1. Definitions
- Agreement
- These Terms, together with the Order Form, the DPA and any documents they expressly incorporate.
- Customer, you
- The organisation named on the Order Form.
- Customer Data
- All data, records, documents and content that you or your Users upload to, or generate within, the Service.
- Competent Authority
- The national aviation authority responsible for your approval, or EASA where it acts as competent authority.
- Order Form
- The ordering document signed by both parties recording the plan, User numbers, term and fees.
- Part-IS
- Commission Delegated Regulation (EU) 2022/1645 and Commission Implementing Regulation (EU) 2023/203, establishing information security management requirements for organisations in civil aviation, together with their Annexes.
- Service
- The Wingcert platform made available at app.wingcert.com and any other workspace or mobile application we provide under the Order Form.
- User
- An individual authorised by you to access the Service under your account.
2. The agreement
- These Terms govern your use of the Service. By signing an Order Form, or by accessing the Service, you agree to them.
- If you are agreeing on behalf of an organisation, you confirm you have authority to bind it.
- If there is a conflict, the order of precedence is: (i) the Order Form; (ii) the DPA; (iii) these Terms. Any purchase order or supplier portal terms you issue have no effect, even if we acknowledge them.
3. The service
- We grant you a non-exclusive, non-transferable right to access and use the Service during the term, for your internal business purposes, subject to the Agreement.
- The Service may be delivered through several workspaces — for example a compliance workspace, a training workspace and an operations control workspace — each at its own address. Which of these you receive is set out in the Order Form.
- We may improve and modify the Service. We will not materially reduce its core functionality during a paid term; if we do, clause 17.5 applies.
- Features described as beta, preview or early access are provided as-is, may be withdrawn, and are excluded from clauses 12 and 13.
4. Orders, users and provisioning
- User subscriptions are for named individuals and may not be shared. A subscription may be reassigned to a replacement individual when the original User leaves the role.
- Read-only users — including inspectors, personnel of your Competent Authority, and colleagues who only view or acknowledge documents — do not consume a paid subscription.
- You may add Users at any time; additional Users are charged pro rata for the remainder of the then-current term. User counts may not be reduced mid-term.
- You are responsible for your Users' compliance with the Agreement, for keeping credentials secure, and for promptly deactivating Users who no longer require access.
- You must notify us without undue delay of any known or suspected unauthorised access to your account.
5. Fees and payment
- Fees are as stated on the Order Form. Unless stated otherwise, they are exclusive of VAT and other applicable taxes, which you pay in addition.
- Invoices are payable within [30] days of the invoice date, in the currency stated.
- Overdue amounts accrue interest at [the statutory rate under Directive 2011/7/EU on combating late payment / X% per annum] from the due date until payment.
- If an invoice is more than [30] days overdue we may suspend the Service on [14] days' written notice. We will not suspend access to your ability to export Customer Data, and we will not suspend where the amount is subject to a good-faith dispute you have raised in writing.
- Fees are non-refundable except where these Terms expressly say otherwise.
- We may change fees for a renewal term on at least [60] days' notice before the renewal date. If you do not accept the change you may decline renewal under clause 17.2.
- Where you are a public body or otherwise required to purchase through a tender, the Order Form may vary this clause.
6. Acceptable use
You must not, and must not permit any User to:
- use the Service unlawfully, or to store or transmit unlawful or infringing material;
- upload malicious code, or interfere with the integrity or performance of the Service;
- attempt to gain unauthorised access to the Service, other tenants' data, or our underlying infrastructure;
- reverse engineer, decompile or disassemble the Service, except to the extent that restriction is prohibited by applicable law;
- resell, sublicense or provide the Service as a service bureau to third parties, unless the Order Form expressly permits it;
- use the Service to build a competing product, or copy its features or user interface for that purpose;
- conduct penetration testing or vulnerability scanning without our prior written consent — which we will not unreasonably withhold, and which we grant readily where you need it for your own Part-IS assurance (see clause 11.6); or
- upload special categories of personal data under Article 9 GDPR unless strictly necessary and lawfully justified (see the Privacy Notice).
7. Regulatory responsibility
Wingcert is a tool you use to discharge your obligations. It is not a substitute for them, and using it does not transfer any part of your accountability to us.
- You remain solely responsible for compliance with all laws, regulations and conditions applicable to your approvals, including those issued under Regulation (EU) 2018/1139 and its implementing and delegated acts.
- You remain solely responsible for your exposition, CAME, MOE, management system manual and equivalent approved documents, and for the accuracy and completeness of the records you keep in the Service.
- Your accountable manager, nominated post-holders and compliance monitoring manager retain their responsibilities in full. Nothing in the Service or the Agreement relieves any of them.
- We do not provide regulatory, legal, airworthiness or safety advice. Requirement libraries, checklist templates, mappings and other reference content are provided as a starting point and must be reviewed and approved by you before use. They may not reflect the most recent amendment of a regulation, national variations, or the conditions attached to your particular approval.
- Automated alerts, expiry warnings, escalations and dashboards are aids. You must not rely on them as your sole means of detecting non-compliance, and their absence is not confirmation of compliance.
- You are responsible for configuring the Service correctly — including permissions, retention settings, approval workflows and the protection of confidential safety reports — so that it reflects your approved procedures.
- You are responsible for determining that the Service is suitable for your intended use before relying on it, and for maintaining alternative means of meeting your obligations during any period of unavailability.
8. Customer data and ownership
- As between the parties, you own all Customer Data and all rights in it. We acquire no rights other than those needed to provide the Service.
- You grant us a non-exclusive licence to host, copy, transmit, display and process Customer Data solely to provide, secure and support the Service, and as instructed under the DPA.
- You are responsible for the accuracy, quality and legality of Customer Data and for having the right to place it in the Service.
- We may generate aggregated, de-identified statistics about use of the Service and use them to operate and improve it. Such statistics will never identify you, your Users or any individual, and will not reveal Customer Data.
- We will not access Customer Data except: to provide the Service; to provide support you have requested; to investigate a security incident; or where legally compelled. Every such access is logged.
9. Our intellectual property
- We and our licensors own all rights in the Service, its software, design, documentation and the Wingcert name and marks. No rights are granted except as expressly stated.
- If you give us feedback or suggestions, we may use them without restriction or obligation to you. This does not give us any right to your Customer Data or Confidential Information.
10. Confidentiality
- Each party may receive information the other treats as confidential. The receiving party will protect it with at least reasonable care, use it only for the Agreement, and disclose it only to personnel and advisers who need it and are bound by equivalent duties.
- These duties do not apply to information that is public through no breach, was already known without duty, is independently developed, or is lawfully received from a third party.
- Disclosure compelled by law or by a Competent Authority is permitted, provided the disclosing party gives prompt notice where legally able, and discloses only what is required.
- Confidentiality obligations survive for [5] years after termination, and indefinitely for trade secrets and for confidential safety reports.
11. Data protection and information security (Part-IS)
- Where we process personal data on your behalf, we do so as processor under the Data Processing Agreement, which forms part of the Agreement.
- We maintain an information security management system and the technical and organisational measures described in our Security & Part-IS overview, which we will not materially degrade during the term.
Part-IS contracted activities
- You may be subject to Part-IS. Under IS.I.OR.235 (and IS.D.OR.235 for design and production organisations), where you contract any activity relevant to your information security management, you must ensure that the contracted activity complies with the regulation, that it works under your oversight, that the associated risks are managed, and that your Competent Authority can have access to the contracted organisation on request.
-
We support you in meeting that obligation. Specifically we will:
- work under your oversight in respect of the services we provide to you, and cooperate with your monitoring of them;
- provide the information you reasonably require to include our services in your information security risk assessment under IS.I.OR.205, including a description of the interfaces between our systems and yours;
- grant your Competent Authority, and EASA where it acts as such, access upon request to the extent necessary to determine continued compliance with the applicable requirements, including access to relevant records, personnel and — where reasonably required and subject to appropriate safeguards for other customers — our facilities; and
- flow equivalent obligations down to any sub-contractor we engage that is material to the security of the Service.
Incident notification
- If we become aware of an information security incident affecting the Service that could plausibly be relevant to your obligations, we will notify you without undue delay and in any event within [24] hours of becoming aware, and will provide the information reasonably available to us. We set this timeline deliberately inside the 72 hours you have under IS.I.OR.230 to report to your Competent Authority a condition representing a significant risk to aviation safety, and inside the 72 hours a controller has under Article 33 GDPR. We will continue to provide information as our investigation progresses, including the recovery and preventive actions taken, so that you can make your follow-up report.
- Determining whether an incident is reportable, and making any report to your Competent Authority, remains your decision and your responsibility. We will not make such a report on your behalf unless you instruct us in writing.
Audit
- Once per twelve-month period, and additionally after a security incident affecting you or where your Competent Authority requires it, you may audit our compliance with this clause 11 on [30] days' notice. Audits take place during business hours, must not unreasonably disrupt our operations, and must not compromise the confidentiality or security of other customers' data. We may satisfy an audit request by providing a current third-party assessment report where it fairly addresses the scope of your request; if it does not, the audit proceeds. Audits required by a Competent Authority under clause 11.4(c) are not subject to the frequency limit in this clause.
12. Availability and support
- We will use commercially reasonable efforts to make the Service available [99.5]% of the time each calendar month, excluding scheduled maintenance, emergency maintenance and force majeure.
- Scheduled maintenance is notified at least [48] hours in advance and is planned outside [06:00–20:00 UTC] wherever practicable.
- Support is provided in English by email to [email protected] during [business hours and days], with target response times per the Order Form or the applicable support schedule.
- Where the Order Form includes a service level agreement with service credits, those credits are your sole and exclusive remedy for failure to meet the availability commitment.
- The mobile field application is designed to operate offline. Availability commitments apply to the hosted Service, not to synchronisation performance on your devices or networks.
13. Warranties
- Each party warrants that it has the authority to enter into the Agreement.
- We warrant that the Service will perform materially in accordance with its then-current documentation, and that we will provide it with reasonable skill and care.
- We warrant that we will not knowingly introduce malicious code into the Service, and that we maintain the measures described in clause 11.2.
- Your exclusive remedy for breach of clause 13.2 is that we will use reasonable efforts to correct the non-conformity; if we cannot do so within a reasonable period, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
14. Disclaimers
- Except as expressly stated in clause 13, and to the maximum extent permitted by law, the Service is provided without warranties of any kind, whether express, implied or statutory, including implied warranties of merchantability, fitness for a particular purpose and non-infringement.
- We do not warrant that the Service will be uninterrupted or error-free, that it will detect every instance of non-compliance, or that its regulatory reference content is complete, current or applicable to your approval. Clause 7 applies.
- Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot lawfully be excluded.
15. Liability
- Subject to clause 14.3, neither party is liable for loss of profit, loss of revenue, loss of anticipated savings, loss of business or goodwill, or for indirect or consequential loss, however arising.
- Subject to clause 14.3, each party's total aggregate liability arising out of the Agreement in any twelve-month period is limited to [the total fees paid or payable by you in the twelve months preceding the event giving rise to the claim].
- The limit in clause 15.2 does not apply to [your obligation to pay fees; either party's breach of confidentiality; your indemnity under clause 16.1; and — subject to negotiation — liability for a data protection breach caused by our failure to implement the measures in Annex II of the DPA, which may be subject to a separate, higher cap].
- Each party must take reasonable steps to mitigate its loss.
- No claim may be brought more than [24] months after the claimant became aware, or should reasonably have become aware, of the facts giving rise to it.
Liability caps in aviation software are frequently negotiated upwards, and enterprise customers will push hard on clause 15.3. Set these figures with counsel and confirm your professional indemnity and cyber cover actually sits above whatever you commit to.
16. Indemnities
- You will indemnify us against claims arising from Customer Data, from your use of the Service in breach of the Agreement, or from your breach of clause 6.
- We will defend you against a third-party claim that the Service, used in accordance with the Agreement, infringes that party's intellectual property rights, and will pay damages finally awarded or agreed in settlement.
- Clause 16.2 does not apply to claims arising from Customer Data, from modifications not made by us, or from use of the Service in combination with anything we did not supply, where the claim would have been avoided but for that.
- If the Service becomes, or we believe it may become, the subject of a claim under clause 16.2, we may at our option procure the right to continue using it, modify it to be non-infringing, or terminate the affected subscription and refund prepaid fees for the unused remainder of the term.
- Each indemnity is conditional on the indemnified party giving prompt notice, allowing the indemnifying party to control the defence, and providing reasonable cooperation. No settlement admitting liability may be made without the indemnified party's consent, not to be unreasonably withheld.
17. Term and termination
- The Agreement starts on the date of the Order Form and runs for the initial term stated there.
- It renews automatically for successive periods equal to the initial term unless either party gives written notice of non-renewal at least [60] days before the end of the then-current term.
- Either party may terminate immediately on written notice if the other commits a material breach that is not remedied within [30] days of notice, or becomes insolvent or subject to equivalent proceedings.
- We may suspend access immediately where necessary to prevent material harm to the Service, to other customers, or to comply with law. We will restore access as soon as the cause is resolved, and will tell you why we suspended and what is required to restore.
- If we materially reduce the core functionality of the Service during a paid term, you may terminate on [30] days' notice and receive a pro-rata refund of prepaid fees for the unused remainder.
- Clauses 8, 9, 10, 14, 15, 16, 18, 22 and 23, and any clause that by its nature should survive, survive termination.
18. Exit and data return
You may have to produce records to your Competent Authority years after you stop using Wingcert. This clause exists so that ending the contract never puts your approval at risk.
- You may export Customer Data at any time during the term, in a structured, machine-readable format, together with the audit trail and attachments.
- For [60] days after termination or expiry we will retain Customer Data and provide reasonable assistance to export it. Suspension for non-payment does not remove your ability to export.
- After that period we will delete Customer Data from live systems, and from backups on the ordinary rotation cycle, unless you have instructed us in writing to retain it or we are legally required to.
- On request we will provide written confirmation of deletion.
- Where you require a longer archival period to meet a regulatory retention obligation, we will agree it in writing; additional fees may apply.
19. Changes to these terms
- We may amend these Terms. For material changes adverse to you we will give at least [30] days' notice by email or in-product.
- If you object to a material change, you may terminate on notice before it takes effect and receive a pro-rata refund of prepaid fees for the unused remainder of the term. Continued use after the effective date constitutes acceptance.
- Changes required by law or to address a security risk may take effect immediately, with notice as soon as practicable.
20. Force majeure
Neither party is liable for failure to perform caused by events beyond its reasonable control, including natural disaster, war, terrorism, civil unrest, epidemic, industrial action not involving its own workforce, failure of public telecommunications or power networks, and acts of government. The affected party must notify the other promptly and use reasonable efforts to mitigate. If the event continues for more than [60] days, either party may terminate on written notice. Payment obligations for services already delivered are not excused.
21. Export control and sanctions
Each party will comply with applicable export control and sanctions laws. You warrant that you are not, and are not owned or controlled by, a person subject to sanctions administered by the EU, the United Kingdom, the United States or the United Nations, and that you will not make the Service available to such a person or use it in a sanctioned territory in breach of those laws.
22. Governing law and disputes
- The Agreement and any non-contractual obligations arising from it are governed by the laws of [jurisdiction], excluding its conflict of laws rules and the UN Convention on Contracts for the International Sale of Goods.
- The courts of [jurisdiction] have exclusive jurisdiction, save that either party may seek injunctive relief in any competent court to protect its intellectual property or confidential information.
- Before commencing proceedings, the parties will attempt in good faith to resolve the dispute through escalation to senior representatives for [30] days. [Consider whether arbitration is preferable for cross-border enterprise customers.]
23. General
- Assignment. Neither party may assign the Agreement without the other's consent, not to be unreasonably withheld, except that either may assign in full to an affiliate or to a successor in a merger or sale of substantially all assets, on notice.
- Subcontracting. We may engage subcontractors and sub-processors to help provide the Service and remain responsible for their performance. Sub-processors are governed by the DPA.
- Notices. Notices must be in writing and sent to the addresses on the Order Form, or to [email protected] for us. Email is sufficient, except for notices of termination or of a claim, which must also be sent by post or courier.
- No partnership. Nothing creates a partnership, joint venture or employment relationship.
- Third parties. No one other than the parties has any right to enforce the Agreement, except that our affiliates may enforce clauses 9 and 15.
- Publicity. Neither party may use the other's name or marks publicly without prior written consent. [If you want a customer-logo right, negotiate it on the Order Form rather than here.]
- Severability. If any provision is held invalid, the rest remains in force and the invalid provision is replaced by one that most nearly achieves its intent.
- Waiver. Failure to enforce a provision is not a waiver of it.
- Entire agreement. The Agreement is the entire agreement between the parties on its subject matter and supersedes all prior discussions. Neither party relies on any statement not set out in it, save for fraudulent misrepresentation.
- Counterparts. The Order Form may be signed in counterparts, including electronically.
[Legal entity name, registered address, company number]