This Addendum forms part of and supplements the Agreement between Spotler Limited (“Spotler”) and
Customer. Capitalised terms not defined in this Addendum shall have the meaning given to them in the
Agreement.
Purpose and Scope
Customer may request that Spotler perform support, consultancy, implementation, troubleshooting,
configuration, remediation, migration, or other agreed services within systems, platforms, environments,
applications, accounts, or tools that are owned, licensed, managed, or controlled by Customer or by
Customer’s third-party providers (“Customer Tooling”).
This Addendum applies whenever Spotler is granted direct or indirect access to Customer Tooling,
including through named user accounts, shared accounts, delegated administration, screen sharing,
remote sessions, API keys, tokens, VPN credentials, SSO access, or any other access mechanism.
The Parties acknowledge that Customer Tooling is not operated or controlled by Spotler and that
Spotler’s actions within such environment are dependent on the permissions, configurations, restrictions,
integrations, safeguards, and operating conditions determined by Customer and/or its third-party
providers.
Customer Instruction and Authorisation
Customer expressly instructs and authorises Spotler to access and use the Customer Tooling solely for
the purpose of performing the services requested by Customer.
Customer represents and warrants that: (a) it is entitled to grant Spotler access to the Customer
Tooling; (b) it has obtained all required internal approvals and, where applicable, third-party permissions;
(c) the requested activities are lawful and do not violate any agreement, policy, regulatory obligation, or
third-party right applicable to Customer; and (d) the Customer representative issuing instructions to
Spotler is duly authorised to do so.
Spotler shall be entitled to rely on instructions and approvals received from Customer’s designated
contacts unless Spotler has actual knowledge that such instruction or approval is unauthorised.
Access Governance and Customer Responsibilities
Customer shall remain fully responsible for: (a) provisioning and managing access rights to the
Customer Tooling; (b) determining the scope of permissions granted to Spotler; (c) ensuring that the
permissions granted are appropriate and limited to what Customer deems necessary; (d) maintaining
backups, version history, recovery capabilities, and business continuity measures within the Customer
Tooling; (e) reviewing and approving any material changes where Customer deems such approval
necessary; and (f) the overall security, resilience, compliance, availability, integrity, and lawful use of the
Customer Tooling.
Customer shall, where reasonably possible, provide Spotler with access on a least-privilege basis and
through individually attributable credentials. Shared credentials should be avoided unless Customer
determines otherwise at its own responsibility.
Customer is solely responsible for ensuring that adequate logging, monitoring, alerting, and approval
workflows exist within the Customer Tooling.
Spotler Obligations When Accessing Customer Tooling
Spotler shall use the Customer Tooling only: (a) on Customer’s documented or otherwise demonstrable
request; (b) for the duration necessary to perform the requested services; and (c) within the limits of the
access rights granted by Customer.
Spotler shall act with reasonable skill and care and in accordance with the Agreement.
Spotler shall, where reasonably practicable: (a) use individually attributable access credentials made
available by Customer; (b) keep records of material actions performed in the context of the requested
services; (c) notify Customer without undue delay of any detected security incident, error, or irregularity
materially affecting the requested services; and (d) cooperate in good faith with Customer in relation to
access review, incident handling, and post-activity follow-up.
Spotler shall not be responsible for validating the commercial, operational, or legal desirability of
Customer’s requested actions within the Customer Tooling unless such validation is expressly included in
the agreed services.
Allocation of Risk for Customer Tooling
Customer acknowledges and agrees that actions performed by Spotler within the Customer Tooling are
performed: (a) in an environment selected, controlled, and maintained by Customer and/or its third-party
providers; (b) on the basis of Customer’s own instructions, approvals, and granted permissions; and (c)
subject to the technical limitations, defects, vulnerabilities, interoperability issues, misconfigurations,
outages, data structures, and processing logic inherent in the Customer Tooling.
Accordingly, Spotler shall not be liable for any damage, loss, corruption, deletion, disclosure,
interruption, delay, failed execution, misrouting, configuration conflict, security weakness, loss of audit
trail, or other any other adverse consequence arising out of or related to: (a) the design, operation,
availability, or security of the Customer Tooling; (b) access rights, permissions, approval flows, or
authentication mechanisms determined by Customer; (c) actions taken by Spotler in accordance with
Customer’s request or instructions; (d) inaccurate, incomplete, outdated, or misleading information or
approvals provided by Customer; (e) acts or omissions of Customer, its employees, affiliates, contractors,
administrators, or other third parties with access to the Customer Tooling; or (f) failures or acts of third
party vendors, subprocessors, cloud providers, or software providers engaged by Customer.
Exclusion and Limitation of Liability
To the maximum extent permitted by applicable law, Spotler shall have no liability for any indirect loss
or damage in connection with access to or activities within Customer Tooling, including loss of profit, loss
of revenue, loss of goodwill, business interruption, loss of anticipated savings, loss of opportunity, or loss
or corruption of data.
To the extent Spotler is held liable notwithstanding Clause 5, such liability shall be subject to the
exclusions, limitations, procedures, thresholds, and caps set out in the Agreement, including the
applicable liability regime under the General Terms and Conditions and, where relevant, the Data
Processing Agreement.
Nothing in this Addendum shall exclude or limit liability which cannot lawfully be excluded or limited
under the laws of England and Wales.
Customer Indemnity
Customer shall indemnify, defend, and hold harmless Spotler against third-party claims, losses,
damages, liabilities, costs, and expenses arising out of or related to: (a) Customer’s lack of authority to
grant access to the Customer Tooling; (b) Customer’s breach of contract, law, or third-party rights in
connection with the requested access or activities; (c) claims by Customer’s own customers, users,
employees, vendors, or regulators resulting from actions performed by Spotler in accordance with
Customer’s instructions; or (d) the operation, use, or malfunction of the Customer Tooling, except to the
extent finally determined by the courts of England and Wales to have been caused by Spotler’s fraud or
deliberate wrongdoing.
Security, Compliance, and Incident Cooperation
Each Party shall remain responsible for compliance with the legal and regulatory obligations that apply
to it in relation to the activities under this Addendum.
Where Spotler’s access to Customer Tooling involves personal data, the Parties’ data protection
obligations shall remain governed by the Agreement and any applicable data processing agreement.
Spotler maintains information security controls as part of its security governance framework.
In the event of a suspected or actual security incident related to Spotler’s access to the Customer
Tooling, the Parties shall cooperate in good faith, each within the boundaries of its own systems,
responsibilities, and legal obligations.
Audit Trail and Evidence
Customer is responsible for enabling and retaining logs in the Customer Tooling environment to the
extent Customer considers such logging necessary for internal control, compliance, audit, or forensic
purposes.
Where reasonably practicable and proportionate, Spotler shall maintain internal records of material
service activities performed under this Addendum.
Any audit or information request relating to Spotler’s performance under this Addendum shall be
subject to the audit and cooperation regime agreed between the Parties under the Agreement.
Suspension or Refusal of Access
Spotler may refuse, suspend, or limit access to Customer Tooling where: (a) the requested instruction
is unlawful, unsafe, or unreasonable in the circumstances; (b) Spotler reasonably believes the requested
activity may create disproportionate security, compliance, or operational risk; (c) Customer has not
provided sufficient authority, information, or access conditions; or (d) continued access would breach
Spotler’s internal security requirements or contractual obligations.
Term and Survival
This Addendum enters into force on the Effective Date of the Agreement or, if later, on the date
Customer first grants Spotler access to Customer Tooling.
This Addendum shall remain in effect for as long as Spotler has, or may reasonably be deemed to
have, access to Customer Tooling under the Agreement.
Clauses relating to liability, indemnity, confidentiality, data protection, audit trail, governing law, and
dispute resolution shall survive termination.
Order of Precedence
This Addendum forms part of the Agreement.
In the event of conflict between this Addendum and the Agreement, this Addendum shall prevail solely
with respect to access to and activities within Customer Tooling. For all other matters, the Agreement shall
remain in full force and effect.
Governing Law and Jurisdiction
This Addendum and any dispute or claim arising out of or in connection with it shall be governed by the
laws of England and Wales.
The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising
out of or in connection with this Addendum.