LEGAL

General Terms and Conditions

These terms apply to all quotations, assignments and agreements of Nexora. They are published here so you can always consult them; our proposals refer to this page. Current version: 1.0 - 12 September 2026.

This is an English translation of the Dutch Algemene Voorwaarden. In the event of any conflict or difference in interpretation, the Dutch version prevails.

For business customers (B2B)

Connected in Finance, People & Performance. These terms and conditions have a modular structure and apply to the NEXORA platform and, to the extent ordered, Finance, Accounting, Payroll, HRM, Planning, CLA & Compliance, Nora/AI, integrations, implementation and additional professional services.

Important when taking the services into use: the online price calculator provides an indication only. An agreement is formed only upon acceptance of a formal quotation/order confirmation or upon activation of the service as described in these terms and conditions.

Reading guide and legal structure

NEXORA combines multiple business processes in a single platform. These General Terms and Conditions therefore consist of a general part and additional modules. A module applies only to the extent that the relevant service, functionality or module has been activated in the Quotation, Order Confirmation or Customer Environment.

Order of precedence of documents. 1. Quotation / Order Confirmation: commercial arrangements, scope, quantities, prices and deviations. 2. Data Processing Agreement (Annex 1): prevails in respect of matters relating exclusively to the processing of personal data. 3. Specific module provisions: prevail over the general part for the specific product or the specific service. 4. Any SLA / service arrangements: prevail over the general part in respect of availability, support and incident handling. 5. General Terms and Conditions: the general legal basis for all NEXORA services.

Part I - General provisions

Article 1 - Definitions

1.1 Administration: a separate financial administration or legal entity maintained within the Platform.

1.2 AI Functionality: functionality that, by means of machine learning, generative AI or other automated models, analyses input and generates output, predictions, recommendations, classifications or actions.

1.3 CLA & Compliance: the NEXORA functionality for making available, structuring, flagging and applying collective labour agreement (CLA), employment law and compliance information.

1.4 Services: all software, modules, support, implementation, integrations and any Professional Services supplied by NEXORA to Customer.

1.5 User: any natural person who is granted access to the Services by or on behalf of Customer, including directors, employees, accountants, advisers and other authorised persons.

1.6 Customer: the natural person acting in the course of a profession or business, or the legal entity, that enters into an Agreement with NEXORA.

1.7 Customer Data: all data, documents, personal data, administrations, files, prompts, instructions and other information supplied or generated by or on behalf of Customer in or through the Services, with the exception of Service Data.

1.8 Customer Environment: the secure digital environment in which Customer manages and uses the Services.

1.9 NEXORA: the legal entity stated in the Quotation or Order Confirmation as the supplier of the Services.

1.10 Nora: the AI assistant and intelligent rules layer of NEXORA, including functions for analysis, flagging, answering questions, preparing actions and, where activated, automated processing.

1.11 Quotation: a proposal issued by NEXORA, including the formal quotation generated via the website after customer details have been entered.

1.12 Order Confirmation: the written or electronic confirmation of the Services ordered by Customer.

1.13 Agreement: the agreement concluded between NEXORA and Customer, consisting of the Quotation/Order Confirmation, these General Terms and Conditions and the applicable annexes.

1.14 Platform: the software environment made available by NEXORA as SaaS, including Finance, Accounting, Payroll, HRM, Planning, CLA & Compliance, dashboards, portals, Nora and integrations.

1.15 Professional Services: services performed by people, such as implementation, migration, configuration, consultancy, administration, payroll support, and tax or financial support, to the extent expressly ordered.

1.16 Service Data: technical log data, telemetry, usage statistics, performance data and aggregated or anonymised data arising from the use of the Services.

1.17 Website: www.nexora.nu and the subdomains, portals and status or support pages designated by NEXORA.

Article 2 - Applicability and business target group

2.1 These General Terms and Conditions apply to every offer, Quotation, Order Confirmation, Agreement and every use of the Services by Customer.

2.2 The Services are intended for business users. Customer declares that it enters into the Agreement in the course of its profession or business. Consumer terms and conditions do not apply, unless NEXORA expressly agrees otherwise in writing.

2.3 The applicability of purchasing conditions or other general terms and conditions of Customer is expressly rejected, unless NEXORA accepts them in writing and expressly.

2.4 Deviations apply only if they have been agreed in writing and solely to the specific case to which they relate.

Article 3 - Quotations, price calculator and formation of the Agreement

3.1 The online price calculator, product pages and price indications on the Website are for information purposes only and do not constitute a binding offer. The calculator is intended to calculate an indicative monthly price on the basis of the configuration entered by Customer.

3.2 A formal Quotation contains at least the selected configuration, the pricing basis, the period of validity and, where relevant, additional commercial arrangements. An Agreement is formed when an authorised representative of Customer accepts the Quotation or Order Confirmation digitally or in writing and NEXORA confirms that acceptance, or when NEXORA activates the Services at Customer's request.

3.3 Customer warrants that the person who digitally accepts, orders or activates modules on behalf of Customer is authorised to do so. Acts of administrators within the Customer Environment are attributed to Customer.

3.4 Obvious errors, calculation errors and clerical errors in price indications or Quotations do not bind NEXORA if Customer ought reasonably to have understood that a mistake had been made.

Article 4 - Nature of the Service and standard SaaS

4.1 NEXORA supplies a standardised, modular SaaS platform. Unless expressly agreed as bespoke work, the Service has not been developed solely for the individual requirements of a single Customer.

4.2 NEXORA may improve, replace or change functionality, interfaces, workflows and technical set-up where this is necessary for security, scalability, laws and regulations, product development or the continuity of the Services. NEXORA endeavours to maintain the core functionality and the agreed purpose of use.

4.3 Roadmaps, demos, prototypes, beta features and statements about future functionality are indicative and do not constitute an obligation of result, unless otherwise agreed in writing.

Article 5 - Obligations and information of Customer

5.1 Customer shall provide in good time all information, data, authorisations, decisions and cooperation reasonably required for the performance of the Agreement and warrants the accuracy, completeness, currency and lawfulness thereof.

5.2 Customer remains responsible for the organisation of its business, internal controls, segregation of duties, approval procedures, statutory obligations and business decisions, including where NEXORA prepares automations, alerts, calculations or draft decisions.

5.3 Delays or additional work resulting from information not being supplied in good time or being supplied incorrectly may be charged by NEXORA to Customer to the extent that additional work is required as a result.

Article 6 - Accounts, users, roles and access security

6.1 Customer is responsible for designating administrators, granting and revoking roles and authorisations and keeping Users up to date.

6.2 Login credentials are personal and may not be shared. Customer shall ensure secure passwords, multi-factor authentication where available, suitable devices and careful handling of access tokens and API keys.

6.3 Customer shall notify NEXORA without delay of suspected misuse, loss of access credentials or unauthorised access. NEXORA may temporarily block accounts if this is reasonably necessary to protect the security of Customer, other customers or the Platform.

Article 7 - Permitted use

7.1 Customer and Users shall use the Services solely for lawful business purposes and in accordance with the Agreement, the documentation and the reasonable instructions of NEXORA.

7.2 The following are not permitted, among other things: (a) unauthorised access or security testing; (b) reverse engineering to the extent not permitted under mandatory law; (c) circumventing usage limits; (d) distributing malware; (e) use that impairs availability for others; (f) processing data for which Customer has no legal basis or authority; and (g) use for prohibited AI practices or other applications prohibited by law.

7.3 In the event of misuse, NEXORA may take appropriate measures, including throttling, restriction of functions or temporary suspension, in which case it will, where possible, first contact Customer.

Article 8 - Third parties, integrations and external services

8.1 The Platform may connect with banks, government portals, payroll and pension chains, email services, document services, AI model providers, cloud providers, APIs and other third-party services. Additional terms and conditions of the relevant third party may apply to such external services.

8.2 NEXORA is responsible for its own integration layer, but not for the availability, content, tariff changes, API restrictions or errors of an external service over which NEXORA has no decisive influence.

8.3 NEXORA may change, temporarily disable or replace an integration if a third party changes its service, terms and conditions, security requirements or technical connection. NEXORA will, where reasonably possible, communicate material consequences for Customer in good time.

Article 9 - Maintenance, updates and changes

9.1 NEXORA may carry out maintenance, security updates and releases. Planned maintenance is preferably carried out outside normal office hours and, if it is expected to have a material impact, announced in advance via the Customer Environment, email or a status page.

9.2 In the event of urgent security risks or statutory obligations, NEXORA may take measures without prior notice. NEXORA limits the impact as far as possible.

9.3 If a change materially and permanently reduces the agreed core functionality without an equivalent alternative, Customer may terminate the directly affected component within thirty days of notification, with effect from the date on which the change takes effect.

Article 10 - Support and availability

10.1 NEXORA provides support through the channels and within the service windows published on the Website, in the Customer Environment or in a separate SLA.

10.2 Unless a specific SLA has been agreed, availability percentages and response times are target values and not guarantees. Incidents are prioritised according to severity and business impact.

10.3 Unavailability resulting from planned maintenance, force majeure, external services, Customer's internet connections, incorrect configuration by Customer or emergency measures to secure the Platform does not constitute an attributable failure on the part of NEXORA.

Article 11 - Prices, usage units, tiered pricing and Fair Use

11.1 Prices and the numbers of Administrations, Users, Employees, payslips, modules or other usage units included therein are set out in the Quotation, Order Confirmation or current pricing arrangement.

11.2 If a price depends on actual use, headcount, number of Users, number of Administrations, payslips, transactions, AI usage or tiered pricing, NEXORA may measure actual use and adjust the fee payable accordingly. Customer shall keep the relevant numbers up to date.

11.3 Where tiered pricing applies, the applicable tier is determined in accordance with the method described in the pricing arrangement. Increased or reduced use takes effect from the moment or the period determined in the Quotation or on the pricing page.

11.4 Fair Use may apply to Nora and other compute-intensive functions. Fair Use means normal and reasonable business use appropriate to the package purchased. In the event of exceptional or structurally excessive use, NEXORA will first contact Customer and may propose reasonable limits, throttling or an appropriate additional package.

11.5 Temporary promotions, introductory discounts and promotional rates end automatically at the end of the agreed promotional period. Thereafter, the regular rate stated in the Quotation or Order Confirmation applies or, if no such rate is stated therein, the regular rate applicable at that time for the relevant package.

Article 12 - Invoicing and payment

12.1 Unless otherwise agreed, periodic subscription fees are invoiced in advance. Variable or usage-based charges may be invoiced in arrears.

12.2 Invoices are subject to a payment term of fourteen days, unless otherwise specified in the Quotation. NEXORA may require payment by direct debit.

12.3 Customer shall notify NEXORA of any substantive objections to an invoice within fourteen days of the invoice date. Submitting an objection does not suspend the payment obligation for the undisputed portion.

12.4 In the event of late payment, Customer owes the statutory commercial interest and reasonable collection costs. If payment is not made, NEXORA may, after a reasonable warning, restrict or suspend the Services.

Article 13 - Price changes

13.1 NEXORA may index its rates once per calendar year on the basis of the movement of an appropriate consumer or services price index published by Statistics Netherlands (CBS), or a successor objective index.

13.2 In addition, NEXORA may adjust its rates in the event of demonstrable substantial changes in taxes, legislation, external licence costs, cloud, AI, banking or other necessary supplier costs. NEXORA shall announce a material non-index-based price increase at least two months in advance.

13.3 In the event of a material non-index-based price increase, Customer has the right to terminate the affected component with effect from the effective date of the increase, unless the increase results directly from changed use, a higher tier, an expansion requested by Customer or mandatory statutory levies.

Article 14 - Suspension

14.1 NEXORA may suspend access in whole or in part if (a) Customer, despite a warning, materially fails to perform, (b) there is an acute security threat, (c) use is unlawful or infringes the rights of third parties, or (d) payment is more than thirty days overdue.

14.2 NEXORA shall apply suspension proportionately and shall restore access as soon as the ground for suspension has been removed. To the extent legally or technically possible, Customer shall retain access during suspension to the functions necessary for a mandatory data export.

Article 15 - Term, notice of termination and termination

15.1 The term and any minimum term shall follow from the Quotation. If nothing has been agreed, the Agreement is entered into for an indefinite period and Customer may terminate it by giving one month's notice, effective at the end of a calendar month.

15.2 An Agreement for a fixed or minimum term cannot be terminated early, unless the Agreement or these General Terms and Conditions expressly grant a right of termination.

15.3 Each Party may rescind the Agreement in whole or in part if the other Party, after written notice of default setting a reasonable period for remedy, continues to materially fail to perform. A notice of default is not required if remedy is permanently impossible or in the event of bankruptcy, liquidation or cessation of the business.

15.4 NEXORA may discontinue a service by giving a reasonable period of notice if continuation is no longer reasonably possible for technical, legal or commercial reasons. NEXORA shall use its best efforts to offer an appropriate migration or alternative arrangement.

Article 16 - Exit, data export and deletion

16.1 After termination, Customer may, for a period of at least thirty days, download its exportable Customer Data in a commonly used, machine-readable format, insofar as the nature of the data permits. NEXORA supports switching and exit in accordance with the applicable rules of the EU Data Act.

16.2 NEXORA shall not charge switching fees insofar as this is not permitted under the Data Act. Additional consultancy, conversion or custom work that is not necessary for the statutory standard export may be performed at the applicable rates.

16.3 Upon expiry of the export or retrieval period, NEXORA shall delete Customer Data from active systems, subject to statutory retention obligations. Data in secured backups shall be deleted or irreversibly kept out of production in accordance with the normal backup cycle.

Article 17 - Ownership of data and use of Service Data

17.1 Customer retains all rights to Customer Data. NEXORA obtains only the right to process Customer Data insofar as necessary for the performance, security, support and improvement of the Services and insofar as permitted under the Agreement and applicable law.

17.2 NEXORA may use aggregated and irreversibly anonymised Service Data for security, product improvement, capacity planning, benchmarking and statistics, provided that such data cannot be traced back to Customer or to natural persons.

17.3 NEXORA does not sell Customer Data. Customer Data is not used to train general or generic AI models of NEXORA or third parties, unless such data has been irreversibly anonymised in advance or Customer has expressly consented to this in writing. Task-specific improvement within the Service may take place subject to the safeguards of the Data Processing Agreement.

Article 18 - Privacy and personal data

18.1 Insofar as NEXORA processes personal data on behalf of Customer, Customer is the controller and NEXORA the processor within the meaning of the GDPR. Annex 1 (Data Processing Agreement) shall then apply in full.

18.2 For personal data that NEXORA processes for its own purposes, such as contact, contract, invoicing and security data, NEXORA acts as an independent controller and NEXORA's privacy policy applies.

18.3 Customer determines which personal data are processed in the Platform and is responsible for a valid legal basis, the duty to inform, retention periods and the use of special categories of personal data.

Article 19 - Confidentiality

19.1 The Parties shall keep confidential all confidential information they obtain in connection with the Agreement and shall use it solely for the performance of the Agreement.

19.2 The duty of confidentiality does not apply to information that is lawfully in the public domain, was already lawfully known, has been independently developed or must be disclosed pursuant to law or a binding order. To the extent permitted by law, the receiving Party shall inform the other Party in advance of a mandatory disclosure.

19.3 The Parties shall impose appropriate confidentiality obligations on employees and engaged third parties who require access to confidential information.

Article 20 - Security

20.1 NEXORA shall take appropriate technical and organisational measures geared to the nature of the Service, the state of the art, the costs of implementation and the risks to the rights and freedoms of data subjects. The main categories of measures are set out in Annex 2.

20.2 NEXORA may change security measures and architecture provided that the level of protection is not materially reduced as a result.

20.3 Customer is responsible for the security of its own devices, networks, email environments, identity management, roles and the correct configuration of integrations and Users.

Article 21 - Intellectual property

21.1 All intellectual property rights in the Platform, Nora, models, software, algorithms, source code, interface, documentation, templates, methodologies, workflows, trademarks and materials developed by NEXORA are vested in NEXORA or its licensors.

21.2 For the term of the Agreement, Customer receives a limited, non-exclusive, non-transferable and non-sublicensable right of use for its own internal business operations, within the agreed numbers and modules.

21.3 The rights in materials supplied by Customer and in Customer Data remain with Customer or the relevant rights holder. Customer grants NEXORA the rights of use necessary to perform the Services.

21.4 Feedback, suggestions for improvement and ideas that Customer voluntarily provides to NEXORA may be used by NEXORA without additional compensation, provided that no confidential information of Customer is thereby disclosed.

Article 22 - Information, signals and no independent professional advice

22.1 The software provides information, signals, classifications, calculations and draft actions in support of business operations. Unless Professional Services have been expressly agreed, these outputs do not constitute independent legal, tax, accountancy, investment, employment law or medical advice.

22.2 Customer shall review, or have reviewed, relevant output before it is used for tax returns, payments, personnel decisions, contractual acts, financial decisions or other acts with legal or financial consequences.

22.3 The fact that NEXORA displays source references, CLA provisions, statutory signals or automations does not release Customer from the responsibility to determine their applicability to its own situation.

Article 23 - Liability

23.1 NEXORA is liable only for direct damage that is the direct result of a failure in performance attributable to NEXORA and after NEXORA, where remedy is possible, has been given a reasonable opportunity to remedy it.

23.2 NEXORA's total cumulative liability per calendar year is limited to the amount that Customer paid to NEXORA for the directly affected Services in the twelve months preceding the event giving rise to the damage, subject to an absolute maximum of EUR 50,000.

23.3 NEXORA is not liable for indirect or consequential damage, including loss of profit, loss of revenue, missed savings, reputational damage, business interruption, loss of opportunity or claims of third parties, except insofar as exclusion is not permitted under mandatory law.

23.4 NEXORA is not liable for damage arising from incorrect, incomplete or late Customer Data, decisions of Customer, unauthorised use, external services or failure to follow clear warnings or checks in the Platform.

23.5 The limitations do not apply in the event of intent or deliberate recklessness on the part of NEXORA's executive management, nor insofar as liability cannot be limited under mandatory law.

23.6 Customer shall report a claim for damages as soon as possible and in any event within three months after Customer has discovered the damage and the possible involvement of NEXORA. A legal claim shall lapse if it has not been brought within twelve months after that report, to the extent permitted by law.

Article 24 - Indemnities

24.1 Customer shall indemnify NEXORA against claims of third parties arising directly from (a) data or content unlawfully supplied by Customer, (b) use of the Services in breach of the Agreement or the law, or (c) employment, tax or other decisions taken by Customer without NEXORA having expressly accepted an obligation of result in that respect.

24.2 NEXORA shall defend Customer against a well-founded claim that standard software developed by NEXORA itself infringes a Dutch or EU intellectual property right, provided that Customer informs NEXORA in good time and leaves the handling of the claim to NEXORA. NEXORA may, at its option, obtain a right of use, modify the functionality or discontinue the affected component with a proportionate refund of amounts paid in advance.

Article 25 - Force majeure

25.1 Neither Party is liable for a failure in performance resulting from force majeure. Force majeure includes, among other things, natural disasters, war, pandemics, large-scale power or internet outages, cyberattacks despite appropriate security, government measures, strikes, failure of essential cloud or telecommunications infrastructure and other circumstances beyond the reasonable control of the affected Party.

25.2 The affected Party shall inform the other Party as soon as possible and shall reasonably limit the consequences. If the force majeure situation lasts longer than sixty days, either Party may terminate the affected part of the Agreement without any obligation to pay compensation.

Article 26 - Third parties, subcontracting and assignment

26.1 NEXORA may engage third parties and group companies for the performance of the Services. The additional safeguards set out in Annex 1 apply to subprocessors.

26.2 Customer may not assign the Agreement without the prior written consent of NEXORA, except as part of a complete legal merger or transfer of the business in which the acquirer assumes all obligations and is not a direct competitor of NEXORA.

26.3 NEXORA may assign the Agreement to a group company or a successor under universal title or in connection with a transfer of the relevant business activity, provided that continuity and core obligations are safeguarded.

Article 27 - Sanctions, export and integrity

27.1 Customer shall not use the Services in breach of applicable sanctions legislation, export restrictions, anti-money laundering rules or other mandatory legislation relevant to the use.

27.2 NEXORA may refuse or suspend access if this is necessary to comply with a binding sanction, an order of a competent authority or a statutory obligation.

Article 28 - Amendment of these terms and conditions

28.1 NEXORA may amend these General Terms and Conditions on account of product development, security, changes in legislation, case law, supervisory requirements, changes in supplier terms or the clarification of existing provisions.

28.2 Non-material amendments may take effect upon publication. For an amendment that materially worsens Customer's contractual position, NEXORA shall inform Customer at least three months in advance, unless a shorter period is necessary on account of mandatory legislation or an urgent security risk.

28.3 If a material amendment substantially adversely affects Customer, Customer may terminate the directly affected component before the effective date. Use after the effective date shall constitute acceptance to the extent permitted by law.

Article 29 - Electronic communication and evidence

29.1 Notices may be given electronically by email, via the Customer Environment, a support ticket or a digital channel designated by NEXORA. Customer shall keep its contact details up to date.

29.2 NEXORA's electronic log files, audit trails, records of sending and receipt, approval actions and system records constitute conclusive evidence of the facts recorded therein, subject to evidence to the contrary provided by Customer.

29.3 Digital acceptance, click-through acceptance and electronic signature have the same contractual effect as a physical signature to the extent permitted by law.

Article 30 - Governing law and disputes

30.1 The Agreement and all legal relationships arising from it are governed exclusively by Dutch law.

30.2 The Parties shall first attempt to resolve a dispute at management level. If no resolution is reached within thirty days, the competent court of the District Court of The Hague (rechtbank Den Haag) shall have exclusive jurisdiction, unless mandatory law provides otherwise.

30.3 The United Nations Convention on Contracts for the International Sale of Goods (CISG) is excluded.

Article 31 - Final provisions

31.1 If a provision is null and void or unenforceable, the remaining provisions shall remain in force. The Parties shall replace the provision concerned with a valid provision that approximates its purpose and intent as closely as possible.

31.2 Failure to exercise a right does not constitute a waiver of that right.

31.3 Provisions which by their nature are intended to survive, including those concerning confidentiality, intellectual property, payment, liability, data export and disputes, shall remain in force after termination.

Part II - Specific NEXORA Modules

The articles in this Part apply additionally as soon as the relevant functionality has been activated in the Quotation, Order Confirmation or Customer Environment.

Article 32 - Platform, Administrations and portals

32.1 The base platform may comprise, among other things, administrations, invoicing, bank connections, dashboards, user management, products, quotations, employee portals and additional modules as specified in the Quotation.

32.2 Customer shall not use more Administrations, admin Users or other licensed units than are included. Extensions may be ordered directly in the Customer Environment or through NEXORA and will be invoiced from the moment of activation.

32.3 The employee portal is intended for persons designated by Customer as employees or authorised users. Customer is responsible for correctly linking identity, rights and employment relationship.

Article 33 - Finance, Accounting and Autobooking

33.1 NEXORA may automatically recognise documents, bank transactions and other financial information, classify proposals, match open items, reconcile and - if Customer activates this - post automatically on the basis of configured rules and confidence thresholds.

33.2 Percentages or claims such as "up to 90% autobooking" are indicative and depend on document quality, source data, configuration, sector, history and exceptions. They do not constitute a guarantee that a specific percentage will be achieved without human review.

33.3 Customer remains responsible for the accuracy of its accounts and for appropriate review of automatic postings. NEXORA may present exceptions and low-confidence cases for assessment.

33.4 Where VAT returns, payment files or other formal outputs are prepared from the Platform, Customer is responsible for final review and explicit approval, unless a different allocation of tasks has been agreed in writing under Professional Services.

Article 34 - Dashboards, Forecasting and Performance

34.1 Dashboards, KPIs, forecasts, scenarios and analyses are built from available Customer Data and selected assumptions. They are intended as management information and may deviate from reality due to incomplete data, delays or assumptions.

34.2 Customer shall verify the relevance of assumptions and data sources before significant decisions are taken. NEXORA does not thereby provide investment advice, credit advice or any guarantee of future results.

Article 35 - Payroll

35.1 The Payroll module supports, among other things, payroll calculations, trial payroll calculations, changes, payslips, payroll tax returns, annual statements and related payroll processes, to the extent activated.

35.2 Customer shall provide changes, terms of employment, contract information, tax data, pension data and absence data completely and in good time. Customer is responsible for the legal accuracy of the terms of employment and for adequate authorisation of data.

35.3 A payroll run shall only be deemed final once the authorised person designated by Customer has approved it, unless a different approval procedure has been laid down in a separate Managed Payroll arrangement.

35.4 NEXORA is not responsible for the timely payment by Customer of net wages, payroll taxes, pension contributions or other amounts, unless this specific payment service has been agreed in writing.

35.5 Corrections after final approval may result in recalculations, correction messages and additional costs where Professional Services are required for this purpose.

Article 36 - HRM, personnel file and talent management

36.1 The HRM module supports personnel files, contracts, leave, absence signals, policies, documents, talent and competency data and other HR processes, to the extent activated.

36.2 Customer remains the employer and is solely responsible for personnel decisions, terms of employment, record-keeping, retention periods, the duty to inform employees and compliance with employment law obligations.

36.3 Customer shall not process via the Platform any medical diagnoses or more health information than is necessary for the permitted HR or absence process. NEXORA may issue warnings where fields are intended for limited absence information.

36.4 Talent, competency and KPI scores are supporting management information and may not be used, without appropriate human assessment, as the sole basis for decisions with significant consequences for an employee.

Article 37 - Planning, rosters and working time

37.1 The Planning module supports rosters, staffing, availability, deployability, requests, communication and, where activated, checks against configured working time rules.

37.2 Signals relating to the Working Hours Act (Arbeidstijdenwet), a collective labour agreement (CLA) or internal rules are verification tools. Customer remains responsible for the final planning, exceptions, consent, rest periods, rules for young workers, pregnancy, on-call duty and other legal circumstances.

37.3 The fact that a roster or deployment proposal can technically be saved does not automatically mean that it is legally permitted.

Article 38 - CLA & Compliance

38.1 NEXORA may structure CLA texts and other sources, extract rules, compare versions, flag applicability and prepare the impact on payroll or planning. Source references and version dates are made visible where possible.

38.2 The applicability of a CLA depends on, among other things, its scope, business activities, declaration of universal applicability (AVV) status, individual employment contracts and exceptions. Customer remains responsible for determining the correct CLA and for situation-specific legal assessment.

38.3 Automatic interpretation of rules is supportive in nature and may miss exceptions. NEXORA may therefore offer checks, confidence indicators and human validation steps. A green or non-deviating status is not a legal guarantee.

38.4 Where legislation or a CLA changes, there may be a period between publication, source processing, validation and activation in the Platform. NEXORA strives to keep the Platform up to date, but does not guarantee immediate processing at the moment of publication.

Article 39 - Nora and other AI Functionality

39.1 Nora is an AI assistant. The user is clearly informed in the interface that he or she is interacting with AI. AI output may be probabilistic and may be incorrect, incomplete or out of date.

39.2 Nora may summarise information, answer questions, flag deviations, generate drafts, prepare scenarios and - if Customer explicitly activates this - prepare or perform actions within defined rights and approval rules.

39.3 Human assessment remains required for actions with financial, tax, employment law, legal or similarly significant consequences. NEXORA positions Nora as a copilot and not as an autonomous final decision-maker, unless a specific function is demonstrably legally permissible and has been expressly agreed as such.

39.4 Customer shall not use Nora for prohibited AI practices, nor as the sole basis for automated decisions producing legal effects or similarly significant effects for individuals without a valid legal basis, appropriate information, human intervention and other safeguards required by law.

39.5 Customer is responsible for the lawfulness of prompts, uploads and instructions. NEXORA may apply technical safety filters, rate limits and policy checks.

39.6 For AI functions, NEXORA may make use of carefully selected model and infrastructure providers as subprocessors or service providers. The processing of personal data is governed by Annex 1. Raw Customer Data is not used for general model training, as provided in Article 17.3.

Article 40 - API, integrations and accountant/partner use

40.1 Where NEXORA offers API access, webhooks, connectors or a partner/accountant portal, the technical limits, authentication requirements and documentation published by NEXORA shall apply.

40.2 Customer is responsible for applications, scripts and integrations that it builds itself or has built by third parties. NEXORA may restrict API traffic in the event of security risks, excessive load or use contrary to the documentation.

40.3 An accountant, adviser or partner who is granted access on behalf of Customer acts under the responsibility of Customer, unless he or she has a separate agreement with NEXORA for separate services.

Article 41 - Implementation, migration and Professional Services

41.1 Implementation, data import, configuration, training, consultancy, accounting support or managed payroll only form part of the Agreement if they are included in the Quotation.

41.2 Customer shall supply source data in the agreed format and, after migration, shall check on a sample basis whether completeness, opening balances, employees, historical data and settings have been correctly transferred.

41.3 Implementation timelines depend on timely cooperation by Customer and third parties and, unless expressly designated as strict deadlines, are target dates.

41.4 Professional Services are performed as an obligation to use reasonable endeavours (inspanningsverplichting) and on the basis of the facts and documents provided by Customer. Where a statutory or professional assessment is required, NEXORA may reasonably request additional information or approval.

41.5 Where NEXORA communicates on behalf of Customer with the Dutch Tax Administration, UWV (Dutch Employee Insurance Agency), pension administrators or other authorities, Customer shall provide the necessary authorisations in good time and Customer remains responsible for the underlying facts and ultimate obligations.

Annex 1 - Data Processing Agreement (GDPR)

This Annex constitutes the data processing agreement referred to in Article 28 GDPR to the extent that NEXORA processes personal data on behalf of Customer.

1. Roles and instructions

Customer is the controller and NEXORA is the processor, unless otherwise agreed in writing for a specific processing operation.

NEXORA processes personal data solely on the documented instructions of Customer, including this Agreement, the chosen configuration and lawful instructions given via the Customer Environment, unless otherwise required by Union law or Dutch law.

NEXORA shall inform Customer if, in its opinion, an instruction infringes privacy legislation and may suspend execution until the instruction has been clarified or amended.

2. Subject matter, duration, nature and purpose

The processing shall continue for as long as the Agreement is in force and during the agreed exit and deletion period.

Purposes include hosting, administration, invoicing, payroll, HRM, planning, document processing, reporting, AI support, support, security, back-up, integrations and other functions activated by Customer.

The specific nature and scope are determined in part by the modules Customer activates and the data Customer processes in them.

3. Data subjects and categories of personal data

Data subjects may include: employees, job applicants, directors, customers of Customer, suppliers, contact persons, shareholders, contractors and other persons appearing in documents or records.

Personal data may include: identification and contact details, financial data, bank details, payroll and tax data, employment contract and HR data, planning and attendance data, user and log data and document content.

Special categories of personal data may only be processed to the extent that Customer enters them lawfully and where necessary. Customer shall avoid storing medical diagnoses or other non-essential health information in general HR fields.

4. Confidentiality

NEXORA shall ensure that persons processing personal data under its authority are bound by a duty of confidentiality and only have access to the extent necessary for their duties.

5. Security

NEXORA shall implement appropriate technical and organisational measures in accordance with Article 32 GDPR. The main categories are set out in Annex 2.

NEXORA shall periodically review its security measures and may amend measures provided that the level of protection remains appropriate.

6. Subprocessors

Customer grants NEXORA general authorisation to engage subprocessors. NEXORA shall make an up-to-date list available via the Website, the Customer Environment or the Trust Center.

NEXORA shall inform Customer in advance of any new subprocessor that materially processes personal data. Customer may object, with reasons, within the notified period on reasonable privacy or security grounds.

NEXORA shall impose on subprocessors data protection obligations that are at least equivalent and shall remain responsible towards Customer for compliance with the processor obligations incumbent on NEXORA.

7. International transfers

Personal data are preferably processed within the EEA. Where a transfer to a third country takes place, NEXORA shall ensure a valid transfer mechanism, such as an adequacy decision or applicable Standard Contractual Clauses, together with supplementary measures where necessary.

8. Data subject rights and DPIA

Taking into account the nature of the processing, NEXORA shall provide Customer with reasonable assistance in respect of data subject requests, DPIAs and prior consultations.

Where additional work falls substantially outside the standard service, reasonable costs may be charged, unless the work is necessitated by a failure on the part of NEXORA.

9. Data breaches

NEXORA shall inform Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.

To the extent available, NEXORA shall provide information on the nature, likely consequences, categories affected, measures taken and a point of contact. Information may be provided in phases if it is not yet fully available.

Customer remains responsible for notifying the supervisory authority and data subjects, unless legislation imposes an obligation directly on NEXORA.

10. Audit and information

NEXORA shall make available the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including relevant security information, audit reports or independent assurance where available.

Customer may request an audit no more than once every twelve months, unless a demonstrable incident or a supervisory authority requires more frequent audits. Audits shall be agreed in advance, shall disrupt the provision of services as little as possible and shall respect the confidentiality and security of other customers.

The costs of a customer-specific audit shall be borne by Customer, unless the audit reveals a material failure on the part of NEXORA.

11. Return and deletion

Upon termination, NEXORA shall enable Customer to export data in accordance with Article 16 and Annex 3. NEXORA shall subsequently delete personal data, unless a statutory retention obligation requires further storage.

Back-up copies shall be deleted in accordance with the normal retention cycle and shall remain shielded from regular use until that time.

Annex 2 - Security measures

NEXORA applies a risk-based security programme. This Annex describes the categories of measures and is deliberately technology-neutral so that measures can be improved without amending the contract.

Access management: role and permission management, least privilege, strong authentication for administrative functions, periodic review of access rights and controlled access by support or technical staff.

Encryption: encrypted communication using up-to-date transport security and appropriate encryption of stored sensitive data where technically appropriate.

Logging and monitoring: recording of relevant security and administrative actions, monitoring for anomalous behaviour and procedures for incident investigation.

Data isolation: logical separation of customer environments and controlled access paths between production, test and development environments.

Back-up and recovery: regular back-ups of relevant production data, recovery procedures and periodic verification of recoverability appropriate to the type of service.

Vulnerabilities and patching: a process for vulnerability management, security updates, dependency management and assessment of critical notifications.

Secure development: code review, controlled deployments, separation of development and production rights and security throughout the software development lifecycle.

Supplier management: assessment of critical cloud and AI providers and subprocessors on relevant security and privacy aspects.

Incident response: an escalation process for security incidents, containment, recovery, communication and evaluation.

Continuity: reasonable measures for business continuity, monitoring and recovery in the event of failures of critical components.

Annex 3 - Data Act, switching and exit

To the extent that NEXORA qualifies as a provider of a data processing service under Regulation (EU) 2023/2854 (Data Act), the following additional arrangements apply.

1. Upon termination, Customer may choose export to another provider, export to its own infrastructure or deletion of exportable data and digital assets.

2. NEXORA shall support a reasonable exit strategy and shall, prior to or during switching, make available information on export formats, dependencies and known continuity risks.

3. The standard transition period shall be no more than thirty calendar days after the end of the applicable notice period, unless this is demonstrably technically unfeasible. In that case NEXORA shall inform Customer in good time, stating reasons and a reasonable alternative period within the limits of applicable legislation.

4. During switching, NEXORA shall maintain appropriate security and continue the necessary provision of services to the extent required by the Agreement and the law.

5. Standard exportable data shall be made available in commonly used, structured and machine-readable formats to the extent technically reasonable and appropriate. Non-exportable items include, among others, source code, NEXORA models, internal security information, platform-wide analytics and intellectual property of NEXORA or third parties.

6. NEXORA shall delete exportable Customer Data after successful switching and expiry of the retrieval period, subject to statutory retention obligations and normal back-up cycles.

7. NEXORA shall not charge switching charges to the extent these are prohibited by the Data Act. Work falling outside statutory switching assistance, such as custom transformation or set-up with a third party, may be performed at rates agreed in advance.

Annex 4 - Service and support framework

This Annex describes the standard framework. If NEXORA publishes or agrees with Customer a separate SLA, that SLA shall prevail with respect to availability, maintenance and response times.

Availability: NEXORA monitors the core environment and strives for high availability. A binding percentage applies only if expressly included in an SLA or Quotation.

Planned maintenance: announced in advance where possible and preferably outside peak hours.

Critical incident: complete or very serious outage of core functions for multiple users; highest priority and continuous triage during applicable service windows.

High incident: important functionality does not work and there is no reasonable workaround; high priority.

Normal incident: limited error, question or problem with a workable workaround; handled in accordance with the normal support queue.

Status communication: NEXORA may provide status updates via the Customer Environment, e-mail, support ticket or status page.

Service credits: applicable only if a specific SLA expressly so provides.

Annex 5 - NEXORA AI and Nora terms of use

This Annex puts into practice the principles: AI supports, people assess, the decision remains human.

Transparency

The interface makes it apparent when a User is interacting with Nora or other AI Functionality. Where required by law, AI-generated or manipulated content is made identifiable as such.

Human oversight

Customer shall put in place appropriate human review of output that may have consequences for tax returns, payments, employees, terms of employment, compliance or other important decisions.

No blind reliance

AI output may contain errors or fabricated details. Users shall verify sources, figures and context before output is used for critical actions.

No prohibited use

Customer shall not use NEXORA AI for AI practices prohibited by law, deception, discrimination, unlawful profiling, social scoring or other prohibited purposes.

HR decisions

Nora and talent/HR signals may not be used, without appropriate human review, as the sole basis for recruitment, appraisal, promotion, dismissal or other decisions with significant consequences for individuals.

Data and prompts

Customer shall only enter data it is authorised to use. Raw Customer Data is not used for general model training, save for the exceptions in Article 17.3.

Model providers

NEXORA may use external models. NEXORA selects and configures these with appropriate contractual and technical safeguards and includes relevant subprocessors in the subprocessor list.

Changing models

Underlying models may be replaced or updated by NEXORA or its providers. As a result, output may change. NEXORA strives for functional continuity and appropriate quality controls.

Audit and logging

Where appropriate, NEXORA may log AI interactions, prompts, actions, confidence indicators and approval moments for security, audit trail and quality control purposes, with due observance of privacy legislation.