Legal
Terms of use
Preliminary version, under legal review. Details not yet defined appear as [pending] and will be completed before the final version.
1. Parties and service
Fiuit: [company name, CNPJ, address and contact pending]. Customer: the business identified at sign-up and responsible for the workspace.
The service organizes catalog, availability, bookings, customer service and messages through the contracted channels. Features, commercial prices and payment terms are those of the approved commercial agreement; these terms do not define them.
2. Access and instructions
The customer manages users and roles, checks invitations and protects its credentials. It must report unauthorized access through the support channel [pending]. The workspace is determined by the credential, not by arbitrary information sent in the request.
End customers should not share passwords, documents or clinical information in the booking conversation. The system does not replace emergency care, diagnosis or medical follow-up.
3. Bookings and messages
Availability, prices and confirmation are controlled by Fiuit’s booking engine, not by free decisions of the language model. The business configuration defines hours, resources, cancellation policies and enabled automations.
A message that has entered the sending queue is not guaranteed to be delivered: channel or provider failures and outages may prevent or delay delivery. The business must follow up on exceptions, respond when a conversation is handed over to a person and check the relevant data.
4. Acceptable use
The service may not be used for spam, unnecessary data collection, exploiting third-party access or violating channel policies. Technical permissions do not replace the authorization of the data subject or the controller for a specific purpose. Test or simulator contacts must not receive messages through the real connection.
5. Data and third parties
The approved data processing agreement (DPA) and privacy policy will form part of the contract. The controller gives lawful instructions and decides purposes and legal bases; Fiuit acts on those instructions for end-customer data. Fiuit’s own processing will be set out separately, without automatically extending the processor role to every activity.
Sub-processors, regions and transfers depend on the approved inventory and contracts. Audio processing by an external provider and the processing of health data remain [pending] and are not authorized by these terms. There is no general authorization to train models on customer data.
6. Security, support and continuity
There are technical controls for workspace isolation, auditing and role-based access; they are not a security certification nor a guarantee that no incident will occur. Service level (SLA), support, maintenance window, liability and indemnity: [pending commercial and legal approval].
Backups, recovery and retention will follow an approved policy and restore tests; internal restore tests do not certify recovery in production.
7. Termination and changes
Export, the period for the controller to recover data, access blocking and deletion at termination will be defined in the approved DPA. Data will not be kept indefinitely for lack of a policy, nor will legally required records be deleted without a documented decision. Material changes require a new version, notice and acceptance, according to the contractual rule [to be defined].
Governing law, venue and complaints channel: [pending]. Nothing in these terms excludes mandatory rights.