Terms of Service and Data Processing Agreement
Effective from: June 21, 2026
Provider: VAPOL CZ s.r.o., company ID 26783789, registered seat Zašová 270, 756 51 Zašová, Czech Republic, registered in the Commercial Register kept by the Regional Court in Ostrava, section C, file 26345 (the “Provider” or “VAPOL”).
This document is the single, binding and complete legal framework for the use of the VOXIBLY mobile application and the web interface at voxibly.vapol.net (together the “Application” or “Service”). By registering, installing or otherwise using the Service, the User unconditionally agrees to these terms. The processing of personal data is described in the Privacy Policy.
PART A: General Terms of Service (ToS)
1. Introductory provisions and the hybrid nature of the Service (Dual-Track Model)
1.1. VOXIBLY is provided as software-as-a-service (SaaS) over the internet. The Service is used to record audio, transcribe it automatically and analyze it using artificial intelligence (AI) algorithms.
1.2. User classification (Dual-Track): The contractual relationship between the Provider and the User is governed by one of two regimes depending on the User's status:
- Business regime (B2B): If the User provides a company ID (IČO), VAT ID (DIČ) during registration or purchase, or if the circumstances indicate that the Service is used for the User's business, work organization or independent profession, the User is considered a “Business”. The relationship is governed exclusively by the B2B provisions. Statutory consumer protection provisions do not apply.
- Consumer regime (B2C): If the User acts outside their business or independent profession and does not provide a company ID at purchase, they are considered a “Consumer”. This relationship is governed by mandatory consumer protection provisions under the law of the Czech Republic and the European Union.
1.3. The User bears full responsibility for the accuracy and truthfulness of the data entered at registration. If a Business fails to provide its company ID, it risks breaching these terms; in such a case the Provider is entitled to unilaterally adjust the billing details and apply the B2B regime ex post.
2. User account and age restriction
2.1. Only fully legally competent natural persons who have reached the age of 18 are entitled to use the Service. Registration of persons under 18 is strictly prohibited.
2.2. The User must secure their access credentials. Sharing the user account with third parties without the Provider's prior written consent is prohibited.
2.3. The Provider is entitled to immediately, without compensation and without prior notice, block or permanently delete a User's account if the User breaches these terms, circumvents the technical tariff limits or engages in activity aimed at harming the Provider's infrastructure.
3. Payment terms and subscription (Google Play Billing)
3.1. The Service is offered in a free mode with limited quotas and in paid tariffs (Pro, Max) provided as a recurring monthly subscription.
3.2. In the Android mobile application, all transactions, payments, invoicing and subscription management are carried out exclusively through the Google Play Billing payment system operated by Google. The contractual and payment relationship arises directly between the User and Google as the transaction intermediary.
3.3. The subscription automatically renews for a further monthly period until the User cancels it in their Google Play account settings.
3.4. The Provider offers full cooperation in resolving technical problems with access to the Service after payment. However, the User acknowledges that all claims for refunds and complaints about payment transactions are governed by Google Play store rules and must be raised directly with Google.
4. Right of withdrawal and its lawful exclusion
4.1. For Businesses (B2B): A Business has no right to withdraw from the Service (subscription) contract without giving a reason.
4.2. For Consumers (B2C): Under Section 1829(1) of the Czech Civil Code, a Consumer has the right to withdraw from a distance contract within 14 days of its conclusion.
4.3. Exclusion of the right of withdrawal for digital content (Section 1837(l) of the Czech Civil Code): The Consumer expressly acknowledges and agrees that the digital content (access to paid VOXIBLY features) will be made available immediately upon completion of the purchase (activation of the Service). By making the purchase and actively ticking the relevant opt-in box in the purchase interface, the Consumer:
- a) expressly requests that the Service be made available before the expiry of the statutory 14-day withdrawal period;
- b) acknowledges and gives express consent that, upon full provision of the Service (commencement of performance), they lose their right to withdraw from the contract without giving a reason within 14 days under Section 1837(l) of the Civil Code.
4.4. If the Consumer does not give this consent, the Service will be made available only after the 14-day period from the conclusion of the contract has elapsed, during which the Consumer retains the right to withdraw without penalty. The Provider will send the Consumer confirmation of the conclusion of the contract and of this consent on a durable medium (e-mail).
5. Liability for defects and limitation of damages (SaaS & AI)
5.1. Agreed characteristics of the Service (Generative AI): The User acknowledges that the Service uses third-party generative AI models (Google Vertex AI). It is an inherent property of these models that the generated outputs (transcripts, analyses, summaries) are probabilistic and may contain inaccuracies, factual errors or distortions (so-called AI hallucinations). These properties and occasional inaccuracies in transcripts or analyses are expressly defined by the parties as agreed characteristics of the Service within the meaning of Sections 2389i and 2389o of the Civil Code, and do not constitute a defect of the digital content. The outputs are of an exclusively indicative and advisory nature.
5.2. The Provider warrants that the Service will be available and functional in the agreed scope for the duration of the subscription, except for scheduled maintenance and outages caused by force majeure or third-party infrastructure (e.g. Google Cloud Platform).
5.3. Limitation of damages (Liability Cap): The parties have agreed to limit the Provider's liability for any damage (financial or non-financial) arising in connection with the use of the Service:
- a) The Provider is in no case liable for lost profit, indirect damages, consequential damages, loss of data, loss of business opportunities or decisions made on the basis of AI-generated outputs.
- b) The Provider's liability for damage caused by simple negligence (mere omission or technical failure) towards the User is limited by a financial cap expressed in Czech koruna (CZK) according to the following formula: Llimit = max(1000; Σ Mi) for i = 1 … n, where n = 3 Where Mi is the monthly subscription fee actually paid by the User in month i, and n = 3 calendar months immediately preceding the month in which the damaging event occurred. The cap thus equals the higher of: CZK 1,000, or the sum of the fees for the last 3 months.
5.4. In accordance with Section 2898 of the Civil Code, the above limitation of liability does not apply to harm caused to a person's natural rights (e.g. health, personality rights), or to harm caused intentionally or by gross negligence. This limitation applies to Consumers to the maximum extent permitted by mandatory consumer protection rules.
6. Fair Use Policy (FUP)
6.1. The Provider sets maximum monthly audio processing limits for individual tariffs (e.g. free tariff: 60 minutes of recordings and 60 minutes of sparring per month).
6.2. If the User exceeds these limits, circumvents them by creating multiple accounts, or uses automated scripts (bots) to overload the API, the Provider is entitled to immediately limit the data transfer rate, temporarily suspend the Service or cancel the user account without compensation.
7. Civil recourse and indemnification clause (Recordings and data protection)
7.1. The User acknowledges that with respect to the audio recordings and the personal data of third parties captured in them, the User acts as an independent data controller under GDPR. The Provider is in the position of a technical processor that merely provides storage and analysis tools on the User's instructions.
7.2. The User undertakes to record only material for which they have a valid legal basis for processing the personal data of the affected third parties (e.g. demonstrable consent of meeting participants) and for which they have fulfilled the information obligation towards them under Art. 13 and 14 GDPR.
7.3. Indemnification clause: Since public-law liability for administrative offences and any criminal liability cannot be contractually transferred to another entity, the parties agree on a civil recourse claim. The User undertakes to fully indemnify, defend and hold the Provider harmless against any claims by third parties, legal costs, damages and in particular administrative fines finally imposed on the Provider by the Czech Office for Personal Data Protection (ÚOOÚ) or other supervisory authorities, arising as a result of:
- a) the User making a recording without a valid legal basis or without the consent of the affected persons;
- b) the User breaching the controller's obligations under GDPR, the Personal Data Processing Act or these terms.
7.4. The User must pay the Provider any such damage or recourse claim in full within 15 days of delivery of the Provider's written request, including legal costs associated with the defense in the relevant administrative or judicial proceedings.
8. Governing law, jurisdiction and out-of-court dispute resolution
8.1. All legal relationships arising under or in connection with the Service are governed exclusively by the law of the Czech Republic, excluding conflict-of-law rules and the UN Convention on Contracts for the International Sale of Goods.
8.2. Jurisdiction for Businesses (B2B): The exclusive local and subject-matter jurisdiction of the courts of the Czech Republic is agreed, specifically the competent court in Ostrava (based on the Provider's seat).
8.3. Out-of-court resolution for Consumers (B2C): In the event of a consumer dispute that cannot be resolved by mutual agreement, the Consumer has the right to file a proposal for out-of-court resolution with the designated alternative dispute resolution (ADR) body, which is the Czech Trade Inspection Authority (ČOI), Central Inspectorate – ADR department, Štěpánská 44, 110 00 Prague 1, adr.coi.cz.
8.4. The Consumer may also use the online dispute resolution platform set up by the European Commission at ec.europa.eu/consumers/odr.
PART C: Data Processing Agreement (DPA)
This Data Processing Agreement (the “DPA”) is concluded between the User (as the “Controller”) and VAPOL CZ s.r.o. (as the “Processor”) in accordance with Article 28(3) GDPR. This DPA is concluded automatically upon completion of the User's registration to the Service.
1. Subject, purpose and duration of processing
1.1. Subject of processing: The Processor undertakes to process for the Controller the personal data captured in audio recordings, transcripts and text analyses that the Controller creates, uploads or generates while using the VOXIBLY Service.
1.2. Purpose of processing: The purpose of processing is solely the technical provision of the Application's functions (storage of audio data, speech-to-text conversion, machine semantic analysis, text summarization and output management).
1.3. Duration: This DPA is concluded for the duration of the contractual relationship on the use of the Service (ToS) and ends with deletion of the user account.
2. Obligations of the Processor (VAPOL)
The Processor undertakes to fulfil the following statutory obligations under Art. 28 GDPR:
2.1. Controller's instructions: The Processor processes personal data only on the documented instructions of the Controller (including instructions given technically through the Application's user interface when starting a recording or analysis).
2.2. Data minimization and confidentiality: The Processor ensures that persons authorized to process personal data (e.g. vetted internal VAPOL developers) have committed to confidentiality or are under a statutory duty of confidentiality.
2.3. Security: The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Art. 32 GDPR), in particular:
- a) encryption of data in transit (HTTPS/TLS protocols) and encryption of data at rest on cloud storage (AES-256);
- b) strict access-rights management (IAM) preventing unauthorized access to databases;
- c) regular testing and backup of data to ensure availability and recoverability.
2.4. Assistance: The Processor is obliged to assist the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights and in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, breach notification, DPIA), to the extent corresponding to the nature of the processing and the information available to it.
2.5. Audits: Upon written request, the Processor will provide the Controller with all information necessary to demonstrate compliance with Art. 28 GDPR and will allow audits, including inspections, conducted by the Controller or an independent auditor. The cost of such an audit is borne entirely by the Controller.
2.6. Handling of data after termination: After termination of the Service and expiry of the 30-day grace period (see art. 5 of the Privacy Policy), the Processor will, at the Controller's decision, either delete or return all personal data and delete existing copies, unless EU or Member State law requires storage of the personal data.
3. Obligations of the Controller (User) and strict prohibition of sensitive data
3.1. The Controller bears full responsibility for determining the legal basis for processing the personal data in recordings and for fulfilling the information obligation towards the affected persons.
3.2. STRICT PROHIBITION OF PROCESSING SPECIAL CATEGORIES OF DATA (sensitive data): The Controller must ensure that recordings and their transcripts do not contain special categories of personal data under Article 9 GDPR, i.e. data revealing:
- racial or ethnic origin, political opinions, religious or philosophical beliefs;
- trade union membership;
- genetic data, biometric data processed for the purpose of unique identification;
- data concerning health, sex life or sexual orientation.
3.3. Exclusion of the Processor's liability: VAPOL has no technical or organizational mechanism to detect the presence of sensitive data. If the Controller breaches this prohibition, it does so at its own risk and responsibility. The Processor bears no liability for the processing of sensitive data in breach of Art. 9 GDPR. A breach of this prohibition establishes the Provider's right to immediately delete the data and block the user account.
4. Sub-processors
4.1. The Controller grants the Processor general written authorization to engage other processors (sub-processors).
4.2. The main sub-processor engaged by the Processor in processing recordings and analyses is Google Cloud EMEA Limited, with its seat at Velika Gordana, Dublin, Ireland (using Google Cloud Platform infrastructure in the EU).
4.3. The Processor undertakes to inform the Controller of any intended changes regarding the addition or replacement of other sub-processors (e.g. by notice in the Application or by e-mail), thereby giving the Controller the opportunity to object to such changes. The same data protection obligations as set out in this DPA must be imposed on the sub-processor.