Master Services Agreement
Version 1.0 · Last updated: 20 July 2026
This agreement is under final legal review and may be updated before it is finalised. Customer-specific terms (the parties, fees, scope, data-residency region and governing law) are set out in the applicable Order Form.
These terms, together with the applicable Order Form and any Statement of Work, form the agreement between Cogent2 Limited ("Cogent²") and the customer identified in the Order Form (the "Customer").
1. Definitions
1.1 In these terms:
- "Cogent²" means Cogent2 Limited, company no. 15512532, registered office Appleton House, 25 Rectory Road, Nottingham NG2 6BE, the supplier and, for the Processing described here, the Processor.
- "Customer" means the customer identified in the applicable Order Form and, for the Processing described here, the Controller.
- "Agreement" means these terms, together with the applicable Order Forms and Statements of Work and the incorporated Annexes.
- "Data Protection Laws" means all laws applicable to the Processing for a given Customer, including the UK GDPR and the Data Protection Act 2018, the EU GDPR, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
- "Platform Services" means the Cogent² iPaaS and the EDI Service.
- "Cogent² iPaaS" means the integration platform service Cogent² provides using the Patchworks integration platform, which Cogent² licenses and resells under its own agreement with Patchworks.
- "EDI Service" means the electronic data interchange file-exchange service under which the Customer's trading partners and suppliers exchange files with the Customer through Amazon S3 storage operated by Cogent².
- "Professional Services" means the consulting, configuration, training and related expert services provided by Cogent² under a Statement of Work or Order Form.
- "Services" means the Platform Services and the Professional Services together.
- "Order Form" and "Statement of Work" mean the ordering documents executed by the parties that reference these terms and set out the Services purchased, the Scope and the Charges.
- "Scope" means the usage limits and restrictions for the Platform Services (including transaction or operation volumes) set out in the Order Form.
- "Initial Term", "Renewal Period" and "Service Term" have the meanings given in clause 10.1.
- "Customer Materials" means the data, content, files, credentials, configurations, flows, connectors, instructions and other materials the Customer or its users provide to, create within, or make available through, the Services.
- "Analytics Data" means aggregated, anonymised data derived from operation of the Services that does not identify the Customer or any Data Subject.
- "Prohibited Data" has the meaning in clause 2.7.
- "Sub-processor" means any third party engaged by Cogent² to Process Personal Data on the Customer's behalf, as listed in Annex 3.
- "Restricted Transfer" means a transfer of Personal Data to a country outside the UK, or (where the EU GDPR applies) outside the EEA, that is not covered by UK adequacy regulations or an adequacy decision under Article 45 EU GDPR; and, for an Australian Customer, a cross-border disclosure of personal information under Australian Privacy Principle 8.
- "UK IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
- "EU SCCs" means the standard contractual clauses for the transfer of personal data to third countries under the EU GDPR (Commission Implementing Decision (EU) 2021/914).
- "UK Addendum" means the UK Addendum to the EU SCCs issued by the UK Information Commissioner.
- "UK GDPR", "EU GDPR", "Controller", "Processor", "Personal Data", "Processing", "Personal Data Breach" and "Data Subject" have the meanings given in the applicable Data Protection Laws. For an Australian Customer, references to Personal Data, Data Subject and Personal Data Breach are read as personal information, individual and eligible data breach (Privacy Act 1988) respectively, and a notification under clause 6.1 is a superset that the Customer assesses against the serious-harm threshold for its Notifiable Data Breaches obligations.
- "Charges" means the fees payable by the Customer to Cogent² under the Order Form or Statement of Work.
- "affiliate" means an entity that controls, is controlled by, or is under common control with a party, where control means holding more than 50% of the voting rights or the power to direct the entity's affairs.
- "business day" means a day other than a Saturday, Sunday or public holiday in England.
2. Roles, scope and Customer data
2.1 For the Personal Data Processed under the Services (both the Platform Services and the Professional Services), the Customer is the Controller and Cogent² is the Processor. Where Cogent² engages a Sub-processor, that Sub-processor acts as a sub-processor of Cogent².
2.2 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are in Annex 1. The specific Services, Scope and Charges are in the applicable Order Form or Statement of Work.
2.3 Cogent² will Process Personal Data only on the Customer's documented instructions, including with regard to transfers of Personal Data to a third country or international organisation (see clause 5), unless required to do otherwise by a law that applies to Cogent², in which case Cogent² will inform the Customer before Processing, unless that law prohibits informing the Customer on important grounds of public interest.
2.4 Cogent² will inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws. Cogent² is not obliged to carry out a legal review of the Customer's instructions.
2.5 The Customer warrants that it has a lawful basis for the Processing, that it has all rights and consents to transfer the Personal Data to Cogent² and the Sub-processors, and that its instructions comply with Data Protection Laws. The Customer is responsible for the accuracy, quality and legality of the Customer Materials.
2.6 Independent-controller purposes and Analytics Data. Cogent² acts as an independent controller only for limited purposes ancillary to the Services: billing and account administration; security, fraud and abuse monitoring; and compliance with its own legal obligations. Cogent² may create and use Analytics Data to operate, secure, benchmark and improve the Services, consistent with the data minimisation in Annex 2 (schema types only, never values). As between the parties, Cogent² owns the Analytics Data. Where the CCPA/CPRA applies, Cogent² will maintain the processes required to treat Analytics Data as deidentified and will not attempt to reidentify it. Cogent² does not otherwise Process the Customer's Personal Data for its own purposes.
2.7 Prohibited Data. The Customer will not submit to the Services any of the following ("Prohibited Data"): (a) health or medical information; (b) government-issued identifiers (for example social security, passport or driver's licence numbers); (c) financial account numbers or payment-card data subject to the PCI DSS; (d) biometric data; (e) special-category data under the UK or EU GDPR; or (f) any unlawful data or data the Customer has no right to submit. Cogent² may, without liability, delete, quarantine or decline to process Prohibited Data it identifies, and will notify the Customer. Inadvertent inclusion of Prohibited Data that the Customer remediates promptly on notice is not a material breach. The iPaaS redaction pipeline (Annex 2) is designed to strip PII-shaped fields but is not a guarantee, and the Customer remains responsible for keeping Prohibited Data out of the Services, in particular out of EDI files, which are stored whole (clause 3.7) and retained under clause 5.6.
2.8 If Cogent² receives a request, objection or complaint directly from a Data Subject (or, for an Australian Customer, an individual) relating to the Customer's Personal Data, Cogent² will not respond substantively except on the Customer's documented instruction, and will forward it to the Customer without undue delay.
3. Cogent² obligations, warranties and IP
3.1 Confidentiality. Cogent² will ensure that persons authorised to Process the Personal Data are bound by confidentiality obligations.
3.2 Security. Cogent² will implement and maintain the measures in Annex 2, appropriate to the risk under Article 32 UK GDPR and the equivalent security obligation under the other applicable Data Protection Laws.
3.3 Assistance. Taking into account the nature of the Processing, Cogent² will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject rights requests, and will assist the Customer with security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to Cogent².
3.4 Records. Cogent² will maintain records of Processing carried out on the Customer's behalf as required by Article 30(2) UK GDPR.
3.5 Deletion and return. On termination of the relevant Service, Cogent² will, at the Customer's choice, delete or return the Personal Data Processed under that Service and delete existing copies within 30 days, unless retention is required by law, and will certify deletion in writing on request. Around termination, Cogent² will also, on request, return the Customer's data in a commonly used format and provide reasonable transition assistance (free of charge for a reasonable period, and thereafter at Cogent²'s standard rates). EDI-specific timing is in clause 5.6 and Annex 1.
3.6 Audit and information. Cogent² will make available information reasonably necessary to demonstrate compliance with Article 28 UK GDPR, and will allow for and contribute to audits, subject to reasonable notice, frequency limits and confidentiality. Each party bears its own costs for one audit in any 12-month period (which Cogent² may satisfy with a recognised third-party certification or report where it reasonably addresses the request); the Customer bears Cogent²'s reasonable additional costs for any further audit in that period. A for-cause audit following a Personal Data Breach caused by Cogent² is at Cogent²'s cost.
3.7 No payload persistence (iPaaS). For the Cogent² iPaaS, raw Customer payload data is not persisted: incoming payloads pass through a redaction pipeline that removes credential-shaped and PII-shaped fields before any storage, schema observation captures data types only and never values, and content sent to the AI Sub-processor is redacted on the same basis. This payload firewall applies to the Cogent² iPaaS. EDI files are necessarily stored whole in Amazon S3 for validation, translation and delivery, and are protected by encryption, access control and the 30-day rolling deletion in clause 5.6 rather than by redaction. Detail is in Annex 2.
3.8 Platform warranty and remedy. Cogent² warrants that during the term the Platform Services will perform materially in accordance with their description. Cogent² does not warrant that they will be error-free or uninterrupted, will work with all systems, or will meet the Customer's individual requirements. In respect of the resold Patchworks platform, this warranty is back-to-back with, and no greater than, the warranty Patchworks gives Cogent² (clause 4.6). If Cogent² breaches this warranty, its sole liability and the Customer's exclusive remedy is that Cogent² will use reasonable efforts to correct or replace the affected Platform Services or, failing that, terminate them and refund Charges paid in advance for the terminated part.
3.9 Professional Services warranty. Cogent² warrants that it will provide the Professional Services with reasonable skill and care and in accordance with good industry practice. If Cogent² breaches this warranty and the Customer notifies it within 30 days of the affected Professional Services being performed, Cogent²'s sole liability and the Customer's exclusive remedy is that Cogent² will re-perform the affected Professional Services or, if it cannot reasonably do so, refund the Charges paid for them.
3.10 Disclaimer. To the maximum extent permitted by law, the express warranties in these terms are the only warranties given, in place of all other representations, warranties and conditions, express, implied or statutory, including implied terms as to satisfactory quality, merchantability, fitness for a particular purpose and non-infringement, all of which are disclaimed.
3.11 Intellectual property (Professional Services). Cogent² retains all right, title and interest in its pre-existing materials, methods, know-how, tools, templates and generic and reusable components. The Customer-specific configurations, flows and connectors built for the Customer under a Statement of Work are Customer Materials owned by the Customer; Cogent² owns the other deliverables. On payment for the relevant Professional Services, Cogent² grants the Customer a non-exclusive, perpetual, irrevocable, worldwide, royalty-free licence to use those other deliverables for its business purposes, extending to the Customer's affiliates and successors in title and to third parties operating or maintaining the deliverables on the Customer's behalf. Cogent²'s retained right to reuse covers only generic, non-customer-specific methods, know-how and components, and never the Customer's confidential data or business rules. An Order Form or Statement of Work may vary this position.
3.12 Ownership. As between the parties, Cogent² owns all right, title and interest (including intellectual property rights) in the Platform Services, the EDI Service, and Cogent²'s software, systems and tools. The Customer owns the Customer Materials. Cogent² may use Analytics Data as set out in clause 2.6. Any feedback, suggestions or ideas the Customer or its users provide about the Services are given freely, and Cogent² may use and incorporate them without restriction or obligation, with no rights accruing to the Customer in the Services as a result.
4. Sub-processors and resale of the integration platform
4.1 The Customer gives Cogent² general written authorisation to engage the Sub-processors in Annex 3, which as at the date of these terms are:
- (a) Railway Corp. for application and compute hosting (EU region);
- (b) Supabase, Inc. for managed database and authentication (EU region);
- (c) Amazon Web Services for object storage supporting the EDI Service (EU region) and supporting cloud infrastructure;
- (d) Patchworks Media Ltd as the integration platform underlying the Cogent² iPaaS, which Cogent² resells to the Customer under its PoweredBy reseller plan and for which Cogent² is the Customer's sole contractual counterparty;
- (e) Anthropic, PBC (United States) for AI model processing powering Cogent² AI features; and
- (f) Resend, Inc. (United States) for transactional email delivery.
4.2 Cogent² additionally notifies the Customer that Voyage AI, Inc. (United States) is a built but currently disabled Sub-processor for text-embedding (semantic search). Cogent² will not activate it for the Customer's Personal Data until the safeguards in clause 5 are in place, and will treat activation as a change under clause 4.4.
4.3 Cogent² has entered into, and will maintain, written contracts with each Sub-processor imposing data-protection obligations that meet the requirements of Article 28 (including the Annex 2 security measures and an obligation to notify Cogent² of a Personal Data Breach without undue delay). Cogent² remains fully liable to the Customer for the performance of each Sub-processor's data-protection obligations, as required by Article 28(4) UK GDPR. The monetary amount recoverable is subject to clause 7. Patchworks' Processing is governed by the Patchworks DPA, which flows down Article 28, commits Patchworks to notify Cogent² of a Personal Data Breach without undue delay, deletes or returns data within 30 days of termination, uses the EU SCCs and UK IDTA for transfers, and under which Patchworks maintains ISO 27001 and SOC 2. Patchworks engages its own sub-processors under that DPA.
4.4 Changes. Cogent² will give at least 30 days' prior notice of any intended addition or replacement of a Sub-processor. The Customer may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected Service, as its sole remedy, on notice.
4.5 The Customer's own connected systems (including its Shopify store, ERP, warehouse and supplier systems, and any source systems it connects through the Cogent² iPaaS) are not Sub-processors of Cogent². The Customer is the Controller for those systems and is responsible for its own arrangements with their providers.
4.6 Back-to-back resale. The Cogent² iPaaS is delivered using the Patchworks platform, which Cogent² licenses and resells under its own agreement with Patchworks. Cogent² is the Customer's sole contractual counterparty for the Cogent² iPaaS and Patchworks is not a party to these terms. Cogent²'s commercial obligations, warranties and liability for the functioning of the Patchworks platform are back-to-back with, and no greater than, the corresponding rights and remedies Cogent² has against Patchworks. This clause does not limit, and is subject to, Cogent²'s obligations and liability as Processor under clauses 2 to 6 and Article 28 (including Article 28(4)), which remain in full force. Cogent² is not in breach where Patchworks modifies, replaces or ends-of-life a platform feature, provided Cogent² passes on any reasonable notice it receives; but where such a change materially and adversely affects the Platform Services for a continuous period of 30 days and Cogent² cannot provide a reasonable equivalent, the Customer may terminate the affected Platform Service on notice as its sole remedy, and Cogent² will refund Charges paid in advance for the terminated part. Cogent² is likewise not in breach where Patchworks suspends, or requires Cogent² to suspend, the platform for a reason not caused by the Customer, provided Cogent² passes on any notice it receives; the same limited remedy applies if such a suspension continues for a continuous period of 30 days.
4.7 Pass-through obligations. The Customer will comply with Patchworks' acceptable-use and usage-scope requirements as passed through and made available by Cogent² (incorporated by reference; Cogent² will provide the current version on request; material changes take effect on reasonable notice, and if a material change adversely affects the Customer it may terminate the affected Platform Service on notice), including transaction and operation volume limits, the prohibitions on reverse engineering and on building a competing product, and the Prohibited Data restrictions. Use in excess of the Scope may incur overage Charges. The parties intend that Patchworks (as the entity named in clause 4.1(d)) may enforce this clause 4.7 in its own right under the Contracts (Rights of Third Parties) Act 1999, and no other person has such a right; for an Order Form governed by EU member-state or Australian law, a jurisdiction-appropriate equivalent applies instead.
5. International transfers and applicable regime
5.1 Cogent² will not make a Restricted Transfer of the Customer's Personal Data except in accordance with this clause 5.
5.2 Where Cogent² makes a Restricted Transfer, it will ensure an appropriate transfer mechanism is in place, being either (a) an adequacy basis where available (including, for a US Sub-processor certified under the EU-US Data Privacy Framework and its UK Extension, that framework); or (b) the UK IDTA, or the EU Standard Contractual Clauses together with the UK Addendum, as provided by the relevant Sub-processor; together with any supplementary measures identified by a transfer risk assessment. Regime-specific detail is in clause 5.8 and Annex 4.
5.3 Cogent² will carry out, document and keep under review a transfer risk assessment for its transfers to the US Sub-processors, taking into account the redaction and data-minimisation measures in Annex 2, which reduce the Personal Data exposed in those transfers.
5.4 Cogent² is established in the United Kingdom, so under Article 3(1) UK GDPR the UK GDPR applies to Cogent²'s Processing under these terms regardless of where the Data Subjects are located. Where the Customer or its Data Subjects are in the EEA, the EU GDPR applies; where in Australia, the Australian Privacy Act 1988 (Cth) applies. A transfer of Personal Data into the UK or EEA is not a Restricted Transfer. Where the EU GDPR applies and the United Kingdom ceases to benefit from an EU adequacy decision, Cogent² will, on the Customer's request, enter into the EU Standard Contractual Clauses (as data importer) to cover the transfer of Personal Data from the Customer to Cogent². Onward transfers by Cogent² to Sub-processors outside the UK or EEA are subject to clauses 5.2 and 5.8.
5.5 EDI Service region. The EDI Service stores files in Amazon S3 in the AWS EU region (for example London, eu-west-2, or Ireland, eu-west-1, as stated in the Order Form). Cogent² does not routinely transfer Personal Data in EDI files outside the UK or EEA in the course of the EDI Service. Any out-of-region access by AWS (for example support access from the United States) is covered by the mechanism in clause 5.2 and the AWS DPA. Delivery of files to, or receipt from, the Customer's trading partners located outside the UK or EEA is a transfer for which the Customer is responsible as Controller. If the Customer requires a specific data-residency region, Cogent² may host the EDI bucket in that region on notice, in which case clause 5.2 applies to any transfer out of the UK or EEA.
5.6 EDI retention and deletion. EDI files are retained for 30 days on a rolling basis and then automatically deleted. On termination of the EDI Service, Cogent² will delete all of the Customer's EDI files within 30 days and, on request, certify the deletion in writing.
5.7 US Sub-processors. Cogent²'s transfers of Personal Data to Anthropic, PBC and Resend, Inc. in the United States are Restricted Transfers, made under the mechanism in clause 5.2. Railway Corp. and Supabase, Inc. host in the EU region but are US-incorporated; any out-of-region support access by them is likewise covered by clause 5.2, consistent with Annex 3. Cogent² will make available, on request, the relevant transfer documentation for each such Sub-processor.
5.8 Regime-specific mechanisms. (a) UK: UK IDTA or UK Addendum to the EU SCCs, or adequacy where available. (b) EU: EU SCCs, or adequacy where available. (c) Australia: for a cross-border disclosure under Australian Privacy Principle 8, Cogent² will take reasonable steps to ensure overseas recipients handle the information consistently with the Australian Privacy Principles, including by binding contractual commitments; the Customer remains accountable under APP 8.1. (d) United States: where the Customer or its Processing is subject to the CCPA or CPRA, the service-provider terms in Annex 5 apply, under which Cogent² acts as a "service provider" or "contractor", Processes the Personal Data only for the business purpose of providing the Services, and will not sell or share it or retain, use or disclose it outside the direct business relationship or as otherwise prohibited by the CCPA.
6. Personal Data Breach
6.1 Cogent² will notify the Customer of a Personal Data Breach affecting the Customer's Personal Data without undue delay and, where feasible, no later than 72 hours after Cogent² becomes aware of it. That period runs from Cogent²'s awareness, not from the occurrence of the breach.
6.2 The notification will describe, to the extent known and as it becomes available: the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Cogent² may provide information in phases.
6.3 Cogent² will require each Sub-processor, including Patchworks and AWS, to notify Cogent² of a Personal Data Breach without undue delay after becoming aware, and will use reasonable efforts to secure a notification target of 24 hours where the Sub-processor's contract permits. A Sub-processor's notification time affects only when Cogent² becomes aware; Cogent²'s obligation under clause 6.1 is always measured from Cogent²'s own awareness.
6.4 Cogent² will assist the Customer in meeting the Customer's own breach-notification and communication obligations to the competent supervisory authority (the ICO in the UK; the competent supervisory authority in the EU, being the lead supervisory authority where the one-stop-shop applies; the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme; or the relevant US authority) and to affected Data Subjects, taking into account the nature of the Processing and the information available to Cogent².
6.5 A notification of a breach is not an acknowledgement of fault or liability.
7. Liability
7.1 Liability cap. Subject to clauses 7.3 and 7.4, Cogent²'s total aggregate liability arising out of or in connection with these terms and the Services, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the greater of (a) 100% of the Charges paid by the Customer under the Agreement in the 12 months immediately preceding the date of the first event giving rise to the claim (or, for a series of connected events, the first such event) and (b) the total annual Charges for the Services under the applicable Order Form. This is a single, shared cap across the Platform Services and the Professional Services.
7.2 Scope of the cap. The cap in clause 7.1 is a single aggregate cap that applies to all claims under or in connection with the Agreement, including claims arising from a breach of Data Protection Laws or a Personal Data Breach, subject only to the exclusions in clause 7.3.
7.3 Nothing in these terms limits or excludes: (a) either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded by law; (b) the Customer's liability for breach of clause 2.5, for its submission of Prohibited Data (clause 2.7, other than inadvertent submission that the Customer remediates promptly on notice), or for breach of the pass-through obligations in clause 4.7; (c) the Customer's obligation to pay the Charges; or (d) the Customer's indemnity in clause 7.7. Cogent²'s own indemnities, including clause 7.9, remain subject to the cap in clause 7.1.
7.4 Subject to clause 7.3, neither party is liable for (a) indirect, consequential, special, punitive or exemplary loss or damage, or (b) loss of profit, revenue, business, anticipated savings, goodwill, or wasted expenditure, in each case whether direct or indirect. Neither party is liable for loss of or damage to data, except that Cogent²'s liability to the Customer for loss of the Customer's data is limited to the reasonable direct costs of restoring that data from Cogent²'s back-ups or, where the data cannot reasonably be restored from those back-ups, to the Customer's direct loss, in each case subject always to the cap in clause 7.1.
7.5 Services exclusions. Cogent² has no liability for: (a) errors or omissions in Customer Materials or any data or instructions the Customer provides; (b) flows, connectors or configurations built by the Customer or a third party on its behalf; (c) actions Cogent² takes at the Customer's direction; (d) acts or omissions of third parties, including the Customer's connected source systems and the connections the Customer configures to them; or (e) any third-party product or service the Customer accesses or connects to through the Services, or the Customer's breach of a third party's terms. Nothing in this clause 7.5 reduces Cogent²'s liability for its Sub-processors under clause 4.3 and Article 28(4) UK GDPR.
7.6 The parties acknowledge that Cogent²'s recoveries from its Sub-processors, including Patchworks and AWS, are themselves capped under Cogent²'s agreements with them. For a claim that is not a data-protection claim and that arises from a Sub-processor's act or omission, Cogent²'s liability to the Customer is further limited to the amount Cogent² actually recovers from the relevant Sub-processor, subject always to clause 7.1. This further limitation does not apply to data-protection claims, for which Cogent² remains fully liable under clause 4.3 and Article 28(4) UK GDPR, subject always to the cap in clause 7.1.
7.7 Customer indemnity. The Customer will indemnify Cogent² against third-party claims, and related losses and reasonable costs, arising from (a) the Customer Materials, including any claim that they infringe a third party's rights; (b) the Customer's breach of clause 2.7 (Prohibited Data), other than inadvertent submission remediated promptly on notice, or clause 4.7 (pass-through obligations); (c) the Customer's unlawful or non-compliant Processing instructions; or (d) the Customer's gross negligence or wilful misconduct. The indemnity is conditional on Cogent²: (i) promptly notifying the Customer in writing of the claim; (ii) not admitting liability or settling without the Customer's prior written consent, not to be unreasonably withheld; (iii) giving the Customer conduct of, or the right to participate in, the defence; and (iv) providing reasonable cooperation at the Customer's cost.
7.8 Each party must take reasonable steps to mitigate its loss, and a party's liability is reduced to the extent the other party's acts or omissions caused or contributed to the loss.
7.9 Cogent² IP indemnity. Cogent² will defend the Customer against third-party claims that the EDI Service or a Professional Services deliverable (excluding the resold Patchworks platform, the Customer Materials, and anything Cogent² provides at the Customer's direction) infringes that third party's intellectual property rights, and will indemnify the Customer for amounts awarded or agreed in settlement, subject to the cap in clause 7.1 (which includes Cogent²'s defence and settlement costs) and to standard exclusions (Customer Materials, Customer modifications, unauthorised combinations, and use contrary to these terms). If a deliverable is, or in Cogent²'s reasonable opinion may be, held to infringe, Cogent² may at its option (i) obtain the right for the Customer to continue using it, (ii) modify or replace it so it is non-infringing, or (iii) refund the Charges paid for it and terminate it. Cogent² has control of the defence and settlement, and the Customer will give prompt notice and reasonable cooperation. For the resold Patchworks platform, Cogent² will pass through to the Customer the benefit of the intellectual-property indemnity that Patchworks gives Cogent², will pursue that indemnity on the Customer's behalf, and will stand behind it up to the cap in clause 7.1. This is Cogent²'s sole liability and the Customer's exclusive remedy for intellectual property infringement.
7.10 Insurance. Cogent² will maintain, with reputable insurers: professional-indemnity insurance of not less than £1,000,000; public and products liability insurance of not less than £2,000,000; employers' liability insurance as required by law; and cyber and data-liability insurance appropriate to the nature and volume of the Processing under the Agreement, at the level stated in the Order Form. Cogent² will provide evidence of that cover on the Customer's reasonable request.
8. The Services and Support
8.1 Grant. Subject to these terms, the applicable Order Form and payment of the Charges, Cogent² grants the Customer a non-exclusive, non-transferable, non-sublicensable right during the Service Term to access and use the Platform Services for its business purposes, within the Scope set out in the Order Form.
8.2 Cogent² iPaaS. The Cogent² iPaaS is delivered by reselling the Patchworks platform on a back-to-back basis (clauses 4.6 and 4.7).
8.3 EDI Service. Cogent² operates the EDI file-exchange service on Amazon S3 (clauses 5.5 and 5.6).
8.4 Professional Services. Professional Services are ordered under an Order Form or Statement of Work that sets out the services, timetable, dependencies and fees. They are provided on a time-and-materials basis unless the Statement of Work states a fixed fee, with reasonable skill and care (clause 3.9), and the intellectual-property position in clause 3.11 applies.
8.5 Support. Cogent² will provide the support level stated in the Order Form using commercially reasonable efforts. Cogent² may modify, replace or end-of-life features of the Platform Services on reasonable prior notice, subject to clause 4.6 for the resold Patchworks platform.
8.6 Availability and service levels. Cogent² targets availability of 99.9% per calendar month for the Platform Services, measured excluding scheduled maintenance notified in advance and events outside Cogent²'s reasonable control. For the resold Patchworks platform this target and its service-credit remedy are provided on a back-to-back basis with the service levels Patchworks provides to Cogent². If availability falls below the target in a month, the Customer's remedy is the service credits stated in the Order Form, which are the Customer's sole financial remedy for a failure to meet the availability target. If availability falls below 99.0% in each of three consecutive months, the Customer may terminate the affected Platform Service on notice.
9. Fees, overages, payment and taxes
9.1 Charges. The Customer will pay the Charges set out in the Order Form or Statement of Work. Subscription and managed-service Charges are payable in advance (monthly or annually as stated in the Order Form). Professional Services are invoiced monthly in arrears on a time-and-materials basis, unless a Statement of Work states a fixed fee and milestones.
9.2 Overages. If the Customer's use exceeds the Scope (including any operation or transaction volume in the Order Form), Cogent² may charge overage fees at the rate in the Order Form or, if none is stated, at Cogent²'s then-current standard overage rate notified to the Customer, invoiced monthly in arrears. Cogent² may also charge for, throttle, or decline to process, use above the Scope.
9.3 Changes to Charges. Cogent² may increase the Charges with effect from a Renewal Period by giving at least 30 days' written notice before the renewal date. Unless the Order Form states otherwise, a single increase will not exceed 5% of the then-current Charges.
9.4 Payment. Unless the Order Form states otherwise, invoices are payable within 30 days of the invoice date, in the currency and by the method in the Order Form, in full and without deduction or set-off.
9.5 Late payment. Overdue amounts that are not the subject of a bona fide dispute accrue interest at 8% per annum above the Bank of England base rate, from the due date until paid, and Cogent² may recover the reasonable costs of collection. The parties agree this is a substantial contractual remedy for the purposes of the Late Payment of Commercial Debts (Interest) Act 1998.
9.6 Taxes. All Charges are exclusive of VAT, GST and other applicable taxes, which the Customer will pay. The Customer will provide any VAT or GST registration details Cogent² reasonably requests. If law requires the Customer to withhold or deduct tax from a payment, the Customer will increase the payment so that Cogent² receives the full amount due, and the parties will cooperate to reduce or reclaim the withholding under any applicable double-tax treaty.
9.7 Non-cancellable. Except as expressly stated in the Agreement, Charges are non-cancellable and amounts paid are non-refundable.
10. Term, renewal, suspension and termination
10.1 Term and renewal. The Agreement starts on the Order Form start date and continues for the initial term stated in the Order Form (the "Initial Term"). It then renews automatically for successive periods of 12 months (or the period stated in the Order Form) (each a "Renewal Period", and together with the Initial Term the "Service Term"), unless either party gives at least 30 days' written notice of non-renewal before the end of the then-current term.
10.2 Termination for cause. Either party may terminate the Agreement (or the affected Order Form) on written notice if the other: materially breaches and, where the breach is capable of remedy, fails to remedy it within 30 days of notice (non-payment being a material breach); or becomes insolvent, enters an insolvency process, or is unable to pay its debts as they fall due. Cogent² may also terminate the Agreement (or the affected Order Form) immediately on written notice, without a cure period, if the Customer submits Prohibited Data (other than an inadvertent submission remediated promptly on notice), uses the Services fraudulently or unlawfully, or breaches clause 11.4 (sanctions and export control).
10.3 Suspension. Cogent² may suspend the Customer's access to the Services, on reasonable notice (or immediately where a security threat, legal requirement or emergency makes notice impractical), for: non-payment of undisputed Charges more than 30 days overdue; a security threat or risk of harm to the Services; compliance with law or a competent authority; breach of clause 11 (acceptable use); or where Patchworks suspends, restricts or requires Cogent² to suspend the underlying platform (with the effect in clause 4.6 where the suspension is not caused by the Customer). Charges continue to accrue during a suspension caused by the Customer's non-payment or breach.
10.4 Effect of termination. On termination or expiry: the Customer's rights to use the Services end and it will stop using them; the Customer will pay all Charges due up to termination and, where Cogent² terminates for the Customer's material breach or insolvency, the Charges for the remainder of the then-current Service Term of the terminated Order Forms; and each party will return or destroy the other's confidential materials. Cogent² will delete or return Personal Data under clause 3.5 and EDI files under clause 5.6.
10.5 Survival. Clauses which by their nature are intended to survive termination survive it, including clauses 3.5, 3.10, 3.11, 3.12, 5.6, 7 (liability), 9, 11, 12, and the data-protection and confidentiality obligations.
11. Acceptable use and Customer obligations
11.1 Acceptable use. The Customer will not, and will ensure its users will not: (a) exceed the Scope; (b) reverse engineer, decompile, copy or create derivative works of the Platform Services or the underlying Cogent² or Patchworks software; (c) resell, sublicense, rent or make the Services available to a third party except as expressly permitted; (d) use the Services to build a competing product or service; (e) use the Services unlawfully, to infringe third-party rights, or to transmit malware; or (f) submit Prohibited Data (clause 2.7). The Customer will comply with the Patchworks pass-through requirements in clause 4.7.
11.2 Authorised users. The Customer is responsible for its authorised users' compliance and for their acts and omissions as if its own, and for safeguarding all credentials and API keys. The Customer will notify Cogent² promptly of any unauthorised use.
11.3 Customer obligations. The Customer will provide the access, information, materials, credentials and cooperation Cogent² reasonably needs to provide the Services, maintain its own systems and connectivity, and comply with applicable law. Cogent² is not responsible for any delay or failure caused by the Customer's failure to meet these obligations, and the Customer's connected systems are its responsibility (clauses 4.5 and 7.5).
11.4 Sanctions and export control. The Customer represents and undertakes that it, its affiliates and its authorised users are not, and are not owned or controlled by or acting on behalf of, a person subject to UK, EU, US or United Nations sanctions or named on a denied-party or restricted-party list, and that it will comply with applicable sanctions, anti-bribery and export-control laws in its use of the Services. Breach of this clause 11.4 is a material breach that is not capable of remedy.
12. General
12.1 Governing law. These terms and any dispute or claim arising out of or in connection with them are governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales, unless the applicable Order Form specifies a different governing law and forum for a given Customer (for example an EU member state or Australia) where required. The applicable Data Protection Laws for a given Customer, and their interaction with the chosen governing law, are set out in Annex 4 and, where applicable, the Order Form.
12.2 Confidentiality. Each party will keep the other's confidential information confidential and use it only to perform the Agreement, using at least reasonable care, except for information that is or becomes public (other than through breach), is independently developed, or is lawfully received from a third party, or where disclosure is required by law. This clause survives for 5 years after termination, and for trade secrets for as long as they remain trade secrets.
12.3 Assignment. The Customer may not assign or transfer the Agreement without Cogent²'s prior written consent (not to be unreasonably withheld). Cogent² may assign or transfer to an affiliate or in connection with a merger, acquisition or sale of the relevant business, on notice.
12.4 Subcontracting. Cogent² may subcontract its obligations but remains responsible for its subcontractors' performance. Sub-processors that Process Personal Data are engaged under clause 4.
12.5 Force majeure. Except for payment obligations, neither party is liable for any delay or failure caused by events beyond its reasonable control. If such an event continues for more than 30 days, the other party may terminate the affected Services on notice.
12.6 Notices. Notices must be in writing to the contact details in the Order Form (email accepted), and are deemed given on delivery or, for email, one business day after sending.
12.7 Waiver. A waiver is effective only in writing; rights under the Agreement are cumulative and do not exclude rights available at law.
12.8 Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary to be enforceable, and the remainder will continue in effect.
12.9 Third-party rights. Except for Patchworks' right to enforce clause 4.7, no one other than the parties has any right under the Contracts (Rights of Third Parties) Act 1999 to enforce the Agreement.
12.10 Entire agreement and precedence. The Agreement (these terms, the Order Forms and Statements of Work, and the incorporated annexes) is the entire agreement between the parties and supersedes prior discussions, and prevails over any terms the Customer issues (including purchase-order terms). In the event of conflict, the order of precedence is: the terms in a section of the Order Form or Statement of Work headed "Special Terms"; these terms; the annexes; then the remainder of the Order Form or Statement of Work. An express provision of these terms that applies "unless the Order Form states otherwise" is given effect by the relevant Order Form field regardless of this order. The separate Cogent² Data Processing Agreement, where provided to the Customer, restates the data-protection terms in clauses 2 to 6 and is to be read consistently with them; in the event of conflict on a data-protection matter, these terms and their annexes prevail.
12.11 Variation. The Agreement may be varied only in writing signed by both parties, except that Cogent² may update operational policies and documentation on reasonable notice where the change does not materially reduce the Services or the Customer's rights.
12.12 Relationship and non-solicitation. The parties are independent contractors. During the Service Term and for 12 months afterwards, neither party will knowingly solicit the other's personnel introduced under the Agreement, excluding responses to general advertising.
12.13 Marketing. Cogent² may name the Customer as a client and describe the engagement in marketing materials only with the Customer's prior written consent (email sufficient).
12.14 Equitable relief. Each party acknowledges that a breach or threatened breach of the confidentiality obligations, the intellectual-property provisions or clause 11 (acceptable use) may cause irreparable harm for which damages alone would be an inadequate remedy. Either party may therefore seek injunctive or other equitable relief for such a breach, without needing to post a bond or other security or to prove actual damage, in addition to any other remedy available at law.
12.15 Escalation. Before starting court proceedings (other than for non-payment or to seek urgent injunctive or equitable relief), the parties will refer the dispute to a senior representative of each, who will attempt in good faith to resolve it within 30 days. This clause does not prevent a party from applying to a court at any time to protect its rights.
Annex 1: Details of Processing
Subject matter and duration: Processing of Personal Data for the provision of the Services for the term of the Agreement, plus the retention periods below.
Nature and purpose:
- Cogent² iPaaS (Patchworks resale): orchestration, mapping and transfer of data between the Customer's connected systems, and Cogent²'s monitoring, diagnosis and AI-assisted support of those integrations.
- EDI Service: receipt, validation, cleaning, translation and delivery of EDI and flat files between the Customer's trading partners and the Customer's systems, via Amazon S3.
- Professional Services: Personal Data incidentally accessed while delivering consulting, configuration and training under a Statement of Work.
Types of Personal Data: names, business and delivery contact details, email addresses, postal addresses and telephone numbers, order and transaction data, and any Personal Data incidentally contained in files or payloads exchanged, excluding Prohibited Data. Cogent²'s redaction pipeline minimises persisted iPaaS data (Annex 2); EDI files are stored whole for up to 30 days.
Categories of Data Subjects: the Customer's end customers, the Customer's suppliers and trading-partner contacts, and the Customer's personnel who use the Services.
Retention: operational metadata for the term; EDI files for 30 days rolling; deletion or return on termination per clauses 3.5 and 5.6.
Annex 2: Technical and organisational measures
- Data minimisation and payload firewall (iPaaS). For the Cogent² iPaaS, raw Customer payload data is not persisted: a redaction pipeline removes credential-shaped and PII-shaped fields before storage; schema observation captures data types only, never values; content sent to the AI Sub-processor is redacted on the same basis; and payloads are truncated before any write. EDI files are stored whole in S3 (clause 3.7) and are protected by measures 2 to 8 below plus the 30-day deletion in clause 5.6.
- Encryption in transit and at rest. Data is transmitted over TLS. Sensitive credentials, including per-account integration keys, are encrypted at rest using authenticated encryption with managed key rotation.
- Access control. Role-based access control with least-privilege roles, tenant isolation and enforced account scoping so one customer account cannot access another's data. Administrative access is restricted and, where enabled, protected by multi-factor authentication.
- Hosting. Application and database hosting in the EU region (Railway, Supabase); EDI object storage in the AWS EU region.
- Logging and monitoring. Operational logging and monitoring, with alerting on integration failures and suspect data.
- Resilience. Back-ups of platform data and documented recovery processes, with target recovery point and recovery time objectives available on request.
- Sub-processor controls. Contractual data-protection terms with all Sub-processors under clause 4.3.
- Testing. Security and cross-account access testing as part of the development lifecycle.
Annex 3: Approved Sub-processors
| Sub-processor (legal entity) | Service provided | Location | Transfer safeguard |
|---|---|---|---|
| Railway Corp. | Application and compute hosting | EU region | In-region; UK IDTA / DPA for out-of-region support |
| Supabase, Inc. | Managed Postgres database and authentication | EU region | In-region; UK IDTA / DPA for out-of-region support |
| Amazon Web Services | S3 object storage for the EDI Service and infrastructure | EU region | In-region; AWS DPA plus UK IDTA / SCCs for out-of-region access |
| Patchworks Media Ltd | White-label integration platform underlying Cogent² iPaaS; ISO 27001 + SOC 2; engages its own sub-processors under the Patchworks DPA | United Kingdom | Patchworks DPA; UK IDTA / SCCs for any onward transfer |
| Anthropic, PBC | AI model processing (redacted content) | United States | Adequacy (EU-US DPF / UK Extension) if certified, else UK IDTA or SCCs plus UK Addendum, with transfer risk assessment |
| Resend, Inc. | Transactional email delivery | United States | Adequacy (EU-US DPF / UK Extension) if certified, else UK IDTA or SCCs plus UK Addendum, with transfer risk assessment |
| Voyage AI, Inc. (built, not active) | Text embeddings for semantic search | United States | Mechanism confirmed before activation |
Annex 4: Jurisdiction and data-protection regime matrix
| Customer region | Applicable data-protection law | Onward-transfer mechanism (to US sub-processors) | Breach regulator | Governing-law default |
|---|---|---|---|---|
| United Kingdom | UK GDPR + Data Protection Act 2018 | UK IDTA or UK Addendum to EU SCCs, or adequacy (DPF / UK data bridge) if certified | ICO | England and Wales |
| European Union / EEA | EU GDPR | EU SCCs, or adequacy (EU-US DPF) if certified | Competent / lead EU supervisory authority | England and Wales, or member-state law if required |
| Australia | Privacy Act 1988 (Cth) + Australian Privacy Principles | APP 8 reasonable steps plus binding contractual commitments | OAIC (Notifiable Data Breaches scheme) | England and Wales, or Australian law if required |
| United States | CCPA / CPRA (service-provider terms, Annex 5) | Intra-US; UK IDTA for the UK-established Processor's onward transfers | State attorney general / CPPA | England and Wales, or US state law if required |
Annex 5: US (CCPA/CPRA) service-provider terms
This Annex applies where the Customer or its Processing is subject to the CCPA or CPRA. Terms used here have the meanings given in the CCPA/CPRA.
- Roles. The Customer is a "business" and Cogent² is a "service provider" (or "contractor"). Cogent² Processes personal information only to provide the Services (the business purpose) under the Agreement.
- No sale or share. Cogent² will not sell or share the personal information.
- Purpose limitation. Cogent² will not retain, use or disclose the personal information for any purpose other than the specified business purposes, including outside the direct business relationship, or as otherwise permitted by the CCPA.
- No combining. Cogent² will not combine the personal information with personal information from other sources, except as permitted by the CCPA for a service provider.
- Equivalent protection. Cogent² will comply with its applicable obligations under the CCPA/CPRA and provide the same level of privacy protection as required of the business.
- Business rights. The Customer may take reasonable and appropriate steps to ensure Cogent² uses the personal information consistently with the Customer's CCPA obligations, and to stop and remediate unauthorised use.
- Notice. Cogent² will notify the Customer if it determines it can no longer meet its obligations under the CCPA/CPRA.
- Consumer requests. Cogent² will reasonably assist the Customer to respond to verifiable consumer requests (access, deletion, correction, opt-out).
- Deletion. On the Customer's instruction, Cogent² will delete personal information, subject to legal retention.
- Sub-processors. Cogent² will engage sub-processors only under a written contract requiring the same level of protection, and will flow down these obligations.
- Certification. Cogent² certifies that it understands the restrictions in this Annex and will comply with them.