Terms and Conditions of Service
Version 2 · Production
These terms of service (the “AGREEMENT”) govern the access to and use of SMARTFENSE services by ADMINISTRATORS, unless the ADMINISTRATOR has entered into a separate written AGREEMENT with SMARTFENSE. These terms and conditions apply in all cases.
This AGREEMENT is deemed accepted by checking the consent box indicating acceptance. Failure to accept these terms and conditions results in the inability to use our services.
The ADMINISTRATOR and SMARTFENSE may be referred to in this Agreement individually as a “party” or collectively as the “parties”. This Agreement governs all SERVICES, as defined below, provided by SMARTFENSE.
Access to the SERVICES for the purpose of monitoring their availability, performance, or functionality, or for any other benchmarking or competitive purpose, or as otherwise restricted by this Agreement, is not permitted. Direct competitors of SMARTFENSE (or external agents acting on behalf of such direct competitors) are prohibited from accessing the Services.
1. Definitions
For the purposes of this Agreement, the following terms shall have the meanings set forth below, unless the context requires otherwise.
1.1 PRODUCER
DEFENSE BALANCE S.L.
1.2 SERVICES or SMARTFENSE
An online Information Security awareness platform that builds secure habits in FINAL RECIPIENTS.
1.3 PARTNER
A natural or legal person who holds a legal agreement with the PRODUCER to provide support and/or manage or commercialize SMARTFENSE Products or Services.
1.4 CLIENT or FINAL CLIENT
A natural or legal person who purchases the services for their own use and not for resale.
1.5 ADMINISTRATOR
A person who accesses the platform to use and/or manage and/or support SMARTFENSE services in the role of account ADMINISTRATOR.
1.6 FINAL RECIPIENT(S)
A person or group of persons to whom one or more awareness campaigns or SMARTFENSE services are sent.
1.7 SUPPORT
A technical assistance service aimed at the implementation and resolution of queries and incidents related to the use of the platform. The modality of support provision may vary depending on the type of service contracted.
2. Purpose and Scope
These Terms and Conditions of Service (hereinafter T&C) are mandatory and binding in order to enable access to the services, thereby constituting a legal contractual relationship between the ADMINISTRATOR and SMARTFENSE. Access to and use of the services implies the ADMINISTRATOR’s acceptance of these T&C; it is therefore recommended that the time deemed necessary be devoted to reading and understanding them. Should the ADMINISTRATOR disagree with these provisions, they must refrain from accessing and/or using any of the services.
3. Services
3.1 Updates
THE ADMINISTRATOR acknowledges that SMARTFENSE is an online Services provider (Software as a Service), based on subscriptions, and that we may make periodic changes to the services, always seeking to improve our security conditions and functionality. Should such changes consist of updates that improve existing services, the ADMINISTRATOR will be notified at the time of their implementation.
3.2 Improvement of Our Services
SMARTFENSE is constantly endeavoring to improve its Products and Services for the benefit of its FINAL CLIENTS. To achieve this, we need to measure, analyze, and aggregate how ADMINISTRATORS AND FINAL RECIPIENTS interact with our Services, as well as usage patterns and characteristics of our ADMINISTRATOR AND FINAL RECIPIENT base. THE ADMINISTRATOR authorizes the measurement of such statistical parameters to cooperate with the improvement of the services.
3.3 Contact with the FINAL CLIENT
In those cases where the service is commercialized through a PARTNER, the PRODUCER reserves the right to establish contact with the FINAL CLIENT, in accordance with the terms of the executed license agreement, in order to verify: a) the level of customer satisfaction; b) whether the implementation carried out was appropriate; c) whether the level of use or underuse is adequate.
4. Administrator Obligations
4.1 Appropriate Use
The ADMINISTRATOR undertakes to use the services appropriately and responsibly. In particular, and without the following list implying the exclusion of other acts, the ADMINISTRATOR undertakes to:
- Use the services in good faith, acting diligently and lawfully;
- Use respectful language, free from any offense toward third parties;
- Respect the subject matter and dynamics of SMARTFENSE, making appropriate use of the services and contents;
- Respect each and every right arising from the ownership of the Service and its contents, in accordance with the provisions of the Terms and Conditions;
- Add SMARTFENSE services to the FINAL CLIENT’s organization’s security tool whitelist to allow certain SERVICE modules to function (for example, sending PHISHING or RANSOMWARE campaigns). This action must be performed prior to the use of the SERVICES — including the launch of simulation campaigns, the sending of Newsletters, the sending of any email or campaign and/or available tools — on the PRODUCER’s platform. The ADMINISTRATOR understands and accepts that the correct configuration and updating of whitelists are necessary to mitigate potential false positives and to avoid the limitation or temporary suspension of the contracted services (due to internal or external blocks on the domains used to provide the service). Furthermore, prior to the launch of any real PHISHING or RANSOMWARE simulation campaign, the ADMINISTRATOR must carry out test campaigns to verify the correct operation of the service and the proper configuration of the whitelists in the FINAL CLIENT’s technological environment. The ADMINISTRATOR understands and accepts that failure to complete this step may result in incorrect results, false positives, or service limitations.
- Inform the FINAL CLIENT that in order to use SMARTFENSE services, they must comply with the Minimum Requirements .
4.2 Use Restrictions
The ADMINISTRATOR understands and accepts that certain actions are considered restricted or prohibited in the use of the SERVICES, and that if any infringement is detected, SMARTFENSE reserves the right to cancel or suspend the infringing account. The actions considered prohibited are:
- Using the identity of natural or legal persons without having sufficient permissions or in violation of intellectual property rights;
- Copying, modifying, or altering in any way the SERVICES or their contents and/or manipulating and/or applying reverse engineering to the SERVICES;
- Uploading or posting in the Services any content in a form or for purposes contrary to the law, morality, good customs, and/or public order;
- Performing improper actions on the SERVICES, such as uploading malware, viruses, or harmful or dangerous content, or actions that generate a disproportionate load on the platform infrastructure or excessive traffic demands, which in any way damage its content and infrastructure, etc.;
- Using SMARTFENSE’s intellectual property or its confidential information to develop similar products or services;
- Using or disclosing, in any manner, the products, services, and any of their contents or other related materials of SMARTFENSE outside the authorized organization of the ADMINISTRATOR and/or FINAL CLIENT;
- Removing, manipulating, or altering any copyright notice, intellectual property trademark, or confidentiality legend placed or available through the services;
- Using the SERVICES in any manner beyond the limits established by this Agreement;
- Sending PHISHING or RANSOMWARE simulation campaigns without having previously properly managed the whitelists in the FINAL CLIENT organization’s security tools.
4.3 Third-Party Service Compliance
In cases where the ADMINISTRATOR’s use of the services platform results in claims for non-compliance with the legal conditions of third-party services (hosting, content storage, campaign distribution, etc.), whether administrative or judicial in nature, against SMARTFENSE, the latter shall be authorized to unilaterally and immediately cancel and/or suspend the infringing campaigns that have been sent, or to proceed with the cancellation and/or temporary suspension of such accounts in order to prevent continued non-compliance with the claim received. In such cases, the ADMINISTRATOR will be previously notified of the situation, stating the cause and the measure implemented, so that it may be resolved, avoiding potential new infractions and non-compliance.
4.4 Access Control Security
The ADMINISTRATOR understands and accepts the obligation to always maintain the secrecy and confidentiality of their access credentials, adopting all possible measures to protect their confidentiality. Any illegitimate or unauthorized use of the access credentials shall be the exclusive responsibility of the ADMINISTRATOR, who agrees to notify SMARTFENSE immediately of any unauthorized use of which they become aware. The ADMINISTRATOR understands and accepts that when creating users for FINAL RECIPIENTS, nominal users must be used (for example: john.smith or jsmith), and the creation of generic or non-nominal users (admin, training, support, etc.) reserved for service administration by the PRODUCER is prohibited.
4.5 Authorization of Use for Internal Purposes
Access to and use of the SERVICES, as well as any of their contents or other related materials of SMARTFENSE (which the parties acknowledge are confidential information and the property of SMARTFENSE), is authorized exclusively for educational and internal awareness purposes of the organization or organizations designated by the FINAL CLIENT, always during the subscription period. Under no circumstances is any other type of use of the SERVICES or contents for purposes other than those described authorized. Exceptionally, the FINAL CLIENT shall be authorized to make limited use of SMARTFENSE’s contents, solely for the generation of content within the platform or for marketing or promotional activities of SMARTFENSE. This authorization is issued for commercial purposes without generating any remuneration or consideration in favor of the parties, since it does not imply franchising or exploitation of the brand or image. Should the contracted SMARTFENSE license be terminated for any reason, all granted licenses shall be deemed automatically rescinded.
4.6 Exclusive Purpose for Corporate Use
The ADMINISTRATOR warrants to SMARTFENSE that, prior to the use of platform modules or functionalities intended for the sending of electronic or telephone communications — including, but not limited to, phishing campaigns, smishing (SMS messages), WhatsApp Business, instant messaging, or vishing (automated or voice-assisted calls) —, they possess and maintain in force all the rights, licenses, consents, and authorizations necessary for the processing and contact of the final recipients of such communications. Sending campaigns to non-corporate recipients, or to those who have not provided their consent to participate in an awareness campaign, shall be considered a serious infringement by the ADMINISTRATOR. Should this type of prohibited behavior be detected, SMARTFENSE reserves the right to immediately pause and/or stop a campaign generated by the ADMINISTRATOR that has been reported for infringement of third-party rights and/or for being sent to recipients who have not in any way consented to receiving the communications intended for the awareness of FINAL RECIPIENTS.
4.7 Responsibility in the Use of the Tool
It is strictly prohibited to share screenshots, downloads, or any other form of copying, duplicating, or replicating the SERVICES or other related materials (including predefined contents). The ADMINISTRATOR acknowledges that some of SMARTFENSE’s Services are designed to assist the FINAL CLIENT in raising awareness among its employees and may include the development, customization, and sending of false information security attack campaigns for employee awareness; therefore, when using them, the ADMINISTRATOR understands and accepts that they will be solely responsible for compliance with all governmental laws and regulations, and for any harmful result or consequence that may arise in connection with the use of the Services (including reports or information produced in connection therewith).
4.8 Limitation on Assignment of Final Recipients per Organization
The ADMINISTRATOR shall be responsible for managing the creation, modification, and deactivation of FINAL RECIPIENTS. Should the number of FINAL RECIPIENTS REACHED exceed the maximum limit established by the purchased license, SMARTFENSE will notify you of such a situation. The ADMINISTRATOR understands and accepts that it is prohibited to reassign or rotate accounts among recipients as a mechanism to circumvent license limits. Consequently, the ADMINISTRATOR expressly undertakes to:
- Guarantee to the PRODUCER that they hold the free, prior, express, and informed consent of the data subjects to receive communications through the aforementioned channels, in accordance with applicable legislation on personal data protection, privacy, and electronic communications.
- Refrain from sending messages, making calls, or executing automated actions that infringe the rights of third parties, undermine the principle of data minimization, or contravene provisions on spam, unsolicited advertising, or digital harassment.
- Hold the PRODUCER harmless from any claim, administrative sanction, judicial or extrajudicial demand arising from the improper use of the communication modules, including fines imposed by applicable supervisory authorities (AAIP, ENACOM, AEPD, or equivalents).
- Ensure that the content, purpose, and frequency of communications are compatible with the legal basis of the consent granted by the FINAL RECIPIENT and with the purposes declared to the PRODUCER.
- Non-compliance with this obligation shall be considered a serious breach, entitling the PRODUCER to suspend the account and/or stop the campaigns sent and/or revoke the ADMINISTRATOR’s access to said modules, without prejudice to initiating corresponding legal or contractual actions for damages.
5. Data and Intellectual Property
5.1 Ownership of Intellectual Property
The intellectual property of all assets related to SMARTFENSE, including source code, brand, logos, content, and denomination, among others, is the property of SMARTFENSE, registered internationally with the corresponding organizations. In the event of third-party claims against the ADMINISTRATOR regarding the licenses or rights of use of SMARTFENSE, the ADMINISTRATOR must notify SMARTFENSE within 24 hours in order to carry out the defense of the brand and the company’s rights.
5.2 Assignment of SMARTFENSE License
THE PRODUCER grants the FINAL CLIENT an international, revocable, limited, non-exclusive, non-sublicensable, and non-transferable license to use the SERVICES for the term and with the characteristics and functionalities applicable according to the contracted service, limited exclusively to internal use within one or more of the FINAL CLIENT’s organizations. In the event that the commercialization and/or management of the platform is carried out through a PARTNER, the latter shall also be the beneficiary of a specific license, limited to providing access and/or management and/or support services to the FINAL CLIENT, where applicable.
5.3 Ownership of ADMINISTRATOR Content
The ADMINISTRATOR retains all rights, title, and interest in the contents that they upload, transmit, or generate entirely through the platform, including, without limitation: texts, images, logos, data, audiovisual materials, and any other element of their exclusive authorship not based on templates, models, or predefined contents owned by SMARTFENSE. The use of the platform does not, under any circumstances, imply the transfer of ownership of such content to SMARTFENSE. The ADMINISTRATOR declares and warrants that:
- They hold the rights and authorizations over the content they process within the platform and/or have the right to grant the necessary licenses to SMARTFENSE and its respective suppliers, licensees, successors, and assignees, so that they may process and host such content;
- The content complies and will continue to comply with this Agreement;
- The content complies and will continue to comply with all international, federal, state, and local laws and regulations;
- The content processed within the platform: (i) does not contain any material that is defamatory, obscene, indecent, abusive, offensive, violent, hateful, inflammatory, or otherwise objectionable; (ii) does not promote sexually explicit or pornographic material, violence, or discrimination based on race, sex, religion, nationality, disability, sexual orientation, or age; (iii) does not infringe any patent, trademark, trade secret, copyright, or other intellectual property or other rights of any person; (iv) does not violate the legal rights (including rights of publicity and privacy) of others or contain any material that may give rise to any civil or criminal liability under applicable laws or regulations or that may otherwise be in conflict with this Agreement; (v) does not promote any illegal activity, or advocate, promote, or assist any unlawful act; (vi) does not intentionally create unreasonable disturbance to any other person or organization; (vii) does not contain any: (A) viruses, trojans, worms, backdoors, or other software or hardware devices whose effect would allow unauthorized access to, or would disable, delete, or otherwise damage any computer, system, software, or content; or (B) time bombs, drop-dead devices, or other software or hardware devices designed to automatically disable a computer program over time or under the positive control of any person, or to deprive SMARTFENSE, or its ADMINISTRATORS, of their legal rights.
5.4 Assignment of License for Information Processing
The ADMINISTRATOR understands and accepts that they possess sufficient and relevant rights and authorizations to use, process, store, and employ the data that will be uploaded to the platform. The ADMINISTRATOR grants SMARTFENSE a non-exclusive, transferable, non-assignable, international, royalty-free license to collect, use, copy, store, transmit, modify, and create derivative works from their data, solely to the extent necessary to provide the SERVICES and to develop and improve SMARTFENSE’s existing or future products or services.
5.5 Processing of Aggregated Data
The ADMINISTRATOR grants SMARTFENSE the ability to use uploaded contents in an aggregated, anonymous, and generic manner for marketing; survey; and benchmarking purposes, in the review and development of current and future Products and Services, use of Products and Services, and other similar purposes. The aggregated data: (a) shall only be used for internal company development and as a source of general usage statistics for the services; (b) does not identify the ADMINISTRATOR or FINAL RECIPIENT nor any individual; and (c) to the extent that such aggregated data is disclosed, it shall only be disclosed in a generic or aggregated manner for the purpose of sharing Product or Services usage and for statistical or benchmarking purposes. Aggregated data shall not be considered confidential information of the ADMINISTRATOR.
5.6 Use of Content
Regardless of the type of content used on the platform, all content — whether predefined, customized predefined, or customized — shall be subject to the following general conditions:
- Its use shall be limited exclusively to the SMARTFENSE platform framework;
- It may only be used for educational and awareness purposes of FINAL RECIPIENTS;
- The ADMINISTRATOR assumes full responsibility for any use made of such content and shall hold SMARTFENSE harmless from any damage, direct or indirect, arising from their use;
- SMARTFENSE warrants that all provided content will be functional in the email clients supported by manufacturers in their latest versions, in accordance with the minimum technical requirements requested by SMARTFENSE. Such warranty shall be excluded in the event of modification/customization by the administrator. Without prejudice to the foregoing, the following is established for each type of content: (a) Predefined Content. These are contents created and provided by SMARTFENSE on the platform by default, the intellectual property of which is and remains exclusively owned by SMARTFENSE. This type of content may not be extracted from the platform under any circumstances. (b) Customized Predefined Content. These are contents created and provided by SMARTFENSE on the platform by default, which the ADMINISTRATOR duplicates as a basis for their customization. The intellectual property of this category of templates is and remains exclusively owned by SMARTFENSE. This type of content may not be extracted from the platform under any circumstances. (c) Customized Content. Customized content is content created, provided, and uploaded to the platform entirely by the ADMINISTRATOR, without relying on templates, models, or predefined content owned by SMARTFENSE. The ADMINISTRATOR retains the intellectual property ownership generated over this type of content. Should the ADMINISTRATOR request the extraction of their customized content, SMARTFENSE may authorize it solely upon prior verification that such content is 100% the ADMINISTRATOR’s own creation and has not been based on SMARTFENSE templates or elements. Such extraction requests may only be made within the validity period of the contracted licenses, with SMARTFENSE reserving the right of prior review before proceeding with the delivery.
5.7 Phishing Report Button: The ADMINISTRATOR will have the option to install and use the “SMARTFENSE Phishing Report Button”
The “SMARTFENSE Phishing Report Button” will allow the FINAL RECIPIENT to directly report, from their own mailbox, any message they consider suspicious or fraudulent. Should they choose to install it, the ADMINISTRATOR expressly authorizes SMARTFENSE to: a) Access, store, and process the content of the reported email, including its metadata (sender, subject, technical headers, associated IP addresses, attachments, among others). b) Incorporate said report into the awareness, prevention, and security incident response campaigns developed by SMARTFENSE. c) Technically analyze the reported emails to determine their nature, adopt mitigation measures, and, where applicable, contribute to the continuous improvement of threat detection capabilities. d) Share in anonymized or aggregated form relevant information with allied third parties, security providers, or competent authorities, only when necessary for research, prevention, or response to cybersecurity incidents. All reported information shall be used exclusively for awareness purposes and to generate a better service experience, always in compliance with the provisions of the Privacy Policy and in accordance with applicable personal data protection regulations.
6. Privacy and Information Security
6.1 Processing of Personal Data
THE ADMINISTRATOR accepts that, for the correct and adequate provision of the contracted services, SMARTFENSE must process the information indicated by the ADMINISTRATOR, including personal data. THE ADMINISTRATOR understands and accepts that the processing of personal data will be carried out in accordance with the provisions of our Privacy Policy. Likewise, the ADMINISTRATOR understands and agrees that it must include, in its own contractual provisions with FINAL CLIENTS, appropriate provisions regarding the processing of personal data, in compliance with the Privacy Policy.
6.2 Compliance with Applicable Regulations
Both SMARTFENSE and THE ADMINISTRATOR understand and accept that each shall be responsible for fulfilling the obligations arising from applicable national and international legislation on personal data protection, especially in compliance with the European Data Protection Regulation (GDPR).
6.3 Infrastructure Security
SMARTFENSE implements internationally accepted industry information security techniques and measures, such as firewalls, access control procedures, and cryptographic mechanisms, to prevent improper or unauthorized access to data. THE ADMINISTRATOR understands and accepts that it is not possible to guarantee that security processes are error-free, nor that data transmissions are always secure, nor that unauthorized third parties will never be able to breach the security measures implemented by SMARTFENSE or those implemented by external service providers. For more information, please refer to the SMARTFENSE – Security, Trust, and Assurance in the Cloud .
6.4 Activity Audit
Each time the ADMINISTRATOR uses SMARTFENSE, information about the device used by the ADMINISTRATOR is automatically obtained and stored, generating an internal audit record of accesses. In order to guarantee the integrity of such activity records (logs), they may not be modified or altered by the ADMINISTRATOR under any circumstances.
6.5 Security in Data Access Control: In compliance with best practices in information security, all accesses to the system are recorded
In all cases, access will always be performed using an internal user (soporte@smartfense.com) designated for such purpose. Should reports on system accesses be required, the ADMINISTRATOR must request them through the Help Center (https://support.smartfense.com/) , and a copy of the records will be sent within 30 (thirty) days.
6.6 Use of DMI Technology (Direct Message Injection)
Enabling DMI technology will optimize and personalize the delivery of awareness messages in your organization’s email inboxes, which is why we recommend its implementation. Once enabled, SMARTFENSE assumes the obligation to use such technology solely for the purpose of sending Phishing simulations that the ADMINISTRATOR has previously generated and agreed to send. DMI technology will also allow the collection and analysis of limited information about user interactions with awareness emails, including, among others, open data, clicks, and actions taken within sent emails. SMARTFENSE technically guarantees that under no aspect or circumstance will it perform any operation outside the purpose authorized by the ADMINISTRATOR. For further information or questions related to the use of DMI technology, the ADMINISTRATOR may contact SMARTFENSE through the Help Center (https://support.smartfense.com/) .
6.7 Backup Copies: SMARTFENSE performs backup copies on a periodic basis, retaining such copies for a period of 90 (ninety) days
Backup copies will only be made for ADMINISTRATOR accounts holding commercial SMARTFENSE licenses, and do not apply to other types of licenses (free trials, trial, freemium, etc.).
6.8 Data Portability
In compliance with Article 20 of Regulation (EU) 2016/679 (GDPR), SMARTFENSE will provide the ADMINISTRATOR with the ability, at any time, to exercise their right to personal data portability, downloading their data in a structured, commonly used, and machine-readable format. Access to such data may be exercised within a maximum period of 90 days from the date of termination of the contracted license. After this period, the data will no longer be available as data deletion procedures will be applied. SMARTFENSE will provide the ADMINISTRATOR with a technical guide outlining the technical procedure to follow when downloading their data. The downloadable data includes metrics and reports generated by the various campaigns. The downloadable data does NOT include predefined and/or modified content within the platform, whose licenses only authorize internal use within the platform.
6.9 Special Consent for Use of AI Modules
The ADMINISTRATOR may at any time voluntarily, freely, and in an informed manner express their consent to access the use of certain Modules that process information using artificial intelligence tools. The ADMINISTRATOR may provide such consent, as well as revoke it at any time. The use of Modules that employ AI shall be conditional upon the prior expression of consent by the ADMINISTRATOR.
6.10 Data Retention and Deletion
Upon confirmation of license termination and after 90 (ninety) calendar days to negotiate the continuation of the service, SMARTFENSE will initiate a secure deletion process for all content uploaded by the ADMINISTRATOR to the instance. The ADMINISTRATOR understands and accepts that, for technological reasons, information stored in backup copies generated prior to the cancellation of the subscription will be deleted as new backup copies replace the sectors of the storage units used for this purpose.
6.11 Use of Custom Domains
Should the license agreement allow it, the ADMINISTRATOR may have access to a custom domain for use with the platform.
6.12 Confidentiality
The parties agree to keep all information received or to which they have access strictly confidential, and undertake not to use the information in their possession for any purpose other than that outlined in this agreement, in accordance with the following conditions:
- It is strictly prohibited to disclose and/or transfer to third parties any information obtained or known during the activity giving rise to this Agreement, and likewise prohibited is any use of the information for personal benefit or for any purpose other than the service being agreed upon under this Agreement;
- The confidentiality obligation encompasses absolutely all information that the parties process, manage, store, or that otherwise exists, including accounting, financial, operational, statistical, administrative information, agreements, or any other type of relationship with other entities, services, and policies of the parties;
- All information referenced in the preceding clauses, for which confidentiality is required, may be contained in any type of electronic or digitized information medium, as well as in books, letters, memoranda, records, spreadsheets, and any other document or communication, and likewise on paper or any other type of physical medium, including waste or discarded materials;
- The aforementioned confidentiality obligation also encompasses any information of the types previously mentioned that may be obtained, accessed, or known in the exchange between the parties and that is not contained in any medium.
6.13 SLA / Service Availability Commitment
During the term of the Agreement, SMARTFENSE guarantees that the monthly uptime percentage will be at least 99.9% (SMARTFENSE SLA) in any calendar month. If SMARTFENSE fails to meet this service availability commitment, the CLIENT may claim the Service Credits described below.
- “Monthly uptime percentage” means the total number of minutes in a calendar month minus the number of minutes of downtime suffered in a calendar month, divided by the total number of minutes in a calendar month. For this calculation, scheduled platform stoppages for the purpose of performing updates shall not be considered as included, provided that they are duly notified in advance to the designated contact and scheduled in a manner that avoids any hindrance to the adequate provision of the service.
- Should SMARTFENSE’s Service uptime be less than 99.9% but greater than 99.0%, the CLIENT will receive 3 days of Service at no charge added to the end of the Service term. Should SMARTFENSE’s Service uptime be less than 99.0% but greater than 95.0%, the CLIENT will receive 7 days of Service at no charge added to the end of the Service term. Should SMARTFENSE’s Service uptime be less than 95.0%, the CLIENT will receive 15 days of Service at no charge added to the end of the Service term. The no-charge service days accrued in favor of the CLIENT will be added as an extension upon the expiration of the contracted license (prior to renewal, if applicable).
- The CLIENT must request service credit. To receive any of the Service Credits described above, the CLIENT must notify SMARTFENSE (or the corresponding PARTNER where applicable, who must in turn notify SMARTFENSE) by creating a support case (through the Help Center (https://support.smartfense.com/) within thirty days from the moment the CLIENT becomes eligible to receive a Service Credit. Failure to comply with this requirement results in the CLIENT forfeiting the right to receive a Service Credit. If the CLIENT contracts the Services through a PARTNER and meets this requirement, the CLIENT will receive the corresponding Service Credit from the PARTNER on behalf of SMARTFENSE.
- The maximum aggregate amount of Service Credits that SMARTFENSE will issue (or, if the CLIENT requests Services from a PARTNER) to the CLIENT for all Downtime occurring in a single calendar month shall not exceed fifteen added Service days until the end of the CLIENT’s Service term. Service Credits may not be redeemed or converted into monetary amounts.
- This SMARTFENSE SLA does not apply to (i) ADMINISTRATOR accounts holding non-commercial SMARTFENSE licenses, such as free trials, trial, freemium (ii) any performance issue: (a) caused by factors described in the “Force Majeure” section of the Agreement; (b) resulting from the CLIENT’s equipment and/or third-party equipment (not within the primary control of SMARTFENSE); or (c) resulting from abuse or other ADMINISTRATOR behaviors that violate the Agreement.
7. Limitation of Liability
7.1 ADMINISTRATOR’s Liability for Legitimacy of Contents
THE ADMINISTRATOR must ensure that the use of their contents and data in the Products and Services is always compliant with applicable local, national, and international laws and regulations. The ADMINISTRATOR warrants under this Agreement that the data provided does not violate any Law (including those related to export controls and electronic communications, among others) nor the rights of any third party. In the event of possible third-party claims for unauthorized use by the ADMINISTRATOR of trademarks, logos, signs, or denominations, SMARTFENSE will notify the ADMINISTRATOR of the infringement, reserving the right to take the technical and legal actions deemed appropriate. In addition to the indemnification obligations of the ADMINISTRATOR contained in this Agreement, the ADMINISTRATOR will defend and indemnify SMARTFENSE and hold it harmless from any and all claims, losses, deficiencies, damages, liabilities, costs, and expenses (including, without limitation, reasonable attorneys’ fees) incurred by SMARTFENSE as a result of any third-party claim arising from SMARTFENSE’s hosting or distribution of the ADMINISTRATOR’s Content as authorized in this Agreement.
7.2 SMARTFENSE’s Liability for Predefined Contents
SMARTFENSE shall be responsible for the contents offered by the platform, whether in templates or original creations, that form part of the SMARTFENSE tool, provided they are used exactly as offered, without modifications or adaptations. The ADMINISTRATOR assumes full responsibility for any use made of such predefined content. SMARTFENSE shall not be liable for any damage, direct or indirect, arising from the use of or reliance on the predefined content offered on the platform.
7.3 ADMINISTRATOR’s Liability for Modification of Predefined Content
The ADMINISTRATOR may generate their own content (for example, customized campaigns with their own logos, texts, and images) based on the predefined content provided by SMARTFENSE. The ADMINISTRATOR shall be the sole and exclusive party responsible for such modified and/or generated contents, fully assuming any legal, administrative, or other consequences that may arise from their creation, modification, and use. Consequently, SMARTFENSE shall bear no liability, either direct or indirect, for the modification, generation, or use of such contents. The ADMINISTRATOR understands and accepts that they must at all times hold the relevant rights, authorizations, and licenses to use the contents uploaded through the platform, including, without limitation, personal data, logos, identifications, texts, and images. Failure to comply with this obligation shall be the exclusive responsibility of the ADMINISTRATOR, who undertakes to hold SMARTFENSE harmless from any third-party claims that may arise from the use of such contents. Should the contents be generated from a template owned by SMARTFENSE, the ADMINISTRATOR shall benefit from a temporary, limited, non-exclusive, and non-transferable license to use such contents, exclusively within the platform and for the period during which they maintain their service access license in force. Outside these terms, any use, reproduction, or distribution of predefined content or those derived therefrom is expressly prohibited.
7.4 ADMINISTRATOR’s Liability for Own Contents
The ADMINISTRATOR may generate their own content entirely within the platform. The ADMINISTRATOR shall be the sole and exclusive party responsible for such contents, fully assuming any legal, administrative, or other consequences that may arise from their creation or use. Consequently, SMARTFENSE shall bear no liability, either direct or indirect, for the generation or use of such content. The ADMINISTRATOR understands and accepts that they must at all times hold the relevant rights, authorizations, and licenses to use all elements incorporated into the platform, including, without limitation, personal data, logos, identifications, texts, and images. Failure to comply with this obligation shall be the exclusive responsibility of the ADMINISTRATOR, who undertakes to hold SMARTFENSE harmless from any third-party claims that may arise from the use of such contents.
7.5 ADMINISTRATOR’s Liability for Legitimacy of Data Processing
THE ADMINISTRATOR understands and accepts the obligation to guarantee the legitimacy of access to, collection of, and processing of any type of personal data processed in the context of service provision, in accordance with the provisions of SMARTFENSE’s Data Processing Agreement, and shall be responsible for any third-party claims regarding such processing, expressly exempting SMARTFENSE from any claims related to the processing carried out by the ADMINISTRATOR. In this regard, the ADMINISTRATOR understands and accepts that they shall be solely responsible for analyzing the legal basis justifying the collection and processing of data about recipients (name, surname, user agent, operating system, IP address, email address, date and time of actions, among other data that may be collected through SMARTFENSE), in accordance with the legislation applicable to them.
7.6 ADMINISTRATOR’s Liability for Proper Use of the Tool
The ADMINISTRATOR understands and accepts that SMARTFENSE is limited exclusively to providing a software tool that operates under the ADMINISTRATOR’s instructions and therefore shall bear no liability whatsoever for the improper, inadequate, or illegitimate use of the tool. THE ADMINISTRATOR undertakes to hold SMARTFENSE harmless from any damage and/or loss, including attorneys’ fees, that may be suffered as a result of the improper or illegitimate use of the services.
7.7 ADMINISTRATOR’s Liability for Use of Third-Party Contents
THE ADMINISTRATOR understands and accepts that they shall be exclusively responsible for any direct or indirect damage that may arise from the unlawful or unconsented use of any type of content (such as logos, identifications, formats, etc.) that affects or could affect the rights of third parties. SMARTFENSE shall only be responsible for the legitimacy of the contents offered or used in the templates and/or original creations that form part of the SMARTFENSE tool.
7.8 Limitation of Liability for Force Majeure Events
Neither party to this Agreement shall be liable for delays or failures in the performance of this Agreement (other than payment obligations or failure to comply with confidentiality requirements) resulting from acts or events beyond the reasonable control of such party, including acts of war, terrorism, acts of God, natural disasters (fires, explosions, earthquakes, hurricanes, floods, storms, infestations, etc.), embargoes, riots, sabotage, governmental acts, Internet failures, power outages, power interruptions or shortages, other utility service interruptions, or telecommunications disruptions, provided that the delayed party: (a) notifies the other party of such cause without undue delay; and (b) uses its reasonable commercial efforts to promptly remedy such failure or delay in performance.
7.9 Limitation of ADMINISTRATOR Liability for Actions within the Services
In the event that ADMINISTRATORS are assigned to different natural or legal persons (PARTNER and/or FINAL CLIENT), each party shall only be responsible for those actions carried out by the ADMINISTRATORS under the management of that party. The primary ADMINISTRATOR (initially granted by SMARTFENSE) may control the existence and privileges of other ADMINISTRATORS created within the contracted instance. Secondary administrators may or may not manage other administrators depending on the privileges configured at the time of their creation by the primary ADMINISTRATOR.
7.10 SMARTFENSE’s Liability for the Use of DMI Technology (Direct Message Injection)
Enabling DMI technology will optimize and personalize the delivery of awareness messages in your organization’s email inboxes, which is why we recommend its implementation. Once enabled by the ADMINISTRATOR or FINAL CLIENT, SMARTFENSE assumes the obligation to use such technology solely to send the Phishing and Ransomware simulations that the ADMINISTRATOR has previously generated and agreed to send. DMI technology will also allow the collection and analysis of limited information about the ADMINISTRATOR’s interactions with awareness emails, including, among others, open data, clicks, and actions taken within sent emails. SMARTFENSE technically guarantees that under no aspect or circumstance will it perform any operation outside the purpose authorized by the ADMINISTRATOR.
7.11 Limitation of Liability on SMARTFENSE’s Operating Warranty
All of SMARTFENSE’s products, services, and content are offered on an “as is” basis, without additional warranties. SMARTFENSE and its suppliers expressly disclaim any type of warranty, including, without limitation, warranties of title, fitness for a particular purpose, functionality, and merchantability, whether express, implied, or statutory, except to the extent that such warranties cannot be excluded under applicable law. SMARTFENSE shall not be liable for delays, interruptions, service failures, or any other inconvenience inherent to the use of the Internet, electronic communications, or other external systems that are beyond its reasonable control. This includes force majeure circumstances and fortuitous events, such as network interruptions, natural disasters, or governmental restrictions. To the extent permitted by law, SMARTFENSE and its suppliers make no warranty or representation regarding the reliability, timeliness, quality, availability, accuracy, or completeness of the products or services, or the contents generated or stored through them. In particular, SMARTFENSE does not warrant that: a) The products or services will be secure, timely, uninterrupted, or error-free; b) The products or services will work in combination with third-party hardware, software, systems, or data; c) The products or services will meet the ADMINISTRATOR’s specific expectations or needs; d) The stored information will always be accurate or reliable, nor will such information be lost, corrupted, or compromised; e) Any errors or defects in the products or services will be corrected; f) The products or services, or the servers that host them, will be free from viruses or other harmful elements. SMARTFENSE and its suppliers assume no responsibility for any damage arising from the use of or inability to use their products and services under the terms specified herein.
7.12 Limitation of SMARTFENSE’s Liability
To the extent permitted by law, SMARTFENSE shall not be liable for loss of use, lost or corrupted data, failures in security mechanisms, interruption of business activity, costs associated with delays, or any other indirect, special, incidental, consequential, or emergent damages of any kind, including, but not limited to, loss of profits, loss of revenue or earnings, or damages arising from reliance-based expectations. SMARTFENSE is expressly exempt from all liability for such damages, regardless of the nature of the legal action, whether contractual, tortious, including negligence, or strict liability. This exemption shall apply even when SMARTFENSE has been previously warned of the possibility of such damages. SMARTFENSE limits its liability exclusively to those cases where applicable law prevents the total exclusion of liability. In such cases, SMARTFENSE’s liability shall be subject to the minimum limits required by the applicable regulations.
7.13 ADMINISTRATOR’s Liability for Use of Custom Domains
The official operation of the SMARTFENSE Service will be through the platform available at the domain “takesecurity.com”. However, depending on the type of service contracted, the ADMINISTRATOR may have the option to use the services through their own custom domain. The ADMINISTRATOR understands and accepts that they shall be exclusively responsible for the availability and operation of the custom domain, as well as for implementing the appropriate technical configuration to ensure the normal operation of the SERVICES. The PROVIDER will provide support services to address any questions that may arise regarding the proper implementation of the service through a custom domain.
8. General Provisions
8.1 Due Authority
Each party represents and warrants that it has the legal authority and power to enter into this Agreement. In the event that the ADMINISTRATOR represents a public or private legal entity, they warrant that they hold the necessary authorizations to bind such party to comply with the terms and conditions of this Agreement.
8.2 Dispute Resolution; Arbitration
In the event of a dispute or claim arising from or related to this Agreement, the parties must consult and negotiate with each other and, recognizing their mutual interests, attempt to reach a solution satisfactory to both parties. If the parties fail to reach an agreement within a period of 60 days, any unresolved dispute or claim arising from or related to this Agreement must proceed to binding arbitration in accordance with the Arbitration Rules of the International Chamber of Commerce. The parties shall endeavor to mutually designate a single arbitrator. If the parties cannot agree on a single arbitrator, there shall be three (3) arbitrators: one chosen by each party and a third chosen by the first two. The arbitration shall take place in the City of León, Spain. All negotiations and arbitration proceedings pursuant to this Clause shall be confidential, and they shall be treated as settlement and compromise negotiations for purposes of all similar rules and evidence codes of applicable jurisdictions and legislation. The language of the arbitration shall be Spanish.
8.3 Governing Law; Jurisdiction
This Agreement shall be governed by and interpreted in accordance with the applicable laws of Spain. Each party irrevocably agrees that any claim, proceeding, or legal action not subject to the arbitration provisions of the Clause (Dispute Resolution; Arbitration) must be brought solely and exclusively in Spain, and shall be subject to service of process and other applicable procedural rules of the courts of Spain, and each party irrevocably submits to the sole and exclusive personal jurisdiction of such courts. Notwithstanding the foregoing, SMARTFENSE may bring a claim for equitable relief in any court with appropriate jurisdiction.
8.4 Equitable Relief; Application
Notwithstanding the provisions of the Clause (Dispute Resolution; Arbitration), nothing in this Agreement shall prevent either party from seeking equitable relief with respect to the violation of intellectual property rights, confidentiality obligations, or the enforcement or recognition of any award or order in any appropriate jurisdiction.
8.5 Amendments
Should it be necessary to modify or update this Agreement, the modified version shall enter into force within 30 days of its notification to the ADMINISTRATOR. Continued access to or use of the Products or Services in any manner implies acceptance of and agreement to the new terms and conditions. Should the ADMINISTRATOR disagree, they must notify of their disagreement.
8.6 Language
This Agreement is drafted in Spanish. In the event of translation into other languages, the Spanish version shall prevail for purposes of interpretation. The parties may request certified translations for local formalities, without such translations modifying the content of the original Agreement.
8.7 Notices
All notices pursuant to this Agreement must be given in writing. Notices sent to the ADMINISTRATOR shall be deemed delivered on the first business day following the day of dispatch. The ADMINISTRATOR wishing to send a notice to SMARTFENSE may do so at C/ Santos Ovejero 1 – Despacho P1-03, 24008 León, León, Spain. Notices sent to SMARTFENSE shall be deemed delivered upon our receipt.
8.8 Enforceability
If any provision of this Agreement is deemed null, invalid, unenforceable, or illegal, the remaining provisions shall continue in full force and effect. This Agreement constitutes the entire agreement between the ADMINISTRATOR and SMARTFENSE with respect to the Services, and it supersedes all prior or contemporaneous oral or written communications, proposals, or representations with respect to the Product or any other subject matter covered by this Agreement.
Effective as of September 1, 2026.