Version: 4.2
NEW Terms & Conditions
These Terms apply to the Customer’s access to and use of the RiskBase Applications and Services. They are incorporated into each Sales Order unless the Sales Order states otherwise.
Important note: where RiskBase processes personal data contained in Customer Data, RiskBase will usually act as processor and the Customer will usually act as controller. Clause 9 and Schedule 1 set out the data processing terms.
1.1 Definitions and interpretation
1.1. In these Terms, the words listed in bold shall have the following meanings:
Agreement means the applicable Sales Order together with these Terms and any schedules or documents expressly incorporated by reference.
Application(s) means the web-based application(s) made available by RiskBase from time to time, including any modules, portals, resident-facing interfaces or related online functionality identified in a Sales Order.
Assessment Output means any assessment, survey, inspection record, report, finding, action, photograph, evidence record, compliance record or other output produced through the Applications for or relating to an End Client, excluding RiskBase IPR and Customer Materials except to the extent those materials are embedded in a static output produced for that End Client.
Authorised User means an individual authorised by the Customer to access or use the Applications, including employees, agents, contractors, consultants and any other user invited by the Customer or approved by RiskBase.
Business Day means any day other than a Saturday, Sunday or public holiday in England.
Customer means the person or organisation identified as the customer in the relevant Sales Order.
Customer Materials means any templates, question sets, forms, logos, branding, report wording, methodologies, documents, data, content or other materials supplied by or on behalf of the Customer for use in connection with the Applications, excluding RiskBase IPR and Assessment Outputs.
Customer Data means all data, information, content and materials uploaded to, stored in, generated through or processed by the Applications by or on behalf of the Customer, any Authorised User or any End Client, including End Client Data.
Data Protection Laws means all applicable laws relating to data protection, privacy and electronic communications in force in the United Kingdom from time to time, including the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
End Client means any person or organisation that is the subject of a risk assessment, resident engagement process, evacuation planning process, compliance process or other activity carried out using the Applications.
End Client Data means Customer Data relating specifically to an End Client, including any resident, occupier, leaseholder, contractor, employee, visitor or other individual whose information is entered into or processed through the Applications whether entered by the Customer, an Authorised User, RiskBase at the Customer’s request, or the relevant End Client.
Excluded Event means any misuse, user error, Customer system failure, failure of Customer Data, unauthorised credential sharing, Customer configuration issue, third-party service failure outside RiskBase’s reasonable control, or other act or omission of the Customer, an Authorised User or a third party.
Fees means the fees and charges payable under the Sales Order.
Initial Subscription Term means the initial fixed period of access to the relevant Subscription-Based Services specified in the Sales Order. If no fixed period is specified for particular Applications or Services, those Applications or Services are provided as Usage-Based Services unless the Sales Order states otherwise.
Intellectual Property Rights means patents, trade marks, service marks, rights in passing off, domain names, copyright, database rights, design rights, rights in confidential information, know-how, rights in inventions and all similar rights anywhere in the world, whether registered or unregistered.
Operating Hours means 09:00 to 17:00 on Business Days, unless the Sales Order states otherwise.
Personal Data has the meaning given in Data Protection Laws.
Renewal Term means each successive renewal period applying to Subscription-Based Services after the Initial Subscription Term, as described in clause 2.2.
RiskBase means RiskBase Limited, a company incorporated in England and Wales with registered number 06222596 and registered office at 101 New Cavendish Street, 1st Floor South, London, W1W 6XH, or such other address as RiskBase notifies from time to time.
RiskBase IPR means all Intellectual Property Rights in the Applications, Services, documentation, software, database structures, templates, configuration tools, platform functionality, know-how, analytics and other materials created, owned, licensed or provided by or on behalf of RiskBase, excluding Customer Data, Customer Materials and Assessment Outputs except to the extent that any RiskBase IPR is embedded in or necessary to use them.
Sales Order means the proposal, quotation, order form, statement of work or other ordering document agreed between RiskBase and the Customer.
Services means the support, hosting, maintenance and other services provided by RiskBase in connection with the Applications, as described in these Terms, the Sales Order or otherwise agreed in writing.
Subscription-Based Services means Applications or Services provided for an Initial Subscription Term or other fixed, rolling, periodic or recurring subscription period stated in a Sales Order.
Terms means these commercial terms and conditions, including all schedules.
UK GDPR means the UK GDPR as defined in section 3(10) of the Data Protection Act 2018.
Usage-Based Services means Applications or Services, sometimes referred to as “pay as you go” or “PAYG” services, charged by reference to usage, transactions, assessments, surveys, records, reports, modules, user activity or other usage metrics, whether or not the Customer also pays a periodic fee for other Applications or Services.
1.2. In these Terms:
1.2.1. words denoting the singular include the plural and vice versa and references to persons include individuals, partnerships, bodies corporate and unincorporated associations; and
1.2.2. words such as “including”, “include”, “in particular” and “for example” are illustrative and do not limit the general meaning of the words that precede them.
1.3. If there is any conflict between these Terms and a Sales Order, the Sales Order prevails to the extent of the conflict, unless the Sales Order states otherwise.
2. Term
2.1. The Agreement starts on the date stated in the Sales Order or, if no date is stated, when the Customer first accesses the Applications or both parties otherwise agree the Sales Order.
2.2. Subscription-Based Services continue for the Initial Subscription Term and then renew for successive periods of three months each unless the Sales Order states otherwise. Either party may prevent renewal by giving at least 28 days’ written notice to expire at the end of the Initial Subscription Term or the then-current Renewal Term, or the Agreement may be terminated earlier in accordance with these Terms.
2.3. Usage-Based Services continue until terminated or closed in accordance with the Agreement. Unless a Sales Order states otherwise, Usage-Based Services do not have an Initial Subscription Term or automatic renewal period.
3. Right to access and use the Applications
3.1. Subject to the Customer paying the Fees and complying with the Agreement, RiskBase grants the Customer a non-exclusive, non-transferable, non-sublicensable right during the Term to permit Authorised Users to access and use the Applications for the Customer’s own business purposes, including providing services to the Customer’s own clients, customers and End Clients, and the purposes described in the relevant Sales Order.
3.2. The Customer may permit its own clients, customers or End Clients to access and use the Applications as Authorised Users as part of the Customer's own services. Such access does not constitute an assignment, transfer or general sub-licence of this Agreement and does not create any contractual relationship between RiskBase and those persons. The Customer remains responsible for all acts and omissions of those Authorised Users and shall ensure that they comply with the Agreement. No such Authorised User shall have any right to enforce this Agreement against RiskBase.
3.3. The Customer shall ensure that all Authorised Users comply with the Agreement. The Customer is responsible for all acts and omissions of Authorised Users as if they were the Customer’s own acts and omissions.
3.4. The Customer shall not, and shall ensure that Authorised Users do not:
3.4.1. use the Applications for any unlawful purpose or in breach of applicable law;
3.4.2. attempt to copy, modify, reverse engineer, decompile or create derivative works from the Applications except to the extent permitted by law;
3.4.3. access or use the Applications to build or support a competing product or service;
3.4.4. introduce malicious code, interfere with security controls or attempt unauthorised access;
3.4.5. share credentials or permit unauthorised persons to access the Applications; or
3.4.6. upload unlawful, infringing, inaccurate or inappropriate Customer Data.
3.5. RiskBase may suspend access to the Applications where it reasonably considers that continued access creates a security, legal, technical, operational or payment risk. RiskBase shall, where reasonably practicable, notify the Customer of the suspension and work with the Customer to resolve the issue.
3.6. All Intellectual Property Rights in the Applications, Services, documentation, software, analytics, know-how and materials created by or on behalf of RiskBase belong to RiskBase or its licensors. The Customer receives only the limited rights expressly granted in the Agreement.
3.7. RiskBase warrants that the Customer’s use of the Applications in accordance with the Agreement will not infringe any third party’s Intellectual Property Rights in the United Kingdom, provided that this warranty shall not apply to any claim arising from Customer Data, Customer configuration, use of the Applications other than in accordance with the Agreement, or any other Excluded Event.
4. Applications and Services
4.1. The Applications are designed to assist with risk management, compliance management, resident engagement, fire-safety and building-safety workflows, data collection, reporting and related processes. They are a software tool and do not replace the Customer’s own professional judgement, statutory duties, risk assessments, compliance processes or legal obligations.
4.2. The Customer remains solely responsible for:
4.2.1. selecting the Applications as suitable for its requirements;
4.2.2. its own compliance with applicable law and regulatory duties;
4.2.3. the accuracy, completeness and lawfulness of Customer Data;
4.2.4. decisions made using outputs from the Applications;
4.2.5. any fire-safety, building-safety, evacuation, remediation or resident-engagement obligations; and
4.2.6. ensuring that competent persons review and implement any relevant assessments, actions or plans.
4.3. RiskBase shall use reasonable skill and care in providing the Services. Unless the Sales Order states otherwise, support is provided by email during Operating Hours.
4.4. RiskBase may apply updates, modifications, maintenance releases and upgrades to the Applications. RiskBase shall use reasonable endeavours to avoid removing or materially reducing the core functionality of the Applications during the Term, but the Customer acknowledges that software evolves over time.
4.5. RiskBase may carry out maintenance from time to time. RiskBase shall use reasonable endeavours to schedule planned maintenance outside Operating Hours where reasonably practicable.
4.6. The Services do not include bespoke development, data cleansing, training, legal advice, compliance consultancy, risk consultancy, system integration, diagnosis of Customer systems or third-party software support unless expressly stated in a Sales Order.
5. Fees and payment
5.1. The Customer shall pay the Fees in accordance with the Sales Order. Fees are exclusive of VAT and other applicable taxes unless stated otherwise.
5.2. Invoices are payable within 28 days of the invoice date unless the Sales Order states otherwise. Payment shall be made without set-off, deduction or withholding except as required by law.
5.3. Unless the Sales Order states otherwise, the Fees for Subscription-Based Services are fixed during the Initial Subscription Term. Each Renewal Term shall renew at the Fees previously agreed for the relevant Subscription-Based Services unless RiskBase gives the Customer at least 28 days’ written notice of an increase before the start of that Renewal Term. Any increase shall take effect from the start of the relevant Renewal Term. If the Customer does not wish to accept the increased Fees, the Customer may prevent renewal in accordance with clause 2.2. If the Customer continues to access or use the relevant Subscription-Based Services after the increased Fees take effect, the Customer will be deemed to have accepted the increased Fees.
5.4. If any undisputed amount is overdue by 14 days or more, RiskBase may suspend access to the Applications and Services until payment is received.
5.5. RiskBase may charge interest on overdue amounts at the statutory rate applicable to late payment of commercial debts, together with reasonable recovery costs.
6. Customer Data
6.1. The Customer retains ownership of all Customer Data and Customer Materials. RiskBase does not acquire ownership of any Customer Data or Customer Materials, except for the rights necessary to host, store, copy, configure, process, display, reproduce, transmit and otherwise use them for the purposes of providing, maintaining, supporting, securing and improving the Applications and Services and exercising its rights and performing its obligations under the Agreement.
6.2. For the avoidance of doubt, Customer Materials form part of Customer Data where they are uploaded to, stored in or used through the Applications, but ownership of Customer Materials remains with the Customer and nothing in the Agreement transfers ownership of any Customer Materials to RiskBase.
6.3. RiskBase retains ownership of all RiskBase IPR. No Customer, Authorised User or End Client acquires any ownership rights in any RiskBase IPR, the Applications, RiskBase templates, RiskBase configuration tools, software, database structures, platform functionality or other materials owned or licensed by RiskBase, except for the limited rights expressly granted under the Agreement or a separate agreement with RiskBase.
6.4. The Customer is responsible for the legality, accuracy, quality and integrity of Customer Data and Customer Materials and for ensuring that Customer Data and Customer Materials are collected, created, uploaded, used and disclosed lawfully.
6.5. The Customer warrants that it has all rights, permissions, notices, lawful bases, consents and authorisations necessary for RiskBase to process Customer Data and Customer Materials in accordance with the Agreement.
6.6. RiskBase shall apply appropriate technical and organisational measures designed to protect Customer Data against unauthorised or unlawful processing and accidental loss, destruction or damage.
6.7. The Customer is responsible for keeping its own copies and records of Customer Data unless the Sales Order states that RiskBase is providing a specific backup or archival service.
6.8. RiskBase is not responsible for loss or unauthorised access caused by stolen, shared or misused passwords, Customer misconfiguration, Customer systems, third-party systems outside RiskBase’s control, or any Excluded Event.
6.9. The Customer acknowledges that End Clients may have legal rights in relation to their Personal Data. RiskBase shall not usually take instructions directly from an End Client in relation to End Client Data where RiskBase acts as processor. Instead, RiskBase may receive the request, help identify the relevant Customer or controller, pass the request to that person or assist the Customer in responding in accordance with clause 9 and Schedule 1. This clause does not prevent RiskBase from responding to a request where RiskBase is acting as controller for its own limited processing activities.
6.10. Where the Customer uses the Applications to carry out assessments, surveys, inspections, compliance processes or other work for or relating to an End Client, the Customer grants, and shall ensure that RiskBase is entitled to grant, the relevant End Client a perpetual, irrevocable, royalty-free licence to access, retain, use, copy and disclose the Assessment Output relating to that End Client for that End Client’s internal business, compliance, safety, audit, regulatory, insurance, property management and record-keeping purposes.
6.11. The licence in clause 6.10 applies to the information and outputs produced for or relating to the End Client. It does not transfer ownership of, or grant the End Client any right to use, the Customer Materials, including the Customer’s templates, question sets, forms, logos, branding, report formats, methodologies or other Customer-owned materials, except to the extent those materials are embedded in a static Assessment Output produced for that End Client. The End Client may not use the Customer Materials to create further assessments, surveys, templates, reports or similar outputs without the Customer’s consent.
6.12. RiskBase may make Assessment Outputs available to the relevant End Client through the Applications, a related portal, export, report or other agreed mechanism, and may enter into a separate agreement with an End Client for access to, use of, management of or addition to End Client Data and Assessment Outputs. Any such access shall not transfer ownership of RiskBase IPR or Customer Materials except as expressly agreed by the relevant owner or required by law.
6.13. The Customer warrants that it has all rights, permissions, notices, lawful bases, consents and authorisations necessary to upload, create, use and process End Client Data and Customer Materials through the Applications, and to permit RiskBase and the relevant End Client to use Assessment Outputs and End Client Data in accordance with the Agreement, the relevant configuration or functionality of the Applications and Data Protection Laws.
6.14. The Customer shall not upload or create End Client Data in the Applications unless it has authority for that End Client Data to be used and made available in accordance with this Agreement and the relevant configuration or functionality of the Applications.
7. Liability
7.1. Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any other liability that cannot lawfully be excluded or limited.
7.2. Subject to clause 7.1, RiskBase shall not be liable for:
7.2.1. loss of profits, revenue, business, goodwill or anticipated savings;
7.2.2. loss or corruption of data, except to the extent caused by RiskBase’s breach of the Agreement;
7.2.3. indirect or consequential loss;
7.2.4. loss arising from Customer Data, Customer decisions, Customer compliance processes or an Excluded Event; or
7.2.5. acts, omissions or failures of the Customer, Authorised Users, End Clients, contractors, fire services, regulators or other third parties.
7.3. Subject to clause 7.1, RiskBase’s total aggregate liability arising out of or in connection with the Agreement in any 12-month period shall not exceed the Fees paid or payable by the Customer in that 12-month period.
7.4. The Applications are provided to assist the Customer. RiskBase does not assume the Customer’s legal, regulatory, fire-safety, building-safety, employment, health and safety or professional obligations.
8. Termination
8.1. Either party may terminate the Agreement immediately by written notice if the other party commits a material breach which cannot be remedied or, if capable of remedy, fails to remedy it within 28 days after receiving written notice requiring remedy.
8.2. Either party may terminate the Agreement immediately by written notice if the other party becomes insolvent, enters administration, liquidation or an analogous process, ceases or threatens to cease trading, or is unable to pay its debts as they fall due.
8.3. On termination or expiry, the Customer’s right to access the Applications ceases and all unpaid Fees become immediately payable.
8.4. The Customer may request a copy or export of Customer Data within 28 days after termination or expiry. RiskBase shall use reasonable endeavours to provide an export in a commonly used format, subject to payment of any reasonable costs where applicable. After that period, RiskBase may archive, delete or anonymise Customer Data in accordance with its retention procedures and Schedule 1, unless law requires otherwise.
8.5. Clauses intended to survive termination shall continue, including clauses relating to intellectual property, confidentiality, data protection, liability, payment, governing law and accrued rights.
8.6. Where an Agreement has no fixed subscription term, or where the Customer uses Usage-Based Services, either party may close the Customer’s account or the relevant Usage-Based Services by giving not less than 28 days’ written notice, unless a Sales Order states otherwise.
8.7. RiskBase may also notify the Customer that an account or Usage-Based Service appears dormant where there has been no chargeable use or active access for a continuous period of 12 months. If the Customer does not confirm that it wishes to keep the account or relevant Usage-Based Service open within the period stated in the notice, RiskBase may close the account or relevant Usage-Based Service.
8.8. Closure of an account or Usage-Based Service means that live access may be suspended or disabled. It does not require RiskBase to delete Customer Data, End Client Data or Assessment Outputs. RiskBase may retain such data in archived form for audit, safety, compliance, legal, regulatory, security, backup, disaster recovery and record-keeping purposes, subject to the Agreement and Data Protection Laws.
8.9. If a Customer whose account has been closed wishes to regain access to archived data, RiskBase may require the Customer to reactivate its account, agree to RiskBase’s then-current terms, enter into a new Sales Order or pay applicable reactivation, subscription, usage, extraction or support charges.
8.10. RiskBase does not warrant that archived data will be retained indefinitely unless expressly agreed in a Sales Order. RiskBase may delete, anonymise or otherwise dispose of archived data in accordance with its retention procedures, the Agreement and Data Protection Laws.
8.11. Account closure shall not, of itself, require deletion of Customer Data, End Client Data or Assessment Outputs. Any request for access, export, deletion or return following account closure shall be dealt with in accordance with clause 8.4, Schedule 1, the Agreement and Data Protection Laws.
9. Personal data and data processing
9.1. The parties shall comply with Data Protection Laws.
9.2. The parties acknowledge that, in relation to Personal Data contained in Customer Data, the Customer will usually be the controller and RiskBase will usually be the processor. Where the Customer acts as processor for another controller, the Customer shall ensure it has authority to appoint RiskBase as sub-processor and to give RiskBase instructions.
9.3. RiskBase may act as controller for limited processing relating to its own business and platform operations, including account administration, support communications, billing, security monitoring, legal compliance, product analytics and internal records. RiskBase’s privacy policy describes that processing.
9.4. Schedule 1 contains the data processing terms required where RiskBase acts as processor. Those terms are incorporated into the Agreement.
9.5. The Customer shall ensure that all required privacy notices, lawful bases, consents, assessments and authorisations are in place for the processing of Personal Data through the Applications, including where End Client Data or resident data is processed.
9.6. Where the Applications are used for RiskBase Engage or similar resident-facing functionality, the Customer is responsible for identifying the relevant controller, providing appropriate resident-facing privacy information, determining lawful bases and special category conditions, managing consent where applicable, handling data subject rights requests, and the Customer must ensure that residents are directed to the Engage resident privacy statement. RiskBase shall provide reasonable processor assistance as set out in Schedule 1.
10. Confidentiality and publicity
10.1. Each party shall keep the other party’s confidential information confidential and shall not disclose it except as permitted by the Agreement or required by law.
10.2. Confidential information includes business, technical, financial, commercial, security, product and customer information disclosed in connection with the Agreement, whether before or after the date of the Agreement.
10.3. A party may disclose confidential information to its employees, contractors, advisers, auditors and subcontractors who need to know it for the purposes of the Agreement, provided they are subject to appropriate confidentiality obligations.
10.4. The confidentiality obligations do not apply to information that is public other than through breach, already lawfully known to the receiving party, independently developed without use of the confidential information, or lawfully received from a third party without confidentiality restriction.
10.5. RiskBase may identify the Customer as a customer in proposals, user lists, website materials and marketing materials, provided that RiskBase shall stop doing so if the Customer reasonably objects in writing. RiskBase shall not issue a press release about the Customer without the Customer’s prior written consent.
11. Changes to these Terms and the Applications
11.1. RiskBase may update these Terms from time to time.
11.2. For Subscription-Based Services, changes shall not apply during the Initial Subscription Term or other applicable subscription period unless:
11.2.1. the Customer agrees to the change;
11.2.2. the change is required by law, regulation or security necessity;
11.2.3. the change relates to data protection, security, acceptable use, technical operation, legal compliance or platform integrity and RiskBase reasonably considers that it should apply during the then-current subscription period;
11.2.4. the change is administrative, clarificatory or non-material and does not materially disadvantage the Customer; or
11.2.5. the change takes effect on renewal after RiskBase has given reasonable notice.
11.3. For Usage-Based Services, RiskBase may update these Terms by giving the Customer reasonable notice by email, in-product notification or other reasonable means. The updated Terms shall apply from the date stated in the notice.
11.4. If the Customer does not agree to the updated Terms under clause 11.3, the Customer must stop using the relevant Usage-Based Services before the effective date of the updated Terms and may request closure of its account. Continued access to or use of the relevant Usage-Based Services after the effective date shall constitute acceptance of the updated Terms.
11.5. Account closure under clause 11.4 shall be dealt with in accordance with clauses 8.6 to 8.11.
12. General
12.1. Neither party shall be liable for delay or failure to perform caused by circumstances beyond its reasonable control.
12.2. The Customer may not assign, novate or transfer the Agreement without RiskBase’s prior written consent. RiskBase may assign or novate the Agreement to a group company or in connection with a merger, reorganisation or sale of substantially all of its business or assets.
12.3. Notices shall be sent by email to the address stated in the Sales Order or another address notified for notices. A notice sent by email is deemed received when sent, provided that no automated bounce-back or delivery failure is received and the notice is sent during Operating Hours; otherwise, it is deemed received at 09:00 on the next Business Day.
12.4. The Agreement constitutes the entire agreement between the parties relating to its subject matter and supersedes previous agreements, discussions and understandings relating to that subject matter.
12.5. Except as expressly stated, no person who is not a party to the Agreement has rights under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of the Agreement.
12.6. No variation of the Agreement is effective unless agreed in writing by the parties, except as permitted under clause 11.
12.7. The Agreement is governed by English law and the parties submit to the exclusive jurisdiction of the English courts.
Schedule 1. Data Processing Terms
This Schedule applies where RiskBase processes Personal Data as processor on behalf of the Customer.
(1) Processing details
Item | Details |
|---|---|
Subject matter | Provision, hosting, support, maintenance and security of the Applications and Services. |
Duration | For the Term and any period required for deletion, return, backup, legal retention or transition. |
Nature and purpose | Storage, hosting, access, retrieval, transmission, support, maintenance, security monitoring, troubleshooting, backup, deletion, export and related processing necessary to provide the Applications and Services. |
Categories of data subjects | Customer representatives, Authorised Users, End Clients, residents, occupiers, leaseholders, contractors, employees, visitors and other individuals identified in Customer Data. |
Types of Personal Data | Names, contact details, job titles, login details, account data, support communications, technical logs, resident engagement data, evacuation assistance information, assessment data or property/unit information where it identifies or relates to an individual, and any other Personal Data contained in Customer Data, End Client Data or Assessment Outputs. |
Special category data | May include health, disability, impairment or assistance-needs information where the Customer uses the Applications for resident engagement, evacuation planning or similar purposes. |
Sub-processors | Hosting providers, infrastructure providers, support tools and other sub-processors appointed by RiskBase in accordance with this Schedule. |
(2) Processor obligations
RiskBase shall:
(a) process Personal Data only on the Customer’s documented instructions, including as set out in the Agreement, unless required by law;
(b) ensure that persons authorised to process Personal Data are subject to confidentiality obligations;
(c) implement appropriate technical and organisational measures;
(d) not appoint a sub-processor except in accordance with this Schedule;
(e) assist the Customer, insofar as reasonably possible, with data subject rights requests;
(f) assist the Customer with security, breach notification, DPIAs and regulator consultation where required by Data Protection Laws, taking account of the nature of processing and information available to RiskBase;
(g) delete or return Personal Data at the end of the Services in accordance with the Agreement and paragraph (9) of this Schedule, unless law requires storage; and
(h) make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR and allow audits as set out below.
(3) Customer instructions
The Customer instructs RiskBase to process Personal Data to provide, secure, support, maintain and improve the Applications and Services and otherwise perform the Agreement. The Customer shall ensure its instructions are lawful.
(4) Sub-processors
(a) The Customer gives RiskBase general authorisation to appoint sub-processors. RiskBase shall impose data protection obligations on sub-processors that are materially equivalent to those in this Schedule. RiskBase shall remain responsible to the Customer for sub-processors’ processing of Personal Data.
(b) RiskBase shall notify the Customer of intended changes concerning the addition or replacement of sub-processors. The Customer may object on reasonable data protection grounds within a reasonable period notified by RiskBase. If the parties cannot resolve the objection, RiskBase may terminate the affected Services or the Customer may stop using the affected functionality.
(5) International transfers
RiskBase shall not make restricted transfers of Personal Data outside the UK or EEA unless appropriate safeguards or another lawful transfer mechanism is in place, such as adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.
(6) Security incidents
RiskBase shall notify the Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed by RiskBase as processor. RiskBase shall provide information reasonably available to it to assist the Customer in meeting its breach notification obligations.
(7) Data subject requests
If RiskBase receives a data subject request relating to Personal Data for which the Customer is controller, RiskBase shall not respond substantively unless authorised by the Customer or required by law. RiskBase may acknowledge receipt, help identify the relevant controller, pass the request to the Customer, or assist the Customer in responding.
(8) Audit
RiskBase shall make available reasonable information to demonstrate compliance with this Schedule. Any audit shall be subject to reasonable notice, confidentiality, security restrictions and measures designed to avoid disruption to RiskBase’s business, systems and other customers. RiskBase may satisfy audit requests by providing third-party certifications, security summaries, policies or questionnaire responses where appropriate.
(9) Deletion and return
RiskBase’s Applications are used to create and maintain safety, compliance, audit and property-related records. The Customer acknowledges that deletion or anonymisation of such records may adversely affect the integrity of the audit trail and the ability of Customers, End Clients or other relevant persons to evidence historic assessments, actions, decisions and compliance activity.
Unless the Customer gives a lawful written instruction requiring return or deletion of Personal Data, or unless deletion is required by Data Protection Laws or expressly agreed in a Sales Order, the Customer instructs RiskBase to retain Personal Data contained in Customer Data, End Client Data and Assessment Outputs in accordance with RiskBase’s retention procedures for the purposes of audit, safety, compliance, legal, regulatory, security, backup, disaster recovery and record-keeping.
RiskBase does not warrant that Customer Data, End Client Data, Assessment Outputs or Personal Data will be retained indefinitely unless expressly agreed in a Sales Order. RiskBase may delete, anonymise or otherwise dispose of data in accordance with the Agreement, its retention procedures and Data Protection Laws.
Where RiskBase is required to delete or return Personal Data at the end of the Services, RiskBase shall do so in accordance with Data Protection Laws, subject to backup cycles, legal retention, audit requirements, regulatory obligations and any continuing controller processing by RiskBase.