OrderMage

Terms and conditions

Terms and conditions

Terms and Conditions

for the Use of the OBJEDNÁME System

Effective as of 1.1.2026

Version Number 1.0.0

1. Introductory provisions and definitions

1.1. Provider

1.1.1 The Provider is the company Objednáme s.r.o., with its registered office at Mlýnská 942/13, 737 01 Český Těšín, Company ID No.: 06419518, registered in the Commercial Register maintained by the Regional Court in Ostrava, under File No. C 71855.

1.1.2 Provider’s Contact Details:

a) address for correspondence: Francouzská 5, Ostrava 70800

b) e-mail address:

info@objedname.eu

1.2. Objednáme System

1.2.1 The Objednáme System is a comprehensive information system designed for operators of restaurants and catering establishments, which the Client can independently activate, configure, and expand.

1.2.2 The Provider enables individual Clients to use the Objednáme System as a SaaS service through remote access to the Provider’s server, where the Objednáme System, including the Client’s data, is hosted. End users access the System via local Applications installed on the Client’s devices and connected to the Provider’s server.

1.3. Definitions of Terms

1.3.1 Admin Panel – the administrative interface of the System through which the Client can, inter alia, activate Products, order Optional Services, communicate with the Provider, etc.;

1.3.2 Activation – enabling access to the System or an individual Product by the Provider, whereby Activation is conditional upon payment of the Subscription Fee unless the Provider offers the Client Activation in a temporary Trial Mode;

1.3.3 Application – any mobile application intended for devices (e.g., mobile phone, tablet) with iOS or Android operating systems, made available by the Provider within the System or individual Products;

1.3.4 Optional Services Fee – the price for Optional Services offered by the Provider;

1.3.5 Price List – the Provider’s price list made available in the Admin Panel, which includes selected prices for Optional Services and the Provider’s hourly rates;

1.3.6 Addendum – an addendum to the Contract under which the Client activates a Product or provides an Optional Service; the Addendum is typically concluded electronically through the Admin Panel;

1.3.7 Client’s Email Address – the email address specified by the Client in the Admin Panel as their official email address;

1.3.8 Franchise – collectively refers to situations where the Client operates multiple branches or offers third parties the opportunity to operate one or more branches under a franchise agreement, using the Client’s brand and under the conditions set by the Client;

1.3.9 End User – a user on the Client’s side to whom the Client has granted access to the System or selected Products, or specific parts thereof;

1.3.10 Regulation – the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council on data protection;

1.3.11 Subscription Period – the period during which the Client has the right to access the System or individual Products for which the Subscription Fee has been paid;

1.3.12 Product – an independent functional component of the System that extends the System’s functionality and can be activated by the Client via the Admin Panel based on an Addendum;

1.3.13 Terms and Conditions – these Terms and Conditions for the use of the Objednáme System, forming part of the Contract and any Addenda referenced herein;

1.3.14 Subscription Fee – the fee paid by the Client in advance for the use of the System, individual Products, and Maintenance and Support Services. The total amount of the Subscription Fee may be determined individually for each Product;

1.3.15 Registration – the electronic process of identifying the Client through a registration form;

1.3.16 Contract – the Contract on the use of the Objednáme System concluded between the Provider and the Client;

1.3.17 Contracting Parties – collectively, the Client and the Provider;

1.3.18 System – collectively, the Objednáme System as described in Article 1.2, made available as a SaaS service, including all activated Products;

1.3.19 Test Operation – a temporary trial mode during which Products activated by the Client are made available free of charge. The Provider reserves the right to terminate Test Operation at any time;

1.3.20 Maintenance and Support Services – services specified in Article 3, aimed at ongoing maintenance and updates of the System (e.g., release of new versions, patches, updates) and resolution of incidents;

1.3.21 Optional Services – services offered by the Provider, typically related to the customization of individual Products, consultancy, training, etc.;

1.3.22 Customer – the Client’s customer or a person interested in the Client’s services, who places an order through any Product.

2. Contract and Subject of the Contract

2.1. Registration and Conclusion of the Contract

2.1.1 The Contract is concluded electronically between the Client and the Provider via a registration form available on the Provider’s website. During Registration, the Client shall:

a) provide identification and contact details as required by the Provider or log in via an alternative account (so-called SSO login, e.g., using a Google or Apple account),

b) select Products (additional Products may be activated later, see Article 2.2),

c) order Optional Services (additional Optional Services may also be ordered later, see Article 2.2),

d) provide other optional data and information related to the Client’s establishments.

2.1.2 Submission of the completed registration form is conditional upon the Client’s acceptance of these Terms and Conditions.

2.1.3 Submission of the registration form is considered the Client’s proposal to conclude the Contract and any Addenda if the Client has activated Products or ordered Optional Services during Registration.

2.1.4 The Provider shall confirm the conclusion of the Contract or any Addenda via the Admin Panel. Sending an invoice for payment of the fee for using the System or individual Products is also considered acceptance of the proposal to conclude an Addendum. The Provider will generally send confirmation of the conclusion of the Contract or Addendum electronically to the Client’s Email Address.

2.2. Subsequent Activation of Products and Ordering of Optional Services

2.2.1 The Client may continuously activate or deactivate individual Products, modify their settings (if permitted by the Provider), and order Optional Services via the Admin Panel.

2.2.2 Rights and obligations related to the Activation and use of individual Products are governed by specific electronic Addenda, which are available in the Admin Panel. Unless otherwise stated in the Addendum (e.g., if the Provider offers temporary free Activation in Test Mode), the Activation and availability of a given Product are conditional upon the Client’s acceptance of the Addendum and proper payment of the Subscription Fee.

2.2.3 Optional Services are of an individual nature; therefore, after placing an order for an Optional Service, the Provider typically contacts the Client to agree on details and any necessary cooperation from the Client to deliver the Optional Service. In certain cases, the Optional Service can be ordered directly via the Admin Panel. Rights and obligations related to the provision of specific Optional Services are governed by individual electronic Addenda, which are available in the Admin Panel, and acceptance of these Addenda is a prerequisite for submitting an order for an Optional Service.

2.3. Subject of the Contract

2.3.1 The Provider undertakes, to the extent specified in these Terms and Conditions and the Addenda, to:

a) make the System available and activated for the Client and allow its use during the temporary Test Mode and subsequently during the Subscription Period,

b) provide Maintenance and Support Services after the Subscription Period,

c) deliver Optional Services to the Client as agreed in the relevant Addendum.

2.3.2 The subject matter of the Contract is not, and the Provider does not provide activities and services not expressly mentioned in these Terms and Conditions or Annexes, even though they may be essential for the proper functionality of the System.

2.3.3 The Client undertakes to:

a) use the System and individual Products exclusively in accordance with these Terms and Conditions and the respective Addenda;

b) pay the Provider the Subscription Fee under the conditions specified in these Terms and Conditions and the Addenda;

c) pay the Provider the agreed price for Optional Services and provide the necessary cooperation.

2.4. Relationship Between These Terms and Conditions and the Addendum

2.4.1 The Addendum governs specific conditions related to a particular Product; however, these Terms and Conditions also apply to the legal relationship established by the conclusion of the Addendum. 3 / 19

Certain provisions of these Terms and Conditions may be excluded or modified in the Addendum, in which case the provisions of the Addendum take precedence over those in these Terms and Conditions.

2.5. Communication Between the Contracting Parties

2.5.1 The Client acknowledges and agrees that, unless explicitly stated in these Terms and Conditions that a specific action must be taken “in writing” or through the Admin Panel, all notifications, requests, warnings, invoices, or other actions related to the relationship established under the Contract or Addendum may be performed via:

a) email sent to the Client’s Email Address or the Provider’s email address as specified in Article 1.1.2, without requiring the emails to be electronically signed, or

b) a data mailbox, or

c) the Admin Panel, if such action (submission) is enabled through it.

3. Use and Configuration of the System

3.1. System as a SaaS Service

3.1.1 During the Subscription Period, the Client acquires a non-exclusive, non-transferable, worldwide right to access and use the System solely for the Client’s internal business operations or for a Franchise, in compliance with these Terms and Conditions, specifically:

a) for a limited number of concurrently active End Users,

b) under additional conditions, if specified in the individual Addenda for specific Products.

3.1.2 The Client acknowledges that the Contract is a service agreement, and the Provider will not supply any copies of computer programs to the Client. Consequently, the Client does not have the right to access the software code (including object code, intermediate code, or source code) during the Subscription Period or after its termination.

3.2. System Configuration and Installation

3.2.1 After Activation, the Client is responsible for configuring the System through the Admin Panel, including the selection of individual Products. The Client also independently installs parts of the System on their selected end devices (e.g., tablets). Such services by the Provider are not included in the Subscription Fee.

3.2.2 During the configuration process, the Client can create access for individual End Users in the Admin Panel, including managing specific End User groups’ access to particular parts or functionalities of the System.

3.2.3 The Client may order System configuration, installation of parts of the System on end devices, consulting services, training, and other Optional Services offered by the Provider as an Optional Service. The specific conditions and timeframe for providing the service will be agreed upon between the Client and the Provider in an Addendum.

3.3. System Activation

3.3.1 The System, or individual Products, will only be activated after the Client has paid the applicable Subscription Fee, unless the Provider offers temporary free Activation of the System or a specific Product as part of Test Mode. The Client acknowledges that Activation may be delayed, for example, due to issues on the part of payment service providers, by up to 72 hours.

4 / 19

3.4. Provision of Data Storage Space and Access Passwords

3.4.1 The Provider undertakes to provide the Client with sufficient data storage space throughout the term of the Contract for the purpose of storing data used within the System. This data storage is provided on the Provider’s servers, hosted in a hosting centre operated by a third party. The cost of providing data storage is included in the Subscription Fee.

3.4.2 The Client is obligated to keep access passwords to the System or other accounts used for logging into the System confidential and treat them as sensitive information. The Provider is not liable for the disclosure of access passwords, which are stored in an encrypted state within the System.

3.5. Data Handling and Personal Data

3.5.1 Given that the Provider acts as a processor of personal data processed within the System (Article 4(8) of the Regulation), the Contracting Parties have entered into a data processing contact pursuant to Article 28(3) of the Regulation, which is an annex to these Terms and Conditions.

3.5.2 To protect the Client’s data against unauthorized or accidental disclosure, the Provider implements appropriate and reasonable technical and organizational measures, as described in the data processing contract. However, this does not affect the Client’s obligation to handle access credentials in accordance with Article 3.4.2.

3.5.3 In the capacity of a personal data controller (Article 4(7) of the Regulation), the Provider processes personal data of persons representing the Client (e.g. a member of the statutory body, other representative, contact person in matters of the Contract, end user of the System), only for the purpose of communication with the Client or individual employees of the Client. Such processing of personal data is necessary for the purposes of the Provider's legitimate interests within the meaning of Article 6(1)(f) of the Regulation, whereby the Provider processes only personal data that are identifying (first and last name), addressable (e-mail address and telephone number/mobile phone number only), descriptive only to the extent of the Client’s representative (e.g. academic degree next to the name), as well as records of communication related to the Contract or the System (requests, complaints, confirmation of service intervention performed). The Provider's necessary legitimate interest in processing the above personal data is the need to communicate with the Client and to fulfil the obligations under the Contract.

3.5.4 If the Contract is concluded with a Client who is a sole trader (natural person conducting business), Article 3.5.3 applies mutatis mutandis. The legal basis for processing the personal data of a sole trader is Article 6(1)(b) of the Regulation, as such processing is necessary for the performance of the Contract to which the data subject is a party.

3.5.5 The Client is obliged to inform individuals acting as its representatives or end users of the System, whose personal data are disclosed to the Provider in connection with the conclusion of the Contract, about their data subject rights in full compliance with Articles 13 and, where applicable, 14 of the Regulation.

3.6. References

3.6.1 The Provider is entitled to publish information in its informational and promotional materials or reference lists stating that the Client has used or is using the Provider’s products or services. This information may also be disclosed via the internet or other means of communication (hereinafter referred to as “Reference”). For this purpose, the Provider is authorized to use the Client’s current logo and trademarks and may include a brief description of the Client (such as the industry of their business or highlighting their size) or a case study of the implementation or use of a specific product or service as part of the Reference. 5 / 19

4. Maintenance and Support Services

4.1. System Updates, Development, Downtime, and Availability

4.1.1 The Provider is entitled to continuously develop the System and perform necessary updates, primarily to improve the System’s stability and to respond to advancements in information technology (e.g., new versions of third-party web browsers). Updates may also be carried out to expand functionality. The provisions of Section 2389d of the Civil Code do not apply to the Contract, and the rights and obligations related to System updates are governed by these Terms and Conditions.

4.1.2 Any changes to the System, including its graphics, control elements, or other modifications, do not constitute a defect of the System. The Client is not entitled to previous versions of the System or any custom modifications.

4.1.3 The Provider is authorized to carry out ongoing maintenance and modifications to the System. In this context, the Provider may temporarily suspend the operation of the System or significantly limit its operation (downtime) for the necessary period. If feasible, the Provider will notify the Client of such downtime in advance via the System’s administrative interface or email. This provision does not affect the Provider’s obligation under Article 4.1.4.

4.1.4 The Provider undertakes to ensure the System’s availability during the Subscription Period, maintaining its essential functions and features, including remote access for the Client to their data hosted on the Provider’s server. The Provider’s obligation to ensure System availability is considered fulfilled in a given month if downtimes and/or critical incidents caused by the Provider do not exceed a total of 48 hours in that month (tolerance limit).

4.1.5 Periods of System unavailability due to circumstances described in Article 4.4.5(c), force majeure (Article 6.3.4), other reasons beyond the Provider’s control (Article 6.3.2), or as a result of enforcing rights related to unlawful content disseminated by the Client via the System (Article 6.2.6), are not counted toward the tolerance limit outlined in Article 4.1.4.

4.2. Backup and Archiving of Client Data

4.2.1 The System enables the Client to export data stored within the System in commonly used formats that allow for data processing by the Client or third parties. The Client may back up their data on an ongoing basis and acknowledges that the Provider is not obligated to perform any data backups for the Client and is not liable for any loss or damage to data stored in the System. Data stored in the System, including receipts, is retained for a period of only three months, after which it is continuously deleted without the possibility of recovery. The Client has the option to configure automatic data export to another information system, such as an accounting system.

4.2.2 The Provider does not perform data archiving or store data on external media (e.g., DVDs, backup drives).

4.3. Client Cooperation and Conditions for Proper System Operation

4.3.1 The Client acknowledges that the proper and flawless operation of the System, including its components installed on the Client’s devices, requires that the Client’s devices and other IT infrastructure components (digital environment) meet the technical specifications provided in the Admin Panel before Activation or subsequent Activation of Products or Optional Services. These specifications primarily include requirements for internet connection capacity and hardware specifications for end devices (e.g., laptops, tablets, printers) used to operate local applications or other System components. Meeting these requirements is essential for seamless use of the System and its proper functionality.

4.3.2 The Client acknowledges that the minimum configuration and internet connection speed requirements may change over time, particularly due to technological advancements and the general increase in hardware and internet connection demands, which may result in increased costs for the Client. The Provider regularly publishes updated requirements for minimum configuration and internet connection speed on its website.

4.3.3 The provisions of Section 2389e of the Civil Code do not apply to the Contract, and the rights and obligations related to defects in the System and the Client’s digital environment are governed by these Terms and Conditions.

4.3.4 The Client is obligated to provide the Provider with the necessary cooperation to enable the Provider to fulfil its obligations under the Contract or Addendum.

4.4. Incident Resolution

4.4.1 The Provider is obligated to respond to incidents in the manner and within the timeframes specified in this Article of the Terms and Conditions. The response time depends on the nature of the incident, classified as follows:

a) Critical Incident – a complete outage of the Product, making it entirely unavailable to the Client’s end users, or complete non-functionality of the Product.

b) Non-Critical Incident – any incident other than a Critical Incident, such as cases where the Product is accessible or partially functional, but data processing speed is reduced, or certain secondary functions exhibit errors.

4.4.2 The Client must report incidents via email, providing a description of the incident, when and how it occurred (or when it was detected), how it manifests, and attaching or copying any error messages, if applicable. If this information is not apparent from the email, the reporting individual must be specifically identified.

4.4.3 The Provider must respond (response time):

a) to a Critical Incident within 24 hours of its reporting,

b) to a Non-Critical Incident within five (5) business days of its reporting.

4.4.4 The response time runs only on business days between 9:00 AM and 5:00 PM. The response time is automatically extended by any period during which remote access was unavailable due to reasons attributable to the Client or third parties.

4.4.5 The Client acknowledges that incidents are often not caused by defects in the System but by other factors listed below. An incident is considered resolved when the Provider:

a) fixes the defect in the System (i.e., restores its agreed functionalities, if the incident was caused by a defect in the System), or

b) provides the Client with instructions for using the System in a way that mitigates the impact of a Critical or Non-Critical Incident, minimizing disruption to the Client’s operations or risk of data loss until the defect is fully resolved, or

c) identifies and informs the Client of the incident’s cause if it was due to:

- defects or failures in the Client’s hardware, software, or services upon which the System’s proper functionality depends (e.g., equipment malfunctions, software issues, or internet connection outages), or improper actions by the Client’s end users (e.g., incorrect device settings, disabling Wi-Fi, activating “airplane mode” on mobile devices, or inputting incorrect data or files in incompatible formats or sizes),

- failures on the part of third-party service or hardware providers (e.g., internet service outages),

- the Client’s failure to provide necessary cooperation or meet the prerequisites for the System’s proper functionality (especially obligations under Article 4.3.1),

- unavailability of third-party data processed by the System,

- changes to data formats, information systems, or procedures of third parties upon which the System or its components depend,

- other unforeseeable events beyond the Provider’s control (e.g., operating system issues, hardware failures, or disruptions caused by web hosting service providers).

4.4.6 If the Client reports more than three (3) incidents in a given calendar month for which the Provider proves that the primary cause was a defect or service failure of third parties or the Client’s own actions (as specified in Article 4.4.5(c)), the Provider is entitled to reasonable compensation. This will be calculated as a multiple of the hourly rate specified in the Price List and the actual hours the Provider spent identifying incidents reported by the Client that were not caused by defects in the System. Time spent traveling to the relevant premises is also included for this purpose. The Provider must submit a written claim specifying the cause of the incident and the amount of time and costs incurred.

4.5. Hotline and Communication Between Contracting Parties

4.5.1 The Provider operates a hotline on business days from 9:00 AM to 5:00 PM, where basic technical support is provided to the Client’s staff free of charge, and incident reports are accepted.

5. Pricing Arrangements and Payment Terms

5.1. Subscription Fees and Changes to Subscription Fees

5.1.1 The Client shall pay a Subscription Fee for the Activation of the System and individual Products. The amount of the Subscription Fee is specified in the Admin Panel, and the Client is informed of it before the Activation of the System or a specific Product. Unless explicitly agreed otherwise, the Subscription Fee paid is non-refundable.

5.1.2 The Client pays the Subscription Fee in advance, either monthly or annually, based on their selection in the Admin Panel.

5.1.3 If the Client does not deactivate the Subscription in the manner described in Article 7.2.1 before the billing date, the Provider is entitled to charge the cost of the next Subscription Period to the payment method provided by the Client.

5.1.4 If the Client activates an additional Product during the current Subscription Period (see Article 2.2), that Product will only be available for the remaining duration of the current Subscription Period. In such cases, the Provider will charge a pro-rata portion of the price for accessing the additionally activated Product. If the Client does not cancel the Subscription for the additionally activated Product in accordance with Article 7.2.1, it will automatically renew for the next Subscription Period. This renewed Subscription Period will apply uniformly to all activated Products.

5.2. Price of Optional Services

5.2.1 The price of Optional Services may be specified in the Admin Panel or agreed upon individually with the Client.

5.3. Invoicing and Payment Terms

5.3.1 At the time of Registration, the Provider offers one or more payment methods. The Subscription Fee

will be charged to the payment method provided by the Client.

5.3.2 The Provider will make tax documents (invoices) available to the Client only via the Admin Panel. If the Client opts for it, the Provider will also send the invoice electronically in PDF or another suitable format.

5.4. Changes to Subscription Fees, Price List, and Prices of Optional Services

5.4.1 The Provider reserves the right to unilaterally increase the Subscription Fee at any time during the term of the Contract. However, already paid Subscription Fees cannot be increased retroactively. Article 8.1 applies appropriately to any increase in the Subscription Fee and the Provider’s obligation to inform the Client about the increase.

5.4.2 The Provider is also entitled to unilaterally amend the Price List at any time during the term of the Contract, including increasing the rates and prices specified therein.

5.4.3 The Provider may unilaterally increase the prices of Optional Services at any time during the term of the Contract. However, the price of an Optional Service already agreed upon in an Addendum cannot be increased retroactively.

5.5. Suspension of the Client’s Access to the System

5.5.1 In the event of the Client’s failure to pay the Subscription Fee or part thereof (e.g., due to the expiration of the payment method or other reasons), the Provider will automatically suspend the Client’s access to the System or the respective Product until the outstanding amount is paid. The Client is not entitled to compensation for damages and/or contractual penalties resulting from such action by the Provider, which does not constitute a delay or incident caused by the Provider.

5.5.2 If the Client’s access to the System is suspended under Article 5.5.1, the Provider must restore access to the System, including all agreed functionalities, within 72 hours of the outstanding payment being credited to its account.

5.5.3 This Article 5.5 does not affect the Provider’s right to terminate the Contract due to its material breach.

6. Liability and Confidentiality Obligations

6.1. Liability for Legal Defects

6.1.1 The Provider guarantees that the System and any other deliverables provided under the Contract are free of third-party rights.

6.1.2 If it becomes evident that a third party asserts rights over the System or another copyrighted work provided or created under the Contract, the Provider must supply the necessary documentation and support for legal defence or take corrective action. The Client must promptly inform the Provider of any third-party claims due to legal defects. In the event of legal proceedings, the Client must diligently pursue the case and take all necessary actions to prevent their rights from being undermined by insufficient legal defence.

6.2. Liability for Content

6.2.1 Except for creating graphical designs as part of ordered Optional Services, the Provider does not participate in creating content that the Client publishes or distributes via the System, whether through specific Products or directly to Customers or third parties (e.g., delivery service operators). The Provider does not create or supply the Client with photographs, texts, images, or other elements that could be copyrighted. The Provider is not obligated to monitor this content or content hosted on third-party servers to which the Client may link.

6.2.2 If the Provider places photographs, texts, images, or other content into specific Products as part of an ordered Optional Service, the content is always supplied by the Client. The Client must ensure that the publication of such content does not infringe on any third-party rights, including personality rights or data protection rights, and does not violate legal regulations, such as copyright laws or industrial property rights.

6.2.3 The Client must not make any unlawful content available via the System and must ensure the compliance of all content published via the System. Unlawful content includes, but is not limited to, content that infringes on the personality rights of third parties, harms the reputation of legal entities, constitutes unfair competition, infringes on copyright or industrial property rights, or promotes illegal or criminal activities.

6.2.4 The Client is prohibited from sending unsolicited commercial communications (SPAM) through the System under Act No. 480/2004 Coll. on Certain Information Society Services.

6.2.5 If a third party contacts the Provider concerning unlawful content published by the Client via the System, the Client must promptly provide the necessary explanations and information to the Provider. This does not affect the Provider’s rights under Article 6.2.6.

6.2.6 Upon discovering a violation of Articles 6.2.3 or 6.2.4, the Provider may:

a) temporarily remove or restrict access to the Client’s unlawful content, and/or

b) deactivate the Client’s ability to send commercial communications via the System, and/or

c) terminate the Contract and subsequently remove or restrict access to all data stored by the Client on the Provider’s servers.

6.2.7 The deletion of unlawful content or deactivation of the entire System under Article 6.2.6 does not constitute a defect in the System or a breach of the Provider’s obligations, even if a court or authority later determines that the content was not unlawful.

6.2.8 If the System or the Client’s data is lawfully removed or restricted, the Client is not entitled to a refund of the Subscription Fee, either in full or in part.

6.3. Liability for Damages

6.3.1 Each Contracting Party is liable for actual damages caused by a culpable breach of their obligations under the Contract or these Terms and Conditions. Neither Party is liable for lost profits. The right to compensation for actual damages is limited to an amount equal to the annual Subscription Fee (if the Client pays annually) or the monthly Subscription Fee (if the Client pays monthly) paid in the year or month in which the damage was reported. This calculation includes all additionally activated Products, excluding VAT. The Provider is not liable for damages beyond this limit unless the damages result from intentional or grossly negligent acts.

6.3.2 The System is not accounting or tax software. The Provider is not liable for any documents generated by the System (e.g., payment receipts or daily reports of received and dispatched orders) or for their use by the Client in relation to their tax, accounting, or record-keeping obligations. The Client must always verify the accuracy of documents generated by the System.

6.3.3 The Provider shall not be liable for damage caused by unavailability of the System or incidents if they were caused by the Client, third parties or circumstances excluding liability. In particular, the Provider shall not be liable for damage caused by

a) the circumstances referred to in Article 4.4.5 c);

b) failure of the Client to provide the necessary assistance, e.g. failure to meet the minimum system or other requirements for the operation of the System, or failure to enable automatic updates or 10 / 19

failure to perform the necessary setup of firewalls and other parts of the Client's IT infrastructure (digital environment) (see Article 4.3);

c) infecting the Client's local network or the Client's computers with computer viruses (spyware, malware, etc.) or hacker attacks or other similar external attacks;

d) improper functioning of technical equipment, operating system, network or other part of the Client's IT infrastructure (digital environment),

e) proven leakage of access passwords to third parties caused by the Client.

6.3.4 The Provider shall be exempt from the obligation to compensate for damages if it is temporarily or permanently prevented from fulfilling its obligations under the Contract by an extraordinary, unforeseeable and insurmountable obstacle arising independently of its will (§ 2913 of the Civil Code); if such an obstacle occurs, the Provider shall notify the Client thereof without undue delay. In particular, unforeseeable and insurmountable obstacles are considered to be extraordinary

a) penetration of viruses into the Client's information system or other similar attack;

b) war, pandemic or epidemic, or strike, if any of these obstacles makes the Provider's business activities impossible or restricted;

c) natural disaster, if such impediment prevents or restricts the Provider's business activities or causes interruptions in the Provider's performance under the Contract;

d) widespread power or internet outages caused by a natural disaster, terrorist or other attack or strike.

6.3.5 The effects excluding liability shall be limited to the duration of the impediment to which such effects are related, unless such circumstances result in software failures, defects or complete destruction of technical equipment or software necessary for the operation of the System, or defects in technical equipment or software of third party manufacturers.

6.4. Confidentiality

6.4.1 The Parties mutually undertake to maintain confidentiality of all material facts obtained in the course of their activities under the Contract, in particular those facts constituting their trade secrets within the meaning of Section 504 of the Civil Code and confidential information (hereinafter referred to as the "Confidentiality Obligation").

6.4.2 Trade secrets consist of competitively significant, identifiable, valuable and normally unavailable in the relevant business circles facts which are related to the Plant and whose owner ensures their confidentiality in an appropriate manner in its interest.

6.4.3 A breach of the Confidentiality Obligation shall be qualified as an act by which one Party wrongfully discloses to another person, makes available, uses for itself or for another, trade secrets or confidential information obtained in the course of its business from the other Party, if this is contrary to the interests of the other Party, and does so without its consent.

6.4.4 Breach of the Confidentiality Obligation is not:

a) disclosure of confidential information to the extent necessary to authorities or persons legally entitled to such information and to control the activities of the Parties;

b) the disclosure of confidential information to persons who are legally bound to confidentiality (notary, lawyer, tax advisor);

c) providing the Client's data or allowing the Provider access to such data to third parties in order to resolve incidents (troubleshooting, etc.), but only to the extent necessary, whereby the Provider is obliged to inform such persons that the information is confidential information of the Client;

d) use of Confidential Information in accordance with this Contract or with the express consent of the relevant Party.

6.4.5 The Parties shall be bound by the Confidentiality Obligation for the duration of the facts giving rise to the Confidentiality Obligation, unless the Confidentiality Obligation is waived or the information in question otherwise becomes publicly available.

7. Termination of the Contract or Amendment

7.1. Duration of the Contract and the Addendum

7.1.1 The Contract shall be for an indefinite term.

7.1.2 The Addendum is agreed for a fixed term, namely for the Subscription Period with the possibility of automatic renewal.

7.2. Subscription Period, Deactivation of the Subscription by the Client and Automatic Renewal

7.2.1 The Client selects the renewal frequency for the Subscription, as specified in the Admin Panel (typically monthly or annual Subscription).

7.2.2 The Client may cancel (deactivate) the Subscription for all or specific Products at any time via the Admin Panel. Access to the deactivated Product will remain available until the end of the Subscription Period.

7.2.3 If the Client does not cancel (deactivate) the Subscription as outlined in Article 7.2.2 before the billing date, the Subscription is automatically renewed in the same scope, and the Provider is entitled to charge the cost for the next Subscription Period to the payment method provided by the Client.

7.3. Termination

7.3.1 Both the Provider and the Client are entitled to terminate the Contract due to a material breach of obligations by the other Party. A material breach of the Client’s obligations includes, in particular, violations of Articles 6.2.3 or 6.2.4.

7.3.2 Termination must be made in written form, either via email, through a data mailbox, or by regular mail. The terminating Party must state the reasons for termination. A valid termination takes effect upon delivery unless the terminating Party specifies a later date for the termination to take effect.

7.3.3 Termination of the Contract automatically results in the deactivation of all Products.

7.4. Settlement of the Contract or Addendum

7.4.1 Since the Client’s work on Optional Services begins immediately after the payment for such services, the paid price for Optional Services, including any proportional part, is non-refundable in the event of termination of the Contract by the Client, even if the System or Product was not activated or operational.

7.4.2 If the Contract is terminated for any reason after the System has been activated, the Client is not entitled to a refund of the paid Subscription Fee or any part thereof.

7.4.3 The Provider is not obligated to assist with the migration of the Client’s data to a new information system or provide any other support related to transitioning to a new system.

7.4.4 The Provider is entitled to delete all Client data stored on its servers or other data carriers 15 days after the termination of the Contract. The Client acknowledges that such deleted data cannot be recovered. If the Client deactivates a specific Product but continues to use other Products, the Provider is entitled to delete all data related to the deactivated Product within the above-mentioned timeframe.

7.4.5 Termination or cancellation of the Contract does not affect claims for damages, contractual penalties, or other provisions that, by the expressed intent of the Contracting Parties or their nature, are intended to remain in effect after the termination of the Contract.

8. Final Provisions

8.1. Unilateral Amendments to the Terms and Conditions

8.1.1 The Provider reserves the right to amend or supplement these Terms and Conditions at any time within a reasonable scope, particularly:

a) due to changes in legislation, technological advancements affecting the functionality of the System or handling of the Client’s data, or due to System expansions, modifications, or the introduction of new services or functionalities by the Provider,

b) if there are changes in market conditions or the commercial or licensing terms of third parties whose software or services the Provider uses to operate the System, or

c) in cases of changes in economic or financial conditions, currency changes (e.g., adoption of the Euro), inflation, or other circumstances creating a significant imbalance in rights and obligations to the detriment of the Provider.

8.1.2 The Provider shall make amended Terms and Conditions available via the Admin Panel and, if selected by the Client, also send them to the Client’s Email Address.

8.1.3 The amended Terms and Conditions take effect on the date specified therein but not earlier than the date the Client is notified of the changes.

8.1.4 If the Client does not agree with the amendments to the Terms and Conditions or the Price List, they are entitled to reject them and terminate the contractual relationship with the Provider by deactivating the Subscription before the amendments take effect.

8.1.5 If the Client does not terminate the contractual relationship as outlined in Article 8.1.4, it is deemed that they have accepted the amendments to the Terms and Conditions.

8.2. General Provisions

8.2.1 The contractual relationship arising from the Contract is governed by Czech law, specifically Act No. 89/2012 Coll., the Civil Code.

8.2.2 Disputes arising from or in connection with this Contract, including disputes regarding its validity or consequences of its invalidity, shall be resolved in the Czech Republic by the competent court in Ostrava.

8.2.3 The current version of these Terms and Conditions and the data processing contract are published in the Admin Panel in a section accessible via an access code/password. The Client may reproduce and archive the Terms and Conditions.

Annex No. 2

of the Contract on the Use of the Objednáme System

Contract on the Processing of Personal Data by the Company Objednáme s.r.o.

1. Introductory Provisions and Definitions

1.1. The company Objednáme s.r.o., with its registered office at Mlýnská 942/13, 737 01 Český Těšín, Company ID No.: 06419518, registered in the Commercial Register maintained by the Regional Court in Ostrava under File No. C 71855 (hereinafter referred to as the “Provider”), has entered into an Contract on the Use of the Objednáme System with the Client (hereinafter referred to as the “Contract” or the “Contract on the Use of the System”), under which the Client is entitled to use the Objednáme System (hereinafter referred to as the “System”).

1.2. Since the System is hosted on the Provider’s server, where the Client’s data, including personal data of the Client’s customers (hereinafter referred to as “Customers”), is transmitted and stored via the System’s local applications, the Provider acts as a processor within the meaning of Article 4(8) of Regulation (EU) 2016/679 of the European Parliament and of the Council on data protection (hereinafter referred to as the “Regulation”). The Client is the controller of the personal data entered into the System, whether by the Client or directly by the Customers.

1.3. As the Client is the controller of personal data entered into the System (i.e., stored on the Provider’s servers) and the Provider is the processor of this personal data within the meaning of the Regulation, this document constitutes Annex No. 1 to the Contract between the Client and the Provider. Since this Annex contains the mandatory provisions required under Article 28 of the Regulation, it will hereinafter be referred to as the “Data Processing Contract.”

1.4. The definitions of terms that are set out in the Terms and Conditions of Use of the Objednáme System (hereinafter referred to as the "T&C") shall also be used in this Data Processing Contract.

2. Subject of Processing

2.1. Subject, Nature, and Purpose of Processing; List of Processing Operations

2.1.1 The subject of processing involves personal data of the data subjects specified in Article 2.2.

2.1.2 The purpose of processing is primarily the fulfilment of the Provider’s obligations under the Contract or as determined by the Client’s instructions.

2.1.3 In connection with the operation of the System, the following processing operations generally occur:

a) storage of personal data on the Provider’s server,

b) structuring, sorting, organizing, adapting, or modifying personal data stored on the Provider’s server,

c) occasional access to personal data (only in connection with resolving and rectifying incidents or defects in the System),

d) deletion or destruction of personal data upon termination of the Contract, deactivation of a Product, or based on the Client’s instructions.

2.2. Categories of Data Subjects and Processed Personal Data

2.2.1 The data subjects whose personal data are temporarily processed by the Provider include:

a) employees of the Client,

b) Customers and other individuals whose personal data are processed by the Client as a controller in connection with the use of the System.

2.2.2 The Client acknowledges that during the term of the Contract, the Provider will process, as instructed by the Client and in accordance with Article 2.1.3, the following categories of personal data:

a) Identification and contact data (e.g., name, surname, date of birth, and for sole traders, also tax identification number and business identification number) and address data (e.g., residential address, email address, phone number, or mobile number) necessary for the unambiguous identification of Customers or other data subjects,

b) Access credentials (Customer login credentials for their user/customer account), c) Data on the Customer’s use of the Client’s services (e.g., purchase history, call records, and other communication records with the Customer),

d) data on the Customer's use of the Customer's services (e.g. purchase history, call records, records of other communications with the Customer), e) Data on the Customer's preferences in relation to allergenic substances. 2.2.3 The system is not intended for processing and storing sensitive personal data fulfilling the characteristics of the so-called special category of personal data within the meaning of Article 9 of the Regulation (data on sexual orientation, health status, etc.), with the exception of data on the Customer's preference for allergenic substances, which are assigned to the Customer's user or customer account and not to a specific person of the data subject.

2.3. Method and Place of Processing, Transfer of Personal Data to Third Countries

2.3.1 The place of processing of personal data is primarily the Czech Republic or another member state of the European Union.

2.3.2 Any processing of personal data in a third country outside the EU is only possible if the conditions for transfer to a third country set out in Article 44 et seq. Regulation.

2.4. Involvement of Other Processors

2.4.1 The Client acknowledges and agrees that the System is operated on servers located in the hosting centre of the hosting provider, whose identification data is provided in the Admin panel / on the Provider's website. The Hosting Provider is an additional processor within the meaning of Article 28(2) of the Regulation.

2.4.2 The Provider is entitled to engage another supplier of hosting, cloud or other services as an additional processor in the processing of personal data, or to replace the hosting operator or any additional processor with another supplier (processor). The Provider is obliged to inform the Client about the involvement of any additional processor via the Admin Panel in advance so that the Client can object to such changes.

2.4.3 The Provider is obliged to ensure that any other processor involved in the processing of personal data complies with the processing conditions at least to the same extent as set out in this Processing Contract, in particular as regards the implementation of technical and organisational measures within the meaning of Article 5.2 of this Processing Contract. If the said further processor does not

fulfil its obligations in the area of personal data protection, the Provider shall remain responsible for the fulfilment of the obligations of the further processor concerned.

3. Processing on the Client's Instruction

3.1. Within the meaning of Article 28(3)(a) of the Regulation, the Provider as a processor is obliged to process personal data only on the basis of documented instructions from the Client, who is in the position of the controller.

3.2. This Processing Contract constitutes the Client's instruction to process personal data, to the extent that this is apparent from the description of the Provider's performance set out in the Contract. Therefore, no further instructions from the Client are required to process personal data entered into the System by the Client, its Customer or a third party. However, the Provider is obliged to observe all the restrictions set out in this Processing Contract.

3.3. In addition to the processing within the scope of Article 3.2 of this Processing Contract, the Provider may process personal data on the basis of a separate instruction (request) from the Client in written form, also electronically via e-mail with a guaranteed electronic signature or via a data box. On the basis of such a separate instruction (request), the Client may request, in particular, the secure deletion of personal data. The Client may export or download data or personal data at any time within the System without the Provider's assistance. The Provider is not entitled to carry out processing on the basis of instructions given to it in a form other than that agreed in this Article of the Processing Contract. The Provider is obliged to archive any separate instructions (requests).

3.4. Persons authorised to give instructions to the Provider are members of the Client's statutory body and contact persons expressly mentioned in the Contract. A member of the Client's statutory body may also authorise another person to give instructions under this Article of the Processing Contract, however, he/she shall be obliged to provide the Provider with written proof of this.

4. Duration of Data Processing

4.1. The duration of the processing of personal data is agreed for a fixed period of time, until the termination or cancellation of the Contract on the Use of the System. This Data Processing Contract is Annex 2 to the Contract on the Use of the System and will terminate automatically on the date of termination of the Contract on the Use of the System.

4.2. The Client acknowledges that in the event of termination of the Contract on the Use of the System, the Provider shall delete all Client's Data, including Personal Data, without the possibility of restoring it, in accordance with Article 7.4.4 of the T&C. The Provider shall also delete all existing copies and backups, unless the law of the Union or an EU Member State requires the storage of the personal data in question, no later than 6 months after the termination of the Contract for the use of the System.

4.3. The Provider shall create a record (confirmation) of the deletion of personal data and send it to the Client's contact e-mail address.

4.4. The Provider is aware that it is not entitled to process the personal data made available to it by the Client without the existence of a valid agreement on the processing of personal data.

5. Obligation of Confidentiality, Technical and Organisational Measures for the Protection of Personal Data

5.1. Confidentiality

5.1.1 The Provider is obliged to take appropriate organizational measures and demonstrably inform all its employees and other persons authorized to process personal data of the obligation to maintain confidentiality of personal data and any other confidential information or trade secrets with which they come into contact, as well as to maintain confidentiality of security, technical or organizational measures, the disclosure of which would compromise the security of personal data processed through the System. The Provider shall also inform the employees that this obligation of confidentiality is unlimited.

5.2. Technical and Organisational Measures

5.2.1 The Provider shall take appropriate technical measures to protect the personal data it processes, taking into account the state of the art, the nature, scope, context and purposes of the processing of this Processing Contract as well as the risks to the rights and freedoms of natural persons.

5.2.2 The Provider hereby declares that it has adopted appropriate technical measures to protect personal data, in particular:

a) Physical security of the Provider's premises,

b) Secure data transmission using TLS, HTTPs.

c) Use of firewalls and monitoring systems designed to detect and warn of security threats,

d) Use of user roles and passwords,

e) Storing passwords in encrypted form,

f) Security of the IT infrastructure and end devices of the Provider or the Provider's employees (including the use of firewalls, backup of the Provider's server, encryption of disks, use of access passwords and biometric security features, etc.).

5.2.3 The Provider hereby declares that it has taken appropriate organisational measures to protect the personal data it processes which are appropriate to the risks arising from the nature of the processing of personal data under this Processing Contract, in particular:

a) It has made the relevant employees aware of the obligation of confidentiality to the extent provided for in Article 5.1,

b) It applies controlled access to the means intended for processing personal data in order to prevent physical or online access by unauthorised persons,

c) It has made its employees aware of the obligations relating to the processing of personal data, including the rights of data subjects under the law, and regularly conducts training of employees,

d) It has processes in place to regularly test, assess and evaluate the effectiveness of the technical and organisational measures in place to ensure the security of the processing of personal data, and these processes are captured in internal regulations.

6. Cooperation and Assistance of the Provider, Responsibility

6.1. Provider's Cooperation

6.1.1 The Provider is obliged to provide the Client with the necessary cooperation in connection with any inspection carried out by a supervisory authority in the field of personal data protection, e.g. the Office for Personal Data Protection.

6.1.2 The Provider shall facilitate audits, including inspections, conducted by the Client or another auditor authorised by the Client, and shall provide the necessary cooperation for audits, inspections and other checks.

6.2. Duty to Assist

6.2.1 The Provider shall assist in ensuring compliance with the obligations under Articles 32 to 36 of the Regulation, taking into account the nature of the processing and the information available to it. In this context, the provider shall:

a) provide the Client in cases of personal data breaches with information to enable the Client to assess whether the breach has resulted in a risk to the rights and freedoms of the data subjects concerned,

b) assist the Client to properly and timely report the personal data breach to the supervisory authority (including the information required in the notification pursuant to Article 33(3) of the Regulation) and to report it to the data subjects concerned.

6.2.2 If the Provider discovers in connection with the operation of the System a breach of personal data security that results in a high risk to the rights and freedoms of natural persons, e.g. unauthorized processing, damage, loss or destruction of personal data, it is obliged to inform the Client of this fact without undue delay, preferably within 48 hours of becoming aware of it, and, if possible, to provide the Client with information within the scope of Article 33(3) of the Regulation.

6.2.3 The Provider is further obliged, as far as possible, to be assisted by appropriate technical and organisational measures to fulfil the obligations of the Client (as a data controller) to respond to requests for the exercise of the rights of data subjects, e.g. in relation to the right to erasure, rectification, portability of personal data, etc. The Client acknowledges that the System enables basic data search and export, therefore, in case of the Client's request under this Article, the Provider shall perform these activities for a reasonable fee, which shall be determined as a multiple of the hourly rate of CZK 1,500.- without VAT/hour and the number of hours actually spent by the Provider on the said activities.

6.3. Liability of the Parties

6.3.1 The Provider shall be liable for damage caused by a breach of the obligations set out in this Processing Contract, or if it has acted in excess of or contrary to a lawful instruction of the Client. However, the Provider may be exempted from liability if it proves that it is not in any way responsible for the event that led to the damage or other harm caused in connection with the processing of personal data.

6.3.2 The Client acknowledges that it is primarily and fully liable as a controller for any harm caused by the processing of personal data in breach of the Regulation or other legal provisions. The Provider shall not be obliged or entitled to check whether the Client complies with its obligations in the processing of personal data which it has as a controller.

6.3.3 The Client shall comply with the principles set out in Article 6 of the Regulation when processing personal data. Among other things, the Client is obliged to consider for itself what personal data it will process through the System and for how long, so that this is in accordance with the principles of "data minimisation" and "storage limitation". The Client is also obliged to inform the data subjects of the purpose, scope, duration of the processing as well as the lawful grounds for the processing of their personal data (the principle of "lawfulness, fairness and transparency" and the principle of "purpose limitation").

6.3.4 The Client is also obliged to apply its own security policies in order to protect data and personal data, in particular to prevent physical unsecured access to the System, disclosure or storage of user 18 / 19

access passwords or the selection of a risky password for access to the Client's user account (e.g. passwords such as "1234", "2468", which are short or do not contain a combination of letters, numbers and characters). The Provider shall not be liable for any harm or damage caused by the Client's violation of security principles and obligations in the area of organizational and technical measures for the protection of personal data.

6.3.5 The Provider shall not be obliged to check whether the Client complies with the obligations set out in the Regulation when processing the personal data of data subjects through the System, nor shall the Provider perform the information obligation towards data subjects on behalf of the Client.

6.3.6 If either Party incurs damage as a result of the culpable breach of an obligation under this Processing Contract by the other Party, the relevant provisions on compensation for such damage in the Contract, or in the Terms and Conditions of Access to the Objednáme Information System, including the provisions on the limitation of compensation for damage, shall apply in respect of compensation for such damage.

7. Final Provisions

7.1. This Processing Contract is governed by Czech law.

7.2. If the EU Commission or the Supervisory Authority adopts standard contractual clauses within the meaning of Article 28(7) or (8), the Parties shall, if necessary, make adjustments to this Processing Contract.

7.3. This Processing Contract is executed in electronic form but forms Annex 2 to the Contract for Use of the System.

7.4. The Provider shall be entitled to engage additional processors in the manner referred to in Article 2.4, to unilaterally supplement and extend the technical and organisational measures for the protection of personal data (Article 5.2), if necessary, and to publish new versions of this Processing Contract without the need for verification or conclusion of amendments regarding such changes and additions.