Legal · SeKondBrain
Part 03 · Business terms

Business Terms
of Service.

The agreement for organisation customers — SeKondBrain for Business (KompanyBrain) and its packs, KIT Team plans and Kemory organisation workspaces — with the UK GDPR Article 28 Data Processing Agreement at Schedule 1.

Individual and self-serve accounts are governed by the Terms of Service for Individuals instead. Enterprise deals on the KIT Master Subscription Agreement or bespoke paper continue on that paper.

Version 1.2 Effective 5 August 2026

1. Structure and formation

1.1 These Business Terms of Service (“Terms”) govern the provision of SeKondBrain’s organisation services — including SeKondBrain for Business (KompanyBrain) and its packs, KIT (Knowledge Intelligent Toolkit) Team plans and Kemory organisation workspaces (the “Services”) — by SeKondBrain AI Labs Limited (Company No. 16806279, registered office 2 Peel Court, 24 St. Cuthberts Way, Darlington, England DL1 1GB) (“SeKondBrain”) to the customer identified on the applicable order form, online order or subscription page (“Order”) (“Customer”).

1.2 The agreement comprises the Order, these Terms and their Schedules (together, the “Agreement”). In conflict, the Order prevails over these Terms, and these Terms prevail over the Schedules other than Schedule 1 (Data Processing) in respect of the processing of personal data.

1.3 The individual accepting the Agreement warrants they have authority to bind the Customer. The Agreement takes effect on acceptance or first use, whichever is earlier.

2. The Services

2.1 SeKondBrain will provide the Services materially as described in the applicable documentation, with reasonable care and skill. KompanyBrain deployments are provisioned with single-tenant data storage per Customer on shared cloud infrastructure; the deployment region — Google Cloud Switzerland (rest of world) or India (customers in India) — is selected at organisation creation.

2.2 SeKondBrain may improve or modify the Services provided that it does not materially degrade the core functionality purchased. Beta, preview and early-access features are provided as-is, may be withdrawn, and are excluded from any service commitments.

2.3 Support and any service levels are as set out in the Order or the then-current support policy.

3. Authorised Users and administration

3.1 Customer may permit its employees and contractors to use the Services up to the purchased seats and usage limits (“Authorised Users”). Customer is responsible for its Authorised Users’ compliance with the Agreement, for the accuracy of its administration (roles, teams, tags, permissions, share links) and for maintaining the confidentiality of credentials and tokens.

3.2 Customer’s administrators can access, manage and delete content in the Customer workspace, configure permission models (role, tag and individual level), manage connectors and integrations, and review audit logs. Customer is responsible for its own permission configuration.

4. Customer Data

4.1 “Customer Data” means data submitted to the Services by or for Customer, including ingested client artefacts (emails, files, meeting records, decisions and communications), documents, manifests, memories, knowledge-graph entities derived from Customer Data, and Captured AI Conversations of Authorised Users within the Customer workspace.

4.2 Customer owns Customer Data. Customer grants SeKondBrain a non-exclusive licence to host, process, transmit and display Customer Data solely to provide and secure the Services, to comply with law, and as otherwise instructed by Customer, including to extract concepts, construct and maintain knowledge graphs and provenance records, generate outputs, and synchronise memory across surfaces and agents Customer authorises.

4.3 Customer responsibilities. Customer warrants that it has, and will maintain, all rights, consents and lawful bases required to ingest and process Customer Data through the Services — including personal data relating to Customer’s own clients, contacts and correspondents contained in ingested emails, files and meeting records — and that it will provide any privacy notices required by applicable law. Customer must not submit data whose processing by SeKondBrain would be unlawful, and is responsible for the legality of recording or ingesting communications and meetings in relevant jurisdictions.

4.4 No training. SeKondBrain will not use Customer Data to train foundation models, except with Customer’s express written opt-in. Customer Data transmitted to inference providers is transmitted solely to generate requested outputs; current sub-processors are listed at docs.sekondbrain.ai/subprocessors.

4.5 Usage data. SeKondBrain may collect and use technical usage and telemetry data that does not reveal Customer Data content, to operate, secure, benchmark and improve the Services.

5. AI features and outputs

5.1 The Services generate content and analysis using artificial intelligence, grounded in retrieval, provenance and query graphs and subject to automated audit. Outputs may nonetheless contain errors or omissions. Customer must ensure Outputs are reviewed by a suitably qualified person before reliance, in particular within regulated workflows. Outputs of the Legal, Consulting, Accounts, Wealth or Advisory packs are informational tools and do not constitute legal, accounting, investment or other professional advice by SeKondBrain, and Customer remains solely responsible for the professional services it provides to its own clients.

5.2 As between the parties, and subject to third-party rights and to similar outputs generated for others, SeKondBrain assigns to Customer its rights (if any) in Outputs generated for Customer.

6. Third-party services, connectors and agents

6.0 How the Services use third-party systems. The Services interoperate with third-party systems as follows: (a) supported AI platforms (currently ChatGPT, Claude, Gemini, Perplexity and Manus) — at an Authorised User’s direction, the browser extension reads that user’s own conversations as displayed in their browser, imports existing history from native export files or via authenticated, rate-limited requests using the user’s own signed-in session, and places selected context into a target platform’s input; Customer is responsible for its and its Authorised Users’ compliance with those platforms’ terms, and acknowledges platforms may change interfaces or restrict automated access, in which case affected features may stop working without liability on SeKondBrain; (b) inference providers — as per clause 4.4 and the sub-processor list; (c) cloud infrastructure — Google Cloud (Switzerland or India per the selected region); (d) billing — per clause 8.0. SeKondBrain is not affiliated with the operators of the supported AI platforms; their marks identify compatibility only.

6.1 Customer may connect third-party services (email, calendar, storage, communications and other connectors) and MCP-compatible agents. Third-party services are governed by their own terms; SeKondBrain does not control them and is not responsible for them. When Customer connects or authorises a third party, Customer instructs SeKondBrain to exchange the relevant data with it under the permissions Customer configures.

7. Acceptable use

7.1 Customer must not (and must ensure Authorised Users do not): use the Services unlawfully or to infringe third-party rights; circumvent security, tenancy or permission controls; access or attempt to access another customer’s data; reverse engineer the Services except as permitted by law; resell or provide the Services to third parties except to Authorised Users; use the Services or Outputs to develop a competing product or to train foundation models; or introduce malicious code. SeKondBrain may suspend access to address a security risk, unlawful use or material breach, giving notice and restoring service promptly once resolved.

8. Fees and payment

8.0 Billing entity. The Agreement is with SeKondBrain AI Labs Limited under the laws of England and Wales. Invoicing and collection are administered globally by SeKondBrain’s affiliate SeKondBrain AI Labs FZCO, United Arab Emirates (the “Billing Entity”) acting as billing and collection agent, and/or through SeKondBrain’s designated payment provider, as stated on the Order or invoice. Payment to the Billing Entity in accordance with the invoice discharges Customer’s payment obligation. The billing arrangement does not change the contracting parties, the governing law, or the parties’ rights and obligations under the Agreement.

8.1 Customer will pay the fees stated in the Order. Unless the Order says otherwise: fees are exclusive of VAT and other applicable taxes, which Customer will pay in addition; subscription fees are invoiced annually or monthly in advance per the Order; usage-based fees are invoiced in arrears; invoices are payable within 30 days; and seats added mid-term are charged pro rata. Fees are non-refundable except as expressly stated in the Agreement.

8.2 SeKondBrain may charge interest on overdue undisputed sums at 4% per annum above the Bank of England base rate, and may suspend the Services for undisputed sums more than 30 days overdue after at least 14 days’ written notice.

8.3 Renewal pricing may change with at least 60 days’ notice before the renewal date.

9. Term and termination

9.1 The Agreement runs for the initial term stated in the Order and renews automatically for successive periods of the same length unless either party gives notice of non-renewal at least 30 days before the end of the then-current term.

9.2 Either party may terminate for material breach not remedied within 30 days of written notice, or immediately on the other’s insolvency.

9.3 On expiry or termination: (a) Customer’s access ends and unpaid fees for the remaining committed term (in the case of termination by SeKondBrain for Customer’s breach) or accrued fees (otherwise) become due; (b) for 30 days, Customer may export Customer Data using the Services’ export tools or request a machine-readable export; and (c) SeKondBrain will thereafter delete Customer Data in accordance with Schedule 1, subject to legal retention obligations and encrypted backups deleted in the ordinary cycle.

9.4 Clauses which by nature should survive (including confidentiality, IP, liability, payment and governing law) survive termination.

10. Confidentiality

10.1 Each party will protect the other’s confidential information with at least reasonable care, use it only to perform the Agreement, and disclose it only to personnel and advisers under confidentiality duties, or as required by law with notice where lawful. Customer Data is Customer’s confidential information; the Services, pricing and non-public documentation are SeKondBrain’s. These obligations last for five years after termination (indefinitely for trade secrets and Customer Data).

11. Intellectual property

11.1 SeKondBrain and its licensors retain all rights in the Services, software, models, ontologies, graph schemas, interfaces and documentation. Customer receives only the rights expressly granted. Customer feedback may be used to improve the Services without restriction. Open-source components are governed by their own licences.

12. Warranties and disclaimers

12.1 Each party warrants it has authority to enter the Agreement. SeKondBrain warrants the Services will materially conform to the documentation and will be provided with reasonable care and skill; Customer’s exclusive remedy for breach of this warranty is re-performance or, if SeKondBrain cannot re-perform within a reasonable time, termination of the affected Services and a pro-rata refund of prepaid fees for the unexpired period.

12.2 Except as expressly stated, the Services are provided without other warranties, and all implied terms (including satisfactory quality, fitness for purpose and non-infringement) are excluded to the maximum extent permitted by law. SeKondBrain does not warrant that the Services will be uninterrupted or error-free or that Outputs will be accurate.

13. Indemnities

13.1 By SeKondBrain. SeKondBrain will defend Customer against third-party claims that the Services, used as permitted, infringe UK or EU intellectual property rights, and will pay resulting damages finally awarded or agreed in settlement — provided Customer gives prompt notice, sole control of the defence to SeKondBrain and reasonable assistance. If a claim arises, SeKondBrain may procure the right to continue, modify the Services to be non-infringing, or terminate the affected Services with a pro-rata refund. This clause does not apply to claims arising from Customer Data, combinations not provided by SeKondBrain, or use in breach of the Agreement, and states SeKondBrain’s entire liability for infringement.

13.2 By Customer. Customer will defend and hold SeKondBrain harmless against third-party claims arising from Customer Data, Customer’s ingestion of client communications without required rights or notices, use of the Services in breach of the Agreement, or measures taken by third-party AI platforms against Customer or its Authorised Users (including account restriction, suspension or termination) in connection with session-based capture, import or hand-off features used at Customer’s or an Authorised User’s direction, on equivalent terms. Customer acknowledges these features operate within Authorised Users’ own signed-in platform sessions and accepts the associated platform-measure risk.

14. Liability

14.1 Nothing limits liability for death or personal injury caused by negligence, fraud, or anything else that cannot be limited under English law.

14.2 Subject to 14.1, neither party is liable for loss of profits, revenue, goodwill, anticipated savings, or indirect or consequential loss.

14.3 Subject to 14.1 and 14.2, each party’s total aggregate liability arising out of or in connection with the Agreement is capped at the sums actually paid by Customer under the Agreement in the 12 months preceding the first event giving rise to liability (pro-rated where the Agreement has run for less than 12 months). Customer’s payment obligations are not limited by this clause.

14A. Assumption of responsibility, claims bar and waiver

14A.1 Customer acknowledges the Services are decision-support and knowledge infrastructure: Outputs inform, and do not replace, the judgment of Customer’s qualified personnel. To the maximum extent permitted by law, Customer waives, and shall bring no claim to the extent it arises from: (a) reliance on an Output that was not reviewed by a suitably qualified person as required by clause 5.1; (b) decisions taken, or professional services provided to Customer’s own clients, informed by the Services; (c) data or content Customer chose to ingest, share, or expose to a third-party platform or agent; or (d) acts, omissions, interface changes, access restrictions or account measures of third-party platforms with which the Services interoperate.

14A.2 Claims bar. Except for payment obligations, indemnity claims under clause 13, and breaches of clause 10 (Confidentiality) or Schedule 1, neither party may bring a claim arising out of or in connection with the Agreement more than 12 months after the date the claiming party became aware, or ought reasonably to have become aware, of the facts giving rise to it.

14A.3 No class or representative actions. All claims must be brought in the claiming party’s individual corporate capacity, and not as a claimant or member of a class, collective, or representative proceeding.

14A.4 Nothing in this clause 14A limits liability that cannot lawfully be limited (clause 14.1).

15. Data protection and security

15.1 Each party will comply with applicable data protection laws. For personal data in Customer Data, Customer is the controller and SeKondBrain the processor, and Schedule 1 (Data Processing Agreement) applies. For account, billing and usage data, SeKondBrain is an independent controller under its Privacy Policy.

15.2 SeKondBrain will maintain the technical and organisational measures summarised in Schedule 2, including encryption in transit and at rest, default-deny authorisation, tenant isolation with single-tenant data storage for KompanyBrain, and hash-chained tamper-evident audit logging.

16. General

16.1 Neither party is liable for delay caused by events beyond its reasonable control. Notices must be in writing to the addresses in the Order (email suffices). Neither party may assign without consent, not unreasonably withheld, except to an affiliate or in a merger or asset sale. The Agreement is the entire agreement and supersedes prior discussions; neither party relies on any representation not set out in it (without excluding fraud). Variations must be agreed in writing, except SeKondBrain may update these Terms for future renewal terms with at least 60 days’ notice. No partnership or agency is created. Third parties have no rights under the Contracts (Rights of Third Parties) Act 1999.

16.2 The Agreement is governed by the laws of England and Wales and the parties submit to the exclusive jurisdiction of the courts of England and Wales.

Schedule 1 — Data Processing Agreement

This Schedule applies where SeKondBrain processes personal data contained in Customer Data as processor for Customer as controller, and is entered into pursuant to Article 28 UK GDPR (and, where applicable, EU GDPR).

1. Processing details

  • Subject matter and duration: provision of the Services for the term of the Agreement plus the export and deletion period.
  • Nature and purpose: hosting, storage, indexing, concept extraction, knowledge-graph construction, retrieval, AI-assisted generation and analysis, memory synchronisation, collaboration, export and related support.
  • Categories of data subjects: Customer’s Authorised Users; Customer’s clients, prospects, suppliers and other correspondents whose data appears in ingested artefacts.
  • Categories of personal data: identity and contact data; professional data; communications content and metadata (emails, meetings, files); any personal data contained in documents Customer ingests, which may incidentally include special category data where Customer includes it.

2. Processor obligations

SeKondBrain will: (a) process personal data only on Customer’s documented instructions (the Agreement and Customer’s configuration of the Services constituting such instructions), unless required by law, in which case SeKondBrain will inform Customer unless prohibited; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the measures in Schedule 2 and appropriate measures under Article 32; (d) assist Customer, taking into account the nature of processing, with data subject requests and with Customer’s obligations under Articles 32–36, at Customer’s reasonable cost where requests are excessive; (e) notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, providing information reasonably required for Customer’s own notification obligations; (f) at Customer’s choice, delete or return all personal data at the end of the Services (subject to clause 9.3 of the Terms and lawful retention), and delete existing copies; and (g) make available information necessary to demonstrate compliance and allow and contribute to audits, which shall in the first instance be satisfied by SeKondBrain’s documentation, certifications and audit reports, with on-site audits no more than annually, on 30 days’ notice, at Customer’s cost, and without access to other customers’ data.

3. Sub-processors

Customer gives general written authorisation to the sub-processors listed in Schedule 2 (or at the URL stated there). SeKondBrain will give at least 30 days’ notice of intended additions or replacements; Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved, Customer may terminate the affected Services with a pro-rata refund. SeKondBrain will impose data-protection obligations on sub-processors materially equivalent to this Schedule and remains liable for their performance.

4. International transfers

Customer Data at rest is stored in the deployment region selected at organisation creation: Google Cloud Switzerland (rest of world) or Google Cloud India (customers in India). Transfers to Switzerland are covered by UK adequacy regulations. Billing and account administration data is processed by SeKondBrain’s group affiliate in the United Arab Emirates under an intra-group data transfer agreement incorporating the UK International Data Transfer Agreement, supported by a transfer risk assessment; no Customer Data content is transferred to that affiliate. Transfers to India, to the UAE, and any other restricted transfer (including processing by inference providers in other jurisdictions), are made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. Transfers to inference providers occur only as disclosed at the sub-processor URL in Schedule 2.

5. Precedence

This Schedule prevails over the rest of the Agreement in respect of the processing of personal data. Nothing in this Schedule limits either party’s liability position under clause 14 of the Terms except where prohibited by data protection law.

Schedule 2 — Sub-processors and security measures

1. Sub-processors — maintained at docs.sekondbrain.ai/subprocessors

  • Google Cloud (cloud infrastructure and storage) — Switzerland (rest of world); India (customers in India);
  • Inference providers — Groq, Concentrate.ai, OpenRunner;
  • Analytics — PostHog;
  • Payments — Paddle and Stripe. Paddle is additionally the merchant of record and, in that capacity, an independent controller of the transaction rather than a processor;
  • Group billing affiliate — SeKondBrain AI Labs FZCO (United Arab Emirates), acting as billing and collection agent under clause 8.0;
  • Notion — purpose pending confirmation;
  • Speech-to-text / text-to-speech providers for Kora Voice · email delivery.

2. Technical and organisational measures (summary)

  • Encryption of data in transit (TLS) and at rest;
  • Single-tenant data storage per KompanyBrain customer; logical tenant isolation elsewhere, scoped by organisation and user identifiers;
  • Default-deny authorisation with role-, tag- and individual-level permissions; explicit consent flows for cross-agent sharing;
  • Hash-chained, tamper-evident audit logging of security-relevant events;
  • Access controls, least privilege, MFA for administrative access, secrets management;
  • Vulnerability management, security testing and incident response procedures;
  • Backup and recovery procedures with encrypted backups and defined deletion cycles;
  • Personnel confidentiality obligations and security training.