Hellomatik Terms of Service
Last updated:
17 March 2026
These Terms of Service govern your access to and use of Hellomatik's AI automation platform. Please read them carefully.
Controller/Contracting Entity: HELLOMATIK, S.L. (CIF B22803126)
Contact: administracion@hellomatik.com
Effective date: 1 October 2025. Last updated: 17 March 2026.
These Terms of Service (the "Terms") govern access to and use of hellomatik.com, app.hellomatik.com, our APIs, voice and chat modules, automations, integrations and related software, websites and services (collectively, the "Service"). If you are entering into these Terms on behalf of an organisation, you represent that you have authority to bind that organisation. By using the Service, you accept these Terms. If you do not agree, do not use the Service.
1. Definitions
For the purposes of these Terms of Service:
"Customer", "you" or "your" means the person or entity using the Service.
"Authorised Users" means individuals you allow to access the Service under your account.
"Customer Content" means data, text, files, audio, transcripts, prompts, outputs, metadata and other material submitted to or processed by the Service under your account.
"Outputs" means content created by the Service in response to Customer inputs or settings.
"Integrations" means third‑party products or services connected to the Service (e.g. CRMs, telephony, storage, messaging, analytics).
"Sub‑processors" means third parties Hellomatik uses to process personal data to provide the Service.
"Security Incident" means unauthorised access to or disclosure of Customer Content in Hellomatik's systems that results from a failure of Hellomatik's reasonable security measures.
2. The Service and business use only
The Service is an enterprise platform that lets you deploy conversational voice and chat, automations and workflows connected to your tools. The Service is for business use only. You are responsible for how you set up and use the Service. You are also responsible for what Integrations you connect and any actions taken by your Authorised Users, agents or workflows.
3. Accounts and customer responsibilities (shared responsibility model)
3.1 Account security
You are solely responsible for: (a) keeping credentials, API keys and tokens confidential; (b) enabling and enforcing security controls such as SSO, MFA, least‑privilege roles, IP allowlisting and key rotation; (c) removing access promptly for departing users and vendors; and (d) monitoring activity in your environment. You must notify Hellomatik promptly of any suspected breach.
3.2 Customer systems and data
You control your data sources and Integrations. You are solely responsible for the legality and accuracy of Customer Content and for how you configure the Service to process it. You are also responsible for giving all notices and obtaining all consents required by law. This includes obligations around call recording and notice for voice features, and telemarketing limits where those apply.
3.3 Misconfiguration and third‑party breaches
Hellomatik is not responsible for unauthorised access, loss or changes caused by: (i) stolen or misused credentials (including phishing or social engineering of your users), (ii) your misconfiguration of the Service or Integrations, (iii) third‑party breaches or outages in your systems, networks or Integrations, or (iv) actions taken according to your instructions or automations you set up.
3.4 Customer backups
Unless we agree otherwise in writing, you are responsible for backing up data held in non‑Hellomatik systems and any copies you export from the Service.
4. Licence and acceptable use
4.1 Licence
Subject to these Terms and timely payment of fees, Hellomatik grants you a non‑exclusive, non‑transferable, non‑sublicensable, revocable licence to access and use the Service for your internal business purposes.
4.2 What you cannot do
You shall not:
(a) copy, modify, translate, adapt or create derivative works of the Service, its components, models or documentation
(b) reverse engineer, decompile, disassemble, extract model weights or attempt in any way to discover the source code, algorithms, underlying models, architecture or logic of the Service (except where applicable law does not permit that restriction)
(c) access the Service to build, train or improve a competing product, service or model, directly or indirectly
(d) scrape, harvest, data mine or extract content, data or Outputs from the Service by automated means without written authorisation
(e) interfere with, disrupt, overload or compromise the security, integrity or performance of the Service or its protective systems
(f) circumvent, disable or manipulate usage limits, rate limits, access controls, technical restrictions or security measures of the Service
(g) remove, alter or obscure intellectual property notices, trademarks, attributions or rights legends
(h) sublicense, resell, rent, lend or distribute access to the Service to third parties without written authorisation
(i) use the Service for high‑risk activities where failure could cause death, personal injury or serious environmental or property damage (e.g. autonomous medical diagnosis, life support, air traffic control, nuclear operations, weapons control); or (j) use Outputs to train, fine‑tune or distil artificial intelligence models owned by you or third parties without Hellomatik's written authorisation.
4.3 Prohibited uses
You are expressly prohibited from using the Service to:
(a) violate applicable laws, regulations or third‑party rights in any jurisdiction
(b) store, process or transmit malicious code, malware, ransomware or tools designed to compromise systems
(c) upload, generate or distribute illegal, defamatory, fraudulent or obscene content, or content that incites hatred, violence or discrimination
(d) send unsolicited communications, spam, automated mass messages or illegal telemarketing through the Service's channels
(e) impersonate persons or entities, or present AI‑generated Outputs as human‑created without adequate disclosure
(f) compromise the privacy or identity rights of third parties, including unauthorised collection of personal data
(g) facilitate fraud, phishing, scams, pyramid schemes, predatory lending or exploitation of vulnerable persons
(h) create, store or distribute child sexual abuse material or facilitate exploitation of minors in any form
(i) generate content promoting suicide, self‑harm, eating disorders or harassment
(j) spread deliberate misinformation, fake news or propaganda designed to deceive
(k) undermine democratic processes, generate deceptive political content targeted at voters or create artificial movements with misrepresented origin
(l) make automated decisions in criminal justice, social scoring, mass surveillance or facial recognition without legal basis
(m) compromise critical infrastructure (power grids, water systems, telecommunications, emergency services)
(n) develop, design or facilitate the creation of weapons, explosives or dangerous substances
(o) generate, store or distribute sexually explicit content through the Service; or (p) coordinate malicious activity across multiple accounts, circumvent bans through new accounts or abuse the platform in any manner.
4.4 Outputs, human review and AI limitations
The Service uses artificial intelligence models that may generate content that is inaccurate, incomplete or biased, or that infringes third‑party rights. Outputs must not be used for medical, legal, financial or safety‑critical decisions without expert human review. You are solely responsible for reviewing, validating and obtaining any necessary legal clearances before using any Output. Hellomatik is not liable for third‑party claims arising from Customer's use of unreviewed or unedited Outputs. To the extent that applicable law (including the EU AI Act) imposes transparency or risk classification obligations for AI systems, Hellomatik will help you comply. But you decide whether the Service is suitable for your own use.
4.5 High‑risk uses and additional requirements
If you use the Service in contexts where Outputs or automations may significantly affect natural persons (including, without limitation: legal interpretation, healthcare diagnosis or care, financial or credit decisions, employment or housing decisions, automated journalistic communications or educational assessments), you must comply with the following requirements:
(a) Human oversight: a qualified professional must review all content or decisions generated by the Service before they take effect on individuals
(b) Disclosure: at the beginning of each interaction, end users must be informed that AI helps generate the content or recommendations
(c) Risk assessment: Customer is responsible for assessing whether their specific use requires additional measures under applicable law (including the EU AI Act). Customer is solely responsible for any failure to meet these requirements in high‑risk contexts.
5. Customer Content, privacy and data processing
5.1 Ownership
You keep all rights in Customer Content.
5.2 Our use of Customer Content
You grant Hellomatik a limited, worldwide, non‑exclusive licence to process Customer Content only to provide and maintain the Service. Hellomatik can also process it to prevent or fix technical or security issues, comply with law and as otherwise allowed in these Terms or your DPA. For the purposes of these Terms, "Customer Content" includes all derived data generated from the technical processing of your data (including the numerical representations used to index and search your data, and operational metadata). Derived data is Customer Content. It receives the same protections and is deleted under the same retention periods.
5.3 No default training
Hellomatik does not use Customer Content to train AI models by default. Any training use would require clear, specific permission that you can withdraw.
5.4 Privacy and DPA
Our Privacy Policy explains how we handle data as a controller. Where Hellomatik processes personal data on your behalf, the parties will sign a Data Processing Agreement (DPA). The DPA forms part of these Terms. If there is a conflict, the DPA controls for processing on your behalf.
5.5 Sub‑processors and transfers
Hellomatik may use sub‑processors under written agreements that impose data protection obligations. Hellomatik will notify Customer at least 15 days before engaging a new sub‑processor. Customer may object in writing within that period; in that case, Hellomatik will seek reasonable alternatives or Customer may terminate the affected Service without penalty. Cross‑border transfers will rely on a valid legal mechanism (e.g. EU Standard Contractual Clauses, adequacy decisions such as the EU‑US Data Privacy Framework or other valid mechanisms).
5.6 End‑user data
The Service may process personal data of your end users (e.g. customers, patients, leads or other individuals who interact with the Service through your channels). You are the data controller of that data and must ensure a valid legal basis for its processing (e.g. consent, legitimate interest or contractual necessity). When an end user exercises data protection rights (access, rectification, erasure, portability), you are responsible for handling those requests. Hellomatik will provide reasonable technical assistance as set out in the DPA.
5.7 DPA and sub‑processor list
Hellomatik makes available to Customers a Data Processing Agreement (DPA) that supplements these Terms and sets out Hellomatik's obligations as data processor under the GDPR and applicable law. The DPA is available upon request at administracion@hellomatik.com or in the legal section of the website. Hellomatik maintains a current sub‑processor list, available in the legal section of the website or upon request. Changes to the list will be notified in accordance with Section 5.5.
6. Security and incidents
6.1 Our security
Hellomatik uses reasonable technical and organisational measures to protect the Service. Examples include encryption in transit, access controls, environment isolation, monitoring and backups.
6.2 Security Incidents
If Hellomatik confirms a Security Incident affecting Customer Content on Hellomatik's systems, Hellomatik will notify you without undue delay, and in any case within 72 hours of confirmation. Notification will include the nature of the incident, affected data, estimated scope and remediation measures taken.
6.3 What is not a Security Incident
A Security Incident does not include unauthorised access, loss or disclosure that results from: (a) your systems or networks, or a third party's; (b) stolen credentials or devices of you or your users; (c) your misconfiguration; or (d) actions performed according to your instructions or automations.
6.4 Working together
Each party will cooperate reasonably in investigating and remediating any incident within its control, including providing logs, responding to enquiries within 48 hours and granting reasonable access to affected systems.
6.5 Audit rights
Upon reasonable request, Hellomatik will provide evidence of its security measures (e.g. third‑party audit reports, certifications or completed security questionnaires). Hellomatik will permit third‑party audits subject to written agreement on scope, schedule and confidentiality, limited to one audit per calendar year.
6.6 Automated decisions
The Service may execute automated actions (including workflows, responses and operations on connected systems) based on Customer's configurations and instructions. Customer is responsible for ensuring that those automations do not amount to decisions taken solely by automated means, without adequate human intervention, where those decisions have significant legal effects on individuals, in accordance with Article 22 of the GDPR and applicable law. Where use of the Service involves automated decisions that produce significant effects, Customer will implement the mechanisms for human review, data subject information and right of contestation required by applicable regulations.
7. Third‑party services and Integrations
The Service may interoperate with or rely on third‑party services (telephony, messaging, cloud, analytics, authentication, etc.). Hellomatik selects and monitors its providers with reasonable diligence and maintains data protection agreements with sub‑processors. However, Hellomatik is not liable for third‑party service failures beyond its control. Where Customer enables an Integration on its own, that Integration accesses or stores data at Customer's discretion and risk.
8. Voice, calling and recordings
You are responsible for the lawful use of inbound and outbound calls, including: (a) obtaining and honouring required consents and notices for recording and transcription; (b) complying with applicable telemarketing and do‑not‑call rules; and (c) honouring opt‑out requests. Call recording laws vary by jurisdiction (for example, Spain requires the consent of both parties, and other EU countries have different requirements). Customer is responsible for understanding and complying with the specific laws in each jurisdiction where Customer uses the Voice module. Hellomatik provides configuration options and disclosures but does not provide legal advice or guarantee Customer's compliance.
9. Beta, preview, free and trial access
Features identified as beta, preview, trial or free are provided "as is" without support or service level agreement, and may change or be discontinued with 30 days' notice where possible. They may be subject to additional terms or limitations. Hellomatik will not retroactively classify a stable feature as beta to avoid support obligations. If discontinuation of a material beta feature materially affects Customer, Customer may terminate the affected Service without penalty.
10. Fees, taxes and changes
Fees are as stated in your Order Form, admin console or applicable plan and are non‑refundable unless required by law. Usage‑based charges (e.g. minutes, events, storage, messages) are billed on actual consumption. You authorise Hellomatik or its payment processor to charge all applicable fees and taxes. Hellomatik will calculate and remit VAT according to Customer's place of establishment and applicable law. For B2B customers within the EU, the reverse‑charge mechanism applies where applicable; Customer is responsible for providing a valid VAT identification number. Hellomatik may update plan pricing or features with at least 30 days' prior notice, which will be consistent with your billing cycle; continued use after the change takes effect constitutes acceptance.
11. Suspension and termination
Hellomatik may suspend or terminate access if:
(a) you breach these Terms or fail to pay
(b) your use risks the security, integrity or availability of the Service; or (c) required by law. Hellomatik will provide written notice describing the violation before any suspension, unless the law requires immediate suspension (e.g. laws on child safety or terrorism) or the use poses imminent risk to Service security. Customer will have 10 business days to cure the violation before suspension becomes final. You may terminate at any time in accordance with your plan. Upon termination, your licence ends and Hellomatik will delete or anonymise Customer Content from active systems within 60 days, in line with the retention periods stated in your account or DPA.
12. Confidentiality
Each party will protect the other's Confidential Information with at least reasonable care. Each party will use it only to perform under these Terms. Confidential Information does not include information that is publicly available without breach, lawfully received from a third party, independently developed or required to be disclosed by law (with prompt notice where lawful).
13. Warranties and disclaimers
13.1 Authority of the parties
Each party confirms it has power to enter into these Terms.
13.2 Service disclaimer
The Service, Outputs, beta features and any documentation are provided "as is" and "as available". Hellomatik disclaims all warranties, express or implied. This includes warranties of satisfactory quality, fitness for a particular purpose and non‑infringement, and any warranties arising from a course of dealing or usage of trade. Hellomatik does not promise that the Service will be error‑free or uninterrupted, or that Outputs will be accurate or suitable for any particular use.
13.3 Your responsibility
Your use of the Service, Outputs and actions executed by automations under your account are at your sole risk and responsibility. You are solely responsible for:
(a) compliance with all applicable laws and regulations regarding your data, communications, Outputs and automations
(b) human review of Outputs before any use, dissemination or decision‑making
(c) all damages, losses or harm caused by your configurations, instructions, credentials, devices, Integrations or by the actions of your Authorised Users or automated agents
(d) obtaining all necessary consents, notices and legal authorisations from your end users
(e) ensuring your use of the Service does not violate third‑party rights or constitute a prohibited use under Section 4.3; and (f) implementing adequate human oversight where the use context requires it. Hellomatik provides tools and configurations but does not monitor, review or approve Customer's use of the Service or the Outputs it generates.
14. Indemnities
14.1 By Customer
You will defend, indemnify and hold harmless Hellomatik and its affiliates, officers, directors, employees and agents from all third‑party claims, damages, liabilities, costs and expenses (including reasonable legal fees) arising from or related to:
(a) your Customer Content, including Outputs generated under your account
(b) your use of the Service in violation of these Terms, Section 4.3 (Prohibited uses) or any applicable law
(c) disputes with your end users, customers or third parties arising from interactions, communications or actions performed by the Service under your account
(d) your Integrations, configurations, workflows and automations, including all actions executed by AI agents under your credentials and instructions
(e) failure to comply with human oversight, disclosure or risk assessment requirements set out in Sections 4.4 and 4.5
(f) any claims arising from automated decisions made without the human intervention required by applicable law; or (g) any violation of data protection, privacy, telecommunications or call recording laws in connection with your use of the Service. This indemnification obligation survives termination of these Terms.
14.2 By Hellomatik (intellectual property)
Hellomatik will defend you against third‑party claims alleging that the Service directly infringes a valid intellectual property right. This applies when you use the Service as allowed and do not combine it with non‑Hellomatik products (except Integrations we supply). Hellomatik will pay damages finally awarded or any settlement it approves in writing. Hellomatik may, at its choice: (i) obtain the right for you to continue using it, (ii) modify or replace the Service to avoid infringement, or (iii) end the affected features and refund prepaid fees for the unused term. Hellomatik has no duty for claims based on Customer Content, your settings, Integrations or use that violates these Terms.
15. Limitation of liability
15.1 Certain damages not covered
To the maximum extent allowed by law, neither party will be liable for indirect, incidental, special, consequential, exemplary or punitive damages. Neither party will be liable for loss of profits, revenues, goodwill, data or business interruption. This applies even if that party was advised of the possibility.
15.2 Total cap
Except for your payment duties and each party's indemnity duties, each party's total liability will not exceed the amounts you paid or owe to Hellomatik for the Service during the 12 months immediately preceding the event causing liability.
15.3 Legal limits preserved
Nothing in these Terms excludes or limits liability where such exclusion or limitation is not allowed by law. Examples include death or personal injury caused by negligence, fraud or wilful misconduct.
15.4 Risk allocation
The fees reflect the allocation of risk in these Terms.
15.5 Customer misuse and unauthorised access
For clarity, Hellomatik is not liable for any unauthorised access, disclosure, loss or damage that results from: (i) stolen credentials (including phishing or social engineering of your users); (ii) your misconfiguration of the Service or Integrations; (iii) problems or outages in third‑party systems or networks you select or control; or (iv) actions performed by automations, agents or users under your account and according to your instructions or settings.
16. Publicity
Unless you opt out by written notice or through your account settings, you grant Hellomatik permission to identify you as a customer and use your name in customer lists, websites and presentations, provided that: (a) logo usage requires prior written approval and (b) you do not falsely imply endorsement or sponsorship. You may revoke this permission at any time.
17. Export controls, sanctions and anti‑bribery
You confirm that you and your users are not subject to sanctions. You will follow export, sanctions and anti‑corruption laws. You will not use the Service in embargoed territories or for prohibited purposes.
18. Changes to the Service and to these Terms
Hellomatik may change features, add limits or stop parts of the Service with reasonable notice where possible. Hellomatik may update these Terms from time to time by posting the revised version and updating the "Last updated" date. Material changes will take effect 30 days after posting (or as stated in the notice). Your continued use after the change takes effect means you accept it.
19. Order of priority, entire agreement and assignment
If there is a conflict between these Terms and an Order Form, SOW or DPA, the order of precedence will be: (1) DPA (for processing on your behalf), (2) Privacy Policy (for Hellomatik‑controlled data), (3) Order Form/SOW, then (4) these Terms. The Privacy Policy and Cookie Policy are binding as part of these Terms.
These Terms constitute the entire agreement on the subject matter and supersede prior agreements. You may not assign these Terms without Hellomatik's written consent; Hellomatik may assign to an affiliate or in connection with a merger, reorganisation or sale of assets, with prior notice to Customer. In the event of acquisition or merger, if the new owner has a material conflict of interest with Customer's industry, Customer may terminate without penalty within 60 days of written notice.
20. Governing law and venue
These Terms are governed by the laws of Spain, without regard to conflict‑of‑laws rules. The parties submit to the exclusive jurisdiction of the courts of Madrid, Spain, and waive any objection to venue or forum non conveniens. Either party may seek injunctive or equitable relief in any court of competent jurisdiction.
21. Notices
Notices to Hellomatik must be sent to administracion@hellomatik.com. Notices are deemed given upon receipt.
22. Force majeure
Neither party will be liable for failure to perform its obligations (except payment obligations) when such failure is due to causes beyond its reasonable control, including natural disasters, pandemics, war, acts of terrorism, government actions, failures of telecommunications or internet providers and large‑scale cyberattacks. The affected party will notify the other without delay and make reasonable efforts to mitigate the impact. If the force majeure event persists for more than 60 days, either party may terminate the affected Service.
23. Data export and portability
Upon request, Hellomatik will export Customer Content in a structured, commonly used format (e.g. JSON, CSV) within 15 business days. Customer may export data at any time via the admin console or API. The first export per calendar month is free; additional exports may incur reasonable fees communicated in advance.
24. Service levels
Production features (non‑beta) have a monthly availability target of 99.5%. If availability falls below this target during a calendar month, Customer may request a credit proportional to the downtime. This commitment does not apply to: (a) beta or preview features, (b) scheduled maintenance previously communicated, (c) force majeure events, or (d) interruptions caused by Customer's Integrations or configurations. Hellomatik will give 90 days' notice before discontinuing or materially changing any API. Customer may terminate without penalty if a material API change is unacceptable.
25. Severability and waiver
If any provision is found unenforceable, the rest will stay in effect. Failure to enforce a provision is not a waiver.
By using the Service, you confirm that you have read these Terms and that you agree to them. You are responsible for the acts and omissions of your Authorised Users, agents and Integrations connected to your account.