General Terms and Conditions of i2R s.r.o.
Article IGeneral provisions
These General Terms and Conditions (hereinafter "GTC") govern the relationship between i2R s.r.o., ID No.: 52 465 098, with its registered office at Myslenická 169, 902 01 Pezinok, registered in the Commercial Register of the City Court Bratislava III, Section: Sro, File No. 138802/B, as the Contractor, and the Customer.
If you are a customer with a registered office in another EU member state, or in a country outside the European Union, you acknowledge that the governing law is the law of the Slovak Republic.
The application of any (general) terms and conditions of the other contracting party, or any other (general) terms and conditions, or amendments to these GTC, is hereby expressly excluded unless the parties agree otherwise in writing.
Amendments to or exclusion of these GTC, or any of their provisions, are binding on the parties only if agreed in writing in the Contract. To the extent that the provisions of the Contract differ from the provisions of the GTC, the diverging arrangements of the Contract shall prevail over these GTC.
Article IIDefinitions
Article IIIPurchase contract
Article IVProcedure for concluding a distance purchase contract
Article VService usage agreement
Article VIPurchase price
Article VIITrial operation and defects
- non-functionality of individual modules including their response,
- individual modules failing to communicate with each other despite the fact that they function correctly individually,
- features of the Computer Program and/or part thereof not corresponding to the agreed and approved features,
- missing agreed and/or necessary functionalities.
Article VIIIDelivery and acceptance
Article IXLiability for damage
Article XThird-party services
Article XIPersonal data protection
Article XIIIFinal provisions
Terms of Service (B2B EU Version)
Article IContractual relationship and its nature
These Terms of Service (hereinafter "Terms") constitute a complete and legally binding agreement between i2R s.r.o., ID No.: 52 465 098, with its registered office at Myslenická 169, 902 01 Pezinok, registered in the Commercial Register of the City Court Bratislava III, Section: Sro, File No. 138802/B, and a natural person, entrepreneur or legal entity that registers for the Services (hereinafter the "Client").
Article IIDefinitions and technical specifications
- Paid Credits: Credits purchased by the Client.
- Free / Promotional Credits: Credits granted as part of a trial or promotional campaign.
Article IIILicensing and intellectual property
- Not to use the Service to train any AI models.
- Not to perform automated scraping of the Provider's interface.
- Not to attempt to reverse-engineer the Provider's "Prompt engineering" technology.
- Not to share access credentials with third parties without written consent.
Article IVSubdomain management, identity, and hosting
- it has been inactive for more than 90 days,
- it infringes a third party's trademark rights,
- it is misleading or imitates state authorities or other brands.
Article VPayment terms, taxes, subscriptions, and credit system
- EU-based Client (outside SR) with valid VAT ID: Reverse-charge regime applies.
- Client without a valid VAT ID or based in SR: VAT will be added at the statutory rate.
- Monthly subscription: If the subscription is canceled, prepaid amounts are non-refundable if the Service or any part of it has begun to be used in the month covered by the subscription.
- Annual subscription: If the subscription is canceled, the unused portion is refunded starting from the month following the cancellation. The month in which the cancellation occurred is not included, even if the Service or any part of it was not used.
- Monthly cycle: Unused credits roll over to the next month, up to a maximum of 100% of the monthly package. Any excess above this limit expires.
- Annual cycle: Rollover is possible up to 12× the monthly allocation.
Article VIData protection and GDPR
Article VIILiability and warranty disclaimer
Article VIIICompliance with AI regulation (EU AI Act)
Article IXGoverning law and dispute resolution
Acceptable Use Policy (AUP)
Article 1Purpose and scope
Article 2Prohibited activities (General Abuse)
The Client undertakes not to use the Services for:
Article 3Specific programming restrictions
It is strictly prohibited to:
Article 4Content restrictions and ethical standards
The Service must not be used to generate code or applications that serve to:
Article 5Deployment responsibility
Article 6Monitoring and Enforcement
- Level 1 (Warning): For unintentional breaches (e.g., attempting to generate borderline content).
- Level 2 (Suspension): Temporary access block for repeat violations.
- Level 3 (Termination): Permanent account closure without compensation, and reporting of the incident to the relevant authorities (in the case of serious criminal activity).
Article 7Abuse Reporting
If a third party discovers that an application hosted on our infrastructure violates this AUP, they may submit a report to: abuse@polyreq.com.
Privacy Policy (GDPR)
Article IIntroductory provisions
Article IICategories of processed data
We process data to the minimum extent necessary for the technical operation of the B2B platform:
Data for managing the contractual relationship and invoicing
- Identification data: First name, last name, title, role at the Client.
- Contact details: Work email address, phone number, ID in communication tools (where integrated).
- Billing details: Company name, registered office, ID No., Tax ID, VAT ID, banking details, payment and subscription history.
Technical and security data (Metadata)
- Access data: IP address, login/logout timestamps, session ID.
- Diagnostic data: Browser version, operating system, technical error logs, metadata about the volume of data transferred (tokens, lines of code).
Article IIILegal bases and purposes of processing
In accordance with Article 6(1) of the GDPR, we process data for the following purposes:
| Purpose of processing | Legal basis | Justification |
|---|---|---|
| Providing platform features | Art. 6(1)(b) GDPR (Performance of contract) | Necessary to create an account, give access to the editor, and manage prepaid credits. |
| Invoicing and tax records | Art. 6(1)(c) GDPR (Legal obligation) | Obligation under the Accounting Act, the VAT Act, and verification in the VIES system. |
| IT infrastructure security | Art. 6(1)(f) GDPR (Legitimate interest) | Protection against cyberattacks (DDoS, brute force), prevention of credit abuse, and protection of intellectual property. |
| B2B communication and support | Art. 6(1)(f) GDPR (Legitimate interest) | Informing existing clients about critical updates and technical changes in the API. |
Article IVRecipients and sub-processors
To ensure top technical quality and security, we use the following vetted sub-processors, with whom we have entered into data-processing agreements (DPAs):
| Sub-processor | Purpose of processing | Location / Regulatory framework |
|---|---|---|
| Amazon Web Services EMEA SARL | Cloud infrastructure (hosting, compute, and database services), user authentication. | EU (Frankfurt, Ireland) / GDPR; SCC + DPF for any transfer outside the EU. ISO 27001, SOC 2. |
| Neo4j Sweden AB | Hosting and management of the graph database (Neo4j AuraDB). | EU / GDPR. ISO 27001, SOC 2. |
| Websupport, s. r. o. | Web application hosting, domain management, email services. | EU / GDPR. ISO 27001. |
| GitHub, Inc. | Source-code hosting, versioning, and management of development environments. | USA / EU Standard Contractual Clauses (SCC) per Decision 2021/914; EU-U.S. Data Privacy Framework (certified). |
| Anthropic PBC | Provision of AI models (Claude) via API. Inputs and outputs are not used for model training (default API policy). | USA / EU SCC; DPA per GDPR Art. 28. Anthropic is a DPA signatory with EU clients. |
| X.AI LLC | Provision of AI models (Grok) via API. | USA / EU SCC under xAI's DPA. |
| Stripe Payments Europe, Ltd. | B2B payment processing, invoicing, VAT-ID verification in VIES. | EU + USA / Globally (PCI DSS certified). |
Technical tools: Services for error logging and stability monitoring that process only technical metadata without PII.
Article VTransfers to third countries (outside EU/EEA)
If the technical solution requires data transfer outside the EU (e.g., the use of services hosted in the USA), the Provider guarantees the security of the transfer through:
- Standard Contractual Clauses (SCC) approved by the European Commission.
- Application of the Data Privacy Framework regime (for certified US entities).
Article VIData retention period
We apply strict rules to minimize retention:
- Contractual and accounting data: 10 years following the year in which the last invoice was issued (statutory archival period).
- Data in the user profile: For the duration of the registration. After the account is deleted, data is immediately deactivated and irreversibly erased after 30 days (backup retention period).
- Security logs (IP addresses): 6 to 12 months, unless required for an ongoing investigation of a security incident.
Article VIIRights of data subjects
You have the right to exercise the following claims at any time:
- Right of access: Request confirmation of processing and a copy of your data.
- Right to rectification: Update your contact details in the system.
- Right to erasure: Request closure of the account and deletion of data (to the extent that this is not overridden by an archival obligation).
- Right to object: Against processing based on legitimate interest.
- Right to lodge a complaint: With the Office for Personal Data Protection of the Slovak Republic (Hraničná 12, Bratislava).
Article VIIIFinal privacy statement
The Provider confirms that the process of generating code with AI is a technical transformation of data. The Client is solely responsible for not entering personal data of their clients or employees into the Service. The Provider is not liable for the processing of data inserted by the Client into the Service in violation of its purpose (software development).
Annex No. 1: Data Processing Addendum (DPA)
Article ISubject and scope
This Addendum applies in all cases where, as part of providing the Services, the Provider processes Personal Data on behalf of the Client (hereinafter "Personal Data").
Article IIClient's instructions
- provision and maintenance of the Services (Platform, Cloud);
- technical support and incident handling;
- ensuring the integrity and security of the platform.
Article IIISpecification of processing
Article IVProvider's obligations
The Provider undertakes to:
- encryption of data in transit (TLS/SSL) and at rest (encryption at rest);
- regular testing of system resilience;
- access-rights management (Principle of Least Privilege).
Article VSub-Processors
- Amazon Web Services EMEA SARL: Cloud infrastructure (hosting, compute, and database services), user authentication.
- Neo4j Sweden AB: Hosting and management of the graph database (Neo4j AuraDB).
- Websupport, s. r. o.: Web application hosting, domain management, email services.
- GitHub, Inc.: Source-code hosting, versioning, and management of development environments.
- Anthropic PBC: Provision of AI models (Claude) via API.
- X.AI LLC: Provision of AI models (Grok) via API.
- Stripe Payments Europe, Ltd.: B2B payment processing, invoicing, VAT-ID verification in VIES.
Article VITransfers to third countries
- an adequacy decision (e.g., the EU-U.S. Data Privacy Framework); or
- Standard Contractual Clauses (SCC) adopted by the European Commission.