CORPILUS

Terms of Service

Last updated: September 11, 2026

1. General provisions

These Terms of Service (the “Terms”) govern the provision and use of the Corpilus service (the “Service”), described on corpilus.com and available through related applications, extensions and interfaces.

The Service is provided by CREBISO | corp.systems s.r.o., a company registered in the Slovak Republic (the “Provider”). Full company details (company ID, VAT ID, registered office) are available on request at info@crebiso.com.

We provide the Service to companies and organisations (the “Customer”) on the basis of an individual price quote and a contract. Where the contract and these Terms differ, the contract prevails.

Anyone acting on behalf of the Customer confirms that they are authorised to do so. By entering into the contract or using the Service, the Customer accepts these Terms.

2. Description of the Service

Corpilus protects company data when people work with artificial intelligence, and protects websites, applications and AI agents. The offer consists of these packages:

  • Privacy — protects what employees type into AI: browser extension, MCP and API, custom data patterns and a kill switch that stops outgoing data.
  • Shield — protects websites, applications and AI agents: widget and SDK / middleware (Python, Node.js, PHP), proxy in front of the model, event overview and export.
  • Studio — Complete — an assistant over the company’s documents: knowledge base with citations, choice of model provider including local models, questions against the database. Privacy is included.
  • Dedicated server / NVIDIA DGX Spark — the whole platform on a dedicated server or directly on the Customer’s premises.

We deliver the Service as a managed installation: we prepare the deployment together with the Customer. Depending on the contract, it runs in an EU cloud, on a dedicated server, on an NVIDIA DGX Spark server on the Customer’s premises, or with local models.

The specific scope (packages, number of people, domains, document volume and type of deployment) is set by the price quote and the contract. Qronos is not part of the offer: it is in development and described on the website only as a direction.

We develop the Service continuously and may add or change features. If a change would materially reduce the agreed scope, we will announce it in advance and proceed according to the contract.

3. Contract, price quote and prices

  • The price of the Service is set by an individual price quote and the contract, based on the agreed scope. We do not publish a price list.
  • A request for a price quote sent through the website does not commit the Customer to anything and does not grant access to the Service.
  • We do not offer free access for testing. A demonstration or a pilot deployment can be agreed individually.
  • On top of the agreed price, cloud storage and AI tokens are charged according to actual use, where the Customer uses models through the Provider. If the Customer uses its own model key, the Provider does not charge for tokens.
  • The currency and billing method are set by the price quote and the contract. VAT is charged according to applicable law.
  • The price may change during the term of the contract only in the way the contract sets out.

4. Payment terms and late payment

  • Invoices are issued and delivered electronically. The due date is stated on the invoice unless the contract says otherwise.
  • If a payment is late, the Provider may charge late-payment interest according to applicable law and claim reasonable costs of recovery.
  • If the Customer does not pay an invoice that is due, the Provider may, after prior written notice and the expiry of a reasonable period, suspend the Service until payment is made.
  • Suspension on its own does not mean the Customer’s data is deleted. Termination and deletion of data are covered by section 12.

5. Access and accounts

  • The Customer decides which of its people have access to the Service and with which permissions. Each user should have their own access; sharing login credentials is not permitted.
  • The Customer keeps login credentials and API keys secure and notifies the Provider without undue delay of any suspected misuse.
  • The Customer is responsible for activity under its accounts and for using the Service lawfully.
  • The Provider may temporarily restrict access that threatens the security of the Service or of other customers, and informs the Customer without undue delay.
  • The Corpilus Privacy browser extension has its own privacy policy, published at corpilus.com/privacy-extension.

6. Customer content and data

  • Data, documents and other content that the Customer puts into the Service or processes through it belong to the Customer.
  • The Provider uses this data only to provide the Service. It does not sell it and does not give it to third parties for their own purposes.
  • The Provider does not use Customer data to train AI models. The learning feature in Studio works with examples stored in the Customer’s environment and does not change model weights.
  • The Provider accesses Customer data only to the extent necessary: for support and troubleshooting, on the Customer’s instruction, or where the law requires it.
  • Data in environments operated by the Provider is backed up regularly. The scope and retention of backups are set by the contract.
  • In a deployment on the Customer’s own server, the data stays on the Customer’s infrastructure. The Provider accesses it only as agreed for installation and support.
  • The Customer is responsible for having the right to process the content it puts into the Service and for that content not infringing the rights of third parties.

7. Personal data protection

  • The Provider processes personal data in line with Regulation (EU) 2016/679 (GDPR), Slovak Act No. 18/2018 Coll. and related regulations.
  • For personal data the Customer processes in the Service, the Customer is the controller and the Provider is the processor.
  • Processing for which the Provider is the controller (the website, price quote requests, the contact form) is described in the Privacy Policy. Data the website stores in the browser is described in the Cookie Policy.
  • The Service operated by the Provider is hosted on infrastructure in the EU. Where data goes outside the European Economic Area, for example to a cloud model provider under section 8, GDPR safeguards apply.

8. Artificial intelligence: outputs and models

  • Answers, summaries and other AI-generated outputs may be incomplete or inaccurate. The Customer verifies them before use and is responsible for decisions made on their basis.
  • Source citations in Studio make verification easier but do not replace it.
  • The Customer chooses the model in the settings. If it enables a cloud model, part of the data (for example the question and related passages from documents) is sent to the chosen model provider, such as OpenAI, Anthropic or Google. Before sending, recognised sensitive data is replaced with placeholders according to the Customer’s settings. Processing by the model provider is also subject to that provider’s terms.
  • With local models, no data is sent to a model provider.
  • Recognition of sensitive data relies on patterns and checks and may not catch every item. The Customer is responsible for configuring the rules and for their fit with its internal policies.
  • Shield evaluates requests and creates rules from traffic. It does not guarantee that every attack is caught and does not replace the Customer’s other security measures.

9. Availability and support

  • The Provider aims for reliable operation of the Service, monitors it and backs up data regularly in environments it operates.
  • The level of availability, response times and the form of support are set by the contract. Where the contract does not set them, we provide support by email at info@crebiso.com on working days, without a committed response time.
  • Planned maintenance that limits the Service is announced in advance.
  • In a deployment on the Customer’s premises, the Customer is responsible for the hardware, network, power and physical security of the server, unless the contract says otherwise.
  • The Provider is not liable for outages caused by force majeure, by outages of third-party services (including AI model providers) or by the Customer’s infrastructure.

10. Intellectual property

  • Rights to the Service (the Corpilus name and brand, software, design and documentation) belong to the Provider or its licensors.
  • For the term of the contract, the Customer receives a non-exclusive, non-transferable right to use the Service for its own purposes within the agreed scope.
  • The Customer may not copy, modify, reverse engineer or decompile the Service, except to the extent the law expressly permits. It may not provide the Service to third parties, circumvent its protective measures or use it to develop a competing product.
  • The Provider may use feedback and suggestions to improve the Service without any obligation to pay for them.

11. Limitation of liability

To the extent permitted by law, and unless the contract says otherwise:

  • the Provider is not liable for lost profit, indirect or consequential damage, or loss of data caused by the Customer’s own actions (for example deletion, misconfiguration or compromised login credentials);
  • the Provider is not liable for content the Customer puts into the Service or for decisions made on the basis of AI outputs.

Nothing in these Terms limits liability that cannot be excluded or limited in advance under applicable law.

12. Termination

  • The term of the contract and notice periods are set by the contract.
  • The Provider may terminate the contract if the Customer materially breaches these Terms or the contract and does not remedy the breach within a reasonable period after written notice. It may terminate without that period if the Customer uses the Service for unlawful purposes or threatens the security of the Service or of other customers.
  • After termination, the Customer may request an export of its data within the period agreed in the contract. After that period, the Provider deletes the Customer’s data from its systems; data is removed from backups in the normal course of their rotation cycle, unless the law requires it to be kept.
  • In a deployment on the Customer’s premises, the data stays on the Customer’s infrastructure. On request, the Provider assists with exporting it and with removing the software.
  • Provisions that by their nature should survive termination (in particular sections 6, 7, 10, 11 and 14) remain in force.

13. Changes to these Terms

  • We may change these Terms for legal, operational or product reasons.
  • We notify the Customer of a change in advance by email or in the application, with reasonable time before it takes effect. Material changes are clearly marked.
  • If the Customer does not agree with a change, it may terminate the contract before the change takes effect, in the way the contract sets out.
  • The current version is always published at corpilus.com/terms.

14. Governing law

  • These Terms and the contract are governed by the law of the Slovak Republic.
  • Disputes are decided by the competent courts of the Slovak Republic.
  • If any provision is found invalid or unenforceable, the remaining provisions stay in force.

15. Contact

Send questions about these Terms to info@crebiso.com.

Provider: CREBISO | corp.systems s.r.o. (product: Corpilus). Full company details (company ID, VAT ID, registered office) are available on request at the same address.

Processing of personal data is described in the Privacy Policy (corpilus.com/privacy), and data stored in the browser in the Cookie Policy (corpilus.com/cookies).