Veloci Terms of Service

The terms that govern use of Veloci, including our data processing commitments.

Last updated: 28 August 2026

1. Who these terms are between

These terms are an agreement between ArcticRex Oy ("ArcticRex", "we", "us") — a Finnish company, business ID 3587587-8, Lapinlahdenkatu 16, 00180 Helsinki, Finland — and you, the customer. Veloci is a professional tool: by accepting these terms you confirm you are using it in the course of a trade, business, or profession, whether on your own account or on behalf of an organization you are authorized to bind. Veloci is not offered to consumers.

You accept these terms by creating an account, or by using Veloci. If you accept on behalf of an organization, "you" means that organization.

2. The service

Veloci keeps you on top of what you've committed to: it connects to services you authorize, captures commitments, helps you prioritize them against your goals, and refits your calendar and focus to match, with AI agents doing the legwork. The Veloci privacy policy describes what data is involved and how it is handled; it forms part of these terms.

Veloci is an evolving product. Features may change, improve, or be withdrawn; we will not materially reduce the core capability you are paying for during a paid term without offering you a remedy under section 11.

3. Your account and connections

  • Keep your credentials confidential; you are responsible for activity under your account.
  • You connect third-party services (Google, Slack, and others) with your own accounts and only with authority to do so. Each connected service's own terms continue to apply to your use of that service.
  • You can disconnect any service at any time; Veloci deletes the stored tokens on disconnect.

4. Your content

You retain all rights to the content Veloci accesses or produces for you — your meetings, events, messages, tasks, and the action items, briefings, and plans generated from them ("Customer Content"). You grant us the license needed to host and process Customer Content solely to provide, secure and maintain the service, as described in the privacy policy.

You also grant us the license to use Customer Content to create derived materials. Any such material will be anonymised, so that no individual can be identified from it. It is therefore not personal data, and we may use it to improve the service.

We do not use Customer Content to train AI models.

Usage telemetry — which never contains Customer Content — may be used to operate and secure the service, and to measure how well it is working, as described in the privacy policy.

You are responsible for having the right to bring content into Veloci — including, where you connect sources that contain other people's data (meeting transcripts, shared channels), any notice or authorization your organization or applicable law requires. You will defend and indemnify us against third-party claims arising from Customer Content you bring into Veloci or from your breach of this section or section 5.

5. Acceptable use

You may not: use Veloci in violation of law or of the terms of the services you connect; attempt to breach, probe, or circumvent its security or tenant isolation; resell or provide the service to third parties; use it to develop a competing product; or introduce malicious code. We may suspend accounts that put the service or other customers at risk, with notice where practicable.

6. Data protection

For personal data in Customer Content — your own, and that of colleagues, meeting participants and contacts — you (or your organization) are the controller and ArcticRex is your processor. This section is the data processing agreement required by Article 28 GDPR, and it applies automatically; no separate signature is needed.

Processing details.

Subject matter and purpose
Providing the service described in section 2.
Duration
The term of these terms.
Nature of processing
Hosting, retrieval, AI-assisted extraction and organization of Customer Content, and the creation of anonymised derived materials from it.
Types of personal data
Identity and contact data, calendar event data, meeting transcript content and excerpts, and task and message content from connected services.
Categories of data subjects
You, your colleagues, meeting participants, and other people appearing in connected content.
Location and transfers
Processing takes place in European Union regions. We will not transfer this personal data outside the EEA without safeguards under Chapter V GDPR.
  • Instructions: we process such personal data only on your documented instructions, which include these terms — to provide the service as configured and used by you, and to create the derived materials described in section 4 — unless EU or member-state law requires otherwise (in which case we inform you unless the law forbids it).
  • Confidentiality: persons we authorize to process personal data are bound by confidentiality obligations.
  • Security: we implement the technical and organizational measures set out in the Annex to these terms, and keep them current; we may improve them but not materially weaken them.
  • Subprocessors: you authorize the subprocessors listed on our subprocessors page. We will update that list and notify account holders by email or in-product notice at least 14 days before adding or replacing a subprocessor — except where replacement is urgently required for security, in which case we notify promptly afterwards. If you object on reasonable data-protection grounds and we cannot accommodate you, you may terminate under section 11 with the pro-rata refund stated there. We remain responsible for our subprocessors' performance.
  • Assistance: we assist you, taking into account the nature of the processing, with data-subject requests and with your obligations under Articles 32–36 GDPR (security, breach notification, impact assessments) — at your reasonable cost where assistance goes beyond the service's built-in features.
  • Breach notification: we notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • Deletion and return: on termination, or on request, we delete or return the personal data we process for you, unless EU or member-state law requires storage.
  • Audit: we make available the information reasonably necessary to demonstrate compliance with this section, including summaries of third-party certifications of our infrastructure providers. Where that documentation is insufficient, we allow audits you are entitled to under Article 28(3)(h) — at most once per 12 months, on 30 days' notice, under confidentiality, and at your cost.

7. Fees

Fees, if any, are according to separately agreed pricing, exclusive of VAT and other applicable taxes.

8. Intellectual property

The service — including its software, designs, interfaces, and documentation — and all intellectual property rights in it are and remain the exclusive property of ArcticRex and its licensors. Subject to your compliance with these terms and payment of any applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the service for your internal business purposes during the term. No other rights are granted, by implication or otherwise, and you receive no rights to our trademarks or branding.

Customer Content remains yours under section 4. Usage telemetry is collected and used as described in the privacy policy.

If you provide suggestions or feedback about the service, you grant us a perpetual, irrevocable, worldwide, royalty-free license to use it without restriction or obligation to you. We will not publicly identify you as its source without your permission.

9. Warranties and disclaimers

We provide Veloci with reasonable skill and care, and we warrant that we process data as the privacy policy and section 6 describe. Otherwise the service is provided "as is" — and, where provided free of charge, "as available" — and we do not warrant that it will be uninterrupted or error-free, or the accuracy of AI-generated output. Veloci's action items, briefings, and plans are assistance, not advice; verify anything consequential before relying on them.

10. Liability

Neither party excludes liability that cannot be excluded by law (including liability for intentional misconduct or gross negligence). Subject to that:

  • Neither party is liable for indirect or consequential loss, loss of profits, or loss of data (other than a breach of section 6).
  • Each party's total aggregate liability under these terms is capped at the greater of (a) the fees you paid for the service in the 12 months before the event giving rise to liability and (b) 500 €.

11. Term, termination, and your data

  • These terms apply while you have an account. You can close your account at any time; either party may terminate for material breach uncured within 30 days of notice.
  • We may terminate or suspend accounts on free plans at any time without notice.
  • If you terminate because we materially reduced core capability during a paid term (section 2), or on a subprocessor objection (section 6), we refund pro-rata any prepaid fees for the remainder of the term.
  • On request within 30 days of termination, we provide an export of your Customer Content in a common machine-readable format.
  • On termination we delete your Customer Content and personal data per section 6 — promptly from live systems, with residual copies in encrypted backups expiring on our backup rotation schedule within 30 days. You can request deletion earlier at any time.

12. Changes to these terms

We may update these terms. For material changes we will give at least 30 days' notice by email or in the product; if you do not accept a material change, you may terminate before it takes effect. Continued use after the effective date is acceptance.

13. Confidentiality

Each party will keep confidential the non-public information it receives from the other in connection with the service, and use it only for the purposes of these terms. For us that includes your business information reached through Veloci. For you it includes unreleased features, roadmap and pricing seen while using it.

This obligation lasts for three years after these terms end. It does not cover the existence of the relationship between us, information that is or becomes public other than by breach of this section, information already known free of obligation, or information independently developed without reference to the other party’s.

14. General

These terms are governed by the laws of Finland, excluding conflict-of-law rules. Before court proceedings, the parties will attempt to resolve any dispute in good-faith discussion for 30 days; unresolved disputes are settled by the District Court of Helsinki. If a provision is unenforceable, the rest stands. Neither party is liable for failure caused by events beyond reasonable control. You may not assign these terms without our consent (not to be unreasonably withheld); we may assign them in a merger or asset sale.

Notices to us are validly given by email to contact@arcticrex.com; notices to you by email to your account address or in-product notice. Sections 4 (indemnity), 6 (deletion and confidentiality duties), 8, 10, 13, and 14 survive termination. These terms, the privacy policy, and any order form are the entire agreement. Where an order form expressly deviates from these terms, the order form prevails for that engagement.

Annex — Technical and organizational measures

The security measures referred to in section 6:

  • Encryption: all data encrypted in transit (TLS 1.2 or higher) and at rest; service access tokens additionally encrypted at the application layer before storage.
  • Isolation: each customer organization's data is held in its own database; tenant isolation is enforced in the platform's data-access layer.
  • Data residency: all processing and storage in European Union regions of AWS, enforced by organization-level infrastructure policy.
  • Access control: authenticated access for every user, with per-user authorization on every request; access to production infrastructure restricted to authorized personnel using role-based access with audited credentials.
  • AI processing: model inference restricted at the infrastructure level to approved models on AWS Bedrock; prompts and outputs are not retained by the inference service and are never disclosed to model providers.
  • Availability and backup: automated database backups with point-in-time recovery; deletion protection on production databases; infrastructure defined as code and rebuildable from version control; restoration tested periodically.
  • Monitoring and response: audit logging of security-relevant actions; error monitoring with customer content scrubbed; a defined process for handling vulnerabilities and security incidents, with breach notification per section 6.
  • Personnel: access to customer data limited to what a task requires, under confidentiality obligations; security review is part of the development process for changes touching credentials, tenant data, or third-party integrations.

Contact

ArcticRex Oy
Lapinlahdenkatu 16
00180 Helsinki, Finland
Email: contact@arcticrex.com (legal & terms) · privacy@arcticrex.com (data protection)