Customer Environment Access Addendum

This Addendum forms part of and supplements the Agreement between Spotler Limited (“Spotler”) and
Customer. Capitalised terms not defined in this Addendum shall have the meaning given to them in the
Agreement.

  1.  Purpose and Scope
    1. Customer may request that Spotler perform support, consultancy, implementation, troubleshooting,
      configuration, remediation, migration, or other agreed services within systems, platforms, environments,
      applications, accounts, or tools that are owned, licensed, managed, or controlled by Customer or by
      Customer’s third-party providers (“Customer Tooling”).
    2. This Addendum applies whenever Spotler is granted direct or indirect access to Customer Tooling,
      including through named user accounts, shared accounts, delegated administration, screen sharing,
      remote sessions, API keys, tokens, VPN credentials, SSO access, or any other access mechanism.
    3. The Parties acknowledge that Customer Tooling is not operated or controlled by Spotler and that
      Spotler’s actions within such environment are dependent on the permissions, configurations, restrictions,
      integrations, safeguards, and operating conditions determined by Customer and/or its third-party
      providers.
  2. Customer Instruction and Authorisation
    1. Customer expressly instructs and authorises Spotler to access and use the Customer Tooling solely for
      the purpose of performing the services requested by Customer.
    2. Customer represents and warrants that: (a) it is entitled to grant Spotler access to the Customer
      Tooling; (b) it has obtained all required internal approvals and, where applicable, third-party permissions;
      (c) the requested activities are lawful and do not violate any agreement, policy, regulatory obligation, or
      third-party right applicable to Customer; and (d) the Customer representative issuing instructions to
      Spotler is duly authorised to do so.
    3. Spotler shall be entitled to rely on instructions and approvals received from Customer’s designated
      contacts unless Spotler has actual knowledge that such instruction or approval is unauthorised.
  3. Access Governance and Customer Responsibilities
    1. Customer shall remain fully responsible for: (a) provisioning and managing access rights to the
      Customer Tooling; (b) determining the scope of permissions granted to Spotler; (c) ensuring that the
      permissions granted are appropriate and limited to what Customer deems necessary; (d) maintaining
      backups, version history, recovery capabilities, and business continuity measures within the Customer
      Tooling; (e) reviewing and approving any material changes where Customer deems such approval
      necessary; and (f) the overall security, resilience, compliance, availability, integrity, and lawful use of the
      Customer Tooling.
    2. Customer shall, where reasonably possible, provide Spotler with access on a least-privilege basis and
      through individually attributable credentials. Shared credentials should be avoided unless Customer
      determines otherwise at its own responsibility.
    3. Customer is solely responsible for ensuring that adequate logging, monitoring, alerting, and approval
      workflows exist within the Customer Tooling.
  4. Spotler Obligations When Accessing Customer Tooling
    1. Spotler shall use the Customer Tooling only: (a) on Customer’s documented or otherwise demonstrable
      request; (b) for the duration necessary to perform the requested services; and (c) within the limits of the
      access rights granted by Customer.
    2. Spotler shall act with reasonable skill and care and in accordance with the Agreement.
    3. Spotler shall, where reasonably practicable: (a) use individually attributable access credentials made
      available by Customer; (b) keep records of material actions performed in the context of the requested
      services; (c) notify Customer without undue delay of any detected security incident, error, or irregularity
      materially affecting the requested services; and (d) cooperate in good faith with Customer in relation to
      access review, incident handling, and post-activity follow-up.
    4. Spotler shall not be responsible for validating the commercial, operational, or legal desirability of
      Customer’s requested actions within the Customer Tooling unless such validation is expressly included in
      the agreed services.
  5. Allocation of Risk for Customer Tooling
    1. Customer acknowledges and agrees that actions performed by Spotler within the Customer Tooling are
      performed: (a) in an environment selected, controlled, and maintained by Customer and/or its third-party
      providers; (b) on the basis of Customer’s own instructions, approvals, and granted permissions; and (c)
      subject to the technical limitations, defects, vulnerabilities, interoperability issues, misconfigurations,
      outages, data structures, and processing logic inherent in the Customer Tooling.
    2. Accordingly, Spotler shall not be liable for any damage, loss, corruption, deletion, disclosure,
      interruption, delay, failed execution, misrouting, configuration conflict, security weakness, loss of audit
      trail, or other any other adverse consequence arising out of or related to: (a) the design, operation,
      availability, or security of the Customer Tooling; (b) access rights, permissions, approval flows, or
      authentication mechanisms determined by Customer; (c) actions taken by Spotler in accordance with
      Customer’s request or instructions; (d) inaccurate, incomplete, outdated, or misleading information or
      approvals provided by Customer; (e) acts or omissions of Customer, its employees, affiliates, contractors,
      administrators, or other third parties with access to the Customer Tooling; or (f) failures or acts of third
      party vendors, subprocessors, cloud providers, or software providers engaged by Customer.
  6. Exclusion and Limitation of Liability
    1. To the maximum extent permitted by applicable law, Spotler shall have no liability for any indirect loss
      or damage in connection with access to or activities within Customer Tooling, including loss of profit, loss
      of revenue, loss of goodwill, business interruption, loss of anticipated savings, loss of opportunity, or loss
      or corruption of data.
    2. To the extent Spotler is held liable notwithstanding Clause 5, such liability shall be subject to the
      exclusions, limitations, procedures, thresholds, and caps set out in the Agreement, including the
      applicable liability regime under the General Terms and Conditions and, where relevant, the Data
      Processing Agreement.
    3. Nothing in this Addendum shall exclude or limit liability which cannot lawfully be excluded or limited
      under the laws of England and Wales.
  7. Customer Indemnity
    1. Customer shall indemnify, defend, and hold harmless Spotler against third-party claims, losses,
      damages, liabilities, costs, and expenses arising out of or related to: (a) Customer’s lack of authority to
      grant access to the Customer Tooling; (b) Customer’s breach of contract, law, or third-party rights in
      connection with the requested access or activities; (c) claims by Customer’s own customers, users,
      employees, vendors, or regulators resulting from actions performed by Spotler in accordance with
      Customer’s instructions; or (d) the operation, use, or malfunction of the Customer Tooling, except to the
      extent finally determined by the courts of England and Wales to have been caused by Spotler’s fraud or
      deliberate wrongdoing.
  8. Security, Compliance, and Incident Cooperation
    1. Each Party shall remain responsible for compliance with the legal and regulatory obligations that apply
      to it in relation to the activities under this Addendum.
    2. Where Spotler’s access to Customer Tooling involves personal data, the Parties’ data protection
      obligations shall remain governed by the Agreement and any applicable data processing agreement.
    3. Spotler maintains information security controls as part of its security governance framework.
    4. In the event of a suspected or actual security incident related to Spotler’s access to the Customer
      Tooling, the Parties shall cooperate in good faith, each within the boundaries of its own systems,
      responsibilities, and legal obligations.
  9. Audit Trail and Evidence
    1. Customer is responsible for enabling and retaining logs in the Customer Tooling environment to the
      extent Customer considers such logging necessary for internal control, compliance, audit, or forensic
      purposes.
    2. Where reasonably practicable and proportionate, Spotler shall maintain internal records of material
      service activities performed under this Addendum.
    3. Any audit or information request relating to Spotler’s performance under this Addendum shall be
      subject to the audit and cooperation regime agreed between the Parties under the Agreement.
  10. Suspension or Refusal of Access
    1. Spotler may refuse, suspend, or limit access to Customer Tooling where: (a) the requested instruction
      is unlawful, unsafe, or unreasonable in the circumstances; (b) Spotler reasonably believes the requested
      activity may create disproportionate security, compliance, or operational risk; (c) Customer has not
      provided sufficient authority, information, or access conditions; or (d) continued access would breach
      Spotler’s internal security requirements or contractual obligations.
  11. Term and Survival
    1. This Addendum enters into force on the Effective Date of the Agreement or, if later, on the date
      Customer first grants Spotler access to Customer Tooling.
    2. This Addendum shall remain in effect for as long as Spotler has, or may reasonably be deemed to
      have, access to Customer Tooling under the Agreement.
    3. Clauses relating to liability, indemnity, confidentiality, data protection, audit trail, governing law, and
      dispute resolution shall survive termination.
  12. Order of Precedence
    1. This Addendum forms part of the Agreement.
    2. In the event of conflict between this Addendum and the Agreement, this Addendum shall prevail solely
      with respect to access to and activities within Customer Tooling. For all other matters, the Agreement shall
      remain in full force and effect.
  13. Governing Law and Jurisdiction
    1. This Addendum and any dispute or claim arising out of or in connection with it shall be governed by the
      laws of England and Wales.
    2. The courts of England and Wales shall have exclusive jurisdiction to settle any dispute or claim arising
      out of or in connection with this Addendum.