Terms and Conditions
Effective date: 1st september 2026
These Terms and Conditions govern access to and use of the VOKT website and the VOKT platform. They form a binding agreement between you and VOKT.
VOKT is operated by Frostbyte Holding AS, Årdalsvegen 35, 6884 Øvre Årdal, a company established in Norway. References below to "we", "us" and "VOKT" mean that company. References to "you" mean the organisation entering into this agreement, and where an individual is acting for an organisation, that individual confirms they have authority to bind it.
By creating an account, signing an order, or using the Services, you accept these terms. If you do not accept them, do not use the Services.
Sections
- 1. Definitions
- 2. The Services
- 3. Accounts and Authorised Users
- 4. Trial, Scoping and Acceleration Sprint
- 5. Fees, Invoicing and Taxes
- 6. Term, Renewal and Termination
- 7. Acceptable Use
- 8. Your Obligations
- 9. Intellectual Property
- 10. Your Data and Data Protection
- 11. Confidentiality
- 12. Suspension
- 13. Warranties and Disclaimers
- 14. Limitation of Liability
- 15. Indemnities
- 16. Publicity
- 17. General
1. Definitions
Agreement means these Terms and Conditions together with any order form, the Data Processing Agreement, the Services Agreement, and any other document expressly incorporated by reference.
Authorised User means an individual you permit to use the Services under your account, including your employees, contractors and agents.
Customer Data means any data, documents, records or other content that you or your Authorised Users connect to, upload to, or generate through the Services, including data held in systems you connect.
Deployment Tier means the configuration in which the Services are provided, being Shared Cloud, Private Cloud, Own Cloud or Sealed, as described in section 2.
Output means the answers, records, reports, workflows and other results the Services produce from Customer Data.
Platform means VOKT Core and any capability we make available on it, including search, retrieval, dashboards, document processing, workflow, agents and application creation.
Services means the Platform, the websites at vokt.ai and its subdomains, and any professional services we provide under an order.
2. The Services
What we provide. VOKT is a business operating system. It connects to the systems, databases and documents your organisation already uses, and allows you to search, understand, build on and automate that estate. We provide the Services in accordance with this Agreement and any order form.
Deployment Tiers. The Services are available in four configurations. Shared Cloud runs on multi-tenant infrastructure we manage in the European Economic Area. Private Cloud runs on dedicated, single-tenant infrastructure we manage. Own Cloud runs inside your own infrastructure. Sealed runs inside your own infrastructure with no connection to the public internet. The tier you select determines where data is held and which third parties, if any, are involved in processing it. Section 10 and the Data Processing Agreement set this out.
Changes to the Services. We may make reasonable updates to the Services from time to time, including improvements, security fixes and new capability. We will not make an update that materially reduces the core functionality of a Service during a committed term.
Discontinuation. If we decide to discontinue a Service or a material part of it, and we do not replace it with something materially similar, we will give you reasonable prior notice. This does not restrict changes we must make to comply with the law, to address a security risk, or to avoid a disproportionate technical or economic burden.
Beta and preview features. We may make features available that are labelled beta, preview or similar. These are provided as they are, without warranty, are excluded from any service level commitment, may change or be withdrawn at any time, and should not be used to process sensitive data.
3. Accounts and Authorised Users
Registration. You must open an account to use the Platform. You are responsible for the accuracy of the information you give us and for keeping it current.
Security of your account. You are responsible for the confidentiality of credentials issued to you and your Authorised Users, and for all activity under your account. You must tell us promptly if you become aware of unauthorised access.
Authorised Users. You may permit Authorised Users to use the Services. You remain responsible for their compliance with this Agreement, and any act or omission by an Authorised User is treated as your own.
Administration. Users with administrative rights in your account can create and remove users, change permissions, and access data and activity records available to your account. Managing those rights is your responsibility, not ours.
4. Trial, Scoping and Acceleration Sprint
Free trial. We offer a thirty day free trial on the Cloud tier. No payment card is required. We may change or withdraw the trial at any time, and we may limit trial usage. At the end of a trial, if you do not subscribe, access ends and trial data may be deleted.
Scoping call. A scoping session is provided at no charge and creates no obligation on either side.
Acceleration Sprint. The Acceleration Sprint is a three week paid evaluation charged at a flat fee of £7,500, during which we work with your actual data to demonstrate the architecture in your environment. If you subsequently commit to a full licence, the sprint fee is credited in full against that licence.
5. Fees, Invoicing and Taxes
Fees. Fees are those stated on our pricing page or in your order form. Shared Cloud is charged per user per month. Private Cloud and Own Cloud are charged monthly with a minimum user count and a committed term. Sealed is quoted individually. Professional services are charged at our standard hourly rates.
Currency. Fees may be stated and invoiced in pounds sterling, Norwegian kroner or euro or any other relevant currency. The currency applicable to your account is the one shown on your order form or invoice.
Invoicing and payment. We invoice in advance for subscription fees and in arrears for usage based and professional services fees. Invoices are issued electronically and you consent to receiving them that way.
Payment is due within 10 days of the invoice date.
Late payment. We may charge interest on overdue amounts at the rate permitted by Norwegian law, and we may suspend the Services under section 12 while an undisputed invoice remains unpaid.
Disputes. If you dispute an invoice in good faith, tell us before the due date and give your reasons. You remain liable for the undisputed balance.
Taxes. Fees are exclusive of value added tax and other applicable taxes, which you pay in addition. If you are entitled to an exemption, give us valid documentation.
Changes to fees. We may change our fees. A change does not affect a committed term already in progress, and we will give reasonable notice before a change takes effect at renewal.
Refunds. Except where this Agreement or the law says otherwise, fees are not refundable, and committed terms are not cancellable.
6. Term, Renewal and Termination
Term. This Agreement starts when you first accept it and continues until terminated. Each subscription runs for the term stated on your order form. Private Cloud and Own Cloud subscriptions are available on six month, one year or two year commitments.
Renewal. Unless your order form says otherwise, a subscription renews for a further term of the same length unless either party gives notice not to renew before the end of the current term.
Termination for breach. Either party may terminate if the other is in material breach and has not cured it within thirty days of written notice.
Termination for convenience. You may stop using the Services at any time, subject to any committed term and the fees due for it.
Termination for legal reasons. We may terminate immediately if continuing to provide the Services would breach the law, or if you have caused us to breach applicable sanctions or export control law.
What happens on termination. Access to the Services ends and all outstanding fees fall due. Return and deletion of Customer Data is governed by the Data Processing Agreement. For Own Cloud and Sealed deployments, data held inside your own infrastructure remains under your control and is not affected.
7. Acceptable Use
You must not, and must not permit an Authorised User to:
Use the Services in breach of any applicable law, or to process data you have no lawful basis to process
Infringe the intellectual property, privacy or other rights of any person
Attempt to gain unauthorised access to the Services, another customer's environment, or any system connected to them
Probe, scan or test the security of the Services except under our Vulnerability Disclosure Policy
Reverse engineer, decompile or disassemble the Platform, or attempt to extract any model, model parameters or weights, except to the extent that restriction is prohibited by law
Resell, sublicense or make the Services available to a third party, except as a partner under a separate written agreement with us
Interfere with the operation of the Services, or circumvent any usage limit, quota or access control
Use the Services to develop a competing product or service
Use the Services in any environment where failure could lead to death, personal injury, or serious environmental or property damage
Output is produced by automated processing and must be evaluated for accuracy as appropriate to your use. The Platform attributes each answer to a source and records each action, so that you can check it. You remain responsible for decisions taken on the basis of Output.
8. Your Obligations
Compliance. You will ensure that your use and your Authorised Users' use of the Services complies with this Agreement and with applicable law.
What you connect. You decide which systems, databases and documents to connect to the Services. You are responsible for having the right to connect them and for the lawfulness of the data they contain.
Notices and consents. Where you process personal data through the Services, you are responsible for providing the privacy notices and obtaining the consents required by data protection law. You confirm to us that you have done so.
Cooperation. You will give us the access and information we reasonably need to provide the Services and to investigate any problem attributable to your environment or your data.
9. Intellectual Property
We keep ours. We and our licensors retain all intellectual property rights in the Platform, the Services, our software and our documentation. Nothing in this Agreement transfers those rights to you.
You keep yours. You retain all intellectual property rights in Customer Data. Nothing in this Agreement transfers those rights to us.
Licence to us. You grant us a non exclusive licence to host, copy, process and transmit Customer Data to the extent necessary to provide the Services to you, and for no other purpose.
Licence to you. We grant you a non exclusive, non transferable right to access and use the Services during the term, for your own business purposes, subject to this Agreement.
What you build. Where you or a partner build a capability on VOKT Core, such as a recruitment, procurement or compliance capability, the configuration, data and rules you create are yours. The underlying Platform remains ours.
Output. As between you and us, Output is yours. Because the Services are used by many organisations, Output may not be unique, and similar inputs may produce similar results for different customers.
Feedback. If you give us suggestions about the Services, we may use them without restriction and without obligation to you.
10. Your Data and Data Protection
Roles. Where the Services process personal data on your behalf, you are the controller and we are the processor. Our obligations in that role are set out in the Data Processing Agreement, which is incorporated into this Agreement and which meets the requirements of Article 28 of the General Data Protection Regulation.
Our own processing. Where we process personal data as a controller, for example about visitors to our website or the individuals who administer your account, our Privacy Policy applies.
Where data is held. In the standard configuration of the Cloud tier, Customer Data is hosted in Helsinki, Finland, and model inference is performed on endpoints in Finland and France. All processing takes place within the European Economic Area. Norway is a party to the Agreement on the European Economic Area, and the General Data Protection Regulation applies to us through it.
Third parties involved. The companies that process Customer Data on our behalf are named in the Data Processing Agreement. All are established within the European Economic Area.
Bringing your own model provider. The Services allow you to connect credentials for a model provider of your choosing. If you connect a provider established outside the European Economic Area, Customer Data from that environment is sent to that provider on your instruction and under your responsibility. We will show a data residency warning and require an explicit acknowledgement before that configuration takes effect. Our European Economic Area residency commitments do not apply to an environment while that configuration is enabled.
Model training. We do not use Customer Data to train, fine tune or otherwise improve any machine learning model, and we require the same of any provider performing inference for us.
Security. We maintain technical and organisational measures appropriate to the risk, as described in the Data Processing Agreement. These include separation of each customer's data at the database level and an activity record that cannot be altered once written.
Audit records. The Services maintain an append only record of activity within your environment. That record is available to you and may be exported to support your own audit and compliance obligations.
11. Confidentiality
Each party will keep the other's confidential information confidential, use it only to perform this Agreement, and disclose it only to those of its people and advisers who need it and who are bound to keep it confidential. This does not apply to information that is or becomes public without fault, is independently developed, or is lawfully received from a third party.
Either party may disclose confidential information where required by law or a valid order. Where it is permitted to do so, it will give the other party prior notice and a reasonable opportunity to object.
Customer Data is your confidential information.
12. Suspension
We may suspend all or part of your access to the Services if:
You are in material breach of section 7 and have not corrected it after notice
We reasonably believe suspension is necessary to protect the Services, our infrastructure, or another customer
We suspect unauthorised access to your account or the Services
An undisputed invoice remains unpaid after notice
We are required to suspend by law
We will give notice before suspending unless the circumstances make that impracticable, and we will lift the suspension once the cause has been resolved. Suspension does not relieve you of the obligation to pay fees for the period.
13. Warranties and Disclaimers
Each party warrants that it has the authority to enter into this Agreement and will comply with the laws applicable to its performance under it.
We warrant that we will provide the Services with reasonable skill and care.
Except as expressly stated in this Agreement, and to the fullest extent permitted by law, we exclude all other warranties, whether express, implied or statutory, including any implied warranty of merchantability, satisfactory quality, fitness for a particular purpose, or non infringement, and any warranty that the Services will be uninterrupted or error free.
The Services apply automated processing to produce Output. Output is probabilistic. The Platform is designed to attribute every answer to a source and to decline to answer where it cannot, but you remain responsible for evaluating Output before relying on it.
14. Limitation of Liability
Nothing in this Agreement limits either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any other liability that cannot lawfully be limited.
Subject to the paragraph above, neither party is liable for indirect, consequential, special or incidental loss, or for loss of revenue, profit, anticipated savings, goodwill or data.
Subject to the two paragraphs above, each party's total liability arising out of or in connection with this Agreement is limited to the fees paid in the twelve months before the event giving rise to the claim.
15. Indemnities
By us. We will defend you against a third party claim that the Services, used in accordance with this Agreement, infringe that third party's intellectual property rights, and will pay any resulting award or agreed settlement. This does not apply to a claim arising from Customer Data, from your breach of this Agreement, or from combining the Services with anything we did not supply.
Our options. If we reasonably believe the Services may infringe, we may procure the right for you to continue using them, modify them so they no longer infringe without materially reducing their functionality, or replace them with materially equivalent functionality. If none of those is commercially reasonable, we may terminate the affected Services and refund prepaid fees for the unused period.
By you. You will defend us against a third party claim arising from Customer Data, or from your or an Authorised User's use of the Services in breach of section 7, and will pay any resulting award or agreed settlement.
Conditions. The party seeking cover must notify the other promptly, give it control of the defence, and cooperate reasonably. Any settlement requiring the other party to admit liability or pay money needs that party's consent, which must not be unreasonably withheld.
16. Publicity
Neither party may use the other's name or brand features in a public announcement without written consent.
17. General
Notices. Notices to you are sent to the email address on your account. Notices to us are sent to the address in the contact section below. Notice is treated as received when sent, provided no delivery failure is received.
Assignment. Neither party may assign this Agreement without the other's written consent, except to an affiliate or in connection with a merger or sale of substantially all its business, provided the assignee agrees to be bound.
Subcontracting. We may subcontract our obligations but remain responsible for performance. Subcontractors processing personal data are governed by the Data Processing Agreement.
Force majeure. Neither party is liable for a failure or delay caused by circumstances beyond its reasonable control.
No partnership. This Agreement does not create an agency, partnership or joint venture.
No waiver. A failure or delay in exercising a right is not a waiver of it.
Severability. If any provision is held invalid, the rest of the Agreement continues in effect.
Entire agreement. This Agreement is the entire agreement between the parties on its subject matter and supersedes any earlier understanding.
Order of precedence. If there is a conflict, the following order applies, in decreasing precedence: the Data Processing Agreement, any signed order form, these Terms and Conditions, and any other document incorporated by reference.
Changes to these terms. We may update these terms. We will post the updated version and change the effective date. A material change takes effect thirty days after posting, except where an earlier date is required by law or to address a security risk. If you do not accept a material change, you may stop using the Services and terminate under section 6.
Governing law and jurisdiction. This Agreement is governed by Norwegian law, and the courts of Oslo have exclusive jurisdiction, without prejudice to any mandatory right a party has to bring proceedings elsewhere.
Contact
Frostbyte Holding AS,
Årdalsvegen 35, 6884 Øvre Årdal, Norge
Org. nr. 934 881 982
Related documents: our Privacy Policy explains how we handle personal data as a controller; our Data Processing Agreement governs personal data we process for you; our Cookie Policy explains what we store on your device; our Vulnerability Disclosure Policy sets out how to report a security issue; acceptable use of the Services is set out in section 7.
References
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), 2016 O.J. (L 119) 1. https://eur-lex.europa.eu/eli/reg/2016/679/oj
Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). https://eur-lex.europa.eu/eli/reg/2024/1689/oj
Agreement on the European Economic Area, 1994 O.J. (L 1) 3. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A21994A0103%2801%29