Liability Limited to EUR 50,000
Direct damages are capped at EUR 50,000; indirect damages are excluded.
🌐 www.sophyco.com
The document includes a data processing agreement with security measures (e.g., HTTPS, encryption, backups) and defines roles (controller/processor), but uses weak MD5 hashing and allows broad data collection for unspecified purposes.
References GDPR and includes a processor agreement with user rights and breach notification, but lacks explicit mention of CCPA or other laws, and the liability cap may conflict with GDPR requirements.
Heavily favors the provider with unilateral modification rights, broad liability waivers, and limited user recourse; the client waives rights to rescind and bears most costs and risks.
The policy is lengthy and legalistic, with complex Dutch terms and limited plain language explanations; key risks (e.g., data use, liability) are buried in dense text.
- The terms define "Klant" (Client) as a business, but the actual service appears to be marketed to freelancers and small business owners, who may be natural persons acting in a professional capacity. This creates a mismatch between the defined user and the actual user, potentially leading to unenforceable clauses regarding consumer protections.
- The provider reserves the right to unilaterally change the terms at any time by posting the modified version. The client's only recourse is to terminate the subscription, creating an imbalance of power.
- The provider can adjust the scope of the Platform or Services. If such adjustments substantially change the client's procedures, the client bears the costs of this adjustment unless it relates to changes in applicable law.
- The provider may continue or modify the Platform using a new or modified version and is not obligated to maintain specific features. This gives the provider broad control over service features without client consent.
- The client waives the right to extrajudicially dissolve the agreement, except where explicitly granted in the terms. This severely limits the client's remedies for breach of contract.
- The provider’s liability for direct damages is capped at the total fees (excl. VAT) agreed for one year, with an absolute maximum of EUR 50,000. This cap applies even if the provider’s fault is the cause.
- Liability for indirect damages, including lost profits, consequential damages, and data loss, is entirely excluded. This excludes common types of business damages that could reasonably occur from service failure.
- The client indemnifies the provider for all claims from third parties arising from using the platform, including misuse. This is a broad and potentially unlimited indemnity obligation.
- The provider can immediately terminate the agreement and demand all outstanding payments if the client files for bankruptcy or ceases business, without any liability.
- The client must pay for any support requests that exceed two man-hours per month, and for changes requested due to their specific industry regulations. The cost of these is not predetermined.
- The client is responsible for the safe storage of access credentials, and the risk of data loss transfers to the client once data is made available to them. This may create unfair liability for data breaches.
- The provider disclaims all warranties regarding the security and error-free operation of the Platform, stating it only uses reasonable efforts. This significantly reduces its accountability for service disruptions.
- The appendix is titled "Verwerkersovereenkomst" (Processor Agreement), but the definitions seem to reverse the roles: "Verwerkingsverantwoordelijke" (Controller) is defined as Sophy &Co. and "Verwerker" (Processor) as the Client. This is a critical error that would misassign legal responsibilities for data protection under the AVG/GDPR.
- Even if the role definitions in the appendix are corrected, the client is required to pay for the provider's audit results and for the provider’s compliance with data subject rights requests, at the provider’s then-current hourly rate.
- Upon termination, the client must pay for the provider’s efforts to return or delete personal data, also at the provider’s hourly rate. This creates a financial barrier to data portability.
- The provider stores passwords using MD5 hashes, which is an outdated and cryptographically weak algorithm for password storage, posing a significant security risk.
- All disputes are subject to the exclusive jurisdiction of the court in Breda, which could be inconvenient and expensive for a client not located in that area.
- The general terms and conditions of the client are explicitly rejected, even if the provider does not object to a reference to them. This creates a take-it-or-leave-it contract with no room for the client's own standard terms.
Direct damages are capped at EUR 50,000; indirect damages are excluded.
The supplier may change the terms; the customer may terminate the agreement in case of objection.
The customer bears the risk of loss, theft, or damage to data.
The supplier does not guarantee that the platform will operate without problems or interruptions.
Both parties may terminate the agreement subject to a one-month notice period.
Install the free Termzy AI browser extension and get instant AI-powered analysis of any legal document you encounter online.
Add Termzy AI to the Browser - It's Free