1. Agreement to terms
These Terms of Service ("Terms", "Agreement") are a legally binding agreement between SopiSafe Oy ("SopiSafe", "we", "us", "our"), a company incorporated in Finland, and the organization or entity ("Customer", "you", "your") subscribing to or using the SopiSafe platform.
By accessing or using the Service, creating an account, or taking a similar affirmative action, you represent that:
- You have the legal authority to bind the Customer to these Terms;
- You have read, understood, and agree to be bound by these Terms;
- The Customer is a duly organized legal entity โ not a consumer individual.
If you do not agree to these Terms, you must not access or use the Service.
These Terms incorporate by reference:
- The Privacy Notice
- The Data Processing Agreement (available on request from legal@sopisafe.com)
- The Acceptable Use Policy (available on request from legal@sopisafe.com)
- The cookies terms in section 10 of the Privacy Notice
- Any applicable Order Form or subscription confirmation
2. Definitions
- "Authorized User" โ an individual authorized by the Customer to access and use the Service under the Customer's account.
- "Customer Content" โ all data, documents, contracts, invoices, and other materials uploaded, submitted, or entered into the Service by or on behalf of the Customer.
- "Documentation" โ the user guides, API documentation, and other technical materials made available by SopiSafe.
- "Effective Date" โ the date the Customer first accesses the Service or the date of the applicable Order Form, whichever is earlier.
- "Order Form" โ an ordering document specifying the plan, billing terms, and any additional terms agreed between the parties.
- "Service" โ the SopiSafe cloud-based contract-to-invoice control platform for detecting supplier billing drift and preparing recovery claims, including all associated APIs, interfaces, and Documentation.
- "Subscription Term" โ the period during which the Customer has an active subscription, as specified in the applicable Order Form.
3. The Service
3.1 Description
SopiSafe provides a cloud-based platform for:
- Detecting discrepancies (โdriftโ) between supplier contracts and invoices
- Managing supplier relationships and compliance tracking
- Preparing recovery claim drafts and workflows โ decisions and supplier contact remain with the Customer
- Generating analytics, reports, and supplier scorecards
- Integrating with third-party accounting and ERP systems
3.2 Availability
We use commercially reasonable efforts to make the Service available with an uptime of no less than 99.5% per calendar month, measured at the API gateway, excluding: scheduled maintenance (notified at least 48 hours in advance), force majeure events (section 16), failures caused by the Customer's systems or third-party services outside our control, and features designated as beta or preview.
3.3 Modifications
We may modify, update, or discontinue features of the Service. We will give at least 30 days' prior written notice of material changes that adversely affect the Customer's use. If a material change makes the Service materially less useful for the Customer's intended purpose, the Customer may terminate under section 12.3.
4. Accounts and security
4.1 Account creation
To use the Service, the Customer creates an organization account and designates at least one administrator. The Customer is responsible for keeping registration information accurate and current.
4.2 Account security
The Customer is responsible for:
- Maintaining the confidentiality of all login credentials, API keys, and access tokens
- Ensuring Authorized Users comply with these Terms
- All activity under the Customer's account
- Promptly notifying SopiSafe of any unauthorized use or security breach at security@sopisafe.com
4.3 Multi-tenancy
The Service operates on a multi-tenant architecture with strict data isolation: each Customer's data is logically separated and inaccessible to other customers.
5. Plans and payment
5.1 Offers
The Service is offered as:
- Leakage Audit โ a one-time, fixed-scope audit at a fixed fee tiered by active supplier count, as published on our website or specified in the Order Form. The audit fee is non-refundable, but is credited in full toward the first year of Continuous Control if the Customer subscribes within 6 months of the audit readout.
- Pilot โ 90 days of the full platform with no subscription fee; SopiSafe is compensated only through a success fee on recovered leakage, as specified in the Order Form. After the pilot, the engagement continues as Continuous Control unless the Customer ends it.
- Continuous Control โ an annual subscription that scales with spend under management, as specified in the Order Form.
Plan features, pricing, and limits are as published on our website or as specified in the applicable Order Form.
5.2 Billing
- Subscription fees are billed monthly or annually in advance, as specified in the Order Form
- All fees are stated in EUR and are exclusive of VAT and other applicable taxes, which are added where required by law
- Payments are processed via Wise Business (TransferWise Ltd) by bank transfer or other methods SopiSafe makes available
- Usage exceeding plan limits may incur overage charges per the Order Form, or the Service may restrict additional usage until the next billing period
5.3 Payment terms
- Invoices are payable within fourteen (14) days of the invoice date
- Late payments accrue interest at the rate prescribed by the Finnish Interest Act (korkolaki 633/1982)
- SopiSafe may suspend the Service after fourteen (14) days of non-payment, following written notice
5.4 Price changes
We may adjust pricing with 60 days' prior written notice before a new Subscription Term begins. If the Customer does not accept the new pricing, it may terminate effective at the end of the then-current Subscription Term.
5.5 Taxes
The Customer is responsible for all taxes, levies, and duties in connection with the Service, excluding taxes based on SopiSafe's net income.
6. Customer rights and obligations
6.1 License
Subject to these Terms, SopiSafe grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service during the Subscription Term, solely for the Customer's internal business purposes and in accordance with the Documentation.
6.2 Customer Content
The Customer retains all intellectual property rights in Customer Content. The Customer grants SopiSafe a limited, non-exclusive license to use, process, copy, store, and display Customer Content solely as necessary to provide the Service and as described in the Privacy Notice and Data Processing Agreement.
6.3 Responsibilities
- Use the Service in compliance with these Terms, the Acceptable Use Policy, and applicable law
- Ensure Customer Content is lawfully obtained and the Customer has the right to upload it
- Not process special categories of personal data (Art. 9 GDPR) through the Service unless explicitly agreed in writing
- Maintain adequate backups of Customer Content outside the Service
- Promptly inform SopiSafe of any discovered security incidents or vulnerabilities
7. Restrictions
The Customer shall not, and shall not permit any third party to:
- Reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code or underlying structure of the Service
- Modify, translate, or create derivative works based on the Service
- License, sell, resell, transfer, assign, or distribute the Service or any rights in it
- Access the Service to build a competing product or service
- Use the Service to store or process data in violation of applicable law, including data protection law
- Remove, alter, or obscure any proprietary notices or marks
- Attempt to gain unauthorized access to the Service, other accounts, or related systems
- Use the Service in a way that could damage, disable, overburden, or impair it, or interfere with other customers' use
- Upload malicious code or harmful components
- Process personal data of EU data subjects without an appropriate legal basis under the GDPR
8. Intellectual property
8.1 SopiSafe IP
SopiSafe and its licensors own all rights, title, and interest in the Service โ software, algorithms, interfaces, documentation, trademarks, and any modifications or derivative works. Nothing in these Terms transfers ownership of any SopiSafe intellectual property to the Customer.
8.2 Feedback
If the Customer provides suggestions or other feedback, SopiSafe may freely use and incorporate it without obligation or compensation.
8.3 Aggregated data
SopiSafe may generate and use aggregated, anonymized, de-identified data derived from use of the Service to improve the Service, conduct research, and produce benchmarking โ provided such data does not identify the Customer or any individual.
9. Confidentiality
"Confidential Information" is any non-public information disclosed by either party that is designated confidential or reasonably should be understood as confidential. Customer Content is the Customer's Confidential Information; the Service's non-public features, pricing, and architecture are SopiSafe's.
Each recipient shall:
- Use the discloser's Confidential Information solely for the purposes of this Agreement
- Protect it with at least the same care it uses for its own confidential information โ and no less than reasonable care
- Disclose it only to employees, contractors, or advisors who need to know and are bound by confidentiality obligations at least as protective
Confidential Information excludes information that is or becomes public without breach, was already known, is independently developed, or is lawfully received from a third party. Disclosure compelled by law is permitted with prompt notice to the discloser where allowed. Confidentiality obligations survive termination for three (3) years; trade secrets remain protected for as long as they remain trade secrets.
10. Warranties and disclaimers
10.1 SopiSafe warrants that
- It has the right and authority to enter into this Agreement
- The Service will perform materially in accordance with the Documentation during the Subscription Term
- It will provide the Service in a professional and workmanlike manner, consistent with industry standards
- It will comply with applicable law in providing the Service, including the GDPR
10.2 The Customer warrants that
- It has the right and authority to enter into this Agreement
- It has all necessary rights to provide Customer Content to SopiSafe
- Customer Content does not infringe any third party's intellectual property rights
- It will use the Service in compliance with applicable law
10.3 Disclaimer
Except for the express warranties above, the Service is provided "as is" and "as available". SopiSafe disclaims all other warranties โ express, implied, statutory, or otherwise โ including implied warranties of merchantability, fitness for a particular purpose, and non-infringement; warranties arising from course of dealing or trade practice; any warranty that the Service will be uninterrupted, error-free, or completely secure; and any warranty regarding the accuracy or completeness of results obtained through the Service, including drift findings, recovery amounts, and supplier risk scores.
Not advice. Drift detection, analysis, and recovery recommendations are informational tools and do not constitute legal, financial, or accounting advice. The Customer assumes full responsibility for decisions made based on Service outputs.
11. Limitation of liability
11.1 No indirect damages
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages; loss of profits, revenue, data, business opportunity, or goodwill; cost of substitute services; or business interruption โ regardless of the theory of liability, even if advised of the possibility.
11.2 Cap
Subject to 11.3, each party's total aggregate liability under this Agreement shall not exceed the greater of: (a) the total fees paid or payable by the Customer during the twelve (12) months preceding the event giving rise to the claim, or (b) ten thousand euros (โฌ10,000).
11.3 Exceptions
The limitations in 11.1 and 11.2 do not apply to:
- Liability arising from intentional misconduct (tahallisuus) or gross negligence (tรถrkeรค tuottamus)
- Indemnification obligations under section 13
- The Customer's payment obligations under section 5
- Breach of confidentiality obligations under section 9
- Breach of data protection obligations under the GDPR or the Data Processing Agreement
- Infringement of the other party's intellectual property rights
The parties acknowledge these limitations reflect a fair allocation of risk and form an essential basis of the bargain.
12. Term and termination
12.1 Term
The Agreement starts on the Effective Date and runs for the initial Subscription Term, then automatically renews for successive periods of equal length unless either party gives written notice of non-renewal at least 30 days before the end of the current term.
12.2 Termination for cause
Either party may terminate immediately on written notice if the other party materially breaches and fails to cure within 30 days of written notice, or becomes insolvent, files for bankruptcy, or ceases to operate in the ordinary course.
12.3 Termination for convenience
The Customer may terminate before the end of the Subscription Term on 30 days' written notice, remaining liable for fees due for the remainder of the current term unless otherwise agreed in writing.
12.4 Effect of termination
- Access ends immediately, or at the end of any applicable notice period
- Data export: Customer Content is available for export in a structured, machine-readable format (JSON/CSV) for 30 days after termination
- Data deletion: after the 30-day export window, all Customer Content is deleted within 60 days, except as required by law or for legal claims
- Certification: on written request, SopiSafe confirms deletion in writing
- Survival: sections 8 (IP), 9 (Confidentiality), 10.3 (Disclaimer), 11 (Liability), 13 (Indemnification), 14 (Governing law), and this section survive termination
13. Indemnification
13.1 By SopiSafe
SopiSafe will defend and indemnify the Customer against third-party claims that the Customer's authorized use of the Service infringes a third party's intellectual property rights โ provided the Customer promptly notifies SopiSafe, gives SopiSafe sole control of the defense (with no settlement imposing obligations on the Customer without its consent), and reasonably cooperates at SopiSafe's expense.
If the Service becomes the subject of such a claim, SopiSafe may procure the right to continue use, replace or modify the Service to be non-infringing, or โ if neither is commercially reasonable โ terminate the Agreement and refund prepaid fees for the unused portion of the Subscription Term. This does not apply to claims arising from modifications not made by SopiSafe, combinations with non-SopiSafe products, Customer Content, or use in violation of these Terms.
13.2 By the Customer
The Customer will defend and indemnify SopiSafe against third-party claims arising from Customer Content or use of the Service in violation of these Terms or applicable law, breach of the Customer's warranties in section 10.2, or the Customer's violation of data protection law in connection with Customer Content.
14. Governing law and disputes
This Agreement is governed by the laws of Finland, excluding its conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods (CISG).
Disputes are finally settled by arbitration under the Arbitration Rules of the Finland Chamber of Commerce, in Helsinki, Finland, in English, by a sole arbitrator appointed under those rules. Either party may nonetheless seek injunctive or other equitable relief in any competent court to protect intellectual property, confidentiality, or data protection obligations. To the extent permitted by law, the Customer waives participation in class actions or class-wide arbitration.
15. Data protection
Processing of personal data in connection with the Service is governed by the Privacy Notice. Where the Customer acts as data controller and SopiSafe as data processor for Customer Content containing personal data, the parties enter into the Data Processing Agreement (request it from legal@sopisafe.com), which is incorporated into these Terms by reference.
16. Force majeure
Neither party is liable for failure or delay (other than payment obligations) caused by circumstances beyond its reasonable control โ including acts of God, fire, flood, earthquake, pandemic, war, terrorism, strikes, government orders, sanctions, power outages, internet failures, or failures of third-party cloud infrastructure. The affected party must promptly notify the other and mitigate. If a force majeure event continues for more than 60 days, either party may terminate on written notice.
17. General provisions
- Entire agreement. These Terms, together with the Order Form, Privacy Notice, DPA, and AUP, are the entire agreement and supersede all prior negotiations and agreements on the subject.
- Amendments. Amendments require writing signed by both parties โ except SopiSafe may update these Terms on 30 days' prior notice, and continued use after notice constitutes acceptance.
- Assignment. Neither party may assign without the other's written consent, except SopiSafe may assign to an affiliate or in connection with a merger, acquisition, or sale of substantially all assets.
- Severability. If any provision is invalid, the rest remains in force; the invalid provision is modified minimally to be enforceable while preserving intent.
- Waiver. Waivers must be in writing; failure to enforce a provision is not a waiver.
- Notices. Notices must be in writing, by email with confirmed receipt or registered mail. Notices to SopiSafe: legal@sopisafe.com.
- Independent contractors. Nothing here creates a partnership, joint venture, employment, or agency relationship.
- No third-party beneficiaries. The Agreement confers rights only on the parties and their permitted successors.
- Export compliance. The Customer must comply with applicable export control laws.
18. Contact
SopiSafe Oy ยท legal@sopisafe.com
By accessing or using the SopiSafe Service, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service.