# Overview

## What is TF Platform?

TF Platform (The Future Platform) is a white-label Communications & Identity platform for developers. Its control plane allows organizations to create and manage tenants, configure identity and access policies, and operate secure communication services. TF Platform is fully API-driven and modular, enabling organizations to deploy and brand their own services with complete flexibility.

***

### Identity & Access

* **Authentication Engine** – authentication services.
* **Authorization Engine** – access control and policy enforcement.
* **Accounting Engine** – event logging and accountability.
* **Human Identity Hub** – human identity management.
* **Machine Identity Hub** – machine and service identity management.
* **Identity Self-Service Portal** – subscriber-facing portal.

***

### Security & Privacy&#x20;

* **Consent & Privacy Hub** – consent and privacy controls.
* **Audit Hub** – auditing of platform events.

***

### Integration & Communication&#x20;

* **Communication Engine** – messaging and communication services.
* **Integration Hub** – connectors and system integrations.


# Data regions

## Data residency

When you create a tenant, you must select a geographic location for data residency. This determines where your data is processed and stored, ensuring compliance and performance.\
\
We currently support two data regions:

* **European Economic Area (EEA) – Netherlands**
  * Deployed on Microsoft Azure
* **India – Mumbai**
  * Deployed on Google Cloud Platform (GCP)

{% hint style="info" %}
**Compliance Note:** Consult legal experts to ensure compliance with applicable regulations.
{% endhint %}

***

### Failover Support

* **Intra-Regional Failover** – supported within each data region to ensure reliability and resilience, while keeping data inside the selected region.
* **Cross-Regional Failover** – not supported. Data always remains within the selected region.

***

### Support

For questions about data storage, contact us at <support@simptel.com> or review our privacy policy.


# Administration


# Organizations

With TF Platform, you can manage Organizations that serve as **top-level** entities, allowing the creation and management of multiple projects. You can easily register an organization using your TF Platform account.\
\ <br>

<details>

<summary>Steps to Join an Organization</summary>

1. **Receive an Invitation**\
   An invitation to join an organization will be sent to you by the organization owner.<br>
2. **Ensure You're Signed In**\
   Log in to your TF Platform account.<br>
3. **Access the Invitation**\
   Click on the invitation link provided in your email or notification.<br>
4. **Review Organization Details**\
   Check the organization name and details to ensure it’s the correct organization you wish to join.<br>
5. **Accept the Invitation**\
   Follow any prompts to confirm your membership in the organization.
6. **Receive Confirmation**\
   Once your membership is confirmed, you will receive a notification that you’ve successfully joined the organization.

</details>

<details>

<summary>Steps to register an Organization</summary>

1. Log in to your TF Platform account.
2. Select **Organizations** from the menu
3. **Register Your Organization**

* Select **Organizations** from the menu.
* Click **Register Organization** and fill in the following details:
  * **Organization Name**
  * **Registration Number**
  * **Country & Address**
* Click **Register**.\
  After this step, your organization will be registered in the system.<br>

</details>

{% hint style="info" %}
Users can be members of multiple organizations if invited by the admin of other organizations. However, you can only register and own one organization for your TF Platform account.&#x20;
{% endhint %}


# Settings


# Delete organization

This article describes how to delete an organization in TF Platform.

Deleting an organization from the TF Platform **permanently removes** it, including all associated data such as projects, users, and settings. While this action is irreversible, you can recover the organization within 30 days.&#x20;

> **Key Considerations**
>
> * Organizations can be recovered within 30 days post-deletion. After this timeframe, all data will be permanently lost.
> * Ensure you have the necessary administrative permissions to perform this action.
> * It is advisable to notify all organization members before deletion to ensure they are aware of the impending changes.
> * A confirmation prompt will appear to verify the deletion request and ensure that the action is intentional.

<details>

<summary>Steps to Delete an Organization</summary>

1. Log in to your TF Platform account.
2. Navigate to **Organizations** from the main menu.
3. Find the organization you wish to delete.
4. Click on the organization name to access its settings.
5. Look for the **Delete** option within the organization settings.
6. A confirmation prompt will appear. Review the warning and confirm that you want to delete the organization.
7. Once confirmed, the organization will be marked for deletion, and you will have 30 days to recover it if needed.

</details>

####


# Modify organization

This article describes how to modify an organization in TF Platform.

#### Steps to Modify Your Organization:

1. **Sign In**\
   Log in to your TF Platform account.<br>
2. **Access Organizations**\
   Select **Organizations** from the menu.<br>
3. **Locate Your Organization**
   * Find the organization you want to modify.
   * Click on the organization name to access its settings.<br>
4. **Edit Organization Details**\
   Modify the necessary details such as:
   * **Organization Name**
   * **Registration Number**
   * **Country & Address**<br>
5. **eKYC Re-verification**\
   Note that changes may require a new eKYC process to verify the updated information.\
   Complete the eKYC to ensure compliance and security.<br>
6. **Save Changes**\
   After updating the details and completing eKYC, ensure you save the changes.

{% hint style="info" %}
**Note**: The **Registration Number** cannot be changed. You must register a new organization if you need a different registration number.
{% endhint %}


# Projects

Organizations can use projects to group access based on teams, use cases, or environments (like development, staging, and production). Each organization starts with one project and can create up to ten projects. Projects within the same organization can share billing accounts.

> Here are the essential characteristics of projects within TF Platform:
>
> * TF Platform service quotas remain at the organization level, and are not enforced per project.
> * An organization can have up to 10 projects.
> * All tenants under the project must be deleted first to delete a project.&#x20;


# Create project

This article provides instructions for creating a project in the TF Platform.

{% hint style="info" %}
**Note:** Only users with organization admin or owner roles can create new projects. If an organization admin creates a project, they automatically become the admin of that project.
{% endhint %}

#### Steps to Create a Project:

1. **Sign In**\
   Log into the TF Platform Portal and choose your organization.<br>
2. **Access Projects**\
   Navigate to **Projects** from the sidebar.<br>
3. **Create a New Project**\
   Click on the "Create a Project" option.<br>
4. **Enter Project Details**\
   Fill in the project display name and description.<br>
5. **Confirm Creation**\
   Click **+ Create project.**


# Modify project

This article describes how to modify a project in TF Platform.

{% hint style="info" %}
**Note:** Only users with the project admin role can edit or delete projects. Refer to the User Permissions for role information.
{% endhint %}

#### Steps to Modify a Project:

1. **Sign In**\
   Log into the TF Platform Portal and choose your organization.<br>
2. **Access Projects** \
   Navigate to Projects from the sidebar.<br>
3. **Locate and Modify**
   * Select **View Project** to access project settings and find the project ID.
   * Expand the menu next to the project and choose:
     * **Edit the project** to modify the project name or description.
     * **Delete** to remove the project.


# Delete project

This article provides instructions for deleting a project in the TF Platform.

{% hint style="warning" %}
Deleting a project from the TF Platform **permanently removes it**, including all associated data such as users and settings. While this action is mostly irreversible, you can recover the project within 30 days.
{% endhint %}

> **Key Considerations**
>
> * All tenants under the project must be deleted first to delete a project.&#x20;
> * Projects can be recovered within 30 days post-deletion. After this timeframe, all data will be permanently lost.
> * Ensure you have the necessary administrative permissions to perform this action.
>
>   It is advisable to notify all project members before deletion to ensure they are aware of the impending changes.
> * A confirmation prompt will appear to verify the deletion request and ensure that the action is intentional.

#### Steps to Delete a Project:

1. **Sign In**\
   Log into the TF Platform Portal and choose your organization.<br>
2. **Access Projects** \
   Navigate to Projects from the sidebar.<br>
3. **Locate Your Project**
   * Select **View Project** to access project settings and find the project ID.
   * Expand the menu next to the project.<br>
4. **Select Delete Option**\
   Look for the **Delete** option within the project settings.<br>
5. **Confirm Deletion**\
   A confirmation prompt will appear. Review the warning and confirm that you want to delete the project.<br>
6. **Final Confirmation**\
   Once confirmed, the project will be marked for deletion, and you will have 30 days to recover it if needed.


# Tenants

This article provides an overview about the concept of Tenants.

### **What is a Tenant?**

A **tenant** on TF Platform is a logically isolated environment where you can manage your own data, applications, resources, and configurations.

{% hint style="info" %}
Each project can have up to 10 tenants.
{% endhint %}

***

### How Are Tenants Identified?

Each tenant has its own domain. When end-users make requests to a configured domain, the platform routes them to the correct tenant environment. This setup ensures secure and independent operations for each tenant. For more information see [Configure custom domain](/tf-platform/administration/organizations/projects/tenants/domains/configure-custom-domain).

**Examples:**

* **Default Domain:** \[subdomain].tfplatform.com
* **Custom Domain:** yourdomain.com


# Create Tenant

Steps to create a tenant

**Create a new tenant**

1. Log into the TF Platform Portal and choose your organization.
2. Select **Projects** in the sidebar and select a project.
3. Click **+ Create tenant**.
4. Enter the Tenant Display name and description.
5. Click **+ Create tenant**.

{% hint style="info" %}
**Note:** Only users with organization admin or owner roles can create new projects. If an organization admin creates a project, they automatically become the admin of that project.
{% endhint %}


# Remove Tenant


# CORS

This article describes an overview of Cross-Origin Resource Sharing within the platform

### What is CORS? <a href="#seo-faq-pairs-what-is-cross-origin-resource-sharing" id="seo-faq-pairs-what-is-cross-origin-resource-sharing"></a>

Cross-Origin Resource Sharing (CORS) is a mechanism that allows web applications to make requests to resources hosted on different domains.&#x20;

The platform lets you configure CORS at the tenant level, enabling precise control over cross-origin access for improved security and flexibility.

### Best Practices

* Regularly review and update your CORS settings to align with security requirements.
* Always use HTTPS in production for secure communication.
* Avoid using the wildcard `*` in production; explicitly specify allowed origins.


# Modifying Allowed Origins

This article provides an overview of modifying cors

**Configuring CORS**

1. **Go to Projects**: Access the "Projects" section within the platform.
2. **Select the Tenant**: Choose the tenant you wish to configure.
3. **Access CORS Settings**: Navigate to the CORS settings in the tenant's "Domains" section.
4. **Allowed Origins**: Specify up to 10 origins allowed to make cross-origin requests.

**Configuration Examples:**

* **Subdomain Wildcard**: `https://*.example.com`
* **Environments**:
  * Production: `https://myapp.com`
  * Local Development: `http://localhost:4200`

{% hint style="info" %}
*Using `*` as a wildcard is not recommended in production environments for security reasons.*
{% endhint %}


# Services


# Enabling/disabling services


# Domains

This article provides instructions for supported custom domains in the TF Platform.

By default, your tenant will be assigned a platform subdomain (`[subdomain].tfplatform.com`).

However, we recommend setting up your own domain for an improved user experience. A custom domain can enhance your brand identity, build trust, and provide a more personalized experience for your end users.\ <br>

### Choose a subdomain

Here are some examples of domains you can set in the Platform.

| Domain type      | Example                                                                                                          | Supported?                                     |
| ---------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------- |
| Apex domain      | `example.com`                                                                                                    | Only if DNS provider supports CNAME flattening |
| `www` subdomain  | `www.example.com`                                                                                                | ✅                                              |
| Custom subdomain | <p><code>platform.example.com</code></p><p><code>portal.example.com</code> <code>anything.example.com</code></p> | ✅                                              |


# Configure custom domain

This article provides instructions for configuring a custom domain in the TF Platform.

### Steps to Configure a Custom Domain

#### 1. Inside the platform

* Navigate to **Add New Domain**.
* In the dialog, enter the domain name.
* And select your ACME Provider: Lets Encrypt or ZeroSSL
* Click **Save** to generate the required CNAME record for DNS setup.

#### 2. Outside the platform

* Log in to your DNS provider’s management console.
* Add the generated CNAME record to your DNS zone.
* Ensure the TXT value has the ACME generated value with right config.
* Ensure the CNAME value points to the target **subdomain.tfplatform.com**.
* Save the updated DNS configuration.

#### 3. Domain Verification

* Return to the **Domains** page.
* Click **Verify** to confirm the DNS changes.
* When the domain is verified, a success message will indicate this. The status will update to “Verified” under the Domain tab.

{% hint style="info" %}
*The verification process can take up to 5 minutes, and DNS changes may take up to 24 hours to fully propagate.*
{% endhint %}

***

### DNS Configuration Tips and Troubleshooting

**DNS Configuration Tips**

* Ensure the CNAME or A record is accurately entered in your DNS settings.
* Confirm that the domain points to the generated CNAME provided by the TF Platform.

**Verification Issues**

If verification fails, the platform will provide troubleshooting steps. Common issues include:

* **Propagation Delays**: DNS changes may take time to propagate. Wait up to 5 minutes for verification and 48 hours for full propagation before retrying.
* **Incorrect DNS Settings**: Double-check that the records were entered correctly.

For persistent issues, consult your DNS provider’s documentation or our support team for further assistance. Following these steps will help ensure the successful configuration of your custom domain.


# Remove custom domain

This article provides instructions for removing a custom domain in the TF Platform.

#### Removing a Custom Domain

**Step 1: Remove the Domain**

* Select the custom domain you wish to remove.
* Click **Delete**. A confirmation dialog will appear.

**Step 2: Confirm Deletion**

* Review the warning, fill in the confirmation prompt, then click **Delete** again to confirm and finalize the removal.

**Step 3: Update DNS Records**

* Access your DNS provider's console after the domain is removed from the platform.
* Remove or unpoint the CNAME record linked to the deleted domain.

{% hint style="warning" %}
Removing a custom domain will disrupt all associated services and features, rendering them inaccessible. Ensure you are prepared for this impact before proceeding with deletion.
{% endhint %}


# Certificates

This article provides an overview of the options for managing SSL Certificates for your domains.

When configuring a custom domain, **Automatic Certificate Management** is enabled by default. You can also opt for **Self-Managed Certificates.** If you disable the active self-managed certificate, the system will automatically revert to Automatic Certificate Management to maintain security.

***

### Automatic Certificate Management

By default, SSL/TLS certificates are automatically issued, renewed, and deployed. This guarantees that your domains remain secure without any manual effort.&#x20;

***

### Self-Managed Certificates

Self-managed certificates are suitable for:

* **Origin Servers**: Configuring SSL/TLS for secure communication between our service and your DNS provider.
* **Custom Certificates**: Providing your own certificates to meet specific requirements.

{% hint style="info" %}
You are responsible for obtaining and renewing certificates from your chosen Certificate Authority (CA) and configuring your DNS provider accordingly.
{% endhint %}


# Renewing Self-Managed Certificates

#### Steps to Renew a Self-Managed Certificate

1. **Monitor Expiration Date**
   * Regularly check the expiration date of your certificate in the **Certificates** section.
2. **Obtain a New Certificate**
   * Before the expiration date, request a new SSL certificate from your Certificate Authority (CA).
3. **Upload the New Certificate**
   * Follow the steps above to upload the new SSL certificate and private key.
4. **Verify and Save**
   * Ensure the new certificate is valid, then click **Save** to apply the changes.
5. **Confirm Successful Update**
   * Review the **Certificates** section to verify that the new certificate is active and that the expiration date has been updated.


# Configure Self-Managed Certificates

This article provides an overview of how to manage, upload, and renew SSL/TLS self-managed certificates.

#### Steps to Add a Self-Managed Certificate

1. **Access the Certificates Section**
   * Navigate to the **Domains** page.
   * Locate and select the **Certificates** section.
2. **Upload the Certificate**
   * Click on the **Upload Certificate** option.
3. **Input Certificate and Key**
   * **Enter SSL Certificate and Private Key**:
     * Ensure your SSL certificate file is in PEM format (typically a `.crt` or `.pem` file).
     * Ensure your private key file is in PEM format (usually a `.key` file).
   * **Copy and Paste Contents**:
     * Copy the contents of your SSL certificate and paste them into the **Certificate** field.
     * Copy the contents of your private key and paste them into the **Private Key** field.
4. **Save the Certificate**
   * Click the **Save** button to upload the certificate
5. **Review Certificate details**
   * **Common Name**: A name for easy identification.
   * **Issuer**: The organization that issued the certificate.
   * **Valid From**: The start date of the certificate's validity.
   * **Valid to**: The certificate's expiration date.
   * **Covered Domains**: Domains secured by the certificate.
   * **Thumbprint**: A unique identifier for quick reference.
6. **Activate the Certificate**
   * After saving, ensure the certificate is activated by clicking the **Activate** button (if applicable) in the Certificates section. This step is essential for enabling secure connections using the newly uploaded certificate.

{% hint style="info" %}
Each tenant is limited to **5 certificates**.
{% endhint %}


# TLS/SSL Support

This article provides an overview of supported TLS/SSL certificates.

When setting up a reverse proxy with self-managed certificates to connect to the TF Platform, it's crucial to ensure that you use a supported TLS version and cipher suite. The TLS handshake, which is the communication between the server and client, specifies the TLS version and cipher suite. Using an unsupported version could lead to failure.

### Supported TLS 1.3 Cipher Suites

* TLS\_AES\_128\_GCM\_SHA256
* TLS\_AES\_256\_GCM\_SHA384
* TLS\_CHACHA20\_POLY1305\_SHA256

{% hint style="info" %}
To learn more, read [Transport Layer Security (TLS) Parameters](https://www.iana.org/assignments/tls-parameters) for the Internet Assigned Numbers Authority (IANA) list of registered parameters, including ciphers.
{% endhint %}


# Reverse Proxies


# Cloudflare as Reverse Proxy

This article provides a steps to configure Cloudflare as a reverse proxy for your application.

#### Steps to Configure Cloudflare

1. **Sign Up for Cloudflare**
   * **Create a Cloudflare Account**: If you don’t already have an account, sign up on Cloudflare's website.
   * **Add Your Domain**: Follow the prompts to add your domain to your account.
2. **Update DNS Settings**
   * **Verify Domain Ownership**: Follow the instructions to verify ownership, typically by adding a TXT record at your domain registrar.
   * **Change DNS Records**:
     * Go to the **DNS** tab in your Cloudflare dashboard.
     * Add or modify DNS records to point to your origin server using the following settings:
       * **Type**: A or CNAME
       * **Name**: Your subdomain (e.g., platform or www)
       * **Value**: Your origin server’s IP address or hostname
       * **Proxy Status**: Set to **Proxied** (indicated by the orange cloud icon).
3. **Configure SSL/TLS Settings**
   * **Set SSL/TLS Mode**: Navigate to the **SSL/TLS** tab and choose an appropriate mode (e.g., Full or Full (strict)). If you have added the origin server certificate as a custom certificate in the platform, use **Full (strict)**.
   * **Enable Always Use HTTPS**: Turn on the **Always Use HTTPS** option to ensure secure connections.
4. **Test Your Setup**
   * **Access Your Tenant**: Ensure your tenant is accessible through the Cloudflare proxy. Verify that SSL/TLS functionality works and that requests are routing correctly to your origin server.


# Access

You can grant TF Platform users access to TF Platform organizations. \
\
\
Assign [user roles](https://www.mongodb.com/docs/atlas/reference/user-roles/#std-label-user-roles) to enforce permission levels for Atlas users.

<br>


# Users

The users to which the organization will provide access through Public OAuth2 Clients.&#x20;


# Applications

The applications that the organization will provide access to through OAuth2 Clients.&#x20;


# Roles

The roles will be a mapping between the APIs of the organization, projects, billing, tenants, services & the permission required in sets.&#x20;

Financial Reporter\
\- Billing Read


# Groups


# Event Feed

The Platform Organization Event Feed displays select events for a given TF Platform organization, such as billing or organization events.

\
**Categories**

* Organization
* Projects
* Billing&#x20;
* Tenants
* Domains


# Billing

This article provides an overview of topics and tasks related to managing your TF Platform Billing accounts.

We provide subscriptions through the **Microsoft Azure Marketplace** and **Google Cloud Marketplace**.\
Our model combines **metered billing** with subscription commitments, ensuring flexibility and predictable coverage.

***

### Billing Models

#### 1. Metered Billing

* Pay for actual usage (e.g., Monthly Active Users, token operations, data transfer, storage).
* Consumption is tracked per project and invoiced through your marketplace account.

#### 2. Fixed Subscriptions

* Choose **monthly** or **annual** subscriptions.
* Pricing includes **service-level agreements (SLAs)** for guaranteed performance and support.
* Annual subscriptions are discounted compared to monthly.

***

### Key Notes

* Subscriptions include already purchased usage and SLA terms.
* All invoicing and payments are handled through your chosen marketplace (Azure or Google).

***

### Next Steps

For detailed pricing, plan comparisons, or to activate a subscription, please contact our **Sales team**.


# Create a new billing account

### Steps to Create a Prepaid Billing Account

1. **Sign In:**\
   Log in to your account with your credentials.
2. **Select Organization:**\
   Choose the appropriate organization from the list if you belong to multiple.
3. **Access Billing Settings:**\
   Navigate to the settings menu and select **Billing Accounts** under **Billing**.
4. **Choose Self-service (Prepaid):**\
   Select the **Self-service (Prepaid)** option, which is the default.
5. **Link Payment Method via Stripe:**\
   Add a payment method through Stripe by following the on-screen prompts.
6. **Provide Account Details:**\
   Fill in any additional required information, such as your billing address.
7. **Enable Auto Top-up (Optional):**\
   Set up auto top-up by choosing a threshold balance and payment method for automatic replenishment.
8. **Review Your Information:**\
   Check that all provided information is accurate.
9. **Submit Your Request:**\
   Click the **Create Account** button to finalize your prepaid billing account setup.
10. **Check for Confirmation:**\
    Look for a confirmation message or email verifying successful account creation.

{% hint style="danger" %}
Ensure that your payment method is valid and has sufficient funds to avoid any interruptions in service once your account is active. If interruptions do occur, you will have **30 days** to recover your account and restore access to your services. If you encounter any issues during the setup process, please **contact support** for assistance.
{% endhint %}


# Disable a Billing account

This article provides an overview to disable a billing account.

### Steps to Disable a Billing Account

1. **Sign In to Your Account:**\
   Log in to your account on the TF Platform.
2. **Select Your Organization:**\
   If you belong to multiple organizations, choose the appropriate organization from the list.
3. **Navigate to Billing Settings:**\
   Go to the settings menu and select **Billing Accounts** under the **Billing** section.
4. **Select Your Billing Account:**\
   Choose the billing account you wish to disable.
5. **Initiate Closure:**\
   Look for the option to **Disable Billing Account** and follow the on-screen prompts.
6. **Confirm Closure:**\
   Review the consequences of closing your account and confirm your decision.
7. **Check for Confirmation:**\
   Ensure you receive a confirmation message or email verifying that your billing account has been successfully closed.

{% hint style="danger" %}
If you disable your active billing account, all services for linked projects will stop, and your data will be retained for **30 days**. After this period, the data cannot be recovered.
{% endhint %}

<br>


# Delete a billing account

TF Platform Billing accounts cannot be deleted. When you close your TF Platform Billing account, the account information is retained for reporting and auditing purposes.

To prevent your TF Platform Billing account from accruing charges, you can either:

* **Disable the TF Platform account.**
* **Unlink the billing account from associated projects.**

If you need to change the payment method linked to your TF Platform Billing account, you can manage your payment options in the **Billing Accounts** section.


# Alerts


# Integrations

Connections of third-party applications  with TF Platform, which are templated or already pre- developed.


# ITSM Ticketing integration

TF Platform allows your ITSM system, such as **ServiceNow or similar alternatives**, to call our APIs to register support tickets directly. This enables your organization to manage incidents and requests within your existing ITSM workflows while keeping records synchronized in both systems.


# SIEM Integration

Coming soon

You can integrate TF Platform with SIEM tools such as **Microsoft Sentinel, Datadog, Splunk, QRadar, and LogRhythm** to monitor security events in real time for your organization’s console access.

***

### How It Works

1. Connect TF Platform to your SIEM using APIs or custom integrations.
2. Stream events and logs into your SIEM.
3. The SIEM analyzes events for threats and anomalies.
4. Alerts and reports are generated for monitoring and compliance.

{% hint style="info" %}
Tenant-level logs must be configured separately for each tenant.
{% endhint %}


# Access Provisioning and SSO

##

TF Platform supports a **SCIM interface** for provisioning from IGA tools such as **SailPoint, Microsoft Entra, or Okta**. This enables centralized management of your organization’s console access.

SCIM provisioning can be combined with **Single Sign-On (SSO)**:

* **SSO** – enabled with Just-in-Time (JIT) provisioning by default.
* **SCIM + SSO** – allows pre-provisioning of users and assignment of roles in the console before first login.


# Support

We provide two types of support:&#x20;

### **Project-Based Support**

* **Implementation Support** – Greenfield deployments, migrations from existing systems, and hybrid setups.
* **Migration Support** – Data transfers, integrations, or platform consolidation, including planning, execution, and validation.
* **Improvement Support** – System enhancements such as architecture optimizations, new integrations, feature enablement, and performance tuning.
* **Decommissioning Support** – Offboarding activities including secure data export, data cleanup, account closure, and migrations to other systems.

{% hint style="info" %}
**Project-Based Support is delivered under Professional Services agreements.**
{% endhint %}

### **Business-as-Usual Support**

* **Operational Support** – Ongoing assistance with platform use, including issue reporting, troubleshooting, under attack, and service requests via the available support channels.

{% hint style="info" %}
**Business-as-Usual (BAU) Support is included in your subscription plan and governed by service level agreements (SLAs).**
{% endhint %}


# Project-Based Support


# Implementation Support

### Implementation Help

Need help with implementing the TF Platform? Our team of experts is available to assist you. Simply email <support@simptel.com> with the subject line "TF Platform Implementation Help." Please include details about your implementation challenges, and we'll provide guidance, best practices, and solutions to address your technical needs.


# Migration Support


# Decommissioning Support


# Operational Support

Depending on your support plan, you can reach us via phone, email, or in-platform ticketing. All requests are logged in our ITSM system for full traceability. We apply service level commitments to ensure timely response, prioritization, and resolution of incidents and requests.\
\ <br>


# Rate Limiting Policy

This article provides an overview of the rate limiting policies within the platform to show how many requests a tenant can sustain.

## How Rate Limiting Works

Each tenant is limited to **600 API requests per minute** on all **public-facing APIs**. This limit maintains fair usage and system stability. Rate limits apply **globally across all public APIs per tenant**. If the limit is exceeded, the API responds with **HTTP 429 – Too Many Requests**.

***

### Event Log Example

Rate limit details are recorded in the event log:

```json
{
  "x-ratelimit": 600,
  "x-ratelimit-remaining": 450,
  "x-ratelimit-reset": 1632425760
}
```

***

### Exceeding the Limit

If the request limit is exceeded, the API responds:

```
HTTP/1.1 429 Too Many Requests
```

The event log shows the limit, remaining requests, and reset time.

***

### Best Practices

* **Retry Logic** – If you receive an HTTP 429 response, use the reset time from the event log to determine when it is safe to retry requests.
* **Monitor Usage** – Regularly review the event log to track request volumes and avoid recurring limit breaches.

***

## Request Higher API Rate Limits

If your workloads require higher public API request capacity, please contact <support@simptel.com>\
to discuss an increase in rate limits.

**How to request:**

1. Have your **Tenant ID** ready.
2. Email **<support@simptel.com>** with subject **“API Rate Limit Increase”**.
3. Include your **Tenant ID** and desired requests per minute, expected peak/average volume, and timeline.


# API Versioning Policy

This article describes how we incorporate versioning of the services.

## API Versioning

TF Platform uses **header-based versioning**. You specify the API version in the request header without altering the URL structure.

```http
TF-API-Version: 1.0.0
```

If no version header is provided, the **latest stable major version** will be used by default.

***

### Semantic Versioning

TF Platform follows **semantic versioning (semver)** in the format **{major}.{minor}.{patch}**:

* **Major (X.0.0)** – breaking changes, not backward-compatible.
* **Minor (X.Y.0)** – backward-compatible new features.
* **Patch (X.Y.Z)** – bug fixes and minor improvements.

**Examples:** v1.2.0, v2.0.3, v3.1.1.

***

### API Request Example

```http
GET https://your-domain.com/api/resource
Host: your-domain.com
TF-API-Version: 1.2.3
```

***

### Best Practices

* Always specify the **full version (X.Y.Z)** in production to avoid unexpected changes.
* Test against new minor versions before upgrading.
* Refer to the **Service Level Agreement (SLA)** for details on version support windows and deprecation notice periods.

***

### Version Tags

All TF Platform open-source components use semantic versioning and are tagged in repositories with a **v** prefix (e.g., `v2.3.1`).


# Overview

The TF Platform’s accounting process captures and records all events generated by its services for your tenant. These events are centralised in the Audit Hub to support auditing and compliance.

You can view these logs on the Event Logs Monitor page or export them to your SIEM, SOR, or XDR systems using the Event Logs stream feature for enhanced security monitoring and auditing.<br>


# Events Log Monitor

The **Event Logs Monitor** page displays near real-time visibility into all API calls passing through your tenant.


# Event Log Streaming - Coming soon

#### Steps to configure audit log streaming <a href="#workflow" id="workflow"></a>

1. Prepare destination and retrieve required credentials. This step varies slightly depending on your SIEM system.
2. Configure the audit log streaming destination in the portal.&#x20;
3. Verify the connection. Use the connection test in the TF Platform UI to generate a log and send it to your SIEM system. Alternatively, take any action in the platform that produces an audit log, such as attempting to log in to TF Platform.
4. View the audit log on your external SIEM system to confirm that streaming is properly configured.


# Human Identity


# Description

## Human Identity Authentication Service

The **Human Identity Authentication Service**, as part of the Human Identity Hub, is the central authority for all human subscriber authentication. It validates subscriber identities and issues authentication assertions to relying parties and service providers registered in the Machine Identity Hub for Human-to-Machine authentication.

***

### Supported Authenticators

The Service supports both internal and external authenticators. Every authenticator must be explicitly enabled and configured; none are active by default.

**Internal Authenticators**

* Password
* Email
* Phone
* Passkeys
* TOTP

**External Authenticators**

* Social IdPs: Apple, Facebook, Google, Microsoft
* Government IdPs: eHerkenning, DigiD, European Login
* Enterprise IdPs: Microsoft Entra ID, Google Workspace, Okta

{% hint style="info" %}
Authenticators are configured at the tenant level. If permitted by tenant policy, organizations may enable or disable individual internal authenticators and add external authenticators.
{% endhint %}

***

### Enrollment and Authenticator Binding

Accounts and authenticators can be established in four ways:

* **Pre-Enrolment** – provisioned in advance, either administratively or through integration with external systems.
* **Self-Registration** – subscribers create accounts directly in the Human Identity Hub and register authenticators during enrollment.
* **Account Linking** – additional authenticators, including external IdPs, may be linked after enrollment.
* **Just-in-Time Registration** – accounts may be created automatically at the first use of an external IdP.

{% hint style="info" %}
**Authenticators can be renewed, revoked, or recovered as part of their lifecycle. Enrollment and recovery are configured at the tenant level. If permitted by tenant policy, organizations may allow or restrict pre-enrollment, account linking, and just-in-time registration.**
{% endhint %}

***

### Account Recovery

The Service supports account recovery in two modes:

* **Manual Recovery** – the credential service provider resets authenticators after validating the subscriber through a support ticket process.
* **Automated Recovery** – will be introduced once it can be delivered securely and reliably.

{% hint style="info" %}
**Account Recovery permissions are configured at the tenant level and may be further refined at the organizational level.**
{% endhint %}

***

### Session Management

The Service maintains authenticated sessions to preserve assurance between authentications. Sessions may require re-authentication after defined periods or inactivity. Logout events can be propagated by relying parties and service providers.

{% hint style="info" %}
**Session management is configured at the tenant level and may be refined at the organizational level if permitted by tenant policy.**
{% endhint %}


# External Authenticators


# Internal Authenticators


# Password

This document describes the configuration options available for enabling password-based user authentication.

#### 🔧 Select Algorithm: **PBKDF2**

PBKDF2 (Password-Based Key Derivation Function 2) is a key stretching algorithm that enhances password security through repeated hashing. It is a FIPS-approved method and widely supported.

***

#### 📌 Configuration Parameters

| Parameter         | Options / Range                                                                                                                | Description                                                                                                             |
| ----------------- | ------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------------- |
| **Hash Function** | `SHA-256` or `SHA-512`                                                                                                         | Selects the underlying HMAC hash function.                                                                              |
| **Key Length**    | <p>Based on hash function:<br>• <code>SHA-256</code> → 32 bytes (256 bits)<br>• <code>SHA-512</code> → 64 bytes (512 bits)</p> | Length of the derived key.                                                                                              |
| **Iterations**    | `300,000` – `600,000`                                                                                                          | Number of hashing rounds to slow down brute-force attacks. Higher values improve security but increase processing time. |

***

#### ✅ Recommendations

* **Preferred Digest**: `SHA-512` for stronger security, with a `key length` of `64 bytes`.
* **Minimum Iterations**: `300,000`\ <br>


# Email-Based Authentication

This section describes the configuration and behavior of email authentication, which enables users to authenticate using an e-mail.

#### ✅ Supported Method

* **OTP via Email**: A randomly generated one-time passcode is sent to the user’s email address. The user must enter this code to complete authentication.

***

#### 🌍 Global Availability

* **All email domains and regions are supported.**
* Domain or country restrictions are not currently configurable.

***

#### ⚙️ Configuration

| Feature                   | Description                  |
| ------------------------- | ---------------------------- |
| **Integrations Provider** | Selected email provider      |
| **OTP Length**            | Typically 6 digits or 8      |
| **Expiration time**       | Default: 1–5 minutes         |
| **Template**              | Subject + message body       |
| **FROM**                  | <noreply@authentication.com> |

***

#### ⚠️ Security Notes

* For enhanced security, especially in sensitive workflows, consider using email OTP **in combination with another factor** (e.g., password or phone).


# Phone-based authentication

### 📱 Phone-Based Authentication

This section describes the configuration and behavior of **phone authentication**, which enables users to authenticate via **SMS** or **voice calls** using one-time passcodes (OTP).

***

#### ✅ Supported Methods

* **SMS**: A one-time code is sent via text message to the user's phone.
* **Voice**: A one-time code is delivered via an automated voice call that reads the code aloud.

***

#### 🌍 Global Availability

* **All countries are supported.**
* **Per-country restrictions are not currently configurable.**

> 📌 *Make sure your SMS/voice provider has global routing and supports compliance (e.g., local regulations, sender ID requirements, etc.) for the countries you serve.*

***

#### ⚙️ Configuration

| Feature                  | Description                                          |
| ------------------------ | ---------------------------------------------------- |
| **Delivery Channels**    | `sms` or `voice`                                     |
| **From number**          | A e164+ number                                       |
| **From name (optional)** | A human identifier for the number, sometime accepted |
| **Digits**               | **6 or 8**                                           |
| **Template**             | code: %otp%                                          |
| **Integration Provider** | Configured Twilio Account                            |
| **Expiry time**          | 60, 120 and 300 seconds                              |

***

#### ⚠️ Security Notes

* Note: SMS and voice OTPs are **vulnerable to SIM swap attacks** and should not be the sole factor


# Passkeys


# Social Identity Providers


# Configuring an e-mail provider

This document explains how to configure an e-mail provider for the system e-mails.

| **Field**        | **Description**                                                     |
| ---------------- | ------------------------------------------------------------------- |
| **Display name** | The name that will appear within the tenants integrations overview. |
| **Description**  | A short description to identify this configuration.                 |
| **Host**         | The SMTP server hostname (e.g., `smtp.example.com`)                 |
| **Username**     | The SMTP account username                                           |
| **Password**     | The SMTP account password                                           |
| Port             | We only support port 465 for security.                              |


# Configuring Twilio for SMS or Voice

Use this configuration to enable Twilio for phone number for the phone authenticator.

### **Technical Settings**

| **Field**       | **Description**                                                                                                        |
| --------------- | ---------------------------------------------------------------------------------------------------------------------- |
| **Account SID** | Your Twilio Account SID                                                                                                |
| **Auth Token**  | Your Twilio Auth Token                                                                                                 |
| **From Number** | A verified Twilio phone number used to send messages or calls                                                          |
| Display name    | The name shown in the tenant’s integrations overview (e.g., "Twilio OTP Service").                                     |
| **Description** | <p>A short explanation of the provider’s purpose<br><em>(e.g., “Sends authentication codes via SMS or voice”)</em></p> |


# Description

The **Human-to-Machine (H2M) authentication model** ensures that all access to machines, applications, or services is traceable to an authenticated human subscriber.

* The **Human Identity Authentication Service** asserts the subscriber’s identity using internal authenticators or federated external authenticators.
* The **Machine Identity Service** binds the authenticated subscriber to a registered machine, device, or service account, and issues assertions to relying parties and service providers.
* This model guarantees that every machine action can be attributed to a specific, authenticated human subscriber.


# Description


# Disclaimer

Simptel B.V. and its subsidiaries (hereafter “Simptel,” “we,” or “us”) are committed to keeping this website accurate and up to date. For details about Simptel and it's subsidiaries, please see our [legal notice.](/legal/legal-notice)\
\
Please let us know if you encounter anything incorrect or outdated. Please indicate where on the website you read the information. We will then look at this as soon as possible. Please send your response by email to: <support@simptel.com>.

We are not liable for loss due to inaccuracies or incompleteness, nor for loss resulting from problems caused by or inherent to disseminating information through the internet, such as disruptions or interruptions. When using web forms, we strive to limit the required fields to a minimum.

For any loss suffered due to the use of data, advice or ideas provided by or on behalf of Simptel via this website, Simptel accepts no liability.

The use of the website and all its components (including our community) is subject to Terms & Conditions. The mere use of this website implies the knowledge and acceptance of these terms.

Responses and privacy inquiries submitted by email or using a web form will be treated like letters. This means you can expect a response from us within one month at the latest. In the case of complex requests, we will let you know within one month if we need a maximum of 3 months.

Any personal data you provide us within the context of your response or request for information will only be used in accordance with our privacy statement.

Simptel shall make every reasonable effort to protect its systems against unlawful use. Simptel shall implement appropriate technical and organizational measures to this end, considering, among other things, state-of-the-art. However, it shall not be liable for any loss whatsoever, direct or indirect, suffered by a user of the website which arises as a result of the unlawful use of its systems by a third party.

Simptel accepts no responsibility for the content of websites to which or from which a hyperlink or other reference is made. Products or services offered by third parties shall be subject to the applicable terms and conditions of those third parties.

All intellectual property rights to content on this website are vested in Simptel. Copying, disseminating and any other use of these materials is not permitted without the written permission of Simptel, except and only insofar as otherwise stipulated in regulations of mandatory law (such as the right to quote), unless specific content dictates otherwise.

If you have any questions or problems with the accessibility of the website, please do not hesitate to contact us.


# Legal Notice

This page provides official company information for Simptel B.V. and its subsidiaries.

## Company Information

**Simptel B.V.**\
Stadhuisplein 10\
5611 EM Eindhoven\
Netherlands\
Chamber of Commerce Number: 75987252\
VAT Identification Number: NL860468690B01

***

**Simptel Services B.V.**\
Stadhuisplein 10\
5611 EM Eindhoven\
Netherlands\
Chamber of Commerce Number: 91391199\
VAT Identification Number: NL865640774B01

***

**Simptel India Private Limited**\
C-305 Ganesh Glory 11, Near BSNL Office\
Vill Jagatpur, Tal Daskroi\
Ahmedabad, Gujarat – 382481\
India\
Corporate Identification Number (CIN): U72900GJ2021FTC126002

***

**Contacts**

* Legal: [**legal@simptel.com**](mailto:legal@simptel.com)
* Support: [**support@simptel.com**](mailto:support@simptel.com)
* General inquiries: [**info@simptel.com**](mailto:info@simptel.com)
* Sales: [**sales@simptel.com**](mailto:sales@simptel.com)
* Finance: <finance@simptel.com>


# Impressum for Germany

This page contains the legally required Impressum for the website simptel.com

### **Serviceanbieter**

\
Simptel B.V.\
Stadhuisplein 10\
5611 EM Eindhoven\
Niederlande

Handelskammer-Nummer: 75987252\
Umsatzsteuer-Identifikationsnummer: NL860468690B01

E-Mail: <info@simptel.com>

Vertretungsberechtigter Geschäftsführer: Izahir Clemencia

### **Verbundene Unternehmen:**

Simptel Services B.V.\
Stadhuisplein 10\
5611 EM Eindhoven\
Niederlande\
Handelskammer-Nummer: 91391199\
Umsatzsteuer-Identifikationsnummer: NL865640774B01

Simptel India Private Limited\
C-305 Ganesh Glory 11, Near BSNL Office\
Vill Jagatpur, Tal Daskroi\
Ahmedabad, Gujarat – 382481\
Indien\
Corporate Identification Number (CIN): U72900GJ2021FTC126002


# Privacy Statement

### Who is Simptel?

Simptel B.V. and its subsidiaries operate services and websites under the domains **simptel.com** and **simptellabs.com**. For details about Simptel and it's subsidiaries, please see our [legal notice.](/legal/legal-notice)\
\
This Privacy Statement explains **what personal data we collect, how we use it, how long we keep it, how we protect it, and what rights you have** when engaging with our platforms, products, and services.

***

### What Data Do We Collect and Why?

We believe in full transparency. Below is an overview of the categories of personal data we may process, the purposes for which we use it, and how long we retain it.

| Category / Data Collected  | Purpose of Processing                              | Retention Period                                      |
| -------------------------- | -------------------------------------------------- | ----------------------------------------------------- |
| Users / Personal Details   | Account creation, identification, service delivery | As long as account is active + legal requirements     |
| Company Information        | Customer administration, invoicing, compliance     | 7 years (tax and accounting compliance)               |
| Contact Information        | Communication, support, service updates            | Until opt-out or account deletion                     |
| Consents & Preferences     | Marketing, personalization                         | Until withdrawal of consent                           |
| Technical Information      | Security, fraud prevention, analytics              | Up to 12 months                                       |
| Location Data              | Geolocation features, security                     | Until consent withdrawal / up to 12 months            |
| Usage & Communication Data | Service delivery, troubleshooting, analytics       | As long as necessary for service + legal requirements |

***

### How Do We Protect Your Data?

We use **technical and organizational security measures** to safeguard your personal data against loss, misuse, and unauthorized access. These measures are reviewed and updated regularly.\
For further information, please see our [**Compliance Statement**](https://chatgpt.com/compliance).

***

### Storage and Retention of Personal Data

We retain personal data **only as long as necessary** for the purposes outlined in this Privacy Statement. Where data is needed to meet legal obligations (such as tax or accounting rules), we will retain it for the legally required period.

* **Usage data** is generally stored for a shorter period, unless needed for security, service improvement, or required by law.

***

### Sharing and Transfer of Personal Data

We may engage **trusted third-party providers** to support services such as:

* Website analytics
* Newsletter subscriptions
* Cloud hosting and storage
* Marketing activities (only with your consent)
* Co-marketing with relevant third parties

These service providers may process personal data **only on our behalf and for the purposes specified**.

Simptel may also share data within its group of companies for the purposes described here.

* **Main processing takes place within the European Economic Area (EEA).**
* Personal data will **not be transferred outside the EEA** unless appropriate legal safeguards (such as Standard Contractual Clauses) are in place.

***

### Your Rights

You have the right to:

* **Access** your personal data
* **Correct or update** inaccurate data
* **Request deletion** of your data (subject to legal obligations)
* **Withdraw consent** where processing is based on consent
* **Object** to processing under certain circumstances

If you wish to exercise your rights or make a complaint, please contact us at [**support@simptel.com**](mailto:support@simptel.com).\
If you are not satisfied with how we handle your request, you have the right to file a complaint with your local **Data Protection Authority**.

***

### Third-Party Websites

Our website may contain links to third-party services or websites. This Privacy Statement does not apply to those external parties. We recommend reviewing their privacy policies before using their services.

***

### Updates to This Privacy Statement

We may update this Privacy Statement from time to time. If material changes occur, we will notify you where required. Please check back regularly to stay informed.

***

### Legal References

Please also review our:

* [**Disclaimer**](/legal)
* [**Terms & Conditions**](https://www.simptel.com/legal/terms-and-conditions)
* [**Legal Notice**](/legal/legal-notice)

These documents work together with this Privacy Statement to govern the use of our services and websites.

***

📧 **Contact us:** <support@simptel.com>\
When reaching out, please include your **Visitor ID or User ID** (if applicable) and the date of your consent.


# Data Processing Addendum (DPA)

### 1. Roles of the Parties

* **Customer as Controller** – Customer acts as the controller of personal data stored in its tenant on the TF Platform (“The Future Platform”).
* **Simptel as Processor** – Simptel acts as processor only with respect to personal data in Customer’s tenant and processes such data solely on Customer’s documented instructions.
* **Customer Responsibility** – Customer is responsible for:
  * Selecting its hosting region (Azure, AWS, or Google Cloud);
  * Managing tenants, access rights, and identity configurations;
  * Configuring and managing third-party integrations.

While the TF Platform makes integrations easy, all third-party integrations (and their API keys or credentials) remain **Customer’s sole responsibility**.

***

### 2. Subject Matter and Scope

Simptel processes Customer Personal Data only for the provision of the **TF Platform**, an identity and security platform.

***

### 3. Processing Location

* **Tenant Data** – Customer Personal Data is processed **exclusively in the region selected by Customer** (Azure, AWS, or Google Cloud). Simptel does not replicate or transfer tenant data outside the selected region.
* **DNS Services** – The TF Platform uses **Google DNS** for the `tfplatform.com` domain, which may involve processing outside the selected region.
* **TLS Certificates** – TLS certificates are issued by **Let’s Encrypt** by default. Customers may alternatively provide their own certificates.
* **Customer Organizational Data** – Data relating to Customer’s own organization (e.g., billing, invoicing, contracting, and account administration) is processed in the **Netherlands** by Simptel. For these purposes, Simptel also uses the following service providers:
  * **Bird.com** – communications;
  * **Azure Marketplace** – subscriptions and procurement;
  * **Stripe** – payments and billing;
  * **Moneybird** – bookkeeping and accounting.

This processing is separate from Customer’s tenant data.

***

### 4. Nature and Purpose of Processing

Simptel processes Customer Personal Data solely to:

* Host, encrypt, and secure tenant data in the chosen region;
* Provide the features and functionality of the TF Platform;
* Manage billing, invoicing, and contracting for Customer’s organization.

***

### 5. Categories of Data and Data Subjects

* **Categories of Data:** Identity data, authentication data, access logs, and any other information uploaded or configured by Customer.
* **Data Subjects:** End-users of Customer’s tenant, such as employees, partners, or customers.

Customer determines what data is processed.

***

### 6. Security Measures

Simptel maintains technical and organizational measures appropriate to the risk, including:

* **Encryption** – All tenant data is encrypted at rest and in transit using **AES-based best practices**;
* **TLS** – Secured by Let’s Encrypt or Customer-provided certificates;
* **Access Controls** – Strict authentication and authorization measures;
* **Logging & Monitoring** – Security and compliance monitoring;
* **Tenant Isolation** – Logical and physical separation of tenants;
* **Certifications** – Simptel is **ISO/IEC 27001:2022 certified** and maintains **SOC 2 Type II compliance**, supported by **yearly independent audits**.

***

### 7. Sub-Processors

Authorized sub-processors are limited to:

**For Tenant Data**

* **Google** – DNS services for `tfplatform.com`;
* **Let’s Encrypt** – TLS certificate authority;
* **Cloud provider chosen by Customer** – Azure, AWS, or Google Cloud, in the region selected by Customer.

**For Customer Organizational Data**

* **Bird.com** – communications;
* **Azure Marketplace** – subscription and procurement;
* **Stripe** – payments and billing;
* **Moneybird** – bookkeeping and accounting.

**Simptel Entities**

* Simptel B.V. – Netherlands;
* Simptel Services B.V. – Netherlands;&#x20;
* Simptel India Private Limited – India&#x20;

Simptel will update this list at least 30 days before engaging a new sub-processor.

***

### 8. International Data Transfers

* **Tenant Data** – Remains in the Customer-selected region, except for DNS services.
* **TLS Certificates** – Let’s Encrypt may process limited technical data (domain validation) outside the selected region.
* **Customer Organizational Data** – Processed in the Netherlands, with Stripe and Bird.com potentially involving transfers outside the EEA.
* Where transfers outside the EEA/UK occur, Simptel ensures appropriate safeguards, including Standard Contractual Clauses.

***

### 9. Assistance to Customer

Simptel will assist Customer, where reasonably possible, with:

* Responding to data subject rights requests;
* Supporting Data Protection Impact Assessments (DPIAs);
* Providing documentation to demonstrate GDPR compliance.

***

### 10. Return or Deletion of Data

Upon termination of services, Simptel will delete or return Customer Personal Data, unless retention is required by law.

***

### 11. Audit Rights

Simptel provides documentation and evidence of compliance, including ISO 27001 and SOC 2 reports. Customer may conduct audits with reasonable notice and subject to confidentiality.

***

### 12. Liability

Each party’s liability under this DPA is subject to the limitations of liability agreed in the Terms & Conditions.

***

### 13. Governing Law

This DPA is governed by the laws of the Netherlands.


# Sub-processors

This page provides information about the sub-processors that Simptel has engaged in accordance with the Simptel Data Processing Addendum (Simptel DPA) to provide processing activities on Customer Data (as defined in the Simptel DPA) on behalf of customers. \
\
Sub-processors relevant to an individual customer will depend on the region the customer selects and the particular Simptel services that the customer uses.

There are three types of sub-processors:

1. Simptel entities that provide the infrastructure on which the Simptel services run;
2. Simptel entities that support specific Simptel services which may require these entities to process Customer Data; and
3. third parties that Simptel has contracted with to provide processing activities for specific Simptel services.

Simptel will update this page at least 30 days before engaging a new sub-processor.

**Simptel Service providers**

| Simptel Entity                | Processing location (if applicable) |
| ----------------------------- | ----------------------------------- |
| Simptel B.V.                  | Netherlands                         |
| Simptel Services B.V.         | Netherlands                         |
| Simptel India Private Limited | India                               |

&#x20;**Third-party service providers**

|               | Simptel Service(s)                    | Processing activities |
| ------------- | ------------------------------------- | --------------------- |
| Google        | Platform infrastructure, Platform DNS |                       |
| Azure         | Platform infrastructure               |                       |
| AWS           | Platform infrastructure               |                       |
| MongoDB Atlas | Database infrastructure               |                       |


# Terms and Conditions

These Terms & Conditions are applicable to Simptel B.V. and its subsidiaries, effective as of July 18, 2023.

Commitment to Accuracy: Simptel and its subsidiaries are dedicated to maintaining the currency and accuracy of these Terms & Conditions. If you discover any inaccuracies or outdated information, please notify us, specifying the section in question. We will promptly review and address it. Please contact us at <support@simptel.com>.

#### 1 Definitions and scope of application

1. These Terms and Conditions apply to all offers made by Simptel or its subsidiaries found in Appendix II, to all agreements that they enter into and to all agreements arising from this, all of which insofar as Simptel or its subsidiary is the supplier or the contractor.
2. Simptel B.V. is referred to as Simptel. The other party is referred to as the Customer or the Vendor. The Simptel website is <https://simptel.com/>. A Vendor is an authorized Simptel reseller on the basis of a vendor agreement between the Vendor and Simptel.
3. The definitions used in these Terms and Conditions will be as listed below and/or as listed in the glossary that is attached to these Terms and Conditions as Appendix I.
4. The Agreement consists of these Terms and Conditions, the Data Processing Agreement, Product Specific Terms, and applicable Service Level Agreement (SLA), and other written Documentation as agreed upon by both parties
5. In the event of conflicts between the Agreement entered into by the Customer or Vendor and Simptel and these Terms and Conditions, the provisions of the Agreement will prevail.
6. In the event of conflicts between these Terms and Conditions and a translation of these Terms and Conditions, the provisions of the English version will prevail.

***

#### 2 Account

1. The Customer or Vendor will be asked to create an account in order to use the Services. In order to create an account to the Services, the Customer or Vendor must (i) be legally able to represents the company or business contracting our Services, and (b) review and accept the Agreement on its behalf. To create an account, the Customer or Vendor will be asked to provide registration information including an e-mail address and (optional) phone number and create a password. The Customer or Vendor agrees to (i) provide true, current and complete information when creating an account, and (ii) keep that information true, current and complete during your use of the Services.
2. If any of the Customer’s or Vendor’s affiliates wants to use the Services, (i) each affiliate must create their own accounts and accept these Terms and Conditions individually, which may require a separate order form, or (ii) the Customer or Vendor may allow its affiliates to the Services without entering into a separate order form by providing such affiliates with a set of Credentials to access and use the Services. If the Customer or Vendor provides its affiliates with access to their accounts, this Agreement applies to each affiliate, and the Customer or Vendor is directly and primarily responsible for all access to and use of the Services by the affiliates. In such cases, references in these Terms and Conditions to “the Customer or Vendor” includes a reference to their relevant affiliates and any (end-)users of their account, login ID, password and/or API key from time to time.

***

#### 3 Services

1. The Services are all products and services that are provided by Simptel or its affiliates that are (i) ordered by the Customer or Vendor under an applicable ordering document between the parties that specifies pricing and other commercial terms: the “order form”, or (ii) used by the Customer or Vendor. The Services are designed for commercial use only and not intended for private, personal or individual usage. As the Services are business-oriented, they will not provide access to emergency services or emergency service providers including but not limited to police, fire department or hospitals. The Customer or Vendor should therefore ensure that they have sufficient separate access to those services through regular communication channels such as (mobile) phones.
2. Simptel’s affiliates may provide Services, or a part thereof to the Customer or Vendor in accordance with these Terms and Conditions and any applicable order forms. Simptel will be responsible for the Services provided by its affiliates and not be relieved of its obligations under these Terms and Conditions. Simptel may exercise its rights and entitlements and discharge its obligations through its affiliates.
3. From time to time, Simptel may change the features and functions of the Services. If so, Simptel will make a reasonable effort to notify the Customer or Vendor of such changes, such as through posting an announcement on the Simptel website or sending an in-application notice or e-mail. Changes to the Service will not materially diminish the overall functionality or features of the Services. Continued use of the Service following the notification or the changes, will constitute an acceptance of such changes. If the Customer or Vendor does not wish to accept such changes, they have to stop using the Services immediately. If applicable law requires Simptel to give a specific notice of such change, Simptel will do so in accordance with these Terms and Conditions.
4. Simptel is under no obligation to monitor any content of communications. However, Simptel may suspend an account immediately if Simptel reasonably determines (i) that the Customer or Vendor or any (end-)users have materially breached any part of the Agreement, including the Product Specific Terms and any limitations included in an order form or on the Simptel or an affiliate’s website, (ii) that Simptel’s provision or the use of the Services by the Customer or Vendor is or becomes prohibited by applicable law or regulation or the terms of third party providers, (iii) there is any use of the Services that in Simptel’s judgment threatens the security, integrity, or availability of the Services or constitutes fraudulent or illegal activity, or (iv) that the Customer’s or Vendor’s account information is untrue or incomplete.
5. If Simptel suspends an account due to the Customer’s or Vendor’s actions or omissions pursuant to these Terms and Conditions, to the greatest extent possible Simptel will not be liable for any damages, liabilities or losses, or any other consequences that the Customer or Vendor may incur as a result. The Customer or Vendor will remain responsible for payment of the fees during the suspension.
6. The Services may become temporarily unavailable (i) to perform scheduled or unscheduled maintenance, modifications or upgrades, (ii) due to hardware failures, power outages, or failures of third party providers (iii) to mitigate or prevent the effects of any threat or attack to the Services or any other network or systems on which the Services rely, or (iv) as required by legal or statutory regulations. Simptel will make a reasonable effort to notify the Customer or Vendor in advance of ant scheduled maintenance or unavailability of the Services. Except as provided in the order form, the Simptel website or SLA to the greatest extent permitted by applicable law, Simptel is not liable for any damages, losses or any other consequences that the Customer or Vendor may incur as a result of unavailability of the Services and/or the failure to provide a notice of unavailability.
7. The Customer or Vendor may be permitted to use the Services free of charge, or may be invited to test products or features of the Services that are not (yet) generally available, referred to as Alpha products, Beta products or Test products. Simptel is not obligated to provide Alpha products, Beta products or Test products to anyone and may choose to discontinue Alpha products, Beta products or Test products at any time.
8. Alpha products, Beta products and Test products are inherently less mature and stable than other functionalities and the Services. Alpha products, Beta products and Test products, and any Services provided free of charge are explicitly excluded from any SLA commitments.

***

#### 4 Responsibilites

1. Simptel will make the Services available to the Customer or Vendor in accordance with the Agreement, including any applicable order forms, and any publicly available technical documentation for such Services made available on the Simptel website or an affiliate’s website, which may be updated from time to time. Simptel will take appropriate security measures to limit abuse of and unauthorized access to personal data. Simple will provide the Services in accordance with all applicable law and regulations in the provision of the Services to the Customer or Vendor. Simptel reserves the right to select the technical methods necessary to ensure and/or optimize delivery of Services in accordance with the Agreement.
2. The Customer or Vendor will use the Services only in accordance with how the Services have been made available to them, the Agreement (including the Product Specific Terms), order forms, documentation on the Simptel website, and applicable law and regulations. The Customer or Vendor will be solely responsible for (i) all use of the Services under their accounts, including prohibited activities such as reverse engineering, copying, disassembling, decompiling, modifying, copying or creating derivative works of any (part) of the Services, (ii) all acts, omissions, and activities of anyone who accesses or otherwise uses the Customer’s or Vendor’s accounts, including their (end-)users and their compliance with the Agreement, (iii) any data or other information or content submitted by the Customer or Vendor (including their (end-)users) or for the Customer or Vendor (including their (end-)users) under the Agreement and processed or stored by the Services and (iv) all applications, web domains, devices and communication channels owned or controlled by the Customer or Vendor or third parties or available to the Customer or Vendor or its (end-)users which access, use, interact with, integrate or depend on the Services (the Application).
3. The Customer will not transfer, resell, lease, license or otherwise make the Services available to third parties without prior written approval from Simptel, except as specifically permitted under the Agreement.
4. The Customer or Vendor will provide prompt and reasonable cooperation regarding information requests Simptel may receive from law enforcement, regulatory institutions or other telecommunication providers.
5. Simptel will apply appropriate security measures and may suspend an account if there is reason to believe it has been compromised. However, the Customer or Vendor is solely responsible for preventing unauthorized access to or use of the Services through their account and will promptly notify Simptel of any unauthorized access or use.
6. The Customer or Vendor will not use the Services (or permit them to be used) to transmit inappropriate content, such as content that (i) is unsolicited, (ii) violates any legal, regulatory, self-regulatory, governmental, statutory or telecommunication network operator’s requirements or codes of practice, (iii) is pornographic, racist, abusive, obscene, offensive, threatening, harassing, defamatory, discriminatory, misleading or inaccurate, (iv) is harmful, including but not limited to hate speech, or (v) encourages, violence, discrimination or illegal, unethical or immoral actions. Simptel may remove any inappropriate content from the Services and/or suspend access to the Services without prior notice where Simptel becomes aware of inappropriate usage.
7. Simptel is not liable for any damages, losses, or any other consequences the Customer or Vendor may incur as a result of any suspension or removal of content in accordance with these Terms and Conditions.
8. The Agreement exclusively specifies and governs the terms and conditions on which the Services will be provided by Simptel. In the event the Services are purchased through an authorized Simptel reseller (Vendor), such purchases will be subject to a separate agreement or ordering document between the buyer and the Vendor which shall address relevant applicable terms and conditions. Any disputes, queries or other matters relating to the agreement with the Vendor, shall be handled directly between the buyer and the Vendor.
9. The Vendor may exchange information with Simptel and the buyer/Customer consents to such information exchange. In the event the Customer purchases Services from Simptel following a referral from a Vendor, Simptel may share limited information with the Vendor solely in connection with discharging any referral fee payments owed by Simptel to the Vendor.

***

#### 5 Fees and Terms of Payment

1. Unless explicitly stated otherwise, all prices and quotations are excluding VAT and ant other applicable direct or indirect taxes, levies, duties or other similar exactions imposed by a legal, governmental or regulatory authority in any applicable jurisdiction. Unless explicitly stated otherwise, all prices are in Euros.
2. All prices and quotations provided by Simptel are non-binding and may be revoked or adjusted if other or additional information is provided.
3. Unless explicitly stated otherwise in the order form or on the Simptel website, any prepaid balance, deposit, wallet fund or other credits the Customer or Vendor purchases or makes will lapse if it’s not used within one year after the purchase date. Simptel is not obligated to refund prepaid balance, including in circumstances where the account is deactivated or suspended because of non-compliance with the Agreement. The prepaid balance will be used and depleted for any Services used by the account. Unless specifically stated otherwise, Simptel may require the Customer or Vendor to have a minimum prepaid balance in order to use the Services. Simptel may refuse to provide Services where the Customer or Vendor has an insufficient prepaid balance. Simptel reserves the right to specify a maximum prepaid balance and to deduct any amounts owed by the Customer or Vendor under the Agreement from the prepaid balance.
4. Simptel may pass on to the Customer or Vendor an increase in cost-determining factors that occurs after entering into the Agreement. The Customer or Vendor is obliged to pay the price increase immediately on Simptel’s request.
5. Payment is made at Simptel’s business address, a payment gateway or into a bank account to be designated by Simptel.
6. Unless explicitly stated otherwise, payments must be made within 30 days of the invoice date.
7. Simptel’s affiliates may directly bill the Customer or Vendor for the Services provided by the affiliate, or as a billing agent or representative for Simptel or another affiliate providing the Services.
8. If the Customer or Vendor fails to fulfill its payment obligations, it is obliged to comply with a request from Simptel for a tender of payment for the agreed amount.
9. The Customer’s or Vendor’s rights to offset its claims against Simptel or to suspend the fulfillment of its obligations is excluded, unless Simptel has been granted a suspension of payments or is bankrupt or the statutory debt adjustment scheme applies to Simptel.
10. Irrespective of whether Simptel had fully executed the agreed performance, everything that the Customer or Vendor owes or will owe under the Agreement is immediately due and payable if: a. A payment term had been exceeded; b. The Customer or Vendor has filed for bankruptcy or suspension of payments; c. The Customer’s or Vendor’s goods or claims have been attached; d. The Customer or Vendor (a company) is dissolved or wound up; e. The Customer or Vendor (a natural person) files an application to be admitted to the statutory debt adjustment scheme, is placed under a guardianship order or had died.
11. If payment is delayed, the Customer or Vendor will owe interest on that sum to Simptel with effect from the day following the day agreed as the final day of payment up to and including the day on which the Customer or Vendor settles the amount in question. If the parties have not agreed on the final day of payment, the interest is due from 30 days after the sum has become due and payable. The interest is 12% per year, but is equal to the statutory interest if this is higher. For the interest calculation, a part of the month is considered to be a full month. At the end of each year, the amount on which the interest is calculated will be increased by the interest due for that year.
12. Simptel is entitled to offset its debts to the Customer or Vendor against claims that companies affiliated to Simptel have against the Customer or Vendor. In addition, Simptel is entitled to offset its claims to the Customer or Vendor against debts that companies affiliated to Simptel have against the Customer or Vendor. Furthermore, Simptel is entitled to offset its debts to the Customer against claims against companies affiliated to the Customer. ‘Affiliated companies’ means all companies belonging to the same group, within the meaning of Book 2, Section 24b of the Dutch Civil Code, and a participation within the meaning of Book 2, Section 24c of the Dutch Civil Code.
13. For late payments, the Customer or Vendor owes Simptel all extrajudicial costs with a minimum of € 75.00. these costs are calculated on the basis of the following table, i.e., the principal sum excluding interest:

| Principal                              | Interest |
| -------------------------------------- | :------: |
| On the first € 3,000.00                |    15%   |
| On the excess up to € 6,000.00         |    10%   |
| On the excess up to € 15,000.00        |    8%    |
| On the excess up to € 60,000.00        |    5%    |
| On the excess from € 60,000.00 or more |    3%    |

The extrajudicial costs actually incurred are due if they are higher than the calculation given above.

1. If judgment is rendered in favour of Simptel in legal proceedings, either entirely or for the most part, the Customer or Vendor will bear all costs incurred in connection with these proceedings.

***

#### 6 Confidentiality

1. Confidential information in the sense of these Terms and Conditions means any information or data disclosed by one party (the disclosing party) to the other (the receiving party) that is marked as confidential or that should reasonably be understood to be confidential given the nature of the information and the circumstances surrounding disclosure. Confidential information does not include any information which (i) is independently publicly available, (ii) was rightfully known by the receiving party prior to disclosure by the disclosing party, (iii) was lawfully disclosed to receiving party by another party not under any obligation or breach of confidentiality, or (iv) is independently developed by or for the receiving party without use of or reference to the confidential information of the disclosing party.
2. Unless specifically agreed to otherwise in writing, the receiving party will not (i) use any confidential information of the disclosing party for any purpose other than fulfilling the receiving party's obligations and rights under the Agreement, or (ii) disclose confidential information to any third party except for entities (including but not limited to contractors and legal counsel) who have a “need to know” in order for the receiving party to fulfill its rights and obligations under these Terms and Conditions. These entities will be bound to protect confidential information under the same terms of confidentiality as the receiving party, and the receiving party will be responsible for any breach of confidentiality by these entities.nd the receiving party will be responsible for any breach of confidentiality by these entities.
3. Receiving party may disclose confidential information of the disclosing party to the extent compelled by regulation, law, subpoena, court order or contractual obligations, provided that (i) the receiving party promptly gives disclosing party prior written notice of the compelled disclosure to the extent legally permitted, (ii) the receiving party discloses only the confidential information legally required and (iii) the receiving party provides reasonable assistance, at the disclosing party's sole expense, if the disclosing party wishes to contest the disclosure.

***

#### 7 Representations, Warranties, Disclaimer

1. The Customer or Vendor represents and warrants that they have obtained all the necessary permissions or consents to deliver customer data to Simptel for use and disclosure pursuant to the Agreement and that none of the customer data or the Application violates any applicable law or third party’s intellectual property or other right.
2. Simptel represents and warrants that the Services will perform materially in accordance with the applicable documentation. Simptel’s sole obligation, and the Customer’s or Vendor’s role and exclusive remedy, in the event of any failure in this regard will be for Simptel to, at Simptel’s option, (i) take commercially reasonable efforts to correct the material failure, or (ii) refund the fees the Customer or Vendor actually paid for the time period during which the material failure affected the Services.
3. Each party represents and warrants that it has the legal right and authority to enter into the Agreement, to perform its obligations under the Agreement, and to grant the rights and licenses described in the Agreement.
4. Each party warrants that it will comply with all anti-corruption, anti-money laundering, anti-human trafficking, anti-bribery, sanctions, export controls and other international trade laws, regulations, and governmental order of any relevant government authority, including obtaining all necessary licenses and/or governmental approvals. The Customer or Vendor will promptly notify Simptel in writing of any potential violation of the laws and regulations specified above in connection with their use of the Services and will take appropriate action to remedy or resolve such violations, including any actions requested by Simptel.
5. Except for the warranties provided in this article, the Services are provided “as is” and to the greatest extent permitted by law, Simptel disclaims all other warranties including any implied warranties of merchantability, fitness for a particular purpose, or any other warranties related to third party telecommunications providers. The Customer or Vendor acknowledges that internet and telecommunications providers are inherently insecure. Beta products are provided “as is” with no warranties and representations. If any part of this article is determined to be unenforceable such that warranties and representations cannot be excluded, then all warranties will, to the greatest extent permitted by applicable law, be limited in duration to thirty (30) days after the effective date of the Agreement, and no warranties or conditions will apply after that period.

***

#### 8 Mutual indemnification

1. Simptel will indemnify the Customer or Vendor and their affiliates and their respective officers, directors and employees (the Customer Indemnified Parties, CIPs) on written demand against all damages, fines, penalties, settlement amounts pre-approved by Simptel, costs, expenses, taxes and other liabilities, including reasonable attorney fees, incurred or awarded against CIPs in connection with any claim, action, demand, suit or proceeding (Claim) made or brought against CIPs by an unaffiliated third party alleging that the use of the Services violates their intellectual property rights (Infringement Claim) and Simptel will take all reasonable steps necessary to defend against such an Infringement Claim at its own expense.
2. In the event of an Infringement Claim, Simptel reserves the right to, at its own option, (i) modify the Services in such a way as to make them non-infringing, or (ii) terminate the infringing Services and refund the Customer or Vendor any unused pre-paid fees. Simptel will have no liability under this section and/or these Terms and Conditions with respect to any Infringement Claim to the extent arising from or out of (i) use the of Services by the Customer or Vendor in breach of the Agreement. (ii) the combination of the Services with other (third party) applications, products and services where the Services by itself would not be infringing, or (iii) Beta products or Services which are provided free of charge.
3. The Customer or Vendor will indemnify Simptel and its affiliates and their respective officers, directors and employees (the Simptel Indemnified Parties, SIPs) on written demand against all losses incurred or awarded against SIPs in connection with any Claim by an unaffiliated third party alleging, or arising out of any use of the Application or the Services through the Customer’s or Vendor’s account constitutes (i) breach of the Customer’s or Vendor’s responsibilities under these Terms and Conditions, (ii) infringement and misappropriation of such third party’s intellectual property rights, or (iii) violation of applicable laws, including applicable data protection laws (Customer Indemnifiable Claims, CICs) and the Customer or Vendor will take all reasonable steps necessary to defend against such CICs at its own expense.
4. Without limiting or affecting Simptel’s other rights and remedies under this Agreement, if and to the extent that Simptel incurs or is notified that it will incur any fine, penalty or analogous charge from an unaffiliated third party arising out of the Customer’s or Vendor’s breach of the Agreement, the Customer or Vendor shall be obligated to pay such fine or penalty on an indemnity basis pursuant to these Terms and Conditions on notice by Simptel to the Customer or Vendor of such fine or penalty.
5. Each party will provide the other party with prompt notice of a Claim. A party’s failure to provide such notice relieves the other party of its obligation to defend and indemnify to the extent that the failure to provide such notice materially harms the other party’s ability to defend against the Claim. The indemnifying party will assume exclusive conduct of the Claim and the indemnified party will provide reasonable assistance in connection with the conduct of the Claim at the indemnifying party’s expense. The indemnified party may appoint a non-controlling counsel to participate in the defense of the Claim at its own expense. The indemnifying party will not settle any Claims for which it has an obligation to indemnify by admitting liability or fault on behalf of the indemnified party, nor create any obligation on behalf of the indemnified party, without the prior written consent of the indemnified party. This written consent shall not be unreasonably withheld.
6. This section states the indemnifying party’s sole liability to, and the indemnified party’s exclusive remedy against, the other party for all third party Claims, but this shall not limit or preclude Simptel’s right to terminate or suspend the Services where Simptel would otherwise be entitled to do so under the Agreement.

***

#### 9 Limitation of liability

1. In no event shall either party have any liability related to the Agreement for any lost profits, revenues, goodwill, data, business interruption or indirect, special, incidental, consequential, or punitive loss or damages, whether an action is in contract or tort or otherwise and regardless of the theory of liability.
2. Simptel’s sole and exclusive remedy for any unavailability, non-performance, or other failure to provide an eligible service under the SLA is a penalty in accordance with the terms of the SLA. To the greatest extent permitted by applicable law, neither party’s liability shall exceed the amounts paid or payable for the Services giving rise to the liability during the twelve (12) month period preceding the first incident out of which the liability arose. Simptel will have no liability regarding the Applications, Beta products or loss of or damage to customer data while in transit via the internet or a telecommunications network.
3. None of the above limitations apply to a breach of the Customer’s or Vendor’s responsibilities, payment obligations or amounts payable pursuant under the mutual indemnification under these Terms and Conditions.

***

#### 10 Publicity

1. Simptel has the right to use the Customer’s or Vendor’s name and logo if the Customer or Vendor uploads their name and logo, and a description of the Customer's or Vendor's use case on the Simptel website, customers lists, or marketing and promotional materials.
2. The Customer or Vendor provides Simptel full permission to use their name, logo and use case n the Simptel website, customers lists, or marketing and promotional materials.

***

#### 11 Contract term and termination and survival

1. These Terms and Conditions commence on the date that they are accepted by the Customer or Vendor or, where an order form applies, on the date specified on the order form and will continue until all order forms and Services used by the Customer or Vendor entered into under these Terms and Conditions have expired or been terminated.
2. Either party may terminate the Agreement, affected order form(s), or Services used by the Customer or Vendor in the event of a material breach if, after providing written notice of the breach, the other party does not remedy the breach within fifteen (15) days.
3. In the event of a material breach by the Customer or Vendor, Simptel may also (i) terminate the Agreement, (ii) close all of the Customer’s or Vendor’s accounts and/or (iii) prohibit the Customer or Vendor from creating any new accounts. Simptel may also terminate or suspend the Agreement of the provision of certain Services with immediate effect by notifying the Customer or Vendor in the event Simptel has substantiated reason to believe that the use of the Services by the Customer or Vendor (i) would constitute a breach of third-party application terms (including but not limited to those set out in the Product Specific Terms) or the terms of the Agreement; (ii) is contrary to applicable laws, regulations, or public order; or (iii) includes transmission of inappropriate as specified in these Terms and Conditions.
4. Either party may terminate the Agreement (and Simptel may close the Customer’s or Vendor’s account(s)) by written notice in the event the other party becomes subject of a petition in bankruptcy or other proceedings relating to insolvency, receivership or liquidation.
5. If Simptel terminates the Agreement because of a material breach of the Customer or Vendor, the Customer or Vendor will pay Simptel any unpaid fees covering the remainder of the term of the Agreement, order form(s), and/or Services used by the Customer or Vendor in the online customer portal. In no event shall termination relieve the Customer or Vendor of their obligation to pay any fees payable to Simptel for the period prior to the effective date of termination.
6. The terms of sections 5, 6, 7, 8, 9 and 14 will survive any termination or expiration under this section.

***

#### 12 Changes Terms & Conditions

1. From time to time, Simptel may update these Terms and Conditions. If Simptel makes material changes, Simptel will notify the Customer or Vendor by sending an e-mail. To the greatest extent permitted by applicable law, the new Terms and Conditions will take immediate effect, and continued use of the Services by the Customer or Vendor following the posting or notice of the changes will constitute acceptance of the updated Terms and Conditions. If any applicable law requires Simptel to give additional notice in respect of some or all of the Services, changes will automatically take effect regarding the use of the relevant Services by the Customer or Vendor upon expiry of such notice period (unless the Customer or Vendor terminates the Agreement during that period) or upon the earlier agreement to such changes. If the Customer or Vendor has the right under applicable law to terminate the Agreement upon receipt of such notice, the Customer or Vendor will not be charged a fee for early termination where the Customer or Vendor exercises that right under applicable law, but any fees previously paid are non-refundable and any fees owing continue to remain due and payable. Changes to these Terms and Conditions will not materially diminish the protections, features and/or functionality of the Service.erially diminish the protections, features and/or functionality of the Service.

***

#### 13 Governing law and dispute resolution

1. Any dispute, claim or controversy arising out of or in connection with the Agreement shall be governed by and construed in accordance with the laws of the Netherlands. The United Nations Convention on Contracts for the International Sale of Goods is explicitly excluded, as is the application of title 7.1, and articles 6:89, 6:93, 7:408(2) and 7:411 of the Dutch Civil Code.
2. The competent courts of ‘s-Hertogenbosch will have exclusive jurisdiction to settle any disputes arising out of or related to the Agreement.
3. To the greatest extent permitted by applicable law, the parties agree that neither party can bring a dispute as a plaintiff or class member in a class action, consolidated action, or representative action.

***

#### 14 Miscellaneous

1. In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (i) the data processing agreement; (ii) the applicable order form, (iii) the Product Specific Terms, (iv) the applicable SLA, (v) these Terms and Conditions, (vi) other applicable documentation.
2. Each party is an independent contractor in the performance of the Agreement and nothing in these Terms and Conditions is intended to create or will be construed as creating an employer-employee relationship or a partnership, agency, joint venture, or franchise. Neither party has the right to authority to commit the other party in any way and will not attempt to do so or imply that it has the right to do so. Nothing in these Terms and Conditions is intended to prevent (i) Simptel from marketing, licensing, selling or otherwise providing Services to any third party and (ii) the Customer or Vendor from obtaining services similar to the Services from a third party.
3. Simptel and/or its Vendors, as applicable, owns and reserves all rights, title and interest, including intellectual property rights, in and to the Services and any relevant, applicable documents. The Customer may not reverse engineer, copy, dissemble, or decompile the Services, or remove any copyright, trademark or any other proprietary rights notices contained in or on the Services.
4. If a court of competent jurisdiction holds any provision of these Terms and Conditions to be contrary to applicable law, that provision will be changed and interpreted so as to best accomplish the objectives of the original provision to the greatest extent permitted by law and the remaining provisions of these Terms and Conditions will remain in full force and effect.
5. If the Customer or Vender needs to provide notice to Simptel under these Terms and Conditions,they may do so via e-mail exclusively to <izahir@simptel.com> or by registered prepaid post to Simptel’s business address with a PDF copy per e-mail exclusively to <legal@simptel.com>. If Simptel needs to provide notice to the Customer or Partner, it will do so, at its own choice, in writing via e-mail to the e-mail address designated in the account or by letter to the address associated with the account. It is the responsibility of the Customer or Partner to keep these addresses associated with the account current and accurate.
6. Except for the payment of fees, each party will be excused from any failure or delay of performance to the extent caused by unavoidable events beyond its reasonable control and not caused by it. These events include, but are not limited to, natural catastrophes, laws, orders, regulations, directions or actions of governmental authorities, acts of war, hostility, or sabotage, failure of telecommunication or digital transmission links, or failure of any third party operating systems, platforms, applications or networks not under the party’s reasonable control. All parties will take reasonable actions to minimize the consequences of these events. In addition, a party will be excused from future performance under this Agreement, if (i) the other party becomes, directly or indirectly, subject to sanctions or restrictive measures imposed by competent governmental authorities, or (ii) the performance of any aspect of this Agreement would require that party to engage in a transaction with a person, directly or indirectly, subject to such sanctions or restrictive measures.
7. With the exception of the rights explicitly provided in the Agreement, each party waives any rights to wholly or partially terminate or rescind the Agreement or to claim termination, rescission or amendment of the Agreement to the greatest extend permitted by applicable law.
8. Neither party may assign or transfer its rights and obligations under this Agreement, wholly or partially, without the prior written consent of the other party. However, either party may assign this Agreement in its entirety without prior consent – but subject to written notice promptly following the event – in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of the relevant party’s assets to a party that is not a competitor of the other party. Any attempted assignment or transfer by either party in violation hereof is void. Each and all of the provisions of this Agreement will be binding and inure to the benefit of the parties to this Agreement and their respective administrators, successors, and permitted assigns.
9. This Agreement represents the full and complete contract between the parties, superseding all prior proposals, statements, or agreements and neither party has entered into this Agreement in reliance on any representations or warranties other than as set out in the Agreement.
10. If the Customer or Vendor is a micro-enterprise, small enterprise or non-profit organization and the Services are provided in the EEA and/or the United Kingdom which are subject to the European Electronic Communications Code (and relevant national implementation measures transposing Directive (EU) 2018/1972 or equivalent provisions in the EEA or UK) (the EECC), to the greatest extent possible under the applicable law, the Customer or Vendor expressly waives their rights under the EECC.
11. The use of the Services indicates acceptance of the Agreement. If and to the extent that parties enter into an Agreement that requires a signature, parties agree to the use of electronic signatures and to be bound by them.
12. In case of any grievances in relation to the Agreement or the Services, contact <support@simptel.com>.
13. A party shall not be entitled to recover more than once under this Agreement in respect of the same loss or damage suffered.
14. References in the Agreement, including all referenced documents comprising part of the Agreement), to “include”, “included”, “including”, and “for example” and like words shall, as the context so requires, be read to refer to those words without limitation.

#### Appendix I – Glossary

| Term                 | Definition                                                                                                                                                                                                     |
| -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| User                 | The individual who interacts with the platform to register an account, recover their account, or access their resources through an account.                                                                    |
| Customer             | A user who has registered an entity with type "customer" to make use of the services provided by the vendor or supplier.                                                                                       |
| Vendor               | A user who has registered an entity with type "vendor" to sell services to customers.                                                                                                                          |
| Supplier             | An entity with type "supplier" that sells services to vendors.                                                                                                                                                 |
| Client               | The application that is attempting to act on the user’s behalf or access the user’s resources.                                                                                                                 |
| Resource Server      | The application that contains the user’s data, which the user or end-user can access through APIs using credentials.                                                                                           |
| Authorization Server | The application that the user interacts with when an application requests access to their account or data. It is responsible for granting access after the user authorizes the application.                    |
| Credentials          | Includes usernames, passwords, emails, phone numbers, access tokens, security tokens, codes, or cookies. These components serve the purpose of identifying users and authorizing access to specific resources. |
| API                  | The Application Programming Interface that acts as a communication channel between applications, enabling them to interact and exchange information with each other.                                           |

#### Appendix II - Entities

| Entity Name             | Headquarters Address                                                                              | Registration Number       |
| ----------------------- | ------------------------------------------------------------------------------------------------- | ------------------------- |
| Simptel B.V.            | Stadhuisplein 10, 5611EM, Eindhoven, North-Brabant, Netherlands                                   | KvK 75987252              |
| Simptel Services B.V.   | Stadhuisplein 10, 5611EM, Eindhoven, North-Brabant, Netherlands                                   | KvK 91391199              |
| Simptel India Pvt. Ltd. | C-305, Ganesh Glory 11, Jagatpur Rd, near BSNL Office, Jagatpur, Ahmedabad, Gujarat 382470, India | CIN U72900GJ2021FTC126002 |


# Service Level Agreement

This Service Level Agreement ("SLA") forms an **integral part of the Simptel Terms and Conditions**.\
Where Simptel has agreed on a custom SLA in a signed contract with a Client, the provisions of that contract will prevail over this SLA.

***

### 1. Definitions

* **Incident**: Any event that causes unavailability or significant degradation of a Simptel Service, impacting the Client’s ability to use it.
* **Business Hours**: Monday to Friday from 08:30 – 17:00 CET/CEST, excluding Dutch national holidays.
* **Business Day**: Eight consecutive Business Hours.
* **Network Operations Centre (NOC)**: A 24/7/365 staffed team responsible for monitoring Simptel services and responding to incidents.
* **Beta / Early Access**: A feature or service still under development, which may not yet be fully operational or stable.

***

### 2. Service Availability

Simptel commits to use all commercially reasonable efforts to provide a highly available, secure, and resilient platform.

**Exclusions from availability calculations:**

* Issues caused by third parties (e.g. internet providers, external carriers)
* Misconfigurations or actions by the Client
* Force majeure events
* Scheduled or emergency maintenance
* Beta or Early Access features

**Custom SLA agreements:**\
If a signed contract specifies different service levels, those provisions will take precedence over this standard SLA.

***

### 3. Measurement

Service availability is measured quarterly using Simptel’s monitoring systems.

**Availability is calculated as:**

```
(total minutes in a quarter - excluded duration - downtime)
÷ (total minutes in a quarter - excluded duration) × 100%
```

***

### 4. Support Access

Clients have access to the **Simptel Support Portal** for documentation, guides, and service updates: <https://docs.simptel.com/tf-platform/administration/organizations/support>

**Support rules:**

* Business Hours chat support is available via the Simptel platform.
* Only authorized users on a Client account may contact support.
* Simptel support does not provide custom development or debugging of Client code.

***

### 5. Response Times

Simptel aims to respond to support requests within **one Business Day**.

* Clients may assign priorities when submitting tickets.
* Simptel may reclassify the priority if the assigned level is not consistent with the actual impact.

***

### 6. Incident Management

Incidents are prioritized according to impact and urgency:

* **P1 – Critical**: Widespread service outage, business-critical impact
* **P2 – High**: Major functionality impaired, limited workaround available
* **P3 – Medium**: Partial degradation or reduced performance
* **P4 – Low**: Minor impact, workaround available
* **P5 – Informational**: Cosmetic issues or non-service-affecting reports

Clients can monitor ongoing incidents via the **Status Page**:  <https://simptel.statuspage.io/>

Notifications are available via email subscription.

***

### 7. Maintenance

Simptel strives to minimize impact of planned maintenance.

* **Scheduled maintenance**: Notice provided at least **two weeks in advance**
* **Emergency maintenance**: Notice provided at least **24 hours in advance**, or as soon as reasonably possible in urgent situations
* All maintenance windows are announced on the **Status Page**:  <https://simptel.statuspage.io/>

***

### 8. Security and Resilience

Simptel maintains a security and compliance framework aligned with industry standards, including:

* Multi-layer security controls for authentication, communications, and data protection
* Redundancy and failover for critical systems
* Regular security testing and vulnerability management
* 24/7 monitoring by the NOC

***

### 9. Updates

This SLA may be updated by Simptel from time to time.\
The latest version is always available at: <https://docs.simptel.com/legal/>


# Governing Law and Disputes

* **Governing Law**\
  All agreements, terms, policies, and related documents issued by Simptel, including but not limited to the Terms & Conditions, Privacy Policy, Data Processing Addendum (DPA), and Service Level Agreements (SLA), are governed by and construed in accordance with the laws of the Netherlands.
* **Jurisdiction**\
  Any dispute, claim, or controversy arising out of or in connection with these agreements or the use of Simptel’s services shall be submitted exclusively to the competent courts of **’s-Hertogenbosch, the Netherlands**.
* **Exclusion of Conflict Rules**\
  The applicability of conflict-of-law rules, including the United Nations Convention on Contracts for the International Sale of Goods (CISG), is expressly excluded.


# Professional services Addendum

This Professional Services Addendum (“Addendum”) forms an integral part of the applicable Terms of Service (“TOS”) and governs the provision of professional services by the Service Provider to the Client.

In the event of conflict between this Addendum and the TOS, this Addendum shall prevail with respect to Professional Services.

### 1. Definitions

Unless otherwise defined herein, capitalized terms shall have the meaning assigned in the TOS.

For purposes of this Addendum:

* **“Professional Services”** means consulting, advisory, technical, implementation, development, support, or other professional services as described in a Statement of Work (“SOW”).
* **“Deliverables”** means any tangible or intangible materials, reports, documentation, software configurations, or other outputs expressly defined in the applicable SOW.
* **“SOW” (Statement of Work)** means a written document describing scope, timelines, fees, assumptions, and deliverables.

### 2. Scope of Services

2.1 Professional Services shall be provided strictly in accordance with the applicable SOW.

2.2 Any modification to scope, deliverables, timelines, assumptions, or pricing must be agreed in writing via a change order signed by both Parties.

2.3 The Service Provider may utilize qualified subcontractors, provided that the Service Provider remains fully responsible for performance under the Agreement.

2.4 Services are provided on a best-efforts basis unless explicitly stated otherwise in the SOW.

### 3. Term and Completion

3.1 Each SOW shall specify its effective date and expected completion timeline.

3.2 Delays caused by the Client, including delayed approvals, access restrictions, or incomplete information, shall:

* extend delivery timelines accordingly; and
* entitle the Service Provider to reasonable additional compensation where applicable.

### 4. Fees and Payment

4.1 Fees shall be as stated in the applicable SOW and may be structured as:

* time and materials (hourly or daily rates),
* fixed price, or
* retainer-based.

4.2 Invoices shall be issued monthly in arrears unless otherwise agreed.

4.3 Payment is due within thirty (30) days from invoice date unless otherwise specified in the SOW.

4.4 Pre-approved travel and reasonable out-of-pocket expenses shall be reimbursed at cost.

4.5 Overdue amounts shall accrue statutory commercial interest in accordance with applicable law.

### 5. Client Obligations

The Client shall:

a) Provide timely access to relevant personnel, systems, information, and facilities;\
b) Ensure prompt internal decision-making and approvals;\
c) Provide accurate and complete information required for service delivery;\
d) Notify the Service Provider promptly of any identified deficiencies.

Failure to meet these obligations may impact timelines and cost.

### 6. Intellectual Property

6.1 Each Party retains ownership of its pre-existing intellectual property.

6.2 Subject to full payment of all fees due, Deliverables specifically created for the Client under the SOW shall become the property of the Client, unless otherwise agreed.

6.3 The Service Provider retains ownership of:

* underlying tools, frameworks, methodologies, know-how, and reusable components;
* general knowledge, skills, and experience acquired during performance.

6.4 To the extent Deliverables include Service Provider proprietary materials, the Client is granted a non-exclusive, perpetual license to use such materials solely for its internal business purposes.

### 7. Confidentiality

7.1 Each Party shall treat all non-public information disclosed in connection with the Professional Services as confidential.

7.2 Confidentiality obligations shall survive termination of the Agreement for a period of five (5) years, or longer where required by law.

7.3 Confidentiality obligations do not apply to information that:

* is publicly available without breach;
* was lawfully known prior to disclosure;
* is independently developed; or
* must be disclosed by law or court order.

### 8. Data Protection

8.1 Each Party shall comply with applicable data protection laws, including the General Data Protection Regulation (GDPR) where applicable.

8.2 Where personal data is processed on behalf of the Client, the Parties shall enter into a separate Data Processing Agreement (DPA).

8.3 The Service Provider shall implement appropriate technical and organizational safeguards.

### 9. Warranties

9.1 The Service Provider warrants that Professional Services shall be performed:

* with reasonable skill and care;
* in accordance with generally accepted industry standards.

9.2 Except as expressly stated, no guarantees are provided regarding specific business, financial, regulatory, or operational outcomes.

### 10. Limitation of Liability

10.1 Liability shall be governed by the TOS.

10.2 Unless otherwise specified in the TOS, aggregate liability relating to a specific SOW shall not exceed the total fees paid or payable under that SOW in the twelve (12) months preceding the claim.

10.3 Neither Party shall be liable for:

* indirect or consequential damages;
* loss of profits;
* loss of business opportunity;
* reputational damage.

10.4 Nothing limits liability for fraud, gross negligence, or wilful misconduct.

### 11. Acceptance of Deliverables

11.1 Deliverables shall be deemed accepted:

* upon written confirmation by the Client; or
* if no material deficiencies are reported within ten (10) business days of delivery.

11.2 The Service Provider shall remedy documented material deficiencies within a reasonable timeframe.

### 12. Termination

12.1 Termination shall be governed by the TOS unless otherwise stated in the SOW.

12.2 Upon termination:

* the Client shall pay for all Services performed up to the termination date;
* agreed minimum commitments remain payable;
* each Party shall return or destroy confidential information.

### 13. Governing Law

This Addendum shall be governed by the law specified in the TOS or applicable SOW.


# Service Specific Terms

DRAFT - WILL BE ACTIVE SOON

These Service-Specific Terms form an extension to the general Terms & Conditions of **Simptel Services B.V.**, Chamber of Commerce number **91391199**, Stadhuisplein 10, 5611 EM Eindhoven, The Netherlands (hereinafter referred to as the **Supplier**).

These Service-Specific Terms apply exclusively to the **European Identity Broker Console**. In the event of conflict, these Service-Specific Terms prevail only with respect to their subject matter. All other provisions of the general Terms & Conditions remain unchanged and fully applicable.

#### Definitions

**European Identity Broker Console**\
A standalone software-as-a-service solution used exclusively for the configuration, management, and monitoring of federated digital identity providers, including use within the Electronic Access Services framework (eTD) for eHerkenning and cross-border electronic identification under eIDAS, where the Supplier acts as a recognition broker (herkenningsmakelaar).

All other definitions are governed by the general Terms & Conditions.

#### Scope and Role

The Supplier acts as a herkenningsmakelaar and enables this role through the European Identity Broker Console, which functions solely as a technical broker and management console supporting eHerkenning and eIDAS authentication flows.

#### Applicable Framework

Where the European Identity Broker Console is used within the eTD framework for eHerkenning and/or under the eIDAS Regulation, the applicable governance, certification, and compliance rules of those frameworks apply.

#### Order of Precedence

In the event of inconsistency between contractual documents, the following order applies:

* Agreement or Order Form
* These Service-Specific Terms
* Service Level Agreement (if applicable)
* General Terms & Conditions

#### Commencement and Use

Access to the European Identity Broker Console commences on the date specified in the Agreement or, if none is specified, upon receipt of the first payment. The Customer is solely responsible for all configuration, integration, and usage decisions made using the European Identity Broker Console.

#### Termination

Upon termination of the Agreement, the Customer’s right to access and use the European Identity Broker Console terminates immediately. Obligations that by their nature survive termination remain in effect.

#### Installation, Integration, and Support

The Customer is solely responsible for installation, configuration, and integration of the European Identity Broker Console within its own IT environment.

Support is provided only during the term of the Agreement. Response times and service levels apply only if explicitly agreed in a Service Level Agreement. Any support provided by the Supplier does not transfer responsibility for Customer-side implementations.

#### Security

The Supplier applies appropriate technical and organisational security measures in line with industry standards. The Supplier maintains an **ISO/IEC 27001–certified information security management system** and has completed a **SOC 2 Type II audit** covering security, availability, and confidentiality controls. The European Identity Broker Console is hosted within the **European Economic Area**.

The Customer shall promptly notify the Supplier of any security incidents related to the use of the European Identity Broker Console.

#### Intellectual Property

All intellectual property rights relating to the European Identity Broker Console remain exclusively with the Supplier. The Customer receives a non-exclusive, non-transferable right of use for the duration of the Agreement. No intellectual property rights relating to identity means or third-party identity providers are transferred.

#### Customisation

The European Identity Broker Console is provided as a standard software-as-a-service offering. Any customisation requires explicit written agreement.

#### Liability

The Supplier’s total liability arising from or related to the European Identity Broker Console is limited to the fees paid by the Customer for the European Identity Broker Console in the twelve months preceding the event giving rise to the claim.

The Supplier is not liable for decisions or failures of eHerkenning or eIDAS identity providers, the legal validity or assurance levels of identity means, Customer configuration choices, or governance or supervisory decisions under eTD or eIDAS.

These limitations do not apply in cases of intent or gross negligence.

#### Force Majeure

Neither Party is liable for failure caused by force majeure, including third-party outages or government measures. If force majeure continues for more than ninety days, either Party may terminate the Agreement.

#### Confidentiality

Each Party shall keep confidential all information designated as confidential or reasonably understood to be confidential. Confidentiality obligations survive termination.

#### Breach

In the event of misuse of the European Identity Broker Console or infringement of intellectual property rights, the Customer shall notify the Supplier without undue delay and cooperate to prevent further harm.

#### Governing Law and Disputes

These Service-Specific Terms are governed exclusively by Dutch law. Parties shall attempt to resolve disputes amicably before initiating legal proceedings. Any dispute shall be submitted exclusively to the competent court of ’s-Hertogenbosch (Den Bosch), The Netherlands.


# Compliance Statement

Simptel shall implement and maintain appropriate technical and organizational measures designed to protect Customer Data against unauthorized or unlawful processing, loss, destruction, damage, alteration, or disclosure. Such measures shall be aligned with industry standards and applicable laws and regulations.

Simptel’s information security program is based on an established Information Security Management System (ISMS) and is aligned with recognized frameworks and standards, including but not limited to **ISO 27001:2022**, **SOC 2 Type II**, and the **General Data Protection Regulation (GDPR)**. Simptel shall maintain these controls and conduct periodic reviews, including independent third-party assessments where applicable.

Simptel employs industry-standard security practices, including but not limited to:

* Encryption of data in transit and at rest using strong, industry-accepted cryptographic standards;
* Strict access controls based on the principle of least privilege, including a **no standing access** approach, where elevated access is granted only when necessary, time-bound, and subject to approval and monitoring;
* Comprehensive insider risk management measures, including monitoring, logging, and controls designed to detect and prevent unauthorized or inappropriate access or use of systems and data;
* Network protection measures, including firewalls, traffic filtering, and denial-of-service mitigation controls;
* Continuous security monitoring and vulnerability management processes;
* Regular security testing and independent security assessments.

Simptel shall follow secure software development lifecycle (SSDLC) practices, including documented change management procedures, testing in non-production environments, and controlled deployment processes. Infrastructure changes shall be managed using infrastructure-as-code methodologies where applicable.

Simptel shall maintain business continuity and disaster recovery capabilities, including regular data backups and periodic testing of recovery procedures.

Simptel shall ensure that its personnel receive appropriate security awareness training and that access to systems and data is limited to authorized individuals with a legitimate business need.

Simptel may update its security measures from time to time, provided that such updates do not materially decrease the overall level of security of the Services.


# European Identity Broker Console

The European Identity Broker Console is a standalone service dedicated to the configuration, management, and monitoring of federated European digital identity providers.


# DigID

Coming soon

The European Identity Broker does not interfaces with the Dutch DigiD network to support national authentication for citizens. <br>


# eHerkenning

The European Identity Broker interfaces with the Dutch eHerkenning network to support national authentication for organizations. eHerkenning is a secure and reliable login method in the Netherlands that enables organizations to access online services on behalf of their organisation. \ <br>


# eIDAS

The European Identity Broker interfaces with the Dutch eIDAS node to support cross-border authentication. This enables nationals from different EU countries to log in using their own national digital identity systems. For example, German nationals can use their German login credentials to access a Dutch service.


