Annex No. 2 to the Terms and Conditions
CLIENT PORTAL TERMS OF USE
This English text is a translation provided for convenience. Only the Slovak wording of this document is legally binding.
These Client Portal Terms of Use (hereinafter referred to as the ‘Rules’) form an integral part of the General Terms and Conditions for the Provision of Services in B2B Relationships of BILVAO s. r. o. (hereinafter referred to as the ‘Terms and Conditions’) and set out the conditions and rules for the Client's use of the Client Portal. Unless expressly stated otherwise in these Rules, the terms used herein shall have the meanings assigned to them in Article II of the Terms and Conditions.
I. INTRODUCTORY PROVISIONS
1. The Client Portal is the Provider's web application available at online.bilvao.com. It is used for the mutual exchange of documents and information required for the Provider to provide the Services to the Client and to make accounting data and other outputs available to the Client.
2. These Rules apply to any use of the Client Portal by the Client, its Authorised Users and other persons acting on behalf of the Client or with its knowledge and consent. The Client is responsible for compliance with these Rules by all persons whom it has allowed to access the Client Portal through its login credentials or by any other means.
3. The provisions of the Terms and Conditions and the interpretation of terms under Article II of the Terms and Conditions shall apply mutatis mutandis to these Rules.
II. ACCESS TO THE CLIENT PORTAL
1. Once the Agreement has been concluded, the Provider shall make access to the Client Portal available to the Client as part of Onboarding pursuant to Article V of the Terms and Conditions. Access shall be provided by means of login credentials delivered by the Provider to the Client electronically or by another agreed method.
2. The Client is solely responsible for keeping the login credentials secure and protecting them against misuse or access by unauthorised third parties. The Client shall be fully liable for any damage arising from the disclosure, misuse or unauthorised use of the login credentials, irrespective of whether such disclosure or misuse results from the Client's inadequate protection of the login credentials or from any other cause not attributable to the Provider.
3. If the Client suspects that the login credentials have been disclosed, misused or used without authorisation, the Client shall immediately inform the Provider and request a reset of the login credentials or another security measure.
III. AUTHORISED USERS AND PROCESSING OF PERSONAL DATA IN THE CLIENT PORTAL
1. The Client shall designate specific natural persons from among its current employees or other associates who are authorised to access the Client Portal on the Client's behalf (hereinafter referred to as the ‘Client's Authorised Users’). The Client shall update the list of Authorised Users whenever the employment relationship or other working relationship with such persons changes and shall immediately inform the Provider of any change to the Authorised Users, in particular the termination of their authorisation to access the Client Portal.
2. The Client is strictly prohibited from granting access to the Client Portal, disclosing login credentials or providing any other form of access to the Provider's Services to any third party who is not one of the Client's Authorised Users within the meaning of paragraph 1 of this Article of the Rules, irrespective of that person's relationship with the Client. This prohibition also applies where the Client intends to grant access to an affiliated undertaking, supplier, external associate or any other third party.
3. The Client shall provide the Provider through the Client Portal only with such personal data, documents and information as are necessary for the Provider to provide the Services. The Client shall comply with the principles arising from the GDPR, in particular the data-minimisation principle, and shall not provide the Provider with personal data, documents or information beyond what is necessary for the provision of the Services (see Article VII of the Terms and Conditions).
4. The processing of data subjects' personal data through the Client Portal by the Provider, acting as processor on behalf of the Client as controller, shall be governed by a separate Data Processing Agreement (DPA) and the relevant provisions of Articles XII and XIII of the Terms and Conditions.
IV. RULES FOR USING THE CLIENT PORTAL
1. The Client may use the Client Portal solely for the purpose of cooperating with the Provider under the Agreement and the Terms and Conditions, in particular for submitting documents and information, accessing its accounting data and outputs, and communicating with the Provider.
2. The Client shall use the Client Portal solely through the official graphical user interface and in accordance with the Provider's instructions, procedures, guides and manuals made available in the Client Portal or delivered to the Client in another form.
3. The Client shall comply with the security and technical rules governing use of the Client Portal and shall refrain from any conduct that could damage the Client Portal, its operation, the data contained therein or the Provider's operational security.
V. PROHIBITED ACTIVITIES
1. The Client and its Authorised Users are strictly prohibited from carrying out, or allowing third parties to carry out, any cyberattacks against the Client Portal or the Provider's infrastructure, including vulnerability scanning, penetration testing without the Provider's prior written consent, distributed denial-of-service (DDoS) attacks, artificially overloading the infrastructure, or any other form of attack.
2. The Client and its Authorised Users are strictly prohibited from analysing the source code, database architecture, know-how or other technical components of the Client Portal by means of decompilation, disassembly, reverse engineering or any other method.
3. The Client and its Authorised Users are strictly prohibited from circumventing the graphical user interface of the Client Portal and from using automated scripts, bots, data-download tools (web scraping) or other tools enabling unauthorised access to the backend, application programming interface (API) or databases of the Client Portal.
4. The Client and its Authorised Users are strictly prohibited from inserting, uploading or otherwise introducing into the Client Portal (including accounting documents and other attachments) any malicious code, computer viruses, malware, Trojan horses or other forms of malicious software.
VI. CONFIDENTIALITY AND PROTECTION OF OPERATIONAL DATA
1. The Client Portal, its source code, database architecture, technical documentation, the Provider's know-how, operational data and other technical components of the Client Portal constitute the Provider's trade secrets within the meaning of Section 17 et seq. of the Commercial Code and are the Provider's confidential information. The Client and its Authorised Users shall keep such information confidential, irrespective of the manner in which they gain access to it when using the Client Portal.
2. If, as a result of a system error, technical fault or otherwise, the Client or its Authorised Users accidentally gain access to the Client Portal's operational data, source code, data of other clients of the Provider or other data not intended for them, they shall:
a) immediately inform the Provider of that fact electronically or through the Client Portal;
b) refrain from any further access to, copying, storage or other handling of such data;
c) at the Provider's instruction, destroy or delete any copies or records of such data that have accidentally come into the Client's possession.
3. The Client and its Authorised Users are strictly prohibited from disclosing, disseminating, providing to third parties or otherwise misusing any data or information obtained through accidental access under the preceding paragraph of these Rules.
VII. FINAL PROVISIONS
1. The Provider may temporarily restrict or interrupt operation of the Client Portal due to scheduled maintenance, technical faults or other operational requirements. The Provider shall use reasonable endeavours to carry out scheduled maintenance of the Client Portal at a time that minimises its impact on the Client and to inform the Client of scheduled maintenance in advance.
2. Any breach of these Rules by the Client or its Authorised Users shall constitute a material breach of the Agreement and the Terms and Conditions. In such a case, the Provider may:
a) temporarily suspend or permanently revoke access to the Client Portal for the Client and its Authorised Users;
b) invoice the Client for the costs incurred in remedying the consequences of a breach of these Rules in accordance with the Price List;
c) withdraw from the Agreement in accordance with the procedure set out in Article XI of the Terms and Conditions;
d) claim compensation from the Client for the full amount of any damage in accordance with Article IX of the Terms and Conditions and the relevant provisions of the Commercial Code.
3. These Rules constitute Annex No. 2 to the Terms and Conditions. The Provider may unilaterally update these Rules in accordance with the procedure set out in the final provisions of the Terms and Conditions.