UpToCRM

Legal

Terms of Use

Effective 3 August 2026 · Version 1.0

UptoCRM Limited · Company no. 17364287 · England and Wales

These Terms are issued by UptoCRM Limited, company number 17364287, of 275 New North Road, Unit 3051, London, N1 7AA, United Kingdom. They govern business access to the UptoCRM Site, Service and Apps.

Business contract: The Service is supplied for business and professional use. If an Order Form names an organisation as Customer, that organisation is responsible for its Users and the Customer Data in its workspace. Mandatory consumer rights apply only where they cannot lawfully be excluded.

1. Parties, acceptance and business use

1.1 Parties. These Terms of Use are between UptoCRM Limited (UptoCRM, we, us or our) and the organisation or person identified in an Order Form or account registration as the customer (Customer, you or your).

1.2 Acceptance. You accept the Agreement by signing or accepting an Order Form, clicking an acceptance control, creating or using an Account, downloading or using an App, or accessing paid Service functionality. A person accepting for an organisation represents that they have authority to bind it.

1.3 Users. Each User must comply with the provisions that apply to access and conduct. Customer is responsible for Users, including administrators and invited Partners, and for acts and omissions through its Account as if they were Customer's own.

1.4 Site visitors. A person who uses only the public Site may use it for lawful information and evaluation purposes, subject to sections 6, 12, 20, 21, 23, 24 and 25 and any notice displayed on the Site.

1.5 No agreement. If you do not agree to the Agreement, do not access the Service or Apps. These Terms do not by themselves oblige us to accept an order, create an Account or continue a free evaluation.

2. Definitions

"Account" means the Customer workspace and associated administrator, Company Member, Partner and other authorised credentials.

"Agreement" means these Terms, the applicable Order Form, Schedule 1, any Service Description or service-level schedule expressly incorporated, and any other document the parties expressly agree forms part of the contract.

"App" means an official UptoCRM mobile or desktop application made available by us through the Apple App Store, Google Play or another authorised distribution channel.

"Authorised User" means an individual whom Customer authorises to access the Service, including a Company Member or invited Partner.

"Company Member" means a User account created by Customer for its employees, contractors or other internal personnel.

"Confidential Information" means non-public information disclosed by or for a party that is identified as confidential or should reasonably be understood to be confidential, including Customer Data and non-public product, security, pricing and business information.

"Customer Data" means data, content, records, configurations and files submitted to, stored in, transmitted through or generated for Customer within the Service, excluding UptoCRM system data and Aggregated Data.

"Documentation" means UptoCRM's then-current user, support and technical materials made available for the Service.

"Fees" means charges specified in an Order Form or authorised marketplace purchase.

"Marketplace Provider" means Apple, Google or another third party that distributes an App or processes an App-related purchase.

"Order Form" means an online order, marketplace purchase, quote, proposal or signed ordering document specifying the Service, plan, Fees, limits and subscription term.

"Partner" means an external referral agent, affiliate or other person invited by Customer to a restricted portal or Account role.

"Service" means the hosted UptoCRM customer-relationship, workflow, task, contact, partner, document, automation, reporting and related functionality ordered or made available to Customer, together with official Documentation and Apps used to access it.

"Subscription Term" means the initial and renewal period stated in the Order Form or, if none is stated, the applicable monthly period.

"UptoCRM IP" means the Service, Apps, Site, Documentation, designs, software, models, methods, know-how and other materials owned or licensed by UptoCRM, including improvements and derivative works, but excluding Customer Data.

3. Agreement structure and precedence

3.1 Contract documents. The Agreement is the entire contract for the ordered Service. Statements in marketing material, a demo, roadmap or informal communication are not binding commitments unless expressly included in an Order Form.

3.2 Precedence. If documents conflict, the following order applies: (a) a signed Order Form or negotiated addendum that expressly overrides another term; (b) Schedule 1 for the processing of Personal Data; (c) a service-level or Service Description schedule; (d) these Terms; and (e) Documentation. Marketplace terms govern the Marketplace Provider's distribution, billing and store services.

3.3 Purchase orders. A purchase order is for Customer's administrative convenience only. Additional or conflicting terms in it do not apply unless we expressly sign them.

4. Eligibility, registration and administration

4.1 Eligibility. The Service is for persons aged 18 or over acting for business or professional purposes. Customer must have legal capacity to contract and may not use the Service if prohibited by applicable law.

4.2 Registration. Customer must provide accurate registration, billing and administrator information and keep it current. We may rely on instructions from an administrator until Customer notifies us of an authorised replacement.

4.3 Administration. Administrators control User invitations, roles, permissions, integrations and workspace configuration. Customer must apply least-privilege access, promptly remove access that is no longer needed and periodically review active Users and Partners.

4.4 Credentials. Credentials are personal and must not be shared, except for properly managed non-human integration credentials expressly supported by the Service. Customer must notify us promptly of suspected unauthorised access, credential compromise or misuse.

4.5 Account activity. Customer is responsible for activity occurring through its Account unless caused by UptoCRM's breach of the Agreement. We may require reasonable verification before acting on a sensitive administrator, billing, export or deletion instruction.

5. Access rights and licence

5.1 Service access. Subject to the Agreement and payment of Fees, we grant Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to allow its Authorised Users to access and use the ordered Service for Customer's internal business operations.

5.2 App licence. For an App not governed by a Marketplace Provider's standard end-user licence, we grant each Authorised User a limited, revocable, non-exclusive and non-transferable licence during the Subscription Term to install and use the App on compatible devices owned or controlled by the User or Customer solely to access the Service. For an Apple App, section 24 and Schedule 2 apply.

5.3 Limits. Access is subject to the plan, User, Partner, storage, source, feature, usage and other limits in the Order Form or Documentation. Customer must not circumvent limits or use credentials allocated to another person.

5.4 Reservation. No right is granted except as expressly stated. Rights may be exercised only by Customer and its Authorised Users and may not be resold, time-shared, made available as a service bureau or used to provide a competing hosted service.

6. Customer responsibilities and acceptable use

6.1 Customer responsibility. Customer is responsible for its business, licences, regulatory status, Users, Customer Data, workflows, communications, decisions, integrations and use of Service outputs. UptoCRM is a software provider and does not act as Customer's broker, agent, fiduciary, legal adviser, financial adviser, property adviser, compliance officer or regulated screening provider.

6.2 Lawful data. Customer must have all rights, notices, permissions, legal bases and consents required to collect, upload, disclose, use and instruct us to process Customer Data. Customer must not instruct us to process data contrary to applicable law or a binding duty owed to another person.

6.3 Configured actions. Customer is responsible for Automation Rules, templates, reminders, scoring, routing, timers, Partner forms and other configurations, including their content, recipients, frequency and effect. Customer must provide appropriate human review where a workflow could materially affect an individual.

6.4 Prohibited use. Customer must not, and must not permit any person to:

• use the Service unlawfully, fraudulently, deceptively or in a way that infringes privacy, intellectual-property or other rights;

• send spam, unlawful direct marketing, harassment, threats, discriminatory content or communications without required consent;

• upload malware, malicious code, unlawful content or content designed to disrupt, damage or gain unauthorised access;

• probe, scan or test security without prior written authorisation, or bypass authentication, permissions, rate limits, usage limits or technical safeguards;

• access another customer's workspace or data, impersonate a person, misrepresent affiliation, or use credentials not assigned to the User;

• reverse engineer, decompile, disassemble, translate or seek source code, except to the limited extent a restriction is prohibited by law after prior written notice;

• scrape, harvest, crawl, systematically extract or create a substitute dataset from the Service except through an authorised export or API used within documented limits;

• benchmark or publish performance or security test results without our prior written consent, or use the Service to develop or train a competing product or model;

• remove proprietary notices, interfere with service integrity, impose an unreasonable load or use automated means inconsistent with Documentation; or

• process special-category, criminal-offence, biometric, children's or other highly sensitive data unless strictly necessary, lawful, documented and protected, and the ordered Service is appropriate for it.

6.5 Permissions and communications. Customer must ensure that its use of contacts, calendars, device permissions, communications and integrations complies with platform rules and applicable privacy, electronic-communications and marketing law.

7. Customer Data and user content

7.1 Ownership and licence. As between the parties, Customer retains its rights in Customer Data. Customer grants UptoCRM and its subprocessors a non-exclusive, worldwide, royalty-free right during the Agreement to host, reproduce, transmit, display, modify for technical formatting, back up and otherwise process Customer Data only to provide, secure, support and comply with the Agreement and Customer's documented instructions.

7.2 Customer warranty. Customer represents that it has the rights and authority required for the licence and instructions in section 7.1 and that Customer Data and its use through the Service do not violate law, contract or third-party rights.

7.3 Aggregated Data. We may generate and use statistics, telemetry and other information derived from use of the Service in aggregated or de-identified form (Aggregated Data) to operate, secure, analyse and improve our services, provided it does not identify Customer or an individual and is not re-identified.

7.4 Content action. We may remove or restrict access to Customer Data where reasonably necessary to address illegality, infringement, security risk or a binding order. Where lawful and practicable, we will notify Customer and allow a reasonable opportunity to respond.

7.5 Customer copies. Customer should maintain exports or independent copies appropriate to its continuity and legal obligations. Our backup and recovery arrangements support the Service but are not a substitute for Customer's own record-retention or archival programme.

8. Integrations and third-party services

8.1 Integrations. The Service may interoperate with third-party services selected or configured by Customer. Customer authorises us to exchange Customer Data with the relevant provider as needed for the integration. Customer is responsible for the provider's terms, permissions and independent processing.

8.2 Third-party responsibility. We do not control third-party services and are not responsible for their availability, security, data handling, changes or acts. We may suspend or remove an integration where required for security, law, provider terms or Service integrity.

8.3 Links and marketplaces. Links to third-party sites are provided for convenience and do not imply endorsement. Marketplace distribution and payment services are governed by section 10, section 24 and the Marketplace Provider's terms.

9. Fees, taxes, invoicing and renewal

9.1 Fees. Customer must pay Fees in the currency, amount and schedule shown in the Order Form. Unless stated otherwise, Fees are billed in advance, non-cancellable during the committed Subscription Term and non-refundable except as expressly stated or required by law.

9.2 Taxes. Fees exclude VAT, sales, use, withholding and similar taxes. Customer is responsible for taxes arising from its purchase, except taxes based on our net income. If withholding is required, Customer must provide valid evidence and, unless prohibited, gross up the payment so we receive the amount that would have been due without withholding.

9.3 Payment. Customer authorises the payment method provided to be charged for Fees, renewals, taxes and approved usage charges. Payment processors and Marketplace Providers handle payment credentials under their own terms. We may correct billing errors and reissue an accurate invoice.

9.4 Late payment. Undisputed overdue amounts may accrue interest at 4% per year above the Bank of England base rate or the maximum lawful rate, whichever is lower, from the due date until payment. We may suspend for non-payment under section 18 after reasonable notice.

9.5 Disputes. Customer must notify us of a good-faith invoice dispute within 15 days after invoice date and pay the undisputed amount. The parties will work promptly to resolve the dispute.

9.6 Fee changes. We may change Fees for a renewal term by giving at least 30 days' notice before renewal. A plan or usage change requested during a term may take effect immediately and be charged on a prorated or other basis shown at checkout or in an Order Form.

10. Marketplace purchases and subscriptions

Separate cancellation: Deleting an Account or App does not cancel a subscription billed by a Marketplace Provider. The subscription must be cancelled through the marketplace account or subscription-management method shown at purchase.

10.1 Marketplace billing. If a subscription or feature is purchased through a Marketplace Provider, that provider may be merchant, billing agent or payment processor and its purchase, renewal, cancellation and refund rules apply in addition to the Agreement.

10.2 Subscription disclosure. Before a recurring purchase, the applicable interface will state the price, billing period, material features, whether a trial converts to paid access and the automatic-renewal terms. Customer authorises recurring charges until cancellation takes effect.

10.3 Cancellation and refunds. Cancellation takes effect at the end of the current paid period unless the Marketplace Provider or applicable law provides otherwise. Access normally continues until that date. Refund requests for marketplace purchases must be directed through the provider's process, and the provider may determine eligibility.

10.4 Trials and renewals. A free trial may require cancellation before the stated conversion date to avoid a charge. Customer is responsible for managing renewal settings and ensuring that administrators receive purchase and renewal notices.

10.5 Mandatory rights. Nothing in the Agreement limits a mandatory cancellation, refund or withdrawal right that applies and cannot lawfully be waived. The Service is primarily supplied for business purposes, so consumer rights may not apply to a business Customer.

11. Trials, previews and beta features

11.1 Evaluation access. We may offer a trial, pilot, free plan, preview or beta feature for evaluation. It may be time-limited, subject to additional limits, changed or withdrawn at any time, and provided without service levels, warranties, indemnities or support commitments except where law requires otherwise.

11.2 Beta restrictions. Customer must use pre-release features only for evaluation, follow any test instructions and not place production or irreplaceable data in them unless we expressly approve production use.

11.3 End of trial. Data in an expired trial may be deleted unless Customer converts to a paid plan or exports it during any period we make available. Conversion and continued access may be subject to a new Order Form.

12. Intellectual property, feedback and open source

12.1 Our rights. UptoCRM and its licensors retain all rights in UptoCRM IP. The Agreement does not transfer ownership or grant any implied licence. Customer may copy Documentation only as reasonably necessary for internal use of the Service.

12.2 Feedback. If Customer or a User provides suggestions, ideas or feedback, Customer grants us a perpetual, irrevocable, worldwide, royalty-free right to use and incorporate it without restriction or attribution, provided we do not identify Customer publicly without permission.

12.3 Open source. An App or Service component may include open-source or third-party software governed by separate licence terms. Those terms apply to the relevant component and prevail only to the extent required by the applicable licence.

12.4 Marks. UptoCRM names, logos and product marks are our or our licensors' trademarks. No right is granted to use them except as necessary to identify the Service in Customer's internal operations or as separately authorised in writing.

13. Confidentiality

13.1 Protection. The receiving party must use the disclosing party's Confidential Information only to perform or receive the Agreement, protect it with at least reasonable care, and disclose it only to personnel, affiliates, advisers and subcontractors who need it and are bound by confidentiality obligations.

13.2 Exclusions. Confidential Information excludes information the recipient can document was lawfully known without restriction, becomes public without breach, is received lawfully from a third party without duty, or is independently developed without use of the information.

13.3 Compelled disclosure. A recipient may disclose Confidential Information where legally required, provided it gives advance notice where lawful, reasonably assists with protective measures at the discloser's cost, and discloses only what is required.

13.4 Duration. On request or termination, a recipient must return or destroy Confidential Information except for information retained under law, professional obligations, automatic backups or the Agreement. Confidentiality continues for five years after disclosure, and for trade secrets and Personal Data for as long as they remain protected by law.

14. Data protection

14.1 Roles. Each party must comply with data protection law applicable to its own processing. For Customer Data containing Personal Data, Customer is the controller and UptoCRM is the processor unless the law or a specific processing activity provides otherwise.

14.2 Data Processing Terms. Schedule 1 applies to UptoCRM's processing of Personal Data for Customer and forms the parties' data processing agreement. If the parties sign a separate data processing addendum, that addendum prevails for the processing it covers.

14.3 UptoCRM controller data. UptoCRM is an independent controller for account administration, billing, security, service analytics, legal compliance and its own business communications as described in the Privacy Policy at https://uptocrm.com/privacy.

14.4 Customer notice. Customer must not treat the Privacy Policy as its own notice to leads, contacts, partners or other individuals. Customer must provide its own transparent information and rights process.

15. Security

15.1 UptoCRM measures. We maintain technical and organisational measures designed to protect the confidentiality, integrity and availability of the Service and Customer Data, taking account of risk, technology, implementation cost and the nature of the processing.

15.2 Customer measures. Customer must secure its Users, endpoints, networks, credentials, permissions, exports, integrations and copies. Customer must not disable or circumvent security controls and must cooperate reasonably with investigation and containment.

15.3 Reporting. Customer must report suspected Service vulnerabilities or unauthorised access promptly to [email protected]. Customer may not publicly disclose a vulnerability before we have had a reasonable opportunity to investigate and remediate, except where protected by law.

16. Availability, support and changes

16.1 Availability. Unless a separate service-level agreement states otherwise, the Service is provided on a commercially reasonable efforts basis without a guaranteed uptime percentage. References within the product to SLA timers or management concern Customer's configured workflows and are not UptoCRM uptime commitments.

16.2 Maintenance. We may perform scheduled and emergency maintenance and use reasonable efforts to give advance notice of planned material disruption. Internet, marketplace, cloud, telecommunications and third-party failures may affect availability.

16.3 Support. We provide support through the channels and hours stated in the Order Form or Documentation. Customer must provide reasonable information and cooperation and should not include unrelated Personal Data in support material.

16.4 Changes. We may modify the Service to improve it, address security or law, comply with provider requirements or reflect product development. During a paid term, we will not materially reduce the core functionality of the ordered Service as a whole without reasonable notice, unless urgently required for security or law.

16.5 Compatibility. Apps may require updates to remain compatible, secure or compliant. Device, operating-system or marketplace changes outside our control may require modification or discontinue compatibility with an older environment.

17. Customer systems, export and backup

17.1 Customer environment. Customer is responsible for systems, connectivity, browsers, devices, third-party accounts and configurations needed to access the Service and for following documented technical requirements.

17.2 Export. During the Subscription Term, Customer may export Customer Data using available Service functions, subject to permissions and plan limits. Additional migration or export services may be charged separately.

17.3 Backup. We maintain service backups for continuity and recovery, not as Customer's legal archive. Restoration may be performed at workspace or system level and may not support recovery of an individual item. Customer should maintain appropriate independent exports.

18. Suspension

18.1 Grounds. We may suspend access in whole or part where reasonably necessary to address overdue undisputed Fees, a material or repeated breach, security risk, suspected fraud, prohibited use, threat to another customer or the Service, a binding legal requirement, or Marketplace Provider action affecting an App.

18.2 Process. Where practicable and lawful, we will give notice and an opportunity to remedy before suspension. We may act immediately where delay could cause harm, and will limit scope and duration where reasonably possible.

18.3 Effect. Suspension does not relieve Customer of accrued payment obligations. We are not liable for loss caused by a reasonable suspension under this section, but nothing excludes liability that cannot lawfully be excluded.

19. Term, termination and consequences

19.1 Term. The Agreement starts on acceptance or the start date in the Order Form and continues for the Subscription Term. It renews for successive periods of the same length unless either party gives any required non-renewal notice at least 30 days before renewal, or the Order Form or Marketplace Provider specifies another process.

19.2 Cause. Either party may terminate for a material breach not cured within 30 days after written notice, or immediately if the breach cannot be cured. Either party may terminate immediately if the other enters insolvency proceedings, ceases business or cannot pay debts, subject to applicable insolvency law.

19.3 Free access. We may terminate an Account or free service on reasonable notice, or immediately for the grounds in section 18. Customer may stop using a free service at any time.

19.4 Consequences. On expiry or termination, access rights end, outstanding amounts become due and Customer must cease use of UptoCRM IP. If termination results from our uncured material breach, we will refund prepaid Fees for the unused remainder of the affected term. If we terminate for Customer breach, committed Fees remain due to the extent permitted by law.

19.5 Data return. We will make Customer Data available for export for at least 30 days after expiry or termination unless law, security, the Marketplace Provider, non-payment or Customer's instruction requires otherwise. We may then delete it in accordance with Schedule 1 and the Privacy Policy.

19.6 Survival. Provisions that by nature should survive do so, including accrued payment, Customer Data responsibility, intellectual property, confidentiality, data protection, disclaimers, liability, indemnities, compliance, governing law and interpretation.

20. Warranties and disclaimers

20.1 Limited warranty. Each party warrants that it has authority to enter the Agreement. We warrant that the paid Service will materially conform to Documentation when used as authorised. Customer's exclusive remedy for breach of this service warranty is reasonable correction or re-performance and, if we cannot provide it within a reasonable time, termination of the affected Service and a refund of prepaid Fees for the unused remainder.

20.2 Disclaimer. To the maximum extent permitted by law, the Site, Service, Apps, trials, beta features, integrations and outputs are otherwise provided as available. We disclaim implied terms as to satisfactory quality, fitness for purpose, non-infringement and uninterrupted, error-free or completely secure operation.

20.3 No professional reliance. The Service organises information and workflows but does not verify Customer Data, counterparties, licences, property information, identity, creditworthiness, sanctions status, legal compliance or transaction suitability. Customer must perform its own professional, regulatory and commercial diligence.

20.4 Outputs. Customer remains responsible for decisions and communications based on the Service and must review material outputs. Automation can amplify configuration or data errors and should be tested and monitored.

20.5 Mandatory law. Nothing in the Agreement excludes a warranty, condition or remedy that cannot lawfully be excluded. Any statutory warranty applies only to the extent required.

21. Liability

21.1 Unlimited matters. Nothing limits liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; wilful misconduct; Customer's obligation to pay Fees; infringement or misappropriation of the other party's intellectual property; or liability that cannot lawfully be limited.

21.2 Excluded loss. Subject to section 21.1, neither party is liable for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business opportunity, goodwill or reputation. UptoCRM is not liable for loss of Customer Data to the extent it could reasonably have been avoided by Customer using available export, backup, permissions or security controls.

21.3 General cap. Subject to sections

21.1 and 21.4, each party's total aggregate liability arising out of or in connection with the Agreement in any rolling 12-month period will not exceed the Fees paid or payable for the affected Service in that period. For an event in the first 12 months, the cap is the Fees paid or payable for the initial 12-month period.

21.4 Enhanced cap. For breach of confidentiality, breach of Schedule 1, a Personal Data incident caused by a party's breach, or UptoCRM's intellectual-property indemnity, the aggregate cap is twice the amount calculated under section 21.3. Customer's indemnity under section 22.1 is not limited by section

21.3 to the extent the claim results from unlawful Customer Data, prohibited use or Customer's regulatory breach.

21.5 Application. The exclusions and caps apply to all causes of action, including contract, tort (including negligence), breach of statutory duty, misrepresentation, restitution and otherwise, and reflect the allocation of risk and Fees. Each party must take reasonable steps to mitigate loss.

22. Indemnities

22.1 Customer indemnity. Customer will indemnify UptoCRM, its affiliates and personnel against third-party claims, damages, penalties and reasonable legal costs arising from Customer Data; Customer's or a User's unlawful or prohibited use; Customer's breach of privacy, marketing, licensing, sanctions, anti-bribery or regulatory obligations; or a Customer-configured communication, integration or Automation Rule, except to the extent caused by UptoCRM's breach.

22.2 IP indemnity. UptoCRM will defend Customer against a third-party claim that the unmodified paid Service, when used as authorised, infringes that party's copyright, patent or trademark, and will pay damages finally awarded or approved in settlement. This does not apply to Customer Data, Customer specifications, third-party services, unauthorised combinations or modifications, continued use after notice, or breach of the Agreement.

22.3 Remedies. For a covered infringement claim, we may procure continued use, modify or replace the affected part, or terminate it and refund prepaid Fees for the unused remainder. Section 22.2 and this section state Customer's exclusive remedy for such claims.

22.4 Procedure. An indemnified party must give prompt notice, allow the indemnifying party to control defence and settlement, and provide reasonable cooperation at the indemnifying party's cost. Delay relieves obligations only to the extent of material prejudice. No settlement may admit fault or impose non-monetary obligations on the indemnified party without consent, not to be unreasonably withheld.

23. Regulatory compliance, sanctions and anti-bribery

23.1 Licensing. Customer is responsible for professional and regulatory licences, registrations and approvals required for its business and markets, including any real-estate, brokerage, property, financial-promotion or referral requirements. UptoCRM does not verify Customer's status.

23.2 AML and KYC. The Service is not an anti-money-laundering, know-your-customer, sanctions-screening or transaction-monitoring system unless an Order Form expressly states otherwise. Customer remains responsible for AML, counter-terrorist-financing and source-of-funds obligations.

23.3 Sanctions and export. Customer represents that it, its controlling persons and, to its knowledge, Users and Partners are not restricted parties and will not use the Service for a prohibited country, person, transaction or end use. Each party must comply with applicable export controls and sanctions, including those administered by the United Kingdom, European Union and United States.

23.4 Anti-bribery. Each party must comply with applicable anti-bribery and anti-corruption law. Customer is responsible for the legality, transparency and documentation of commissions, referral payments, gifts and benefits managed through the Service.

23.5 Compliance action. We may request reasonable information to assess legal or security risk and may refuse, suspend or terminate access where reasonably necessary to avoid violation or exposure.

24. App marketplaces

24.1 Separate relationships. A Marketplace Provider is not a party to the Agreement between Customer and UptoCRM. The Marketplace Provider's store, device, usage and payment terms also apply, and Customer and Users must comply with them.

24.2 Apple standard licence. Unless the applicable App Store product page states that a custom UptoCRM end-user licence applies, Apple's then-current Standard Licensed Application End User License Agreement governs the licence to an App acquired from Apple. These Terms separately govern the UptoCRM Account, hosted Service, Customer Data, Fees owed to UptoCRM and business relationship.

24.3 Support. UptoCRM, not Apple or Google, is responsible for the Service, App content and support we promise under the Agreement. Marketplace Providers have no obligation to provide maintenance or support for the Service, except for their own marketplace services.

24.4 Marketplace control. Marketplace availability is outside our control. A Marketplace Provider may review, reject, remove, suspend or restrict an App or purchase. We may modify an App to comply with current platform requirements.

24.5 Addendum. Schedule 2 contains additional terms required or appropriate for Apps distributed through Apple, Google or another Marketplace Provider. If Schedule 2 conflicts with this section for a particular marketplace, Schedule 2 prevails to the extent required by the provider's terms or applicable law.

25. General provisions

25.1 Assignment. Customer may not assign or transfer the Agreement without our prior written consent, not to be unreasonably withheld for a bona fide internal reorganisation. We may assign it to an affiliate or in connection with a merger, financing, reorganisation or sale of all or substantially all relevant business or assets. An unauthorised assignment is void to the extent permitted by law.

25.2 Subcontracting. We may use affiliates and subcontractors to perform the Agreement and remain responsible for their performance as required by law and the Agreement. Subprocessors are governed by Schedule 1.

25.3 Force majeure. Neither party is liable for delay or failure caused by events beyond reasonable control, excluding payment obligations. The affected party must use reasonable efforts to mitigate and resume. If a material force-majeure event continues for more than 60 days, either party may terminate the affected Service on written notice.

25.4 Notices. Formal notices must be in writing and sent to the Order Form contact and, for UptoCRM, to [email protected]. Email is received on the next business day after sending unless a delivery failure is received. Notices of legal proceedings must also be sent by tracked post or recognised courier to the registered office.

25.5 Changes to Terms. We may update online Terms. A change required for law, security or a marketplace may take effect on notice. For another material change that adversely affects a paid Customer, we will give at least 30 days' notice; it applies at the next renewal unless earlier acceptance is required for a new feature. If a mandatory mid-term change materially reduces Customer's rights, Customer may terminate the affected Service before it takes effect and receive a pro-rata refund of unused prepaid Fees.

25.6 Entire agreement. The Agreement is the entire agreement about its subject and supersedes prior proposals and discussions. Each party acknowledges that it has not relied on a statement not set out in the Agreement, without limiting liability for fraud.

25.7 Severability. If a provision is illegal or unenforceable, it is modified to the minimum extent needed to make it effective, or severed if modification is not possible. The rest remains effective.

25.8 Waiver. A waiver must be written and applies only to the stated instance. Delay or failure to exercise a right is not a waiver. Rights and remedies are cumulative unless expressly exclusive.

25.9 Relationship. The parties are independent contractors. The Agreement does not create partnership, joint venture, employment, fiduciary or agency authority, except for a Marketplace Provider relationship separately established by its terms.

25.10 Third-party rights. Except for Apple and its subsidiaries as stated in Schedule 2 and any permitted indemnified person, no person who is not a party may enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999. The parties may vary or end the Agreement without third-party consent.

25.11 Interpretation. Headings aid navigation only. Including means including without limitation. A reference to law includes amendments and replacements. Singular includes plural. A requirement not to do something includes not permitting it. English controls over a translation unless mandatory law provides otherwise.

25.12 Governing law. The Agreement and any non-contractual dispute are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction, except that either party may seek urgent injunctive relief in any competent court and mandatory consumer law may provide another forum.

26. Contact details

26.1 Email. Legal notices and questions: [email protected].

26.2 Privacy. Privacy questions: [email protected].

26.3 Post. Postal address: UptoCRM Limited, 275 New North Road, Unit 3051, London, N1 7AA, United Kingdom.

26.4 Online. Website: https://uptocrm.com.

26.5 Support. Product support is available through the in-app support channel and any additional channel stated in the applicable Order Form or Documentation.

Schedule 1 — Data Processing Terms

These Data Processing Terms apply where UptoCRM processes Personal Data in Customer Data on Customer's behalf. Terms used in applicable data protection law, including controller, processor, data subject, process and Personal Data, have their statutory meanings.

1. Scope and processing details

S1.1 The subject matter is the processing of Customer Data to provide, secure, maintain and support the Service. The duration is the Agreement plus the return and deletion period. The nature and purposes include collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, availability, alignment, restriction, export, backup and deletion as instructed through the Agreement and Service.

S1.2 Data subjects may include Customer personnel, Company Members, Partners, leads, prospects, property buyers, sellers, landlords, tenants, investors, contacts, suppliers, counterparties and other individuals whose information Customer submits.

S1.3 Personal Data may include identity, contact, employment and organisation details; account, authentication and permission data; property and transaction preferences; budget, financing and mortgage information; communications, tasks, meetings and notes; referral and source data; device, log and usage data; and information in documents, free text and attachments selected by Customer.

S1.4 Special-category, criminal-offence, children's or other highly sensitive data is not intended unless expressly supported and lawfully instructed. Customer must identify additional requirements before submitting such data.

2. Instructions and compliance

S2.1 UptoCRM will process Personal Data only on documented Customer instructions, including the Agreement, Customer's configuration and Authorised User actions, unless law requires otherwise. If legally permitted, UptoCRM will inform Customer before required processing.

S2.2 If UptoCRM reasonably believes an instruction infringes applicable data protection law, it will inform Customer and may suspend the affected processing until the parties resolve the issue. UptoCRM is not required to give legal advice or perform an unlawful instruction.

S2.3 Customer is responsible for the lawfulness, fairness, transparency, accuracy and proportionality of its instructions; its legal basis; notices and consents; data-subject rights; and any controller authorisation needed for UptoCRM and subprocessors.

3. Confidentiality and security

S3.1 UptoCRM will ensure that personnel authorised to process Personal Data are bound by confidentiality and receive appropriate privacy and security instruction.

S3.2 Taking account of technology, implementation cost, scope, context, purposes and risk, UptoCRM will maintain appropriate technical and organisational measures under Article 32 of the UK GDPR and, where applicable, EU GDPR. Measures include access control, encryption in transit, authentication, logging, secure development, vulnerability management, backup, resilience, provider governance and incident response, as appropriate to the Service.

S3.3 Customer acknowledges that Service security also depends on Customer's configuration, credentials, endpoints, integrations and User conduct. Customer must implement measures appropriate to its risks.

4. Personal Data incidents

S4.1 UptoCRM will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Data and provide information reasonably available to help Customer meet notification duties. Information may be supplied in phases as investigation continues.

S4.2 Notification is not an admission of fault or liability. Customer is responsible for determining whether to notify an authority or individual and for the content of that notice, with UptoCRM's reasonable assistance.

5. Subprocessors

S5.1 Customer gives general written authorisation for UptoCRM to use subprocessors to provide the Service. UptoCRM will impose data protection obligations that provide materially equivalent protection for the relevant processing and remains responsible for subprocessor performance as required by law.

S5.2 Current subprocessor categories and locations are available on request to [email protected]. UptoCRM will give reasonable advance notice of a new or replacement subprocessor that processes Customer Data.

S5.3 Customer may object on reasonable, documented data protection grounds during the notice period. The parties will work in good faith on a commercially reasonable solution. If none is available without material burden or cost, either party may terminate the affected Service and UptoCRM will refund prepaid Fees for the unused remainder.

6. Assistance

S6.1 Taking account of the nature of processing, UptoCRM will provide reasonable assistance through available functionality and support for data-subject requests, security, breach response, data protection impact assessments and prior consultation with authorities.

S6.2 If UptoCRM receives a request relating to Customer Data, it will not respond substantively except on Customer's instruction or where legally required, and will refer the request to Customer where practicable.

S6.3 Assistance beyond standard Service functionality may be charged at agreed rates where the request is extensive, repetitive or caused by Customer's configuration or breach, unless applicable law requires assistance without charge.

7. International transfers

S7.1 UptoCRM will not make a restricted transfer of Customer Personal Data unless a lawful mechanism applies. For UK transfers, this may include UK adequacy regulations, the UK International Data Transfer Agreement or the UK Addendum. For EEA transfers, it may include an adequacy decision or the European Commission Standard Contractual Clauses.

S7.2 Where required and not otherwise executed, the applicable standard contractual clauses and UK Addendum are incorporated by reference with the modules and selections that correspond to the parties' roles, the processing details in this Schedule, optional docking clause, and the competent authority and governing law required by the clauses. The parties will complete additional details reasonably required for effectiveness.

S7.3 Each party will provide information and cooperation reasonably needed for a transfer assessment and supplementary measures applicable to its responsibilities.

8. Return and deletion

S8.1 During the term and for at least 30 days after expiry or termination, Customer may use available export functions, unless access is restricted lawfully for security, non-payment or legal reasons.

S8.2 After the export period, UptoCRM will delete or anonymise Personal Data in active Customer Data and require subprocessors to do the same, unless law requires retention. Backup copies will be protected from ordinary use and expire through the applicable cycle, normally within 90 further days.

9. Information and audit

S9.1 UptoCRM will make information reasonably necessary to demonstrate compliance available to Customer, which may include security summaries, certifications, audit reports, questionnaires and contractual information, subject to confidentiality and security restrictions.

S9.2 If that information is insufficient, Customer may conduct one audit per 12-month period on at least 30 days' notice, during business hours, through an independent qualified auditor bound by confidentiality. Additional audits are permitted after a material incident or where a regulator requires them.

S9.3 An audit must not access another customer's data, disrupt operations or compromise security. Customer bears its costs and reimburses reasonable UptoCRM costs for an audit beyond standard materials, unless it identifies a material breach by UptoCRM.

10. Controller information

S10.1 Customer authorises UptoCRM to process limited account, security, billing, analytics and support information as an independent controller as described in the Privacy Policy. This processing is outside Customer's instructions under this Schedule.

S10.2 If applicable law treats a specific activity differently from the roles stated here, the parties will comply with the legally required role and cooperate in good faith on necessary amendments.

Schedule 2 — Mobile Marketplace Addendum

This Addendum applies only where an App is acquired or used through a Marketplace Provider. It supplements, and does not replace, the provider's own terms.

1. Apple App Store

S2.1 Customer and each User acknowledge that the Agreement is between them and UptoCRM, not Apple. UptoCRM is solely responsible for the Service and its content. The licence to an Apple-distributed App is governed by Apple's Standard Licensed Application End User License Agreement unless the applicable App Store product page expressly designates a custom UptoCRM licence.

S2.2 Any App licence is limited to a non-transferable right to use the App on Apple-branded products the User owns or controls, as permitted by the Apple Media Services Terms and applicable usage rules, including any permitted Family Sharing, volume-purchase or legacy-account access.

S2.3 UptoCRM, not Apple, is responsible for maintenance and support promised for the App. Apple has no obligation to provide maintenance or support.

S2.4 To the extent an App fails to conform to an applicable warranty and Apple is required by its terms to refund the purchase price, the User may notify Apple. To the maximum extent permitted by law, Apple has no other warranty obligation for the App; UptoCRM is responsible for other warranty claims to the extent stated in the Agreement or required by law.

S2.5 UptoCRM, not Apple, is responsible for addressing claims relating to the App or its possession or use, including product-liability, legal or regulatory compliance, privacy and consumer-protection claims, to the extent provided by applicable law and the Agreement.

S2.6 If a third party claims that an App or its possession and authorised use infringes intellectual-property rights, UptoCRM, not Apple, is responsible for investigation, defence, settlement and discharge to the extent provided in section 22.

S2.7 Each User represents that the User is not located in a country or region subject to a United States Government embargo or designated as supporting terrorism, and is not listed on a United States Government prohibited or restricted-party list, subject to applicable law.

S2.8 Users must comply with applicable third-party terms when using the App, including wireless-data, device, employer and integration terms.

S2.9 Questions, complaints and claims about the App should be directed to UptoCRM Limited, 275 New North Road, Unit 3051, London, N1 7AA, United Kingdom, at [email protected], or through the in-app support channel.

S2.10 Apple and its subsidiaries are third-party beneficiaries of this Addendum and, upon acceptance, may enforce the Apple-specific provisions against the User. No other Marketplace Provider obtains that right unless its terms require it.

2. Google Play and other marketplaces

S2.11 Google and any other Marketplace Provider are not responsible for UptoCRM support, Service performance, Customer Data or claims between Customer and UptoCRM, except for the provider's own store, billing, refund or platform obligations.

S2.12 Purchases, renewals, cancellations and refunds processed through Google Play are subject to Google Play's then-current billing and subscription rules. Customer must use the Google Play subscription-management method for a Google-billed subscription unless another compliant cancellation method is offered.

S2.13 Users must comply with Google Play terms, device permissions and acceptable-use requirements. UptoCRM may update, restrict or withdraw an App where necessary for current marketplace policy or technical compatibility.

S2.14 Marketplace privacy summaries, permissions and Data safety disclosures describe the relevant App's practices in a platform format and must be read with the UptoCRM Privacy Policy.