Terms of Service
Last updated: June 2026
Preamble — Regulatory Orientation
Virtualway S.r.l. has designed isolAIted with a deliberate commitment to European regulatory compliance, in particular Regulation (EU) 2024/1689 on Artificial Intelligence (AI Act) and Regulation (EU) 2016/679 on the protection of personal data (GDPR). This is not a formal tick-box exercise: it is an architectural choice that runs through the Software from its foundations.
These Terms reflect this approach through four principles that guide the distribution of responsibilities between the Provider and the Deployer:
- ·Clear risk classification: isolAIted does not fall within the prohibited AI practices (Chapter II AI Act) or high-risk AI systems (Chapter III AI Act). It is classifiable as a limited-risk AI system, subject to the transparency obligations of Chapter IV.
- ·Distinct regulatory roles: Virtualway S.r.l. is the Provider of the Software under the AI Act; the organisation or professional that deploys it is the Deployer. This distinction determines precisely who is accountable for what under the law.
- ·Structural Privacy by Design: the on-premise architecture ensures that the organisation's data never leaves the Deployer's own infrastructure. The Provider has no technical ability to access the data processed, and is neither Controller nor Processor under the GDPR.
- ·Voluntary adherence to the highest standards: although not required to do so as a limited-risk system, the Provider has voluntarily implemented features that satisfy the requirements the AI Act prescribes for high-risk systems (human oversight, event logging, transparency, technical documentation), in keeping with the spirit of Art. 95 AI Act on voluntary codes of conduct.
These Terms do not constitute legal advice. The Deployer is responsible for assessing their own specific regulatory position with the support of a qualified adviser.
1. Definitions
For the purposes of these Terms:
- ·Software: the artificial intelligence system named isolAIted, in its form as a desktop application for the local orchestration of AI models.
- ·Provider (within the meaning of Art. 3(3) of Reg. EU 2024/1689): Virtualway S.r.l., as the entity that develops and places the Software on the market. Also referred to in these Terms as Developer.
- ·Deployer (within the meaning of Art. 3(4) of Reg. EU 2024/1689): any natural or legal person that uses the Software under their own responsibility in a professional context. Also referred to in these Terms as User.
- ·AI System (within the meaning of Art. 3(1) of Reg. EU 2024/1689): the Software in its entirety, i.e. the automated system designed to operate with varying levels of autonomy and to produce outputs such as predictions, recommendations, decisions or content.
- ·LLM Models / Third-party AI Models: artificial intelligence models developed, trained and published by independent third parties, downloadable and usable through the Software.
- ·GPAI Model (within the meaning of Art. 3(63) of Reg. EU 2024/1689): a general-purpose AI model — i.e. the underlying mathematical model (raw LLM) developed by third parties. The Software is not a GPAI model: it is an application that enables the orchestration of third-party GPAI models.
- ·GPAI Model with Systemic Risk (within the meaning of Art. 51 of Reg. EU 2024/1689): a GPAI model with training compute exceeding 1025 FLOPs, or classified as such by the European Commission. The Provider does not develop or distribute such models.
- ·Output: any content (text, code, images, analysis, recommendations) generated by the Software through AI models.
- ·Controller (within the meaning of Art. 4(7) of Reg. EU 2016/679 — GDPR): the Deployer, as the sole entity that determines the purposes and means of processing of personal data handled through the Software.
2. Scope of the Service
The isolAIted Software is a local Artificial Intelligence System that enables:
- ·AI chatbot interactions
- ·creation of AI agents
- ·definition of AI agent-based workflows
- ·use of autonomous AI agents
- ·content generation
The Software operates primarily offline, except for the optional download of AI models from external sources.
3. Licence
The Provider grants the Deployer a licence that is:
- ·free of charge
- ·non-exclusive
- ·non-transferable
- ·revocable
for use of the Software for personal and commercial purposes.
The following are strictly prohibited:
- ·Modifying, altering, translating, decompiling, disassembling or reverse engineering the Software or any part thereof.
- ·Selling, renting, sublicensing, distributing or redistributing the Software to third parties, whether free of charge or for commercial purposes, through any channel or platform not explicitly authorised by the Provider. Downloading and distributing the Software is permitted exclusively through the Provider's official channels.
- ·Removing, obscuring or altering any trademarks, logos or copyright notices present in the Software.
3.1 Third-Party Components (Open Source)
The Software integrates or interacts with third-party libraries and tools released under open-source licences, including: LangChain and LangGraph (MIT Licence), Ollama (MIT Licence), OpenTelemetry (Apache License 2.0), Grafana (GNU Affero General Public License v3.0 — used in its original form as a Docker service, without any modifications to the source code), Grafana Loki (GNU Affero General Public License v3.0 — used in its original form as a Docker service, without any modifications to the source code). Such components remain the property of their respective rights holders.
The text of the relevant licences and copyright notices is available within the application (section "Legal Notices and Credits"), in the official documentation on the Provider's website, or upon written request to the Provider.
This proprietary licence applies exclusively to the overall architecture, proprietary code and interface developed by the Provider, without limiting any rights of the Deployer arising from the open-source licences of the individual third-party components.
4. Third-Party AI Models
The Software allows the download and local use of AI models developed by third parties. The Provider is not the manufacturer of such models and does not control their operation, content or safety characteristics.
The Deployer acknowledges that:
- ·such models are not owned by the Provider and are subject to separate licence agreements
- ·the Provider is not responsible for their operation, content, quality or behaviour
- ·the Deployer is responsible for reviewing the licence terms, model cards and any restrictions applicable to each model before use
The Software includes a system for detecting the computational complexity of downloaded models. When a model exceeds the potential systemic risk threshold under Art. 51 of Reg. EU 2024/1689 (training compute ≥ 1025 FLOPs or parameters indicative of that category), the Software notifies the Deployer before use, enabling them to carry out the appropriate assessments.
Note — GPAI models with systemic risk (Art. 51 AI Act): The specific obligations under the AI Act for systemic-risk models (notification to the EU AI Office, technical reports, advanced security measures) fall exclusively on the manufacturers and distributors of those models — not on the Deployer who runs them locally, nor on the Provider who makes the orchestration application available.
4.1 Disclaimer of Liability for Model Output
The Provider exercises no editorial, technical or safety control over third-party models or the outputs they generate.
The Provider disclaims all liability with respect to:
- ·the accuracy, legality, safety, quality or appropriateness of any output generated by the models, including uncensored models
- ·any violations of intellectual property rights or copyright committed upstream by model creators during the training phase (upstream IP violations)
- ·malfunctions, biases, hallucinations or harmful content arising from the local execution of the models
- ·failure by model providers to comply with their obligations under the AI Act or other applicable legislation
5. Use of the Software
The Deployer agrees to use the Software in compliance with applicable law.
The Software must not be used for:
- ·illegal activities or activities prohibited by applicable law
- ·any practice prohibited by Art. 5 of Reg. EU 2024/1689 (AI Act), including subliminal manipulation, social scoring, and unauthorised mass biometric surveillance
- ·generating or distributing unlawful content, including undisclosed deep fakes
- ·infringing third-party rights, including intellectual property rights and personal data rights
The Deployer is solely responsible for all activities carried out through the Software on their local instance.
6. AI Output
The Software generates content automatically through third-party AI models.
The Deployer acknowledges that:
- ·Outputs may be inaccurate, incomplete or incorrect (so-called hallucinations)
- ·Outputs do not constitute professional advice of any kind
- ·the Provider does not guarantee reliability, accuracy or suitability of Outputs for any specific purpose
The Deployer is responsible for the use, verification and any dissemination of Outputs.
7. Intended Use and Professional Contexts
isolAIted is an AI model orchestration software, designed as a neutral tool for productivity support, document processing and workflow automation. The Software does not constitute or incorporate a GPAI model within the meaning of Reg. EU 2024/1689.
The Software is a tool for:
- ·document processing and knowledge base querying
- ·drafting assistance, research support and content synthesis
- ·building AI agents and automating internal workflows
- ·supporting the analysis and organisation of business information
The Software is not, and must not be used as:
- ·a legal, medical, financial or other regulated professional adviser
- ·a diagnostic or clinical assessment tool
- ·an automated decision-making system producing legal or significant effects on individuals without human oversight
- ·a substitute for qualified professional judgement
Every output generated by the Software must be reviewed and validated by a qualified human operator before any professional application. The Deployer assumes the role of active supervisor (Human-in-the-Loop) and retains full responsibility for all decisions made on the basis of Software outputs.
Where the Software is used in specialist professional contexts, the Deployer is responsible for:
- ·verifying whether their specific use constitutes a high-risk system under Annex III of Reg. EU 2024/1689 and fulfilling the resulting obligations
- ·complying with the regulatory obligations applicable to their sector
- ·ensuring their workflow implementation complies with the AI governance policies applicable to their industry
- ·informing their end users of the supportive — not professionally advisory — nature of the generated outputs
8. Automations and Data Transmission to External Services
The Software operates locally and does not transmit data externally by nature. The Provider has no technical access to the data processed by the Deployer within their own instance.
However, the Deployer may configure the Software to:
- ·create automations that interact with external services
- ·configure agents with access to third-party systems
- ·send data to external APIs or cloud services
In such cases:
- ·any data transmission is the sole responsibility of the Deployer, including verification of GDPR compliance for flows to recipients outside the EU
- ·the Provider has no control over or responsibility for such data flows
9. GDPR Compliance — Reg. EU 2016/679
The Provider has designed the Software in accordance with the principles of Privacy by Design and Privacy by Default set out in Art. 25 of Reg. EU 2016/679 (GDPR). The on-premise architecture ensures that personal data processed by the Deployer never leaves infrastructure owned or controlled by the Deployer. The architectural guarantees are organised by functional layer, consistently with the Software's technical compliance documentation.
GDPR roles:
- ·The Deployer is the Controller under Art. 4(7) GDPR: the sole entity that determines the purposes and means of processing personal data handled through the Software.
- ·The Provider is not a Controller, Joint Controller, or Processor under the GDPR: it has no technical access to the personal data processed by the Deployer and determines neither its purposes nor its essential means.
- ·No Data Processing Agreement (DPA) is therefore required between the Provider and the Deployer for use of the Software in its standard on-premise configuration.
Layer 1 — Data Ingestion & Sanitization
- ·PII Detection Layer: the Software includes a layer for detecting personally identifiable information (PII) in inputs and outputs, acting before text is indexed in local databases or forwarded to agent contexts. The strategy for handling detected PII is configurable by the Deployer, who retains full decision-making responsibility.
- ·Knowledge base warning: when creating a knowledge base, the Software displays an explicit notice inviting the Deployer to assess the nature of the data they are about to index, reducing the risk of inadvertent processing of personal or sensitive data.
Layer 2 — Access Control & Local Security
- ·Isolation by design: the Software operates entirely locally. All data — conversations, sessions, knowledge bases — is saved exclusively in the protected folders of the logged-in user profile, in accordance with the operating system's access policies. The Provider has no technical access to such data.
- ·Per-user isolated agent memory: personal information saved by agents at the user's explicit request is stored exclusively in the operating system area associated with their profile, structurally reducing the risk of data breaches.
- ·Account data minimisation: the Provider collects only the data strictly necessary for account management (email address, credentials in protected form), in accordance with Art. 5(1)(c) GDPR.
Layer 3 — Monitoring & Auditing
- ·Anonymised Audit Log: the Software automatically records system events and user and AI agent operations. The log captures usage metadata only (who, what, when) without retaining the content of prompts or responses, in line with the data minimisation principle and to avoid duplicating personal data in logs.
- ·Configurable retention: the Software provides the Deployer with tools to define retention periods for conversations, sessions, logs and audit trails. The Deployer is responsible for configuring retention consistently with their legal basis for processing.
Layer 4 — Explainability
- ·Source traceability: in chat and agent sessions, the Software displays the documentary sources used by the model to generate its response, enabling the user to verify the accuracy and provenance of the information. These references are not saved in session history.
- ·Reasoning visualisation (Thinking Chain): for models that support it, the Software makes the agent's reasoning chain visible in chat, eliminating the "black box" effect and enabling the user to understand the logic followed before acting on outputs. Reasoning is also not saved in session history.
- ·Transparency towards data subjects: the Software includes features enabling the Deployer to make the AI nature of interactions identifiable to their end users, in accordance with Art. 13-14 GDPR and Art. 50 AI Act. The Deployer is responsible for activating them in their configuration.
Layer 5 — Data Lifecycle & User Rights
- ·Right to data portability (Art. 20 GDPR): the Software allows the end user to export their data in a machine-readable format: personal details, conversations, uploaded documents and memories accumulated by the agent.
- ·Right to erasure (Art. 17 GDPR): the Software implements erasure in two phases: upon request, data is made immediately inaccessible; within a configurable technical processing period, content is physically deleted and personal identifiers replaced with anonymous values. The audit log is anonymised but never deleted (Art. 5(2) GDPR). For each request an ErasureReceipt is generated — an immutable record constituting proof of the completed erasure.
- ·Training lock: the Software does not provide tools for training or fine-tuning AI models. Models operate exclusively in inference mode: data processed cannot modify model parameters, ensuring purpose limitation of processing.
- ·Human in the Loop — HITL (Art. 22 GDPR): the Software includes a native mechanism requiring the user's explicit approval before an AI agent performs an action. HITL is configurable per agent and per tool, ensuring human oversight over automated decision-making.
Layer 6 — Documentation & User Interface
- ·Integrated Privacy Notice (Art. 12-13 GDPR): at first launch and in a dedicated section always accessible within the application, the Software presents a notice describing the local processing model, the data collected by the application, telemetry retention, and how to exercise rights.
- ·Trust Center: the Software includes direct access to a dedicated web page where the Provider's compliance documents are collected and available for download, including the Privacy Policy, Terms of Service and EULA.
- ·Consent collection (Art. 7(1) GDPR): the Software expressly requires end users to provide their consent to the processing of their personal data and includes a local system for recording acceptance (timestamp, identifier, version of the text accepted).
- ·Withdrawal of consent (Art. 7(3) GDPR): the end user may withdraw their consent at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal. Since consent is the legal basis for processing, its withdrawal results in suspension of access to the application.
Exclusive responsibilities of the Deployer:
- ·Establishing the legal basis for processing personal data handled through the Software (Art. 6 GDPR)
- ·Drafting and keeping up to date the privacy notice for their end users (Art. 13-14 GDPR), incorporating information on the AI nature of interactions
- ·Independently assessing whether their processing requires a data protection impact assessment (Art. 35 GDPR)
- ·Handling requests from data subjects to exercise their rights (access, rectification, erasure, portability, objection — Arts. 15–22 GDPR). The Provider is not the recipient of such requests and is not in a position to respond to them.
- ·Ensuring the security of the infrastructure on which the Software is installed (Art. 32 GDPR), including physical and logical security measures for the device hosting the local instance
- ·Consciously configuring retention periods and activating the compliance tools made available by the Provider, without leaving default values in place without an explicit, documented choice
- ·Verifying GDPR compliance of data flows to external services potentially configured through the Software's automation features (see §8)
The processing of the Deployer's personal data (account registration data) is governed separately in the Privacy Policy.
10. Compliance with Reg. EU 2024/1689 (AI Act)
isolAIted is an AI System within the meaning of Art. 3(1) of Reg. EU 2024/1689, in the specific form of software for the local orchestration of third-party AI models.
Risk classification:
- ·Does not fall within prohibited practices (Chapter II AI Act): the Software does not implement or enable subliminal manipulation, social scoring, unauthorised biometric recognition in public spaces or other practices prohibited by Art. 5 of Reg. EU 2024/1689.
- ·Is not a high-risk system (Chapter III AI Act): the Software, in its standard configuration, does not fall within the categories of Annex III of Reg. EU 2024/1689. Risk classification depends on the specific use the Deployer decides to make of it in their operational context.
- ·Is subject to transparency obligations (Chapter IV AI Act): as an AI system designed to interact with natural persons, the Software is subject to the obligations of Art. 50 of Reg. EU 2024/1689, the implementation of which is shared between the Provider and the Deployer as described in §10.1.
- ·Is not a GPAI system (Chapter V AI Act): the Provider does not develop or distribute GPAI models and is not subject to the obligations of Chapter V. Third-party GPAI models usable through the Software remain under the responsibility of their respective manufacturers.
Voluntary adherence to Chapter III standards (Art. 95 AI Act):
Although not required to do so, the Provider has voluntarily implemented features that satisfy the requirements the AI Act prescribes for high-risk systems, in keeping with the spirit of Art. 95 on voluntary codes of conduct. These features are available to the Deployer and allow isolAIted to be used — subject to the Deployer's own assessment — in contexts that require high standards of AI governance:
- ·Human oversight — Art. 14 AI Act (HITL): the Software includes native Human-in-the-Loop mechanisms enabling the Deployer to maintain control and oversight over AI system operations, including the ability to interrupt, correct or cancel agent actions.
- ·Transparency and information to the Deployer — Art. 13 AI Act: the Software provides detailed technical documentation on its operation, the capabilities and limitations of the system, the modes of interaction with AI models, and the integrated logging and observability mechanisms.
- ·Automatic event logging — Art. 12 AI Act (Audit Log): the Software automatically records relevant events, operations performed by AI agents, user interactions and system decisions, with identification of the natural persons who performed them, integrated observability tools and configurable retention.
- ·Technical documentation — Art. 11 AI Act: the Provider maintains and makes available detailed technical documentation on the System's architecture, integrated third-party components, security mechanisms and deployment procedures.
Important: the features described above are made available by the Provider but do not exempt the Deployer from the obligation to carry out their own risk assessment if they intend to use the Software in contexts that may constitute a high-risk system under Annex III of Reg. EU 2024/1689.
10.1 Transparency Obligations — Art. 50 AI Act
Art. 50 of Reg. EU 2024/1689 — applicable from 2 August 2026 — establishes transparency obligations allocated between the Provider and the Deployer.
Provider obligations — met:
- ·Art. 50(1) — AI system identifiability: the Software is designed so that natural persons interacting directly with it are made aware that they are interacting with an artificial intelligence system, unless this is obvious from the context.
- ·Art. 50(2) — Technical marking of AI-generated output: the Software ensures that outputs generated synthetically (text, images, audio, video) are marked in machine-readable format so as to be technically detectable as artificially generated. This marking capability is implemented and available in the current version of the Software.
Deployer obligations:
- ·Activate and keep operational the transparency features made available by the Provider in their Software configuration.
- ·Inform their end users that they are interacting with an AI system, clearly and no later than the first interaction (Art. 50(5) AI Act; Art. 13–14 GDPR).
- ·Explicitly disclose the artificially generated nature of deep fake content produced through the Software, where such content is publicly disseminated (Art. 50(4) AI Act).
- ·Disclose that texts generated by the Software on matters of public interest have been artificially generated or manipulated, where such texts are published for informational purposes (Art. 50(4) AI Act).
- ·Not remove, disable or circumvent the technical markings applied by the Provider to AI-generated outputs, nor distribute outputs from which such markings have been removed (Art. 50(2) AI Act).
Note — on-premise architecture and marking: the Provider implements technical marking in the outputs generated by the Software before they are delivered to the user interface. The responsibility for not removing the markings and for meeting disclosure obligations towards the public and end users rests exclusively with the Deployer.
11. Indemnification
The Deployer agrees to indemnify and hold harmless the Provider from any claims, damages, liabilities, costs or expenses (including legal fees) arising from:
- ·breach of these Terms
- ·unlawful use of the Software
- ·content generated, processed or distributed through the Software
- ·violation of third-party rights, including GDPR or AI Act obligations applicable to the Deployer
- ·failure to configure or disabling of compliance tools made available by the Provider
12. Limitation of Liability
The Software is provided "as is", without warranties of any kind.
To the maximum extent permitted by law:
- ·the Provider shall not be liable for any direct or indirect damages arising from use of the Software
- ·the Provider shall not be liable for loss of data, profits or opportunities
- ·the Provider shall not be liable for decisions made on the basis of Outputs
- ·the Provider shall not be liable for the Deployer's failure to fulfil their GDPR or AI Act obligations
The total liability of the Provider is limited to €0 (zero euros), as the Software is provided free of charge. If such limitation is not enforceable, liability shall be limited to the minimum amount permitted by law.
The Software is distributed in its standard configuration and the Deployer is solely responsible for installation, configuration and use on their own. Acceptance of these Terms does not imply or include any personalised technical support, remote installation, system configuration, Software customisation, training or consultancy by the Provider. The Provider may, at its sole discretion, make additional professional services available — including, by way of example, assisted installation, customisation and training — under separate contractual agreements between the parties, subject to specific commercial terms.
13. Availability and Updates
The Provider does not guarantee:
- ·continuity of the Software
- ·future updates
- ·compatibility with all operating systems or hardware configurations
Updates may modify the functionality, behaviour or system requirements of the Software.
14. Changes to the Terms
The Provider reserves the right to modify these Terms, including to reflect regulatory developments (AI Act, GDPR, applicable national law).
Continued use of the Software following publication of any changes constitutes acceptance of those changes.
15. Governing Law and Jurisdiction
These Terms are governed by Italian law, in compliance with applicable European Union law, including Reg. EU 2024/1689 and Reg. EU 2016/679.
For any dispute:
- ·the competent court shall be that of the Provider's place of residence or registered office
- ·without prejudice to any consumer rights provided by law
16. Term and Termination
These Terms apply for the entire duration of use of the Software.
The Provider reserves the right to revoke or restrict the licence in the event of:
- ·breach of these Terms
- ·improper or unlawful use of the Software
Upon termination:
- ·the Deployer must stop using the Software
- ·the Deployer must delete all copies in their possession
17. Feedback
Any suggestions or feedback provided by the Deployer may be freely used by the Provider to improve the Software.
The Deployer acknowledges that:
- ·such contributions are non-confidential
- ·no compensation is due
18. Acceptance
Use of the Software constitutes full acceptance of these Terms of Service, including the provisions relating to compliance with Reg. EU 2024/1689 (AI Act) and Reg. EU 2016/679 (GDPR).
For any questions about these Terms: info@isolaited.com