Skip to main content
HR Flow
  • Why HR Flow
  • Features
  • Pricing
Language selectorEnglish
  • Italiano
  • Français
  • English
Log inRequest a demo
Menu
  • Why HR Flow
  • Features
  • Pricing
Language selectorEnglish
  • Italiano
  • Français
  • English
Log inRequest a demo
  1. Home
  2. / General terms

General Terms

General Terms | HR Flow

General SaaS B2B supply and software licence terms for HR Flow for companies, professionals, and organisations.

GENERAL TERMS OF SUPPLY AND SaaS SOFTWARE LICENCE

HR FLOW

Version 0.3 — August 1, 2026

Provider: IGESA S.r.l.

B2B contractual document intended for companies, professionals, and organisations

Recitals

IGESA S.r.l., with registered office at Via Consolare Antica n. 308, 98071 Capo d'Orlando (ME), tax code and VAT number 01564760831, represented by its legal representative pro tempore, hereinafter "IGESA" or the "Provider", develops and markets the software solution known as HR Flow.

These General Terms govern the supply of HR Flow as Software as a Service, as well as the related support, maintenance, and update services.

HR Flow is intended exclusively for companies, professionals, public entities, and private entities acting within their business, professional, or institutional activity.

The Customer therefore declares that it is not purchasing the Service as a consumer.

The Recitals, the Commercial Offer, any annexes, and these Terms form an integral part of the contract.

1. Definitions

Customer
the company, professional, or entity signing the Commercial Offer.
Service
the HR Flow software solution delivered as SaaS.
Platform
the application environment through which the Service is delivered.
Offer
the commercial document signed by the Customer, containing commercial terms, features, modules, limits, and purchased services.
Plan
the commercial configuration identified in the Offer.
Authorised User
the person enabled by the Customer to access the Platform.
Customer Administrator
the user to whom the Customer assigns configuration and administration privileges.
Customer Data
data, documents, information, and content uploaded, transmitted, or generated by the Customer through the Service.
Documentation
manuals, guides, and instructions made available by IGESA.
DPA
the personal data processing agreement entered into under Article 28 of Regulation (EU) 2016/679.
SLA
any specific agreement regarding service levels.
Business Day
any day from Monday to Friday, excluding Italian national holidays.

2. Contractual documents

The relationship between IGESA and the Customer is governed, in order of priority, by:

  1. the signed Commercial Offer;
  2. any special conditions;
  3. any SLA or Enterprise annex;
  4. the DPA and its annexes;
  5. these General Terms;
  6. the technical Documentation.

Offer precedence

The Offer prevails with respect to purchased features, included modules, technical or quantitative limits, fees, duration, professional services, and special conditions.

DPA precedence

The DPA prevails for matters relating to the processing of personal data.

3. Subject matter of the contract

IGESA grants the Customer, for the term of the contract, the right to access and use HR Flow in accordance with the Offer, the subscribed Plan, these Terms, the Documentation, and any annexes.

The Service is delivered remotely through cloud infrastructure.

The Customer does not purchase a copy of the software and acquires no rights in the source code or the application infrastructure.

Features not expressly indicated in the Offer are not considered included.

4. Software licence

IGESA grants the Customer a licence that is:

  • non-exclusive;
  • non-transferable;
  • non-assignable;
  • non-sublicensable;
  • limited to the term of the contract;
  • intended solely for the Customer's internal activities;
  • subject to payment of the applicable fees.

Licence limits

The licence does not include the right to:

  • distribute the software;
  • resell the Service;
  • grant the Service to third parties;
  • copy the code;
  • modify the software;
  • carry out reverse engineering beyond mandatory legal limits;
  • create derivative products;
  • use components of HR Flow separately from the Service.

5. Plans and Offer configuration

HR Flow may be marketed through different Plans, including Starter, Business, Professional, Enterprise, and any further configurations defined by IGESA.

The name of the Plan does not automatically determine a specific number of users, managed employees, features, modules, document storage, or support level.

For each Customer, the Offer defines:

  • included features and modules;
  • any limits relating to users or managed employees;
  • document storage;
  • configurations;
  • integrations;
  • support services;
  • service levels;
  • technical or quantitative limits;
  • the fee;
  • commercial terms;
  • professional services;
  • any customised security conditions.

General descriptions of the Plans appearing on the website, in marketing materials, or in presentations are for information purposes only. In the event of conflict, the content of the Offer signed by the Customer always prevails.

6. Enterprise Plan

The Enterprise Plan is defined through a commercial discussion and a customised Offer. It may include, by way of example:

  • customised features;
  • integrations;
  • priority support;
  • dedicated SLAs;
  • SSO;
  • audit log;
  • customised retention;
  • dedicated infrastructure configurations;
  • additional environments;
  • security procedures;
  • business continuity requirements;
  • support for NIS2 obligations;
  • controls linked to ISO/IEC 27001 management systems.

Reference to regulations, certifications, or standards does not automatically constitute a declaration of compliance or certification of HR Flow. The obligations actually undertaken by IGESA must result from the Offer or from a specific contractual annex.

7. Plan changes

If the Customer requests features, modules, capacity, or services not included in the Offer, IGESA may propose:

  • moving to a different Plan;
  • purchasing additional modules;
  • adjusting the fee;
  • a customised configuration;
  • additional professional services.

Changes become effective only after acceptance of the relevant Offer or contractual variation.

If the limits set out in the Offer are exceeded, IGESA informs the Customer and grants a reasonable period to regularise the position.

IGESA does not automatically block the Service for occasional overruns, except where there are risks to security, stability, or continuity of the Service.

8. Activation

The Service is activated according to the timing stated in the Offer. The Customer must promptly provide:

  • the necessary data and information;
  • the names of administrators;
  • the required configurations;
  • any initial content;
  • the cooperation reasonably required.

Any delay attributable to the Customer may postpone activation times without liability for IGESA.

Activation, initial configuration, and data migration may be subject to separate consideration.

9. Duration

The contract lasts 12 months from the date indicated in the Offer.

At expiry, the contract automatically renews for further 12-month periods, unless terminated by the Customer or by IGESA.

Any different initial periods must be indicated in the Offer.

10. Non-renewal

The Customer may communicate its intention not to renew the contract at any time before the yearly expiry.

No minimum notice period is required, provided that the communication is received by IGESA before renewal.

Non-renewal:

  • takes effect on the yearly expiry date;
  • prevents the following renewal;
  • does not entitle the Customer to reimbursement of fees already paid;
  • does not cancel amounts already accrued;
  • does not constitute early termination.

The communication must be sent by PEC to igesa@pec-legal.it or by registered letter with return receipt to IGESA's registered office.

11. Early termination

The Customer may terminate the contract early in the cases provided by law, in the event of a serious breach by IGESA not remedied within the assigned period, in the cases expressly provided by the Offer, or by written agreement between the Parties.

Early termination at the Customer's choice does not remove the obligation to pay the fees due for the current annual period, unless otherwise agreed in writing.

12. Free periods and promotions

No automatic free period is provided.

IGESA may grant, through the Offer, trial periods, free access, discounts, promotional terms, or temporary access to additional modules.

The Offer must indicate the duration, available features, any limitations, the end date, and the conditions of any subsequent service.

The free period does not automatically convert into a paid service without acceptance of the relevant commercial terms.

13. Fees

The annual fee is stated in the Offer.

The fee may depend on the Plan, features, modules, users, managed employees, document storage, integrations, support, SLAs, customised configurations, and additional services.

All prices are net of VAT, unless otherwise indicated.

Activities not included in the fee are invoiced separately after acceptance of the relevant quotation.

14. Billing and payments

Payments may be made by:

  • bank transfer;
  • credit card;
  • debit card;
  • Stripe;
  • PayPal.

IGESA may enable recurring payments only after the Customer's acceptance.

Stripe and PayPal handle payment data according to their own terms and notices.

IGESA does not directly store full card details, except as strictly required by the technical payment method used.

Payment is deemed made when the amount is credited or confirmed by the payment service provider.

15. Fee changes

The fee may be changed in the event of renewal, Plan change, addition of features, increase of limits, purchase of modules, configuration changes, request for additional services, or change in service levels.

Changes have no retroactive effect.

Increases applicable at renewal are communicated before the annual expiry.

The Customer who does not intend to accept them may notify non-renewal before renewal.

16. Non-payment

In the event of non-payment, the Customer has 10 days from the due date to regularise its position. After that period, following communication to the Customer, IGESA may:

  • block access to the Platform;
  • suspend functionalities;
  • prevent new entries;
  • temporarily interrupt ancillary services;
  • start the termination procedure.

Suspension does not entail immediate deletion of data, does not cancel the amounts due, does not prevent statutory interest from accruing, and ends after regularisation unless the contract is terminated.

17. Credentials and authorised users

The Customer is responsible for:

  • identifying users;
  • assigning roles;
  • revoking access;
  • safeguarding credentials;
  • correctly configuring permissions;
  • activities carried out by its users.

Credentials are personal and must not be shared.

The Customer must immediately inform IGESA of suspicious access, loss of credentials, compromise, unauthorised use, or a security incident.

18. Customer obligations

The Customer undertakes to:

  • use the Service lawfully;
  • enter correct and relevant data;
  • have the necessary legal bases;
  • provide the required privacy notices;
  • correctly manage authorisations and roles;
  • protect devices and networks under its control;
  • not upload unlawful content;
  • not compromise security;
  • cooperate with IGESA;
  • comply with the Documentation.

HR Flow is a management tool. The Customer remains responsible for organisational, administrative, contractual, and employment decisions taken by using the information available in the Platform.

19. Prohibited uses

It is prohibited to:

  • grant access to unauthorised persons;
  • share credentials;
  • resell the Service without authorisation;
  • circumvent technical or commercial limits;
  • carry out reverse engineering beyond legal limits;
  • copy or distribute the software;
  • introduce malware;
  • compromise other tenants;
  • carry out unauthorised security testing;
  • systematically extract proprietary components;
  • use the Service for unlawful purposes;
  • infringe third-party rights.

IGESA may suspend activities that create a concrete and immediate risk.

20. Included support

Unless otherwise provided in the Offer, the fee includes:

  • technical support;
  • corrective maintenance;
  • ordinary updates;
  • security updates;
  • general evolutionary updates available for the Plan.

Technical support is available Monday to Friday, excluding Italian public holidays, from 8:30 to 13:00 and from 14:30 to 18:00.

21. Activities not included

Unless otherwise provided, the fee does not include:

  • training;
  • initial configuration;
  • data import or migration;
  • data cleansing;
  • consulting;
  • customisation;
  • integration development;
  • connector development;
  • on-site activities;
  • out-of-hours support;
  • changes requested exclusively by the Customer.

Such activities are quoted separately.

22. Updates and maintenance

IGESA may carry out:

  • corrective maintenance;
  • evolutionary maintenance;
  • security updates;
  • general regulatory updates;
  • technical changes;
  • interface changes;
  • infrastructure adjustments.

Scheduled interventions with a significant impact are communicated with reasonable notice where possible. Urgent interventions may be carried out without notice where necessary to correct vulnerabilities, contain incidents, protect data, ensure continuity, or comply with legal obligations.

23. Service availability

For ordinary Plans, IGESA sets an annual average availability target of 99%. The following are excluded from the calculation: scheduled maintenance, urgent security interventions, causes attributable to the Customer, the Customer's networks and devices, SMTP services chosen by the Customer, force majeure, general internet outages, third-party services not directly controllable, and suspensions provided for by the contract.

The 99% availability is a standard target. Higher guarantees or service credits must be expressly provided in an Enterprise SLA.

24. Management of unavailability

In the event of total unavailability of the Platform:

  • the report is taken in charge during support hours;
  • IGESA starts diagnosis and restoration activities;
  • the objective is to restore the Service or make a temporary solution available within one Business Day from the time the issue is taken in charge.

This timeframe is an operational objective and not an absolute guarantee where restoration depends on third parties, force majeure, complex incidents, cyberattacks, external infrastructures, or Customer cooperation.

25. Backups

IGESA performs at least one daily backup of the data handled by the Platform. Ordinary retention includes the last seven daily copies. Backups are kept on multiple machines or systems according to the adopted technical architecture.

Backups:

  • are intended for continuity and restoration of the Service;
  • do not replace the Customer's retention obligations;
  • do not guarantee point recovery of data voluntarily deleted;
  • are deleted according to the ordinary retention cycle.

Different RPOs, RTOs, or retention periods must be provided in an Enterprise Offer.

26. Hosting

The Service is hosted on Hetzner infrastructure located in Germany. IGESA may change servers, configurations, or data centres provided that an adequate level of protection is ensured, contractual obligations and applicable rules are respected, and relevant changes are documented.

Hetzner is indicated in the DPA and in the list of subprocessors for processing carried out on behalf of the Customer.

27. Customer-configured SMTP

Each tenant may configure its own SMTP service. Where the Customer uses a provider chosen independently:

  • the provider is selected by the Customer;
  • the Customer verifies its security and terms;
  • the Customer manages the contractual relationship with the provider;
  • IGESA is not responsible for the availability of the SMTP service;
  • IGESA is not responsible for the retention policies adopted by the provider.

IGESA remains responsible for the correct technical management of the integration within its scope.

28. Ownership of Customer Data

The Customer retains all rights to its data and documents. IGESA:

  • does not acquire ownership of Customer Data;
  • uses them solely to provide the Service;
  • does not sell them;
  • does not use them for incompatible purposes;
  • does not use them to train artificial intelligence systems without a specific agreement.

IGESA may use aggregated and genuinely anonymised information for technical statistics, security, performance analysis, and improvement of the Service, provided that it cannot be traced back to the Customer or to data subjects.

29. Data export

The Customer may request export of its data in a structured, commonly used, and machine-readable format, within technically applicable limits.

Export does not include:

  • source code;
  • algorithms;
  • proprietary components;
  • IGESA trade secrets;
  • other customers' data;
  • information that compromises security;
  • items not belonging to the Customer.

Mandatory switching and export activities are provided according to applicable law.

30. Additional migration services

The following may be charged separately, after request and acceptance by the Customer:

  • customised conversions;
  • data cleansing;
  • connector development;
  • specialist assistance;
  • migration to third-party systems;
  • loading with a new provider;
  • reconstruction of non-standard formats;
  • consulting.

Costs must be communicated and accepted in advance. No costs are charged for mandatory switching activities in the cases and from the dates on which applicable law prohibits such charges.

31. Retrieval and deletion after termination

After termination:

  1. the Customer may request export of the data;
  2. the data remain retrievable for at least 30 days;
  3. after that period, IGESA starts deletion;
  4. copies in backups are eliminated according to the ordinary seven-day cycle;
  5. any legal retention obligations remain unaffected.

The Customer must promptly start retrieval activities. The operating procedures are described in the DPA and in the termination procedure.

32. Intellectual property

IGESA retains all rights relating to:

  • HR Flow;
  • source code;
  • object code;
  • architecture;
  • interface;
  • database and related structure;
  • algorithms;
  • models;
  • trademarks;
  • design;
  • documentation;
  • updates;
  • general developments;
  • know-how.

Configurations carried out for the Customer do not transfer rights in the Platform. Specific developments commissioned by the Customer are regulated by a separate agreement.

33. Feedback

The Customer may submit suggestions and enhancement requests. Unless otherwise agreed:

  • IGESA may use feedback to improve HR Flow;
  • the Customer acquires no exclusive rights over general developments;
  • the Customer's confidential information remains protected;
  • commissioned developments are governed by a specific agreement.

34. Confidentiality

The Parties must protect confidential information received. Confidential information includes:

  • credentials;
  • personal data;
  • trade secrets;
  • technical documentation;
  • configurations;
  • non-public commercial terms;
  • security information;
  • business data;
  • employee-related information.

Obligations concerning personal data continue for the time required by law. Obligations concerning trade secrets continue for as long as the information remains confidential. Information may be disclosed where required by law or by a competent authority.

35. Personal data protection

For personal data entered by the Customer into the Platform:

  • the Customer normally acts as controller;
  • IGESA normally acts as processor;
  • the processing is governed by a DPA.

The Customer is responsible for the lawfulness of the processing, the notices, the legal bases, the instructions given to IGESA, internal authorisations, and the exercise of data subject rights.

IGESA acts as an independent controller for data necessary for contract management, billing, payments, system security, legal compliance, and protection of its rights.

36. DPA

The DPA forms an integral part of the contractual relationship whenever IGESA processes personal data on behalf of the Customer. It governs at least:

  • the subject matter and duration of the processing;
  • nature and purposes;
  • categories of data subjects;
  • categories of data;
  • Customer instructions;
  • confidentiality;
  • security measures;
  • subprocessors;
  • assistance to the Customer;
  • breach management;
  • audits;
  • return of data;
  • export;
  • deletion;
  • international transfers.

37. Subprocessors

IGESA may use subprocessors necessary for delivery of the Service.

The initial list includes Hetzner for hosting infrastructure in Germany.

Any new subprocessors are managed according to the DPA and applicable law.

Stripe and PayPal may process payment-related data according to the roles and terms defined by their respective notices and applicable agreements. The SMTP provider chosen directly by the Customer is not appointed by IGESA as its own subprocessor, unless a different contractual setup applies.

38. Security

IGESA adopts technical and organisational measures proportionate to the nature of the Service, the data processed, the risks, the state of the art, and implementation costs.

The measures actually adopted are described in the DPA and related annexes. No certification or compliance is declared unless it has genuinely been obtained, documented, and indicated in the Offer. Customised security terms may be agreed for the Enterprise Plan.

39. Warranties

IGESA warrants that:

  • the Service is provided with professional diligence;
  • it has the rights necessary to grant its use;
  • it adopts reasonable measures to correct reproducible malfunctions;
  • it provides the updates provided by the contract.

IGESA does not warrant:

  • that the Service will always be error-free;
  • that every interruption can be avoided;
  • that every uncommunicated need will be met;
  • that the Service is compatible with undeclared systems;
  • that every specific update requested by the Customer is included;
  • that the Service replaces legal, tax, employment, or organisational advice.

40. Customer liability

The Customer is responsible for:

  • the data entered;
  • the lawfulness of the processing;
  • the configurations;
  • the roles assigned;
  • the decisions adopted;
  • the devices under its control;
  • the networks used;
  • the authorised users;
  • externally chosen services.

The Customer shall indemnify IGESA against claims arising from unlawful data or uses attributable to the Customer, except where IGESA is liable.

41. Limitation of liability

Subject to wilful misconduct, gross negligence, personal injury, and liabilities that cannot be limited by law, IGESA's overall liability arising from the contract may not exceed the net fees paid by the Customer in the six months preceding the event that caused the damage.

To the extent permitted by law, the following are excluded:

  • indirect damages;
  • loss of profit;
  • loss of opportunity;
  • reputational loss;
  • unrealised savings;
  • consequences of inaccurate data entered by the Customer;
  • damages resulting from negligently managed credentials;
  • service issues attributable to the Customer's systems;
  • service issues attributable to providers chosen by the Customer.

This clause must be specifically approved.

42. Force majeure

Neither Party is liable for delays or non-performance caused by events beyond its reasonable control, including:

  • natural disasters;
  • wars;
  • riots;
  • widespread blackouts;
  • general telecommunications outages;
  • measures by authorities;
  • general strikes;
  • widespread cyberattacks not avoidable through reasonable measures;
  • extraordinary unavailability of essential infrastructure.

The affected Party shall inform the other and take reasonable measures to mitigate the effects.

43. Suspension for security reasons

IGESA may suspend the Service when necessary to:

  • contain an incident;
  • protect data and infrastructure;
  • block abusive access;
  • prevent harm to other customers;
  • comply with authority orders;
  • correct urgent vulnerabilities.

Suspension is limited in time and scope to what is reasonably necessary. The Customer is informed as soon as possible, except where prohibited by law or where security needs prevent it.

44. Termination

Each Party may terminate the contract in the event of a serious breach by the other Party not remedied within 15 days from written notice. IGESA may terminate the contract in the event of:

  • persistent non-payment;
  • unlawful use;
  • serious security violation;
  • unauthorised assignment;
  • intellectual property infringement;
  • activities damaging systems or third parties;
  • repeated breach of these Terms.

Termination does not affect amounts already accrued. Provisions concerning export, retrieval, and deletion of data remain applicable.

45. Changes to the Service

IGESA may modify and evolve the Service while preserving its essential nature. Substantial changes that significantly reduce purchased features are communicated with reasonable notice. Where necessary, IGESA may propose:

  • an alternative feature;
  • an adjustment of the Plan;
  • a transitional period;
  • a different technical solution;
  • termination at expiry.

46. Changes to the Terms

IGESA may update these Terms:

  • for regulatory adjustments;
  • for security needs;
  • for technical changes;
  • for evolution of the Service;
  • for organisational updates.

Substantial changes are communicated to the Customer. Except for changes imposed by law or necessary for security, the new Terms apply from the next renewal. The Customer who does not intend to accept them may notify non-renewal before that renewal.

47. Communications

Ordinary communications may take place by email. Communications relating to non-renewal, termination, formal notice, formal disputes, assignment, and corporate changes must be sent by PEC or registered letter with return receipt.

IGESA's PEC is igesa@pec-legal.it. The Customer must keep its contact details up to date.

48. Assignment of the contract

The Customer may not assign the contract without IGESA's written consent.

IGESA may assign the contract in the context of a merger, corporate reorganisation, business transfer, transfer of a business branch, or product transfer, provided that the Customer's safeguards are not substantially reduced.

49. Validity of clauses

Any nullity, invalidity, or ineffectiveness of a clause does not affect the validity of the remaining provisions. The invalid clause shall, where possible, be replaced with a valid provision having an equivalent economic purpose.

50. Governing law

The contract is governed by Italian law, without prejudice to mandatory provisions of European Union law.

51. Jurisdiction

For any dispute relating to the interpretation, validity, performance, or termination of the contract, the Court of Patti has exclusive jurisdiction, without prejudice to any mandatory jurisdiction provided by law.

52. Acceptance

The Customer declares:

  • that it has read these Terms;
  • that it received them before entering into the contract;
  • that it can retain and reproduce them;
  • that it accepts them in full;
  • that it acts for professional, business, or institutional purposes;
  • that it does not act as a consumer.

Place and date

______________________________

IGESA S.r.l. - Signature

______________________________

Customer - Company name

______________________________

Customer - Tax code / VAT number

______________________________

Customer - Signature

______________________________

53. Specific approval

Pursuant to Articles 1341 and 1342 of the Italian Civil Code, the Customer declares that it specifically approves the following clauses:

  • article 7 — Plan changes and exceeding limits;
  • article 9 — automatic renewal;
  • article 10 — methods and effects of non-renewal;
  • article 11 — early termination;
  • article 15 — fee changes;
  • article 16 — suspension for non-payment;
  • article 19 — prohibited uses;
  • article 23 — Service availability;
  • article 24 — restoration objectives;
  • articles 29, 30, and 31 — export, migration, and deletion;
  • article 39 — warranty limitations;
  • article 40 — Customer responsibility;
  • article 41 — limitation of liability;
  • article 43 — suspension for security;
  • article 44 — termination;
  • article 45 — changes to the Service;
  • article 46 — changes to the Terms;
  • article 48 — assignment of the contract;
  • article 51 — jurisdiction.

Place and date

______________________________

Customer - Specific signature

______________________________

Planned contractual annexes

  1. Commercial Offer.
  2. Description of purchased features and modules.
  3. Commercial terms.
  4. DPA.
  5. Technical and organisational measures.
  6. List of subprocessors.
  7. Any Enterprise SLA.
  8. Export and termination procedure.
  9. Any Security/NIS2 annex.
  10. Any professional services price list.

Igesa

Management software solutions for retail, organised distribution and small and medium-sized businesses.

  • Why HR Flow
  • Features
  • Pricing
  • General Terms
Log inRequest a demo

© 2026 Igesa Srl. All Rights Reserved. 1988 – 2026

  • Privacy Policy
  • –
  • Cookie Policy

Cookie preferences

We use necessary technical cookies and, with your consent, Analytics cookies for website statistics.

Manage cookie preferences

You can accept or reject analytics tools. Technical cookies stay active because they are required for the site to work and to remember your choice.

Technical and necessary cookies

They are used for website operation, security, and to store your cookie preferences.

Always active

Analytics and statistics

They enable Google Analytics 4 to measure traffic, visited pages, and general website usage.

This configuration does not include a Google Analytics ID, so this category stays inactive.