ProAuth Software Licence Agreement
Agreement version: 3.0-2026-09-28
Version date: 28 September 2026
This version applies to Orders that expressly incorporate it. It does not automatically replace the terms of existing Orders.
1. Parties, scope and acceptance
1.1 This Software Licence Agreement (the Agreement) is between 4tecture GmbH, Industriestrasse 25, 8604 Volketswil, Switzerland (4tecture), and the business or public-sector organisation identified in the applicable Order (Customer). It governs the licensing of ProAuth as self-hosted software and the associated support and upgrade services expressly purchased. It is intended exclusively for customers acting in their business or professional capacity, not for consumer purchases.
1.2 An Order is a quotation, order form or electronic order that identifies this Agreement by version, specifies the purchased entitlements and is accepted by both parties. Customer must receive an opportunity to read, download and retain this Agreement and incorporated schedules before accepting. Acceptance may be by signature, electronic signature or an explicit electronic acceptance recorded with the Order. A person accepting for an organisation represents that they are authorised to bind it. Downloading a new software release alone does not replace previously agreed terms.
1.3 The Software means the ProAuth executable software, container images and accompanying proprietary components supplied under the Order, including covered updates. Documentation means the applicable product documentation and specifications supplied or identified in the Order. Source code is not supplied or licensed unless expressly agreed. Separately licensed client libraries, open-source components and third-party materials are addressed in section 12.
1.4 In a conflict, the following order of precedence applies: (a) a signed amendment expressly identifying the provision changed; (b) an agreed data processing agreement for its data-protection subject matter; (c) the Order, including expressly identified negotiated departures; (d) this Agreement; and (e) incorporated product or support schedules. Customer purchase-order terms do not apply merely because 4tecture accepts an order number, receives payment or performs services. Any departure requires 4tecture's express agreement.
1.5 An incorporated schedule must be identified by date or version and made available before acceptance. Subsequent website edits do not change an existing Order. Descriptions of future functionality are not delivery commitments unless expressly included in an Order. Nothing in this section excludes liability for fraud or other liability that cannot lawfully be excluded.
2. Licence grant and permitted users
2.1 Subject to this Agreement and payment of the applicable fees, 4tecture grants Customer a non-exclusive, worldwide right to install and use the Software and Documentation within the scope of the Order and sections 3–5. The licence is non-transferable and non-sublicensable except as expressly permitted here or required by mandatory law. Worldwide use remains subject to section 18.
2.2 Customer may use ProAuth to authenticate and authorise its employees, contractors, partners and customers, including users of Customer's own commercial applications and SaaS services. This permitted use does not itself constitute resale of ProAuth. There is no per-user, per-authentication, CPU, node, container or replica licence charge under this Agreement. Edition features and the configuration limits stated in the Order still apply.
2.3 Only Customer and its subsidiaries expressly identified by legal name in the Order may share the licensed deployment. A Permitted Subsidiary is an entity so identified and controlled by Customer through ownership of more than 50% of voting rights or equivalent power to direct management, for as long as that control continues. Customer is responsible for each Permitted Subsidiary's compliance as for its own conduct. Parent companies, sister companies and other group entities are not included by this permission. Each separate production installation requires its own licence; sharing the licensed installation does not create an additional deployment entitlement.
2.4 Customer may engage hosting providers, managed service providers and other contractors to install and operate the Software on Customer's behalf, including in public or private clouds. They must be bound to protect the Software and Customer's information and may use it only for Customer's permitted purposes. Customer remains responsible for their compliance. The licence is held by Customer and does not authorise the contractor to serve other customers under it.
2.5 Redistribution, OEM embedding or distribution of ProAuth, sublicensing, and selling a standalone identity or authentication service to third parties require a separate written agreement. Permitting users to authenticate to Customer's own applications under section 2.2 does not grant those users rights to install, administer for unrelated purposes or redistribute ProAuth.
3. Production deployments, scaling and non-production use
3.1 Unless the Order expressly purchases more, one production licence covers one Production Deployment: one installed ProAuth system, normally deployed within one Kubernetes cluster, including the runtime instances and replicas used to scale that installation. An installation on another supported infrastructure is counted on the same basis. Each separate production installation requires its own production licence, even if installations share a corporate owner, administrator, upstream identity provider, synchronised data or configuration. Multiple separate installations within one cluster are also separate deployments. Multiple tenants or issuer addresses within one installation do not by themselves create additional deployments. The limited recovery and replacement arrangements in section 3.4 apply separately.
3.2 Production use means use to provide live authentication, authorisation or identity-management services on which actual business operations or services depend. An environment's label does not determine its status. A purported test environment serving live business traffic is production.
3.3 Within a licensed Production Deployment, Customer may run an unlimited number of Software instances and replicas for scaling, load balancing, high availability and failover, without additional instance fees. This right scales the licensed installation; it does not authorise additional production installations on other clusters or in other locations. A separate production installation requires another production licence unless expressly included in the Order or permitted by section 3.4.
3.4 Backup copies and passive disaster-recovery installations for the licensed Production Deployment are included. Customer may test recovery and activate a recovery installation to replace an unavailable primary installation. Temporary overlap necessary for failover, failback or migration of the same system is included for up to 30 days per event; 4tecture will not unreasonably refuse a documented request for a longer transition. Running the installations as independent ongoing production services requires additional licensing. Permanently active replicas of the same system are governed by section 3.3, not this transition limit.
3.5 Each valid production licence includes a corresponding development/test licence with the same licensed features. Customer may use that licence to install and use the licensed edition in unlimited Non-Production Environments, without a separate environment fee or a limit on installations, instances, developers or concurrent environments. These include local development, automated builds and CI/CD, ephemeral preview environments, integration testing, quality assurance, user acceptance testing, staging, performance testing, security testing, training and internal demonstrations supporting Customer's licensed use. They must not provide live business services or substitute for an independently licensed production system.
3.6 Non-production rights use the same licensed edition, feature entitlements and covered versions. Unless the Order expressly permits higher test limits, configuration limits apply separately within each non-production environment; copies of configurations in those environments do not consume production allowances. The number of environments is unrestricted. A perpetual licence retains these rights for its covered versions; subscription non-production rights end with the subscription. An evaluation without a production licence requires a separate evaluation entitlement.
3.7 The Order must state any limits for client application registrations, user-store configurations and federated identity-provider configurations, and their counting rules. A configured federated identity provider is not a running ProAuth container or replica. Limits apply to the Production Deployment as a whole, not separately to each replica or tenant. Replicating the same configuration for availability does not multiply its count. No unstated user or instance limit may be inferred from a technical licence-key field.
3.8 Customer may move the licensed deployment to replacement infrastructure within this scope. Technical registration of deployment addresses or licence keys does not create an additional fee for otherwise permitted scaling, migration or non-production use. Customer must request any necessary replacement keys and allow reasonable provisioning time. 4tecture will provide keys consistent with the purchased entitlements.
4. Subscription and perpetual licences
4.1 Subscriptions. A subscription permits use during the subscription term specified in the Order. Unless stated otherwise, its initial term is 12 months, starting on the agreed commencement date, provided the Software and necessary keys have been made available. Generally released updates and upgrades for the purchased edition are included during the term. Separately sold products or optional modules are not included merely because they integrate with ProAuth.
4.2 Perpetual licences. A perpetual licence is available only when expressly identified in the Order. After full payment, Customer may use the covered versions indefinitely, subject to termination for cause under section 16. The initial purchase includes 12 months of upgrade coverage from delivery unless the Order provides a longer period. Covered versions include the version delivered and generally released versions of the purchased edition made available during paid or included upgrade coverage. Customer may retain and use those versions after coverage ends, within the same deployment entitlement.
4.3 Continued upgrade coverage for a perpetual licence is optional. Its expiry does not terminate a paid perpetual licence or oblige Customer to uninstall covered versions. Later feature releases and ordinary fixes require active upgrade coverage or a separate purchase, subject always to section 7.4. Reinstatement after a lapse requires an agreed quotation; there is no automatic retrospective maintenance charge under this Agreement.
4.4 A perpetual right to use is not a promise of perpetual maintenance, compatibility with future platforms or access to future versions. Customer should retain secure copies of its covered images, keys and Documentation. 4tecture will not deliberately impose an expiring use entitlement on a fully paid perpetual version solely because optional upgrade coverage expires.
5. Renewal and changes
5.1 Unless the Order states otherwise, subscriptions renew for successive 12-month terms unless either party gives notice of non-renewal at least 30 days before the current term ends. Optional perpetual upgrade coverage and separately purchased support renew automatically only if the Order expressly says so. A perpetual use licence does not require renewal.
5.2 Fees are fixed for the committed term. 4tecture may change recurring fees for a renewal by notifying Customer at least 60 days before that renewal. If notice is later, the increase applies only to a later renewal meeting that notice period, unless Customer expressly agrees otherwise. Customer may decline renewal within the applicable cancellation period. Taxes imposed by law may change when the law requires.
5.3 A new version of this Agreement applies to an existing Order only by agreement. Continued use, installing an update or a website change alone is not acceptance of new terms. A renewal under section 5.1 retains the existing terms except for fees properly changed under section 5.2 and amendments expressly accepted by both parties.
6. Delivery, fees and payment
6.1 Delivery is electronic and occurs when the agreed Software and usable licence credentials are made available to Customer. Installation, migration, hosting, infrastructure, third-party subscriptions, messaging charges, training and professional services are excluded unless expressly purchased.
6.2 Fees, currency and payment schedule are specified in the Order. Unless otherwise stated, licence fees and annual recurring fees are invoiced in advance and payable within 30 days of invoice. Additional services require Customer's authorisation and are charged at the agreed rates. Travel and expenses require advance agreement.
6.3 Fees exclude VAT, sales, use and similar transaction taxes. Customer pays applicable transaction taxes, but not taxes on 4tecture's net income. If law requires withholding, Customer must provide the official withholding evidence and cooperate in obtaining available treaty relief. To the extent lawful, Customer must increase the payment so that 4tecture receives the agreed net fee, except to the extent the withholding results from 4tecture's failure to provide reasonably requested available tax documentation.
6.4 Customer must notify 4tecture promptly of a good-faith invoice dispute and pay the undisputed portion when due. Delay in raising a dispute does not waive mandatory rights. Overdue undisputed amounts bear simple interest at 5% per year from default, or the lower mandatory maximum. Suspension and termination require the procedures in section 16.
6.5 Committed fees are non-cancellable and non-refundable except where this Agreement, the Order or mandatory law provides otherwise. Customer may not set off disputed counterclaims unless established by a final decision; this does not restrict mandatory set-off rights.
7. Support, updates and security maintenance
7.1 Basic Support for supported versions is included during an active subscription or the included or renewed upgrade coverage for a perpetual licence. It covers reporting and triage of suspected product defects and communication of applicable remedies and security advisories. It does not include implementation, environment troubleshooting, configuration or integration assistance. After perpetual upgrade coverage expires, ordinary technical support and access to later ordinary fixes or feature releases require a separate purchase. 4tecture will continue to accept vulnerability reports and provide the security handling, communications and remedies required under sections 7.4–7.8; these do not include a general technical-support plan or its response commitments unless expressly agreed or required by law.
7.2 The purchased support plan, service hours, first-response commitments, escalation allowances and applicable remedies must be stated in the Order or an attached, versioned support schedule. Unless that schedule provides otherwise, Basic Support provides an initial substantive response within one Business Day through the designated support channel. Business Hours are 09:00–17:00 Europe/Zurich local time, Monday to Friday, excluding public holidays at 4tecture's registered office. One Business Day means eight Business Hours. Response clocks run only during those hours unless 24-hour coverage is expressly purchased. A response commitment is not a resolution deadline or a guarantee of Customer's service availability.
7.3 Customer must provide reasonably available diagnostic information and cooperate with reproduction and mitigation. 4tecture may request use of a supported corrective release or a reasonable workaround. Customer must authorise chargeable work before it begins; confirmed product defects are not chargeable configuration cases. 4tecture is not responsible for operating Customer's infrastructure or deploying patches unless separately agreed. Support exclusions apply only to the extent an issue is caused by Customer's environment, unsupported modifications, third-party services or use contrary to Documentation.
7.4 Nothing in this Agreement conditions a security update, advisory, vulnerability report or other protection required by applicable mandatory law on payment for optional upgrade coverage or support. 4tecture will fulfil applicable manufacturer obligations, including required vulnerability handling and the supply of required security updates without a separate charge where the law requires. Any licence permission necessary to install and use such an update for an otherwise valid licence is included. For a perpetual licence, expiry of commercial upgrade coverage does not shorten an applicable mandatory security-support period. For a subscription, contractual use and update entitlements end with the subscription; mandatory duties, including any continuing update-availability or reporting duties, remain unaffected. Receipt or availability of a security update does not renew an expired subscription or authorise continued operation, except where mandatory law requires otherwise.
7.5 Support periods. For a perpetual licence, commercial entitlement to security updates lasts for the included upgrade coverage (12 months unless the Order provides longer) and any subsequent purchased coverage under section 4. Beyond that coverage, 4tecture provides security maintenance only for the period and to the extent required by applicable mandatory law or expressly agreed in the Order. A perpetual use right does not create a lifetime security-maintenance obligation.
Where the support-period requirements of Regulation (EU) 2024/2847 (the EU Cyber Resilience Act) apply to a perpetual supply, the security-support period is five years from delivery of that supply to Customer, or longer where mandatory law requires. This five-year provision does not create an additional voluntary support period for supplies outside those requirements. Other applicable mandatory periods remain unaffected. The Order or an attached lifecycle schedule supplied before acceptance must state the applicable security-support start and end dates, separately from commercial upgrade coverage and individual release-maintenance dates. It must identify the supported releases or replacement-release paths. Later supplies and substantially modified versions remain subject to their own applicable requirements; the initial delivery date cannot curtail those requirements. For subscriptions, section 7.4 governs expiry and continuing mandatory duties.
4tecture sets individual release-maintenance periods by reference to the support lifecycles of the underlying .NET runtime and other essential dependencies. Customer may be required to transition to a supported successor release to receive further fixes, subject to section 7.6. Security support does not promise maintenance of the original release, runtime or every historical version throughout Customer's coverage. A dependency's end of support does not shorten a mandatory period: where coverage continues, 4tecture must provide a qualifying successor or another legally adequate remedy.
Release-maintenance end dates and transition requirements will be communicated in the lifecycle schedule, with reasonable advance notice of changes. 4tecture will not shorten an agreed or mandatory security-support period through a later schedule change. Contracted support will not be withdrawn during a prepaid term without equivalent support or a refund for the withdrawn portion; a refund does not discharge mandatory duties. After the applicable security-support period ends, no further fixes are promised unless coverage is renewed or law requires them. Expiry does not end a valid perpetual use licence. Required retention and availability of already-issued updates, vulnerability reporting and other continuing legal duties remain unaffected.
7.6 Security remedies through newer versions. Where permitted by applicable law, 4tecture may fulfil a security-remediation obligation by providing a corrected newer version instead of backporting a fix to an older version. For a perpetual licence, the right to use the supplied replacement version is also perpetual within the existing deployment scope, even if paid upgrade coverage has expired; this does not renew commercial upgrade coverage or create additional production entitlements. 4tecture will provide the necessary licence keys without an additional licence or upgrade fee. Where relying on Article 13(10) of the EU Cyber Resilience Act, 4tecture must meet its conditions, including free access to the applicable latest version and no additional costs to Customer to adjust the hardware and software environment in which it uses the original version. Merely announcing an older feature's deprecation does not establish that these conditions are met.
7.7 Feature entitlements in security replacements. A security replacement does not automatically include optional new features or separately sold modules outside Customer's existing entitlements. 4tecture may control access to those additional capabilities through licence keys or feature flags only to the extent consistent with applicable law. Such controls must not withhold required security remediation, reduce Customer's existing purchased entitlements, or require a paid feature to retain the licensed functionality or a materially equivalent secure replacement. Where a proposed replacement or its feature restrictions do not meet applicable mandatory conditions, 4tecture must provide another legally adequate remedy. These provisions do not oblige Customer to renew paid upgrade coverage to receive a mandatory security remedy.
7.8 Where applicable law requires security updates to be supplied separately from functionality updates when technically feasible, 4tecture will do so. The availability of a newer combined release does not by itself remove that requirement. Customer remains responsible for its deployment under section 8.1; this does not transfer 4tecture's mandatory manufacturer obligations to Customer.
8. Customer operation and responsibilities
8.1 ProAuth is self-hosted. Customer controls its infrastructure and is responsible for its deployment architecture, availability, capacity, secure configuration, privileged access, secrets and signing keys, lawful data processing, monitoring, backups and tested recovery procedures. Customer must assess updates, apply appropriate security measures and install security fixes within a reasonable period taking account of risk and operational requirements.
8.2 Customer is responsible for its applications, identity data, policies, authentication flows and third-party integrations. Product support for a protocol or security profile does not certify Customer's complete deployment or guarantee compliance with sector-specific rules. Any required certification, regulated outsourcing arrangement or special operational commitment must be separately agreed.
8.3 Customer must protect licence credentials from unauthorised use and maintain accurate records of production deployments and purchased configuration allowances. 4tecture may request proportionate evidence of licence compliance under section 13.
8.4 The Software may validate licence keys, covered versions, deployment addresses and configuration allowances. Expired or invalid entitlements may prevent functionality as described in the applicable Documentation. Technical operation beyond an entitlement is not a licence extension. These mechanisms do not authorise 4tecture to access Customer's systems, delete data or narrow agreed licence rights. Errors affecting valid entitlements must be addressed promptly through support.
8.5 The Software is not supplied as a safety-certified control system for uses in which its failure directly causes death, personal injury or severe physical or environmental damage. Such use requires a separately agreed specification and appropriate independent safeguards. This limitation does not exclude otherwise permitted enterprise identity use merely because continuity is commercially important.
9. Restrictions and intellectual property
9.1 Except as expressly permitted, Customer must not copy or modify proprietary Software, create derivative works from it, distribute it, rent or sublicense it, remove proprietary notices, disclose keys to unauthorised persons, or bypass entitlement controls. Configuration, documented extensions, integrations through published interfaces, internal security testing and permitted deployment copies are authorised within Customer's licensed scope.
9.2 Customer must not reverse engineer, decompile or disassemble proprietary Software except to the extent applicable law grants rights that cannot be excluded by contract. Mandatory rights concerning interoperability, observation, testing, backup copies, error correction and exhaustion of distribution rights remain unaffected. Customer should first request reasonably available interoperability information from 4tecture where practicable; this request is not a condition overriding a mandatory right.
9.3 4tecture and its licensors retain all rights in the Software and Documentation not expressly granted. Customer retains its rights in its own data, applications, configurations and independently developed extensions. No customer data ownership passes to 4tecture. Customer may voluntarily provide suggestions; 4tecture may use non-confidential suggestions without payment, but this does not license Customer's code, data, trademarks or confidential information.
9.4 Neither party may use the other's name, logo or customer relationship in publicity without prior consent, except for a truthful disclosure required by law. No source-code escrow, delivery of source code or bespoke development is included unless separately agreed.
10. Confidentiality
10.1 Each party must protect non-public information received from the other that is marked confidential or reasonably understood to be confidential, using reasonable care and at least the care it uses for its own comparable information. Protected information includes non-public Software, keys, security reports, business information and Customer data.
10.2 The receiving party may use confidential information only to perform or exercise rights under this Agreement and disclose it only to personnel, permitted contractors and professional advisers who need it and are subject to suitable confidentiality duties. The receiving party is responsible for their compliance.
10.3 These duties do not cover information the recipient can establish was lawfully known without restriction, became public without breach, was received lawfully from a third party without a duty of confidence, or was independently developed. Legally required disclosures are permitted; where lawful, the recipient must give advance notice and reasonable assistance to seek protection. Nothing prevents lawful reports to authorities or disclosures required by security or vulnerability-reporting law.
10.4 Confidentiality continues for five years after termination, and for trade secrets, credentials and personal data for as long as their nature or applicable law requires protection. Copies retained for legal obligations or routine backup purposes remain protected and may not be used for unrelated purposes.
11. Data protection and access
11.1 Supplying a self-hosted licence does not by itself appoint 4tecture to process Customer's identity data. Each party must comply with data-protection duties applicable to its actual activities. Customer determines its own lawful purposes, notices, access policies, retention and use of personal data in its deployment.
11.2 If support, diagnostics or managed services require 4tecture to process personal data on Customer's behalf, the parties must put an appropriate data processing agreement in place before that processing begins, including applicable Swiss FADP and GDPR requirements, security measures, approved subprocessors and required international-transfer safeguards. The roles depend on the actual processing, not solely on the labels used in this Agreement. This licence is not a substitute for that agreement.
11.3 Customer should minimise and, where practicable, redact diagnostic data and use synthetic test data. Customer must not send passwords, private signing keys or production databases through ordinary support channels. Necessary access must use an agreed secure method, scope and duration. 4tecture may process supplied materials only to deliver the agreed services, protect their security and meet legal obligations, subject to the applicable data processing agreement.
11.4 4tecture processes business contact, contracting and billing information for its own administration under its applicable privacy notice. Telemetry or remote access is not authorised merely by accepting this licence; any such processing must be described accurately and have the required legal basis. Nothing restricts data subjects' or supervisory authorities' rights.
12. Third-party components and services
12.1 Third-party and open-source components are governed by their applicable licences and notices supplied with the Software or accompanying materials. Those terms prevail for the relevant component where they conflict with this Agreement. This Agreement does not restrict rights directly granted by those licences or impose fees on the exercise of such independent rights.
12.2 Customer must obtain its own rights to separately procured infrastructure, databases, messaging services and identity-provider services. Their fees, availability and terms are outside this licence. 4tecture does not guarantee uninterrupted third-party availability or unchanged third-party interfaces.
12.3 Third-party terms do not release 4tecture from its express commitments for the Software as supplied or applicable mandatory obligations. 4tecture must provide required attribution, licence texts and source-code offers where applicable.
13. Licence compliance verification
13.1 On reasonable request, no more than once in any 12-month period unless there is substantiated evidence of a material breach, Customer must provide a written licence-compliance statement and reasonably necessary deployment and configuration counts. The request must not require identity records, passwords, private keys or unrelated confidential information.
13.2 If that information reasonably fails to resolve a material compliance concern, 4tecture may arrange a limited audit by an independent, professionally qualified auditor bound by confidentiality and not a direct competitor of Customer. At least 20 Business Days' notice is required. The parties must agree reasonable security arrangements, use records-based verification where practicable and avoid disruption. This clause grants no right of unannounced access or unrestricted scanning of production systems.
13.3 4tecture bears audit costs unless the audit establishes underpaid licence fees exceeding 5% of fees due for the audited period, in which case Customer must reimburse reasonable, evidenced audit costs. Customer must pay verified shortfalls at the applicable agreed rates, or the rates applicable when the unlicensed use began if no rate was agreed. No penalty multiplier applies. Customer may dispute findings in good faith. Verification does not replace termination safeguards or mandatory data-protection restrictions.
14. Limited warranty and remedies
14.1 4tecture warrants that it has authority to grant the rights promised here. For 12 months from initial delivery of a paid perpetual licence, and throughout a paid subscription term, the unmodified Software used in a supported environment in accordance with Documentation will materially conform to the agreed functional specifications. Covered updates do not restart a perpetual warranty period. Separately purchased professional services will be performed with reasonable professional care and skill.
14.2 Customer must report a material non-conformity promptly after discovery, describing its effect and reasonably available reproduction information, and allow 4tecture a reasonable opportunity to investigate and remedy it. Delay bars a claim only to the extent it materially prejudices investigation or remedy, subject to applicable limitation periods. Exclusions for misuse, modification, unsupported environments or third-party components apply only to the extent they caused the defect.
14.3 4tecture may remedy a covered defect by repair, replacement or a reasonable workaround that restores materially equivalent functionality without materially impairing security. If it cannot do so within a reasonable period after written notice, Customer may terminate the affected entitlement and receive: (a) prepaid subscription and service fees for the unused period after termination; or (b) the purchase price of the affected perpetual licence if termination is for a defect covered by its initial warranty, plus unused prepaid associated service fees. Customer must cease using the refunded entitlement. The parties may agree a proportionate price reduction instead.
14.4 These are the contractual remedies for non-conformity, without limiting section 15, claims for recoverable damages under section 17, or mandatory remedies. Apart from express promises in this Agreement or the Order, implied warranties and conditions are excluded to the extent permitted by law, including implied fitness for a particular purpose. 4tecture does not warrant that the Software is free of every defect or vulnerability, prevents every attack, operates without interruption, or meets uncommunicated requirements. These qualifications do not negate the express warranty or mandatory security duties.
15. Third-party claims
15.1 No included supplier IP defence or indemnity. This Agreement does not include an obligation for 4tecture to defend Customer against third-party intellectual-property claims or reimburse Customer's defence costs, awards or settlements. Such an obligation arises only under an expressly agreed written IP-defence addendum signed by both parties. This provision does not remove the express warranty in section 14.1, the remedies in sections 14 and 15.3, or liability that section 17.1 preserves. The absence of an indemnity does not restrict the worldwide licence grant.
15.2 Optional IP protection. Any IP-defence addendum must identify the covered rights, territories, period, exclusions, defence procedure, fees and liability allocation. Unless that addendum expressly changes section 17.3, all 4tecture defence costs, awards, settlements and other payments under it share the aggregate cap for the affected Order and do not create a separate cap. No supplier defence or indemnity may be inferred from an edition name, support plan, insurance certificate or general assurance about the Software. Customer must notify 4tecture promptly of a claim affecting use of the Software so that 4tecture can assess available remedies; notification alone does not create a defence obligation.
15.3 If an infringement claim is made or reasonably likely, 4tecture may obtain continued use rights or modify or replace the affected Software with materially equivalent non-infringing Software. If neither is commercially reasonable, it may terminate the affected entitlement on reasonable notice and refund unused prepaid recurring fees and, for a perpetual licence, the purchase price less straight-line depreciation over 36 months from initial delivery, with a minimum of zero. Customer must cease using the terminated entitlement. This provision does not reduce an applicable warranty remedy under section 14 or a mandatory remedy. It grants no right to reimbursement of third-party awards, settlements or defence costs in the absence of an addendum under section 15.1.
15.4 Customer's protection of 4tecture. Customer will defend 4tecture against third-party claims to the extent caused by Customer's unlawful data or content, infringement by Customer-supplied materials, or unauthorised redistribution or sublicensing in breach of this Agreement. Customer will pay damages and reasonable costs finally awarded and settlements it approves. This does not cover claims caused by a defect in the Software or 4tecture's breach, negligence or misconduct. Mere authorised use of ProAuth does not create a general customer indemnity.
15.5 For the indemnity in section 15.4, and any supplier indemnity expressly agreed under section 15.1 unless its addendum provides otherwise, the protected party must notify the other promptly, provide reasonable cooperation at the defending party's expense and allow it control of the defence with competent counsel. Late notice reduces protection only to the extent it causes material prejudice. The protected party may participate with its own counsel at its expense. No settlement may admit fault by, impose non-monetary obligations on, or fail to release the protected party without its consent, which must not be unreasonably withheld. Defence costs, awards, settlements and infringement refunds under this section all count towards any applicable cap. Unless an addendum expressly provides otherwise, 4tecture has no further funded defence obligation once its applicable cap is exhausted and must cooperate in an orderly handover. This procedure does not itself create a supplier indemnity. Section 17.1 applies throughout.
16. Suspension, termination and consequences
16.1 Either party may terminate an affected Order for the other's material breach if that breach remains uncured 30 days after written notice specifying the breach and the intention to terminate. A non-payment notice must identify the overdue undisputed sum. A good-faith invoice dispute is not by itself grounds for suspension while undisputed amounts are paid.
16.2 After that cure period, 4tecture may suspend relevant downloads, optional support or subscription entitlements instead of terminating, with notice of scope and effect. Immediate proportionate suspension or termination is permitted only where continued performance would be unlawful or Customer commits an intentional material infringement or unauthorised distribution that cannot reasonably be remedied. 4tecture must give notice where legally permitted and restore suspended performance promptly once the grounds are resolved. This clause does not authorise deletion of Customer data or remote entry into Customer systems.
16.3 Either party may terminate if the other becomes insolvent or ceases business to the extent applicable insolvency law permits. An unaffected, fully paid perpetual licence is not terminated solely because optional support ends, upgrade coverage lapses or an unrelated Order is disputed. 4tecture has no general right to revoke a paid perpetual licence for convenience.
16.4 On expiry or valid termination of an entitlement, Customer must immediately stop using the Software under that entitlement and remove operational copies within 30 days, including non-production copies dependent on it. The removal period is not a continued-use entitlement. Customer must arrange any necessary data export before expiry or obtain a separate, express transition entitlement. One inaccessible archival copy and copies in routine immutable backups may be retained for legal or evidentiary purposes, without operational use and subject to continuing confidentiality. Customer must confirm compliance on reasonable request. Nothing here requires destruction of security-update archives or other materials that must remain available under mandatory law.
16.5 Customer retains its data and must plan export and migration. 4tecture is not required to host data or perform migration without an agreed service engagement. Deletion of Software does not require deletion of Customer's own data. Where Customer validly terminates for 4tecture's uncured material breach, 4tecture will refund prepaid recurring fees for the unused affected period. Perpetual licence refunds are governed by section 14, section 15 or mandatory law.
16.6 Accrued payment obligations and provisions intended to survive, including intellectual property, confidentiality, retained-data obligations, limits of liability and dispute resolution, survive termination. Termination does not reduce mandatory security or regulatory obligations that continue by law.
17. Allocation and limitation of liability
17.1 Mandatory exceptions. Nothing in this Agreement excludes or limits liability to the extent applicable law prohibits that exclusion or limitation. In particular, liability for a party's own unlawful intent or gross negligence, including conduct of its corporate organs attributed to it as its own conduct, remains unaffected to the extent required by Article 100 of the Swiss Code of Obligations. Fraud, fraudulent concealment, death or personal injury, product liability and other statutory liabilities remain unaffected to the extent mandatory law so requires. Liability for auxiliary persons is addressed separately in section 17.6. All exclusions, caps, remedy restrictions, indemnities and disclaimers are subject to this paragraph; listing a category does not create additional liability beyond applicable law. The Agreement does not bind regulators or restrict third parties' mandatory rights.
17.2 Ordinary negligence and excluded losses. Subject to section 17.1, 4tecture excludes liability to Customer for damages caused by ordinary negligence, including slight negligence, to the fullest extent permitted by applicable law. This exclusion does not release 4tecture from its express delivery and performance obligations, agreed repair, replacement or refund remedies, mandatory security-maintenance duties, or an IP-defence obligation expressly assumed under section 15.1. It limits damages rather than cancelling those obligations. If the exclusion does not apply or is unenforceable, any remaining liability is subject to the following loss exclusions and section 17.3, but only to the extent those limitations are themselves lawful.
Subject to section 17.1, neither party is liable to the other for indirect or consequential loss, loss of profit or revenue, lost business opportunities, loss of goodwill, or business interruption, whether or not foreseeable. Where damages for lost or corrupted data remain recoverable despite the exclusions above, they are limited to reasonable direct restoration costs, taking account of reasonable backups that should have been maintained, and remain subject to the applicable cap. These loss exclusions do not exclude amounts expressly covered by the customer indemnity in section 15.4 or a separately agreed supplier indemnity merely because a third party's awarded loss falls into one of these categories.
17.3 4tecture's aggregate fallback cap. To the extent 4tecture has monetary liability that is not excluded under this Agreement and may lawfully be capped, its aggregate liability arising out of or relating to an affected Order is limited to the following amounts. This cap does not create a right to damages or cap liability which section 17.1 preserves:
- for a subscription or a stand-alone recurring service, the fees paid or payable for that Order for the 12 months immediately preceding the first event giving rise to a claim; if that event occurs during the first 12 months, the committed fees for the first 12 months apply;
- for a perpetual licence Order, the one-time licence purchase price plus associated recurring service fees paid or payable for the 12 months preceding that first event.
Related events are treated as one event. The cap is aggregate across all claims and legal theories and is not multiplied by the number of users, Permitted Subsidiaries, environments or claimants. Where more than one Order is directly affected, the relevant caps are added without counting a fee twice. Any liability for confidentiality, data protection, security incidents or section 15 which survives the exclusions shares this cap to the extent lawful, unless a separately signed agreement expressly provides otherwise. Insurance coverage or its limits do not increase the contractual cap or create an additional payment obligation. Refunds expressly payable under sections 7.5, 14.3, 16.5, 18.1 and 19.1 remain payable outside this damages cap; infringement refunds under section 15.3 are treated as specified in section 15.5. Section 17.5 prevents duplicate recovery.
17.4 Customer liability. Customer's ordinary contractual damages liability is subject to the same fee-based cap. The cap does not reduce fees actually due, amounts payable for unlicensed use, Customer's liability for infringement or misappropriation of 4tecture's intellectual property, or Customer's obligations under section 15.4. These exceptions remain subject to section 17.1 and mandatory law.
17.5 Each party must take reasonable steps to mitigate loss. A party is responsible only to the extent its conduct caused the loss, taking account of the other party's contribution. No party may recover the same loss twice. These provisions apply to contract, tort, pre-contractual and other claims to the extent lawful and extend to 4tecture's personnel and subcontractors when acting in connection with the Agreement.
17.6 Auxiliary persons. To the fullest extent permitted by Article 101 of the Swiss Code of Obligations and other applicable law, 4tecture excludes its contractual liability in damages for acts or omissions of employees, subcontractors and other auxiliary persons engaged in performance. This exclusion applies only where their conduct is legally treated as that of an auxiliary person; it does not reclassify a corporate organ's conduct or exclude 4tecture's own non-excludable liability, including for selection, instruction or supervision. The preserved performance obligations and remedies in section 17.2 remain unaffected. Where this exclusion does not apply, the other exclusions and cap apply only to the extent legally permitted.
18. International trade and mandatory local rules
18.1 Each party must comply with export-control, sanctions and trade laws applicable to its own activities. Customer must not export, re-export, transfer or make the Software available to a prohibited person, destination or end use, and must obtain authorisations required for its deployments. This clause does not impose a foreign trade regime where it does not otherwise apply. 4tecture may withhold a prohibited supply and must notify Customer where lawful. Prepaid fees for an unprovided period will be returned to the extent legally permitted, less amounts properly due for delivered performance.
18.2 A worldwide licence does not dispense with local mandatory requirements, regulatory approvals or agreed data-transfer safeguards. Country-specific or regulated-sector terms must be agreed where necessary. Nothing purports to waive non-excludable local rights or duties. Consumer purchases require separate terms and are outside the intended scope of this Agreement.
19. General provisions
19.1 Force majeure. Neither party is responsible for delay caused by an event beyond its reasonable control that could not reasonably have been prevented or overcome. The affected party must notify the other, mitigate and resume performance promptly. Lack of funds, ordinary staffing shortages and preventable failures of reasonable security or continuity measures do not qualify. Accrued payment obligations remain due. If a material interruption continues for more than 60 days, either party may terminate the affected unperformed services; prepaid fees for undelivered performance must be refunded. A force-majeure event does not by itself revoke an existing paid perpetual licence.
19.2 Assignment. Customer may assign an Order only with 4tecture's prior consent, not to be unreasonably withheld for a genuine corporate reorganisation or transfer of the relevant business to an eligible successor that assumes the obligations and does not expand the scope. Mandatory transfer and exhaustion rights remain unaffected. 4tecture may assign the Agreement with the ProAuth business to a successor capable of performing it, on notice and without reducing Customer's contracted rights. Other assignments by 4tecture require Customer's consent, not to be unreasonably withheld. Assignment does not itself authorise new personal-data transfers.
19.3 Subcontractors. 4tecture may use qualified subcontractors and remains responsible for their performance of its contractual obligations. Personal-data processing remains subject to the applicable data processing agreement and law.
19.4 Notices. Contractual notices must be in English or another agreed language and sent to the legal-notice contacts in the Order. Unless changed by notice, 4tecture's contact is info@4tecture.ch or its postal address in section 1.1. Email is sufficient for cancellation, non-renewal, breach and other contractual notices if receipt can be evidenced; a failed or bounced transmission is not notice. Each party must maintain a current contact. Court service follows applicable procedural law.
19.5 Entire agreement and severability. This Agreement, the Order and expressly incorporated schedules state the parties' agreement for their subject matter. They do not retrospectively extinguish rights under earlier orders unless a signed amendment expressly does so. Amendments require recorded agreement by authorised representatives. Failure to enforce a right is not a waiver. If a provision is invalid, the remaining provisions continue to the extent lawful; the invalid provision is addressed under applicable law, without automatically expanding an unlawful exclusion. The parties are independent contractors.
19.6 Language. The agreed English text governs between the parties unless an Order expressly adopts another language, subject to mandatory local language requirements.
20. Governing law and jurisdiction
20.1 This Agreement and disputes arising out of or relating to it are governed by the substantive laws of Switzerland, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG). Overriding mandatory laws remain applicable where legally required.
20.2 Subject to mandatory jurisdiction rules, the courts having subject-matter jurisdiction for Volketswil, Canton of Zurich, Switzerland, have exclusive jurisdiction over disputes arising out of or relating to this Agreement, including its formation, validity, performance and termination. Either party may request provisional or protective measures from a court competent to grant them; this does not change the exclusive forum for the merits. Recognition and enforcement abroad remain subject to applicable law and treaties.