← Support DEENFRES

Aigis · Terms and Conditions · 1.3 — The German version is authoritative.

General Terms and Conditions (GTC) — Aigis Platform

Version 1.3 · as of 17.08.2026 · The GERMAN version is the authoritative one.

*This English text is a reading aid provided so that no one has to accept terms they cannot read.

It does not constitute a separate contractual version. By accepting, you accept German version 1.3.*

1. Provider and scope

The provider of the "Aigis" platform (aigis.one) is Hofmann Computer Systems e.U., proprietor

Andreas Hofmann, Martinigasse 1, 7537 Neuberg im Bgld., Austria (E: office@hsys.at · VAT

ATU 64168108 · FN 30810h). These terms govern all use of the platform. The offering is directed

exclusively at entrepreneurs within the meaning of § 1 KSchG and Art. 2 of Directive 2011/83/EU; no

consumer transaction is established. Deviating terms of the customer apply only upon express

written acknowledgement.

2. Subject of the service

Aigis is a software-as-a-service platform for requirements, compliance and code analysis: capture

and distillation of requirements (documents and text), AI-assisted checks (including contradiction

and document review, code analyses CORE/PULSE/SHIELD), reports, registers and audit evidence.

Individual functions are designed as bookable modules; scope and conditions follow from the

description and price overview displayed in the platform at the relevant time.

3. Registration and account

Accounts are personal. The customer warrants that registration details are accurate, that

credentials are kept secret, and that the platform's password requirements and — where required —

two-factor requirements are observed. Accounts unused for a longer period may be blocked

automatically for security reasons; reactivation is handled by the customer's administration.

4a. Intended purpose and AI Regulation (EU) 2024/1689

Aigis is an AI-assisted analysis tool for source code and requirements documents. It is **not

intended** for the assessment of natural persons or for the purposes listed in Annex III of

Regulation (EU) 2024/1689 (including employment, creditworthiness, law enforcement, critical

infrastructure within the meaning of that Annex). Any repurposing use is the customer's sole

responsibility (Art. 25 of Regulation (EU) 2024/1689). AI-generated content of the platform is

machine-readably marked as such pursuant to Art. 50 of the Regulation; the customer shall not

remove this marking when processing it further. Where the customer publishes AI-generated texts to

inform the public, the customer is subject to its own disclosure obligations (Art. 50(4) of the

Regulation), unless human editorial responsibility exists.

4. AI results — an analysis aid, not legal advice, not a decision

The platform's results (findings, guidelines, conflict lists, reports) are produced using large

language models. They are analysis aids and replace neither legal, tax nor other professional

advice, nor the customer's own review. Where the customer's requirements collide with one another,

Aigis exposes the decision space but makes no decision as to which requirement prevails — that

decision and the responsibility for it remain with the customer. AI results may be incomplete or

erroneous; recognised limits (e.g. sources read only in truncated form) are disclosed by the

platform.

5. Processing by AI providers, sub-processors

In order to perform the analyses, the customer's content (requirement texts, documents, source

code) is transmitted to commissioned AI providers or to systems controlled by the provider and

processed there. A list of the sub-processors used, as well as a data processing agreement

pursuant to Art. 28 GDPR, will be made available on request (office@hsys.at). On request, the

customer may supply its own keys for the encryption of data at rest (BYOK).

6. Customer obligations

The customer uploads only content to which it holds the necessary rights, and no content whose

processing would violate applicable law. Malicious code may be introduced solely for the purpose of

analysis within the framework provided for that purpose. The customer designates internal

responsible persons (roles) truthfully; actions performed under an account are attributed to the

account holder.

7. Rights of use

The customer's content remains the customer's property; the provider receives the simple right of

processing required to render the service. Analysis results and reports belong to the customer. All

rights in the platform, its prompts, procedures and presentations remain with the provider.

8. Availability and warranty

The provider renders the service with reasonable care but owes **no particular or uninterrupted

availability** and no particular service level unless separately agreed in writing. Maintenance

windows, further development and disruptions of third parties (in particular AI providers, hosting

and network connectivity) may temporarily restrict use. The platform is provided "as is";

fitness for a particular purpose, the accuracy, completeness or usability of the AI-assisted

results, and any particular commercial success are not warranted. Statutory warranty is

excluded vis-à-vis entrepreneurs to the extent permitted by law; § 924 ABGB (presumption of

defectiveness) is contracted out, and the burden of proof lies with the customer from handover

onwards. The customer shall examine the service without delay and give written notice of defects

within the meaning of § 377 UGB without delay, at the latest within seven days; otherwise the

service is deemed approved.

9. Fees

Chargeable modules and quotas are governed by the price overview displayed in the platform in the version valid at the time of booking. Default in

payment entitles the provider, after a reminder, to block chargeable functions.

10. Confidentiality and security

The provider treats customer content as confidential and protects it by technical and

organisational measures oriented towards ISO/IEC 27001 (including encryption of data at rest

and in transit, role-based access, two-factor protection of privileged actions, audit-proof

logging, anomaly detection, regular access review). No certification is thereby warranted.

11. Data protection

The privacy policy on aigis.one applies. The provider processes personal data in accordance with

the GDPR; data subject rights (Art. 15–21 GDPR) may be addressed to office@hsys.at; complaints to

the Austrian Data Protection Authority (dsb.gv.at).

12. Handover and deletion after project closure — no archive

12.1 No archive. The provider is not a custodian. Customer content is not kept beyond the

purpose of the contract; archiving does not take place and is not offered.

12.2 Three months for handover. When a project is closed, the customer is asked to download all

evaluations, reports and registers of that project. The platform's exports are available for this

(PDF, Excel, Markdown, CSV, PowerPoint). The period is three months from closure. It is stated

to the customer at closure and displayed in the platform for as long as it runs.

12.3 Deletion after the period. Once the three months have elapsed, the provider deletes the

content and evaluations of the closed project from the platform. A deletion certificate is issued

on request. An active legal hold takes precedence over deletion.

12.4 Exception in case of payment default. If the customer is in default on a due payment, the

provider may retain the affected content beyond the period, to the extent and for as long as it is

needed to prove the service rendered. This retention serves that purpose alone: the content is

not processed further, not evaluated and not made accessible to anyone. It is deleted as soon as

the claim has been settled or conclusively resolved.

12.5 Deletion on request. Irrespective of the period, the customer may request the deletion of

individual content or of an entire project at any time. Clause 12.4 remains unaffected.

12.6 Billing data is not covered. Invoice and accounting data do not fall under this clause. It

contains no customer content but the type, scope and time of the service obtained, and is subject

to the statutory retention obligation (§ 132 BAO, seven years).

13. Liability

This contractual relationship is a business-to-business transaction; the following limitations

apply comprehensively to the extent permitted by law. Parts that reach impermissibly far are

reduced to the permissible extent without affecting the remaining limitations.

13.1 Unlimited liability exists only where mandatory: for intent, for damage arising from injury

to life, body or health, under the Product Liability Act, and for fraudulently concealed defects or

expressly warranted characteristics given in writing.

13.2 Gross negligence: For property and financial loss caused by gross negligence the provider

is liable limited in amount to the net fees actually paid for the affected service in the twelve

months preceding the damaging event.

13.3 Slight negligence: For damage caused by slight negligence the provider is liable **only for

breach of a material contractual obligation** (an obligation whose fulfilment makes the proper

performance of the contract possible in the first place and on whose observance the customer may

regularly rely), and even then only limited to the damage typically foreseeable at conclusion of

the contract, at most to the amount under clause 13.2. Otherwise liability for slight negligence is

excluded.

13.4 Excluded — outside clause 13.1 and to the extent permitted by law — is in particular

liability for lost profit, savings not realised, business interruption, loss of production,

indirect damage and consequential damage caused by defects, third-party claims, reputational damage,

and damage arising from the failure, delay or malfunction of commissioned third parties (AI

providers, hosting, network) and from events of force majeure.

13.5 Loss of data: Liability for the loss of data is limited to the effort that would have been

required for restoration given proper customer-side data backup in line with the state of the

art. The customer is itself responsible for backing up its content regularly.

13.6 AI results and compliance decisions: The provider is not liable for damage arising from

reliance on AI-assisted results (findings, guidelines, conflict lists, reports) or from decisions

made by the customer on that basis; the results are analysis aids and not a binding statement

(cf. clause 4). Where requirements collide, the customer makes the decision and bears the

responsibility for it.

13.7 Limitation and assertion: Claims for damages against the provider become time-barred, to

the extent permitted by law, within twelve months of knowledge of the damage and of the party

causing it, at the latest within the statutory maximum periods; they must be asserted in writing

within that period. The limitations of this clause also apply in favour of the provider's vicarious

agents and legal representatives.

14. Term, termination, blocking

Unless agreed otherwise, use may be terminated at any time with effect from the end of the month.

The provider may block accounts in the event of serious breaches of these terms after prior notice,

and immediately where there is imminent danger. Clause 12 applies accordingly to content after the

end of the contract.

15. Amendments to these terms

Amendments are announced in the platform together with a version number. Continued use after such

announcement, as well as any renewed acceptance at sign-in, is deemed acceptance; material

amendments are submitted for separate consent.

16. Final provisions

Austrian law applies, excluding the UN Convention on Contracts for the International Sale of Goods

and its conflict-of-law rules. The place of jurisdiction is the court with subject-matter

jurisdiction in Güssing. Should individual provisions be invalid, the remainder of the contract

remains effective; the invalid provision is replaced by the effective rule that comes closest to

its economic purpose.