MASTER SAAS AGREEMENT
The Johnson Controls Master SaaS Agreement (this “MSA”) governs your use of the Services made available to you under this Agreement. This Agreement is a binding legal contract between you or the entity on whose behalf you accept this Agreement ("you" and "your") and the Johnson Controls affiliate offering the applicable Service ("JCI", "we", or "us"). JCI and Customer are each individually a “Party” hereunder or, collectively, the “Parties” hereunder. Defined Terms used but not defined in this MSA have the meaning set forth in Section 14.
By entering into an Order or by receiving, accessing or using the Services, you agree that you have read, understand, and agree to be bound by this Agreement, as amended from time to time. If you do not or cannot agree to be bound by this Agreement, you may not receive, access or use the Services. If you are accessing or using the Services on behalf of a person or an organization, you are agreeing to this Agreement for that person or organization and representing to JCI that you have the authority to bind that person or organization to this Agreement.
-
Orders; Affiliates. JCI will provide the SaaS Services and the Installation Services in accordance with an applicable Order. Nothing in this MSA will obligate a Party to enter into any Order. JCI (or any JCI Affiliate) may enter into an Order with Customer (or any Customer Affiliate). By such Affiliate entering into an Order, that Affiliate agrees to be bound by the terms of this Agreement as if it were an original party hereto, and for purposes of such Order, shall also be deemed “Customer” or “JCI” hereunder, as applicable. Unless stated otherwise on an Order, Customer and its Affiliates who sign Orders under this Agreement shall be deemed jointly liable for a breach of this Agreement.
-
SaaS Services.
-
Use Rights. Subject to Customer’s compliance with the terms of this Agreement, Customer may access and use the SaaS Services for its internal business purposes only, subject to restrictions set forth in the Documentation and the Order. The SaaS Services includes access to JCI’s then-current generally available documentation for use and operation of the SaaS Service (the “Documentation”).
-
Authorized Users. Customer will only permit the maximum number of individuals identified on the Order to be Authorized Users. Each user name and password ("Access Credentials") for the SaaS Services may not be used by more than one Authorized User. Customer will ensure the security and confidentiality of Access Credentials and is responsible for all activities performed in the SaaS Services with such Access Credentials. Customer is responsible for breach of this Agreement by its Authorized Users.
-
Updates; Fixes. JCI may, at any time and in its sole discretion modify, update, or release a Fix for the SaaS Services. JCI may withdraw a SaaS Service on six months’ notice. JCI will continue to provide the withdrawn SaaS Service for the remainder of Customer’s subscription term or work to migrate Customer to another generally available JCI SaaS Service offering.
-
Suspension. JCI may suspend or limit use of the SaaS Services if Customer is in breach of its payment obligations hereunder and has not cured such breach within 10 days of notice or if JCI reasonably believes that: : (I) it is necessary to prevent unauthorized access to the SaaS Services, (ii) Customer’s continued use would result in a security risk or other material harm to the SaaS Services or its users; (iii) Customer’s use is prohibited by applicable law, rule or regulation or Customer is violating the Agreement. JCI will promptly notify Customer of the suspension or limitation.
-
SaaS IP; Subscription. JCI does not transfer any ownership rights to the SaaS Services, and, except for the limited use rights and other terms expressly set forth in this Section 2, all right, title and interest in and to the intellectual property in the SaaS Servies will remain the property of JCI. To the extent permitted by applicable law, SaaS Services purchased hereunder are non-cancelable, and the sums paid nonrefundable and, unless otherwise set forth in the applicable Order, such subscriptions shall such subscriptions shall commence on the date a customer tenant is provisioned for installation and configuration.
-
Third Party Materials and Web Services. Separate license terms apply to third party open-source technology used in the SaaS Services (“OSS”). Where required, JCI provides attribution for the OSS distributed with SaaS Services in accordance with the applicable open source license(s). The SaaS Service may include integrations with web services made available by third parties (other than JCI and its affiliates) that are accessed through the SaaS Service and subject to terms and conditions with those third parties. These third party web services are not part of the SaaS Service and this Agreement does cover those third party products.
-
Service Levels; Ancillary Hardware. JCI shall provide the support and other service levels for the applicable SaaS Services as set forth at https://www.johnsoncontrols.com/legal/digital/sla. The SaaS Services may require the installation of ancillary hardware or virtualized hardware on customer premises or systems (“Ancillary Hardware”). Such hardware is provided on the hardware terms set forth at http://www.johnsoncontrols.com/legal/digital/hardware_terms. If Customer elects to purchase the Hardware-as-a-Service subscription, then such hardware is provided on the HaaS Terms set forth at https://www.johnsoncontrols.com/legal/digital/haas-terms.
-
AI Terms. Products that include or use artificial intelligence are covered by our https://www.johnsoncontrols.com/legal/digital/aiterms (“AI Terms”) and https://www.johnsoncontrols.com/legal/digital/aicoc (“AI Code of Conduct”).
-
Supplemental Terms. Service specific, supplemental terms governing particular Services are set forth at www.johnsoncontrols.com/techterms (the “Supplemental Terms”). Applicable Supplemental Terms are incorporated by reference in this Agreement.
-
-
Installation Services.
-
Independent Work. All rights, title, and interest in technology, inventions, know-how, computer code or other materials or intellectual property developed or otherwise obtained by or for the Parties or their Affiliates prior to the Effective Date or independent of the Agreement (“Independent Work”) are and shall remain the sole property of the Party developing such Independent Work. During the performance of Installation Services, if Customer provides Independent Work for the purpose of the Order, then Customer grants to JCI a non-exclusive license to use, reproduce and modify any of Customer’s Independent Work provided to JCI, solely as needed to perform its obligations in connection with the Installation Services.
-
Developments. All rights in any technology, inventions, know-how, research, computer code, or other materials, any and all improvements to the foregoing, and all intellectual property rights in and to each of the foregoing developed by JCI hereunder (the “Developments”), other than the Confidential Information of Customer and other than as specifically set forth in an Order, is and shall remain the property of JCI. Upon payment in full, JCI grants to Customer (i) a non-exclusive, worldwide, perpetual license to use the Deliverables for Customer’s internal business purposes, and (ii) a limited, revocable, non-exclusive license to use any Developments or JCI Independent Works solely to the extent included in a Deliverable, solely as embodied in the Deliverable, for the sole purpose of utilizing such Deliverable in connection with the SaaS Service for which such Deliverable was provided for Customer’s internal business purposes. All rights not expressly granted to Customer herein are reserved to JCI.
-
Schedule. JCI will commence the Installation Services in accordance with the applicable Order. JCI will use commercially reasonable efforts to meet any performance dates specified in the Order. JCI will have no obligation to perform the Installation Services until Customer has: (i) provided JCI access to the required site, networks and systems; (ii) provided JCI required data and building information, BIM Files, utilities information; and (iii) fulfilled any other prerequisites or conditions identified in the Order.
-
Delays and Impacts; Force Majeure. If JCI is delayed, impacted, or interfered with in the commencement, performance, or completion of the Installation Services by causes beyond its control, including, but not limited to, inability to access property; a Force Majeure Event; failure by Customer or those under the control of Customer to perform their obligations; or failure by Customer or those under the control of Customer to cooperate with JCI in the timely completion of the Installation Services, JCI will provide notice to Customer of the existence of such delays or impacts. Under such circumstances, JCI will be entitled to a Change Order setting forth an equitable adjustment in the time for performance, price for the Installation Services, and any other provisions of this Agreement so impacted. Neither Party will be liable for a delay or inability to fulfill its obligations under this Agreement due to a Force Majeure Event.
-
Changes. The Parties may request changes to the Installation Services, including additions, deletions, or other revisions to the price, time for performance or other provisions of an Order (a “Change Order”). Except where a party is specifically entitled to a Change Order under this Agreement, any Change Order shall be agreed to in writing signed by an authorized representative of each Party.
-
-
Customer Restrictions.
Unless expressly permitted, Customer will not:. Unless expressly permitted in an Order or in a separate written agreement signed by an authorized representative of each Party, Customer will not: (i) access or use the Services or the Deliverables for any purpose, other than as expressly permitted by this Agreement; (ii) transfer, sell, sublicense, service bureau, distribute, or make the SaaS Services functionality available to any third party; (iii) create derivative works, reverse engineer, decompile, decrypt, disassemble, or modify any SaaS Service or related software, unless permitted by law or open source license; (iv) reference or use SaaS Services to develop competing offerings; (v) remove any copyright, trademark, proprietary rights, disclaimer, or warning notice included on or embedded in any part of the Documentation or SaaS Services; (vi) bypass, breach, or disable any security measures used in the SaaS Service or Deliverable; (vii) jeopardize service security or interfere with another customer’s service usage; (viii) submit data to the SaaS Service that is not contemplated in the Documentation; or (ix) facilitate an attack on or disruption of the SaaS Services, including DDOS attack, unauthorized access, penetration testing, distribution of viruses or other malware. Customer will promptly notify JCI in writing of any unauthorized use of the SaaS Services and provide cooperation related thereto.
-
Prices; Payment.
-
Customer will pay all fees set forth in an Order within 30 days of the date of invoice, unless the Order provides otherwise, and Fees for SaaS Services will be invoiced annually in advance, invoiced on the subscription start date and each subsequent anniversary thereof. JCI may charge separately, and Customer will pay for reasonable out of pocket expenses, such as travel, incurred in providing the Installation Services. Unless otherwise set forth in an Order, any renewal of SaaS Services will be at the then-applicable JCI list price. JCI’s fees exclude any taxes, duties, tariffs, levies or other governmental charges (including, without limitation, any value added taxes), which, if applicable, will be billed to and paid by Customer. JCI is responsible for taxes based upon its personal property ownership and net income. Customer remains obligated to pay JCI for tax withheld until Customer provides to JCI the official receipt and other documents reasonably requested. JCI may, at its option, assess a finance charge of the lesser of 1.5% per month, accrued, calculated and payable monthly, or the highest amount allowed by law, on all past due amounts due to JCI, and Customer shall be responsible for any amounts incurred by JCI for collection of such past due amounts. JCI will have no obligation to continue to provide Services if Customer fails to make timely payment.
-
-
Confidentiality.
-
Obligations. In connection with this Agreement, a Party may disclose its Confidential Information to the other Party. Each Party will disclose only information that is required for the performance of obligations under the Agreement. Each Party will not (i) use the other party’s Confidential Information for other than fulfilling its obligations or exercising its rights under this Agreement or (ii) disclose the other Party’s Confidential Information to any third party other than those set forth in the following sentence. Each party may disclose the other Party’s Confidential Information only to those employees or agents or subcontractors who are required to protect it against unauthorized disclosure on terms consistent with this Agreement.
-
Permitted Disclosures. Notwithstanding the foregoing subsection, each Party may disclose the other Party’s Confidential Information if required to comply with a court order or other government demand that has the force of law. Before doing so, each Party will (to the extent permitted by law) give the other Party enough prior notice to provide a reasonable chance to seek a protective order.
-
-
Customer Data; Security; Feedback.
-
Customer Data. As between the Parties, Customer owns all Customer Data and all intellectual property rights therein, subject to the limited license set forth herein. Customer grants to JCI and its affiliates a non-exclusive, worldwide, sublicensable, perpetual, paid-up right and license to use the Customer Data to provide, maintain, protect, and improve the SaaS Services and to improve and develop our products and services. Notwithstanding the other terms in this Agreement, JCI may use or disclose De-Identified Data for any purpose. "De-Identified Data" means Customer Data that does not identify Customer or any users directly or by inference.
-
Personal Data. Any Customer Data that is personal information will be processed by JCI in accordance with either (i) JCI’s Data Processing Addendum set forth at https://www.johnsoncontrols.com/trust-center/privacy/global-privacy-notice/johnson-controls-data-processing-addendum to the extent that JCI factually acts as processor or (ii) the Johnson Controls Privacy Notice at https://www.johnsoncontrols.com/trust-center/privacy, to the extent that JCI factually acts as controller (for example for business contact and other contract administrative info such as names, email, invoicing contact information).
-
Security. JCI maintains a written information security program under which JCI implements and maintains physical, administrative and technical safeguards designed to protect the confidentiality, integrity, availability and security of its SaaS Services and Customer Data as set forth on Schedule 1 – Security Addendum (the “Security Standards”). JCI may modify the Security Standards from time to time but will continue to provide at least the same level of security as is described in the Security Standards on the Effective Date. Customer is responsible for providing security and redundancy for Customer’s systems, networks, data and information.
-
Feedback. Customer hereby grants to JCI a nonexclusive, worldwide, perpetual, irrevocable, transferable, sublicensable, royalty-free, fully paid-up license to use, disclose and otherwise exploit any comments, suggestions or feedback regarding JCI’s business, products or Services (“Feedback”).
-
-
Non-JCI Software and Technology. Customer is solely responsible for any non-JCI software or technology that it installs or uses with the SaaS Services or the Deliverables. JCI is not a Party to and is not bound by any terms governing Customer's use of such non-JCI software or technology. If Customer installs or uses any non-JCI software or technology with the SaaS Services or the Deliverables, it will not do so in any way that would subject JCI's intellectual property or any of its technology to obligations beyond those included in the Agreement.
-
Warranties.
-
Mutual Warranty. Each Party warrants and covenants that it will respectively perform and use the Services in compliance with applicable laws.
-
Customer Warranties. Customer warrants and covenants to JCI that: (i) Customer has the necessary rights in the Customer Data to provide it and all other such data and information to JCI as set forth in this Agreement and to receive the Services; (ii) all Customer Data and other data and information provided by or for Customer to JCI will be reliable and accurate such that JCI can rely on such information without further investigation; (iii) Customer has the necessary rights, including any required consents, to grant JCI access to Customer’s networks and systems as contemplated by this Agreement; and (iv) without first providing written notice to JCI and receiving JCI’s prior written consent to do so, Customer will not transmit, disclose, or make available Sensitive Personal Data to JCI or JCI’s third party providers.
-
JCI Warranties.
-
SaaS Services. JCI warrants that the SaaS Services will perform substantially in conformance with the Documentation throughout the term of the SaaS Services subscription. JCI's sole obligation and Customer's sole and exclusive remedy for breach of the foregoing warranty shall be to use reasonable endeavors to remedy the breach or provide a workaround as set forth in the applicable Service Level Agreement set forth at https://www.johnsoncontrols.com/legal/digital/sla.
-
Installation Services. JCI warrants that it will perform the Installation Services in a professional and workmanlike manner. Customer must notify JCI of a warranty claim within 90 days from the date of delivery of a Deliverable, unless otherwise stated in an Order. This limited warranty does not cover problems caused by accident, abuse or use in a manner inconsistent with this Agreement or resulting from events beyond JCI’s reasonable control. To the extent permitted by law, Customer’s sole and exclusive remedy and JCI’s sole liability under or in connection with this warranty will be, at JCI’s option, reperformance of the specific Installation Service or Deliverable, or a termination of the applicable Installation Service and a refund of the price paid for the applicable specific Installation Service or Deliverable.
-
-
Disclaimer. EXCEPT FOR THE EXPRESS WARRANTIES SPECIFICED IN THIS SECTION, JCI MAKES NO WARRANTIES HEREUNDER AND EXPRESSLY DISCLAIMS AND EXCLUDES ALL OTHER WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, INCLUDING WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY, TITLE, NON-INFRINGEMENT, FITNESS FOR A PARTICULAR PURPOSE, USE AND WARRANTIES IMPLIED FROM A COURSE OF DEALING OR PERFORMANCE OR USAGE OF TRADE OR THAT THE SERVICES WILL BE UNINTERRUPTED, SECURE OR ERROR-FREE. ANY WARRANTIES, GUARANTEES, OR CONDITIONS THAT CANNOT BE DISCLAIMED AS A MATTER OF LAW LAST FOR 1 YEAR FROM THE START OF THE LIMITED WARRANTY.
-
-
Limitation of Liability. NOTWITHSTANDING ANYTHING TO THE CONTRARY AND TO THE FULLEST EXTENT PERMITTED BY LAW, IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER PARTY FOR OR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, SPECIAL, PUNITIVE OR EXEMPLARY DAMAGES OF ANY KIND OR NATURE, LOST PROFITS, REVENUES, DATA, CUSTOMER OPPORTUNITIES, BUSINESS, ANTICIPATED SAVINGS, OR GOODWILL, IRRESPECTIVE OF CAUSE OR ORIGIN, ARISING DIRECTLY OR INDIRECTLY OUT OF THIS AGREEMENT, , REGARDLESS OF WHETHER ENTITLEMENT TO SUCH DAMAGES IS BASED ON TORT, CONTRACT, OR ANY OTHER LEGAL THEORY AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. NOTWITHSTANDING ANYTHING TO THE CONTRARY, THE ENTIRE AGGREGATE LIABILITY OF EITHER PARTY UNDER THIS AGREEMENT, WHETHER ARISING OUT OF OR RELATED TO BREACH OF CONTRACT, TORT, OR OTHERWISE, WILL BE LIMITED TO THE LESSER OF (i) 250,000 USD OR (ii) THE FEES PAID BY CUSTOMER UNDER THIS AGREEMENT IN THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE DATE ON WHICH THE FIRST CLAIM ARISES. The foregoing limitations will not apply to: (a) Customer’s indemnification obligations under Section 11(c); (b) Customer’s payment obligations; or (c) either Party’s liability for third-party claims to the extent such liability cannot be limited under applicable law. This limitation of liability is single aggregate cumulative cap and not per claim instance and/or occurrence basis. The fees, disclaimers and limitations of liability set forth in this Agreement are essential components of this Agreement and form the basis for determining the price charged for the Services; and JCI would not enter into this Agreement without these limitations on its liability. These limitations will apply notwithstanding any failure of essential purpose of any limited remedy.
-
Third Party Claims.
-
JCI’s Indemnification Obligations. JCI will defend Customer against any unaffiliated third party claim, action, proceeding or suit (each a “Claim”), and will pay for the resulting costs and damages finally awarded against Customer to such third party by a court of competent jurisdiction or agreed to in settlement by JCI to the extent arising from the infringement of an intellectual property right of that third party by the Deliverables or arising from a Customer’s use of the SaaS Services in accordance with this Agreement. JCI will have no indemnification obligations arising from this Section to the extent such liability arises from: (1) modification or alteration of the SaaS Services or Deliverables by anyone other than JCI; (2) the use or combination of the SaaS Services or Deliverables with any hardware, software, products, information, data, or other materials not provided by JCI (3) Customer’s misuse of the SaaS Services or Deliverables; (4) use of infringing aspects of the SaaS Service or Deliverables after JCI has provided a non-infringing alternative or after JCI has terminated Customer’s rights to use the applicable Deliverable; or (5) compliance with Customer’s designs, specification or instructions (collectively, the “Excluded Claims”). If the SaaS Service or Deliverable becomes, or in JCI’s reasonable opinion is likely to become, the subject of an infringement claim, JCI may, at its option and expense, either: (i) procure for Customer the right to continue using the allegedly infringing item; or (ii) replace or modify the allegedly infringing item so that it becomes non-infringing, provided, however, that any such replacement or modification will not materially degrade the functionality of the affected portion of the SaaS Service or Deliverables. If JCI determines that either of these remedies is not reasonably available to JCI or if legally required, JCI may terminate Customer’s right to use the applicable SaaS Services or Deliverable and refund to Customer, in the case of a Deliverable, any fees paid for the Deliverable or in the case of SaaS Services, any prepaid fees for the unused remainder of the current term.
-
Customer’s Indemnification Obligations. Customer will defend the JCI Parties against any Claim, and will pay for the resulting costs, damages (including punitive damages) and fines awarded against JCI to such third party by a court of competent jurisdiction or agreed to in settlement by Customer, arising from: (i) Customer’s breach of its warranties in Section 9 (Warranties); (ii) the Excluded Claims; and (iii) Customer’s use of the Services or Deliverables in breach of this Agreement.
-
Procedure. The foregoing indemnification obligations are conditioned on the indemnified Party (i) notifying the indemnifying Party promptly in writing of such action; (ii) giving the indemnifying Party sole control of the defense thereof and any related settlement negotiations; and, (iii) cooperating with the indemnifying Party in connection with such defense or settlement at the indemnifying Party’s cost. The indemnifying Party will not, without the prior written consent of the indemnified Party, consent to the entry of any judgment or enter into any settlement that provides for non-monetary relief affecting the indemnified Party. No consent is required if such judgment or settlement provides for an unconditional and full release of the indemnified Party.
EXCEPT TO THE EXTENT PROHIBITED BY APPLICABLE LAWS, THE PROVISIONS OF THIS SECTION STATE THE SOLE AND EXCLUSIVE OBLIGATIONS AND LIABILITY OF JCI AND CUSTOMER’S SOLE REMEDY FOR ANY CLAIM OF INTELLECTUAL PROPERTY INFRINGEMENT, MISAPPROPRIATION, OR OTHER VIOLATION OF THIRD PARTY INTELLECTUAL PROPERTY RIGHTS ARISING OUT OF OR RELATING TO THE AGREEMENT.
-
-
Term and Termination.
-
MSA. This MSA will remain in effect until terminated. Either Party may terminate it at any time by giving at least 30 days’ prior written notice. The sole effect of terminating this MSA will be to terminate the ability of either Party to enter into subsequent Orders under this MSA. Termination of this MSA will not, by itself, result in the termination of any Order previously entered into under this MSA, and the terms of this MSA will continue to apply to any Order until that Order itself is terminated or expires.
-
Orders. The duration of SaaS Service subscriptions will be set forth in the applicable Order. Either Party may terminate an Order or applicable SaaS Service subscriptions therein if the other Party (1) is in breach of any material obligation that is not cured within 30 days’ notice of such breach or (2) fails to pay any invoice that is more than 30 days outstanding. At the expiration of any SaaS Service subscriptions, such subscriptions will automatically renew for consecutive one-year terms unless either party provides the other party with a notice of non-renewal at least sixty days prior to the expiration of the then-current term.
-
-
Miscellaneous.
-
In General. The Agreement constitutes the entire agreement among the Parties with respect to the subject matter hereof and supersedes and merges all prior proposals, understandings and contemporaneous communications. In the event of any conflict between the terms of this MSA and any terms of any Order, the terms of this MSA will control. The Agreement may be amended only by a formal written agreement signed by both Parties. Any terms and conditions contained in a purchase order or other document that are in addition to or contradict the terms of this Agreement will not apply and will be deemed rejected by JCI in their entirety. The Parties are independent contractors, and the Agreement does not create or imply any partnership, agency or joint venture. If a court holds any provision of the Agreement to be illegal, invalid, or unenforceable, the rest of the document will remain in effect, and the Agreement will be amended to give effect to the eliminated provision to the maximum extent possible. A waiver of any breach of the Agreement is not a waiver of any other breach. Any waiver must be in writing and signed by an authorized representative of the waiving Party. Provisions regarding ownership and perpetual license rights, fees, limitations of liability, confidentiality, obligations on termination or expiration, and the other provisions in this section entitled “Miscellaneous” will survive termination or expiration of this MSA and of any Order.
-
Notices. All notices under the Agreement must be in writing and delivered by hand or recognized courier to the address specified in the Agreement, the applicable Order, or another designated address. Notices are deemed given upon personal delivery or courier confirmation. Customer must also send a copy of any notice to JCI to: Johnson Controls Legal Department 5757 N Green Bay Avenue, Milwaukee, WI 53209, USA.
-
Assignment. This Agreement and any associated rights or obligations, may not be assigned or otherwise transferred by Customer without JCI’s prior written consent. This Agreement may be assigned by JCI without restriction. This Agreement is binding upon any permitted assignee.
-
Governing Law. Any dispute arising out of or in relation to this Agreement or the Services will be governed by the laws of the State of Wisconsin without regard to any conflict of law rules or principles that would cause the application of the laws of any other jurisdiction. The 1980 United Nations Convention on Contracts for the International Sale of Goods and its related instruments will not apply to the Agreement. Any dispute between the Parties will be resolved in the state or federal courts of Wisconsin and the United States, respectively, sitting in Milwaukee County.
-
U.S. Export. SaaS Services and Developments are subject to the export control laws, regulations and orders of the U.S. and may be subject to the export or import control laws and regulations of other countries. Customer will comply with all such laws and regulations that apply to the SaaS Services and Developments.
-
Government End Users. The SaaS Services and Developments are comprised of commercial computer software. If Customer is an agency, department, or other entity of the U.S. Government, the use, duplication, reproduction, release, modification, disclosure, or transfer of the SaaS Services and Developments, or any related documentation of any kind, including technical data and manuals, is restricted by this Agreement in accordance with FAR 12.212 for civilian purposes and DFARS 227.7202 for military purposes. The SaaS Services and Developments and software contained therein were developed fully at private expense. All other use is prohibited.
-
-
Definitions.
-
“Affiliate” means any legal entity that a Party owns, that owns a Party or that is under common ownership with a Party, where “ownership” for purposes of this definition means control, directly or indirectly, of more than a fifty percent (50%) interest in an entity.
-
"Agreement" means collectively this MSA, including any exhibits and attachments hereto, and any applicable Order entered into.
-
"Authorized User" means any individual that Customer authorizes to use the SaaS Services, including consultants, contractors and agents and individuals interacting with the SaaS Services as Customer’s visitor or customer.
-
"Confidential Information" means non-public information regarding either Party’s products, customers, marketing, pricing and promotions, confidential intellectual property, trade secrets, third-party confidential information, and other sensitive or proprietary information whether or not marked, designated, or otherwise identified as "confidential". Confidential Information does not include information that: (i) is, or becomes, publicly available without a breach of the Agreement; (ii) was lawfully known to the receiver prior to such disclosure without an obligation to keep it confidential; (iii) is received from another source who can disclose it lawfully and without an obligation to keep it confidential; (iv) is independently developed by a Party without use of or reference to the other Party’s Confidential Information; or (v) is Feedback.
-
"Customer Data" means, for Installation Services, all data and information residing in Customer’s computer networks and systems that is processed by JCI in performing the Installation Services and, for SaaS Services, data that Customer or anyone acting on Customer’s behalf runs on the SaaS Service, causes to interface with the SaaS Service or submits to the SaaS Service.
-
"Deliverable" means work product or tangible results of the Installation Services (including computer code, documents, and other materials) that are set forth in an Order to be provided to Customer, or any report, document, file, or other tangible output which is generated as a result of Customer’s use of the SaaS Services. Deliverables do not include the SaaS Services or improvements thereto.
-
"Fix" means fixes, modifications or enhancements, or their derivatives that JCI or its licensors either release generally or provide to Customer to address a specific issue.
-
"Force Majeure Event" means a cause beyond a Party’s reasonable control, regardless of whether such cause is foreseeable (such cause, a “Force Majeure Event”), including any: (i) act of God; (ii) flood, fire, explosion, natural disaster; (iii) act of terrorism, war, invasion, riot or other disturbances; (iv) interruption, loss, or malfunction of utilities, transportation, communications or computer software, hardware or services; (v) act, regulation, or law of any government, civil or military authority; (vi) a trade restriction in effect on or after the Effective Date; (vii) national or regional emergency; or (viii) epidemic, pandemic or other contagion.
-
"Installation Services" mean any installation, configuration, consulting, or other professional services to be provided by JCI under the Agreement, as described in more detail in an applicable Order. The Installation Services do not include SaaS Services.
-
"Order" means the applicable order, order form, statement of work or other similar document that describes the Services to be performed and any Deliverables to be provided and that is executed by JCI and Customer and incorporates the terms of this MSA.
-
"SaaS Services" means JCI hosted software-based services provided under an Order. SaaS Services include any ancillary software and any Fixes, support patches, updates, upgrades, or other modifications to the applicable SaaS Services. Releases of separate modules of the SaaS Services may be subject to additional fees.
-
"Sensitive Personal Data" means special category data or other sensitive data under applicable privacy or data protection laws, including but not limited to (i) government-issued identification number, including Social Security number, driver's license number, or state-issued identification number; (ii) financial account number, PIN or credentials, credit report information, or credit, debit, or other payment cardholder information; or (iii) biometric, genetic, health, or health insurance data.
-
"Services" mean, collectively, the SaaS Services and the Installation Services.
-
Schedule 1 – Security Addendum
JCI maintains a written information security program (including the adoption and enforcement of internal policies and procedures) under which JCI implements and maintains physical, administrative and technical safeguards, designed to protect the confidentiality, integrity, availability and security of its SaaS Services and Customer Data against accidental or unlawful loss, access or disclosure. The information security program will include the following measures:
-
Dedicated Security Organizations. JCI maintains dedicated, global enterprise product security and information security organizations that collaborate on security initiatives within the organization. JCI also maintains dedicated privacy and physical enterprise security departments within the organization.
-
Security Measures. JCI has implemented and maintains reasonable physical, technical and organizational measures designed to protect the confidentiality, security and integrity of Customer Data in JCI’s possession or control or that is otherwise processed in the SaaS Services. JCI (or its subcontractors) performs continuous monitoring of its SaaS Services with the goal of identifying and preventing potential vulnerabilities or threats to the SaaS Services.
-
Third-Party Certifications and Audits. JCI’s SaaS Services deploy security measures in alignment with the International Organization for Standardization (ISO) 27001, or a materially similar standard recognized within the industry. Certain SaaS Services are reported or certified to comply under SSAE 18 SOC 2 Type I, SSAE 18 SOC 2 Type II, ISO 27001 (or their successor standards), or other similar standards. A list of such services is available at the Johnson Controls’ Trust Center. Upon Customer’s written request, no more than once in any twelve (12)-month period, JCI will make available for Customer’s review, via a secure screenshare session, the executive summary or other auditor-permitted portions of JCI’s then-current SOC 2 Type II report applicable to the SaaS Services.
-
Security by Design. JCI has achieved and will maintain a certification under ISASecure Secure Development Lifecycle Assurance, in conformance with ISA/IEC 62443-4-1 (or its successor or materially similar standard) for all JCI’s SaaS Services, which requires JCI to follow industry standard (or better) requirements pertaining to “security by design.” Product development teams consider security at every stage in the development process.
-
Encryption. Customer Data stored or processed in the SaaS Services is encrypted in transit and at rest.
-
Penetration Testing.. As a part of its software development process, JCI conducts penetration testing on SaaS Services that process Customer Data with the purpose of identifying and thereafter remediating security vulnerabilities in its SaaS Services.
-
Hosting. If JCI uses third-party vendors to host SaaS Services, JCI uses reputable third-party vendors who are recognized within the industry for the reliability and security of their services, such as Amazon Web Services (AWS) or Microsoft Azure. JCI is a global organization; therefore, unless the parties have expressly agreed to specific location requirements in the Agreement (which is not available for all SaaS Services), JCI may host and support SaaS Services on a worldwide basis.
-
Intrusion Detection. JCI uses industry standard intrusion detection and prevention systems with respect to the SaaS Services that are designed to detect known malware and intrusion. JCI will promptly install all relevant security patches released with respect to such programs as recommended by its security personnel.
-
Logical Separation. Customer Data stored or otherwise processed in the SaaS Services is logically separated from other customers’ data and any of JCI’s data.
-
Access Controls. JCI’ administrators with access to the SaaS Services are required to use MFA. Access rights are assigned according to least privileged principles.
-
Business Continuity Plan.. JCI has implemented and maintains a BCP for its SaaS Services designed with the goal of preventing and promptly responding to cyber attacks and other threats to the security and availability of its SaaS Services.
-
Disaster Recovery. JCI has implemented and maintains disaster recovery policies and procedures with regard to its support infrastructure and SaaS Services.
-
Vendor Management. JCI maintains a vendor management program, and subcontractors with access to Customer Data, Customer’s Network or Customer’s premises are required to execute confidentiality, privacy and security terms with JCI commensurate with the nature of such vendor’s access.
-
Background Checks. JCI’s employees who access Customer Data or Customer’s Network in the course of their job duties must undergo an industry standard, pre-employment, background check unless prohibited by applicable laws. It is JCI’s policy to contractually require its subcontractors who have access to Customer Data, Customer’s Network or Customer’s premises to also undergo industry standard background checks.
-
Training. JCI maintains a Cybersecurity Training and Awareness Policy that requires all employees and contingent workers with JCI login credentials to participate in mandatory cybersecurity training. JCI also maintains a Global Information Security Awareness Program that delivers end user information security and policy awareness education and content commensurate with the user’s role and regulatory requirements. JCI maintains a privacy training program that requires all employees and contingent workers with JCI login credentials to participate in mandatory privacy training..
-
Customer Obligations. Customer shall follow data minimization principles in compliance with industry standards and applicable laws. Customer shall limit JCI’s access to Customer Data to that which is required for JCI to perform its obligations under the Agreement. Any permitted monitoring, testing or event logging related to Ancillary Hardware residing within Customer’s Network are solely the responsibility of Customer. Customer is solely responsible for establishing and maintaining the Customer’s Network and the physical, technical and organizational measures designed to protect the confidentiality, security and integrity of the Customer’s Network, and all devices/software thereon, in compliance with industry standards and applicable laws. JCI publishes best practices and hardening guides for Ancillary Hardware, and it is Customer’s responsibility to review and implement such practices and guides. “Customer’s Network” means the Customer’s internal information technology network which includes certain hardware, software, communication systems, infrastructure, network architecture, equipment and electronic devices.

















.jpg?la=en&h=320&w=720&hash=244C75B74F0F77521D56164450973BCD)














.jpg?la=en&h=310&w=720&hash=8D9823F26AA80B2B75C3E4B2E61770DC)


.jpg?la=en&h=320&w=719&hash=13CA7E4AA3E453809B6726B561F2F4DD)
.jpg?la=en&h=306&w=720&hash=F21A7CD3C49EFBF4D41F00691D09AEAC)

.png?la=en&h=320&w=720&hash=18CFCCD916C92D922F600511FABD775D)


