Terms of service
Last updated: 9 August 2026
Service provider: PuroCRM Oy (Business ID: 3640952-9), mailing address: Viereläntie 4 A, 90630 Oulu
Contact person and data protection: Juha-Pekka Teirikangas, juha-pekka@purocrm.fi
Website: purocrm.fi
These terms of service apply to the use of the PuroCRM service, its related mobile application (fi.purocrm.app), the public API and all related features. The service is intended exclusively for businesses and other organisations engaged in commercial or professional activities. The service is not a consumer service, and these terms have not been drafted for consumer transactions.
PuroCRM is a multi-tenant cloud-based sales and marketing ERP system used for customer management, sales pipeline management, campaigns, activities, reporting, proposals, contracts, electronic signing, mobile use, and tenant-managed integrations and API usage. The processing of personal data is described further in the Privacy Policy, and the use of cookies in the Cookie Policy.
General information and scope
1. Acceptance of the agreement and parties. The agreement for the use of the PuroCRM service is established when the Tenant subscribes to the service, accepts a proposal, order form or other equivalent commercial document, and the tenant's admin user or another person authorised by the Tenant accepts these terms of service electronically or commences the use of the service. If an individual accepts these terms on behalf of the Tenant, that individual warrants that they are authorised to bind the Tenant to these terms. The Tenant is responsible for ensuring that its admin users, users, API key holders and other persons acting on its behalf are authorised to use the service on behalf of the Tenant.
2. Scope of the service. These terms of service apply to all use of the PuroCRM service, including the web application, mobile application, public API, documentation, support services, notifications, webhooks, reporting and other features provided by the Service Provider from time to time, unless expressly agreed otherwise in a specific order or written agreement. The service is granted to the Tenant as a right of use, not as a transfer of ownership.
3. B2B service. The service is intended for business customers only. The Tenant warrants that it is subscribing to and using the service as part of its own commercial or professional activities. PuroCRM has the right to decline the activation of or to close the service if it transpires that the subscriber or the use case is not B2B in nature.
4. Service description and changes. PuroCRM provides a multi-tenant workspace service where each Tenant has its own logically isolated workspace. Service features may include, for example, a customer register, campaigns, emails, social media planning, sales pipeline, proposals, contracts, electronic signing, activities, calendar, call lists, notifications, news monitoring, reporting, user management, API keys, webhook endpoints, audit trail logs, GDPR exports, AI features, SMS functions and a mobile application. The Service Provider has the right to develop, modify, add, remove, fix or replace service features, the user interface, security mechanisms, usage limits, third-party integrations and technical implementations. If a change materially degrades the Tenant's use of the service and the change is not due to law, security, a third-party change or a compelling operational need, the Service Provider will endeavour to notify the Tenant at least 30 days in advance.
5. Related documents. In addition to these terms of service, the use of the service is governed, as applicable, by the order or proposal, any separate service description, the data processing agreement (DPA), the Privacy Policy, the Cookie Policy and the terms of third-party services to the extent the Tenant uses such integrations or features.
Definitions
Data protection roles and contractual titles are interpreted based on their actual content. The status of data controller and data processor is not determined by title alone but by the parties' actual roles, decision-making authority and processing purposes.
| Term | Meaning |
|---|---|
| Agreement | The entirety of the agreement between the Tenant and the Service Provider, comprising at least the order or proposal, these terms of service and, where applicable, the DPA. |
| Service | The PuroCRM service in its entirety, including the web application, mobile application, public API, documentation and related features. |
| Tenant | The company or other organisation that enters into an agreement for the PuroCRM service and receives its own workspace in the service. |
| Admin user | An administrative user designated by the Tenant, with the right to manage user accounts, settings, API keys, billing and other administrative functions of the Tenant. |
| User | An employee or other person authorised by the Tenant, for whom the Tenant has created a user account in the service. |
| Platform admin | An internal administrator or other authorised person of the Service Provider, with access to the service's maintenance and support functions. |
| Customer Data | All data stored, sent, uploaded, synchronised, produced or otherwise processed by the Tenant or its users through the service, including personal data, files, messages, campaigns, contacts, proposals, contracts, transcriptions, summaries and other content. |
| Service Data | Technical, administrative and operational data arising from the use of the service, such as logs, audit trail entries, metrics, diagnostics, usage statistics, error reports and billing-related event data. |
| Content | The part of Customer Data consisting of texts, images, files, campaigns, contract drafts, messages, audio recordings, emails, publication drafts or other material produced or requested by the Tenant. |
| API key | A credential managed by the Tenant that grants access to the Tenant's public API functions. |
| AI Output | Text, images, summaries, transcriptions, segmentations, predictions, proposal suggestions, contract drafts, social media posts or other machine-generated material produced by an AI feature. |
| Confidential Information | All non-public commercial, technical, contractual, security-related or other confidential information received from the other party, including Customer Data, information related to source code and architecture, and pricing and business plans. |
| DPA | The data processing agreement between the parties, specifying the terms for the processing of personal data when the Service Provider acts as a data processor on behalf of the Tenant. |
| Third-party service | An external service, integration, cloud or communication service, or AI service used by the Service Provider or the Tenant as part of the delivery or use of the Service. |
| Force majeure | An exceptional and unforeseeable obstacle beyond the party's control that the party could not reasonably have anticipated, avoided or overcome. |
| Subscription period | The calendar period, fixed term or indefinite contract period for which the service is billed and used. |
Use of the service and acceptable use
6. Account creation and user responsibility. One tenant account is created per company or contracting entity, unless otherwise agreed in writing. The Tenant is responsible for ensuring that all information provided during registration and maintenance is correct, current and complete. The Tenant's admin user is responsible for creating user accounts, granting permissions, removing users, maintaining billing information, managing API keys and other administrative actions. The Tenant is responsible for all actions taken through admin users, users, integrations and API keys as if the Tenant had carried them out itself.
7. Credential security. User credentials are personal. The Tenant and its users must not share credentials with each other or with third parties. The Tenant is responsible for the secure management of passwords, MFA methods, API keys, webhook secrets, device tokens and other access credentials. The Tenant must promptly revoke access for persons who no longer have grounds to use the service, such as upon termination of employment or assignment. The Service Provider may require multi-factor authentication for certain roles, risk situations or features.
8. Right of use. The Tenant is granted a limited, non-exclusive, non-transferable, revocable right to use the service for its own internal business purposes during the term of the Agreement, in accordance with these terms, the order and the documentation. Without the prior written consent of the Service Provider, the Tenant may not resell the service, offer it as a service bureau to third parties, lease it, sublicense it or use it primarily for the benefit of a third party.
9. Usage restrictions. The Tenant and its users must not:
- copy, modify, decompile, reverse-engineer or otherwise attempt to discover the source code of the service, except to the extent permitted by mandatory law;
- use the service unlawfully, misleadingly or in violation of good practice;
- upload, process or distribute content that infringes intellectual property rights, trade secrets or data protection obligations;
- use the service for malware, phishing, fraud, identity theft, unauthorised profiling or other harmful activities;
- test, scan, load-test, breach or otherwise interfere with the security of the service without the prior written permission of the Service Provider;
- circumvent or attempt to circumvent rate limits, usage limits, authentication or other technical control mechanisms;
- use AI features to produce illegal, discriminatory, misleading, harmful or rights-infringing material;
- use company-data searches (e.g. ProFinder, Vainu), news searches or other data sources for unjustified mass queries, unlawful marketing or otherwise without a proper purpose.
10. Acceptable use in marketing and communications. The Tenant is solely responsible for ensuring that all email, SMS, webhook and other communication functions are carried out lawfully. This applies in particular to informing recipients, obtaining consents where required, relying on legitimate interests, respecting opt-out rights, providing unsubscribe mechanisms, ensuring messages are identifiable as marketing, and complying with all other obligations under the GDPR, the Finnish Data Protection Act, Chapter 24 of the Finnish Act on Electronic Communications Services and any additional requirements of the recipient's country. The Service Provider acts as a technical channel for communications and is not responsible for the lawfulness of the Tenant's marketing activities.
11. Right to address misuse. If the Service Provider has reasonable grounds to suspect use in violation of these terms, the law, third-party terms or security requirements, the Service Provider has the right, without prior notice, to restrict, block or suspend the use of the service in whole or in part, change credentials, revoke API keys, block message sending, remove harmful content or take other necessary protective measures. The Service Provider will endeavour to notify the Tenant without delay, unless notification would jeopardise an investigation, security or legal compliance.
12. Public API. The service's public API is intended for the Tenant's own integrations and automations. API usage requires API keys generated by the Tenant. All of the Tenant's API keys have full access to the Tenant's data to the extent the API permits at any given time, and there is no per-endpoint access control in the user interface. The Tenant is responsible for storing API keys securely, using them only for authorised purposes, rotating them regularly and deleting them immediately if misuse is suspected. The Service Provider has the right to apply, modify and enforce API rate limits and to block or restrict usage for security, stability or cost reasons. Current rate limits are described in the API documentation.
13. Mobile application special terms. The PuroCRM mobile application is distributed through Google Play Store and Apple App Store under the name fi.purocrm.app. Google Play distribution terms apply as applicable to Android distribution, and for iOS distribution these terms apply together with the Apple Licensed Application End User License Agreement or other license arrangement mandatorily applicable to App Store distribution at any given time. The application is licensed to the user, not sold. Push notifications are delivered via Firebase Cloud Messaging, and release builds may use Firebase Crashlytics for error and crash reporting.
14. Mobile application permissions, recording and synchronisation. The mobile application may request permissions for internet access, microphone use and notifications. Microphone use is based on the user's explicit initiation of recording. The user is solely responsible for ensuring that the recording of a meeting, call or other event is lawful in all applicable countries, industries and contractual contexts, and that all necessary notifications, consents or other prerequisites have been fulfilled before starting the recording. PuroCRM is not responsible for the legality of any recording or whether a particular recording situation meets local legal requirements. Recorded audio may be sent to ElevenLabs or Google Cloud AI services for transcription and summarisation. Such outputs are generated by machine and may contain errors, so the Tenant and user must always verify their accuracy before decision-making or other significant use. The application can also operate offline; in such cases changes are stored locally and synchronised when connectivity returns. In the event of conflicts, a last-write-wins approach is applied by default. The Service Provider may require a minimum application version for security, compatibility or functionality purposes.
Pricing, billing and contract term
15. Pricing. The service's prices, subscription type, billing basis, any usage quotas, user counts and other commercial terms are agreed separately when ordering the service. Prices may be agreed as, for example, monthly or annual fees, per-user fees, feature-specific add-on fees, usage-based fees or combinations thereof. Unless otherwise stated, prices are quoted excluding value added tax and other government charges.
16. Billing and payment terms. Billing is primarily handled manually according to agreed practice, for example by invoice delivered by email or other billing method agreed between the parties. No in-app purchase mechanism is used in the mobile application. The standard payment term is 14 days net from the date of invoice, unless otherwise agreed in the order. The Tenant is responsible for keeping billing addresses, e-invoicing details, contact persons and other billing-relevant information up to date.
17. Usage metering and usage-based charges. The Service Provider has the right to measure, record and analyse the Tenant's use of the service for billing, capacity management, abuse prevention, technical support, cost allocation and service development purposes. Metering may cover, for example, user counts, sent emails, SMS messages, AI requests, news searches, transcriptions, API calls, storage, webhook traffic or other usage-based events. If the Tenant exceeds agreed usage quotas or uses the service beyond the agreed commercial tier, the Service Provider has the right to charge the excess usage in accordance with the price list, order or otherwise on a reasonable and pre-notified basis, or to restrict usage until additional capacity has been agreed.
18. Late payment and collection. If the Tenant does not pay an invoice by the due date, the Service Provider has the right to charge penalty interest in accordance with the Finnish Interest Act and reasonable collection costs. The Service Provider may also suspend the use of the service if an overdue payment remains unpaid and the Tenant does not remedy the default within a reasonable additional period. Late payment does not release the Tenant from its contractual obligations.
19. Price changes. The Service Provider has the right to change prices, billing bases, usage quotas and other commercial terms by notifying the Tenant at least 60 days before the start of the next billing period. If the change is materially disadvantageous to the Tenant and is not based on law, a government decision, a tax change, a third-party cost change or a mandatory security measure, the Tenant has the right to terminate the agreement before the change takes effect by giving written notice before the effective date of the change.
20. Demo, pilot and possible free trial. If the Service Provider offers a demo account, pilot, trial period or other limited-use period, these terms apply unless otherwise agreed in writing. The Service Provider has the right to limit the features, retention periods, support level, integrations and service level of such use and to end or modify the trial at any time. Unless otherwise agreed, the Service Provider has no obligation to retain trial data after the trial ends.
21. Contract term and termination. The agreement is valid for the period agreed in the order. Unless otherwise agreed, the agreement is either fixed-term or valid until further notice. An agreement valid until further notice may be terminated in writing with one month's notice. A fixed-term agreement binds the parties for the agreed term, unless the agreement states otherwise. The Service Provider has the right to terminate or rescind the agreement with immediate effect if the Tenant materially breaches these terms, uses the service unlawfully, compromises security, violates acceptable use, repeatedly fails to make payments, or enters insolvency proceedings that materially jeopardise the fulfilment of the agreement.
Data, privacy, intellectual property and technology terms
22. Ownership and right of use of Customer Data. The Tenant retains ownership and other rights to its Customer Data. These terms do not transfer ownership of the Tenant's Customer Data to the Service Provider. However, the Tenant grants the Service Provider a limited right during the term of the Agreement to process, store, copy, organise, transfer, back up, transform and otherwise use Customer Data to the extent necessary for providing, maintaining, protecting, supporting, developing, billing, preventing misuse and executing the Tenant's instructions.
23. Tenant's responsibility for Customer Data. The Tenant is responsible for ensuring that it has the right to store, use and process all data it brings into the Service and that such processing is lawful. The Tenant is also responsible for ensuring that Customer Data is sufficiently accurate, relevant and up to date for the Tenant's own purposes. The Service Provider is not responsible for the content, legality, integrity or accuracy of Customer Data, or for whether it is suitable for the Tenant's business, tax, accounting or legal needs.
24. Data protection roles and DPA. When the Tenant stores personal data in the service for its own purposes, the Tenant acts as the data controller and the Service Provider as the data processor to the extent that the Service Provider processes such personal data on behalf of the Tenant for the provision of the service. However, the Service Provider acts as an independent data controller with respect to its own customer relationship, billing, contract, security, logging and statutory obligations to the extent that it determines the purposes and means of processing. The processing of personal data is specified in the DPA, which forms part of the Agreement when required by Article 28 of the GDPR.
25. Sub-processors and international transfers. The Service Provider may use sub-processors and other technical service providers in the delivery of the service. The Tenant accepts this when the use of a sub-processor is necessary for the provision of the service and the sub-processor is bound by appropriate data protection and security obligations. The transfer of personal data outside the EU or EEA may be carried out under, among other things, the European Commission's Standard Contractual Clauses (SCC) where no other applicable transfer mechanism is available.
The Service Provider's sub-processors under this section are distinguished from external services selected and connected by the Tenant or its authorised user. An external service does not become a sub-processor of the Service Provider solely because PuroCRM provides a technical integration to it, where the Tenant or its user selects and controls the receiving account and the recipient processes the data under its own user or customer relationship. Such integrations are additionally governed by section 33.
The following third parties and sub-processors may be used in the service:
| Service | Role | Primary processing location / transfer mechanism |
|---|---|---|
| DigitalOcean | Hosting | Germany (EU) |
| Mailgun (Sinch Email) | EU (api.eu.mailgun.net) | |
| Quriiri | SMS | Finland (EU) |
| Google Cloud (Vertex AI, Gmail API, Calendar API, Pub/Sub) | AI generation, email receiving, calendar | EU multi-region (eu) |
| Anthropic (Claude via Google Vertex AI) | AI text generation (premium tier) | EU multi-region (via Google Cloud) |
| ElevenLabs Inc. | Meeting audio transcription | USA (SCC) |
| Brave Software Inc. | News search | USA (SCC) |
| ProFinder | B2B company data search | Finland |
| Vainu Finland Oy | B2B company data search | Finland (EU) |
| Firebase (Google) | Push notifications and crash reporting in the mobile application | Global |
26. Security. The Service Provider implements reasonable technical and organisational measures to protect the security, integrity and confidentiality of the service relative to its nature. The Service Provider may use log data, audit trail entries, usage analytics, error reports and other security mechanisms for monitoring security, investigating incidents, preventing misuse and developing the service. Platform admin access to Tenant data is limited to situations where access is necessary for the provision, support, troubleshooting, security, statutory obligation or processing of the Tenant's request.
27. Retention periods and deletion. Unless mandatory law requires otherwise or the Tenant deletes the material itself beforehand, the following retention periods apply by default in the Service: raw audio uploaded via the mobile application is automatically deleted after 30 days, audit logs are retained for 12 months by default, a user account may be retained for the duration of the contractual relationship plus a maximum of 30 days as a deletion or recovery grace period, and transcriptions and summaries managed by the Tenant are retained until the Tenant deletes them or the agreement ends. To the extent that material subject to the Finnish Accounting Act is generated or stored in the service, retention periods are determined by law; certain material must be retained for at least six years and accounting books for at least ten years from the end of the financial year. The Tenant may have built-in export and data request features that it should use to fulfil its own data protection obligations.
28. Intellectual property rights in the service. All intellectual property rights related to the service, software, database structures, user interface, documentation, trademarks, web content, templates, analytics, system logic and other material provided by the Service Provider belong to the Service Provider or its licensors. The Tenant may not remove or conceal copyright or other proprietary notices or use PuroCRM's name, trademarks or materials in a manner that could cause confusion as to ownership or source.
29. Feedback and development suggestions. If the Tenant or its user provides the Service Provider with feedback, development suggestions, bug reports, comments or other ideas related to the development of the service, the Service Provider has the right to use them without separate compensation as part of developing, improving and commercialising the service, provided that the Tenant's Confidential Information is not disclosed in violation of these terms.
30. AI features and AI Outputs. PuroCRM may use Google Vertex AI services (Google Gemini and Anthropic Claude models, served within the EU) to generate text, images, segmentations, predictions, proposal drafts, contract drafts, campaign content, social media posts, news assessments, transcriptions and other AI Outputs. AI Outputs are generated probabilistically and may be incorrect, incomplete, biased, outdated, similar to other outputs or infringing on third-party rights without the Service Provider detecting it. The Tenant is responsible for reviewing AI Outputs before use and must not use them as-is without professional judgement in situations where an error could cause legal, financial, data protection or reputational harm. Google Cloud states that customer data is not used to train or fine-tune models in Vertex AI managed model services without the customer's prior consent or instruction. Under the EU AI Act, in certain situations synthetic content produced by AI systems must be machine-detectably marked where technically feasible. The Tenant is responsible for complying with all applicable obligations regarding AI use, transparency, labelling, copyright, data protection and industry regulation in its own activities.
31. Rights to AI Outputs. To the extent that a transferable copyright or other intellectual property right arises in an AI Output and the Service Provider has a transferable right therein, such right transfers to the Tenant or the Tenant is granted a broad right of use as part of the Agreement. The Service Provider does not, however, transfer rights to the underlying models, algorithms, software, documentation or third-party technology, and does not guarantee the exclusivity, novelty, copyrightability or non-infringement of AI Outputs.
32. Contracts and electronic signing. PuroCRM may offer contract creation and an electronic signing process as part of the service. PuroCRM's electronic signature is not a qualified electronic signature under the eIDAS Regulation and does not include strong electronic identification by default. The Tenant understands that different levels of electronic signature carry different legal effects: an electronic signature may not be denied legal effect solely because it is electronic or is not qualified, but only a qualified electronic signature has the same legal effect as a handwritten signature throughout the EU. For significant legal transactions, government interactions, documents subject to sector-specific regulation, or situations requiring a high level of assurance, the Tenant should use a separate strong identification or qualified electronic signature service.
33. Third parties and integrations. Parts of the service may depend on third-party services such as Mailgun, Quriiri, Google Cloud, ElevenLabs, Brave Search API, ProFinder and Firebase. The Tenant undertakes to comply with the applicable terms of use, technical limitations and privacy policies of these services to the extent the Tenant uses such features. The Service Provider is not responsible for outages, delays, pricing changes, feature removals, API changes, deliverability, credential revocations, platform sanctions or the error-free operation of any third-party service in conjunction with PuroCRM.
The Service may also allow an authorised user of the Tenant to connect their own third-party account, such as a Dropbox account, to PuroCRM. When the user confirms the transfer of a file to such a service, PuroCRM sends the Customer Data selected by the user to the destination designated by the user. No transfer is made before the user's confirmation.
The Tenant is responsible for ensuring that its users are appropriately authorised to connect the account in question, that the selected recipient and storage destination are appropriate for the Tenant's Customer Data, and that the user reviews any AI-proposed file path and filename before confirming the transfer. Once the third-party service has received the data, its applicable terms and privacy arrangements govern the storage and subsequent processing of that data.
Nothing in this section transfers to the Tenant the Service Provider's responsibility for its own processing of personal data, for its security obligations or for compliance with its obligations under the Agreement.
34. Service level and support. The Service Provider strives to maintain good usability and availability of the service and targets approximately 99.5 per cent monthly availability, excluding scheduled maintenance, third-party disruptions, disruptions caused by the Tenant or its integrations, force majeure events and other matters beyond the Service Provider's reasonable control. This target level is a goal only and is not a binding service guarantee or basis for compensation. The Service Provider has the right to carry out scheduled maintenance primarily on Sundays between 02:00 and 06:00 Finnish time or at other reasonable times. Support is provided primarily by email at juha-pekka@purocrm.fi. Any response or handling times are indicative, not binding, unless expressly agreed otherwise in writing.
Liabilities, termination and other terms
35. Confidentiality. Each party undertakes to keep the other party's Confidential Information confidential and to use it solely for the exercise of rights and obligations under the Agreement. Confidential Information may not be disclosed to third parties without the prior written consent of the disclosing party, except where disclosure is necessary for the performance of the Agreement, the fulfilment of a statutory obligation, compliance with a government request, or to a permitted subcontractor for the purpose contemplated by the Agreement. The confidentiality obligation does not apply to information that is public without breach by the receiving party, was lawfully in the receiving party's possession before disclosure, was lawfully obtained from a third party without a confidentiality obligation, or was independently developed by the receiving party. The confidentiality obligation remains in effect during the Agreement and for five years after its termination.
36. Limitation of warranties. The service is provided on an "as is" and "as available" basis. The Service Provider does not warrant that the service is completely error-free, uninterrupted, compatible with all devices, browsers, operating systems or third-party systems, or that every feature meets the Tenant's specific business requirements. To the extent permitted by mandatory law, all express or implied warranties, including implied warranties of merchantability, fitness for a particular purpose and non-infringement, are excluded.
37. Limitation of liability. Neither party is liable for indirect or consequential damages, such as lost business profits, revenue, customer relationships, reputation, expected savings or production, or indirect losses arising from third-party claims, unless mandatory law requires otherwise. The Service Provider's total liability to the Tenant under the Agreement for the same or related damage events is limited to the amount of service fees paid by the Tenant to the Service Provider during the 12 months immediately preceding the damage event. If the Agreement has been in force for less than 12 months, the maximum liability is the amount actually paid by the Tenant during that period. Liability limitations do not apply to damage caused intentionally or through gross negligence, or to liability that cannot be limited under mandatory law. The Tenant's payment obligations are not limited by this section.
38. Indemnification for Tenant's actions. The Tenant undertakes to defend and hold harmless the Service Provider, its personnel and subcontractors from all third-party claims, fines, sanctions, costs and damages arising from the Tenant's Customer Data, the actions of the Tenant's users, marketing sent by the Tenant, the Tenant's API or integration use, the unlawfulness of instructions given by the Tenant, or the Tenant's breach of these terms, the law or third-party rights. This obligation requires the Service Provider to notify the Tenant of the claim within a reasonable time and to allow the Tenant to take over the matter, provided that the Tenant may not enter into a settlement binding on the Service Provider without the Service Provider's written consent if the settlement includes an admission, payment obligation or other adverse obligation for the Service Provider.
39. Suspension and effects of termination. Upon termination of the Agreement, the Tenant's right to use the service ends, unless the agreement or mandatory law provides otherwise. The Tenant must export any data it needs from the service within 30 days of termination, unless otherwise agreed in writing. After this, the Service Provider has the right to delete or anonymise the Tenant's Customer Data and user accounts in accordance with the Privacy Policy, the DPA and these terms, except for material that must be retained for legal, security, dispute resolution or accounting reasons. If the Tenant's service has been suspended due to payment default or breach of contract, the Service Provider has no obligation to maintain the service's availability, synchronisations or integrations during the suspension.
40. Force majeure. A party is released from delay or failure to perform to the extent caused by a force majeure event. Force majeure includes, among other things, a widespread electricity grid failure, a major internet or telecommunications failure, a significant cloud provider outage, a cyberattack, government action, war, insurrection, strike, lockout, natural disaster, pandemic, import or export restriction, telecommunications failure or other comparable exceptional event beyond the party's control. A party must notify the other party of a force majeure event without undue delay when reasonably possible.
41. Changes to terms. The Service Provider has the right to modify these terms of service, for example due to changes in legislation, government orders, service development, security reasons, third-party changes or changes to the business model. Material changes will be notified at least 30 days before they take effect, for example by email to the Tenant's admin user, by an in-service notification or by other reasonable means. By continuing to use the service after the change takes effect, the Tenant accepts the updated terms. If the Tenant does not accept a material change, the Tenant must stop using the service and terminate the agreement before the change takes effect.
42. Communications. The Service Provider may deliver agreement-related notices by email to the Tenant's designated contact address, the admin user's account, the service's internal notification function or other reasonable electronic means. The Tenant is responsible for ensuring that its contact details are correct and that the Tenant actively monitors notifications. Electronic communications are considered valid notification under the Agreement.
43. Assignment of the agreement. The Service Provider has the right to assign the Agreement or the rights and obligations thereunder, in whole or in part, to a group company or in connection with a business acquisition, merger, demerger, corporate reorganisation or other similar arrangement without the Tenant's separate consent. The Tenant may not assign the Agreement or its rights or obligations thereunder without the prior written consent of the Service Provider.
44. Entire agreement and order of precedence. The Agreement constitutes the entire agreement between the parties regarding the use of the service and supersedes all prior oral and written discussions to the extent they relate to the same subject matter. In the event of a conflict between documents, the following order of precedence applies: (i) the order, proposal or other individual commercial agreement, (ii) these terms of service, (iii) the DPA and (iv) the Privacy Policy. To the extent that an express provision of the DPA or mandatory data protection legislation requires a different outcome on a specific data processing matter, the DPA or mandatory law takes precedence on that processing matter.
45. Severability and non-waiver. If any provision of these terms is found to be invalid, unenforceable or unlawful, the remaining terms shall remain in force. The invalid provision shall be replaced with an interpretation or provision that corresponds as closely as possible to the purpose of the original provision within the limits of the law. The failure of a party to enforce any right does not constitute a waiver of that right or any other right.
46. Governing law and dispute resolution. The Agreement is governed by the laws of Finland, excluding its conflict of laws rules. All disputes arising from the Agreement or the use of the service shall primarily be resolved by negotiation between the parties. If a settlement cannot be reached within a reasonable time, the dispute shall be resolved as the court of first instance by the Helsinki District Court.
These terms of service may be updated as the service evolves, legislation changes, security requirements are refined or third-party services change. The Tenant is advised to retain its own copy of the terms in force at any given time.