Terms and conditions

End User License Agreement

Restrict the license for End User’s own internal business or personal use and not for resale, distribution, sublicense or commercial use.

Include a provision acknowledging that the Licensed Products are the confidential information of TomTom and prohibiting disclosure of the Licensed Products to third parties.

Expressly prohibit unauthorized copying.

Prohibit the removal or obscuring of any copyright, trademark notice, or restrictive legend.

Include a provision whereby TomTom shall have the right to audit the Distributor, Licensee Value Added Reseller or End User.

Include a provision whereby TomTom is a third party beneficiary of Your rights under the End User License Agreement. For example: The covenants and obligations undertaken by the End User herein are intended for the direct benefit of TomTom and may be enforced by TomTom directly against the End User.

Include the following limitation of liability language:

Neither TomTom nor its suppliers shall be liable to the undersigned for any incidental, consequential, special, indirect or exemplary damages arising out of this agreement, including lost profits or costs of cover, loss of use or business interruption or the like, regardless of whether the party was advised of the possibility of such damages. Notwithstanding anything to the contrary contained herein, TomTom or its suppliers shall have no monetary liability to the undersigned for any cause (regardless of the form of action) under or relating to this agreement.

Disclaim all warranties of TomTom and its suppliers of the same scope as in this Agreement. For example:

The licensed products are provided on an “as is” and “with all faults basis” and TomTom and its suppliers expressly disclaim all warranties, express or implied, including but not limited to, the implied warranties of non-infringement, merchantability, satisfactory quality, accuracy, title and fitness for a particular purpose. No oral or written advice or information provided by TomTom or any of its agents, employees or third party providers shall create a warranty, and you are not entitled to rely on any such advice or information. This disclaimer of warranties is an essential condition of the agreement.

End User shall not use the Authorized Application to create (or assist in the creation of) a digital map database. A “digital map database” means a database of geospatial data containing the following information and attributes: (x) road geometry and street names; or (y) routing attributes that enable turn-by-turn navigation on such road geometry; or (z) latitude and longitude of individual addresses and house number ranges.

End User shall not use the Authorized Application to provide competitive information about TomTom or its products to third parties.

Licensee shall not use the Licensed Products for in-flight or drone navigation or in connection with any high risk systems, devices, products or services that are critical to the health and safety or security of people and property.

In the event that any End User is a government entity, include the following:

U.S. GOVERNMENT RIGHTS. If End User is an agency, department, or other entity of the United States Government, or funded in whole or in part by the United States Government, then use, duplication, reproduction, release, modification, disclosure or transfer of this commercial product and accompanying documentation, is restricted in accordance with the LIMITED or RESTRICTED rights as described in any applicable DFARS or FAR. In case of conflict between any of the FAR and/or DFARS that may apply to the Licensed Product, the construction that provides greater limitations on the Government’s rights shall control. Contractor/manufacturer is TomTom North America, Inc., 11 Lafayette Street, Lebanon, NH 03766-1445. Phone: 603.643.0330. The Licensed Products are © 1992-2024 by TomTom. ALL RIGHTS RESERVED. For purpose of any public disclosure provision under any federal, state or local law, it is agreed that the Licensed Products are a trade secret and a proprietary commercial product and not subject to disclosure.

U.S. Government RESTRICTED RIGHTS. The LBS Software is provided as “Commercial Computer Software” or “restricted computer software”. Use, duplication, or disclosure by the U.S. Government or U.S. Government subcontractor is subject to the restrictions set forth in 48.C.F.R. Section 12.212 or 48 C.F.R.227.2702, as applicable or successor provisions. The manufacturer is Uber Technologies, Inc., San Francisco, CA, 94103

If End User is an agency, department, or other entity of any State government, the United States Government or any other public entity or funded in whole or in part by the United States Government, then End User hereby agrees to protect the Licensed Products from public disclosure and to consider the Licensed Products exempt from any statute, law, regulation, or code, including any Sunshine Act, Public Records Act, Freedom of Information Act, or equivalent, which permits public access and/or reproduction or use of the Licensed Products. In the event that such exemption is challenged under any such laws, this agreement shall be considered breached and any and all right to retain any copies or to use of the Licensed Products shall be terminated and considered immediately null and void. Any copies of the Licensed Products held by You shall immediately be destroyed. If any court of competent jurisdiction considers this clause void and unenforceable, in whole or in part, for any reason, this agreement shall be considered terminated and null and void, in its entirety, and any and all copies of the Licensed Products shall immediately be destroyed.

Security terms

You shall utilize industry security best practices, including but not limited to any measures used and/or reasonably recommended by TomTom, to safeguard, secure and prevent piracy and unauthorized access of the Licensed Products and the Authorized Application. This shall include adequate physical perimeter and entry controls in line with local regulations and standards to ensure that only authorized personnel are allowed access.

You shall ensure that Your own environments used for functions relating to the Licensed Products and the Authorized Application are monitored in such a manner that prevents violating information and/or IT security are detected and traceable. You shall inform TomTom as soon as reasonably possible of any potential security incidents relating to the Licensed Products and the Authorized Application of which You become aware.

You shall not disclose any TomTom information which may be considered as business or trade secrets, except to the extent necessary for the performance of its assignment under the Agreement.

You shall use suitable encryption techniques for protection of the information of TomTom. Where encryption cannot be implemented, appropriate compensating controls must be implemented to reduce the risk of unauthorized disclosure.

You shall implement policies and processes to identify and remediate vulnerabilities in a timely manner in its own environments used for functions relating to the Licensed Products and the Authorized Application. Vulnerability management includes both infrastructure and applications. At a minimum, You shall scan infrastructure and applications for security vulnerabilities every 90 days.

Data Processing Schedule

This data processing schedule (“Schedule”) is between the customer entity (“Licensee”) and the TomTom entity and its Affiliates (“TomTom”) which are a parties to the agreement for use of TomTom’s maps, software, live services, traffic stats and online services (“Agreement”) under which TomTom performs certain services. The parties agree that the Schedule supplements the Agreement and applies to the products supplied and services performed by TomTom (together for the purposes of this Schedule the (“Services”), as defined in the Agreement to the extent that the same involve the processing by TomTom of Personal Data on behalf of Licensee.

Definitions

Terms defined in the Agreement between Licensee and TomTom shall have the same meaning when used in this Schedule. In addition, the definitions below apply in this Schedule:

Unless otherwise specified, all references to the GDPR shall be understood to be references to the applicable local equivalent which implements said reference into local law.

Subject and term

The purpose of this Schedule is to describe the work to be carried out by TomTom in relation with the Agreement. This Schedule forms an integral part of the Agreement. This Schedule shall be deemed to take effect from the Effective Date of the Agreement and shall continue in full force and effect until the termination of the Agreement.

Scope of the work

The purpose for the collection, processing and use of the Personal Data on behalf of Licensee is to provide the products and services as described in the Agreement, which forms an integral part hereof. Licensee warrants that it has all necessary rights to provide the Personal Data to TomTom for the processing to be performed in relation to the products and services, and that one or more lawful bases set forth in the GDPR support the lawfulness of the processing. To the extent required by GDPR or any other applicable privacy regulations, Licensee is responsible for ensuring that all necessary privacy notices are provided to data subjects, and unless another legal basis set forth in the GDPR supports the lawfulness of the processing, that any necessary data subject consents to the processing are obtained, and for ensuring that a record of such consents is maintained.

The processing of the Personal Data by TomTom shall take place within the framework of i) the Agreement and ii) this Schedule and only to the extent that Licensee has instructed TomTom in writing to do so in relation with the Agreement. Such instructions shall be deemed to be provided by Licensee’s use of the Services as is further described under the particular Services documentation (the “Documentation”) (such as, for example, by making an API call to the TomTom servers running the Services). In the event TomTom modifies the Documentation, continued use by Licensee of the Services shall be deemed to constitute acceptance by Licensee of the change in the manner under which TomTom processes the Personal Data and a revised instruction from Licensee accordingly.

TomTom processes the Personal Data on behalf of Licensee. If applicable law requires TomTom to process Personal Data other than in accordance with Licensee’s instructions, TomTom shall notify Licensee of such processing unless prohibited from doing so by applicable law. TomTom shall not use the Personal Data for any other purpose as required under the Agreement or this Schedule. However, and in addition to usage already agreed in the Agreement, Licensee is aware of and explicitly authorizes TomTom to use aggregated, de-identified and/or anonymized Personal Data (“Aggregated Data”), from time to time, for analytics, improvement of products and services and internal purposes, provided that the Aggregated Data shall not be used to directly or indirectly identify any of the Licensee’s customers, except for the Licensee’s explicit instructions to perform such identification.

Licensee has defined that the following data categories will be processed by TomTom under this Schedule.

Data categories

Technical and organizational measures

TomTom shall implement and maintain appropriate security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing. Such measures ensure a level of security appropriate to the risks presented by the processing and the nature of the Personal Data to be protected taking into account the state of the art and the cost of their implementation.

TomTom ensures in particular that it has implemented the appropriate measures to:
a. Prevent unauthorized persons from gaining access to data processing systems with which personal data are processes or used;
b. Prevent data processing systems from being used without authorization;
c. Ensure that persons entitled to use a data processing system have access only to the Personal Data to which they have a right of access, and that personal data cannot be read, copied, modified or removed without authorization during processing or use and after storage;
d. Ensure that personal data cannot be read, copied, modified or removed without authorization during electronic transmission or transport, and that it is impossible to check and establish to which bodies the transfer of personal data by means of data transmission facilities is envisaged;
e. Ensure that it is possible to check and establish whether and by whom personal data has been input into data processing systems, modified or removed;
f. Ensure that, for commissioned processing of personal data, the Personal Data is processed strictly in accordance with the instructions of the Licensee (job control).

TomTom shall further ensure that the processing of the Personal Data has been and will continue to be carried out in accordance with the relevant provisions of the applicable data protection law and does not violate the relevant provisions.

TomTom’s obligations

Under this Schedule, TomTom has the obligation to

a. Process the Personal Data only on behalf of Licensee and in compliance with its instructions;
b. Ensure that only appropriately trained personnel shall have access to the Personal Data;
c. Provide Licensee with such cooperation (including access to its facilities) as Licensee may reasonably request, subject to Licensee’s Rights and Obligations provision;
d. Implement such technical and organizational measures to protect the Personal Data as required by the GDPR;
e. Notify Licensee as soon as reasonably possible of monitoring activities and measures in relation to the relevant processing, undertaken by the relevant authority that supervises the applicable data protection legislation;
f. Support Licensee regarding Licensee‘s obligations to provide information about the collection, processing or usage of Personal Data to a data subject;
g. Ensure that the Personal Data is not in any way used, manipulated, distributed, copied or processed for any other purpose than for the fulfilment of the contractual obligations as explicitly agreed upon

Sub-processing

Licensee authorizes TomTom to appoint sub-processors to process Personal Data in accordance with this Clause. TomTom shall conclude written agreements with sub-processors to protect Personal Data subject to conditions that are materially similar to the standards set forth in this Schedule. Where the sub-processor fails to fulfil its data protection obligations under such written agreement, TomTom shall remain fully liable to Licensee for the performance of the sub-processor's obligations under such agreement

When sub-processors located outside the European Economic Area are involved, parties hereby mutually agree that TomTom shall act as the data exporter and shall consequently in accordance with the applicable laws engage in Standard Contractual Clauses (EU Commission Decision 2021/94/EU adopted on 4 June 2021) with the relevant sub-processors, unless a sub-processor is able to benefit from an adequacy decision pursuant to Article 45 GDPR that covers the transfer to the respective country of such sub-processor.

To the extent that Parties are relying in a specific statutory mechanism to normalize international data transfers and that mechanism is subsequently modified, revoked, or held in a court of competent jurisdiction to be invalid, the Parties agree to cooperate in good faith to promptly suspend the transfer or to pursue a suitable alternate mechanism that can lawfully support the transfer.

TomTom may continue to use those sub-processors already engaged as of the Effective Date of the Agreement, including Amazon Web Services, Microsoft Azure, and Grafana (EU data center locations). It is acknowledged and agreed that as of the Effective Date of the Agreement TomTom may provide necessary data access to operations staff employed by TomTom’s global affiliates or service partners contracted by TomTom.

TomTom shall inform Licensee of the appointment of any new sub-processor and Licensee shall have the right to reasonably oppose the appointment of a new sub-processor if Licensee shall have substantive and legitimate reasons for opposing the specific sub-processor. Licensee shall notify TomTom of such objections in writing within thirty (30) days after receipt of TomTom’s notice relating to such sub-processor. If Licensee provides written notice of objection, Parties shall discuss the objection in good faith to resolve it. The addition or removal of a sub-processor should not negatively affect the level of security within the agreement to less than that which existed.

Licensee’s Rights And Obligations

Rights to monitor: on an annual basis, Licensee is entitled to appoint a third party independent auditor in the possession of the required professional qualifications and bound by a duty of confidentiality, which auditor must be reasonably acceptable to TomTom, to access data records as reasonably required to audit TomTom’s compliance with this Schedule and the applicable data protection legislation to determine the truthfulness and completeness of the statements submitted by TomTom under this Schedule. Licensee’s right to audit shall be subject to giving TomTom at least thirty (30) days prior written notice and Licensee shall bear all costs related to such audit. The audit shall not disrupt the business operations of TomTom

TomTom shall deal properly with all inquiries from Licensee and shall grant reasonably access to its data records relating to the processing of the Personal Data subject to this Schedule. TomTom shall not be required to provide access to records or systems related to the delivery of products and services of customers other than Licensee. Rectification, deletion and blocking of data: upon instruction by Licensee, TomTom shall correct, rectify or block the Personal Data. Any request from a data subject directly received by TomTom shall be directed to Licensee.

Information Obligations

If TomTom does not comply or foresees that it shall not comply with its obligations as set out in this Schedule, for whatever reasons, it agrees to as soon as reasonably possible inform Licensee of its inability to comply, in which case Licensee is entitled to suspend the transfer of the Personal Data.

TomTom will as soon as reasonably possible notify Licensee about:

1. Any legally binding request for disclosure of the Personal Data by a law enforcement authority unless otherwise prohibited, such as a prohibition under criminal law to preserve the confidentiality of a law enforcement investigation;
2. Any request received directly from the data subject without responding to that request, unless it has been otherwise authorized to do so; and
3. Any unauthorized acquisition, access, use, disclosure or destruction of the Personal Data constituting a personal data breach as defined in the GDPR. Such notification shall take place without undue delay, and no later than seventy-two (72) hours after TomTom has become aware with a reasonable degree of certainty of such personal data breach. TomTom shall use reasonable efforts to report the following information:

a. a description of the personal data breach, including the date and time the breach was discovered;
b. an overview of the Personal Data that was (potentially) lost or unlawfully processed as a result of the personal data breach;
c. information on the likely consequences of the personal data breach; and
d. a description of the measures taken by TomTom to limit the consequences of the personal data breach.

Assignment

Neither Party shall without the prior written consent of the other Party assign or transfer this Schedule or the benefit or burden of or the rights under this Schedule save that TomTom shall be entitled to assign or transfer this Schedule (whether in whole or in part) without the prior consent of Licensee, but with prior written notice to Licensee: (i) to an affiliate of TomTom; or (ii) to an acquirer of all or substantially all of its assets, business or equity securities.

Term and termination

This Schedule shall continue in full force and effect until the Agreement expires or terminates or so long as TomTom possesses or is processing Personal Data, including backups, on behalf of Licensee beyond that date, whichever is later.

The Parties agree that after the termination of the provision of the products and services, TomTom and the sub-processor shall, at the choice of Licensee, return all the Personal Data transferred including any data storage media supplied to TomTom, and the copies thereof to Licensee or shall destroy all the Personal Data and certify to Licensee that it has done so, unless a contractual obligation or legislation imposed upon TomTom prevent it from returning or destroying all or part of the Personal Data transferred. In that case, TomTom warrants the confidentiality of the personal data transferred.

Confidentiality

Any information of whatever kind (whether technical, commercial, financial, operational or otherwise) and in whatever form (whether oral, written, recorded or otherwise), including Personal Data, data relating to Licensee’s customers database, procedures and knowledge, which may be disclosed in any form or matter by one Party to the other Party, with respect to, or as a result of this Schedule, shall be deemed to be of a confidential nature and shall be treated in accordance with the confidentiality terms as set out in the Agreement.