Partner Agreement for Consultants
Terms for a consultant who runs their clients’ organisations inside the platform: who pays for what, who is responsible for the data, and what may be done on a client’s behalf.
Partner Agreement for Consultants
Template version: 1.0 Version date: 1 September 2026 Document address: https://guardiso.com/umowa-partnerska
Date of conclusion: ………………………
Agreement concluded between:
the Partner — ……………………………………………, tax identification number ………………………, with its registered office at ……………………………………………, represented by ……………………………………………, email address ………………………, hereinafter referred to as the Partner,
and
Guardiso Michał Lewandowski, ulica Święty Marcin 29 lokal 8, 61-806 Poznań, tax identification number 6060011996, trading under the Guardiso brand, email address kontakt@guardiso.com, hereinafter referred to as Guardiso.
This Agreement gives effect to the reference contained in § 4(11) of the End User Licence Agreement and sets out the rules for cooperation with entities which, by means of the Platform, provide their own services to other companies.
Table of Sections
- Definitions and the place of this Agreement among the documents
- Who may become a Partner and the procedure for joining
- Subject matter of the Agreement and what the Agreement does not cover
- Adding and removing Serviced Companies
- Fees, settlements and who pays for what
- Roles in personal data protection — who is the controller
- Sub-processing — Guardiso as sub-processor
- The second variant — a direct data processing agreement with the Serviced Company
- Separation of data between Serviced Companies
- Access of persons on the Partner's side and management of permissions
- The Partner's liability towards Serviced Companies
- The Partner's liability towards Guardiso and Guardiso's liability
- Prohibition on reselling access as the Partner's own service
- What the Partner may do without separate consent
- Use of the Guardiso Designations
- Marking materials with the Partner's brand
- Support, training and materials for the Partner
- Confidentiality
- Absence of exclusivity and independence of the parties
- The Partner's representations and warranties
- Duration of the Agreement
- Termination of the Agreement
- Consequences of the end of the Agreement for Serviced Companies
- Amendments to the Agreement
- Final provisions
Annex No 1 — List of Serviced Companies Annex No 2 — Rules for the use of the Guardiso Designations Annex No 3 — Declaration of the Partner as to its authority to entrust processing
§ 1. Definitions and the place of this Agreement among the documents
-
Terms written in this Agreement with an initial capital letter which are not defined below have the meaning given to them in the Terms of Service for the Provision of Services by Electronic Means and in the End User Licence Agreement. This applies in particular to the terms: Service, Platform, Plan, Subscription, Billing Period, Price List, Account, Organisation, Account Owner, User, Customer, Protected Customer, Customer Data, Business Day, Content Library, Application Programming Interface and Access Key.
-
In addition, in this Agreement:
-
Partner — a Customer which has concluded this Agreement and maintains on the Platform at least one Organisation corresponding to an entity other than itself. The Partner is a Consultant within the meaning of § 1(5)(6) of the End User Licence Agreement.
-
Serviced Company — an entity for which the Partner maintains an Organisation on the Platform. A Serviced Company is a Consultant's Client within the meaning of the End User Licence Agreement.
-
Partner's Account — the Account on which the Partner maintains the Organisations of Serviced Companies and, if it so decides, its own Organisation.
-
Data Processing Agreement — the agreement on the entrustment of the processing of personal data concluded between Guardiso and the Partner or, in the case described in § 8, between Guardiso and the Serviced Company.
-
Guardiso Designations — the name "Guardiso", the graphic sign, the colours and other distinctive designations used by Guardiso in trade.
-
Partner's Materials — reports, assessments and other documents prepared by the Partner for a Serviced Company by means of the Platform.
-
Schedule of Limitations — § 4 of the Service Level Agreement and Part B of Annex 1 to the Data Processing Agreement, which state expressly what Guardiso does not measure, what it does not promise and what it has not so far confirmed by a test.
-
-
This Agreement supplements the Terms of Service, the End User Licence Agreement, the Data Processing Agreement, the Service Level Agreement, the Acceptable Use Policy and the Service Exit and Data Portability Rules. This Agreement replaces none of those documents.
-
The order of precedence is set out in § 23 of the Terms of Service. This Agreement is a separate written agreement within the meaning of § 23(1)(1) of the Terms of Service solely in respect of the matters expressly regulated in it. In matters of personal data protection, the Data Processing Agreement takes precedence.
-
This Agreement does not change the scope of the licence. The scope of the licence, the rights to the Content Library and the rules for using the Application Programming Interface are set out in the End User Licence Agreement.
-
For the Partner, this Agreement is of a professional nature, because it concerns the provision by the Partner of services to third parties. In the scope of this Agreement the Partner is not a Protected Customer. This does not exclude the protection of the Partner as a Protected Customer under the remaining documents, if the Partner meets the conditions set out in § 2 point 12 of the Terms of Service.
§ 2. Who may become a Partner and the procedure for joining
-
A Partner may be an entrepreneur which:
- has concluded an Agreement with Guardiso and holds a paid-for Plan;
- provides to other entities advisory, implementation, audit or support services in the field of information security, personal data protection or regulatory compliance, or acts for them as data protection officer or as the person responsible for information security;
- intends to maintain on the Platform at least one Organisation corresponding to an entity other than itself;
- has made the declarations indicated in § 20 and in Annex No 3.
-
A Partner may also be an entity maintaining the Organisations of companies belonging to the same capital group, as well as a law firm, an accounting office or another entity handling its clients' compliance documentation.
-
Concluding this Agreement is not a condition for maintaining more than one Organisation. Maintaining paid-for Organisations for entities other than the Partner falls within the licence pursuant to § 4 of the End User Licence Agreement and does not require this Agreement. This Agreement is needed solely in order to obtain the entitlements described in §§ 13, 15 and 16.
-
Procedure for joining. The interested party submits an application to kontakt@guardiso.com, indicating: its business name and registration details, the scope of the services it provides, the anticipated number of Serviced Companies and a contact person. Guardiso considers the application on Business Days.
-
Guardiso does not undertake to conclude this Agreement and does not undertake to consider the application within any specified time limit. A refusal does not require any justification; at the applicant's request Guardiso indicates the reason.
-
This Agreement is concluded upon its signature by both parties or upon the exchange of declarations in documentary form, including by electronic mail from the addresses indicated in the preamble.
-
The submission of an application does not create an obligation on the part of either party.
§ 3. Subject matter of the Agreement and what the Agreement does not cover
-
The subject matter of this Agreement is to set out the rules on which the Partner:
- maintains on the Platform the Organisations of Serviced Companies and settles accounts with Guardiso in that respect;
- provides its own services by means of the Platform;
- uses the Guardiso Designations;
- marks the Partner's Materials with its own brand;
- participates — to the extent covered by Guardiso's consent — in making access to the Platform available to Serviced Companies.
-
This Agreement in particular DOES NOT cover and DOES NOT create:
- any commission, discount or other remuneration for the Partner. This Agreement grants the Partner no reduction from the Price List and no commission on sales. Commercial terms departing from the Price List require a separate written arrangement and an entry in Annex No 1;
- any undertaking on the part of Guardiso to pass on to the Partner enquiries, contacts or other sales opportunities;
- any separate support channel for the Partner, any dedicated account manager or any shortened response times — the support rules are set out in § 17;
- any Partner certification programme, partner portal or budget for joint marketing activities — Guardiso operates none of these arrangements today;
- any undertaking on the part of Guardiso as to the availability of the Service, the time to restore operation after a failure, round-the-clock on-call cover or a cycle of penetration tests — the scope of what Guardiso does not measure and does not promise is described in the Schedule of Limitations;
- any territorial, sectoral or other exclusivity.
-
This Agreement does not create an employment relationship, a civil-law partnership, a commercial company, a commercial representation or an agency. The Partner is not a representative of Guardiso, does not conclude agreements on its behalf and does not act as an intermediary in their conclusion, unless Guardiso gives its consent on the terms set out in § 13.
§ 4. Adding and removing Serviced Companies
-
The list of Serviced Companies constitutes Annex No 1 to this Agreement. The list contains: the name and registration details of the Serviced Company, the name of the Organisation on the Platform, the date on which the maintenance of that Organisation began and ended, and an indication of the personal data protection variant in accordance with § 6.
-
Adding a Serviced Company. The Partner notifies its intention to add a Serviced Company to kontakt@guardiso.com, indicating the details listed in paragraph 1. Guardiso confirms the addition in documentary form and updates Annex No 1. Updating Annex No 1 does not require an amendment to this Agreement.
-
How this works today — we say so expressly. The Platform currently has no self-service mechanism for adding and paying for a further Organisation. There is no such item in the payment system's price list, and the number of Organisations on an Account is not enforced by any technical mechanism. Adding a Serviced Company therefore takes place manually, upon notification, and the fee is added to the invoice. Guardiso does not undertake to any deadline for performing this action. Guardiso will update this paragraph once a self-service mechanism is made available.
-
Settlement based on a declaration. In the absence of the mechanism referred to in paragraph 3, the settlement of the number of Serviced Companies is based on Annex No 1 and on the Partner's declaration. The Partner notifies each new Serviced Company before beginning to maintain an Organisation for it.
-
Declaration as to the manner of use. At the justified request of Guardiso, the Partner submits in documentary form a declaration as to the number of Organisations maintained and the entities for which they are maintained. The request states the circumstances justifying a suspicion of discrepancy. Guardiso is not entitled to inspect the Partner's IT systems.
-
Removing a Serviced Company. The Partner notifies the end of the maintenance of an Organisation for a Serviced Company to kontakt@guardiso.com. The fee for that Organisation ceases to be charged from the next Billing Period following the notification. The fate of the data collected in that Organisation is governed by the document "Service Exit and Data Portability Rules", in particular by § 14 thereof.
-
Transfer of an Organisation to the Serviced Company's account takes place upon a joint request of the Partner and the Serviced Company, requires confirmation by Guardiso and is performed manually. Guardiso does not undertake to any deadline for performing it.
§ 5. Fees, settlements and who pays for what
-
Each Organisation is separately chargeable. The Partner's Plan covers one Organisation, unless the Price List or an individual arrangement provides otherwise. Maintaining each further Organisation is subject to a fee in the amount specified in the Price List, charged independently of the Plan fee.
-
Currency. The Polish language version of the website sells in Polish zloty; every other version sells in euro. The Partner's settlement currency is the same for the Plan and for all Serviced Companies.
-
Who pays. The Partner is liable to Guardiso for the payment of all fees, that is, the Plan fee and the fees for all Organisations maintained on the Partner's Account, irrespective of the manner in which it settles accounts with Serviced Companies.
-
Settlements between the Partner and a Serviced Company are a matter solely between them. Non-payment by a Serviced Company does not release the Partner from its payment obligation towards Guardiso and does not constitute grounds for withholding payment or for reducing the fee.
-
Variant with direct payment. The parties may agree that a Serviced Company concludes its own Agreement with Guardiso and pays directly. In that case the Serviced Company is a separate Customer and the Partner is not liable for its fees. Such an arrangement is recorded in Annex No 1.
-
Invoices are issued by Guardiso to the Partner's details indicated in the preamble. The Partner notifies any change to its invoicing details before the invoice for the given Billing Period is issued.
-
Price changes take place on the terms described in § 11 of the Terms of Service. A change to the price of a further Organisation is announced in the same manner as a change to the prices of the Plans.
-
Payment arrears. Arrears are governed by § 13 of the Terms of Service. Suspension of access on account of the Partner's arrears affects all Organisations on the Partner's Account, including the Organisations of Serviced Companies. The Partner informs Serviced Companies of this before cooperation begins. Arrears are not grounds for refusing to release data — § 3(2)(4) of the Service Exit and Data Portability Rules applies.
-
Maintaining an Organisation without paying the fee due constitutes a breach of the licence. Guardiso is entitled to claim payment of the fees for the entire period of such use, in accordance with the Price List in force during that period, on the terms set out in § 15(5) of the End User Licence Agreement.
§ 6. Roles in personal data protection — who is the controller
-
Determining the roles is the most important part of this Agreement, because it determines who is answerable to whom for the personal data collected in the Organisation of a Serviced Company.
-
Variant A — sub-processing. The default variant for the Partner.
- the Serviced Company is the controller of the personal data collected in the Organisation maintained for it;
- the Partner is the processor, acting on the basis of its own data processing agreement concluded with the Serviced Company;
- Guardiso is the sub-processor, on the basis of the Data Processing Agreement concluded with the Partner;
- the details are set out in § 7.
-
Variant B — direct entrustment.
- the Serviced Company is the controller and concludes its own Data Processing Agreement directly with Guardiso;
- Guardiso is then the processor in relation to the Serviced Company, and not a sub-processor;
- the Partner is then a separate processor of the same controller, or a person authorised by the controller to process data on its behalf — depending on the content of the agreement concluded by the Partner with the Serviced Company;
- the details are set out in § 8.
-
Variant C — the Partner as controller. In respect of the Partner's own Organisation and of the data of the Partner's own employees and associates, the Partner is the controller and Guardiso is the processor on the basis of the Data Processing Agreement.
-
User account data. Irrespective of the variant, in respect of the personal data of Users processed for the purposes of maintaining the Account, authentication, settlements and contact, Guardiso is the controller, on the terms described in the Privacy Policy.
-
The choice of variant for each Serviced Company is recorded in Annex No 1. Where no indication is given, Variant A applies.
-
The Partner may not unilaterally change the variant once processing has begun. A change requires the consent of the Serviced Company and confirmation by Guardiso, and must be recorded in Annex No 1.
§ 7. Sub-processing — Guardiso as sub-processor
-
Legal basis. Sub-processing takes place pursuant to Article 28(2) and (4) of Regulation (EU) 2016/679 of the European Parliament and of the Council. Under Article 28(2), a processor shall not engage another processor without prior specific or general written authorisation of the controller.
-
The Partner's declaration. The Partner declares that, in respect of each Serviced Company covered by Variant A:
- it has concluded with the Serviced Company a data processing agreement meeting the requirements of Article 28(3) of Regulation (EU) 2016/679;
- it has obtained the controller's authorisation — specific or general, given in writing — to use Guardiso as a sub-processor;
- it has informed the controller of the identity of Guardiso, of the scope of the processing operations entrusted to it, of the place where the data is stored and of the sub-processors indicated in Annex 2 to the Data Processing Agreement;
- it has provided the controller with the Schedule of Limitations.
The wording of the declaration is set out in Annex No 3.
-
The same level of obligations. Guardiso assumes the same data protection obligations as those imposed on the Partner in relation to the controller, to the extent that it carries out processing operations — in accordance with Article 28(4) of Regulation (EU) 2016/679. Those obligations are set out in the Data Processing Agreement concluded between Guardiso and the Partner, which under Variant A applies in such a way that wherever it refers to the Controller, this is to be understood as the Partner acting on the instructions of the controller.
-
Allocation of liability. In accordance with the final sentence of Article 28(4) of Regulation (EU) 2016/679, where Guardiso fails to fulfil its data protection obligations, the Partner remains fully liable to the controller. Guardiso is liable to the Partner on the terms described in § 13 of the Data Processing Agreement. This provision does not exclude Guardiso's liability towards the data subject arising under Article 82 of Regulation (EU) 2016/679.
-
Chain of instructions. Guardiso processes data solely on the documented instructions of the Partner. Guardiso does not accept instructions directly from a Serviced Company, unless the Partner indicates it as entitled to give instructions and Guardiso confirms this. Such an indication is recorded in Annex No 1.
-
Requests from data subjects. If a data subject approaches Guardiso directly, Guardiso does not respond to the request on the merits, but promptly, and no later than within three business days, forwards it to the Partner and informs the person making the request who the controller of their data is. The Partner promptly forwards the request to the controller.
-
Personal data breach. Guardiso reports a breach to the Partner, without undue delay and no later than within 48 hours of the breach being established by Guardiso, on the terms and with the content described in the Data Processing Agreement. Guardiso does not report a breach directly to the controller or to the supervisory authority. The obligations towards the controller and towards the authority are performed by the Partner, within its own time limits arising under Article 33 of Regulation (EU) 2016/679. The Partner informs Guardiso of the notification made.
-
Change of sub-processors. Guardiso informs the Partner of its intention to add a new sub-processor or to replace an existing one with at least thirty days' notice. The Partner promptly forwards that information to the controller. The Partner notifies the controller's objection to Guardiso within the same period of thirty days. The consequences of an objection are governed by § 7 of the Data Processing Agreement.
-
Audit. The controller exercises its audit right through the Partner, on the terms described in § 12 of the Data Processing Agreement, including with thirty days' notice. Guardiso may present, in place of an inspection, a current certificate or the report of an independent auditor, if it covers the scope of the request. The Partner may not confer on the controller audit rights wider than those it holds itself.
-
End of the processing. After the maintenance of an Organisation ends, Guardiso returns or erases the data on the instructions of the Partner, on the terms set out in § 11 of the Data Processing Agreement and in the document "Service Exit and Data Portability Rules". If the request is made directly by the Serviced Company, Guardiso performs it after confirmation by the Partner or after the Serviced Company presents evidence of the termination of its agreement with the Partner. Guardiso then notifies the Partner.
-
Record of processing activities. Guardiso maintains a record of the categories of processing activities carried out on behalf of the Partner, in accordance with Article 30(2) of Regulation (EU) 2016/679, and makes it available to the Partner on request.
-
Data location. The data is stored in the Republic of Poland, in a data centre in Warsaw. Some of the sub-processors operate outside the European Economic Area; the legal basis for each such transfer is indicated in Annex 2 to the Data Processing Agreement.
§ 8. The second variant — a direct data processing agreement with the Serviced Company
-
Variant B applies where a Serviced Company wishes to be a party to a data processing agreement directly with Guardiso, in particular where its own policy or the requirements of its auditor so demand.
-
Under Variant B:
- the Serviced Company concludes with Guardiso a Data Processing Agreement in its own name;
- Guardiso performs towards it all the obligations of a processor, including reporting personal data breaches to it directly, within 48 hours of their being established;
- the Serviced Company exercises its audit right directly in relation to Guardiso;
- the Partner obtains access to the Organisation on the basis of an authorisation or of its own agreement concluded with the Serviced Company, and not on the basis of this Agreement.
-
Who pays under Variant B is determined in accordance with § 5(5). Unless the parties agree otherwise, the fee for the Organisation is borne by the Partner.
-
Under Variant B the Partner does not become a party to the relationship between Guardiso and the Serviced Company and may not make declarations to Guardiso on its behalf, unless it presents a power of attorney.
-
The choice of Variant B does not release the Partner from the obligations described in §§ 9, 10, 11 and 20 of this Agreement.
§ 9. Separation of data between Serviced Companies
-
Each Serviced Company has a separate Organisation, constituting a separate data space. The personal data of each Organisation is encrypted with a separate key assigned solely to that Organisation. Compromise of the key of one Organisation does not expose the data of another.
-
Prohibition on maintaining several companies in one Organisation. The Partner does not maintain in one Organisation the documentation of more than one entity. The prohibition applies irrespective of whether this would serve to avoid a fee.
-
Prohibition on transferring data between Organisations otherwise than by means of the functions made available on the Platform for that purpose, and solely where the Partner has a legal basis for doing so.
-
Prohibition on using the data of one Serviced Company for the benefit of another Serviced Company, or for the Partner's own purposes going beyond the servicing of that Organisation.
-
What the prohibition in paragraph 4 does not cover. The Partner may use its own professional knowledge, experience and skills acquired in the course of its work. This does not constitute a breach of this Agreement, provided that it does not involve the transfer, disclosure or reconstruction of the data, documents or confidential information of a Serviced Company.
-
Review of permissions. The Partner reviews the permissions granted in each Organisation no less frequently than once every six months, and in each case after the end of cooperation with a person who held such access.
-
Guardiso has no standing access to the data collected in Organisations. Every access by Guardiso personnel requires a request stating the scope, the duration and the justification, and approval on the customer's side; it is time-limited and visible in the access log. Consent to access the Organisation of a Serviced Company is given by the entity indicated as entitled in accordance with § 7(5).
-
Guardiso is not liable for the consequences of the Partner granting access to an unauthorised person, nor for the scope of the access which the Partner granted.
§ 10. Access of persons on the Partner's side and management of permissions
-
Accounts are personal. The Partner grants access solely to identified natural persons and does not create shared accounts. The reason is the accountability of the entries in the activity log, and not any limit on the number of Users — the Plans do not limit the number of Users.
-
Principle of the necessary scope. The Partner grants access to an Organisation solely to those persons who need it in order to perform tasks in that Organisation, and only to the extent necessary for that purpose.
-
Authorisations and confidentiality. The Partner ensures that every person admitted to processing data in the Organisation of a Serviced Company has been authorised to do so and has undertaken to maintain confidentiality, in accordance with Article 28(3)(b) of Regulation (EU) 2016/679.
-
Withdrawal of access. The Partner promptly withdraws access from persons who have ceased to perform tasks in the given Organisation, in particular after the end of cooperation with the Serviced Company.
-
Access Keys to the Application Programming Interface operate solely within the boundaries of a single Organisation. The Partner does not create additional Access Keys, Accounts or Organisations in order to circumvent limits.
-
The Partner is liable for the acts and omissions of the Users and Serviced Companies to which it has granted access as for its own acts.
-
The Partner promptly notifies Guardiso at security@guardiso.com of any suspicion of unauthorised access to the Partner's Account or to any of the Organisations maintained.
§ 11. The Partner's liability towards Serviced Companies
-
The Partner provides its own services in its own name and for its own account. Guardiso is not a party to the agreement between the Partner and a Serviced Company and is not liable for its performance.
-
Prohibition on giving assurances on behalf of Guardiso. The Partner makes no declarations or assurances on behalf of Guardiso. In particular, the Partner does not assure a Serviced Company of:
- any specified percentage level of availability of the Service — Guardiso does not measure availability and gives no such undertaking;
- any guaranteed time to restore operation after a failure or any guaranteed scope of data recovery from backup — Guardiso has not to date carried out a documented recovery test;
- round-the-clock on-call cover or the existence of an incident response team — Guardiso does not operate them;
- automatic notification of a failure — Guardiso does not maintain such a mechanism;
- periodic penetration tests at any specified frequency — Guardiso does not undertake to a fixed cycle.
-
Obligation to provide the Schedule of Limitations. The Partner provides the Serviced Company with the Schedule of Limitations before concluding an agreement with it, so that it can take those circumstances into account in its own risk assessment and in its own data protection impact assessment.
-
Duty to inform as to the nature of the tool. The Partner informs the Serviced Company that the Platform is a tool supporting compliance management, that the assessment of compliance, decisions concerning risk and the content of the documentation are matters for the Serviced Company, and that indicators, proposals and content generated by artificial intelligence are of an auxiliary nature and require verification by a human being.
-
Indemnity. The Partner indemnifies Guardiso against liability towards the Serviced Company and towards third parties to the extent that the claim arises from an assurance given by the Partner going beyond the scope resulting from the Guardiso documents, from failure to perform the obligations under paragraphs 3 and 4, or from the Partner's own services. Guardiso promptly notifies the Partner of any such claim, does not acknowledge it without the Partner's consent and enables the Partner to take part in the defence.
-
Claims of a Serviced Company against Guardiso are available solely to the extent resulting from the documents to which the Serviced Company is a party and from mandatory provisions of law, including Article 82 of Regulation (EU) 2016/679.
-
The Partner enables the Serviced Company to obtain the documentation collected in the Organisation maintained for it, in accordance with § 14 of the document "Service Exit and Data Portability Rules".
§ 12. The Partner's liability towards Guardiso and Guardiso's liability
-
The Partner is liable to Guardiso for the manner in which each Organisation maintained is used, for the acts and omissions of the Users and Serviced Companies to which it has granted access as for its own acts, and for the payment of the fees for all Organisations maintained.
-
Guardiso's liability to the Partner under this Agreement is limited to the total of the net fees paid by the Partner in the twelve months preceding the event giving rise to the claim.
-
Guardiso is not liable to the Partner for lost profits, for loss of reputation, for loss of anticipated savings or for indirect damage. Guardiso is not liable for the outcome of any audit, inspection or certification proceedings conducted in relation to the Partner or to a Serviced Company.
-
No provision of this Agreement excludes or limits liability for damage caused intentionally. A stipulation to the contrary would be invalid by force of Article 473 § 2 of the Civil Code. Nor is there any exclusion of liability for gross negligence, for personal injury, or of any liability whose exclusion is impermissible under mandatory provisions of law.
-
The limitations in paragraphs 2 and 3 do not apply to Guardiso's claims for breach of the licence, in particular the claims described in § 15(5) of the End User Licence Agreement and in § 13(5) of this Agreement.
-
Liability in the field of personal data protection is governed by the Data Processing Agreement and by Article 82 of Regulation (EU) 2016/679. The provisions of this section do not limit the liability of either party towards the data subject.
-
Guardiso provides the Service with due professional care. The scope of Guardiso's undertakings as to support, response times and backups is set out in the Service Level Agreement.
§ 13. Prohibition on reselling access as the Partner's own service
-
Without the prior consent of Guardiso the Partner may not:
- sell, resell, rent out or otherwise make available access to the Platform as a separate service, including acting as an intermediary in the sale of Subscriptions;
- present the Platform as its own software or as its own service provided under its own brand, including making it available under its own domain or trade name;
- make one paid-for Organisation available to several entities in order to avoid the fee for further Organisations;
- offer access to the Platform as an element of its own offering in a situation in which the recipient pays the Partner for access to the Platform as such, and not for a service of the Partner performed by means of it.
-
The dividing criterion. What is decisive is what the recipient pays for. If the recipient pays for the Partner's work — for implementation, for maintaining documentation, for preparation for an audit, for holding a function — this is permitted. If the recipient pays for access to the tool as such and the Partner is merely an intermediary, consent is required.
-
Procedure for obtaining consent. The Partner submits an application to kontakt@guardiso.com, describing the model of cooperation, the manner of settlement with the recipient, the manner in which the Platform is presented and the anticipated scale. Guardiso replies in documentary form. Consent may be granted conditionally, for a fixed term and with a right of revocation on notice of not less than thirty days.
-
Guardiso is not obliged to grant consent. A refusal does not require any justification; at the Partner's request Guardiso indicates the reason.
-
Consequences of a breach. In the event of a breach of this section, Guardiso is entitled to:
- a claim for cessation of the breach and for the removal of its effects;
- a claim for payment of the fees for Organisations maintained without payment of the fee due, for the entire period of such use, in accordance with the Price List in force during that period;
- a claim for compensation for damage on general principles;
- the right to terminate this Agreement with immediate effect, on the terms set out in § 22.
-
This Agreement does not provide for contractual penalties.
§ 14. What the Partner may do without separate consent
-
Providing the Partner's own services for consideration by means of the Platform, in paid-for Organisations, is permitted and constitutes the essence of the cooperation. This covers in particular:
- implementing an information security and compliance management system at Serviced Companies;
- maintaining the documentation, registers and evidence of a Serviced Company;
- preparing a Serviced Company for an audit and supporting that audit;
- acting for a Serviced Company as data protection officer or as the person responsible for information security;
- preparing the Partner's Materials and providing them to the Serviced Company.
-
Use of the Content Library when working for Serviced Companies is permitted within the boundaries of paid-for Organisations, together with the right to provide the Serviced Company with the documentation produced in that way. This does not cover providing the Content Library in unprocessed form — as a set of templates, a catalogue or mappings — to an entity other than the entity for which a paid-for Organisation is maintained. The rules are set out in § 8 of the End User Licence Agreement.
-
Informing others about the cooperation. The Partner may state that it uses the Platform in its work, on the terms described in § 15.
-
Granting access to the auditor of a Serviced Company, to a certification body and to other third parties performing a task for it is permitted to the extent of the functions provided on the Platform for that purpose.
§ 15. Use of the Guardiso Designations
-
Guardiso grants the Partner a non-exclusive, non-transferable and revocable right to use the Guardiso Designations solely for the purpose of stating that the Partner provides services by means of the Platform. That right lasts for the term of this Agreement.
-
The Partner may in particular:
- use the description "Guardiso Partner" and place the Guardiso graphic sign on its website, in its information materials and in its offers, in the form and proportions described in Annex No 2;
- refer to the Platform by name in the description of its own services;
- use the information materials made available to it by Guardiso, without altering them.
-
The Partner may not:
- use the Guardiso Designations in a manner suggesting that it is an organisational unit of Guardiso, its representative or agent, or that it acts on its behalf;
- use the Guardiso Designations in its business name, in its trade name or in the name of its own product or service;
- register domain names, social media accounts or trade marks containing the Guardiso Designations or designations similar to them to a degree giving rise to a likelihood of confusion;
- conduct paid advertising activities based on the Guardiso Designations as a keyword — without the prior consent of Guardiso;
- alter the graphic sign, its proportions or its colours, or combine it with its own sign in a manner creating a new designation;
- make declarations on behalf of Guardiso as to the characteristics of the Service, in particular the assurances listed in § 11(2);
- issue press releases, publications or statements to the media on behalf of Guardiso;
- use the ISO/IEC 27001 certificate held by Guardiso as its own certificate, or suggest that the Guardiso certificate covers the Partner's activity.
-
Publication of materials using the Guardiso Designations in channels with public reach, including social media and press materials, requires the prior consent of Guardiso given in documentary form.
-
Naming the Partner as a reference. Guardiso may name the Partner as a reference, giving solely its name and trade mark, after obtaining the Partner's prior consent given in documentary form. Consent may be withdrawn at any time with effect for the future. The rule applies symmetrically.
-
Revocation of the right. Guardiso may revoke the right under paragraph 1 in the event of a breach of this section, setting the Partner a time limit of not less than fourteen days to remedy the breach. In the event of a breach threatening Guardiso's reputation, revocation may take place immediately, with notification after the event.
-
Guardiso retains all rights to the Guardiso Designations. This Agreement transfers no rights to them to the Partner.
§ 16. Marking materials with the Partner's brand
-
To the extent that the Platform makes this available, the Partner may mark the Partner's Materials with its own name, graphic sign and colours.
-
The Partner declares that it holds the rights to the designations used and indemnifies Guardiso against liability in respect of third-party claims concerning those designations.
-
The entitlement under paragraph 1 does not constitute consent to presenting the Platform itself as the Partner's software or service. The marking concerns a document prepared by the Partner, and not the tool in which it was produced.
-
The Partner does not remove or alter the indications of origin, rights notices or watermarks placed on materials downloaded from the Platform or made available through it.
-
The scope of the material-marking functions depends on what the Platform makes available at any given time. Guardiso does not undertake to maintain the scope of those functions unchanged or to extend them. Changes are governed by § 12 of the Terms of Service.
§ 17. Support, training and materials for the Partner
-
The Partner uses support on the same terms as any other Customer, through the support request channel, during the support hours and with the response times set out in the Service Level Agreement, as applicable to its Plan.
-
Guardiso does not operate today — and we say so expressly:
- any separate support channel for Partners;
- any dedicated Partner account manager;
- any shortened response times for Partner requests;
- any partner portal;
- any Partner certification programme;
- any training or examination programme for Partners;
- any budget for joint marketing activities;
- any programme for passing enquiries and sales contacts on to Partners.
-
Support requests concerning the Organisations of Serviced Companies are submitted by the Partner in its own name. Guardiso does not accept requests directly from a Serviced Company, unless Variant B applies or the Partner has indicated it as entitled in accordance with § 7(5).
-
Information materials — descriptions of the Platform, materials to be passed on to a Serviced Company and the Schedule of Limitations — are made available by Guardiso to the Partner on request, with no undertaking as to time.
-
If Guardiso launches any of the arrangements listed in paragraph 2, it will amend the content of this section in the manner set out in § 24.
§ 18. Confidentiality
-
Confidential Information means any information obtained by one party from the other in connection with this Agreement, irrespective of its form and the manner in which it was communicated, and in particular:
- on the Partner's side — the data collected in the Organisations maintained, information about Serviced Companies, about their safeguards, vulnerabilities, incidents, audit results and risk assessments, and also commercial terms agreed individually;
- on Guardiso's side — the Content Library, technical documentation, information about the architecture and safeguards of the Platform, information about identified vulnerabilities, and commercial terms agreed individually.
-
Each party undertakes not to disclose Confidential Information to third parties and to use it solely for the purpose of performing this Agreement. A party may make Confidential Information available solely to those of its employees, associates and subcontractors who need it in order to perform this Agreement, binding them to maintain confidentiality to the same extent.
-
The confidentiality obligation does not cover information which is publicly available without a breach of this Agreement, which was known to the party before it was received, which was obtained from a third party entitled to disclose it, and information whose disclosure is required by a mandatory provision of law or by a decision of a competent authority. In the last case, the disclosing party notifies the other party before disclosure, unless the provision prohibits this.
-
The confidentiality obligation binds for the term of this Agreement and for three years after it ends. The obligation concerning personal data lasts indefinitely, in accordance with the Data Processing Agreement.
-
The provisions of this section do not limit the Partner's obligations towards Serviced Companies arising under agreements concluded by the Partner with those entities.
§ 19. Absence of exclusivity and independence of the parties
-
This Agreement creates no exclusivity on the part of either party.
-
The Partner may provide services using the tools of other suppliers, including tools competing with the Platform, and conclude partner agreements with other suppliers. Guardiso does not in this respect restrict the Partner's freedom to conduct business activity.
-
Guardiso may conclude partner agreements with other entities, sell the Service directly and conduct its own commercial activities on any market.
-
Guardiso's undertaking. Guardiso will not use information about Serviced Companies obtained under this Agreement in order to address a commercial offer to them bypassing the Partner during the term of this Agreement and for twelve months after it ends. The undertaking does not apply to entities which approached Guardiso on their own initiative, or to entities of which Guardiso had knowledge independently of this Agreement.
-
Prohibition on building a competing product. The Partner does not use the Content Library or information about the architecture and safeguards of the Platform in order to build a product or service competing with the Platform. That prohibition concerns solely the use of Guardiso's materials and information and does not restrict the Partner's right to conduct any activity based on its own resources.
-
The parties are independent entrepreneurs. Each party bears its own costs of performing this Agreement and is independently responsible for its own public-law obligations.
-
This Agreement is not an agency agreement within the meaning of Article 758 et seq. of the Civil Code. The Partner does not act as an intermediary in the conclusion of agreements for Guardiso and does not conclude them on its behalf.
§ 20. The Partner's representations and warranties
The Partner represents and warrants that:
-
it carries on business activity and holds the authorisations necessary to provide the services which it offers to Serviced Companies;
-
the details indicated in the preamble and in Annex No 1 are true and up to date, and it will notify Guardiso of any change to them promptly;
-
in respect of each Serviced Company covered by Variant A it is authorised to entrust the processing of personal data to Guardiso and has obtained the required authorisation of the controller, in accordance with § 7(2) and Annex No 3;
-
it has concluded with each Serviced Company an agreement setting out the scope of its own services and of its own liability;
-
it has provided, or will provide, each Serviced Company with the Schedule of Limitations before concluding an agreement with it;
-
it has not given and will not give, on behalf of Guardiso, the assurances listed in § 11(2);
-
it has a legal basis for the processing of the personal data entered into the Organisations maintained and has performed the duty to inform the data subjects, or that the controller has performed that duty;
-
it has read and accepts the content of the Terms of Service, the End User Licence Agreement, the Data Processing Agreement, the Service Level Agreement, the Acceptable Use Policy and the Service Exit and Data Portability Rules;
-
it has made the Users to whom it grants access familiar with the Acceptable Use Policy.
§ 21. Duration of the Agreement
-
This Agreement is concluded for an indefinite period.
-
This Agreement enters into force on the date of its conclusion and remains in force for as long as the Partner holds a paid-for Plan.
-
Expiry of the Customer's Agreement. The end of the Agreement for the provision of the Service concluded between Guardiso and the Partner causes this Agreement to expire on the same date. The consequences are governed by § 23.
-
Suspension of access to the Partner's Account does not cause this Agreement to expire, but suspends the exercise of the entitlements under §§ 15 and 16 for the duration of the suspension.
§ 22. Termination of the Agreement
-
Either party may terminate this Agreement on one month's notice, with effect at the end of a calendar month, without giving reasons. Notice of termination is given in documentary form.
-
Termination of the Partner Agreement is not termination of the Agreement for the provision of the Service. A Partner which has terminated this Agreement remains a Customer and may continue to maintain paid-for Organisations within the boundaries of § 4 of the End User Licence Agreement, losing the entitlements under §§ 13, 15 and 16 of this Agreement.
-
Guardiso may terminate this Agreement with immediate effect solely for important reasons, which include:
- a breach of § 13, that is, resale of access without Guardiso's consent;
- a breach of § 15 threatening Guardiso's reputation, in particular giving on behalf of Guardiso the assurances listed in § 11(2);
- a breach of § 9, that is, a breach of the separation of data between Serviced Companies;
- making an untrue declaration as referred to in § 20 point 3, concerning the authority to entrust processing;
- maintaining an Organisation without paying the fee due, despite an unsuccessful demand;
- a gross breach of the Acceptable Use Policy, despite an unsuccessful demand.
-
The Partner may terminate this Agreement with immediate effect if Guardiso grossly breaches this Agreement and does not remedy the breach within the time limit set in the demand, being not less than fourteen days.
-
Demand before termination. Save in the cases listed in paragraph 3 points 1, 2 and 4, before terminating with immediate effect Guardiso demands that the Partner cease the breach and remove its effects, setting a time limit of not less than fourteen days.
-
Termination does not deprive the parties of claims which arose before it was given.
§ 23. Consequences of the end of the Agreement for Serviced Companies
-
The end of this Agreement does not of itself bring about the end of the Subscription, the deletion of Organisations or the deletion of the data of Serviced Companies. Guardiso does not apply loss of data as a consequence of the end of partner cooperation.
-
The Partner promptly notifies Serviced Companies of the end of this Agreement and of its consequences.
-
Within thirty days of the end of this Agreement the parties determine the fate of each Organisation indicated in Annex No 1. For each of them the following solutions are possible:
- taking over the Organisation by the Serviced Company onto its own Account — upon a joint request of the Partner and the Serviced Company, after confirmation by Guardiso and after the Serviced Company has secured a paid-for Plan; the transfer is performed manually and Guardiso does not undertake to any deadline for performing it;
- continued maintenance of the Organisation by the Partner within the boundaries of § 4 of the End User Licence Agreement, without the entitlements arising under §§ 13, 15 and 16 of this Agreement; this solution is possible solely where the Partner retains a paid-for Plan, and therefore not where this Agreement has expired as a result of the end of the Agreement for the provision of the Service in accordance with § 21(3);
- ending the maintenance of the Organisation and exit on the terms described in the document "Service Exit and Data Portability Rules", including with the thirty-day data download period.
-
Until a solution is determined, Guardiso preserves the existing state and does not delete data.
-
Dispute between the Partner and a Serviced Company. Guardiso does not resolve such disputes. This does not limit Guardiso's obligations arising under the personal data protection legislation towards the entity which is the controller of the data collected in the given Organisation.
-
Ceasing to use the Guardiso Designations. Within fourteen days of the end of this Agreement the Partner removes the Guardiso Designations from its website, from its information materials and from its offers, and ceases to use the description "Guardiso Partner".
-
Settlement. Fees are due until the date on which the maintenance of the individual Organisations ends, and not until the date on which this Agreement ends.
-
After the end of this Agreement the following continue to apply: § 9(4) in respect of the prohibition on using data, § 12, § 15(7), § 18, § 19(4) and (5), this section and § 25.
§ 24. Amendments to the Agreement
-
Amendments to this Agreement are announced by Guardiso thirty days' in advance, with notice to the Partner by electronic mail to the address indicated in the preamble. The absence of an objection within that period means acceptance of the amendment. An objection entitles the Partner to terminate this Agreement with effect as at the date on which the amendment enters into force.
-
Updating Annex No 1 — the list of Serviced Companies — takes place in the manner set out in § 4 and does not require compliance with the time limit under paragraph 1.
-
An amendment may not deprive the Partner of entitlements acquired before the date on which it enters into force, or affect the fate of the data of Serviced Companies collected before that date.
-
A change to the Price List takes place in the manner set out in § 11 of the Terms of Service, and not in the manner set out in this section.
-
Individual commercial arrangements require written or documentary form on pain of invalidity and take precedence over the provisions of the template of this Agreement.
§ 25. Final provisions
-
The governing law is Polish law.
-
The competent court for disputes arising under this Agreement is the common court having local jurisdiction over Guardiso's registered office.
-
Before bringing a matter before the courts, a party shall notify the other party of its claim in writing or by electronic mail, setting a time limit of not less than fourteen days for a position to be taken.
-
The Partner may not transfer the rights and obligations arising under this Agreement without the prior consent of Guardiso given in documentary form. This also applies to the transfer of the Partner's Account.
-
If any provision of this Agreement proves to be invalid or ineffective, the remaining provisions remain in force. In place of the invalid provision, the provision of law applies, and in the absence of such a provision — the provision closest to the intended economic purpose.
-
This Agreement is drawn up in the Polish language. If a translation into another language is made available, in the event of any discrepancy the Polish version prevails.
-
Annexes forming an integral part of this Agreement:
- Annex No 1 — List of Serviced Companies;
- Annex No 2 — Rules for the use of the Guardiso Designations;
- Annex No 3 — Declaration of the Partner as to its authority to entrust processing.
-
This Agreement has been drawn up in two identical counterparts, one for each party, or concluded in documentary form by the exchange of declarations.
The Partner ……………………………………………
Guardiso ……………………………………………
Annex No 1 — List of Serviced Companies
The list is updated in the manner set out in § 4 of this Agreement and does not require an amendment to it. The current version of the list applies from the date on which Guardiso confirms it in documentary form.
| No | Serviced Company — name and tax identification number | Name of the Organisation on the Platform | Data protection variant (A, B or C) | Entity entitled to give instructions in accordance with § 7(5) | Who pays for the Organisation | Start date | End date |
|---|---|---|---|---|---|---|---|
| 1 | |||||||
| 2 | |||||||
| 3 |
Commercial arrangements departing from the Price List: …………………………………………… (The absence of an entry means that the Price List applies and that the Partner is entitled to no discount and no commission.)
Number of Organisations covered by the price of the Plan: ………… Fee for each further Organisation: in the amount specified in the Price List, in accordance with the Partner's settlement currency.
Annex No 2 — Rules for the use of the Guardiso Designations
-
Form of the sign. The Partner uses solely the graphic sign files provided to it by Guardiso. The sign may not be reproduced independently or redrawn.
-
Proportions and clear space. The sign may not be stretched, compressed, rotated or cropped. Clear space of a width not less than the height of the letter "G" in the sign is maintained around the sign.
-
Colours. The sign is used in its original colours or in the monochrome version provided by Guardiso. The colours may not be altered, and the sign may not be placed on a background making it impossible to read.
-
Permitted descriptions:
- "Guardiso Partner";
- "We work in Guardiso";
- "We implement using the Guardiso platform".
-
Impermissible descriptions:
- "Guardiso [name of the Partner]" and any other combination creating a new designation;
- "Authorised representative of Guardiso", "Guardiso branch", "Guardiso Polska" and similar descriptions suggesting an organisational connection;
- "Certified by Guardiso" — Guardiso does not operate a Partner certification programme;
- any description suggesting that the ISO/IEC 27001 certificate held by Guardiso covers the Partner's activity.
-
The Schedule of Limitations in the Partner's materials. In every material in which the Partner describes the characteristics of the Platform, it is prohibited to state the undertakings listed in § 11(2) of this Agreement. The Partner describes solely those characteristics which result from the current Guardiso documents.
-
Consent to publication. Publication of materials using the Guardiso Designations in channels with public reach requires the prior consent of Guardiso in documentary form. Guardiso considers the application on Business Days.
-
Cessation. Within fourteen days of the end of this Agreement or of the revocation of the right, the Partner removes the Guardiso Designations from all of its materials, including from its website and from its social media profiles.
Annex No 3 — Declaration of the Partner as to its authority to entrust processing
(Made separately for each Serviced Company covered by Variant A.)
Partner: ……………………………………………, tax identification number ………………………
Serviced Company: ……………………………………………, tax identification number ………………………
Name of the Organisation on the Platform: ……………………………………………
Acting on behalf of the Partner, I declare that:
-
The Serviced Company is the controller of the personal data collected in the indicated Organisation, and the Partner is its processor.
-
The Partner has concluded with the Serviced Company a data processing agreement meeting the requirements of Article 28(3) of Regulation (EU) 2016/679 of the European Parliament and of the Council, in force on the date this declaration is made.
-
The Partner has obtained the controller's authorisation — specific or general, given in writing — to use Guardiso as a sub-processor, in accordance with Article 28(2) of that Regulation.
-
The Partner has informed the controller:
- of the identity of Guardiso and of the scope of the processing operations entrusted to it;
- of the place where the data is stored — the Republic of Poland, a data centre in Warsaw;
- of the sub-processors indicated in Annex 2 to the Data Processing Agreement and of the bases for transferring data outside the European Economic Area;
- of the procedure for notifying changes to the list of sub-processors and of the right to object.
-
The Partner has provided the controller with the Schedule of Limitations, that is, § 4 of the Service Level Agreement and Part B of Annex 1 to the Data Processing Agreement, which state expressly what Guardiso does not measure, what it does not promise and what it has not so far confirmed by a test, so that the controller can take those circumstances into account in its own risk assessment.
-
The Partner has given the controller no assurance concerning the level of availability of the Service, the time to restore operation after a failure, the scope of data recovery from backup, round-the-clock on-call cover, automatic notification of a failure or the frequency of penetration tests.
-
The Partner will notify Guardiso promptly if any of the above declarations ceases to correspond to the facts.
Place and date: ………………………
Signature of the person authorised to represent the Partner: ……………………………………………