Legal

Terms of Service (SaaS)

Last updated: 2026/10/01 Version: 1

1. Acceptance of the Terms

These Terms of Service ("Terms") govern access to and use of the Orbitar SaaS platform provided by Smotics - Unipessoal, Lda ("Provider").

By creating an account, subscribing to or using the platform, the customer and its authorised users accept these Terms.

2. Contracting Parties and Definitions

  • Provider: Smotics - Unipessoal, Lda.
  • Customer or Tenant: the legal entity subscribing to the service.
  • Authorised User: an individual authorised by the Customer to use the platform.
  • Customer Data: data submitted to the platform by or on behalf of the Customer.
  • AI Agent: a software feature configured by the Customer or the Provider that uses artificial intelligence models to support conversations, search, information extraction, content generation or assisted tool execution.

3. Service Description

Orbitar is a multi-tenant SaaS platform. Tenant data is logically isolated, including through schema-level separation, while the service infrastructure is centrally managed by the Provider.

The platform may include optional AI agent, voice transcription, document extraction, assisted search and tool automation features. These features are intended to support authorised users and do not replace human assessment where relevant decisions are involved.

4. Eligibility and Account Security

The Customer must ensure that all Authorised Users:

  • provide accurate account information
  • keep their credentials confidential
  • use access strictly within their assigned functions and permissions

The Customer is responsible for activities carried out through its accounts, except to the extent caused by the Provider's breach.

5. Legal Documents and Order of Precedence

The service relationship is governed by:

  1. the signed commercial agreement/proposal, if any
  2. the Data Processing Agreement (DPA)
  3. these Terms
  4. the Privacy Policy

In the event of a conflict, the document higher in the list prevails for the matter in question.

6. Mandatory Acceptance of Legal Terms

To use the platform, Authorised Users may be required to accept:

  • the Terms of Service
  • the Privacy Policy

Acceptance may be required at first login and again when material updates are published.

7. Cookies Required for Use of the Service

The platform uses cookies and similar technologies necessary for authentication, session continuity and security.

The essential cookies currently used include orbitar_sessionid, orbitar_csrftoken and orbitar_device. The platform may also store technical or interface preferences, such as light/dark theme and sidebar size, in the user's account or in browser local storage.

Important:

  • There is no optional cookie consent centre for cookies required by the service.
  • Acceptance of the necessary cookies is a condition for using the platform.
  • If an Authorised User refuses the necessary cookies, login and access to the service may not be possible.

8. Customer Responsibilities (Data Protection and Compliance)

The Customer acknowledges and agrees that:

  • The Customer is the Controller of Customer Data, including personal data of its own customers, employees, suppliers and other entities.
  • The Customer is solely responsible for identifying lawful bases for processing and complying with applicable privacy law.
  • The Customer must provide the required notices to its own data subjects and obtain consent where legally required.
  • The Customer must manage data subject requests relating to Customer Data.
  • The Customer is responsible for configuring and using AI agents, voice transcription, tools and knowledge sources lawfully, proportionately and consistently with the intended purpose.
  • The Customer must not use AI agents for solely automated decisions producing legal or similarly significant effects, nor for high-risk uses under the European Union Artificial Intelligence Act, unless a specific agreement, appropriate assessment and applicable legal, technical and organisational controls are in place.

9. Acceptable Use

The Customer and Authorised Users must not:

  • access data without authorisation
  • interfere with the security or availability of the service
  • attempt to circumvent tenant isolation or access controls
  • use the service for unlawful, infringing or abusive activities
  • configure AI agents or tools to obtain, disclose, alter or delete data without authorisation
  • use AI features for surveillance, discrimination, manipulation, unjustified assessment of people, prohibited decision-making or any other unlawful use or use incompatible with the applicable documentation and terms
  • submit to AI agents, voice transcription or tools data that the Customer is not authorised to process or transmit to sub-processors

10. Provider Responsibilities

The Provider will:

  • provide the service with reasonable skill and care
  • implement appropriate technical and organisational security measures proportionate to the risk
  • process Customer personal data in accordance with the DPA
  • identify AI agents as such in the interface when they interact directly with users, unless this is clear from the context
  • use European providers and configurations for AI and transcription features where this is the contracted configuration, designed to support compliance with the GDPR, the European Union Artificial Intelligence Act and other applicable European legislation
  • use AI providers that may involve processing or transfer of data outside the EEA, such as OpenAI, only when that option is configured, contracted or authorised by the Customer, in accordance with the Privacy Policy and DPA

11. Sub-processors and Infrastructure

The Customer authorises the Provider to use sub-processors necessary to provide the service, subject to the data protection obligations set out in the DPA.

Current sub-processors are identified in the Privacy Policy and DPA. Depending on the feature used, they include hosting/infrastructure, email, backup, monitoring, push notification, AI gateway/model and voice transcription providers.

12. Availability and Support

The Provider will use commercially reasonable efforts to maintain platform availability and support operations. Unless expressly stated in a signed SLA, the service is provided without a guarantee of uninterrupted availability.

13. Fees and Payment

Fees, billing terms and taxes are set out in the applicable proposal or commercial agreement.

14. Intellectual Property

The Provider retains all rights in the platform, software, documentation and related intellectual property, except for Customer Data.

The Customer retains all rights in Customer Data.

15. Suspension and Termination

The Provider may suspend access where reasonably necessary for security, legal compliance, non-payment or material breach.

Either party may terminate the agreement in accordance with the applicable commercial terms. Upon termination, the return/deletion of Customer Data is handled under the DPA and the agreement.

16. Disclaimer of Warranties

Unless expressly agreed in writing, the service is provided "as is" and "as available", to the maximum extent permitted by law.

AI-generated responses, transcripts, extractions and suggestions may be incomplete, inaccurate or out of date. The Customer and Authorised Users must review results before using them in operational, legal, financial, employment or other relevant decisions.

17. Limitation of Liability

To the maximum extent permitted by law:

  • The Provider is not liable for indirect, incidental, special, consequential or punitive damages.
  • The Provider is not liable for unlawful processing decisions made by the Customer in its capacity as Controller.
  • overall liability caps and any exclusions are set out in the signed commercial agreement.

Nothing excludes liability that cannot be excluded under applicable law.

18. Confidentiality

Each party must protect the other's confidential information using at least reasonable care, and may use it only for contractual purposes.

19. Applicable Law and Jurisdiction

These Terms are governed by Portuguese law and interpreted in accordance with applicable European Union law, including Regulation (EU) 2016/679 (GDPR), where relevant.

The courts of Faro, Portugal, have jurisdiction, without prejudice to mandatory rights under applicable law.

20. Changes to the Terms

The Provider may update these Terms periodically. Material changes will be communicated with a new effective date and may require renewed acceptance before continued use.

21. Contact

Legal contact:

  • geral@smotics.pt
  • Estrada da Garganta, Quinta Saude Rio Seco, 8005-130 Faro, Portugal