Legal · Terms of ServiceLast updated August 2026

The terms we operate under.

What the platform does, what you can expect from us, and what we expect from you — written plainly, section by section.

These terms bind every workspace on oathly.ai.They are between Oathly ApS and the organisation that creates a workspace. Where an order form has been signed, it takes precedence. Personal data we process on a customer's behalf is covered by the data processing agreement; data we handle in our own right is covered by the privacy policy.

01Introduction

These Terms of Service govern access to and use of the oathly.ai platform, the oathly.ai website, and any trust centers published with it (together, the Service). They form an agreement between Oathly ApS, a private limited company (anpartsselskab) registered in Denmark under CVR number 46654897 (VAT DK46654897), with its registered office at A.P. Møllers Allé 43B, 2791 Dragør, Denmark (oathly.ai, we, us) and the organisation that creates a workspace (the Customer).

By creating an account, accepting an invitation to a workspace, or using a trust center published on the Service, you agree to these terms on behalf of yourself and, where applicable, the organisation you represent. If you are accepting on behalf of an organisation, you confirm you are authorised to bind it.

The Service is offered to organisations acting in the course of their business. It is not offered to consumers, and the statutory rights that apply to consumer contracts — including the right of withdrawal under the Danish Consumer Contracts Act — do not apply to a business customer.

Where the Customer has signed an order form or another written agreement with us, that document governs to the extent it conflicts with these terms.

02The Service

oathly.ai is a trust center and security-review automation platform. It lets a Customer publish a trust center, control who can see which documents, answer security questionnaires with AI assistance, and track the resulting activity.

Functionally, the Service includes:

  • Hosted public trust centers, optionally served on a Customer-verified custom domain.
  • A library of policies, files, certifications and knowledge-base content, with access rules, approval workflows and expiry controls.
  • AI-assisted drafting of questionnaire and conversation answers, restricted to content the Customer has approved and citing the source it came from.
  • Optional integrations with third-party systems such as CRMs and document stores.
  • Analytics on visitor and questionnaire activity.

Features evolve. We may add, change or withdraw functionality, and we will not materially reduce the core functionality a paying Customer relies on during a paid term without at least 30 days' notice. If we do materially reduce it, the Customer may terminate and receive a pro-rata refund of fees prepaid for the unused remainder of the term.

We aim to keep the Service available continuously, but we do not commit to a specific uptime level in these terms. Planned maintenance is announced in advance where practical. An availability commitment, if the Customer needs one, is agreed in an order form.

03Accounts, workspaces and roles

A workspace has one owner. The owner and administrators may invite other members and assign them roles that determine what each member can see and change. Ownership of a workspace is not granted through invitations.

The Customer is responsible for the accuracy of its account details, for the actions of its members, and for keeping credentials secure. Tell us promptly at security@oathly.ai if you believe an account has been compromised.

Visitors to a trust center may be asked to identify themselves before content is released to them. Access decisions are made by the Customer that operates the trust center, using the rules it configures — not by oathly.ai.

04Acceptable use

You agree not to:

  • Use the Service unlawfully, or to publish content you have no right to publish.
  • Attempt to bypass access rules, authentication, tenancy boundaries, rate limits or any other technical control.
  • Access another organisation's workspace, trust center content or data without authorisation.
  • Upload malware, or content intended to disrupt the Service or other users.
  • Reverse engineer, resell or white-label the Service except as expressly agreed in writing.
  • Use automated means to scrape gated content, or to overload the Service.

We may suspend access that puts the Service, its users, or their data at risk. Where we can, we will tell you first; where we cannot, we will tell you as soon as we reasonably can afterwards and restore access once the risk is resolved.

05Customer content and ownership

The Customer keeps ownership of everything it uploads or publishes — policies, files, answers, questionnaire responses and the content of its trust centers (Customer Content). The Customer grants oathly.ai a non-exclusive, worldwide licence, for the duration of the agreement, to host, process, index, transmit and display that content for the sole purpose of providing the Service.

oathly.ai keeps ownership of the platform itself: the software, its interfaces, and any aggregated, non-identifying operational data used to improve reliability and performance. Aggregated data never identifies a Customer, a visitor or the content of a workspace.

The Customer is responsible for what it publishes and for the access rules it configures. Content set to public is visible to anyone who reaches the trust center.

If the Customer gives us feedback or suggestions, we may use them to improve the Service without obligation or attribution. Feedback never includes Customer Content.

06AI-assisted answers

The Service can draft answers to questionnaires and visitor questions using AI models. Those drafts are generated from content the Customer has approved, and each answer cites the source it drew from. Drafts are a starting point, not a decision: a person reviews and approves an answer before it is delivered, wherever the Customer's workflow requires it.

We do not train models on Customer Content. We do not use Customer Content, visitor data or questionnaire answers to train, fine-tune or evaluate any machine-learning model, our own or anyone else's, and we only use model providers whose terms prohibit training on the data submitted to them. Where a provider offers an option that retains submitted data for training, we do not enable it.

The Customer chooses which model provider handles its content, including self-hosted models for deployments that must keep inference in-house. Content sent to a third-party model provider is also subject to that provider's terms; the providers we use are named on our trust center at trust.oathly.ai.

AI output can be wrong. The Customer remains responsible for every answer it sends and every document it publishes.

07Third-party integrations

Connecting a third-party system — a CRM, a document store, a notification channel — authorises oathly.ai to exchange data with that system on the Customer's behalf, within the scopes granted at connection time. Those services are operated by their providers under their own terms; we are not responsible for their availability or behaviour.

A connection can be revoked at any time from the workspace's integration settings.

08Plans, fees and taxes

Plans and prices are those published at oathly.ai/pricing or set out in the Customer's order form. Fees are stated in euro (EUR) and are exclusive of VAT and any other applicable tax or duty.

Billing

Self-serve plans are charged in advance for each billing period — monthly or annual, as selected — to the payment method on file. Payments are processed by Stripe; by subscribing, the Customer authorises us to charge that payment method for each renewal until the subscription is cancelled. Invoices and payment-method changes are available in the billing portal linked from the workspace's billing settings.

Tax

We apply VAT where required. Customers in Denmark are charged Danish VAT. For business customers elsewhere in the EU who supply a valid VAT identification number, the reverse charge applies and no VAT is added; it is the Customer's responsibility to supply a valid number and to account for the tax in its own country. Customers outside the EU are responsible for any import, withholding or local tax arising on the supply, and fees are payable without deduction for it.

Failed payment

If a charge fails, our payment processor retries it and notifies the Customer. If the balance is still unpaid 14 days after the first failure notice, we may suspend access to paid functionality; if it is still unpaid 30 days after that notice, we may terminate the subscription. Suspension for non-payment does not delete Customer Content, and access is restored on payment.

Price changes

We may change prices. A change takes effect at the Customer's next renewal and only after at least 30 days' notice to the workspace owner. A Customer that does not accept a new price may cancel before the renewal date, and the current term runs out at the old price.

Free plans, trials and limits

Free plans and trials are provided as they are, may carry usage limits (including limits on AI usage, trust centers and members), and may be changed or withdrawn on 30 days' notice. Where a limit is reached, functionality above the limit may be paused until the Customer upgrades. We do not accept invoicing, purchase-order or offline-payment arrangements on self-serve plans; those are handled through an order form.

Disputes

If the Customer believes an invoice is wrong, tell us within 30 days of the invoice date at legal@oathly.ai and we will investigate in good faith. Undisputed amounts remain payable while we do.

09Renewal, cancellation and refunds

Subscriptions renew automatically for a further period of the same length — monthly or annual — until cancelled. Annual customers are notified before each renewal charge.

The Customer may cancel at any time from the billing portal. Cancellation takes effect at the end of the period already paid for: access continues until then, and no further charge is made. Downgrades take effect at the end of the current period; upgrades take effect immediately, with the change in price prorated by our payment processor.

Fees already paid are not refundable, in whole or in part, for a period that has begun — including where a Customer cancels early, stops using the Service, or is terminated for breach. The two exceptions are stated in these terms: a material reduction in core functionality during a paid term (section 2), and an intellectual-property claim we choose to resolve by terminating (section 15). This does not affect any right the Customer has under mandatory law.

10Data protection

Where we process personal data on the Customer's behalf — workspace members, trust-center visitors, and any personal data inside Customer Content — the Customer is the controller and oathly.ai is the processor. That processing is governed by our data processing agreement (DPA), available at trust.oathly.ai, which forms part of these terms. Our own processing as a controller — account holders, website visitors, prospects — is described in our privacy policy.

The platform and its data are hosted in the European Union. We use sub-processors to provide the Service; the current list, what each does and where it processes, is published on our trust center, which also carries our security documentation. We give notice of new sub-processors as set out in the DPA, and where a sub-processor processes personal data outside the EEA we rely on the European Commission's Standard Contractual Clauses.

We notify the Customer without undue delay after becoming aware of a personal data breach affecting its data, with the information the Customer needs to meet its own notification duties.

11Confidentiality

Each party may receive information from the other that is not public. Neither party will use the other's confidential information other than to perform under these terms, or disclose it except to people who need it and are bound by comparable obligations. Customer Content that a Customer publishes to a public trust center is not confidential.

These obligations do not apply to information that is or becomes public without breach, was already known free of any duty of confidence, or is independently developed. Where disclosure is legally compelled, the disclosing party will give notice where it lawfully can so the other party may seek protection. Confidentiality survives termination for three years, and for as long as the information remains a trade secret.

12Term, suspension and termination

These terms apply for as long as a workspace exists. The Customer may stop using the Service and close its workspace at any time; closing a workspace does not by itself refund fees or cancel a subscription, which is done in the billing portal.

Either party may terminate for material breach that is not cured within 30 days of written notice describing it. We may also terminate for non-payment as described in section 8, and may suspend immediately — with notice as soon as we reasonably can — where continued use presents a security, legal or integrity risk to the Service or its users.

On termination, trust centers stop being served and members lose access to the workspace. What happens to the content depends on who ended the agreement:

  • If the Customer deletes its workspace, deletion is immediate and permanent. The action is available only to the workspace owner and requires typing the workspace name to confirm; once confirmed, content, files and member records are erased from our live systems straight away and cannot be recovered. Export anything you need first.
  • If we terminate — for non-payment, or for a material breach left uncured — the workspace stays available in a read-only state for 30 days so the Customer can export its content, and Customer Content is then deleted from our live systems within 60 days of termination.

In either case, deleted content rolls out of our encrypted backups within a further 35 days, and we may retain what we must to comply with a legal obligation — such as invoices under accounting law — for the period that obligation requires, using it for nothing else.

We will confirm deletion in writing on request. Sections on content ownership, confidentiality, fees already due, disclaimers, liability, indemnities and governing law survive termination.

13Warranties and disclaimers

We warrant that we will provide the Service with reasonable skill and care, that it will perform materially as described in our documentation, and that we have the right to grant the rights we grant here. If the Service does not meet that standard, tell us and we will correct it — that correction is the Customer's primary remedy, without affecting the rest of these terms.

Each party warrants that it has the authority to enter into this agreement, and the Customer warrants that it has the rights necessary to publish and process the Customer Content it puts into the Service.

Beyond what is stated above, and to the extent the law allows, the Service is provided as is: we give no other warranty, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement, and we do not warrant that the Service will be uninterrupted, error-free, or that it will detect every problem in the content a Customer publishes.

The Service supports a Customer's security-review and trust workflow. It is not legal advice, it is not a compliance certification, and it does not warrant that any answer, document or published claim is accurate — that responsibility stays with the Customer. Framework mappings, AI-drafted answers and expiry or recertification reminders are aids to the Customer's own judgement, not a substitute for it.

14Limitation of liability

Neither party is liable to the other for indirect or consequential loss, or for loss of profit, revenue, anticipated savings, business, goodwill or reputation, however caused, even if the loss was foreseeable.

Each party's total aggregate liability arising out of or in connection with these terms — whether in contract, tort (including negligence) or otherwise — is limited to the total fees paid or payable by the Customer in the 12 months immediately before the event giving rise to the liability.

That limit and those exclusions do not apply to:

  • death or personal injury caused by negligence;
  • fraud or fraudulent misrepresentation;
  • wilful misconduct or gross negligence;
  • either party's indemnity obligations under section 15;
  • breach of the confidentiality obligations in section 11;
  • the Customer's obligation to pay fees due; or
  • any liability that cannot be limited or excluded under applicable law.

Nothing in this section limits either party's duty to mitigate its loss. Claims must be brought within 12 months of the date the claiming party became aware, or ought reasonably to have become aware, of the facts giving rise to them.

15Indemnities

By oathly.ai. We will defend the Customer against a third-party claim that the Service, used as permitted by these terms, infringes that third party's intellectual property rights, and pay the damages finally awarded or agreed in settlement. If such a claim is made or looks likely, we may at our option procure the right to keep using the Service, modify it so it is no longer infringing, or terminate the affected subscription and refund fees prepaid for the unused remainder of the term. This does not cover claims arising from Customer Content, from modifications we did not make, or from use in breach of these terms.

By the Customer. The Customer will defend us against a third-party claim arising from Customer Content, from claims the Customer publishes on its trust center, or from its use of the Service in breach of section 4, and pay the damages finally awarded or agreed in settlement.

In each case the indemnity is conditional on the indemnified party notifying the other promptly, allowing it to control the defence, and providing reasonable assistance at the indemnifying party's cost. No settlement that admits fault or imposes an obligation on the indemnified party is made without its consent.

16General

Force majeure

Neither party is liable for a delay or failure caused by something outside its reasonable control — including internet or infrastructure failure, the act of a public authority, natural disaster or armed conflict — provided it tells the other party and works to resume performance. This never excuses an obligation to pay for the Service already provided.

Subcontracting and assignment

We may use subcontractors and sub-processors to provide the Service and remain responsible for their performance. Neither party may assign this agreement without the other's written consent, except that either may assign it in full to a successor in a merger, acquisition or sale of substantially all its assets, on notice to the other.

Publicity

We will not use a Customer's name or logo publicly as a reference without its prior written consent, and consent can be withdrawn at any time.

Notices

We give notice by email to the workspace owner and, for material changes, in the platform. Notices to us go to legal@oathly.ai. It is the Customer's responsibility to keep the owner's address current.

Entire agreement

These terms, the DPA, our privacy policy and any order form are the entire agreement between the parties on this subject and replace anything said or written before. Where they conflict, the order of precedence is: order form, then DPA, then these terms. Nothing in this paragraph limits liability for fraud.

Severability, waiver and language

If a provision is held unenforceable, the rest stays in force and the provision is read down to the minimum extent needed to make it enforceable. Not enforcing a right is not a waiver of it. These terms are written in English; a translation is provided for convenience only and the English version governs. Nothing here creates a partnership, agency or employment relationship, and no one other than the parties may enforce these terms.

17Changes to these terms

We may update these terms as the Service changes. The "last updated" date at the top of this page always reflects the current version, and we will give workspace owners at least 30 days' notice of a material change before it takes effect. Continued use after that date means the updated terms apply; a Customer that does not accept a material change may terminate before it takes effect and receive a pro-rata refund of fees prepaid for the unused remainder of the term.

Changes required by law or needed to address a security risk may take effect immediately, and we will say so when we give notice.

18Governing law and disputes

These terms, and any dispute or claim arising out of or in connection with them or their subject matter, are governed by Danish law, without regard to its conflict-of-law rules. The UN Convention on Contracts for the International Sale of Goods does not apply.

If a dispute arises, the parties will first try in good faith to resolve it between themselves within 30 days of written notice. If they cannot, the courts of Denmark have exclusive jurisdiction, with the Copenhagen City Court (Københavns Byret) as the court of first instance. Either party may still apply to any competent court for interim or injunctive relief.

Questions about this document?Email legal@oathly.ai or use the contact page — every message is logged with an owner and a reply deadline.