Nutzungsbestimmungen
Die Nutzungsbestimmungen regeln die Nutzung der Plattform fortControl durch Kunden und Nutzer.
Die Nutzungsbestimmungen regeln die Nutzung der Plattform fortControl durch Kunden und Nutzer.
1.1. Unter Security Management wird ein Instrument (Organisation, Prozesse, Technologie) zur Gewährleistung der Sicherheit im gewählten Themenbereich (z.B. Cybersicherheit) verstanden.
1.2. fortControl (nachfolgend: FORTCONTROL) ist ein von der FortIT AG (nachfolgend: FortIT) betriebener Software-as-a-Service (SaaS), mittels welchem ihre Kunden ihr Security Management in ausgewählten Themenbereichen durchführen oder unterstützen können.
1.3. Ein Nutzer ist eine natürliche Person, die auf FORTCONTROL zugreift und dieses nutzt. Nutzer können Angestellte, Vertreter, Berater, Auftragnehmer oder Agenten des Kunden sein, die vom Kunden berechtigt sind, FORTCONTROL zu nutzen, und denen zu diesem Zweck vom Kunden oder im Namen des Kunden Zugangsdaten zur Verfügung gestellt wurden.
1.4. Die Swiss Deployment Option ist die Bereitstellungsvariante von FORTCONTROL, bei der die Infrastruktur und der Betrieb ausschliesslich in der Schweiz durch Schweizer Anbieter erfolgen (vgl. Ziffer 2.5).
1.5. KI-Funktionen sind optionale Funktionen von FORTCONTROL, die Inhalte mithilfe von Modellen der künstlichen Intelligenz (KI) eines Drittanbieters analysieren, zusammenfassen, übersetzen, vorschlagen oder erzeugen. KI-Funktionen sind standardmässig deaktiviert und müssen vom Kunden aktiviert werden (Ziffer 3.7).
1.6. Ein eigener KI-Agent ist ein vom Kunden oder in seinem Auftrag betriebenes KI-System, das über die von FortIT dafür vorgesehenen Schnittstellen auf FORTCONTROL zugreift und dort gespeicherte Daten liest oder bearbeitet (Ziffer 3.12).
2.1. Security Management ist ein essenzieller Teil des übergeordneten Risikomanagements eines Unternehmens oder einer Organisation. Ein wirksames Security Management System managt aktiv die Sicherheitsrisiken durch einen systematischen Ansatz zur Risikoidentifikation, -beurteilung, -kommunikation und -behandlung. Typische Beispiele solcher risikobasierten Managementsysteme sind Informationssicherheitsmanagement oder Business Continuity Management.
2.2. Gegenstand dieses Nutzungsvertrags ist die Nutzung der von FortIT bereitgestellten Softwareapplikation FORTCONTROL, wobei der Kunde im Sinne eines «Software-as-a-Service» online über das Internet auf die Softwareapplikation zugreifen sowie die applikationsbezogenen Daten des Kunden auf Servern von FortIT oder eines Service Providers von FortIT speichern lassen kann. Dieses Angebot von FortIT wird nachfolgend in seiner Gesamtheit als FORTCONTROL bezeichnet.
2.3. Die wechselseitig geschuldeten Leistungen in Bezug auf Bereitstellung und Nutzung von FORTCONTROL ergeben sich aus:
2.4. Sämtliche der vorgenannten Dokumente sind als integrierter Bestandteil dieser Vereinbarung zu verstehen. Der Begriff «Nutzungsvertrag» umfasst deshalb neben diesem Vertrag auch sämtliche der oben aufgeführten Dokumente. Bei Widersprüchen gehen die Bestimmungen der Offerte bzw. des separat unterzeichneten Vertrags den übrigen Dokumenten vor.
2.5. FORTCONTROL wird in zwei Bereitstellungsvarianten angeboten: (a) in der Standard-Bereitstellung auf Cloud-Infrastruktur mit Datenstandort Schweiz sowie (b) in der Swiss Deployment Option, bei der Infrastruktur, Betrieb und E-Mail-Versand ausschliesslich in der Schweiz durch Schweizer Anbieter erfolgen. Die für den Kunden geltende Bereitstellungsvariante ergibt sich aus der Offerte bzw. dem Vertrag; ohne ausdrückliche Vereinbarung gilt die Standard-Bereitstellung. Die je Variante eingesetzten Unter-Auftragsbearbeiter sind in der Vereinbarung zur Auftragsbearbeitung aufgeführt. Die optionalen KI-Funktionen (Ziffer 3.7) werden in beiden Bereitstellungsvarianten durch den in der Vereinbarung zur Auftragsbearbeitung genannten KI-Anbieter in der EU (Frankreich) erbracht – nur pro Anfrage und ohne Training mit Kundendaten – und setzen deshalb auch bei der Swiss Deployment Option die ausdrückliche Aktivierung durch einen Administrator des Kunden voraus.
3.1. FORTCONTROL bietet Nutzern die Möglichkeit, ein individuelles Security Management effizient aufzubauen und zu betreiben. Dies umfasst insbesondere folgende Leistungen (nicht abschliessend):
3.2. FORTCONTROL unterstützt den Kunden bei seinem Security Management; die Verantwortung für die Ausgestaltung, die Angemessenheit und die Umsetzung des Security Managements sowie für die daraus abgeleiteten Entscheide verbleibt beim Kunden. Für allfällige Schäden, die im Rahmen des Security Managements des Kunden auftreten, ist allein der Kunde verantwortlich; eine Haftung von FortIT ist insoweit ausgeschlossen, soweit gesetzlich zulässig.
3.3. Während der Vertragsdauer darf der Kunde FORTCONTROL gemäss Funktionsbeschrieb und im durch diesen Nutzungsvertrag gesteckten Rahmen nutzen.
3.4. FortIT wird ihre Leistungen in guten Treuen, mit der notwendigen Sorgfalt und in Übereinstimmung mit den gemeinhin anerkannten und üblichen Branchenstandards erbringen. Eine hundertprozentige Verfügbarkeit des applikatorischen Teils von FORTCONTROL und der für den Betrieb verwendeten Infrastruktur ist technisch allerdings nicht zu realisieren. FortIT bemüht sich jedoch auf einer «Best-Effort»-Basis mit den ihr zur Verfügung stehenden Mitteln und im Rahmen der Wirtschaftlichkeit, FORTCONTROL in hohem Masse verfügbar zu halten. FortIT behält sich vor, wartungsbedingte Unterbrechungen von FORTCONTROL vorzunehmen und damit die Verfügbarkeit in Teilen oder insgesamt vorübergehend einzuschränken oder zu unterbrechen. Planbare Wartungsarbeiten führt FortIT nach Möglichkeit in den in Ziffer 6.4 der TOM beschriebenen Wartungsfenstern durch. Unaufschiebbare Wartungsarbeiten können von FortIT demgegenüber jederzeit vorgenommen werden.
3.5. Während der Vertragsdauer wird FortIT FORTCONTROL mit Blick auf die technischen und organisatorischen Rahmenbedingungen laufend aktuell und nützlich erhalten, kann aber nicht die Störungsfreiheit von FORTCONTROL garantieren. FortIT überwacht die Funktionstüchtigkeit von FORTCONTROL gemäss Ziffer 6 der TOM laufend und beseitigt im Rahmen der technischen Möglichkeiten allfällige selbst entdeckte oder vom Kunden gemeldete Störungen des Betriebs oder der Applikation auf einer «Best-Effort»-Basis. Es steht FortIT dabei frei, Fehlfunktionen, welche die Nutzung respektive die Funktionalitäten von FORTCONTROL für den Kunden nicht massgeblich einschränken, nicht unmittelbar, sondern in einem der Folgereleases von FORTCONTROL zu adressieren.
3.6. Es besteht kein Anspruch einzelner Kunden auf eine bestimmte Ausgestaltung von FORTCONTROL oder auf die Beibehaltung von darüber zugänglichen Funktionen. FortIT hat zur Wahrung des Qualitätsstandards, aber auch im Hinblick auf technische oder wirtschaftliche Entwicklungen, das Recht, FORTCONTROL sowie die darunter angebotenen Funktionalitäten und Inhalte jederzeit anzupassen. Wesentliche Einschränkungen bestehender Funktionen kündigt FortIT dem Kunden nach Möglichkeit mit angemessener Frist an.
3.7. Aktivierung von KI-Funktionen: KI-Funktionen sind standardmässig deaktiviert. Sie können ausschliesslich durch einen Administrator des Kunden für dessen Mandanten aktiviert und jederzeit wieder deaktiviert werden. Mit der Aktivierung weist der Kunde FortIT an, die dafür erforderlichen Daten an den in der Vereinbarung zur Auftragsbearbeitung (Ziffer 2.7.2 Tabelle C) genannten KI-Anbieter zu übermitteln. Der Kunde stellt sicher, dass die Aktivierung mit seinen internen Vorgaben und den für ihn geltenden gesetzlichen Bestimmungen vereinbar ist. Ohne Aktivierung werden keine Daten des Kunden an einen KI-Anbieter übermittelt.
3.8. Datenbearbeitung durch KI-Funktionen: Bei aktivierten KI-Funktionen werden die vom Nutzer ausgewählten Inhalte sowie der dafür erforderliche Kontext an den KI-Anbieter übermittelt und dort ausschliesslich zur Erbringung der jeweiligen Funktion bearbeitet. FortIT vereinbart mit dem KI-Anbieter, dass Eingaben und Ergebnisse nicht zum Training von KI-Modellen verwendet und nicht über eine allfällige kurzzeitige Missbrauchskontrolle hinaus gespeichert werden. Einzelheiten zu Anbieter, Bearbeitungsort und Schutzmassnahmen regeln die Vereinbarung zur Auftragsbearbeitung (Ziffer 2.7) und die TOM (Ziffer 3.3).
3.9. Charakter der Ergebnisse: KI-Funktionen beruhen auf grossen Sprachmodellen. Diese arbeiten wahrscheinlichkeitsbasiert; ihre Ergebnisse können unvollständig, unzutreffend, veraltet oder irreführend sein und sind nicht reproduzierbar. Von KI-Funktionen erzeugte Inhalte sind Vorschläge und Arbeitshilfen. Sie ersetzen weder die fachliche Prüfung durch den Kunden noch eine rechtliche, technische oder sonstige Beratung. Der Kunde ist verpflichtet, KI-generierte Inhalte vor ihrer Verwendung – insbesondere vor Entscheidungen im Rahmen seines Security Management, vor der Übernahme in Richtlinien, Risikobewertungen, Berichte oder Nachweise und vor der Weitergabe an Dritte – auf Richtigkeit, Vollständigkeit und Angemessenheit zu prüfen. FortIT kennzeichnet KI-generierte Inhalte in FORTCONTROL als solche.
3.10. Verantwortung und Haftung: Die Verantwortung für die Verwendung von KI-generierten Inhalten und die daraus abgeleiteten Entscheide liegt beim Kunden (Ziffer 3.2). FortIT gewährleistet weder die Richtigkeit, Vollständigkeit oder Eignung der Ergebnisse noch die dauernde Verfügbarkeit bestimmter KI-Modelle. FortIT kann KI-Modelle wechseln, sofern das in der Vereinbarung zur Auftragsbearbeitung zugesicherte Schutzniveau gewahrt bleibt; für den Wechsel des KI-Anbieters gilt Ziffer 2.7.3 der Vereinbarung zur Auftragsbearbeitung. Für Schäden aus der Verwendung ungeprüfter KI-generierter Inhalte haftet FortIT nicht; die übrigen Haftungsbestimmungen dieses Nutzungsvertrags bleiben unberührt.
3.11. Zulässige Nutzung von KI-Funktionen: Der Kunde nutzt KI-Funktionen nur im Rahmen des Security Management gemäss dieser Ziffer 3 und nicht, um (a) Personen ausschliesslich automatisiert zu bewerten oder Entscheidungen mit rechtlicher Wirkung für Personen ohne menschliche Prüfung zu treffen, (b) Inhalte zu erzeugen, die Rechte Dritter oder geltendes Recht verletzen, (c) die Schutzmechanismen des KI-Anbieters zu umgehen oder (d) KI-Modelle zu extrahieren oder nachzubilden. Der Kunde stellt sicher, dass besonders schützenswerte Personendaten nur dann in KI-Funktionen verwendet werden, wenn er dazu berechtigt ist.
3.12. Eigene KI-Agenten des Kunden: FortIT stellt dokumentierte Schnittstellen bereit, über die der Kunde eigene KI-Agenten an FORTCONTROL anbinden kann. Der Kunde entscheidet allein, ob und welchen KI-Agenten er einsetzt. Der Zugriff erfolgt über persönliche oder technische Zugangsdaten (API-Schlüssel) mit den vom Kunden vergebenen Berechtigungen; der Kunde behandelt diese Zugangsdaten vertraulich, beschränkt die Berechtigungen auf das Erforderliche und widerruft sie bei Bedarf umgehend. Der eigene KI-Agent, dessen Anbieter, der Ort und die Sicherheit der dortigen Datenbearbeitung sowie dessen Ergebnisse liegen ausserhalb des Verantwortungsbereichs von FortIT; FortIT ist dafür weder Auftragsbearbeiterin noch Unter-Auftragsbearbeiterin. Der Kunde bleibt für alle Aktionen verantwortlich, die sein KI-Agent in FORTCONTROL ausführt, einschliesslich des Erstellens, Änderns und Löschens von Daten. Die Ziffern 3.9 und 3.10 gelten sinngemäss. Ziffer 7.4 bleibt anwendbar; FortIT kann Zugriffe drosseln oder sperren, die den Betrieb von FORTCONTROL beeinträchtigen.
4.1. Für Auskünfte zur Benutzung von FORTCONTROL und zur Meldung allfälliger Störungen und Fehlfunktionen (Support) betreibt FortIT ein Helpdesk, das der Kunde per E-Mail an help@fortcontrol.swiss sowie über Telefon (Hotline) erreichen kann. Das Helpdesk steht dem Kunden Montag bis Freitag (gesetzliche Feiertage am Sitz von FortIT ausgenommen) zwischen 9.00 und 17.00 Uhr MEZ/MESZ zur Verfügung. Die Zugangsnummer der Hotline wird dem Kunden separat mitgeteilt oder ist auf den Websites von FortIT bezeichnet. Ergänzend stellt FortIT eine Online-Dokumentation mit Anleitungen und Antworten auf häufige Fragen bereit.
4.2. Die Supportleistungen von FortIT sind auf die Diagnose und Analyse von gemeldeten Störungen oder Fehlfunktionen und deren Behebung respektive die Aufrechterhaltung der Verfügbarkeit von FORTCONTROL gerichtet. Weitere Leistungen wie z.B. Implementationssupport, Consulting oder die Umsetzung kundenspezifischer Wünsche sind nicht im Support enthalten und werden separat vereinbart.
5.1. FortIT (a) überlässt dem Kunden einen definierten Speicherplatz auf einem von FortIT oder einem Subakkordanten betriebenen Cloudspeicher und (b) räumt dem Kunden das nicht ausschliessliche, auf die Vertragsdauer beschränkte, nicht übertragbare und nicht unterlizenzierbare Recht zur bestimmungsgemässen Nutzung von FORTCONTROL ein. Das vorgenannte Nutzungsrecht des Kunden steht unter dem Vorbehalt der zeitgerechten Bezahlung der anfallenden Nutzungsgebühren.
5.2. Das Nutzungsrecht umfasst das Recht, Nutzer mit Zugangsdaten auszustatten und ihnen die in FORTCONTROL vorgesehenen Rollen und Rechte einzuräumen (z.B. Kunden-Administratorenrechte, Leserechte etc.).
5.3. Der Kunde ist nicht berechtigt, FORTCONTROL insgesamt oder nur bezüglich gewisser Teilaspekte Dritten ausserhalb des eigenen Unternehmens entgeltlich oder unentgeltlich zur Verfügung zu stellen oder zugänglich zu machen.
5.4. Der Zugang zu FORTCONTROL erfolgt verschlüsselt über das Internet. Nutzer können vom Kunden in FORTCONTROL autorisiert und mit Rollen versehen werden.
5.5. Der Kunde verpflichtet sich, dafür zu sorgen, dass die von ihm berechtigten Nutzer ihre Zugangsdaten keinen unbefugten Personen offenlegen und diese sorgfältig und vor dem Zugriff durch Dritte adäquat geschützt aufbewahren. Der Kunde setzt die in FORTCONTROL verfügbaren Sicherheitsfunktionen (z.B. Mehrfaktor-Authentisierung oder Anmeldung über den Identitätsdienst des Kunden) nach Massgabe seines Schutzbedarfs ein und entzieht ausscheidenden Nutzern den Zugang unverzüglich.
5.6. FortIT lehnt jegliche Haftung für Schäden ab, die dem Kunden durch Missbrauch oder Verlust der den jeweiligen Nutzern überlassenen respektive von diesen selbst gewählten Zugangsdaten (z.B. Benutzeridentifikation, Passwort) entstehen.
5.7. Die Softwareapplikation, welche FORTCONTROL zugrunde liegt, ist urheberrechtlich geschützt. Sämtliche Rechte an dieser Softwareapplikation stehen FortIT selbst und/oder Vertragspartnern von FortIT zu. fortControl ist eine eingetragene Marke der FortIT AG.
5.8. Von KI-Funktionen erzeugte Inhalte stehen im Verhältnis zwischen FortIT und dem Kunden dem Kunden zu; FortIT macht daran keine Rechte geltend. Der Kunde nimmt zur Kenntnis, dass KI-generierte Inhalte nach geltendem Recht unter Umständen keinen urheberrechtlichen Schutz geniessen und dass gleiche oder ähnliche Inhalte auch für andere Kunden erzeugt werden können.
6.1. Der Kunde unterstützt FortIT bei der Vorbereitung und Erbringung ihrer Leistungen, soweit zumutbar, erforderlich und zweckdienlich, und stellt FortIT alle vernünftigerweise erforderlichen Leistungen, Informationen, Sachmittel und Rechte auf eigene Kosten und Gefahr zur Verfügung.
6.2. Der Kunde ist dafür verantwortlich, dass die auf seiner Seite erforderlichen technischen Voraussetzungen für den Zugang zu FORTCONTROL bestehen und aufrechterhalten werden. Die technischen Anforderungen betreffend die Anbindung an und die Nutzung von FORTCONTROL richten sich nach den von FortIT ausgegebenen Systemanforderungen.
6.3. Der Kunde bezeichnet FortIT eine Kontaktperson (Kunden-Administrator) für organisatorische und technische Fragen und hält deren Angaben aktuell.
7.1. Der Kunde ist dafür verantwortlich, dass die Nutzung von FORTCONTROL durch die von ihm autorisierten Nutzer (a) nicht gegen die Bestimmungen dieses Nutzungsvertrags, Rechte Dritter (z.B. Urheberrechte, andere Immaterialgüterrechte, Forderungsrechte aller Art, Eigentumsrechte und sonstige dingliche Rechte sowie Persönlichkeitsrechte), gesetzliche Bestimmungen und/oder gegen die guten Sitten verstösst; (b) in keiner Art und Weise die Funktionsfähigkeit von FORTCONTROL und/oder der dahinterstehenden Infrastruktur negativ und zum Schaden von FortIT, anderer Anwender oder weiterer Dritter beeinträchtigt.
7.2. Der Kunde ist für den Inhalt der Informationen (Daten in jeglicher Form) verantwortlich, welche er respektive seine Nutzer in FORTCONTROL erfassen, speichern, übermitteln, bearbeiten und/oder bereitstellen.
7.3. Der Kunde ist verpflichtet, dafür Sorge zu tragen, dass seine Nutzer Daten und Informationen vor der Übermittlung und Speicherung in FORTCONTROL auf Viren oder sonstige schädliche Softwareroutinen überprüfen und hierzu dem Stand der Technik entsprechende Schutzprogramme verwenden.
7.4. Automatisierte Zugriffe auf FORTCONTROL (z.B. über Schnittstellen oder Skripte) sind nur im Rahmen der von FortIT dafür vorgesehenen und dokumentierten Funktionen zulässig. Sicherheitstests gegen FORTCONTROL bedürfen der vorgängigen schriftlichen Zustimmung von FortIT. Dies gilt auch für Zugriffe durch eigene KI-Agenten des Kunden (Ziffer 3.12).
8.1. Beim Anwählen von vordefinierten Control-Sets, die auf urheberrechtlich geschützten Normen basieren, müssen die Nutzer in FORTCONTROL angeben, ob sie (resp. der Kunde) über eine Lizenz für die jeweilige Norm verfügen.
8.2. Der Kunde gewährleistet, dass er im Rahmen dieses Services ausschliesslich diejenigen in FORTCONTROL verfügbaren Control-Sets verwendet, die entweder urheberrechtsfrei sind oder für die der Kunde selbst über eine entsprechende Lizenz verfügt.
9.1. FortIT ist in Bezug auf die vom Kunden respektive dessen Nutzern auf FORTCONTROL abgelegten Daten verpflichtet, geeignete Vorkehrungen gegen Verlust, Kompromittierung und unbefugte Zugriffe durch Dritte zu treffen. Die getroffenen Massnahmen – insbesondere zu Zugriffskontrolle, Verschlüsselung, Datensicherung, Protokollierung und Störungsbehebung – sind in den technischen und organisatorischen Massnahmen (TOM) beschrieben, abrufbar unter https://www.fortcontrol.swiss/tom/.
9.2. Die Daten des Kunden werden entsprechend der vereinbarten Bereitstellungsvariante (Ziffer 2.5) in der Schweiz gespeichert. Details zu Speicherorten, Unter-Auftragsbearbeitern und technischen und organisatorischen Massnahmen regelt die Vereinbarung zur Auftragsbearbeitung mit den TOM als deren Anhang.
9.3. FortIT löscht alle im Rahmen des Vertragsverhältnisses in FORTCONTROL gespeicherten Daten unwiderruflich nach Ablauf von 90 Tagen nach Beendigung des Vertragsverhältnisses ohne vorherige Ankündigung.
9.4. An den vom Kunden respektive seinen Nutzern in FORTCONTROL abgelegten Daten bleibt der Kunde allein berechtigt. Der Kunde kann daher von FortIT jederzeit (im Rahmen der Karenzfrist gemäss vorstehender Ziffer auch nach Beendigung des Vertrags) die Herausgabe einzelner oder sämtlicher Daten an sich selbst verlangen, soweit dies nicht bereits über das Nutzer-Frontend möglich ist. Die Herausgabe der Daten erfolgt mangels abweichender Abrede durch einen Datenbankexport in einem gängigen, maschinenlesbaren Format.
10.1. Die geltenden und jeweils anwendbaren Datenschutz- und Sicherheitsbestimmungen sind von beiden Parteien einzuhalten. Die Vereinbarung zur Auftragsbearbeitung (AVV) von FortIT, abrufbar unter https://www.fortcontrol.swiss/avv/, gilt für die vertragliche Bearbeitung von Personendaten durch FortIT für den Kunden und ist integrierter Bestandteil dieses Nutzungsvertrags.
10.2. Der Kunde ist verantwortlich für alle allenfalls erforderlichen Mitteilungen, Zustimmungen und/oder Genehmigungen im Zusammenhang mit der Bereitstellung von Personendaten durch den Kunden und der Bearbeitung von Personendaten durch FortIT im Rahmen der Bereitstellung von FORTCONTROL.
10.3. Zur Abwicklung des Vertragsverhältnisses erfasst und bearbeitet FortIT die hierfür notwendigen Angaben über den Kunden und die von ihm autorisierten Nutzer (Kundenkennung, Nutzerangaben und Nutzungsdaten) als Verantwortliche im Sinne der anwendbaren Datenschutzgesetze. FortIT behandelt diese Daten vertraulich, bearbeitet sie ausschliesslich für die Bereitstellung, den Betrieb, die Sicherheit und die Abrechnung von FORTCONTROL sowie für den Support, setzt dafür nur die in der Vereinbarung zur Auftragsbearbeitung genannten Unter-Auftragsbearbeiter ein und löscht oder anonymisiert sie nach Beendigung des Vertrags, soweit keine gesetzlichen Aufbewahrungspflichten bestehen. Auskunfts- und weitere Betroffenenrechte können über office@fort-it.ch geltend gemacht werden. Für die Nutzung von FORTCONTROL gelten ausschliesslich dieser Nutzungsvertrag, die Vereinbarung zur Auftragsbearbeitung und die TOM; die Allgemeine Datenschutzerklärung von FortIT betrifft nur die Websites, die Kontaktaufnahme und den Support von FortIT.
10.4. FortIT ist berechtigt, die durch die Nutzung von FORTCONTROL durch den Kunden resp. seine Nutzer gewonnenen Daten (Nutzungsdaten, Verhaltensmuster etc.) zur Verbesserung der Plattform zu nutzen. FortIT kann diese Daten auch in aggregierter Form zur Erstellung von anonymen Profilen und Benchmark-Daten verwenden, die keine Identifizierung des Kunden oder der Nutzer zulassen.
10.5. Darüber hinaus kann FortIT (i) statistische und andere Informationen in Bezug auf die Leistung, den Betrieb und die Nutzung von FORTCONTROL zusammenstellen und (ii) Daten aus FORTCONTROL in zusammengefasster Form für das Sicherheits- und Betriebsmanagement, zur Erstellung statistischer Analysen und für Forschungs- und Entwicklungszwecke verwenden (die Klauseln (i) und (ii) werden zusammen als «Dienstanalysen» bezeichnet). FortIT kann Dienstanalysen öffentlich zugänglich machen; Dienstanalysen werden jedoch keine vom Kunden hochgeladenen Daten, Personendaten oder vertraulichen Informationen in einer Form enthalten, die zur Identifizierung des Kunden, der Nutzer oder anderer Personen dienen könnte. FortIT hält alle geistigen Eigentumsrechte an den Dienstanalysen.
11.1. Demozugang: Der Vertrag zwischen FortIT und dem Kunden kommt mit der Registrierung eines Accounts und der dabei erfolgten Annahme dieses Nutzungsvertrags zustande und hat eine Laufzeit von drei Monaten. Der Demozugang endet ohne Kündigung automatisch; für den Demozugang steht ausschliesslich die Standard-Bereitstellung zur Verfügung.
11.2. Kostenpflichtiger Zugang: Der Vertrag zwischen FortIT und dem Kunden kommt mit der schriftlichen Annahme einer entsprechenden Offerte oder durch die Unterzeichnung eines separaten Vertrags zustande. Die Mindestlaufzeit und die Bereitstellungsvariante werden im Vertrag oder in der Offerte festgehalten.
11.3. Der Vertrag über die Nutzung von FORTCONTROL wird für die im Vertrag festgelegte Laufzeit geschlossen. Nach Ablauf dieser Laufzeit verlängert sich der Vertrag automatisch um jeweils ein weiteres Jahr, sofern der Vertrag nicht von einer der Parteien gekündigt wird.
11.4. Der Vertrag kann ohne Angabe von Gründen auf Ende der Laufzeit unter Einhaltung einer zweimonatigen Kündigungsfrist schriftlich (Brief oder E-Mail) gekündigt werden.
12.1. FortIT behält sich das Recht vor, den Zugang zu FORTCONTROL gesamthaft oder für einzelne Nutzer ohne Vorankündigung zu sistieren oder auf bestimmte Funktionen einzuschränken, wenn
12.2. FortIT informiert den Kunden über eine Sistierung und deren Gründe so rasch wie möglich und hebt die Sistierung auf, sobald deren Grund entfallen ist.
12.3. FortIT ist im Fall einer solchen Sistierung nicht verpflichtet, auf die Erhebung von Gebühren für die Zeit der Sistierung zu verzichten, und haftet zudem generell nicht für die Folgen einer Sistierung.
13.1. FortIT kann den vorliegenden Nutzungsvertrag ändern. Es gilt jeweils die online unter https://www.fortcontrol.swiss/nutzungsbedingungen/ abrufbare Version des Nutzungsvertrags. Wesentliche Änderungen zum Nachteil des Kunden teilt FortIT dem Kunden mindestens 30 Tage vor Inkrafttreten mit; widerspricht der Kunde nicht innert dieser Frist schriftlich, gelten die Änderungen als angenommen. Im Fall eines Widerspruchs kann jede Partei den Vertrag auf den Zeitpunkt des Inkrafttretens der Änderung kündigen.
13.2. Sollte eine Bestimmung dieses Nutzungsvertrags unwirksam oder undurchführbar sein oder werden, so wird die Wirksamkeit der übrigen Bestimmungen davon nicht berührt. Die Parteien ersetzen die unwirksame Bestimmung durch eine wirksame, die dem wirtschaftlichen Zweck der unwirksamen Bestimmung möglichst nahekommt.
13.3. Dieser Nutzungsvertrag untersteht schweizerischem Recht unter Ausschluss der kollisionsrechtlichen Bestimmungen und des Übereinkommens der Vereinten Nationen über Verträge über den internationalen Warenkauf (CISG). Ausschliesslicher Gerichtsstand ist Zürich, Schweiz; zwingende gesetzliche Gerichtsstände bleiben vorbehalten.
13.4. Dieser Nutzungsvertrag ist in deutscher Sprache verfasst. Übersetzungen dienen nur der Information; bei Abweichungen ist die deutsche Fassung massgebend.
1.1. Security management means an instrument (organisation, processes, technology) for ensuring security in the chosen subject area (e.g. cyber security).
1.2. fortControl (hereinafter: FORTCONTROL) is a software-as-a-service (SaaS) operated by FortIT AG (hereinafter: FortIT) that enables its customers to carry out or support their security management in selected subject areas.
1.3. A user is a natural person who accesses and uses FORTCONTROL. Users may be employees, representatives, consultants, contractors or agents of the customer who are authorised by the customer to use FORTCONTROL and who have been provided with access credentials for this purpose by or on behalf of the customer.
1.4. The Swiss Deployment Option is the deployment variant of FORTCONTROL in which the infrastructure and operation are provided exclusively in Switzerland by Swiss providers (see clause 2.5).
1.5. AI functions are optional functions of FORTCONTROL that analyse, summarise, translate, suggest or generate content using artificial intelligence (AI) models of a third-party provider. AI functions are deactivated by default and must be activated by the customer (clause 3.7).
1.6. A customer's own AI agent is an AI system operated by or on behalf of the customer that accesses FORTCONTROL via the interfaces provided by FortIT for this purpose and reads or processes data stored there (clause 3.12).
2.1. Security management is an essential part of the overarching risk management of a company or organisation. An effective security management system actively manages security risks through a systematic approach to risk identification, assessment, communication and treatment. Typical examples of such risk-based management systems are information security management or business continuity management.
2.2. The subject of this user agreement is the use of the FORTCONTROL software application provided by FortIT, whereby the customer, in the sense of "software-as-a-service", can access the software application online via the internet and have the customer's application-related data stored on servers of FortIT or of a service provider of FortIT. This offering of FortIT is hereinafter referred to in its entirety as FORTCONTROL.
2.3. The services mutually owed in relation to the provision and use of FORTCONTROL result from:
2.4. All of the aforementioned documents are to be understood as an integral part of this agreement. The term "user agreement" therefore includes, in addition to this agreement, all of the documents listed above. In the event of contradictions, the provisions of the offer or the separately signed contract take precedence over the other documents.
2.5. FORTCONTROL is offered in two deployment variants: (a) the standard deployment on cloud infrastructure with data location in Switzerland, and (b) the Swiss Deployment Option, in which infrastructure, operation and e-mail delivery are provided exclusively in Switzerland by Swiss providers. The deployment variant applicable to the customer results from the offer or the contract; in the absence of an express agreement, the standard deployment applies. The sub-processors used for each variant are listed in the Data Processing Agreement. The optional AI functions (section 3.7) are provided in both deployment variants by the AI provider named in the Data Processing Agreement in the EU (France) – per request only and without training on customer data – and therefore require express activation by an administrator of the customer in the Swiss Deployment Option as well.
3.1. FORTCONTROL offers users the possibility of efficiently establishing and operating an individual security management. This includes in particular the following services (non-exhaustive):
3.2. FORTCONTROL supports the customer in its security management; responsibility for the design, appropriateness and implementation of the security management and for the decisions derived from it remains with the customer. The customer alone is responsible for any damage occurring in the context of the customer's security management; any liability of FortIT in this respect is excluded to the extent permitted by law.
3.3. During the term of the contract, the customer may use FORTCONTROL in accordance with the functional description and within the framework set by this user agreement.
3.4. FortIT will provide its services in good faith, with the necessary care and in accordance with generally recognised and customary industry standards. However, one hundred per cent availability of the application part of FORTCONTROL and of the infrastructure used for operation is technically not achievable. FortIT nevertheless endeavours, on a best-effort basis, with the means available to it and within the bounds of economic viability, to keep FORTCONTROL highly available. FortIT reserves the right to carry out maintenance-related interruptions of FORTCONTROL and thereby to temporarily restrict or interrupt availability in part or in whole. FortIT carries out plannable maintenance work where possible within the maintenance windows described in clause 6.4 of the TOM. Maintenance work that cannot be postponed may, however, be carried out by FortIT at any time.
3.5. During the term of the contract, FortIT will keep FORTCONTROL up to date and useful on an ongoing basis with regard to the technical and organisational framework conditions, but cannot guarantee that FORTCONTROL will be free of disruptions. FortIT continuously monitors the functionality of FORTCONTROL in accordance with clause 6 of the TOM and, within the scope of technical possibilities, remedies any disruptions of operation or of the application that it discovers itself or that are reported by the customer on a best-effort basis. FortIT is free to address malfunctions that do not materially restrict the customer's use or the functionalities of FORTCONTROL not immediately but in one of the subsequent releases of FORTCONTROL.
3.6. Individual customers have no claim to a specific design of FORTCONTROL or to the retention of functions accessible through it. In order to maintain the quality standard, but also in view of technical or economic developments, FortIT has the right to adapt FORTCONTROL and the functionalities and content offered under it at any time. FortIT will, where possible, announce material restrictions of existing functions to the customer with reasonable notice.
3.7. Activation of AI functions: AI functions are deactivated by default. They can be activated for the customer's tenant exclusively by an administrator of the customer and can be deactivated again at any time. By activating them, the customer instructs FortIT to transmit the data required for this purpose to the AI provider named in the Data Processing Agreement (section 2.7.2, Table C). The customer ensures that the activation is compatible with its internal policies and the statutory provisions applicable to it. Without activation, no customer data is transmitted to an AI provider.
3.8. Data processing by AI functions: When AI functions are activated, the content selected by the user and the context required for it are transmitted to the AI provider and processed there exclusively to deliver the respective function. FortIT agrees with the AI provider that inputs and outputs are not used to train AI models and are not stored beyond any short-term abuse monitoring. Details on the provider, processing location and protective measures are governed by the Data Processing Agreement (section 2.7) and the TOM (section 3.3).
3.9. Nature of the results: AI functions are based on large language models. These operate on a probabilistic basis; their results may be incomplete, inaccurate, outdated or misleading and are not reproducible. Content generated by AI functions constitutes suggestions and working aids. It replaces neither the customer's professional review nor legal, technical or other advice. The customer is obliged to check AI-generated content for accuracy, completeness and appropriateness before using it – in particular before making decisions within its security management, before adopting it in policies, risk assessments, reports or evidence, and before passing it on to third parties. FortIT labels AI-generated content in FORTCONTROL as such.
3.10. Responsibility and liability: Responsibility for the use of AI-generated content and the decisions derived from it lies with the customer (clause 3.2). FortIT warrants neither the accuracy, completeness or suitability of the results nor the continued availability of specific AI models. FortIT may change AI models provided that the level of protection assured in the Data Processing Agreement is maintained; a change of AI provider is governed by section 2.7.3 of the Data Processing Agreement. FortIT is not liable for damage arising from the use of unverified AI-generated content; the other liability provisions of this Usage Agreement remain unaffected.
3.11. Permitted use of AI functions: The customer uses AI functions only within the scope of security management pursuant to this clause 3 and not to (a) evaluate persons on a purely automated basis or make decisions with legal effect for persons without human review, (b) generate content that infringes the rights of third parties or applicable law, (c) circumvent the AI provider's safeguards, or (d) extract or replicate AI models. The customer ensures that sensitive personal data is only used in AI functions where it is authorised to do so.
3.12. Customer's own AI agents: FortIT provides documented interfaces through which the customer can connect its own AI agents to FORTCONTROL. The customer alone decides whether and which AI agent it uses. Access is granted via personal or technical credentials (API keys) with the permissions assigned by the customer; the customer keeps these credentials confidential, limits the permissions to what is necessary and revokes them immediately where required. The customer's own AI agent, its provider, the location and security of the data processing there and its results are outside FortIT's area of responsibility; FortIT is neither processor nor sub-processor in this respect. The customer remains responsible for all actions its AI agent performs in FORTCONTROL, including creating, changing and deleting data. Clauses 3.9 and 3.10 apply mutatis mutandis. Clause 7.4 remains applicable; FortIT may throttle or block access that impairs the operation of FORTCONTROL.
4.1. For information on the use of FORTCONTROL and for reporting any disruptions and malfunctions (support), FortIT operates a helpdesk that the customer can reach by e-mail at help@fortcontrol.swiss and by telephone (hotline). The helpdesk is available to the customer Monday to Friday (excluding public holidays at FortIT's registered office) between 9 a.m. and 5 p.m. CET/CEST. The hotline number is communicated to the customer separately or is indicated on FortIT's websites. In addition, FortIT provides online documentation with guides and answers to frequently asked questions.
4.2. FortIT's support services are aimed at diagnosing and analysing reported disruptions or malfunctions and remedying them, or maintaining the availability of FORTCONTROL. Further services such as implementation support, consulting or the implementation of customer-specific requests are not included in the support and are agreed separately.
5.1. FortIT (a) provides the customer with a defined storage space on cloud storage operated by FortIT or a subcontractor and (b) grants the customer the non-exclusive, non-transferable and non-sublicensable right, limited to the term of the contract, to use FORTCONTROL as intended. The customer's aforementioned right of use is subject to timely payment of the applicable usage fees.
5.2. The right of use includes the right to provide users with access credentials and to grant them the roles and rights provided for in FORTCONTROL (e.g. customer administrator rights, read rights, etc.).
5.3. The customer is not entitled to make FORTCONTROL as a whole or only with regard to certain partial aspects available or accessible to third parties outside its own company, whether for a fee or free of charge.
5.4. Access to FORTCONTROL takes place in encrypted form via the internet. Users can be authorised and assigned roles by the customer in FORTCONTROL.
5.5. The customer undertakes to ensure that the users authorised by it do not disclose their access credentials to unauthorised persons and keep them carefully and adequately protected against access by third parties. The customer uses the security functions available in FORTCONTROL (e.g. multi-factor authentication or login via the customer's identity service) in accordance with its protection needs and revokes the access of departing users without delay.
5.6. FortIT rejects any liability for damage incurred by the customer through misuse or loss of the access credentials provided to the respective users or chosen by them (e.g. user identification, password).
5.7. The software application underlying FORTCONTROL is protected by copyright. All rights to this software application belong to FortIT itself and/or to contractual partners of FortIT. fortControl is a registered trademark of FortIT AG.
5.8. As between FortIT and the customer, content generated by AI functions belongs to the customer; FortIT asserts no rights to it. The customer acknowledges that AI-generated content may not enjoy copyright protection under applicable law and that identical or similar content may also be generated for other customers.
6.1. The customer supports FortIT in the preparation and provision of its services to the extent reasonable, necessary and expedient, and provides FortIT with all reasonably required services, information, resources and rights at its own expense and risk.
6.2. The customer is responsible for ensuring that the technical requirements on its side for access to FORTCONTROL exist and are maintained. The technical requirements regarding connection to and use of FORTCONTROL are governed by the system requirements issued by FortIT.
6.3. The customer designates a contact person (customer administrator) to FortIT for organisational and technical questions and keeps their details up to date.
7.1. The customer is responsible for ensuring that the use of FORTCONTROL by the users authorised by it (a) does not violate the provisions of this user agreement, the rights of third parties (e.g. copyrights, other intellectual property rights, claims of any kind, property rights and other rights in rem as well as personality rights), statutory provisions and/or public morals; (b) does not in any way negatively affect the functionality of FORTCONTROL and/or the underlying infrastructure to the detriment of FortIT, other users or other third parties.
7.2. The customer is responsible for the content of the information (data in any form) that it or its users record, store, transmit, process and/or make available in FORTCONTROL.
7.3. The customer is obliged to ensure that its users check data and information for viruses or other harmful software routines before transmitting and storing them in FORTCONTROL and use state-of-the-art protection programs for this purpose.
7.4. Automated access to FORTCONTROL (e.g. via interfaces or scripts) is permitted only within the scope of the functions provided and documented by FortIT for this purpose. Security tests against FORTCONTROL require the prior written consent of FortIT. This also applies to access by the customer's own AI agents (clause 3.12).
8.1. When selecting predefined control sets based on copyrighted standards, users must indicate in FORTCONTROL whether they (or the customer) hold a licence for the respective standard.
8.2. The customer warrants that, within the scope of this service, it uses exclusively those control sets available in FORTCONTROL that are either free of copyright or for which the customer itself holds a corresponding licence.
9.1. With regard to the data stored on FORTCONTROL by the customer or its users, FortIT is obliged to take appropriate precautions against loss, compromise and unauthorised access by third parties. The measures taken – in particular regarding access control, encryption, data backup, logging and incident handling – are described in the technical and organisational measures (TOM), available at https://www.fortcontrol.swiss/tom/.
9.2. The customer's data is stored in Switzerland in accordance with the agreed deployment variant (clause 2.5). Details on storage locations, sub-processors and technical and organisational measures are governed by the Data Processing Agreement together with the TOM as its annex.
9.3. FortIT irrevocably deletes all data stored in FORTCONTROL within the scope of the contractual relationship 90 days after termination of the contractual relationship without prior notice.
9.4. The customer remains solely entitled to the data stored in FORTCONTROL by the customer or its users. The customer may therefore at any time (within the grace period pursuant to the preceding clause also after termination of the contract) request FortIT to hand over individual or all data to the customer, insofar as this is not already possible via the user front end. Unless otherwise agreed, the data is handed over by means of a database export in a common, machine-readable format.
10.1. The applicable data protection and security provisions in force at the relevant time must be complied with by both parties. FortIT's Data Processing Agreement (DPA), available at https://www.fortcontrol.swiss/avv/, applies to the contractual processing of personal data by FortIT for the customer and is an integral part of this user agreement.
10.2. The customer is responsible for all notifications, consents and/or approvals that may be required in connection with the provision of personal data by the customer and the processing of personal data by FortIT within the scope of the provision of FORTCONTROL.
10.3. For the administration of the contractual relationship, FortIT collects and processes the information required for this purpose about the customer and the users authorised by it (customer identifier, user details and usage data) as a controller within the meaning of the applicable data protection laws. FortIT treats this data confidentially, processes it exclusively for the provision, operation, security and invoicing of FORTCONTROL and for support, uses only the sub-processors named in the Data Processing Agreement for this purpose, and deletes or anonymises it after termination of the contract unless statutory retention obligations apply. Requests for access and other data subject rights may be addressed to office@fort-it.ch. The use of FORTCONTROL is governed exclusively by this Usage Agreement, the Data Processing Agreement and the TOM; FortIT's general privacy policy covers only FortIT's websites, contact channels and support.
10.4. FortIT is entitled to use the data obtained through the use of FORTCONTROL by the customer or its users (usage data, behavioural patterns, etc.) to improve the platform. FortIT may also use this data in aggregated form to create anonymous profiles and benchmark data that do not allow identification of the customer or the users.
10.5. In addition, FortIT may (i) compile statistical and other information relating to the performance, operation and use of FORTCONTROL and (ii) use data from FORTCONTROL in aggregated form for security and operations management, for the preparation of statistical analyses and for research and development purposes (clauses (i) and (ii) together referred to as "service analyses"). FortIT may make service analyses publicly available; however, service analyses will not contain any data uploaded by the customer, personal data or confidential information in a form that could serve to identify the customer, the users or other persons. FortIT holds all intellectual property rights in the service analyses.
11.1. Demo access: the contract between FortIT and the customer is concluded upon registration of an account and the acceptance of this user agreement made in the process, and has a term of three months. Demo access ends automatically without notice; only the standard deployment is available for demo access.
11.2. Paid access: the contract between FortIT and the customer is concluded upon written acceptance of a corresponding offer or by signing a separate contract. The minimum term and the deployment variant are set out in the contract or the offer.
11.3. The contract for the use of FORTCONTROL is concluded for the term specified in the contract. After expiry of this term, the contract is automatically renewed for one further year at a time unless it is terminated by one of the parties.
11.4. The contract may be terminated in writing (letter or e-mail) without stating reasons as of the end of the term, subject to a notice period of two months.
12.1. FortIT reserves the right to suspend access to FORTCONTROL as a whole or for individual users without prior notice or to restrict it to certain functions if
12.2. FortIT informs the customer of a suspension and its reasons as quickly as possible and lifts the suspension as soon as the reason for it no longer applies.
12.3. In the event of such a suspension, FortIT is not obliged to waive the charging of fees for the period of the suspension and, moreover, is generally not liable for the consequences of a suspension.
13.1. FortIT may amend this user agreement. The version of the user agreement available online at https://www.fortcontrol.swiss/nutzungsbedingungen/ applies at the relevant time. FortIT notifies the customer of material amendments to the customer's detriment at least 30 days before they take effect; if the customer does not object in writing within this period, the amendments are deemed accepted. In the event of an objection, either party may terminate the contract as of the date on which the amendment takes effect.
13.2. Should any provision of this user agreement be or become invalid or unenforceable, the validity of the remaining provisions shall not be affected. The parties shall replace the invalid provision with a valid one that comes as close as possible to the economic purpose of the invalid provision.
13.3. This user agreement is governed by Swiss law, excluding the conflict-of-laws provisions and the United Nations Convention on Contracts for the International Sale of Goods (CISG). The exclusive place of jurisdiction is Zurich, Switzerland; mandatory statutory places of jurisdiction are reserved.
13.4. This user agreement is written in German. Translations are for information purposes only; in the event of discrepancies, the German version is authoritative.
1.1. Par gestion de la sécurité (Security Management), on entend un instrument (organisation, processus, technologie) destiné à garantir la sécurité dans le domaine thématique choisi (p. ex. cybersécurité).
1.2. fortControl (ci-après: FORTCONTROL) est un logiciel en tant que service (SaaS) exploité par FortIT AG (ci-après: FortIT), au moyen duquel ses clients peuvent mener ou soutenir leur gestion de la sécurité dans des domaines thématiques sélectionnés.
1.3. Un utilisateur est une personne physique qui accède à FORTCONTROL et l'utilise. Les utilisateurs peuvent être des employés, représentants, conseillers, mandataires ou agents du client, autorisés par le client à utiliser FORTCONTROL et auxquels des données d'accès ont été mises à disposition à cet effet par le client ou en son nom.
1.4. La Swiss Deployment Option est la variante de mise à disposition de FORTCONTROL dans laquelle l'infrastructure et l'exploitation sont assurées exclusivement en Suisse par des fournisseurs suisses (voir chiffre 2.5).
1.5. Les fonctions d'IA sont des fonctions optionnelles de FORTCONTROL qui analysent, résument, traduisent, proposent ou génèrent des contenus à l'aide de modèles d'intelligence artificielle (IA) d'un fournisseur tiers. Les fonctions d'IA sont désactivées par défaut et doivent être activées par le client (chiffre 3.7).
1.6. Un agent d'IA propre est un système d'IA exploité par le client ou pour son compte, qui accède à FORTCONTROL via les interfaces prévues à cet effet par FortIT et y lit ou traite des données enregistrées (chiffre 3.12).
2.1. La gestion de la sécurité est une composante essentielle de la gestion globale des risques d'une entreprise ou d'une organisation. Un système de gestion de la sécurité efficace gère activement les risques de sécurité grâce à une approche systématique d'identification, d'appréciation, de communication et de traitement des risques. Des exemples typiques de tels systèmes de gestion fondés sur les risques sont la gestion de la sécurité de l'information ou la gestion de la continuité des activités.
2.2. Le présent contrat d'utilisation a pour objet l'utilisation de l'application logicielle FORTCONTROL mise à disposition par FortIT, le client pouvant, au sens d'un «software-as-a-service», accéder en ligne à l'application logicielle via Internet et faire stocker les données du client liées à l'application sur des serveurs de FortIT ou d'un prestataire de services de FortIT. Cette offre de FortIT est désignée ci-après dans son ensemble par FORTCONTROL.
2.3. Les prestations réciproques dues en relation avec la mise à disposition et l'utilisation de FORTCONTROL résultent:
2.4. L'ensemble des documents précités font partie intégrante du présent accord. Le terme «contrat d'utilisation» englobe donc, outre le présent contrat, l'ensemble des documents énumérés ci-dessus. En cas de contradictions, les dispositions de l'offre ou du contrat signé séparément prévalent sur les autres documents.
2.5. FORTCONTROL est proposé en deux variantes de mise à disposition: (a) la mise à disposition standard sur une infrastructure cloud avec localisation des données en Suisse et (b) la Swiss Deployment Option, dans laquelle l'infrastructure, l'exploitation et l'envoi d'e-mails sont assurés exclusivement en Suisse par des fournisseurs suisses. La variante applicable au client résulte de l'offre ou du contrat; à défaut d'accord exprès, la mise à disposition standard s'applique. Les sous-traitants ultérieurs utilisés pour chaque variante sont énumérés dans le contrat de sous-traitance. Les fonctions d'IA optionnelles (chiffre 3.7) sont fournies, dans les deux variantes de mise à disposition, par le fournisseur d'IA désigné dans le contrat de sous-traitance dans l'UE (France) – uniquement par requête et sans entraînement avec des données des clients – et requièrent donc, également avec la Swiss Deployment Option, l'activation explicite par un administrateur du client.
3.1. FORTCONTROL offre aux utilisateurs la possibilité de mettre en place et d'exploiter efficacement une gestion de la sécurité individuelle. Cela comprend notamment les prestations suivantes (liste non exhaustive):
3.2. FORTCONTROL soutient le client dans sa gestion de la sécurité; la responsabilité de la conception, de l'adéquation et de la mise en œuvre de la gestion de la sécurité ainsi que des décisions qui en découlent demeure auprès du client. Le client est seul responsable des éventuels dommages survenant dans le cadre de sa gestion de la sécurité; toute responsabilité de FortIT est exclue à cet égard dans la mesure permise par la loi.
3.3. Pendant la durée du contrat, le client peut utiliser FORTCONTROL conformément au descriptif des fonctions et dans le cadre défini par le présent contrat d'utilisation.
3.4. FortIT fournira ses prestations de bonne foi, avec la diligence requise et conformément aux normes généralement reconnues et usuelles de la branche. Une disponibilité à cent pour cent de la partie applicative de FORTCONTROL et de l'infrastructure utilisée pour l'exploitation n'est toutefois techniquement pas réalisable. FortIT s'efforce néanmoins, sur la base du «best effort», avec les moyens à sa disposition et dans les limites de la rentabilité économique, de maintenir FORTCONTROL à un niveau de disponibilité élevé. FortIT se réserve le droit de procéder à des interruptions de FORTCONTROL pour des raisons de maintenance et de restreindre ou d'interrompre ainsi temporairement la disponibilité en tout ou en partie. FortIT effectue les travaux de maintenance planifiables, dans la mesure du possible, dans les fenêtres de maintenance décrites au chiffre 6.4 des TOM. Les travaux de maintenance ne pouvant être différés peuvent en revanche être effectués par FortIT à tout moment.
3.5. Pendant la durée du contrat, FortIT maintiendra FORTCONTROL en permanence à jour et utile au regard des conditions-cadres techniques et organisationnelles, mais ne peut garantir l'absence de perturbations de FORTCONTROL. FortIT surveille en permanence le bon fonctionnement de FORTCONTROL conformément au chiffre 6 des TOM et élimine, dans les limites des possibilités techniques et sur la base du «best effort», les éventuelles perturbations de l'exploitation ou de l'application qu'elle a elle-même découvertes ou qui lui ont été signalées par le client. FortIT est libre de traiter les dysfonctionnements qui ne restreignent pas de manière significative l'utilisation ou les fonctionnalités de FORTCONTROL pour le client non pas immédiatement, mais dans l'une des versions ultérieures de FORTCONTROL.
3.6. Les clients individuels ne peuvent prétendre à une conception particulière de FORTCONTROL ni au maintien des fonctions accessibles par son intermédiaire. Afin de préserver le niveau de qualité, mais aussi au regard des évolutions techniques ou économiques, FortIT a le droit d'adapter à tout moment FORTCONTROL ainsi que les fonctionnalités et contenus proposés dans ce cadre. FortIT annonce au client, dans la mesure du possible et avec un préavis raisonnable, les restrictions importantes de fonctions existantes.
3.7. Activation des fonctions d'IA: les fonctions d'IA sont désactivées par défaut. Elles ne peuvent être activées pour le mandant du client que par un administrateur du client et peuvent être désactivées à tout moment. Par l'activation, le client charge FortIT de transmettre les données nécessaires à cet effet au fournisseur d'IA désigné dans le contrat de sous-traitance (chiffre 2.7.2, tableau C). Le client s'assure que l'activation est compatible avec ses directives internes et les dispositions légales qui lui sont applicables. Sans activation, aucune donnée du client n'est transmise à un fournisseur d'IA.
3.8. Traitement des données par les fonctions d'IA: lorsque les fonctions d'IA sont activées, les contenus sélectionnés par l'utilisateur ainsi que le contexte nécessaire sont transmis au fournisseur d'IA et y sont traités exclusivement pour la fourniture de la fonction concernée. FortIT convient avec le fournisseur d'IA que les entrées et les résultats ne sont pas utilisés pour l'entraînement de modèles d'IA et ne sont pas conservés au-delà d'un éventuel contrôle des abus de courte durée. Les détails relatifs au fournisseur, au lieu de traitement et aux mesures de protection sont réglés dans le contrat de sous-traitance (chiffre 2.7) et les TOM (chiffre 3.3).
3.9. Nature des résultats: les fonctions d'IA reposent sur de grands modèles de langage. Ceux-ci fonctionnent sur une base probabiliste; leurs résultats peuvent être incomplets, inexacts, obsolètes ou trompeurs et ne sont pas reproductibles. Les contenus générés par les fonctions d'IA sont des propositions et des aides de travail. Ils ne remplacent ni l'examen professionnel par le client ni un conseil juridique, technique ou autre. Le client est tenu de vérifier l'exactitude, l'exhaustivité et la pertinence des contenus générés par l'IA avant de les utiliser – en particulier avant toute décision dans le cadre de son Security Management, avant leur reprise dans des directives, des évaluations des risques, des rapports ou des justificatifs et avant leur transmission à des tiers. FortIT signale comme tels les contenus générés par l'IA dans FORTCONTROL.
3.10. Responsabilité: la responsabilité de l'utilisation des contenus générés par l'IA et des décisions qui en découlent incombe au client (chiffre 3.2). FortIT ne garantit ni l'exactitude, l'exhaustivité ou l'adéquation des résultats ni la disponibilité durable de modèles d'IA déterminés. FortIT peut changer de modèles d'IA pour autant que le niveau de protection assuré dans le contrat de sous-traitance soit maintenu; le changement de fournisseur d'IA est régi par le chiffre 2.7.3 du contrat de sous-traitance. FortIT ne répond pas des dommages résultant de l'utilisation de contenus générés par l'IA non vérifiés; les autres dispositions du présent contrat d'utilisation relatives à la responsabilité demeurent inchangées.
3.11. Utilisation admise des fonctions d'IA: le client n'utilise les fonctions d'IA que dans le cadre du Security Management selon le présent chiffre 3 et non pour (a) évaluer des personnes de manière exclusivement automatisée ou prendre des décisions produisant des effets juridiques pour des personnes sans examen humain, (b) générer des contenus qui violent des droits de tiers ou le droit applicable, (c) contourner les mécanismes de protection du fournisseur d'IA ou (d) extraire ou reproduire des modèles d'IA. Le client s'assure que des données personnelles sensibles ne sont utilisées dans les fonctions d'IA que s'il y est autorisé.
3.12. Agents d'IA propres du client: FortIT met à disposition des interfaces documentées permettant au client de connecter ses propres agents d'IA à FORTCONTROL. Le client décide seul s'il utilise un agent d'IA et lequel. L'accès s'effectue au moyen d'informations d'identification personnelles ou techniques (clés API) assorties des autorisations attribuées par le client; le client traite ces informations d'identification de manière confidentielle, limite les autorisations au nécessaire et les révoque sans délai en cas de besoin. L'agent d'IA propre, son fournisseur, le lieu et la sécurité du traitement des données qui y est effectué ainsi que ses résultats se situent hors du domaine de responsabilité de FortIT; FortIT n'est à cet égard ni sous-traitant ni sous-traitant ultérieur. Le client demeure responsable de toutes les actions que son agent d'IA exécute dans FORTCONTROL, y compris la création, la modification et la suppression de données. Les chiffres 3.9 et 3.10 s'appliquent par analogie. Le chiffre 7.4 demeure applicable; FortIT peut limiter ou bloquer les accès qui perturbent l'exploitation de FORTCONTROL.
4.1. Pour les renseignements relatifs à l'utilisation de FORTCONTROL et pour le signalement d'éventuelles perturbations et dysfonctionnements (support), FortIT exploite un helpdesk que le client peut joindre par e-mail à l'adresse help@fortcontrol.swiss ainsi que par téléphone (hotline). Le helpdesk est à la disposition du client du lundi au vendredi (à l'exception des jours fériés légaux au siège de FortIT) entre 9h00 et 17h00 HEC/HEEC. Le numéro de la hotline est communiqué séparément au client ou indiqué sur les sites web de FortIT. En complément, FortIT met à disposition une documentation en ligne comprenant des guides et des réponses aux questions fréquentes.
4.2. Les prestations de support de FortIT visent le diagnostic et l'analyse des perturbations ou dysfonctionnements signalés ainsi que leur élimination, respectivement le maintien de la disponibilité de FORTCONTROL. D'autres prestations telles que le support à l'implémentation, le conseil ou la mise en œuvre de souhaits spécifiques du client ne sont pas comprises dans le support et font l'objet d'un accord séparé.
5.1. FortIT (a) met à la disposition du client un espace de stockage défini sur un stockage cloud exploité par FortIT ou un sous-traitant et (b) accorde au client le droit non exclusif, limité à la durée du contrat, non transmissible et non sous-licenciable d'utiliser FORTCONTROL conformément à sa destination. Le droit d'utilisation précité du client est subordonné au paiement en temps utile des redevances d'utilisation dues.
5.2. Le droit d'utilisation comprend le droit de doter les utilisateurs de données d'accès et de leur attribuer les rôles et droits prévus dans FORTCONTROL (p. ex. droits d'administrateur client, droits de lecture, etc.).
5.3. Le client n'est pas autorisé à mettre FORTCONTROL, dans son ensemble ou seulement pour certains aspects partiels, à la disposition de tiers extérieurs à sa propre entreprise ou à le rendre accessible à ceux-ci, à titre onéreux ou gratuit.
5.4. L'accès à FORTCONTROL s'effectue de manière chiffrée via Internet. Les utilisateurs peuvent être autorisés par le client dans FORTCONTROL et dotés de rôles.
5.5. Le client s'engage à veiller à ce que les utilisateurs qu'il a autorisés ne divulguent pas leurs données d'accès à des personnes non autorisées et les conservent avec soin et protégées de manière adéquate contre l'accès de tiers. Le client utilise les fonctions de sécurité disponibles dans FORTCONTROL (p. ex. authentification multifacteur ou connexion via le service d'identité du client) en fonction de ses besoins de protection et retire sans délai l'accès aux utilisateurs qui quittent l'organisation.
5.6. FortIT décline toute responsabilité pour les dommages subis par le client du fait de l'utilisation abusive ou de la perte des données d'accès remises aux utilisateurs concernés ou choisies par ceux-ci (p. ex. identifiant utilisateur, mot de passe).
5.7. L'application logicielle sur laquelle repose FORTCONTROL est protégée par le droit d'auteur. L'ensemble des droits sur cette application logicielle appartiennent à FortIT elle-même et/ou à des partenaires contractuels de FortIT. fortControl est une marque déposée de FortIT AG.
5.8. Dans les rapports entre FortIT et le client, les contenus générés par les fonctions d'IA reviennent au client; FortIT ne fait valoir aucun droit sur ceux-ci. Le client prend acte que les contenus générés par l'IA peuvent, selon le droit applicable, ne bénéficier d'aucune protection au titre du droit d'auteur et que des contenus identiques ou similaires peuvent également être générés pour d'autres clients.
6.1. Le client soutient FortIT dans la préparation et la fourniture de ses prestations, dans la mesure où cela est raisonnable, nécessaire et utile, et met à la disposition de FortIT, à ses propres frais et risques, toutes les prestations, informations, ressources matérielles et droits raisonnablement nécessaires.
6.2. Le client est responsable de l'existence et du maintien, de son côté, des conditions techniques requises pour l'accès à FORTCONTROL. Les exigences techniques relatives au raccordement à FORTCONTROL et à son utilisation sont régies par les exigences système publiées par FortIT.
6.3. Le client désigne à FortIT une personne de contact (administrateur client) pour les questions organisationnelles et techniques et tient ses coordonnées à jour.
7.1. Le client est responsable de ce que l'utilisation de FORTCONTROL par les utilisateurs qu'il a autorisés (a) n'enfreigne pas les dispositions du présent contrat d'utilisation, les droits de tiers (p. ex. droits d'auteur, autres droits de propriété intellectuelle, créances de toute nature, droits de propriété et autres droits réels ainsi que droits de la personnalité), les dispositions légales et/ou les bonnes mœurs; (b) ne porte en aucune manière atteinte au bon fonctionnement de FORTCONTROL et/ou de l'infrastructure sous-jacente au détriment de FortIT, d'autres utilisateurs ou d'autres tiers.
7.2. Le client est responsable du contenu des informations (données sous quelque forme que ce soit) que lui-même ou ses utilisateurs saisissent, stockent, transmettent, traitent et/ou mettent à disposition dans FORTCONTROL.
7.3. Le client est tenu de veiller à ce que ses utilisateurs vérifient les données et informations quant à la présence de virus ou d'autres routines logicielles nuisibles avant leur transmission et leur stockage dans FORTCONTROL, et utilisent à cet effet des programmes de protection conformes à l'état de la technique.
7.4. Les accès automatisés à FORTCONTROL (p. ex. via des interfaces ou des scripts) ne sont admis que dans le cadre des fonctions prévues et documentées à cet effet par FortIT. Les tests de sécurité visant FORTCONTROL requièrent l'accord écrit préalable de FortIT. Cela vaut également pour les accès par les agents d'IA propres du client (chiffre 3.12).
8.1. Lors de la sélection de Control-Sets prédéfinis fondés sur des normes protégées par le droit d'auteur, les utilisateurs doivent indiquer dans FORTCONTROL s'ils (respectivement le client) disposent d'une licence pour la norme concernée.
8.2. Le client garantit qu'il n'utilise, dans le cadre de ce service, que les Control-Sets disponibles dans FORTCONTROL qui sont soit libres de droits d'auteur, soit pour lesquels le client dispose lui-même d'une licence correspondante.
9.1. FortIT est tenue, en ce qui concerne les données déposées sur FORTCONTROL par le client ou ses utilisateurs, de prendre des précautions appropriées contre la perte, la compromission et les accès non autorisés de tiers. Les mesures prises – notamment en matière de contrôle d'accès, de chiffrement, de sauvegarde des données, de journalisation et de traitement des incidents – sont décrites dans les mesures techniques et organisationnelles (TOM), disponibles sous https://www.fortcontrol.swiss/tom/.
9.2. Les données du client sont stockées en Suisse conformément à la variante de mise à disposition convenue (chiffre 2.5). Les détails relatifs aux lieux de stockage, aux sous-traitants ultérieurs ainsi qu'aux mesures techniques et organisationnelles sont réglés dans le contrat de sous-traitance et dans les TOM qui en constituent l'annexe.
9.3. FortIT supprime irrévocablement, sans préavis, toutes les données stockées dans FORTCONTROL dans le cadre de la relation contractuelle à l'expiration d'un délai de 90 jours après la fin de la relation contractuelle.
9.4. Le client demeure seul ayant droit sur les données déposées dans FORTCONTROL par lui-même ou ses utilisateurs. Le client peut donc exiger à tout moment de FortIT (dans le cadre du délai de carence prévu au chiffre précédent, également après la fin du contrat) la remise de certaines ou de l'ensemble des données à lui-même, dans la mesure où cela n'est pas déjà possible via l'interface utilisateur. Sauf convention contraire, la remise des données s'effectue par une exportation de la base de données dans un format courant et lisible par machine.
10.1. Les dispositions en vigueur et applicables en matière de protection et de sécurité des données doivent être respectées par les deux parties. Le contrat de sous-traitance (CST) de FortIT, disponible sous https://www.fortcontrol.swiss/avv/, s'applique au traitement contractuel de données personnelles par FortIT pour le client et fait partie intégrante du présent contrat d'utilisation.
10.2. Le client est responsable de toutes les communications, autorisations et/ou approbations éventuellement requises en relation avec la mise à disposition de données personnelles par le client et le traitement de données personnelles par FortIT dans le cadre de la mise à disposition de FORTCONTROL.
10.3. Pour l'exécution de la relation contractuelle, FortIT collecte et traite les informations nécessaires à cet effet concernant le client et les utilisateurs qu'il a autorisés (identifiant client, données des utilisateurs et données d'utilisation) en qualité de responsable du traitement au sens des lois applicables en matière de protection des données. FortIT traite ces données de manière confidentielle, les utilise exclusivement pour la mise à disposition, l'exploitation, la sécurité et la facturation de FORTCONTROL ainsi que pour le support, ne fait appel à cet effet qu'aux sous-traitants ultérieurs désignés dans le contrat de sous-traitance et les efface ou les anonymise après la fin du contrat, sauf obligations légales de conservation. Les demandes d'accès et les autres droits des personnes concernées peuvent être exercés via office@fort-it.ch. L'utilisation de FORTCONTROL est régie exclusivement par le présent contrat d'utilisation, le contrat de sous-traitance et les TOM; la déclaration générale de protection des données de FortIT ne concerne que les sites web, la prise de contact et le support de FortIT.
10.4. FortIT est en droit d'utiliser les données obtenues grâce à l'utilisation de FORTCONTROL par le client ou ses utilisateurs (données d'utilisation, schémas de comportement, etc.) pour améliorer la plateforme. FortIT peut également utiliser ces données sous forme agrégée pour établir des profils anonymes et des données de référence (benchmarks) ne permettant pas d'identifier le client ou les utilisateurs.
10.5. En outre, FortIT peut (i) compiler des informations statistiques et autres relatives à la performance, à l'exploitation et à l'utilisation de FORTCONTROL et (ii) utiliser des données issues de FORTCONTROL sous forme agrégée pour la gestion de la sécurité et de l'exploitation, pour l'établissement d'analyses statistiques et à des fins de recherche et de développement (les clauses (i) et (ii) étant désignées ensemble par «analyses de service»). FortIT peut rendre les analyses de service accessibles au public; les analyses de service ne contiendront toutefois aucune donnée téléversée par le client, donnée personnelle ou information confidentielle sous une forme permettant d'identifier le client, les utilisateurs ou d'autres personnes. FortIT détient l'ensemble des droits de propriété intellectuelle sur les analyses de service.
11.1. Accès de démonstration: le contrat entre FortIT et le client est conclu par l'enregistrement d'un compte et l'acceptation du présent contrat d'utilisation intervenant à cette occasion, et a une durée de trois mois. L'accès de démonstration prend fin automatiquement sans résiliation; seule la mise à disposition standard est disponible pour l'accès de démonstration.
11.2. Accès payant: le contrat entre FortIT et le client est conclu par l'acceptation écrite d'une offre correspondante ou par la signature d'un contrat séparé. La durée minimale et la variante de mise à disposition sont fixées dans le contrat ou dans l'offre.
11.3. Le contrat relatif à l'utilisation de FORTCONTROL est conclu pour la durée fixée dans le contrat. À l'expiration de cette durée, le contrat se prolonge automatiquement d'une année supplémentaire à chaque fois, sauf résiliation par l'une des parties.
11.4. Le contrat peut être résilié par écrit (lettre ou e-mail), sans indication de motifs, pour la fin de la durée contractuelle, moyennant un préavis de deux mois.
12.1. FortIT se réserve le droit de suspendre sans préavis l'accès à FORTCONTROL dans son ensemble ou pour certains utilisateurs, ou de le restreindre à certaines fonctions, lorsque
12.2. FortIT informe le client d'une suspension et de ses motifs aussi rapidement que possible et lève la suspension dès que son motif a disparu.
12.3. En cas d'une telle suspension, FortIT n'est pas tenue de renoncer à la perception de redevances pour la période de suspension et n'est en outre généralement pas responsable des conséquences d'une suspension.
13.1. FortIT peut modifier le présent contrat d'utilisation. La version du contrat d'utilisation disponible en ligne sous https://www.fortcontrol.swiss/nutzungsbedingungen/ fait foi. FortIT communique au client les modifications importantes à son détriment au moins 30 jours avant leur entrée en vigueur; si le client ne s'y oppose pas par écrit dans ce délai, les modifications sont réputées acceptées. En cas d'opposition, chaque partie peut résilier le contrat pour la date d'entrée en vigueur de la modification.
13.2. Si une disposition du présent contrat d'utilisation est ou devient invalide ou inapplicable, la validité des autres dispositions n'en est pas affectée. Les parties remplacent la disposition invalide par une disposition valide se rapprochant le plus possible de l'objectif économique de la disposition invalide.
13.3. Le présent contrat d'utilisation est soumis au droit suisse, à l'exclusion des règles de conflit de lois et de la Convention des Nations Unies sur les contrats de vente internationale de marchandises (CVIM). Le for exclusif est Zurich, Suisse; les fors légaux impératifs demeurent réservés.
13.4. Le présent contrat d'utilisation est rédigé en langue allemande. Les traductions sont fournies à titre d'information uniquement; en cas de divergences, la version allemande fait foi.
1.1. Per gestione della sicurezza (Security Management) si intende uno strumento (organizzazione, processi, tecnologia) volto a garantire la sicurezza nell'ambito tematico scelto (p. es. cibersicurezza).
1.2. fortControl (di seguito: FORTCONTROL) è un software as a service (SaaS) gestito da FortIT AG (di seguito: FortIT), tramite il quale i suoi clienti possono svolgere o supportare la propria gestione della sicurezza in ambiti tematici selezionati.
1.3. Un utente è una persona fisica che accede a FORTCONTROL e lo utilizza. Gli utenti possono essere dipendenti, rappresentanti, consulenti, appaltatori o agenti del cliente, autorizzati dal cliente a utilizzare FORTCONTROL e ai quali a tale scopo sono stati messi a disposizione dati di accesso dal cliente o in suo nome.
1.4. La Swiss Deployment Option è la variante di messa a disposizione di FORTCONTROL nella quale l'infrastruttura e la gestione operativa sono assicurate esclusivamente in Svizzera da fornitori svizzeri (cfr. cifra 2.5).
1.5. Le funzioni di IA sono funzioni opzionali di FORTCONTROL che analizzano, riassumono, traducono, propongono o generano contenuti mediante modelli di intelligenza artificiale (IA) di un fornitore terzo. Le funzioni di IA sono disattivate per impostazione predefinita e devono essere attivate dal cliente (cifra 3.7).
1.6. Un agente di IA proprio è un sistema di IA gestito dal cliente o per suo conto che accede a FORTCONTROL tramite le interfacce previste a tale scopo da FortIT e vi legge o tratta dati memorizzati (cifra 3.12).
2.1. La gestione della sicurezza è una componente essenziale della gestione complessiva dei rischi di un'impresa o di un'organizzazione. Un sistema efficace di gestione della sicurezza gestisce attivamente i rischi di sicurezza attraverso un approccio sistematico di identificazione, valutazione, comunicazione e trattamento dei rischi. Esempi tipici di tali sistemi di gestione basati sui rischi sono la gestione della sicurezza delle informazioni o la gestione della continuità operativa.
2.2. Oggetto del presente contratto di utilizzo è l'utilizzo dell'applicazione software FORTCONTROL messa a disposizione da FortIT, per cui il cliente, nel senso di un «software as a service», può accedere online tramite Internet all'applicazione software e far memorizzare i dati del cliente relativi all'applicazione su server di FortIT o di un fornitore di servizi di FortIT. Questa offerta di FortIT è di seguito denominata nel suo insieme FORTCONTROL.
2.3. Le prestazioni reciprocamente dovute in relazione alla messa a disposizione e all'utilizzo di FORTCONTROL risultano da:
2.4. Tutti i documenti sopra menzionati sono da intendersi quale parte integrante del presente accordo. Il termine «contratto di utilizzo» comprende pertanto, oltre al presente contratto, anche tutti i documenti sopra elencati. In caso di contraddizioni, le disposizioni dell'offerta o del contratto firmato separatamente prevalgono sugli altri documenti.
2.5. FORTCONTROL è offerto in due varianti di messa a disposizione: (a) la messa a disposizione standard su infrastruttura cloud con ubicazione dei dati in Svizzera e (b) la Swiss Deployment Option, nella quale infrastruttura, gestione operativa e invio di e-mail sono assicurati esclusivamente in Svizzera da fornitori svizzeri. La variante applicabile al cliente risulta dall'offerta o dal contratto; in assenza di un accordo esplicito si applica la messa a disposizione standard. I subresponsabili impiegati per ciascuna variante sono elencati nel contratto di trattamento dei dati per conto terzi. Le funzioni di IA opzionali (cifra 3.7) sono fornite, in entrambe le varianti di messa a disposizione, dal fornitore di IA indicato nel contratto di trattamento dei dati per conto terzi nell'UE (Francia) – solo per richiesta e senza addestramento con dati dei clienti – e presuppongono pertanto, anche con la Swiss Deployment Option, l'attivazione esplicita da parte di un amministratore del cliente.
3.1. FORTCONTROL offre agli utenti la possibilità di costruire e gestire in modo efficiente una gestione della sicurezza individuale. Ciò comprende in particolare le seguenti prestazioni (elenco non esaustivo):
3.2. FORTCONTROL supporta il cliente nella sua gestione della sicurezza; la responsabilità per l'impostazione, l'adeguatezza e l'attuazione della gestione della sicurezza nonché per le decisioni che ne derivano rimane al cliente. Per eventuali danni che si verificano nell'ambito della gestione della sicurezza del cliente è responsabile unicamente il cliente; una responsabilità di FortIT è esclusa a tale riguardo nella misura consentita dalla legge.
3.3. Durante la durata del contratto il cliente può utilizzare FORTCONTROL conformemente alla descrizione delle funzioni e nel quadro definito dal presente contratto di utilizzo.
3.4. FortIT fornirà le proprie prestazioni in buona fede, con la diligenza necessaria e in conformità agli standard di settore generalmente riconosciuti e usuali. Una disponibilità al cento per cento della parte applicativa di FORTCONTROL e dell'infrastruttura utilizzata per la gestione operativa non è tuttavia tecnicamente realizzabile. FortIT si impegna comunque, su base «best effort», con i mezzi a sua disposizione e nei limiti dell'economicità, a mantenere FORTCONTROL a un livello elevato di disponibilità. FortIT si riserva il diritto di effettuare interruzioni di FORTCONTROL per motivi di manutenzione e di limitare o interrompere così temporaneamente la disponibilità in tutto o in parte. FortIT esegue i lavori di manutenzione pianificabili, ove possibile, nelle finestre di manutenzione descritte alla cifra 6.4 delle TOM. I lavori di manutenzione non differibili possono invece essere eseguiti da FortIT in qualsiasi momento.
3.5. Durante la durata del contratto FortIT manterrà FORTCONTROL costantemente aggiornato e utile in relazione alle condizioni quadro tecniche e organizzative, ma non può garantire l'assenza di disturbi di FORTCONTROL. FortIT monitora costantemente la funzionalità di FORTCONTROL conformemente alla cifra 6 delle TOM ed elimina, nei limiti delle possibilità tecniche e su base «best effort», eventuali disturbi della gestione operativa o dell'applicazione da essa stessa rilevati o segnalati dal cliente. FortIT è libera di affrontare i malfunzionamenti che non limitano in modo significativo l'utilizzo o le funzionalità di FORTCONTROL per il cliente non immediatamente, ma in una delle release successive di FORTCONTROL.
3.6. Non sussiste alcun diritto dei singoli clienti a una determinata configurazione di FORTCONTROL o al mantenimento delle funzioni accessibili tramite esso. Per preservare lo standard di qualità, ma anche in considerazione degli sviluppi tecnici o economici, FortIT ha il diritto di adeguare in qualsiasi momento FORTCONTROL nonché le funzionalità e i contenuti ivi offerti. FortIT annuncia al cliente, ove possibile e con un preavviso ragionevole, le limitazioni sostanziali di funzioni esistenti.
3.7. Attivazione delle funzioni di IA: le funzioni di IA sono disattivate per impostazione predefinita. Possono essere attivate per il mandante del cliente esclusivamente da un amministratore del cliente e possono essere disattivate in qualsiasi momento. Con l'attivazione il cliente incarica FortIT di trasmettere i dati a tal fine necessari al fornitore di IA indicato nel contratto di trattamento dei dati per conto terzi (cifra 2.7.2, tabella C). Il cliente si assicura che l'attivazione sia compatibile con le proprie direttive interne e con le disposizioni legali a lui applicabili. Senza attivazione nessun dato del cliente viene trasmesso a un fornitore di IA.
3.8. Trattamento dei dati da parte delle funzioni di IA: con le funzioni di IA attivate, i contenuti selezionati dall'utente e il contesto a tal fine necessario sono trasmessi al fornitore di IA e ivi trattati esclusivamente per fornire la rispettiva funzione. FortIT conviene con il fornitore di IA che input e risultati non siano utilizzati per l'addestramento di modelli di IA e non siano conservati oltre un eventuale controllo degli abusi di breve durata. I dettagli relativi a fornitore, luogo di trattamento e misure di protezione sono disciplinati nel contratto di trattamento dei dati per conto terzi (cifra 2.7) e nelle TOM (cifra 3.3).
3.9. Natura dei risultati: le funzioni di IA si basano su grandi modelli linguistici. Questi operano su base probabilistica; i loro risultati possono essere incompleti, inesatti, obsoleti o fuorvianti e non sono riproducibili. I contenuti generati dalle funzioni di IA sono proposte e ausili di lavoro. Non sostituiscono né la verifica specialistica da parte del cliente né una consulenza legale, tecnica o di altro tipo. Il cliente è tenuto a verificare la correttezza, la completezza e l'adeguatezza dei contenuti generati dall'IA prima di utilizzarli – in particolare prima di decisioni nell'ambito del proprio Security Management, prima di riprenderli in direttive, valutazioni dei rischi, rapporti o attestazioni e prima di trasmetterli a terzi. FortIT contrassegna come tali i contenuti generati dall'IA in FORTCONTROL.
3.10. Responsabilità: la responsabilità per l'utilizzo dei contenuti generati dall'IA e per le decisioni che ne derivano spetta al cliente (cifra 3.2). FortIT non garantisce né la correttezza, la completezza o l'idoneità dei risultati né la disponibilità permanente di determinati modelli di IA. FortIT può cambiare i modelli di IA purché resti garantito il livello di protezione assicurato nel contratto di trattamento dei dati per conto terzi; il cambio del fornitore di IA è disciplinato dalla cifra 2.7.3 del contratto di trattamento dei dati per conto terzi. FortIT non risponde dei danni derivanti dall'utilizzo di contenuti generati dall'IA non verificati; le altre disposizioni del presente contratto di utilizzo in materia di responsabilità restano invariate.
3.11. Utilizzo ammesso delle funzioni di IA: il cliente utilizza le funzioni di IA solo nell'ambito del Security Management secondo la presente cifra 3 e non per (a) valutare persone in modo esclusivamente automatizzato o prendere decisioni con effetti giuridici per persone senza verifica umana, (b) generare contenuti che violano diritti di terzi o il diritto applicabile, (c) eludere i meccanismi di protezione del fornitore di IA o (d) estrarre o replicare modelli di IA. Il cliente si assicura che dati personali degni di particolare protezione siano utilizzati nelle funzioni di IA solo se vi è autorizzato.
3.12. Agenti di IA propri del cliente: FortIT mette a disposizione interfacce documentate tramite le quali il cliente può collegare a FORTCONTROL i propri agenti di IA. Il cliente decide da solo se e quale agente di IA impiegare. L'accesso avviene tramite credenziali personali o tecniche (chiavi API) con le autorizzazioni assegnate dal cliente; il cliente tratta tali credenziali in modo confidenziale, limita le autorizzazioni al necessario e le revoca tempestivamente in caso di necessità. L'agente di IA proprio, il suo fornitore, il luogo e la sicurezza del trattamento dei dati ivi effettuato nonché i suoi risultati esulano dall'ambito di responsabilità di FortIT; FortIT non è al riguardo né responsabile del trattamento né subresponsabile. Il cliente resta responsabile di tutte le azioni che il suo agente di IA esegue in FORTCONTROL, compresa la creazione, la modifica e la cancellazione di dati. Le cifre 3.9 e 3.10 si applicano per analogia. La cifra 7.4 resta applicabile; FortIT può limitare o bloccare gli accessi che pregiudicano l'esercizio di FORTCONTROL.
4.1. Per informazioni sull'utilizzo di FORTCONTROL e per la segnalazione di eventuali disturbi e malfunzionamenti (supporto), FortIT gestisce un helpdesk che il cliente può raggiungere via e-mail all'indirizzo help@fortcontrol.swiss e per telefono (hotline). L'helpdesk è a disposizione del cliente dal lunedì al venerdì (esclusi i giorni festivi legali presso la sede di FortIT) tra le 9.00 e le 17.00 CET/CEST. Il numero della hotline viene comunicato separatamente al cliente o è indicato sui siti web di FortIT. A complemento, FortIT mette a disposizione una documentazione online con guide e risposte alle domande frequenti.
4.2. Le prestazioni di supporto di FortIT sono volte alla diagnosi e all'analisi dei disturbi o malfunzionamenti segnalati e alla loro eliminazione, rispettivamente al mantenimento della disponibilità di FORTCONTROL. Ulteriori prestazioni quali p. es. supporto all'implementazione, consulenza o realizzazione di richieste specifiche del cliente non sono comprese nel supporto e vengono convenute separatamente.
5.1. FortIT (a) mette a disposizione del cliente uno spazio di memoria definito su uno storage cloud gestito da FortIT o da un subappaltatore e (b) concede al cliente il diritto non esclusivo, limitato alla durata del contratto, non trasferibile e non sublicenziabile di utilizzare FORTCONTROL conformemente alla sua destinazione. Il suddetto diritto di utilizzo del cliente è subordinato al pagamento tempestivo dei canoni di utilizzo dovuti.
5.2. Il diritto di utilizzo comprende il diritto di dotare gli utenti di dati di accesso e di attribuire loro i ruoli e i diritti previsti in FORTCONTROL (p. es. diritti di amministratore cliente, diritti di lettura ecc.).
5.3. Il cliente non è autorizzato a mettere a disposizione o rendere accessibile FORTCONTROL, nel suo insieme o solo per determinati aspetti parziali, a terzi esterni alla propria impresa, a titolo oneroso o gratuito.
5.4. L'accesso a FORTCONTROL avviene in forma cifrata tramite Internet. Gli utenti possono essere autorizzati dal cliente in FORTCONTROL e dotati di ruoli.
5.5. Il cliente si impegna a garantire che gli utenti da lui autorizzati non rivelino i propri dati di accesso a persone non autorizzate e li conservino con cura e adeguatamente protetti dall'accesso di terzi. Il cliente utilizza le funzioni di sicurezza disponibili in FORTCONTROL (p. es. autenticazione a più fattori o accesso tramite il servizio di identità del cliente) in base alle proprie esigenze di protezione e revoca senza indugio l'accesso agli utenti che lasciano l'organizzazione.
5.6. FortIT declina qualsiasi responsabilità per danni subiti dal cliente a seguito dell'uso abusivo o della perdita dei dati di accesso consegnati ai rispettivi utenti o da essi scelti (p. es. identificativo utente, password).
5.7. L'applicazione software su cui si basa FORTCONTROL è protetta dal diritto d'autore. Tutti i diritti su tale applicazione software spettano a FortIT stessa e/o a partner contrattuali di FortIT. fortControl è un marchio registrato di FortIT AG.
5.8. Nei rapporti tra FortIT e il cliente, i contenuti generati dalle funzioni di IA spettano al cliente; FortIT non fa valere alcun diritto su di essi. Il cliente prende atto che i contenuti generati dall'IA possono, secondo il diritto applicabile, non godere di protezione ai sensi del diritto d'autore e che contenuti identici o simili possono essere generati anche per altri clienti.
6.1. Il cliente supporta FortIT nella preparazione e nella fornitura delle sue prestazioni, nella misura in cui ciò sia ragionevole, necessario e opportuno, e mette a disposizione di FortIT, a proprie spese e a proprio rischio, tutte le prestazioni, informazioni, risorse materiali e diritti ragionevolmente necessari.
6.2. Il cliente è responsabile della sussistenza e del mantenimento, dal suo lato, dei presupposti tecnici necessari per l'accesso a FORTCONTROL. I requisiti tecnici relativi al collegamento a FORTCONTROL e al suo utilizzo sono disciplinati dai requisiti di sistema pubblicati da FortIT.
6.3. Il cliente designa a FortIT una persona di contatto (amministratore cliente) per le questioni organizzative e tecniche e ne mantiene aggiornati i dati.
7.1. Il cliente è responsabile del fatto che l'utilizzo di FORTCONTROL da parte degli utenti da lui autorizzati (a) non violi le disposizioni del presente contratto di utilizzo, i diritti di terzi (p. es. diritti d'autore, altri diritti di proprietà intellettuale, crediti di ogni tipo, diritti di proprietà e altri diritti reali nonché diritti della personalità), le disposizioni legali e/o il buon costume; (b) non pregiudichi in alcun modo la funzionalità di FORTCONTROL e/o dell'infrastruttura sottostante a danno di FortIT, di altri utilizzatori o di ulteriori terzi.
7.2. Il cliente è responsabile del contenuto delle informazioni (dati in qualsiasi forma) che egli stesso o i suoi utenti registrano, memorizzano, trasmettono, trattano e/o mettono a disposizione in FORTCONTROL.
7.3. Il cliente è tenuto a garantire che i suoi utenti verifichino i dati e le informazioni quanto alla presenza di virus o altre routine software dannose prima della trasmissione e della memorizzazione in FORTCONTROL e utilizzino a tale scopo programmi di protezione conformi allo stato della tecnica.
7.4. Gli accessi automatizzati a FORTCONTROL (p. es. tramite interfacce o script) sono ammessi solo nell'ambito delle funzioni previste e documentate a tale scopo da FortIT. I test di sicurezza contro FORTCONTROL richiedono il previo consenso scritto di FortIT. Ciò vale anche per gli accessi da parte di agenti di IA propri del cliente (cifra 3.12).
8.1. Al momento della selezione di Control-Set predefiniti basati su norme protette dal diritto d'autore, gli utenti devono indicare in FORTCONTROL se essi (rispettivamente il cliente) dispongono di una licenza per la norma in questione.
8.2. Il cliente garantisce di utilizzare, nell'ambito di questo servizio, esclusivamente i Control-Set disponibili in FORTCONTROL che sono liberi da diritti d'autore o per i quali il cliente stesso dispone di una licenza corrispondente.
9.1. FortIT è tenuta, in relazione ai dati depositati su FORTCONTROL dal cliente o dai suoi utenti, ad adottare precauzioni idonee contro la perdita, la compromissione e gli accessi non autorizzati da parte di terzi. Le misure adottate – in particolare in materia di controllo degli accessi, cifratura, salvataggio dei dati, registrazione dei log e gestione delle anomalie – sono descritte nelle misure tecniche e organizzative (TOM), disponibili all'indirizzo https://www.fortcontrol.swiss/tom/.
9.2. I dati del cliente sono memorizzati in Svizzera conformemente alla variante di messa a disposizione convenuta (cifra 2.5). I dettagli relativi ai luoghi di memorizzazione, ai subresponsabili e alle misure tecniche e organizzative sono disciplinati nel contratto di trattamento dei dati per conto terzi e nelle TOM quale suo allegato.
9.3. FortIT cancella irrevocabilmente e senza preavviso tutti i dati memorizzati in FORTCONTROL nell'ambito del rapporto contrattuale decorsi 90 giorni dalla cessazione del rapporto contrattuale.
9.4. Il cliente rimane l'unico titolare dei diritti sui dati depositati in FORTCONTROL da lui stesso o dai suoi utenti. Il cliente può pertanto esigere in qualsiasi momento da FortIT (nell'ambito del periodo di carenza di cui alla cifra precedente anche dopo la cessazione del contratto) la consegna di singoli dati o di tutti i dati a sé stesso, nella misura in cui ciò non sia già possibile tramite l'interfaccia utente. Salvo diverso accordo, la consegna dei dati avviene mediante un'esportazione della banca dati in un formato corrente e leggibile a macchina.
10.1. Le disposizioni vigenti e di volta in volta applicabili in materia di protezione e sicurezza dei dati devono essere rispettate da entrambe le parti. Il contratto di trattamento dei dati per conto terzi (CTD) di FortIT, disponibile all'indirizzo https://www.fortcontrol.swiss/avv/, si applica al trattamento contrattuale di dati personali da parte di FortIT per il cliente ed è parte integrante del presente contratto di utilizzo.
10.2. Il cliente è responsabile di tutte le comunicazioni, i consensi e/o le autorizzazioni eventualmente necessari in relazione alla messa a disposizione di dati personali da parte del cliente e al trattamento di dati personali da parte di FortIT nell'ambito della messa a disposizione di FORTCONTROL.
10.3. Per la gestione del rapporto contrattuale FortIT raccoglie e tratta le informazioni a tal fine necessarie sul cliente e sugli utenti da lui autorizzati (identificativo cliente, dati degli utenti e dati di utilizzo) in qualità di titolare del trattamento ai sensi delle leggi applicabili in materia di protezione dei dati. FortIT tratta tali dati in modo confidenziale, li utilizza esclusivamente per la messa a disposizione, l'esercizio, la sicurezza e la fatturazione di FORTCONTROL nonché per il supporto, ricorre a tale scopo soltanto ai subresponsabili indicati nel contratto di trattamento dei dati per conto terzi e li cancella o anonimizza dopo la fine del contratto, salvo obblighi legali di conservazione. Le richieste di accesso e gli altri diritti degli interessati possono essere esercitati tramite office@fort-it.ch. Per l'utilizzo di FORTCONTROL valgono esclusivamente il presente contratto di utilizzo, il contratto di trattamento dei dati per conto terzi e le TOM; la dichiarazione generale sulla protezione dei dati di FortIT riguarda soltanto i siti web, la presa di contatto e il supporto di FortIT.
10.4. FortIT è autorizzata a utilizzare i dati ottenuti attraverso l'utilizzo di FORTCONTROL da parte del cliente o dei suoi utenti (dati di utilizzo, modelli di comportamento ecc.) per migliorare la piattaforma. FortIT può utilizzare tali dati anche in forma aggregata per creare profili anonimi e dati di benchmark che non consentono l'identificazione del cliente o degli utenti.
10.5. Inoltre FortIT può (i) compilare informazioni statistiche e di altro tipo relative alle prestazioni, alla gestione operativa e all'utilizzo di FORTCONTROL e (ii) utilizzare dati provenienti da FORTCONTROL in forma aggregata per la gestione della sicurezza e dell'esercizio, per l'elaborazione di analisi statistiche e per scopi di ricerca e sviluppo (le clausole (i) e (ii) sono denominate congiuntamente «analisi del servizio»). FortIT può rendere pubblicamente accessibili le analisi del servizio; le analisi del servizio non conterranno tuttavia dati caricati dal cliente, dati personali o informazioni confidenziali in una forma che possa servire a identificare il cliente, gli utenti o altre persone. FortIT detiene tutti i diritti di proprietà intellettuale sulle analisi del servizio.
11.1. Accesso demo: il contratto tra FortIT e il cliente si conclude con la registrazione di un account e con l'accettazione del presente contratto di utilizzo effettuata in tale occasione, e ha una durata di tre mesi. L'accesso demo termina automaticamente senza disdetta; per l'accesso demo è disponibile esclusivamente la messa a disposizione standard.
11.2. Accesso a pagamento: il contratto tra FortIT e il cliente si conclude con l'accettazione scritta di un'offerta corrispondente o con la firma di un contratto separato. La durata minima e la variante di messa a disposizione sono stabilite nel contratto o nell'offerta.
11.3. Il contratto relativo all'utilizzo di FORTCONTROL è concluso per la durata stabilita nel contratto. Alla scadenza di tale durata il contratto si rinnova automaticamente di volta in volta per un ulteriore anno, salvo disdetta da parte di una delle parti.
11.4. Il contratto può essere disdetto per iscritto (lettera o e-mail), senza indicazione di motivi, per la fine della durata contrattuale con un preavviso di due mesi.
12.1. FortIT si riserva il diritto di sospendere senza preavviso l'accesso a FORTCONTROL nel suo insieme o per singoli utenti, o di limitarlo a determinate funzioni, qualora
12.2. FortIT informa il cliente di una sospensione e dei relativi motivi il più rapidamente possibile e revoca la sospensione non appena il motivo è venuto meno.
12.3. In caso di tale sospensione FortIT non è tenuta a rinunciare alla riscossione dei canoni per il periodo della sospensione e, inoltre, non risponde in generale delle conseguenze di una sospensione.
13.1. FortIT può modificare il presente contratto di utilizzo. Fa stato di volta in volta la versione del contratto di utilizzo disponibile online all'indirizzo https://www.fortcontrol.swiss/nutzungsbedingungen/. FortIT comunica al cliente le modifiche sostanziali a suo svantaggio almeno 30 giorni prima della loro entrata in vigore; se il cliente non si oppone per iscritto entro tale termine, le modifiche si considerano accettate. In caso di opposizione, ciascuna parte può disdire il contratto per la data di entrata in vigore della modifica.
13.2. Qualora una disposizione del presente contratto di utilizzo sia o divenga inefficace o inattuabile, l'efficacia delle restanti disposizioni non ne è pregiudicata. Le parti sostituiscono la disposizione inefficace con una disposizione efficace che si avvicini il più possibile allo scopo economico della disposizione inefficace.
13.3. Il presente contratto di utilizzo è soggetto al diritto svizzero, con esclusione delle norme sui conflitti di leggi e della Convenzione delle Nazioni Unite sui contratti di compravendita internazionale di merci (CISG). Foro esclusivo è Zurigo, Svizzera; restano riservati i fori legali imperativi.
13.4. Il presente contratto di utilizzo è redatto in lingua tedesca. Le traduzioni hanno unicamente scopo informativo; in caso di divergenze fa stato la versione tedesca.
Lernen Sie fortControl in einer persönlichen Demo kennen.
fortControl – Risikomanagement und Informationssicherheit einfach steuern.