End User License Agreement (EULA)
This End User License Agreement (EULA) establishes the legally binding framework governing access to and use of the myDRE platform via mydre.org. Authenticating and logging into the platform constitutes explicit acceptance of this agreement and its underlying security governance profiles, supporting compliance under ISO 27001:2023 (A.05.10, A.05.20) and NIS 2.
anDREa reserves the right to modify this EULA and the associated Service Level Agreement (SLA) at its sole discretion. Updates become binding immediately upon publication on mydre.org or through direct client notification. Continued use of the platform denotes ongoing consent to updated revisions.
1. Integrated Policy Stack
The EULA is structurally defined by the most current versions of the following documentation. Users must read, understand, and comply with this complete policy ecosystem:
Enforceable Agreements & Policies
- Terms of Service
- Privacy Policy
- Cookie Policies
- Data Protection Policy
- Data Processing Agreement (specimen)
- Password Policy
- Logon policy
- Coordinated Vulnerability Discosure Policy
Reference & Accountability Blueprints
To understand the division of liability between anDREa and your organization, users should review:
2. Mandatory User Responsibilities
Every platform participant is bound by the following operational security obligations:
- Policy Alignment: Users must comply with the EULA guidelines and all cross-referenced security documentation.
- Account Security: Users hold exclusive accountability for safeguarding their account credentials. Any suspected credential compromise, anomaly, or unauthorized system access must be escalated to anDREa security channels immediately.
- Regulatory Compliance: Handled data must strictly align with the GDPR and the guidelines defined within the anDREa Security Manifesto.
- Appropriate Use: Platform interactions must remain lawful. Actions must not degrade infrastructure, compromise intellectual property, or impede other authorized users.
- Vulnerability Reporting: System anomalies, functional bugs, or security vulnerabilities must be disclosed promptly via the myDRE Support Portal in compliance with the Coordinated Vulnerability Discosure Policy.
- Training & Awareness: Users are responsible for completing necessary onboarding and maintaining competency regarding their obligations under anDREa's data protection parameters.
3. Usage Restrictions & Software Ownership
Prohibited Actions
Users are strictly prohibited from performing the following actions, either directly or through a third party:
- Modifying, adapting, translating, or creating derivative works of the myDRE codebase or software.
- Distributing, selling, licensing, leasing, or commercially exploiting platform access.
- Reverse engineering, decompiling, disassembling, or attempting to derive the source code of the underlying platform.
- Utilizing the software for unlawful means or to execute unauthorized network operations.
- Unauthorized hacking, pentesting, and similar activities.
Intellectual Property Allocation
The myDRE platform is licensed, not sold. All Intelectual Property, exclusive rights, legal titles, and interests in, to, and concerning the software, including all underlying intellectual property and platform configurations belong to the shareholders.
4. Legal Governance & Termination
Governing Law & Jurisdictional Statutes
This agreement is governed by and construed in accordance with the laws of the Netherlands. Both parties submit to the exclusive jurisdiction of the Dutch legal system and agree to maintain compliance with:
- The General Data Protection Regulation (GDPR).
- The Dutch Implementation Act for GDPR (Uitvoeringswet AVG).
- Historical contexts preserved from the Dutch Data Protection Act (Wet bescherming persoonsgegevens - Wbp).
- Information security baselines managed under the ISO/IEC 27001:2023 framework.
Automated Termination
Any violation of these terms triggers an automatic termination of this license agreement. Upon termination, user access will be immediately revoked, and the user must cease all operations on the software and destroy any local or extracted platform components within their possession.