
BETWEEN THE UNDERSIGNED:
CYPHERLOCK INC., a cybersecurity consulting company, with its registered office located at 16192 Coastal Highway – Lewes – Delaware 19958 – Sussex County, registered under number 10096838, represented by Charly Prudent, duly authorized for the purposes hereof,
Hereinafter referred to as the “Service Provider” or “CYPHERLOCK”,
AND
[CLIENT COMPANY NAME], a [LEGAL FORM], with its registered office located at ___________________________, registered under number ______________, represented by _______________[REPRESENTATIVE NAME AND TITLE], duly authorized for the purposes hereof,
Hereinafter referred to as the “Client”,
The Service Provider and the Client being individually referred to as a “Party” and collectively as the “Parties”.
PREAMBLE
WHEREAS the Service Provider has recognized expertise in cybersecurity;
WHEREAS the Client wishes to benefit from the Service Provider’s services for the evaluation, improvement, and maintenance of its information system security;
WHEREAS the Service Provider is certified as a “CYBERSECURITY Analyst” and commits to complying with all applicable data protection regulations, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA);
THE PARTIES AGREE AS FOLLOWS:
ARTICLE 1: CONTRACT PURPOSE
This contract (hereinafter the “Contract”) aims to define the conditions under which the Service Provider will provide the Client with cybersecurity consulting services as detailed in Appendix 1 (hereinafter the “Services”).
ARTICLE 2: SERVICE DESCRIPTION
2.1 The Service Provider commits to providing the Client with the following Services, detailed in Appendix 1:
- Security audit and risk assessment
- Compliance with applicable standards and regulations
- Security incident management
- Personnel training and awareness
- Strategic cybersecurity consulting
2.2 Any service not expressly mentioned in Appendix 1 will be the subject of an amendment to this Contract or a separate contract.
ARTICLE 3: CONTRACT DURATION
3.1 This Contract takes effect upon signature by both Parties for an initial period of 12 months.
3.2 At the end of this initial period, the Contract will be automatically renewed for successive periods of the same duration, unless terminated by either Party with 3 months’ notice sent by email.
ARTICLE 4: FINANCIAL CONDITIONS
4.1 In consideration of the Services provided, the Client commits to paying the Service Provider the fees detailed in Appendix 2.
4.2 Invoices will be issued monthly and payable within 30 days of their issuance date.
4.3 Any payment delay will result in late payment penalties calculated based on an interest rate three times the legal interest rate in effect, plus a fixed recovery fee of 40 euros.
ARTICLE 5: SERVICE PROVIDER OBLIGATIONS
5.1 The Service Provider commits to:
- Execute the Services with diligence, professionalism, and in accordance with industry best practices
- Respect the schedule agreed upon by the Parties
- Assign qualified personnel to Service execution
- Guarantee the confidentiality of accessed information
- Comply with all applicable regulations, particularly those related to data protection
5.2 The Service Provider declares to have all necessary authorizations, certifications, and insurance for conducting its activities and executing the Services.
ARTICLE 6: CLIENT OBLIGATIONS
6.1 The Client commits to:
- Provide the Service Provider with all necessary information and documents for Service execution
- Designate a single point of contact for coordination with the Service Provider
- Allow the Service Provider access to information systems concerned by the Services
- Pay fees within the agreed timeframes
- Cooperate in good faith with the Service Provider
6.2 The Client acknowledges that the quality of Services partially depends on its active cooperation.
ARTICLE 7: PERSONAL DATA PROTECTION
7.1 In executing this Contract, each Party commits to respecting applicable personal data protection regulations, specifically the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
7.2 When the Service Provider acts as a processor under GDPR, the Parties commit to signing a specific data processing agreement compliant with Article 28 of the GDPR, to be annexed to this Contract (Appendix 3).
7.3 The Service Provider commits to:
- Process personal data only on documented Client instructions
- Guarantee personal data confidentiality
- Implement appropriate technical and organizational measures to ensure data security
- Help the Client respond to data subject rights requests
- Notify the Client of any personal data breach within 48 hours of discovery
7.4 The Client remains responsible for the accuracy and legality of personal data transmitted to the Service Provider.
ARTICLE 8-17: [Remaining articles remain substantially the same as in the original French document, translated to US English]
GOVERNING LAW AND JURISDICTION
17.1 This Contract is governed by United States law.
17.2 In the event of a dispute relating to the formation, interpretation, execution, or termination of this Contract, the Parties will endeavor to find an amicable solution.
17.3 In the absence of an amicable resolution within 60 days, the dispute will be submitted to the exclusive jurisdiction of the Delaware Court of Chancery in the United States.
Executed in ______, on _________, in two (2) original copies.
For CYPHERLOCK INC. [SIGNATORY NAME AND TITLE] Signature: ____________________
For [CLIENT COMPANY NAME] [SIGNATORY NAME AND TITLE] Signature: ____________________
APPENDIX 1: DETAILED SERVICE DESCRIPTION [TO BE DETAILED]
APPENDIX 2: FINANCIAL CONDITIONS [TO BE DETAILED]
APPENDIX 3: DATA PROCESSING AGREEMENT [TO BE INTEGRATED IN COMPLIANCE WITH ARTICLE 28 OF GDPR]
