Terms of Service

Version v1 · en

General Terms and Conditions of Risk at Work B.V.

Version: 2026-05-20 — English courtesy translation. The Dutch version is authoritative.

NOT LEGALLY VALID — REASONABLE DRAFT ONLY. This document is shipped as a starting point and must be reviewed and adapted by a qualified legal professional before production use. Do not rely on it as legal advice.


Structure and Applicability

These General Terms and Conditions consist of five chapters:

  • Chapter 1 — General Provisions applies to all agreements between Risk at Work B.V. and the Client.
  • Chapter 2 — Consultancy Services applies when the Agreement covers advisory, analysis, development, or other deliverable-based services.
  • Chapter 3 — Software and SaaS applies when the Agreement covers the provision of software, whether licensed for installation by the Client or made available as a service.
  • Chapter 4 — AI Services applies when the Agreement involves the development, provision, or use of artificial intelligence components.

The Data Processing Addendum (DPA), available separately, is incorporated by reference into any Agreement under which Risk at Work B.V. processes Personal Data on behalf of the Client.

In the event of conflict between these documents, the following order of precedence applies, with earlier documents prevailing over later ones:

  1. The executed Order Form (opdrachtbevestiging) and any annexes thereto
  2. The DPA (for matters of personal data processing)
  3. Chapter 4 (if applicable)
  4. Chapter 3 (if applicable)
  5. Chapter 2 (if applicable)
  6. Chapter 1

Chapter 1 — General Provisions

Article 1 — Definitions

In these General Terms and Conditions:

Agreement: the contractual relationship between Risk at Work B.V. and the Client, consisting of the Order Form, any annexes, these General Terms and Conditions, and any other documents expressly incorporated therein.

Client (Opdrachtgever): the party that engages Risk at Work B.V..

Consultant: any natural person who, under an employment agreement or other engagement with Risk at Work B.V., performs or is designated to perform work for the Client.

Deliverable: any report, analysis, calculation model, dataset, software, document, presentation, or other work product that Risk at Work B.V. produces or makes available under the Agreement.

DPA: the Data Processing Addendum between the Parties governing the processing of Personal Data, as published by Risk at Work B.V. and incorporated into the Agreement.

Intellectual Property Rights: all intellectual property rights worldwide, including patents, trademarks, copyrights, database rights, design rights, trade secrets, know-how, and all applications for and registrations of any of the foregoing.

Material Breach: a breach of an essential obligation under the Agreement, including without limitation (a) failure to pay any undisputed amount within thirty (30) days of the due date; (b) breach of confidentiality obligations; (c) breach of Intellectual Property Rights; (d) use of services or Deliverables in violation of applicable law or in a manner likely to cause material damage to the other Party's reputation, business operations, or legal standing; and (e) repeated violations of data protection or security obligations.

Offer (Offerte): a written offer by Risk at Work B.V. to enter into an Agreement.

Order Form (Opdrachtbevestiging): the document signed by both Parties that specifies the scope, fees, duration, and any specific terms of a particular engagement.

Parties: Risk at Work B.V. and the Client jointly.

Personal Data: has the meaning given in Regulation (EU) 2016/679 (GDPR).

Risk at Work B.V. (Opdrachtnemer): the private limited company Risk at Work B.V., having its registered office in Prinsenbeek and registered with the Dutch Chamber of Commerce under number 72356219.

Working Day: Monday through Friday, excluding Dutch national public holidays, between 08:30 and 17:00 Central European Time.

Writing (Schriftelijk): any communication by letter, email, or electronic signature platform accepted by both Parties.

Article 2 — Formation and Scope of the Agreement

2.1 All engagements are accepted and performed exclusively by Risk at Work B.V., with express exclusion of Articles 7:404 and 7:407(2) of the Dutch Civil Code. No partner, employee, or person associated with Risk at Work B.V. shall be personally bound to perform the Agreement.

2.2 Offers are non-binding unless otherwise stated in writing, and may be amended or withdrawn by Risk at Work B.V. at any time prior to acceptance.

2.3 The Agreement is formed when the Order Form signed by both Parties has been received by Risk at Work B.V.. The Order Form is based on information provided by the Client at the time of its issuance and is deemed to reflect the Agreement completely and accurately.

2.4 The Agreement between the Parties consists of the Order Form, these General Terms and Conditions, the DPA (where applicable), and any other documents expressly incorporated by reference. Together these constitute the entire agreement between the Parties and supersede all prior written or oral proposals, communications, and correspondence.

2.5 Risk at Work B.V. expressly rejects the applicability of any general terms and conditions of the Client or any third party. Any such terms included in a Client order, purchase order, invoice, or other document or correspondence provided to Risk at Work B.V. shall not apply to any Agreement or negotiation between the Parties.

2.6 Deviations from these General Terms and Conditions are binding only if agreed in writing and signed by an authorised representative of Risk at Work B.V..

Article 3 — Amendment of Terms

3.1 Risk at Work B.V. may amend these General Terms and Conditions. Material amendments shall be notified to the Client in writing, together with the effective date of the amendment, which shall be no less than thirty (30) days after notification.

3.2 If the Client objects to a material amendment in writing within thirty (30) days of notification, the prior version of the General Terms and Conditions shall continue to apply to existing Agreements for the remainder of their term, except where the amendment is required by mandatory law, regulatory requirement, or authoritative interpretation, in which case the amended version shall apply from the effective date.

3.3 Amendments that are not material — including clarifications, corrections, and changes to references to external documents — shall take effect upon notification.

Article 4 — Client Cooperation

4.1 The Client shall provide Risk at Work B.V. with all information, documentation, access to personnel, and cooperation reasonably required for the performance of the Agreement, in a timely and complete manner. Risk at Work B.V. is entitled to rely on the accuracy and completeness of information provided by the Client and is not responsible for verifying the same.

4.2 If the Client fails to provide information or cooperation in a timely manner, or otherwise fails to comply with its obligations, Risk at Work B.V. shall be entitled to suspend performance in whole or in part, to adjust timelines, and to charge any additional costs incurred as a result at its usual rates.

4.3 When Consultants perform work at the Client's premises, the Client shall provide reasonable facilities including a suitable workspace, network access, and such other resources as the Consultant may reasonably require. The workspace shall comply with all applicable laws and regulations concerning working conditions.

Article 5 — Fees and Payment

5.1 Fees for Risk at Work B.V.'s services are not contingent on the outcome of the engagement. Risk at Work B.V. provides services on a best-efforts basis (inspanningsverplichting) and does not guarantee any particular result, except where a specific and sufficiently defined result has been expressly agreed in writing.

5.2 All fees and prices stated by Risk at Work B.V. are exclusive of VAT and any other applicable taxes, levies, or charges. Fees are quoted in Euros unless otherwise agreed.

5.3 Unless otherwise agreed in the Order Form, Risk at Work B.V. invoices on a monthly basis for services rendered, on a quarterly basis for software subscriptions and licences, and upon completion for fixed-price engagements. Disbursements and expenses reasonably incurred in the performance of the Agreement, including travel beyond ordinary commuting, are charged in addition to fees.

5.4 The agreed price is inclusive of ordinary commuting but exclusive of business travel requested by the Client. Time spent by Consultants on business travel at the Client's request is charged at the applicable rate.

5.5 For time-and-materials engagements, Risk at Work B.V. may adjust its hourly and daily rates annually as of 1 January to reflect changes in the consumer price index as published by Statistics Netherlands (CBS), with such adjustment taking effect for work performed on or after that date. Fixed-price fees agreed in an Order Form are not subject to annual indexation during the term of the relevant engagement. Risk at Work B.V. shall pass through any statutory changes affecting applicable rates as of the effective date of such changes.

5.6 Payment shall be made in Euros, without deduction, discount, set-off, or suspension, within fourteen (14) days of the invoice date, to a bank account designated by Risk at Work B.V..

5.7 The Client may dispute an invoice in writing and in good faith within fourteen (14) days of the invoice date. The undisputed portion of the invoice remains payable on time. A dispute does not suspend the payment obligation for the undisputed portion.

5.8 If the Client fails to pay any amount by the due date, the Client shall be in default by operation of law (van rechtswege in verzuim) without further notice, and shall owe statutory commercial interest pursuant to Article 6:119a of the Dutch Civil Code from the due date until the date of full payment. The Client shall also reimburse Risk at Work B.V. for all reasonable judicial and extrajudicial costs of collection.

5.9 Risk at Work B.V. may suspend the provision of services if the Client is in default of payment, and may require advance payment or other security as a condition of continued performance.

Article 6 — Confidentiality

6.1 Each Party shall keep confidential any information received from the other Party that is marked as confidential or that should reasonably be understood to be confidential given its nature or the circumstances of its disclosure ("Confidential Information"). The Receiving Party shall apply the same standard of care it applies to its own confidential information of like kind, and in no event less than reasonable care.

6.2 The Receiving Party shall use Confidential Information only for the purpose of performing its obligations or exercising its rights under the Agreement. Disclosure to employees, affiliates, subcontractors, or professional advisers is permitted only where they have a need to know and are bound by confidentiality obligations no less protective than those in this Article.

6.3 Confidential Information does not include information that: (a) is or becomes publicly known other than through breach of this Article; (b) was lawfully in the Receiving Party's possession before disclosure; (c) is lawfully received from a third party without confidentiality obligations; or (d) is independently developed without reference to the Disclosing Party's Confidential Information.

6.4 If the Receiving Party is required by law, court order, or regulatory authority to disclose Confidential Information, it shall (where legally permitted) give the Disclosing Party prior written notice sufficient to allow the Disclosing Party to seek a protective order or other appropriate remedy.

6.5 Obligations under this Article shall apply during the term of the Agreement and for a period of five (5) years following its termination. Information that constitutes a trade secret (bedrijfsgeheim) shall remain protected for as long as it retains its status as a trade secret under applicable law.

6.6 Risk at Work B.V. reserves the right to use the Client's name and a general description of the engagement for reference and marketing purposes, provided that no Confidential Information of the Client is disclosed.

Article 7 — Non-Solicitation of Personnel

7.1 During the term of the Agreement — including the period between the formation of the Agreement and the commencement of work — neither the Client nor any of its affiliates shall enter into an employment agreement with any Consultant, nor engage any Consultant on the basis of any other agreement to perform work, without the prior written consent of Risk at Work B.V.. In the event of a breach, the Client shall owe an immediately payable penalty of EUR 50,000 per breach, plus EUR 5,000 for each day the breach continues, without prejudice to the right of Risk at Work B.V. to claim full damages.

7.2 For a period of eighteen (18) months after the end of the Agreement, the Client and its affiliates may enter into an employment or other engagement agreement with any natural person who, at the time of such engagement or within the preceding six (6) months, is or was a Consultant of Risk at Work B.V., only on payment of a reasonable compensation to Risk at Work B.V.. Such compensation shall be the higher of (a) thirty percent (30%) of the total fees invoiced to the Client in respect of that Consultant over the full duration of the Agreement, or (b) thirty percent (30%) of the Consultant's most recent gross annual base salary in their new position. VAT is payable in addition. This compensation is deemed by the Parties to be a reasonable compensation within the meaning of Article 9a(2) of the Dutch Act on the Allocation of Workers by Intermediaries (Wet allocatie arbeidskrachten door intermediairs).

7.3 If the Client wishes to approach a Consultant, it shall first notify Risk at Work B.V. in writing.

Article 8 — Intellectual Property Rights

8.1 All Intellectual Property Rights in Deliverables, including without limitation software, calculation models (rekenmodellen), analyses, tools, designs, reports, documentation, preparatory materials, methods, frameworks, algorithms, statistical techniques, and source code developed or made available by Risk at Work B.V. under the Agreement, vest exclusively in Risk at Work B.V., its licensors, or its suppliers. No Intellectual Property Rights are transferred to the Client except as expressly agreed in writing.

8.2 Subject to full payment of the fees due under the Agreement, the Client obtains a non-exclusive, non-transferable, non-sublicensable right to use the Deliverables for its own internal business purposes and for the purpose for which they were produced. Any other or broader right, including the right to reproduce, distribute, publish, sublicense, or make available to third parties, requires the prior written consent of Risk at Work B.V..

8.3 Notwithstanding any transfer of Intellectual Property Rights in a specific Deliverable that may be expressly agreed in writing, Risk at Work B.V. retains the right to use and exploit, without restriction, the general principles, ideas, concepts, methods, frameworks, know-how, programming languages, algorithms, statistical techniques, and preparatory materials underlying the Deliverable, whether for its own purposes or on behalf of other clients, including clients in the same industry as the Client.

8.4 IP warranty and indemnity. Risk at Work B.V. warrants that Deliverables, when used in accordance with the Agreement and excluding Client materials and any modifications or combinations made by or on behalf of the Client, will not infringe the Intellectual Property Rights of any third party. Risk at Work B.V. shall defend, indemnify, and hold the Client harmless against any third-party claim alleging such infringement, provided the Client (a) promptly notifies Risk at Work B.V. of the claim; (b) allows Risk at Work B.V. to control the defence and settlement; and (c) provides reasonable cooperation at Risk at Work B.V.'s expense. As the Client's sole remedy, Risk at Work B.V. may at its option (i) procure the right for the Client to continue use, (ii) modify the Deliverable so it becomes non-infringing, or (iii) terminate the affected portion of the Agreement with a pro-rata refund of prepaid fees. This indemnity does not apply to claims arising from (1) Client modifications not authorised by Risk at Work B.V., (2) combinations with products, services, or data not provided by Risk at Work B.V., or (3) use in breach of the Agreement.

8.5 Open-source and third-party components. Deliverables may include open-source software components and other third-party materials, the use of which is subject to the licence terms accompanying those components. To the extent of any conflict between the Agreement and such third-party licence terms in respect of such components, the third-party licence terms prevail. Risk at Work B.V.'s warranty and indemnity under Article 8.4 do not extend beyond what is provided under the applicable third-party licence.

8.6 Client-provided materials. The Client warrants that all information, data, and materials it provides to Risk at Work B.V. for use in connection with the Agreement are free from any infringement of third-party rights and are not unlawful in any other respect. The Client shall indemnify Risk at Work B.V. against any third-party claim relating to such materials.

8.7 The Client shall not remove or alter any notices of confidentiality, copyright, trademarks, trade names, or other Intellectual Property Rights from Deliverables or materials provided by Risk at Work B.V., and shall promptly notify Risk at Work B.V. of any actual or suspected claim by a third party concerning Risk at Work B.V.'s Intellectual Property Rights.

Article 9 — Data Protection

9.1 Where Risk at Work B.V. processes Personal Data on behalf of the Client in the performance of the Agreement, it acts as a processor (verwerker) within the meaning of the GDPR, and the DPA applies. The DPA forms an integral part of the Agreement.

9.2 The Client is responsible as controller (verwerkingsverantwoordelijke) for the lawfulness of the Personal Data processed under the Agreement, including the existence of a valid legal basis for processing and the fulfilment of information obligations towards data subjects.

9.3 The Client shall not provide Risk at Work B.V. with Personal Data that is not required for the services to be provided. The Client shall indemnify Risk at Work B.V. against any damage resulting from the provision of Personal Data in breach of this Article.

9.4 Where Risk at Work B.V. processes Personal Data for its own purposes — including account management, invoicing, and compliance with its own legal obligations — it acts as an independent controller.

Article 10 — Warranties and Client Acknowledgments

10.1 Risk at Work B.V. shall perform its services with the care and professionalism that may reasonably be expected of a competent provider of comparable services, and shall assign personnel with appropriate qualifications, training, and experience.

10.2 The Client may only rely on the final Deliverable as formally delivered by Risk at Work B.V., and not on interim drafts, concepts, prototypes, or oral statements made during the course of the engagement.

10.3 The Client acknowledges the advisory nature of services and the supporting nature of software provided under the Agreement. The decision whether and how to act on a Deliverable, and the consequences of such decision, remain the responsibility of the Client.

10.4 Risk at Work B.V. does not warrant that services or Deliverables will meet any internal performance targets, benchmarks, or objectives of the Client, unless such targets have been expressly and specifically agreed in writing as measurable acceptance criteria.

10.5 Timelines stated by Risk at Work B.V. or agreed between the Parties are indicative unless expressly designated as firm deadlines in writing. The mere passing of an indicative date does not place Risk at Work B.V. in default; a written notice of default granting a reasonable cure period is required in all cases.

Article 11 — Liability

11.1 Risk at Work B.V. is liable only for damage directly caused by an attributable failure in the performance of the Agreement that would have been avoided with due care, and only if the Client has given Risk at Work B.V. prompt and detailed written notice of default and a reasonable opportunity to cure. The notice of default shall describe the alleged failure in sufficient detail to enable an adequate response.

11.2 The aggregate liability of Risk at Work B.V. under or in connection with the Agreement, regardless of the legal basis of the claim, is limited to the lower of:

(a) the fees received by Risk at Work B.V. under the engagement in the twelve (12) months immediately preceding the event giving rise to the claim (or, for engagements of shorter duration, the total fees received for the engagement); and

(b) EUR 500,000 (five hundred thousand Euros) per engagement.

In no event shall the aggregate liability of Risk at Work B.V. to a single Client exceed EUR 1,000,000 (one million Euros) in any consecutive twelve-month period.

11.3 Risk at Work B.V. shall not be liable for any indirect or consequential damage, including without limitation loss of profits, loss of revenue, loss of savings, loss of goodwill, reputational damage, business interruption, loss of data, loss of use, claims by clients of the Client, damage arising from the use of third-party materials or services prescribed by the Client, or any damage arising from decisions by the Client to act (or not to act) on a Deliverable.

11.4 The limitations in Articles 11.2 and 11.3 do not apply to damage caused by intent (opzet) or gross negligence (grove schuld) of Risk at Work B.V.'s management, nor to liability that cannot be limited or excluded under mandatory law.

11.5 Risk at Work B.V. is not liable for damage caused by errors or omissions in information provided by the Client, nor for the consequences of the Client's failure to validate Deliverables in accordance with its obligations under this Agreement.

11.6 Any claim against Risk at Work B.V. must be brought within twelve (12) months after the Client became aware, or reasonably should have become aware, of the facts giving rise to the claim, failing which the claim shall lapse. This provision derogates from the statutory limitation periods.

11.7 The Client is liable for and shall indemnify Risk at Work B.V. against any damage or costs incurred by Consultants in the performance of their work at the Client's premises, to the extent such liability arises under applicable law, including Articles 7:611 and 7:658 of the Dutch Civil Code concerning working conditions and employer's liability.

11.8 Risk at Work B.V. shall always be given a reasonable opportunity to limit or avoid any damage the Client may suffer.

Article 12 — Insurance

12.1 Risk at Work B.V. maintains appropriate professional indemnity insurance (beroepsaansprakelijkheidsverzekering) and employer's liability insurance at levels consistent with industry standards for a consultancy of its size and activities. On the Client's reasonable written request, Risk at Work B.V. shall provide a certificate or written confirmation of such cover, subject to confidentiality.

Article 13 — Force Majeure

13.1 Neither Party is liable for any failure to perform its obligations under the Agreement (except for obligations to pay amounts already due) where such failure is caused by force majeure (overmacht).

13.2 For the purposes of this Agreement, force majeure includes any circumstance beyond a Party's reasonable control, including without limitation: acts of government or regulatory authority, war or acts of war, terrorism, civil unrest, strikes or industrial action, pandemics, epidemics, natural disasters, fire, flood, failures in energy or telecommunications supply, failures of third-party cloud or internet infrastructure, cyber-attacks not attributable to a failure of the affected Party's reasonable security measures, failures of suppliers or subcontractors whose use is prescribed by the other Party, and the unavailability of key personnel due to illness or other causes beyond the affected Party's control.

13.3 A Party invoking force majeure shall notify the other Party in writing as soon as reasonably practicable, describing the event, its expected impact, and the anticipated duration. The obligations of the affected Party shall be suspended for the duration of the force majeure event.

13.4 If a force majeure event continues for more than ninety (90) consecutive days, either Party may terminate the Agreement by written notice. In that event, Risk at Work B.V. shall be entitled to payment for work performed and costs reasonably incurred up to the date of termination, and neither Party shall owe any further compensation to the other on account of the termination.

Article 14 — Suspension and Termination

14.1 Contrary to Article 7:408(1) of the Dutch Civil Code, the Client is not entitled to terminate a fixed-term Agreement for convenience. Either Party may terminate the Agreement only in accordance with this Article.

14.2 Either Party may terminate the Agreement with immediate effect by written notice, without liability to compensate the other Party, if:

(a) the other Party is declared bankrupt or applies for or is granted suspension of payments (surseance van betaling), debt restructuring, or any similar insolvency procedure; (b) the other Party is dissolved, liquidated, or ceases to conduct its business other than for the purpose of reorganisation or a merger; (c) force majeure affecting the other Party continues for more than ninety (90) consecutive days; (d) the other Party commits a Material Breach and fails to cure such breach within a reasonable period (and in any event no less than ten (10) Working Days) after receiving a detailed written notice of default.

14.3 Risk at Work B.V. may additionally terminate the Agreement with immediate effect upon a change of control in respect of the Client. For the purposes of this Article, "change of control" means the acquisition by a third party, whether in a single transaction or a series of related transactions, of the ability to direct the management and policies of the Client, whether through ownership of voting securities, contract, or otherwise.

14.4 Risk at Work B.V. may suspend its services, without liability to compensate the Client, if the Client is in Material Breach of the Agreement, including non-payment of undisputed amounts.

14.5 On termination, Deliverables already received by the Client and the related payment obligations shall not be unwound, unless Risk at Work B.V. is in default in respect of those Deliverables. Amounts already invoiced in respect of services properly performed prior to termination shall remain due in full and become immediately payable.

14.6 Provisions of the Agreement that by their nature or express terms are intended to survive termination shall continue in full force and effect, including Articles 6 (Confidentiality), 7 (Non-Solicitation), 8 (Intellectual Property), 9 (Data Protection), 11 (Liability), 14.5–14.6 (Survival), 15 (Assignment), 17 (Governing Law), and any corresponding provisions in Chapters 2–4.

Article 15 — Assignment

15.1 The Client may not assign, transfer, or encumber any of its rights or obligations under the Agreement without the prior written consent of Risk at Work B.V..

15.2 Risk at Work B.V. may assign or transfer its rights and obligations under the Agreement to an affiliate or to a successor acquiring all or substantially all of its business or assets, and may assign claims for payment of fees to a third party.

15.3 Risk at Work B.V. may engage subcontractors in the performance of the Agreement. It remains responsible for the performance of its obligations.

Article 16 — Compliance with Law

16.1 Anti-bribery and anti-corruption. Each Party warrants that it will comply with all applicable anti-bribery and anti-corruption laws, including the Dutch Criminal Code (Wetboek van Strafrecht) and, where relevant, the US Foreign Corrupt Practices Act and the UK Bribery Act 2010. Neither Party shall offer, promise, give, or accept any undue financial or other advantage in connection with the Agreement.

16.2 Sanctions and anti-money laundering. Each Party warrants that it will comply with applicable sanctions regimes, including those administered by the EU, the United Nations, the United Kingdom, and the United States, and with applicable anti-money laundering laws, including the Dutch Act on the Prevention of Money Laundering and Financing of Terrorism (Wet ter voorkoming van witwassen en financieren van terrorisme, "Wwft").

16.3 Export control. The Client warrants that it will not use the services or Deliverables in, or export or re-export them to, any country or to any person in violation of applicable EU, UK, or US export control laws or sanctions. The Client shall not use the services or Deliverables to provide any benefit to any person or entity subject to sanctions.

16.4 A breach of this Article constitutes a Material Breach entitling the non-breaching Party to terminate the Agreement with immediate effect under Article 14.2(d), without any cure period.

Article 17 — Notices

17.1 Notices under the Agreement shall be in writing and sent to the address specified in the Order Form or to such other address as a Party may designate in writing. Notice by email is effective on written confirmation of receipt by the recipient or on the next Working Day, whichever is earlier.

Article 18 — Governing Law and Disputes

18.1 The Agreement and any non-contractual obligations arising out of or in connection with it are governed exclusively by Dutch law. The applicability of the United Nations Convention on Contracts for the International Sale of Goods is excluded.

18.2 The Parties shall attempt in good faith to resolve any dispute arising out of or in connection with the Agreement through negotiation between authorised representatives.

18.3 If the dispute cannot be resolved by negotiation within thirty (30) days, the dispute shall be submitted to the exclusive jurisdiction of the District Court of Amsterdam (Rechtbank Amsterdam), the Netherlands. Nothing in this Article prevents either Party from seeking provisional measures from any competent court.

18.4 The Parties may agree in the Order Form to submit disputes, in addition to or instead of the jurisdiction set out in Article 18.3, to arbitration in accordance with the Arbitration Rules of the Foundation for the Settlement of Automation Disputes (Stichting Geschillenoplossing Automatisering, "SGOA"), with seat in The Hague, the Netherlands.

Article 19 — Miscellaneous

19.1 Severability. If any provision of these General Terms and Conditions is or becomes invalid, void, or unenforceable, the remaining provisions shall continue in full force and effect. The invalid provision shall be replaced by a valid provision that approximates the original commercial intent as closely as possible.

19.2 Waiver. Failure or delay by either Party in exercising any right under the Agreement does not constitute a waiver of that right. Any waiver must be in writing to be effective.

19.3 No Partnership. Nothing in the Agreement creates a partnership, joint venture, agency, or employer-employee relationship between the Parties.

19.4 Electronic Signatures. The Parties agree that electronic signatures have the same legal effect as handwritten signatures.

19.5 Language. These General Terms and Conditions are published in Dutch and are available in an English courtesy translation. In the event of any inconsistency between the language versions, the Dutch version shall prevail.


Chapter 2 — Consultancy Services

This Chapter applies when the Agreement covers advisory, analysis, model development, or other deliverable-based services (together, "Consultancy Services"), in addition to Chapter 1.

Article 20 — Performance of Consultancy Services

20.1 Risk at Work B.V. performs Consultancy Services independently and at its own discretion, not under the direction or supervision of the Client.

20.2 Risk at Work B.V. determines the manner in which, and the persons by whom, Consultancy Services are performed. Risk at Work B.V. is entitled, after consultation with the Client, to replace assigned personnel with other persons of equivalent qualifications.

20.3 If the Consultancy Services are to be performed in phases, Risk at Work B.V. may suspend work on subsequent phases until the Client has approved the results of the preceding phase in writing and has paid all amounts then due.

Article 21 — Additional Work and Change Requests

21.1 Work or performance requested by the Client that falls outside the agreed scope ("Additional Work") shall be compensated at Risk at Work B.V.'s standard rates, unless otherwise agreed in writing.

21.2 Risk at Work B.V. is not obliged to perform Additional Work and may require that a separate written agreement or amendment to the Order Form be concluded before commencing Additional Work.

21.3 The Client accepts that Additional Work may affect timelines and the allocation of responsibilities between the Parties. A request for Additional Work does not constitute grounds for termination or dissolution of the Agreement.

Article 22 — Acceptance and Defects

22.1 The Client shall inspect Deliverables promptly upon receipt and, in any event, within twenty (20) Working Days or such longer period as is reasonable given the nature and complexity of the Deliverable ("Acceptance Period"). Any defects or non-conformities must be reported in writing to Risk at Work B.V. within the Acceptance Period, with sufficient detail to enable investigation.

22.2 If the Client does not report defects within the Acceptance Period, the Deliverable shall be deemed accepted.

22.3 If timely reported defects are attributable to Risk at Work B.V., Risk at Work B.V. shall remedy them without charge within a reasonable period. If remediation is not technically or reasonably possible, Risk at Work B.V. may credit the fees paid for the affected Deliverable, in which case the Client shall have no further claim on account of the defect.

22.4 Defects arising from incorrect or incomplete information provided by the Client, modification of the Deliverable by the Client or a third party, or use of the Deliverable outside its intended purpose are not attributable to Risk at Work B.V..


Chapter 3 — Software and SaaS

This Chapter applies when the Agreement covers the provision of software, whether licensed for installation by the Client or made available as a service (together, "Software Services"), in addition to Chapter 1.

Article 23 — Licence Grant and Scope

23.1 Subject to the Client's compliance with the Agreement and payment of all fees due, Risk at Work B.V. grants the Client a non-exclusive, non-transferable, non-sublicensable licence to use the Software Services during the term of the Agreement, for the Client's internal business purposes, within the scope set out in the Order Form (including any limits on users, seats, volumes, or use cases).

23.2 The Client shall not, and shall not permit any third party to: (a) reverse engineer, decompile, or disassemble the software except to the extent permitted by mandatory law; (b) copy, modify, or create derivative works of the software; (c) circumvent technical protection measures; (d) resell, sublicense, or provide the software as a service to third parties; (e) use the software to develop or provide any competing product or service; or (f) remove or alter any proprietary notices.

23.3 Risk at Work B.V. may apply technical measures to enforce the scope of the licence, including but not limited to user authentication, usage metering, and feature gating.

Article 24 — Service Availability and Maintenance

24.1 Where an SLA is incorporated into the Agreement, Risk at Work B.V. shall make commercially reasonable efforts to meet the service levels set out therein. In the absence of an SLA, Risk at Work B.V. shall provide Software Services with a level of availability reasonable given the nature of the service.

24.2 Risk at Work B.V. may perform scheduled maintenance and updates. Scheduled maintenance shall, where reasonably practicable, be notified in advance and performed outside normal business hours. Emergency maintenance may be performed at any time where necessary to preserve the security or integrity of the Software Services.

24.3 Risk at Work B.V. may update, modify, or deprecate features of the Software Services in the course of ongoing development, provided that such changes do not materially reduce the core functionality of the Software Services. Deprecation of features shall be notified with reasonable advance notice.

24.4 Risk at Work B.V. does not warrant that the Software Services will be uninterrupted or error-free. The Client acknowledges that internet and cloud infrastructure involve inherent risks of unavailability, latency, and data loss.

Article 25 — Client Data and Security

25.1 As between the Parties, the Client retains all right, title, and interest in the Client's data, including Personal Data, submitted to or processed by the Software Services ("Client Data").

25.2 Risk at Work B.V. shall process Client Data only for the purposes of providing the Software Services and performing its obligations under the Agreement, and in accordance with the DPA where applicable.

25.3 Risk at Work B.V. shall implement appropriate technical and organisational measures to protect Client Data, as set out in the DPA and in any security documentation referenced in the Order Form. The Client is responsible for evaluating the adequacy of these measures for its own regulatory and risk requirements.

25.4 The Client is responsible for the lawfulness of the Client Data it provides, for obtaining any necessary consents, and for managing user access credentials. Risk at Work B.V. is not liable for damage resulting from the Client's failure to do so, or from use of the Software Services by persons authorised by the Client (whether or not such use was authorised).

Article 26 — Acceptable Use

26.1 The Client shall not use the Software Services to: (a) violate applicable law; (b) infringe the rights of any third party; (c) transmit malware or content that is unlawful, defamatory, or harmful; (d) attempt to gain unauthorised access to Risk at Work B.V.'s systems or those of other clients; or (e) interfere with the integrity or performance of the Software Services.

26.2 Risk at Work B.V. may suspend access to the Software Services, in whole or in part, without prior notice, where continued use poses a material risk to the security, integrity, or lawful operation of the Software Services, or where required by law or regulatory order. Risk at Work B.V. shall restore access as soon as reasonably practicable after the underlying cause has been addressed.

Article 27 — Fees and Usage

27.1 Fees for Software Services may include subscription fees, one-time fees, and usage-based fees, as specified in the Order Form. Subscription fees are invoiced in advance; usage-based fees are invoiced in arrears based on Risk at Work B.V.'s records, which are conclusive for billing purposes absent manifest error.

27.2 The Client shall pay for usage exceeding any allocations specified in the Order Form at Risk at Work B.V.'s standard overage rates. Unused allocations do not carry over between periods and are non-refundable.

Article 28 — Information and Audit

28.1 On reasonable written request by the Client, and no more than once in any twelve-month period except where required by applicable law or regulator, Risk at Work B.V. shall provide information reasonably necessary for the Client to verify Risk at Work B.V.'s compliance with the Agreement in respect of the Software Services. Where Risk at Work B.V. holds third-party certifications or audit reports (such as ISO 27001 or SOC 2) relevant to the request, provision of the relevant certificate or report shall discharge Risk at Work B.V.'s obligations under this Article.

28.2 Audit activity shall be conducted during normal business hours, on reasonable prior notice, shall not unreasonably interfere with Risk at Work B.V.'s operations, and shall be subject to confidentiality. The Client shall bear its own costs and shall reimburse Risk at Work B.V.'s reasonable costs of cooperation.

28.3 Where the Client is a financial entity subject to Regulation (EU) 2022/2554 on digital operational resilience (DORA) and the Software Services constitute an ICT service to the Client, the Parties shall agree additional audit, information-provision, and incident-reporting terms in a DORA-specific addendum referenced in the Order Form.

Article 29 — Data Export, Deletion, and Exit Assistance

29.1 For a period of thirty (30) days following termination of the Agreement, Risk at Work B.V. shall make Client Data available for export in a commonly used, machine-readable format, subject to the Client's compliance with any outstanding payment obligations.

29.2 After expiry of the export period, Risk at Work B.V. shall delete Client Data from its active systems within a further reasonable period, save to the extent that retention is required by law or for the legitimate protection of Risk at Work B.V.'s rights. Backup copies shall be deleted or overwritten in the ordinary course of Risk at Work B.V.'s backup retention cycle. On written request, Risk at Work B.V. shall confirm completion of deletion.

29.3 The Client is responsible for exporting Client Data within the export period. Risk at Work B.V. is not liable for Client Data deleted after the export period in accordance with this Article.

29.4 Exit assistance. On the Client's written request made no later than thirty (30) days before the effective date of termination, Risk at Work B.V. shall provide reasonable transition assistance on commercial terms, for a period not exceeding ninety (90) days from the termination date, to facilitate the Client's migration to an alternative provider or to in-house operation. Exit assistance shall be charged at Risk at Work B.V.'s standard rates, unless otherwise agreed.

Article 30 — Sub-processors and Infrastructure

30.1 Risk at Work B.V. may engage sub-processors in the provision of Software Services. The current list of sub-processors is published at a URL specified in the DPA or on Risk at Work B.V.'s website, and is updated in accordance with the DPA.

30.2 Risk at Work B.V. hosts Software Services on infrastructure located within the European Economic Area, except where otherwise specified in the Order Form or DPA. Any cross-border transfer of Personal Data shall be carried out in accordance with the DPA.


Chapter 4 — AI Services

This Chapter applies when the Agreement involves the development, provision, or use of artificial intelligence components, including machine learning models, generative AI, or AI-powered software features (together, "AI Services"), in addition to Chapter 1 and, where applicable, Chapters 2 and 3.

Article 31 — Nature and Limitations of AI Services

31.1 The Client acknowledges that AI Services rely on probabilistic algorithms and machine learning techniques that, by their nature, may produce outputs that are inaccurate, incomplete, biased, outdated, or otherwise inappropriate for the Client's intended use. This is an inherent characteristic of AI systems and not a defect.

31.2 Risk at Work B.V. does not warrant the accuracy, completeness, reliability, freedom from third-party rights, or fitness for any particular purpose of outputs produced by AI Services. Any metric, benchmark, or performance indication communicated by Risk at Work B.V. is indicative and does not constitute a guarantee.

31.3 The Client is solely responsible for validating outputs before relying on them or acting on them, and for determining whether outputs are suitable for the Client's intended use.

Article 32 — No Regulated Advice

32.1 Outputs produced by AI Services do not constitute and shall not be relied upon as investment advice, actuarial advice, financial advice, tax advice, legal advice, medical advice, or any other form of regulated professional advice, regardless of the subject matter of the outputs or the capacity in which the Client receives them.

32.2 Where outputs are used to inform decisions that have regulatory, supervisory, or fiduciary consequences — including decisions affecting regulatory capital, pricing, solvency, creditworthiness, risk classification, or the provision of advice to end customers — such outputs shall be reviewed, validated, and approved by a qualified human professional before being acted on. The Client is responsible for implementing this review.

Article 33 — Client Disclosure Obligations

33.1 Where the Client integrates AI Services into a product or service offered to end users, the Client shall provide clear, accurate, and legally compliant information to those end users concerning the involvement, capabilities, and limitations of the AI Services, including any applicable disclosures required by law.

33.2 The Client shall obtain all consents and legal bases required for the processing of data by AI Services, including in respect of any Personal Data used for inference or improvement of models.

Article 34 — Data, Models, and AI Artefacts

34.1 Client Data. Data provided by or on behalf of the Client for use with AI Services ("Client Data") remains the property of the Client. Risk at Work B.V. processes Client Data only for the purposes of providing AI Services and in accordance with the Agreement.

34.2 Provider IP. All Intellectual Property Rights in Risk at Work B.V.'s AI models, including base models, weights, architectures, training pipelines, prompts, and documentation, remain exclusively with Risk at Work B.V. or its licensors. Where Risk at Work B.V. applies fine-tuning, parameter-efficient adaptation, or similar techniques using Client Data, the resulting adapted models and weights constitute Risk at Work B.V. Intellectual Property, subject to the following.

34.3 Carve-out for Client-confidential weights. Where adapted models are fine-tuned on Client Data that constitutes Confidential Information, Risk at Work B.V. shall not deploy such adapted models for the benefit of any third party. On written request by the Client during the term of the Agreement or within thirty (30) days of its termination, Risk at Work B.V. shall delete such adapted models from its active systems within a reasonable period. Backup copies shall be deleted or overwritten in the ordinary course of Risk at Work B.V.'s backup retention cycle. Risk at Work B.V.'s right to use the underlying general methods, techniques, and know-how remains unaffected in accordance with Article 8.3.

34.4 Outputs. Subject to the Client's payment of fees due, the Client owns the specific outputs generated by AI Services for the Client's use, without prejudice to the rights of third parties in any pre-existing material from which such outputs are derived, and without prejudice to Risk at Work B.V.'s rights in the underlying AI Services.

34.5 Training data. Risk at Work B.V. shall not use Client Data to train general-purpose or multi-tenant AI models, except with the Client's prior written consent or where Client Data has been irreversibly anonymised such that it cannot be re-identified.

Article 35 — EU AI Act Allocation

35.1 The Parties acknowledge that Regulation (EU) 2024/1689 (the "AI Act") allocates obligations between the "provider" and the "deployer" of an AI system. The applicable role of each Party shall be determined by reference to the factual circumstances of the particular use case.

35.2 Where Risk at Work B.V. supplies an AI system for the Client's use, the Client shall be the deployer within the meaning of the AI Act unless otherwise expressly agreed. The Client acknowledges that deployer obligations under the AI Act may include, depending on the classification of the AI system: implementing human oversight measures, monitoring the operation of the system, maintaining logs where these are under its control, informing affected natural persons of their exposure to the system, and cooperating with competent authorities. The Client is responsible for complying with its deployer obligations.

35.3 Where the Client places an AI system on the market or into service under its own name or trademark, or where the Client substantially modifies an AI system supplied by Risk at Work B.V., the Client shall assume the obligations of a provider under the AI Act in respect of such system.

35.4 The Parties shall cooperate in good faith to provide each other with the information reasonably necessary for the fulfilment of their respective obligations under the AI Act, subject to the protection of Confidential Information and Intellectual Property Rights.

Article 36 — Prohibited and High-Risk Use Cases

36.1 The Client shall not use AI Services for any purpose prohibited by the AI Act or applicable law, including the practices listed in Article 5 of the AI Act.

36.2 Any use of AI Services for a purpose classified as high-risk under Annex III of the AI Act — including, without limitation, credit scoring, insurance risk assessment and pricing, and creditworthiness evaluation affecting natural persons — requires a prior written agreement between the Parties setting out the additional technical, organisational, and contractual measures required to ensure compliance with the AI Act. The Client shall notify Risk at Work B.V. in writing before any such use is commenced.


Annexes

  • Annex A — Data Processing Addendum (DPA) [separate document, incorporated by reference]
  • Annex B — Service Level Agreement [separate document, applicable when Chapter 3 applies and an SLA is specified in the Order Form]
  • Annex C — List of Sub-processors [published at /trust/sub-processors, updated in accordance with the DPA]

These General Terms and Conditions are filed with the Chamber of Commerce under number 72356219 and available at /legal/tos/v1.