Legal

Serafinox Terms and Conditions

Effective Date: 22-06-2026  |  Solution Name: Serafinox  |  Provider: Orient CDS Private Limited

These Terms and Conditions govern the customer’s access to and use of Serafinox, a spend management solution designed to support corporate card management, employee reimbursement, petty cash, travel expense, approval workflows, mobile spend management, and related spend visibility capabilities within or alongside SAP environments.

By ordering, accessing, implementing, or using Serafinox, the customer agrees to these Terms and Conditions, together with the applicable order form, subscription document, statement of work, SAP Store purchase documentation, data processing agreement, support terms, and any other written agreement executed between the parties.

1. Definitions

“Agreement” means these Terms and Conditions together with the applicable order form, subscription document, statement of work, data processing agreement, support schedule, and any other applicable written terms.

“Customer” means the legal entity ordering, subscribing to, accessing, or using Serafinox.

“Provider” means Orient CDS Private Limited, the owner, developer, operator, or authorized commercial provider of Serafinox.

“Serafinox” means the software solution, add-on, extension, mobile application, configuration content, integration components, documentation, and related services made available by the Provider.

“Authorized Users” means Customer’s employees, contractors, finance users, approvers, administrators, or other individuals authorized by Customer to use Serafinox for Customer’s internal business purposes.

“Customer Data” means data submitted to, processed by, generated through, or accessed by Serafinox on behalf of Customer, including spend claims, expense data, employee information, approval data, corporate card transaction data, receipt images, accounting references, cost objects, and related business records.

“SAP Environment” means Customer’s SAP systems, including SAP S/4HANA, SAP BTP, SAP Fiori launchpad, SAP Mobile Services, identity services, workflow services, integration services, or other SAP products used with Serafinox.

2. Scope of Serafinox

Serafinox is provided as a spend management solution intended to help organizations manage and control business spend. Depending on the subscribed scope, Serafinox may support:

  1. corporate card transaction management;
  2. employee reimbursement claims;
  3. petty cash processes;
  4. travel and expense management;
  5. transaction enrichment, classification, and spend type mapping;
  6. approval workflows based on configurable business conditions;
  7. mobile spend management through SAP Mobile Services;
  8. receipt capture, attachment handling, claim submission, and approval actions;
  9. integration with SAP finance, workflow, authorization, and master data processes; and
  10. spend visibility, reporting, audit support, and process control capabilities.

The exact functionality, licensed scope, usage metrics, implementation responsibilities, and commercial terms are defined in the applicable order form, subscription document, statement of work, or SAP Store listing.

3. Relationship with SAP and SAP Store

Serafinox is a partner-provided solution and is not part of the standard SAP software unless expressly stated in the applicable order documentation.

Customer is responsible for maintaining the required SAP licenses, SAP infrastructure, SAP user authorizations, connectivity, system configuration, and any SAP services required to operate Serafinox. Use of SAP products, SAP Store, SAP BTP, SAP Mobile Services, SAP S/4HANA, or other SAP components remains subject to the applicable SAP agreements between Customer and SAP.

Nothing in these Terms transfers, modifies, or replaces any rights or obligations under Customer’s separate agreements with SAP.

4. Subscription Rights and Permitted Use

Subject to Customer’s payment of applicable fees and compliance with the Agreement, Provider grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use Serafinox during the applicable subscription term solely for Customer’s internal business operations.

Customer may allow Authorized Users to use Serafinox within the licensed scope. Customer is responsible for all activity performed by its Authorized Users.

Customer shall not:

  1. copy, modify, reverse engineer, decompile, disassemble, or attempt to derive the source code of Serafinox, except to the extent prohibited by applicable law;
  2. sell, resell, lease, sublicense, distribute, or provide Serafinox to third parties as a service bureau or managed service without Provider’s written consent;
  3. use Serafinox to process data for entities or users outside the licensed scope;
  4. bypass usage restrictions, technical controls, authorization checks, or license metrics;
  5. use Serafinox for unlawful, fraudulent, harmful, or unauthorized purposes; or
  6. interfere with the security, availability, or integrity of Serafinox or connected systems.

5. Customer Responsibilities

Customer is responsible for:

  1. ensuring that its SAP Environment is correctly licensed, configured, secured, and available;
  2. maintaining accurate master data, company codes, cost centers, internal orders, WBS elements, employees, vendors, tax codes, GL accounts, card user assignments, approval roles, and workflow responsibilities;
  3. defining and validating its spend policies, approval matrix, accounting rules, tax rules, reimbursement rules, petty cash rules, corporate card rules, and financial control requirements;
  4. testing Serafinox configuration before productive use;
  5. ensuring that Authorized Users are properly trained;
  6. managing user access, segregation of duties, and authorization roles;
  7. ensuring that Customer Data submitted to Serafinox is accurate, lawful, and complete;
  8. obtaining all required employee, cardholder, bank, issuer, or third-party consents where applicable; and
  9. complying with applicable employment, tax, accounting, financial, privacy, and data protection laws.

Serafinox supports spend management processes, but Customer remains responsible for its accounting decisions, approvals, postings, reimbursements, tax treatment, statutory compliance, and internal controls.

6. Corporate Card and Third-Party Integrations

Serafinox may support integration scenarios with corporate card providers, banks, payment networks, expense data providers, SAP systems, identity providers, mobile services, document services, and other third-party systems.

Unless expressly agreed otherwise:

  1. Provider is not a bank, card issuer, payment processor, payment network, or financial institution;
  2. Provider does not authorize, settle, clear, or execute payment card transactions;
  3. Provider is not responsible for the accuracy, completeness, timeliness, or availability of data received from banks, card issuers, payment networks, or third-party providers;
  4. Customer is responsible for its agreements with card issuers, banks, payment networks, and other third-party providers; and
  5. third-party services may be subject to separate terms, fees, limitations, and availability.

Serafinox is designed to support corporate card transaction visibility and spend management. Unless specifically agreed in writing and implemented under applicable compliance controls, Serafinox should not be used to store full card numbers, CVV values, PINs, magnetic stripe data, or other prohibited sensitive payment authentication data.

7. Mobile Application and SAP Mobile Services

Where the mobile application is included in the subscribed scope, Serafinox may use SAP Mobile Services or related SAP technologies to support secure mobile access, authentication, application lifecycle management, and enterprise-grade mobile connectivity.

Customer is responsible for configuring mobile access policies, identity management, device management, network access, user provisioning, and any required mobile device management or enterprise mobility management controls.

Provider may support rebranding or customer-specific mobile application customization where agreed in the applicable statement of work or commercial order.

8. Implementation, Configuration, and Professional Services

Implementation, configuration, migration, integration, enhancement, testing, training, support, and advisory services are included only where expressly stated in the applicable order form or statement of work.

Any implementation timelines, deliverables, assumptions, dependencies, roles, and responsibilities shall be governed by the applicable statement of work.

Customer acknowledges that successful implementation depends on timely access to Customer’s SAP systems, business users, technical teams, master data, configuration decisions, connectivity, test scenarios, and approval from relevant stakeholders.

9. Support and Maintenance

Provider will provide support for Serafinox as described in the applicable support schedule, order form, or SAP Store listing.

Unless a separate support schedule or service level agreement applies, support will be provided on a commercially reasonable basis during Provider’s standard business hours.

Provider may provide updates, patches, corrections, enhancements, or new releases from time to time. Customer is responsible for applying, testing, and validating updates in accordance with the agreed deployment model and Customer’s change management process.

Provider is not responsible for issues caused by:

  1. unauthorized modifications;
  2. unsupported SAP releases or system changes;
  3. incorrect configuration by Customer or third parties;
  4. failed third-party integrations;
  5. Customer network, infrastructure, security, or identity management issues;
  6. inaccurate or incomplete master data; or
  7. use outside the licensed or documented scope.

10. Data Protection and Privacy

Each party shall comply with applicable data protection and privacy laws.

Customer remains the controller or owner of Customer Data, and Provider processes Customer Data only to provide, support, secure, improve, and maintain Serafinox, or as otherwise permitted under the Agreement.

Where Serafinox processes personal data, the parties shall enter into an appropriate data processing agreement, including provisions on processing instructions, confidentiality, security measures, sub-processors, data subject rights, breach notification, data retention, and deletion.

Customer acknowledges that Serafinox may process personal data such as employee identifiers, names, email addresses, personnel numbers, organizational assignments, expense details, approval records, receipt images, reimbursement information, corporate card transaction references, and audit logs.

Customer shall not submit sensitive personal data, special category data, full payment card data, health data, biometric data, or government identification data into Serafinox unless expressly agreed in writing and supported by appropriate legal, technical, and organizational safeguards.

11. Security

Provider will maintain commercially reasonable technical and organizational measures designed to protect Serafinox and Customer Data against unauthorized access, accidental loss, misuse, alteration, or disclosure.

Customer is responsible for securing its SAP Environment, user accounts, roles, authorizations, identity providers, devices, integrations, network connections, and administrative access.

Customer shall promptly notify Provider of any suspected unauthorized access, credential compromise, security incident, or misuse affecting Serafinox.

Provider may suspend access to Serafinox where reasonably necessary to prevent security risks, unauthorized access, legal violations, or harm to Provider, SAP systems, Customer systems, other customers, or third parties.

12. Customer Data Ownership

Customer retains all rights, title, and interest in Customer Data.

Provider does not acquire ownership of Customer Data. Provider may use Customer Data only as required to provide Serafinox, perform support, meet legal obligations, prevent fraud or security threats, and improve the reliability, performance, and functionality of the solution, subject to applicable confidentiality and data protection obligations.

Provider may use aggregated or anonymized data that does not identify Customer, Authorized Users, or individuals for analytics, benchmarking, product improvement, and service optimization.

13. Intellectual Property Rights

Provider and its licensors retain all rights, title, and interest in Serafinox, including software, source code, object code, architecture, designs, workflows, templates, configurations, documentation, APIs, connectors, user interfaces, know-how, trademarks, service marks, and related intellectual property.

No rights are granted to Customer except the limited usage rights expressly stated in the Agreement.

Customer grants Provider a limited right to use Customer Data, Customer materials, logos, and system access only as necessary to provide Serafinox and related services, or as separately agreed in writing.

Customer feedback, suggestions, enhancement requests, or recommendations may be used by Provider to improve Serafinox without restriction, provided Provider does not disclose Customer’s confidential information.

14. Confidentiality

Each party may receive confidential information from the other party. Confidential information includes non-public business, technical, financial, product, security, system, pricing, roadmap, customer, employee, and process information.

The receiving party shall protect confidential information using at least reasonable care and shall not disclose it to third parties except to employees, contractors, advisors, affiliates, sub-processors, or service providers who need to know it and are bound by confidentiality obligations.

Confidentiality obligations do not apply to information that is publicly available, already known without restriction, independently developed, lawfully received from a third party, or required to be disclosed by law or court order.

15. Fees, Taxes, and Payment

Fees, payment terms, billing frequency, subscription term, renewal terms, usage metrics, and applicable taxes are specified in the order form, SAP Store order, or commercial agreement.

Unless otherwise stated, fees are non-refundable and payable without deduction or set-off.

Customer is responsible for all applicable taxes, duties, levies, withholding taxes, and similar charges, excluding taxes based on Provider’s net income.

Provider may suspend access to Serafinox for non-payment after providing reasonable notice, unless the non-payment is due to a good-faith billing dispute.

16. Warranties

Provider warrants that, during the applicable subscription term, Serafinox will materially perform in accordance with the applicable documentation when used in accordance with the Agreement.

Customer’s exclusive remedy for breach of this warranty is for Provider to use commercially reasonable efforts to correct the non-conformity. If Provider cannot reasonably correct the non-conformity, either party may terminate the affected subscription, and Customer may receive a pro-rated refund of prepaid unused fees for the affected subscription period.

Serafinox is not warranted to be error-free, uninterrupted, or compatible with every Customer system, configuration, third-party service, or custom development.

17. Disclaimer

Except as expressly stated in the Agreement, Serafinox is provided “as is” and “as available” to the maximum extent permitted by law.

Provider disclaims all implied warranties, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, uninterrupted operation, and error-free performance.

Provider does not provide legal, tax, accounting, employment, audit, banking, or financial advice. Customer should consult its own advisors for such matters.

18. Limitation of Liability

To the maximum extent permitted by law, each party’s total aggregate liability arising out of or relating to the Agreement shall not exceed the fees paid or payable by Customer for Serafinox during the twelve months immediately preceding the event giving rise to the claim.

Neither party shall be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profits, loss of revenue, loss of goodwill, loss of business opportunity, loss of anticipated savings, or loss of data, even if advised of the possibility of such damages.

The limitations in this section do not apply to liability that cannot be excluded or limited under applicable law, payment obligations, confidentiality breaches, infringement of intellectual property rights, fraud, willful misconduct, or misuse of the other party’s intellectual property.

19. Indemnity

Customer shall indemnify and defend Provider against claims arising from:

  1. Customer Data;
  2. Customer’s unlawful use of Serafinox;
  3. Customer’s breach of the Agreement;
  4. Customer’s violation of third-party rights;
  5. Customer’s SAP Environment, integrations, configurations, or business processes; or
  6. Customer’s failure to comply with applicable laws.

Provider shall indemnify and defend Customer against third-party claims alleging that Serafinox infringes intellectual property rights, provided that Customer promptly notifies Provider, allows Provider to control the defense, and reasonably cooperates.

Provider has no indemnity obligation for claims arising from Customer modifications, third-party components, unsupported use, combination with non-Provider systems, or use outside the Agreement.

20. Compliance

Each party shall comply with applicable laws, including anti-bribery, anti-corruption, sanctions, export control, data protection, employment, and financial compliance laws.

Customer shall not use Serafinox in embargoed countries or for prohibited end users, prohibited end uses, or unlawful activities.

Customer is responsible for ensuring that its use of Serafinox complies with internal policies, accounting rules, tax rules, reimbursement policies, corporate card policies, audit requirements, and statutory obligations.

21. Audit and Usage Verification

Provider may monitor usage of Serafinox to verify compliance with licensed metrics, security requirements, and operational limits.

Upon reasonable notice, Provider may request usage information or conduct a reasonable audit to verify Customer’s compliance with the Agreement. Any audit shall be conducted in a manner that minimizes disruption to Customer’s business.

If usage exceeds the licensed scope, Customer shall pay applicable additional fees.

22. Suspension

Provider may suspend access to Serafinox if:

  1. Customer fails to pay undisputed fees;
  2. Customer or its Authorized Users breach the Agreement;
  3. continued access creates a security, legal, operational, or financial risk;
  4. Customer uses Serafinox outside the licensed scope; or
  5. suspension is required by law, SAP platform requirements, third-party service restrictions, or governmental authority.

Provider will use reasonable efforts to provide prior notice where practical.

23. Term and Termination

The subscription term begins and ends as stated in the applicable order form or SAP Store order.

Either party may terminate the Agreement if the other party materially breaches it and fails to cure the breach within thirty days after written notice.

Upon termination or expiration:

  1. Customer’s right to use Serafinox will end;
  2. Customer shall stop using Serafinox and remove access for Authorized Users;
  3. unpaid fees become due;
  4. Provider may delete or return Customer Data in accordance with the applicable data processing agreement and retention policy; and
  5. provisions intended to survive termination shall continue, including confidentiality, payment, intellectual property, limitation of liability, and compliance provisions.

24. Data Return and Deletion

Upon termination or expiration, Customer may request return or export of Customer Data within the period specified in the applicable agreement or data processing terms.

After the applicable retention period, Provider may delete Customer Data from active systems and backups in accordance with its standard deletion procedures, unless retention is required by law or agreed otherwise in writing.

Customer is responsible for maintaining its own statutory records, financial records, audit documents, receipts, and accounting backups as required by applicable law.

25. Changes to Serafinox

Provider may modify, enhance, update, or discontinue features of Serafinox from time to time, provided that such changes do not materially reduce the core functionality of the subscribed solution during the active subscription term.

Provider may make changes required for security, legal compliance, SAP platform compatibility, technical stability, or third-party dependency changes.

26. Publicity

Provider may identify Customer as a customer of Serafinox only with Customer’s prior written consent, unless otherwise permitted in the applicable order form.

Any use of Customer’s name, logo, trademark, or case study requires Customer’s prior approval.

27. SAP and Third-Party Trademarks

SAP, SAP S/4HANA, SAP Fiori, SAP BTP, SAP Mobile Services, and other SAP names are trademarks or registered trademarks of SAP SE or its affiliates.

All third-party trademarks, product names, and company names remain the property of their respective owners. Use of such names does not imply endorsement unless expressly stated.

28. Governing Law and Jurisdiction

This Agreement shall be governed by the laws of [Insert Jurisdiction], excluding conflict of law rules.

The courts of [Insert Venue] shall have exclusive jurisdiction over disputes arising out of or relating to the Agreement, unless otherwise agreed in writing.

29. Order of Precedence

In the event of conflict, the following order of precedence applies unless expressly stated otherwise:

signed order form or subscription agreement;

data processing agreement;

statement of work;

support schedule or service level agreement;

these Terms and Conditions;

documentation.

SAP Store purchase terms or SAP platform terms may also apply separately where the transaction, subscription, or deployment is made through SAP Store or SAP services.

30. Entire Agreement

The Agreement constitutes the entire agreement between Customer and Provider regarding Serafinox and supersedes all prior discussions, proposals, presentations, or understandings relating to the subject matter.

Any amendment must be in writing and agreed by both parties, unless Provider updates these Terms for future subscriptions or renewals.

31. Contact

For legal notices:

Orient CDS Private Limited

Address: SBC2 3rd Floor, SEZ IT Building, Ashtamudi Towers, Technopark Campus Kundara,

Email: empower@orientcds.com