Wendory
AI Annex – AI features and AI agents

Version 1.0 · As of 20 September 2026 · Annex to the Terms & Conditions

Draft – legal review required

Draft for legal review. The AI Annex governs the AI features already in use and forms the basis for the future sale of AI agents. Before selling agents this annex (in particular §§ 4, 5, 13, 14) must be reviewed by a lawyer and adapted to the applicable risk class.

§ 1 Subject matter and relationship to the Terms

This AI Annex supplements the Terms & Conditions (the "Terms") and governs the use of features whose output is generated wholly or partly by machine learning or language models (the "AI features").

In case of conflict, the provisions of this Annex prevail over the general provisions of the Terms for AI features. Otherwise the Terms apply unchanged.

This AI Annex applies to AI features provided today and to AI agents offered in the future unless separately agreed.

§ 2 Definitions

"AI feature": any feature of the Platform that transmits input (prompts, texts, files, profile data) to a language model and generates output from it.

"AI agent": an AI system able to perform several steps autonomously towards a defined goal (e.g. research, drafting, suggesting a meeting, proposing a reply) without each step being triggered individually.

"Model": the third-party model used (e.g. provider A/B/C) including its respective version.

"Output": the result generated by the model (text, suggestion, rating, summary, code).

"Deployer": the User using AI features; "Provider": Wendory as the supplier of the feature.

§ 3 Scope of AI features

Provided in particular: an assistant for preparing and drafting tenders, text improvements, suggested replies in chat, conversation summaries, rating and suitability assessments (match scores) and meeting suggestions.

AI features are supporting tools. They do not replace the User's own professional, legal, tax or commercial assessment.

The Provider may change, extend, restrict or discontinue individual AI features; § 12 of the Terms applies accordingly. The model provider used may change; the Privacy Policy lists the current processors.

§ 4 Roles and obligations under the EU AI Act (Regulation (EU) 2024/1689)

The parties assume that the AI features provided are not high-risk AI systems within the meaning of the AI Act and are not intended for high-risk purposes.

Wendory acts as a provider of the AI features within the meaning of the AI Act and fulfils the associated obligations, in particular transparency towards users, technical documentation and – where required – marking of AI output.

The User acts as a deployer and ensures that it uses the AI features as intended, reviews the output before use and fulfils its own information and due diligence obligations towards third parties.

If the User intends to use the AI features in a high-risk context (e.g. recruitment, credit decisions, medical purposes, critical infrastructure, justice or biometric surveillance), this must be agreed in writing with the Provider in advance and is prohibited without such consent.

§ 5 Prohibited uses

The use of AI features is prohibited for: behavioural manipulation or exploitation of vulnerabilities; social scoring; untargeted scraping of biometric data; emotion recognition in the workplace or in education; biometric categorisation; predictive policing; selection of individuals in high-risk areas without human review; and for unlawful, discriminatory or misleading purposes.

The User ensures that its input does not contain special categories of personal data (Art. 9 GDPR) unless this is expressly necessary and lawful.

In the event of breaches the Provider may suspend access to AI features immediately.

§ 6 No legally binding statements, human oversight

AI features do not make legally binding statements and do not act as representatives or messengers of the User (sections 164 et seq. BGB). Declarations with legal effect (e.g. conclusion of a contract, termination, submission of an offer) require confirmation by a natural person with the appropriate authority.

AI features do not bring about a decision based solely on automated processing with legal effect or similarly significant effects within the meaning of Art. 22 GDPR. Users must not adopt output without review.

Where AI features prepare decisions (e.g. match scores), these are non-binding suggestions.

§ 7 Output, accuracy and duty to verify

Output from AI features may be incorrect, incomplete, outdated or misleading (so-called hallucinations). The Provider does not owe any specific accuracy, completeness or fitness for a particular purpose unless expressly agreed in writing.

The User must verify output before any use – in particular before passing it on to contracting parties, applicants or end customers – for accuracy, completeness, third-party rights and suitability.

Publishing AI output in tenders, profiles or messages is at the User's own responsibility.

§ 8 Rights to input and output

Input (prompts, texts, attachments) remains the property of the User. The User grants the Provider the rights necessary to provide the AI feature to process, transmit to the model provider and temporarily store it.

To the extent legally possible, the Provider grants the User a simple, non-exclusive right to use the output for its own business purposes. No warranty is given that output is free from third-party rights; there is no indemnity claim for intellectual property infringements caused by AI output.

The User must not use AI features to infringe third-party rights or to exploit protected works unlawfully.

§ 9 Data processing, training and sub-processors

The Provider stores input and output to provide the service, for error analysis and for logging (see Privacy Policy). Content is not used to train own or third-party models without the User's express written instruction.

Where the model provider contractually assures that transmitted data is not used for model training, the Provider passes this assurance on. No guarantee is given for the conduct of third parties.

Processing by model providers outside the EU/EEA takes place only on the basis of appropriate safeguards (standard contractual clauses, adequacy decision, Data Privacy Framework). The current list of processors and third-country transfers forms part of the Privacy Policy.

§ 10 Labelling and transparency

Output from AI features is labelled in the Platform as AI-generated where required by law or necessary to avoid misleading users (cf. Art. 50 AI Act).

Users must not present AI-generated content to third parties as exclusively human-made where this is not verifiable for the recipient (e.g. chat replies to end customers, rating texts).

If AI agents in future communicate directly with the User's end customers, the involvement of AI will be disclosed to them.

§ 11 Usage limits, logging and security

The Provider may set usage limits (e.g. number of requests per period, tokens, file sizes) to ensure stability, cost transparency and abuse protection.

Input and output may be logged for troubleshooting and abuse protection. Logs are used only for these purposes and deleted after the periods stated in the Privacy Policy.

The User must not circumvent security mechanisms, submit input designed to circumvent model policies (prompt injection) or carry out automated bulk requests.

§ 12 Liability for AI services

The liability provisions of the Terms (§ 15) apply to AI features with the following qualifications: the Provider is not liable for decisions the User makes based on AI output, nor for damage resulting from unreviewed use.

Liability for AI services is limited – except for intent, gross negligence, injury to life, body or health and mandatory statutory grounds – to the fees paid for the AI feature in the last twelve months.

The Provider does not maintain insurance for the User's AI-specific risks; the User is responsible for adequate insurance cover.

The Provider may temporarily disable AI features in the event of security risks, abuse or loss of legal permissibility.

§ 13 Product liability and cybersecurity

The Provider monitors developments in product liability for software and AI (implementation of the new EU Product Liability Directive) and the Cyber Resilience Act and will adapt this Annex when those rules take effect.

Until then the Provider supplies the AI features with customary industry security measures (transport encryption, access control, logging, update maintenance). Security vulnerabilities must be reported without delay to the address stated in the legal notice.

The User uses only the current version provided and makes no modifications that circumvent security functions.

§ 14 Future AI agents (special provisions)

When AI agents are sold or provided, the following is additionally agreed: purpose and limits of the agent, permitted tools and data access, approval processes (human in the loop) for declarations with legal effect, budgets and limits, logging and information duties, and service and support levels.

AI agents act exclusively in the name and for the account of the User, who is responsible for all declarations made and actions triggered via the agent as for its own actions.

Use of agents for the purposes prohibited under § 5 is excluded; the Provider may deactivate agents immediately in the event of abuse or security risks.

Any assurance beyond § 12 (e.g. outcome, revenue or suitability guarantee) requires a separate written agreement. Agents with their own authority to conclude contracts require the Provider's express written approval.

§ 15 Changes to and term of this Annex

§ 18 of the Terms applies to changes to this Annex. The Annex ends when the user agreement between the parties ends.

On registration and when concluding paid services, express reference is made to the applicable version. The current version is available at /agb/ki with a version note.

This text is a carefully structured draft and not legal advice. Before commercial operation a qualified lawyer must review it and complete the items marked with [ ].