Terms of Service
Effective: March 12, 2026
1. Agreement to Terms
These Terms of Service ("Terms") govern your access to and use of:
- The Omnitrex website at omnitrex.eu ("Website")
- The Omnitrex GRC platform at app.omnitrex.eu ("Hosted Service")
- Self-hosted deployments of the Omnitrex platform ("Software")
By accessing or using any of the above, you agree to be bound by these Terms. If you are acting on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.
2. Definitions
| Term | Meaning |
|---|---|
| "Omnitrex", "we", "us" | Omnitrex, KvK 99586355, Netherlands |
| "Customer", "you" | The individual or legal entity agreeing to these Terms |
| "Platform" | The Omnitrex GRC software application |
| "Hosted Service" | The Platform as hosted and managed by Omnitrex at app.omnitrex.eu |
| "Software" | The Platform source code as published under the BUSL-1.1 license |
| "Customer Data" | All data, content, and materials you upload to or create within the Platform |
| "Services" | The Hosted Service, the Website, and any related support or professional services |
| "Early Access Period" | The current period during which the Hosted Service is available at no charge, prior to the launch of paid plans |
3. Service Description & Early Access
Omnitrex is a Governance, Risk, and Compliance (GRC) platform supporting compliance with GDPR, DORA, AI Act, NIS2, ISO 27001, and SOC 2 frameworks. The Platform includes:
- Organizational modeling across 15 domains
- Risk-control mapping
- Audit logging
- Reporting and compliance gap analysis
- API and agent integrations
Early Access Notice
The Hosted Service is currently in Early Access. During this period:
- Access is provided at no charge
- No service level agreement (SLA) applies
- Features, APIs, and data formats may change
- We will provide reasonable notice before discontinuing the Early Access program
- Commercial terms (pricing, SLA, support tiers) will be published before general availability
- We will provide at least 30 days' notice and a data export period before any transition to paid plans
4. Editions & Licensing
A. Community Edition (Self-Hosted)
The Platform source code is licensed under the Business Source License 1.1 (BUSL-1.1). You may use, copy, modify, and redistribute the Software for any purpose, including production self-hosting.
Restriction: You may not offer the Software to third parties as a commercial hosted GRC service.
Clarifying examples:
- Permitted: Using Omnitrex internally for your organization's own compliance program
- Permitted: A consulting firm using Omnitrex for its own internal GRC processes
- Permitted: Modifying the source code for your own deployment
- Not permitted: Reselling or white-labeling Omnitrex as a hosted service to your clients
- Not permitted: Offering a managed Omnitrex instance as a competing SaaS product
On March 1, 2029 (or the fourth anniversary of each version's first public release, whichever is first), the license converts to Apache License 2.0.
Community Edition is provided without support or SLA. Community support is available via GitHub. Full license text: see LICENSE.md in the repository.
B. Professional Edition (Hosted)
A managed, Omnitrex-hosted edition is planned. Terms, pricing, and service levels will be published before the Professional Edition launches.
During the Early Access Period, access to the Hosted Service is governed by these Terms.
C. Enterprise Edition
Enterprise agreements are available for organizations requiring custom terms. Enterprise agreements may include:
- Custom SLA with uptime commitments
- Dedicated support with defined response times
- Custom Data Processing Agreement (DPA)
- Audit rights and compliance evidence
- Data residency requirements
- Onboarding and training
- Custom integrations and SSO configuration
- Negotiated liability terms
Contact info@omnitrex.eu for Enterprise inquiries.
5. Account Terms
- You must be at least 18 years old (or the age of legal majority in your jurisdiction) to use the Services
- You must provide accurate and complete registration information
- You must maintain the security of your account credentials. Password requirements: minimum 8 characters, including uppercase, lowercase, number, and special character
- You must notify us immediately of any unauthorized access to your account
- You are responsible for all activity under your account
- One account per person; organizational accounts are managed by the Customer
We may suspend accounts that violate these Terms, with notice except in cases of imminent security risk.
6. Customer Data & Ownership
You own your data. We claim no ownership of Customer Data.
- We process Customer Data solely to provide the Services
- We do not use Customer Data for advertising, profiling, or any purpose unrelated to service delivery
- We do not sell, rent, or trade Customer Data
- You grant us a limited, non-exclusive license to process Customer Data as necessary to operate the Services (including backups, security monitoring, and support)
- You are responsible for the legality of Customer Data you upload, including any personal data of third parties
Upon termination: see Section 13 (Data Portability & Switching).
7. Data Processing & Privacy
- Personal data processing is governed by our Privacy Notice
- For the Hosted Service: Omnitrex acts as a data processor (Art. 28 GDPR) with respect to personal data you upload. You remain the data controller
- A standalone Data Processing Agreement (DPA) is available on request and will be published at omnitrex.eu/dpa
- Until a signed DPA is in place, the data processing terms in this section and our Privacy Notice apply
- Sub-processors are listed in our Privacy Notice
- We will notify you of changes to sub-processors at least 30 days in advance
For the Community Edition (self-hosted): you are both controller and processor of any personal data stored in your own deployment. Omnitrex has no access to your self-hosted data.
8. AI-Powered Features
The Platform includes optional AI-powered features, including:
- Workflow automation prompts
- Agent integrations via MCP (Model Context Protocol)
- AI-assisted proposals and compliance analysis
AI features use third-party AI providers. Currently: Anthropic (Claude). Providers may change; we will update this section accordingly.
- AI output is not legal, regulatory, or compliance advice — see Section 9
- You control whether and how AI features are used within your account
- AI-generated changes are tracked in the audit log with model and session identifiers
- Customer Data sent to AI providers is governed by our Privacy Notice and the provider's data processing terms
- You own all content generated by AI features within your account
- AI features may produce inaccurate or incomplete results. You are responsible for reviewing and validating all AI-generated output before relying on it
- API keys used by AI agents are subject to the same rate limits and access controls as other API access
9. No Legal or Compliance Advice
The Platform is a tool, not a legal advisor. Omnitrex provides software to support your compliance program — it does not provide legal, regulatory, or compliance advice.
- Compliance assessments, gap analyses, risk scores, and framework mappings generated by the Platform are informational and should be independently verified
- We do not guarantee that use of the Platform will result in regulatory compliance
- You remain solely responsible for your organization's compliance obligations
- We recommend consulting qualified legal and compliance professionals for regulatory decisions
- Nothing in the Platform or these Terms creates a lawyer-client or advisor-client relationship
10. Acceptable Use
You agree not to:
- Use the Services in violation of applicable law (including GDPR, DORA, NIS2, or other regulations)
- Upload content that infringes third-party intellectual property rights
- Attempt to gain unauthorized access to the Services or other users' data
- Transmit malicious code or interfere with service operation
- Use the Services to store or process data in violation of export control laws
- Circumvent technical restrictions, rate limits, or access controls
- Use automated means to scrape or extract data from the Services (except via the documented API)
Violation may result in suspension or termination, with notice (except in cases of imminent security risk or legal obligation).
11. Intellectual Property
- Omnitrex IP: The Platform, its design, branding, documentation, and non-BUSL-1.1 proprietary components are owned by Omnitrex
- Software license: The Platform source code is licensed under BUSL-1.1 as described in Section 4. The license grants you specific rights to use, copy, modify, and redistribute — subject to the Additional Use Grant restriction
- Trademarks: "Omnitrex" and the Omnitrex logo are trademarks of Omnitrex. You may not use them without our written permission, except as required to comply with the BUSL-1.1 license
- Your IP: You retain all rights to your Customer Data. We claim no ownership of content you create using the Platform
- Feedback: If you provide suggestions, feature requests, or feedback, you grant us a non-exclusive, royalty-free, perpetual license to use that feedback to improve the Services. This does not apply to your Customer Data
12. Service Availability & SLA
- During Early Access: The Hosted Service is provided on an "as available" basis. No uptime commitment or SLA applies. We will use reasonable efforts to maintain availability, but the service may be interrupted for maintenance, updates, or unforeseen issues
- After General Availability: A published SLA with uptime commitments and service credits will apply to paid plans. Enterprise customers may negotiate custom SLA terms
- Planned maintenance: We will provide reasonable advance notice of scheduled maintenance
- Self-hosted deployments: Availability is your responsibility. We provide documentation but no uptime guarantee for self-hosted instances
13. Data Portability & Switching
Your data, your choice. No lock-in.
- You may export your Customer Data at any time via the Platform's export functionality, in standard machine-readable formats (CSV, JSON, XLSX)
- The Platform source code is publicly available under BUSL-1.1, providing an additional layer of portability — you can always inspect exactly how your data is stored and processed
If you decide to switch to another provider:
- You may terminate your account with no more than 2 months' notice (as required by Regulation (EU) 2023/2854, the EU Data Act)
- We will provide a 30-day transition period during which you can export all Customer Data
- We will provide reasonable switching assistance during the transition period at no additional charge
- After the transition period, we will delete your data in accordance with Section 15
These rights apply regardless of your edition or plan tier. We do not impose contractual, commercial, technical, or organizational barriers to switching.
14. Payment Terms
- During Early Access: The Hosted Service is provided at no charge. No payment is required
- After General Availability: Paid plans will be introduced with published pricing. We will notify existing users at least 30 days before paid plans take effect. You will not be charged without explicit consent. Existing free-tier or Community Edition users will not be retroactively charged
- Refunds (once paid plans are active): Governed by the applicable plan terms. We will comply with applicable Dutch and EU consumer protection law, although our services are directed at businesses (B2B)
15. Termination
By you
You may terminate at any time by contacting info@omnitrex.eu or using the account deletion feature. For the Community Edition, you may stop using the Software at any time (subject to the BUSL-1.1 license terms for any copies you retain).
By us
We may terminate or suspend your access if:
- You materially breach these Terms and fail to cure within 14 days of notice
- You use the Services in a way that poses a security risk or legal liability
- Required by law or court order
- We discontinue the Early Access program (with at least 30 days' notice)
Effect of termination
- Your access to the Hosted Service will cease
- You may export your Customer Data during a 30-day post-termination period
- After the 30-day period, Customer Data will be permanently deleted (with a 30-day soft-delete grace period as described on our Security page)
- Sections that by their nature should survive termination will survive (intellectual property, liability, governing law, data portability obligations)
16. Limitation of Liability
- Our total aggregate liability for any claims arising under or in connection with these Terms is limited to the total fees paid by you to Omnitrex in the twelve (12) months preceding the event giving rise to the claim
- During the Early Access Period (when no fees are charged), our total aggregate liability is limited to EUR 0 (zero)
- We are not liable for indirect, incidental, special, or consequential damages, including but not limited to: loss of profits, loss of data, loss of business opportunity, regulatory fines or penalties, or cost of procuring substitute services
Exclusions from the cap
The above limitations do not apply to:
- Liability arising from gross negligence (grove schuld) or willful misconduct (opzet) by Omnitrex
- Liability that cannot be limited under mandatory Dutch law
- Your payment obligations (once paid plans are active)
These limitations apply to the maximum extent permitted by Dutch law (Book 6 of the Dutch Civil Code) and reflect the allocation of risk between the parties.
17. Changes to These Terms
- We may update these Terms from time to time
- Material changes: we will notify you via email (if we have your address) or a prominent notice on the website, at least 30 days before the changes take effect
- Non-material changes (formatting, clarifications): effective immediately upon posting
- If you do not agree with material changes, you may terminate your account before the changes take effect
- Continued use of the Services after the effective date constitutes acceptance
- Previous versions of these Terms will be archived and available on request
18. General Provisions
A. Governing Law
These Terms are governed by the laws of the Netherlands. Applicable EU regulations (including GDPR, the EU Data Act, and the Digital Services Act) apply directly.
B. Dispute Resolution
Any disputes arising from these Terms shall be submitted to the exclusive jurisdiction of the Amsterdam District Court (Rechtbank Amsterdam). Before initiating proceedings, both parties will attempt to resolve the dispute informally within 30 days.
C. Entire Agreement
These Terms, together with the Privacy Notice, Security page, and any applicable DPA or Enterprise Agreement, constitute the entire agreement between you and Omnitrex.
D. Severability
If any provision of these Terms is found unenforceable, the remaining provisions remain in full force.
E. Assignment
We may assign these Terms in connection with a merger, acquisition, or sale of substantially all assets, with notice to you. You may not assign without our written consent.
F. No Waiver
Failure to enforce any provision does not waive our right to enforce it later.