General Terms of Sale and Use (B2B)
KAIUS — SaaS application for law firm management, including artificial intelligence features
Publisher: Okipio Management SPRL, BCE/VAT 0878.030.538, Belgium. Recipients: professionals only (B2B).
Article 1 — Purpose and acceptance
1.1. These General Terms of Sale and Use (the "Terms") govern access to the KAIUS Service and its use by professional clients.
1.2. By creating an account and using the Service, the Client declares that it is acting for professional purposes and accepts these Terms without reservation, including Annex 1 — Data Processing Agreement (DPA) and the Cookies Policy.
1.3. The Service is not intended for consumers. Consumer protection rules do not apply.
Article 2 — Definitions
For the purposes of these Terms:
2.1. "Client" means any legal entity or professional natural-person business that subscribes to the Service.
2.2. "User" means any natural person authorised by the Client to use the Service.
2.3. "Client Data" means all data, documents, files and content imported, entered or generated by the Client and/or its Users in the Service, including prompts and outputs of AI features.
2.4. "Sub-processors" means the technical providers used by the Publisher to deliver the Service (hosting, AI, payments, emails, etc.).
Article 3 — Entry into force, changes to the Terms and the Service
3.1. The Terms enter into force on the subscription date.
3.2. The Publisher may evolve the Service (improvements, additions or removal of non-essential features) to ensure its quality, security and compliance.
3.3. In the event of a material change to the Terms or prices, the Client is informed at least 30 days before the effective date. Failing termination before the effective date, the changes apply at the next renewal. No refund is due for the current period.
Article 4 — Account creation and security
4.1. The Client warrants the accuracy of the information provided upon registration and its update.
4.2. Login credentials are personal and confidential. Any operation performed using these credentials is deemed to be performed by the Client, who takes reasonable measures to preserve their confidentiality.
Article 5 — Intellectual property and licence
5.1. The Service, its code, interfaces, documentation and trademarks are the exclusive property of the Publisher and are protected by applicable intellectual property rights.
5.2. The Client is granted a non-exclusive, non-transferable right to use the Service, for the duration of its subscription and for its internal professional needs.
5.3. Client Data remains the property of the Client. The Publisher acquires no rights over Client Data, other than those strictly necessary to provide, support and secure the Service.
5.4. The Publisher may produce and use aggregated, anonymised or de-identified information derived from the use of the Service, for statistical, security and improvement purposes, without disclosing any confidential information of the Client.
5.5. Subject to third-party rights and content provided by the Client, the Client holds professional usage rights over the content generated by the AI via the Service.
Article 6 — Artificial intelligence features
6.1. Transparency. The Service indicates in its interfaces when a feature uses AI and states its limits and precautions of use.
6.2. Human oversight. AI features are assistance tools. They do not replace professional judgement. The Client retains effective human oversight and reviews the results before any use, particularly in a professional or judicial context.
6.3. Prohibited uses. The Client shall not use the AI to: (i) generate or distribute unlawful content or content infringing third-party rights; (ii) profile, evaluate or classify natural persons based on sensitive criteria; (iii) attempt to circumvent security measures, mass-extract data or retrain models on data for which it does not hold sufficient rights; (iv) make high-stakes decisions without appropriate oversight.
6.4. Input and output data. Prompts, contexts and outputs of AI features may be processed and retained by the Publisher solely for the purposes of providing, supporting, securing, improving and complying with the Service, in accordance with Annex 1.
6.5. No guarantee of results. AI outputs may contain errors. The Client remains fully responsible for their verification and use.
Article 7 — Subscriptions, prices and invoicing
7.1. Plans. The subscription is monthly or annual, prepaid, with tacit renewal at each term.
7.2. Prices. Prices in force are communicated at the time of subscription. Prices are exclusive of taxes and will be increased by applicable taxes. An annual plan may benefit from a preferential rate.
7.3. Payment. Payment is made by bank card via a secure provider. In the event of failure, additional attempts may be made. Failing payment, the Publisher may suspend access to the Service.
7.4. Late payment. Any unpaid amount produces, as of right, late-payment interest and reasonable collection costs. Access to the Service may be suspended until full payment.
7.5. Price changes. Any price change is notified at least 30 days before its entry into force and will apply at the next renewal. If the Client does not consent, it may terminate before the effective date. No refund is due for the current period.
Article 8 — Free trial
8.1. The Client may benefit from a 14-day free trial from account creation. At its end, access is suspended in the absence of a subscription.
8.2. In the absence of a subscription, Client Data is retained for 30 days from the end of the trial, then irreversibly deleted.
Article 9 — Availability, maintenance and support
9.1. The Publisher endeavours to ensure a target annual availability of 99.5%, excluding scheduled maintenance and excluded cases (in particular force majeure, third-party failures, public networks, use contrary to the Terms).
9.2. The Publisher may carry out maintenance operations. Where reasonably possible, prior information is provided via the interface or by email.
9.3. Standard support is provided on business days through the channels indicated in the Service. Services outside the standard scope may be invoiced.
Article 10 — Client Data and confidentiality
10.1. The Client is solely responsible for the lawfulness of the Client Data it imports, enters or generates.
10.2. The Publisher processes Client Data confidentially and grants access only to duly authorised persons bound by a confidentiality obligation, strictly to the extent necessary to provide, support and secure the Service.
10.3. The Publisher acknowledges that some Client Data may be covered by professional secrecy and implements appropriate organisational and technical measures to preserve its confidentiality.
10.4. The Publisher may use Sub-processors in accordance with Annex 1.
Article 11 — Personal data protection
11.1. To the extent that the Publisher processes personal data on behalf of the Client, it acts as a processor and the Client as a controller.
11.2. The terms of processing are set out in Annex 1 — Data Processing Agreement, which forms an integral part of these Terms.
11.3. Hosting takes place within the European Economic Area. Any transfer outside the EEA is framed by mechanisms compliant with applicable regulations, as detailed in Annex 1.
Article 12 — Cookies
12.1. Strictly necessary cookies (session). The Service uses technical cookies essential to its operation (authentication, session persistence, security). They do not require consent.
12.2. Analytical cookies (optional). Subject to the User's prior consent, analytical cookies are used to measure audience and improve the ergonomics of the Service. In the absence of consent, or upon withdrawal, these cookies are not set.
12.3. Consent management. The cookie banner allows analytical cookies to be accepted or refused and these choices to be changed at any time via the "Cookie Preferences" section.
12.4. Details. The Cookies Policy describes, for each cookie, its purpose, duration and, where applicable, the identity of third-party setters. No advertising cookies are used.
Article 13 — Warranties and exclusions
13.1. The Service is provided "as is" and "as available". The Publisher grants no warranty of fitness for a particular purpose or of a total absence of minor errors.
13.2. The Client remains responsible for the configuration of its systems, the security of its workstations, the quality of Client Data and the use it makes of the Service and AI outputs.
Article 14 — Limitation of liability
14.1. Within the limits allowed by applicable law, the Publisher's liability is limited to direct, proven and foreseeable damages suffered by the Client, to the exclusion of any indirect, consequential or immaterial damage (including loss of turnover, clientele, profit, opportunity, anticipated savings, as well as any loss, alteration or corruption of data).
14.2. The Publisher's aggregate liability, for all causes and all damages combined, is capped at the total amounts actually paid by the Client for the Service during the twelve (12) months preceding the triggering event.
14.3. No provision of these Terms is intended to exclude liability that cannot legally be excluded.
Article 15 — Force majeure
15.1. Neither party may be held liable for a breach due to an unforeseeable, irresistible and external event beyond its reasonable control.
15.2. The affected party informs the other party and makes reasonable efforts to mitigate the effects and resume performance. If the situation persists for more than sixty (60) days, either party may terminate the contract without indemnity.
Article 16 — Term, termination and fate of Data
16.1. The contract takes effect upon subscription, for the term of the chosen plan, and is tacitly renewed at each term.
16.2. The Client may terminate at any time from its client area. Termination takes effect at the end of the current period. No refund is due for the current period.
16.3. In the event of a serious breach not remedied within fifteen (15) days of a written notice, the other party may terminate as of right.
16.4. The Publisher may suspend access in the event of non-payment, a proven security risk or a clear violation of the Terms, upon notice where reasonably possible.
16.5. Upon termination of the contract, access to the Service is suspended. Client Data is retained for thirty (30) days, during which the Client may reactivate its subscription or export its Data via the features provided. Upon expiry of that period, the Data is irreversibly deleted.
Article 17 — Assignment and sub-contracting
17.1. The Client may not assign the contract without the prior written consent of the Publisher.
17.2. The Publisher may freely sub-contract all or part of the performance of the Service, under its responsibility, in accordance with Annex 1.
Article 18 — Applicable law and jurisdiction
18.1. These Terms are governed by Belgian law.
18.2. Any dispute shall be submitted to the competent courts of the judicial district of Walloon Brabant.
Article 19 — General provisions
19.1. Entirety. These Terms, their Annex 1 and the Cookies Policy constitute the entirety of the agreement between the parties and replace any prior agreement relating to the same subject matter.
19.2. Partial invalidity. If a provision is declared invalid, the others remain applicable. The invalid provision is replaced by a valid provision pursuing an equivalent economic objective.
19.3. Tolerance. The fact that a party does not rely on a provision does not amount to a waiver of the right to rely on it later.
19.4. Notices. Notices are made via the Service interface or to the email address designated by each party.
19.5. Language. The French version prevails in the event of divergence.
Annex 1 — Data Processing Agreement (DPA)
In accordance with Article 28 of Regulation (EU) 2016/679 — GDPR
Between:
Okipio Management SPRL, BCE/VAT 0878.030.538, with its registered office in Belgium (hereinafter "the Processor"),
And:
The professional client having accepted the KAIUS Terms of Service (hereinafter "the Controller" or "the Client").
This Annex forms an integral part of the KAIUS Terms of Service and applies whenever the Processor processes personal data on behalf of the Client.
1. Purpose, scope and duration
1.1. This agreement governs the processing of personal data carried out by the Processor on behalf of the Client in connection with the provision, maintenance, support and security of the KAIUS Service, including its AI assistance features.
1.2. The duration of processing corresponds to the term of the Terms of Service, extended by the period strictly necessary for the return and deletion operations set out in this Annex.
2. Description of processing
2.1. Purposes of processing:
- Provision and operation of the Service (hosting, storage, indexing and search, AI assistance, report generation).
- Access and permissions management, support and maintenance, Service security and integrity, business continuity and backups, technical metrics and logging required for proper operation.
2.2. Nature of operations: collection through use, recording, organisation, storage, adaptation, consultation, use, transmission on instruction, restriction, erasure and destruction.
2.3. Types of data processed (depending on Client use):
- Professional identification and contact data (e.g. surname, first name, role, contact details).
- Content and documents related to cases, correspondence, exhibits and notes.
- Billing and payment data on a "tokenised" basis (card data is handled by the payment provider).
- Technical logs, device/session identifiers, prompts and outputs of AI features.
2.4. Categories of data subjects: the Client's authorised users, the Client's professional clients and correspondents, parties and third parties appearing in the cases.
2.5. Location of processing: primary hosting takes place within the European Economic Area. Certain limited and necessary processing operations may involve sub-processors (cf. article 6).
3. Roles, instructions and Client responsibilities
3.1. The Client is the Controller. It determines the purposes and means of the processing carried out through the Service, provides documented and lawful instructions, and remains responsible for their legality.
3.2. The Client:
- Configures permissions and manages User access.
- Ensures the lawfulness of data imported or generated and the information of data subjects.
- Avoids introducing unnecessary sensitive data into the Service and applies appropriate retention periods.
3.3. Instructions must be compatible with the standard features of the Service. Any instruction outside the standard scope, technically unreasonable or unlawful may be refused by the Processor.
4. General obligations of the Processor
4.1. The Processor processes data only on documented instructions from the Client and solely for the purposes of providing, maintaining, securing and supporting the Service.
4.2. The Processor's authorised personnel are bound by an enforceable confidentiality obligation and receive appropriate data protection awareness.
4.3. The Processor keeps proportionate internal documentation evidencing the proper performance of the obligations set out in this Annex.
4.4. The Processor claims no rights over the Client's data, beyond what is strictly necessary to operate and secure the Service.
5. Security — technical and organisational measures (TOMs)
5.1. The Processor implements technical and organisational measures proportionate to the risks, including in particular:
- Encryption of data in transit and at rest according to the state of the art.
- Role-based access controls, strong authentication for operational staff, and the need-to-know principle.
- Proportionate security logging; technical monitoring and vulnerability management.
- Environment segmentation, configuration hardening, periodic access reviews.
- Regular backups, restore testing and business continuity plan.
5.2. Detailed measures are set out in the "Register of technical and organisational measures" at the end of this Annex and may evolve to maintain an at least equivalent level of protection.
6. Sub-processors
6.1. The Client grants a general authorisation to use sub-processors necessary for the provision of the Service (for example: cloud hosting and infrastructure, transactional email, payment services, AI providers).
6.2. The Processor contractually imposes on any sub-processor confidentiality and security obligations at least equivalent to those of this agreement.
6.3. The Processor maintains and updates a register of the categories of sub-processors. The Client will be informed of any material addition or replacement of a sub-processor category within a reasonable period.
6.4. If the Client raises a reasoned and reasonable objection to a sub-processor, the parties shall seek in good faith a technical or organisational solution. Failing a reasonable solution within an appropriate period, the Processor may, at its option: (i) propose an alternative, or (ii) allow termination, without penalty, of the affected part of the Service only, without refund of periods already commenced.
7. Artificial intelligence features
7.1. Prompts, contexts and outputs of AI features may contain personal data provided by the Client. The Client ensures the lawfulness of such data and avoids including unnecessary sensitive information.
7.2. The Processor may rely on AI providers as sub-processors. These providers are not authorised to use Client Data to train general models made available to the public or to other clients, unless the Client gives express prior authorisation.
7.3. AI-generated content is provided as assistance. The Client retains effective human oversight and reviews the results before use.
8. Data subject requests and assistance
8.1. The Processor does not act on requests addressed directly to it by data subjects and redirects them to the Client, unless otherwise instructed by the Client.
8.2. The Processor provides reasonable assistance to the Client in responding to data subject rights requests, within a period proportionate to the complexity of the request. Any intervention beyond standard support may be invoiced to the Client at the prevailing rates.
9. Impact assessments, authorities and compliance
9.1. At the Client's request, the Processor provides information reasonably necessary to carry out data protection impact assessments (DPIA) and prior consultations, insofar as such information relates to the Service and is available. This assistance may be invoiced.
9.2. In the event of a request or investigation by a data protection authority relating to processing carried out on behalf of the Client, the Processor cooperates reasonably. Costs and time spent beyond standard support are chargeable.
10. Security incidents and data breaches
10.1. The Processor notifies the Client, without undue delay after becoming aware, of any security incident with a confirmed impact on personal data processed on behalf of the Client. The notification includes the information available at that stage on the nature of the incident, the categories of data concerned, the likely consequences and the initial measures taken or proposed.
10.2. The Processor will provide reasonable updates as the technical investigation progresses and will cooperate to enable the Client to satisfy its own notification obligations, if any.
11. International data transfers
11.1. Primary hosting takes place within the European Economic Area. Where a sub-processor's involvement entails processing from a third country, the Processor puts in place an appropriate transfer mechanism and reasonable supplementary measures where necessary.
11.2. At the Client's request, the Processor may provide available information on the mechanisms put in place with its sub-processors. Any exceptional due diligence may be invoiced.
12. Return and deletion of data
12.1. Upon termination of the Service, the Client's access is disabled. For thirty (30) days, the Client may reactivate its subscription or export its data via the features provided.
12.2. After that period, the Processor proceeds with the deletion of the Client's data in its active and backup environments at the end of their retention cycle. On request, a deletion certificate may be issued. Any specific export or migration assistance beyond standard features may be invoiced.
13. Audits and attestations
13.1. The Processor may, at its discretion, make available to the Client information, independent security reports or attestations where these exist (for example, summaries of audits performed by third parties). The provision of such items may be sufficient to satisfy the audit obligation.
13.2. The Client may request a targeted audit relating exclusively to processing carried out on its behalf, subject to the following cumulative conditions:
- Written notice of at least thirty (30) working days, specifying the intended subject matter, scope and methodology.
- A maximum frequency of one (1) audit per twelve (12) month period, save for a justified major security incident concerning the Client's data.
- An audit that is primarily document-based and remote; any on-site visit is subject to the Processor's prior consent and is strictly framed.
- Performance by an independent, reputable third party bound by strict confidentiality.
- Compliance with security requirements, confidentiality of other clients, protection of source code and trade secrets; no access is granted to shared environments beyond what is strictly necessary.
13.3. All costs, fees and disbursements related to the audit (including time spent by the Processor's staff) are borne by the Client. If the audit reveals a serious breach directly attributable to the Processor, the parties agree to discuss in good faith remedial measures and, where applicable, reasonable compensation for audit costs directly related to verifying remediation.
14. Liability and contractual hierarchy
14.1. The applicable liability regime, exclusions and caps are those set out in the Terms of Service. In the event of a conflict between the Terms of Service and this Annex, the Terms of Service prevail, unless this Annex expressly provides otherwise on a specific data protection point.
14.2. No provision of this Annex may be construed as extending the Processor's liability beyond what is provided for in the Terms of Service.
15. Amendments, notices and language
15.1. This Annex may be updated in accordance with the amendment terms set out in the Terms of Service. Updated versions replace and supersede any previous version.
15.2. Notices under this Annex follow the notice arrangements set out in the Terms of Service.
15.3. The French version of this Annex prevails in the event of divergence.
Register of technical and organisational measures (TOMs)
Without prejudice to technical evolutions, the Processor implements the following measures, proportionate to the risks, to preserve the confidentiality, integrity and availability of data processed on behalf of the Client:
1. Governance and access control
- Role-based access control policy, periodic permission reviews and the need-to-know principle.
- Strong authentication for operational staff; management of segregation of sensitive duties.
- Logging of access to production environments and retention of logs for a proportionate period.
2. Communications and data protection
- Encryption of network communications using recognised protocols.
- Encryption at rest of data volumes; secure key management.
- System hardening, network segmentation and logical separation between environments (development, test, production).
3. Development, testing and deployments
- Secure development practices, version control, code reviews on sensitive components where relevant.
- Controlled deployment pipelines, prior validation and restriction of deployment access.
4. Vulnerability and patch management
- Security watch, patch management within reasonable timeframes based on criticality.
- Suitable periodic security testing (automated scans; use of independent assessments where relevant).
5. Continuity and backups
- Regular backups of Client data, encrypted storage and restore tests at reasonable intervals.
- Continuity plan and recovery procedures appropriate to the nature of the Service.
6. Operational security and monitoring
- Proportionate technical monitoring, alerts for significant security events.
- Internal escalation and incident response procedures.
7. Contractual confidentiality and training
- Contractual confidentiality commitments of persons authorised to process the data.
- Periodic awareness and reminders on data protection and security.
8. Sub-processors and AI
- Due diligence on the selection of sub-processors, contractual confidentiality and security clauses.
- Specific framing of AI providers to prohibit the use of Client data for the training of general models made available to the public, unless the Client expressly agrees.
9. Deletion and return
- Procedures for deleting Client data at the end of the applicable periods, including in backups at the end of their cycle.
- At the Client's request, issuance of a deletion attestation once operations are complete.
10. Limits and continuous improvement
- Measures may be adjusted to reflect changes in risks and the state of the art, provided the overall level of protection remains at least equivalent.
- The Processor documents significant changes affecting the security of the Service.
Points of contact
- Privacy and data protection contact: via the Service interface or the contact address indicated in the Client account.
- Security/incident contact: via the designated support channel.