Terms and conditions
This is a translation of the Dutch terms and conditions (Algemene voorwaarden). In case of any difference between the versions, the Dutch text prevails.
Article 1 – Definitions
- MindfulSec: the sole proprietorship MindfulSec, registered with the Dutch Chamber of Commerce under number 81091133.
- Client: the natural person acting in the course of a profession or business, or the legal entity, that engages MindfulSec.
- Assignment: the agreement under which MindfulSec provides services such as a pentest, quick scan, security advice, training or phishing simulation.
- Pentest: an authorised security test in which MindfulSec, within an agreed scope, attempts to find and exploit vulnerabilities in web applications and/or APIs.
- Quick scan: a limited, mainly external check of a website, web application or API within an agreed scope.
- Scope: the systems, URLs, IP addresses, API endpoints, accounts, test methods, test period and exclusions recorded in writing.
- Authorisation statement: the written statement signed by the Client that records the Scope and the permission to test.
- Report: the written report containing findings, risk assessment and recommendations.
Article 2 – Applicability
- These terms apply to all quotes, Assignments and services of MindfulSec.
- MindfulSec works exclusively for business clients. These terms are not intended for consumers.
- The Client’s general terms and conditions do not apply unless MindfulSec agrees to them in writing.
- Deviations from these terms only apply if agreed in writing.
- If a provision proves to be void or voidable, the other provisions remain in force. The parties will then replace that provision with one that comes as close as possible to its intent.
Article 3 – Quotes and formation of the agreement
- Quotes are non-binding and valid for 30 days unless stated otherwise.
- Prices on the website are indications ("from") and not an offer. The price of an Assignment follows from the quote, based on the agreed Scope.
- An Assignment is formed when the Client accepts the quote in writing or by email.
- A pentest or quick scan only starts once the Authorisation statement has also been signed (Article 4).
Article 4 – Authorisation and scope
- MindfulSec performs no test whatsoever without a signed Authorisation statement. No testing takes place outside the Scope or outside the test period.
- The Client guarantees that it is authorised to give permission to test all systems within the Scope.
- Where systems are managed or hosted by third parties (such as a hosting company, cloud provider or SaaS vendor), the Client obtains the necessary permission from those third parties before the start. The Client informs MindfulSec of any restrictions set by those third parties.
- The Client appoints a contact person who can be reached during the test period, including for urgent reports.
- Changes to the Scope are recorded in writing and may affect price and planning.
Article 5 – Performance
- MindfulSec performs Assignments to the best of its knowledge and ability, using established methods such as the OWASP guidelines. This is an obligation of effort, not an obligation of result.
- A pentest or quick scan is a snapshot within a limited Scope and time. MindfulSec does not guarantee that all vulnerabilities will be found or that systems will be secure afterwards.
- If MindfulSec finds a critical vulnerability during the test, or signs that the systems have already been compromised by a third party, MindfulSec reports this immediately to the contact person. MindfulSec may then pause the test until consultation has taken place.
- MindfulSec may stop the test immediately if the stability of systems appears to be at risk.
- MindfulSec performs the Assignment personally. Third parties are only engaged with the Client’s written consent.
Article 6 – Risks of testing
- The Client acknowledges that security testing, even when carried out carefully, may cause delays, disruption, unavailability or changes to data.
- Before the start, the Client makes up-to-date backups of all systems and data within the Scope and checks that they can be restored.
- The Client preferably has testing done on a test or acceptance environment. If the Client chooses a production environment, the Client bears the risk of disruption of that environment, except in the case of intent or deliberate recklessness on the part of MindfulSec.
Article 7 – Obligations of the Client
- The Client provides all information, test accounts, access and documentation that MindfulSec needs, in good time.
- The Client informs relevant parties, such as an administrator or monitoring service, of the test period so that the test is not wrongly treated as an attack.
- If the Client does not provide what is needed in time, MindfulSec may suspend performance and charge the additional costs.
Article 8 – Training and phishing simulations
- For a phishing simulation, the parties agree in writing beforehand on the target group, the scenarios, the period and which data will be collected.
- The Client is responsible for the lawfulness of a phishing simulation towards its employees, for example informing employees and, where applicable, the works council, and complying with privacy rules.
- By default, MindfulSec reports phishing simulation results at group level, not per person, unless agreed otherwise in writing.
- A training session can be rescheduled free of charge up to 5 working days before the date. After that, Article 13 applies.
Article 9 – Advice
- Advice, policy documents and incident response plans from MindfulSec are based on the information provided by the Client and on the knowledge available at that time.
- The Client remains responsible for deciding whether to follow advice and for implementing it.
- MindfulSec does not guarantee that, after following advice, the Client complies with laws, regulations or a standard.
- MindfulSec is independent of vendors. If MindfulSec receives a fee from a vendor it recommends, MindfulSec discloses this in advance.
Article 10 – Reporting and intellectual property
- After a pentest or quick scan, the Client receives a Report. A pentest includes a debrief and one retest of the reported findings, to be carried out within 3 months of delivery of the Report.
- The Report is intended for the Client’s internal use. The Client may share it with its own advisers, auditors or customers who need it, stating that it is a snapshot.
- Intellectual property rights in reports, training material, methods and tools remain with MindfulSec. The Client receives a non-exclusive right of use for its own internal purposes once all invoices have been paid.
- MindfulSec may use anonymised and non-traceable insights for knowledge sharing and content. MindfulSec only uses a case with a name or recognisable details with the Client’s written consent.
Article 11 – Confidentiality
- Both parties keep confidential information secret, including after the Assignment has ended. Findings, vulnerabilities, access credentials and reports are always confidential.
- MindfulSec stores test data and reports encrypted and deletes access credentials after the Assignment has ended.
- MindfulSec deletes other test data no later than 12 months after completion, unless the parties agree otherwise or a statutory retention obligation applies.
- The duty of confidentiality does not apply where a legal obligation or court order requires disclosure.
Article 12 – Personal data
- If MindfulSec may access or process the Client’s personal data during an Assignment, the parties conclude a data processing agreement.
- MindfulSec processes personal data only to the extent necessary for the Assignment, and does not copy or export more data than needed to demonstrate a vulnerability.
Article 13 – Prices, payment and cancellation
- All prices are in euros and exclude VAT.
- Work outside the agreed Scope (additional work) is only performed with the Client’s approval and is invoiced at the hourly rate applicable at that time.
- Payment is due within 14 days of the invoice date. MindfulSec may request a deposit of 50% upon confirmation of the Assignment.
- In the event of late payment, the Client is in default without notice of default and owes the statutory commercial interest under Dutch law. Reasonable collection costs are borne by the Client.
- If the Client cancels or reschedules a planned Assignment, the following is due: more than 10 working days before the start, no costs; 5 to 10 working days before the start, 25% of the Assignment fee; fewer than 5 working days before the start, 50% of the Assignment fee.
- If MindfulSec has to interrupt a test due to a cause on the Client’s side (for example no access or an unreachable contact person), MindfulSec may charge for the time lost.
Article 14 – Liability
- MindfulSec is only liable for direct damage resulting from an attributable failure in the performance of the Assignment.
- Liability is limited to the amount paid out by MindfulSec’s professional liability insurance in the case concerned, plus the deductible. If the insurance does not pay out, liability is limited to the invoice amount of the Assignment (excluding VAT), up to a maximum of the amount invoiced over the last 6 months.
- MindfulSec is not liable for indirect damage, including consequential damage, lost profit, lost savings, business interruption, reputational damage and loss of or damage to data.
- MindfulSec is not liable for damage caused by disruption or loss of data as a result of testing within the Scope (Article 6), for damage caused by incorrect or incomplete information from the Client, or for vulnerabilities that were not found (Article 5.2).
- The limitations in this Article do not apply in the case of intent or deliberate recklessness on the part of MindfulSec.
- A claim for damages lapses if the Client does not report the damage in writing within 3 months of discovery, and in any event 12 months after completion of the Assignment.
Article 15 – Indemnification
The Client indemnifies MindfulSec against claims from third parties (such as hosting companies, cloud providers or employees) related to work within the Scope. This applies in particular if the Client was not authorised to give permission or had not arranged third-party permission (Article 4), except in the case of intent or deliberate recklessness on the part of MindfulSec.
Article 16 – Force majeure
- MindfulSec is not obliged to perform in the event of force majeure, such as illness, failures at third parties (internet, power, hosting) or government measures.
- If force majeure lasts longer than 30 days, either party may terminate the Assignment in writing. Work already delivered is invoiced proportionally.
Article 17 – Complaints
- The Client reports complaints about the performance in writing within 14 days of delivery via [email protected], describing them as clearly as possible.
- If a complaint is justified, MindfulSec performs the work concerned after all or again. If that is no longer meaningful, Article 14 applies.
- A complaint does not suspend the payment obligation.
Article 18 – Governing law and disputes
- All Assignments are governed by Dutch law.
- Disputes are submitted to the competent court in the district where MindfulSec is established, unless mandatory law provides otherwise.
- MindfulSec may amend these terms. Ongoing Assignments are governed by the terms applicable at the time the Assignment was formed.
- These terms are available in Dutch, English and Portuguese. In case of any difference between the versions, the Dutch text prevails.