Public Terms

Last updated: May 29, 2026

AGREEMENT TO OUR PUBLIC TERMS

We are Bohdan Matviichuk ("Company," "we," "us," "our"), a company registered in Poland at ul. Dziewanny 21/19, 20-539 Lublin. Our VAT number is PL7123452217.

We operate the website https://planvault.ai (the "Site"), related public pages, documentation, demo-request and support forms, policy pages, and any PlanVault™ product surface that expressly links to these public terms (collectively, the "Public Services"). PlanVault™ is secure AI orchestration software for customer-controlled B2B deployments, helping businesses integrate AI capabilities with their tools and data, with built-in access control, usage tracking, and runtime audit features.

You can contact us by email at support@planvault.ai or by mail to ul. Dziewanny 21/19, 20-539 Lublin, Poland.

These Public Terms constitute a legally binding agreement made between you, whether personally or on behalf of an entity ("you"), and Bohdan Matviichuk, concerning your access to and use of the Public Services. By accessing the Public Services, you agree that you have read, understood, and agreed to be bound by these Public Terms. IF YOU DO NOT AGREE WITH THESE PUBLIC TERMS, THEN YOU MUST NOT ACCESS OR USE THE PUBLIC SERVICES.

THE PUBLIC SERVICES AND PLANVAULT PRODUCT ARE INTENDED STRICTLY FOR BUSINESS, COMMERCIAL, AND PROFESSIONAL USE (B2B). By accessing or using the Public Services for business evaluation, procurement, support, documentation, or product-related purposes, you represent and warrant that you are acting in a professional or commercial capacity on behalf of a legal entity or a business, and not as a "consumer" within the meaning of Article 22¹ of the Polish Civil Code, Article 2(1) of Directive 2011/83/EU on consumer rights, or any equivalent provision of applicable consumer-protection law. If mandatory consumer-protection rights apply to a visitor despite this B2B scope, nothing in these Public Terms excludes or limits those mandatory rights. If you cannot make the B2B representation for product-related use, you must not request access to, evaluate, procure, or use PlanVault™.

Customer deployments are governed primarily by a signed written agreement. PlanVault™ is not offered as a self-serve public SaaS for production use. Production deployments are customer-controlled and are made available under a separate written agreement, such as an Enterprise Agreement, Master Services Agreement, License Agreement, Order Form, Data Processing Agreement, Pilot Agreement, Design Partner Agreement, statement of work, or other written amendment signed or otherwise accepted by the parties (a "Customer Agreement").

Precedence of documents (order of priority). If you or the legal entity on whose behalf you act have a Customer Agreement with us that governs the same subject matter, that Customer Agreement prevails over these Public Terms and the other policies listed below in the event of any conflict or inconsistency, to the extent of that conflict. Absent such a Customer Agreement, the following order of priority applies from highest to lowest: (1) any Order Form, statement of work, or written amendment signed by both parties and expressly referencing these Public Terms; (2) these Public Terms; (3) the Acceptable Use Policy (https://planvault.ai/acceptable-use); (4) the Privacy Policy (https://planvault.ai/privacy), Cookie Policy (https://planvault.ai/cookies), and Security Page (https://planvault.ai/security); and (5) any other operating rules, product documentation, or help-center articles we publish. This precedence rule does NOT waive any statutory data-protection obligation owed to data subjects.

Some customer-controlled deployments may present an in-product acknowledgement or policy notice to administrators or users. Where that happens, the notice is for the deployment, policy versioning, audit, or Customer Agreement workflow described in that environment; it does not make these Public Terms override a Customer Agreement. Any personal data recorded as policy evidence, such as version, timestamp, IP address, or User-Agent, is handled as described in the Privacy Policy and any applicable Customer Agreement.

The Public Services are intended for users who are at least 18 years old. Persons under the age of 18 are not permitted to use the Public Services.

We recommend that you print a copy of these Public Terms for your records.

1. SCOPE OF THE PUBLIC SERVICES

The Public Services include the Site, public documentation, marketing materials, legal and policy pages, support and contact channels, demo-request flows, public API references, and any product surface that expressly links to these Public Terms. They do not, by themselves, grant a production license to install, host, operate, resell, or provide PlanVault™ to third parties.

Production use, evaluation environments, support commitments, license keys, deployment scope, service levels, implementation services, security obligations, data-processing terms, fees, renewal, and termination rights are governed by the applicable Customer Agreement. If no Customer Agreement applies, you may use the Public Services only for lawful B2B evaluation, informational, contact, and documentation purposes.

The information provided through the Public Services is not intended for distribution to or use by any person or entity in any jurisdiction or country where such distribution or use would be contrary to law or regulation or would subject us to any registration requirement. Persons who access the Public Services from other locations do so on their own initiative and are solely responsible for compliance with local laws, if and to the extent local laws apply.

PlanVault™ is not represented as certified for industry-specific regulatory regimes unless a Customer Agreement expressly says so. If your deployment or workload is subject to sector-specific obligations such as HIPAA, FISMA, GLBA, financial-services outsourcing rules, public-sector procurement rules, or regulated medical-device requirements, you are responsible for confirming the applicable legal and contractual requirements before using PlanVault™.

2. INTELLECTUAL PROPERTY RIGHTS

Our intellectual property We are the owner or the licensee of all intellectual property rights in the Public Services and PlanVault™ product, including source code, databases, functionality, software, website designs, audio, video, text, photographs, graphics, documentation, interfaces, product names, trademarks, service marks, and logos (collectively, the "Content" and "Marks").

Our Content and Marks are protected by copyright and trademark laws (and various other intellectual property rights and unfair competition laws) and treaties around the world.

The Content and Marks are provided in or through the Public Services "AS IS" for your internal business purpose only. Subject to your compliance with these Public Terms, including the "PROHIBITED ACTIVITIES" section below, we grant you a non-exclusive, non-transferable, revocable license to access the Public Services and download or print a copy of any portion of the Content to which you have properly gained access, solely for your internal business purpose.

Except as set out in this section, in a Customer Agreement, or elsewhere in these Public Terms, no part of the Public Services, PlanVault™ product, Content, or Marks may be copied, reproduced, aggregated, republished, uploaded, posted, publicly displayed, encoded, translated, transmitted, distributed, sold, licensed, hosted, sublicensed, or otherwise exploited for any commercial purpose without our express prior written permission.

If you wish to make any use of the Public Services, Content, or Marks other than as set out in this section, a Customer Agreement, or elsewhere in these Public Terms, please address your request to: support@planvault.ai. If we grant you permission to post, reproduce, or publicly display any part of our Public Services or Content, you must identify us as the owners or licensors of the Public Services, Content, or Marks and ensure that any copyright or proprietary notice appears or is visible on posting, reproducing, or displaying our Content.

We reserve all rights not expressly granted to you in and to the Public Services, PlanVault™ product, Content, and Marks. Any breach of these Intellectual Property Rights will constitute a material breach of these Public Terms and may terminate your right to use the Public Services immediately. Your submissions Please review this section and the "PROHIBITED ACTIVITIES" section carefully prior to using the Public Services to understand the (a) rights you give us and (b) obligations you have when you send us free-form product feedback.

Submissions (scope): For the purposes of this section, "Submissions" means free-form product feedback that you voluntarily provide to us about the Public Services or PlanVault™ product — for example bug reports, feature requests, suggestions, comments, ideas, questions, or other feedback sent to support@planvault.ai, posted in a feedback form, or otherwise communicated to us outside the normal operation of a customer deployment. "Submissions" expressly does NOT include Customer Content (as defined in Section 7), including prompts, API requests and payloads, session or runtime content, tool inputs and outputs, uploaded files, configuration, credentials, logs, deployment data, or personal data submitted through an admin console, Runtime API, MCP interface, webhook, or other documented product interface. Customer Content is governed by Section 7 (Customer Content and Runtime Data), Section 25 (Customer Data and AI Service Providers), and any Customer Agreement that applies, and no license is granted to us over Customer Content under these Public Terms.

Submissions (license): By sending us a Submission as scoped above, you grant us a non-exclusive, royalty-free, worldwide, perpetual, irrevocable license to use, reproduce, modify, and incorporate such Submission for the limited purpose of operating, improving, and supporting the Public Services and PlanVault™ product. We will not commercially redistribute, sublicense, or transfer Submissions to unaffiliated third parties as a stand-alone product. You are not required to provide Submissions; if you choose to provide them, you confirm that you have the rights necessary to grant this license.

You are responsible for what you submit: By sending us Submissions you: confirm that you have read and agree with our "PROHIBITED ACTIVITIES" and will not send us any Submission that is illegal, harassing, hateful, harmful, defamatory, obscene, bullying, abusive, discriminatory, threatening to any person or group, sexually explicit, false, inaccurate, deceitful, or misleading; to the extent permissible by applicable law, waive any and all moral rights to any such Submission; warrant that any such Submission is original to you or that you have the necessary rights and licenses to grant us the license above; and warrant and represent that your Submissions do not constitute confidential information of you or any third party. You are solely responsible for your Submissions and you expressly agree to reimburse us for any and all losses that we may suffer because of your breach of (a) this section, (b) any third party’s intellectual property rights, or (c) applicable law. Copyright infringement We respect the intellectual property rights of others. If you believe that any material available on or through the Public Services infringes upon any copyright you own or control, please immediately refer to the "COPYRIGHT INFRINGEMENTS" section below.

3. USER REPRESENTATIONS

By using the Public Services, you represent and warrant that: (1) all registration, contact, demo-request, support, and evaluation information you submit will be true, accurate, current, and complete; (2) you will maintain the accuracy of such information and promptly update it as necessary; (3) you have the legal capacity and authority to comply with these Public Terms on behalf of the organization you represent; (4) you are not a minor in the jurisdiction in which you reside; (5) except for programmatic access expressly permitted under Section 26 (Programmatic Access), you will not access the Public Services through automated or non-human means, whether through a bot, script, scraper, crawler, or otherwise; (6) you will not use the Public Services for any illegal or unauthorized purpose; (7) your use of the Public Services will not violate any applicable law or regulation; and (8) you are accessing and using the Public Services exclusively for business, commercial, or professional purposes, on behalf of a legal entity or a business, and not as a "consumer" within the meaning of Article 22¹ of the Polish Civil Code or Article 2(1) of Directive 2011/83/EU, and you are not an individual entrepreneur whose purchase is unconnected with their professional activity within the meaning of Article 385⁵ of the Polish Civil Code.

If you provide any information that is untrue, inaccurate, not current, incomplete, or submitted without authority, we may reject the submission, suspend or terminate access to the relevant Public Services, decline a demo or support request, or take other appropriate action.

4. USER REGISTRATION

The public Site does not provide self-serve production registration. If we provide an evaluation, demo, support portal, documentation account, license portal, or customer-controlled deployment account, you agree to keep your credentials confidential and to be responsible for activity under credentials assigned to you or your organization. Access provisioning, role administration, and account lifecycle for a customer-controlled deployment are governed by the applicable Customer Agreement and deployment configuration.

5. PURCHASES AND PAYMENT

We do not sell self-serve SaaS subscriptions or process purchases through the public Site. Fees, taxes, payment terms, license metrics, renewal, refund, suspension, professional services, and support commitments apply only if stated in a Customer Agreement, Order Form, statement of work, or other written commercial document accepted by the parties.

Submitting a demo request, support request, early-access form, or other contact form does not create a paid subscription, production license, or obligation for us to provide PlanVault™. If you provide account, billing, procurement, security-review, or contact information, you agree to keep that information current, complete, and accurate so we can communicate with you about the relevant request or Customer Agreement.

6. PROHIBITED ACTIVITIES

This Section 6, together with the Acceptable Use Policy (https://planvault.ai/acceptable-use), constitutes the rules on use of the Public Services and, where applicable, PlanVault™ product surfaces for the purposes of Article 14 of Regulation (EU) 2022/2065 (Digital Services Act). It is presented here in clear and unambiguous language so that users can foresee the consequences of breach.

You may not access or use the Public Services or PlanVault™ product for any purpose other than lawful internal business evaluation, documentation, support, contact, and authorized product use under a Customer Agreement. Without our prior written approval, you may not resell access to the Public Services or PlanVault™ product, operate PlanVault™ as a standalone managed service for unrelated third parties, provide outsourced access to unaffiliated organizations, or use PlanVault™ primarily to build or operate a competing orchestration product (see also the "Competitive Use" rule below).

As a user of the Public Services or PlanVault™ product, you agree not to:

  • Systematically retrieve data or other content from the Public Services or PlanVault™ product to create or compile, directly or indirectly, a collection, compilation, database, or directory without written permission from us.
  • Trick, defraud, or mislead us and other users, especially in any attempt to learn sensitive account information such as user passwords.
  • Circumvent, disable, or otherwise interfere with security-related features of the Public Services or PlanVault™ product, including features that prevent or restrict the use or copying of any Content or enforce limitations on use of the Public Services, PlanVault™ product, or Content contained therein.
  • Use any information obtained from the Public Services or PlanVault™ product in order to harass, abuse, or harm another person.
  • Make improper use of our support services or submit false reports of abuse or misconduct.
  • Use the Public Services or PlanVault™ product in a manner inconsistent with any applicable laws or regulations.
  • Engage in unauthorized framing of or linking to the Public Services.
  • Upload or transmit (or attempt to upload or to transmit) viruses, Trojan horses, or other material, including excessive use of capital letters and spamming (continuous posting of repetitive text), that interferes with any party’s uninterrupted use and enjoyment of the Public Services or PlanVault™ product or modifies, impairs, disrupts, alters, or interferes with their use, features, functions, operation, or maintenance.
  • Except as permitted under Section 26 (Programmatic Access), engage in any automated use of the Public Services or PlanVault™ product, such as using scripts to send comments or messages, or using any data mining, robots, or similar data gathering and extraction tools.
  • Delete the copyright or other proprietary rights notice from any Content.
  • Attempt to impersonate another user or person or use the username of another user.
  • Upload or transmit (or attempt to upload or to transmit) any material that acts as a passive or active information collection or transmission mechanism, including without limitation, clear graphics interchange formats ("gifs"), 1×1 pixels, web bugs, cookies, or other similar devices (sometimes referred to as "spyware" or "passive collection mechanisms" or "pcms").
  • Interfere with, disrupt, or create an undue burden on the Public Services, PlanVault™ product, or the networks or services connected to them.
  • Harass, annoy, intimidate, or threaten any of our employees or agents engaged in providing any portion of the Public Services or PlanVault™ product to you.
  • Attempt to bypass any measures designed to prevent or restrict access to the Public Services, PlanVault™ product, or any portion of them.
  • Copy or adapt PlanVault™ software, including but not limited to front-end assets, server-side components, or other code comprising the product, except as expressly permitted by a Customer Agreement.
  • Except as permitted by applicable law or a Customer Agreement, decipher, decompile, disassemble, or reverse engineer any software comprising or in any way making up a part of the Public Services or PlanVault™ product.
  • Except as permitted under Section 26 (Programmatic Access) and except as may be the result of standard search engine or Internet browser usage, use, launch, develop, or distribute any automated system, including without limitation, any spider, robot, cheat utility, scraper, or offline reader that accesses the Public Services, or use or launch any unauthorized script or other software.
  • Use a buying agent or purchasing agent to make purchases through the Public Services.
  • Make any unauthorized use of the Public Services or PlanVault™ product, including collecting usernames and/or email addresses by electronic or other means for the purpose of sending unsolicited email, or creating accounts, demo requests, support requests, organizations, deployments, or API credentials by automated means or under false pretenses.
  • Use the Public Services, PlanVault™ product, or Content as part of any effort to compete with us or otherwise use them for an unauthorized revenue-generating endeavor or commercial enterprise.
  • Use the Public Services or PlanVault™ product to advertise or offer to sell goods and services without our prior written approval.
  • Sell or otherwise transfer your account, deployment access, license key, API credential, or profile except as expressly permitted by a Customer Agreement.
  • Malicious AI Usage: Using the Public Services or PlanVault™ product to generate, route, or facilitate illegal, abusive, or harmful content (e.g., malware, phishing, spam)
  • System Abuse: Circumventing rate limits, usage quotas, license checks, or billing mechanisms.
  • Reverse Engineering: Attempting to decompile or reverse-engineer the platform, tool retrieval logic, or underlying LLM models.
  • Competitive Use: Using the runtime API or admin console to build a competing AI orchestration platform or service.
  • Unauthorized Data Access: Attempting to access, modify, or delete data belonging to other organizations or users within the platform, or bypassing multi-tenant access controls.
  • Credential Misuse: Sharing, publishing, or exposing API keys, authentication tokens, license keys, or other credentials generated by or used within the platform.
  • Automated Scraping: Using bots, scrapers, or automated tools to extract data, content, or metadata from the Public Services or PlanVault™ product outside of the documented API.

7. CUSTOMER CONTENT AND RUNTIME DATA

PlanVault™ can allow a customer organization to submit data and content as part of using a customer-controlled deployment — for example prompts, API requests and payloads, tool inputs and outputs, configuration, uploaded files, credentials you configure, session or runtime content, deployment metadata, and related materials submitted through an admin console, Runtime API, webhook, MCP interface, or other documented product interface (together, "Customer Content"). PlanVault™ does not operate as a public forum, social network, or open user-to-user content platform. Customer Content is processed in connection with the applicable customer environment, deployment instructions, Customer Agreement, and Acceptable Use Policy (https://planvault.ai/acceptable-use).

Ownership of Customer Content. As between you and us, you (and/or your licensors) retain all right, title, and interest in and to Customer Content, including all intellectual property rights. No license to Customer Content is granted to us under these Public Terms. For the avoidance of doubt, Customer Content is NOT a "Submission" under Section 2, and the IP assignment, license grant, and similar provisions in Section 2 do NOT apply to Customer Content. This Section 7, together with Section 25 (Customer Data and AI Service Providers), applies only as a public baseline unless a Customer Agreement says otherwise.

Limited operational authority. Where we need access to Customer Content to provide support, implementation, security investigation, maintenance, migration, or other services requested by the customer, we will access, store, transmit, process, or display Customer Content only to the extent necessary for those purposes and subject to the applicable Customer Agreement, documented deployment controls, and data-protection terms. In a customer-controlled deployment, the customer determines the hosting environment, provider credentials, routing configuration, retention settings, and whether optional features such as Semantic Routing Cache are enabled. We will not use Customer Content to train any foundation model or other AI model operated by us and will not sell Customer Content.

Your responsibility. You must ensure you have all rights and a valid lawful basis to submit Customer Content and to authorize any processing requested from us. The "PROHIBITED ACTIVITIES" rules in Section 6 (subject to Section 26 for programmatic access), Section 25 (Customer Data and AI Service Providers), the Acceptable Use Policy, and any Customer Agreement apply to Customer Content.

8. CONTRIBUTION LICENSE

You and we agree that we may access, store, process, and use information and personal data that you provide through the Public Services in accordance with the Privacy Policy and your choices (including settings). Customer Content in a customer-controlled deployment remains governed by Section 7, Section 25, and the applicable Customer Agreement.

By submitting suggestions or other feedback regarding the Public Services or PlanVault™ product, you agree that we can use such feedback to operate, improve, and support PlanVault™ without compensation to you, subject to the Customer Content carve-out in Section 2.

9. THIRD-PARTY WEBSITES AND CONTENT

The Public Services may contain (or you may be sent via the Site) links to other websites ("Third-Party Websites") as well as articles, photographs, text, graphics, pictures, designs, music, sound, video, information, applications, software, and other content or items belonging to or originating from third parties ("Third-Party Content"). Such Third-Party Websites and Third-Party Content are not investigated, monitored, or checked for accuracy, appropriateness, or completeness by us, and we are not responsible for any Third-Party Websites accessed through the Public Services or any Third-Party Content posted on, available through, or installed from the Public Services, including the content, accuracy, offensiveness, opinions, reliability, privacy practices, or other policies of or contained in the Third-Party Websites or the Third-Party Content. Inclusion of, linking to, or permitting the use or installation of any Third-Party Websites or any Third-Party Content does not imply approval or endorsement. If you decide to leave the Public Services and access Third-Party Websites or use Third-Party Content, you do so at your own risk, and you should be aware these Public Terms no longer govern. You should review the applicable terms and policies of any third-party website, application, model provider, infrastructure provider, or integration you choose to use.

10. SERVICES MANAGEMENT

We reserve the right, but not the obligation, to: (1) monitor the Public Services for violations of these Public Terms; (2) take appropriate legal action against anyone who violates the law or these Public Terms, including reporting a user to law enforcement authorities where appropriate; (3) refuse, restrict, or disable access to the Public Services or public contact channels where necessary to protect security, availability, rights, property, or legal compliance; (4) remove or disable public submissions, form entries, files, or content that are unlawful, abusive, excessive in size, malicious, or burdensome to our systems; and (5) otherwise manage the Public Services in a manner designed to protect our rights and property and facilitate their proper functioning. Customer deployment management, suspension, support access, and remediation rights are governed by the applicable Customer Agreement.

11. PRIVACY POLICY

We care about data privacy and security. Our Privacy Policy (https://planvault.ai/privacy), Cookie Policy (https://planvault.ai/cookies), and Security page (https://planvault.ai/security) describe how we process personal data and our security posture. By using the Public Services, you acknowledge those policies where applicable.

Customer production deployments follow the customer's infrastructure choices; data residency and connected providers depend on the customer deployment.

12. COPYRIGHT INFRINGEMENTS

We respect the intellectual property rights of others. If you believe that any material available on or through the Public Services infringes upon any copyright you own or control, please immediately notify us using the contact information provided below (a "Notification"). A copy of your Notification may be sent to the person or organization responsible for the material addressed in the Notification where appropriate. Please be advised that pursuant to applicable law you may be held liable for damages if you make material misrepresentations in a Notification. Thus, if you are not sure that material located on or linked to by the Public Services infringes your copyright, you should consider first contacting an attorney.

13. TERM AND TERMINATION

These Public Terms remain in full force and effect while you use the Public Services. Without limiting any other provision of these Public Terms, we may deny, suspend, restrict, or terminate access to the Public Services (including blocking certain IP addresses) where we reasonably believe this is necessary to address breach, abuse, unlawful conduct, security risk, operational risk, or non-compliance with applicable law.

If we terminate or suspend public access, you are prohibited from creating a new account, request, or submission under a false, borrowed, or unauthorized identity. Customer deployment termination, license expiry, data return, data deletion, support wind-down, and post-termination obligations are governed by the applicable Customer Agreement.

14. MODIFICATIONS AND INTERRUPTIONS

We may change, modify, or remove public content on the Public Services at any time. We have no obligation to update public information, although we aim to keep legal, security, and product materials accurate as they evolve. Public descriptions, roadmap statements, screenshots, diagrams, API examples, and documentation are informational unless a Customer Agreement expressly incorporates them.

We cannot guarantee that the Public Services will be available at all times. We may experience hardware, software, network, security, or maintenance issues resulting in interruptions, delays, or errors. Service levels, maintenance windows, release obligations, update rights, support obligations, and remedies for customer-controlled deployments apply only as stated in a Customer Agreement.

15. GOVERNING LAW

These Public Terms are governed by and construed in accordance with the laws of Poland, and the application of the United Nations Convention on Contracts for the International Sale of Goods is expressly excluded. Subject to any Customer Agreement that states a different forum or governing law, the parties irrevocably submit to the exclusive jurisdiction of the competent courts of Lublin, Poland for any dispute, claim, or controversy arising out of or in connection with these Public Terms or the Public Services (including their formation, validity, interpretation, performance, breach, or termination), and each party irrevocably waives any objection it may have at any time to the laying of venue in those courts, any claim that a proceeding has been brought in an inconvenient forum (forum non conveniens), and any claim that those courts lack personal jurisdiction. This exclusive choice-of-court provision is made pursuant to Article 25 of Regulation (EU) No 1215/2012 (Brussels I-bis). The Public Services are offered for business-to-business purposes (see AGREEMENT TO OUR PUBLIC TERMS and Section 3); however, nothing in this Section 15 excludes any mandatory forum, venue, or applicable-law protection that cannot be waived under applicable law. Nothing in this Section 15 prevents either party from (i) seeking urgent injunctive or other interim protective relief in any court of competent jurisdiction where such relief is necessary to preserve the status quo, prevent immediate and irreparable harm, or enforce intellectual-property rights, or (ii) enforcing a final judgment obtained in the courts of Lublin, Poland in any other jurisdiction where enforcement is sought.

16. CORRECTIONS

There may be information on the Public Services that contains typographical errors, inaccuracies, or omissions, including product descriptions, deployment descriptions, roadmap references, pricing references, availability, legal summaries, and other information. We reserve the right to correct any errors, inaccuracies, or omissions and to change or update public information at any time, without prior notice.

17. DISCLAIMER

THE PUBLIC SERVICES ARE PROVIDED ON AN AS-IS AND AS-AVAILABLE BASIS. TO THE FULLEST EXTENT PERMITTED BY LAW, AND SUBJECT TO ANY CUSTOMER AGREEMENT THAT EXPRESSLY STATES OTHERWISE, WE DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, IN CONNECTION WITH THE PUBLIC SERVICES AND YOUR USE THEREOF, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT. PUBLIC PRODUCT MATERIALS, DOCUMENTATION, SECURITY DESCRIPTIONS, ROADMAPS, API EXAMPLES, AND DEPLOYMENT GUIDANCE ARE PROVIDED FOR INFORMATIONAL PURPOSES AND DO NOT CREATE A WARRANTY, SERVICE LEVEL, SECURITY COMMITMENT, PROFESSIONAL ADVICE, OR CERTIFICATION UNLESS EXPRESSLY INCORPORATED INTO A CUSTOMER AGREEMENT.

18. LIMITATIONS OF LIABILITY

IN NO EVENT WILL WE OR OUR DIRECTORS, EMPLOYEES, OR AGENTS BE LIABLE TO YOU OR ANY THIRD PARTY FOR ANY INDIRECT, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFIT, LOST REVENUE, LOSS OF DATA, PROCUREMENT OF SUBSTITUTE SERVICES, OR OTHER DAMAGES ARISING FROM YOUR USE OF THE PUBLIC SERVICES, EVEN IF WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. SUBJECT TO ANY CUSTOMER AGREEMENT THAT EXPRESSLY STATES OTHERWISE, OUR LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF ACTION ARISING FROM THE PUBLIC SERVICES WILL AT ALL TIMES BE LIMITED TO 1,000 (EUR).

The exclusions and the EUR 1,000 cap in this Section 18 shall NOT apply to, and shall not be construed as limiting: (a) any data-subject claim against the Company under Article 82(1) GDPR (the data subject is not a party to these Public Terms and any joint-and-several allocation between the Company and the Customer under Article 82(4) GDPR remains unaffected by inter-party caps); (b) liability arising from a party's wilful misconduct ("wina umyślna") or gross negligence ("rażące niedbalstwo"), to the extent that such liability cannot be limited under Article 473 §2 of the Polish Civil Code; (c) liability for personal injury or death caused by negligence; (d) liability for infringement of the other party's intellectual property rights; (e) the indemnification obligations under Section 19; and (f) any other liability that, under mandatory provisions of applicable law, cannot be excluded or limited.

For paid customer deployments, evaluation programs, support, implementation, or licensed product use, the applicable liability allocation is set in the Customer Agreement. These Public Terms do not reduce any liability cap, exclusion, service credit, indemnity, or remedy expressly agreed in a Customer Agreement.

19. INDEMNIFICATION

You agree to defend, indemnify, and hold us harmless, including our subsidiaries, affiliates, and all of our respective officers, agents, partners, and employees, from and against any loss, damage, liability, claim, or demand, including reasonable attorneys’ fees and expenses, made by any third party due to or arising out of: (1) misuse of the Public Services; (2) breach of these Public Terms; (3) any breach of your representations and warranties set forth in these Public Terms; (4) your violation of the rights of a third party, including intellectual property, privacy, or data-protection rights; or (5) your unlawful or unauthorized submission of Customer Content, credentials, personal data, or third-party material. Notwithstanding the foregoing, we reserve the right, at your expense, to assume the exclusive defense and control of any matter for which you are required to indemnify us, and you agree to cooperate, at your expense, with our defense of such claims. We will use reasonable efforts to notify you of any claim, action, or proceeding subject to this indemnification upon becoming aware of it. Any indemnity in a Customer Agreement prevails for the customer deployment it governs.

20. USER DATA

We may maintain certain data that you transmit through the Public Services for the purpose of operating the Site, responding to requests, maintaining security, preserving legal evidence, and managing the performance of the Public Services, as described in the Privacy Policy. For customer-controlled deployments, backup scope, retention, export, deletion, disaster recovery, and responsibility for Customer Content are governed by the Customer Agreement and the customer's deployment choices.

21. ELECTRONIC COMMUNICATIONS, TRANSACTIONS, AND SIGNATURES

Visiting the Public Services, sending us emails, and completing online forms constitute electronic communications. You consent to receive electronic communications, and you agree that agreements, notices, disclosures, and other communications we provide to you electronically, via email, through the Public Services, or through a customer-controlled deployment satisfy any legal requirement that such communication be in writing, to the extent permitted by law. YOU HEREBY AGREE TO THE USE OF ELECTRONIC SIGNATURES, CONTRACTS, ORDERS, AND OTHER RECORDS, AND TO ELECTRONIC DELIVERY OF NOTICES, POLICIES, AND RECORDS OF TRANSACTIONS INITIATED OR COMPLETED BY US OR THROUGH THE PUBLIC SERVICES. Customer Agreement signature mechanics, procurement terms, and notice channels prevail where they differ.

22. MISCELLANEOUS

These Public Terms, together with any policies or operating rules posted by us on the Public Services and, where applicable, any Customer Agreement between the parties (as described in the "Precedence of documents" paragraph in AGREEMENT TO OUR PUBLIC TERMS), constitute the agreement and understanding between you and us with respect to the subject matter covered by those documents. In the event of any conflict between these Public Terms and a Customer Agreement, the order of priority in the "Precedence of documents" paragraph applies. Our failure to exercise or enforce any right or provision of these Public Terms shall not operate as a waiver of such right or provision. These Public Terms operate to the fullest extent permissible by law. We may assign, transfer, delegate, or novate any or all of our rights and obligations under these Public Terms to any affiliated entity, successor in interest, or new corporate entity established in connection with a reorganization, incorporation, or investment transaction (including, without limitation, a transfer from the current Polish sole-proprietorship (JDG) structure to a Polish limited liability company (Sp. z o.o.) or to a new corporate vehicle formed in connection with accelerator or investor participation). By accepting these Public Terms you grant your advance, blanket consent to such assignment, transfer, and novation for the purposes of Article 519 of the Polish Civil Code and any equivalent provisions of applicable law, and you agree that the successor entity will assume our position as contracting party under these Public Terms with the same rights and obligations. We will provide reasonable prior notice of any such novation through the Public Services or by email, together with the identity and contact details of the successor entity. We shall not be responsible or liable for any loss, damage, delay, or failure to act caused by any cause beyond our reasonable control. If any provision or part of a provision of these Public Terms is determined to be unlawful, void, or unenforceable, that provision or part of the provision is deemed severable from these Public Terms and does not affect the validity and enforceability of any remaining provisions. There is no joint venture, partnership, employment, or agency relationship created between you and us as a result of these Public Terms or use of the Public Services. You agree that these Public Terms will not be construed against us by virtue of having drafted them. You hereby waive any and all defenses you may have based on the electronic form of these Public Terms and the lack of signing by the parties hereto to execute these Public Terms.

23. AI OUTPUTS DISCLAIMER

PlanVault™ deployments may route requests to external large language models (LLMs), embedding models, and other AI services selected and configured by the customer. AI-generated outputs may be inaccurate, incomplete, misleading, or unsuitable for a particular purpose. Customers and users are responsible for reviewing, verifying, and evaluating the accuracy, legality, safety, and appropriateness of AI-generated output before relying on or using it. To the maximum extent permitted by law and subject to any Customer Agreement, we disclaim liability for losses or damages resulting from reliance on AI-generated outputs. See also the Acceptable Use Policy for the parties' respective roles under the AI Act.

24. ACCEPTABLE USE POLICY

Your use of the Public Services and any authorized PlanVault™ product use is also subject to our Acceptable Use Policy, which is incorporated into these Public Terms by reference. By accessing or using the Public Services or PlanVault™ product, you agree to comply with the Acceptable Use Policy. We may suspend or terminate access to the Public Services for violations of the Acceptable Use Policy. Suspension or termination of a customer-controlled deployment is governed by the applicable Customer Agreement.

25. CUSTOMER DATA AND AI SERVICE PROVIDERS

PlanVault™ uses a bring-your-own-key (BYOK) model for customer AI traffic unless a Customer Agreement states otherwise. Customers select AI providers, supply credentials, and maintain their provider relationships. PlanVault™ provides orchestration in the customer deployment. See the Privacy Policy (Section 11) and Security page for detail. Customer Content is not licensed to us under these Public Terms.

26. PROGRAMMATIC ACCESS

Notwithstanding any contrary language in Section 6 (PROHIBITED ACTIVITIES) — including, without limitation, the Section 6 bullets prohibiting automated use of the system, scripts, bots, robots, spiders, scrapers, cheat utilities, offline readers, data mining tools, automated systems, and "Automated Scraping" — the restriction on automated or non-human access does NOT apply to authorized use of the PlanVault™ Runtime API, Model Context Protocol (MCP) servers, inbound and outbound webhooks, SDKs, or other programmatic interfaces that we document as part of PlanVault™. These interfaces are specifically designed for automated and machine-to-machine access and may be used in accordance with the applicable documentation, deployment configuration, rate limits, quotas, Customer Agreement, and these Public Terms.

For clarity, the Section 6 prohibition on automated extraction, scraping, bots, and similar tools continues to apply in full to: (a) the public marketing site at https://planvault.ai and any of its subpages (for example policies and security pages) outside of endpoints explicitly documented as programmatic interfaces; (b) any attempt to extract data, content, or metadata from the Public Services or PlanVault™ product outside documented API, MCP, and webhook interfaces; (c) any circumvention of authentication, scope, license, or rate-limiting controls; and (d) any automated access to accounts, organizations, deployments, projects, or environments other than those for which you have been authorized. Violations of this Section 26 — including exceeding documented rate limits, using undocumented endpoints in an automated manner, or bypassing access controls — remain violations of Section 3(5), Section 6, and these Public Terms.

27. CUSTOMER-CONTROLLED DATA PROCESSING

If you are a business customer using PlanVault™ to process personal data of your end users, you are responsible for the lawful basis, transparency notices, documented instructions, deployment controls, provider selection, AI-provider configuration, retention settings, and any data-protection terms required for that processing. PlanVault™ provides technical controls for encryption, retention, export, erasure, and audit, but those controls do not replace your legal process or any Customer Agreement between us.

28. CONTACT US

In order to resolve a complaint regarding the Public Services or to receive further information regarding use of PlanVault™, please contact us at:

Bohdan Matviichuk ul. Dziewanny 21/19 20-539 Lublin Poland General inquiries: support@planvault.ai Privacy, data protection, and GDPR requests (preferred): privacy@planvault.ai

29. ILLEGAL CONTENT NOTICES (DIGITAL SERVICES ACT)

Pursuant to Article 16 of Regulation (EU) 2022/2065 (Digital Services Act), any individual or entity may notify us of specific items of Customer Content hosted on, transmitted through, or made available by Public Services or a customer deployment for which we provide hosting or moderation functions, where they consider that content to be illegal content under Union law or the national law of a Member State.

To submit a notice, email legal@planvault.ai with the following information: (a) a sufficiently substantiated explanation of the reasons why the individual or entity considers the information to be illegal content; (b) a clear indication of the exact electronic location of the information, such as the exact URL(s), and, where necessary, additional information enabling the identification of the illegal content as appropriate to the type of content and to the specific type of hosting service; (c) the name and email address of the individual or entity submitting the notice (except in cases of suspected offences involving Articles 3 to 7 of Directive 2011/93/EU); (d) a statement confirming the bona fide belief of the individual or entity submitting the notice that the information and allegations contained therein are accurate and complete.

We will acknowledge receipt of a substantiated notice without undue delay and will take a decision in respect of the information to which the notice relates, in a timely, diligent, non-arbitrary, and objective manner, in accordance with Article 16(6) DSA where the DSA applies to the relevant service. Where we restrict the visibility of, or remove, Customer Content following a notice, we will provide a statement of reasons to the affected Customer pursuant to Article 17 DSA, unless a lawful exception applies.

Statements of reasons and other formal moderation communications are prepared manually and delivered by email from notifications@planvault.ai; always verify the sender domain.

For notices involving suspected offences against children (Article 16(c) DSA exception covering Articles 3–7 of Directive 2011/93/EU) or other highly sensitive evidence, contact security@planvault.ai instead, and we will arrange an encrypted submission channel as described in our Security page (Section 16). Do not include sensitive evidence in plaintext SMTP.

Microenterprise scope (Article 19 DSA). Because the Public Services are currently operated by a microenterprise within the meaning of Article 2(3) of Commission Recommendation 2003/361/EC and Article 19(1) DSA (single natural person, well below the 10-employee / €2 million annual turnover (or balance-sheet total) threshold defined there), the obligation to establish a formal internal complaint-handling system under Article 20 DSA does not currently apply to us. The microenterprise exemption in Article 19 does not, however, relieve us of the obligation under Article 16 DSA to operate a notice-and-action mechanism where applicable, nor of the obligation under Article 17 DSA to provide a statement of reasons for content-moderation decisions where applicable — both are addressed by this Section 29. We will re-evaluate the Article 20 obligation if we cease to qualify as a microenterprise.