01Scope and structure
These service terms describe our standard commercial position for software development, team extension and long-term engineering partnership. Individual engagements are agreed in a signed contract, statement of work or order form, which takes precedence over this page wherever the two differ.
The contracting party is Gambridge Technologies Ltd, Eria, P. Byrdone Street, Naxxar NXR 2320, Malta. Services are provided to businesses only.
02Services and scope changes
Each statement of work defines the deliverables, the assumptions behind them, the acceptance criteria and the responsibilities on both sides. We work in two-week increments with a demo at the end of each, so scope questions surface early.
Changes to an agreed scope are handled through a written change request that states the effect on price and schedule before work begins. Where a dependency outside our control blocks progress — an acquirer certification slot, a third-party sandbox, a missing decision — we flag it, propose alternatives, and record the schedule impact.
03Fees, invoicing and expenses
Fees are agreed per statement of work as a fixed price for a defined scope, as a time-and-materials rate, or as a monthly retainer for team extension and engineering partnership. All amounts are net of VAT and any other applicable tax, charged in EUR unless agreed otherwise.
We invoice monthly in arrears unless the statement of work says otherwise, with payment due within 14 days. Late payment carries interest at the statutory rate. Travel and third-party costs are charged at cost, only where agreed in advance. Retainers cover an agreed capacity, are payable whether or not that capacity is used, and are not carried forward between months unless expressly agreed.
04Client responsibilities
Timely delivery depends on cooperation. You agree to nominate a decision-maker with authority over scope, provide timely access to systems, credentials, test accounts, acquirer and provider contacts and documentation, respond to review requests within agreed periods, and make sure your own licences and third-party agreements permit the work.
You remain responsible for your regulatory position, your acquiring and scheme relationships, your own compliance certifications, and your business decisions on risk, pricing and market. We advise on the engineering consequences of those decisions; we do not take them for you.
05Intellectual property
On full payment of the fees due for the relevant deliverable, all intellectual property rights in the bespoke work product we create for you — source code, infrastructure definitions, documentation, test suites — transfer to you, to the fullest extent transfer is possible under applicable law, together with a perpetual, worldwide, irrevocable licence for anything that cannot be transferred.
We retain ownership of our pre-existing tools, libraries, frameworks and know-how, including general methods and techniques learned during the engagement. Where those are embedded in a deliverable, you receive a perpetual, worldwide, non-exclusive, transferable and sublicensable licence to use, modify and distribute them as part of the deliverable, at no additional cost. Third-party and open-source components are documented with their licences; we flag any copyleft implications before use.
06Confidentiality
Each party keeps the other's confidential information confidential, uses it only for the engagement, discloses it only to people who need it and are bound by equivalent obligations, and protects it with the same care it applies to its own confidential information. These obligations survive the engagement by five years, and indefinitely for trade secrets and cardholder-related material.
We sign a mutual NDA before technical detail is exchanged. Naming you as a reference or publishing anything about the engagement requires your prior written consent.
07Data protection and security
Where we process personal data on your behalf we act as processor under a data processing agreement pursuant to Art. 28 GDPR, which forms part of the contract. It covers scope and instructions, confidentiality, technical and organisational measures, an approved sub-processor list with a change notification period, assistance with data subject requests and impact assessments, breach notification without undue delay, audit rights and deletion or return on termination.
Our default is that production personal data and live cardholder data are not used in development or test environments. Where a specific analysis cannot be performed otherwise, access is named, time-limited, logged and agreed in writing beforehand. Details of our handling of personal data as controller are in the privacy notice.
08Certification and assessment outcomes
Where we support a PCI DSS assessment, a 3-D Secure certification or a comparable audit, we deliver engineering work and the supporting evidence. The assessment outcome is determined by your QSA, your auditor or the relevant scheme, and we do not warrant that outcome.
09Warranties and defects
We warrant that services are performed with the reasonable skill and care of a competent professional in the field, and that deliverables will substantially conform to the agreed specification for 90 days after acceptance. Within that period we correct reported non-conformities at no charge; that correction is your primary remedy.
The warranty does not cover defects caused by changes made without our involvement, use outside the agreed specification, third-party components or services, or your failure to apply a fix or update we have supplied. Except as stated here and to the extent permitted by law, all other warranties, whether express or implied, are excluded.
10Liability
Neither party excludes liability for death or personal injury caused by negligence, for fraud, for wilful misconduct, or for anything else that cannot lawfully be excluded.
Subject to that, neither party is liable for loss of profit, revenue, business, goodwill, anticipated savings, or for indirect or consequential loss. Our aggregate liability under an engagement is limited to the fees paid by you under that engagement in the twelve months preceding the event giving rise to the claim. Claims for loss of data are limited to the cost of restoring it from backups you are contractually required to keep.
Where the risk profile of an engagement warrants a different allocation, we agree it in the contract rather than leaving it to a standard page.
11Personnel and subcontractors
We decide who performs the work and remain responsible for it. We name key personnel in the statement of work and will not replace them without notice and an equivalent replacement. Our people are not your employees, and nothing in the engagement creates an employment relationship, partnership or agency.
We may use subcontractors for defined parts of the work and remain fully liable for their performance; subcontractors handling personal data are added as sub-processors under the data processing agreement. Neither party solicits the other's personnel during the engagement and for twelve months after it, except where the person responds to a public advertisement.
12Term, termination and transition
An engagement runs for the term stated in the statement of work. Time-and-materials work and retainers may be terminated by either party on 30 days' written notice, with retainers subject to any agreed minimum term. Fixed-scope work may be terminated for convenience by you against payment for work performed and irrevocable commitments made.
Either party may terminate with immediate effect for material breach that is not remedied within 30 days of written notice, or on insolvency of the other party.
On termination we hand over source code, credentials, infrastructure access, documentation and runbooks, and we offer a transition period at our standard rates. For an engineering partnership, a run-off period of at least 60 days is available so a live payment platform is never left without operational cover.
13Force majeure and governing law
Neither party is liable for delay caused by events beyond its reasonable control, including scheme or regulatory intervention, failures of third-party providers, and widespread infrastructure or network outages. The affected party notifies the other promptly and mitigates the effect.
The contract is governed by the laws of Malta. The parties will first attempt to resolve any dispute through good-faith discussion at management level within 30 days. Failing that, the courts of Malta have exclusive jurisdiction. Nothing prevents either party from seeking urgent injunctive relief where necessary.