts as the processor of Personal Data, it will only process the Personal Data on Client"s reasonable and lawful documented instructions which are recorded in this DPA and to the extent that this is required to fulfil the Business Purposes. Any additional instructions from Client"s authorized representatives ("Authorized Persons") must be documented and agreed between NTT DATA and Client. NTT DATA will not process the Personal Data for any other purpose or in a way that does not comply with this DPA or applicable Data Protection Laws. Should NTT DATA reasonably believe that a specific processing activity beyond the scope of Client"s instructions is required to comply with a legal obligation to which NTT DATA is subject, NTT DATA must inform Client of that legal obligation and seek explicit authorization from Client before undertaking such processing. NTT DATA will not process the Personal Data in a manner inconsistent with Client"s documented instructions.
6.2Independent controller. To the extent NTT DATA uses or otherwise processes Personal Data in connection with NTT DATA"s legitimate business operations, NTT DATA will be an independent controller for such use, will process Personal Data in accordance with its applicable Privacy Statement, and will be responsible for complying with all applicable laws and controller obligations.
6.3Compliance. NTT DATA will reasonably assist Client in complying with Client"s obligations under applicable Data Protection Laws. In doing so it will take into account the nature of NTT DATA"s processing and the information made available to NTT DATA, including in relation to Data Subject rights, data protection impact assessments, transfer impact assessments and reporting to and consulting with data protection authorities under applicable Data Protection Laws. NTT DATA will without undue delay notify Client if, in its opinion, any instruction infringes applicable Data Protection Laws. Client shall ensure its instructions comply with applicable Data Protection Laws and this notification will neither constitute a general obligation on the part of NTT DATA to monitor or interpret the laws applicable to Client, nor constitute legal advice to Client.
6.4Disclosure. NTT DATA may disclose the Personal Data to third parties where: (a) requested to do so by Client; (b) reasonably required in connection with the Services, provided that any such disclosure complies with the terms of this DPA; or (c) required to do so to comply with Data Protection Laws, or an order of any court, tribunal, regulator or government agency with competent jurisdiction to which NTT DATA is subject, provided that NTT DATA will (to the extent permitted by law) inform Client in advance of making any such disclosure and will reasonably co-operate with Client to limit the scope of the disclosure to what is legally required.
7. Contracting With Sub-Processors
7.1Use of sub-processors. NTT DATA uses sub-processors which may be located outside the country where Personal Data is collected, and which will process personal data as sub-processors. Some sub-processors might make further onward transfers of Personal Data.
7.2List of sub-processors. A list of NTT DATA's sub-processors that NTT DATA directly engages for the Services as a processor is available on request to the NTT DATA contact mentioned in 0 or as otherwise made available on an NTT DATA website.
7.3General authorization. Client provides its general authorization to NTT DATA"s engagement with sub-processors, including Affiliates of NTT DATA, to provide some or all Services and process Personal Data on its behalf. To the fullest extent permissible under applicable Data Protection Laws this DPA will constitute Client"s general written authorization to the subcontracting by NTT DATA of the processing of Personal Data to this agreed list of sub-processors.
7.4Changes. NTT DATA will notify the Client in writing of any intended changes to the agreed list of sub-processors at least 30 days in advance, thereby allowing the Client to object to such changes. Such objection must be made in writing to the NTT DATA contact mentioned in 0 within 14 days of notification. Client"s failure to submit a written objection to the agreed list of sub-processors within 14 days of notification, will be deemed acceptance of the changes to the agreed list of sub-processors.
7.5Performance. NTT DATA is responsible for its sub-processors compliance with NTT DATA"s obligations in this DPA.
8. Client Obligations
8.1Data Subject requests. If NTT DATA receives a request from Client's Data Subject to exercise one or more of its rights under applicable Data Protection Laws, in connection with the Services for which NTT DATA is a processor or sub-processor, NTT DATA will as soon as is reasonably practicable redirect the Data Subject to make its request directly to Client. Client will be responsible for responding to any such request. NTT DATA will comply with reasonable requests by Client to assist with Client's response to such a Data Subject request. Client will be responsible for reasonable costs NTT DATA incurs in providing this assistance.
8.2Client requests. NTT DATA must promptly comply with any Client request or instruction from Authorized Persons (a) requiring NTT DATA to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorized processing, (b) relating to Client's obligations regarding the security of processing and (c) requiring Client's prior consultation obligations in terms of applicable Data Protection Laws, considering the nature of the processing and the information available to NTT DATA.
8.3Warranty. The Client remains responsible for its compliance obligations under applicable Data Protection Laws and Client warrants and represents (on its behalf and on behalf of each of its Client Affiliates) that it has taken all steps legally required under Data Protection Laws, including but not limited to, providing notice and obtaining all necessary authorisations and consents required for compliance with Data Protection Laws, prior to disclosing, transferring, or otherwise making available, any Personal Data to NTT DATA under this DPA. Should such consent be revoked by a Data Subject, Client is responsible for communicating the fact of such revocation to NTT DATA, and NTT DATA remains responsible for implementing Client's instruction with respect to the processing of that Personal Data.
9. Security
9.1TOMs. NTT DATA will implement appropriate Technical and Organizational Measures ("TOMs') to ensure the security of the Personal Data in terms of applicable Data Protection Laws, including the security measures set out in 0.
9.2Access to Personal Data. NTT DATA will grant access to the Personal Data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring these Terms. NTT DATA will ensure that persons authorized to process the Personal Data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
9.3Cost negotiations. The parties will negotiate in good faith the cost, if any, to implement material changes other than those required by specific updated security requirements set forth in applicable Data Protection Laws or by data protection authorities of competent jurisdiction (in which case NTT DATA will bear the responsibility for such cost).
10. Audits
10.1Certifications. NTT DATA will maintain any certifications that it is contractually obligated to maintain and comply with as expressly stated in these Terms. NTT DATA will re-certify against those certifications as reasonably required.
10.2Provision of evidence. At Client's written request, NTT DATA will provide Client with evidence of those certifications relating to the processing of Personal Data, including applicable certifications or audit reports so that Client can reasonably verify NTT DATA's compliance with its obligations under this DPA.
10.3Compliance with TOMS. NTT DATA may also rely on those certifications to demonstrate compliance with the requirements set out in clause 0.
10.4Confidential information. Any evidence provided by NTT DATA is confidential information and is subject to non-disclosure and distribution limitations of NTT DATA and/or any NTT DATA sub-processor.
10.5Client Audits. Client may carry out audits of NTT DATA´s premises and operations as these relate to the Personal Data of Client if:
- NTT DATA has not provided sufficient evidence of the measures taken under clause 9; or
- an audit is formally required by a data protection authority of competent jurisdiction; or
- applicable Data Protection Laws provide Client with a direct audit right (and as long as Client only conducts an audit once in any twelve-month period, unless mandatory applicable Data Protection Laws require more frequent audits).
Client audit process. The Client audit may be carried out by a third party (but must not be a competitor of NTT DATA or not suitably qualified or independent) who must first enter into a confidentiality these Terms with NTT DATA. Client must provide at least 30 days advance notice of any audit unless mandatory applicable Data Protection Laws or a data protection authority of competent jurisdiction requires shorter notice. NTT DATA will cooperate with such audits carried out and will grant Client´s auditors' reasonable access to any premises and devices involved with the processing of the Client's Personal Data during NTT DATA's business hours. Client and its auditors must comply with applicable NTT DATA policies and procedures. The Client audits will be limited in time to once a year and a maximum of three business days. Beyond such restrictions, the parties will use current certifications or other audit reports to avoid or minimize repetitive audits. The Client must bear the costs of any Client audit unless the audit reveals a material breach by NTT DATA of this DPA in which case NTT DATA will bear the costs of the audit. If the audit determines that NTT DATA has breached its obligations under the DPA, NTT DATA will promptly remedy the breach at its own cost.
11. Incident Management
11.1Personal Data Breach. If NTT DATA becomes aware of a Personal Data Breach, NTT DATA will promptly and without undue delay:
- notify Client of the Personal Data Breach;
- investigate the Personal Data Breach and provide Client with sufficient information about the Personal Data Breach, including whether the Personal Data Breach involves Personal Data of the Client;
- take reasonable steps to mitigate the effects and minimize any damage resulting from the Personal Data Breach.
11.2Notification. Notification(s) of Personal Data Breaches will take place in accordance with clause 0. Where the Personal Data Breach involves Personal Data of the Client, NTT DATA will make reasonable efforts to enable Client to perform a thorough investigation into the Personal Data Breach, formulate a correct response, and take suitable further steps in respect of the Personal Data Breach. NTT DATA will make reasonable efforts to assist Client in fulfilling Client's obligation under applicable Data Protection Laws to notify the relevant data protection authority and Data Subjects about such Personal Data Breach. NTT DATA's notification of or response to a Personal Data Breach under this clause is not an acknowledgement by NTT DATA of any fault or liability for the Personal Data Breach. The Client must bear the costs of NTT DATA's assistance unless the Personal Data Breach is directly caused by NTT DATA.
11.3Other incidents. NTT DATA will notify Client promptly if NTT DATA becomes aware of:
- a complaint or a request concerning the exercise of a Data Subject's rights under any applicable Data Protection Laws about Personal Data NTT DATA processes on behalf of Client and its Data Subjects; or
- an investigation into or seizure of the Personal Data of Client by government officials, or a specific indication that such an investigation or seizure is imminent; or
- where, in the opinion of NTT DATA, implementing an instruction received from Client about the processing of Personal Data would violate applicable laws to which Client or NTT DATA are subject.
11.4Client notifications. Any notifications made to Client under clause 11 will be addressed to the Client contact mentioned in 0 using one of the contact methods set out in 0.
12. Cross Border Transfers Of Personal Data
12.1General. Except as described elsewhere in the DPA, Personal Data that NTT DATA processes on Client's behalf may be transferred to and stored and processed in any country in which NTT DATA or its sub-processors may operate.
12.2Restricted Transfers. Where there is a Restricted Transfer of Personal Data, the Data Exporter and the Data Importer must transfer and process the Personal Data in accordance with all applicable Data Protection Laws. In particular:
- Attachment D will apply where Personal Data that is subject to EU Data Protection Laws is transferred from a Data Exporter to a Data Importer acting as a Processor.
- Attachment E will apply where Personal Data that is subject to applicable Data Protection Laws in the specific jurisdiction provisions set forth in Attachment E is transferred outside the listed jurisdictions.
12.3Execution of SCCs. If any cross-border transfer of Personal Data between NTT DATA and the Client requires the execution of SCCs to comply with the applicable Data Protection Law, the parties' signature to this DPA or these Terms will be considered as signature to the SCCs. Where the SCCs are the EU SCCs, Annex I must be signed in addition to this DPA or These Terms. Such signature must comply with the national law governing the EU SCCs.
12.4Change of statutory transfer mechanism. To the extent that NTT DATA is relying on the EU SCCs, UK Addendum or another specific statutory mechanism to normalize international data transfers and those mechanisms are subsequently modified, revoked, or held in a court of competent jurisdiction to be invalid, Client and NTT DATA agree to cooperate in good faith to promptly suspend the transfer or to pursue a suitable alternate mechanism that can lawfully support the transfer.
13. Return Or Destruction Of Personal Data
13.1Client deletion. For certain Services, Client is responsible for installing, hosting, processing and using Personal Data. Here only Client can access, extract and delete Personal Data stored in that Service. Where the particular Service does not support access, retention or extraction of software provided by Client, NTT DATA has no liability for the deletion of Personal Data as described in this clause 0.
13.2Delete or return. Where these Terms require NTT DATA to retain Personal Data, NTT DATA will delete that Personal Data within the period agreed to in these Terms, unless NTT DATA is permitted or required by legal, regulatory, judicial, audit or internal compliance requirements to retain such Personal Data. Where the retention of Personal Data has not been addressed in these Terms, NTT DATA will either delete, destroy or return all Personal Data to Client and destroy or return any existing copies when NTT DATA has finished providing Services:
- related to the processing;
- when this DPA terminates;
- Client requests NTT DATA to do so in writing; or
- NTT DATA has otherwise fulfilled all purposes agreed in the context of the Services related to the processing activities where Client does not require NTT DATA to do any further processing.
13.3Certificate of destruction. NTT DATA will provide Client with a destruction certificate at Client's request. Where the deletion or return of the Personal Data is impossible for any reason, or where backups and/or archived copies have been made of the Personal Data, NTT DATA will retain such Personal Data in compliance with applicable Data Protection Laws.
13.3Third parties. On termination of this DPA, NTT DATA will notify all sub-processors supporting its processing and request that they either destroy the Personal Data or return the Personal Data to Client.
14. Liability And Warranty
14.1Any limitation of liability in these Terms will apply to this DPA, other than to the extent such limitation (a) limits the liability of the parties to Data Subjects or (b) is not permitted by applicable law.
15. Notice
15.1Any notice or other communication given to a party under or in connection with this DPA must be in writing and delivered to the other party by email.
15.2Clause 0 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.
15.3Any notice or other communication will be deemed given when:
- delivered in person;
- received by mail (postage prepaid, registered or certified mail, return receipt requested); or
- received by an internationally recognized courier service (proof of delivery received by the noticing party) at the physical notice address (as identified above), with an electronic copy sent to the electronic notice address (as identified in the table above).
16. Miscellaneous
16.1Conflict of terms. The Terms to which this Data Processing Agreement is annexed shall remain in full force and effect, except as expressly modified by this DPA. In the event of any conflict between the provisions of this DPA and the Terms, the provisions of this DPA shall prevail. Unless expressly stated otherwise, in the event of any conflict between this DPA and applicable Data Protection Laws, the applicable Data Protection Laws shall prevail.
16.2Governing law. This DPA is governed by the laws of the country specified in the relevant provisions of these Terms and the EU SCCs and UK Addendum are governed by the laws as provided for in the EU SCCs or UK Addendum.
16.3Dispute resolution. Any disputes arising from or in connection with this DPA will be brought exclusively before the competent court of the jurisdiction specified in the relevant provisions of these Terms.
16.4Amendments. NTT DATA will publish any intended amendments to this DPA on an NTT DATA website or send written notification to the Client at least 14 days in advance, allowing the Client to object to such amendments. Such objection must be made in writing to the NTT DATA contact mentioned in 0 within ten days of notification. Client's failure to submit a written objection to the intended amendments within ten days of notification will be deemed acceptance of the amendments to this DPA. The Parties may agree on special conditions to supplement or amend this DPA by adding such conditions to an Order Form.
Attachment A - Contact Points
Contact information of the of Client:
Where applicable, as set forth in these Terms, Order Form, or as provided for on the Client's website or to be provided by the Client in writing.
Contact information of the data protection officer of NTT DATA:
Contact information: Physical address; phone; email Contact Information of NTT DATA's Global Data Protection Officer: Ashleigh Meiring, Vice President, Data Privacy & Protection; privacyoffice@nttdata.com
Attachment B - Particulars of Processing
Categories of Data Subjects whose personal data is transferred
NTT DATA acknowledges that, depending on Client's use of the Services, the data importer may process the personal data of any of the following types of Data Subjects:
- Employees, contractors, temporary workers, agents and representatives of data exporter;
- Users (e.g., Clients end users) and other Data Subjects that are users of the Services;
- Juristic or legal persons (where applicable).
Categories of personal data transferred
NTT DATA acknowledges that, depending on Client's use of the Services, the types of Personal Data processed by NTT DATA may include, but are not limited to the following:
- Basic personal data (for example first name, last name, email address and work address);
- Bank account information;
- Authentication data (for example username and password);
- Contact information (for example work email and phone number);
- Professional or employment-related information (for example, employer name and job title);
- Unique identification numbers and signatures (for example IP addresses);
- Location data (for example, geo-location network data);
- Device identification (for example IMEI-number and MAC address).
Sensitive data transferred
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. [add applicable categories and delete any categories which are not applicable]
- Biometric Information (for example fingerprints at NTT DATA data centers);
NTT DATA will notify Client in writing to the extent NTT DATA needs to collect additional sensitive data beyond those listed above in order to provide the Services. Please see Attachment C for applied restrictions.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Personal data may be transferred on a continuous basis in order to provide the Services under the existing Terms
Nature of the processing
The Personal Data transferred will be subject to the following basic processing activities:
- Receiving data, including collection, accessing, retrieval, recording, and data entry
- Holding data, including storage, organisation and structuring
- Using data, including analysing, consultation, testing, automated decision making and profiling
- Updating data, including correcting, adaptation, alteration, alignment and combination
- Protecting data, including restricting, encrypting, and security testing
- Sharing data, including disclosure, dissemination, allowing access or otherwise making available
- Returning data to the data exporter or Data Subject
- Erasing data, including destruction and deletion.
Purpose(s) of the data transfer and further processing
The purpose of processing personal data is for NTT DATA to provide the Services under the existing Terms.
This may include:
- Provision of Services: To provide products and services in line with these Terms;
- Ticket Resolution: To communicate and co-ordinate resolution of support requests in a timely manner;
- Business Process Improvements: To improve the way Services are delivered to Client;
- Reporting on Contract Performance: To report on contracted services and resolution activities;
- Billing and contract management: To manage contracts, contract renewals and associated invoicing;
- Security and Authentication: To identify and verify the identity of individuals prior to providing access to systems and data; coordinate responses to potential information security events; and
- Administration of systems: To ensure the availability and security of systems
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
See clause 13 of the DPA.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
A list of NTT DATA's sub-processors that NTT DATA directly engages for the specific Services as a processor is available on request to the NTT DATA contact mentioned in 0 or as otherwise made available on a NTT DATA website. Any such sub-processors will be permitted to obtain personal data only to provide some or all of the Services NTT DATA has engaged them to provide, and they are prohibited from using personal data for any other purpose.
Authorized persons
NTT DATA will only process the personal data on Client's documented instructions from the following categories of persons that the Client authorizes to give personal data processing instructions to NTT DATA:
As advised by Client in writing from time to time.
Attachment C - Technical and Organizational Measures
Introduction
At NTT DATA it is our vision, through technology and innovation, to enable a secure and connected future. We have
From strategic consulting to leading-edge technologies, NTT DATA enables experiences that transform organizations for success, disrupt industries for good and shape a better society for all.
Our technical and organizational measures describe how we ensure the protection of personal data in a transparent, fair, ethical and lawful way. They are based on industry best practices and applicable legal requirements in jurisdictions in which we operate, taking into account the nature of the data we process and cost of implementation.
If you have any questions about these technical and organizational measures or how they relate to our products, services and solutions, please contact privacyoffice@nttdata.com.
(A) Data Privacy and Protection Measures
1. Governance And Operating Model
1.1NTT DATA is committed to demonstrating accountability when processing personal data. We have the appropriate organizational structures, roles and responsibilities for managing and providing oversight of the processing of personal data.
1.2In each jurisdiction where we operate, organizational units are required to dedicate appropriate resources to comply with applicable data protection laws. This includes appointing skilled data privacy resources to oversee compliance, as well as establishing appropriate reporting structures.
1.3NTT DATA reports on the design and operating effectiveness of data privacy and protection activities to senior management on a periodic basis.
2. Policies, Processes, And Guidelines
2.1NTT DATA has implemented and communicated its policies, processes, standards and guidelines that detail how NTT DATA employees are expected to process personal data.
2.2NTT DATA has defined and communicated privacy notices that provide information to employees, clients and other stakeholders about how personal data is processed.
2.3NTT DATA has implemented processes and templates for performing risk assessments, including data protection impact assessments (DPIAs), legitimate interest assessments (LIAs) and transfer risk assessments, in accordance with applicable data protection laws.
3. Data Protection By Design
3.1NTT DATA is committed to implementing reasonable measures to support its clients' ability to comply with data protection laws. As far as possible, the principles of data protection by design and by default are applied during the development of NTT DATA products, services and solutions.
4. Data Landscape
4.1NTT DATA has implemented processes to identify, record, assess and understand the personal data that it processes.
4.2NTT DATA maintains a record of the personal data processed in accordance with applicable data protection laws.
5. Information Lifecycle Management
5.1NTT DATA has implemented policies and processes to ensure that personal data is processed appropriately throughout its lifecycle (from collection through to use, retention, disclosure and destruction).
5.2NTT DATA maintains data retention policies and schedules, which are aligned to applicable laws. NTT DATA retains personal data only where there is a legitimate business reason for doing so, and in accordance with its obligations under law. NTT DATA destroys, deletes or deidentifies personal data when the retention period lapses and there is no legitimate business interest to retain the personal data for a longer period.
5.3NTT DATA keeps the personal data processed on behalf of its clients in accordance with client requirements and applicable laws and will securely destroy, delete, deidentify or return personal data when requested and where there are no further obligations to retain the personal data under applicable law.
5.4NTT DATA has implemented all reasonable efforts to ensure that personal data is accurate, complete and up to date.
6. Data Subject Rights
6.1Data protection laws in certain countries provide Data Subjects with specific rights about their personal data.
6.2Data protection laws in certain countries provide data subjects with specific rights in relation to their personal data. NTT DATA is committed to upholding these rights and responding to data subject requests in a timely, transparent, fair, ethical and lawful way.
6.3NTT DATA has implemented appropriate policies and procedures to uphold the data subject rights in accordance with applicable data protection laws.
6.4NTT DATA supports the following data subject rights:
- Right to be informed
- Right of access
- Right to rectification
- Right to be forgotten
- Right to data portability
- Right to restrict use
- Right to object (including the right to opt-out of direct marketing and the sale of personal data)
- Right to challenge automated decisions
- Right to nondiscrimination
- Right to complain
6.5NTT DATA ensures appropriate channels are available to data subjects so they can exercise their rights in relation to personal data that NTT DATA may process about them.
6.6NTT DATA maintains a record of all data subject requests received and the actions taken in response to these requests.
6.7NTT DATA will provide all reasonable support to clients in responding to data subject requests, in accordance with existing Terms.
6.8NTT DATA has established policies and procedures for responding to requests from public authorities to access personal data in accordance with applicable laws and contractual requirements. NTT DATA maintains a record of these requests and their outcomes.
7. Cross-border Transfers
7.1NTT DATA establishes appropriate safeguards (such as adequacy decisions, standard contractual clauses and other tools set out in applicable legislation) when engaging in cross-border data transfers.
7.2When personal data is transferred across borders, NTT DATA performs transfer impact assessments (TIAs) to ensure the destination country offers an equivalent level of protection to the rights and freedoms of data subjects as the country where data was originally collected. Where such equivalence does not exist, we will assess and adopt supplementary measures to support data subject rights in accordance with our policies and legislative requirements. Where such supplementary measures cannot be implemented, NTT DATA will cease the transfer of personal data.
7.3NTT DATA relies on standard contractual clauses to support the lawful transfer of personal data outside the country where it was originally collected. To support such transfers, appropriate these Terms are in place with NTT DATA subsidiaries, group companies, affiliates, processors, sub-processors, and clients.
8. Regulatory
8.1NTT DATA monitors changes to data protection laws in the countries in which it operates and has implemented processes and tools to support compliance.
9. Training And Awareness
9.1NTT DATA is committed to implementing a culture of awareness and compliance through ongoing training and awareness initiatives. We require all employees to complete mandatory data privacy and protection training on a periodic basis. Training materials and related policies, processes, standards and guidelines are available to employees and communicated regularly. Where required, local, regional or functional training is provided to support employees to act in line with the requirements in specific countries, regions or business functions.
10. Security For Privacy
10.1NTT DATA has implemented appropriate technical and organizational measures to ensure the confidentiality, integrity and availability of personal data, taking into account the state of the art, cost of implementation and the nature, scope, context and purpose of processing personal data, as well as the risks to the rights and freedoms of data subjects.
10.2NTT DATA's security methodologies are aligned to ISO 27001 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF).
11. Breach Response And Notification
11.1NTT DATA has policies, processes and procedures for identifying, detecting, responding to and recovering from a personal data breach, as well as for notifying appropriate stakeholders in the event of such a breach. These include mechanisms for performing a root cause analysis and undertaking corrective actions.
11.2NTT DATA is committed to ensuring that applicable data protection authorities, affected clients and affected data subjects are notified in the event of a personal data breach, in compliance with applicable data protection laws and any contractual commitments.
11.3NTT DATA maintains a record of all personal data breaches and the actions taken in response to these events.
11.4Section B: Information security measures outlines our incident management measures to identify, detect, respond and recover from information security incidents.
12. Third Party Management
12.1NTT DATA is accountable for the actions of processors and sub-processors who process personal data on our behalf. We assess the ability of these processors and sub-processors to protect personal data in accordance with NTT DATA standards at the time of selection and on a periodic basis thereafter.
12.2NTT DATA processors and sub-processors are required to sign appropriate agreements that govern the processing and protection of personal data. These agreements include requirements to ensure that the same obligations are passed to any other processors who may process personal data.
(B) Information Security Measures
NTT DATA is committed to ensuring that information security is implemented and properly managed in order to protect the confidentiality, integrity and availability of personal data.
NTT DATA has established appropriate policies, processes, procedures, standards and guidelines to ensure the security of data that it processes. NTT DATA's security methodologies are aligned to ISO 27001 as well as other industry best practices.
13. Information Security Roles And Responsibilities
13.1Roles and responsibilities for information security have been formally assigned, with reporting lines that ensure
13.2Roles and responsibilities for information security, including a Chief Security Officer and Business Information Security Officers throughout the organization, have been formally assigned, with reporting lines which ensure the independence of the function.
13.3NTT DATA employees are responsible for acting in accordance with our information security policies, processes, standards and guidelines in their day-to-day business activities.
14. Information Security Policies
14.1NTT DATA has documented and published a set of information security policies. These policies and supporting documentation are reviewed periodically.
15. Mobile Device Management
15.1NTT DATA has established a zero trust architecture framework to implement and maintain security controls to access and interact with NTT DATA systems and information assets. This framework includes:
- End-user device management (EDM) policies and supporting procedures.
- Controls and tools to maintain the security.
- Confidentiality, availability and integrity of enterprise data. This data could be housed in or accessible via endpoint user devices (including mobile phones, tablets and devices allowing remote access).
16. Human Resources
16.1NTT DATA performs background and employment screening for its employees, to the extent permitted under applicable law, to validate their suitability for hiring, and for handling company and client information (including personal data). The extent of the screening is proportional to the business requirements and classification of information that the employee will have access to.
16.2NTT DATA requires that all employees (including contractors and temporary employees) agree to maintain the confidentiality of company and client data (including personal data).
16.3NTT DATA employees are required to complete information security awareness training and periodic refresher training. Information security policies and supporting procedures, processes and guidelines are made available to employees. Employees also receive relevant information about trends, threats and best practices. Security awareness campaigns are run periodically to ensure continued awareness.
17. Acceptable Use
17.1NTT DATA has established policies that support the proper and effective use of our information assets, which include computer and telecommunications resources, products, services, solutions and IT infrastructure.
17.2NTT DATA has established information classification policies to support appropriate controls for handling information based on its classification. Information and assets are protected in line with the classification label.
18. Access Controls
18.1NTT DATA has established access control policies, supporting procedures and logical and physical access measures to ensure that only authorized persons have access to information, based on the principles of least privilege.
18.2Where applicable, NTT DATA has applied industry-standard encryption at rest and in transit to ensure that personal data is protected against any unauthorized access or disclosure.
18.3Access reviews are periodically performed to ensure only authorized individuals have access to NTT DATA systems and information assets.
18.4NTT DATA has undertaken reasonable efforts to limit the number of users who have privileged access to NTT DATA systems and information assets.
18.5NTT DATA does not permit sharing of accounts or credentials unless this has been approved through the relevant exception management process.
19. Asset Management And Classification
19.1NTT DATA has established policies which govern the classification and handling of physical and informational assets, including the secure disposal of assets, to ensure that the information is protected at the appropriate level.
19.2Assets are based on business criticality to determine confidentiality requirements. Industry guidance for handling personal data provides the framework for technical, organizational and physical safeguards. These safeguards may include controls such as access management, encryption, logging and monitoring, and data destruction.
20. Physical And Environmental Security
20.1NTT DATA has implemented reasonable and appropriate measures in line with our physical security policies to prevent unauthorized physical access or damage to, or interference with information, applications, systems, databases and infrastructure. These include:
- Physical access controls
- Monitoring and auditing of physical access
- Protection from environmental hazards
- Securing physical assets
- Handling of physical assets
- Maintenance and disposal of physical assets
- Clear desk and screen practices
- Visitors access and supervision
21. Operational Security
21.1NTT DATA has established appropriate specialist teams who are responsible for managing and protecting NTT DATA's information systems and infrastructure.
21.2NTT DATA has established policies and supporting procedures for managing changes to business processes, information systems and infrastructure. NTT DATA has established several governance structures to review and approve any changes based on the size and scope of the change and strategic objectives. All requests and their outcomes are logged and documented.
21.3NTT DATA has established threat and vulnerability management programs, supported by industry-standard tools, for identifying, managing and mitigating risks to company information, including the personal data of employees and clients. This includes next-generation endpoint detection and response (EDR) for antivirus and antimalware tools, regular scanning of environments, patching protocols, and the management of remediation and improvement activities.
21.4Capacity requirements are continuously monitored and regularly reviewed. Systems and networks are managed and scaled in line with these reviews.
21.5System availability includes architecture, high-availability design, disaster recovery, and/or backups based on the risk and availability requirements for each system. The method for maintaining system availability or recovery, including the scope and frequency of backups, is determined by NTT DATA business requirements, including client requirements, and the criticality of the information. Disaster recovery plans are tested periodically. Backup processes are monitored to ensure the successful completion of backups, as well as manage any backup issues, exceptions or failures.
21.6NTT DATA applies reasonable efforts to maintain audit logging on applications and systems. Logs are periodically reviewed and are available for investigation purposes. Access to logs is strictly limited to authorized personnel only.
22. System Acquisition, Development And Maintenance
22.1NTT DATA has established a zero trust architecture framework to govern the design, acquisition, development and maintenance of information systems and architecture.
22.2Architecture and design policies and supporting standards and procedures exist to ensure that security-by-design principles are applied within the software development lifecycle.
23. Third Party Management
23.1NTT DATA has established policies and practices for third party management to ensure that information assets are protected when NTT DATA engages third party service providers and/or processors. These include requirements for information security due diligence and information security risk assessments to be performed to ensure that:
- Information security requirements are clearly articulated and documented in these Terms in accordance with NTT DATA's information security standards.
- NTT DATA service providers and processors implement the same level of protection and control as NTT DATA.
- Service providers and processors are required to report any suspected or actual information security incidents to NTT DATA in a timely manner.
24. Information Security Incident Management
24.1NTT DATA has policies, processes and procedures for identifying, detecting, responding to and recovering from an information security incident, including personal data breaches, and notifying appropriate stakeholders in the event of such an incident. These include mechanisms for performing a root cause analysis and undertaking corrective actions to remediate and prevent a reoccurrence.
24.2NTT DATA has established enterprise-wide security operations to proactively monitor and manage all network and computing assets. These operations are supported by technical tools for information security incident response and recovery.
25. Business Continuity
25.1NTT DATA has established business continuity and disaster recovery plans. NTT DATA has adopted a layered approach to business continuity to ensure the availability of systems and data.
26. Compliance
26.1NTT DATA has established roles and responsibilities for identifying laws and regulations that affect our business operations. Responsibility for compliance with laws and regulations is established at a group and regional level to ensure NTT DATA meets global and local requirements.
Attachment D - EU Standard Contractual Clauses
1. Definitions
1.1For the purposes of this Attachment D, the following definitions will apply:
- "C-to-P Transfer Clauses" means Sections I, II, III and IV (as applicable) in so far as they relate to Module Two (Controller-to-Processor) within the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by EC Commission Decision of 4 June 2021.
- "P-to-C Transfer Clauses" means Sections I, II, III and IV (as applicable) in so far as they relate to Module Four (Processor-to-Controller) within the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by EC Commission Decision of 4 June 2021.
- "P-to-P Transfer Clauses" means Sections I, II, III and IV (as applicable) in so far as they relate to Module Three (Processor-to-Processor) within the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by EC Commission Decision of 4 June 2021.
2. All Modules
2.1If, in the performance of the Services, Personal Data that is subject to EU Data Protection Laws is transferred from a Data Exporter to a Data Importer, then the parties must comply with the terms of the EU SCCs (as further described in section 3 to 5 below) and the following provisions will apply:
- Clause 7 (docking clause) of the EU SCCs will not apply.
- The option under Clause 11 (redress) of the EU SCCs will not apply.
- Any dispute arising from the EU SCCs will be resolved by the courts of an EU Member State, as specified in these Terms. Where no EU Member State is specified, disputes will be resolved by the courts of the Netherlands.
- Annex I.A to the EU SCCs (List of the Parties): The activities relevant to the transfer of Personal Data under the EU SCCs relate to the Services provided by NTT DATA to Client (see details on front page) under the Client These Terms. Attachment A includes the contact person's name, position and contact details. The parties agree that their signature to the Client These Terms, to this DPA or to any other binding document which otherwise incorporates the DPA will be considered as signature to the SCCs in accordance with the terms set out therein.
- The contents of Attachment B will form Annex I.B to the EU SCCs (Description of Transfer).
- The supervisory authority of the country where the Client's registered office is located will act as the competent supervisory Authority for the purposes of Annex I.C of the EU SCCs (Competent Supervisory Authority).and will be determined by reference to the list of supervisory authorities of the EFTA EEA States found here: https://edpb.europa.eu/about-edpb/about-edpb/members_en
.
3. C-P Transfer Clauses
3.1Where Client is the controller and Data Exporter of Personal Data and NTT DATA is a processor and Data Importer in respect of that Personal Data, then the parties must comply with the terms of the C-to-P Transfer Clauses and the following provisions will also apply:
- Option 2 under Clause 9(a) (general written authorisation) will apply and "[Specify time period]' will be replaced with "14 (fourteen) days';
- For the purposes of Clause 13(a) (supervision), the relevant option set out in Clause 13(a) will apply depending on whether the Data Exporter is (i) established in an EU Member State, (ii) is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with its Article 3(2) of the GDPR and has appointed a representative pursuant to Article 27(1) of the GDPR or (iii) is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of the GDPR;
- Option 1 under Clause 17 (governing law) will apply and the governing law will be the EU Member State specified in these Terms. Where no EU Member State is specified, the governing law will be the law of the Netherlands.
- The contents of 0 to this DPA (Technical and Organizational Measures) will form Annex II of the C-P Transfer Clauses (Technical and organisational measures including technical and organisational measures to ensure the security of the data); and
- The list of sub-processors referred to in 0 to this DPA will form Annex III of the C-P Transfer Clauses (List of Subprocessors).
4. P-P Transfer Clauses
4.1Where NTT DATA is the processor and Data Exporter of the Personal Data and the sub-processer is the Data Importer of that Personal Data, then the parties will comply with the terms of the P-to-P Transfer Clauses and the following provisions will also apply.
- For the purposes of Clause 8.6(c) and (d) (security of processing), the sub-processor must provide notification of a personal data breach concerning Personal Data processed by the sub-processor to NTT DATA and not directly to the Client. Where appropriate, NTT DATA will forward the notification to the Client;
- For the purposes of Clause 8.9 (documentation and compliance), all enquiries from a Client will be provided to the Client by NTT DATA;
- Option 2 under Clause 9 (general written authorization) will apply and "[Specify time period]' be replaced with '14 days'. The parties also agree that the controller has delegated the decision making and approval authority for sub-processing to the Client for the purposes of Clause 9 (use of sub-processors). NTT DATA has the Client's general authorization (on behalf of the controller) for the engagement of the sub-processors referred to in Attachment B to this DPA. NTT DATA will follow the process set out in clause 0 of this DPA to inform Client and not the controller of any intended changes to that list. Where appropriate, the Client will inform the controller of any changes;
- For the purposes of Clause 10 (Data Subject rights), NTT DATA will notify Client and not the controller about any request it has received directly from a Data Subject. Where appropriate, the Client will forward the notification to the relevant controller. The authorization to respond to the request must be provided to NTT DATA by the Client on behalf of the controller.
- For the purposes of Clause 13(a) (supervision), the relevant option set out in Clause 13(a) will apply depending on whether Data Exporter is (i) established in an EU Member State, (ii) is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with its Article 3(2) of the GDPR and has appointed a representative pursuant to Article 27(1) of the GDPR or (iii) is not established in an EU Member State, but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of the GDPR;
- For the purposes of Clause 15 (obligations of the data importer in case of access by public authorities), NTT DATA will notify Client and not the Data Subject(s) in case of access by public authorities. NTT DATA agrees to provide information on request for access by public authorities to the Client in accordance with section 0 of this Attachment D. In the event that NTT DATA receives a request from the competent data protection authorities for the information it preserves pursuant to Clauses 15.1 (a) to (c) or 15.2(b) under the P-P Transfer Clauses it will inform the Client and involve the Client in responding to the competent data protection authority;
- Option 1 under Clause 17 (governing law) will apply and the governing law will be the EU Member State specified in these Terms. Where no EU Member State is specified, the governing law will be the law of the Netherlands.
- The contents of 0 to this DPA (Technical and Organizational Measures) will form Annex II of the P-P Transfer Clauses (Technical and organisational measures including technical and organisational measures to ensure the security of the data).
5. P-C Transfer Clauses
5.1Where NTT DATA is the processor and Data Exporter of Personal Data and Client is a controller and Data Importer in respect of that Personal Data, then the parties will comply with the terms of the P-to-C Transfer Clauses and the governing law in Clause 17 (governing law) will be the law of an EU Member State, as specified in these Terms.
6. Additional Safeguards To The EU SCCs
6.1To the extent that the EU SCCs apply, the following safeguards will apply to the EU SCCs set out in this section 6 of this 0.
6.2Where in the Client's reasonable opinion transfer impact assessments, or risk assessments, are necessary, NTT DATA will upon request promptly provide reasonable assistance and cooperation to the Client (at the Client's own cost) about the carrying out of the transfer impact assessments, or risk assessments, to enable the Client to normalize the international data transfers.
6.3Each party warrants that it has no reason to believe that applicable laws to which it is subject, including any requirements to disclose Personal Data or measures authorising access by public authorities, prevent it from fulfilling its obligations under this DPA and Data Protection Laws. Each party declares that in providing this warranty, it has taken due account in particular of the following elements:
- the specific circumstances of the processing, including the scale and regularity of processing subject to such applicable laws; the transmission channels used; the nature of the relevant Personal Data; any relevant practical experience with prior instances, or the absence of requests for disclosure from public authorities received by it for the type of Personal Data processed by it;
- the applicable laws to which it is/are subject, including those requiring to disclose data to public authorities or authorizing access by such authorities, as well as the applicable limitations and safeguards; and
- safeguards in addition to those under this DPA, including the technical and organisational measures applied to the processing of Personal Data by NTT DATA and the relevant sub-processor.
6.4Each party warrants that, in carrying out the assessment under section 0 above, it has made its best efforts to provide relevant information and agrees that it will continue to cooperate in ensuring compliance with this DPA. The parties agree to document this assessment and make it available on request and it agrees that such assessment may also be made available to a data protection authority.
6.5NTT DATA agrees to promptly notify the Client if, after having agreed to this DPA and for the duration of the term of this DPA, NTT DATA has reason to believe that it is or has become subject to applicable laws not in line with the requirements under section 0, including following a change of applicable laws to which is it is subject or a measure (such as a disclosure request) indicating an application of such applicable laws in practice that is not in line with the requirements under section 0. Following such notification, or if Client otherwise has reason to believe that NTT DATA can no longer fulfil its obligations under this DPA (including in relation to the relevant sub-processor), Client will promptly identify supplementary measures (such as, for instance, technical or organisational measures to ensure security and confidentiality) to be adopted by itself or NTT DATA (and/or the relevant sub-processor), at Client's cost, to protect the Personal Data against any interference that goes beyond what is necessary in a democratic society to safeguard national security, defence and public security, if appropriate in consultation with the competent data protection authority.
6.6Unless prohibited by applicable law, NTT DATA agrees to promptly notify Client if it (or the relevant sub-processor to whom a transfer is made):
- receives a legally binding request by a public authority under applicable laws to which it (or the relevant sub-processor) is subject for disclosure of Personal Data. NTT DATA agrees to review (and to procure that the relevant sub-processor to whom the transfer is made will review) the request, having regard to applicable laws to which it (and the relevant sub-processor) is subject, the legality of the request for disclosure, notably whether it remains within the powers granted to the requesting public authority. The notification to the Client will include information about the Personal Data requested, the requesting authority and the legal basis for the request;
- becomes aware of any direct access by public authorities to Personal Data under applicable laws to which it (or the relevant sub-processor) is subject; such notification will include all information available to NTT DATA (and the relevant sub-processor).
6.7If NTT DATA (or the relevant sub-processor to whom the transfer is made) is prohibited by applicable law from notifying the Client as set out in section 0, NTT DATA will use its best efforts to obtain a waiver of the prohibition, to communicate as much information as possible, as soon as possible to the Client. If NTT DATA cannot obtain a waiver of the prohibition and is under a compelling legal obligation to disclose a legally binding request from a public authority, NTT DATA will provide the minimum information permitted by applicable law when responding to a request. Unless NTT DATA is legally prohibited from doing so (for example if there is a prohibition under criminal law to preserve the confidentiality of the investigation by the public authority), NTT DATA will provide the Client with any responses provided to the public authority.
6.8NTT DATA agrees to document its (and the relevant sub-processors) legal assessment as well as any challenge to the request for disclosure and, to the extent permissible under applicable laws to which it (or the relevant sub-processor) is subject, make it available to Client. It will also make it available to the competent data protection authority upon request.
6.9NTT DATA will use reasonable endeavours to provide (and to procure that the relevant sub-processor to whom the transfer is made will provide) the minimum amount of information permissible when responding to a request for disclosure, based on a reasonable interpretation of the request.
6.10To the extent permissible under the applicable laws to which NTT DATA (and the relevant sub-processor) is subject, NTT DATA agrees to publish transparency reports or summaries regarding requests from public authorities to NTT DATA for access to data and the kind of reply provided, insofar publication is allowed by applicable law.
6.11NTT DATA agrees to preserve the information under section 0 for the duration of the processing and make it available to the competent data protection authority upon request.
6.12NTT DATA will comply with its Public Authority Data Request Policy governing the disclosure of Personal Data in response to requests from public authorities.
6.13NTT DATA will inform (and will procure that the relevant sub-processor to whom the transfer is made will inform) Data Subjects in a transparent and easily accessible format, on its website, of a contact point authorised to handle complaints or requests and NTT DATA will (and will procure that the sub-processors will) promptly deal with any complaints about requests from public authorities.
Attachment E - Cross-border specific jurisdiction provisions
1. General
1.1In the interest of meeting their obligations under Data Protection Laws, the parties agree that this General section 1 of Attachment E will apply where:
- Personal Data is transferred from a Data Exporter to a Data Importer; and
- the jurisdiction from which the Personal Data originates recognizes the EU SCCs as an adequacy mechanism, or such jurisdiction has not adopted another legally sufficient transfer mechanism under Data Protection Laws or such Restricted Transfer is not otherwise governed by country-specific laws, under this Attachment E, or
- the cross-border transfer mechanism for the Data Importer to process Personal Data outside China to comply with cross-border transfer restrictions is either a Security Assessment by the CAC, the China SCC"s or a Personal Information Protection Certification.
1.2For the purposes of this General section of Attachment E the EU SCCs will be amended as follows:
-
the EU SCCs are deemed to be amended to the extent necessary so they operate:
- for transfers made by the Data Exporter to the Data Importer, to the extent that applicable Data Protection Laws apply to the Data Exporter"s processing when making that Restricted Transfer; and
- to provide appropriate safeguards for the transfers in accordance with applicable Data Protection Laws.
- references to "Regulation (EU) 2016/679" or "that Regulation" in the EU SCCs must be understood as references to "applicable Data Protection Laws";
- references to specific articles of "Regulation (EU) 2016/679" in the EU SCCs are removed and replaced with the equivalent article or section of applicable Data Protection Laws, where appropriate;
- references to "Regulation (EU) 2018/1725" are removed;
- references to a "Member State" or "EU Member States" in the EU SCCs must be understood as references to "the country where the Data Exporter is established", except for Clause 11(c)(i), where applicable, where reference to "Member State" will be replaced with "country"; and
- the footnotes to the EU SCCs are removed.
1.3For the avoidance of any doubt, the parties do not intend to grant third-party beneficiary rights to Data Subjects under the EU SCCs when those Data Subjects would not otherwise benefit from such rights under Data Protection Laws. The higher level of protection provided by the EU SCCs will only apply in jurisdictions outside Europe where such a higher level of protection is required for the protection of Personal Data being transferred under Data Protection Laws.
2. China
2.1Where a Restricted Transfer of Personal Data is required, the Data Importer may only lawfully receive and process Personal Data in a foreign jurisdiction through one of the following cross-border transfer mechanisms available under China Data Protection Law:
- a mandatory data security assessment by the Cyberspace Administration of China, or
- the certification of Personal Data protection by a professional institution, or
- the signing of the Standard Contract.
2.2The parties must attach the mechanism that enables the Data Importer to process the Personal Data in a foreign country to this DPA.
2.3If any Personal Data transfer between the Data Importer and the Data Exporter requires execution of the Standard Contract, the parties will execute the Standard Contract and take all other actions required to legitimise the transfer, including filing the Standard Contract with the competent authorities, or implementing any necessary supplementary measures.
2.4The Data Importer will not transfer any Personal Data to another country unless the transfer complies with Data Protection Laws.
2.5The Data Exporter must obtain and maintain all applicable regulatory filings, approvals, consents, and certifications from the relevant PRC authorities for the transfers of Personal Data collected and generated by the Data Exporter located in China.
3. Switzerland
3.1Where a Restricted Transfer of Personal Data from a Data Exporter to a Data Importer is subject to the GDPR and the FADP, the following additional provisions to the EU SCCs will apply for the EU SCCs to be suitable for ensuring an adequate level of protection for such transfer in accordance with Article 6 paragraph 2 letter (a) of FADP:
- "FDPIC" means the Swiss Federal Data Protection and Information Commissioner.
- "Revised FADP" means the revised version of the FADP of 25 September 2020, which came into force on 1 September 2023.
- The term "EU Member State" must not be interpreted in such a way as to exclude Data Subjects in Switzerland from the possibility pursuing their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c).
- The EU SCCs also protect the data of legal entities until the entry into force of the Revised FADP.
- The FDPIC will act as the "competent supervisory authority" insofar as the relevant Restricted Transfer is governed by the FADP.
3.2The parties will also comply with the additional safeguards to the EU SCCs as set out in section 6 of Attachment D.
4. UK
4.1Where a Restricted Transfer of Personal Data from a Data Exporter to a Data Importer is subject to UK Data Protection Laws, this section 4 of Attachment E will apply. The parties also agree to comply with the additional safeguards to the EU SCCs as set out in section 6 of Attachment D.
Part 1 - Tables
Table 1: Parties and signatures
| Start date | DPA effective date | |
| The Parties | Exporter (who sends the Restricted Transfer) | Importer (who receives the Restricted Transfer) |
| Parties' details | NTT DATA or Client, as applicable. See Attachment B | NTT DATA or Client, as applicable. See 0. |
| Key Contact | Please see Attachment A | |
| Signatures (if required for the purposes of Section 2) | N/A | N/A |
Table 2: Selected SCCs, Modules and Selected Clauses
| Addendum EU SCCs | The version of the Approved EU SCCs which this Addendum is appended to, detailed in Attachment E, including the Appendix Information. |
Table 3: Appendix Information
"Appendix Information" means the information which must be provided for the selected modules as set out in the Appendix of the Approved EU SCCs (other than the parties), and which for this DPA is set out in:
| Annex 1A: List of Parties | The contents of Annex I.A of 0 |
| Annex 1B: Description of Transfer | See 0 |
| Annex II: Technical and organisational measures including technical and organisational measures to ensure the security of the data | See 0 |
| Annex III: List of Sub processors (Modules 2 and 3 only) | See 0 |
Table 4: Ending this Addendum when the Approved Addendum Changes
| Ending this Addendum when the Approved Addendum changes |
Which Parties may end this Addendum as set out in Section 19:
|
Part 2 - Mandatory Clauses
Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.
Attachment F - California Consumer Privacy Act Terms
These CCPA terms only apply where NTT DATA processes personal data of California residents.
1. Definitions
1.1The following definitions apply:
- "CCPA" means the California Consumer Privacy Act of 2018, as amended (Cal. Civ. Code §§ 1798.100 to 1798.199), and any related regulations or guidance provided by the California Attorney General.
- "Contracted Business Purposes" mean the purposes for processing personal information as set out in 0.
- "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.
1.2.The following lower case terms used but not defined in this 0 such as "aggregate consumer information", "business purposes", "commercial purposes", "consumer", "de-identify", "processing", "pseudonymize", "sale", and "verifiable consumer request" will have the same meaning as set forth in §§ 1798.14 of the CCPA.
2. NTT DATA's CCPA Obligations
2.1.NTT DATA will only process Personal Information for the Contracted Business Purposes for which Client provides or permits Personal Information access, including under any "sale" exemption.
2.2.NTT DATA will not process, sell, or otherwise make Personal Information available for NTT DATA's own commercial purposes or in a way that does not comply with the CCPA. If a law requires NTT DATA to disclose Personal Information for a purpose unrelated to the Contracted Business Purposes, NTT DATA must first inform the Client of the legal requirement and give the Client an opportunity to object or challenge the requirement, unless the law prohibits such notice.
2.3.NTT DATA will limit Personal Information processing to activities reasonably necessary and proportionate to achieve the Contracted Business Purposes or another compatible business purpose.
2.4.NTT DATA must promptly comply with any Client request or instruction from Authorized Persons requiring NTT DATA to provide, amend, transfer, or delete the Personal Information, or to stop, mitigate, or remedy any unauthorized processing.
2.5.If the Contracted Business Purposes require the collection of Personal Information from consumers on the Client's behalf, Client must provide NTT DATA with a CCPA-compliant notice addressing use and collection methods that the Client specifically pre-approves in writing. NTT DATA will not modify or alter the notice in any way without the Client's prior written consent.
2.6.If the CCPA permits, NTT DATA may aggregate, de-identify, or anonymize Personal Information so it no longer meets the Personal Information definition, and may use such aggregated, deidentified, or anonymized data for its own research and development purposes.
3. Assistance with Client's CCPA Obligations
3.1.NTT DATA will reasonably cooperate and assist Client with meeting the Client's CCPA compliance obligations and responding to CCPA-related inquiries, including responding to verifiable consumer requests, taking into account the nature of NTT DATA's processing and the information available to NTT DATA.
3.2.NTT DATA must notify Client immediately if it receives any complaint, notice, or communication that directly or indirectly relates to either party's compliance with the CCPA. Specifically, NTT DATA must notify the Client within 5 working days if it receives a verifiable consumer request under the CCPA.
4. Subcontracting
4.1.NTT DATA may use subcontractors to provide the Contracted Business Purposes. Any subcontractor used must qualify as a service provider under the CCPA and NTT DATA cannot make any disclosures to the subcontractor that the CCPA would treat as a sale.
4.2.For each subcontractor used, NTT DATA will give Client an up-to-date list disclosing:
- The subcontractor's name, address, and contact information.
- The type of services provided by the subcontractor.
- The Personal Information categories disclosed to the subcontractor in the preceding 12 months.
4.3.NTT DATA remains fully liable to the Client for the subcontractor's performance of its these Terms obligations. NTT DATA will audit a subcontractor's compliance with its Personal Information obligations in accordance with our policies on a periodic basis and provide the Client with the audit results on request.
5. CCPA Warranties
5.1.Both parties will comply with all applicable requirements of the CCPA when processing Personal Information.
Annex B - Artificial Intelligence features integrated in the software asset
1. Purpose
This Annex sets forth the general conditions for the use of Artificial Intelligence (hereinafter "AI" or "AI System") features integrated into the Software Asset.
When the Software Asset incorporates AI functionalities provided by third parties ("Third-Party AI Provider"), NTT DATA shall act solely as an integrator or intermediary of such AI functionalities under our "Global Assets AI Responsibility Model".
This shall not be construed as NTT DATA being a provider of, or bearing responsibility for, the internal operation of such third-party AI functionalities and NTT DATA does not assume obligations applicable to providers under applicable AI legislation or standards. The specific conditions applicable to the AI functionalities, the role assumed by NTT DATA in accordance with applicable AI legislation or standards, including Regulation (EU) 2024/1689, and the requirements of the third-party AI functionalities shall be detailed in the corresponding Order Form.
Where applicable, the Client must comply with the applicable licensing and usage terms of the ThirdParty AI Provider. NTT DATA shall bear no responsibility for Client's noncompliance with such applicable ThirdParty AI Provider terms.
2. Intellectual Property
When the input data for the use, customization, or training of the AI System is provided by the Client, the Client shall be responsible for ensuring that such data does not infringe the rights of third parties and that the data complies with all applicable legal and ethical requirements, including the obtaining of any necessary consents, licenses, or authorizations.
Regarding the resulting output, including any developments, configurations, or content specifically generated as a result of the execution of the AI System ("output"), unless otherwise specified in the Order Form or in the terms of the Third-Party AI Provider, and to the extent permitted under applicable law, the Client shall be the default owner. The Client acknowledges that AI-generated output may not qualify for copyright or intellectual property protection under applicable law. NTT DATA shall retain a non-exclusive, non-transferable license to use such output for purposes of maintenance, traceability, and contractual compliance.
The Client acknowledges that the ownership, use, or exploitation of the output may be subject to applicable law and the licensing and usage terms established by the Third-Party AI Providers, in which case such terms shall prevail over the provisions set forth in this section.
3. Permitted Use
The Client will use the AI and AI System solely for the purposes defined in these Terms, the corresponding Order Form, and within the scope of authorized purposes for the contracted Software Asset and always in compliance with applicable law.
The following is expressly prohibited and the Client shall refrain from the following:
- Using AI for unlawful purposes, practices prohibited under applicable AI laws, including Article 5 of the Regulation, such as exploitative profiling, subliminal manipulation, or discriminatory outcomes as defined by applicable AI laws, or activities that infringe fundamental rights.
- Generating discriminatory results or results contrary to professional ethics.
- Processing personal data without sufficient legal basis.
- Training, correcting, or introducing instructions to intentionally generate biases in the data or the output.
- Introducing or manipulating data into the AI System with the intent to "poison the model," understood as any deliberate action of introducing malicious or erroneous data or information to degrade the quality, functionality, or reliability of the AI System.
- Any other use that is prohibited by the applicable Third-Party AI Provider, as specified in the relevant Order Form.
The Client shall maintain reasonable controls to ensure compliance with these terms and shall implement usage logs when required by applicable laws.
4. Liability
4.1 Liability of NTT DATA
NTT DATA's liability in relation to the AI System shall be subject to the same limitations set forth in Clause 13 of these Terms and, where applicable, to the terms and conditions of the Third-Party AI Provider as specified in the Order Form.
In the event of defects solely attributable to NTT DATA, NTT DATA undertakes to remedy such issues within a reasonable timeframe, providing temporary solutions when necessary to mitigate any impact on the Client's operations, in accordance with the provisions of these Terms.
However, NTT DATA will not be liable for:
- Incorrect, incomplete, or unauthorized data or instructions provided by the Client, including cases where they cause biases in the AI System.
- Improper use of the AI System outside the scope of its intended purpose, agreed conditions, or technical specifications set forth in these Terms.
- Failures resulting from third-party integrations or external elements not directly controlled by NTT DATA, including hallucinations of the AI System.
4.2 Client's Responsibilities
The Client shall be responsible for supervising the use of the AI System and for informing end users about the purposes, risks, and limitations associated with the AI System, as well as with AI-generated content, by providing clear and appropriate instructions.
4.3 Indemnification
The Client will indemnify and hold NTT DATA harmless from any damage, penalty, or claim that NTT DATA may suffer as a result of the Client's non-compliance with this Annex, the conditions applicable to the use of the AI System, including those imposed by Third-Party AI Providers.
5. Generated Results
The Client acknowledges that the output will depend, among other factors, on the quality, accuracy, and relevance of the training data provided by the Client, as well as the instructions and parameters defined by the Client for training and customizing the AI System as agreed in the Order Form. NTT DATA assumes no responsibility for decisions made by the Client based on the AI System.
Where applicable, the output may be of an indicative nature only, based on data collected and processed from the sources provided and may contain errors, biases or inaccuracies. The Client acknowledges that output should be subject to human oversight and should replace the Client's judgment. NTT DATA makes no representations regarding the accuracy, legality, or suitability of such results for any specific purpose. The Client shall promptly notify NTT DATA of any serious incident, or malfunction, of the AI System or risk to fundamental rights as a result of output.