B2B Licence Agreement

Effective 30 June 2026
Abuse / takedown contact
abuse@tryreflecta.app

This B2B Licence Agreement (the “Agreement”) is made on the Effective Date between:

(1) REFLECTA LABS SOFTWARE TRADING L.L.C, a Limited Liability Company - Single Owner (LLC - SO) incorporated and licensed in Dubai, United Arab Emirates, with Commercial Licence No. 1606456, Commercial Register No. 2819318, DCCI Membership No. 674950, licensed activity: Computer Systems & Communication Equipment Software Trading, and registered address at Office 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates (“Reflecta”, “Service Provider”, “we”, “us” or “our”); and

(2) [CLIENT LEGAL NAME], a company duly incorporated and existing under the laws of [jurisdiction], with registered number [●] and registered office at [address] (the “Client”).

Reflecta and the Client are each a “Party” and together the “Parties”.

1. Background

1.1

Reflecta operates an AI-powered creative generation platform with private user workspaces. The Services allow users to upload or select visual assets, create and manage workspaces, use platform-provided materials, and generate visual Outputs using AI-powered tools.

1.2

Reflecta does not operate a public social network, public feed or public in-app user-to-user content platform.

1.3

The Client wishes to access and use the Services for its internal business, product visualisation, marketing, editorial, creative, prototyping or other commercial purposes, subject to the terms of this Agreement and the applicable Order Form.

1.4

This Agreement is intended for negotiated B2B / enterprise use. It does not replace the public user-side legal package for ordinary self-serve users, except to the extent expressly stated in this Agreement or the applicable Order Form.

2. Documents Incorporated by Reference and Order of Precedence

2.1

This Agreement should be read together with:

2.2

In the event of conflict between the documents listed above, the following order of precedence applies, unless a specific document expressly provides otherwise:

2.3

The Reflecta Terms of Use apply to Authorised Users only to the extent they access the Services through individual Accounts or user-facing interfaces and only where they do not conflict with this Agreement.

2.4

For the Client’s enterprise use, this Agreement prevails over the Reflecta Terms of Use to the extent of any inconsistency.

3. Definitions

In this Agreement, unless the context requires otherwise:

Account
means a user account registered with Reflecta.
Affiliate
means, in relation to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with that Party, where “control” means the power to direct or cause the direction of the management and policies of such entity.
AI Features
means AI-powered generation, editing, styling and transformation tools made available through the Services, including tools that generate fashion, product, editorial, marketing-style or other visual Outputs using Client Assets, Platform Assets, prompts, styles, products, collections, settings and other inputs.
AI Infrastructure Provider
means a third-party provider used by Reflecta to process inputs, prompts, images, generation parameters or other data to provide AI-powered functionality.
App Marketplace
means Apple App Store or any other digital marketplace through which the Services may be distributed from time to time.
Apple IAP
means Apple In-App Purchase and related Apple payment infrastructure used for purchases made inside the iOS application.
Authorised Users
means the Client’s employees, officers, contractors, consultants, representatives or other individual users authorised by the Client to access the Services through the Client’s Workspace, subject to this Agreement and the applicable Order Form.
Business Day
means any day other than a Saturday, Sunday or public holiday in Dubai, United Arab Emirates.
Client Asset
means any image, product photograph, person/model reference, setting or scene reference, text, prompt, tag, description, collection, product reference or other material uploaded, created, selected, stored or submitted by or on behalf of the Client or any Authorised User through the Services.
Client Content
means any Client Asset, prompt, photo, image, text, metadata, tag, description, communication, report or other material that the Client or any Authorised User uploads, submits, transmits, creates, selects or otherwise provides to the Services.
Client Personal Data
means Personal Data contained in, or forming part of, Client Content or otherwise processed by Reflecta on behalf of the Client in connection with the Services.
Confidential Information
has the meaning given in Clause 25.
Credits
means credits, tokens, allowances or similar digital units that may be used within the Services to access or redeem eligible AI Features, generation requests, exports or other digital functionality.
Data Protection Laws
means all data protection and privacy laws applicable to a Party’s processing of Personal Data under this Agreement, including, where applicable, GDPR, UK GDPR, Swiss data protection law, UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, and any other applicable privacy or data protection legislation.
Effective Date
means the date on which this Agreement is executed by the last of the Parties to sign, unless a different effective date is stated in the applicable Order Form.
Fees
means the fees payable by the Client as set out in the applicable Order Form.
High-Risk Likeness
means any person, model, persona, character, likeness, celebrity, public figure, influencer, brand ambassador, employee, customer or identifiable individual whose use may require enhanced legal clearance due to publicity rights, personality rights, privacy rights, data protection rights, contractual restrictions, copyright, trademark, endorsement risk, reputational risk or other legal or commercial considerations.
Initial Term
means the initial term set out in the applicable Order Form.
Intellectual Property Rights
means all patents, copyrights, database rights, design rights, trademarks, service marks, trade names, trade secrets, domain names, moral rights, neighbouring rights, rights in confidential information, rights in goodwill and all other intellectual property rights, whether registered or unregistered, anywhere in the world.
Order Form
means any written order form executed by the Parties which references this Agreement and sets out the commercial, subscription, Workspace, output licence, support, fee and other terms of the Services.
Output or Outputs
means images or other content generated, edited or transformed by the Services based on Client Assets, Platform Assets, prompts or other inputs.
Paid Services
means subscriptions, Credits, premium features, paid digital functionality, credit packs, enhanced Outputs, high-resolution exports, business plans, enterprise features or other paid offerings made available through the Services.
Person / Model Asset
means an image or reference representing a human person, model, persona, likeness or identifiable individual that is uploaded, selected or used as a visual reference in the Services. A Person / Model Asset is not an AI model.
Personal Data
means information relating to an identified or identifiable natural person, or information otherwise treated as personal information, personal data or personally identifiable information under applicable Data Protection Laws.
Platform Asset
means any asset, template, style, scene, product, collection, sample prompt, preset, reference material, model image, setting or other content made available by Reflecta within the Services.
Reflecta Content
means the Services and all software, AI systems, workflows, interfaces, designs, text, graphics, images, examples, templates, Platform Assets, styles, scenes, products, collections, presets, documentation, trademarks, trade names, service marks, logos, slogans and other content made available by Reflecta.
Services
means the Reflecta platform, including the Reflecta website, iOS mobile application, software, AI Features, account workspaces, content libraries, billing features, support channels and related services.
Subscription
means a recurring paid plan that provides access to specified Paid Services for a subscription period, subject to this Agreement and the applicable Order Form.
Term
means the term of this Agreement, including the Initial Term and any renewal period.
Workspace
means an account environment, workspace, organization profile or team space associated with the Client for managing Authorised Users, subscriptions, Credits, Client Assets, Outputs and related settings.

4. Enterprise Access and Grant of Licence

4.1

Subject to the Client’s compliance with this Agreement and payment of all Fees, Reflecta grants the Client a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence during the Term to access and use the Services for the Client’s internal business purposes and for the permitted use of Outputs as set out in this Agreement and the applicable Order Form.

4.2

The licence granted under Clause 4.1 is limited to:

  • the number of Authorised Users set out in the applicable Order Form;
  • the Workspace identified in the Order Form;
  • the subscription tier, functionality, Credits and usage limits specified in the Order Form;
  • the permitted business purposes and Output use described in this Agreement and the Order Form.

4.3

The Client shall ensure that access to the Services is restricted to Authorised Users.

4.4

The Client shall ensure that Authorised Users keep login credentials confidential and do not share Accounts, passwords or access tokens.

4.5

The Client is responsible for all activity carried out through its Workspace, Accounts and Authorised Users.

4.6

Reflecta may suspend access to the Services where reasonably necessary to protect its legitimate legal, security, technical, operational or commercial interests, including in the event of non-payment, material breach, sanctions risk, security incident, suspected misuse, unlawful content, abuse, App Marketplace requirement, payment-provider requirement or service-provider restriction.

5. Authorised Users

5.1

The Client may permit Authorised Users to access the Services only for the Client’s lawful business purposes and only in accordance with this Agreement.

5.2

The Client shall ensure that each Authorised User complies with:

5.3

The Client shall remain liable for the acts and omissions of its Authorised Users as if they were the acts and omissions of the Client.

5.4

The Client shall promptly remove or request removal of access for any person who is no longer authorised to use the Services.

6. Workspace Administration

6.1

The Client shall designate one or more Workspace administrators.

6.2

Workspace administrators may be able to invite Authorised Users, manage access, view usage, manage Client Assets and Outputs, configure certain settings and perform other administrative functions.

6.3

The Client is responsible for ensuring that Workspace administrators are properly authorised and trained.

6.4

Reflecta is not responsible for unauthorised access resulting from the Client’s failure to manage Authorised Users, Workspace permissions or Account credentials.

7. Client Content and Client Assets

7.1

Ownership of Client Content remains with the Client or its licensors.

7.2

Reflecta does not claim ownership of Client Content.

7.3

The Client grants Reflecta a non-exclusive, worldwide, royalty-free, fully paid, transferable and sublicensable licence to host, store, temporarily cache, reproduce, modify as technically necessary, process, transmit, display and otherwise use Client Content solely for the following purposes:

  • providing, operating, maintaining, securing and supporting the Services;
  • generating, editing, rendering, storing and displaying Outputs at the Client’s or Authorised Users’ direction;
  • enabling library, download, Workspace, sharing and collaboration features where enabled;
  • applying safety, abuse-prevention, fraud-prevention and policy-enforcement controls;
  • debugging, quality assurance, technical support, error monitoring and service reliability;
  • complying with law, legal process, rights complaints and regulatory obligations;
  • enforcing this Agreement and the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.

7.4

The licence in Clause 7.3 is limited to the purposes described above. It does not permit Reflecta to sell Client Content, use Client Content for third-party marketing, or train Reflecta’s general AI models unless the Client expressly opts in under Clause 14 or the applicable Order Form.

7.5

The licence in Clause 7.3 terminates when the relevant Client Content is deleted from the Services or this Agreement expires or terminates, subject to limited retention reasonably necessary for backups, disaster recovery, security investigations, fraud prevention, abuse records, legal compliance, dispute resolution, audit, accounting and other lawful purposes.

8. Client Responsibilities for Client Content

8.1

The Client represents and warrants that:

  • it owns Client Content or has all rights, licences, permissions, consents and legal bases necessary to upload, process and use Client Content in the Services;
  • Client Content does not infringe or violate any copyright, trademark, design right, trade dress right, database right, moral right, privacy right, publicity right, personality right, data protection right, contractual right, confidentiality obligation or other right;
  • where Client Content depicts another person, the Client has obtained all legally required permissions, releases, consents and legal bases to upload and process that image and use the resulting Outputs;
  • where Client Content includes images of employees, contractors, customers, influencers, models, ambassadors, celebrities or public figures, the Client has obtained all necessary employment, model, influencer, ambassador, talent, publicity, likeness, privacy, commercial-use and data-protection consents;
  • where Client Content includes branded materials, products, trade dress, logos, artwork, designs, packaging, fashion items, textile prints, campaign images or photographs, the Client has obtained all necessary IP and commercial-use rights;
  • Client Content is not unlawful, harmful, infringing, misleading, exploitative, abusive, unsafe or otherwise prohibited by the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.

8.2

The Client must not upload images of minors.

8.3

The Client must never upload, generate, request, store, share or attempt to generate sexual, exploitative, harmful, abusive, age-inappropriate or unlawful content involving minors.

8.4

The Client is solely responsible for the legal clearance and commercial use of Client Content and Outputs, including in each jurisdiction where the Client uses, publishes, distributes or commercialises Outputs.

9. Platform Assets and Reflecta Content

9.1

Reflecta and its licensors retain all rights, title and interest in and to Reflecta Content, Platform Assets, the Services, software, AI systems, workflows, interfaces, designs, prompts, templates, styles, scenes, products, collections, presets, documentation, trademarks, trade names, service marks, logos and all related Intellectual Property Rights.

9.2

Except as expressly stated in this Agreement or the applicable Order Form, no rights in Reflecta Content or Platform Assets are transferred to the Client.

9.3

The Client may use Platform Assets only as part of authorised use of the Services and only to generate Outputs in accordance with this Agreement.

9.4

The Client shall not extract, reproduce, resell, sublicense, distribute, scrape, copy, reverse engineer, independently exploit or create derivative services from Platform Assets, Reflecta Content or any non-public part of the Services except as expressly permitted in writing by Reflecta.

10. Outputs

10.1

Subject to the Client’s compliance with this Agreement and payment of all Fees, Reflecta grants the Client the right to use Outputs generated through the Services during the Term within the scope set out in this Agreement and the applicable Order Form.

10.2

Unless otherwise stated in the Order Form, the Client may use Outputs for internal business, product visualisation, editorial, marketing, creative, prototyping and commercial purposes, provided that such use complies with this Agreement, applicable law and third-party rights.

10.3

The applicable Order Form may specify:

  • permitted media channels;
  • permitted territory;
  • permitted duration;
  • whether high-resolution export is included;
  • whether use is limited to a campaign;
  • whether exclusivity applies;
  • whether any High-Risk Likeness is approved;
  • whether any additional clearance, approval or licence is required.

10.4

As between the Parties, Reflecta does not claim ownership of Client Content merely because it is used to generate an Output.

10.5

To the extent Reflecta owns or controls any rights in an Output that are necessary for the Client’s permitted use under this Agreement, Reflecta grants the Client a non-exclusive, worldwide, royalty-free, fully paid licence to use such rights for the permitted scope set out in this Agreement and the applicable Order Form.

10.6

No assignment of Intellectual Property Rights in Outputs occurs unless expressly agreed in writing by authorised representatives of both Parties.

10.7

AI-generated Outputs may not be protected by copyright in all jurisdictions and may be identical or similar to Outputs generated for others. Reflecta does not guarantee that any Output is unique, exclusive, registrable, copyrightable or free from third-party rights.

10.8

The Client is responsible for reviewing Outputs before using, publishing, distributing or commercially exploiting them.

10.9

The Client must not represent that an Output is a real photograph, authentic endorsement, official product image, official campaign, human-only creation or factual depiction where doing so would be misleading.

11. Commercial Use of Outputs

11.1

Subject to the applicable Order Form, the Client may use Outputs for:

  • websites;
  • social media;
  • e-commerce platforms;
  • digital advertising;
  • print advertising;
  • exhibitions and trade fairs;
  • out-of-home campaigns;
  • product visualisation;
  • internal design, concepting, prototyping and creative review;
  • other channels expressly approved in the Order Form.

11.2

The Client must ensure that the use of Outputs complies with:

  • advertising law;
  • consumer protection law;
  • intellectual property law;
  • privacy, publicity and image rights;
  • data protection law;
  • platform rules;
  • sector-specific regulatory requirements;
  • applicable disclosure requirements for AI-generated or materially modified content.

11.3

Reflecta does not warrant that any Output is free from third-party rights or suitable for commercial use in a particular jurisdiction, industry, campaign or media channel.

12. High-Risk Likenesses and Restricted Uses

12.1

The Client must not use a High-Risk Likeness unless:

  • the relevant use is expressly permitted in the applicable Order Form; or
  • Reflecta has approved the relevant use in writing; and
  • the Client has obtained all required rights, licences, permissions, clearances and consents.

12.2

Reflecta may require evidence of clearance before enabling, exporting or permitting commercial deployment of Outputs incorporating a High-Risk Likeness.

12.3

Reflecta makes no representation or warranty that any High-Risk Likeness is cleared, authorised or available for commercial use unless expressly confirmed in writing by Reflecta.

12.4

The Client must not use Outputs to imply endorsement, sponsorship, affiliation, certification, origin, approval or association by any person, brand, model, celebrity, public figure, institution, platform, rights holder or third-party provider unless the Client has independently obtained all necessary rights.

13. Acceptable Use and Content Safety

13.1

The Client and Authorised Users must comply with the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.

13.2

The Client must not use the Services, Client Content, Platform Assets or Outputs for illegal, harmful, abusive, deceptive, unsafe, exploitative or rights-infringing purposes.

13.3

Reflecta may use automated safeguards, AI provider safety controls, user reporting channels, manual review and account-enforcement measures to reduce misuse.

13.4

Reflecta does not guarantee that all unlawful, infringing, unsafe or policy-violating Content will be detected or blocked.

13.5

If a request cannot be processed because it may violate Reflecta’s content safety rules, Reflecta may return a generic safety message and may record relevant metadata for safety, abuse-prevention and legal purposes.

13.6

Reflecta may remove, restrict, suspend or disable Client Content, Outputs, features, Accounts or Workspaces where reasonably necessary to address actual or suspected breach, legal risk, rights complaints, minor safety, abuse, fraud, sanctions, payment issues, security concerns or service-provider requirements.

14. AI Training and Service Improvement

14.1

Reflecta does not use Client Content, Client Assets, prompts, generated Outputs or Client Personal Data to train Reflecta’s general AI models or create separate AI products made available to other users unless the Client expressly opts in under the applicable Order Form or a separate written agreement.

14.2

Nothing in Clause 14.1 prevents Reflecta from processing Client Content where reasonably necessary to:

  • provide the Services;
  • generate Outputs requested by the Client or Authorised Users;
  • maintain and secure the Services;
  • apply safety controls;
  • detect or prevent misuse;
  • investigate technical issues;
  • debug and maintain service reliability;
  • comply with legal obligations;
  • respond to rights complaints, abuse reports or legal requests.

14.3

Third-party AI Infrastructure Providers may process inputs, prompts, Client Assets, Outputs and related technical data in accordance with their own terms, privacy policies, data processing commitments and technical safeguards, as further described in the Reflecta Privacy Notice and any applicable data processing addendum.

14.4

If the Client opts in to an AI training or improvement programme:

  • the opt-in must be express and recorded in the Order Form or a separate written agreement;
  • the scope of Client Content covered must be identified;
  • the purposes of use must be described;
  • any exclusions must be stated;
  • the Client may withdraw the opt-in with prospective effect unless otherwise expressly agreed;
  • Reflecta shall not use excluded Client Content for future training after the exclusion becomes effective.

14.5

Unless expressly agreed otherwise, Client Content used for optional training or improvement shall not be externally disclosed in identifiable form or used in a manner that identifies the Client in marketing or public materials.

15. AI Generation, Non-Uniqueness and No Professional Advice

15.1

Outputs are generated through machine-learning systems that operate probabilistically rather than deterministically.

15.2

Outputs may:

  • differ from instructions or reference materials;
  • vary between identical generation requests;
  • contain inaccuracies or inconsistencies;
  • omit or introduce visual elements;
  • resemble Outputs generated for other users;
  • contain artefacts, distortions or unexpected features.

15.3

Outputs should not be interpreted as statements of fact, official product images, authentic endorsements, professional advice or human-only creations unless they have been independently verified and are not misleading in context.

15.4

The Client is responsible for all human review, clearance, legal review, marketing review, product review, regulatory review and approval processes required for its intended use of Outputs.

16. Image Processing and Non-Biometric Use

16.1

Reflecta processes uploaded images and image-derived technical information as visual assets and reference inputs for AI generation.

16.2

Reflecta does not operate a facial recognition, identity verification, biometric authentication, face-matching, person-search or liveness-detection service.

16.3

Reflecta does not use uploaded images or image-derived information to identify, authenticate, verify, compare, search for or recognise a person, and does not create a facial recognition database, face ID, biometric template, liveness profile or identity verification record.

16.4

The Client must not use the Services or Outputs as the sole basis for legal, financial, medical, employment, housing, insurance, immigration, law-enforcement, biometric-identification or similarly significant decisions about a person.

17. Fees, Invoicing and Payment

17.1

The Client shall pay the Fees set out in the applicable Order Form.

17.2

Unless otherwise stated in the Order Form:

  • Fees are payable annually in advance;
  • invoices are payable within 30 days of invoice date;
  • all Fees are exclusive of VAT, sales tax, withholding tax, duties, bank charges and similar taxes or charges;
  • the Client is responsible for all applicable taxes, except taxes based on Reflecta’s net income.

17.3

If any undisputed amount remains unpaid after its due date, Reflecta may:

  • suspend access to the Services;
  • suspend the relevant Workspace;
  • withhold Credits or other entitlements;
  • charge late payment interest at the rate specified in the Order Form or, if none is specified, the maximum rate permitted by applicable law;
  • recover reasonable costs of collection.

17.4

The Client shall not withhold payment, set off amounts or make deductions unless required by law or agreed in writing by Reflecta.

17.5

If the Client is required by law to withhold or deduct tax from any payment, the Client shall gross up the payment so that Reflecta receives the amount it would have received absent such withholding or deduction, unless otherwise agreed in the Order Form.

18. Credits, Usage Limits and Subscription Mechanics

18.1

The Order Form may specify Credits, usage allowances, generation limits, export limits, storage limits, Workspace limits, Authorised User limits or other plan restrictions.

18.2

Credits and usage allowances have no monetary value outside the Services and are not redeemable for cash except where required by applicable law.

18.3

Unused Credits may expire, roll over or be forfeited as specified in the Order Form.

18.4

Reflecta may monitor usage for billing, security, support, abuse-prevention and compliance purposes.

18.5

Reflecta may restrict or suspend usage that exceeds the limits in the Order Form unless the Parties agree additional Fees or upgraded terms.

19. App Marketplace and Payment Channel Rules

19.1

Where the Client or Authorised Users access the Services through the iOS application, use of the application may be subject to Apple App Store rules and Apple’s applicable terms.

19.2

Unless a permitted enterprise arrangement, custom access method or applicable App Marketplace rule allows otherwise, digital features purchased inside the iOS application must be purchased through Apple IAP.

19.3

Direct enterprise invoice billing may be made available only where Reflecta considers it legally, technically and commercially appropriate.

19.4

Reflecta is not responsible for independent acts or omissions of App Marketplaces or payment providers outside Reflecta’s reasonable control.

20. Service Levels and Support

20.1

Reflecta shall provide support in accordance with the support tier specified in the Order Form.

20.2

Unless a specific service level is stated in the Order Form, Reflecta provides standard business-hours email support only.

20.3

Reflecta does not guarantee uninterrupted, error-free or defect-free operation of the Services.

20.4

The Services may be unavailable due to scheduled maintenance, emergency maintenance, provider outages, infrastructure failures, App Marketplace issues, payment-provider restrictions, security updates, legal requirements, force majeure events or circumstances outside Reflecta’s reasonable control.

20.5

Reflecta may modify, suspend or discontinue features, models, providers, styles, Platform Assets, Credits, pricing plans or functionality where reasonably necessary to improve security, reliability, performance, legal compliance, safety controls, provider compliance or user experience.

21. Security

21.1

Reflecta shall implement reasonable technical and organisational measures designed to protect Client Content and Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

21.2

Such measures may include:

  • encryption in transit;
  • encryption at rest where supported by infrastructure providers;
  • password hashing;
  • HTTP-only session cookies;
  • access controls;
  • role-based internal access;
  • API access checks;
  • Workspace-level access restrictions;
  • secure cloud infrastructure;
  • vendor due diligence;
  • limited administrative access;
  • crash and error monitoring;
  • abuse and account enforcement procedures.

21.3

The Client is responsible for managing Authorised Users, permissions, devices, credentials, internal security, local downloads, exported Outputs and any Client-side security controls.

21.4

No method of transmission or storage is completely secure.

22. Data Protection

22.1

Each Party shall comply with Data Protection Laws applicable to it in connection with this Agreement.

22.2

Reflecta processes Personal Data in accordance with the Reflecta Privacy Notice.

22.3

In relation to Account data, billing data, support communications, security data, abuse records and Reflecta’s own operational records, Reflecta may act as an independent controller or business, depending on applicable law.

22.4

In relation to Client Personal Data contained in Client Content and processed by Reflecta solely on behalf of the Client to provide the Services, Reflecta may act as processor or service provider, depending on applicable law.

22.5

Where Reflecta acts as processor or service provider, the Data Processing Addendum in Schedule 2 applies.

22.6

The Client is responsible for ensuring that:

  • it has a lawful basis for uploading and processing Client Personal Data through the Services;
  • it provides all required notices to data subjects;
  • it obtains all required consents, releases and permissions;
  • it does not upload images of minors;
  • it does not upload sensitive Personal Data unless legally permitted and necessary for the intended use;
  • its use of Outputs complies with applicable data protection, privacy, publicity and image-rights laws.

23. Third-Party Providers and Subprocessors

23.1

The Services may rely on third-party providers, including cloud infrastructure providers, database hosting providers, file storage providers, AI Infrastructure Providers, crash-reporting providers, payment processors, App Marketplaces, authentication providers, email providers, support providers and professional advisers.

23.2

Third-party services may be subject to their own terms, privacy policies and technical safeguards.

23.3

Reflecta is responsible for the Services it provides, but is not responsible for the independent acts or omissions of third-party providers outside Reflecta’s reasonable control.

23.4

Reflecta may change third-party providers where reasonably necessary for operational, technical, legal, commercial, security or provider-management reasons.

23.5

Where required by the applicable data processing addendum, Reflecta shall provide information about subprocessors and subprocessor changes.

24. Confidentiality

24.1

“Confidential Information” means all non-public information disclosed by one Party to the other in connection with this Agreement which is marked as confidential or which by its nature ought reasonably to be regarded as confidential.

24.2

Confidential Information includes business information, technical information, commercial information, pricing, product plans, Client Content, security information, credentials, usage data, non-public features, documentation and any non-public information relating to AI systems, workflows, models, prompts, safety controls or provider configurations.

24.3

Each Party shall:

  • keep Confidential Information strictly confidential;
  • use it solely for the purposes of this Agreement;
  • disclose it only to employees, Affiliates, contractors, professional advisers, service providers or representatives who have a need to know and are bound by confidentiality obligations;
  • protect it using reasonable care.

24.4

Confidential Information does not include information that:

  • becomes public through no breach of this Agreement;
  • was lawfully known to the receiving Party before disclosure;
  • is independently developed without use of the disclosing Party’s Confidential Information;
  • is lawfully received from a third party without confidentiality restriction;
  • is required to be disclosed by law, court order, regulator, authority or stock exchange requirement.

24.5

Where disclosure is required by law, the receiving Party shall, where legally permitted, provide prompt notice to the disclosing Party and cooperate to limit disclosure.

24.6

Confidentiality obligations survive termination for five years, except that trade secrets and highly sensitive technical, security, business or Client Content information remain confidential for so long as they remain non-public and commercially sensitive.

25. Warranties

25.1

Each Party warrants that:

  • it has full power and authority to enter into this Agreement;
  • it will comply with applicable law;
  • its performance of this Agreement will not breach any obligation owed to a third party.

25.2

Reflecta warrants that it will provide the Services using reasonable skill and care.

25.3

Reflecta warrants that, to its knowledge, the Services as provided by Reflecta and used in accordance with this Agreement do not infringe third-party Intellectual Property Rights, excluding claims arising from Client Content, Client instructions, third-party services, Platform Assets licensed from third parties, AI Infrastructure Providers, campaign use, or use in breach of this Agreement.

25.4

The Client warrants that Client Content, Client instructions and Client use of Outputs comply with this Agreement, applicable law and third-party rights.

25.5

Except as expressly stated in this Agreement, the Services, AI Features, Platform Assets and Outputs are provided on an “as is” and “as available” basis.

25.6

Reflecta does not warrant that:

  • the Services will be uninterrupted, error-free or secure at all times;
  • Outputs will be accurate, complete, lawful, unique, exclusive, copyrightable, registrable or suitable for a particular purpose;
  • Outputs will be free from third-party rights;
  • any specific AI model, provider, feature, style, Platform Asset or workflow will remain available;
  • safety systems will detect or block all unlawful, unsafe or infringing Content.

26. Indemnities

26.1

Reflecta shall indemnify the Client against third-party claims alleging that the Services, as provided by Reflecta and used in accordance with this Agreement, infringe third-party Intellectual Property Rights.

26.2

The indemnity in Clause 26.1 does not apply to claims arising from:

  • Client Content;
  • Client instructions;
  • Client’s use of Outputs;
  • campaign context, advertising claims, endorsement claims or product claims;
  • use of High-Risk Likenesses;
  • use in breach of this Agreement;
  • modification of the Services by anyone other than Reflecta;
  • combination with systems, materials or services not provided by Reflecta;
  • third-party providers, AI Infrastructure Providers or App Marketplaces outside Reflecta’s reasonable control;
  • Client’s failure to stop use after being notified to do so.

26.3

The Client shall indemnify Reflecta against claims, demands, losses, liabilities, damages, costs and expenses arising out of or relating to:

  • Client Content;
  • Client instructions;
  • Client’s or Authorised Users’ use of the Services or Outputs;
  • infringement or alleged infringement of third-party intellectual property, privacy, publicity, personality, data protection, confidentiality or other rights;
  • use of images of persons without required consent;
  • use of High-Risk Likenesses;
  • advertising, marketing, publication, distribution or commercial exploitation of Outputs;
  • breach of the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy;
  • breach of Data Protection Laws caused by the Client or Authorised Users;
  • fraud, misuse, sanctions breach, unlawful activity or wilful misconduct by the Client or Authorised Users.

27. Indemnity Procedure

27.1

The indemnified Party shall promptly notify the indemnifying Party of any claim.

27.2

Failure to provide prompt notice shall reduce the indemnifying Party’s liability only to the extent the delay materially prejudiced the defence or settlement of the claim.

27.3

The indemnifying Party shall have control of the defence and settlement of the claim, provided that no settlement may impose liability, admission, payment obligation, operational restriction or reputational commitment on the indemnified Party without that Party’s prior written consent.

27.4

The indemnified Party shall provide reasonable assistance at the indemnifying Party’s expense.

27.5

If the Services become, or in Reflecta’s reasonable opinion are likely to become, subject to an infringement claim, Reflecta may:

  • procure the right for continued use;
  • modify the Services to avoid infringement;
  • replace the relevant functionality;
  • suspend the affected functionality;
  • terminate the affected Services and refund prepaid unused Fees for the terminated portion.

28. Limitation of Liability

28.1

Nothing in this Agreement excludes or limits liability for:

  • death or personal injury caused by negligence;
  • fraud or fraudulent misrepresentation;
  • wilful misconduct where liability cannot be excluded;
  • payment obligations;
  • liability that cannot lawfully be excluded or limited.

28.2

Subject to Clause 28.1, neither Party shall be liable for:

  • loss of profits;
  • loss of revenue;
  • loss of goodwill;
  • loss of anticipated savings;
  • loss of business opportunity;
  • business interruption;
  • indirect, special, incidental, exemplary, punitive or consequential losses;
  • replacement costs;
  • loss of data except to the extent caused by breach of express obligations under this Agreement.

28.3

Subject to Clauses 28.1 and 28.4, each Party’s total aggregate liability arising out of or in connection with this Agreement shall not exceed the Fees paid or payable by the Client under the applicable Order Form in the twelve months preceding the event giving rise to liability.

28.4

The liability cap in Clause 28.3 shall not apply to:

  • the Client’s payment obligations;
  • the Client’s indemnity obligations under Clause 26.3;
  • breach of confidentiality obligations;
  • misuse of Intellectual Property Rights;
  • deliberate unauthorised use of the Services;
  • sanctions or export-control breach;
  • fraud or wilful misconduct.

28.5

Where liability under Clause 28.4 may lawfully be capped, each Party’s total aggregate liability for such claims shall not exceed three times the Fees paid or payable under the applicable Order Form in the twelve months preceding the event giving rise to liability, except for payment obligations, fraud, wilful misconduct and liability that cannot lawfully be limited.

29. Term and Renewal

29.1

This Agreement starts on the Effective Date and continues for the Initial Term specified in the applicable Order Form.

29.2

Unless otherwise stated in the Order Form, this Agreement renews for successive twelve-month periods unless either Party gives written notice of non-renewal at least 60 days before the end of the then-current term.

29.3

Renewal Fees shall be as stated in the Order Form or, if not stated, as notified by Reflecta before renewal.

30. Termination

30.1

Either Party may terminate this Agreement or an affected Order Form by written notice if the other Party commits a material breach and fails to remedy it within 30 days after receiving written notice requiring remedy.

30.2

Reflecta may terminate or suspend this Agreement, an Order Form, the Services, a Workspace or any Account immediately if:

  • the Client fails to pay undisputed Fees when due;
  • the Client or any Authorised User breaches acceptable use, minor safety, sanctions, security, confidentiality or IP restrictions;
  • continued provision of the Services would create legal, security, sanctions, payment, provider, App Marketplace or regulatory risk;
  • the Client becomes insolvent, enters liquidation, administration or similar proceedings;
  • required by law, competent authority, App Marketplace, payment provider or service provider.

30.3

The Client may terminate this Agreement if Reflecta materially suspends the Services without legal, technical, payment, safety, security, provider or contractual justification and fails to restore access within a reasonable period after notice.

31. Effect of Termination

31.1

Upon termination or expiry:

  • the Client’s right to access and use the Services ends;
  • Authorised Users must stop using the Services;
  • unpaid Fees become immediately due;
  • Reflecta may disable the Client’s Workspace and Accounts;
  • the Client remains responsible for exported Outputs and prior use of the Services.

31.2

Unless otherwise stated in the Order Form, the Client may continue using Outputs validly generated and exported during the Term within the permitted licence scope, provided that:

  • all Fees have been paid;
  • the Client continues to comply with this Agreement;
  • the Output does not violate applicable law or third-party rights;
  • the Output was not generated in breach of this Agreement.

31.3

Reflecta may delete or de-identify Client Content after termination in accordance with the Privacy Notice, data processing addendum, backup cycles and legal retention obligations.

31.4

Clauses intended to survive termination shall survive, including clauses relating to fees, Client Content licences for retained records, Outputs, intellectual property, confidentiality, data protection, indemnities, limitation of liability, dispute resolution, governing law, legal compliance and accrued rights.

32. Audit and Compliance

32.1

Reflecta may, on reasonable written notice and during normal business hours, audit the Client’s use of the Services to verify compliance with this Agreement.

32.2

Any audit shall not occur more than once in any twelve-month period unless material breach, misuse, security incident, payment issue, rights complaint or legal risk is reasonably suspected.

32.3

The Client shall provide reasonable cooperation with any audit.

32.4

Reflecta shall conduct audits in a manner designed to minimise disruption to the Client’s business and protect the Client’s Confidential Information.

33. Export Controls, Sanctions and Restricted Availability

33.1

Reflecta may restrict, suspend, refuse or terminate access to the Services where required or reasonably appropriate under applicable sanctions laws, export controls, payment processor requirements, App Marketplace requirements, service-provider restrictions, legal requirements or internal risk controls.

33.2

The Client must not use the Services in or for the benefit of any restricted territory, sanctioned person, prohibited end use or jurisdiction where access is restricted by law, payment rules, App Marketplace rules, provider requirements or Reflecta’s risk controls.

33.3

Restricted territories may include, without limitation, Russia, Crimea, North Korea, Iran and any other territory where the Services are unavailable or restricted due to sanctions, export controls, payment processor rules, App Marketplace rules, service-provider restrictions or Reflecta’s internal risk controls.

33.4

The Client represents and warrants that neither it nor any Authorised User is prohibited from using the Services under applicable sanctions or export-control laws.

34. Force Majeure

34.1

Neither Party shall be liable for failure or delay in performing its obligations to the extent such failure or delay results from events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, labour disputes, government action, sanctions, export restrictions, internet outages, power failures, infrastructure failures, cloud-provider outages, AI provider outages, App Marketplace actions, payment-provider restrictions or other events beyond reasonable control.

34.2

The affected Party shall notify the other Party promptly and use reasonable efforts to mitigate the effects of the force majeure event.

34.3

Payment obligations already accrued are not excused by force majeure.

35. Assignment

35.1

The Client shall not assign, transfer, novate, subcontract or delegate this Agreement or any rights or obligations under it without Reflecta’s prior written consent.

35.2

Reflecta may assign, transfer or novate this Agreement to an Affiliate, successor, purchaser, investor or acquirer in connection with a merger, acquisition, restructuring, financing, sale of assets or similar transaction, provided that such transfer does not materially reduce the Client’s rights under this Agreement.

36. Subcontracting

36.1

Reflecta may subcontract performance of its obligations to Affiliates, service providers, AI Infrastructure Providers, cloud providers, support providers, payment providers, professional advisers and other subcontractors.

36.2

Reflecta remains responsible for subcontracted performance to the extent required by this Agreement.

36.3

Subprocessing of Client Personal Data is governed by the applicable data processing addendum.

37. Notices

37.1

Any notice under this Agreement shall be in writing and delivered by hand, courier or email to the addresses specified in the Order Form or otherwise notified in writing.

37.2

Notices to Reflecta shall be sent to:

Company
REFLECTA LABS SOFTWARE TRADING L.L.C
Address
Office 02-102, Dubai World Trade Centre Company,
Trade Centre Second,
Dubai, United Arab Emirates

37.3

Notices shall be deemed received:

  • if delivered by hand, when delivered;
  • if sent by courier, on confirmed delivery;
  • if sent by email, when sent, provided no bounce-back or delivery failure is received.

37.4

Formal notices relating to breach, termination, disputes or legal claims should also be copied to the Parties’ legal contacts stated in the Order Form.

38. Entire Agreement

38.1

This Agreement, the applicable Order Form and incorporated documents constitute the entire agreement between the Parties regarding the Services and supersede all prior agreements, proposals, communications, representations and understandings relating to the Services.

38.2

Each Party acknowledges that it has not relied on any representation not expressly set out in this Agreement or the applicable Order Form.

39. Variation

No variation of this Agreement is effective unless in writing and signed by authorised representatives of both Parties.

40. Waiver

No failure or delay by either Party in exercising any right or remedy under this Agreement constitutes a waiver of that right or remedy.

41. Severance

If any provision of this Agreement is invalid, illegal or unenforceable, it shall be modified to the minimum extent necessary to make it valid, legal and enforceable. If modification is not possible, the provision shall be deemed deleted, and the remaining provisions shall remain in full force.

42. Third-Party Rights

A person who is not a Party has no right to enforce this Agreement under the Contracts (Rights of Third Parties) Act 1999 or otherwise, except that Reflecta Affiliates, licensors, service providers and indemnified persons may enforce provisions intended for their benefit.

43. Governing Law and Arbitration

43.1

This Agreement and any dispute arising out of or relating to it, including non-contractual disputes or claims, shall be governed by the laws of England and Wales.

43.2

Any dispute arising out of or relating to this Agreement shall be finally resolved by arbitration under the Rules of Arbitration of the Dubai International Arbitration Centre (DIAC) in force at the time of commencement of arbitration.

43.3

The seat of arbitration shall be the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates.

43.4

The tribunal shall consist of one arbitrator unless the DIAC Rules require otherwise.

43.5

The language of arbitration shall be English.

43.6

The arbitral award shall be final and binding, and judgment on the award may be entered in any court of competent jurisdiction.

43.7

Nothing prevents either Party from seeking interim, injunctive or protective relief before any competent court where such relief is available.

Signature Page

For and on behalf of REFLECTA LABS SOFTWARE TRADING L.L.C

Signature
___________________________
Name
______________________________
Title
_______________________________
Date
_______________________________

For and on behalf of [CLIENT LEGAL NAME]

Signature
___________________________
Name
______________________________
Title
_______________________________
Date
_______________________________

Schedule 1 – Order Form

This Order Form is entered into pursuant to the Reflecta B2B Licence Agreement dated [●] between Reflecta and the Client.

1. Parties

ItemDetails
Service ProviderREFLECTA LABS SOFTWARE TRADING L.L.C
Service Provider addressOffice 02-102, Dubai World Trade Centre Company, Trade Centre Second, Dubai, United Arab Emirates
Client[●]
Client address[●]
Effective Date[●]

2. Commercial Summary

ItemDetails
Initial Term[12 months from Effective Date / other]
Renewal[automatic 12-month renewal unless 60 days’ written notice / other]
Subscription tier[Professional / Enterprise / Custom]
Authorised Users[●] users
Workspace name[●]
Territory of use[Worldwide / EU / GCC / specified countries]
Permitted channels[Digital / social / print / OOH / exhibition / e-commerce / other]
High-resolution export[included / not included]
High-Risk Likeness use[enabled / disabled / subject to approval]
Support tier[Standard / Priority / Dedicated]

3. Fees

3.1 Subscription Fees

Annual Subscription Fee: [currency / amount]

Payment frequency: [annually in advance / quarterly in advance / monthly / other]

3.2 Credits

Included Credits per month: [●]

Additional Credits: [currency / amount] per [●] Credits

Unused Credits:

  • ☐ expire monthly
  • ☐ roll over for [●] months
  • ☐ do not expire during active Subscription
  • ☐ other: [●]

3.3 Additional Services

ServiceFee
Dedicated onboarding[●]
Custom Workspace configuration[●]
Priority support[●]
Custom integration[●]
Other[●]

All Fees are exclusive of VAT, sales tax and applicable taxes unless expressly stated otherwise.

4. Output Licence Scope

4.1 Permitted Media Channels

  • ☐ Websites
  • ☐ Social media platforms
  • ☐ E-commerce platforms
  • ☐ Digital advertising networks
  • ☐ Print advertising
  • ☐ Exhibitions and trade fairs
  • ☐ Out-of-home campaigns
  • ☐ Internal business use
  • ☐ Product visualisation / prototyping
  • ☐ Other: [●]

4.2 Territory

  • ☐ Worldwide
  • ☐ European Union
  • ☐ GCC
  • ☐ Specified countries: [●]

4.3 Duration

  • ☐ Perpetual licence for Outputs validly generated during the Term
  • ☐ Campaign-limited licence: [campaign name]
  • ☐ Term-limited licence: [●] years
  • ☐ Other: [●]

5. High-Risk Likenesses

The following High-Risk Likenesses are authorised under this Order Form, if any:

High-Risk LikenessClearance confirmedNotes
[●][yes / no][●]

Outputs incorporating High-Risk Likenesses may not be exported or commercially deployed unless the required clearance has been confirmed in writing.

6. Exclusivity

If applicable, the following exclusivity rights apply:

ScopeDetails
Exclusivity subject[persona / asset / style / category / other]
Territory[●]
Duration[●]
Fee[●]
Limitations[●]

Exclusivity is strictly limited to the parameters stated above and does not extend beyond them.

7. AI Training / Improvement Opt-In

Default position: Reflecta does not use Client Content, Client Assets, prompts, generated Outputs or Client Personal Data to train Reflecta’s general AI models or create separate AI products made available to other users unless the Client expressly opts in.

Select one:

  • ☐ Client does not opt in to AI training or general model-improvement use.
  • ☐ Client expressly opts in to the use of the following Client Content for AI training or improvement purposes, subject to Clause 14 of the Agreement: [describe scope precisely]

Excluded materials: [●]

Withdrawal process / notice period: [●]

8. Data Processing

Does the Client intend to upload images or other Client Content containing Personal Data?

  • ☐ Yes
  • ☐ No

If yes, Schedule 2 applies.

Additional data processing terms: [●]

9. Support

Support tier:

  • ☐ Standard business-hours email support
  • ☐ Priority support
  • ☐ Dedicated account manager
  • ☐ Custom SLA attached

Response time commitment: [●] Business Hours

Support contact: support@tryreflecta.app

10. Payment Terms

Invoices payable within: [30] days from invoice date.

Late payment interest: [●].

Billing contact: [●].

Purchase order required: [yes / no].

11. Special Terms

[Insert any special terms.]

12. Acceptance

Signed for and on behalf of REFLECTA LABS SOFTWARE TRADING L.L.C

Signature
___________________________
Name
______________________________
Title
_______________________________
Date
_______________________________

Signed for and on behalf of [CLIENT LEGAL NAME]

Signature
___________________________
Name
______________________________
Title
_______________________________
Date
_______________________________

Schedule 2 – Data Processing Addendum

This Schedule 2 applies where Reflecta processes Client Personal Data on behalf of the Client in connection with the Services.

1. Roles of the Parties

1.1

For Account data, billing data, support communications, security data, abuse records, legal records and Reflecta’s own operational records, Reflecta may act as an independent controller or business, depending on applicable Data Protection Laws.

1.2

For Client Personal Data contained in Client Content and processed by Reflecta solely on behalf of the Client to provide the Services, the Client acts as controller and Reflecta acts as processor, unless applicable law requires a different classification.

1.3

The Client is responsible for determining the purposes and means of processing Client Personal Data and for ensuring that Client Personal Data may lawfully be uploaded to and processed through the Services.

2. Subject Matter and Duration

2.1

Subject matter: Reflecta’s processing of Client Personal Data to provide the Services under the Agreement.

2.2

Duration: the Term of the Agreement and any period during which Reflecta retains Client Personal Data in accordance with the Agreement, the Privacy Notice, legal obligations, backup cycles or agreed deletion processes.

3. Nature and Purpose of Processing

Processing may include:

  • hosting;
  • storage;
  • transmission;
  • retrieval;
  • organisation;
  • display;
  • deletion;
  • AI generation;
  • safety filtering;
  • support;
  • debugging;
  • security monitoring;
  • abuse prevention;
  • legal compliance.

4. Categories of Data Subjects

Client Personal Data may relate to:

  • Authorised Users;
  • Client employees;
  • contractors;
  • models;
  • influencers;
  • customers;
  • brand ambassadors;
  • persons depicted in Client Assets;
  • persons communicating with support or involved in complaints.

The Client must not upload images of minors.

5. Categories of Personal Data

Client Personal Data may include:

  • names;
  • business contact details;
  • Account identifiers;
  • Workspace identifiers;
  • uploaded images;
  • Person / Model Assets;
  • likeness, image and visual characteristics;
  • prompts and metadata;
  • generated Outputs;
  • support communications;
  • technical logs;
  • usage data;
  • complaint and takedown data.

6. Sensitive Data

6.1

Images may reveal sensitive information, such as racial or ethnic origin, religious dress, health indicators or other sensitive characteristics.

6.2

The Client shall not upload sensitive Personal Data unless:

  • it is lawful to do so;
  • it is necessary for the intended use;
  • the Client has obtained all required consents and provided all required notices;
  • the upload complies with the Agreement and applicable law.

6.3

The Client must not upload images of minors.

7. Client Instructions

7.1

Reflecta shall process Client Personal Data only on documented instructions from the Client, including this Agreement, the Order Form, the Client’s use of the Services, Authorised User actions and any written instructions accepted by Reflecta.

7.2

Reflecta may refuse or suspend an instruction where it reasonably believes the instruction violates applicable law, the Agreement, safety requirements, sanctions requirements, provider rules or the Reflecta Acceptable Use, Content Safety and Notice-and-Takedown Policy.

8. Confidentiality

Reflecta shall ensure that persons authorised to process Client Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

9. Security Measures

Reflecta shall implement reasonable technical and organisational measures designed to protect Client Personal Data, including measures described in Clause 21 of the Agreement and any additional security schedule agreed by the Parties.

10. Subprocessors

10.1

The Client authorises Reflecta to use subprocessors to provide the Services.

10.2

Current subprocessors may include database hosting providers, file storage providers, cloud infrastructure providers, AI Infrastructure Providers, crash-reporting providers, payment processors, App Marketplaces, support providers and professional advisers.

10.3

Reflecta shall impose data protection obligations on subprocessors that are appropriate to the nature of the services provided.

10.4

Reflecta may change subprocessors where reasonably necessary. Where required by applicable law or agreed process, Reflecta shall provide notice of material subprocessor changes.

11. International Transfers

11.1

Client Personal Data may be transferred to and processed in countries outside the Client’s country of establishment, including the United Arab Emirates, United Kingdom, European Economic Area, United States and other locations used by Reflecta and its service providers.

11.2

Where required by applicable Data Protection Laws, Reflecta shall use appropriate transfer mechanisms, which may include adequacy decisions, standard contractual clauses, the UK International Data Transfer Agreement or UK Addendum, data processing agreements, transfer risk assessments and technical and organisational safeguards.

12. Assistance with Data Subject Requests

12.1

Reflecta shall provide reasonable assistance to the Client, taking into account the nature of processing and information available to Reflecta, to respond to data subject requests relating to Client Personal Data.

12.2

Reflecta may direct data subjects to the Client where the Client is responsible for responding to the request.

12.3

Reflecta may charge reasonable fees for assistance that is excessive, complex or outside ordinary support.

13. Personal Data Breach

13.1

Reflecta shall notify the Client without undue delay after becoming aware of a Personal Data breach affecting Client Personal Data processed by Reflecta as processor.

13.2

The notification shall include information reasonably available to Reflecta, taking into account the nature of the breach and the information available at the time.

13.3

Reflecta’s notification of a breach does not constitute an admission of fault or liability.

14. Deletion and Return

14.1

Upon termination or expiry of the Agreement, Reflecta shall delete or de-identify Client Personal Data in accordance with the Agreement, Privacy Notice, backup cycles, legal obligations and agreed deletion processes.

14.2

Reflecta may retain Client Personal Data where required or permitted for legal compliance, tax, accounting, fraud prevention, security, abuse prevention, dispute resolution, legal claims, backup cycles or other lawful purposes.

14.3

Backup copies may be deleted or overwritten in accordance with normal backup cycles.

15. Audits

15.1

Reflecta shall make available information reasonably necessary to demonstrate compliance with this Schedule, subject to confidentiality, security, legal and commercial restrictions.

15.2

Any audit must be reasonable, proportionate, limited to relevant processing, conducted during normal business hours and subject to Reflecta’s security requirements.

15.3

The Client shall not access systems, data or information relating to other customers or users.

16. Liability

Liability under this Schedule is subject to the limitations and exclusions in the Agreement, unless applicable Data Protection Laws require otherwise.

Schedule 3 – Security Measures

Reflecta may implement the following security measures, as applicable to the Services:

  • encryption in transit;
  • encryption at rest where supported by infrastructure providers;
  • password hashing;
  • HTTP-only session cookies;
  • access controls;
  • role-based internal access;
  • API access checks;
  • Workspace-level access restrictions;
  • secure cloud infrastructure;
  • limited administrative access;
  • vendor due diligence;
  • crash and error monitoring;
  • abuse and Account enforcement procedures;
  • technical logging for security and reliability;
  • backup and disaster recovery processes;
  • incident response procedures;
  • internal confidentiality obligations;
  • subprocessor controls;
  • deletion and de-identification processes where applicable;
  • periodic review of security practices.