1. Terms and Conditions
1.1 Preamble
Welcome to SummarizeBot! We (SIA Textifai, an entity registered in the Republic of Latvia) develop and deploy proprietary artificial intelligence (AI) solutions - including large and small language models (LLMs and SLMs) and classical natural language processing (NLP) systems - for various tasks such as: semantic search, summarization, question answering, sentiment analysis, named entity recognition, synthetic data generation, data extraction and analysis, documents analysis, AI workflow automation for Clinical Evaluation Reports (CERs) and literature reviews, news aggregation and analysis, fake news detection, hallucination detection in AI applications, AI agent development, speech recognition and more.
Our Products and Services include:
-
Document Intelligence Platform – search, analyze, answer questions from, summarize, and extract data from documents
-
CER Automation Platform – AI workflows tailored to Clinical Evaluation Reports
-
AI-powered NLP/LLM APIs (Cloud API Services)
-
Custom AI Agents (including retrieval-augmented generation approaches, proprietary AI "judges" and "agents")
-
Free Summarization Chatbots for Google Workspace, Slack, and Facebook Messenger
-
Sustainability Collaboration Platform
-
Sports Analytics Platform
-
Document Summarization Platform
-
E-discovery Platform
-
Literature Review Platform
-
Life Sciences Search Engine
You will find pricing for our paid products on our website.
Important Data Handling Notes
-
We do not train our AI models on user or client data, including data you provide to our free services.
-
We rely on publicly available anonymized datasets, synthetically generated data, and proprietary created datasets.
-
We maintain a human-in-the-loop approach to ensure responsible, transparent, and lawful operation.
By creating an account or using our platform/services, you accept these Terms of Use ("Terms" or "Agreement"), forming a legally binding agreement between SummarizeBot ("We," "Us," "Our") and you, the user ("Customer," "You," "Your"), covering your use and subscription to our Services.
1.2 Parties
These Terms of Use are entered into by and between:
1. SIA Textifai, a company incorporated under the laws of the Republic of Latvia ("SummarizeBot," "We," "Us," "Our");
2. You, an individual or organization (the "Customer" or "You") who accesses or uses our Services under these Terms.
1.3 What These Terms Cover
These Terms govern:
1. Your use of our Services (online platforms, webapps, tools, chatbots and APIs).
2. Additional Terms that may apply to specific features or subscription plans.
3. Our Data Processing Agreement (DPA) if you are a Commercial Customer (found in Section 5: Data Processing Agreement).
4. Our Privacy Policy (Section 4: Privacy Policy) and Cookie Policy (Section 6: Cookie Policy), which are incorporated by reference.
1.4 What These Terms Do Not Cover
These Terms do not apply if you access our Services via a partner-provided or third-party environment under separate terms or if specific partner-hosted deployment terms apply instead (see Section 3: Partner Hosted – Deployment Terms).
1.5 Definitions
-
Account: Your user account with SummarizeBot, either an Admin Account or Standard Account.
-
Administrator: Someone with an Admin Account managing or configuring the Services.
-
Agreement: Collectively, these Terms of Use, Additional Terms, the DPA, and referenced documents.
-
Applicable Data Protection Law: Any applicable privacy or data protection regulation, such as the GDPR.
-
Authorized Users: Your employees or contractors authorized to use the Services under your Subscription.
-
Beta Services: Services provided by us for testing prior to official release.
-
Billing Cycle: The frequency (e.g., monthly) of billing for Paid Services.
-
Commercial Customer: A user subscribing for business or professional purposes.
-
Consumer: An individual user acting outside their trade or profession.
-
Customer Offerings: Your products or services integrating our Services or Outputs.
-
Data Processing Agreement: The agreement governing data processing when we act as Data Processor (Section 5).
-
Effective Date: The earlier of (1) date you first use our Services or (2) date you accept these Terms.
-
End-Users: Individuals using your Customer Offerings reliant on our Services/Outputs.
-
Feedback: Your feedback to us (e.g., about our Services or Outputs).
-
Fees: Payments due for our Paid Services.
-
Filters: Automated content-moderation or risk-screening mechanisms.
-
Input: Any data (text, documents, images, etc.) you provide to the Services.
-
Intellectual Property: All recognized IP rights worldwide, including SummarizeBot’s AI models.
-
Model(s): Our proprietary AI models (LLMs, SLMs, classical NLP models) and related documentation.
-
Output: Any content generated by the Models in response to your Input.
-
Parties: SummarizeBot and You.
-
Payment Services: Payment gateways we use (e.g., Stripe, FastSpring).
-
Services: The range of SummarizeBot’s offerings, both free and paid (CER Automation, NLP/LLM APIs, etc.).
-
Subscription: Your subscription to our Services.
-
Subscription Plan: The plan tier specifying which Services/features you can use.
-
Support: Any support or maintenance services we provide.
-
Term: The duration of this Agreement (see Section 1.19: Term, Suspension, and Termination).
-
User Data: All data you submit or generate (including Input, Output, Feedback).
-
Workspace: An environment for Commercial Customers to configure and collaborate on Services.
1.6 Purpose and Scope
1.6.1 Purpose
These Terms detail both parties’ rights and obligations concerning SummarizeBot’s AI-powered services (Document Intelligence Platform, CER Automation Platform, NLP/LLM APIs, custom AI solutions, etc.).
1.6.2 Scope & Contractual Documents
1. Scope: These Terms govern all Subscriptions to and use of our Services.
2. Additional Terms: Certain features or plans may include additional conditions.
3. Hierarchy: If there is a conflict, Additional Terms override these Terms of Use.
1.7 Acceptance
By clicking "I agree" or using our Services, you confirm acceptance of these Terms.
If accepting on behalf of an organization, you represent you have authority to bind that organization.
1.8 Access to Our Services
1.8.1 Age Limitation
You must be at least 14 years old (or the age of digital consent in your jurisdiction) to use our Services.
1.8.2 Technical Requirements
You must have a compatible device and sufficient internet access to use the Services.
1.8.3 Costs
You bear any device, internet, or related costs for accessing the Services.
1.9 Your Account
1.9.1 Account Creation
Provide accurate info when creating an account.
SummarizeBot or its representatives may also create an account on your behalf.
1.9.2 Account Types
Admin Account: Full permissions for configuring Workspaces and inviting users.
Standard Account: Permissions set by an Administrator.
1.9.3 Security Obligations
Keep your login credentials secure.
Notify us immediately if you suspect unauthorized access.
1.9.4 Suspension/Deactivation
We may suspend or deactivate accounts for breaches of these Terms or suspected fraud/unlawful use (see Section 1.19).
1.10 Subscription
1.10.1 Free Services
Certain services (like our free summarization bots for Google Workspace, Slack, Facebook Messenger) are offered free of charge, subject to usage limits.
Even in these Free Services, we do not train our AI models on your data.
1.10.2 Paid Services
You must select a plan, provide billing/payment info, and pay applicable Fees.
A confirmation email is sent once payment is processed; you can then start the Paid Services.
We or our Payment Service Provider may perform anti-fraud or sanctions checks.
1.10.3 Changing Subscription Plan
You can upgrade/downgrade your plan, subject to available tiers and paying any applicable Fees.
1.11. Your Use of Our Services
1.11.1 Description of Our Services
SummarizeBot offers AI-driven capabilities, including:
-
Document Intelligence Platform – search, analyze, answer questions from, summarize, and extract data from documents.
-
CER Automation Platform – AI workflows tailored to Clinical Evaluation Reports.
-
AI-powered NLP/LLM APIs (Cloud API Services).
-
Custom AI Agents (including retrieval-augmented generation approaches, proprietary AI "judges" and "agents").
-
Free Summarization Bots for Google Workspace, Slack, and Facebook Messenger.
-
Sustainability Collaboration Platform
-
Sports Analytics Platform
-
Document Summarization Platform
-
E-discovery Platform
-
Literature Review Platform
-
Life Sciences Search Engine
These services may be free or paid, subject to rate limits or Additional Terms.
Support
Our customer support is available exclusively within the European Union. We do not outsource support operations to any party outside the EU. All customer inquiries are handled by our in-house support team, reachable at support@summarizebot.com.
1.11.2 Availability & Evolution
We strive for 24/7 uptime but may have downtime (maintenance, force majeure, etc.).
We may enhance or update the Services, remove outdated features, or discontinue certain models (with prior notice if feasible).
1.11.3 Beta Services
Provided "as is," with no guarantee of reliability or continued availability.
Feedback about Beta Services is owned by SummarizeBot.
1.11.4 Terms for Models API
Rate Limits: Free tiers may have strict usage limits; if you exceed them, we may block access unless you upgrade.
We Do Not Train on Your Data: Whether you are on a free or paid tier, your data (Input/Output) is never used to train our general AI models.
Zero Data Retention: If you need zero data retention for especially sensitive data, you can request it. Approval is at our discretion.
1.12 Your User Data
1.12.1 Responsibility
You are solely responsible for the accuracy, legality, and appropriateness of data you provide or process via the Services.
1.12.2 Ownership
Input: You retain all rights to the data you submit.
Output: You own the content generated in response to your Input (excluding SummarizeBot’s underlying model weights or code).
1.12.3 No Training on User Data
We do not train our AI models on user-provided data, including free tier data.
1.12.4 Data We Store
Emails & Contacts from contact forms.
Documents sent by Email (we store them to provide requested Services).
Documents uploaded to our Document Intelligence Platform or other SummarizeBot’s AI-powered platforms (you agree to our storing them by uploading).
Standard Marketing Data (e.g., for lead generation or analytics).
All in compliance with our Privacy Policy and Cookie Policy.
1.12.5 Accuracy & Moderation
AI outputs can be inaccurate or incomplete. You must verify them.
We employ filters, but we cannot guarantee all offensive content is removed.
1.13 Fees, Billing, and Payment
1.13.1 Fees
• Listed on our site or otherwise communicated.
• Subject to change with 30 days’ notice.
1.13.2 Billing
• Payment method required (credit card or other).
• Billing is per your chosen plan’s cycle.
1.13.3 Suspension for Non-Payment
We may suspend or terminate your Paid Services if Fees are overdue.
1.13.4 Commercial Customers
• Late payments may incur interest and collection costs.
• You are responsible for all taxes or duties.
1.14 Your Obligations
1. Comply with Laws: Use the Services in accordance with applicable laws.
2. Truthful Information: Provide accurate, updated info.
3. No Unauthorized Use: Don’t hack, misuse, or resell our Services.
4. Respect IP & Rights: No infringing or illegal content.
5. Security: Don’t attempt to bypass our security or cause disruptions.
1.15 Our Obligations
1. Reasonable Efforts: Keep the Services functional and secure.
2. Security Measures: Implement standard technical and organizational safeguards.
3. Illicit Content Reporting: If you see illicit or infringing content, report it to privacy@summarizebot.com.
1.16 Intellectual Property
1.16.1 License to Use Services
We grant you a non-exclusive, revocable license to use the Services during the Term, subject to these Terms.
1.16.2 SummarizeBot IP
SummarizeBot owns all rights to the Models, code, and associated IP. No implied license is granted.
1.17 Warranties and Indemnification
1.17.1 SummarizeBot Warranties
• Services are provided "as is," with no guarantees of fitness for a particular purpose.
• We disclaim liability for any decisions you make based on AI-generated content.
1.17.2 Customer Warranties
• You have the authority to use the Services and submit data.
• You will follow applicable laws and not infringe third parties’ rights.
1.17.3 Indemnification
• By SummarizeBot: We defend you against claims that our underlying technology (unmodified) infringes IP rights, except to the extent caused by your misuse or unauthorized changes.
• By You: You defend us against claims arising from your breach of these Terms or your data, including IP infringement from your Input or modifications.
1.18 Liability
1.18.1 Disclaimer
To the fullest extent allowed by law, SummarizeBot is not liable for:
• Force majeure events,
• Third-party network failures,
• Your misuse,
• Lost profits, data, or goodwill,
• Any indirect or consequential damages.
1.19 Term, Suspension, and Termination
1.19.1 Duration
These Terms commence on the Effective Date and continue until terminated.
1.19.2 Suspension
We may suspend your account for breach, non-payment, or security concerns, providing notice where feasible.
1.19.3 Termination
• For Convenience: You can terminate any time (for Paid Services, termination is effective at the end of the current Billing Cycle).
• For Cause: Either party may terminate for a material breach not cured within 30 days.
• Effects: Access ends; no refunds of pre-paid Fees. Surviving clauses remain (IP, liability limitations, etc.).
1.20. Personal Data
See our Privacy Policy (Section 4: Privacy Policy) and Data Processing Agreement (Section 5: Data Processing Agreement) for details on how we handle personal data in accordance with GDPR or other data protection laws.
1.21 Provisions for Consumers
If you are a Consumer, local consumer laws may give you additional rights (e.g., withdrawal rights).
1.22 Changes to These Terms
We may update or modify these Terms. If changes significantly affect your rights, we will provide 30 days’ notice. You may terminate if you disagree.
1.23 General Provisions
• Non-Waiver: Failure to enforce a provision is not a waiver of future enforcement.
• Severance: Invalid terms do not affect the remaining Terms.
• No Partnership: These Terms do not create a partnership or joint venture.
• Entire Agreement: These Terms plus references are the entire agreement.
• Force Majeure: Neither party is liable for events beyond their reasonable control.
1.24 Dispute Resolution & Applicable Law
• Governing Law: Laws of the Republic of Latvia, unless consumer-protection rules in your jurisdiction dictate otherwise.
• Amicable Resolution: We will attempt in good faith to resolve disputes first.
• Jurisdiction: Failing amicable resolution, disputes go to the courts of Riga, Latvia (unless arbitration is selected).
1.25 ISO 13485 Certification
We do not require ISO 13485 certification because our AI services merely extract, analyze, summarize, and process information; they do not perform regulated medical functions. Our software does not diagnose, treat, or otherwise directly influence patient outcomes. Hence, it falls outside the scope of medical device classification. While we do not adhere to ISO 13485, we maintain a high level of quality and security via robust internal processes.
2. AI Transparency Disclosure
2.1 Introduction
Welcome to SummarizeBot. We develop and deploy proprietary artificial intelligence (AI) solutions - including large and small language models (LLMs and SLMs) and classical natural language processing (NLP) systems - for various tasks such as semantic search, summarization, question answering, sentiment analysis, synthetic data generation, named entity recognition and more. Our commitment is to build and operate these AI systems in a responsible, transparent, and lawful manner.
Based on our assessment with the official EU AI Act Compliance Checker, our AI models, tools, platforms, and systems qualify as general-purpose AI and are therefore excluded from the scope of the EU AI Act, meaning we currently do not face specific obligations under that law. Nonetheless, we publish this disclosure to inform users and clients about our AI practices, as part of our dedication to ethical and transparent AI.
Important: If you intend to use our AI Services for high-risk decision-making scenarios (as defined by the EU AI Act or other regulations), please contact us before you begin. Such usage is prohibited without prior notice and coordination.
2.2 Scope
This disclosure applies to all AI-related features, services, platforms, APIs, and tools we offer (collectively, "AI Services"). By using our AI Services, you agree to the practices described herein, as well as in our Privacy Policy (Section 4) and Terms of Service (Section 1).
2.3 Our Approach to Responsible AI Development
2.3.1 Technology Stack
• We use a hybrid approach, combining classical NLP and statistical methods with more advanced techniques, including large language models (LLMs), small language models (SLMs), and Retrieval-Augmented Generation (RAG).
• We also deploy proprietary AI "judges" and agents to validate and reduce the risk of hallucinations or inaccuracies in LLM outputs.
2.3.2 Data Sources
• We do not train our models on user or client data.
• Our training data is derived from publicly available, anonymized datasets, synthetically generated data, and proprietary datasets that we own or license.
• All training occurs under human supervision (human-in-the-loop), ensuring we mitigate errors and biases.
2.3.3 Risk Assessment
• We conduct regular internal evaluations to classify our AI models as "High-Risk," "Limited Risk," or "Minimal Risk," based on the latest regulatory frameworks and industry standards.
• We update these evaluations to remain compliant with any evolving legal requirements or best practices.
2.3.4 Quality Assurance & Testing
• Our AI models undergo continuous testing and performance monitoring for accuracy, reliability, and fairness.
• We document error rates, biases, and other performance indicators to guide iterative improvements.
2.4 Transparency & User Awareness
2.4.1 Notification of AI Interaction
• We clearly indicate when a user is interacting with, or receiving an output from, an AI-driven component of our services.
• We provide disclaimers about potential limitations, such as the risk of inaccuracies or biases.
2.4.2 Explainability
• We strive to make our AI processes as explainable as possible, within the technical limits of our proprietary models.
• If you have questions about how an AI-driven output or decision was generated, please contact us at contacts@summarizebot.com.
2.5 Fairness & Non-Discrimination
2.5.1 Bias Monitoring & Mitigation
• We routinely analyze model outputs for potential biases and take steps to mitigate discriminatory results in line with ethical AI principles.
• We encourage users to report any biased or unfair outputs for further investigation.
2.5.2 Accessibility
We design our AI Services to be as accessible as possible, considering diverse user needs and ensuring inclusive access to our technologies.
2.6 Accountability & Governance
2.6.1 Leadership Oversight
• Our leadership team oversees AI compliance and ethical standards, ensuring alignment with internal policies and external regulations.
• Employees are trained on AI ethics, data protection, and relevant legal obligations.
2.6.2 Incident Reporting
If there is a data breach or an unintended AI behavior posing significant risk or harm, we will promptly notify affected parties and regulators as required by law.
2.7 Post-Market Monitoring
2.7.1 Continuous Improvement
• Even after deployment, we continuously monitor AI models for performance, data drift, and emerging risks.
• Updates and retraining are performed as necessary to maintain or improve the accuracy and safety of our systems.
2.7.2 User Feedback & Redress
• We encourage feedback on AI outputs at contacts@summarizebot.com.
• If you believe an AI-driven outcome is inaccurate or unfair, you can request a review or escalate the issue for further investigation.
2.8 High-Risk Usage Warning
• If you plan to deploy our AI Services in contexts that may be deemed high-risk—for example, where decisions could significantly impact individuals’ rights, health, or livelihoods - please contact us first.
• Using our AI solutions in such scenarios without our prior knowledge or consent is prohibited.
2.9 Updates to This Policy
We may update this AI Transparency Disclosure periodically to reflect changes in our practices, technology, or regulatory environment. When we do, the "Last Updated" date will be revised, and we will inform users as required.
2.10 Contact Us
If you have questions about this disclosure, wish to report an issue, or need more information on how we handle data in our AI Services, please reach out: privacy@summarizebot.com
3. Partner Hosted – Deployment Terms
3.1 Preamble
These Deployment Terms apply if you access SummarizeBot’s Models or Services via a Cloud Provider that hosts our solutions. They do not supersede your agreements with the Cloud Provider.
3.2 Definitions
• Cloud Provider: A third-party hosting environment.
• Cloud Infrastructure: The environment where SummarizeBot’s Models run, provided by the Cloud Provider.
• Specific Access: If you have direct access to underlying model weights or code.
3.3 Allocation of Responsibilities
1. SummarizeBot’s Role: We provide the Models, updates, and technical guidance to the Cloud Provider.
2. Cloud Provider’s Role: They handle subscription, billing, environment availability.
3. Your Role: Use the Models in compliance with these Deployment Terms, pay the Cloud Provider, and comply with relevant laws.
3.4 Your Use of Our Services
1. License: A non-transferable license to use SummarizeBot’s AI on the Cloud Infrastructure.
2. Support: Contact the Cloud Provider for first-level support; they escalate to us if needed.
3. Prohibited Actions: No reverse engineering, exploitation, or violation of IP rights.
3.5 Your User Data
SummarizeBot does not access or process your data on the Cloud Infrastructure unless you grant explicit permission for support. We do not train on your data in any scenario.
3.6 Payment
All payments go to the Cloud Provider under their terms.
3.7 Term, Suspension, Termination
• These Terms remain in effect until ended by you, SummarizeBot, or the Cloud Provider.
• SummarizeBot may request suspension if you breach these Terms.
• On termination, you lose rights to use the Models; we instruct the Cloud Provider to remove them.
3.8 Liability & Indemnification
• We disclaim liability for Cloud Infrastructure failures.
• Our total liability is limited to the Cloud Provider Fees you paid in the last 12 months.
• We indemnify you for IP claims except if caused by your misuse or modifications.
3.9 Personal Data & Confidentiality
• If we access personal data on your behalf, the DPA applies.
• Keep our proprietary model code (weights) confidential.
3.10 Governing Law & Dispute Resolution
• Governed by laws of the Republic of Latvia (unless agreed otherwise).
• Disputes go to the courts of Riga, Latvia, unless an arbitration agreement is in place.
4. Privacy Policy
4.1 Preamble
We are committed to protecting personal data. This Privacy Policy explains how SummarizeBot (SIA Textifai) handles data when acting as Data Controller (e.g., for account management, billing, marketing). If you are a Commercial Customer (acting as Data Controller), our Data Processing Agreement (Section 5: Data Processing Agreement) applies.
Our customer support is available exclusively within the European Union. We do not outsource support operations to any party outside the EU. All customer inquiries are handled by our in-house support team, reachable at support@summarizebot.com.
4.2 Definitions (GDPR-Specific)
1. "Personal Data", "Processing," "Data Controller," "Data Processor," "Data Subject," and "Supervisory Authority" have the meanings given by the GDPR.
2. "GDPR" means the General Data Protection Regulation (EU) 2016/679.
4.3 Data We Collect
4.3.1 Direct Collection
• Account Details: Name, email, password
• Payment Info: For billing if you subscribe to Paid Services.
4.3.2 Automatic Collection
• Logs: IP address, device info, timestamps.
• Cookies: Usage data, analytics (see Section 6: Cookie Policy).
4.3.3 Publicly Available Data
Our AI Models may be pre-trained on publicly available data; we do not incorporate your private data into our training sets.
4.4 Why We Use Your Data
1. Service Delivery: Account creation, usage analytics, security.
2. Billing & Administration: Invoicing, subscription management.
3. Marketing: With consent or legitimate interest (e.g., newsletter).
4. Legal Compliance: Tax regulations, responding to lawful requests.
5. Support: Handling queries, bug fixes.
4.5 Data Retention
• Account Data: Retained as long as your account is active + 1 year for evidentiary or legal obligations.
• Logs: Up to 1 year for security.
• Uploaded Documents: Typically retained for the duration of providing the Services or as instructed by you.
• Invoices: 10 years per financial regulations.
• Marketing Data: Up to 3 years from last contact.
4.6 Sharing Personal Data
We share data on a need-to-know basis with:
• Authorized SummarizeBot Staff,
• Payment Processors (e.g., Stripe, FastSpring),
• Hosting/Cloud Providers (AWS, Azure, GCP, etc.),
• Analytics/Monitoring services (Google Analytics, LinkedIn Pixel, etc.),
• Affiliates or advisors when legally required or for corporate transactions.
4.6.1 Sub-Processors
We engage certain sub-processors to deliver our Services. A non-exhaustive list:
Infrastructure Services
• Amazon Web Services (AWS) – EU/USA
• Microsoft Azure – EU/USA
• Google Cloud – EU/USA
• DigitalOcean – EU/USA
• Scaleway – EU
Analytics & Monitoring
• Google Pixel/Analytics/Ads – USA
• Facebook Pixel – USA
• LinkedIn Pixel – USA
• X - USA
• Quora - USA
Payment Processing
• Stripe – USA
• FastSpring – USA/EU
Communication & Messaging
• Slack – USA
• SendGrid (Twilio) – USA
• Gmail (Google) – USA
• Zoom – USA
• Instantly.ai – USA
AI/ML Tools and Services
• SummarizeBot – EU
• Hugging Face – USA
• OpenAI – USA
• Claude LLM / Anthropic – USA
We may update this list periodically. We ensure these sub-processors adhere to GDPR-level safeguards.
4.7 International Transfers
Some sub-processors or affiliates may be outside the EEA. We use Standard Contractual Clauses (SCCs) or equivalent measures to ensure adequate protection.
4.8 Your Rights (GDPR)
Depending on your jurisdiction, you may have:
• Right of Access, Rectification, Deletion, Restriction
• Right to Data Portability
• Right to Object to certain processing
• Right to Withdraw Consent (where processing is based on consent)
• Right to Lodge a Complaint with a Supervisory Authority
Contact us at privacy@summarizebot.com to exercise these rights.
4.9 Data Protection Officer
We have appointed a Data Protection Officer (DPO) reachable at:
• Email: dpo@summarizebot.com
• Address: Audeju street 15-4, Riga, Latvia, LV-1050, EU
4.10 Security Measures
We implement:
• Encryption (at rest and in transit),
• Access controls and authentication,
• Staff training on data protection,
• Incident detection/response procedures,
• Regular security assessments.
4.11 Data Breach Notification
We will notify affected parties without undue delay if we become aware of a personal data breach, providing details on the nature, scope, likely consequences, and remediation.
4.12 Updates
We may amend this Privacy Policy. Material changes will be notified with reasonable notice.
5. Data Processing Agreement
5.1 Preamble
This DPA supplements the Terms of Use if SummarizeBot acts as Data Processor on behalf of you, the Data Controller. In case of conflict, this DPA prevails regarding personal data processing matters.
5.2 Definitions
• Personal Data, Processing, Data Controller, Data Processor, Data Subject, Supervisory Authority have GDPR meanings (EU 2016/679).
• GDPR: The General Data Protection Regulation.
• Service Provider: SummarizeBot (SIA Textifai) acting as Data Processor.
• Client: The organization using our services, acting as Data Controller (Commercial Customer).
5.3 Roles and Responsibilities
1. Client as Controller: Determines the purposes and means of Processing Personal Data.
2. Service Provider (SummarizeBot) as Processor: Processes Personal Data only on documented instructions from the Client.
5.4 Data Protection Officer
If we have appointed a DPO (see Privacy Policy, Section 4.9: Data Protection Officer), you may contact them for data protection queries.
5.5 Scope of Processing
5.5.1 Nature and Purpose
We process Personal Data for:
• Document processing, storage, analysis (as part of our AI or document-intelligence features),
• Contract or business data analysis,
• Other related operations needed to provide our Services under the Agreement.
5.5.3 Categories of Data Subjects
• Client’s employees, customers, or other individuals whose data appears in processed content.
5.6 Instructions and International Transfers
We will only process Personal Data per the Client’s instructions, including for transfers to third countries. Where such transfers occur, we use SCCs or lawful transfer mechanisms.
5.7 Security Measures
We maintain appropriate technical and organizational measures (TOMs):
• Encryption (in transit and rest),
• Access controls,
• Incident response,
• Regular testing of security systems,
• Staff under confidentiality.
5.8 Subprocessing
1. List of Subprocessors: Listed in the Privacy Policy (Section 4.6.1: Sub-Processors).
2. General Authorization: The Client authorizes SummarizeBot to engage these subprocessors.
3. Engagement Requirements:
• Prior notice to the Client of new subprocessors,
• Ensuring subprocessors comply with GDPR requirements,
• Written agreements with subprocessors mirroring these obligations.
5.9 Data Subject Rights
We assist the Client in fulfilling data subject requests (access, rectification, erasure, portability, etc.) by providing appropriate technical/organizational tools.
5.10 Data Breach Notification
We notify the Client without undue delay if we become aware of a personal data breach, including details about scope, likely consequences, and mitigation steps.
5.11 Data Protection Impact Assessment
We help the Client conduct DPIAs where processing is likely to result in high risk to data subjects.
5.12 Audit Rights
• We make available documentation to demonstrate GDPR compliance.
• We allow audits/inspections by the Client or their mandated auditor, provided they give reasonable notice and follow agreed security measures.
5.13 Data Return and Deletion
Upon termination or at the Client’s request, we will return or securely delete all Personal Data, unless EU or Member State law requires storage.
5.14 Liability
SummarizeBot is liable only for damages caused by processing where it has breached GDPR obligations specifically directed to processors or acted outside Client instructions.
5.15 Updates and Amendments
We may update this DPA due to legal changes or recommendations from Supervisory Authorities. Material changes will be communicated with reasonable notice to the Client.
7. Security Policy
7.1 Information Security Program
We have an Information Security Program in place that is communicated throughout the organization. Our Information Security Program follows the criteria set forth by the SOC 2 Framework. SOC 2 is a widely known information security auditing procedure created by the American Institute of Certified Public Accountants.
7.2 Third-Party Audits
Our organization undergoes independent third-party assessments to test our security and compliance controls.
7.3 Third-Party Penetration Testing
We perform an independent third-party penetration at least annually to ensure that the security posture of our services is uncompromised.
7.4 Roles and Responsibilities
Roles and responsibilities related to our Information Security Program and the protection of our customer’s data are well defined and documented. Our team members are required to review and accept all of the security policies.
7.5 Security Awareness Training
Our team members are required to go through employee security awareness training covering industry standard practices and information security topics such as phishing and password management.
7.6 Confidentiality
All team members are required to sign and adhere to an industry standard confidentiality agreement prior to their first day of work.
7.7 Background Checks
We perform background checks on all new team members in accordance with local laws.
7.8 Cloud Security
7.8.1 Cloud Infrastructure Security
All of our services are hosted with Google Cloud Platform (GCP). They employ a robust security program with multiple certifications. For more information on our provider’s security processes, please visit GCP Security.
7.8.2 Data Hosting Security
All of our data is hosted on Google Cloud Platform (GCP) databases. Please reference the above vendor specific documentation for more information.
7.8.3 Encryption at Rest
All databases are encrypted at rest.
7.8.4 Encryption in Transit
Our applications encrypt in transit with TLS/SSL only.
7.8.5 Vulnerability Scanning
We perform vulnerability scanning and actively monitor for threats.
7.8.6 Logging and Monitoring
We actively monitor and log various cloud services.
7.8.7 Business Continuity and Disaster Recovery
We use our data hosting provider’s backup services to reduce any risk of data loss in the event of a hardware failure. We utilize monitoring services to alert the team in the event of any failures affecting users.
7.8.8 Incident Response
We have a process for handling information security events which includes escalation procedures, rapid mitigation and communication.
7.9 Access Security
7.9.1 Permissions and Authentication
Access to cloud infrastructure and other sensitive tools are limited to authorized employees who require it for their role.
Where available we have Single Sign-on (SSO), 2-factor authentication (2FA) and strong password policies to ensure access to cloud services are protected.
7.9.2 Least Privilege Access Control
We follow the principle of least privilege with respect to identity and access management.
7.9.3 Quarterly Access Reviews
We perform quarterly access reviews of all team members with access to sensitive systems.
7.9.4 Password Requirements
All team members are required to adhere to a minimum set of password requirements and complexity for access.
7.9.5 Password Managers
All company issued laptops utilize a password manager for team members to manage passwords and maintain password complexity.
7.10 Vendor and Risk Management
7.10.1 Annual Risk Assessments
We undergo at least annual risk assessments to identify any potential threats, including considerations for fraud.
7.10.2 Vendor Risk Management
Vendor risk is determined and the appropriate vendor reviews are performed prior to authorizing a new vendor.
7.11 Reporting Security Findings
7.11.1 Reporting Process
If you believe you’ve discovered a security vulnerability in our systems or services, we appreciate your efforts in notifying us promptly. Here’s how you can report security findings to our team:
• Review Our Responsible Disclosure Policy: Before submitting a report, please review our Responsible Disclosure Policy to understand the scope of acceptable findings and our commitment to addressing reported vulnerabilities.
• Submit a Security Report: To report a security vulnerability, please send an email to security@summarizebot.com with detailed information about the issue you’ve identified. Include any relevant technical details, steps to reproduce the vulnerability, and any potential impact on our systems or users.
• Response and Collaboration: Once we receive your report, our security team will review the information provided and investigate the reported vulnerability. We may reach out to you for additional details or clarification as needed. We’ll keep you informed of our progress and any actions taken to address the issue.
7.11.2 Responsible Disclosure Policy
Our Responsible Disclosure Policy outlines our commitment to working collaboratively with security researchers and members of the community to address security vulnerabilities in a timely and responsible manner. While we don’t operate a bug bounty program, we recognize the value of security research and may consider offering bounties for certain critical findings on a case-by-case basis. We consider those vulnerabilities that pose a severe risk to the confidentiality, integrity, or availability of our systems or user data. Examples include RCE, authentication bypass, and critical data leakage vulnerabilities.
7.11.3 Legal Considerations
Please note that any security testing or research activities should be conducted in accordance with applicable laws and regulations. Unauthorized access to or exploitation of our systems may be considered illegal and could result in legal consequences.
7.11.4 Contact Information
For questions or concerns about our security reporting process, please contact our security team at security@summarizebot.com.