Effective date: 29 September 2026
1. Parties and agreement
1.1 Operator
aiwrness.com, app.aiwrness.com and the related services (Service) are operated by RMVG TECH, LDA, a Portuguese private limited company (sociedade por quotas), with registered office at Avenida Miguel Fernandes, 28, 7800-396 Beja, Portugal, NIPC 519625862, registered at Conservatória do Registo Comercial R.N.P.C. under registration number 519625862, share capital EUR 5,000 (aiwrness, we, us). Contact: support@aiwrness.com or our registered address.
1.2 Customer and users
The Customer (you) is the business or professional subscribing to the Service. Its representative must have authority to bind it. Invited individuals are Authorised Users. They must follow these Terms and their workspace permissions; an invitation alone does not make them personally liable for subscription fees.
1.3 Acceptance
You accept these Terms through the registration or ordering step. You can review, correct and save the order details and Terms before ordering. Paid access starts when we confirm the order and payment requirements are met. We provide confirmation you can retain.
1.4 Contract documents
The agreement includes these Terms, the accepted plan/order details and the Data Processing Agreement in Schedule A below (DPA), where applicable. A signed order overrides these Terms only on matters it expressly addresses. The DPA prevails for Customer Personal Data; mandatory transfer clauses take precedence where required.
1.5 DPA and privacy
The Customer’s authorised acceptance also accepts Schedule A and the version of the provider schedule supplied with it, made available with these Terms. No separate signature is required unless agreed or legally necessary. An invited user’s acceptance does not itself authorise a new Customer contract. The Privacy Policy explains processing; accepting these Terms is not cookie, marketing or blanket privacy consent.
1.6 Additional customer terms
Additional terms in a purchase order or other Customer document apply only if expressly agreed by us. They do not replace the accepted Agreement merely because we receive the document or provide the Service.
1.7 Availability of these Terms
We make these Terms, Schedule A and the provider schedule available in full before acceptance, in a form you can read, store and reproduce, and we answer questions about them before you order. We record which version you accepted, with the date. A clause you could not reasonably have known about before accepting does not form part of your contract.
2. Eligibility and accounts
2.1 Professional use
The Service is for businesses, agencies and independent professionals. By accepting as Customer or its representative, you confirm professional use and authority to contract. Account holders must be at least 18 and legally capable. We do not accept private consumer orders under this offering.
2.2 Mandatory rights
Legal status depends on the actual transaction and applicable law. A business label, declaration or tax number does not remove mandatory consumer protection. If your purchase is in fact a consumer contract, clause 5.6 applies. Contact us before ordering if your eligibility is unclear.
2.3 International availability
At launch, paid subscriptions are offered only to eligible Customers with billing addresses in the 27 member states of the European Union. The countries available at checkout control the actual offer and remain subject to law, sanctions, payment and fiscal requirements. Availability does not mean every feature is supported in every country. Necessary restrictions on new sales do not remove rights under existing valid agreements.
2.4 Account security
Provide accurate registration and billing information, keep it current, protect credentials and report suspected unauthorised access promptly. You are responsible for users acting within your authorisation and security measures under your control, without assuming responsibility for failures attributable to us.
2.5 Workspace permissions
Workspace owners control membership and available permissions. Their subscription can determine invited users’ access and limits. Removing a member ends access without necessarily deleting Customer records they created. Obtain appropriate authority before requesting destructive workspace actions.
3. Service and plans
3.1 Functions
aiwrness analyses how supported AI and search services mention brands, products and competitors, including the sources those services cite, which can include news, forums, video services and public professional profiles. Plan features may include scheduled analyses, visibility metrics, sentiment, citations, reported queries, comparisons, opportunities, collaboration, prospect pitches, reports and compatible AI-assistant access.
3.2 Processing workflow
You configure questions, brands, markets and related records. We send necessary context to the relevant providers and process their responses. Supporting analysis can send one provider’s answer to another provider. The Privacy Policy and provider schedule describe these flows.
3.3 Limits and availability
Your plan specifies features, models, quotas and run frequency. Provider limits, failures, retries and maintenance can affect timing and completeness; clause 11.5 explains what we owe when an analysis fails and the remedy if too many do. Missing or unclassifiable results do not establish that a brand is absent from every answer or market.
3.4 Free access
Diagnostics and promotions have the limits disclosed when offered. They do not promise a permanent free subscription. Receiving a free report does not authorise recurring charges or a paid subscription.
4. AI results, outputs and reliance
4.1 What is measured
The Service measures responses to configured requests, not every answer seen by every consumer AI user. API and consumer-interface results can differ because of models, settings, location, personalisation, sources and timing.
4.2 Accuracy
Generated answers, classifications, citations and suggestions may be incorrect, incomplete, biased or outdated. Scores describe the relevant dataset and methodology; they do not certify facts, reputation or market share. Sentiment classifies language, not a person’s actual beliefs or emotions.
4.3 Your assessment
Check underlying answers, dates and sources before relying on or republishing results. We do not guarantee rankings, recommendations, traffic, sales or revenue. The Service is not regulated professional advice and must not be the sole basis for decisions with legal or similarly significant effects on individuals.
4.4 Our obligations
These limitations do not remove our duty to provide the contracted Service with reasonable skill and care or any obligation that cannot legally be excluded.
4.5 AI-generated outputs are third-party content
Answers, summaries, quoted passages, names, figures, citations and other material shown in results are generated by third-party AI and search services in response to the requests you configure. They are not statements by aiwrness. We do not write, verify, adopt, approve or endorse them. Our function is to transmit your requests, receive what those services return, and organise and measure the result.
Outputs may contain statements about individuals, companies, products or events that are inaccurate, outdated, misleading, offensive, defamatory or infringing, and may reproduce material from sources we do not control. Different models, and the same model at different times, can return contradictory statements about the same subject. An output is evidence of what a model returned at a given moment. It is not evidence that its content is true.
You are responsible for reviewing outputs before relying on them, acting on them, sharing them, or including them in a report, pitch or other document delivered to a client or third party. When you republish an output outside the Service, you do so on your own account, keeping the attribution, dating and qualifications required by clauses 4.8 and 7.1.
Subject to clause 4.4 and Section 14, aiwrness is not responsible for the content of outputs, or for loss caused by their content, including loss caused by acting on an inaccurate statement an AI service produced. This clause describes what the Service delivers. It does not exclude liability for our own breach, for failing to supply the Service with reasonable skill and care, or for anything that cannot lawfully be excluded.
4.6 External links, citations and source material
AI-generated answers and citations may contain links to third-party websites, pages or files, and may reproduce titles, short extracts, images and other material from those destinations. aiwrness does not control those destinations or their content. Displaying a link, a title or an extract is not an endorsement or verification of its accuracy, legality, availability or safety. Links may be incorrect, outdated or lead to content that changes after the analysis.
Where source material is shown, it is reproduced to identify and analyse what an AI or search service relied on, and is attributed to its source. Rights in that material remain with their holders. Clause 4.7 explains how to raise a complaint about specific material, and we act on valid notices.
Subject to clause 4.4 and Section 14, aiwrness is not responsible for third-party content, products or services, or loss caused by accessing, downloading or relying on them. External sites apply their own terms and privacy practices. This clause does not exclude liability for our own breach or any responsibility that cannot lawfully be excluded.
4.7 Reporting inaccurate or unlawful content
If an output, citation or stored source item is inaccurate about you or another person, unlawful, or infringes a right, tell us at support@aiwrness.com, identifying the item, where it appears and the reason. Every report is reviewed by us; there is no automated takedown. We assess it without undue delay and, where appropriate, correct, annotate, restrict, remove or stop reproducing it within our control, and inform the relevant Customer or provider. Where a data subject’s valid objection or erasure right requires it, we exclude that individual from further analyses under Schedule A, clause D6.3.
We cannot remove content from independent websites, from a provider’s underlying model, or from copies already exported by a Customer. This procedure does not replace any statutory right or remedy against the person who published the material.
4.8 AI transparency and excluded contexts
The Service uses third-party general-purpose AI systems and our own classification and scoring components. Results are AI-generated. When you republish results, keep any AI-generated marking and make their nature clear to the recipient, as applicable AI transparency rules require.
You must not use the Service or its outputs:
- to make or support decisions about recruitment, employment, promotion, task allocation, discipline, termination or workplace monitoring;
- to infer or monitor the emotions of individuals in a workplace or educational context;
- for credit, insurance, housing, education-access or similar assessments about individuals;
- for social scoring, or to evaluate individuals by behaviour or characteristics unrelated to the professional analysis the Service provides; or
- for any purpose prohibited by applicable AI regulation.
Sentiment and tone features classify the language of a text. They do not detect or report a person’s actual emotions or beliefs, and must not be presented as doing so.
We assess our own role under applicable AI regulation for each component of the Service and make the corresponding information available through support.
5. Prices, taxes and payment
5.1 Published prices
All published prices exclude VAT and other applicable taxes. Pricing displays use “+ taxes” to indicate this.
5.2 Taxes at checkout
Applicable taxes are calculated from your billing details and added at checkout. The tax amount and total payable are shown before you confirm payment. Exemptions and reverse-charge treatment apply only where legally available and validated. Provide accurate billing and tax details; a tax number alone does not guarantee exemption.
5.3 Billing period
Subscriptions are payable in advance for the selected monthly or annual period. A monthly equivalent displayed for an annual plan does not mean monthly payment unless expressly stated. Checkout identifies the currency, recurring price, billing interval and total payable. Before an annual order, we also disclose the comparable monthly price and the early-termination adjustment in clause 13.7.
5.4 Payments and invoices
Stripe processes payments. For each charge we issue a tax invoice through certified invoicing software, showing your billing details and tax identifier where supplied, as Portuguese law requires. A payment confirmation from Stripe is not a tax invoice; the two serve different purposes. Report apparent billing errors promptly; this does not shorten statutory claim periods or remove dispute rights.
5.5 Authorised charges
You authorise recurring charges accepted at checkout. Additional paid features, overages or paid conversions require prior disclosure and the authorisation required by the agreement and law. Your bank or payment provider may charge its own conversion or transaction fees.
5.6 Right of withdrawal where you are legally a consumer
This offering is for professional use under clause 2.1. If applicable law nevertheless treats your purchase as a consumer contract, you have a right of withdrawal of 14 calendar days from conclusion of the contract, under the Portuguese distance-selling rules that govern this Agreement. Where mandatory law in your own country gives you a different or longer period, that period applies instead.
Paid access normally begins immediately at your request. Before you are taken to payment, we ask for your express request to begin immediately and, as a separate acknowledgement, your confirmation that the right of withdrawal is lost once the service has been fully supplied, and that if you withdraw during the period you pay an amount proportionate to what was supplied up to that moment. We record that request and acknowledgement with your order, together with the wording shown to you and the date. Where mandatory law applicable to you does not allow that acknowledgement to limit your right, it does not apply to you.
To withdraw, tell us at support@aiwrness.com within the period by any clear statement; no particular form is required. We reimburse the amounts due without undue delay and within 14 days of being informed, by the original payment method unless you agree otherwise. This clause does not restrict any wider mandatory right, and clause 6.7 does not limit it.
6. Renewal, cancellation and refunds
6.1 Renewal
Subscriptions renew for the selected billing period unless cancelled before renewal. The account’s plan or billing area shows the renewal date and status.
6.2 Cancelling renewal
Cancel through the plan controls in your account’s settings, or support@aiwrness.com if the control is unavailable. Requests received before renewal stop that renewal. We confirm the effective date. Paid access normally continues until the current period ends, unless you request earlier closure or access is lawfully suspended.
6.3 Personal account closure
Request closure or erasure through support, including if you cannot sign in. Closing a personal login is not, by itself, an instruction to terminate an organisation’s subscription or delete its workspaces. We verify identity, scope and authority proportionately and explain destructive effects before acting.
6.4 Owners and invited users
An invited user’s departure removes their access and unnecessary personal-account data. Customer records may remain for the continuing service, subject to individual privacy rights. When an organisation’s owner leaves, we address authorised administration or termination before destructive workspace action. Any assisted transfer depends on verification and technical feasibility; no self-service transfer is promised.
6.5 Customer workspace closure
An authorised instruction to terminate and delete Customer workspaces can end access for all their members. It does not delete members’ unrelated accounts or workspaces. Closure remains subject to lawful retention and does not itself create a refund entitlement.
6.6 Plan changes
Upgrades may start after additional payment is confirmed. Downgrades, benefit reductions and annual-to-monthly changes generally start at renewal. The confirmation screen states the effective date, proration and recurring price. A pending payment is not a completed upgrade. Allowances reset as displayed and do not carry forward unless stated.
6.7 Refunds
We do not offer discretionary refunds for change of mind, non-use, voluntary cancellation, data export or switching. Cancelling renewal normally leaves access available until the paid period ends. Refunds required by law, billing corrections and refunds expressly provided by the Agreement remain available, including under clause 5.6, for our breach, and under clauses 11.3, 12.3, 13.7 and Schedule A, clause D5.3.
6.8 Failed payments
We may notify you, retry authorised payment and restrict paid functions. Where reasonably possible, we allow an opportunity to resolve the issue. Dashboard restrictions do not prevent lawful access, erasure or switching requests. Properly incurred fees remain due, subject to valid disputes and mandatory rights.
7. Permitted and prohibited use
7.1 Professional and agency use
Within your plan, you may use the Service for your business and prepare client reports or prospect diagnostics with the necessary rights and lawful basis. Preserve relevant dates, source attribution, AI-generated markings and material limitations when sharing reports. This grants no rights in third-party content that neither party holds.
7.2 Content and personal data
Do not infringe privacy, intellectual-property or confidentiality rights. Do not place credentials, card details, private customer databases or unnecessary personal data in prompts. Special-category, criminal-offence or children’s data requires an expressly agreed, lawful supported arrangement. Do not use professional-profile monitoring for stalking, harassment, discrimination or sensitive profiling, or for any purpose excluded by clause 4.8.
Where a valid objection, correction or erasure right requires it, we exclude that individual from analyses and remove or restrict the stored results, under Schedule A, clause D6.3. That is a compliance measure, assessed case by case, and we tell you its scope.
7.3 Security and access
Do not bypass permissions, authentication, payment controls, quotas or safeguards; disrupt the Service; resell account access; sublicense the software; or provide an unauthorised proxy to our provider accounts. Intrusive testing requires an agreed arrangement. Lawful good-faith vulnerability reporting remains permitted.
7.4 Extraction and representation
Do not extract data in ways that infringe rights, compromise security or exceed agreed access, or train competing foundation models in breach of rights or applicable provider restrictions. Do not remove required attribution or AI notices, imply false endorsements or describe API samples as exhaustive consumer behaviour.
7.5 Protected activities
These restrictions do not prevent lawful interoperability, protected research, mandatory portability, ordinary service evaluation or use of your own data outside the Service.
8. Content and intellectual property
8.1 Your content
You retain your rights in submitted prompts, brand information, products, notes and other records (Customer Content). You must hold the rights and lawful basis needed for the requested processing. Public availability does not remove privacy or copyright obligations.
8.2 Limited processing permission
You permit us and authorised providers to host, reproduce, transmit and process Customer Content only to provide, secure and support the Service, follow lawful instructions and meet legal obligations. Permission ends with that processing, subject to lawful retention. It does not authorise advertising with your name or logo, content sales or independent general-purpose AI training.
8.3 Results
You may use supplied results and reports for permitted professional purposes, subject to third-party rights, clauses 4.5 to 4.8 and disclosed feature restrictions. We do not guarantee exclusivity or copyright protection in AI-generated material, which may not attract protection at all. Storage in aiwrness does not transfer your ownership to us. Clause 14.5 governs claims by third parties.
8.4 Workspace records
For administration, return and deletion, prompts, answers, history, citations and reports maintained for a Customer are Customer workspace records, whoever created them. This classification neither transfers third-party intellectual property nor makes every record personal data about its creator. Personal information within records remains protected by applicable law.
8.5 Service rights
We and our licensors retain rights in the software, interface, methods, documentation and branding. You receive a limited, non-exclusive right to access the Service for the agreed term. Third-party names and marks remain their owners’ property; inclusion implies no affiliation or endorsement.
9. Confidentiality and data protection
9.1 Confidential information
Each party protects information marked confidential or reasonably understood to be confidential, including qualifying workspace content and results. Use is limited to performing the agreement. Access is restricted to personnel and authorised providers who need it and have confidentiality duties. Apply reasonable protective measures.
9.2 Exceptions and disclosure
Confidentiality excludes information lawfully public, independently developed, already lawfully known or lawfully received without restriction. Compelled disclosure is limited to what the law requires, with notice and reasonable protective assistance where lawful. Confidentiality survives while the information remains confidential, subject to lawful deletion and retention.
9.3 Processing roles
The Privacy Policy covers processing we control, including billing, accounts, security and public diagnostics requested by visitors. The DPA covers personal data processed on Customer instructions. Agencies must obtain authority and required permission to appoint us as a subprocessor. Each party remains responsible for its own legal duties.
10. Providers and integrations
10.1 Service providers
The provider schedule identifies supported infrastructure, AI and search services. We remain responsible for our contractual obligations. Material feature restrictions must be disclosed before use or purchase; provider terms do not create an unlimited waiver of your rights against us.
10.2 External AI assistants
Authorising an MCP or other supported assistant connection allows the selected data and actions within its scopes, workspaces, role and plan. Review permissions and the assistant account’s own data-use terms. You must have organisational authority for the connection and supervise your instructions.
10.3 Revocation
Revoke through available controls or support. Revocation stops future access once effective but cannot recall copies already received. Authorising access does not replace a lawful basis or required agreement with the external provider.
11. Operation and service changes
11.1 Service standard
We provide the Service with reasonable skill and care, maintain appropriate security and take reasonable steps to remedy material defects. No uptime, response-time or service-credit guarantee applies unless expressly agreed.
11.2 Maintenance and necessary changes
Maintenance, provider changes and events beyond reasonable control may affect availability. We seek to reduce disruption and give practical advance notice of planned material disruption. We may make changes needed for security, law, compatibility or continued operation. Supported models may change where reasonably necessary, subject to clause 11.3 and the DPA’s subprocessor process.
11.3 Material feature reductions and model substitution
We will not materially reduce principal paid functionality during a prepaid term without an appropriate remedy. If a necessary adverse change has no reasonably equivalent replacement, you may terminate the affected service by notifying us and receive a proportionate refund for its unused prepaid period. No separate refund request is required after that notice. Other legal remedies remain available.
Substitution. If a supported model or provider is withdrawn, ceases to be available to us, or is unavailable for a prolonged period, we may replace it with another model of our choosing, at no additional cost to you, so that the Service continues. We tell you which models changed and when, and a reasonably equivalent replacement is not a material reduction under this clause.
Where the replacement uses a provider already named in the provider schedule, it is a change in which authorised recipient handles the request and processing continues under Schedule A unchanged. A replacement that would introduce a provider not already named follows Schedule A, clause D5, including its notice and objection process, and clause D5.4 where continuity is urgent. Substitution does not override those rights.
If no reasonably equivalent replacement exists, the first paragraph applies.
11.4 Price and plan changes
An increase applies only at a renewal at least 30 days after direct notice, unless you expressly agree otherwise. You may cancel renewal before it applies. We do not increase an already paid period’s price retrospectively, and no increase takes effect mid-term.
Taxes are not a price increase. Published prices exclude tax (clause 5.1), so a change in an applicable tax rate changes the total payable without being an increase under this clause, and applies when the law says it does.
Plan restructuring. We may reorganise or retire plans. If the plan you are on is retired, we give the same 30 days’ direct notice before a renewal and either keep you on your current terms or offer the nearest equivalent plan. We do not move you to a more expensive or a materially reduced plan without your express agreement; clause 11.3 applies if the change reduces principal paid functionality.
Promotional pricing ends as disclosed when it was offered. The standard price then applies from the next renewal, with notice under this clause.
Changes to quotas, features or included models are governed by clause 11.3 and, where they require changing these Terms, by Section 15.
11.5 Failed analyses
An analysis is one configured prompt submitted to one supported model in one scheduled run.
Running an analysis means submitting your request to the selected provider and recording any usable answer it returns, or recording why no answer was available. We retry transient failures up to a configured limit. A valid Google search without an AI Overview is recorded as unavailable, without treating it as a zero mention. A provider can be unavailable, rate-limit us, time out, refuse a request or return something unusable.
We retry transient request failures on later collection passes, and a batch we could not submit is re-submitted, each up to a configured limit. An absent AI Overview is recorded without an automatic retry. Failures are shown to you rather than hidden; clause 3.3 applies.
Our execution duty. We take reasonable care to submit eligible scheduled analyses and process provider responses. We do not guarantee that a provider will generate a usable answer or that Google will display an AI Overview for a particular query.
If our system fails to submit an eligible scheduled analysis, tell us. We will run it without an additional charge within a reasonable time or, if that is no longer useful or possible, credit the corresponding share of that billing period’s fee. We calculate that share as the period fee multiplied by the number of eligible analyses we failed to submit, divided by all eligible analyses scheduled for that period; the credit cannot exceed that fee. This does not affect clauses 11.3 and 12.3, your rights if we breach the Agreement, or any mandatory right.
Eligible analyses exclude requests that could not be scheduled because your plan quota was exhausted, your configuration was invalid or incomplete, you paused a brand or prompt, your account was suspended or unpaid, or a change you requested took effect during the period. A request submitted to a provider counts as submitted even if the provider returns no usable answer; we record that outcome separately.
Subject to clauses 4.4 and 14.3, we are not otherwise liable for a provider’s unavailability or for what it returns.
11.6 Reporting problems
Report material defects to support with enough information to investigate and reasonably cooperate with diagnosis. We will take reasonable steps to address confirmed issues. Reporting requirements do not remove mandatory remedies or automatically forfeit a claim.
12. Suspension and termination
12.1 Material breach
Either party may terminate for a material breach not remedied within 30 days of written notice, if capable of remedy. An isolated, non-systemic failure to submit or complete an individual prompt does not by itself constitute a material breach; clause 11.5 applies. Repeated or prolonged failures are assessed in light of their severity, duration and effect on the Service. Serious abuse, material security threats, binding law or irremediable material breach may require proportionate immediate suspension or termination.
12.2 Suspension review
We limit suspension to what is reasonably necessary, explain it where lawful and practical, and restore access when resolved. Request review through support. Suspension does not determine that content is unlawful for every purpose.
12.3 Discontinuation
If we discontinue the Service or terminate for convenience, we ordinarily give at least 30 days’ notice, allow reasonable retrieval and refund the unused prepaid period without requiring a request from you. Alternatively, we may complete the prepaid term. Rights arising from our breach remain unaffected.
12.4 Effect of termination
Access ends subject to export and retrieval rights. Accrued payment duties, lawful retention, confidentiality, intellectual-property rights and provisions intended to survive remain effective.
13. Data export, switching and deletion
13.1 Ordinary retrieval
Request authorised Customer data through available exports or support. After ordinary paid access ends, we retain workspace records for 90 calendar days for assisted retrieval or reactivation, without new analyses. We notify the account contact of the deadline. You may instruct earlier deletion.
13.2 Deletion periods
After the retrieval period or an earlier final deletion instruction, active data is deleted without undue delay and within 30 calendar days, except specific lawful retention. Supabase database backups rotate within 7 days after active deletion under the current production backup setting; any separate backup system must have its own documented limit. These are separate stages; shorter legal deadlines and valid individual rights prevail.
13.3 Data Act requests
Where Chapter VI of the EU Data Act applies, clauses 13.3-13.7 prevail over inconsistent cancellation or retention terms. Request switching to another provider, transfer to your infrastructure or deletion on termination through support. Identify the chosen route and an authorised contact. If you choose another provider, give us the details of that provider and the technical information reasonably needed for the transfer. We may verify your authority to instruct the Customer’s exit, but do not require proof that you have purchased a replacement service or completed a migration. The notice period is 30 calendar days from receipt, or a shorter agreed period.
13.4 Transition
We arrange transition after notice, provide reasonable assistance, maintain continuity and security, and identify known continuity risks. The standard transition lasts no more than 30 calendar days. A technically necessary extension follows the statutory process: reasoned notice within 14 working days of the request and an alternative within the legal maximum. You retain statutory extension rights.
13.5 Export scope
Exportable data includes Customer inputs, outputs and usage metadata within the statutory definition: workspace records, questions, products, profiles, results, metrics, citations, queries, tags, events and relevant identifiers. We provide structured, commonly used, machine-readable files, such as CSV or JSON, with interpretation information. Export remains subject to others’ privacy rights.
Exclusions are limited to non-exportable material such as our software, security secrets and protected internal methods. We explain exclusions and do not use them to obstruct switching or withhold exportable Customer data.
13.6 Completion and retrieval
We confirm completion. The affected agreement ends on successful switching, or at the notice period’s end for deletion-only requests, consistently with the Data Act. 90 calendar days of post-transition retrieval are available, matching clause 13.1, unless you request earlier deletion. Exercising a statutory switching right never produces a shorter retrieval period than ordinary cancellation. We then erase exportable data and assets, subject to lawful retention and protected backups under the DPA.
13.7 Switching and payment
We charge no separate switching or data-egress fee. Disclosed ordinary service fees apply while the agreement continues.
If an annual prepaid term ends early under clause 13.6 at your request, including a deletion-only request, we apply a proportionate early-termination adjustment for the annual discount. It does not apply where termination results from our breach or from clauses 11.3, 12.3 or D5.3, or where a mandatory remedy requires otherwise. The refund, before tax adjustments, is max(0, A − 12 × M × D/T), where A is the annual subscription fee paid excluding taxes, M is the comparable monthly subscription price excluding taxes shown when you ordered, D is the number of days elapsed in the annual term at effective termination, and T is the total number of days in that term. If no comparable monthly price was disclosed before the order, the refund is the unused annual fee prorated by days instead. We do not charge beyond the annual fee already paid. Applicable tax adjustments are handled under tax law. We show the calculation on request.
This adjustment is for early termination of the fixed annual commitment, not for exporting data. There is no separate switching or data-egress fee. Where applicable law requires a greater refund or does not permit the adjustment, we follow that law. No payment dispute suspends mandatory switching assistance.
13.8 Preserved rights
We do not promise identical functionality in another provider’s system. This section does not restrict statutory access, portability, erasure or switching rights, or the DPA choice of return or deletion. One user’s departure alone does not require deletion of a continuing Customer’s records.
14. Responsibility and liability
14.1 Responsibility
Each party is responsible for loss caused by its breach under applicable law and must reasonably mitigate loss. You remain responsible for business decisions and checking results where reliance could cause harm. This does not excuse our breach.
14.2 Ordinary negligence cap
Subject to clause 14.3, our aggregate liability for contractual damages caused by ordinary negligence is capped at the greater of EUR 1,000 or fees paid or payable for the Service in the 12 months before the event giving rise to the claim. This cap applies to contractual claims under Schedule A only to the extent permitted by law. Refund obligations are separate from this damages cap.
14.3 Exceptions
The cap does not cover fraud, intentional misconduct, gross negligence, death or injury, harm to physical or moral integrity or health, non-contractual property damage where limitation is prohibited, intentional or grossly negligent acts of representatives or auxiliaries, or other non-limitable liability.
It also does not touch anything the law places outside the parties’ agreement: a data subject’s right to compensation, a supervisory authority’s powers, or either party’s statutory recourse against the other under Article 82(5) GDPR or its equivalent.
14.4 Other remedies
There is no blanket exclusion of lost profits, data loss or third-party claims; applicable law and any lawful cap determine recovery. Lawful withholding of performance, termination, set-off and mandatory remedies remain available.
14.5 Mutual indemnities
You will indemnify us against third-party claims, and resulting awards, approved settlements and reasonable legal costs, arising from (a) Customer Content or instructions that infringe a third party’s rights or breach clause 7.2, (b) your unlawful or materially misleading republication or distribution of results in breach of this Agreement, a third party’s rights or applicable law, or (c) use of the Service for a purpose excluded by clause 4.8. Ordinary permitted sharing of results does not, by itself, trigger this indemnity.
We will indemnify you against third-party claims that the Service itself, as supplied by us and used in accordance with the Agreement, infringes a third party’s intellectual property rights. This does not extend to claims arising from Customer Content, from outputs generated by third-party AI or search services, or from material those services reproduced from external sources.
The party seeking indemnity must notify the other promptly, must not admit liability, must allow the indemnifying party to conduct the defence with competent counsel and must provide reasonable assistance at the indemnifying party’s cost. Neither party may agree a settlement imposing an obligation on the other without its consent, not to be unreasonably withheld. For ordinary negligence, each party’s indemnity liability is subject to the monetary cap in clause 14.2, applied separately to that party; clause 14.3 and mandatory law prevail.
15. Changes to the Terms
15.1 Notice
We may propose changes for identified legal, security, technical or commercial reasons. Material adverse changes receive direct explanation and at least 30 days’ notice. Silence or browsing is not acceptance where express agreement is required.
15.2 Existing commitments
Changes require a lawful basis and any necessary agreement. Without agreement, current terms continue for the prepaid period, unless mandatory law or urgent security requires earlier action. We explain any resulting termination or refund rights. Renewal changes require proper notice and valid acceptance where necessary.
15.3 Clarifications
Non-material clarifications may be published with a new version date. Changes cannot retrospectively remove accrued rights or settle existing disputes in our favour.
16. Law and general provisions
16.1 Governing law and jurisdiction
Portuguese law governs. The courts of Lisbon, Portugal have non-exclusive jurisdiction; either party may also bring proceedings in any other court competent under applicable rules. Overriding mandatory local law, mandatory jurisdiction rules and consumer protections remain effective wherever they apply, and prevail over this clause. A B2B label does not waive protection that legally applies, and where you are legally a consumer, jurisdiction follows the mandatory rules that protect you rather than this clause.
16.2 Disputes
Contact support so we can try to resolve a dispute. This does not restrict urgent court relief, regulator complaints or proceedings available by law. These Terms impose no mandatory private arbitration or class-action waiver.
16.3 Transfers of the agreement
Neither party may transfer the agreement, substitute the counterparty or transfer contractual debts without consent where legally required. Lawful succession remains possible. Authorised providers remain governed by the DPA and provider schedule; we remain responsible for our obligations.
16.4 Severability and relationship
Invalid provisions leave the remainder effective where legally possible; applicable law fills any gap. Failure to enforce once is not a general waiver. The agreement creates no employment, partnership or agency relationship.
16.5 Notices and language
Notices may use the parties’ supplied contact details, with effectiveness determined by law. Keep your account contact current.
English is the reference language of the Agreement. We also publish a Portuguese version. Where you contracted in Portuguese, that version prevails if the versions diverge; otherwise the English version prevails. Mandatory local-language requirements remain effective.
Schedule A. Data Processing Agreement
This Schedule is part of the Terms. Its clauses use the prefix D to distinguish them from the main Terms. It applies only to Customer Personal Data processed on Customer instructions.
D1. Parties and scope
D1.1 Parties
This DPA, incorporated as Schedule A to the Terms, forms part of the service agreement (Agreement) between RMVG TECH, LDA, trading as aiwrness, Avenida Miguel Fernandes, 28, 7800-396 Beja, Portugal, NIPC 519625862 (Processor), and the Customer identified in the accepted order/account records (Customer).
D1.2 Acceptance
The Customer accepts through authorised acceptance of the Terms incorporating this DPA, or another valid written instrument, including electronic form. The version of this DPA and of the incorporated provider schedule must be available before acceptance and recorded with the acceptance. An invited user’s acceptance alone does not make that individual the Customer or bind the organisation.
D1.3 Covered data
Customer Personal Data means personal data processed on Customer instructions to supply the Service. Our independent-controller processing, such as statutory invoicing, necessary account security and public diagnostics requested by visitors, is described in the Privacy Policy. We must not reclassify data to avoid this DPA.
D1.4 Applicable law and roles
Data Protection Law means the GDPR, applicable Portuguese implementing and electronic-privacy law, and any other data-protection requirement binding on the processing.
This definition is open. A regime applies because its own territorial and material scope makes it apply, not because it is named here, and adding a sales territory does not require amending this clause. GDPR terms have their statutory meanings; Actual activities determine roles.
D1.5 Agency Customers
The Customer acts as controller or as a processor authorised by its client to appoint aiwrness as subprocessor. It must obtain required authority and communicate upstream restrictions. Corresponding processor duties apply to aiwrness in both cases. Additional mandatory local requirements must also be met.
D2. Instructions and permitted purposes
D2.1 Documented instructions
The Processor shall process only to provide the agreed Service under the Agreement, this DPA, authorised Customer configuration and subsequent lawful written instructions, including transfer instructions. Annex 1 describes the processing.
D2.2 Provider workflows
Instructions cover the specific workflows and recipients in the completed Annexes, including supporting OpenAI classification where applicable. They do not authorise undisclosed secondary use or unlawful transfers. Customer-selected assistant access is limited to authorised permissions.
D2.3 Legal conflicts
If EU or Member State law requires other processing, the Processor shall inform the Customer beforehand unless prohibited for important public-interest reasons. It shall promptly flag instructions it considers unlawful and suspend the affected instruction where necessary while seeking clarification.
D2.4 Prohibited secondary uses
The Processor shall not sell Customer Personal Data, use it for advertising audiences, independently profile individuals, train a general-purpose AI model on it, or authorise subprocessors to do so. Producing anonymous statistics requires documented instructions and effective anonymisation under applicable law; pseudonymisation is insufficient.
D2.5 Excluded purposes
Processing for a purpose excluded by clause 4.8 of the Terms is outside these instructions. The Processor shall not knowingly perform it and shall raise it under D2.3 if instructed to.
D3. Customer duties
D3.1 Lawful collection and use
The Customer shall maintain a lawful basis, give required notices, honour individual rights, minimise data and issue lawful instructions. Special-category, criminal-offence or children’s data requires an expressly agreed, lawful supported arrangement.
Where the Customer configures monitoring of individuals whose data was not obtained from them, it remains responsible for the information duty under Article 14 GDPR, including any documented reliance on Article 14(5)(b). The Processor publishes a general notice for those individuals and operates the mechanism in D6.3, which supports but does not discharge that duty.
D3.2 Administration
The Customer shall manage users and assistant connections, protect credentials under its control and maintain operational/incident contacts. These duties do not remove the Processor’s obligations or excuse processing outside instructions.
D4. Confidentiality and security
D4.1 Personnel
Authorised personnel shall have contractual or statutory confidentiality duties. Access is limited to what authorised work requires.
D4.2 Measures
The Processor shall maintain risk-appropriate technical and organisational measures, considering processing context, state of the art and implementation costs. Annex 2 sets minimum measures. Changes must not materially reduce overall protection; material changes to processing or risk require relevant information to the Customer.
D4.3 Review and records
The Processor shall regularly assess effectiveness, maintain appropriate processing records and cooperate with competent supervisory authorities as required.
D5. Subprocessors
D5.1 Initial authorisation
The Customer authorises subprocessors identified in the completed Annex 3 for the stated functions and locations. Appointment requires due diligence and a written agreement imposing the protection required by GDPR Article 28. The Processor remains fully liable for their performance of those obligations.
D5.2 Changes
General written authorisation for additions/replacements is subject to 30 days’ prior notice, sent directly to the Customer’s account contact and published on the provider schedule, identifying entity, service, location, data and transfer arrangements. The Customer may object on reasonable data-protection grounds within that period. Silence does not waive statutory rights.
D5.3 Objections
The parties shall seek a reasonable solution, including an alternative recipient, a different configuration or disabling an optional function.
While an objection is unresolved, the Processor shall not begin the new or replacement processing objected to, and shall suspend the affected function where it is technically separable from the rest of the Service. Where the objected-to recipient supplies infrastructure that cannot be separated from the Service, the Processor shall say so promptly in writing rather than give an assurance it cannot honour.
If the objection is not resolved, the Customer may end the affected service, or the Agreement where the function is inseparable, before the new processing starts, and receive a proportionate refund of the unused prepayment.
D5.4 Urgent changes
Continuity or security urgency does not waive Article 28 rights. Where ordinary notice cannot be followed, the Processor shall notify promptly and obtain specific authorisation where required before the new recipient processes data.
D5.5 Independent recipients
Customer-selected assistants, sign-in providers and payment services acting independently are not automatically subprocessors. Listing them for transparency does not create processor terms they have not accepted.
D6. Assistance
D6.1 Individual rights
Considering the processing, the Processor shall provide appropriate technical and organisational assistance with rights requests. It shall promptly forward Customer-controlled requests and respond on the Customer’s behalf only on instructions or as legally required. It may acknowledge receipt and identify the relevant controller.
D6.2 Compliance assistance
The Processor shall reasonably assist with security, breach assessment/notification, impact assessments and prior consultation, considering the processing and information available. Routine DPA compliance assistance is included. Exceptional charges require prior agreement, must be lawful and proportionate, and must not delay legal duties or shift the cost of remedying the Processor’s breach to the Customer.
D6.3 Objections and corrections by people who are not users
This clause applies where an individual who is not a Customer user exercises a right in respect of data processed in a Customer workspace, typically someone named in an answer or in a cited source.
Requests are made to support@aiwrness.com and assessed case by case. There is no automated or self-service suppression control; each request is reviewed by the Processor before anything is changed.
The Processor shall inform the Customer without undue delay and the parties shall address the request. Where the Customer does not act within a reasonable period, where the Customer cannot be reached, or where the same individual is affected across several customers, the Processor shall give effect to a valid right under Article 17 or 21 GDPR by removing or restricting the relevant records and excluding that individual from further analyses.
The Processor shall keep the minimum record needed to maintain that exclusion, tell affected Customers that it has been applied and its scope, and lift it if the basis ceases. This is a compliance measure, not a discretionary content control, and the Processor shall not use it for any other purpose.
D7. Personal data breaches
D7.1 Notification
The Processor shall notify the Customer without undue delay after awareness of a breach affecting Customer Personal Data. It shall not await a complete investigation or a decision about regulatory notification. Information may be supplied in stages.
D7.2 Information and response
To the extent known, notification shall describe the breach, affected data/people and approximate numbers, contact point, likely consequences and mitigation. The Processor shall preserve relevant evidence, investigate, take reasonable remedial action and cooperate with the Customer.
D7.3 Statutory notifications
The Customer remains responsible for its controller notifications, including the applicable GDPR 72-hour rule. This does not permit the Processor to wait 72 hours. Neither party may prevent legally required notification.
D8. International transfers
D8.1 Requirements
Transfers outside the EEA require documented instructions and GDPR Chapter V compliance. Annex 3 shall identify recipients, countries and valid mechanisms, covering onward transfers and third-country access.
The countries named in Annex 3 are those where recipients process data. They are not a list of the territories where the Service is sold, and selling into a further territory does not by itself add an entry. A new entry is required only when data reaches a new recipient or a new processing location.
D8.2 Standard clauses and transfer assessments
Where required, the relevant exporter/importer shall execute the correct EU Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, with the module that matches the actual roles: Module Three (processor to processor) where the Processor transfers Customer Personal Data to a subprocessor, and Module Two (controller to processor) for personal data the Processor controls in its own right. The executed module, annexes and optional selections shall be recorded for each recipient; naming a module is not a substitute for executing it.
Where an adequacy decision is relied on, the Processor shall record that the actual recipient entity and the actual service fall within its scope, and shall re-verify that whenever the provider schedule changes. Adequacy is a status that can lapse, so the record is of a check made on a date, not of a permanent fact.
Where the clauses are relied on, the Processor shall carry out and keep current a documented transfer impact assessment for that recipient, covering its legal environment and government-access exposure, the categories of data transferred, the supplementary technical, organisational and contractual measures applied, and the resulting conclusion. Each completed assessment is made available to the Customer on request under D9.
Referring to Standard Contractual Clauses in this DPA neither executes them nor completes an assessment.
D8.3 Other regimes
Where a non-EEA data protection regime reaches a transfer, its own mechanism must also be established. EU clauses are not automatically sufficient outside their scope, and the Processor shall record which instrument covers each flow.
D8.4 Loss of safeguards
The Processor shall report inability to comply with a transfer mechanism and cooperate on remedies, including suspension where necessary. Customer acceptance does not validate an unlawful transfer; choosing a market is not blanket transfer consent.
D9. Information and audits
D9.1 Audit rights
The Processor shall provide information needed to demonstrate DPA and Article 28 compliance, and allow and contribute to Customer audits, including inspections by a mandated independent auditor.
D9.2 Practical arrangements
The parties may first use current documentation and independent assurance, without replacing a reasonably necessary inspection. Audits ordinarily use reasonable notice, business hours, confidentiality and safeguards for other customers and system security. Arrangements must not frustrate effective rights.
D9.3 Exceptions and costs
Notice, timing or frequency restrictions yield to law, authority requests and reasonable evidence of significant incidents/non-compliance. Each party ordinarily bears its own costs unless reasonably agreed otherwise. Costs must not make audit rights ineffective.
D10. Return and deletion
D10.1 Departing users
Personal-account closure does not itself terminate processing for an entire Customer workspace. The Processor shall distinguish individual rights from Customer instructions, verify organisational owners’ authority/scope and avoid destroying unrelated records solely because a departing user created them. This does not justify ignoring erasure rights or retaining identifiers without a lawful purpose.
D10.2 Attribution of records
Workspace records are attributed to the Customer, not to the individual who created them. Account deletion is not self-service. The Processor removes an account only on a verified request, and before acting assesses and records the effect on Customer records, brands, analyses and history, preserving or reassigning them as required. Personal identifiers of a departing user within those records are assessed separately under that individual’s rights.
D10.3 Customer choice
At the Customer’s choice, the Processor shall return or delete Customer Personal Data after processing services end. Active copies are deleted under clause D10.4; residual database backup copies are kept beyond ordinary use only until they expire under clause D10.5. Copies required by EU or Member State law may be retained only as described in clause D10.6. Lawful switching/retrieval arrangements must allow the Customer to exercise its choice before destruction.
D10.4 Active deletion
Return shall use a secure, reasonably usable format, normally a structured machine-readable export. Following final instructions or the retrieval period, active deletion shall occur without undue delay and within 30 calendar days, or a shorter legal deadline. This includes soft-deleted records and relevant provider files under the Processor’s control. It shall instruct subprocessors and confirm completion in writing on request.
D10.5 Backups
Supabase database backups rotate within 7 days after active deletion under the current production setting. Any other backup copy must have a documented expiry and equivalent restricted-access, restoration and erasure controls before use. Deletion instructions are reapplied after restoration. This does not permit indefinite production copies or provider files without defined expiry.
D10.6 Legal retention
Required retained copies shall be limited to the necessary information/purpose, protected and deleted when the duty ends. Independent-controller fiscal retention does not justify retaining complete Customer workspaces.
D11. Duration and priority
D11.1 Duration
This DPA applies throughout processing, including protected residual copies after termination. It prevails over conflicting processing provisions in the Agreement. Mandatory transfer terms and statutory rights take precedence.
D11.2 Responsibility
The Agreement governs liability only where lawful, and clause 14.2 of the Terms sets the applicable cap, subject to the exceptions in clause 14.3. No limitation restricts individual rights, statutory compensation, supervisory powers, statutory recourse between the parties or non-limitable liability. This DPA does not assign all privacy risk to the Customer.
DPA Annex 1. Processing description
A1.1 Subject and duration
Operation of Customer workspaces, AI visibility analyses, prospect diagnostics and authorised integrations, throughout service, lawful retrieval/transition and Section D10 deletion/backup periods.
A1.2 Operations and purposes
Collection, recording, organisation, storage, approved transmission, output generation/classification, matching, aggregation, retrieval, authorised disclosure/export, restriction and erasure. Purposes are answering configured questions, analysing visibility/mentions/sources/sentiment, organising records and supporting reports, users and integrations. AI outputs may be inaccurate. Independent advertising, general-purpose training, unrelated profiling and the purposes excluded by clause 4.8 of the Terms are outside this description.
A1.3 Individuals
Customer/client representatives; users where processed on Customer instructions; self-employed brand owners; public professionals and creators; and people mentioned in supplied material, answers or sources.
A1.4 Data categories
Names, professional aliases, profile/social/image URLs, affiliations, supplied business contacts, information in prompts/descriptions/notes/events, generated statements, mentions, classifications, citations, query metadata, identifiers and dates. Data processed independently for aiwrness billing/security is excluded to that extent.
A1.5 Sensitive data
Article 9/10 and children’s data are not intentionally supported. Because collected source material can contain such data without being requested, the Processor applies proportionate technical minimisation and filtering to collected content, and assesses, restricts or deletes special-category data identified in it. A contractual prohibition alone is not treated as a sufficient control. Incidental discovery requires prompt assessment, minimisation and appropriate restriction/deletion, or a specifically agreed lawful arrangement.
A1.6 Frequency and contacts
Processing involves ongoing storage, scheduled analyses, requested setup/diagnostics and authorised integration calls. Customer identity/address and authorised contact are recorded in the accepted order/account; the Customer shall maintain a privacy/incident contact. Processor and urgent incident contact: support@aiwrness.com.
DPA Annex 2. Security measures
A2.1 Access
Individual authenticated accounts; role checks and tenant separation; least-privilege administration; timely access removal; multifactor protection for privileged production access; controlled support access.
A2.2 Transmission and storage
Encrypted application/provider connections; protected server-side credentials and secrets; rotation/revocation procedures; provider-supported encryption at rest for personal data and backups; restricted database access. Credentials must not enter ordinary prompts or public/browser configuration. This is not a claim of end-to-end encryption.
A2.3 Application integrity
Input validation, safe output/link handling, server-side authorisation, dependency/security updates and review of material changes. Payment operations and retries must guard against unauthorised or duplicate actions.
A2.4 Data lifecycle
Minimum necessary provider context; separation of fiscal records from technical payloads; documented deletion of active data, soft-deleted data, logs, files and backups; precise restrictions and legal holds. Account removal follows a controlled procedure with prior assessment of its effect on Customer records, consistently with D10.2.
A2.5 Recovery and incidents
Risk-appropriate backups, restoration testing, continuity responsibilities and reapplication of erasure/restriction on restore. Proportionate logging with limited retention/access; incident escalation, containment and prompt Customer notification.
A2.6 Personnel and suppliers
Confidentiality, relevant training including applicable AI-literacy requirements, supplier due diligence, current processing/transfer records including the assessments under D8.2, and procedures for supplier changes and government-access requests.
A2.7 Rights and review
Proportionate identity/authority checks, secure exports, instruction/completion records and rights processes independent of paid dashboard access, including the suppression mechanism in D6.3. Periodic control reviews, security testing and reassessment of new data categories, purposes, jurisdictions and AI capabilities.
DPA Annex 3. Subprocessors and transfers
A3.1 Incorporated schedule
The Service Providers and Subprocessors version supplied at acceptance forms part of this DPA. Subprocessor entries apply to contracted features. Independent controllers and Customer-selected services are not appointed by this Annex.
A3.2 Completion and changes
The schedule shall identify actual entities, functions, data, countries and lawful transfer arrangements. Changes follow Section D5.
Where a particular entry is incomplete, that entry alone establishes neither a valid appointment nor executed transfer safeguards, and the Processor shall not rely on it. An incomplete entry does not affect entries that are complete.
A3.3 Acceptance record
Record the Customer, authorised representative, acceptance date, DPA version and provider schedule version through the incorporated Terms or a separate instrument, so that the subprocessors authorised at acceptance can be identified later. A separate signature page is not required for ordinary valid electronic acceptance.