Terms for merchants using the Service (B2B)
The purpose of these general terms and conditions (the “Terms”) is to govern the mutual rights and obligations between MAMA media s.r.o., with its registered office at Na Hrebienku 1, 811 02 Bratislava, Slovak Republic, Company ID: 36 767 549, registered in the Commercial Register of the Bratislava III Municipal Court, Section: Sro, Insert No. 45585/B (the “Provider” or also the “Company”), and the Customer in connection with the use of the VEXiON cards Services, to govern the process of ordering them, the conditions of their use and other matters relevant to the use of the Services. Annex 1 (Data Processing Addendum), Annex 2 (Categories of Sub-processors), Annex 3 (Security Measures and Safeguards) and the separate Complaints Procedure attached after these Terms form an integral part of these Terms.
These Terms apply exclusively to relationships in which the Customer enters into the Agreement within the scope of its business activity, employment or profession (a B2B relationship). If the Service is ordered by a natural person acting outside that scope (a Consumer within the meaning of Section 52(4) of Act No. 40/1964 Coll., the Civil Code, as amended, in conjunction with Act No. 108/2024 Coll. on consumer protection and on amendments to certain acts), these Terms do not apply to that person; such a relationship is governed by the separate VEXiON cards Consumer Terms, by the loyalty club rules of the individual Customer and by mandatory consumer protection legislation, which prevails. The status of a Consumer cannot be excluded by a unilateral declaration in the Order or by any other arrangement in these Terms.
By paying the price or by taking over the Account set up by the Provider, the Customer expresses its consent to the wording of these Terms valid and effective at that time, confirms that it has acquainted itself with the personal data protection information published on the Website, and agrees to the conditions for the processing of personal data under Article 15 of these Terms and Annex 1.
The sale of VEXiON gift vouchers and relationships with their buyers and recipients are not governed by these Terms but by the VEXiON Gift Voucher Sales Terms published on the Website, which take account of the buyer’s status as a Consumer, including the buyer’s statutory right to withdraw from the contract under Act No. 108/2024 Coll. These Terms govern exclusively the relationship between the Provider and the Customer (the merchant) concerning the provision of the Service, not the sale of vouchers to end consumers. The conditions under which the Customer sells gift vouchers through the Service, including the Provider’s commission, are governed by clause 1.6.
Legal relationships not governed by these Terms are governed by the applicable legislation of the Slovak Republic and the European Union, in particular by Act No. 513/1991 Coll., the Commercial Code, subsidiarily by Act No. 40/1964 Coll., the Civil Code, as well as by personal data protection legislation, in particular Regulation (EU) 2016/679 (GDPR) and Act No. 18/2018 Coll.
Where the Customer offers and sells gift vouchers through the Service, the seller towards the buyer is the Customer. The Provider provides the technical environment and arranges payment through the Stripe payment gateway and is not a party to the purchase contract between the Customer and the buyer; the buyer pays the price directly to the Customer’s account and the Provider deducts from the payment a platform commission in the amount set out in the Price List or agreed individually. The Customer is responsible for handling withdrawals from the contract, for complaints and for fulfilling information duties towards the buyer as a consumer under the VEXiON Gift Voucher Sales Terms published at https://www.vexioncards.one/gift-card-terms, whereby the buyer, when placing the order, expressly requests that provision begin before the withdrawal period expires and confirms that the right of withdrawal lapses upon delivery of the voucher, and the Provider records this act, for correctly determining the VAT regime of the voucher according to its nature, and for obligations arising from the unredeemed value of the voucher. The validity period of the voucher is determined by the Customer in the settings of the Service; if the Customer does not determine it, a period of 12 months from issue applies. The Customer shall indemnify the Provider against claims by buyers or recipients arising from a breach of this clause.
Contractor: an independent contractor or consultant of the Customer who is not a direct competitor of the Provider.
Customer Data: any data that the Customer, or a third party on the Customer’s behalf, submits, uploads or imports into the Services, including End Customer data.
DPA: the Data Processing Addendum attached to these Terms as Annex 1.
Documentation: the technical user documentation provided with the Services.
Intellectual Property Rights: all valid patents, trade marks, copyright, trade secrets and other intellectual property rights, including their renewals, extensions and improvements.
Laws: all applicable legislation of the Slovak Republic and the European Union, including consumer protection and personal data protection legislation.
Order Form (Order): a written or electronic form for ordering the Services that refers to these Terms and that, once confirmed by both Parties, is subject to the terms of this Agreement.
Customer: a natural person acting within the scope of its business activity, employment or profession, or a legal person, or a person authorised to act on its behalf, which has entered into or is entering into the Agreement with the Provider.
Agreement: the contract concluded electronically between the Provider and the Customer, of which these Terms, their Annexes, the Complaints Procedure and all valid Order Forms form an integral part.
Contracting Party / Party: the Provider or the Customer; “Parties” means both of them.
Authorised User: an employee or Contractor of the Customer who is authorised to access the Services.
Renewal Period: consecutive periods equal in length to the Subscription Period, beginning after the then current Subscription Period.
Sensitive Personal Data: payment card data subject to PCI DSS or any special category personal data within the meaning of Article 9 GDPR.
Service/Services: the digital loyalty programme platform and its administration provided by the Provider as software as a service, enabling the Customer to create, manage and distribute digital loyalty cards to its End Customers, including related features, the optional Scanner and, where the Provider makes it available, the public API under Article 8.
Scanner: an optional physical device for scanning digital loyalty cards.
Subscription Period: the period specified in the Order Form during which the Services are provided to the Customer, including the then current Renewal Period.
Price List: the current overview of Subscription Plans and their prices published on the Website, which forms an integral part of the Agreement.
Support: standard technical support and maintenance of the Services.
Taxes: any sales taxes, VAT, withholding or similar taxes and levies, other than taxes on the Provider’s income.
Third Party Platform: any software or other product not provided by the Provider that is integrated with the Services at the instruction or selection of the Customer (for example a payment gateway, an e-commerce or POS system, a booking system, a third party developer acting on the basis of the Customer’s API key).
End Customer: a natural person who is a member of or a participant in a loyalty programme operated by the Customer through the Services; the End Customer is not a party to this Agreement.
Website: the website www.vexioncards.one
Feedback: the Customer’s suggestions and proposals for improving the Services
Account: the Customer’s user account in the Service, set up by the Provider or created on the basis of an Order, through which the Customer accesses the Services, manages its loyalty programme and configures its Subscription Plan.
The Agreement is formed in one of two ways: a) by an order and payment of the price by payment card via the Website, in which case the Agreement is formed upon payment of the price, b) by the Provider setting up an Account on the basis of an arrangement concluded outside the Website, in particular in the case of payment by bank transfer against an invoice, in the case of networks and in the case of partner programmes, in which case the Agreement is formed upon the Account being set up and taken over by the Customer.
The Customer enters its billing details during payment on a secure payment page or provides them to the Provider when the Account is set up. The Customer is responsible for their accuracy and completeness.
Immediately after the Agreement is formed, the Provider makes available to the Customer a link for taking over the Account; the Customer sets its own login credentials.
In the case of an Agreement under clause 3.1(a), the Agreement and the availability of the selected Service begin at the moment the payment for the Service is successfully received. In the case of an Account set up by the Provider, the Agreement is formed upon its being taken over, irrespective of the moment of payment.
The Provider is entitled to cancel an Order or part of it if:
The current types and content of the Subscription Plans for the Service, including their prices, are set out in the Price List published on the Website. The Price List forms an integral part of the Agreement in the wording valid as at the date of the Order.
Payments are processed through the Stripe payment gateway. The payment methods made available by that payment gateway are accepted. In the case of an Account set up under clause 3.1(b), the subscription may be paid by bank transfer against an invoice with a payment period of 14 days. In the case of a self-service order under clause 3.1(a), card payment is the only option.
In the case of card payment, the Customer acknowledges that these are automatically renewing payments (recurring payments) through the Stripe system, and agrees to the price of the selected Subscription Plan being charged automatically to its payment card, without the need for separate authorisation of each individual recurring payment.
Automatic recurring payments are made for an indefinite period until the next scheduled payment is cancelled. The Customer may cancel a scheduled payment, and thereby the Subscription Plan from the beginning of the following period, at any time before it is made, through the customer interface available after logging in on the Website.
The Provider does not store the number of the payment card used to pay for the Subscription. Online payments are made exclusively through secure third party payment interfaces.
The Customer is entitled to move from the ONE plan to the PRO plan directly in the Account. Moving from the PRO plan to the ONE plan is not possible. The Provider is not obliged to allow the purchase of a plan whose limits are exceeded by the current use of the Account. An alternative to moving to a lower plan is the free suspension of the subscription under this Article.
The price for the selected Subscription Plan is payable for the whole of the selected period, with no possibility of a pro rata refund for the period during which the Customer did not use the Service, save in the cases under clause 9.3.
The Provider reserves the right to change the prices of the Services. The Customer will be informed of a price change by e-mail at least 30 days before it takes effect. If the Customer does not agree with the price change, it has the right to cancel the Subscription before the change takes effect, following the procedure under clause 4.4.
The Provider is entitled to suspend the Customer’s access to the Services, without liability towards the Customer, if (i) payment is more than 14 days overdue, (ii) the Customer is in breach of clause 5.7 or clause 6.5, or (iii) this is necessary to protect the security or integrity of the Services or of other customers. The Provider will restore access without delay once the reason for suspension has been removed.
The Customer acknowledges that once the Account is locked its End Customers will cease to collect and redeem stamps and points. The Provider will notify the Customer of this in advance. Once the amount owed has been paid, the original state of the loyalty cards will be restored.
In addition to the price of the Subscription Plan, the Customer is obliged to pay a one-off Service set-up fee in the amount set out in the Price List. This fee is not charged for an annual PRO subscription. The one-off Service set-up fee and the one-off Scanner activation fee under clause 11.3 are non-refundable, whether in whole or pro rata, including where the Customer terminates the Agreement on the grounds of a material breach of the Agreement by the Provider, since the performance for which those fees are paid is delivered in full at the time it is provided.
Prices are stated and invoiced in euros. If the Customer is identified for value added tax in another Member State of the European Union and its identification number is verified in the VIES system, the reverse charge applies; value added tax is not charged to a Customer established outside the European Union.
The Provider does not offer a trial period. The Service is made available only after the Agreement is formed under Article 3.
The Customer is entitled to suspend the subscription free of charge at any time through the Account and to resume it in the same way. During suspension the subscription is not charged and the Account is retained; however, during that period its End Customers cannot collect or redeem stamps and points, just as when the Account is locked.
The Provider makes the Service available in virtual form by setting up an Account, through which the Customer has access to the features of the Service within the scope of the selected Subscription Plan and the Documentation.
The Account is made available to the Customer without delay after the Agreement is formed. The design and final configuration of the cards and the delivery of the Scanner then follow, as a rule within 3 to 7 working days; this is the usual time, not a binding deadline.
Only Authorised Users may access the Services. The Customer shall ensure that Authorised Users keep their access credentials confidential; the Customer is responsible for all acts performed under its account. If an Authorised User ceases to be an employee or Contractor of the Customer, the Customer shall revoke that person’s access without delay.
The Provider reserves the right, as part of the ongoing development of the Services, to add, change, discontinue or otherwise modify their elements and features. If a modification materially degrades the Services provided, the Provider will inform the Customer of this reasonably in advance.
If the Provider makes an API available, it may monitor its use and limit the number of calls if it believes that the use breaches this Agreement or endangers the security or integrity of the Services. The conditions of the public API are governed by Article 8.
To the extent that the Provider makes applications available for use with the Services, it grants the Customer a limited, non-transferable, non-exclusive licence to use them internally during the Subscription Period, solely in connection with the use of the Services.
If the Services are used contrary to these Terms or to other contractual documents, including any form of misuse of the Services or breach of the Customer’s contractual obligations, the Provider becomes entitled to interrupt the provision of the Services. For the period of such an interruption for reasons on the Customer’s side, the Customer is not entitled to any financial or other compensation for unused Services.
All Services are provided through remote access to the Provider’s server via the Website and the user Account, on the basis of an internet connection and the use of an internet browser.
The Scanner remains the property of the Provider throughout the term of the Agreement; it is provided to the Customer for use for the duration of the Subscription Period under the conditions set out in this Article and in clause 11.3. The Provider has no remote access to the Scanner. It is configured solely by scanning configuration barcodes supplied by the Provider.
The Customer is obliged to check that the Scanner consignment is physically intact and complete upon taking delivery of it.
If the consignment is damaged, the Customer is obliged to draw up a damage report with the carrier and to inform the Provider without delay.
Complaints concerning Scanner consignments and damage arising during transport will not be accepted without a damage report having been drawn up. This condition does not apply to other defects of the Scanner.
After the Agreement ends, the Customer is obliged to return the Scanner to the Provider within 14 days, at its own cost and in the manner determined by the Provider.
The Customer must not use the Service to send End Customers unsolicited communications or communications without a valid legal basis. The Customer must not upload to the Service any End Customer databases for which it has no legal basis for processing and for contacting those persons. The Customer must not load the interfaces of the Service beyond the limits of the selected Subscription Plan or circumvent the technical limits of the Service. The Provider is entitled to suspend the sending of messages or access to the Service upon a breach of any of these obligations, following the procedure under clause 4.9.
The Provider may make available to the Customer features designated as trial, beta or preview features. Those features are provided “as is”, without the warranty under clause 11.1, the Provider may change or discontinue them at any time and their unavailability is not regarded as a defect of the Service under the Complaints Procedure. If a trial feature processes End Customers’ personal data, it is activated solely on the express instruction of the Customer under clause 6.3 of the DPA.
All personal data processing activities in connection with the Services are governed by the DPA (Annex 1), which forms an integral part of this Agreement and binds the Customer upon conclusion of the Agreement without the need for a separate signature, in accordance with Article 15.
As between the Parties, the Customer retains all rights to the Customer Data. The Customer grants the Provider a non-exclusive, royalty-free right to use, copy, store, transmit and display the Customer Data solely to the extent necessary to provide the Services.
The Provider undertakes not to intentionally delete the Customer Data before the end of the Subscription Period. After the Agreement ends, the Customer has the right for 30 days to export the Customer Data through the Account or on written request; after that period the Provider will delete or anonymise the data from production systems within 90 days at the latest (in accordance with the storage limitation principle under Article 5(1)(e) GDPR, unless its retention is required by specific legislation or the Parties agree otherwise). No later than the last day of the export period, the Customer may give the Provider an explicit documented instruction under Article 28(3)(g) GDPR that, instead of deleting the Customer Data, the Provider is to keep them in an inactive state for the purpose of a possible restoration of the Service, for no longer than 12 months from the end of the Agreement. During that time the Provider only stores the Customer Data in separate storage, does not make them available, does not use them for any other purpose, sends no messages to End Customers and does not pass them to further processors beyond the necessary infrastructure. The Customer is responsible for End Customers being informed of that retention under Article 13 GDPR and for having a valid legal basis for it. At the Customer’s request, or at the request of an End Customer forwarded by the Customer, the Provider will delete the data concerned at the latest within 30 days. If the Customer gives no instruction, no retention takes place and the Customer Data are deleted or anonymised within the period under the second sentence of this clause.
Copies of the Customer Data in backups expire within 6 months at the latest and are not used for restoration.
The Customer is solely responsible for the accuracy, content and lawfulness of the Customer Data and declares that it has all the rights and consents necessary for their processing through the Services, including consent to the granting of rights to the Provider under clause 6.2. The Customer undertakes not to use the Services to collect Sensitive Personal Data unless the Parties agree otherwise in writing; the Provider is not a payment card processor and the Services are not certified under PCI DSS. The Customer undertakes to comply with all applicable Laws when using the Services, including the rules on direct marketing towards End Customers. The Customer carries out marketing communications towards End Customers in its own name and solely in relation to its own similar goods and services; the Service may not be used to send out third party offers. If the Customer exports the End Customer database and uploads it into its own tool, that tool becomes a processor of the Customer, not of the Provider; responsibility for the contractual arrangements governing that relationship lies solely with the Customer. If the Customer exports the End Customer database, it is obliged to respect opt-outs from marketing communications recorded in the Service outside the Service as well. It is likewise obliged to handle without undue delay an objection of an End Customer passed on to it by the Provider in third-party systems connected to the Service through which it sends messages to End Customers.
The Provider may collect and aggregate technical and other data on the use of the Services that are not identifiable in relation to the Customer, and use them to analyse, improve and operate the Services, as well as to produce industry overviews, without the Customer being identified as the source. More detailed rules on automated processing and aggregated data are set out in Article 6 of the DPA (Annex 1).
The Customer may, in the Card settings, specify a link to its own loyalty programme rules, which is shown to the End Customer on registration together with the Consumer Terms and the Provider’s Privacy Policy. The Customer’s own rules only supplement those documents and do not replace them, and in the event of a conflict the Consumer Terms prevail. The Customer is solely responsible for the content, lawfulness, availability and currency of its rules and the Provider does not check their content. If the Customer does not specify its own rules, the template club rules in Annex 2 to the Consumer Terms apply.
Personal data processed within the Service are stored in the European Union, in the Amazon Web Services environment in the eu-central-1 region (Frankfurt am Main) and in a MongoDB Atlas database operated in the same region. Transfers outside the European Economic Area occur solely in the case of individual sub-processors listed in the list and are covered by the mechanism stated for each of them. The Provider does not offer a choice of another storage region.
The Services may support integrations with Third Party Platforms selected by the Customer (for example an e-commerce or POS system, a booking system, an individual integration developer), including platforms connected by the Provider on the written instruction of the Customer. By enabling such an integration, the Customer authorises the Provider to access its account on that Platform for the purposes of providing the Services.
In relation to personal data exchanged between a Third Party Platform and the Provider on the Customer’s instruction, that Platform is a processor chosen by the Customer and not by the Provider; the Customer is responsible for the legal relationship with it, including its own data processing addendum. The Provider is not responsible for Third Party Platforms or for the way in which they process the Customer Data after their export to that platform, and may deactivate the relevant integration at any time.
If the Provider makes a public API available for connecting external applications, its use will be governed by separate Developer Terms published on the Website; until those are published, these Terms apply to it, and clause 5.5, Article 7 and Article 15 of these Terms apply mutatis mutandis. Responsibility for third party applications connected via the API lies with their operator, or with the Customer that granted them access.
The Subscription Period renews automatically for a further period of the same length. The Customer is entitled to stop the automatic renewal at any time before it takes place, following the procedure under clause 4.4, with effect at the end of the current Subscription Period. The Provider is entitled to notify the Customer that the Subscription Period will not be renewed at least 30 days before it expires; if that period lapses without such notice, the Subscription Period renews automatically. The Order Form may agree a different arrangement.
The Agreement may be cancelled in the following ways:
After the Agreement ends, the Customer shall without delay cease using the Services and delete, or at the Provider’s request return, all access credentials and Confidential Information of the Provider in its possession. The export and deletion of the Customer Data are governed by clause 6.3. If the Customer terminates the Agreement because of an unremedied material breach by the Provider, the Provider will refund the pro rata part of the fees paid in advance for the unused period. If the Provider terminates the Agreement because of a breach on the Customer’s side, unpaid fees due for the Subscription Period already commenced become immediately payable; no fees arise for subsequent renewal periods.
Provisions which by their nature are intended to survive the end of the Agreement (in particular clause 6.3, Article 10, Article 12, Article 13, Article 14, Article 15, Article 17 and Article 18) remain in force after its expiry or termination.
The Customer acknowledges that the Website and the Services, including the databases, features, products, graphical representations, user interface, texts, logo and designs, contain information and materials protected by legislation governing intellectual property rights, of which the Provider is the owner. This Agreement is a subscription agreement for access to and use of the Services; it does not establish any transfer of ownership rights to the Customer.
The Customer undertakes to use the Services solely for the purposes and within the scope set out in this Agreement and will not (and will not allow a third party to): (a) lease, provide access to or sublicense the Services to a third party beyond their proper use; (b) use the Services to provide its own competing product; (c) reverse engineer or decompile the Services, except to the extent expressly permitted by law; (d) copy or modify the Services or create derivative works from them; (e) remove proprietary notices from the Services; (f) circumvent or breach security measures, upload malicious files, or otherwise act unlawfully.
By using the Services the Customer acquires no licence or other intellectual property rights beyond those expressly set out in this Agreement. The Provider may freely use Feedback in connection with the Services, including in relation to third parties, without disclosing the Customer’s name.
The Provider has the right to terminate the Agreement unilaterally with immediate effect if the Customer breaches this provision by its conduct.
The Provider warrants that the Services will operate in substantial conformity with the Documentation and with applicable Laws. The sole remedy for a breach of this warranty is the free of charge correction of the reported non conformity within a reasonable period, or, where such a remedy is not practicable, termination of the relevant Subscription Period with a refund of the pro rata part of the fees paid in advance. This warranty does not apply if the Customer fails to report the non conformity within 30 days of discovering it, or if it was caused by improper use or unauthorised modification.
With the exception of the warranty under clause 11.1, the Services are provided “as is”. To the extent permitted by the mandatory provisions of the Commercial Code, the Provider excludes all other warranties, in particular as regards uninterrupted or error-free operation. The Provider is not liable for delays or failures caused by circumstances inherent in the internet, electronic communications or Third Party Platforms, beyond its reasonable control.
The Scanner is provided to the Customer for a one-off activation fee of 35 € for the USB version and 55 € for the wireless version; with an annual PRO subscription the Customer is entitled to one Scanner per location without that fee. The Scanner is provided with a limited warranty of 12 months from the date it is taken over. In the case of a justified complaint, the Scanner will be repaired or replaced. If the Scanner is damaged, lost or stolen through the fault of the Customer, and also in the case of damage outside the warranty period caused by improper use, the Customer is obliged to pay the Provider compensation of 105 € for the USB version and 165 € for the wireless version, corresponding to the acquisition value of the Scanner. This is without prejudice to the Provider’s right to compensation for damage actually incurred, if it proves such damage. After payment, the Provider will supply the Customer with a replacement Scanner with a 12-month warranty; the replacement Scanner remains the property of the Provider even after the compensation has been paid.
The Scanner is subject to CE, RoHS and WEEE requirements; take-back in accordance with Act No. 79/2015 Coll. on waste is arranged by the Provider.
Complaints concerning both the Scanner and the Service are made and handled under the separate Complaints Procedure attached after these Terms.
Neither Party is liable to the other Party for lost profit, loss of data or indirect or consequential damage arising in connection with these Terms, save in the cases under clauses 12.3 and 12.4.
The total liability of each Party towards the other Party arising from these Terms is, to the extent permitted by law, limited to the aggregate of the fees actually paid or payable by the Customer to the Provider for the 12 months preceding the event giving rise to the liability. The amount of liability determined in this way must under no circumstances be lower than 1 000 EUR.
The limitations of liability under clauses 12.1 and 12.2 do not apply to damage caused intentionally, nor in any other case in which their application would conflict with mandatory provisions of the law, in particular with Section 386(1) of the Commercial Code, under which a claim for compensation for damage cannot be waived in advance, or with the principle of fair business dealing under Section 265 of the Commercial Code; this applies above all to damage caused by gross negligence. This clause applies equally to both Parties, including in the case of any intentional or grossly negligent breach of the duty of confidentiality under Article 14.
The limitations of liability under clauses 12.1 and 12.2 further do not apply to: (a) the Customer’s obligation to pay the agreed fees; (b) a breach of Article 10 or Article 14 of these Terms by the Customer; and (c) the obligation to provide indemnification under clause 13.2.
The Provider adopts appropriate technical and organisational measures to protect and back up the Customer Data in accordance with its security policy and Annex 3. The Customer is nevertheless advised to keep its own regular exports of key data.
The Provider shall indemnify the Customer against a third party claim that the Services infringe that party’s intellectual property right valid in the Slovak Republic or the European Union, with the exception of claims arising from use of the Services contrary to the Agreement, from their combination with third party products, or from unapproved modification. The Provider may, at its own discretion, secure for the Customer the continued use of the Services, modify them so that the infringement ceases, or terminate the Agreement with a refund of the pro rata part of the fees; this is the Customer’s exclusive remedy.
The Customer shall indemnify the Provider against a third party claim arising from (i) the Customer Data, (ii) the Customer’s use of a Third Party Platform, or (iii) the Customer’s use of the Services contrary to the Laws or to this Agreement.
The Party seeking indemnification shall give the indemnifying Party prompt notice of the claim, allow it sole control over the defence and provide reasonable cooperation.
Each Party shall keep confidential the confidential business, technical and financial information obtained from the other Party that is marked as such or is evidently confidential by its nature, and shall not use it for any purpose other than performing this Agreement. The Provider’s technology, information on the performance of the Services and the content of this Agreement are always regarded as Confidential Information of the Provider. This obligation lasts for 3 years after the end of the Subscription Period and does not apply to information that was already lawfully known to the Party, is publicly available through no fault of its own, or was lawfully obtained from a third party. Notwithstanding the limitation of liability under Article 12, either Party is liable to the other Party in full for an intentional or grossly negligent breach of this obligation.
To the extent that the Provider processes End Customers’ personal data on behalf of and on the instruction of the Customer, the Provider is a processor within the meaning of Article 28 GDPR and the Customer is the controller. The conditions of that processing are governed by the DPA (Annex 1), which forms an integral part of these Terms without the need for a separate signature and which, in matters concerning the processing of End Customers’ personal data, prevails over the other provisions of these Terms.
The Customer is responsible for fulfilling the information duty under Article 13 GDPR towards its End Customers and for the existence of a valid legal basis for their processing, including the compliance of its own loyalty club rules with the Laws. For that purpose the Service displays, alongside the registration form, the Consumer Terms including the Information on the processing of loyalty club members’ personal data (Annex 1 to the Consumer Terms) and allows the Customer to add a link to its own loyalty programme rules under clause 6.7, in which it may supplement the information on processing. When making a purchase or registering in the Customer’s e-shop, an End Customer becomes a member either if that person chooses to join the loyalty programme, or if membership arises under the terms and conditions of the Customer’s e-shop; the second route is permissible only if those terms and conditions state, before the order is submitted or the registration completed, that the loyalty programme exists, link to the club rules, name the Provider as processor and state that membership can be cancelled at any time, and only if the Customer passes to the Provider the source and time of every such enrolment. The Customer is responsible for those conditions being met; the Provider does not verify them.
Where membership arises under the terms and conditions of the Customer’s e-shop, the Customer will, before enrolment, make available to the End Customer in particular: the identity and contact details of the Customer as controller and a contact for exercising rights; the purposes of processing, that is running the membership, issuing and updating the card, crediting and redeeming points and rewards, and communicating about the programme; the legal basis under Article 6(1)(b) and (f) GDPR and, for legitimate interest, a description of it; the categories of data processed; the fact that the Provider acts as processor, with a link to the list of sub-processors; the digital wallet providers as separate controllers; the retention period; the rights under Articles 15 to 22 GDPR including the right to object; the right to lodge a complaint with a supervisory authority; and the information that joining the programme is not a condition of making a purchase and that membership can be cancelled at any time. The Customer will state, in its own terms and conditions and policies, that membership of the loyalty programme includes marketing notifications delivered to the card, and how a member can switch them off or refuse them at any time without losing the membership.
The Provider is entitled to state the Customer’s business name and logo as one of its customers on the Website and in promotional materials, solely in connection with the use of the Services, on the basis of its legitimate interest in presenting its own references. The Customer has the right to object to such a mention at any time and to request its removal, using the contact details under Article 18; the Provider will comply with the request without undue delay. When using the logo, the Provider will take into account any written instructions of the Customer concerning the form in which it is displayed. Stating the Customer as a reference is not regarded as an endorsement of the Services by the Customer, nor as a joint statement about the quality of the Services.
The Provider may process the business contact details of the Customer and of its contact persons (in particular name, surname, e-mail) for the purposes of direct marketing of its own similar services, including through third party advertising platforms, on the basis of legitimate interest under Article 6(1)(f) GDPR, with the Customer’s right to object at any time. In relation to some advertising platforms the Provider may act as a joint controller within the meaning of Article 26 GDPR; details, including the list of platforms and the scope of the data transferred, are set out in the VEXiON cards Privacy Policy, in the annex on joint controllership at https://www.vexioncards.one/gdpr#meta. This Article does not concern End Customer data, which are governed exclusively by the DPA (Annex 1).
The Parties have agreed that delivery, communication and notification between them will take place primarily in electronic form, by e-mail or through the web interface of the Service, to the addresses set out in the Order Form or in Article 18.
The day of delivery of a document sent by e-mail is deemed to be the day following the day on which it was sent, unless proven otherwise.
Severability. If any provision of this Agreement becomes unenforceable, the remaining provisions remain in force; the invalid provision will be replaced by one that comes closest to the original in its purpose.
Governing law and dispute resolution. This Agreement is governed by the law of the Slovak Republic. The Parties will endeavour to resolve disputes primarily by amicable settlement; if that is not successful, the dispute will be decided by the court of the Slovak Republic having subject matter and territorial jurisdiction under Act No. 160/2015 Coll., the Civil Dispute Procedure Code. The Parties have agreed that jurisdiction over disputes arising from these Terms lies exclusively with the courts of the Slovak Republic; this is without prejudice to the provisions of Regulation (EU) No 1215/2012 from which no derogation is permitted.
If the Customer is a natural person, an entrepreneur, who in the circumstances acts in the position of a weaker contracting party comparable to a consumer under the law of the state of its habitual residence, Article 6 of Regulation (EC) No 593/2008 (Rome I) applies in relation to that person in such a way that it retains the protection of the mandatory provisions of the law of that state regardless of the choice of Slovak law under the preceding clause.
Entire agreement. These Terms constitute the entire agreement of the Parties on its subject matter and supersede all previous arrangements and wordings of the Terms. Provisions of any business form of the Customer that differ from these Terms have no legal effect, save as provided in clause 17.10.
Changes to these Terms. The Provider is entitled to amend these Terms. The Provider will inform the Customer of a change, including the date on which it takes effect and the substance of the change, electronically in advance, at least 30 days before it takes effect. If the Customer does not agree with the change, it is entitled to terminate the Agreement as at the date the change takes effect, with a refund of the pro rata part of the subscription paid in advance for the unused period, following the procedure under clause 9.2(c); if the Customer does not do so by the date the change takes effect, the new wording of the Terms becomes effective for it. A change required for compliance with the Laws (including the addition or amendment of the DPA) may take effect earlier, without prejudice to the Customer’s obligation to ensure that the processing of the Customer Data complies with the Laws in the interim.
Force majeure. Neither Party is liable for a delay caused by circumstances beyond its reasonable control (for example a natural event, a network outage, a decision of a public authority), with the exception of a delay in payment.
Subcontractors. The Provider may use subcontractors to provide the Services, while remaining responsible for their performance towards the Customer. In relation to Sub-processors processing End Customers’ personal data, Article 8 of the DPA (Annex 1) applies.
Independence of the Parties. These Terms do not establish a joint venture, agency or employment relationship between the Parties.
Counterparts and language. The Slovak wording of these Terms is binding; any translations into other languages serve only to facilitate understanding and, in the event of a conflict, the Slovak wording prevails. The Provider publishes translations into other languages on the Website.
The Customer is not entitled to assign the rights and obligations arising from these Terms to a third party without the prior written consent of the Provider. In the event of a conflict between these Terms and an individual written contract between the Parties, the individual contract prevails.
The supervisory authority in matters of personal data protection is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava 27, www.dataprotection.gov.sk
These Terms become valid on the day they are published, 27 September 2026. They apply to Contracts concluded from that day from the day the Contract is concluded. They apply to Contracts concluded before that day from 29 October 2026, when they supersede the previous wording of 5 November 2024; until then such Contracts are governed by the previous wording.
The Complaints Procedure attached below, Annex 1 (DPA), Annex 2 (Categories of Sub-processors) and Annex 3 (Security Measures and Safeguards) form an integral part of these Terms.
The purpose of this Complaints Procedure is to inform the Customer of the conditions for and the manner of making a complaint concerning the Service and the Scanner, including information on where the Customer may make a complaint, as well as of the rights arising from liability for defects.
This Complaints Procedure applies to Customers within the meaning of Article 1 of the Terms (a B2B relationship) and governs the contractual warranty provided by the Provider; it does not concern the exercise of Consumer rights under the Civil Code, since these Terms and this Complaints Procedure do not apply to Consumers (clause 1.2 of the Terms).
The Provider is liable for defects in the Service during the term of the Agreement; it is not liable for defects caused by use of the Service contrary to the Terms or to the law.
Having regard to the nature of the Service, a defect may consist in particular in its unavailability.
The Customer is obliged to make a complaint without undue delay after becoming aware of the defect. If it fails to do so, its claim arising from that defect lapses to the extent that the damage arose or increased as a result of the delay.
The complaints procedure begins at the latest on the day the complaint is delivered to the Provider.
The current availability status of the Service and the record of operational incidents are published at https://status.vexioncards.one. The Provider does not guarantee a specific percentage availability; guaranteed availability may be agreed individually.
The Customer makes a complaint electronically, in particular at the e-mail address support@vexioncards.one, stating the nature of the defect, how long it lasted and the date on which it occurred.
The Provider is entitled to ask the Customer to demonstrate that it is a Contracting Party or a person authorised to act for a Contracting Party.
Where the defect is one that can be remedied, the Customer has the right to have it remedied free of charge, in good time and properly. The Provider is obliged to remedy the defect without undue delay. If the defect cannot be remedied within a reasonable period, the Customer has the right to a reasonable discount from the price of the Service for the period during which the defect persisted.
Where the defect is one that cannot be remedied and that prevents the proper use of the Service, the Customer has the right to withdraw from the Agreement with a refund of the pro rata part of the subscription for the unused period. In the case of the repeated occurrence of a remediable defect, of a larger number of defects and of other irremediable defects, the Customer has the right to a reasonable discount from the price of the Service.
The Provider will send the Customer by e-mail a confirmation that the complaint has been made (a complaint record) stating the day on which it was made, a reference number, the identification details of the Parties, a description of the defect, the right exercised and a list of attachments.
Once the complaint has been handled, the Provider will issue a record of the handling of the complaint containing the reference number, the identification details of the Parties, the day on which the complaints procedure began and the manner of handling.
The Provider endeavours to handle a complaint without delay; in technically complex cases, within 30 days of it being made at the latest. If the Provider does not handle the complaint within that period, the Customer has the right to withdraw from the Agreement.
This Complaints Procedure forms an integral part of the Terms and takes effect and becomes valid together with them under clause 19.1.
The Provider is entitled to amend this Complaints Procedure following the procedure under clause 17.5 of the Terms.
This data processing addendum (the “DPA”) is concluded within the meaning of Article 28 GDPR, forms an integral part of the Terms and is incorporated in the Terms (Article 15 of the Terms). By concluding the Agreement, the Customer confirms that it has read and understood the DPA and agrees to be bound by it, without the need for a separate signature.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed by the Provider under this DPA.
“Data Protection Laws” means the GDPR, Act No. 18/2018 Coll., Directive 2002/58/EC (ePrivacy) as transposed into the Slovak legal order, in particular by Section 116 of Act No. 452/2021 Coll. on electronic communications, as amended, and any other binding legislation applicable to the processing of personal data under this Agreement.
“Personal Data” means any information relating to an identified or identifiable natural person that the Provider processes on behalf of the Customer in providing the Services, as set out in Annex 1(2).
“Sub-processor” means a third party engaged by the Provider to process personal data as a further processor, listed by category in Annex 2.
“Standard Contractual Clauses” or “SCC” means the standard contractual clauses for the transfer of personal data to third countries, in the wording currently in force as approved by the European Commission.
Roles of the parties. For the purposes of the GDPR, the Customer is the controller of End Customers’ personal data and the Provider processes them as a processor.
Permitted purposes. The Provider processes personal data only for the purposes set out in Annex 1(2) and in accordance with the Customer’s documented instructions, unless required to do otherwise by Union law or the law of a Member State to which the Provider is subject; in such a case it will inform the Customer in advance, unless the relevant law prohibits this on important grounds of public interest.
Instructions. If the Provider believes that an instruction of the Customer breaches the Data Protection Laws, it will notify the Customer of this without delay. If it is unable to carry out an instruction, it will inform the Customer of this without undue delay.
Security measures. The Provider will implement and maintain appropriate technical and organisational measures under Article 32 GDPR, at least to the extent set out in Annex 3.
Confidentiality. The Provider will ensure that persons authorised to process personal data are bound by a duty of confidentiality and have access only to the extent necessary for the performance of the Services.
Return and deletion of data. After the Agreement ends, the Customer chooses under Article 28(3)(g) GDPR between the return and the deletion of the personal data. If the Customer requests neither return nor retention, the Provider will delete or anonymise the personal data in accordance with clauses 6.3 and 6.4 of the Terms. Retention for the purpose of a possible restoration of the Service is possible only on an explicit documented instruction of the Customer, on the conditions and for no longer than the period under clause 6.3 of the Terms; at the Customer’s request the Provider will delete data so retained at the latest within 30 days.
Impact assessment. At the Customer’s request, the Provider will provide the Customer with reasonable cooperation in carrying out a data protection impact assessment under Article 35 GDPR and in prior consultation with the supervisory authority under Article 36 GDPR, to the extent of the information on the processing and on the security measures available to the Provider. If the scope of the cooperation requested is disproportionate to the usual scope of the Services, the Provider may agree reasonable reimbursement of the costs incurred.
Requests from public authorities. If the Provider receives from a public authority a binding request for disclosure of personal data processed for the Customer, it will inform the Customer of this without undue delay, unless prohibited from doing so by law, and, to the extent permissible, will refer the authority directly to the Customer as the controller. The Provider does not disclose personal data to a public authority voluntarily, in the absence of a binding legal request.
Records. The Provider maintains records of the categories of processing activities carried out on behalf of the Customer under Article 30(2) GDPR and will, on request, make them available to the Customer to the extent that they concern it.
The Customer has the right to verify compliance with the Provider’s obligations under Article 28 GDPR and this DPA, on the basis of written notice given at least 30 days in advance, no more than once a year, at the Customer’s cost, and to an extent not exceeding 1 working day. The Provider may object to an external auditor who is not adequately qualified or independent or who is a competitor of the Provider.
The obligation under the preceding clause may also be fulfilled by the Provider submitting to the Customer a valid certification under a recognised security standard, a completed security questionnaire or an independent auditor’s report, provided these were produced or obtained within the last 12 months, provided compliance with the obligations under Article 28 GDPR and this DPA can reasonably be verified from them, and provided the Provider confirms that there has been no material change in the measures assessed since then. If the Customer demonstrates that the documents submitted are not sufficient for verification, its right to an audit under the preceding clause is preserved.
The Customer is responsible for the lawfulness and accuracy of the personal data it enters into the Services, for fulfilling the information duty and obtaining the necessary consents in relation to End Customers, for fulfilling its registration or notification obligations under the Data Protection Laws, and for the secure use of the Services, including the protection of its access credentials. The Customer is also obliged to respect opt-outs from marketing communications under clause 6.5 of the Terms in relation to data it has exported from the Service.
The Provider will give the Customer reasonable cooperation in handling End Customers’ requests to exercise their rights under the GDPR; if such a request is delivered directly to the Provider, it will inform the Customer of this without delay and will not respond to it directly unless legally obliged to do so, and will do so within a period allowing the Customer to meet the deadline under Article 12(3) GDPR. However, an End Customer's request to erase their personal data, or their objection to marketing communications, that is delivered directly to the Provider is handled by the Provider itself on the basis of this instruction of the Customer, and the Provider informs the Customer of it; this also applies where the Customer's access to the Service is suspended or the Contract has ended.
Anonymised and aggregate data. The Provider is entitled to derive anonymised and aggregate statistics from the personal data processed under this Agreement, in particular on the frequency of visits, on the rate at which rewards are redeemed or on behaviour at the level of a category of locations across several customers, and to use them for the operation, improvement and development of the Services. In doing so it applies that a) neither from the resulting data set nor from a tool built on it is it reasonably possible to determine a specific data subject, to link that person with other data about them or to infer anything about them, b) the source identifiable records are not kept alongside the anonymised output for longer than is necessary to create it, and c) the Provider regularly reassesses the risk of re-identification. Data meeting this standard are not personal data and the provisions of this DPA do not apply to them.
Identifiable data only on instruction. The Provider activates any feature using identifiable personal data of specific End Customers solely on the basis of an express, documented instruction of the Customer, revocable at any time, under Article 28(3)(a) GDPR. Switching such a feature on in the Account is regarded as a documented instruction of the Customer.
The Provider may process data by automated means for the purposes of the operation, security and improvement of the Service, including the personalisation of offers within the Customer’s loyalty programme. For improving the Service across Customers it uses exclusively aggregated or anonymised data from which an End Customer cannot be identified.
Automated decision-making. The Provider does not take decisions with legal or similarly significant effects in relation to an End Customer within the meaning of Article 22 GDPR; automated measures against abuse of the referral programme concern solely the entitlement to a reward and an End Customer may object to them.
Upon becoming aware of a Personal Data Breach, the Provider will, without undue delay, as a rule within 48 hours and within 72 hours at the latest, inform the Customer and provide it with the information and cooperation needed to fulfil its notification obligation under Articles 33 and 34 GDPR. Such a notification is not regarded as an acknowledgement of liability by the Provider.
The Customer grants the Provider general authorisation to engage Sub-processors in the categories set out in Annex 2. The Provider maintains on an ongoing basis and publishes the current named list of sub-processors in each category, stating the legal entity, the purpose of processing, the location of the data and the mechanism for transfers outside the EEA, at https://www.vexioncards.one/gdpr#sprostredkovatelia. The list contains the date of the last update; the Provider will inform the Customer of changes to it by e-mail in accordance with clause 8.2.
The Provider will notify the Customer of every engagement of a new Sub-processor and of every replacement of an existing Sub-processor by another, including within an existing category under Annex 2, at least 30 days before the new Sub-processor begins to process personal data. The notification will be made by publication at the address referred to in clause 8.1 and at the same time by e-mail sent to the Customer’s contact address stated in the Account. On data protection grounds, the Customer may raise a reasoned objection within 10 days of the notification. If the Provider does not resolve the objection within 30 days of its delivery, the Customer has the right to terminate the affected part of the Service without penalty, with a refund of the pro rata part of the subscription for that part. If the Customer does not raise an objection within that period, the Sub-processor is deemed to be approved.
The Provider remains responsible for the performance of a Sub-processor’s obligations to the extent that the Sub-processor fails to perform them, and will contractually impose on it the same data protection obligations as those it has itself under this DPA.
The Provider is established in the European Union and processes personal data in the European Union. The transmission of personal data between the Customer and the Provider is not a transfer to a third country under Chapter V GDPR and the Standard Contractual Clauses do not apply to it.
Location of the data. Personal data processed within the Service are stored in the European Union, in the Amazon Web Services environment in the eu-central-1 region (Frankfurt am Main) and in a MongoDB Atlas database operated in the same region. Transfers outside the European Economic Area occur solely in the case of individual sub-processors listed in the list and are covered by the mechanism stated for each of them. The Provider does not offer a choice of another storage region.
The Customer authorises the Provider to transmit personal data onward to the Sub-processors listed in the list referred to in clause 8.1. If a Sub-processor is established outside the European Economic Area, the Provider will secure the transfer by an adequacy decision, where one is in force for that country at the relevant time, or by the Standard Contractual Clauses. The mechanism used is stated for each Sub-processor in the list.
The Provider will provide the Customer on request with a copy of the clauses concluded with a Sub-processor; it may remove commercial information and parts unrelated to personal data protection before providing it.
If the transfer mechanism used ceases to be valid or a supervisory authority suspends its use, the Provider will, without undue delay, move to another permissible mechanism or replace the Sub-processor concerned.
Digital wallet providers as referred to in the note to Annex 2 are not Sub-processors of the Provider and the transmission of data to them is governed by their own terms.
The Provider’s liability arising from this DPA is subject to the limitations of liability agreed in Article 12 of the Terms. This DPA is governed by the law and the jurisdiction agreed in clause 17.2 of the Terms, unless the Data Protection Laws require otherwise, and remains effective for the term of the Agreement and, after it ends, until the Provider ceases to process personal data on behalf of the Customer. In the event of a conflict between the provisions of this DPA and the other provisions of the Terms, the provisions of this DPA prevail in matters of personal data processing.
The Provider’s point of contact in matters of personal data protection is support@vexioncards.one.
| Controller | Processor |
|---|---|
| Name: the Customer as stated in the Order Form, and where no Order Form was drawn up, as stated in the details held in the Account | Name: MAMA media s.r.o. |
| Address: as stated in the Order Form, otherwise as stated in the billing details held in the Account | Address: Na Hrebienku 1, 811 02 Bratislava, Company ID: 36 767 549, registered in the Commercial Register of the Bratislava III Municipal Court, Section Sro, Insert No. 45585/B |
| Role: Controller | Role: Processor |
| Category | Content |
|---|---|
| Categories of data subjects | End Customers, that is, members of the Customer’s loyalty programme. Employees and other persons acting for the Customer, solely to the extent of their identifier recorded in a transaction carried out in the Account. Data on the Customer and on the users of its Account processed for the purposes of contract administration, invoicing, support and development of the Services are processed by the Provider in its own name as a controller and are not the subject of this DPA. |
| Categories of personal data | Name, e-mail, telephone, date of birth (where collected), preferred language, photograph (where the End Customer provides one), history of transactions and of loyalty programme redemptions, technical device identifier and device type, identifiers for delivering notifications, location and time of the visit, and data in optional fields whose scope is determined by the Customer. A transaction record contains the amount, points, stamps, time, location and a reference to the order in the POS system; the record may also include the purchase items, that is the name, quantity and price, where the Customer’s POS system or e-shop passes them on |
| Special categories of data | The Provider does not intentionally collect them or require them in order to provide the Services. If the Customer uses the Service in a vertical in which special categories of data under Article 9 GDPR might be processed, such processing is governed by a separate addendum to this DPA |
| Frequency of the processing | Continuous, for the term of the Agreement |
| Nature and purpose of the processing | Hosting, operation of the digital loyalty card, recording of transactions and loyalty balances, delivery of notifications, the referral programme between End Customers, the recording and redemption of gift vouchers after their activation, the creation and delivery of marketing campaigns and segmentation on the Customer’s instruction, and technical support |
| Duration of the processing | The term of the Agreement and the periods under clauses 6.3 and 6.4 of the Terms |
The competent supervisory authority is the supervisory authority competent by reference to the main establishment of the Customer as controller. For a Customer with its registered office in the Slovak Republic this is the Office for Personal Data Protection of the Slovak Republic, Hraničná 12, 820 07 Bratislava. For the Provider as processor, the competent supervisory authority is the Office for Personal Data Protection of the Slovak Republic.
In accordance with Article 8 of the DPA, Sub-processors are listed by category of the recurring shape of the relationship, not by individual company, so that a change of a particular supplier within the same category does not make it necessary to amend these Terms. The Provider maintains on an ongoing basis and publishes the current named list of sub-processors in each category, stating the legal entity, the purpose of processing, the location of the data and the mechanism for transfers outside the EEA, at https://www.vexioncards.one/gdpr#sprostredkovatelia. The list contains the date of the last update; the Provider will inform the Customer of changes to it by e-mail in accordance with clause 8.2 of the DPA.
Digital wallets (Apple Wallet, Google Wallet) act, under those providers’ own terms, as separate controllers and not as Sub-processors of the Provider; the same applies to the platforms listed in category K4.
| Cat. | Category of relationship | Who selects the supplier | Role of the Provider |
|---|---|---|---|
| K1 | Core platform infrastructure and services (hosting, database, payments, login, communications, monitoring) | Provider | Processor towards the Customer; controller in respect of its own B2B data |
| K2 | POS systems chosen and operated by the Customer and connected to the Service on its instruction | Customer | Not a Sub-processor of the Provider, it is a processor of the Customer, see Article 7 of the Terms |
| K3 | Booking systems chosen and operated by the Customer and connected to the Service on its instruction | Customer | Not a Sub-processor of the Provider, it is a processor of the Customer, see Article 7 of the Terms |
| K4 | E-commerce and other platforms that the Customer uses for its own activity and that are connected to the Service, whether connected by the Customer itself, by a developer it has chosen, or by the Provider on the basis of an arrangement with the Customer. On the Customer’s instruction, the Provider writes a loyalty programme membership marker and its tier into the customer records in that platform; those data remain in the Customer’s system and the retention periods under Article 6 of the Terms do not apply to them | Customer, or the Provider on the basis of an arrangement with the Customer | Not a Sub-processor of the Provider: the Customer’s own platform or processor, see Article 7 of the Terms |
| K5 | Partner systems with a reversed relationship, where the source is a contractual partner of the Provider (for example where the partner integrates the Service into its own system for its own end customers) | Partner | Reversed relationship: the partner is the controller of its end customers, the Provider is its further processor; governed by a separate contract outside this Agreement, does not concern the Customer |
| K6 | Automated data processing and enrichment tools that process exclusively data at the level of the Customer (not of End Customers) | Provider | Processor for the Customer’s data |
| K7 | Professional advisers (accounting, legal and tax advice, audit) | Provider | Processor; access to personal data solely to the extent necessary to provide the advice and subject to a duty of confidentiality under specific legislation |
The Provider does not hold SOC 2 or ISO 27001 certification, does not process payment card data and is not certified under PCI DSS.
Last updated: 27 September 2026. Previous version, effective from 5 November 2024: General Terms and Conditions (PDF).