Noetis — Terms of Service
Version 2.0 · Effective date: to be announced upon release · Last updated: to be announced upon release
These Terms of Service ("Terms") form a binding agreement between Final Frame, registered with the Dutch Chamber of Commerce under number 92376193, with its registered office at Defensie-eiland 110, 3441 VL Woerden, Netherlands, VAT NL004950760B86, trading as Noetis ("Noetis", "we", "us"), and the business or other legal entity accepting or using the Service ("Customer", "you").
These Terms are intended for business use only. Unless expressly agreed otherwise in writing, the Service is not offered to consumers acting outside their trade, business or profession.
By creating an account, accepting an Order, clicking acceptance, subscribing to, enabling or using the Service, Customer accepts these Terms.
If an individual accepts these Terms for an organisation, that individual represents that they have authority to bind that organisation.
1. Definitions
Service / Platform means the Noetis website intelligence, optimisation and growth platform, including hosting, analytics, Visitor Intelligence, heatmaps, session recordings, experimentation, personalisation, AI generation, autonomous optimisation, Growth Engine functionality, dashboards, APIs and related functionality.
Customer Data means all content, data, media, code, configuration, Personal Data, Visitor Data and other material submitted to, collected through, generated from, or processed by the Service on Customer's behalf.
Visitor Data means Customer Data concerning an End User, including behavioural events, online identifiers, Visitor Profiles, Derived Data, experiment assignments and Personalisation Records.
End User / Visitor means a natural person who accesses or interacts with a Customer Property.
Customer Property means a website, application, page or other digital property operated by or for Customer and connected to the Service.
Visitor Identifier means a pseudonymous identifier used to distinguish or, where lawfully enabled, recognise an End User across sessions.
Visitor Profile means a collection of behavioural history, Derived Data and other signals associated with a Visitor Identifier.
Derived Data means interests, preferences, intent signals, behavioural segments, persona hypotheses, confidence scores or other characteristics inferred from Visitor Data.
Personalisation means automated selection, modification, ordering or presentation of eligible website content or variants based on Visitor Data or a Visitor Profile.
Personalisation Record means a record concerning a personalisation decision, including eligibility, selected treatment, rendering, viewability, interaction and related decision information.
AI Output means content, recommendations, hypotheses, experiments, copy, images, layouts, code, classifications, personalisations or other output generated or materially assisted by AI systems.
Autonomous Mode means functionality expressly enabled by Customer that may generate, evaluate, select, publish, modify, test, pause or roll back eligible content without case-by-case Customer approval.
Growth Engine means functionality that may identify content or growth opportunities and generate, create, test, optimise or, where authorised, publish content or webpages.
Optimisation Boundaries means the scope, permissions, exclusions, source information, pages, elements, content types and other controls configured by Customer.
Immutable Content means content that the Service is not authorised to autonomously change, including actual prices, contractual terms, privacy notices, mandatory legal disclosures and other content designated immutable by Noetis or Customer.
Order means the subscription, plan, order form or other commercial arrangement governing Customer's purchase.
DPA means the Noetis Data Processing Agreement.
2. Provision of the Service
Subject to these Terms and payment of applicable fees, Noetis grants Customer a limited, non-exclusive, non-transferable and non-sublicensable right to use the Service during the Subscription for Customer's internal business purposes.
Noetis may develop, modify and improve the Service provided that it does not materially remove core paid functionality during a committed Subscription term without reasonable justification or an appropriate alternative.
Features identified as beta, preview, experimental or early access may be modified, suspended or withdrawn and are provided without SLA commitment.
A description of functionality in these Terms or the incorporated policies does not mean that every optional feature is active for Customer, technically available in Customer's plan, enabled in Customer's configuration or production-certified. Actual availability depends on the functionality actually provided, Customer's plan, Customer's permissions and configuration, and the applicable safeguards.
3. Customer accounts and security
Customer is responsible for:
- maintaining accurate account information;
- maintaining confidentiality of credentials;
- activity occurring through its accounts;
- assigning appropriate permissions;
- using available security controls appropriate to its use;
- promptly notifying Noetis of suspected unauthorised access.
Customer shall not share privileged credentials except with authorised personnel.
4. Customer instructions and configuration
Customer determines the purposes for which it uses the Service and is responsible for configuring the Service consistently with applicable law.
For purposes of the DPA, Customer acknowledges that actions including:
- enabling a feature;
- connecting a data source;
- selecting a processing purpose;
- configuring consent requirements;
- enabling Visitor Intelligence;
- defining Optimisation Boundaries;
- enabling Autonomous Mode;
- approving a template;
- defining publication rules;
- activating an experiment; or
- otherwise configuring the Service,
constitute documented instructions to Noetis to the extent those actions concern processing performed on Customer's behalf.
Noetis may rely on Customer's instructions, configuration and consent signals unless Noetis knows or reasonably believes that processing pursuant to them would violate applicable data-protection law.
5. Visitor Intelligence and Personalisation
Where enabled, the Service may process Visitor Data to analyse behaviour, recognise returning Visitors, generate and update Visitor Profiles, infer interests or preferences, assign Visitors to experiments or cohorts and select eligible personalised experiences.
Such processing is subject to the Visitor Intelligence & Personalisation Addendum and DPA.
Customer is solely responsible for determining the lawful purposes and lawful basis for its use of Visitor Intelligence and for providing legally required information to End Users.
Where consent is legally required, Customer must obtain valid consent before enabling the relevant processing and must communicate the applicable consent state accurately to Noetis.
For processing configured as consent-dependent, only a supported affirmative consent state may activate that processing. An unknown, missing, malformed, rejected or withdrawn consent state does not count as consent.
Noetis is entitled to rely on consent and preference signals technically communicated by Customer.
Customer shall not deliberately circumvent Noetis consent controls or cause the Service to treat an End User as consenting where valid consent has not been obtained.
6. Prohibited sensitive profiling
The Service is not designed or authorised to infer, classify, predict, target, personalise or make decisions based on, whether directly or through deliberate indirect proxies:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic data or genetic characteristics;
- biometric data used for unique identification;
- health information, including physical or mental health and sensitive disability information;
- sex life or sexual orientation;
- criminal convictions or offences; or
- other highly sensitive categories designated by Noetis.
Customer shall not configure, instruct, manipulate or use the Service for these purposes — including through custom events, event names, persona names, segments, prompts, APIs, integrations, metadata, source content or indirect proxies — unless Noetis has expressly authorised the specific processing in writing and all applicable legal requirements have independently been satisfied.
Noetis may block or suspend processing reasonably suspected of violating this Section.
7. Significant automated decisions
The Service is not designed to make solely automated decisions producing legal effects concerning an End User or similarly significantly affecting an End User.
Customer shall not use the Service for such decision-making, including decisions materially determining eligibility for employment, credit, insurance, healthcare, education, housing or essential services, unless expressly authorised by Noetis in writing and Customer has independently established all required legal bases, safeguards, notices and human-review mechanisms.
8. AI and autonomous functionality
AI Output may be probabilistic, inaccurate, incomplete, misleading, outdated, duplicative or otherwise unsuitable.
Noetis does not warrant the factual accuracy, originality, legality or suitability of AI Output.
8.1 Manual mode
Where a feature requires Customer approval, Customer is responsible for reviewing and approving AI Output before publication.
8.2 Autonomous Mode
Where Customer enables Autonomous Mode, Customer expressly instructs and authorises Noetis to perform eligible autonomous operations — which, depending on the functionality actually available and Customer's configuration, may include generating, evaluating, selecting, modifying, testing, activating, publishing, pausing and rolling back eligible AI Output — without case-by-case human approval, but only within the Optimisation Boundaries configured by Customer and subject to the applicable safeguards.
Enabling Autonomous Mode constitutes advance authorisation for changes falling within those boundaries. It does not authorise every theoretically possible autonomous action: actual autonomous actions depend on the functionality actually available, Customer's permissions, Customer's configuration, the applicable Optimisation Boundaries and the applicable safeguards.
Customer remains responsible for:
- selecting appropriate boundaries;
- maintaining accurate source information;
- determining whether autonomous publication is appropriate for its business;
- monitoring the Service using the controls made available by Noetis; and
- compliance obligations that legally rest with Customer.
Customer may disable Autonomous Mode or use available rollback controls.
9. Automated safeguards
Noetis may operate automated, rules-based and AI-assisted safeguards intended to detect unsupported claims, semantic deviation, unsafe content, anomalous behaviour or other risks.
A classification such as PASS, APPROVED, SAFE, ELIGIBLE or similar means only that the Output satisfied the applicable automated control.
It does not constitute:
- legal advice;
- regulatory approval;
- factual verification, unless the specific control actually verifies against an identified source;
- professional review;
- certification;
- warranty of accuracy;
- warranty of non-infringement; or
- guarantee that the Output is lawful or suitable.
FAIL means the applicable automated control was not satisfied. UNCERTAIN or an equivalent classification means the Service did not establish sufficient confidence.
Automated safeguards reduce risk but cannot eliminate all errors. Instructions given to an AI model are not, by themselves, a hard enforcement boundary.
10. Growth Engine
Where enabled, the Growth Engine may analyse Customer Properties and connected data to identify opportunities and generate content, pages, articles, structures, recommendations or other material.
Where Customer enables autonomous publication, Customer authorises Noetis to publish eligible material within configured publication rules and Optimisation Boundaries.
Noetis does not guarantee:
- originality;
- factual accuracy;
- non-infringement;
- search-engine indexing;
- ranking;
- traffic;
- leads;
- revenue;
- conversion;
- continued search visibility; or
- compliance with sector-specific advertising or content regulation.
Search engines, discovery platforms and third-party distribution channels may change their algorithms, policies and treatment of AI-generated content without notice.
Customer is responsible for maintaining accurate source-of-truth information supplied to the Service.
11. Regulated and professional content
Unless expressly enabled by Noetis, Customer shall not use Autonomous Mode to publish personalised professional advice or make regulated claims in medical, legal, investment, credit, insurance or other regulated fields where human or professional review is legally required.
Customer remains responsible for sector-specific requirements applicable to its business.
12. Acceptable use
Customer shall not use the Service to:
- (a) violate law or third-party rights;
- (b) process data it has no lawful right to process;
- (c) generate or distribute unlawful, fraudulent, defamatory or infringing material;
- (d) introduce malware or malicious code;
- (e) circumvent billing, security, consent, rate or usage controls;
- (f) obtain unauthorised access;
- (g) reverse engineer the Service except where such restriction is prohibited by mandatory law;
- (h) use the Service or its confidential components to build or train a materially competing product or model;
- (i) unlawfully discriminate against or exploit End Users;
- (j) use prohibited sensitive profiling;
- (k) make prohibited significant automated decisions; or
- (l) deliberately interfere with experimentation or measurement integrity.
13. Suspension
Noetis may immediately suspend affected functionality where reasonably necessary to:
- prevent security or privacy harm;
- respond to unlawful use;
- protect End Users;
- prevent material damage;
- respond to non-payment;
- protect the integrity of the Platform; or
- comply with law or binding authority.
Where reasonably practicable, Noetis will notify Customer.
14. Intellectual property
Noetis and its licensors retain all rights in the Platform, source code, infrastructure, prompts, orchestration, algorithms, templates, decision systems, experimentation systems, models and related technology.
Customer retains its rights in Customer Data.
For clarity, Customer Data includes Customer-specific:
- Visitor Data;
- Visitor Profiles;
- behavioural histories;
- Derived Data;
- experiment records; and
- Personalisation Records.
Noetis retains all rights in the general methods, algorithms and technology used to generate those materials.
Customer grants Noetis a worldwide, non-exclusive licence to process Customer Data only as necessary to provide, secure, maintain and support the Service and otherwise as permitted by the DPA.
15. No cross-customer identity graph
Noetis will not intentionally combine identifiable or pseudonymous Visitor Profiles of unrelated Customers to identify the same Visitor across unrelated Customer Properties, perform cross-customer behavioural advertising or targeting, or create a shared Visitor identity graph.
Pseudonymised data is not treated as anonymous merely because direct identifiers are absent.
Noetis may use information that has been genuinely aggregated or de-identified so that it no longer identifies Customer or a natural person for security, statistics, benchmarking and improvement of the Service.
16. AI training
Customer Data will not be used by Noetis to train public or shared third-party foundation models.
Where third-party AI providers process Customer Data, they are engaged subject to the applicable contractual and data-processing arrangements.
Noetis may use aggregated or de-identified information that is no longer Personal Data to improve the Service.
17. Third-party services
The Service relies on third-party infrastructure and services.
Noetis is not responsible for failures caused solely by third parties outside Noetis's reasonable control, except to the extent Noetis remains responsible for a subprocessor under the DPA, remains responsible for its own selection and configuration of providers, or responsibility cannot lawfully be excluded.
Noetis may replace providers where reasonably necessary to operate or improve the Service, subject to applicable DPA obligations.
18. Fees
Customer shall pay all fees stated in the applicable Order.
Fees exclude VAT and applicable taxes unless expressly stated otherwise.
Usage-based charges and AI credits may be charged as described in the Order or Platform.
Prepaid credits are non-refundable except where mandatory law or the applicable Order provides otherwise.
Overdue amounts may accrue applicable statutory commercial interest and reasonable collection costs.
Noetis may suspend the Service for material non-payment after reasonable notice.
Noetis may change pricing for a renewal term with at least 30 days' prior notice.
19. Term and termination
These Terms remain effective while Customer uses or subscribes to the Service.
Unless an Order states otherwise, cancellation prevents renewal but does not terminate an existing committed Subscription term or create a right to refund prepaid fees.
Either party may terminate for a material breach not cured within 30 days after written notice.
A party may terminate immediately where the breach cannot reasonably be cured, use is unlawful, or the other party becomes insolvent to the extent termination is permitted by applicable law.
Noetis may terminate or suspend a specific high-risk feature rather than the entire Service where reasonably sufficient.
20. Effect of termination
Upon termination:
- Customer's right to use the Service ends;
- outstanding payment obligations remain due;
- Customer should export Customer Data before termination;
- Customer Data will be returned or deleted in accordance with the DPA;
- applicable backup retention cycles may continue temporarily; and
- provisions intended by their nature to survive remain effective.
21. Warranties and disclaimers
Each party warrants that it has authority to enter into these Terms.
Except as expressly stated and to the maximum extent permitted by applicable law, the Service, AI Output, Derived Data, predictions, recommendations and autonomous functionality are provided "as is" and "as available."
Noetis does not guarantee:
- uninterrupted operation;
- error-free operation;
- any specific inference or Visitor Profile being correct;
- conversion uplift;
- revenue;
- profit;
- leads;
- traffic;
- SEO performance;
- rankings;
- customer acquisition;
- accuracy of AI Output; or
- any particular commercial result.
Visitor Profiles and Derived Data are probabilistic inferences and must not be treated as verified facts about an individual.
22. Limitation of liability
22.1 Excluded losses
To the maximum extent permitted by law, Noetis shall not be liable for indirect or consequential loss, including loss of profit, revenue, anticipated savings, business, contracts, goodwill, reputation, customers, search ranking, traffic or opportunities.
22.2 General cap
Subject to Sections 22.3 and 22.4, Noetis's total aggregate contractual and non-contractual liability arising out of or relating to the Service during any twelve-month period shall not exceed the fees actually paid to Noetis for the affected Service during the twelve months immediately preceding the event giving rise to liability.
22.3 Enhanced cap
Where liability arises directly from Noetis's material breach of its confidentiality obligations, the DPA, or Noetis's IP indemnity under Section 23.2, Noetis's aggregate liability shall not exceed two times the General Cap, except where mandatory law requires otherwise.
22.4 Non-excludable liability
Nothing excludes or limits liability to the extent exclusion or limitation is prohibited by mandatory applicable law, including liability for fraud or intentional misconduct to the extent it cannot lawfully be limited.
Nothing in these Terms affects a data subject's rights under Article 82 GDPR.
Customer's obligation to pay valid fees is not subject to the liability cap.
22.5 Allocation of risk
The limitations in this Section reflect the nature and price of the Service and form an essential part of the parties' allocation of risk.
23. Indemnification
23.1 Customer indemnity
Customer shall defend, indemnify and hold Noetis harmless against third-party claims, regulatory claims to the extent legally indemnifiable, damages, settlements and reasonable external legal costs arising from:
- Customer Data or Customer content;
- Customer's unlawful instructions;
- Customer's failure to provide required notices;
- invalid, absent or improperly obtained consent;
- Customer's cookie/CMP configuration;
- unlawful profiling or personalisation criteria selected by Customer;
- prohibited sensitive profiling;
- Customer's use of the Service for significant automated decisions;
- discriminatory or unlawful targeting;
- Customer's regulated or sector-specific claims;
- Customer's publication or use of AI Output;
- autonomous publication authorised by Customer;
- Customer's failure to maintain accurate source information;
- Customer's infringement of third-party rights; or
- Customer's breach of applicable law or these Terms,
except to the extent the claim was directly caused by Noetis's breach of these Terms or applicable law.
23.2 Noetis IP indemnity
Noetis will defend Customer against a third-party claim alleging that the unmodified core Service, when used as authorised, directly infringes that third party's intellectual-property rights and will pay final court-awarded damages or settlements approved by Noetis.
This obligation does not apply to claims caused by:
- Customer Data;
- AI Output;
- Customer instructions;
- combinations with non-Noetis products;
- Customer modifications;
- continued use after Noetis provides a non-infringing alternative; or
- use outside the Documentation.
Noetis may, at its option, modify or replace affected functionality or terminate the affected Service and refund prepaid fees for the unused committed period.
This Section states Customer's exclusive contractual remedy for third-party IP infringement by the Service.
24. Indemnity procedure
The indemnified party must:
- promptly notify the indemnifying party;
- provide reasonable cooperation;
- allow the indemnifying party control of the defence and settlement.
No settlement may admit liability or impose non-monetary obligations on the indemnified party without its prior reasonable consent.
25. Confidentiality
Each party shall protect the other's Confidential Information using at least reasonable care and use it only for purposes connected with the agreement.
Confidential Information may be disclosed to personnel, professional advisers and service providers with a need to know and appropriate confidentiality obligations.
Standard exclusions apply to information independently developed, lawfully received from another source or publicly available without breach.
Required legal disclosure is permitted, with advance notice where legally permitted.
26. Compliance and assessments
Customer is responsible for determining whether its intended use requires:
- a DPIA;
- legitimate-interest assessment;
- consent assessment;
- sector-specific assessment;
- AI impact or conformity assessment; or
- prior consultation with an authority.
Noetis will provide reasonable information available to it that Customer reasonably requires to perform an applicable assessment.
Noetis does not provide Customer with legal advice by providing compliance tools, templates or documentation.
27. AI Act
Each party is responsible for obligations applicable to its respective role under the EU AI Act or other applicable AI legislation.
Customer shall not intentionally configure or deploy the Service so as to materially change its intended purpose into a prohibited or high-risk use without Noetis's prior written approval.
Where Customer's use causes Customer to become a regulated provider, deployer or other operator with additional obligations, Customer is responsible for those obligations except to the extent applicable law expressly assigns them to Noetis.
28. Changes
Noetis may update these Terms.
Material adverse changes during a committed paid term will be notified at least 30 days in advance unless a shorter period is reasonably necessary for security, legal or regulatory reasons.
Material commercial changes will ordinarily apply from renewal.
Where law requires renewed consent, Noetis will request it.
29. Governing law and jurisdiction
These Terms are governed by Dutch law.
The United Nations Convention on Contracts for the International Sale of Goods does not apply.
To the extent legally permitted, disputes shall be submitted exclusively to the competent court of the Rechtbank Midden-Nederland.
30. General
Customer may not assign these Terms without Noetis's prior written consent.
Noetis may assign these Terms in connection with a merger, corporate restructuring, financing, acquisition or sale of all or substantially all relevant assets or business.
The Order, DPA, these Terms and incorporated policies constitute the entire agreement.
In case of conflict:
1. signed Order; 2. DPA for Personal Data processing matters; 3. Visitor Intelligence & Personalisation Addendum for Visitor Intelligence matters not governed by the DPA; 4. these Terms; 5. AI & Autonomous Systems Policy; 6. Security & Compliance Addendum; 7. SLA; 8. other incorporated policies, including the Cookie & Similar Technologies Policy.
Failure to enforce a right is not a waiver.
Invalid provisions shall be modified or severed to the minimum extent necessary.
Neither party is liable for delay caused by events outside its reasonable control, except payment obligations already due.
Legal contact: chris@noetis.nl