Terms of service

Last updated: 25 August 2026. This document is provided in English and German. Where the two differ, the English version controls for customers of visibleIT Inc.; the German version controls for customers of visibleIT GmbH.

1. The parties

These terms are the agreement between your organisation ("you") and one of the visibleIT companies ("we", "us"). The company you contract with depends on where you are billed:

visibleIT GmbH
Hunoldstr. 13, 34479 Breuna, Germany. Contracts with customers billed in the EU, UK, EEA and Switzerland.
visibleIT Inc.
12625 Caballo Ct, Estero, FL 33928, USA. Contracts with customers billed in the United States and the Rest of the World.

2. What you get

A multi-tenant SaaS where you create, configure and run AI agents — voice, email, and sales-analysis — under your organisation's account. The exact features available depend on your plan; the Billing page lists what's included.

What the service is. The platform is software. Where an agent is reached by telephone, the connectivity is provided by third-party carriers whose services we buy; we operate no telecommunications network of our own. A telephone number is an optional add-on to an agent — agents run on your own website, by voice and by chat, without one — and everything the platform does is metered against a single credit balance under one price list.

Self-service platform. The Free, Starter, Pro and Business plans are self-service: you build, configure, and manage your own agents, instructions, channels and connections. Our responsibility on these plans is to provide the platform itself with reasonable skill and care (section 19); it does not include building or operating your agents for you.

Optional managed & professional services. As a separate, chargeable offering we can set up your agents for you, write and tune their instructions, connect your channels, and carry out changes on your behalf ("Managed Services"). Managed Services are scoped, quoted and agreed with you separately from your plan and credits, and are typically provided under an Enterprise or custom agreement. Where we perform Managed Services, we act on your instructions: you remain the controller of your Customer Data and end users (section 7), you are responsible for reviewing and approving the configuration and outputs (section 11), and the allocation of liability in sections 19 and 20 applies. Any statement of work or quote we agree for Managed Services governs that work; nothing in it removes your obligations under these terms.

Changes to the platform. We may add, change, update, suspend, deprecate, or remove any feature, capability, integration, model version, or plan structure at any time, at our reasonable discretion. Improvements, ports, vendor changes and security patches happen continuously and do not require prior notice. Where a change materially reduces a feature you actively rely on in a paid plan within the current billing cycle, we will give reasonable advance notice and provide either a comparable replacement feature or a credit on your account in equivalent value. No cash refund is provided for changes of this kind (see section 12).

3. Beta and early-access features

From time to time we offer features labelled "beta", "preview", "early access" or similar. These features are provided as-is, may change or be withdrawn at any time without notice, do not carry any service-level commitment, and are not covered by the warranties in section 19. By using a beta feature you accept that it may be incomplete, unstable, or removed; we welcome feedback but do not undertake to act on it.

4. Your account

To use the platform you create an account, verify your email, and join or create an organisation. The first person who creates the organisation is the owner; the owner can invite others and assign roles.

Accurate information. You are responsible for providing and maintaining accurate, complete and up-to-date information for your account and organisation — including legal name, registered address, billing contact, billing phone, VAT or tax identification, and any verification documents we or our telecom providers require for phone-number provisioning. Inaccurate information may delay or block features (e.g. phone-number issuance), invalidate invoices, or be grounds for suspension under section 13.

5. Security and access — mandatory MFA

Security is core to how we run the platform. As a condition of use, every account must protect access with at least one second factor of authentication ("MFA"). The platform supports two options:

  • Passkeys (WebAuthn)strongly preferred. Passkeys are phishing-resistant, hardware-bound, and unique per site. Use them wherever your device allows.
  • Authenticator-app codes (TOTP) — acceptable as a fallback when a passkey is not available, but materially weaker against phishing and credential-theft.

Operator-level access (the super-admin console) is restricted to passkeys only — TOTP is not accepted for that surface. We may require passkey enrolment for any role we determine carries elevated risk.

You are responsible for:

  • keeping your second factor secure and not sharing credentials;
  • using a passkey instead of TOTP wherever your device supports it;
  • promptly removing access for members who leave your organisation;
  • notifying us at the email shown for your controller in the privacy policy if you suspect an account has been compromised.

We may suspend an account at short notice if we see clear indicators of compromise, and we will work with you to restore safe access.

6. How you may use the platform

The following are not permitted. They are grounds for suspension and, on repeat or severe misuse, for termination without refund.

  • Anything illegal under applicable law.
  • Sending unsolicited marketing voice calls, text messages or emails in violation of telemarketing laws (e.g. TCPA in the US, GDPR + ePrivacy in the EU). Outbound campaigns require recipient consent obtained by you.
  • Using the platform to deceive end users about what they are talking to. Voice and chat agents must disclose to the end user that they are interacting with an AI, in the way required by your local law and the EU AI Act.
  • Recording or transcribing calls in jurisdictions that require all-party consent without obtaining that consent first. See the privacy policy §9.
  • Generating, storing or matching voiceprints, faceprints or any other biometric identifier from end users.
  • Using the platform for life-safety, medical-diagnostic, emergency-response, or other high-risk decisions without meaningful human review.
  • Configuring an agent to take solely automated decisions with legal or similarly significant effect on a person (GDPR Art. 22) unless you provide the safeguards Art. 22 requires.
  • Impersonating a real person without their consent, including voice cloning.
  • Fraud, harassment, defamation, hate speech, child sexual abuse material, terrorism content, or any content that violates third-party rights.
  • Scraping, mirroring, reverse-engineering or attempting to extract the underlying AI models, prompts, or system logic.
  • Security testing, penetration testing or load testing without our prior written agreement. We welcome responsible-disclosure reports — contact us first.
  • Uploading malware, illegal content, or data you do not have the rights to use.

7. Your responsibilities for end users

Where someone calls, emails or chats with an agent you have configured, that person is your end user — not ours. You are the controller of their personal data; we are your processor. See the privacy policy for the detail. Concretely, you are responsible for:

  • Disclosing the AI. Tell every end user, at the start of the interaction, that they are speaking or writing with an AI agent — as required by your local law and the EU AI Act.
  • Disclosing recording, transcription and storage. Tell every end user that the conversation will be recorded (where applicable), transcribed, and stored on the platform — and for how long, based on the retention you have configured. This duty applies in every jurisdiction, including ones that do not require all-party consent to record, because transparency about processing of personal data is a separate obligation (e.g. GDPR Art. 13, EU AI Act).
  • Obtaining consent where required. In jurisdictions that require all-party consent to record or transcribe a call — including those listed in the privacy policy §9 — obtain that consent before the conversation begins.
  • Handling rights requests. Receive and answer your end users' access, correction, deletion, restriction, portability and objection requests. We provide the technical means (export, deletion, retention controls per agent) to fulfil them.
  • Reviewing what the agent does. The agent can make mistakes and acts on your configuration and your end users' inputs. Do not present it to your end users as infallible, and do not rely on it, without appropriate human review, where an error would be unacceptable (money, legal rights, medical, safety). Where you let an agent take actions on its own — such as recording a booking or writing to a data table — you are responsible for the settings that enable this and for the results. See section 11.

A simple opening line works for most voice agents — for example: "Hi, you're speaking with our AI assistant; this call is recorded and transcribed for [purpose]; say 'stop' or ask for a person if you'd rather not continue." Wording is your decision, the obligation is yours; we provide the greeting field and the recording / retention controls to help.

8. Phone numbers

Voice agents can be served by phone numbers we provision on your behalf through our telecom providers. The following terms apply to any number assigned to your organisation:

  • Right of use, not ownership. You receive a non-exclusive right to use the number while your subscription remains active and while your plan's credit balance covers its monthly consumption. You do not own the number. The underlying carrier retains all rights to the number under their own terms and applicable law.
  • Metered in credits, not separately invoiced. A number in use consumes credits from your plan allowance each month, at the rate shown on the Billing page. It is not billed as a separate fee and is not a service you can buy on its own — like every other capability of the platform, it is metered against the single credit balance included in your plan. Credits already consumed are not refunded (see section 12).
  • Verification. Many countries require operators to provide verified business or personal identity, registered address, emergency-service registration (e.g. E.911 in the US, Notruf in Germany) and a stated use case. You are responsible for providing this information promptly and accurately. We may delay or refuse provisioning, or release a number, where required information is missing or incorrect.
  • Release on cancellation, non-payment or termination. When you cancel a number, downgrade off a plan that includes it, fail to pay the monthly fee, or your organisation is terminated under section 13, the number is released back to the carrier and may be reassigned. We do not guarantee that a released number can be recovered.
  • Portability. Number portability between carriers is not guaranteed and is not part of the standard service. Where it is possible, we will support a reasonable porting request at our then-current rates, subject to the receiving carrier's rules.
  • Compliance. You will use numbers only for the purposes declared at provisioning, comply with telemarketing, anti-fraud and STIR/SHAKEN-style call-authentication rules where applicable, and not use the number to impersonate a third party.
  • Call forwarding is a higher-tier feature. The ability to configure an agent to forward or transfer a live call to an external number is included only on the Pro, Business and Enterprise plans, not on Free or Starter. Which premium features each plan includes is shown on the Billing page; we may change the plan a given feature belongs to under section 2. Any forwarded outbound call is metered as normal phone usage.

9. Integrations you configure

The platform lets you connect your agents to third-party systems you control or to which you have lawful access — including your own Microsoft 365 mailbox or calendar, your CRM, your scheduling tool, your webhook endpoints, and any custom connector defined by your administrator.

  • Your endpoints, your responsibility. You are responsible for the URLs, secrets, API keys, OAuth scopes and authorisations you configure, for the security and availability of any endpoint we transmit to on your instruction, and for the lawfulness of the processing that happens at the receiving end.
  • OAuth tokens. When you connect a Microsoft 365 (or other) account, you authorise the platform to act on that account within the scopes you grant for as long as the connection is active. We store the OAuth refresh token in our secret store and use it only to perform the configured agent actions.
  • Disconnection. You may disconnect any connection at any time. We delete the relevant OAuth tokens and stop further calls to that integration. Past data already exchanged is governed by the receiving system's terms.
  • Third-party terms. Connected systems are subject to their own terms with you (Microsoft, Google, your CRM vendor, etc.). We are not a party to those agreements and not liable for what they charge, change, throttle or break.

10. Your content

You retain ownership of everything you put into the platform — your system prompts, knowledge documents, attachments, structured-data tables and imports, agent configuration, conversation transcripts, email content, and any other material you or your members upload, paste, import or generate on the platform ("Customer Data"). You grant us a limited, non-exclusive licence to host, process and transmit Customer Data only as needed to operate the platform for you. We never use Customer Data to train AI models for other customers.

Your warranties for what you upload. You represent and warrant that, for every piece of Customer Data you place on the platform:

  • you have the right and authority to upload it and to have us process it as part of the service;
  • it does not infringe the intellectual-property rights, privacy rights, publicity rights, or contractual rights of any third party;
  • where it contains personal data of third parties (for example, a customer list in a knowledge file, a price sheet that names individuals, contact details inside a CSV import), you have a lawful basis under applicable data-protection law to collect, store and have us process that data on your behalf, and you have given any notices and obtained any consents the law requires;
  • it is free of malware, viruses, exploit code, and prompt-injection content designed to manipulate model behaviour for malicious ends;
  • it does not contain content of the kinds prohibited by section 6 (illegal material, content that infringes third-party rights, child sexual abuse material, terrorism content, biometric identifiers, etc.).

Our right to scan, quarantine and remove. We may scan, quarantine, restrict access to, or remove Customer Data that we believe on reasonable grounds breaches these terms, is required to be removed by law, or threatens the security or integrity of the platform — with notice to you where practical, and without notice where the risk is immediate (section 13). Routine scanning for malware or abuse is part of normal operation.

Your own backups. The platform retains Customer Data for the durations set out in the privacy policy §7. If a complete and accurate independent copy matters to your business — particularly knowledge files, structured data, and conversation archives — you are responsible for keeping your own export. The platform provides export tools for this.

11. Outputs and AI behaviour

AI-generated outputs are probabilistic. They may be inaccurate, out of date, or unsuitable for a specific purpose. Treat them as drafts that need your review before they are relied upon — especially anything that affects money, legal rights, medical decisions, or safety.

An agent acts on the instructions you configure — its system prompt, tools, data tables and connected actions — and on what your end users say to it during a conversation. The correctness of any output or action therefore depends on both your configuration and your end users' inputs, neither of which we control. You are responsible for the instructions you give an agent and for reviewing, and where appropriate confirming, actions it takes on your behalf — for example writing to a data table, recording or changing a booking, or sending a reply. To the extent permitted by law, and subject to sections 19 and 20, we are not responsible for outcomes that result from an agent following your configuration or your end users' inputs, including mistakes, omissions or double-bookings in data the agent maintains.

You own the outputs generated for your organisation, subject to the underlying model providers' terms. We don't claim ownership of agent replies, transcripts or analyses produced for you.

12. Billing and credits

Plans, credit allowances, top-up packs and the credit cost of each feature are shown on the Billing page. The prices visible there are the binding offer; nothing else in this document or in marketing material overrides them.

  • Subscriptions renew automatically at the end of each cycle until you cancel. You can change plan or cancel at any time on the Billing page.
  • Plan upgrades take effect immediately. Where you upgrade mid-cycle, we charge a pro-rated difference for the remainder of the current cycle and the full new plan fee from the next cycle onwards.
  • Plan downgrades take effect at the end of the current paid cycle. You keep the higher plan's features until then. No portion of the original payment is refunded.
  • Credits meter your agents' AI usage. They are consumed as conversations, drafts and analyses run. Configuration changes (writing a prompt, asking the help assistant, designing a table) do not consume credits.
  • Top-up packs are pre-paid credit purchases. Unused top-up credits roll over after the monthly allowance resets.
  • Managed & professional services (section 2) — done-for-you setup, configuration, or ongoing management of your agents — are not covered by your plan fee or credits. They are quoted and invoiced separately per the statement of work or quote we agree with you, and are non-refundable once the work has been performed.
  • Taxes are added on top of the displayed price where applicable. visibleIT GmbH invoices include German VAT or, for valid EU VAT-IDs, reverse charge; visibleIT Inc. invoices include US sales tax where due.
  • Late payment. If a payment fails we retry per the payment provider's schedule and notify you. If payment is not received after the grace period the account is suspended. Persistent non-payment may lead to data deletion after the retention window in the privacy policy.
  • No refunds. All payments for monthly subscriptions and top-up packs are non-refundable once charged, including any unused portion of the current cycle when you cancel, downgrade, are suspended, or have your account terminated for breach. Cancellation stops future charges; it does not return amounts already paid. The only exceptions are (a) manifest billing errors we cause — for example, a double charge or a charge taken after you have confirmed cancellation — which we refund without argument, and (b) where the law in your jurisdiction grants a mandatory refund right that cannot be excluded.

13. Suspension and termination

You may close your organisation at any time on the Settings page. Before you cancel or terminate, we recommend you export any Customer Data you want to keep: conversation transcripts (CSV), knowledge files, structured data tables and email/sales analyses. Once an organisation is closed we soft-delete the data and retain a 90-day grace window during which restoration is possible; after that the data is permanently deleted. Statutory invoice retention is independent of this.

Our right to suspend, terminate or delete. We may, at our reasonable discretion and with or without prior notice, restrict access to, suspend, terminate or permanently delete any account, organisation or specific agent if we believe on reasonable grounds that:

  • you, a member of your organisation, or an end user is using the platform in breach of section 6 (acceptable use);
  • the activity is illegal, fraudulent, deceptive, abusive, or harms or threatens to harm us, other customers, end users, our infrastructure providers, or any third party;
  • invoices remain unpaid after the payment grace period;
  • we are required to act by law, court order, regulator, or by a contractual obligation we owe to our own service providers;
  • continued operation creates an imminent security risk to platform integrity or to other tenants.

Where the breach is fixable and the risk is not immediate, we aim to notify you first and give you a reasonable chance to cure. Where the breach is severe, repeated, or threatens immediate harm — including fraud, abuse of end users, illegal content, security incidents, or attempts to circumvent platform safeguards — we may act immediately, without prior notice, and without any refund, and explain the action afterwards.

Suspension does not, on its own, end this agreement; we may convert a suspension into a termination if the underlying issue is not resolved within a reasonable period. Termination ends your right to use the platform; the consequences for your data are set out in the privacy policy and at the top of this section.

14. Service availability

We design the platform for high availability but do not currently commit to a contractual service level. If we introduce one for a plan tier it will appear on that tier's plan page and in this document. We perform scheduled maintenance outside of EU business hours where possible and announce major upgrades in the platform.

15. Security commitments

Beyond the MFA requirement in section 5, our standing security practices are described in the privacy policy §11. We rely on our infrastructure providers' underlying certifications (ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3) for the infrastructure layer.

16. Confidentiality

Each side will treat the other's non-public information as confidential and use it only to perform this agreement. Customer Data is treated as your confidential information. Aggregate, anonymised usage figures we derive for our own operations are not.

17. No resale or white-labelling

Unless we have agreed otherwise in a separate signed contract, you may not resell, rent, sub-license, white-label, or rebrand the platform or any part of it to a third party, nor operate the platform as a service to clients of your own under your own brand. The platform is licensed for use by your own organisation and its end users. Reseller and partner arrangements are possible — contact us before you build on top of the service for resale.

18. Export controls and sanctions

You will comply with all applicable export-control and economic-sanctions laws, including those of the United States, the European Union, the United Kingdom and Germany. You represent and warrant that:

  • neither you, nor any member of your organisation with platform access, is on a denied-party, sanctions, or restricted-party list (e.g. OFAC SDN, EU consolidated list);
  • you will not access or use the platform from, or for the benefit of any person in, a country or region subject to a comprehensive embargo (currently Cuba, Iran, North Korea, Syria, and the Crimea / DNR / LNR regions of Ukraine);
  • you will not use the platform to develop, design, produce or stockpile weapons of mass destruction or for any other end-use prohibited by applicable export-control law.

We may suspend or terminate access immediately if we determine that continuing the service would violate, or place us at serious risk of violating, these laws.

19. Warranties and disclaimers

We warrant that we will provide the platform with reasonable skill and care and in line with the description on our public pages. Beyond that — and to the extent allowed by law — the platform is provided "as is", and we disclaim all other warranties, express or implied, including fitness for a particular purpose, merchantability, and non-infringement. Beta features (section 3) carry no warranty at all.

20. Limitation of liability

Neither side excludes or limits liability for death or personal injury caused by negligence, for fraud, or for anything else that cannot be excluded under applicable law (including, under German law, liability for intent and gross negligence and breach of cardinal contractual duties).

Subject to that, neither side will be liable to the other for loss of profits, loss of revenue, loss of data unrelated to our direct fault, loss of opportunity, or any indirect or consequential loss. Each side's total aggregate liability under this agreement is limited to the fees paid by you in the twelve (12) months preceding the event giving rise to the claim.

21. Your indemnity

You will indemnify us against third-party claims that arise from (a) your or your end users' use of the platform in breach of section 6 or 7, (b) content you upload that infringes third-party rights, (c) your failure to obtain a consent the law required you to obtain (for example, all-party recording consent), or (d) any third-party endpoint or integration you configured under section 9. We will tell you about any such claim, let you control the defence, and reasonably cooperate.

22. Force majeure

Neither side is liable for failure or delay caused by events outside its reasonable control (e.g. extended internet outages, government action, natural disasters). The affected side will use reasonable efforts to restore performance.

23. Changes to these terms

We may update these terms. Material changes will be announced via email or a notice in the platform at least 30 days before they take effect; continuing to use the service after that date means you accept the change. If you don't, you may cancel before the effective date. Non-material changes (clarifications, typos) take effect on posting.

24. Governing law and jurisdiction

For customers contracted with visibleIT GmbH: these terms are governed by the laws of the Federal Republic of Germany (excluding the UN Convention on Contracts for the International Sale of Goods). The courts of Kassel, Germany have exclusive jurisdiction, subject to any mandatory consumer-protection venue. Place of performance is Breuna.

For customers contracted with visibleIT Inc.: these terms are governed by the laws of the State of Florida, USA, without regard to conflict-of-law rules. The state and federal courts located in Lee County, Florida, USA have exclusive jurisdiction.

25. General

  • Entire agreement. These terms, the privacy policy, the Data Processing Agreement (where signed) and any plan-specific document on the Billing page form the entire agreement between us and supersede earlier communications.
  • Assignment. You may not assign your rights without our written consent, except to a successor of substantially all of your business. We may assign to an affiliate or in connection with a corporate restructuring.
  • Severability. If a clause is unenforceable, the rest still applies.
  • No waiver. Failing to enforce a term once does not waive the right to enforce it later.
  • Notices. Legal notices to us should be sent by email to the address shown in section 1 and, where you want certainty, also by registered post. Notices from us to you may be sent to the email address on your owner account or via an in-product notice.
  • No agency. Nothing here creates a partnership, joint venture, or employment relationship.

26. Contact

visibleIT GmbH — info@visible-it.de
visibleIT Inc. — info@visible-it.io