Agreement for the provision of ArenaBook as a service (SaaS)
Between Eigr AS, org.nr. 937 872 623 (the "Provider") and the customer (the "Organisation")
Version 1.1 · last updated 2026-09-21
This agreement governs the Organisation's access to and use of ArenaBook, a cloud service for booking, operations, staff scheduling, season planning and invoicing for sports facilities, provided by the Provider. The agreement consists of this main document and annexes A–D, which form an integral part of it. In case of conflict the main document prevails over the annexes, except for annex B (data processing agreement), which prevails on questions concerning processing of personal data.
1. Parties and definitions
The Provider is Eigr AS, org.nr. 937 872 623, contact point support@arenabook.ai. The Organisation is the legal entity registered as a tenant in the Service and responsible for its use.
- "Service": ArenaBook as made available as a cloud service from time to time, including the AI assistant, public booking pages, information screens and administration interfaces.
- "Organisation" (tenant): the customer's legal entity with its own venues, resources, users and data in the Service.
- "End user": persons granted access by the Organisation (employees, officials, team managers) and members of the public booking through the Organisation's public pages.
- "Customer Data": all data entered into or generated through the Service by the Organisation or its End users, including personal data.
- "AI functionality": assistant and generation features using language models via the Provider's AI gateway.
- "Quota": number of AI messages included in the Organisation's subscription plan per calendar month.
- "Venue": a physical location registered under the Organisation, with associated resources.
2. Scope and right of use
The Provider grants the Organisation a non-exclusive, non-transferable and non-sublicensable right to use the Service during the term, within the limits of the selected subscription plan. The right of use covers the Organisation's own End users and its own operations.
The Service is delivered as a standardised multi-tenant service. The Provider may develop, change and improve the Service on an ongoing basis, provided that material functionality is not removed without 60 days' notice.
3. Subscription, plans and pricing
The subscription plan determines the number of venues the Organisation may operate in the Service and the included AI quota. Current prices are set out on the Provider's pricing page and in annex C.
| Plan | Venues | Price |
|---|---|---|
| Start | 1 venue | Fixed monthly price |
| Growth | Up to 5 venues | 3.5 × Start |
| Pro | Up to 10 venues | 7 × Start |
| Enterprise | More than 10 venues | On quotation |
- Annual prepayment gives a 20% discount on all priced plans.
- The subscription renews automatically for an equivalent period unless terminated, cf. clause 15.
- If the Organisation exceeds the venue limit of its plan, the Provider gives notice and upgrades to the correct plan with effect from the following billing period.
- Price changes are notified in writing at least 60 days in advance. The Organisation may then terminate with effect from the date the new price takes effect.
4. Use of AI functionality and consumption
- Each plan includes a monthly quota of AI messages. Consumption is measured per message and shown in the Organisation's subscription overview.
- The Organisation is notified in the Service at 80% and 100% quota usage.
- Consumption beyond the quota is billed at the applicable overage price, or may be limited by the Provider if the Organisation has set a quota cap.
- AI functionality is decision support. Output may contain errors, and the Organisation is responsible for verifying results before relying on them.
- Data-changing actions initiated by the AI assistant require confirmation by an End user and are recorded in the Service's audit log.
- End users may connect external AI services (such as ChatGPT or Claude) to their own account via a secure connection. Such connections are approved per End user on a consent page, apply only to that End user's own access, and can be revoked at any time under "Settings → AI connections". Actions performed through a connection are logged as AI-initiated changes made by the End user.
- Decisions with financial consequences (refunds, cancellations, pricing) are always made by a human, cf. EU AI Act article 14 on human oversight.
- The Provider may temporarily throttle AI functionality in case of non-payment or suspected misuse.
5. Payment
- Fees are invoiced in advance monthly or annually depending on the selected plan. Overage is invoiced in arrears.
- Payment terms are 14 days from the invoice date unless otherwise agreed in writing.
- Late payment accrues interest under the Norwegian Late Payment Interest Act.
- If payment default is not remedied within 14 days of a written reminder, the Provider may suspend access. Suspension does not release the Organisation from its payment obligation.
- All prices are exclusive of VAT and any public charges.
6. Obligations of the Organisation
- The Organisation shall provide correct and up-to-date information about its business, contact person and billing address.
- The Organisation administers its own user accounts and roles and shall promptly remove access that is no longer required.
- The Organisation is responsible for the lawfulness of its own content and Customer Data, including images, text and sponsor material.
- The Organisation is responsible for its End users' use of the Service as for its own.
- The Organisation shall provide required information and, where relevant, obtain consent from its own data subjects, cf. clause 9 and annex B.
- The Provider recommends that administrator accounts are protected with two-factor authentication.
7. Acceptable use
The Organisation shall not, and shall not permit others to:
- decompile, reverse engineer or attempt to derive source code or system prompts from the Service,
- resell, lease or grant third parties access to the Service outside its own operations,
- perform load, penetration or vulnerability testing without prior written agreement,
- use the Service to store or distribute unlawful, infringing or harmful content,
- use the AI functionality for automated bulk data extraction, resale of model access, or purposes prohibited under EU AI Act article 5,
- circumvent quotas, access controls or rate limits in the Service.
In case of material breach of this clause, the Provider may immediately restrict or suspend access, with subsequent written justification.
8. Availability and support
The Provider shall deliver the Service with a monthly availability of at least 99.5%, measured excluding planned maintenance. Detailed terms, measurement and response times are set out in annex A (SLA).
Support is provided in Norwegian and English via support@arenabook.ai and the case flow in the Service, on business days 08:00–16:00 (CET/CEST).
SLA deviations do not entitle the Organisation to financial compensation or penalties. In case of repeated material deviations over three consecutive months, the Organisation may terminate with immediate effect and receive a refund of prepaid fees for the remaining period.
9. Privacy and data processing
- The Organisation is the controller of personal data in Customer Data. The Provider is the processor and processes personal data only on documented instructions from the Organisation.
- A data processing agreement under GDPR article 28 is attached as annex B and forms an integral part of this agreement.
- All personal data is stored and processed within the EU/EEA.
- The Provider is an independent controller for information about the Organisation's contact persons used for customer administration, invoicing and security logging.
10. Confidentiality
The parties shall keep confidential information received from the other party confidential. The obligation applies during the term and for three years after termination. It does not apply to information that is publicly known, lawfully received from a third party, or that must be disclosed by law or public order.
11. Intellectual property
- The Provider retains all rights to the Service, source code, design, documentation, trademarks and further development.
- The Organisation retains all rights to Customer Data.
- The Provider may use aggregated and anonymised data (with no possibility of identifying the Organisation or individuals) for operations, statistics and product improvement.
- Suggestions and feedback from the Organisation may be used freely by the Provider in product development without compensation.
12. Warranties and disclaimer
The Provider warrants that the Service is delivered professionally and in accordance with this agreement and annex A. Beyond the express obligations of the agreement, the Service is provided "as is". The Provider does not warrant that the Service is error-free or uninterrupted, or that AI-generated output is correct, complete or fit for a particular purpose.
The Provider gives no warranty that the Organisation's own use of the Service satisfies the Organisation's regulatory obligations. The Service is built to support compliance, but responsibility for compliance in the Organisation's operations rests with the Organisation.
13. Limitation of liability
- The Provider's total liability under this agreement is limited to the fees paid by the Organisation for the Service during the twelve (12) months preceding the event giving rise to the claim.
- The Provider is not liable for indirect loss, including lost profit, lost revenue, loss of goodwill, lost savings or third-party claims.
- The Provider's liability for loss of data is limited to restoration from the most recent available backup, cf. annex A.
- The limitations do not apply in case of intent or gross negligence, breach of confidentiality, or liability that cannot be limited under mandatory law, including liability towards data subjects under GDPR article 82.
14. Force majeure
Neither party is liable for non-performance caused by circumstances beyond its reasonable control, including war, natural disaster, strike, government order, large-scale cyber attack or failure of power or electronic communication suppliers. If the situation lasts more than 60 days, either party may terminate without liability.
15. Term and termination
- The agreement runs from activation of the Organisation's account until terminated.
- A monthly plan may be terminated with one month's written notice, effective at the end of the current billing month.
- An annually prepaid plan runs until the end of the paid period. Termination must be given at least 30 days before renewal.
- Either party may terminate for the other's material breach not remedied within 30 days of written notice.
- The Provider may terminate for repeated breach of clause 7, or upon the Organisation's insolvency or bankruptcy.
16. Exit and data export
- The Organisation may export Customer Data in machine-readable format (JSON/CSV) at any time.
- After termination, Customer Data remains available for export for 30 days.
- Customer Data is then deleted within 90 days, except data the Provider is required by law to retain (accounting data for up to five years and security logs for up to two years).
- The Provider may assist with structured extraction or migration at an hourly rate by agreement.
17. Changes to the agreement
The Provider may amend the agreement with 30 days' written notice. Changes that are materially detrimental to the Organisation entitle it to terminate with effect from the date the change takes effect. Changes required to comply with law or public orders may be implemented without notice period but are notified as soon as possible.
18. Assignment and miscellaneous
- The Organisation may not assign the agreement without the Provider's written consent, which shall not be unreasonably withheld.
- The Provider may assign the agreement in connection with a merger, demerger or transfer of business, subject to written notice.
- If any provision is invalid, the remainder of the agreement stands and the provision is replaced by a valid provision with a corresponding purpose.
- The agreement with annexes constitutes the parties' entire understanding and supersedes previous agreements on the same subject.
- The Provider may refer to the Organisation as a customer by name and logo, unless the Organisation objects in writing.
19. Governing law and venue
The agreement is governed by Norwegian law. Disputes shall be sought resolved amicably. Failing that, Oslo District Court is agreed as the legal venue.
The agreement exists in Norwegian and English. In case of conflict, the Norwegian version prevails.
Annex A – Service level agreement (SLA)
Availability is measured per calendar month as the share of minutes the Service responds to requests, divided by total minutes in the month, less planned maintenance. Target: 99.5%.
- Planned maintenance is announced at least 48 hours in advance and normally scheduled between 22:00 and 06:00 CET.
- Downtime caused by the Organisation, force majeure or third-party payment services is not counted.
- Backups are taken daily with point-in-time recovery (PITR). Recovery point objective (RPO): 24 hours. Recovery time objective (RTO): 8 hours.
| Priority | Description | First response | Resolution target |
|---|---|---|---|
| Critical | Service unavailable or booking blocked for all users | 4 hours | Continuous work until workaround exists |
| High | Material function unavailable with no workaround | 1 business day | 5 business days |
| Normal | Defect with available workaround | 3 business days | Next planned release |
| Low | Cosmetic defect, question or improvement request | 5 business days | Considered in product plan |
Cases are reported in the Service's support module or to support@arenabook.ai. Critical cases are escalated to the Provider's operations lead. Security incidents are handled under annex B clause 8.
Annex B – Data processing agreement (GDPR article 28)
This data processing agreement is entered into between the Organisation as controller and the Provider as processor, and covers all processing of personal data carried out by the Provider on behalf of the Organisation in the Service.
1. Purpose and nature of processing: delivery, operation, support and further development of booking, staff scheduling, season, invoicing and assistant functionality in the Service. Duration: for the term of the agreement, with deletion under clause 16 of the main agreement.
| Category of data subjects | Categories of personal data |
|---|---|
| Employees and officials of the Organisation | Name, email, phone, job title, role, shifts and working hours |
| Customers, teams and team managers | Name, email, phone, company and billing details, booking history |
| Members of the public booking | Name, email, phone, booking and payment status |
| All users | Account identifier, sign-in events, consents, messages to the AI assistant, security log |
No special categories of personal data under article 9 shall be recorded in the Service. The Organisation shall not enter health data or other sensitive information into free-text fields.
- 2. Instructions: The Provider processes personal data only on documented instructions from the Organisation, including this agreement and use of the Service's features. The Provider notifies the Organisation if an instruction is considered to infringe data protection law.
- 3. Confidentiality: All personnel with access at the Provider are bound by confidentiality and granted access on a least-privilege basis.
- 4. Security measures (article 32): encryption in transit (TLS) and at rest, row-level security and role-based access control on all data tables, checking passwords against known breaches, append-only security log, rate limiting, separated environments, vulnerability scanning before each production release and daily backups.
- 5. Sub-processors: The Organisation gives general authorisation for the use of sub-processors. The Provider has entered into agreements with each on at least equivalent terms and notifies changes at least 30 days in advance. The Organisation may object on reasonable grounds within that period and may terminate if the parties cannot find a solution.
| Sub-processor | Purpose | Location |
|---|---|---|
| Lovable Cloud / Supabase | Database, authentication, file storage | EU |
| Cloudflare | Application runtime, CDN and DDoS protection | EU edge |
| Lovable AI Gateway | Execution of AI assistant requests | EU |
| Vipps MobilePay | Payment processing for individual bookings | EU/EEA |
| Resend | Transactional and notification email delivery | EU |
- 6. Third-country transfers: All processing takes place within the EU/EEA. No transfer outside the EEA occurs without prior written agreement and a valid transfer mechanism (standard contractual clauses with supplementary measures).
- 7. Assistance to the controller: The Provider assists the Organisation in responding to data subject requests (articles 12–23) through self-service access, export and deletion in the Service, and manually where required. The Provider also assists with data protection impact assessments and prior consultation under articles 35–36.
- 8. Personal data breach: The Provider notifies the Organisation without undue delay and no later than 48 hours after becoming aware of a breach, describing its nature, likely consequences and measures taken. The Organisation is responsible for notifying the supervisory authority under article 33 and data subjects under article 34.
- 9. Audit: The Organisation may request documentation of compliance annually, and otherwise on suspicion of breach. On-site audits may be carried out with 30 days' notice, during business hours, at the Organisation's cost, and shall not unreasonably disrupt the Provider's operations.
- 10. Deletion and return: On termination, personal data is deleted or returned under clause 16 of the main agreement, unless retention is required by law.
- 11. Records: The Provider maintains records of processing activities under article 30(2) and makes them available on request.
Annex C – Service description and plan limits
The Service comprises organisation, venue and resource administration, a booking calendar with rules engine and pitch layouts, public booking and organisation pages, information screens with sponsor display, staff scheduling with shift requests and notifications, season planning with self-service for team managers, customer and team registers, invoicing and Vipps payment, audit log, support case flow and an AI assistant for search, registration and summaries.
| Plan | Venues | Included AI quota per month | Overage |
|---|---|---|---|
| Start | 1 | 500 messages | At the applicable unit price |
| Growth | Up to 5 | 1,500 messages | At the applicable unit price |
| Pro | Up to 10 | 3,000 messages | At the applicable unit price |
| Enterprise | More than 10 | From 4,500 messages, by agreement | By agreement |
Quotas and unit prices are set out at any time on the Provider's pricing page and in the subscription overview in the Service. In case of discrepancy between this annex and a confirmed quotation, the quotation prevails.
Annex D – EU/EEA regulatory matrix
| Regulation | Relevance | How the agreement and Service respond |
|---|---|---|
| GDPR | Processing of personal data on employees, customers and the public | Annex B (art. 28), data minimisation, self-service access/export/deletion, defined retention periods, EU/EEA storage, cookie consent log |
| EU AI Act | AI assistant classified as limited risk | Clause 4: clear AI labelling, no prohibited practices, human oversight for financial decisions, logging of AI-initiated changes, documented model and provider use |
| NIS2 | Security management and incident handling | Annex A and annex B clauses 4 and 8: access control, vulnerability hygiene, security log, incident notification deadline, backup and recovery |
| DORA | Not relevant | The Service is delivered to sports facilities and voluntary organisations, not financial entities. The Provider is not a critical ICT third-party provider under DORA. Reassessed if the customer segment changes |
| ePrivacy / cookie rules | Use of cookies on public pages | Necessary cookies without consent, analytics only after explicit consent, consents logged with timestamp and version |
| Norwegian Transparency and Bookkeeping Acts | Documentation and retention | Clause 16: accounting data retained for the statutory period, other data deleted according to defined deadlines |
Signatures
- Place and date: ______________________________
- For the Provider (Eigr AS, org.nr. 937 872 623): ______________________________
- For the Organisation: ______________________________
- Name and title: ______________________________
See also privacy and security.