Version 1.3 · as of 17.08.2026 · The GERMAN version is the authoritative one.
*This English text is a reading aid provided so that no one has to accept terms they cannot read.
It does not constitute a separate contractual version. By accepting, you accept German version 1.3.*
The provider of the "Aigis" platform (aigis.one) is Hofmann Computer Systems e.U., proprietor
Andreas Hofmann, Martinigasse 1, 7537 Neuberg im Bgld., Austria (E: office@hsys.at · VAT
ATU 64168108 · FN 30810h). These terms govern all use of the platform. The offering is directed
exclusively at entrepreneurs within the meaning of § 1 KSchG and Art. 2 of Directive 2011/83/EU; no
consumer transaction is established. Deviating terms of the customer apply only upon express
written acknowledgement.
Aigis is a software-as-a-service platform for requirements, compliance and code analysis: capture
and distillation of requirements (documents and text), AI-assisted checks (including contradiction
and document review, code analyses CORE/PULSE/SHIELD), reports, registers and audit evidence.
Individual functions are designed as bookable modules; scope and conditions follow from the
description and price overview displayed in the platform at the relevant time.
Accounts are personal. The customer warrants that registration details are accurate, that
credentials are kept secret, and that the platform's password requirements and — where required —
two-factor requirements are observed. Accounts unused for a longer period may be blocked
automatically for security reasons; reactivation is handled by the customer's administration.
Aigis is an AI-assisted analysis tool for source code and requirements documents. It is **not
intended** for the assessment of natural persons or for the purposes listed in Annex III of
Regulation (EU) 2024/1689 (including employment, creditworthiness, law enforcement, critical
infrastructure within the meaning of that Annex). Any repurposing use is the customer's sole
responsibility (Art. 25 of Regulation (EU) 2024/1689). AI-generated content of the platform is
machine-readably marked as such pursuant to Art. 50 of the Regulation; the customer shall not
remove this marking when processing it further. Where the customer publishes AI-generated texts to
inform the public, the customer is subject to its own disclosure obligations (Art. 50(4) of the
Regulation), unless human editorial responsibility exists.
The platform's results (findings, guidelines, conflict lists, reports) are produced using large
language models. They are analysis aids and replace neither legal, tax nor other professional
advice, nor the customer's own review. Where the customer's requirements collide with one another,
Aigis exposes the decision space but makes no decision as to which requirement prevails — that
decision and the responsibility for it remain with the customer. AI results may be incomplete or
erroneous; recognised limits (e.g. sources read only in truncated form) are disclosed by the
platform.
In order to perform the analyses, the customer's content (requirement texts, documents, source
code) is transmitted to commissioned AI providers or to systems controlled by the provider and
processed there. A list of the sub-processors used, as well as a data processing agreement
pursuant to Art. 28 GDPR, will be made available on request (office@hsys.at). On request, the
customer may supply its own keys for the encryption of data at rest (BYOK).
The customer uploads only content to which it holds the necessary rights, and no content whose
processing would violate applicable law. Malicious code may be introduced solely for the purpose of
analysis within the framework provided for that purpose. The customer designates internal
responsible persons (roles) truthfully; actions performed under an account are attributed to the
account holder.
The customer's content remains the customer's property; the provider receives the simple right of
processing required to render the service. Analysis results and reports belong to the customer. All
rights in the platform, its prompts, procedures and presentations remain with the provider.
The provider renders the service with reasonable care but owes **no particular or uninterrupted
availability** and no particular service level unless separately agreed in writing. Maintenance
windows, further development and disruptions of third parties (in particular AI providers, hosting
and network connectivity) may temporarily restrict use. The platform is provided "as is";
fitness for a particular purpose, the accuracy, completeness or usability of the AI-assisted
results, and any particular commercial success are not warranted. Statutory warranty is
excluded vis-à-vis entrepreneurs to the extent permitted by law; § 924 ABGB (presumption of
defectiveness) is contracted out, and the burden of proof lies with the customer from handover
onwards. The customer shall examine the service without delay and give written notice of defects
within the meaning of § 377 UGB without delay, at the latest within seven days; otherwise the
service is deemed approved.
Chargeable modules and quotas are governed by the price overview displayed in the platform in the version valid at the time of booking. Default in
payment entitles the provider, after a reminder, to block chargeable functions.
The provider treats customer content as confidential and protects it by technical and
organisational measures oriented towards ISO/IEC 27001 (including encryption of data at rest
and in transit, role-based access, two-factor protection of privileged actions, audit-proof
logging, anomaly detection, regular access review). No certification is thereby warranted.
The privacy policy on aigis.one applies. The provider processes personal data in accordance with
the GDPR; data subject rights (Art. 15–21 GDPR) may be addressed to office@hsys.at; complaints to
the Austrian Data Protection Authority (dsb.gv.at).
12.1 No archive. The provider is not a custodian. Customer content is not kept beyond the
purpose of the contract; archiving does not take place and is not offered.
12.2 Three months for handover. When a project is closed, the customer is asked to download all
evaluations, reports and registers of that project. The platform's exports are available for this
(PDF, Excel, Markdown, CSV, PowerPoint). The period is three months from closure. It is stated
to the customer at closure and displayed in the platform for as long as it runs.
12.3 Deletion after the period. Once the three months have elapsed, the provider deletes the
content and evaluations of the closed project from the platform. A deletion certificate is issued
on request. An active legal hold takes precedence over deletion.
12.4 Exception in case of payment default. If the customer is in default on a due payment, the
provider may retain the affected content beyond the period, to the extent and for as long as it is
needed to prove the service rendered. This retention serves that purpose alone: the content is
not processed further, not evaluated and not made accessible to anyone. It is deleted as soon as
the claim has been settled or conclusively resolved.
12.5 Deletion on request. Irrespective of the period, the customer may request the deletion of
individual content or of an entire project at any time. Clause 12.4 remains unaffected.
12.6 Billing data is not covered. Invoice and accounting data do not fall under this clause. It
contains no customer content but the type, scope and time of the service obtained, and is subject
to the statutory retention obligation (§ 132 BAO, seven years).
This contractual relationship is a business-to-business transaction; the following limitations
apply comprehensively to the extent permitted by law. Parts that reach impermissibly far are
reduced to the permissible extent without affecting the remaining limitations.
13.1 Unlimited liability exists only where mandatory: for intent, for damage arising from injury
to life, body or health, under the Product Liability Act, and for fraudulently concealed defects or
expressly warranted characteristics given in writing.
13.2 Gross negligence: For property and financial loss caused by gross negligence the provider
is liable limited in amount to the net fees actually paid for the affected service in the twelve
months preceding the damaging event.
13.3 Slight negligence: For damage caused by slight negligence the provider is liable **only for
breach of a material contractual obligation** (an obligation whose fulfilment makes the proper
performance of the contract possible in the first place and on whose observance the customer may
regularly rely), and even then only limited to the damage typically foreseeable at conclusion of
the contract, at most to the amount under clause 13.2. Otherwise liability for slight negligence is
excluded.
13.4 Excluded — outside clause 13.1 and to the extent permitted by law — is in particular
liability for lost profit, savings not realised, business interruption, loss of production,
indirect damage and consequential damage caused by defects, third-party claims, reputational damage,
and damage arising from the failure, delay or malfunction of commissioned third parties (AI
providers, hosting, network) and from events of force majeure.
13.5 Loss of data: Liability for the loss of data is limited to the effort that would have been
required for restoration given proper customer-side data backup in line with the state of the
art. The customer is itself responsible for backing up its content regularly.
13.6 AI results and compliance decisions: The provider is not liable for damage arising from
reliance on AI-assisted results (findings, guidelines, conflict lists, reports) or from decisions
made by the customer on that basis; the results are analysis aids and not a binding statement
(cf. clause 4). Where requirements collide, the customer makes the decision and bears the
responsibility for it.
13.7 Limitation and assertion: Claims for damages against the provider become time-barred, to
the extent permitted by law, within twelve months of knowledge of the damage and of the party
causing it, at the latest within the statutory maximum periods; they must be asserted in writing
within that period. The limitations of this clause also apply in favour of the provider's vicarious
agents and legal representatives.
Unless agreed otherwise, use may be terminated at any time with effect from the end of the month.
The provider may block accounts in the event of serious breaches of these terms after prior notice,
and immediately where there is imminent danger. Clause 12 applies accordingly to content after the
end of the contract.
Amendments are announced in the platform together with a version number. Continued use after such
announcement, as well as any renewed acceptance at sign-in, is deemed acceptance; material
amendments are submitted for separate consent.
Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods
and its conflict-of-law rules. The place of jurisdiction is the court with subject-matter
jurisdiction in Güssing. Should individual provisions be invalid, the remainder of the contract
remains effective; the invalid provision is replaced by the effective rule that comes closest to
its economic purpose.