# GENERAL TERMS AND CONDITIONS

Clientology Institute s.r.o.

## 1. Introductory provisions

**1.1.** Clientology Institute s.r.o. issues these General Terms and Conditions, which govern the basic rules of business relations between the Provider and the Customer in the provision of Services and the use of Online Applications.

**1.2.** The General Terms and Conditions form an integral part of the Agreement concluded between the Customer and the Provider.

## 2. Definitions

**2.1.** For the purposes of these GTC, the definitions below have the following meanings:

| Term | Meaning |
| --- | --- |
| Administrator | means a person designated by the Customer to administer its User Account; |
| Clientology Scan | means an online application that serves as a tool for evaluating customer experience (CX), to which the Provider grants the Customer a licence as part of the Service provided; |
| Customer Journey Guide | means an online application that serves as a marketing tool for describing customer behaviour at various stages of interaction with the Customer, to which the Provider grants the Customer a licence as part of the Service provided; |
| Form | means a tool located in the Online Application for contacting the Provider, in particular to extend the scope of the agreed Services, report errors in the Online Application, send suggestions and proposals for modifications to the Online Applications, and provide Customer support; |
| GDPR | means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC; |
| Additional Service | means a service consisting of the creation of new functionality and/or modification of the Online Applications at the Customer's request; |
| Civil Code | means Act No. 89/2012 Coll., the Civil Code, as amended; |
| Business Corporations Act | means Act No. 90/2012 Coll., on Business Companies and Cooperatives (the Business Corporations Act), as amended; |
| Order | means the Customer's proposal to conclude the Agreement, specifying, in particular, the Services ordered; |
| Online Applications | means all products available on the Provider's website. |
| Provider | means Clientology Institute s.r.o., with its registered office at Nad Helmrovkou 276/8, Lysolaje, 165 00 Praha 6, Company ID No.: 03335526, registered in the Commercial Register maintained by the Municipal Court in Prague under file No. C 229964; |
| Business Day | means a day that is not a Saturday, Sunday or a non-working day under the laws of the Czech Republic; |
| Business Hours | means Monday to Friday, excluding non-working days under the laws of the Czech Republic, from 8:00 to 16:00 Central European Time; |
| Service Outage Resolution | means the document attached as Annex No. 2 to these GTC, describing the procedure for resolving Service outages; |
| Service | means an Online Application or any other service provided by the Provider to the Customer under the Agreement, to the extent agreed in the Agreement or specified on the Provider's website (i.e. the currently offered Service “packages”); |
| Agreement | means the agreement for the provision of services concluded between the Customer and the Provider; |
| Parties | means the Customer and the Provider jointly; |
| Trial Version of the Service | means a trial version of any Service, if made available to the Customer free of charge and with a limited scope; |
| User | means a natural person for whom the Customer creates a User Account; |
| User Account | means a user account in an Online Application and/or another Service available on the Provider's website, to which a unique access code and password are assigned; |
| GTC | means these General Terms and Conditions; |
| Customer | means a person who concludes the Agreement with the Provider. |

## 3. Conclusion of the Agreement

**3.1.** The Service, including the Trial Version of the Service, where available, is provided to the Customer on the basis of a concluded Agreement. The Agreement is deemed concluded no later than when the Customer's user account is created on the basis of its order, in particular by completing the initial questionnaire for account creation. The Order and these GTC form an integral part of the Agreement.

## 4. Provision of the Service

**4.1.** The Provider operates the Online Applications on the Provider's website and its subdomains.

**4.2.** The Provider undertakes to provide the Customer with the Services agreed in the Agreement, to the extent specified in the Order.

**4.3.** The scope of the agreed Services (including the number of User Accounts) may be increased during the term of the Agreement at the Customer's request. The amendment to the Agreement takes effect on the day the extended Service is provided and is treated as an addendum to the Agreement for the purposes of these GTC. The Provider is not obliged to accept the Customer's request to extend the scope of the Services.

## 5. Trial Version of the Service

**5.1.** The Provider may allow the Customer to try Customer Journey Guide through the website www.customerjourneyguide.com as a Trial Version of the Service, to the extent defined by the Provider.

**5.2.** The Trial Version of the Service is provided to the Customer free of charge for the period specified in the Price List, unless otherwise agreed between the Parties.

**5.3.** The Customer may store data when using the Trial Version of the Service, but solely for the purpose of verifying the system's functionality. The Customer acknowledges that the Provider bears no responsibility for the availability or retention of data stored by the Customer when using the Trial Version of the Service.

**5.4.** Before the Trial Version of the Service expires, the Provider will allow the Customer to switch to the paid version of the Service and will provide non-binding payment details. Payment of the price activates the Service to the agreed extent, and the data stored by the Customer in the Trial Version of the Service will be transferred to the full version of the Service.

**5.5.** If the Customer does not switch to the paid version of the Service, the provision of the Trial Version of the Service ends upon expiry of the period for which it was provided to the Customer.

**5.6.** The Customer hereby acknowledges that, if the situation contemplated in Article 5.5 of these GTC occurs, the data stored by the Customer in the Trial Version of the Service will be irreversibly deleted upon expiry of the period for which the Trial Version of the Service was provided. The Customer will be informed of the approaching end of the Trial Version of the Service and the deletion of data after its expiry by email or through the Trial Version of the Service portal.

## 6. Duration of the Service

**6.1.** The Agreement specifies whether it is concluded for a fixed or indefinite term.

**6.2.** If the Agreement contains no provision regarding its duration, it is deemed concluded for an indefinite term.

**6.3.** If the Agreement is concluded for a fixed term, payment details for payment of the price of the Service for the next period will be sent to the Customer before expiry of the term for which the Agreement was concluded. Payment of the price of the Service in accordance with the payment details extends the Agreement by its originally agreed term.

## 7. Price

**7.1.** The Customer is obliged to pay for use of the Service in accordance with Article 7.3, on the basis of tax documents (invoices) issued by the Provider and delivered to the Customer.

**7.2.** Invoices will be issued electronically and are payable within 30 days of delivery to the Customer's contact email address.

**7.3.** The prices of the Services are determined by the price list valid on the date the Order is submitted or, if a request to extend the Services under Article 4.3 of these GTC is made, on the date of switching to the extended Service package. Unless otherwise provided in the Agreement, VAT is charged in addition to the price in accordance with applicable law. The prices determined in this way increase each year on 1 January by the official inflation rate published by the Czech Statistical Office for the preceding calendar year; the increase takes effect upon publication in the Price List.

**7.4.** The Provider may change the price of the Service with effect from the date of renewal or extension of the Agreement, provided that it notifies the Customer of the new price at least 30 days in advance. If the Customer disagrees with the new price, it may terminate the Agreement as of the day preceding the renewal or extension date by a notice delivered to the Provider before that date at the latest. If the Customer does not terminate the Agreement within this period, it is deemed to have accepted the new price.

**7.5.** If the Agreement is terminated during a period for which the price of the Services has already been paid, no pro rata portion of the price of the Services will be refunded, except where termination is solely for reasons attributable to the Provider.

**7.6.** During the term of the Agreement, the Provider may verify whether the Customer complies with the agreed scope of use, particularly the number of User Accounts or plan limits for Service packages. If a discrepancy is identified, the Provider will notify the Customer without delay and may require payment for Services already provided beyond the agreed scope and an appropriate increase in the price of the Services in accordance with the price list.

## 8. Payment terms

**8.1.** For an Agreement concluded for an indefinite term, the billing period is a calendar month or calendar year, or a pro rata part thereof according to the date of conclusion of the Agreement. For an Agreement concluded for a fixed term, the billing period is the period (number of months) for which it was concluded.

**8.2.** If the Agreement and/or its addendum extending the Services is not in effect for an entire calendar month, the price of the Services is reduced pro rata.

**8.3.** If, during the term of the Agreement, the Customer is designated an unreliable VAT payer by a decision of the tax authority under Section 106a of Act No. 235/2004 Coll., on Value Added Tax, as amended, the Provider may pay the relevant value added tax directly to the tax authority under Section 109a of that Act. The amount paid in this way will be deducted from the invoiced price of the Services. If the Provider, as a guarantor, is called upon to pay value added tax on behalf of the Customer and actually pays that amount, the Customer undertakes to reimburse the Provider for all amounts so paid.

## 9. Licence arrangements and intellectual property rights

**9.1.** The Customer acknowledges that all economic copyright and other intellectual property rights in the Online Applications belong to the Provider. The Customer is therefore obliged to use the Online Applications solely within the scope of the licence granted, as specified below.

**9.2.** Upon conclusion of the Agreement and/or on the date the Additional Service is provided, the Customer acquires a non-exclusive, revocable, non-transferable licence to the Provider's Online Application specified in the Order and to use it, without the right to grant sublicences for access (the “Licence”).

**9.3.** The Licence is granted for the term of the Agreement and covers all updates, upgrades or other modifications to the Online Applications made by the Provider.

**9.4.** Without the Provider's written consent, the Customer and other authorised Users are not permitted, in particular, to:

**a)** modify the Online Applications in any way beyond the capabilities of the tools contained in the module;

**b)** translate them into other programming or natural languages, incorporate them into another software product, or distribute the resulting products;

**c)** authorise other legal or natural persons to exercise the right to use the Online Applications;

**d)** reproduce the Online Applications for the benefit of other legal or natural persons and subsequently distribute, rent, lend, display or otherwise deal with such copies beyond what is permitted by the Agreement or these GTC;

**e)** allow third parties remote access to the Online Applications for the benefit of other legal or natural persons, reproduce the Online Applications and subsequently distribute, rent, lend, display or otherwise deal with such copies beyond what is permitted by the Agreement or these GTC.

**9.5.** Each Party retains all rights to its Pre-existing Intellectual Property, i.e. intellectual property rights, know-how, data, software, documentation, methods, processes, tools and other materials that it owns or controls or that were created independently of the Agreement.

**9.6.** To the extent that any feedback, suggestions, ideas for improvement or other know-how or input is provided by the Customer to the Provider during the provision of the Services, the Customer hereby grants a non-exclusive, royalty-free, perpetual, irrevocable and worldwide licence to use, reproduce, modify, adapt and incorporate such input into the Online Applications or other Services of the Provider and to exploit it commercially.

## 10. Additional Services (Joint development)

**10.1.** The Parties may agree on the provision of an Additional Service in the form of new functionality or an extension of functionality on the basis of a separate agreement for the provision or development of Additional Services. If required, the Customer will submit a request for Additional Services to the Provider through the Form. Following agreement with the Customer and any clarification of the request, the Provider will price the request and send an offer to the Customer. The separate agreement for the provision of Additional Services is concluded when the Provider receives the Customer's confirmation accepting the terms for provision of the Additional Service.

**10.2.** A request for an Additional Service must contain at least:

**a)** a specification of the Additional Service; and

**b)** the preferred date for provision of the Additional Service.

**10.3.** The Customer acknowledges that, in this case as well, the licence is granted to the Customer as a non-exclusive licence within the scope of Article 9 of these GTC.

## 11. Service availability

**11.1.** The Customer acknowledges that events beyond the Provider's control may occur that affect the functionality of the Service or its availability to Users (e.g. an internet connection outage on the Customer's side, natural disasters, attacks on the Provider's technical equipment and other events). The Provider bears no liability for damage incurred by the Customer in connection with such events.

**11.2.** The Customer acknowledges and agrees that the Provider may temporarily stop providing the Service for serious reasons (e.g. an outage affecting the provider of cloud storage for the Online Applications or a third party, the need to prevent a cyberattack, or a serious malfunction of an Online Application requiring a necessary shutdown) or during regular maintenance. The Customer must be notified immediately of any interruption of the Service. However, the Provider undertakes to implement appropriate operational and security measures to minimise any malfunction or partial or complete unavailability of the Service.

**11.3.** The Customer is entitled to a reasonable discount on the price of the Service if a Service outage lasts more than 14 consecutive days. The Customer must claim the discount within 30 days of the Service becoming available again; otherwise, its right to the discount expires.

## 12. Rights and obligations of the Provider

**12.1.** The Provider undertakes to exercise reasonable care consistent with customary business practice to keep the Online Applications functional and available so that the Customer can use them under the Agreement and these GTC. The Provider gives no warranty that the Online Applications will be error-free or continuously available, or that identified errors will or can be corrected. The Services are always provided to the Client “as is” and “as available”, without any express or implied representations, warranties or assurances regarding their compatibility, completeness, interoperability, integration, reliability, availability, performance or security.

**12.2.** If an abnormal situation occurs in the operation of the Service, the Provider will proceed, in particular, in accordance with the Service Outage Resolution document.

**12.3.** The Provider undertakes not to modify and/or monitor the Customer's data in any way and is likewise not obliged to assess their compliance with applicable law.

**12.4.** The Provider may collect and use anonymised aggregated data on use of the Service and data derived from the Customer's content in anonymised form for the operation, development and improvement of the Services, statistics and benchmarking, without any time limit, including after the Agreement ends. The Provider guarantees that the Customer and its Users cannot be identified from data anonymised and used in accordance with this Article.

**12.5.** The Provider undertakes to implement reasonable technical and organisational measures to secure data and access to them, corresponding to the level of identified risk. In accordance with the transparency requirement, the Provider develops and continuously updates its data security system.

## 13. Rights and obligations of the Customer

**13.1.** The Customer undertakes to use the Online Applications solely for the purpose defined in the Agreement and these GTC.

**13.2.** At the Provider's request, the Customer undertakes to provide the necessary cooperation in remedying malfunctions or making modifications to the Online Applications.

**13.3.** The Customer must keep access credentials for the Online Applications confidential and must not disclose them to anyone or otherwise allow access to them. It must also secure its technical equipment to a reasonably required extent to minimise the risk of misuse of User Account access credentials.

**13.4.** If the Customer discovers that the Service may become accessible to third parties as a result of a leak of access information, it must notify the Provider of this fact without delay through the Form.

**13.5.** The Customer bears full responsibility for use of the Service by Users, actions taken by those Users and all data uploaded to the Customer's account. The Customer must ensure that all its Users comply with these GTC.

**13.6.** If the Customer discovers problems with Service availability, it must report them to the Provider without delay through the Form. The Provider must respond to such a report within 24 hours if it was delivered by 14:00 Central European Time, or otherwise on the following Business Day.

**13.7.** If the Customer breaches the obligations regarding the security of data and access credentials for the Online Applications set out in these GTC, the Provider bears no liability for damage incurred by the Customer, and the Customer is fully liable for damage incurred by the Provider or third parties.

## 14. User Account

**14.1.** The Customer may have one or more User Accounts for any of the Online Applications.

**14.2.** Each User Account may be used by only one User. The Customer may not have a User Account created for a third party unless provided for in the Agreement or these GTC. The Customer may not share User Accounts among multiple Users. However, the Customer may transfer an unused User Account to a new User at any time.

**14.3.** If the Online Application or another Service permits it, the Customer may select one or more User Accounts to have Administrator rights. Upon commencement of the Services, the User whose first name and surname are provided to the Provider in the Order becomes the Administrator. The Administrator may perform the following operations:

**a)** add, modify and remove User Accounts and set access rights for those accounts;

**b)** select another User Account to become the Administrator.

## 15. Cooperation between the Parties

**15.1.** The Parties undertake to cooperate closely, in particular by providing each other with complete, truthful and timely information necessary for the proper performance of their obligations.

**15.2.** To ensure optimal performance of the Agreement, the Parties must perform their obligations properly and on time so as to avoid delay. If either Party is in delay in performing its obligations, it must notify the other Party without undue delay of the reason for the delay and the expected date and manner of remedying it.

**15.3.** During performance of the Agreement, the Customer will actively provide the cooperation necessary to carry out the agreed performance. If the Customer breaches its cooperation obligation for more than 14 Business Days, counted from the day the Provider was notified of this, the Provider may suspend performance of its obligations affected by the failure to cooperate until cooperation resumes. The specified deadlines and dates for performance will be extended appropriately, by at least the period of their justified suspension under this provision. If the Customer is in delay under this Article, has been demonstrably notified of it in writing by the Provider, and fails to remedy it within an additional period of at least fourteen (14) days, the Provider may withdraw from the Agreement.

## 16. Prohibited conduct

**16.1.** The Customer undertakes not to upload, send or otherwise store in the Online Applications content that may contain a software virus or other files and programs that could destroy, damage or limit the functionality of the Provider's or other Customers' equipment.

**16.2.** The Customer may not upload to the Online Applications content whose possession or dissemination is illegal, content that unlawfully infringes a third party's copyright or forms part of criminal activity, or attempt to gain access to another customer's User Account or the Provider's servers.

## 17. Penalties

**17.1.** If the Customer is late in paying the price of the Service, the Provider is entitled to late-payment interest of 0.1% of the outstanding amount for each commenced day of delay. If the Customer is more than 30 days late in paying the invoiced amount, the Provider may suspend or restrict provision of the Service until the outstanding claim is paid in full. During any suspension or restriction of the Service, the Customer's obligation to pay the price of the Services provided continues.

**17.2.** If the Customer has demonstrably breached:

**i.** its confidentiality obligation under Article 20 of these GTC;

**ii.** its obligations under Article 9.4(a), (c), (d), (e) of these GTC;

**iii.** its obligation under Article 14.2 of these GTC; or

the Provider may demand payment of a contractual penalty of CZK 100,000 (in words: one hundred thousand Czech crowns) for each individual breach, and the Customer must pay the contractual penalty.

**17.3.** If the Customer has demonstrably breached its obligation under Article 9.4(b) of these GTC, the Provider may demand payment of a contractual penalty of CZK 2,000,000 (in words: two million Czech crowns), and the Customer must pay the contractual penalty.

**17.4.** The contractual penalty is payable on the 15th day after delivery of a written demand for payment.

**17.5.** Payment of the contractual penalty does not affect the entitled Party's right to compensation for damage.

## 18. Liability for damage and indemnification obligation

**18.1.** The Parties agree that the Provider's total liability for any claim arising from the legal relationship established by the Agreement will not exceed, and is limited to, an amount corresponding to the price of the Services provided to the Customer in the preceding calendar month. If that amount cannot be determined, compensation for damage is limited to the price paid by the Customer in the given year.

**18.2.** The Provider is not liable for indirect damage arising from the provision of the Services, i.e. lost profits, loss of revenue, loss of data, financial damage, or indirect, special or consequential damage.

**18.3.** The Customer undertakes to indemnify the Provider and compensate it for all harm and costs (including reasonably incurred legal representation costs) incurred by the Provider in connection with any third-party claims arising in connection with:

**i.** content and data uploaded or otherwise made available by the Customer or its Users (in particular for infringement of intellectual property rights, personality rights or other third-party rights);

**ii.** use of the Service by the Customer and/or its Users in breach of the Agreement, these GTC or applicable law;

**iii.** misuse, unauthorised access or a security incident arising for reasons attributable to the Customer and/or its Users;

**iv.** claims by the Customer's clients, customers, suppliers or other contractual partners brought against the Provider in connection with use of the Service by the Customer or its Users.

The Customer's obligation under this Article does not apply to the extent that the harm, damage, costs or expenses were demonstrably caused by a breach of the Provider's obligations.

**18.4.** In the cases under Article 18.3(i)–(iii), in addition to indemnification for harm, the Provider may suspend the Customer's and/or User's access to the Service and remove or disable access to content that violates applicable law or these GTC, in each case without any entitlement to compensation or reimbursement.

**18.5.** To the extent that the Service allows integration with third-party services, those services are governed by the terms of the respective third parties. The Provider is not liable for the activities of independent services selected by the Customer to the extent permitted by law; this does not affect the Provider's liability for its own obligations or for Sub-processors it has engaged in providing the Services. Article 25 of the GTC also applies to the MCP interface.

## 19. Personal data protection and use of artificial intelligence

**19.1.** The Provider takes care to protect personal data and secure data entrusted by the Customer in the provision of the Services.

**19.2.** Information on the processing of the Customer's personal data is available on the Provider's website: https://www.clientology.cz/en/ochrana-osobnich-udaju.

**19.3.** The rights and obligations between the Provider, as the processor of personal data, and the Customer, as the controller of the personal data of its clients and other persons, are set out in Annex No. 1 to these GTC.

**19.4.** The terms for making available and using features based on artificial intelligence in the Online Applications and other services provided by the Provider are governed by the rules set out in Annex No. 3 to these GTC.

## 20. Protection of confidential information

**20.1.** In performing obligations under the Agreement, the Customer and the Provider may exchange information considered confidential. Confidential information includes, among other things, all information exchanged between them that constitutes a trade secret within the meaning of Section 504 of the Civil Code. The exchange of information will be limited to those employees of the Parties directly involved in activities forming the subject matter of the Agreement. The information provided will be used solely to perform the Parties' obligations under the Agreement and these GTC.

**20.2.** Neither Party may disclose or otherwise make available to any third party any information about the terms, subject matter or performance of the Agreement, or any other information concerning negotiations connected with the Agreement or relating to the other Party, or use such information for its own purposes contrary to its intended purpose, without the prior written consent of the Party concerned, except for information published by the Parties pursuant to a statutory obligation. The Parties consider such information confidential and undertake to maintain its confidentiality to the fullest extent possible. The confidentiality obligation under the preceding sentence of this Article is also subject to exceptions for information disclosed:

**a)** to employees, advisers and other collaborators or subcontractors of the Parties who are bound by similar confidentiality obligations;

**b)** to employees of the relevant state institutions and courts where disclosure is required by law or otherwise lawfully requested;

**c)** where the relevant Party has already published the information or it was already generally known without either Party breaching its obligations;

**d)** to persons affiliated with a Party within the meaning of Sections 74 to 77 of the Business Corporations Act, where such disclosure is necessary for the performance of that Party's obligations under the Agreement;

**e)** by the Provider or the Customer to its owner, to whom it is obliged to report on the company's operations.

**20.3.** Subject to the conditions of this Article and provided that the Customer's rights and legitimate interests are not affected, the Customer consents to the Provider using the Customer's business name as a reference in its printed materials and promotional activities.

## 21. Amendments to the GTC

**21.1.** The Provider may propose amendments to the GTC, in particular in response to changes in law, in the interests of improving the quality of the services provided and with regard to the Provider's business objectives.

**21.2.** The Provider will inform the Customer of a proposed amendment to the GTC at least 2 months before the proposed effective date of the amendments, including information on that proposed effective date.

**21.3.** Unless the Customer rejects the proposed amendment to the GTC in relation to the services provided in writing no later than 15 days before the proposed effective date, the Customer is deemed to have accepted the proposed amendment with effect from the date proposed by the Provider. Amendments to the GTC apply to both new and previously provided services, unless the Provider specifies otherwise in the GTC.

**21.4.** If the Customer rejects the proposed amendment to the GTC in relation to the services provided in writing, or accepts it with reservations, within the period under Article 21.3, the Provider may terminate the Agreement by notice with effect from the effective date of the amendment to the GTC. If the Provider does not give notice of termination, the Agreement remains valid and effective between the Parties under the original wording of the GTC or, as applicable, the wording of the GTC subject to the reservation.

## 22. Termination of the Agreement

**22.1.** The Agreement may end by withdrawal from the Agreement, expiry of its agreed term, agreement between the Parties, or expiry of the Trial Version of the Service, where available, if the Customer does not switch to the paid version of the Service.

**22.2.** If the Agreement is concluded for an indefinite term, the Customer may terminate it by notice at any time without giving a reason. The notice period is three (3) months and begins on the first day of the calendar month following delivery of the notice to the Provider.

**22.3.** The Provider may terminate the Agreement by notice at any time without giving a reason. The notice period is three (3) months and begins on the first day of the calendar month following delivery of the notice to the Customer.

**22.4.** If the Customer materially breaches its obligations under these GTC or the Agreement, or repeatedly breaches them during the preceding five (5) months, the Provider may withdraw from the Agreement. Withdrawal takes effect 24 hours after delivery of the withdrawal notice to the Customer. If the Provider withdraws from the Agreement, the Customer will be denied access to its User Account from the time the withdrawal takes effect, but will be allowed to export data under Article 23 of these GTC.

**22.5.** For the purposes of these GTC, a material breach of the Customer's obligations includes, in particular:

**a)** the Customer being more than 30 days late in paying the Price or any part thereof;

**b)** insolvency proceedings having been initiated against the Customer or the Customer entering liquidation; and

**c)** a breach of the obligations set out in Articles 9.4, 13.3 and 16 of these GTC.

**22.6.** After withdrawal, the Provider does not refund payments for performance already provided under the Agreement.

**22.7.** Termination of the Agreement does not affect the Parties' rights and obligations that, by their nature or by express agreement, are intended to survive termination. This applies in particular, but not exclusively, to provisions governing the protection of confidential information, intellectual property rights, licences under Article 9.6, limitations of liability, contractual penalties and claims for compensation or indemnification for harm.

## 23. Retrieval of data after termination of the Agreement

**23.1.** For 30 days from termination of the Agreement, the Customer may use its User Account to export data stored in the Online Application in PDF and/or CSV format, depending on the type of Service.

**23.2.** After the period specified in the preceding paragraph expires, the data will be irreversibly deleted.

## 24. Final provisions

**24.1.** The Parties may perform their obligations through third parties without the other Party's written consent, but remain liable as if they had performed the obligations themselves.

**24.2.** If the Provider and the Customer agree that their mutual relations are governed by general terms and conditions, their mutual relations are always governed by the most recent version of the GTC valid at the time of conclusion of the Agreement.

**24.3.** In the event of a conflict between the Agreement, the Annexes and the GTC, the documents apply in the following order of precedence: first the Agreement, then the Annexes, and finally the GTC.

**24.4.** Rights arising for the Customer under the Agreement and these GTC may not be assigned without the Provider's prior written consent. Rights arising for the Provider under the Agreement and these GTC may be assigned without the Customer's prior consent.

**24.5.** The Customer may not unilaterally set off its claims against the Provider without the Provider's prior written consent. The Provider may unilaterally set off its claims against the Customer without the Customer's consent.

**24.6.** If any provision of the Agreement or these GTC is or becomes invalid, unenforceable, legally non-existent or ineffective, this does not affect the validity, enforceability or effectiveness of the other provisions of the Agreement or these GTC. In such a case, the Parties must make every effort to conclude an addendum to the Agreement replacing the invalid, unenforceable or ineffective provision with a new provision corresponding to the originally intended purpose.

**24.7.** These GTC are governed by the laws of the Czech Republic. All disputes arising between the Provider and the Customer that cannot first be resolved amicably will be decided by the Czech court having subject-matter and territorial jurisdiction.

**24.8.** The following Annexes form an integral part of these GTC:

Annex No. 1 – Processing of personal data

Annex No. 2 – Service Outage Resolution

Annex No. 3 – Artificial intelligence features

**24.9.** These GTC become valid and effective on 1 October 2026.

## 25. MCP interface and integration with third-party services

**25.1.** The MCP interface means the Provider's interface using the Model Context Protocol, which enables an Online Application to be connected to an external client, application, AI assistant or other service selected by the Customer (an “External Client”). The MCP interface is an optional feature activated by the Customer in its workspace settings, where available for the relevant Online Application.

**25.2.** By activating the MCP interface and granting access permissions to an External Client, the Customer instructs the Provider to make data available to that External Client within the scope of the permissions granted and its authorised requests. Activation of the MCP interface alone does not authorise disclosure of data to unauthorised persons. The MCP interface supports reading, modifying and deleting data; specific operations may be performed only within the scope of the permissions granted and the External Client's authorised requests.

**25.3.** The Customer is responsible for selecting the External Client and its operator, the lawfulness of the connection and data disclosure, the scope of the permissions granted, the security of access credentials on its side, and the actions of Users to whom it grants access to the MCP interface. Before connecting an External Client, the Customer must assess its terms of use and data protection terms and ensure the necessary permissions, lawful bases and fulfilment of information obligations towards affected persons.

**25.4.** The Customer acknowledges that an External Client may store, process or disclose the data made available to it to other persons, including AI model providers, and may process them outside the European Economic Area. Such subsequent handling of data is governed by the terms of the respective external services. Merely connecting an External Client selected by the Customer does not make its operator a Sub-processor engaged by the Provider; its role is assessed according to the actual nature of the processing and applicable law.

**25.5.** To the extent permitted by law, the Provider is not liable for the subsequent storage, use, disclosure or transfer of data by an independent External Client selected by the Customer, or for harm caused by its activities, provided that the Provider made the data available in accordance with the Customer's authorised instruction and the permissions granted. This provision does not exclude or limit the Provider's liability for breaches of its own obligations, in particular inadequate security of the MCP interface, disclosure of data beyond the permissions granted, or breaches of obligations under personal data protection legislation. This is without prejudice to Data Subjects' claims or liability that cannot be excluded or limited under applicable law.

**25.6.** The Customer may deactivate the MCP interface and revoke access permissions through the relevant settings or by submitting a request to the Provider. Following deactivation or effective revocation of permissions, the Provider will prevent further access within the affected scope. This does not automatically delete data already disclosed to an External Client; the Customer must arrange any deletion with the operator of the relevant external service. The Provider may restrict or suspend access through the MCP interface to the extent necessary to address a security incident, misuse or a breach of the Agreement or applicable law.

## Annex No. 1 to the GTC – Processing of personal data

## 1. Processing of personal data

**1.1.** In providing the Services under the Agreement and these GTC, personal data of third parties (“Data Subjects”) entered into the Online Application by the Customer are processed. For the purposes of the GDPR, the Customer acts as the controller of the Data Subjects' personal data and the Provider acts as the processor; their relationship is governed by this Annex No. 1 to the GTC.

**1.2.** For the purpose of carrying out activities under the Agreement, the Provider may process the Data Subjects' personal data, in particular identification and contact data.

## 2. Manner of processing personal data

**2.1.** The Provider may process the Data Subjects' personal data on behalf of the Customer as follows:

**a)** manner of processing: personal data may be processed manually, semi-automatically or automatically;

**b)** duration of processing: throughout the term of the Agreement and for 1 year from its termination, unless otherwise agreed between the Parties;

**c)** nature of processing: in accordance with the precisely specified rules under the Agreement and the Customer's written instructions;

**d)** purpose of processing: performance of the Agreement; and

**e)** categories of Data Subjects: the Customer's clients and other persons.

## 3. Provider's representations

**3.1.** The Provider represents and warrants to the Customer that it has adopted appropriate technical and organisational measures to ensure that the processing of personal data meets all requirements of the GDPR and related legislation concerning personal data security, so as to protect the rights of Data Subjects.

**3.2.** The Provider will also ensure compliance with this representation where personal data are processed through any representatives authorised by it and/or other processors engaged by the Provider in processing personal data in accordance with this Agreement (“Sub-processors”).

## 4. Rights and obligations of the Provider

**4.1.** The Provider must follow the Customer's instructions and process personal data solely for the purposes and to the extent necessary to carry out activities under the Agreement. The Provider must inform the Customer without delay if, in its opinion, an instruction violates applicable law.

**4.2.** The Provider must also:

**a)** maintain the confidentiality of personal data, including after the Agreement ends;

**b)** process personal data solely to the extent necessary for the proper performance of activities under the Agreement;

**c)** keep personal data obtained for different purposes separate; and

**d)** process personal data in a manner ensuring sufficient security of personal data, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, through appropriate technical or organisational measures corresponding to the manner in which personal data are processed.

**4.3.** At the Customer's written request, the Provider must demonstrate that, when processing the Data Subjects' personal data, it complies with all obligations set out in this Agreement, the GDPR and related legislation. The Provider undertakes to allow the Customer or a person authorised by it to inspect compliance with these obligations at the Provider's premises.

**4.4.** The Provider undertakes, within its capabilities, to cooperate with the Customer in the performance of the Customer's obligation.

## 5. Personal data breach

**5.1.** In connection with a personal data breach and/or any security incident, the Provider must notify the Customer of the identified breach without delay at its contact email address.

**5.2.** The Provider further undertakes to provide the necessary cooperation to the Customer in notifying the Office for Personal Data Protection of the security breach or informing Data Subjects.

**5.3.** The Provider undertakes to adopt measures to minimise the effects of the security breach on the rights of Data Subjects.

## 6. Rights and obligations of the Customer

**6.1.** The Customer may require the Provider to demonstrate compliance with its obligations, including the adoption of appropriate technical and organisational measures to ensure and be able to demonstrate that personal data are processed in accordance with this Agreement, the GDPR and other related legislation.

**6.2.** The Customer may conduct a personal data protection audit at the Provider, and the Provider must cooperate in the personal data protection audit and inspection by the Customer and/or an auditor authorised by the Customer. The date, scope and other conditions of the audit are subject to prior agreement between the Parties.

**6.3.** The Customer undertakes to cooperate with the Provider in the performance of its obligations under the GDPR and related personal data protection legislation.

## 7. Obligations of the Parties towards Data Subjects

**7.1.** The Customer must ensure that Data Subjects can exercise all rights they have against it.

**7.2.** If a Data Subject addresses a request to the Provider, the Provider must forward the Data Subject's request to the Customer without undue delay and inform the Data Subject that the request has been forwarded to the Customer.

**7.3.** The Customer undertakes to cooperate with the Provider in the performance of its obligations under the GDPR and related personal data protection legislation.

## 8. Involvement of other persons in processing

**8.1.** By concluding the Agreement, the Customer grants the Provider general written authorisation to engage Sub-processors in the processing of personal data subject to this Annex and Article 28 of the GDPR. The Provider will enter into an agreement with each Sub-processor imposing data protection obligations to the extent required by Article 28(4) of the GDPR.

**8.2.** The Provider is fully liable to the Customer for breaches of a Sub-processor's obligations.

**8.3.** The Provider must ensure that its employees and/or Sub-processors, or any other person designated by it who processes personal data for the Provider:

**a)** are properly and thoroughly instructed on the rights and obligations relating to the processing of personal data;

**b)** are bound by a duty of confidentiality regarding such data, including after their legal relationship with the Provider ends;

**c)** comply with the adopted technical and organisational measures and the conditions for processing personal data under this Agreement; and

**d)** are bound to fulfil the obligations under this Agreement to at least the same extent as the Provider.

**8.4.** Before the relevant processing begins, the Provider will make an up-to-date list of Sub-processors available to the Customer, identifying each Sub-processor, the service provided, the purpose and scope of processing, the countries or areas of processing, and any safeguards for transfers outside the European Economic Area. For AI Features, the Provider uses Microsoft Azure OpenAI operated by a company within the Microsoft group; the specific Microsoft contracting entity will be identified in that list.

**8.5.** The Provider will notify the Customer at its contact email address of any intended addition or replacement of a Sub-processor at least 30 days before that Sub-processor is engaged. Within that period, the Customer may submit a reasoned written objection on data protection grounds. Until the objection is resolved, the Provider will not transfer the Customer's personal data to the new Sub-processor concerned, and the Parties will discuss a reasonable alternative solution.

**8.6.** If the Parties do not agree on a solution to the objection and the relevant part of the Service cannot be provided without the Sub-processor concerned, either Party may terminate that part of the Service in writing. If it is inseparable from the other Services, either Party may terminate the Agreement under the same conditions. In such a case, the Provider will refund the pro rata portion of the prepaid price for Services not provided for the period following termination; for this case, this rule replaces Article 7.5 of the GTC.

**8.7.** Personal data may be transferred outside the European Economic Area only where the conditions of Chapter V of the GDPR are met, in particular on the basis of a valid adequacy decision or appropriate safeguards, including standard contractual clauses and any supplementary measures where required.

## Annex No. 2 to the GTC – Service Outage Resolution

## 1. Resolution of defects and problems

**1.1.** Definitions:

For the purposes of this Annex, a Critical Problem means a complete failure of the entire supported Online Application or a part thereof that prevents basic operations from being performed.

For the purposes of this Annex, a Serious Problem means a condition of the supported Online Application or a part thereof that allows basic operational functions to be performed, but with a substantial reduction in processing speed or under exceptional operational measures.

For the purposes of this Annex, a Problem means any defect in the supported Online Application that does not fall within any of the above categories.

**1.2.** During the provision of the Service by the Provider to the Customer, problems may arise in operating the product that can be divided into three priority categories according to their severity (urgency):

**a)** Priority 1 – Critical Problem

**b)** Priority 2 – Serious Problem

**c)** Priority 3 – Problem

**1.3.** Authorised employees of the Customer communicate the appropriate priority classification based on problem reports from Users through the Form. The Customer must specify a contact person in the report, including their telephone number.

**1.4.** The Provider undertakes to respond with a statement to any report under Article 1.3 above within the time limits set out below, measured from receipt of the Customer's problem report, in accordance with the rules specified below. The Provider's response to a reported system problem means confirmation of receipt of the problem report and of the adoption of measures to resolve the reported problem. The Provider may discuss the reported problem with the contact person and, following that discussion, change its category (priority). The Parties agree that operational rules and mechanisms will be specified during implementation of the agreed performance and confirmed by both Parties in an implementation protocol.

**1.5.** Commencement of handling a defect claim for all urgency categories of Defects means that, within the specified time, an employee of the Provider will inform the Customer's contact person named in the defect claim report electronically through the Online Application or by telephone:

whether the defect claim is accepted as justified in the urgency category (priority) specified by the Customer,

or whether it is a defect claim in a different urgency category (priority),

or ask additional questions to clarify the difficulties with the relevant Online Application,

or whether the defect claim is unjustified or further information is required to verify it,

or that the problem is being referred to a third party for resolution,

and at the same time propose further action, either by providing an acceptable solution to the problem or commencing work to rectify or locate the defect covered by the claim.

**1.6.** Following expert assessment of properly submitted Defect Claims, information about the claim will be sent to the Customer by email no later than the deadline specified for the relevant category.

Where necessary, the Customer will be informed whether its defect claim has been classified as:

a justified defect claim in urgency category Priority 1, 2 or 3,

an unjustified defect claim,

or whether further information is required to process it.

For a justified defect claim, the Customer will be informed of the resolution method and the expected date for distribution of the fix.

For an unjustified defect claim, the correct procedure will be explained.

**1.7.** The Provider guarantees the Customer a response within the following time limits from receipt of a problem report:

**a)** Priority 1 – Critical Problem:

The Provider's telephone response to the Customer's reported problem, commencing its resolution, will occur within 24 hours if the report was delivered by 14:00 Central European Time, or otherwise on the following Business Day. If a defect in the supplied software is identified, the Provider will agree with the Customer on the method and date of rectification, no later than within 3 Business Days, either by rectifying the defect or implementing an alternative workaround that ensures basic functionality so that the condition no longer meets the definition of a Critical Problem or Serious Problem.

**b)** Priority 2 – Serious Problem:

The Provider's telephone response to the Customer's reported problem, commencing its resolution, will occur within 24 hours if the report was delivered by 14:00 Central European Time, or otherwise on the following Business Day. If a defect in the supplied software is identified, the Provider will agree with the Customer on the method and date of rectification, no later than within 5 Business Days, either by rectifying the defect or implementing an alternative workaround that ensures basic functionality so that the condition no longer meets the definition of a Serious Problem.

**c)** Priority 3 – Problem:

The Provider's telephone response to the Customer's reported problem will occur within 24 hours if the report was delivered by 14:00 Central European Time, or otherwise on the following Business Day. Within 10 Business Days, the Customer will either be provided with alternative instructions for resolving the problem or notified of the date of an analytical meeting at which both Parties will assess the problem and propose a method of resolving it.

**1.8.** A contact person for communication during resolution of the problem must be specified when the problem is reported.

**1.9.** The problem report, describing how and when the problem occurs, must state the procedure that led to the problem and should, where possible, be supported by an accurate description of error messages or an accurate record of input and output (incorrect) values or resulting symptoms. A problem is considered resolved if the Provider resolves the reported request and informs the Customer, and the Customer does not object to that method of resolution within 10 Business Days. An employee of the Customer will confirm or comment on the method of resolving the request no later than 3 Business Days after the Provider provides information on the resolution method. The Provider will ensure automatic notification of all the Customer's employees designated by the Customer as contact persons.

**1.10.** The Customer's objections under the preceding paragraph will be treated as a problem report under Article 1.3 and will be subject to new time limits for the Provider's response under Article 1.7 of this Annex.

**1.11.** If the problem was not caused by the Provider's fault or a defect in the work, the Provider may charge properly documented costs associated with identifying the problem and any repair.

**1.12.** The designated representatives of the Parties must respond within 5 Business Days at the latest to other types of requests submitted to the Provider. If the Customer's representative does not respond to the Provider's position within the specified period, the Customer is deemed to agree with the proposal and, where applicable, the Provider may close the request.

## Annex No. 3 to the GTC – Artificial intelligence features

## 1. Introductory provisions and definitions

**1.1.** This Annex forms an integral part of the Provider's General Terms and Conditions (“GTC”) and governs the terms for making available and using features based on artificial intelligence in the Online Applications and other services provided by the Provider.

**1.2.** The Provider may determine that certain AI Features will be available only for selected Online Applications, plans, user roles or groups of Customers.

**1.3.** Capitalised terms not defined in this AI Annex have the meanings assigned to them in the GTC.

**1.4.** For the purposes of this Annex, the terms below have the following meanings:

“AI Features” means features of the Online Applications that use an artificial intelligence system, generative model, large language model, machine learning or other similar technology to work with content.

“Input” means any prompt, instruction, query, text, document, file, image, data, content or other information entered into an AI Feature by the Customer or a User or otherwise made available to an AI Feature by them.

“Output” means any content, response, text, proposal, recommendation, summary, classification, analysis, image, data output or other result generated by an AI Feature on the basis of Input.

“AI Model Provider” means a third party that provides, operates or makes available to the Provider a model, infrastructure or other artificial intelligence technology used within the AI Features.

## 2. Nature of AI Features and Outputs

**2.1.** The Customer acknowledges that AI Features are based on probabilistic models. Outputs may therefore be inaccurate, incomplete, outdated, misleading, inappropriate or factually incorrect, even if they appear convincing or are expressed as unambiguous facts. Outputs do not constitute legal, tax, accounting, investment, medical, human resources or other professional advice provided by the Provider.

**2.2.** The Provider does not guarantee that:

**a)** an Output will be correct, accurate, complete, current or suitable for a particular purpose;

**b)** an Output will meet the Customer's expectations;

**c)** use of an Output in a particular case will comply with applicable law, professional rules or the Customer's internal regulations;

**d)** an Output will not contain content identical or similar to content provided to other customers; or

**e)** an Output or its use will not infringe third-party rights.

This is without prejudice to the Provider's liability to the extent that it cannot be excluded or limited under mandatory law.

**2.3.** The Customer will ensure that Users to whom it grants access to AI Features are appropriately instructed, before using them, on the nature, capabilities and limitations of AI Features, in particular the risk of inaccurate, incomplete or misleading Outputs, the obligation of human review, and the prohibition on using AI Features in breach of this AI Annex, the GTC or applicable law.

**2.4.** The Customer must not present an Output as a verified or reliable result of the Provider.

## 3. Responsibility for Inputs

**3.1.** The Customer is solely responsible for Inputs and the manner in which they are used.

**3.2.** The Customer represents and warrants that:

**a)** it is authorised to enter the Input into the AI Feature and permit its processing in accordance with this AI Annex;

**b)** neither the Input nor its processing violates applicable law, contractual obligations or third-party rights;

**c)** it has obtained all necessary permissions, consents and licences relating to the Input; and

**d)** the Input contains no malicious code, unlawful content or instructions intended to circumvent security measures of the Online Applications or the AI model.

**3.3.** The Customer must not use AI Features to process information whose disclosure to the Provider or the AI Model Provider would breach a duty of confidentiality, trade secret protection or another obligation to protect confidential information, unless it is authorised to make such disclosure.

**3.4.** The Customer is also responsible for Inputs entered by Users to whom it has granted access to the Online Application.

## 4. Personal data and sensitive information

**4.1.** The Customer may enter personal data into AI Features only if their processing complies with applicable law and the personal data processing agreement concluded between the Customer and the Provider, is necessary for the use of the Online Applications, the Customer has a lawful basis for their disclosure, and it has fulfilled all other obligations under personal data protection legislation.

**4.2.** Under no circumstances may the Customer enter special categories of personal data within the meaning of Articles 9 and 10 of the GDPR into the Online Applications through AI Features.

**4.3.** The Customer must also not enter access passwords, authentication credentials, private cryptographic keys or other data whose disclosure could immediately jeopardise the security of the Customer or a third party into AI Features.

**4.4.** The Customer is responsible for the consequences of entering personal data or other protected information in breach of this Article.

## 5. Involvement of AI Model Providers

**5.1.** To provide AI Features, the Provider may transfer Inputs and, where applicable, related technical data to AI Model Providers. Such transfer will be limited to the extent necessary, in particular, to generate the Output, ensure security, prevent misuse and technically operate the AI Feature, and to resolve technical incidents or support requests.

**5.2.** The Provider will make information on the AI Model Providers currently used available in the Online Application, documentation, a list of Sub-processors or by other reasonable means. Engagement and changes of Sub-processors are governed by Annex No. 1 to the GTC.

**5.3.** To provide AI Features, the Provider uses OpenAI models through Microsoft Azure OpenAI, operated by a company within the Microsoft group. In this deployment, the service is operated within Microsoft Azure; it does not involve direct use of the public ChatGPT service or the API operated by OpenAI. Engagement of additional or replacement providers is governed by this Annex and, where personal data are processed, Annex No. 1 to the GTC.

**5.4.** To process an AI Feature request, Inputs and relevant parts of workspace or Online Application content needed for that feature, and any related technical data, may be sent to the service. Disclosure is limited to the extent necessary for the purposes under Article 5.1 of this Annex and must respect the Customer's and User's access permissions. The Provider will make information on the scope of content disclosed for each AI Feature available in the Online Application or its documentation.

**5.5.** Processing of data through Microsoft Azure OpenAI is governed by the features used, the service configuration and the applicable contractual data protection terms. It may include retention of data and processing for security and abuse prevention purposes. This provision does not guarantee a specific technical region, processing exclusively within the European Union or the absence of data storage. This does not affect the Provider's obligations concerning security, limitation of retention periods and provision of information under applicable law and Annex No. 1 to the GTC. Any transfer of personal data outside the European Economic Area is permitted only subject to the conditions set out in Annex No. 1 to the GTC.

## 6. Use and review of Outputs

**6.1.** The Customer alone decides whether and how an Output will be used. The Customer is responsible for all decisions, actions, communications, documents and other results based wholly or partly on an Output.

**6.2.** Before using an Output, the Customer must ensure appropriate human review, in particular verification of its correctness, completeness, currency, lawfulness, suitability and any effects on the rights or legitimate interests of other persons.

**6.3.** The Customer acknowledges that the same or similar Output may also be generated for other users of the Online Applications and AI Features.

**6.4.** To the extent that the Provider acquires transferable or licensable rights to an Output, the Provider grants the Customer permission to use the Output for the purposes for which the Customer is authorised to use the Online Application. This is without prejudice to third-party rights or restrictions arising from applicable law.

## 7. Anonymised and aggregated data

**7.1.** The Provider may use Inputs, Outputs and data on use of AI Features in anonymised or aggregated form for the purposes of:

**a)** developing and improving the Online Applications and AI Features;

**b)** measuring the quality, reliability, security and performance of the Online Applications;

**c)** detecting errors, misuse and security risks; and

**d)** creating statistics and analytical outputs.

**7.2.** Data under the preceding paragraph may be used only if they have been processed so that, using reasonably available means, they cannot be attributed to a specific Customer, User or other identified or identifiable natural person. Mere pseudonymisation of data does not constitute anonymisation for the purposes of this AI Annex.

## 8. Prohibition of automated decision-making and other restrictions on use of AI Features

**8.1.** The Customer must not use AI Features or Outputs as the sole or effectively decisive basis for legally or similarly significant decisions that (i) establish, modify or extinguish the rights or obligations of a natural person; or (ii) may affect a natural person in another similarly significant manner, unless real and meaningful human review is ensured before such a decision is made.

**8.2.** The Customer is responsible for fulfilling information obligations towards persons affected by the use of AI Features and ensuring the possibility of human review or challenge of a decision where required by law. If the Customer uses an Output in communication with a natural person or as part of content made available to third parties, it will ensure that the person is informed, to the extent required by law and appropriately to the nature of the use, that the content was created or modified using an AI Feature.

**8.3.** AI Features must not be used in a manner prohibited by law. The Provider may issue specific documentation, instructions, usage limits or security rules for a particular AI Feature. The Customer must ensure that both it and its Users comply with such documentation, instructions, limits and rules.

**8.4.** AI Features are not intended to be used as a high-risk AI system within the meaning of directly applicable European Union legislation on artificial intelligence. The Customer must not use AI Features in areas or in a manner that would result in an AI Feature being classified as a high-risk AI system or in special obligations being imposed on the Provider.

## 9. Changes, restrictions and suspension of AI Features

**9.1.** The Provider may continuously modify, update or replace AI Features, the models used or AI Model Providers, in particular with regard to technological developments, changes in law, security risks, availability of third-party services or business and operational needs.

**9.2.** The Provider may temporarily restrict or suspend an AI Feature, where necessary, in particular:

**a)** for security, legal or technical reasons;

**b)** as a result of an outage or restriction affecting an AI Model Provider;

**c)** due to suspected misuse of an AI Feature; or

**d)** if the Customer or a User breaches this AI Annex, the GTC or applicable law.

**9.3.** The Provider does not guarantee continuous availability of a particular AI Feature or AI model, or the preservation of identical characteristics or methods of generating Outputs.

**9.4.** If an AI Feature is a material part of an agreed paid Online Application, the Provider will notify the Customer reasonably in advance of any material restriction or discontinuation of that AI Feature, unless prevented by security, legal, technical or similarly serious reasons. This is without prejudice to the Customer's rights under the GTC or under mandatory law.

## 10. Liability

**10.1.** The liability rules and limits set out in the GTC apply to the liability of the Parties.

**10.2.** The Provider is not liable for harm arising from:

**a)** use of an Output without appropriate review by the Customer;

**b)** a decision or action by the Customer based on an incorrect, incomplete or inappropriate Output;

**c)** an Input that the Customer was not authorised to enter or process;

**d)** infringement of third-party rights caused by an Input or the manner in which the Customer uses an Output;

**e)** use of AI Features contrary to their purpose, documentation, the GTC or this AI Annex;

**f)** a decision made by the Customer solely or predominantly on the basis of an Output; or

**g)** temporary unavailability or a change in an AI Feature caused by dependence on the services of an AI Model Provider.

**10.3.** The provisions of this Article apply only to the extent permitted by mandatory law. In particular, they do not affect consumer rights, the rights of a weaker party or liability that cannot be excluded or limited in advance under applicable law.

## 11. Final provisions

**11.1.** In the event of a conflict between this AI Annex and the GTC, this AI Annex takes precedence in relation to the use of AI Features. In matters of personal data protection and processing, a personal data processing agreement takes precedence if one has been concluded; otherwise, the personal data processing rules in Annex No. 1 apply.

**11.2.** The rights and obligations under this AI Annex apply to a particular Customer from the day the Provider makes at least one AI Feature available to that Customer. Before that day, this AI Annex does not give the Customer a right to demand access to AI Features.
