Terms & Conditions — closed beta¶
Document version: beta-2026-08-12
Status: Closed beta. These terms govern your access to and use of the zGentic service during its closed beta phase. You must accept them before an organization can be created.
1. Who these terms are between¶
These terms form an agreement between:
- The supplier — X-CITE S.A., a société anonyme incorporated in the Grand Duchy of Luxembourg, registered office 31, Domaine de Beauregard, L-8357 Goeblange, Grand Duchy of Luxembourg, registered with the Luxembourg Trade and Companies Register (RCS Luxembourg) under B225206, VAT LU30332513 ("we", "us", "our"); and
- You — the organization you register on your first sign-up, and every person who signs in under it ("you", "your", "the customer").
The person who accepts these terms confirms they are authorised to bind their organization.
You must be at least 18 years old and acting in a business or professional capacity. The service is offered business-to-business only and is not offered to consumers during the beta, so the consumer-protection rules of Luxembourg and EU law that apply to consumer contracts are not engaged.
2. What the closed beta is¶
The service is pre-release software offered for evaluation. It is incomplete, changes without notice, and is made available to a limited number of invited organizations.
We may, at any time and without liability to you:
- change, add or remove features, models, limits and interfaces;
- interrupt or suspend the service for maintenance, safety or capacity reasons;
- reset, migrate or delete beta data as part of a release; and
- end the beta programme entirely.
2.1 No service level, no availability commitment¶
The service is provided "as is" and "as available". During the beta we give:
- no uptime, availability or response-time commitment, and no service credits;
- no commitment that data you place in the service will be preserved — keep your own copy of anything you cannot afford to lose;
- no commitment of backwards compatibility between releases; and
- no warranty of merchantability, fitness for a particular purpose, accuracy, or non-infringement, to the fullest extent the law allows.
Nothing in the product interface, documentation or a conversation with us creates a service level during the beta. Any such commitment must be in a separate written agreement.
2.2 Output is not advice, and must be checked¶
The service uses large language models. Their output can be wrong, incomplete, outdated, biased, or fabricated while appearing confident, and can differ between runs on the same input. Output is not legal, financial, medical, safety or professional advice.
You are responsible for reviewing output before you rely on it, publish it, or use it to make a decision that affects a person. Do not use the service as the sole basis for a decision with legal, financial, safety or health consequences for anyone.
3. Your account and your organization¶
You are responsible for:
- the accuracy of the registration details you give us;
- keeping sign-in credentials and API keys confidential;
- everyone who acts under your organization, including anyone you invite; and
- the roles and permissions you grant inside your organization.
Tell us promptly if you believe an account or key has been compromised. We may disable an account, a key or an entire organization immediately where we reasonably believe it is necessary to protect the service, other customers or a third party.
4. Your data¶
4.1 Ownership¶
Your content stays yours. "Your content" means everything you or your users submit — prompts, chats, uploaded files, connected source documents, agent definitions, and the output generated for you. We claim no ownership of it.
4.2 What we do with it¶
We process your content in order to provide the service: to answer your requests, to index documents you connect so they can be retrieved with the permissions you set, to run the agents and tools you invoke, to meter usage for billing, and to keep the service secure and working.
We do not use your content to train our own or a third party's foundation models.
4.3 Who can access it¶
Access to your content is restricted to:
- your own users, according to the roles and document permissions you configure;
- our authorised personnel, only where necessary to operate the service, investigate a fault you report, or respond to a security or abuse incident — under confidentiality obligations and on a least-access basis;
- the third-party providers described in section 5, for the purpose of serving your request; and
- anyone else you tell us to share it with, or where we are legally required to disclose it (where we may lawfully do so, we will tell you first).
Your organization is logically separated from every other customer's. We do not disclose your content to another customer.
4.4 Personal data¶
Where your content contains personal data, you are the controller and we act as processor on your instructions, within the meaning of Regulation (EU) 2016/679 (GDPR) as applied in Luxembourg.
The applicable data-processing terms are set out in Annex A at the end of this document and form part of these terms. Annex A, and any dispute about it, is governed by the laws of the Grand Duchy of Luxembourg, and the courts of Luxembourg have exclusive jurisdiction over it — the same law and forum as the rest of these terms (section 13).
The sub-processors we use are named in Annex A, section A.6, together with what each one processes and, where it is established outside the EEA, the transfer mechanism relied on. The list is inside this document rather than on a separate page, so it is fixed by the version you accepted and cannot be changed without issuing a new version (section 13).
Do not submit special-category personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation), payment-card numbers, government identity numbers, or credentials to third-party systems, unless we have agreed it in writing for your beta.
4.5 Deletion¶
You can delete chats, files and projects from within the product. Deleting your organization removes its content, including the files stored for it. Records we are required to keep — a minimal audit record of administrative actions, billing records with a retention basis, and the record that these terms were accepted (kept for 10 years, and containing no readable identifier — see section 12.1) — are retained after deletion.
4.6 Feedback¶
If you send us feedback, bug reports or feature suggestions, we may use them to improve the service without obligation or payment to you. Feedback is not your confidential information, but we will not publish your content as part of it.
5. Third-party model providers¶
Content you submit is sent to third-party model providers to be processed. This is inherent to how the service works, not an optional extra.
- Which providers and models are used depends on the configuration of your organization and the model you or your administrator selects.
- Your prompts, the documents and images you attach, tool results, and the surrounding conversation are transmitted to the selected provider so it can generate a response.
- Processing may take place outside Luxembourg and outside the European Economic Area, depending on the provider and model selected — see section 5.1 for exactly which of the providers we use are established outside the EU. Transfers outside the EEA rely on the mechanisms recorded in Annex A, section A.7.
- Providers operate under their own terms and their own security and retention practices. We select providers with commitments we consider appropriate for a business service, and we ask that submitted content not be used for model training — but a provider's own terms govern its processing and we do not control them.
- Search, web-fetch, code-execution and connector features send data to further third parties when you invoke them. The ones we operate are named in Annex A, section A.6.
If you may not lawfully or contractually send a piece of content to a third-party processor, do not put it into the service.
5.1 Where the model providers are established — only Fireworks is outside the EU¶
Of the model providers named in Annex A, section A.6:
- Established in the EU: TensorX Ltd (Ireland; inference in Dublin and Helsinki) and Nebius B.V. (Netherlands).
- Established outside the EU: Fireworks AI (United States) — and, in addition, selected partners of OpenRouter. OpenRouter, Inc. is itself established in the United States and does not run models: it forwards a request to an upstream partner provider, and those partners are in different countries, some inside and some outside the EU. Which partner serves a request depends on the model and on the routing preference configured for your organization.
The default routes outside the EU, and we would rather say so than imply otherwise. A newly created organization is configured with Fireworks AI as its primary model provider, and picture analysis is served through OpenRouter. So unless an administrator of your organization changes the configuration, your prompts, attachments, tool results and conversation context are processed in the United States, under the transfer mechanisms in Annex A, section A.7.
An EU-only alternative is configured and ready, but you have to choose it. Every organization — new and existing — now has TensorX available as a selectable model provider, serving open-weight models on EU-sovereign hardware in Dublin and Helsinki. Selecting a TensorX model under Admin → Model backend keeps that request's processing inside the EU. We have deliberately not made it the default, because changing the model an organization runs on changes the answers it gets, and that is your decision rather than ours. Until an administrator or a user selects one of its models, TensorX processes nothing for you.
5.2 You choose the provider, and the choice is applied per request¶
Provider choice is yours, per organization:
- An administrator of your organization sets the model backend, the default model, the permitted model set and — where the provider supports it — the routing region, under Admin → Model backend in the product.
- That configuration is stored against your organization and is resolved at the moment each request is made, not cached from an earlier session, so a change you make applies to the next request.
- You may supply your own account key for a provider. Your requests are then served under your own contract with that provider, and that provider's terms apply to you directly.
- An organization normally has more than one provider configured — the default configuration installs one provider for text and a second for picture analysis. If establishment or region matters to you, check every entry in the configuration, not only the primary one.
If you need a residency or provider configuration the product does not currently offer, tell us before you put content into the service rather than after.
6. Acceptable use¶
You must not, and must not permit anyone else to:
- break the law, infringe anyone's rights, or help anyone else do either;
- submit content you have no right to submit, or that you are contractually barred from disclosing to a processor;
- generate or distribute malware, phishing material, or content designed to defraud;
- generate sexual content involving minors, content that sexualises real people without consent, or targeted harassment of a person;
- generate content intended to cause serious physical harm, including the design or acquisition of weapons, explosives or biological, chemical, radiological or nuclear agents;
- use the service to make an automated decision about a person's employment, credit, housing, insurance, education, immigration status, or access to essential services, without meaningful human review;
- present model output as human-authored where doing so would deceive someone to their detriment, or produce political disinformation or synthetic media of a real person intended to mislead;
- probe, scan, penetration-test, denial-of-service, or attempt to bypass a security, isolation, rate-limiting or usage-metering control of the service, except with our prior written permission and within an agreed scope;
- attempt to reach data belonging to another customer, or to escape a code-execution sandbox;
- reverse-engineer, decompile, resell, sublicense, white-label or benchmark-publish the service, or use it to build a competing product;
- remove or obscure a notice, watermark or attribution the service produces;
- exceed the usage limits set for your organization, share your credentials outside your organization, or automate sign-ups; or
- use the service in a safety-critical system — including medical devices, vehicle or aircraft control, industrial control, weapons systems, or emergency response.
You are responsible for the lawfulness of the content you submit and of what you do with the output.
We may investigate a suspected breach and may suspend access, remove content, or terminate your participation. Where a breach is serious, ongoing, or unlawful, we may act immediately and without prior notice.
7. Confidentiality of the beta¶
The beta programme is confidential. Unless we agree otherwise in writing, you must not disclose to anyone outside your organization:
- that you are participating in the beta, if we have asked you to keep that confidential;
- unreleased features, screenshots, recordings, prompts, model configurations, pricing or roadmap information you learn through the beta; or
- benchmark, performance or evaluation results about the service.
This obligation lasts for three (3) months from the date you learn the information, or until we make the information public, whichever comes first. It does not apply to information you already lawfully held, that becomes public through no fault of yours, or that you must disclose by law — in which case tell us first if you may lawfully do so.
Each side must protect the other's confidential information with at least the care it uses for its own, and use it only for the beta.
8. Fees¶
The fees are those shown in the Platform. The prices that apply to your organization are displayed in the product under Admin → Billing & usage, which shows the price per model per 1,000,000 tokens in euro, your current balance, and your consumption. Those displayed figures are the price list for the purpose of these terms. This document deliberately does not restate them, so that it cannot fall out of step with them.
- Usage is metered per request and priced against the rates shown for the model that served the request, separately for input and output tokens. Prices are shown in euro.
- A price change applies to usage after the change takes effect. Figures shown in the product for usage already incurred are a statement of consumption, not an invoice.
- Where your beta invitation or order form states a different commercial basis for the beta — a credit grant, an allowance, or free-of-charge access — that document prevails for what it covers (see the order of precedence in section 13).
Invoicing, payment and tax. Fees are exclusive of VAT. Usage draws down a prepaid credit balance, which you top up in the product; where we issue an invoice instead, it is payable within 30 days of the invoice date, in euro.
- If you are established in Luxembourg, we charge Luxembourg VAT at the standard rate.
- If you are a taxable person established in another EU Member State and you give us a valid VAT identification number, the supply is subject to the B2B reverse charge (Article 44 of Directive 2006/112/EC): we charge no Luxembourg VAT, and you account for VAT in your own Member State. Keep the number current — if it is not valid at the time of supply, we must charge Luxembourg VAT.
- If you are established outside the EU, the supply is outside the scope of Luxembourg VAT.
9. Intellectual property¶
We (and our licensors) own the service, its software, models we supply, documentation, trade marks and everything else we make available to you, together with all improvements to them. Nothing here transfers any of that to you.
We grant you a limited, non-exclusive, non-transferable, revocable right to use the service during the beta, for your own internal business purposes, in accordance with these terms.
As between you and us, output generated for you is yours to use, subject to these terms and to the terms of the third-party provider that generated it. We make no claim that output is unique — the service may generate similar or identical output for someone else — and we do not warrant that output does not infringe a third party's rights.
10. Limitation of liability¶
Nothing in this section limits or excludes liability that cannot lawfully be limited or excluded. In particular, the cap and the exclusions below do not apply to:
- death or personal injury caused by negligence;
- fraud or fraudulent misrepresentation;
- wilful misconduct (dol) or gross negligence (faute lourde);
- liability under Article 82 GDPR for damage caused to a person by processing that infringes the GDPR, and any administrative fine imposed on the party that incurred it; or
- any other liability that the applicable law says may not be excluded or limited.
Subject to that:
- Neither side is liable for indirect, special, incidental, consequential or punitive loss, or for loss of profit, revenue, anticipated savings, goodwill, business opportunity, or for loss or corruption of data — however caused, even if the loss was foreseeable.
- Our total aggregate liability arising out of or in connection with these terms and your use of the service is limited to EUR 150,000 (one hundred and fifty thousand euro). That is an aggregate cap for the whole of this agreement — the maximum for all claims taken together, however many there are and whenever they arise. It is not a fresh amount per claim, per incident, or per twelve-month period. The cap is stated as a fixed figure on purpose: both sides can compute it from this document alone, without reference to records that only one of them holds.
- We are not liable for a decision you or anyone else takes on the basis of model output, nor for the acts, omissions, availability or accuracy of a third-party model provider or other third-party service.
- We are not liable for loss caused by your failure to keep your own copy of your content, by credentials you failed to keep confidential, or by content you were not entitled to submit.
Your obligation to pay amounts properly due, and each side's confidentiality obligations, are not limited by this section.
You will indemnify us against third-party claims arising from your content, from your use of the service in breach of section 6, or from your infringement of a third party's rights.
11. Term and termination¶
These terms apply from the moment you accept them until the beta ends or your participation is terminated.
- You may stop using the service at any time, and may delete your organization from within the product.
- We may end your participation, or the beta programme as a whole, on 30 days' written notice — or immediately if you breach section 6 or section 7, if we are required to by law, or if continuing would create a security, safety or legal risk.
On termination: your right to use the service stops immediately. Export anything you want to keep beforehand — after termination we are not obliged to keep, restore or hand back your content, and we may delete it. Sections 4.6, 7, 9, 10, 12 and 13 survive termination, together with any provision that by its nature is intended to.
12. Record of your acceptance¶
We record, and retain, the fact that these terms were accepted: the time of acceptance, the version identifier of this document, a fingerprint of this document's text, and a one-way cryptographic hash of the email address that accepted it.
- The record is stored outside your organization's data and is deliberately retained when your organization is deleted. It is the evidence that a specific person accepted a specific version of these terms at a specific time, and it would be worthless if it disappeared with the thing it evidences.
- The record contains no readable email address, name or other contact detail — only the one-way hash. It cannot be reversed, and it cannot be used to contact anyone or to re-identify a person from the record alone. It can only be checked against an email address that someone already presents.
12.1 How long we keep it — 10 years¶
RETENTION PERIOD — 10 YEARS. We keep the acceptance record for ten (10) years, counted from the close of the financial year in which the acceptance was given.
That period is not a preference of ours. An acceptance of these terms is a commercial record, and Luxembourg commercial law — Article 16 of the Code de commerce — requires a merchant to keep its commercial and accounting records for ten years from the close of the financial year to which they relate. We apply that single period rather than a shorter one, so there is no ambiguity about which rule governs.
What is kept for those ten years is not your email address. It is a one-way hash of the address, computed under a random value unique to that one record, together with the time of acceptance, the version identifier of this document and a fingerprint of its text. There is no plaintext email address, no name, and no user or organization identifier in the record. It cannot be reversed and cannot be used to contact anyone; it can only be checked against an address that someone already presents.
The ten years run from acceptance whatever happens to your organization afterwards: deleting your organization does not shorten the period, because the record deliberately sits outside your organization's data (see the first bullet above). The two rules are consistent — the record survives the organization, and it survives for ten years, not indefinitely.
Deletion at the end of the ten years is an administrative step we take; it is not automated. The service does not currently run a scheduled job that erases these records when the period expires, and we would rather say so than let this clause imply a mechanism that does not exist.
If you ask us to erase your personal data, this record is not an obstacle: there is no personal data in it to erase, and the hash is retained on the basis of our legitimate interest in being able to evidence a contract we entered into, and of the legal obligation described above.
13. General¶
Changes to these terms. We may issue a new version. The version identifier at the top of this document changes when we do. Material changes are notified to the organization's owner before they take effect; continuing to use the service after that date means the new version applies. Your recorded acceptance always names the version you actually accepted. Because the sub-processor list lives in Annex A, adding or replacing a sub-processor is a change to this document and follows this paragraph and Annex A, section A.8.
Notices. We may contact you at the email address registered for your organization's owner. You can reach us in writing at X-CITE S.A., 31, Domaine de Beauregard, L-8357 Goeblange, Grand Duchy of Luxembourg, or by email at legal@x-cite.io. That mailbox exists for legal notices and is monitored for them, which is why notice must be sent there: a general enquiries or support alias is not monitored for legal purposes, so a notice sent to one is not served on us.
Assignment. You may not assign these terms without our written consent. We may assign them to an affiliate or in connection with a reorganisation, merger or sale of the business.
Subcontracting. We may use subcontractors and sub-processors to provide the service; we remain responsible for their performance under these terms.
Force majeure. Neither side is liable for a delay or failure caused by an event outside its reasonable control, provided it tells the other side and works to limit the effect.
Export and sanctions. You confirm that you, your organization, and your users are not subject to sanctions that would prohibit the supply of the service, and that you will not make the service available in breach of export-control or sanctions law.
No partnership. Nothing here creates a partnership, joint venture, agency or employment relationship between us.
Entire agreement. These terms, together with any written order form or beta invitation and the data-processing terms in Annex A, are the whole agreement about the service, and supersede earlier statements about it. Nothing in this paragraph limits liability for fraud.
Severability and waiver. If a provision is unenforceable, the rest stays in force. A failure to enforce a right is not a waiver of it.
Order of precedence. If a signed order form conflicts with these terms, the order form prevails for the subject it covers.
Governing law and jurisdiction. These terms, and any dispute or claim arising out of or in connection with them or their subject matter, are governed by the laws of the Grand Duchy of Luxembourg, without regard to its conflict-of-laws rules. The courts of Luxembourg have exclusive jurisdiction — venue the courts of the city of Luxembourg. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Annex A — Data Processing Agreement¶
Sources. The entity details and transfer mechanisms in section A.6 are taken from each counterparty's own published terms and data-processing documents, and from the company register of its jurisdiction. The source for each entry is given in the table.
A.1 What this Annex is¶
This Annex is the data-processing agreement required by Article 28(3) GDPR for the processing we carry out on your behalf. It forms part of these terms (section 4.4). Where this Annex conflicts with the rest of these terms on a data-protection question, this Annex prevails.
Governing law and forum. This Annex, and any dispute or claim arising out of or in connection with it, are governed by the laws of the Grand Duchy of Luxembourg, and the courts of Luxembourg have exclusive jurisdiction (section 13).
A.2 Roles¶
- You are the controller. You decide what personal data enters the service, whose it is, and why.
- We are the processor. We process it only to provide the service to you, and only on your instructions. These terms, the Annex, and your use of the product's features are your instructions.
- The sub-processors in section A.6 are our sub-processors, engaged under Article 28(2) and (4) GDPR. You give your general authorisation to our use of them; section A.8 says how a change is notified and how you may object.
- Where we process personal data about your users for our own purposes — account security, abuse prevention, metering and invoicing, and the acceptance record in section 12 — we act as controller for that limited processing, not as your processor.
A.3 Subject matter, duration, nature and purpose¶
| Subject matter | Provision of the closed-beta service described in these terms |
| Duration | For as long as your organization exists, plus the retention periods stated in sections 4.5 and 12.1 |
| Nature and purpose | Storage, indexing, retrieval, transmission to model providers, generation of output, metering, security and support |
| Types of personal data | Whatever your users submit — prompt and chat content, uploaded files and pictures, connected source documents, and the output generated from them; plus account data (name, email, role) and usage records |
| Categories of data subject | Your users, and any person appearing in the content you submit |
| Special categories | Not permitted — see section 4.4 of these terms |
A.4 Our obligations¶
We will: process personal data only on your documented instructions; ensure that personnel with access are bound by confidentiality and have access only where they need it; implement appropriate technical and organisational measures under Article 32 GDPR — including per-organization logical separation enforced in the database, role-based access control, encryption in transit, encryption at rest for provider credentials, and audit logging of administrative actions; assist you with data-subject requests, data-protection impact assessments and regulator enquiries, so far as we reasonably can; and notify you without undue delay after becoming aware of a personal-data breach affecting your content, with the information you need for your own Article 33 notification.
A.5 Deletion and return¶
You can delete content from within the product at any time. On the deletion of your organization we run one audited operation that removes the organization's database rows and purges the files stored for it in object storage. The exceptions are the records named in section 4.5, and they are the only ones.
A.6 Sub-processors¶
A.6.1 Model providers. These process the content you submit for the purpose of generating a response. Section 5.1 states which of them are established outside the EU.
| Sub-processor (legal entity) | Established in | What it processes for us | Transfer mechanism | Source |
|---|---|---|---|---|
| Fireworks.ai, Inc. (trading as Fireworks AI), 2317 Broadway, Suite 150, Redwood City, California, United States | United States — outside the EU | The default text model provider. Prompts, attached files and pictures, tool results and the surrounding conversation, for text generation | EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two — controller-to-processor) under the Fireworks data-processing addendum. EEA/UK representative appointed (GDPR Local) | https://fireworks.ai/privacy-policy · https://fireworks.ai/dpa · https://docs.fireworks.ai/guides/security_compliance/data_security |
| OpenRouter, Inc., 169 Madison Avenue, New York, NY 10016, United States | United States — outside the EU | Model routing. Prompts, attachments, tool results and conversation context pass through it and are forwarded to an upstream partner provider. Used by default for picture analysis | Article 28 data-processing agreement in place, incorporating the EU Standard Contractual Clauses (Decision (EU) 2021/914, Module Two). OpenRouter publishes its own authorised sub-processor list, linked opposite | https://openrouter.ai/terms · https://openrouter.ai/privacy · https://openrouter.ai/authorized-sub-processors |
| Nebius B.V., Schiphol Boulevard 165, 1118 BG Schiphol, Netherlands (KvK 51515539) | Netherlands — EU | Inference on EU infrastructure. Reached as an upstream partner of OpenRouter, not as a provider your organization can select directly | None required for Nebius itself (EU). The OpenRouter routing hop is in the United States and relies on the row above | https://docs.nebius.com/legal/digital-rights/gdpr-compliance-faqs |
| TensorX Ltd, Unit 25, Classon House, Dundrum Business Park, Dublin 14, Ireland (company no. 796387) | Ireland — EU | EU-sovereign inference on dedicated hardware in Dublin and Helsinki. Offered as a selectable model provider and configured for every organization: prompts, attached files, tool results and the surrounding conversation, for text generation, whenever one of its models is selected. It is not the default — an organization that never selects a TensorX model sends it nothing | None required (EU/EEA) | https://tensorx.ai/privacy-policy/ · Irish CRO company no. 796387 |
A.6.2 Infrastructure.
| Sub-processor (legal entity) | Established in | What it processes for us | Transfer mechanism | Source |
|---|---|---|---|---|
| Google Cloud EMEA Limited, Velasco, Clanwilliam Place, Dublin 2, Ireland (CRO 660412, VAT IE3668997OH) | Ireland — EU, with the service hosted in the europe-west3 (Frankfurt) region | Hosting of the service; object storage of the files you upload and the artefacts generated for you; operational telemetry | None required for the contracting entity or the hosting region (both EU). Google may itself use sub-processors outside the EEA under its own data-processing addendum and the SCCs incorporated in it | https://cloud.google.com/terms/google-entity · https://cloud.google.com/terms/data-processing-addendum · https://cloud.google.com/security/compliance/eu-scc |
A.6.3 Other sub-processors. The model and infrastructure providers above are not the whole list. The following also process personal data for us, and a sub-processor list that omitted them would be misleading.
| Sub-processor / service | Established in | What it processes for us | Transfer mechanism |
|---|---|---|---|
| Resend, Inc. — transactional email | United States | The recipient's email address and the content of service emails: sign-up, notifications, review requests | EU Standard Contractual Clauses (Decision (EU) 2021/914, Module Two) |
| Google Ireland Limited — reCAPTCHA bot defence on self-service sign-up, where enabled | Ireland — EU | The visitor's IP address and interaction signals at sign-up | None required for the contracting entity (EU); Google's onward transfers ride its own terms |
Perplexity AI, Inc. — live web search behind the web_search tool, only when a user invokes it |
United States | The search query derived from the user's request | EU Standard Contractual Clauses (Decision (EU) 2021/914, Module Two) |
| Connector and tool providers you enable — e.g. Google Drive, Microsoft 365, and the connectors you switch on for your organization | Varies by provider | The documents and metadata you authorise us to read, and the OAuth identity used to read them | Engaged only on your instruction, under your own account with that provider, whose terms apply to you directly |
| Payments | — | Billing contact and transaction data, where the beta is paid | No live payment provider is engaged for the closed beta. If one is engaged, it becomes a sub-processor and section A.8 applies |
A.7 Transfers outside the EEA¶
Where a sub-processor in section A.6 is established outside the EEA, or routes to a provider that is, the transfer relies on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two — controller-to-processor), incorporated by the counterparty's own data-processing agreement, together with the technical measures in section A.4. We do not rely on an adequacy decision for any of them.
You can reduce this to nothing. If your organization is configured to use only the EU-established providers in section A.6.1 for every model it permits, no model content is transferred outside the EEA (section 5.2). The default configuration does not do this — see section 5.1.
A.8 Changing the sub-processor list¶
Because the list is inside this document, we cannot add or replace a sub-processor without issuing a new document version. We will notify the organization's owner before the change takes effect, and you may object on reasonable data-protection grounds; if we cannot accommodate the objection, you may stop using the service and delete your organization, and neither side owes the other anything further for that.
A.9 Audit¶
On reasonable written request, and no more than once a year unless a regulator or an incident requires otherwise, we will provide the information you reasonably need to satisfy yourself that we comply with this Annex.
End of document — version beta-2026-08-12.