WHAT IF spaces OÜ (registry code 16602451, Rotermanni 2, 10111 Tallinn, Estonia) (the "Service Provider", "we", "us") operates Franklin, an AI-based building data and document intelligence platform (the "Platform"). These Terms of Service govern access to and use of the Platform and related services.
Version 1.1 · Effective date: 11 August 2026
1. The Agreement
1.1 These Terms of Service apply to every legal person (the "Client") that subscribes to or uses the Services. The Services are provided to businesses and organisations only and are not directed at consumers.
1.2 The agreement between the Service Provider and the Client (the "Agreement") comprises the following documents, which together form a single binding agreement:
- (a) the Subscription Plan — the subscription tier, scope, Fees, and term selected by the Client in its Account when subscribing to the Services;
- (b) these Terms of Service;
- (c) the Service Level Agreement set out in Annex 1 (the "SLA");
- (d) the Technical and Organisational Measures set out in Annex 2 (the “TOM”)
1.3 In the event of any discrepancy between these Terms of Service and the Subscription Plan, these Terms of Services shall prevail, save that the Subscription Plan shall govern the subscription scope, Fees, and term. In the event of any discrepancy between these Terms of Service and the SLA, the SLA shall prevail with respect to availability, incident management, support, and maintenance.
1.4 By creating an Account, subscribing to a Subscription Plan, or using the Services, the Client confirms that it has read, understood, and agrees to be bound by the Agreement, and that the individual accepting has authority to bind the Client.
2. Access to and Use of the Services
2.1 Subject to all limitations and restrictions contained herein, the Service Provider grants the Client a non-exclusive and non-transferable subscription right to access and use the Services. The Client may:
- (a) use the Services via the web application, the HTTPS protocol, and API endpoints;
- (b) make the Services available to Users.
2.2 To access and use the Services, the Client shall have the right to an Account with administrative control. The Service Provider shall create such an Account for the Client and disclose the credentials to the Client. The Client shall retain ultimate administrative control over its Account for the Term.
2.3 The Client shall have the right to create, designate, and terminate User accounts. Users shall be permitted to access the Services subject to User rights assigned to them by the Client. The Client agrees and acknowledges that it approves all creation, designation, and termination of User accounts.
2.4 The Client is responsible for keeping the Account secure while using the Services. The Client is responsible for all Client Data uploaded and all activity that occurs under the Account. The Service Provider cannot and will not be liable for any loss or damage arising from the Client's failure to comply with this obligation. The Client will promptly notify the Service Provider if the Client becomes aware of any unauthorised use of, or access to, the Services through the Account, including any unauthorised use of the password or the Account.
2.5 The Client shall use the Services only in accordance with the Agreement and Applicable Laws. Unless expressly otherwise agreed between the Parties, the Client shall not:
- (a) modify, copy, enhance, improve, alter, reverse engineer, decompile, disassemble, deconstruct, translate, decrypt, reverse compile or convert into human readable form the Services or any part thereof, except to the extent permitted by Applicable Laws;
- (b) work around any technical limitations or restrictions of the Services;
- (c) remove, deface, cover or otherwise obscure any proprietary rights notice or identification from the Services (including without limitation any copyright notice);
- (d) authorise or permit any third party to engage in the aforementioned activities.
2.6 The Client agrees to refrain from conducting any activity harmful to the Service Provider and/or the Services. The Client shall not:
- (a) use the Services in a manner that interferes with, corrupts, damages, or destroys the Services, including any software or the servers that administer the Services, or the data and information in the Services;
- (b) use the Services in any way that is or may be unlawful, illegal, fraudulent, harmful, or in connection with any unlawful, illegal, fraudulent or harmful purpose or activity;
- (c) transmit malware to the Services or use the Services maliciously;
- (d) significantly increase the workload of the Services above what is reasonably expected from the Client;
- (e) use the Services in any other way that is reasonably likely to result in damage to the Service Provider or another client of the Services.
3. Intellectual Property Rights
3.1 All IPR to the Services, including their components, any upgrades, additions, corrections, improvements, and any other proprietary software made available by the Service Provider to the Client will at all times remain the sole property of the Service Provider or its licensors. The Agreement does not transfer or convey any IPR from the Service Provider to the Client, nor does it grant the Client any rights in or to the Service Provider's IPR, except for the limited rights expressly granted under the Agreement.
3.2 Subject to full and timely payment of all Fees, the Service Provider grants the Client a non-exclusive, non-transferable, non-sublicensable, limited right and license to access and use the Services for the duration of the Term. This license is provided solely for the Client's internal business purposes, and the Client agrees to use the Services in accordance with the terms and conditions set forth in the Agreement.
3.3 The Parties acknowledge and agree that the Client and/or its Affiliates shall retain sole ownership of all IPR in and to the Client Data. The Agreement does not constitute a transfer of any IPR over the Client Data from the Client to the Service Provider. The Service Provider is authorised to use the Client Data exclusively for the purpose of rendering the Services as stipulated in the Agreement. Any such use shall be in compliance with the terms of the Agreement, the GDPR, and the Service Provider's Privacy Policy. The Service Provider acknowledges that it has no right to disclose, replicate, or use the Client Data for any purpose other than as expressly permitted in the Agreement.
3.4 The Client warrants that it has all rights necessary to upload the Client Data to the Platform and that the Client Data does not infringe the rights of any third party.
3.5 The Client may provide the Service Provider with feedback, suggestions, or ideas regarding the Services. The Service Provider may freely use such feedback without restriction or obligation, provided that no Client Confidential Information is disclosed in doing so.
4. Availability and Support
4.1 The Service Provider commits to maintaining the availability of the Services as detailed in the SLA.
4.2 The Service Provider shall use commercially reasonable efforts to ensure that the Services are available with the uptime and performance standards specified in the SLA. However, the Service Provider does not warrant uninterrupted or error-free operation of the Services and does not guarantee that the Services will be available 24/7, year-round.
4.3 The Service Provider agrees to perform any maintenance or support activities for the Services with reasonable skill and care, in accordance with the terms outlined in the SLA.
4.4 The Service Provider's obligations regarding availability levels, incident management, support services, and maintenance of the Services are exhaustively defined in the SLA. The SLA also provides the Client's sole and exhaustive remedies for the Service Provider's breach of such obligations.
4.5 The Parties may, from time to time, agree on additional work relating to the Services based on the Client's needs and requirements. Such additional work shall be agreed upon by the Parties in a separate written agreement detailing the scope, usage, and fees associated with such additional work.
5. AI Features
5.1 Scope. The Platform integrates artificial intelligence (AI) and machine learning (ML) features.
5.2 Third-party AI models. AI processing is performed using pre-trained foundation models provided by third-party providers listed in the infrastructure service provider list (see the Privacy Policy). The Service Provider maintains a multi-provider strategy with fallback chains to ensure resilience.
5.3 No training on Client Data. The Service Provider does not train, and does not permit any third party to train, any machine learning model on Client Data. The Service Provider has in place zero-retention and no-training arrangements with each AI provider used to process Client Data, so that content submitted for AI processing is not retained by the provider, not used for model training, and not used for service improvement beyond real-time processing. Any future custom model training on Client Data would require the Client's explicit opt-in consent and a separate written agreement detailing scope, retention, and security.
5.4 Aggregated metrics. The Service Provider may collect and use aggregated, anonymised performance metrics (processing times, error rates, model latency, confidence score distributions) for system optimisation and service improvement. These metrics do not include document content, Personal Data, or tenant-identifiable information.
5.5 Tenant isolation. The Services enforce strict tenant isolation: database row-level security scoped by organisation, organisation-scoped embedding retrieval, and role-based access control. The AI features do not access or learn from documents outside the Client's organisation.
5.6 Human oversight. All AI-generated outputs (classifications, extractions, assistant responses) are labelled as AI-generated and displayed with confidence scores where applicable. Users can review, override, correct, or reject AI outputs. No AI decision in the Platform has automatic legal effect or produces binding outcomes without human review.
5.7 Known limitations. The Client acknowledges that AI outputs may contain errors, inaccuracies, omissions, misclassifications, biases, or fabricated content ("hallucinations"). Precision may fluctuate with new languages, document types, poor-quality scans, handwritten annotations, complex layouts, numerical values and units, and CAD/DWG files (processed as raster images). Hallucination risk is reduced through grounding instructions but cannot be eliminated entirely.
5.8 AI and DWG/IFC comparison output disclaimer: AI outputs and the DWG and IFC comparisons are not guaranteed to be accurate, complete, or legally binding. The Client and its Users are responsible for reviewing and verifying AI and DWG and IFC outputs before using them for decision-making or compliance purposes. The Service Provider shall not be liable for damages arising from reliance on unverified AI or DWG and IFC comparison outputs.
5.9 EU AI Act. The Platform's AI features fall into the limited-risk category under Regulation (EU) 2024/1689 (the EU AI Act): document classification and extraction are informational in nature with no binding legal effect, all outputs are subject to human review before use in compliance decisions, and no high-risk AI systems are deployed. The Service Provider meets the applicable transparency obligations by labelling AI outputs, disclosing AI limitations, and enabling User overrides.
5.10 Changes to AI processing. Changes to AI Models or providers (version upgrades, new providers, retirement of models) require prior notification to the Client. Non-material improvements may be implemented with general notification. Material changes (accuracy decrease, data handling policy changes) require 30 days' advance notice. If a material change to AI processing is materially adverse to the Client's interests and the Service Provider cannot mitigate those concerns, the Client may terminate the Agreement with effect from the end of the then-current subscription period.
6. Fees
6.1 The Client shall pay to the Service Provider as consideration for the Services the Fees applicable to the Subscription Plan selected by the Client, as set out in the Service Provider's published price list in force at the time of subscription. The Fees cover the total fees for all Services to be performed under the Agreement. The Parties may agree on any additional fees payable by the Client for ancillary services.
6.2 All Fees are exclusive of ancillary fees and taxes. If VAT or any other taxes are applicable to any Fee, such taxes shall be added to the respective invoice pertaining to the relevant Fee.
6.3 The Service Provider shall issue invoices to the Client per the Fees applicable to the Client's Subscription Plan. All invoices shall be sent electronically to the invoicing address specified by the Client in its Account.
6.4 If the Client receives an invoice which it reasonably believes includes a sum which is not valid and properly due, the Client shall notify the Service Provider in writing within 10 days from the receipt of such invoice. The Service Provider shall review the disputed invoice and notify the Client whether the disputed invoice is correct, or if incorrect, issue a corrected invoice.
6.5 The Fee shall be deemed paid when the corresponding payment card charge has been successfully settled or, where payment is made by bank transfer, when the sum is credited to the Service Provider's bank account indicated on the invoice. The Client shall pay any additional costs required for payment of the Fee, such as bank transfer fees.
6.6. If a payment card charge is declined, reversed, or otherwise fails, the Client shall be in delay from the due date and shall provide valid payment card details or settle the outstanding Fee by bank transfer within five (5) business days.
6.7 All sums payable under the Agreement shall be paid in euros (EUR) and shall be paid in full without any set-off, counterclaim, deduction or withholding unless required by law or unless the SLA requires otherwise.
6.8 If the Client is in delay with payment of undisputed Fees for more than 30 days, the Service Provider may, having given at least 10 days' prior written notice, suspend access to the Services until all outstanding undisputed Fees are paid. Suspension does not release the Client from its payment obligations and does not constitute a breach by the Service Provider.
6.9 Unless otherwise agreed by the Parties, all Fees are payable by payment card remittance. The Client shall provide and maintain valid, current payment card details in its Account and authorises the Service Provider, acting through its payment service provider, to charge that card for all Fees due under the Agreement, including recurring Fees falling due on each renewal of the subscription period. The Service Provider does not store full payment card data itself; card data is processed by its payment service provider.
7. Confidentiality
7.1 The Parties shall maintain and keep confidential and shall not disclose directly or indirectly to any third party the other Party's Confidential Information and shall prevent third parties' access to such information. Either Party shall:
(a) use Confidential Information only for performing the Agreement and, in the case of the Service Provider, for providing, supporting, and securing the Services, including as permitted by Section 5.4;
(b) treat all Confidential Information as strictly confidential and implement and maintain the technical and organisational security measures described in Section 8 and the SLA, and such other measures as are appropriate in the circumstances, to protect Confidential Information against unauthorised or unlawful processing, accidental loss, distribution or damage;
(c) in case Confidential Information includes Personal Data, follow the disclosing Party's instructions on processing Personal Data and adhere to the GDPR;
(d) disclose Confidential Information only to its advisers and members of governing bodies, directors, officers, members, employees, agents, managers, consultants, and individuals required to perform the Agreement, and ensure that all those to whom Confidential Information is disclosed are aware of and observe the terms of this Section as if they were a party to the Agreement;
(e) ensure that any subcontractor to whom Confidential Information is disclosed is bound by written confidentiality obligations no less protective than those set out in this Section 7;
(f) limit copies of, and access to, Confidential Information to those persons and to the extent strictly necessary for performing the Agreement; and
(g) not, without the disclosing Party's prior written consent, use Confidential Information for its advantage, commercial or otherwise.
7.2 Notwithstanding the foregoing, disclosure of Confidential Information is not considered a breach of the Agreement if the receiving Party is required to disclose it by applicable law or a court of competent jurisdiction, but only to the minimum extent of such requirement and provided that the receiving Party, to the extent permitted by applicable law, gives the disclosing Party prior advance notice before making such disclosure so as to afford the disclosing Party a reasonable opportunity to object to and obtain a protective order or other appropriate relief regarding such disclosure. Each Party may also disclose the other Party's Confidential Information to its auditors and to actual or prospective investors, acquirers, or financing parties, provided that each recipient is bound by confidentiality obligations no less protective than those set out in this Section 7.
7.3 The receiving Party shall notify the disclosing Party immediately in writing if it becomes aware that Confidential Information has been disclosed to an unauthorised third party and take all reasonable measures to prevent or reduce damage to the disclosing Party.
7.4 In case of any reasonable doubt whether particular information shall be treated as Confidential Information and whether and to what extent it might be disclosed to third parties, the Parties shall treat such information as Confidential Information.
7.5 Except for the limited right to use Confidential Information for performing the Agreement, the Agreement does not grant the receiving Party any right to such information, including to use, sell, copy, further develop or create derivative works based on such information. The disclosing Party remains the owner of the Confidential Information, regardless of any disclosure of the same.
7.6 The confidentiality obligations in this Section 7 shall remain effective for five (5) years after the termination of the Agreement for whatever reason, and for an indefinite term in respect of any Confidential Information that constitutes a trade secret under applicable law.
8. Data Security
8.1 The Service Provider shall implement technical and organisational measures to ensure the security, confidentiality, and integrity of the Client Data, including any Personal Data. The Service Provider shall at least meet or exceed (a) the requirements of the Agreement, including the technical and organisational measures described in the Technical and Organisational Measures published by the Service Provider; and (b) good industry standards and practices.
8.2 The Service Provider shall (a) ensure at all times the confidentiality, integrity, availability, backup, and resilience of systems and services processing Client Data; (b) restore the availability and access to Client Data in a timely manner in the event of a security incident involving Client Data; and (c) regularly test, assess and evaluate the effectiveness of technical and organisational measures for ensuring the security of the Client Data.
8.3 The Service Provider shall inform the Client without undue delay about any incidents in which the security of the Client Data has been compromised, including any events of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to the Client Data transmitted to, stored or processed by the Service Provider. The Service Provider shall take due measures in response to security incidents in order to restore the confidentiality, integrity, and availability of the Client Data.
9. Infrastructure Service Providers
9.1 The Client acknowledges that the Services are delivered using third-party technical infrastructure and service providers, including cloud hosting and storage, networking and content delivery, AI Model and inference providers, payment processing, and monitoring, logging, and support tooling. The Service Provider is entitled to engage, replace, and remove such infrastructure service providers in the performance of the Services without the Client's prior consent. Prior to engaging any infrastructure service provider that will host or have access to Client Data, the Service Provider shall assess that infrastructure service providers's technical and organisational security measures, compliance with applicable legal and regulatory requirements, and record of service reliability.
9.2 If the infrastructure service provider maintains the Client Data, the Service Provider shall (a) only use such subcontractors that can provide appropriate technical and organisational measures in such a manner that the processing will meet the requirements of the GDPR and ensure the protection of the rights of the data subject; and (b) impose on the subcontractor the same confidentiality obligations and security requirements as it has under the Agreement.
9.3 The Service Provider shall evaluate its infrastructure service providers on a regular basis to ensure ongoing compliance with the standards set forth in the Agreement and any changes in legal or regulatory requirements. The current register of infrastructure service providers used in providing the Services is set out in the Privacy Policy. The Service Provider may add, replace, or remove infrastructure service providers at its discretion and shall update that register accordingly, without any obligation to notify the Client in advance. The Service Provider remains responsible for the acts and omissions of its subcontractors in the performance of the Services to the same extent as for its own.
10. Indemnification
10.1 The Service Provider shall defend and indemnify at its own expense the Client against claims and actions that the use of the Services infringes the IPR of a third party (the "IPR Claim"), provided that the Client notifies the Service Provider without delay, in writing, after becoming aware of such claims, permits the Service Provider to independently defend or settle the claims, gives the Service Provider all reasonably necessary information and assistance available and all necessary authorisations, and does not agree to the settlement of any such claim prior to a final judgment thereon, or make any admission in relation to the claim, without the prior written consent of the Service Provider. The Service Provider shall, to the extent possible, endeavour to protect the goodwill and reputation of the Client in connection with such claims.
10.2 If it is established that, or if in the justified opinion of the Service Provider, the use of the Services infringes the IPR of a third party, the Service Provider shall at its own expense either (a) obtain the continued right to the use of the Services for the Client in accordance with the terms of the Agreement; or (b) modify or replace the Services in order to eliminate the infringement.
10.3 The Service Provider shall, however, not be liable to the Client for any IPR Claim if it (a) results from the use of the Services in combination with any hardware, product, software or service of a third party not furnished by the Service Provider; (b) results from compliance with the Client's instructions; (c) is based on or arises out of the use of the Services outside the scope set forth in the Agreement or in violation of the Agreement; or (d) results from compliance with international standards.
10.4 This Section 10 states the entire liability of the Service Provider and the Client's sole and exclusive remedies for any IPR Claim. The Service Provider shall indemnify the Client and pay all direct damages, costs and expenses (including reasonable legal costs and expenses) awarded against or incurred by the Client as a result of any IPR Claim but shall not be responsible under this indemnity for any settlement or compromise made by the Client without its consent.
10.5 The Client shall indemnify and hold the Service Provider harmless from any damages, costs or fines awarded against or claimed from the Service Provider in respect of (a) any legal action by the Client's customers in connection with a breach of an agreement between the Client and its customers; and (b) any third-party claim arising from Client Data uploaded in breach of Section 3.4, provided that the Service Provider notifies the Client without delay, in writing, after becoming aware of such claims.
11. Limitations of Liability
11.1 Subject to Sections 11.2 and 11.6, the maximum aggregate liability of the Service Provider under or in connection with the Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall in no event exceed an amount equal to the Fees the Client paid to the Service Provider in the six (6) months immediately preceding the event giving rise to the claim, or, if fewer than six months have passed since the Effective Date, 100% of the Fees attributable to the full calendar months that have passed since the Effective Date.
11.2 Nothing in the Agreement limits or excludes the liability of either Party for (a) death or personal injury caused by its negligence; (b) fraud or fraudulent misrepresentation; (c) gross negligence or willful misconduct; or (d) any other liability that cannot be limited or excluded under Applicable Laws.
11.3 Neither Party shall be liable to the other Party for any loss of use, goodwill, revenue, or profits, or for any incidental, indirect, special, consequential, or exemplary damages, howsoever caused, even if the Party has been advised of the possibility of such damages.
11.4 The Client acknowledges and agrees that the Services, including any AI-based features (such as automated outputs, classifications, recommendations or similar functionalities), may contain errors, inaccuracies, omissions, misclassifications, biases, or so-called "hallucinations", as provided in Section 5.
11.5 The Service Provider shall not be liable for any errors, unavailability, or malfunctions of the Services due to (a) Force Majeure Events; (b) the fault or failure of computer systems or networks (including fault or failure of the internet or any public telecommunications network, network overload, disturbances or malfunctions); (c) third-party integrations or the software or systems that make the Services available; (d) loss, alteration, or unauthorised access to the Client Data caused by circumstances outside the Service Provider's reasonable control; or (e) any errors, bugs or any inappropriate functioning or malfunctioning of the Services which results from any changes or modifications to the Services made by the Client or any third party acting on behalf of the Client.
11.6 The Service Provider's liability for the availability of the Services, maintenance, support, and incident management shall be defined, governed, and limited exclusively by the SLA. The Service Credits and other compensation set out in the SLA are the Client's sole and exclusive remedy, and the Service Provider's entire liability, for any failure to meet the availability or response targets set out in the SLA, and are applied as credits against subsequent invoices rather than paid as cash refunds. Any Service Credits granted count towards the aggregate cap in Section 11.1. In the event of any inconsistency between this Section 11 and the SLA in respect of availability, maintenance, support, or incident management, the SLA shall prevail.
12. Representations and Warranties
12.1 Each Party represents and warrants to the other that (a) the Party is properly constituted and incorporated under the respective Applicable Laws; (b) the Party has full authority to enter into and perform the Agreement; (c) the representative of the Party has all rights, including necessary internal corporate approvals (if applicable), necessary to enter into the Agreement; (d) the obligations of the Party set forth in the Agreement are valid, binding on and enforceable against the relevant Party; and (e) neither the signing nor the performance of the Agreement conflicts with or results in a violation of any provisions of any legal acts to which the Party is subject, any agreement or obligation binding on the Party, any judgment, order, injunction, decree or ruling of any court or governmental or local authority to which the Party is subject, or the terms and conditions of any licence or permit granted to the Party.
12.2 The Service Provider represents and warrants that (a) elements of the Services which constitute Open Source Software, if any, are delivered in a manner which is compliant with their licence terms; and (b) the Services are delivered in a manner which complies with Applicable Laws.
12.3 The Services, including AI-generated classifications, extractions, and assistant responses, are provided "as is" without any warranty of accuracy, completeness, or fitness for a particular purpose. Except as expressly set forth in the Agreement, the Service Provider disclaims all warranties and representations of any kind, whether express or implied, including but not limited to warranties of merchantability, non-infringement, or fitness for a particular purpose. The Service Provider makes no warranties regarding the use of the Services or the results obtained from such use, and the Client acknowledges that it has relied solely on the express warranties set forth in the Agreement.
12.4 The Client acknowledges and agrees that, while the Service Provider endeavours to deliver high-quality services, no software service can be guaranteed to be completely free from bugs or errors. Accordingly, the Service Provider does not represent or warrant that the Services will operate with 100% uptime or be entirely free from bugs and errors. Furthermore, the Service Provider disclaims any warranties regarding the acts and omissions of third-party vendors and hosting partners, including but not limited to their ability to provide the necessary hardware, software, networking, storage, and related technology required to deliver the Services. The Service Provider's obligations with respect to service availability and performance are solely as expressly set forth in the SLA.
13. Notices and Communications
13.1 Any notices, requests, or other communications to be given or made under the Agreement to a Party shall be directed, in the case of the Client, to the contact details specified by the Client in its Account and, in the case of the Service Provider, to the contact address published on the Platform. The Client is obliged to keep the contact details in its Account accurate and up to date.
13.2 All documents to be furnished or communications to be given or made under the Agreement shall be at least in a form that can be reproduced in writing and in the English language, unless the Parties agree otherwise.
14. Term and Termination
14.1 The term of the Agreement corresponds to the subscription period applicable to the Client's Subscription Plan, and renews automatically for successive periods of the same length unless terminated in accordance with this Section 14.
14.2 Neither Party may terminate the Agreement or the Client's Subscription Plan for convenience before the end of the then-current subscription period. Either Party may prevent the automatic renewal of the subscription period by giving notice to the other Party no later than 30 days before the end of the then-current subscription period, in which case the Agreement terminates at the end of that period. The Client may give such notice through its Account. Termination by non-renewal takes effect only at the end of the then-current subscription period, the Client retains access to the Services until that date, and no refund or credit of Fees is payable in respect of that period
14.3 In the event of termination:
(a) the Service Provider agrees to provide reasonable assistance to the Client for the smooth transition of the Services to another provider or to the Client itself, for a period not exceeding 3 months after termination. This assistance may include transferring data, providing necessary documentation, and support in migrating services;
(b) the Service Provider shall provide the Client with all Client Data, including Users' data in its possession, in a commonly used format, ensuring compliance with data protection laws and regulations. Unless legally required to retain it, the Service Provider shall delete the Client Data (including Users' data) in its possession within 90 days after the effective date of termination or upon confirmation of successful transfer, whichever is earlier;
(c) any final settlements, including outstanding payments , between the Parties shall be completed within 30 days following the effective date of termination. The terms for such settlements shall be based on the pre-existing contractual obligations and any additional agreements made during the termination process.
14.4 Termination of the Agreement does not release the Parties from their outstanding obligations arising from the Agreement and does not affect the rights or remedies of a Party arising out of breach of the Agreement.
14.5 Termination of the Agreement shall not affect the validity of such terms which by their nature survive the termination of the Agreement.
14.6 All Fees are non-refundable. Except where expressly stated otherwise in these Terms of Service or required by applicable law, the Client is not entitled to any refund or credit of prepaid Fees, whether in respect of an unused portion of a subscription period, unused capacity or Users, non-use of the Services, or termination or expiry of the Agreement for any reason.
15. Changes to These Terms of Service
15.1 The Service Provider may amend these Terms of Service, from time to time. Material amendments shall be notified to the Client at least 30 days before they take effect, by e-mail to the Client's designated contact and/or by a prominent notice in the Platform.
15.2 If a material amendment is adverse to the Client, the Client may terminate the Agreement with effect from the date the amendment takes effect by giving written notice before that date. The Client's continued use of the Services after the effective date of an amendment constitutes acceptance of the amended terms. Amendments do not apply retroactively.
16. Final Provisions
16.1 The Agreement constitutes the entire agreement between the Parties relating to the subject matter hereof and supersedes any previous communications, whether oral or written, between the Parties in respect of the subject matter hereof.
16.2 The Service Provider is an independent contractor and nothing in the Agreement shall render the Service Provider an employee or agent of the Client, and the Service Provider shall not present itself towards third persons as such.
16.3 Neither Party may transfer or otherwise assign any of its rights or obligations arising from the Agreement to a third party without the prior written consent of the other Party, except that the Service Provider may assign the Agreement in its entirety, without the Client's consent, to an Affiliate or in connection with a merger, acquisition, corporate reorganisation, or sale of all or substantially all of its assets, provided that the assignee assumes all obligations under the Agreement and the Client is notified in writing without undue delay.
16.4 The invalidity of any portion of the Agreement shall not render the Agreement itself or any other portion hereof invalid. If any provision of the Agreement is held invalid or unenforceable, the remaining provisions will remain in full force and effect. The Parties shall take due measures to replace the invalid or unenforceable provision with a provision that best reflects the intent of both Parties.
16.5 The Agreement is governed by and construed in accordance with the laws of the Republic of Estonia, excluding its conflict of laws rules.
16.6 All disputes arising from the Agreement shall be settled via negotiations. If an amicable settlement cannot be reached, the dispute shall be exclusively settled in accordance with the laws of the Republic of Estonia, in Harju County Court in Tallinn.
17. Glossary
The following capitalised terms and acronyms have the meanings assigned to them below, unless the context requires otherwise. These definitions apply throughout these Terms of Service and the documents comprising the Agreement.
Account means the central means of access to the Services;
Affiliate means an entity that is (a) directly or indirectly owning or controlling a Party; (b) under the same direct or indirect ownership or control as a Party; or (c) directly or indirectly controlled by a Party, for so long as such ownership or control lasts. Ownership or control shall exist through direct or indirect ownership of fifty per cent (50%) or more of the nominal value of the issued equity share capital or of fifty per cent (50%) or more of the shares entitling the holders to vote for the election of the members of the board of directors or persons performing similar functions;
Agreement means the software-as-a-service agreement described in Section 1.2, including all its constituent documents, as may be amended from time to time;
AI Model means a machine learning model or neural network trained on data, capable of making predictions, classifications, or generating text;
Applicable Laws means all local, state, national, and international laws, regulations, and treaties that apply to the Parties, the Agreement, and the subject matter of the Agreement, including, without limitation, all forms of statutes, regulations, judgments, injunctions, orders, and decrees, as well as any governmental authorisations, licences, and permits;
Client Data means all data, information, and materials provided, disclosed, or submitted by or on behalf of the Client to the Service Provider in connection with the Agreement, including, but not limited to, Personal Data, confidential business information, customer details, technical data, and any other information provided by the Client for the purpose of enabling the Service Provider to perform its obligations under the Agreement or as otherwise agreed upon by the Parties;
Confidential Information means the Agreement, the data and documentation related to the businesses and clients of a Party and its Affiliates, including know-how and all other specifications, trade secrets, technical information, software, models, designs, business information, unpatented technology, research information, statistical information and analyses, information on methods, processes and facilities related either to any software or business activities of any of the Parties. For the avoidance of doubt, client information shall be deemed to be confidential. However, information that was in the possession of the disclosing Party without an obligation of confidentiality before its disclosure and information that is generally available to the public shall not be deemed confidential;
Effective Date means the date on which the Client first accepts these Terms of Service, whether by creating an Account, subscribing to a Subscription Plan, or commencing use of the Services;
Fees means the service or other fees payable by the Client in consideration for the Services, further specified in Section 6 and the Service Provider's published price list;
Force Majeure Event means unforeseeable circumstances which the Party who has violated the obligation is unable to control and the prevention of which by the same cannot be expected proceeding from the principle of reasonableness. Force majeure events include but are not limited to severe acts of nature, war, riot, acts of terrorism, the activities of public authorities (e.g. the state, local government) and other circumstances independent of the parties (e.g. strike, the general failure of the computer system, failure of communications lines or power failure, denial-of-service attack);
GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), as well as other applicable data protection laws;
Intellectual Property Rights or IPR means all intellectual and industrial property rights and similar rights of whatever nature anywhere in the world, whether currently existing or coming into existence in the future, whether recorded or registered in any manner or otherwise, including (but not limited to) any copyrights and related rights, industrial design rights and other design rights, registered designs, patents, utility models, inventions (whether or not patentable), trademarks, service marks, database and software rights, rights to layout-designs of integrated circuits, trade secrets, know-how, confidential information, business names, trade names, brand names, domain names and all other legal rights anywhere in the world protecting such property, including, where applicable, all renewals, extensions and applications for registration, the right to apply for registration, and the right to sue for damages for past and then-current infringement in respect of any of the same;
Open Source Software means software that is, contains or is derived from software distributed as freeware, shareware or open source software, or under similar licensing or distribution models that (a) require the licensing, disclosure or distribution of source code to any other person; (b) prohibit or limit the receipt of consideration in connection with licensing or distributing any software; (c) allow any person to decompile, disassemble or reverse engineer any software; (d) require the licensing or distribution of any software to any other person for the purpose of making derivative works; (e) are identified by the Open Source Initiative as open source licensing or distribution models at www.opensource.org; or (f) are identified by the Free Software Foundation as free software licences at www.gnu.org;
Personal Data means any information relating to an identified or identifiable natural person as defined in the GDPR;
Service Levels means the target performance levels applicable to the Services and any other service levels provided in the SLA;
Services means services provided by the Service Provider under the Agreement, including the Franklin platform, as well as any other services agreed upon by the Parties from time to time;
Subscription Plan means the subscription tier, scope, and term selected by the Client in its Account when subscribing to the Services, priced in accordance with the Service Provider's published price list in force at the time of subscription;
User means any individual who is authorised by the Client to access and use the Services under the Agreement, including, but not limited to, the Client's employees, representatives, consultants, contractors, agents, or other entities authorised by the Client.
Service Level Agreement
This ANNEX 1 “Service Level Agreement” is an integral part of the provision of services by the Service Provider to the Client in accordance with the main Agreement. The capitalised terms used in this Service Level Agreement shall have the meaning assigned to them in the main Agreement.
-
Scope and Subject
-
The Service Provider undertakes to provide the Client with the
following ancillary services regarding the Services:
- Availability;
- Incident Management;
- Support;
- Maintenance and Updates.
-
The Service Provider undertakes to provide the Client with the
following ancillary services regarding the Services:
-
Availability
- The Service Provider shall ensure that the Services are available at least 90% of the total time. The Services availability is calculated as the cumulative availability of all requests of the Services, by taking into account successful requests divided by total requests in a calendar month (excluding time spent under maintenance) (the Availability).
-
Service Credits
- In the event that the Service Provider fails to meet the Availability, Service Credits will be granted to the Client at the latter’s request.
-
The following sums shall be credited to the Client if the
Service Provider fails to meet the following availability
criteria (the Service Credits):
- if below 90% availability –10% of the monthly fee;
- The Service Credits are not cash refunds but are instead applied to the next month’s invoice issued to the Client for payment of the Fee.
- To be eligible for Service Credits, the Client must notify the Service Provider of its intent to claim such Service Credits within fifteen (15) days following the end of the calendar month during which the Client first became entitled to the Service Credit. Failure to comply with this notification requirement within the specified timeframe will result in the Client forfeiting the right to receive the Service Credit for that particular incident.
- This Section 3 states the entire liability of the Service Provider and the Client’s sole and exclusive remedies regarding the Availability.
-
Maintenance and Scheduled Interruptions
- The Service Provider shall maintain the Services and its availability during the term of the Agreement.
- The Service Provider shall maintain the Plaform in a cloud. The maintenance costs are borne by the Client as part of the Fee.
- The Service Provider shall notify the Client in advance of planned interruptions to improve the functionality, add new features, solve errors, or otherwise improve the operation of the Services.
-
Incident Management
- The Service Provider provides an incident management service to the Client (the Incident Management), which is differentiated based on incidents occurring within or outside of working time. At this time, the Service Provider is unable to provide a resolution time, but can deliver on the time to own requirements and provides constant communication with the Client in order to swiftly resolve any critical incidents.
|
Priority |
Severity |
Description |
Time To Own |
Rectification of error |
Process |
|
09:00-17:00 (EET) |
|||||
|
0 |
Blocking |
1) Usage completely blocked for all 2) Major business-critical functions unavailable for all |
30 minutes |
Continuously during support hours until: The problem is solved or degraded to a lower severity. |
Manual |
|
1 |
Critical |
1) Critical function with a major impact on usage 2) Completely blocked usage for a moderate number of users 3) Critical error but workaround available |
2 hours |
Continuously during support hours until: The problem is solved or degraded to a lower severity. |
Manual |
|
2 |
Normal (default) |
1) Malfunction is minor; not critical 2) Minimal number of users affected and/or not in a significant way |
8 hours |
During support hours, provided no higher priority incidents need managing at that time. |
Manual |
|
3 |
Trivial |
Cosmetic |
40 hours |
Provide the resolution with the next update, if feasible. |
Manual |
-
-
If the Client discovers any errors in the Services, the
designated persons of the Client shall inform the Service
Provider, providing at least the following information:
- time of occurrence;
- detailed description of the error (with pictures), log extract, relevant technical identifiers;
- description of activities performed immediately prior to the error occurring.
- The Service Provider shall use all commercially reasonable efforts to respond to the Client’s error reports in accordance with the severity of the incident.
- In the event that the Service Provider fails to meet the time to own targets outlined in Section 5.1, the Client shall be entitled to compensation of 10%.
- The maximum limit on the compensation that the Client can accrue in a given month is 50%.
- To claim the compensation, the Client has to submit a notification to the Service Provider, detailing the percentage of compensation the Client is eligible for the calendar month.
- The compensation for Incident Management is not a cash refund but is instead applied to the next invoice for payment of the Fee issued to the Client.
- This Section 5 provides the entire liability of the Service Provider and the Client’s sole and exclusive remedies regarding the Incident Management.
-
If the Client discovers any errors in the Services, the
designated persons of the Client shall inform the Service
Provider, providing at least the following information:
-
Support
-
The Client may require support from the Service Provider from
time to time (the Support) such as:
- manned telephone support;
- monitored email support;
- proactive real-time monitoring of the software;
- remote assistance in the event of system failure;
- software troubleshooting.
- Fees for these Support services are detailed in the Service Provider's published Subscription Plan.
-
The Client may require support from the Service Provider from
time to time (the Support) such as:
-
Final Provisions
- The terms and conditions of the main Agreement shall apply to this Service Level Agreement accordingly.
- In the event of any discrepancy between the provisions of this Service Level Agreement and the main Agreement, the provisions of this Service Level Agreement shall prevail.
TECHNICAL AND ORGANISATIONAL MEASURES
This ANNEX 2 “Technical and Organisational Measures” is an integral part of the provision of services by the Service Provider to the Client in accordance with the main Agreement. The capitalised terms used in this ANNEX 2 shall have the meaning assigned to them in the main Agreement.
1. Access Control
- Row-Level Security (RLS) in PostgreSQL ensures that every table is scoped by organization_id, so users can only access data for their organization
- JWT-based authentication with OAuth support (Supabase Auth) for secure user login
- Role-based access control with 5 defined roles: org_owner, mgmt_dev_manager, project_manager, project_member, share_link_user
- RLS-protected storage buckets with signed URLs for document access
2. Encryption
- TLS encryption in transit for all API calls (HTTPS/TLS 1.2+)
- Encryption at rest for sensitive data in the database (to be confirmed with Supabase configuration)
- Secure token generation for share links
3. Network Security
- Defense in Depth: security enforced at UI, API, and database layers
- API-level validation and authorization checks
- Domain-Driven Design with explicit business domain boundaries
- Rate limiting and DDoS protection (managed by Supabase and Vercel)
4. Data Minimization
- Only necessary Personal Data is collected and processed
- Automatic document processing includes only text and image content necessary for classification
- Optional Room Extractor functionality is limited to architectural plan analysis
5. Audit Logging and Monitoring
- System logs and audit trails record user actions, timestamps, and IP addresses
- Error tracking via Sentry for security monitoring and incident response
- Logs are retained per legal requirements
- Regular security reviews and vulnerability assessments
6. Incident Management
- Incident detection and response protocols
- Post-incident review and remediation
7. Personnel Security
- Staff training on data protection and security
- Confidentiality agreements with employees
- Access to Personal Data restricted to authorized personnel only
8. Infrastructure provider Security
- AI providers (OpenAI, Google, Mistral) maintain their own security controls and certifications
- Supabase, Render, Vercel, and Sentry are industry-standard providers with SOC 2 certifications or equivalent
- Regular reviews of infrastructure provider security controls