Terms & Conditions
1. Parties and Definitions
These general terms and conditions apply to the Launch Check offered online by Resync via re-sync.nl.
- Resync: the sole proprietorship Resync, established at De Wherelanden 11, 1441 ZM Purmerend, the Netherlands, registered with the Netherlands Chamber of Commerce under number 99738929, VAT identification number NL005407604B29, e-mail info@re-sync.nl; the contractor.
- Client: the legal or natural person acting in the exercise of a profession or business who requests a Launch Check via the intake form.
- Launch Check: the fixed-price, time-boxed security assessment of one application designated by the Client, as described in Article 2, including reporting.
- Target Application: the application designated by the Client in the request that falls within the scope of the Launch Check.
- Intake Form: the online form on re-sync.nl through which the Client requests a Launch Check and accepts these terms.
- Portal: the secure environment at portal.re-sync.nl through which the Client supplies information and receives the report.
- Payment Service Provider: Mollie B.V., which processes the payment on behalf of Resync. The Payment Service Provider's own terms also apply to the processing of the payment; the contract for the Launch Check is concluded exclusively with Resync.
- Agreement: the agreement between Resync and the Client for the performance of a Launch Check, concluded as described in Article 4.
The applicability of any purchasing or other general terms and conditions of the Client is expressly rejected. Deviations from or additions to these terms apply only if agreed between the parties in writing.
2. Nature and Scope of the Launch Check
The Launch Check is a security assessment with a fixed price and a fixed, limited scope, directed at a single Target Application. The assessment provides a point-in-time snapshot of security at the time it is performed and is by its nature not exhaustive. The absence of findings does not constitute a guarantee that the Target Application is free of vulnerabilities.
The Launch Check is a best-efforts obligation (inspanningsverbintenis) and not an obligation to achieve a specific result. Resync performs the assessment with the care that may be expected of a reasonably competent and reasonably acting professional, but does not warrant that all vulnerabilities present will be found or that any particular result will be achieved. The assessment comprises no more than one working day of effective testing time on the Target Application; this duration limits the scope of the work.
Only the Target Application designated in the request falls within scope. The following fall outside scope unless separately agreed in writing:
- Denial-of-Service (DoS/DDoS) attacks;
- social engineering and phishing directed at the Client's staff or third parties;
- physical security of premises;
- third-party infrastructure and services (including hosting, cloud and CDN providers), insofar as not agreed as part of the Target Application;
- systems, domains or applications not designated as the Target Application.
Within the agreed scope, Resync reasonably determines which techniques are used. Additional or differing work requires a separate engagement agreed in writing.
3. Business Client; No Consumer Sale
The Launch Check is offered exclusively to business customers. The Client declares that it requests the Launch Check in the exercise of a profession or business and not as a consumer. On making the request the Client provides a valid registration or VAT number (such as a KvK, KBO, HRB, Companies House or comparable registration number). In doing so the Client states its country of establishment and, where applicable, its VAT identification number; these details co-determine the VAT treatment under Article 5.
Because the Client is not a consumer, the provisions on consumer protection for distance contracts — including the statutory right of withdrawal (herroepingsrecht) under Section 6.5.2B of the Dutch Civil Code — do not apply. The request therefore carries no cooling-off period or statutory right of withdrawal. The refund arrangement in Article 6 applies instead.
Resync may verify the registration or VAT number provided by the Client and may reject a request where the Client's business status cannot be established (Article 6).
Should a Client, notwithstanding its declaration, nonetheless qualify as a consumer within the meaning of the law given the circumstances, the following applies. By placing the request and asking for the Launch Check to be performed, the Client expressly requests Resync to commence performance as soon as ownership verification has been completed and the agreed date has been reached, and the Client acknowledges that it loses its right of withdrawal once Resync has fully performed the Launch Check (Section 6:230p, opening words and under (d), of the Dutch Civil Code). Insofar as performance has commenced at the Client's request but is not yet complete, the Client owes a proportionate part of the price on withdrawal.
4. Formation of the Agreement
The Agreement is concluded by electronic means. The request proceeds as follows:
- The Client completes the Intake Form, confirms the version of these terms shown at that time, and pays the amount displayed at checkout through the Payment Service Provider.
- The payment constitutes the Client's request for the performance of a Launch Check. The Agreement is concluded subject to the condition that Resync accepts the request following its assessment (Article 6).
- Resync confirms receipt of the payment by electronic means. This acknowledgement of receipt does not yet constitute acceptance of the request.
Until Resync has accepted the request, the amount paid is fully refundable in accordance with Article 6. If the request is declined, the Agreement does not come into being and the full amount is refunded.
A deposited or signed paper contract is not required for the Launch Check; the electronically recorded request, the accepted version of these terms and the payment together constitute evidence of the Agreement.
Before the Client finally submits the request, the Intake Form shows an overview of the information entered and offers the opportunity to correct input errors or to change or abandon the request. The Client is responsible for the accuracy of the information it confirms.
Resync records, for each request, the accepted version of these terms, the time of acceptance and the information provided by the Client. On confirmation of payment, Resync makes these terms available to the Client as a file (PDF), so that the Client can store and consult it. These terms can also be consulted and stored on re-sync.nl at any time.
5. Price and Payment
The price of the Launch Check is a fixed price and is stated exclusive of VAT. Which VAT treatment applies is determined by the Client's place of establishment and status and by the VAT identification or registration number the Client provides on the request, in accordance with the statutory place-of-supply rules for business-to-business services:
- Client in the Netherlands. Dutch VAT is added to the price.
- Business Client in another Member State of the European Union holding a valid VAT identification number: VAT is reverse-charged to the Client (VAT reverse-charged). Resync charges no Dutch VAT; the Client accounts for VAT in its own Member State under the rules applicable there. The invoice states both VAT identification numbers and the notation “VAT reverse-charged”.
- Client established outside the European Union. The service is not taxable in the Netherlands and no Dutch VAT is charged. Any tax due in the Client's country is for the Client's account.
The reverse charge, or the service falling outside the scope of Dutch VAT, applies only if the Client provides a valid, verifiable VAT identification number or, as the case may be, evidences its business status and establishment outside the Netherlands. Resync may verify the VAT identification number provided, including via the European Commission's VIES system. If a number provided proves invalid or incorrect, Resync is entitled to charge the VAT legally due after all; the Client indemnifies Resync against VAT, interest and penalties arising from a number or status incorrectly stated by the Client.
Taking into account the VAT treatment set out above, the amount displayed at checkout is the amount the Client actually pays. Payment is made in advance and in full, by electronic means through the Payment Service Provider. Resync issues an invoice for the Launch Check that complies with the applicable VAT rules. As payment is made in advance and in full, Article 6 (assessment and refund) is the only arrangement under which an amount already paid is refunded in whole or in part.
6. Assessment, Scheduling and Refund
Upon receipt of payment, Resync assesses the request, in principle within two working days and no later than within ten working days. One of the following outcomes applies as a result of that assessment:
- Acceptance. Resync accepts the request and schedules the Launch Check, in principle within one week of acceptance, in consultation with the Client.
- Revised quotation. If the request shows that the Target Application or the work desired falls outside the scope of the Launch Check, Resync may issue a revised quotation. The Client is free to accept or reject it. If the Client rejects the revised quotation, or does not respond within a reasonable period, the Agreement does not come into being and the full amount paid is refunded.
- Rejection. Resync may reject the request, including where the required ownership verification or authorisation is absent, where performance would breach applicable law, or where the Target Application is not suited to a Launch Check. In that case the Agreement does not come into being and the full amount paid is refunded.
Refunds are made by the same electronic means as the payment. Any transaction costs charged by the Payment Service Provider on a refund are borne by Resync; the amount paid by the Client is refunded in full.
After acceptance and commencement of performance there is no right to a refund, save as provided in Articles 10 (liability) and 13 (force majeure) and save for mandatory law. If the Client cancels after acceptance but before commencement, the parties will endeavour to agree a new date; Resync may charge or set off any reasonable, demonstrable costs already incurred.
Following acceptance, the Client's cooperation is required to reach performance, including completing ownership verification (Article 7), supplying the necessary information and access (Article 8), and agreeing a date for performance. If the Client does not provide this cooperation within thirty calendar days of acceptance, despite at least one reminder from Resync, Resync is entitled to cancel the Agreement. In that case Resync refunds fifty percent (50%) of the amount paid by the Client, less costs already incurred, including the Payment Service Provider's transaction costs. The non-refunded part serves as compensation for the capacity reserved by Resync and the assessment already carried out.
Resync is furthermore entitled to suspend or dissolve the Agreement with immediate effect if it appears, after acceptance, that the information provided by the Client about the Target Application or the scope is incorrect or incomplete, that the required control or permission (Article 7) is absent or has been withdrawn, that the access granted has been withdrawn, or that continuation would breach applicable law or regulation. Work already performed and costs already incurred may in that case be charged or set off; no further right to a refund exists, save for mandatory law.
7. Ownership Verification and Authorisation
Performance of the Launch Check requires that the Client is demonstrably entitled to have the Target Application tested. The Client declares and warrants that:
- it is the owner of, or is demonstrably authorised in respect of, the Target Application and all components tested within the scope;
- it grants Resync explicit permission to perform the Launch Check on the Target Application;
- performance does not conflict with any applicable law or regulation or with the rights of third parties;
- it has informed any third parties whose infrastructure or services may be affected by the test (including hosting and cloud providers) and, where required, has obtained their permission;
- the natural person placing the request on the Client's behalf is authorised to bind the Client to this Agreement.
The Client demonstrates control over the Target Application by publishing a verification code supplied by Resync at a location within the Target Application indicated by Resync. Resync checks this verification manually. Resync does not commence performance until ownership verification has been completed. If verification is absent or proves incorrect, Article 6 (rejection and refund) applies.
On making the request, the Client records the name and role of the natural person placing the request on its behalf. Based on the information recorded with the request and the ownership verification, Resync may draw up a consent and authorisation statement, stating the Target Application, the scope, the permission granted, the name and role of the requester and the date of verification. This statement serves as evidence between the parties of the permission and authority granted by the Client.
The Client indemnifies Resync against claims by third parties and against fines or claims by regulators arising from the absence of the required control, permission or authority on the Client's part.
8. Client Obligations
The Client is responsible for:
- providing accurate, complete and representative information on the request and through the Portal, including the designation of the Target Application and any test data (such as credentials);
- supplying sensitive data, such as credentials, exclusively through the dedicated secure upload in the Portal, which encrypts the data in the Client's browser;
- making available, where possible, a representative test or acceptance environment and, where applicable, adequate separation between test, acceptance and production environments;
- informing relevant internal stakeholders of the test activities;
- taking customary precautions, such as up-to-date backups, before the assessment begins.
9. Performance and Delivery
Resync performs the Launch Check within the agreed window and delivers the report through the Portal, in principle within fourteen calendar days of completion of the assessment. Each finding is accompanied by a risk assessment, in which the likelihood of exploitation is plotted against its impact according to the risk matrix below. A debrief of the report can be provided at the Client's request.
If, during performance, Resync encounters indications that the Target Application has already been compromised, that an active security incident is occurring, or that personal data has already been or is being leaked, Resync suspends the work to the extent necessary and notifies the Client without delay, so the Client can take appropriate measures. If Resync identifies a vulnerability in a service or component of a third party that does not form part of the Target Application (including a hosting or cloud provider, or a more widely used software component), Resync notifies the Client and may, with due regard for confidentiality and after consulting the Client, make a coordinated disclosure to the third party concerned through a responsible channel. Resync does not disclose such a finding without necessity, and not before doing so through that coordinated-disclosure channel.
| Likelihood \ Impact | Informational | Low | Medium | High |
|---|---|---|---|---|
| Low | Informational | Low | Low | Medium |
| Medium | Informational | Low | Medium | High |
| High | Informational | Medium | High | Critical |
As the Launch Check is paid in advance and in full, the report is delivered on completion without any further payment condition.
One retest is included with the Launch Check. The retest serves solely to verify whether the findings set out in the report have been remediated and does not include any new or changed scope. The Client requests the retest within sixty calendar days of delivery of the report; after that period the right to the included retest lapses. Following the retest, the Client receives written confirmation of the status of the earlier findings.
Upon payment in full, the Client obtains the right to use, reproduce and share the report with third parties — such as auditors, investors or regulators — for the purposes of its own business operations and compliance. The Client may present the report only unaltered, as an authentic document. The Client is not permitted to alter, shorten or take out of context the report or parts of it and then present it as delivered by Resync or as genuine. Every delivered report is digitally signed; its authenticity and integrity can be verified by anyone via re-sync.nl/verify.
The copyright and all other intellectual property rights in the methods, techniques, templates and tools used by Resync, and in the form of the report, vest in and remain with Resync. The findings specifically concerning the Client's Target Application belong to the Client. Resync is entitled to retain one copy of the report and the underlying findings, subject to the retention period in Article 12, among other things for the purposes of authenticity verification and any retest.
The Client examines the report after delivery. The Client reports complaints about the performance of the Launch Check or about the report, on pain of forfeiture of its rights in that respect, within a reasonable time after discovering the defect or after it reasonably should have discovered it, and no later than fourteen calendar days after delivery, in writing and with reasons, to Resync (Section 6:89 of the Dutch Civil Code).
10. Liability
A security assessment may, by its nature, cause temporary disruption to systems, services or functionality. Resync takes reasonable precautions to limit such disruption as far as possible.
The liability of Resync is in all cases limited to the amount charged for the Launch Check concerned, except in the case of intent or wilful recklessness (opzet or bewuste roekeloosheid) on the part of Resync. Resync expressly excludes liability for:
- indirect damages, consequential damages or loss of profit;
- reputational damage or loss of business;
- claims by third parties arising from the engagement;
- damage resulting from incorrect or incomplete information provided by the Client;
- damage caused by activities outside the agreed scope;
- damage resulting from the absence of the control or authorisation referred to in Article 7;
- incidents involving personal data encountered during the assessment, unless caused by gross negligence or wilful misconduct on the part of Resync.
Without prejudice to the statutory limitation periods, any right of action or other entitlement of the Client against Resync in respect of the Launch Check lapses in any event twelve months after the day on which the Client became aware, or could reasonably have become aware, of the damage or defect, and in any event twenty-four months after delivery of the report.
11. Confidentiality
Resync undertakes to keep confidential all confidential information obtained during the engagement. The Client decides whether and how the report is shared with third parties. This obligation of confidentiality survives termination of the Agreement for a period of five years.
Any reference by Resync to the engagement, even in anonymised form, is permitted only with the separate written agreement of the Client.
The confidentiality obligation does not apply to information that: (a) is or becomes public without breach of this Agreement; (b) was lawfully obtained from a third party without any obligation of confidentiality; (c) was already lawfully known to the receiving party; or (d) must be disclosed pursuant to a statutory obligation, a court order, or a lawfully issued official order. In the case referred to under (d), the party required to disclose notifies the other party in advance, to the extent legally permitted.
This provision serves between the parties as the agreed confidentiality or non-disclosure arrangement. A separate non-disclosure agreement is not required for the Launch Check but may still be entered into at the Client's request.
12. Personal Data
Resync processes the information provided on the request only insofar as necessary to handle and perform the Launch Check. Information provided on the request is retained until the request is accepted or rejected; following acceptance and processing, personal data from the request that is no longer needed is deleted.
Personal data may be encountered during the assessment. Resync processes such data only insofar as necessary for performance and retains data from the assessment for a maximum of one year in encrypted form, after which it is deleted. Where the nature of the work requires it, the parties conclude a data processing agreement pursuant to Article 28 GDPR prior to commencement.
13. Force Majeure
Force majeure means any circumstance that prevents performance of the Agreement and that is not attributable to Resync. In the event of force majeure, obligations are suspended. If the force majeure lasts longer than thirty days, either party may dissolve the Agreement; in that case Resync refunds, on a pro-rata basis, the amount paid for work not yet performed.
Force majeure also includes prolonged incapacity for work, illness or other impediment on the part of the natural person who personally performs the Launch Check, given that the service is by its nature performed personally and is not outsourced. If such an impediment arises after the request has been accepted, Resync notifies the Client as soon as possible, and the Client chooses, without having to wait out the thirty-day period, between: (a) rescheduling performance to a later date in consultation; or (b) dissolving the Agreement, with a refund of the amount paid for work not yet performed.
14. Amendment of the Terms
Resync may amend these terms. Each request is governed by the terms in the version shown on the Intake Form and confirmed by the Client at the time of the request. A later amendment does not apply retroactively to an Agreement already concluded.
15. Governing Law and Jurisdiction
The Agreement and these terms are governed exclusively by Dutch law. The applicability of the United Nations Convention on Contracts for the International Sale of Goods (CISG) is excluded. Disputes arising from or in connection with the Agreement are submitted to the exclusive jurisdiction of the District Court of Noord-Holland (Rechtbank Noord-Holland), the Netherlands.
These terms have been drawn up in Dutch and in English. The Dutch text is the authentic version; in the event of any discrepancy between the two texts, the Dutch text prevails.
Annex 1 Data Processing Agreement
This data processing agreement forms part of the Agreement and applies insofar as Resync, in performing the Launch Check, processes personal data on behalf of and under instruction from the Client. The Client is the controller in respect of that processing; Resync is the processor. Terms have the meaning given to them by the General Data Protection Regulation (GDPR) and these terms.
1. Subject matter and scope. This annex concerns solely personal data present in, or originating from, the Target Application and the test data supplied by the Client, which Resync observes or processes during the Launch Check. It does not concern the personal data the Client provides to Resync on the request, which Resync processes as an independent controller; Article 12 of these terms applies to that data.
2. Nature and purpose; instructions. Resync processes the personal data solely to perform the Launch Check and report on it, and solely on the documented instructions of the Client, of which the Agreement, this annex and the request form part. Resync notifies the Client if, in its view, an instruction conflicts with the GDPR or other data protection legislation.
3. Categories of data subjects and data. The data subjects are the individuals (such as users, customers or staff of the Client) whose personal data is present in the Target Application. The nature and categories of the personal data are determined by the content of the Target Application and the test data, and are not determined by Resync. The Client endeavours to limit the data made available to Resync to what is necessary and to use pseudonymised or test data where possible.
4. Confidentiality. Individuals with access to the personal data under Resync's responsibility are bound to confidentiality under Article 11 of these terms.
5. Security. Resync takes appropriate technical and organisational measures as referred to in Article 32 GDPR, including encryption of data in transit (the secure upload in the Portal already encrypts sensitive data in the Client's browser) and at rest, access controls, and management of the data in an environment operated by Resync itself. The measures are proportionate to the risk of the processing.
6. Sub-processors. Resync does not engage any third party as a sub-processor for the processing referred to in this annex; the Portal and the processing environment are operated by Resync itself. Should Resync nonetheless wish to engage a sub-processor, it will inform the Client in advance and give it the opportunity to object, impose on the sub-processor by agreement the same obligations as set out in this annex, and remain liable to the Client for the sub-processor's performance of those obligations.
7. Assistance. Taking into account the nature of the processing and the information available to it, Resync provides the Client with reasonable assistance in complying with requests from data subjects to exercise their rights and with the obligations under Articles 32 to 36 GDPR.
8. Personal data breach. Resync notifies the Client without undue delay, and in principle within forty-eight hours of becoming aware of it, of a personal data breach, providing the information available at that time (Article 33(2) GDPR). Notification to the supervisory authority and to data subjects is the Client's responsibility as controller.
9. Retention and return. Resync retains personal data from the assessment for a maximum of one year in encrypted form in accordance with Article 12 of these terms, after which it is deleted. At the Client's request, Resync deletes or returns the data sooner, unless a statutory retention obligation applies.
10. Audit. On request, Resync makes available to the Client the information necessary to demonstrate compliance with this annex, and allows for reasonable audits by the Client or an auditor engaged by it, with due regard for confidentiality and a reasonable notice period.
11. Duration and liability. This annex applies for as long as Resync processes personal data on behalf of the Client, as well as during the retention period. Liability under this annex is subject to the limitations of Article 10 of these terms, to the extent permitted by mandatory law.