Legal

Terms of Service

These business terms govern access to Boundlane, the governed automation platform provided by Boundlane AG. They are written for companies, public bodies and other organisations—not for personal or household use.

Effective
1 August 2026
Last updated
1 August 2026
Version
2026-08-01

1. The agreement and the parties

These Terms of Service (the Terms) are between Boundlane AG, Switzerland (the Provider, we or us), and the organisation that accepts an Order Form or whose authorised representative creates a workspace (the Customer or you).

The person accepting for the Customer confirms that they have authority to bind it. Other invited users agree to follow these Terms as authorised users, but do not change the Customer’s contract. The Service is offered only for professional use. If mandatory consumer law nevertheless applies, nothing in these Terms removes rights that cannot lawfully be waived.

The agreement consists of an executed Order Form or online order, these Terms, the Data Processing Addendum where applicable, and policies expressly incorporated here. In a conflict, an Order Form prevails, then the DPA for data-protection matters, then these Terms.

2. The Service

Boundlane lets the Customer describe business processes, connect authorised systems, build versioned automation packages, test and promote them through governed rollout stages, and run them on shared or dedicated infrastructure. Features and plan limits are described at checkout, in the applicable Order Form and in the product documentation.

During the subscription, we grant the Customer a limited, non-exclusive, non-transferable right to access and use the Service for its internal business purposes. The Customer may permit its employees, contractors and service providers to use the Service under its workspace, and remains responsible for their use.

We may improve or change the Service. We will not materially reduce a paid plan’s core functionality during its committed term without reasonable notice, unless a change is required for security, law, or a third-party service outside our control. Preview or beta functions are identified as such and may change or be withdrawn.

3. Accounts, workspaces and authority

Users must provide accurate account information, protect their sign-in methods, and notify us promptly of suspected compromise. The Customer controls membership, platform roles, business roles, connected systems, credentials, approval assignments and rollout decisions in its workspace.

The first authorised user who creates a workspace is its initial owner. Later users must be invited, provisioned through a directory, or authenticated by the Customer’s identity provider. Sharing an email domain does not by itself admit a person to an existing workspace.

4. Automation controls and Customer decisions

New automations start in a non-writing stage. Customer administrators decide whether and when to widen a rollout. Automation calls to Customer-connected systems use scoped credentials and an explicit hostname allowlist. State-changing actions are recorded in the audit trail.

The runtime prevents tools classified as universally forbidden. The current default list includes changing supplier bank details, releasing or initiating payment, and acting on a callback requesting those actions. Product documentation and the Customer’s configured policies determine the complete effective list.

These controls constrain authority; they do not decide whether an automation is suitable, legally compliant or correct for the Customer’s business. The Customer must review evidence, configure approvals, test material scenarios, use appropriately scoped credentials and maintain human oversight wherever the impact warrants it. The Service does not provide legal, accounting, employment, medical or other professional advice.

5. Customer Data and instructions

Customer Data means information submitted to, generated through, or accessed from systems connected to the Customer’s workspace. The Customer retains all rights in Customer Data and instructs us to process it only to provide, secure, support and improve the Service as described in the agreement and the DPA.

The Customer is responsible for the legality, accuracy and quality of Customer Data; for giving required notices and obtaining required permissions; and for ensuring its instructions do not violate law or third- party rights. The Customer must not provide data it is prohibited from processing. Sensitive or regulated data may be used only where the Customer has completed the necessary risk assessment and the selected plan, contracts and technical configuration are appropriate for it.

6. Ownership and licences

We and our licensors own the Service, its infrastructure, interfaces, documentation, first-party templates and other Provider materials. Except for the access right expressly granted above, no rights in those materials are transferred.

As between the parties, the Customer owns its Customer Data, configurations, process descriptions and the customer-specific automation packages and generated source created for it, excluding Provider materials and third-party materials. We assign to the Customer any rights we acquire in that customer-specific generated material and grant a perpetual, worldwide, non-exclusive licence to any Provider material embedded in an exported package solely as necessary to use that package. Model output may not qualify for intellectual- property protection in every jurisdiction.

Feedback may be used without restriction or attribution, but we will not identify the Customer or disclose its Confidential Information when doing so. Marketplace content remains owned by its publisher and is licensed under the terms shown with its listing. The Customer must not publish a package unless it has all rights needed to do so.

7. Confidentiality

Each party will protect the other party’s non-public business, technical and security information using at least reasonable care, use it only to perform the agreement, and disclose it only to people who need it and are bound by confidentiality obligations. Customer Data is Customer Confidential Information.

Confidentiality does not cover information the receiving party can show was lawfully known without restriction, independently developed, received lawfully from another source, or made public without breach. A legally compelled disclosure is permitted after advance notice where lawful and reasonable assistance at the disclosing party’s cost.

8. Acceptable use

The Customer and its users must not:

  • break applicable law, infringe rights, or access a system or data without authority;
  • circumvent security, policy, quota, approval, egress or rollout controls;
  • introduce malware, conduct vulnerability testing without written permission, or disrupt the Service;
  • use the Service to make unlawful discriminatory decisions or solely automated decisions where law requires meaningful human review;
  • resell or provide the Service as a bureau service unless an Order Form permits it; or
  • reverse engineer the Service except to the limited extent that applicable law does not permit that restriction.

We may investigate suspected misuse and take proportionate measures to protect the Service, other customers and affected people.

9. Third-party services and models

The Service interoperates with systems, identity providers, payment services, infrastructure and model providers supplied by third parties. The Customer authorises calls to the services it selects and is responsible for its accounts and permissions with them. Their own terms govern the Customer’s direct use of those services.

We are responsible for our integration and our processors as stated in the DPA, but not for a third party changing, suspending or misdescribing its service. Model providers may produce incomplete or incorrect output. The promotion gate and runtime controls reduce risk but do not replace Customer validation.

10. Security and data protection

We maintain technical and organisational measures designed to protect Customer Data, including tenant isolation, encryption, scoped credentials, policy enforcement and traceable changes. The Security page describes the current controls; it is informational and does not expand the warranties in these Terms.

The Privacy Notice explains processing for which we are a controller. Where we process personal data for the Customer, the DPA applies and is incorporated into the agreement. Current processors and transfer information are listed on the Subprocessor page.

11. Fees, taxes and plan limits

Fees, currency, billing period, included usage and commitment are shown at checkout or in an Order Form. Paid self-service plans are billed in advance through Stripe and renew for the same period until cancelled. Fees exclude taxes unless stated otherwise; the Customer is responsible for applicable taxes other than taxes on our net income.

Runs, build turns and model spend are hard ceilings unless an Order Form says otherwise. At a ceiling, the affected work stops rather than becoming an unapproved overage. A plan change takes effect as shown at checkout. Cancellation stops the next renewal and does not refund the current period except where the agreement or mandatory law requires it.

Overdue undisputed amounts may lead to suspension after notice and a reasonable opportunity to cure. The Customer must raise a good-faith invoice dispute promptly and pay undisputed amounts when due.

12. Term, suspension and termination

These Terms start when accepted and continue while the Customer has a workspace or active Order Form. Either party may terminate for a material breach not cured within 30 days after written notice, or immediately if cure is impossible, the other party becomes insolvent, or continued performance would violate law.

We may suspend only the affected access or workload where reasonably necessary for a material security risk, unlawful use, attack, non-payment, a binding legal requirement, or a serious breach of these Terms. Where practicable, we will give notice, explain the reason and restore access after the issue is resolved.

Before cancellation or workspace erasure, the Customer should export anything it wishes to keep. Termination stops active automations and access. Workspace erasure removes tenant data from active systems and stored traces; provider backups expire through their protected rotation schedules, and limited billing, tax, legal- hold and non-personal erasure records may remain. The Retention schedule gives the applicable criteria. Sections intended by their nature to survive—including fees, ownership, confidentiality, liability and general terms—will survive.

13. Warranties

We warrant that we will provide paid Services with reasonable skill and care and materially in accordance with their documentation. If the Customer reports a material breach of that warranty, we will use reasonable efforts to correct it; if we cannot, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period. This is the Customer’s exclusive contractual remedy for breach of this warranty.

To the maximum extent permitted by law, the Service, preview features, model output and third-party services are otherwise provided without additional representations or warranties. We do not warrant uninterrupted or error-free operation, that an automation will produce a particular business outcome, or that a connected system will behave as its vendor documents.

14. Indemnities

We will defend the Customer against a third-party claim that the unmodified paid Service infringes an intellectual-property right and pay finally awarded damages or an approved settlement. We may modify or replace the affected Service or terminate it and refund prepaid unused fees. This obligation does not cover Customer Data, Customer instructions, third-party material, unauthorised changes or combinations not supplied by us.

The Customer will defend us against third-party claims arising from Customer Data, unlawful instructions, unauthorised access to connected systems, or the Customer’s material violation of the Acceptable Use section, and pay finally awarded damages or an approved settlement. The indemnified party must give prompt notice, reasonable cooperation and control of the defence, and no settlement may admit fault or impose a non-monetary obligation on it without consent.

15. Liability

Neither party is liable for indirect or consequential loss, lost profit, lost revenue, loss of goodwill, or loss of data that could reasonably have been restored from an available backup, to the extent permitted by law. Each party must take reasonable steps to mitigate loss.

Subject to the next paragraph, each party’s aggregate liability arising from the agreement is limited to the fees paid or payable for the affected Service during the 12 months before the event giving rise to the claim; for a free Service, the cap is CHF 1,000. The cap applies in aggregate across contract, tort and other legal bases.

The exclusions and cap do not apply to payment obligations, fraud, wilful misconduct, gross negligence, death or personal injury caused unlawfully, or liability that applicable law does not permit a party to exclude or limit.

16. General terms

Neither party is liable for delay caused by events beyond its reasonable control, except payment obligations. The parties are independent contractors. Neither may assign the agreement without the other’s consent, except to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the assignee can perform the agreement.

Notices must be in writing. Operational notices may be delivered in the Service or by email to the account owner; legal notices to us must be sent to hello@boundlane.com. A failure to enforce a provision is not a waiver. If a provision is unenforceable, it will be adjusted only as necessary and the remainder continues. The agreement is the entire agreement about the Service and does not create third-party beneficiaries.

Swiss law governs, without regard to conflict-of-laws rules or the UN Convention on Contracts for the International Sale of Goods. The courts at the Provider’s registered seat in Switzerland have exclusive jurisdiction, subject to any mandatory venue. Before filing, the parties will try in good faith for 30 days to resolve the dispute through business representatives.

17. Changes and contact

We may update these Terms for legal, security or product reasons. We will give workspace owners at least 30 days’ notice of a material change unless law or an urgent security issue requires less. A material new version will be presented for acceptance; prior versions remain available in the version archive. Changes do not retroactively alter an executed Order Form.

Questions about these Terms may be sent to hello@boundlane.com or through the contact page.