virbe.
Legal documentVersion 2

Terms of Service

Effective November 16, 2026

Summary (not part of the Terms). Virbe provides a business-only platform for building and running conversational AI assistants ("virtual beings") on websites, in kiosks and in apps. You own your data, inputs and outputs, and we never use them to train AI models. You choose and configure the AI providers your assistants use. Under the EU AI Act we provide the platform and its built-in transparency features, and you deploy your assistants responsibly, in line with our Acceptable Use Policy. Our liability is limited as set out in Section 17. Higher service levels, liability caps and indemnities are available under an Enterprise Agreement. Polish law applies.

1. Who we are and how these Terms apply

1.1. The Services are provided by Virbe sp. z o.o., ul. Tomasza Zana 11A, 20-601 Lublin, Poland, entered in the register of entrepreneurs of the National Court Register kept by the District Court for Lublin-Wschód in Lublin with its seat in Świdnik, VI Commercial Division of the National Court Register, under KRS number 0000780459, NIP 9462687906, REGON 383015364, share capital PLN 6,000 ("Virbe", "we", "us"). You can contact us at [email protected] (legal matters), [email protected] (data protection) and [email protected] (support).

1.2. These Terms of Service ("Terms") govern access to and use of the Services by the Customer. They also constitute the terms and conditions for services provided by electronic means (regulamin) within the meaning of Article 8 of the Polish Act of 18 July 2002 on Providing Services by Electronic Means. We make these Terms available free of charge before the Agreement is concluded, in a form that can be downloaded, stored and printed.

1.3. The Agreement is concluded when the Customer (a) accepts these Terms during sign-up or in the Dashboard, (b) signs or accepts an Order Form or Enterprise Agreement that refers to these Terms, or (c) purchases the Services through a Marketplace. The person accepting these Terms on behalf of an organisation confirms that they are authorised to bind that organisation, and the organisation is the Customer. An Authorized User who is not authorised to bind the Customer, and who is asked to accept these Terms in the Dashboard, accepts them only as the rules for their own use of the Services under the Agreement concluded by the Customer.

2. Definitions and interpretation

2.1. In these Terms, the following capitalised terms have the meanings below:

  • "Affiliate" means an entity that controls, is controlled by or is under common control with a party, where control means direct or indirect ownership of more than 50% of the voting rights.
  • "Agreement" means these Terms together with the documents listed in Section 3.1 that apply to the Customer.
  • "AI Act" means Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, as amended.
  • "Aggregated Data" means statistical or other information derived from the use and operation of the Services that is aggregated or de-identified so that it does not identify the Customer, any End User or any other natural person.
  • "Authorized User" means an individual whom the Customer allows to access the Dashboard or other administrative interfaces of the Services under the Customer's account, such as employees and contractors of the Customer.
  • "Customer" or "you" means the business entity that concludes the Agreement with Virbe.
  • "Customer Agent" means a conversational assistant, virtual being, workflow or other configuration that the Customer builds, configures or operates with the Services.
  • "Customer Data" means all data that the Customer, its Authorized Users or End Users submit to, or generate through, the Services, including Inputs, Outputs, conversation transcripts, audio, Knowledge Base content, configuration, prompts and system instructions, but excluding Usage Data and Aggregated Data.
  • "Customer-Hosted" means a Hosting Mode in which the Platform runs in infrastructure controlled by the Customer, such as the Customer's own Microsoft Azure subscription deployed through a Marketplace.
  • "Dashboard" means the web interface through which Authorized Users configure and manage Customer Agents.
  • "Data Act" means Regulation (EU) 2023/2854 on harmonised rules on fair access to and use of data.
  • "Documentation" means the user documentation for the Services published by Virbe (currently at https://docs.virbe.ai or within the Dashboard), as updated from time to time.
  • "DPA" means Virbe's Data Processing Agreement available at https://virbe.ai/dpa, which forms part of the Agreement.
  • "End User" means a natural person who interacts with a Customer Agent, for example through a Widget, a Kiosk or an application built by the Customer.
  • "Enterprise Agreement" means a separate agreement or Order Form signed by Virbe and the Customer (on paper or electronically) that expressly supplements or overrides these Terms.
  • "Exportable Data" means the data and digital assets of the Customer listed in Annex B.1.
  • "Fees" means the fees payable for the Services under the applicable Plan, Order Form or Marketplace offer.
  • "GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
  • "Hosting Mode" means Virbe-Hosted or Customer-Hosted.
  • "Inputs" means any content provided to a Customer Agent or the Services, including End User messages and voice, documents and Knowledge Base content, prompts and configuration.
  • "Kiosk" means a physical device on which the Customer runs the Kiosk Application.
  • "Knowledge Base" means the documents, web pages, records and other content that the Customer adds to the Services so that Customer Agents can use it to answer questions.
  • "Kiosk Application" means the downloadable Virbe software for running Customer Agents on Kiosks.
  • "Marketplace" means a third-party marketplace through which the Services may be purchased, such as Microsoft Azure Marketplace.
  • "Order Form" means an ordering document, quote or online checkout that specifies the Services, Plan, Fees and Subscription Term.
  • "Outputs" means content generated by the Services or by AI models in response to Inputs, including text, synthetic speech and avatar animation.
  • "Plan" means the subscription plan, licence or package selected by the Customer, with the features, limits and Fees described on Virbe's pricing page or in the Order Form.
  • "Platform" means Virbe's software platform, including the Virbe Hub, the Dashboard, APIs, SDKs, the Widget and the Kiosk Application.
  • "Provider Credentials" means API keys or other credentials for Third-Party Services.
  • "Services" means the Platform and related services provided by Virbe under the Agreement, including support.
  • "Subscription Term" means the period for which the Customer has subscribed to the Services, including any renewal.
  • "Third-Party Services" means services, models, engines and content not provided by Virbe, such as large language models (LLMs), speech-to-text (STT), text-to-speech (TTS), voice cloning, conversational engines, avatar technologies, webhooks and custom endpoints, that the Customer chooses to connect to the Services, in particular using its own Provider Credentials.
  • "Usage Data" means technical and operational data about the use of the Services, such as logs, performance metrics, feature usage, conversation counts and billing measurements. To the extent Usage Data contains Customer Personal Data (as defined in the DPA), Virbe processes it only as a processor under the DPA.
  • "Virbe Content" means content provided by Virbe as part of the Services, such as stock avatars, characters, 3D models, animations, voices, templates and sample content.
  • "Virbe-Hosted" means a Hosting Mode in which the Platform runs in cloud infrastructure operated by or for Virbe.
  • "Widget" means the Virbe web component that embeds a Customer Agent in a website or web application.

2.2. Headings are for convenience only. "Including" means "including without limitation". References to legislation include that legislation as amended or replaced.

3. Documents and order of precedence

3.1. The Agreement consists of the following documents, which apply in this order of precedence in case of conflict:

  1. an Enterprise Agreement, if any;
  2. an Order Form, if any;
  3. the DPA, in relation to the processing of personal data;
  4. these Terms;
  5. the Acceptable Use Policy (https://virbe.ai/legal/acceptable-use-policy), the Service Level Agreement (https://virbe.ai/legal/service-level-agreement) and the other policies referred to in these Terms;
  6. the Documentation.

3.2. An Enterprise Agreement may override any provision of these Terms, the DPA, the Acceptable Use Policy and the Service Level Agreement, including the liability provisions, and may fix the version of these documents and of the Documentation that applies to the Customer.

3.3. Any general terms and conditions of the Customer, including purchasing terms referred to in purchase orders, vendor portals or similar documents, do not apply, even if Virbe does not object to them, unless Virbe expressly accepts them in an Enterprise Agreement. Virbe hereby declares, within the meaning of Article 385⁴ § 2 of the Polish Civil Code, that it does not intend to conclude the Agreement on terms other than those of the documents listed in Section 3.1.

3.4. The Privacy Policy (https://virbe.ai/privacy) is an information notice and does not form part of the Agreement.

4. Business customers only

4.1. The Services are intended exclusively for businesses, public bodies and other organisations acting for purposes related to their trade, business, craft or profession. They are not offered to consumers. By accepting these Terms the Customer confirms that it concludes the Agreement for such purposes.

4.2. If the Customer is a natural person conducting business activity in Poland, and the Agreement is directly connected with that activity but is not of a professional nature for that person (in particular in light of the business activity codes registered in the Central Register and Information on Economic Activity (CEIDG)), then, to the extent required by Article 385⁵ of the Polish Civil Code and Article 7aa of the Polish Consumer Rights Act of 30 May 2014: (a) provisions of these Terms considered prohibited contractual provisions do not bind that Customer; (b) the Customer may withdraw from the Agreement within 14 days of its conclusion without giving reasons by notice to [email protected], and if the Customer expressly requested, on a durable medium, that the Services start before the end of that period, it pays for the Services provided up to the withdrawal in proportion to the agreed Fees; and (c) the statutory rules on the conformity of digital services with the contract apply. Section 23.11 does not apply to such a Customer's choice of court.

5. The Services

5.1. The Services enable the Customer to build, configure, deploy and monitor Customer Agents that converse with End Users by text and voice and that may be represented by animated avatars, through the Widget, Kiosks, APIs and other channels described in the Documentation. The functionality, limits and technical requirements of each Plan are described on Virbe's pricing page, in the Order Form and in the Documentation. The minimum technical requirements are set out in Annex A.

5.2. Hosting Modes. The Services are provided in the Hosting Mode selected by the Customer:

  • (a) Virbe-Hosted: Virbe operates the Platform in cloud infrastructure in the region selected by the Customer when setting up the Services, or, if none is selected, in the European Union. Virbe does not move Customer Data out of the selected region without the Customer's prior consent, as described in Section 8 of the DPA.
  • (b) Customer-Hosted: the Platform is deployed in the Customer's own infrastructure (for example, its Microsoft Azure subscription). The Customer is responsible for that infrastructure, including its security, availability, region, backups, costs and the contracts with its cloud provider. Virbe has no standing access to a Customer-Hosted deployment and accesses it only at the Customer's request for support, maintenance or upgrades.

5.3. Updates. Virbe continuously develops the Services and may update, improve or modify them. Virbe will not materially reduce the core functionality of a paid Plan during the current Subscription Term, except where required by law, for security reasons or because a Third-Party Service is no longer available. Virbe will give at least 30 days' notice of the discontinuation of a material feature, unless this is not possible for reasons beyond its control. For Customer-Hosted deployments, the Customer triggers upgrades itself, or requests them from Virbe under an Enterprise Agreement; Virbe supports the current major version of the Platform and the version immediately preceding it.

5.4. Beta Features. Virbe may offer features designated as beta, preview, early access or similar ("Beta Features") for testing and evaluation. Beta Features are provided "as is", may be changed or discontinued at any time, are not covered by the Service Level Agreement and are excluded from the switching obligations of Chapter VI of the Data Act to the extent permitted by Article 31(2) of the Data Act.

5.5. Trials. If Virbe offers a free trial or free Plan, the Customer may use the Services for the duration and within the limits stated in the offer. Unless the Customer moves to a paid Plan, Virbe may delete Customer Data 30 days after the end of the trial.

5.6. Subcontractors. Virbe may use subcontractors to provide the Services and remains responsible for their performance under the Agreement. Third-Party Services are not subcontractors of Virbe (see Section 10).

6. Accounts and Authorized Users

6.1. The Customer must provide accurate and complete account and billing information and keep it up to date.

6.2. The Customer is responsible for its Authorized Users and for all activity under its account, and must ensure that Authorized Users comply with the Agreement. The Customer must keep credentials (including Profile Secrets and Provider Credentials) confidential, use multi-factor authentication where available, promptly remove access for persons who no longer need it, and notify Virbe without undue delay at [email protected] of any suspected unauthorised access.

6.3. Access is limited to the number of Authorized Users, Customer Agents, Kiosks, usage volumes and other limits of the Plan. Credentials may not be shared between individuals.

7. Plans, Fees, payment and taxes

7.1. The Fees, billing frequency and currency are stated in the Order Form, at checkout or on Virbe's pricing page. Usage-based charges (for example, for conversations, minutes or tokens above the Plan's allowance) are calculated from Virbe's Usage Data, which is the basis for billing unless the Customer shows it to be incorrect.

7.2. Renewal. Unless the Order Form states otherwise, subscriptions renew automatically for successive periods equal to the initial billing period, unless either party gives notice of non-renewal before the end of the current period (for self-serve Plans, by cancelling in the Dashboard).

7.3. Payment. Self-serve Fees are charged in advance through Virbe's payment provider (currently Stripe), which may store the Customer's payment method; the Customer authorises recurring charges for renewals and usage-based charges. Invoiced Fees are payable within 14 days of the invoice date by bank transfer. Purchases made through a Marketplace are billed and collected by the Marketplace operator under its terms.

7.4. Invoices. Virbe issues invoices electronically, including through the Polish National e-Invoicing System (KSeF) where required by law. The Customer agrees to receive invoices and payment reminders electronically.

7.5. Taxes. Fees are exclusive of VAT and other taxes and duties, which the Customer pays in addition where applicable. For Customers established in another EU Member State and registered for VAT, the reverse-charge mechanism applies; the Customer must provide a valid VAT number.

7.6. Late payment. If the Customer does not pay on time, Virbe may charge statutory interest for delay in commercial transactions and the fixed compensation for recovery costs under the Polish Act of 8 March 2013 on Counteracting Excessive Delays in Commercial Transactions, and may suspend the Services in accordance with Section 15.2.

7.7. Price changes. Virbe may change its prices for the next renewal period by giving at least 30 days' notice before the renewal. Prices fixed in an Order Form apply for the term stated in it.

7.8. No refunds. Fees are non-refundable and the Customer is not entitled to credits for unused periods, downgrades or unused allowances, except where the Agreement expressly provides otherwise (Sections 15.5, 16.1, 18.3, 20.3 and 23.3 and Section 7.3 of the DPA) or mandatory law requires.

8. Customer Data, Inputs and Outputs

8.1. Ownership. As between the parties, the Customer retains all rights in Customer Data. Virbe does not acquire any rights in Customer Data other than the licence in Section 8.2.

8.2. Licence to Virbe. The Customer grants Virbe a non-exclusive, worldwide, royalty-free licence, for the duration of the Agreement and the periods in Section 18, to host, store, copy, transmit, process, display and adapt Customer Data solely to provide, secure and support the Services, to comply with law and to exercise its rights under the Agreement, including by transmitting Customer Data to Third-Party Services configured by the Customer.

8.3. No training. Virbe does not use Customer Data to train, fine-tune or otherwise improve any AI model, whether Virbe's own or a third party's. This includes Aggregated Data derived from the content of Inputs, Outputs or Knowledge Base content. Where Virbe itself engages AI model providers to process Customer Data (Section 10.3), it does so only on terms that prohibit the provider from using Customer Data to train its models. The handling of data by Third-Party Services connected with the Customer's own Provider Credentials is governed by the Customer's contract with that provider.

8.4. Usage Data and Aggregated Data. Virbe may collect Usage Data and create and use Aggregated Data to operate, secure, bill, analyse, maintain and improve the Services. Virbe does not disclose Usage Data that identifies the Customer to third parties, except to its subcontractors or as required by law. The creation of Aggregated Data from personal data is carried out on the Customer's instruction under the DPA.

8.5. Customer responsibilities. The Customer is responsible for Customer Data and Customer Agents, including: (a) the lawfulness of Inputs and of the way it collects End User data; (b) having all rights, licences and consents needed for Virbe and Third-Party Services to process Customer Data under the Agreement; (c) the accuracy, completeness, timeliness and legality of Knowledge Base content, prompts and configuration; and (d) its own backups of Customer Data it considers critical, including by using the export functions of the Services.

8.6. Personal data. Each party complies with the GDPR and other applicable data protection laws. Virbe processes personal data in Customer Data as the Customer's processor under the DPA. The Customer must not design Customer Agents to request special categories of personal data (Article 9 GDPR) or data relating to criminal convictions unless this is agreed in an Enterprise Agreement, and should not design them to request payment card data, passwords or government identifiers unless it has a lawful basis and appropriate safeguards and has configured the Services accordingly (for example, using PII redaction and short retention periods).

9. AI Features

9.1. Intended purpose. The Services are intended to be used to build and operate conversational assistants (text, voice and animated "virtual beings") that provide information, customer service, sales assistance, guidance and engagement to natural persons, including on Kiosks with optional on-device presence detection and audience analytics. They are not intended for any practice prohibited by Article 5 of the AI Act, or for any use listed in Annex III of the AI Act or any other use that would make the Services or a Customer Agent a high-risk AI system ("Restricted Uses"). Restricted Uses are permitted only under an Enterprise Agreement that expressly allows them and allocates the related obligations.

9.2. Roles under the AI Act. Virbe acts as the provider of the Platform as an AI system placed on the market under Virbe's name. The Customer acts as the deployer of the Services and of its Customer Agents. Where the Customer makes a Customer Agent available under its own name or trademark, or substantially modifies it, so that it qualifies as a provider of that Customer Agent, the Customer is responsible for the provider obligations relating to its modifications and must keep the transparency features described in Section 9.3 enabled. Virbe hereby clearly specifies, within the meaning of Article 25(2) of the AI Act, that the Services are not to be changed into, or used as, a high-risk AI system. If the Customer nevertheless uses the Services for a Restricted Use, the Customer is responsible for all resulting obligations, including those of a provider under Article 25(1) of the AI Act.

9.3. Transparency. To meet the transparency obligations of Article 50 of the AI Act:

  • (a) Virbe designs the Widget, the Kiosk Application and voice channels so that End Users are informed, at the latest at the start of the interaction, that they are interacting with an AI system. This disclosure is enabled by default. The Customer may adapt its wording and presentation within the limits described in the Documentation but must not disable it, hide it or make it ineffective, and must not present Customer Agents or Outputs as human. Where the Customer builds its own interface on the APIs or SDKs, the Customer implements an equivalent disclosure in that interface.
  • (b) Virbe marks Outputs delivered through the Widget, the Kiosk Application and the APIs (text, audio and video) in a machine-readable format and makes them detectable as artificially generated, where and to the extent technically feasible, regardless of the engine used, and preserves marks applied by model providers, in line with the Code of Practice on transparency of AI-generated content. The Customer must not remove or tamper with such marks.
  • (c) As deployer, the Customer is responsible for: (i) informing natural persons exposed to camera-based features of Kiosks in accordance with Article 50(3) of the AI Act (Section 9.7); (ii) disclosing that content has been artificially generated or manipulated where an avatar, voice or other Output resembles an existing person, object, place or event (a "deep fake" or digital replica) in accordance with Article 50(4) of the AI Act; and (iii) labelling AI-generated text that it publishes to inform the public on matters of public interest, unless an exception applies.

9.4. Nature of Outputs. The Customer acknowledges that Outputs are generated by probabilistic AI models and may be inaccurate, incomplete, outdated, biased, offensive or not unique, even when the Services work correctly ("model errors", sometimes called hallucinations). A model error is not, in itself, a defect of the Services. A defect of the Services is a failure of the Platform to operate materially in accordance with the Documentation, such as a Customer Agent not responding, executing the wrong flow because of a defect in the Platform, or failing to call a configured model. Outputs do not constitute legal, financial, medical, tax or other professional advice and do not express Virbe's views.

9.5. Human oversight. The Customer is responsible for: (a) designing, testing and monitoring its Customer Agents before and after going live; (b) following the Documentation and the guidance of the relevant model providers; (c) using appropriate safeguards, such as Knowledge Base grounding, content filters, escalation to a human and clear notices to End Users not to rely on Outputs for important decisions; (d) ensuring that Outputs are reviewed by a competent person before they are used as the basis for decisions that produce legal or similarly significant effects for any person; and (e) taking measures, appropriate to its circumstances and whether or not Article 4 of the AI Act applies to it, to support a sufficient level of AI literacy of its staff and others operating the Services on its behalf. Virbe supports this through the Documentation.

9.6. AI models and engines. The Services work with AI models and engines of third-party providers. Their availability, behaviour and terms are determined by those providers and may change. Virbe may add, replace or remove the models and engines that Virbe itself provides (including pre-provisioned engines and models provided under an Enterprise Agreement), giving at least 30 days' notice of any change that materially affects the Customer's Customer Agents, unless the change is required by law, for security reasons or because the provider deprecates or withdraws the model at shorter notice, in which case Virbe gives notice as soon as reasonably practicable. Models and engines that the Customer connects with its own Provider Credentials are not changed by Virbe. The Customer must comply with the usage policies of the model providers whose models its Customer Agents use.

9.7. Kiosk camera features. Camera-based features of the Kiosk Application (such as presence detection and age or gender estimation) are disabled by default and process camera images locally on the Kiosk; only aggregated statistics are transmitted to the Services. If the Customer enables them, the Customer, as controller and deployer, must: (a) have a lawful basis for the processing and carry out a data protection impact assessment where required; (b) place clear notices, before persons enter the camera's field of view, informing them of the operation of the system in accordance with Article 50(3) of the AI Act and Articles 13 and 21 GDPR; (c) not use these features to identify individuals, to infer emotions or sensitive characteristics, in workplaces in relation to the Customer's employees, in educational institutions or in places primarily intended for minors, or to target or exploit persons because of their age, disability or social or economic situation; and (d) not adapt the treatment of individual persons in a way that produces legal or similarly significant effects on the basis of these features. Virbe may restrict the availability of these features in particular jurisdictions or Plans where needed to comply with law.

9.8. Incidents and cooperation. The Customer will inform Virbe without undue delay at [email protected] if it becomes aware of a malfunction of the Services or of a serious incident within the meaning of the AI Act involving a Customer Agent. Each party will provide the other with information reasonably necessary to comply with the AI Act, subject to Section 13.

10. Third-Party Services and the Enterprise proxy

10.1. The Customer may connect Third-Party Services to the Services, in particular by entering its own Provider Credentials. When the Customer does so: (a) the Customer chooses the provider and the relevant terms are agreed directly between the Customer and that provider; (b) Virbe transmits Customer Data to that provider on the Customer's instruction and only as needed for the configured function; and (c) the provider is not Virbe's subcontractor or sub-processor, and Virbe is not responsible for its services, availability, security, data handling or Outputs. The Customer should review each provider's terms, including on data retention, data location and model training, before going live.

10.2. Some third-party technologies or content used in the Services (for example avatar frameworks, 3D assets or engines) are subject to the licence terms of their owners, which are listed or linked in the Documentation. The Customer must comply with those terms.

10.3. Virbe-provided engines and the Enterprise proxy. Where Virbe provides or pre-provisions models or engines with its own credentials, or acts as an intermediary between the Customer's deployment and a model provider under an Enterprise Agreement, the provider acts as Virbe's sub-processor and is listed at https://virbe.ai/legal/subprocessors. Virbe passes through to the Customer the service commitments that it receives from that provider and, except as required by the DPA or mandatory law, does not assume obligations regarding that provider's services beyond what the provider itself offers.

11. Acceptable use; voice and likeness

11.1. The Customer must use the Services in accordance with the Agreement, the Documentation, applicable law and the Acceptable Use Policy, and must ensure that its Authorized Users and, through appropriate terms or notices, its End Users do the same. The Customer must not provide, or allow the provision of, unlawful content through the Services.

11.2. The Customer must not, and must not allow anyone to: (a) reverse engineer, decompile or disassemble the Platform, except to the extent permitted by mandatory law; (b) resell, sublicense or make the Services available to third parties other than End Users interacting with Customer Agents, unless agreed in an Enterprise Agreement; (c) circumvent usage limits, security measures, content filters or transparency features; (d) use the Services to build a competing product or to train AI models; or (e) interfere with the integrity or performance of the Services.

11.3. Voice and likeness. If the Customer uses the image, likeness, voice or name of a real person (including to create a custom avatar, voice or other digital replica, whether through Virbe or a Third-Party Service), the Customer represents and ensures that: (a) the person is an adult and has given free, specific, informed and documented consent, which the Customer will provide to Virbe on request; (b) the Customer holds all rights required under copyright and personality rights law, including Article 81 of the Polish Act on Copyright and Related Rights and Articles 23 and 24 of the Polish Civil Code; (c) the use is not misleading, does not impersonate the person without authorisation and is disclosed in accordance with Section 9.3(c); and (d) the Customer will stop the use and delete the related assets if consent is withdrawn.

12. Intellectual property

12.1. Virbe and its licensors retain all rights in the Services, the Platform, the Documentation, Virbe Content, Usage Data and Aggregated Data, and in any improvements to them. No rights are granted except as expressly stated in the Agreement.

12.2. Licence to the Customer. During the Subscription Term, Virbe grants the Customer a non-exclusive, non-transferable, worldwide licence, without the right to sublicense (except to its Affiliates and contractors acting on its behalf), to use the Services, Documentation and Virbe Content for its business purposes, including operating Customer Agents for End Users, within the limits of the Plan. The licence covers the following fields of exploitation: (a) for software (including the Kiosk Application, the Widget and SDKs): permanent or temporary reproduction, in whole or in part, by any means and in any form, to the extent necessary to install, display, run, transmit and store it for the purposes of using the Services; and (b) for Virbe Content and Documentation: recording and reproduction by digital technique, public display, public performance and making available to the public in such a way that members of the public may access it from a place and at a time individually chosen by them, as part of Customer Agents and in the Customer's materials presenting its Customer Agents (including on social media).

12.3. Outputs. Virbe does not claim any rights in Outputs. To the extent Virbe holds any rights in Outputs, it grants the Customer a non-exclusive, worldwide, perpetual, irrevocable, royalty-free and transferable licence to use them, in the fields of exploitation listed in Section 12.2(b) as well as fixation, reproduction by any technique, distribution, adaptation and translation. Outputs may not be protected by copyright, and similar Outputs may be generated for other customers. An assignment of rights in Outputs requires an Enterprise Agreement concluded in written form or with qualified electronic signatures.

12.4. Feedback. If the Customer provides suggestions or feedback about the Services, Virbe may use them without restriction or compensation.

12.5. The Customer may identify Virbe as a technology provider. Virbe may name the Customer (including by logo) as a customer in its marketing materials unless the Customer objects by notice to [email protected].

13. Confidentiality

13.1. Each party will keep confidential all non-public information disclosed by the other party in connection with the Agreement that is marked as confidential or should reasonably be understood to be confidential, including Customer Data, the terms of any Enterprise Agreement, security reports and pricing ("Confidential Information"). The receiving party will use Confidential Information only to perform the Agreement and will disclose it only to its employees, Affiliates, subcontractors and advisers who need to know it and are bound by equivalent obligations.

13.2. These obligations do not apply to information that is or becomes public without breach, was lawfully known to the receiving party before disclosure, is lawfully received from a third party without confidentiality obligations, or is independently developed. A party may disclose Confidential Information where required by law or by a competent authority, after informing the other party where legally permitted.

13.3. These obligations continue for 5 years after the end of the Agreement and, for trade secrets, for as long as they remain trade secrets.

14. Data protection

14.1. The DPA applies to the processing of personal data by Virbe on behalf of the Customer and is concluded by accepting these Terms. The Customer may request a copy of the DPA signed by Virbe at [email protected].

14.2. Virbe processes personal data of the Customer's representatives and Authorized Users as a controller, as described in the Privacy Policy.

15. Suspension

15.1. Virbe may suspend the Services, in whole or in part, to the extent and for as long as reasonably necessary if: (a) the Customer's use poses a security risk to the Services or to others, or may cause harm to End Users or third parties; (b) the Customer or a Customer Agent materially breaches Section 9, Section 11 or the Acceptable Use Policy, or provides unlawful content; (c) suspension is required by law or by a competent authority; or (d) the conditions in Section 15.2 are met.

15.2. If any undisputed Fees are more than 14 days overdue, Virbe may suspend the Services after giving the Customer at least 7 days' notice.

15.3. Virbe will limit any suspension to the affected Customer Agents, features or Authorized Users where practicable, and will give prior notice unless urgent action is needed to prevent harm or comply with law, in which case it will notify the Customer promptly after the suspension. Each notice will include a statement of reasons in accordance with Article 17 of Regulation (EU) 2022/2065 (Digital Services Act) where that regulation applies, provided at the latest when the suspension takes effect.

15.4. The Customer may contest a suspension at [email protected]. A person at Virbe will review the request and respond within 14 days. Virbe will lift the suspension once its cause has been remedied.

15.5. If a suspension under Section 15.1(a) or (c) that was not caused by the Customer lasts more than 30 consecutive days, the Customer may terminate the affected Services and Virbe will refund prepaid Fees for the remaining Subscription Term.

16. Warranties and disclaimers

16.1. Virbe will provide the Services with reasonable skill and care and in material accordance with the Documentation. If the Services do not conform to this warranty, the Customer must notify Virbe in accordance with Section 21, and Virbe will, at its option, correct the non-conformity within a reasonable time or, if it cannot do so, allow the Customer to terminate the affected Services and refund prepaid Fees for the remaining Subscription Term. This is the Customer's sole remedy for such non-conformity, without prejudice to Section 22 and to liability under Section 17.1.

16.2. Except as expressly stated in the Agreement, and to the fullest extent permitted by law, the Services, Virbe Content and Outputs are provided "as is" and "as available". Virbe does not warrant that the Services will be uninterrupted or error-free, that Outputs will be accurate, complete or suitable for any purpose, or that the Services will meet requirements that the Customer has not agreed in an Order Form or Enterprise Agreement. Statutory warranty for defects (rękojmia) is excluded to the extent permitted by Article 558 § 1 of the Polish Civil Code.

16.3. Virbe is not responsible for Third-Party Services, the Customer's infrastructure (including Customer-Hosted deployments and Kiosk hardware), public networks, or failures caused by the Customer's configuration, Knowledge Base content or failure to follow the Documentation.

17. Liability

17.1. Unlimited liability. Nothing in the Agreement excludes or limits either party's liability: (a) for damage caused intentionally or through gross negligence; (b) for death or personal injury; (c) under the rules implementing Directive 85/374/EEC or Directive (EU) 2024/2853 on liability for defective products, or any other liability that cannot be limited under mandatory law; or (d) of the Customer, for payment of the Fees, under Section 17.6 or for breach of Section 9.1, Section 11 or the Acceptable Use Policy.

17.2. Excluded losses. Subject to Section 17.1, neither party is liable for loss of profits (utracone korzyści), revenue, business, goodwill or anticipated savings, or for indirect or consequential losses, whether foreseeable or not.

17.3. Data obligations cap. Subject to Section 17.1, each party's total liability arising from breach of its obligations under the DPA, Section 13 (Confidentiality) or Section 18 (data export, switching and deletion) is limited to the greater of: (a) the total Fees paid and payable by the Customer for the Services in the 12 months preceding the event giving rise to the liability; and (b) EUR 2,000. Liability under this Section is not counted towards the cap in Section 17.4.

17.4. General cap. Subject to Sections 17.1 and 17.3, each party's total liability for all other claims arising out of or in connection with the Agreement, whether in contract, tort or otherwise, is limited to the greater of: (a) the total Fees paid and payable by the Customer for the Services in the 6 months preceding the event giving rise to the liability; and (b) EUR 1,000.

17.5. Enterprise terms. Higher liability caps, indemnities for intellectual property infringement claims, enhanced service levels and other extended commitments are available only under an Enterprise Agreement.

17.6. Customer indemnity. The Customer will hold Virbe and its Affiliates harmless from, and reimburse them for, losses, damages, fines and reasonable costs (including legal fees) arising from third-party claims or regulatory proceedings that result from: (a) Customer Data or Customer Agents, including claims by End Users; (b) use of the Services in breach of the Agreement or the law; (c) the use of a person's image, likeness or voice in breach of Section 11.3; or (d) Third-Party Services connected by the Customer; except to the extent the claim, fine or loss results from Virbe's breach of the Agreement or the DPA or from Virbe's own infringement of law. Virbe will notify the Customer of the claim promptly, allow the Customer to conduct its defence and cooperate reasonably at the Customer's expense, and will not settle the claim without the Customer's consent, which may not be unreasonably withheld.

17.7. Recourse. If Virbe is held liable to a third party under mandatory product liability or similar rules for damage caused in whole or in part by Customer Data, the Customer's configuration or modification of the Services, or a Third-Party Service connected by the Customer, the Customer will reimburse Virbe to the extent of its contribution.

17.8. Personal data claims by data subjects under Article 82 GDPR are not limited by this Section in relation to the data subjects; this Section governs the allocation of liability between the parties.

18. Term, termination, data export and switching

18.1. Term. The Agreement starts when it is concluded and continues for as long as the Customer has an active Subscription Term or uses the Services.

18.2. Termination by the Customer. The Customer may terminate the Agreement: (a) at any time, with effect at the end of the current billing period, by cancelling in the Dashboard or by notice to [email protected]; or (b) under Sections 15.5, 18.3, 18.4 or 20.3. If the Customer terminates before the end of a fixed Subscription Term, including by switching under Section 18.5, the early termination fee stated in the Order Form or at checkout applies (if none is stated, none applies), and Fees prepaid for that term are not refunded. These conditions are disclosed to the Customer before the Agreement is concluded, in accordance with Article 29 of the Data Act.

18.3. Termination for breach. Either party may terminate the Agreement with immediate effect by notice if the other party materially breaches the Agreement and fails to remedy the breach within 30 days of receiving notice describing it (or 14 days for non-payment). Virbe may terminate with immediate effect, without a remedy period, for a serious breach of Section 9.1, Section 11 or the Acceptable Use Policy that by its nature cannot be remedied, such as a prohibited AI practice or the creation of a digital replica without consent. If the Customer terminates under this Section, Virbe refunds prepaid Fees for the remaining Subscription Term.

18.4. Either party may terminate the Agreement with immediate effect if the other party becomes insolvent, enters liquidation, or if continuing the Agreement would breach applicable sanctions.

18.5. Switching and export (Data Act). In accordance with Chapter VI of the Data Act:

  • (a) The Customer may at any time request to switch to another provider of data processing services or to its own ICT infrastructure, or to export its Exportable Data, by notice to [email protected]. The Customer may set a notice period of up to 2 months; at the end of the notice period Virbe starts the switching process.
  • (b) The transitional period during which Virbe provides the switching assistance and continues the Services lasts up to 30 calendar days. If this is technically unfeasible, Virbe will inform the Customer within 14 working days of the request, give reasons and indicate an alternative transitional period of up to 7 months, during which the Services continue at the applicable Fees.
  • (c) During the transitional period Virbe provides reasonable assistance, including by providing all relevant information to support the Customer's exit strategy, acts with due care to maintain business continuity, informs the Customer of known risks to continuity and maintains a high level of security. The Customer may extend the transitional period once, for a period it considers more appropriate, by notice before it ends.
  • (d) After the transitional period, the Customer may retrieve its Exportable Data for at least 30 days (the "retrieval period").
  • (e) After the retrieval period Virbe erases all Exportable Data and other Customer Data in accordance with the DPA, and confirms the erasure on request, unless law requires their retention.
  • (f) Upon successful completion of switching, the Agreement terminates and Virbe notifies the Customer. If the Customer requests only the erasure of its Exportable Data and not switching, the Agreement terminates at the end of the notice period.
  • (g) The Exportable Data, the data excluded from export and the available formats are listed in Annex B. Information about switching procedures, formats, standards and known limitations is available at https://virbe.ai/legal/trust-and-data-location.
  • (h) Virbe does not charge any switching or data export fees.

18.6. Effect of termination. When the Agreement ends, the Customer's right to use the Services ends, and Virbe makes Customer Data available for export for 30 days and then deletes it in accordance with the DPA. Sections 7 (for Fees accrued before termination), 8, 12, 13, 17, 18.5(d) and (e), 18.6, 21.3 and 23, and any provisions that by their nature are intended to survive, continue to apply.

19. Notices of illegal content and points of contact

19.1. To the extent that Virbe provides a hosting service within the meaning of Regulation (EU) 2022/2065 (Digital Services Act), the following applies:

  • (a) Points of contact. The single point of contact for authorities of the Member States, the European Commission and the European Board for Digital Services, and for recipients of the Services, is [email protected]. Communications may be made in Polish or English.
  • (b) Notices. Any person may notify Virbe of content stored in the Services that they consider illegal by sending a notice to [email protected] containing: a sufficiently substantiated explanation of why the content is considered illegal; the exact electronic location of the content (for example the URL of the website with the Customer Agent and a description of the conversation or Output); the name and e-mail address of the person submitting the notice (except for notices concerning offences relating to child sexual abuse); and a statement confirming the bona fide belief that the notice is accurate and complete. Virbe confirms receipt, processes notices in a timely, diligent, non-arbitrary and objective manner, informs the notifier of its decision and of the possibilities for redress, and states whether automated means were used to process the notice or take the decision.
  • (c) Content moderation. Virbe does not monitor Customer Data in general. It acts on notices, on reports from model providers' safety systems and on its own security monitoring. Measures may include restricting a Customer Agent or content, suspension under Section 15 or termination. Automated tools may be used to detect abuse (for example content filters of model providers), but decisions to restrict a Customer's account are taken or reviewed by a person. The Customer is informed by a statement of reasons and may contest the decision under Section 15.4.
  • (d) If Virbe becomes aware of information giving rise to a suspicion that a criminal offence involving a threat to the life or safety of persons has taken place, is taking place or is likely to take place, it promptly informs the law enforcement or judicial authorities of the Member State or Member States concerned and provides all relevant information available.

19.2. The Customer is responsible, as operator of its Customer Agents and websites, for handling notices and complaints of End Users concerning its own content and Customer Agents.

20. Changes to these Terms

20.1. Virbe may change these Terms, the DPA, the Acceptable Use Policy and the Service Level Agreement for valid reasons, such as changes in law or regulatory guidance, changes to the Services, security requirements or changes in Third-Party Services. Virbe publishes each version with its effective date at https://virbe.ai/legal, where previous versions remain available.

20.2. Virbe will notify the Customer of material changes by e-mail to the account's contact address and in the Dashboard at least 30 days before they take effect. Changes that are required by law or a competent authority, or that are needed to address security risks, may take effect sooner if necessary. Changes that only benefit the Customer or are purely editorial may take effect on publication.

20.3. If the Customer does not accept a material change, it may terminate the Agreement with effect from the date the change takes effect by notice given before that date, and Virbe will refund prepaid Fees for the period after termination. If the Customer continues to use the Services after the effective date, the change applies. Virbe may require Authorized Users to confirm acceptance of a new version in the Dashboard.

20.4. Changes do not apply to the extent an Enterprise Agreement fixes the version of these Terms that applies to the Customer. Acceptance of a new version by an Authorized User in the Dashboard does not amend an Enterprise Agreement.

21. Complaints

21.1. The Customer may submit complaints regarding the Services, including non-conformity with the Agreement, to [email protected] or [email protected]. A complaint should include the Customer's account details, a description of the problem and, where possible, the date, the affected Customer Agent and any relevant screenshots or logs.

21.2. Virbe will respond to the complaint within 30 days of receiving it, by e-mail to the address from which it was submitted, unless the Customer asks for another channel.

21.3. Claims under the Agreement should be notified within 12 months of the date on which the Customer became aware of the circumstances giving rise to them, without prejudice to statutory limitation periods.

22. Service levels and support

22.1. For paid Plans in the Virbe-Hosted mode, Virbe provides the Services in accordance with the Service Level Agreement. Service credits under the Service Level Agreement are the Customer's sole financial remedy for unavailability, without prejudice to Section 17.1.

22.2. Virbe provides support through the channels and within the hours described in the Service Level Agreement and the Documentation. Support for Customer-Hosted deployments is limited to the Platform and does not cover the Customer's infrastructure.

22.3. Enhanced service levels, dedicated support, maintenance windows and change-control processes are available under an Enterprise Agreement.

23. General provisions

23.1. Previous versions. These Terms replace any previous terms and conditions of Virbe accepted by the Customer, from the earlier of: (a) their acceptance by the Customer, including by an Authorized User in the Dashboard; and (b) the date on which they take effect under the change provisions of the previous terms.

23.2. Assignment. The Customer may not assign or transfer the Agreement without Virbe's prior consent in documentary form. Virbe may assign the Agreement to an Affiliate or to a successor in a merger, acquisition or transfer of its business, by notice to the Customer.

23.3. Force majeure. Neither party is liable for failure or delay in performing its obligations (other than payment obligations) caused by events beyond its reasonable control, including natural disasters, war, terrorism, epidemics, governmental actions, large-scale failures of public networks or energy supply, and outages or withdrawal of third-party cloud or AI services that Virbe could not reasonably avoid. The affected party will notify the other party and use reasonable efforts to mitigate the effects. If a force majeure event lasts more than 60 days, either party may terminate the affected Services, and Virbe refunds prepaid Fees for the period after termination.

23.4. Notices and form. Notices under the Agreement may be given in documentary form (forma dokumentowa, Article 77² of the Polish Civil Code), including by e-mail: to Virbe at [email protected], and to the Customer at the e-mail address of its account owner or as stated in the Order Form. Amendments to an Enterprise Agreement require the form stated in it.

23.5. Sanctions and export control. The Customer represents that neither it nor its owners or End Users it knowingly serves are subject to sanctions of the European Union, the United Nations, the United Kingdom or the United States, including under Council Regulations (EU) No 833/2014 and No 269/2014, and that it will not use the Services in breach of sanctions or export control laws. Virbe may suspend or terminate the Services as necessary to comply with such laws.

23.6. Independent parties. The parties are independent contractors. The Agreement does not create a partnership, joint venture or agency.

23.7. Severability. If any provision of the Agreement is invalid or unenforceable, the remaining provisions remain in force, and the invalid provision will be replaced by a valid provision that comes closest to its economic purpose.

23.8. No waiver. Failure to exercise a right is not a waiver of it.

23.9. Change in law. If a change in applicable law or binding regulatory guidance (including under the EU Digital Omnibus legislation) materially affects the performance of the Agreement, the parties will negotiate in good faith the amendments needed, and Virbe may update these Terms in accordance with Section 20.

23.10. Language. These Terms are drawn up in English. If Virbe provides a translation, the English version prevails, except where mandatory law requires otherwise.

23.11. Governing law and jurisdiction. The Agreement and any non-contractual obligations arising from it are governed by the laws of Poland, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods. The parties will first try to resolve disputes amicably, including through the complaint procedure in Section 21. Disputes that cannot be resolved amicably are subject to the exclusive jurisdiction of the common courts competent for Virbe's registered office in Lublin, Poland.

Annex A — Technical requirements, installed software and support period

A.1. Dashboard. A current version of Google Chrome, Microsoft Edge, Mozilla Firefox or Apple Safari on a desktop computer, with JavaScript enabled and a stable internet connection.

A.2. Widget. Current versions of the major desktop and mobile browsers (Chrome, Edge, Firefox, Safari on macOS, Windows, Android and iOS) supporting Web Components and WebGL, with JavaScript enabled. Voice features require microphone access granted by the End User.

A.3. Kiosk Application. A Windows device meeting the minimum hardware requirements in the Documentation (current minimum: 4-core CPU, 16 GB RAM, a dedicated GPU with ray-tracing support), a microphone and loudspeakers, and optionally a camera for the features described in Section 9.7.

A.4. Software installed on the Customer's or End User's devices (information under Article 6 of the Polish Act on Providing Services by Electronic Means):

  • The Widget is a JavaScript component loaded in the End User's browser from Virbe's servers. It renders the Customer Agent, transmits messages and, if enabled, microphone audio to the Services, and may store technical data in the browser (such as a session identifier) that is necessary to maintain the conversation. Details are in the Cookie Policy (https://virbe.ai/legal/cookie-policy).
  • The Kiosk Application is installed by the Customer on Kiosks. It runs Customer Agents, captures microphone audio for speech recognition and, if enabled, processes camera images locally for the features described in Section 9.7. It connects to the Services to download configuration and updates and to transmit conversations and aggregated analytics.
  • Use of the Services involves the usual risks of electronic communication, such as malware, phishing and unauthorised access to accounts or devices. The Customer should keep devices updated, protect credentials and follow the security guidance in the Documentation.

A.5. Security updates. Virbe provides security updates for each major version of the Kiosk Application and the Widget, without additional charge, for at least 5 years from its release, or until Virbe makes a supported successor version available free of charge to the Customer, whichever is earlier, and handles vulnerabilities in accordance with Regulation (EU) 2024/2847 (Cyber Resilience Act) as it becomes applicable. Vulnerabilities can be reported to [email protected].

Annex B — Exportable Data (Data Act)

B.1. Exportable Data. The following data and digital assets of the Customer can be exported in the formats indicated:

  • conversation transcripts and conversation metadata (JSON or CSV);
  • stored conversation audio, where audio storage is enabled (original format);
  • Knowledge Base content uploaded or created by the Customer (original files where stored, otherwise text in Markdown or JSON);
  • configurations of Customer Agents, including flows, prompts, system instructions, variables, profiles and settings (JSON);
  • analytics reports available in the Dashboard (CSV);
  • custom assets uploaded by the Customer, such as images, avatars and audio files (original formats);
  • data on Authorized Users and their roles (CSV or JSON);
  • usage and billing records relating to the Customer's account (CSV);
  • on request, vector embeddings of the Customer's Knowledge Base content, together with the identifier of the embedding model used (JSON).

B.2. Excluded data. The following are excluded from export because they are Virbe's internal data or would compromise the security or integrity of the Services or infringe the rights of Virbe or third parties: source code and binaries of the Platform; Virbe Content (stock avatars, voices, animations), which remain licensed only under Section 12.2; Aggregated Data and Usage Data relating to more than one customer; security logs; Virbe's own Provider Credentials; and the internal index structures of the Platform other than the embeddings listed in Annex B.1.

B.3. Means of export. Exportable Data can be exported through the export functions of the Dashboard and the APIs described in the Documentation and, where these are insufficient, with Virbe's assistance on request to [email protected].