ITHENA Logo

EULA Addendums

Supplements to the End User License Agreement and Privacy Policy

These Addendums supplement and are incorporated by reference into the ITHENA End User License Agreement (https://eula.ithena.io/) and Privacy Policy (https://privacy.ithena.io/). In the event of a conflict, the terms of the specific Addendum control with respect to the subject matter it addresses.

Addendum 01

Payment Processing

1. Definitions

1.1 Cardholder Data — Primary Account Number, Card Verification Value, expiration date, or similar payment card identifiers under PCI-DSS standards.

1.2 Payment Token — A surrogate value issued by a Payment Processor that replaces raw Cardholder Data for transaction processing without revealing the PAN or CVV.

1.3 Payment Processor — A third-party payment services provider integrated for processing payment card transactions.

1.4 Chargeback — A reversal, retrieval, or dispute of a payment card transaction by the cardholder, issuing bank, or Payment Processor.

1.5 Invoice — A transaction instruction from a Merchant/Client reflecting a sale of parts, goods, or services intended for payment processing.

1.6 PCI-DSS — The Payment Card Industry Data Security Standard, as updated from time to time.

1.7 Company Indemnitees — ITHENA, its affiliates, and their respective directors, officers, employees, contractors, representatives, and agents.

1.8 OEM — The original equipment manufacturer licensing or purchasing the Platform.

1.9 End Customer — Any customer of an OEM accessing or using the Platform to purchase parts or submit orders.

1.10 Merchant/Client — The OEM and, where applicable, its End Customers.

1.11 Platform — The hosted aftermarket e-commerce service provided by the Company.

2. Indemnification

2.1 Indemnification by OEM and End Customers. OEM and each End Customer (each an "Indemnifying Party") shall defend, indemnify, and hold harmless the Company Indemnitees from all losses, damages, liabilities, penalties, fines, costs, expenses, settlements, interest, judgments, and reasonable attorneys' fees ("Losses") arising from:

  1. Third-party claims regarding the OEM's or End Customer's collection, storage, or use of Cardholder Data, Payment Tokens, or Invoices; payment disputes, chargebacks, or refund obligations; or failure to comply with PCI-DSS or applicable law;
  2. Misuse of Payment Tokens or payment credentials by the OEM or End Customer;
  3. Breach by the OEM or End Customer of Agreement obligations or agreements with End Customers.

Exception: Indemnification does not apply to Losses arising solely from the Company's willful misconduct, gross negligence, or intentional fraud.

3. Limitation of Liability

3.1 Limitation on Damages. Company Indemnitees shall not be liable for direct, indirect, consequential, incidental, special, exemplary, or punitive damages, or lost profits, revenues, savings, business, goodwill, or data.

3.2 Aggregate Cap. The Company's total liability for all claims shall not exceed fees paid by the OEM during the preceding twelve (12) months.

3.3 Application. These limitations apply regardless of the theory of liability (breach of contract, warranty, tort, strict liability, or otherwise).

4. Data Security and Non-Use

4.1 Non-Handling of Cardholder Data. The Company does not request, collect, or transmit raw Cardholder Data, except information passed directly to the payment gateway. The Company never stores raw Cardholder Data. Payment processing (card entry, pre-authorization, authorization) is performed solely by the Payment Processor. The Company receives and stores only Payment Tokens returned by the Payment Processor.

4.2 Storage of Tokens. Payment Tokens are stored exclusively in secure, industry-recognized key management or cloud storage services (Microsoft Azure Key Vault, AWS KMS, Google Cloud KMS). Tokens are used solely for processing Invoices per OEM or End Customer instructions. The Company shall not use Payment Tokens for any other purpose.

4.3 Reliance on Third-Party Providers. OEM acknowledges that:

  1. the Payment Processor/Gateway (e.g., Stripe, PayPal, Moneris) is solely responsible for infrastructure, security, and PCI-DSS compliance regarding Cardholder Data;
  2. the key management or cloud storage provider (Microsoft, AWS, Google Cloud) is solely responsible for security, availability, and compliance; and
  3. the Company does not control third-party acts or omissions and shall not be liable except for the Company's willful misconduct or gross negligence.

4.4 OEM and End Customer Responsibilities. OEM and End Customers shall:

  1. comply with applicable laws, card-network rules, and PCI-DSS requirements;
  2. ensure only Payment Tokens (not raw Cardholder Data) are transmitted through the Platform;
  3. not misuse Payment Tokens or credentials; and
  4. be solely responsible for End Customer disputes, refunds, chargebacks, and Payment Processor compliance.

4.5 No Access to Cardholder Data. OEM and End Customers acknowledge the Company has no role in receiving raw Cardholder Data, and shall not attempt to cause the Platform to receive, access, or store raw Cardholder Data.

4.6 Notification. If unauthorized access to Cardholder Data, Payment Tokens, or credentials occurs, the OEM or End Customer shall immediately notify the Company and cooperate in good faith to contain and remediate.

Addendum 02

Security, Compliance & Data Governance

This Addendum describes the operational security controls, compliance posture, and data governance practices applicable to ITHENA-managed environments and the Platform.

1. Compliance Standards

StandardStatus
SOC 2 Type IICompleted
ISO 27001Aligned
GDPRReady — supports EU data subject rights and cross-border transfer safeguards
IEC 62443Aligned, for OT connectivity

ITHENA has completed a SOC 2 Type II audit covering access controls and audit logging. Copies of the SOC 2 report and other compliance documentation are available to customers under NDA upon request.

2. Operational Security

3. Deployment and Data Governance

4. GDPR and Data Protection

4.1 Roles. Where ITHENA processes personal data on behalf of a customer, ITHENA acts as a processor and the customer acts as controller, subject to a Data Processing Agreement ("DPA") available upon request.

4.2 Data subject rights. ITHENA supports customer fulfillment of data subject requests (access, rectification, erasure, restriction, portability, and objection) within the timeframes required by applicable law.

4.3 International transfers. Where personal data is transferred outside the EEA/UK, ITHENA relies on Standard Contractual Clauses or another lawful transfer mechanism.

4.4 Breach notification. ITHENA will notify affected customers without undue delay upon confirming a security incident involving personal data, and will cooperate on required regulatory notifications.

4.5 Sub-processors. ITHENA maintains a list of sub-processors used in delivering the Platform and will provide notice of material changes as required by the DPA.

For SOC 2 reports, DPAs, or other compliance documentation, contact ITHENA through your account representative or at the address listed in the EULA.