SPECIAL CONDITIONS FOR THE FLUIDUM AI PLATFORM
These Special Conditions for the FLUIDUM AI platform (hereinafter referred to as "Conditions") govern the use of the FLUIDUM AI platform and artificial intelligence tools provided by ui42 s.r.o., ID 35713003, with its registered office at Haydnova 20/B, 811 02 Bratislava (hereinafter referred to as "Supplier"), and the processing of data when using them. They apply to the customer using the platform (hereinafter referred to as "Client"). The Supplier and the Client are hereinafter collectively referred to as "Parties".
Article 1 — Subject, Acceptance, and Relationship to Data Protection
1.1 These Terms govern the rights and obligations of the Parties when using the FLUIDUM AI platform and other artificial intelligence tools of the Supplier (hereinafter referred to as the "Platform") and when processing data during their use. They apply only to the extent that the Client uses the Platform.
1.2 The Terms become binding for the Client upon their acceptance, particularly by signing an order or another contract signed by both Parties that refers to this version of the Terms (the version and reference text are stated in the header), or by another demonstrable expression of the Client's consent.
1.3 To the extent that personal data is processed when using the Platform, the Supplier acts as a processor and the Client as a controller, and these Terms form part of the personal data processing arrangement according to Article 28 of Regulation (EU) 2016/679 (GDPR). General data protection obligations agreed between the Parties — particularly the lawfulness of processing, security, confidentiality, cooperation in exercising the rights of data subjects, audit, and data deletion — also apply to processing through the Platform.
1.4 In the event of a conflict between these Terms and another data processing agreement concluded between the Parties, these Terms take precedence regarding the Platform.
Article 2 — Classification and Obligations under the AI Act
2.1 The Platform is an AI system built on general-purpose models (GPAI) of third parties, which the Supplier integrates through commercial APIs. The Supplier acts as the provider of the AI system (Platform) in the sense of Regulation (EU) 2024/1689 (AI Act). The Client's status depends on the method of use: if the Client operates the Platform themselves, they act as a deploying entity (deployer); if the Supplier operates the Platform and only provides outputs to the Client, the Supplier assumes the status of the deploying entity.
2.2 When used for its intended purpose (supporting marketing analysis, reporting, audits, and content creation), the Platform is not classified as a high-risk system according to Annex III and does not engage in prohibited practices under Article 5 of the AI Act. Strategic and business decisions and responsibility for them remain with the Client.
2.3 According to Article 4 of the AI Act, the Parties ensure an adequate level of AI literacy for their employees and persons using the Platform on their behalf, appropriate to their roles and the context of use.
Article 3 — Prohibition of Training on Client Data
3.1 The Supplier will not use any Client data (inputs or outputs) for training or tuning its own artificial intelligence models.
3.2 The Supplier selects additional processors (subcontractors) operating language models so that their commercial (B2B / API) terms exclude the use of input data for model training and commits to maintaining such terms during cooperation. Beyond these guarantees, the Supplier is not responsible for the actions of the subcontractor that are contrary to them, exceeding claims applicable against the subcontractor; the Supplier remains responsible to the Client for imposing corresponding data protection obligations on the subcontractor.
Article 4 — Transit Processing and Retention with Sub-processors
4.1 Data is sent to language models in real-time for the purpose of performing operations and is stored in operational memory or temporary storage during processing.
4.2 According to the commercial terms of subcontractors, input and output data are not used for training and may be retained briefly — according to the terms of the specific subcontractor, usually up to 30 days — solely for abuse detection (Trust & Safety), without access by human operators except for flagged suspicious content, after which they are irretrievably deleted; content flagged as suspicious may be retained longer for abuse investigation or if required by law.
4.3 The Supplier does not have an agreement with current subcontractors for zero retention (Zero Data Retention). If the Client is interested in a stricter regime, the Parties will agree on specific terms and pricing adjustments.
Article 5 — Persistent Knowledge Memory of the Agent
5.1 The Platform includes a persistent knowledge memory of the agent (particularly account and campaign identifiers, report preferences, contextual notes on projects, and reference templates). It does not constitute model training but isolated storage of context for a specific Client.
5.2 In relation to this memory, the Supplier acts as an independent controller for the purpose of improving service quality for the Client. The memory is logically and accessibly isolated between Clients and physically stored on the infrastructure of Hetzner Online GmbH in Germany (EU).
5.3 The Client has the right to extract, delete a specific record or the entire memory, and export it in a machine-readable format upon termination of the contractual relationship; the Supplier will fulfill the request without undue delay, no later than 15 business days. Upon termination of the contractual relationship, the Supplier will irretrievably delete the memory content, except for legal retention.
Article 6 — Security of Inputs and Responsibility for Prompts
6.1 The Platform in its current version does not provide automatic detection, masking, or anonymization of sensitive personal data in inputs (DLP / PII redaction). The Client bears full responsibility for the content of prompts and input data.
6.2 The Client instructs their personnel not to enter into the Platform (unless necessary and agreed in writing in advance): personal identification numbers and national identifiers; passwords, tokens, and API keys; special categories of data according to Article 9 of the Regulation; data of children under 16 years; biometric and genetic data; payment card and account data beyond the necessary extent; trade secrets of third parties without authorization; classified information.
6.3 If the Client enters data according to point 6.2 in violation of these Terms, the Supplier is not responsible for the consequences of their processing on the part of subcontractors.
Article 7 — Nature of AI Outputs and Responsibility
7.1 The Platform's outputs may contain inaccuracies, incompleteness, or fabricated information (hallucinations); this is an inherent feature of language models and does not constitute a defect in the service.
7.2 The Client is obliged to critically verify each output before using it in decision-making, external communication, or legally binding actions. Outputs are not legal, tax, accounting, investment, or other professional advice.
7.3 The Supplier is not liable for damages arising from the Client's actions based on unverified or incorrectly interpreted outputs, except for damage caused intentionally or through gross negligence.
Article 8 — AI Transparency (Article 50 of the AI Act)
8.1 The Supplier, as a provider, ensures that the Platform's user interface clearly informs that the user is interacting with an AI system.
8.2 If the Client further publishes AI-generated content, they are responsible for labeling it to the extent required by Article 50 of the AI Act — particularly for synthetically generated images, audio, or video, and for text published to inform the public about matters of public interest; this obligation generally does not apply to ordinary marketing text and product descriptions. The Supplier will provide the Client with reasonable cooperation.
Article 9 — Security Incidents
9.1 The Supplier will notify the Client of a personal data breach related to the Platform without undue delay, no later than 72 hours after discovery, including a description of the nature of the incident, affected categories and number of persons, probable consequences, and measures taken.
Article 10 — Metadata and Rights to Outputs
10.1 The Supplier, as an independent controller, uses aggregated and anonymized metadata about Platform usage (number and types of prompts, types of tasks, performance metrics, error states) for the operation and improvement of the Platform. These metadata do not contain the content of prompts, outputs, personal or identifiable corporate data of the Client.
10.2 Rights to the Platform's outputs belong to the Client at the moment of their generation and provision, to the extent of possible copyright protection.
Article 11 — Cross-border Transfer with Platform Sub-processors
11.1 When transferring personal data to Platform subcontractors outside the EEA, the Supplier ensures appropriate safeguards, primarily through Standard Contractual Clauses (SCCs) according to Commission Decision (EU) 2021/914, additionally through an adequacy decision (particularly the EU–US Data Privacy Framework for certified recipients), or by processing in data centers within the EU. The list of Platform subcontractors is provided in the Appendix to these Terms.
Article 12 — Final Provisions
12.1 These Terms are binding for the Client from the moment of their acceptance according to Article 1.2 and apply during the period of the Client's use of the Platform.
12.2 These Terms are maintained under the version stated in the header and published at the specified address; each version has its own reference text, and older versions remain permanently available. The issuance of a new version does not itself change the obligations agreed upon according to the version accepted by the Client; the new version applies to the Client only upon its acceptance according to Article 1.2. The Supplier notifies the Client of changes to Platform subcontractors in advance in a demonstrable manner.
12.3 If any provision becomes invalid, it does not affect the validity of the others; the Parties will replace it with a provision closest to the original intent.
Appendix — List of Additional Processors (Subcontractors) of the FLUIDUM AI Platform
|
Subcontractor |
Headquarters / Entity |
Purpose of Processing |
Legal Basis for Transfer |
|
Anthropic, PBC (or Anthropic Ireland Ltd.) |
San Francisco, USA / Dublin, Ireland |
Semantic analysis, audit, text output generation (Claude API – B2B tier) |
SCCs + Commercial Terms (no-training, usually up to 30 days abuse monitoring); EU-US DPF if certified |
|
Google LLC / Google Ireland Ltd. |
California, USA / Dublin, Ireland (EU regions) |
Multimodal data analysis, processing of marketing metrics (Gemini API – paid tier) |
Processing in EU region, or SCCs + Google Cloud DPA (no-training for paid tier) |
|
OpenAI, L.L.C. (or OpenAI Ireland Ltd.) |
San Francisco, USA / Dublin, Ireland |
Content generation, copywriting, creative outputs (OpenAI API – B2B tier) |
SCCs + OpenAI Business Terms (no-training, usually up to 30 days abuse monitoring); EU-US DPF if certified |
|
Hetzner Online GmbH |
Gunzenhausen, Germany |
Hosting of Platform infrastructure including persistent agent memory and operational logs |
Processing in EU (Germany), Hetzner DPA |
|
Mattermost, Inc. |
Palo Alto, USA (self-hosted in EU possible) |
Communication channel between the Client and the Platform (if managed by the Supplier) |
SCCs; or self-hosted in the Supplier's EU infrastructure |
|
Slack Technologies, LLC (Salesforce, Inc.) |
San Francisco, USA |
Communication channel between the Client and the Platform (if managed by the Supplier) |
SCCs + Salesforce DPA; EU-US DPF if certified |
Note: The list of actively used subcontractors may change according to these Terms. The current status is available upon request.