The agreement for organisations using a Summa business workspace. Together with the Order Form, the Data Processing Agreement and the schedules, these terms form the Agreement between Schmeitzke and the customer.
1. Parties and structure
The supplier is Schmeitzke, trading as Summa / Summa Labs, registered in the Netherlands (KVK 91878381). The customer is the entity identified in the Order Form or business registration flow, and the individual accepting the Agreement represents they have authority to bind the customer.
The Order Form, these Business Terms, the Data Processing Agreement and the schedules form the "Agreement". In the event of conflict: mandatory law prevails; the DPA prevails for personal-data processing; the Order Form prevails for commercial details; and the Business Terms prevail over other schedules.
2. Service and authorised users
Summa provides an organisation-managed AI workspace with agreed features such as authorised-user accounts, role and membership administration, AI conversations and history, usage controls, audit events, data export, and billing and seat administration. The scope, plan, seat count, fees and any special commitments are stated in the Order Form.
The customer may permit employees, contractors and other authorised individuals to use the service for the customer’s internal business purposes, and is responsible for assigning users and roles, removing access promptly, ensuring administrators are properly authorised, informing users about workplace processing, and ensuring lawful and policy-compliant use.
3. AI functionality and customer responsibility
The customer acknowledges that users interact with an AI system, that output may be inaccurate or unsuitable and requires human review, that Summa does not provide regulated professional advice, and that the customer remains responsible for decisions and downstream use. The customer must not use output as the sole basis for a high-impact decision concerning an individual.
4. Customer data and data-protection roles
"Customer Data" means content and personal data submitted to or generated within the customer workspace, excluding Summa’s software, models, general service metadata and pre-existing intellectual property. As between the parties, the customer retains its rights in Customer Data and grants Summa the limited rights necessary to provide and secure the service, follow instructions, prevent misuse, comply with law, and defend legal claims.
For Customer Data processed to provide the workspace, the customer is controller and Summa is processor; the DPA applies. Summa acts independently as controller for its own contract administration, billing, platform security, fraud prevention, legal compliance, supplier management and aggregated service administration. Summa will not use Customer Data to train or fine-tune the general Summa model unless the customer enters into a separate written agreement.
5. Lawful instructions and restricted use cases
The customer warrants that it has a lawful basis for Customer Data, provides necessary information to data subjects, gives lawful instructions, and has assessed any special-category or high-risk processing. Summa may suspend an instruction and notify the customer where it reasonably believes the instruction breaches applicable law.
Unless expressly approved in an Order Form, the service is not certified for classified government information, full payment-card data, patient-record systems, biometric identification, criminal-intelligence databases, safety-critical control, autonomous high-impact decisions, or data subject to sector-specific hosting the service has not obtained.
6. Fees, seats, term and renewal
Business prices exclude VAT unless the Order Form states otherwise. Fees may be based on purchased or active seats; a reduction ordinarily takes effect at the next renewal. No overage charge applies unless its calculation and price were disclosed before the relevant usage.
The initial term and billing cycle are in the Order Form. Unless stated otherwise, monthly subscriptions renew monthly, annual subscriptions renew annually, fees are charged in advance, and the Agreement renews until properly terminated. The customer’s notice period will not exceed two months.
7. Security, confidentiality and availability
Summa maintains the Technical and Organisational Measures in the applicable schedule and will not materially reduce overall security during the term. The customer remains responsible for endpoint and device security, internal access governance, lawful instructions, credential protection, and appropriate data classification. Each party protects the other’s confidential information using at least reasonable care.
Unless an Order Form includes an SLA, the service is provided without a contractual uptime percentage; Summa uses commercially reasonable efforts to maintain availability and communicate material incidents. Beta functionality is subject to the Beta Schedule.
8. Suspension, termination and exit
Summa may suspend affected access where reasonably necessary for an immediate security risk, unlawful or prohibited use, non-payment, legal compliance, or to protect other customers, giving notice and a reasonable opportunity to remedy except in urgent circumstances. Either party may terminate for material breach not remedied within 30 days after written notice; immediate termination is permitted where the breach cannot be remedied or continued performance would be unlawful.
On termination, access ends as agreed, accrued fees remain payable, the customer may retrieve exportable data under the Data Act Exit Schedule, and Summa returns or deletes Customer Data in accordance with the DPA.
9. Intellectual property and warranties
Summa and its licensors retain all rights in the platform software, interfaces, model-serving architecture, documentation, improvements, trademarks and general know-how. The customer receives a non-exclusive, non-transferable right to use the service during the term for its internal purposes. AI output may not be unique; the customer must review output before publication or commercial reliance.
Summa warrants that it will provide the service with reasonable care and skill, materially follow the service description, maintain the agreed security measures, and comply with law applicable to it as service provider and processor. No warranty is given that AI output is factually correct, legally sufficient, non-infringing, or suitable for an unreviewed decision.
10. Liability
Neither party excludes liability that cannot legally be excluded, or is liable for indirect, consequential or remote loss except where such exclusion is not permitted. Subject to the following, each party’s aggregate liability is limited to the fees paid or payable in the 12 months preceding the event. A separate aggregate cap equal to twice that amount applies to breach of confidentiality, breach of the DPA, or a security breach caused by failure to maintain committed measures.
The caps do not apply to intentional misconduct or deliberate recklessness, death or personal injury caused by negligence, unpaid fees, infringement caused by a party’s unauthorised use of the other’s intellectual property, or liability that applicable law prohibits from being limited.
11. Compliance evidence, governing law and disputes
On reasonable request and subject to confidentiality, Summa provides available information reasonably necessary to assess security measures, subprocessors, data locations, incident management, backup and continuity, AI governance and compliance status, without disclosing information that would materially weaken security or violate another party’s rights.
Dutch law applies. The parties first escalate disputes to authorised commercial representatives; if unresolved, the District Court of Limburg, Maastricht location, has exclusive jurisdiction, unless mandatory law requires otherwise.