Coreline OS
ProductHow it worksPricing
Open StudioGet started

Legal

Coreline OS Terms of Service

The current contract terms for customer use of Coreline OS.

Document version1.2.0
Published29 August 2026
Effective date28 September 2026
Supersedes1.1.0
Canonical URLhttps://corelineos.com/en/terms

These Terms of Service (the Terms) govern access to and use of Coreline OS, including its web interfaces, APIs, Model Context Protocol (MCP) endpoints, integrations, documentation and related support (collectively, the Service). Please read them carefully.

The customer-facing Service is made available through the official Coreline OS addresses listed in clause 1.5. Those addresses, including their paths and interfaces, are covered by these Terms.

1. Parties, scope and order of precedence

  1. The Service is provided by Boeni Industries AG, Sihleggstrasse 23, CH-8832 Wollerau, Switzerland, registered in the Commercial Register of the Canton of Schwyz under CHE-404.375.091 (we, us or our).
  2. The person or organisation accepting these Terms, or on whose behalf the Service is used, is the Customer, you or your. If an individual accepts these Terms for an organisation, that individual represents and warrants that they have authority to bind that organisation. The organisation is the Customer.
  3. The Service is intended solely for organisations and professional users. It is not offered to consumers or children. If mandatory law nevertheless applies, nothing in these Terms limits rights that cannot lawfully be excluded.
  4. These Terms apply to the Service and not merely to a visit to corelineos.com. A separately signed agreement or an order form expressly incorporating different terms prevails over these Terms to the extent of a conflict. The Data Processing Addendum in Annex 1 prevails over the other Terms for the processing of Customer Personal Data.
  5. The official customer-facing Coreline OS addresses are:
ServiceOfficial address
Commercial websitehttps://corelineos.com and https://www.corelineos.com
Coreline OS Studiohttps://studio.corelineos.com
Coreline OS APIhttps://api.corelineos.com
Coreline OS platform and tenant platform MCPhttps://platform.corelineos.com
Coreline OS runtime MCPhttps://mcp.corelineos.com

Coreline OS may also send transactional email from @mail.corelineos.com. No other domain or address is an official customer-facing Coreline OS service unless Boeni Industries AG communicates it through one of the addresses above or in a signed agreement.

2. Formation of the agreement and changes

  1. The agreement begins when Boeni Industries AG activates a Customer workspace, confirms an order, or otherwise enables use of the Service, whichever occurs first. Your use of the Service confirms acceptance of these Terms.
  2. Boeni Industries AG may update these Terms for legal, security, technical or commercial reasons. We will give at least 30 days' prior notice of a material adverse change by email, in the Service, or by another reasonable durable means, except where a shorter period is required to comply with law, address an urgent security risk or prevent abuse. If you do not agree, you may terminate the affected Service before the change takes effect. Continued use after the effective date constitutes acceptance.

3. The Service

  1. Coreline OS is a multi-tenant operational software service that enables Customers to configure and run applications, workflows, integrations and AI-assisted or agent-operated functions. Its features may be accessed by people, software clients and authorised agents through the interfaces we make available.
  2. Subject to these Terms, Boeni Industries AG grants the Customer a non-exclusive, non-transferable, non-sublicensable, revocable right during the term to permit its Authorised Users to access and use the Service for the Customer's internal business purposes.
  3. Authorised Users are the Customer's employees, contractors and other persons whom the Customer authorises to use its workspace, each acting under the Customer's responsibility. The Customer is responsible for their acts and omissions and for keeping account, role and access information current.
  4. Boeni Industries AG may provide beta, preview, trial or free functions. They may be changed, suspended or withdrawn at any time and are provided without any commitment as to availability, support, continuity or suitability. The liability limitations in clause 15 apply, subject to mandatory law.
  5. Documentation, public product descriptions and roadmaps describe the Service generally; they are not a promise that a feature will be available at a particular time or in a particular form.
  6. Except where a signed order form expressly states otherwise, Boeni Industries AG is not required to maintain a particular feature, interface, API version, integration, model, output format or backwards compatibility. The Customer is responsible for maintaining its own integrations, configurations, controls and contingency arrangements.

4. Accounts, security and authority

  1. The Customer must provide accurate account and billing information and promptly update it. Account credentials are personal and must not be shared. The Customer must use reasonable measures to protect credentials, access tokens, API keys and connected-system credentials.
  2. The Customer must promptly notify Boeni Industries AG at hello@corelineos.com if it suspects unauthorised access, loss of credentials or a security incident affecting the Service. Boeni Industries AG may require credential rotation, disable compromised access, or take other proportionate protective measures.
  3. A workspace administrator may invite users, assign roles, configure applications, connect third-party services, authorise spending or capacity controls, and enable agent or automated actions within the permissions available to that administrator. The Customer is responsible for selecting administrators and for all instructions and configurations made through its accounts.
  4. The Customer is responsible for all activity through its accounts, including activity by Authorised Users, administrators, software clients and agents, except to the extent directly caused by Boeni Industries AG's breach of these Terms or mandatory law.

5. Acceptable use

  1. The Customer and its Authorised Users must use the Service lawfully, professionally and in accordance with these Terms, applicable documentation and all applicable laws and regulations.
  2. The Customer must not, and must not permit any third party to:
    • use the Service to infringe rights, breach confidentiality, process data unlawfully, deceive others, or facilitate unlawful, harmful, discriminatory or fraudulent conduct;
    • upload, transmit or make available malware, destructive code, or material that is unlawful or infringes another person's rights;
    • interfere with, disrupt, bypass, probe or compromise the Service, its security controls, rate limits, tenant isolation or other users' access;
    • access the Service or non-public data except through authorised interfaces and permissions, or attempt to gain unauthorised access to any account, system, network or data;
    • reverse engineer, decompile, disassemble or attempt to derive source code from the Service, except to the extent such restriction is prohibited by mandatory law;
    • rent, lease, resell, time-share, provide service-bureau access to, or otherwise make the Service available to unauthorised third parties;
    • remove proprietary notices; use Coreline OS name, marks or logos except as permitted in writing; or use the Service to develop a competing hosted service by copying its non-public features or interfaces;
    • use the Service in a manner that creates an unreasonable load or evades usage, capacity, payment, safety or access controls; or
    • use an AI or agent function to make a decision or take an action where human review, consent, authority or other safeguards are required by law or appropriate to the risk.
    • use the Service in breach of applicable export controls, sanctions, anti-bribery, anti-corruption, anti-money-laundering or trade-compliance laws; or
    • use the Service in a prohibited, regulated or high-risk context without obtaining all approvals, licences, notices, consents, human oversight and safeguards required by applicable law and appropriate to the risk.
  3. Boeni Industries AG may investigate suspected misuse and may suspend access under clause 16. We will use reasonable efforts to limit the scope and duration of a suspension.

6. Customer Data, Customer Content and AI-assisted functions

  1. Customer Data means data, content, instructions, prompts, files, records, credentials, configurations and other materials submitted to, stored in, generated for, or made accessible through the Customer's use of the Service, including data received from a connected service. Customer Data does not include Boeni Industries AG's service telemetry, aggregated or de-identified information, or data Boeni Industries AG independently obtains outside the Service.
  2. As between the parties, the Customer retains all rights in Customer Data. The Customer grants Boeni Industries AG the limited rights necessary to host, process, transmit, display, back up, secure, support and otherwise provide and improve the Service in accordance with these Terms and the Data Processing Addendum.
  3. The Customer represents and warrants that Customer Data, instructions, configurations, Connected Services and use of the Service are accurate, lawful and appropriately authorised, and that it has all rights, lawful bases, notices, consents, approvals and permissions necessary for Boeni Industries AG and its subprocessors to process Customer Data as instructed through the Service. The Customer must not submit data subject to a legal or contractual restriction that would make the contemplated processing unlawful.
  4. AI-assisted and agent functions may produce incomplete, incorrect, unsuitable or unexpected output and may initiate actions only to the extent configured and authorised in the Service. The Customer must independently review outputs and configure appropriate permissions, approval steps, spending limits, monitoring, escalation and human oversight before relying on an output or allowing an automated action to have legal, financial, employment, safety, medical, regulatory or other material effect. The Customer remains responsible for decisions and actions taken through its workspace.
  5. Boeni Industries AG does not claim ownership of Customer Data or use it to train generally available foundation models, except where the Customer has expressly agreed otherwise. We may use aggregated or de-identified information, and Service telemetry that does not identify the Customer or a person, to operate, secure, analyse and improve the Service.

7. Connected services and third-party materials

  1. The Service may enable the Customer to connect third-party services, software, data sources, models or content (Connected Services). The Customer decides whether to enable a Connected Service and what permissions or data it receives.
  2. Connected Services are governed by their own terms and privacy notices. Boeni Industries AG does not control them and is not responsible for their availability, security, content, acts, omissions or handling of Customer Data. The Customer is responsible for obtaining all rights, permissions and consents needed to connect and use them.
  3. Boeni Industries AG may disable, limit or remove a Connected Service where reasonably necessary for security, legal compliance, service integrity, third-party requirements or technical compatibility.

8. Service operation, support and changes

  1. Boeni Industries AG will provide the Service with reasonable care and skill and maintain reasonable technical and organisational measures appropriate to the nature of the Service. The Service is complex and internet-dependent; uninterrupted, error-free or completely secure operation is not guaranteed.
  2. We may perform planned or emergency maintenance and may modify, discontinue, replace or limit any feature, interface, API, integration, model, output format or third-party dependency for security, legal, commercial, operational, technical or product-development reasons. Where commercially reasonable and practicable, we will give advance notice of a material change to paid core functionality. We have no liability for a change, discontinuation or incompatibility permitted by this clause, subject to clause 15 and mandatory law.
  3. Unless agreed otherwise in writing, the Service does not include a service-level agreement, a particular response time, implementation services, legal, tax, accounting, medical or other professional advice.

9. Fees, capacity and payments

  1. Boeni Industries AG's current rate card, capacity offer and any applicable order form state the relevant prices, currency, taxes, expiry conditions and purchase terms. The Customer pays for rated operational work and any separately agreed services; Boeni Industries AG does not charge for seats, named users, workspaces, Domain Packs, connections or feature access unless an order form expressly says otherwise.
  2. Purchased capacity is a prepaid right to receive Coreline OS SaaS Services rated under the applicable offer. It is non-transferable and non-refundable except as provided in clause 9.6; it may be redeemed only in the Customer workspace for Coreline OS SaaS Services and not for third-party products or services. Capacity is not money, a stored-value account, a deposit, a financial instrument or property, and has no cash value. Promotional, trial, Heartbeat, grant or service-recovery capacity may have additional eligibility, expiry and abuse-prevention conditions.
  3. Boeni Industries AG records rated usage and capacity movements. The Customer must review any usage information made available in the Service and notify us of a good-faith, reasonably detailed billing query without undue delay. An obvious rating error will be corrected prospectively or by restoring capacity, as appropriate.
  4. For self-service purchases, the designated merchant of record or payment provider (currently Creem, where offered) processes checkout, payment methods, taxes, invoices or receipts, refunds, payment disputes and payment-related personal data under its own terms. The merchant of record is the seller of record for that transaction. The Customer must comply with its applicable terms. Boeni Industries AG remains responsible for the Service and the capacity ledger described in these Terms.
  5. Optional scheduled purchases or auto top-ups must be expressly enabled by an authorised billing user. The Customer may cancel them through the relevant Service or merchant-of-record flow, subject to the applicable offer and provider terms. They are purchases of capacity, not a recurring access subscription.
  6. Prices are exclusive of VAT and similar taxes unless expressly stated otherwise. The Customer is responsible for taxes that the merchant of record does not collect or remit, excluding taxes based on Boeni Industries AG's net income. A refund is available only where required by mandatory law, stated in the applicable offer, or approved by the merchant of record under its refund process. This does not limit a correction for Boeni Industries AG-caused rating error under clause 9.3.
  7. Amounts due must be paid in full, without set-off, counterclaim, deduction or withholding except where mandatory law requires otherwise. The Customer bears bank, transfer, collection and similar charges and must provide any documentation reasonably required for tax treatment. Overdue amounts bear interest at the statutory rate or, if higher, the rate stated in an applicable order form, plus reasonable collection costs.
  8. Boeni Industries AG's operational, security, capacity and usage records are authoritative absent manifest error. The Customer must raise a good-faith, reasonably detailed billing query within 30 days after the relevant record or invoice is made available; this does not permit withholding of undisputed amounts.

10. Intellectual property and feedback

  1. Boeni Industries AG and its licensors retain all rights, title and interest in and to the Service, documentation, software, designs, methods, models, templates, trademarks and other Coreline OS materials, including all related intellectual-property rights. No rights are granted except those expressly stated in these Terms.
  2. If the Customer gives Boeni Industries AG feedback, suggestions or improvement ideas, Boeni Industries AG may use them without restriction or compensation. The Customer grants Boeni Industries AG a perpetual, worldwide, irrevocable, royalty-free licence to do so, but Boeni Industries AG will not identify the Customer as the source without permission.

11. Confidentiality

  1. Each party may receive non-public information of the other party that is identified as confidential or should reasonably be understood as confidential (Confidential Information). Customer Data and non-public information about the Service are Confidential Information.
  2. The receiving party will use the disclosing party's Confidential Information only to perform or exercise rights under these Terms, protect it with at least reasonable care, and disclose it only to personnel, advisers, affiliates and subprocessors who need to know it and are bound by confidentiality obligations no less protective than this clause.
  3. Confidential Information does not include information the receiving party can demonstrate: (a) is or becomes public without breach of these Terms; (b) was already lawfully known without a confidentiality obligation; (c) is lawfully received from a third party without restriction; or (d) is independently developed without use of the Confidential Information.
  4. A party may disclose Confidential Information where required by law, regulation or valid order, provided it gives prior notice where legally permitted and reasonably cooperates with efforts to obtain protective treatment. This clause survives for five years after termination; trade secrets and Customer Data remain protected for as long as they qualify as confidential under applicable law.

12. Data protection and security

  1. Each party will comply with applicable data-protection law. To the extent Boeni Industries AG processes personal data contained in Customer Data on the Customer's behalf, the Data Processing Addendum in Annex 1 applies.
  2. The Customer is normally the controller (or processor acting for another controller) for Customer Personal Data and determines the purposes and means of processing through its use and configuration of the Service. Boeni Industries AG acts as processor to the extent stated in Annex 1. Boeni Industries AG may independently act as controller for account, contact, billing, security and service-telemetry data it processes for its own legitimate service-operation purposes; Boeni Industries AG's Privacy Policy applies to that processing.
  3. Boeni Industries AG maintains measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. No security measure is absolute. The Customer is responsible for its own endpoint security, user permissions, authentication choices, configuration, Connected Services and backups or exports it chooses to retain.

13. Indemnification

  1. The Customer will defend, indemnify and hold harmless Boeni Industries AG, its affiliates, licensors, subprocessors and personnel against third-party claims, losses, damages, liabilities, fines, penalties, costs and reasonable legal fees arising from: (a) Customer Data; (b) the Customer's or an Authorised User's use of the Service, an AI or agent function, or a Connected Service; (c) an instruction, configuration, approval or action supplied or authorised by the Customer; (d) the Customer's breach of these Terms, the Data Processing Addendum or applicable law; or (e) an allegation that Customer Data, an instruction or the Customer's use infringes rights or breaches confidentiality, in each case except to the extent caused by Boeni Industries AG's wilful misconduct or gross negligence where liability cannot be excluded by mandatory law.
  2. Boeni Industries AG may elect to control the defence of a claim where reasonably necessary to protect its interests. Otherwise, the Customer controls the defence with counsel reasonably acceptable to Boeni Industries AG and provides reasonable cooperation at the Customer's expense. The Customer may not settle a claim without Boeni Industries AG's prior written consent unless the settlement fully releases Boeni Industries AG without admission, payment or restriction.

14. Warranties and disclaimers

  1. Each party represents that it has authority to enter into these Terms.
  2. Except for the express commitments in these Terms and to the maximum extent permitted by law, the Service, beta functions, AI outputs and third-party materials are provided "as is" and "as available". Boeni Industries AG disclaims all implied warranties, including merchantability, fitness for a particular purpose, non-infringement, accuracy, availability and uninterrupted or error-free operation.
  3. Boeni Industries AG does not warrant that the Service will meet every Customer requirement, produce a particular business outcome, detect every error or threat, or make AI-generated output correct, complete, safe, lawful or suitable for any particular purpose.

15. Liability

  1. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for wilful misconduct or gross negligence where exclusion is prohibited by Article 100 of the Swiss Code of Obligations.
  2. Subject to clause 15.1, Boeni Industries AG is not liable for indirect, incidental, special, punitive or consequential loss, or for loss of profit, revenue, business, goodwill, anticipated savings, opportunity, data or business interruption, even if advised of the possibility of such loss.
  3. Subject to clauses 15.1 and 15.2, Boeni Industries AG's aggregate liability arising out of or relating to these Terms, including under clause 11 (Confidentiality), in any 12-month period is limited to the amounts paid or payable by the Customer to Boeni Industries AG for the Service in the 12 months immediately preceding the event giving rise to the claim. This cap does not limit the Customer's payment obligations or obligations under clause 13 (Indemnification).
  4. Nothing in this clause restricts a data subject's statutory rights or liability that cannot lawfully be excluded or limited under applicable data-protection law.
  5. The limitations in this clause apply regardless of the legal basis of a claim, to the maximum extent permitted by law.

16. Suspension and termination

  1. The Customer may stop using the Service at any time. A scheduled capacity purchase or auto top-up must be cancelled through the applicable flow. Stopping use does not entitle the Customer to a refund for capacity already purchased, except as required by law or the applicable offer.
  2. Boeni Industries AG may suspend, restrict or disable the Service or particular access immediately where reasonably necessary to protect the Service, Customer Data, other users or third parties; investigate suspected misuse; comply with law, sanctions, a valid authority request or third-party requirements; address non-payment; or protect Boeni Industries AG's security, legal, commercial or reputational interests. Where practicable, Boeni Industries AG will give notice and an opportunity to cure. The Customer remains responsible for amounts due and for reasonable reactivation, support or remediation costs.
  3. Either party may terminate these Terms for material breach if the breach is not cured within 30 days after written notice, unless it cannot reasonably be cured or an immediate suspension or termination is justified under clause 16.2. Boeni Industries AG may terminate for convenience on 30 days' notice where no separately agreed minimum term applies and may terminate immediately for non-payment that remains uncured for 10 days after notice.
  4. On termination, the Customer's right to access and use the Service ends. At the Customer's request made before termination or during the retention period, Boeni Industries AG will make Customer Data available for export in a commonly used format where technically feasible. Boeni Industries AG has no obligation to convert, consolidate, recreate or deliver data in a bespoke format and may charge for non-standard export or transition assistance. Unless an order form states a different period, Boeni Industries AG will retain Customer Data for 30 days after termination so the Customer can request an export, then delete or anonymise it in accordance with its deletion processes, except where retention is required by law or reasonable backup, security, dispute or audit needs. Deleted data may persist in backups for a limited period before overwrite and will not be restored except as required for disaster recovery.
  5. Clauses that by their nature should survive do so, including clauses 6, 9, 10, 11, 13, 14, 15, 16.4, 17, 18 and 19.

17. Notices

  1. Notices to Boeni Industries AG must be sent to hello@corelineos.com and, for formal legal notices, to Boeni Industries AG, Sihleggstrasse 23, CH-8832 Wollerau, Switzerland.
  2. Boeni Industries AG may send notices to the Customer's administrative or billing email address, through the Service, or to the postal address on file. Notices are deemed received when sent electronically, unless the sender receives a delivery-failure notice, or three business days after postal dispatch within Switzerland (or seven business days internationally).

18. Governing law and venue

  1. These Terms and any non-contractual obligations arising from them are governed by substantive Swiss law, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods (CISG).
  2. The courts at the registered seat of Boeni Industries AG in Wollerau, Canton of Schwyz, Switzerland have exclusive jurisdiction, subject to mandatory statutory venues.

19. Compliance with laws

  1. The Customer must comply with all laws applicable to its use of the Service, including export-control, sanctions, anti-bribery, anti-corruption, anti-money-laundering, data-protection and sector-specific laws. The Customer represents that neither it nor any person receiving access through it is subject to sanctions or restrictions that prohibit Boeni Industries AG from providing the Service.
  2. Boeni Industries AG may take any action it reasonably considers necessary to comply with applicable law, sanctions or a third-party requirement, without liability subject to clause 15 and mandatory law.

20. General provisions

  1. The Customer may not assign or transfer these Terms, by operation of law or otherwise, without Boeni Industries AG's prior written consent. Boeni Industries AG may assign these Terms to an affiliate or in connection with a merger, reorganisation, sale of business or assets, or similar transaction, provided the successor assumes the relevant obligations.
  2. Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, excluding payment obligations. The affected party will use reasonable efforts to mitigate the effect.
  3. These Terms, any applicable order form and Annex 1 are the entire agreement concerning the Service and supersede prior discussions or agreements on that subject. Terms in a purchase order or similar Customer document do not apply unless Boeni Industries AG expressly accepts them in writing.
  4. If any provision is invalid or unenforceable, it will be modified to the minimum extent necessary or severed, and the remaining provisions remain effective. A waiver must be in writing and applies only to the specific instance. Failure to enforce a provision is not a waiver.
  5. Headings are for convenience only. The English version is authoritative unless a separately signed agreement expressly provides otherwise.

21. Version history

VersionPublishedEffectiveChange summary
1.0.022 August 202622 August 2026Initial public Terms of Service, including the Data Processing Addendum.
1.1.022 August 202621 September 2026Clarified service-change, payment, enforcement, liability, suspension, compliance, export and Data Processing Addendum protections.
1.2.029 August 202628 September 2026Clarified that purchased capacity is non-transferable, non-cash prepaid Coreline OS SaaS capacity and cannot be redeemed for third-party products or services.

Annex 1 — Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the Terms. It applies where Boeni Industries AG processes Customer Personal Data as processor on the Customer's documented instructions. It is intended to satisfy Article 9 of the Swiss Federal Act on Data Protection (FADP) and, where applicable, Article 28 of the EU General Data Protection Regulation (GDPR).

A. Definitions and roles

  1. Customer Personal Data means personal data contained in Customer Data that Boeni Industries AG processes on the Customer's behalf.
  2. The Customer is the controller of Customer Personal Data, or a processor acting on behalf of its controller, and Boeni Industries AG is the processor. If the Customer is a processor, it confirms that its instructions and this DPA are authorised by the relevant controller and that it will meet its own processor obligations.
  3. The Customer's documented instructions are these Terms, this DPA, the applicable order form, the Customer's use and configuration of the Service, and further written instructions that are consistent with them. Boeni Industries AG will inform the Customer if an instruction infringes applicable data-protection law, unless prohibited by law.

B. Details of processing

ItemDescription
Subject matterProvision, operation, support, security and maintenance of the Service for the Customer. Any improvement based on Customer Personal Data requires the Customer's separate documented instruction; use of aggregated or de-identified information is governed by the Terms.
DurationThe term of the Terms plus the retention and deletion period in clause 16.4 of the Terms, unless applicable law requires longer retention.
Nature and purposeHosting, storage, organisation, retrieval, transmission, analysis, automation, generation of configured outputs, support, security monitoring, backup and deletion as needed to provide the Service and comply with documented instructions.
Categories of data subjectsPersons whose data the Customer or its Authorised Users submit or make available through the Service, which may include employees, contractors, customers, prospects, suppliers, business contacts, end users and other persons relevant to the Customer's operations.
Categories of personal dataData determined by the Customer, which may include identity, contact, employment, business, transactional, technical, usage, content, prompt, file and connected-service data. The Customer must not submit special categories or sensitive personal data unless the Service is configured and lawfully suitable for that processing.

C. Boeni Industries AG's obligations

  1. Boeni Industries AG will process Customer Personal Data only on the Customer's documented instructions, unless required otherwise by applicable law. In that case, Boeni Industries AG will inform the Customer before processing unless the law prohibits notice.
  2. Boeni Industries AG will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
  3. Boeni Industries AG will implement appropriate technical and organisational measures, taking into account the state of the art, implementation costs, nature, scope, context and purposes of processing and the risks to individuals. Those measures include, as appropriate, access control, authentication, tenant segregation, encryption in transit, logging, vulnerability management, backup and recovery procedures, and controlled operational access.
  4. Taking into account the nature of processing and information available to Boeni Industries AG, Boeni Industries AG will provide reasonable assistance to enable the Customer to respond to data-subject requests, data-protection impact assessments, consultations with authorities, and its security and breach-notification obligations. Boeni Industries AG may charge reasonable fees for assistance beyond the ordinary operation of the Service.
  5. Boeni Industries AG will notify the Customer without undue delay after becoming aware of a personal-data security breach affecting Customer Personal Data and will provide available information reasonably necessary for the Customer to meet its legal obligations.
  6. On termination, Boeni Industries AG will delete or return Customer Personal Data in accordance with clause 16.4 of the Terms, unless law requires retention.

D. Subprocessors

  1. The Customer gives Boeni Industries AG general written authorisation to use subprocessors for the Service. Boeni Industries AG will ensure that a subprocessor is bound by written obligations materially consistent with this DPA and remains responsible for the subprocessor's performance of the delegated processing.
  2. Boeni Industries AG's current material subprocessors and processing locations are identified in its Privacy Policy or other current subprocessor information made available to the Customer. Boeni Industries AG may appoint or replace subprocessors and will provide reasonable prior notice of a material new subprocessor where required by applicable law or the Customer's written agreement. The Customer may object within 30 days of notice only on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable solution; if none is available, the Customer may terminate only the affected Service before the new subprocessor begins processing, without penalty other than amounts already due.

E. Audits and information

  1. On reasonable written request and no more than once annually, Boeni Industries AG will make available information reasonably necessary to demonstrate compliance with this DPA. Boeni Industries AG may satisfy this obligation through current independent audit reports, certifications, summaries, questionnaires or other documentary information. The Customer may conduct an audit only where such information is insufficient to demonstrate compliance or where required by a competent authority, on at least 60 days' prior written notice, during normal business hours, remotely where reasonably possible, without unreasonable disruption, and subject to confidentiality and security requirements.
  2. Audits must be performed by an independent auditor bound by confidentiality. They must not access other customers' information, penetrate production systems, perform security testing or compromise service security. The Customer bears its own audit costs and reimburses Boeni Industries AG's reasonable costs for audit support.

F. International transfers

  1. Customer Personal Data is hosted in Switzerland unless otherwise agreed or required by a Connected Service selected by the Customer. Boeni Industries AG may transfer Customer Personal Data to countries outside Switzerland or the European Economic Area only where permitted by applicable data-protection law and subject to required safeguards.
  2. Where a transfer requires contractual safeguards, the parties incorporate the European Commission Standard Contractual Clauses for controller-to-processor or processor-to-processor transfers, as applicable, with the adaptations required for Swiss law, or another valid transfer mechanism. The Customer authorises Boeni Industries AG to enter into such safeguards with subprocessors on the Customer's behalf where legally permitted.

G. Precedence

If this DPA conflicts with the Terms concerning the processing of Customer Personal Data, this DPA prevails. Nothing in this DPA requires either party to act contrary to applicable data-protection law.

Coreline OS
© 2026 Boeni Industries AG · Switzerland
Open StudioPricingLegal noticePrivacyTerms