This English version is a translation provided for your convenience. In the event of any discrepancy, the Polish version of these Terms of Service shall prevail and is legally binding.

Terms of Service for the Vendispace system

I. General provisions

The administrator of the service and the provider of the services is Nova-Vision Sp. z o.o., with its registered office in Warsaw, 00-687, ul. Wspólna 63B/2, entered in the KRS: 0000671851, NIP: 7010679178, REGON: 366943436, e-mail address: biuro@nova-vision.pl, hereinafter referred to as the "Vendispace" or the "Service Provider".

The user of the service is an entrepreneur (a natural person conducting business activity, a legal person or an organisational unit without legal personality), hereinafter referred to as the "Client".

Vendispace provides the service of access to a B2B system used to handle sales processes, made available in the SaaS (Software as a Service) model, hereinafter referred to as the "Service".

Acceptance of these Terms of Service by the Client is voluntary but necessary in order to use the system. Acceptance of the Terms of Service constitutes the moment of conclusion of the Agreement for the provision of Services on the terms set out therein.

II. Rules for using the Service and registration

Access to the Services is possible after the Client has created an account and after verification of the Client's company data (including the NIP number).

The Client undertakes to use the Services in accordance with the provisions of law, good practice and the intended purpose of the B2B system.

III. Service packages

Vendispace offers three main subscription packages:

  • FreeSpace — a free package. It covers the basic functions of the system for 1 user with a limit on the number of orders.
  • FullSpace — a paid subscription package. It covers the basic functions of the system with limitations: a maximum of up to 10 users and up to 100 orders per billing period.
  • ProfiSpace — a paid subscription package. No limitations as to the number of users or the number of processed orders.

Switching from the free package to a paid package is not automatic and requires the Client to make a payment for the selected paid package.

Switching from a paid package to the free package is not possible.

A detailed list of the functions available in the individual packages, information about the limitations and about the possibilities of discounts for paying for packages for longer periods can be found in the price list available on the Vendispace website and in the Client panel.

IV. Fees, renewal and suspension of access

The amount of the fees for the Paid Packages (FullSpace and ProfiSpace) and for additional services is set out in the current price list available on the Vendispace website and in the Client panel. All prices are net prices, to which VAT is added.

The billing period for subscription packages is 30 days.

The subscription package is renewed automatically for the next billing period after it has been paid by the Client or after the funds have been charged from the linked payment card.

A VAT invoice is issued after the payment has been booked and is available in the Client panel and in the KSeF system.

Failure to make payment within the required deadline results in the immediate and automatic blocking of (absence of) access to the Service for a grace period of up to a maximum of 30 days.

V. Deletion of the Client's database

In the event of non-payment and the blocking of access to the account, Vendispace stores the Client's data for a grace period of 30 calendar days.

If the Client does not settle the arrears within 30 days from the date on which access was blocked, the Client's database is irreversibly deleted (removed from the servers). Vendispace is not liable for damage resulting from the irretrievable loss of this data after the expiry of the grace period.

VI. Integrations and third-party services

The Vendispace platform enables integration with the systems of external providers in order to extend the functionality of the B2B system. This concerns in particular integration with:

  • online payment systems,
  • warehouse systems,
  • accounting services (e.g. automatic issuance of invoices),
  • courier and logistics services,
  • financial services (including payment financing / factoring / deferred payments for the Client's contractors).

Vendispace provides solely the technical infrastructure (plugins, API, integration modules) enabling the exchange of data with the above-mentioned systems.

Vendispace is not a party to the agreements between the Client and the external service providers and bears no liability whatsoever for the correct operation, availability, quality, financial settlements or legal consequences of the use of these external services. Their providers bear sole liability. Use of these integrations may require acceptance of the separate terms and conditions of the external entities.

VII. Additional paid services (prepaid and postpaid)

Vendispace may make available within the platform additional services that are not included in the standard price of the subscription packages.

An example of an additional paid service is the provision of an SMS gateway used for communication with and notification of the Client's contractors.

Additional services may be settled in the prepaid model (prepayment) or the postpaid model (payment after the service has been performed/delivered). In the case of prepaid services, the Client tops up the virtual balance of its account in Vendispace with a chosen amount, from which fees for actual usage are charged (e.g. for each SMS message sent in accordance with the price list).

In the event that the funds on the prepaid balance are exhausted (absence of funds), the provision of the given additional service is automatically suspended until the Client tops up the balance again.

VIII. Liability

Vendispace makes efforts to ensure that the Service is available 24 hours a day, 7 days a week. Vendispace does not, however, guarantee 100% availability. Vendispace is not liable for interruptions in the operation of the Service resulting from technical reasons, force majeure or the actions of third parties.

Vendispace is not liable for damage resulting from the improper use of the Service by the Client, nor for the loss of data caused by the actions of the Client or of third parties (subject to Chapter V point 2).

The total compensatory liability of Vendispace towards the Client on any account under the SaaS agreement (including for interruptions in access to the system) is limited to the amount actually paid by the Client for the current subscription package in the given 30-day billing period in which the damage occurred.

Vendispace is not liable for the Client's lost profits (lucrum cessans).

IX. Processing of personal data

The rules for entrusting the personal data of the Client and of the Client's contractors, which are entered into the Vendispace system, are governed by the Data Processing Agreement – DPA, constituting Appendix No. 1 to these Terms of Service as an integral part thereof.

X. Complaints

Complaints regarding the Service may be submitted electronically to the Vendispace e-mail address: biuro@nova-vision.pl.

A complaint should contain the Client's login, a description of the problem and the Client's request.

Vendispace examines complaints within 14 days of their receipt.

XI. Final provisions

Vendispace reserves the right to amend these Terms of Service. The amendments come into force on the day of their publication on the website, and Clients will be informed of material amendments by e-mail 14 days before their introduction. Continued use of the Service after the introduction of the amendments constitutes their acceptance.

In matters not regulated by these Terms of Service, the provisions of Polish law apply.

All disputes arising in connection with the Agreement for the provision of the Service shall be resolved by the court having jurisdiction over the registered office of Vendispace.


Appendix No. 1 — Personal data processing agreement

concluded between the Client, hereinafter referred to as the Controller, and Nova-Vision Sp. z o.o., with its registered office in Warsaw, 00-687, ul. Wspólna 63B/2, entered in the KRS: 0000671851, NIP: 7010679178, REGON: 366943436, hereinafter referred to as the Processor, with the following content:

§ 1 Entrustment of the processing of personal data

In connection with the performance of the agreement for the provision of services binding the Parties, the Controller – acting pursuant to Art. 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), hereinafter referred to as the "Regulation" – entrusts the Processor with the processing of personal data within the scope of the Services specified in the agreement.

The entrustment of the processing of personal data takes place for the categories of personal data and to the extent indicated in the Detailed description of the processed data, constituting appendix No. 1 to this Agreement.

The Controller declares that it is the controller of the entrusted personal data or is the Processor of this data to whom the controller of the personal data has entrusted the processing of personal data pursuant to Art. 28 of the General Regulation, and therefore declares that in each of the above-indicated cases it is authorised to entrust the processing thereof to the Processor.

The Controller declares that in the cases in which the Controller is not the controller of the data referred to in § 1 sec. 1, the controllers of this data have consented to the further entrustment of the processing of personal data by the Controller to the Processor.

The entrustment of the processing of personal data, in each of the cases indicated above, shall take place on the principles and conditions set out in this Agreement and in accordance with the provisions of the Regulation and other provisions of generally applicable law in the field of data processing.

§ 2 Obligations of the Processor relating to the performance of the Agreement

The Processor undertakes to process the personal data entrusted to it in accordance with this Agreement and with the provisions of generally applicable law that protect the rights of the data subjects.

The Processor undertakes, when processing the entrusted personal data, to secure it by applying appropriate technical and organisational measures ensuring an adequate degree of security corresponding to the risk associated with the processing of personal data, referred to in Art. 32 of the Regulation.

The Processor undertakes to exercise due diligence when processing the entrusted personal data.

The Processor is obliged to perform the above-mentioned obligations arising from the provisions of generally applicable law in the field of the protection of personal data solely to the extent adapted to the type of service provided by the Processor. The Controller is obliged to perform the remaining obligations arising from the provisions of generally applicable law in the field of the protection of personal data on its own.

The Processor undertakes to grant authorisations to process personal data to the persons who will process the entrusted data for the purpose of performing this agreement.

The Processor undertakes to ensure that the confidentiality referred to in Art. 28 sec. 3 point b of the Regulation of the processed data is maintained by the persons whom it authorises to process personal data for the purpose of performing this agreement, both during their employment with the Processor and after its termination. The performance of the above obligation shall be carried out in particular by obligating these persons to maintain confidentiality of the processed data and of all information concerning the manner of securing it.

In the event of establishing any situation constituting a breach of the security of the personal data entrusted for processing, the Processor, after establishing the breach of the protection of personal data, is obliged without undue delay to:

  • inform the Controller thereof no later than within 24 hours, providing all information concerning such a breach,
  • establish the cause of the breach,
  • immediately undertake all actions aimed at remedying the breach and duly securing the personal data against further breaches,
  • collect all possible data and documents that may help to establish the circumstances of the breach and to counteract similar breaches in the future, and for this purpose cooperate with the Controller at every stage of clarifying the matter.

As far as possible, the Processor assists the Controller, to the necessary extent, in fulfilling the obligation to respond to requests from the data subject and in fulfilling the obligations set out in Art. 32-36 of the Regulation.

The Processor shall promptly inform the Controller of requests under Art. 15-22 of the Regulation with which the persons whose personal data is concerned have addressed the Processor directly.

§ 3 Right of control

The Controller, in accordance with Art. 28 sec. 3 point h) of the Regulation, has the right to control whether the measures applied by the Processor in the processing and securing of the entrusted personal data fulfil the provisions of the agreement and the provisions of law, in particular the Regulation. The control may be carried out after prior notification of the control at least 3 working days before its commencement, or immediately in the event of a breach occurring.

The control may be carried out by persons designated by name by the Controller.

The Processor makes available to the Controller all information necessary to demonstrate compliance with the obligations set out in Art. 28 of the Regulation upon its written request.

§ 4 The Processor's use of sub-processors

The Parties agree that the Processor may use sub-processors in the process of processing personal data solely for the purpose of performing the Main Agreement.

The Controller confirms that in the cases in which the Controller is not the controller of the entrusted data, the controllers of the personal data have consented to any further entrustment.

The sub-processor referred to above should fulfil the same guarantees and obligations as have been imposed on the Processor in this Agreement and in the Main Agreement.

The processor bears full liability towards the Controller for its sub-processors.

§ 5 Duration of the entrustment Agreement

This Agreement is concluded for the duration of the Main Agreement. For the avoidance of doubt, the Parties agree that upon the termination or expiry of the Main Agreement, this Agreement shall terminate. This Agreement shall remain in force for the entire duration of the lawful entrustment of personal data for processing to the Processor by the Controller.

In the event of termination of the Main Agreement, the Processor has no right to further process the entrusted personal data and, subject to sec. 3, is obliged to permanently delete all remaining personal data and to delete all existing copies thereof, under pain of remedying all damage associated with a breach thereof.

Further processing of the personal data entrusted by the Controller is permissible solely to the extent arising from the applicable provisions of law.

§ 6 Liability

  1. The Processor is responsible for processing the personal data entrusted to it in accordance with the provisions of this Agreement and with the provisions of generally applicable law, in particular the Regulation.
  2. The Processor is responsible for making available or using the entrusted personal data in a manner inconsistent with the content of the agreement, and in particular for making the personal data entrusted for processing available to unauthorised persons.
  3. The Parties undertake to promptly inform each other of the submission by third parties of requests or of the initiation of proceedings, in particular administrative or judicial, concerning the processing of personal data specified in the agreement, of any administrative decision or ruling concerning the processing of this data, addressed to the Processor or the Controller. This section concerns solely the personal data entrusted to the Processor by the Controller.
  4. If a Party fails to perform or improperly performs the obligation arising from sec. 3, or if the performance of this obligation, for formal reasons (in particular as regards joining any proceedings pending in the matter or by reason of mandatory provisions of law), proves impossible or hindered, the other Party has the right to undertake all legally permissible actions in order to protect its interests.
  5. The Processor undertakes to promptly inform of the planned, insofar as they are known, or ongoing controls and inspections concerning the processing of personal data at the Processor by the supervisory authorities, and concerning the personal data entrusted to the Processor by the Controller.

§ 7 Confidentiality

Neither Party shall, without the consent of the other Party, disclose any information concerning the provisions of the Agreement, both as regards its conclusion and its performance, except in the cases:

  • where this is required under mandatory provisions of law and/or for the purposes of judicial proceedings,
  • where such information has been made publicly available by the other Party, of disclosure of the information to its employees and professional advisers where such necessity arises, and/or,
  • where the other party has consented to the disclosure of this information.

The information referred to above shall be treated as fully confidential and constituting a secret within the meaning of Art. 11 sec. 4 of the Act of 16 April 1993 on combating unfair competition.

§ 8 Final provisions

Any amendments to this Agreement require written form under pain of nullity, with the exception of a change in the address details or name of the Parties, which must be notified to the other Party in writing within 7 days from the date on which such a change occurred, under pain of the change being deemed ineffective.

The Controller may make contact on all matters relating to the protection of personal data by directing an enquiry to the e-mail address: biuro@nova-vision.pl

In matters not regulated in this Agreement, the provisions of generally applicable Polish law apply, in particular the Civil Code.

All disputes arising under the Agreement shall be resolved by the Court having jurisdiction over the branch of the Processor.

Appendix No. 1 to the personal data processing agreement — Detailed description of the data processing operations

This Appendix explains the subject matter, scope, nature and purpose of the data processing operations that are subject to the provisions contained herein. This Appendix constitutes an integral part of the Agreement.

Category and scope of the processed personal data. The personal data processed by the Processor concerns the Employees and clients of the Controller, to the extent of:

  • first name (first names), surname,
  • place of residence and correspondence address,
  • date of birth,
  • telephone number,
  • e-mail address.

Data processing operations. The personal data will be subject to the following processing operations:

  • collection,
  • storage,
  • disclosure by transmission,
  • deletion.

The Processor undertakes to process the Personal Data for the purpose of performing the subject matter of the Main Agreement.

Location of the processing of the Controller's Personal Data: a State of the European Economic Area.