EDUBOT CUSTOMER AGREEMENT
V3 | SOUTH AFRICA | JULY 2026
| SUPPLIER | SIS Global Services (Pty) Ltd |
|---|---|
| REGISTRATION NUMBER | 2014/175261/07 |
| PHYSICAL ADDRESS | 9 The Straight Avenue, Pineslopes, Gauteng, 2191, South Africa |
| NOTICE EMAIL | legal@sisglobal.com |
| CUSTOMER | The customer identified in the applicable Subscription Order |
AGREEMENT OVERVIEW
This EduBot Customer Agreement is between SIS Global Services (Pty) Ltd, registration number 2014/175261/07 ("Supplier"), and the customer identified in an applicable Subscription Order. It governs the Customer's access to and use of EduBot and all related services ordered from Supplier.
Supplier may use its Affiliates, licensors, technology providers and subcontractors to develop, host, operate, implement, maintain and support components of EduBot. Supplier remains the Customer's sole contractual counterparty and is responsible for the performance of its obligations under this Agreement, subject to the exclusions, dependencies and limitations stated in the Agreement.
By signing or otherwise accepting a Subscription Order that refers to this Agreement, the Customer agrees to this Agreement. Each Subscription Order forms a separate binding contract under these terms.
1. AGREEMENT AND ORDER OF PRECEDENCE
1.1 Contract documents. The agreement between the parties consists of: (a) the applicable Subscription Order; (b) this EduBot Customer Agreement, including Schedule 1 - South African Data Processing and Security Terms; and (c) any statement of work or other document expressly incorporated into the Subscription Order. Together, these documents are the "Agreement".
1.2 Order of precedence. If there is any inconsistency, the Subscription Order prevails for customer-specific Services, quantities, Fees, Term, region, support level, retention and other expressly stated customer-specific selections. Schedule 1 prevails for the processing and security of Personal Information. The General Terms prevail over any statement of work, proposal or other incorporated document unless the Subscription Order expressly states otherwise. A document varies another only where the variation is express and specific. Any purchase order, purchase-order terms, tender conditions, supplier-portal terms or other procurement document issued by the Customer is administrative only and does not amend or supplement the Agreement unless the amendment is expressly identified and signed by authorised representatives of both parties.
1.3 Version control. The version of this Agreement identified in the Subscription Order applies during the current committed Order Term. Supplier may propose an updated version for a Renewal Term by giving reasonable advance notice. An updated version applies only if accepted by the Customer in writing, through a renewal order or through another agreed electronic acceptance process. If the parties do not agree the applicable terms before renewal, the Order will not renew unless they agree otherwise in writing.
1.4 Separate Orders. Each Subscription Order is a separate commitment. Ending one Order does not end another Order unless the parties agree otherwise in writing.
2. DEFINITIONS AND INTERPRETATION
2.1 AI Input means any prompt, query, instruction, content or data submitted to an artificial-intelligence feature through EduBot.
2.2 AI Output means content generated, classified, summarised or transformed by an artificial-intelligence feature in response to an AI Input.
2.3 Applicable Law means all laws and binding regulatory requirements applicable to a party's performance under the Agreement, including applicable data-protection and electronic-communications laws.
2.4 Authorised User means an employee, contractor, administrator, agent or other person whom the Customer authorises to access EduBot.
2.5 Business Day means any day other than a Saturday, Sunday or public holiday in South Africa.
2.6 Confidential Information means non-public information disclosed by or on behalf of a party that is identified as confidential or that a reasonable person would understand to be confidential. It includes Customer Data, pricing, security information, software, product plans and business information.
2.7 Customer Data means all data, content, Personal Information, records, documents, messages, files, images, audio, instructions, configurations, transaction information, integration data, prompts, outputs and other information submitted to, stored in, transmitted through, generated for, or made accessible to the Services by or on behalf of the Customer or an End User. Customer Data may include any category of Personal Information or other institutional information that the Customer lawfully elects to process through the ordered or configured Services. Customer Data includes AI Inputs and customer-specific AI Outputs, but excludes Service Data and Derived Data.
2.8 Derived Data means aggregated, statistical, de-identified, anonymised, abstracted, transformed or inferred information, including metrics, patterns, trends, classifications, taxonomies, benchmarks, models and insights, created from Customer Data, Customer Materials or Service Data, that: (a) does not identify and cannot reasonably be used, alone or with reasonably available information, to identify any person or the Customer; (b) does not disclose Customer Confidential Information or reproduce material portions of Customer Data or Customer Materials; and (c) cannot reasonably be used to reconstruct the underlying Customer Data.
2.9 Documentation means the user, administration, support and service documentation made available by Supplier for EduBot.
2.10 End User means a person who interacts with EduBot through a Customer channel, including a student, prospective student, applicant, employee or member of the public.
2.11 Fees means the subscription, usage, professional-services, third-party and other charges stated in a Subscription Order or agreed statement of work.
2.12 Message means the unit of consumption described in the Subscription Order. If the Order is silent, each inbound or outbound message handled by EduBot counts as one Message, excluding purely technical delivery acknowledgements.
2.13 Personal Information has the meaning assigned to it in the Protection of Personal Information Act 4 of 2013 ("POPIA") and includes, where applicable, Special Personal Information and Personal Information of Children.
2.14 Security Incident means an accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data. It excludes unsuccessful attempts that do not compromise Customer Data.
2.15 Service Data means technical, security, billing, diagnostic and operational data generated through the operation of EduBot, such as usage, performance, error and security logs. Service Data does not include message content except where temporarily included in logs reasonably required to diagnose an incident.
2.16 Services means the EduBot subscription services, support, artificial-intelligence features, messaging channels, analytics, integrations, professional services and other services identified in a Subscription Order.
2.17 Supplier IP means EduBot, the Documentation, software, system prompts, orchestration, standard configurations, generic taxonomies, templates, methods, analytics methodologies, connectors, know-how, Derived Data, improvements and other intellectual property owned by or licensed to Supplier, or made available to Supplier by its Affiliates or licensors, excluding Customer Data and Customer Materials.
2.18 Subscription Order or Order means an ordering document accepted by the parties that identifies the Services, quantities, Fees, Term, region and applicable selections.
2.19 Third-Party Service means a product or service supplied by a third party and used with or embedded in EduBot, including Microsoft Azure, enterprise artificial-intelligence models, Meta or WhatsApp, SMS, email, telephony and carrier services.
2.20 Affiliate means an entity that directly or indirectly controls, is controlled by, or is under common control with a party.
2.21 Supplier means SIS Global Services (Pty) Ltd, registration number 2014/175261/07, as the contracting supplier of EduBot under the Agreement.
2.22 Technology Provider means an Affiliate, licensor, cloud provider, software provider or other third party whose technology or services are used to develop, host, operate, maintain or support EduBot.
2.23 Sub-operator means an Affiliate or third party appointed by Supplier to process Personal Information on Supplier's behalf in connection with the Services.
2.24 Customer Materials means Customer Data, the Customer's trademarks, institutional content, policies, rules, workflows, business logic and other materials supplied by or on behalf of the Customer.
2.25 High-Impact Decision means a decision that has a legal or similarly significant effect on a person, including admission, financial aid, academic progression, discipline, exclusion, disability accommodation or a comparable decision.
2.26 Initial Term means the initial committed period stated in the applicable Order.
2.27 Order Term means the Initial Term and each Renewal Term of an Order.
2.28 Renewal Term means a renewal period stated in or arising under an Order.
2.29 Support Hour means an hour falling within the applicable support hours stated in clause 14.7 or the Order.
2.30 Unavailable Minutes means minutes during which the production EduBot platform is unavailable to the Customer, excluding the events listed in clause 14.3.
2.31 Data Protection Laws means POPIA, the regulations issued under POPIA, any binding code of conduct applicable to the processing, and binding requirements issued by the Information Regulator.
2.32 Data Subject means the person to whom Personal Information relates, as contemplated in POPIA.
2.33 Personal Information of Children means Personal Information relating to a natural person under the age of 18 years who is not legally competent, without the assistance of a competent person, to take an action or decision in respect of that person.
2.34 Special Personal Information means the categories of Personal Information contemplated in sections 26 to 33 of POPIA.
2.35 Customer Branding means the Customer's approved names, logos, trademarks, colour schemes, tone of voice, interface names and other branding provided or approved for use with the Services.
2.36 Customer-Facing Name means the name selected by the Customer for its configured EduBot deployment and stated in the applicable Order or otherwise approved through the agreed administrative process.
2.37 Interpretation. Headings are for convenience only. The singular includes the plural, "including" means including without limitation, and references to a law include its amendments and replacements.
3. SUBSCRIPTION AND SERVICES
3.1 Right to use. Subject to payment of the Fees and compliance with the Agreement, Supplier grants the Customer a limited, non-exclusive, non-transferable right during the applicable Order Term for the Customer and its Authorised Users to access and use the ordered Services for the Customer's internal institutional operations and for authorised communications and service delivery to students, applicants, staff and other End Users.
3.2 Ordered scope. The Customer may use only the plans, quantities, capacity, environments, regions, channels, integrations and Authorised Users stated in the Order. Usage above an included quantity may incur additional Fees in accordance with the Order.
3.3 Service operation and changes. Supplier may update the Services itself or through its Affiliates, licensors, Technology Providers and subcontractors to improve security, performance, usability or functionality, or to comply with law, licence terms or third-party requirements. Supplier will not materially reduce the core functionality purchased by the Customer during a committed Order Term without providing a reasonable alternative or the remedy in clause 11.4.
3.4 Provision through Affiliates and providers. Components of the Services may be developed, owned, licensed, hosted, operated, implemented, maintained or supported by Supplier's Affiliates, licensors, Technology Providers and subcontractors as part of Supplier's integrated EduBot offering. Those persons are not parties to the Agreement and do not owe the Customer direct contractual obligations unless the Customer separately contracts with them. Supplier remains responsible to the Customer for the performance of its obligations under the Agreement, subject to the exclusions, dependencies and liability limits stated in it.
3.5 Restrictions. The Customer must not: (a) reverse engineer, decompile or attempt to derive source code, except to the limited extent that Applicable Law prohibits the restriction; (b) circumvent security, metering or technical limits; (c) resell, sublicense, lease or provide EduBot as a service bureau; (d) use Supplier Confidential Information to develop a competing product; (e) remove proprietary notices; (f) introduce malicious code; or (g) use the Services unlawfully or in a way that materially threatens the security or availability of the Services.
3.6 No source-code rights. No source code, model weights, system prompts, internal architecture or unpublished technical documentation of Supplier, its Affiliates, licensors or Technology Providers is licensed or delivered unless expressly stated in a signed statement of work.
3.7 Supplier-hosted platform. EduBot is a hosted software-as-a-service platform operated within Supplier-controlled or Supplier-managed cloud infrastructure. Customer Data is stored and processed within that environment and is not deployed into the Customer's tenant unless an Order expressly states otherwise. Supplier will maintain logical separation between Customer Data and data belonging to other customers.
3.8 Customer-facing deployment name. The Customer may make its configured EduBot deployment available to End Users under a Customer-Facing Name and Customer Branding. The Customer-Facing Name is a branding and configuration selection only and does not create a separate product, change the identity of the Services or Supplier, alter the parties' legal roles, or transfer ownership of Supplier IP. A reasonable change to the Customer-Facing Name or branding may be managed through the agreed administrative or change-control process and does not amend the Agreement unless it requires additional Services, custom development or Fees.
4. ORDERS AND CUSTOMER CONTACTS
4.1 Order acceptance. An Order becomes binding when accepted by the Customer and Supplier. The Order must identify the Services, quantities, Fees, Term and customer-specific selections.
4.2 Order administration. Supplier may use an Affiliate or service provider to perform administrative, invoicing, implementation or delivery activities on Supplier's behalf. No such person may vary Supplier's obligations or bind Supplier to additional terms unless Supplier expressly authorises it in writing.
4.3 Administrative access. Supplier and its approved Affiliates, Technology Providers and subcontractors may receive administrative access to the Customer's environment or Customer Data only where the access is authorised by the Customer, reasonably required to provide or support the Services, and governed by the confidentiality, security and data-protection obligations in the Agreement.
4.4 Customer contacts. The Customer must maintain accurate billing, technical, security and administrative contacts. Supplier may rely on instructions from an authorised contact until it receives written notice of a change.
5. FEES, CAPACITY AND PAYMENT
5.1 Fees and invoicing. Fees, billing frequency and payment terms are stated in the Order. Unless the Order states otherwise, subscription Fees are invoiced in advance, usage and pass-through charges are invoiced in arrears, and invoices are payable within thirty days.
5.2 Taxes. Fees exclude VAT and other applicable taxes. The Customer must pay taxes that Supplier is legally required to collect, excluding taxes on Supplier's net income.
5.3 Included capacity. Capacity included for an annual, monthly or other stated period is available only during that period, does not roll over and has no cash or credit value unless the Order expressly states otherwise.
5.4 Overage and metering. Usage above included capacity is charged in the block size and at the rate stated in the Order. Supplier's metering records are the primary record of usage. The Customer must dispute measured usage within thirty days after the relevant report or invoice and provide reasonable supporting information.
5.5 Third-party charges. Carrier, Meta or WhatsApp, SMS, telephony, regulatory and other third-party charges may change when the provider changes them. Supplier may pass those changes through from their effective date on reasonable notice.
5.6 Price protection and renewal. Recurring Fees remain fixed during the committed Order Term except for usage, pass-through charges, taxes, changes requested by the Customer or an adjustment expressly stated in the Order. Unless the Order states otherwise, recurring Fees will increase by six percent at the start of each Renewal Term.
5.7 Invoice disputes. The Customer must notify Supplier of a good-faith invoice dispute before the due date, identify the disputed amount and reasons, and pay all undisputed amounts. The parties will work in good faith to resolve the dispute promptly.
5.8 Overdue amounts. Supplier may charge interest on overdue undisputed amounts at the lower of 1.5 percent per month and the maximum lawful rate. Supplier may suspend the affected Services under clause 19.5 if an undisputed amount remains unpaid after written notice.
6. CUSTOMER RESPONSIBILITIES AND ACCEPTABLE USE
6.1 Customer responsibilities. The Customer is responsible for: (a) selecting and approving its institutional content; (b) ensuring that Customer Data and instructions are accurate, lawful and appropriate; (c) managing Authorised Users and their credentials; (d) maintaining its devices, systems, networks and integrations; (e) defining escalation, routing and human-review procedures; and (f) using the Services in accordance with Applicable Law.
6.2 End-user transparency. The Customer is responsible for approving and maintaining an appropriate student-facing notice or disclaimer that satisfies section 18 of POPIA and any other applicable transparency requirements. The Customer may meet this obligation through its institutional privacy information, a customer-specific disclaimer, a linked notice, or a combination of those materials, provided the required information is reasonably accessible to End Users. Supplier will configure EduBot to display or link to the Customer-approved wording through the ordered channels where technically practicable. The wording must explain that End Users may be interacting with an artificial-intelligence system, that answers may require verification, that interactions may be logged and analysed, what Personal Information is collected and why, how to obtain human assistance, how anonymous and aggregated information may be used to improve the Services and create sector insights or benchmarks, and how to exercise applicable rights. The Customer must not present EduBot as an emergency channel.
6.3 Personal Information selected by the Customer. The Customer may configure and use the Services to process Personal Information, including Special Personal Information, Personal Information of Children, financial information and other sensitive records, where the Customer has determined that the processing is lawful, necessary and appropriate. The Customer is responsible for its processing purposes, lawful justification, notices, permissions, retention requirements, configurations and authorised users. Supplier processes that information only to provide and secure the Services, create Derived Data as permitted by clause 8, and act in accordance with the Customer's documented instructions and Schedule 1.
6.4 Prohibited use. The Customer must not use the Services to create, transmit or facilitate unlawful, discriminatory, deceptive, harmful, exploitative or infringing content; impersonate a person unlawfully; bypass safety measures; perform prohibited surveillance or profiling; or interfere with another customer's use of the Services.
6.5 Customer dependencies. The Customer must provide reasonably required content, access, approvals, systems, technical contacts and decisions. Supplier is not responsible for a delay or failure caused by a Customer dependency, and agreed dates may be adjusted accordingly.
6.6 Electronic direct marketing. Supplier will not use Customer Personal Information to conduct direct marketing on its own behalf. Where the Customer instructs Supplier to send promotional, recruitment or other direct-marketing communications, the Customer is responsible for compliance with section 69 of POPIA, including any consent, existing-customer conditions and opt-out requirements.
6.7 End-user terms. Supplier may apply its standard AI Student Assistant End-User Terms - South Africa to individual End Users, regardless of the Customer-Facing Name used for the deployment. The Customer may display those terms under its Customer-Facing Name, provided the underlying terms are not substantively changed without Supplier's written approval. The End-User Terms govern individual acceptable use only; they do not amend the Agreement, reduce either party's obligations under Applicable Law, or make Supplier the Responsible Party for Customer Personal Information.
7. ARTIFICIAL-INTELLIGENCE SERVICES
7.1 AI functionality. EduBot may use enterprise artificial-intelligence services to understand questions, retrieve approved information, classify interactions, create summaries, draft responses, assist staff and provide analytics or recommendations.
7.2 Output limitations. AI Output is generated probabilistically and may be inaccurate, incomplete, outdated, non-unique, biased or unsuitable for a particular purpose. Supplier does not warrant the accuracy or completeness of every AI Output. The Customer must apply human review appropriate to the nature and risk of the use before relying on, publishing or acting on AI Output.
7.3 High-impact decisions and professional advice. AI Output must not be used as the sole basis for a decision that has a legal or similarly significant effect on a person, including admission, financial aid, academic progression, discipline, exclusion or disability accommodation. The Customer must not use EduBot as a substitute for qualified medical, legal, financial, emergency or other professional advice.
7.4 Safeguards. Supplier will configure, or contractually require its relevant Technology Providers to configure, reasonable grounding, content-filtering, escalation, testing and monitoring controls appropriate to the ordered Services. These controls reduce but do not eliminate the risks associated with artificial intelligence.
7.5 No training of general-purpose AI models using raw Customer Data. Supplier will not, and will require its relevant Affiliates, enterprise AI providers and Sub-operators not to, use raw Customer Data, identifiable AI Inputs, identifiable AI Outputs or identifiable End User interactions to train or improve a general-purpose artificial-intelligence model made available to unrelated customers, unless the Customer expressly authorises that use in writing. This restriction does not prevent processing necessary to provide the Services, customer-specific configuration or analytics, or Supplier's creation and use of Derived Data in accordance with clause 8.
7.6 Provider processing. Enterprise AI providers and other approved Sub-operators may process AI Inputs and Outputs and may apply content filtering and abuse monitoring in accordance with their applicable enterprise terms and deployment configuration. Supplier will use enterprise offerings under which Customer prompts and completions are not used to train or improve general-purpose artificial-intelligence models without the Customer's permission or instruction.
7.7 Model and technology changes. Supplier may change an underlying model, model version, AI provider or Technology Provider to improve quality, security, availability or cost, or because a provider changes or retires a service. Supplier will notify the Customer of a material change that is reasonably expected to reduce key functionality, materially change the processing of Customer Data or change the primary hosting region.
7.8 Customer-specific models. Fine-tuning or customer-specific model training by Supplier or a Technology Provider is not included unless an Order or signed statement of work identifies the approved data, purpose, provider, retention, evaluation, ownership and deletion requirements.
8. DATA OWNERSHIP AND ANALYTICS
8.1 Customer ownership. As between the parties, the Customer retains all right, title and interest in Customer Data and in the Customer's content, trademarks, policies, workflows and other materials.
8.2 Processing rights. The Customer authorises and instructs Supplier and its approved Sub-operators to host, copy, transmit, transform and otherwise process Customer Data and Customer Materials as reasonably necessary to provide, secure, support and administer the Services, comply with documented instructions and legal obligations, and create Derived Data under clauses 8.5 to 8.7. Sub-operators may exercise those rights only on Supplier's behalf and subject to written obligations.
8.3 Customer-specific analytics. Reports, metrics, classifications, findings and recommendations generated from Customer Data for the Customer are Customer Confidential Information. The Customer may use them for its internal institutional purposes and authorised service delivery. Supplier and its licensors retain ownership of the underlying software, generic taxonomies, scoring methods, templates and analytics methodologies.
8.4 Service Data. Supplier may use Service Data, and may permit approved Sub-operators to process Service Data on Supplier's behalf, to operate, secure, bill, support, capacity-plan, analyse and improve EduBot, provided that message content is not used beyond what is reasonably necessary for those purposes or to create Derived Data under this clause 8.
8.5 Creation of Derived Data. Supplier may process any Customer Data, Customer Materials and Service Data to create Derived Data. Supplier may use approved Sub-operators to assist with that processing, subject to written confidentiality, security and use restrictions. Information will not be treated as Derived Data merely because obvious identifiers have been removed; it must meet the standard in clause 2.8.
8.6 Use and ownership of Derived Data. Supplier owns all rights in Derived Data and may retain, combine, analyse, use, reproduce, develop and provide Derived Data for any lawful business purpose, including operating, securing and improving EduBot; developing products, features, analytics, workflows and artificial-intelligence capabilities; conducting research and quality evaluation; identifying sector trends and service gaps; and creating anonymous reports, insights and benchmarks. Derived Data that meets clause 2.8 is not Customer Data or Customer Confidential Information.
8.7 Safeguards. Supplier will not attempt to re-identify Derived Data or use it in a manner reasonably likely to identify an individual or the Customer, disclose Customer Confidential Information, reproduce material Customer content or enable reconstruction of the underlying Customer Data. Raw Customer Data, identifiable interactions and customer-identifiable results remain subject to the Agreement and may not be used to train or improve a general-purpose artificial-intelligence model made available to unrelated customers without the Customer's express written authorisation.
8.8 No sale or customer-identifiable disclosure. Supplier will not sell Customer Data or disclose customer-identifiable performance, raw interactions or Customer Materials to another customer or the public. Public case studies, named benchmarks and use of the Customer's name or logo require the Customer's prior written approval. This clause does not restrict Supplier's use of Derived Data in accordance with clauses 8.5 to 8.7.
9. DATA PROTECTION
9.1 Schedule 1. Schedule 1 forms part of this Agreement and governs Supplier's processing and security of Personal Information under POPIA.
9.2 Roles. For Customer Personal Information processed through the Services on the Customer's instructions, the Customer is the Responsible Party and Supplier is the Operator. Supplier may use approved Sub-operators and remains responsible to the Customer as stated in the Agreement and Schedule 1.
9.3 Configurable enterprise platform. EduBot is a configurable, Supplier-hosted enterprise platform. The Customer determines the business purposes, data categories, configurations, integrations, workflows and authorised users. Supplier does not independently determine the lawfulness of the Customer's use and does not assume the Customer's obligations as Responsible Party.
9.4 Supplier processing. Supplier and its approved Sub-operators may access and process Customer Data only where reasonably necessary to provide, host, operate, secure, maintain, support or troubleshoot the Services, create Derived Data as permitted by clause 8, comply with South African law, or follow the Customer's documented instructions. Access is subject to confidentiality, role-based access, least privilege, logging and the controls in Schedule 1.
9.5 No unauthorised use. Supplier will not sell Customer Personal Information, use it for Supplier direct marketing, disclose customer-identifiable performance to another customer, or use raw Customer Data to train or improve a general-purpose artificial-intelligence model made available to unrelated customers unless the Customer expressly authorises that use in writing.
10. SECURITY
10.1 Security programme. Supplier will maintain appropriate, reasonable technical and organisational safeguards for the nature of the Services and Customer Data and will contractually require material Sub-operators to maintain safeguards appropriate to their roles. Supplier will identify reasonably foreseeable internal and external risks to Personal Information; establish and maintain safeguards against those risks; regularly verify that safeguards are effectively implemented; and update safeguards in response to new risks or deficiencies. Safeguards include, where applicable, role-based access, least privilege, multi-factor authentication for privileged access, encryption in transit and at rest, secure development and deployment, vulnerability management, logging and monitoring, backups, incident response, personnel controls and supplier-risk management.
10.2 Changes to safeguards. Supplier may replace a safeguard with an alternative that provides materially equivalent or better protection and may update safeguards to address new risks, technology or legal requirements.
10.3 Customer security. The Customer is responsible for the security of its devices, accounts, integrations, networks, credentials and Authorised Users. It must promptly notify Supplier of suspected credential compromise or unauthorised access.
10.4 Security suspension. Supplier may suspend an account, integration or affected function where reasonably necessary to contain a security risk. Supplier will notify the Customer where lawful and practicable, limit the suspension to what is reasonably necessary and restore the affected Service once the risk has been addressed.
11. TECHNOLOGY PROVIDERS AND THIRD-PARTY SERVICES
11.1 Technology foundation. EduBot may incorporate technology developed, owned, licensed, hosted or operated by Supplier's Affiliates, licensors and Technology Providers. The Services may also use Microsoft Azure, Microsoft Foundry, Azure OpenAI, Meta or WhatsApp, communications providers and other Third-Party Services. Supplier's use of those technologies is governed by its agreements with the relevant providers.
11.2 Customer compliance and no direct provider contract. The Customer must comply with mandatory provider restrictions that Supplier is required to pass through and makes reasonably available to the Customer. Supplier's Affiliates, licensors, Technology Providers and Sub-operators are not parties to the Agreement and do not owe the Customer direct contractual obligations unless the Customer separately contracts with them. Supplier remains the Customer's contractual point of accountability for the Services supplied under the Agreement.
11.3 Provider changes. A Technology Provider may change, suspend or discontinue a technology or service. Supplier may replace an affected component or Third-Party Service with a materially equivalent alternative and remains responsible for the core Services supplied by Supplier, subject to the dependencies and exclusions in the Agreement.
11.4 Material provider or licence change. If a provider or licence change, loss of a necessary technology right, or new law makes an ordered Service unlawful, unavailable or commercially impracticable, Supplier may modify the affected Service on notice. If the modification materially reduces the contracted capability and Supplier cannot provide a reasonable alternative within sixty days, either party may terminate the affected Service and Supplier will refund prepaid Fees for the unused period.
11.5 Provider credits. Where Supplier receives a provider service credit specifically attributable to the Customer's affected Service, Supplier will pass through the credit to the extent that the same interruption has not already resulted in an EduBot service credit. There is no double recovery.
12. PROFESSIONAL SERVICES AND CHANGE CONTROL
12.1 Agreed scope. Implementation, configuration, integration, training, data migration, custom development and other professional services will be described in an Order or statement of work, including the scope, assumptions, responsibilities, Fees and timing.
12.2 Change control. A material change to scope, integrations, data sources, channels, workflows, reports or deliverables requires written agreement on the effect on Fees, responsibilities and timing. Supplier is not required to perform changed work before the change is agreed.
12.3 Dependencies and delays. Dates depend on the assumptions and Customer dependencies stated in the relevant document. Customer delays, unavailable systems, incomplete content, late approvals or third-party constraints may result in a reasonable adjustment to dates and Fees.
12.4 Acceptance. Unless otherwise stated, a deliverable is accepted when the Customer approves it, uses it in production, or does not reject it with details of a material non-conformity within ten Business Days after delivery. Supplier will correct a valid material non-conformity as the Customer's remedy.
12.5 Deliverable rights. Customer materials remain the Customer's property. Customer-specific configurations and deliverables are licensed for use with EduBot during the applicable subscription unless the relevant statement of work grants a longer right. Generic improvements, reusable code, connectors, methods and know-how remain Supplier IP.
13. CONFIDENTIALITY
13.1 Use and protection. Each receiving party will use the other party's Confidential Information only to perform or receive the Services and will protect it using at least reasonable care. Clause 8 governs Supplier's authorised processing of Customer Data and Customer Materials to create and use Derived Data.
13.2 Permitted recipients. A receiving party may disclose Confidential Information to its personnel, affiliates, professional advisers, insurers and contractors who need it and are bound by appropriate confidentiality obligations. The receiving party remains responsible for their compliance.
13.3 Exclusions. Confidential Information excludes information that the receiving party can show: (a) is public without breach of the Agreement; (b) was lawfully known without restriction; (c) is lawfully received from a third party without confidentiality obligations; or (d) is independently developed without use of the Confidential Information.
13.4 Required disclosure. A party may disclose Confidential Information where legally required, but must, where lawful, give prior notice and reasonable assistance to seek protective treatment.
13.5 Duration. These obligations continue for five years after disclosure. Customer Data, Personal Information, security information and trade secrets remain protected for as long as they remain confidential or Applicable Law requires.
14. SUPPORT AND SERVICE LEVELS
14.1 Included support and support chain. Supplier is the Customer's single point of contact for the support and maintenance included in the applicable plan or Order. Supplier may use approved Affiliates and subcontractors for second- or third-line platform support, but the Customer is not required to contract with or contact them. Support includes platform monitoring, incident management, defect correction, security and version updates, and reasonable administrative guidance. It excludes new features, material configuration changes, content creation and integrations not stated in the Order.
14.2 Availability target. The monthly availability target for the production EduBot platform is 99.5 percent unless the Order states otherwise. Monthly availability is calculated as the total minutes in the month, less Unavailable Minutes, divided by the total minutes in the month, multiplied by 100.
14.3 Exclusions. Unavailable Minutes exclude planned or emergency maintenance; Customer systems, misuse or breach; internet, carrier or Third-Party Service failures outside Supplier's reasonable control; preview features; permitted suspension; force majeure; and failures of integrations not managed by Supplier.
14.4 Maintenance. Supplier will use reasonable efforts to give five Business Days' notice of planned maintenance that may materially affect production. Emergency maintenance may be performed without prior notice where reasonably necessary for security or stability.
14.5 Service credits. If monthly availability is:
| Monthly availability | Service credit |
|---|---|
| (a) At least 99.0 percent but below 99.5 percent | 5 percent of the affected monthly recurring platform Fee |
| (b) At least 95.0 percent but below 99.0 percent | 10 percent |
| (c) Below 95.0 percent | 20 percent |
14.6 Credit conditions. A credit must be claimed within thirty days after the affected month with reasonable supporting details, is applied to a future invoice and may not exceed 20 percent of the affected monthly recurring platform Fee. Service credits are the Customer's sole monetary remedy for an availability failure, without limiting clause 14.9.
14.7 Support hours. Standard support hours are 07:00 to 19:00 South African time on Business Days. Critical incidents may be logged through the designated emergency channel at any time. The Order may include extended coverage.
14.8 Response targets. Unless the Order states otherwise, the initial response targets are:
| Priority | Initial response | Description |
|---|---|---|
| (a) Critical | one support hour | a complete production outage or confirmed major security incident |
| (b) High | two support hours | a major failure with material operational impact |
| (c) Medium | eight support hours | a non-critical defect with a workaround |
| (d) Low | one Business Day | a minor defect, advice or administrative request |
These are response targets, not guaranteed resolution times. Resolution depends on complexity, Customer cooperation and third-party dependencies.
14.9 Chronic failure. If monthly availability is below 95 percent for three consecutive months or for four months in any six-month period, the Customer may terminate the affected production Order by notice given within thirty days after the final affected month and receive a refund of prepaid Fees for the unused period.
15. INTELLECTUAL PROPERTY
15.1 Ownership. Supplier, its Affiliates and licensors retain all right, title and interest in Supplier IP, including EduBot, the underlying platform technology, standard software, Documentation, models, workflows, methods, analytics and related technology. The Customer receives only the rights expressly granted under the Agreement. No ownership rights or direct licence from an Affiliate, licensor or Technology Provider are transferred to the Customer.
15.2 Customer Materials. The Customer retains ownership of Customer Data and Customer Materials. Supplier and its approved Sub-operators may use them only as permitted by the Agreement and documented Customer instructions, including to create Derived Data under clause 8.
15.3 Feedback. Supplier may use feedback provided by the Customer without restriction, provided that it does not disclose Customer Confidential Information or Personal Information.
15.4 AI Output. AI Output may not be unique and similar output may be generated for others. Subject to Supplier's and its licensors' retained rights and third-party rights, the Customer may use customer-specific AI Output generated through its authorised use of EduBot for its internal institutional operations and for authorised communications and service delivery to students, applicants, staff and other End Users.
15.5 Publicity. Neither party may use the other party's name, logo, case study, testimonial or public statement without prior written approval, except where disclosure is legally required.
15.6 Customer Branding. The Customer retains ownership of Customer Branding and grants Supplier, its Affiliates and approved service providers a limited, non-exclusive licence during the applicable Order Term to reproduce, display and use Customer Branding solely to configure, provide, support and identify the Customer's deployment of the Services. The Customer warrants that it has the rights required to provide and authorise use of Customer Branding. Supplier acquires no ownership in Customer Branding, and any use for publicity remains subject to clause 15.5.
16. WARRANTIES AND DISCLAIMERS
16.1 Supplier warranties. Supplier warrants that during an Order Term: (a) EduBot will materially conform to the Documentation; (b) professional services will be performed with reasonable skill and care; (c) Supplier will not knowingly introduce malicious code into the Services; and (d) Supplier has the contractual rights necessary to supply EduBot and grant the use rights stated in the Agreement.
16.2 Remedy. If Supplier breaches clause 16.1, it will use reasonable efforts to correct or reperform the affected Service. If it cannot do so within a reasonable period, the Customer may terminate the materially affected Service and receive a refund of prepaid Fees for the unused period.
16.3 Exclusions. The warranties do not apply to issues caused by Customer Data or systems, unauthorised changes, misuse, failure to follow Documentation, Third-Party Services selected or controlled by the Customer, provider failures outside Supplier's reasonable control that do not form part of the core EduBot platform, preview features or unsupported configurations. This clause does not remove Supplier's responsibility for the core EduBot Services merely because Supplier performs through an Affiliate or subcontractor.
16.4 Disclaimers. Except for the express warranties in the Agreement and to the maximum extent permitted by law, the Services are provided as available. Supplier does not warrant uninterrupted or error-free operation, the accuracy or completeness of every AI Output, or that analytics, recommendations or predictions will produce a particular student, financial or operational outcome.
16.5 Statutory rights. Nothing in the Agreement excludes a warranty, right or remedy that Applicable Law does not permit the parties to exclude or limit.
17. THIRD-PARTY CLAIMS AND INDEMNITIES
17.1 Supplier IP indemnity. Supplier will defend the Customer against a third-party claim that the unmodified proprietary EduBot software or technology supplied by Supplier infringes that party's copyright, patent or trademark, and will pay damages finally awarded or settlement amounts approved by Supplier, subject to this clause 17.
17.2 Supplier options. If an infringement claim is made or is reasonably likely, Supplier may obtain the right to continue use, modify or replace the affected Service without material loss of function, or terminate the affected Service and refund prepaid Fees for the unused period.
17.3 Exclusions. Supplier has no liability for a claim arising from Customer Materials or instructions, a combination not supplied by Supplier, modification by another person, continued use after notice, use outside the Agreement or a Third-Party Service selected by the Customer. The use of Affiliates, licensors or Technology Providers to supply components of EduBot does not by itself exclude the indemnity in clause 17.1.
17.4 Customer indemnity. The Customer will defend Supplier and its affiliates against a third-party claim arising from Customer materials, unlawful End User content, Customer instructions or prohibited use of the Services, and will pay damages finally awarded or settlement amounts approved by the Customer.
17.5 Procedure. The indemnified party must promptly notify the indemnifying party, allow it to control the defence and settlement, and provide reasonable assistance at the indemnifying party's expense. A settlement may not admit fault by or impose a non-monetary obligation on the indemnified party without its consent.
18. LIMITATION OF LIABILITY
18.1 General cap. Except for the liabilities in clause 18.3, each party's total aggregate liability arising out of an Order will not exceed the Fees paid or payable under that Order during the twelve months immediately preceding the event giving rise to liability.
18.2 Enhanced cap. Each party's total aggregate liability for breach of confidentiality, data-protection or security obligations, and for its indemnity obligations under clause 17, will not exceed twice the cap in clause 18.1.
18.3 Uncapped matters. No cap or exclusion applies to fraud or wilful misconduct, death or personal injury to the extent liability cannot be limited, deliberate infringement or misappropriation of the other party's intellectual property, the Customer's obligation to pay Fees, or liability that Applicable Law prohibits the parties from limiting.
18.4 Excluded losses. Neither party is liable for indirect, special, incidental, exemplary or consequential loss, or for loss of profit, revenue, goodwill or anticipated savings. This exclusion does not prevent recovery of direct and reasonable costs incurred to investigate, contain, notify and remediate a Security Incident caused by the other party, subject to the applicable cap.
18.5 AI reliance. Supplier is not liable for a decision made by the Customer or an Authorised User based on AI Output where the Customer failed to apply the human review or safeguards required by the Agreement.
18.6 Application. These limitations apply to the maximum extent permitted by law, regardless of the legal theory, and each party must take reasonable steps to mitigate its loss.
18.7 Provider-related claims and no double recovery. Any act or omission of an Affiliate or subcontractor for which Supplier is responsible under the Agreement is treated as an act or omission of Supplier for purposes of this clause 18. The Customer may not recover more than once for the same loss from Supplier or another responsible person.
19. TERM, RENEWAL, SUSPENSION AND TERMINATION
19.1 Agreement term. This Agreement begins when the first Order referring to it is accepted and continues while any Order remains in effect. Each Order begins on its commencement date and continues for its Initial Term.
19.2 Renewal. Unless the Order states otherwise, following the Initial Term an Order automatically renews for successive periods of twelve (12) months, each a "Renewal Term", unless either party gives the other party written notice of non-renewal at least thirty (30) days before the end of the Initial Term or the then-current Renewal Term.
19.3 Committed Term. An Order is non-cancellable during its committed Term except as expressly provided in the Agreement or required by Applicable Law.
19.4 Termination for cause. Either party may terminate an affected Order for a material breach that is not cured within thirty days after written notice. The cure period is seven days for undisputed non-payment, prohibited use, a material security breach or unlawful processing. A breach that cannot be cured permits immediate termination.
19.5 Suspension. Supplier may suspend all or part of an affected Service where reasonably necessary because of overdue undisputed Fees, a security risk, unlawful or prohibited use, a provider suspension, excessive usage that materially threatens the platform, or a legal requirement. Supplier will give prior notice where practicable, limit the suspension to what is reasonably necessary and restore the Service when the reason has been addressed.
19.6 Effect of termination. On termination, access rights end and accrued Fees become payable. Prepaid unused subscription Fees are refunded only where the Customer terminates for Supplier's uncured material breach or where the Agreement expressly provides for a refund.
19.7 Consumer law. If the Consumer Protection Act 68 of 2008 or another mandatory consumer law applies to an Order, any non-excludable cancellation or renewal rights under that law prevail to the extent of a conflict.
20. DATA EXPORT, RETENTION AND EXIT
20.1 Export during the Term. During the Order Term, the Customer may export available Customer Data and reports using standard export functions. Additional extraction, migration, transformation or transition services may be charged at agreed rates.
20.2 Post-termination export. Unless the Order states otherwise, Supplier will make a standard export of Customer Data available for thirty days after termination, subject to payment of undisputed Fees.
20.3 Deletion. After the export period, Supplier will delete, destroy or de-identify production Customer Data within sixty days and will require relevant Sub-operators to return, delete or destroy Customer Data in accordance with their applicable obligations. Deletion or destruction will be performed in a manner that prevents reconstruction of Personal Information in an intelligible form. Backup copies may expire through ordinary cycles within ninety days unless POPIA, another South African law or a documented legal hold requires longer retention. Security, billing and audit records may be retained for legitimate compliance purposes.
20.4 Derived Data. Supplier may retain and continue to use Derived Data lawfully created before termination in accordance with clause 8, provided that it continues to meet the standard in clause 2.8 and is not re-identified.
20.5 Transition. The parties will reasonably cooperate on deactivation or transfer of Customer-owned channels, credentials, integrations and identifiers, subject to provider requirements and agreed transition Fees.
21. GENERAL
21.1 Force majeure. Neither party is liable for delay or failure caused by an event beyond its reasonable control, excluding payment obligations. The affected party must notify the other and use reasonable efforts to resume performance.
21.2 Affiliates and subcontractors. Supplier may perform through Affiliates, licensors, Technology Providers and other subcontractors and remains responsible for their performance to the same extent as if Supplier performed the obligation itself, subject to the limitations and dependencies in the Agreement.
21.3 Assignment. Either party may assign the Agreement to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant business or assets, on notice and provided the assignee assumes the obligations. Any other assignment requires consent, which may not be unreasonably withheld.
21.4 Relationship. The parties are independent contractors. The Agreement does not create a partnership, employment, fiduciary or agency relationship between the Customer and Supplier or between the Customer and any Affiliate, licensor, Technology Provider or Sub-operator. No such provider may bind the Customer or vary the Agreement unless expressly authorised in writing by the relevant party.
21.5 Notices. A formal notice must be in writing and sent to the notice details in the Order. Notices to Supplier must also be copied to legal@sisglobal.com. A notice of termination or legal proceedings must also be delivered by courier or registered mail. Email notice is effective when transmitted unless the sender receives a delivery-failure notification.
21.6 Electronic contracting. The parties may sign electronically and in counterparts. An electronic signature, electronic acceptance or accepted online Order has the same effect as an original to the extent permitted by Applicable Law.
21.7 Amendments. The Agreement may be amended only by a written document accepted by authorised representatives of both parties. Supplier may update Documentation and operational policies where the update does not materially reduce the Services or Customer protections during an Order Term.
21.8 Severability and waiver. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remaining provisions remain effective. A waiver must be in writing and applies only to the specific instance.
21.9 Entire agreement. The Agreement is the entire agreement on its subject matter and replaces prior proposals, representations and discussions, except for a proposal or statement of work expressly incorporated into an Order.
21.10 Dispute escalation. The parties will first attempt in good faith to resolve a dispute through designated senior representatives. If it remains unresolved after ten Business Days, either party may commence proceedings.
21.11 Governing law and jurisdiction. The Agreement is governed by South African law. The parties submit to the jurisdiction of the High Court of South Africa, Gauteng Division, Johannesburg, without preventing either party from seeking urgent interim relief from another competent court.
21.12 Survival. Provisions relating to payment, confidentiality, data protection, intellectual property, indemnities, liability, data exit, dispute resolution and any provision intended by its nature to survive will continue after termination.
END OF GENERAL TERMS - SCHEDULE 1 FOLLOWS
SCHEDULE 1 - SOUTH AFRICAN DATA PROCESSING AND SECURITY TERMS
INTEGRATED INTO EDUBOT CUSTOMER AGREEMENT V3 | JULY 2026
This Schedule applies to processing under the Protection of Personal Information Act 4 of 2013 ("POPIA"). It does not create contractual rights under the GDPR, UK GDPR or another foreign data-protection regime unless the parties sign a separate addendum.
S1.1 Scope and precedence. This Schedule forms part of the Agreement. Capitalised terms not defined here have the meanings in the General Terms or POPIA. If this Schedule conflicts with the General Terms on the processing or security of Personal Information, this Schedule prevails. The Subscription Order prevails for customer-specific hosting, retention and any express restriction on AI use of Customer Data.
S1.2 Roles. For Customer Personal Information processed to provide the Services, the Customer is the Responsible Party and Supplier is the Operator. A provider appointed by Supplier to process Personal Information on Supplier's behalf is a Sub-operator. Supplier acts as a separate Responsible Party only for limited information processed for its own contracting, billing, fraud-prevention, security, legal-compliance and claims purposes.
S1.3 Documented instructions. Supplier will process Customer Personal Information only on documented instructions contained in the Agreement, the Subscription Order, authorised configurations and integrations, instructions from an authorised Customer contact, and the Customer's use of the Services, except where South African law requires otherwise.
S1.4 Configurable processing. The Services are configurable and may process any Customer Data that the Customer lawfully submits, connects, generates or makes available through ordered functionality. Any data examples or processing profile in an Order describe the expected initial deployment and do not exhaustively limit the categories of Customer Data that may be processed through authorised configurations or integrations.
S1.5 Customer responsibilities. The Customer determines the purposes and means of its institutional processing and is responsible for the lawfulness, transparency, minimality, accuracy, retention, compatibility of further processing, authorised users, access permissions, configurations, integrations and business decisions. The Customer will identify an appropriate justification under section 11 of POPIA and provide notices required under section 18.
S1.6 Sensitive, financial and children's information. The Customer may configure the Services to process Special Personal Information, Personal Information of Children, financial, banking, payment, refund, identity, academic, employee or other sensitive information where the Customer has determined that the processing is lawful and appropriate. The Customer is responsible for any authorisation, consent, prior authorisation, notice, access restriction or additional safeguard required under POPIA. Supplier does not use Customer Personal Information for its own direct marketing.
S1.7 Processing purposes. Supplier and its approved Sub-operators may process Customer Data to provide, host, operate, secure, maintain, support and administer EduBot, including conversational engagement, knowledge retrieval, workflow execution, authentication, communications, ticketing, case handling, integrations, transaction support, analytics, reporting, agent assistance, backup, recovery, other functionality ordered or configured by the Customer, and creation of Derived Data as permitted by clause 8.
S1.8 Confidentiality and access. Supplier will limit access to personnel and Sub-operators with a need to know. Access to Customer Data within Supplier-managed infrastructure is permitted only where reasonably necessary for the purposes in S1.7, compliance with law or the Customer's documented instructions, and is subject to confidentiality, role-based access, least privilege and logging.
S1.9 Sub-operators. The Customer generally authorises Supplier to appoint Sub-operators required for cloud infrastructure, enterprise AI, communications channels, platform operation, security, monitoring and support. Supplier will impose written confidentiality, security, incident-notification, location, assistance and return-or-deletion obligations appropriate to their role. Supplier remains responsible to the Customer for their performance to the extent stated in the Agreement and required by POPIA.
S1.10 Sub-operator register and changes. Supplier will maintain a current Material Sub-operator and Data Location Register and make it available electronically or on reasonable request. The register is maintained for transparency and does not form part of the Agreement. Supplier will give reasonable advance notice of a material new Sub-operator that will process Customer Personal Information where practicable. The Customer may object on reasonable and documented POPIA grounds, and the parties will work in good faith to resolve the objection.
S1.11 Security safeguards. Supplier will implement appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of Personal Information. Supplier will identify reasonably foreseeable internal and external risks, establish and maintain safeguards, regularly verify effective implementation and update safeguards in response to new risks or deficiencies. Controls include, as appropriate to the ordered Services, logical customer separation, role-based access, privileged-access controls, multi-factor authentication, encryption in transit and at rest, secure development and change control, vulnerability management, logging and monitoring, backup and recovery, incident response, personnel controls and supplier-risk management. A control may be replaced by a materially equivalent or stronger control.
S1.12 Customer-controlled security. The Customer remains responsible for its users, credentials, devices, networks, identity provider, channel accounts, Customer-controlled integrations, data sources, configurations, access granted to its personnel and decisions made using the Services.
S1.13 Security compromises. Supplier will notify the Customer immediately after it has reasonable grounds to believe that Customer Personal Information has been accessed or acquired by an unauthorised person, and without undue delay after becoming aware of another material Security Incident. Supplier will provide available information, reasonable updates and cooperation, and root-cause and remediation information when available. The Customer is responsible for notices to the Information Regulator and Data Subjects unless POPIA requires Supplier to notify directly.
S1.14 Data Subject and regulatory assistance. Taking into account the nature of the processing and functionality available, Supplier will reasonably assist the Customer with access, correction, deletion, destruction, restriction and objection requests under POPIA, privacy and security assessments, prior-authorisation determinations and Information Regulator enquiries. Substantial assistance beyond standard functionality may be charged at agreed rates unless required because of Supplier's breach.
S1.15 Location and transborder processing. Customer Data at rest will be hosted in the primary region stated in the Order. Remote support, resilience, communications delivery, security operations and approved Sub-operator processing may occur in locations identified in the current Material Sub-operator and Data Location Register. Supplier will ensure that transfers outside South Africa satisfy section 72 of POPIA.
S1.16 Service Data and Derived Data. Supplier may use Service Data and create, retain and use Derived Data as permitted by clause 8 of the General Terms. Raw Customer Data and identifiable interactions will not be treated as Derived Data merely because obvious identifiers have been removed.
S1.17 Return, retention and deletion. During the Order Term, the Customer may use standard export functionality. After termination, the export and deletion periods in the General Terms or Order apply. Supplier will delete, destroy or de-identify production Customer Data and require relevant Sub-operators to do the same, subject to ordinary backup cycles and lawful retention. Destruction will prevent reconstruction of Personal Information in an intelligible form.
S1.18 Compliance information. Supplier will make available reasonable information necessary to demonstrate compliance with its Operator obligations, subject to confidentiality, security, legal privilege and protection of other customers. Audits will ordinarily be satisfied through certifications, independent reports, security summaries and written responses. Additional audit activity must be reasonable, proportionate and coordinated to avoid disruption.
S1.19 Liability and duration. The exclusions and limitations of liability in the General Terms apply to this Schedule. This Schedule remains effective while Supplier processes Customer Personal Information under the Agreement and survives termination only for as long as Supplier retains that information.
END OF AGREEMENT
