Terms of Service
General terms of service
This English version is a courtesy translation. The Italian original is the only legally binding text and prevails in case of any discrepancy.
These General Terms of Service (the “Terms”) govern access to and use of the intelligence platform available at https://intelligence.searchbridge.ai/ (the “Platform”) made available by Search Bridge s.r.l. SB, tax code and VAT no. 04313431209, registered office in Bologna, Via Del Giacinto 32, email privacy@searchbridge.ai, certified email (PEC) searchbridgesrl@pec.it, REA BO-584315 – share capital € 10,000 fully paid up – SDI recipient code K95IV18 (the “Provider”), to the party that registers or signs the order (the “Customer”). The Terms are intended exclusively for customers acting in the course of a business or professional activity; they do not apply to consumers.
1. Definitions
Services: the Platform services for analysing the visibility and reputation of brands in artificial intelligence systems (Intelligence Beam line) and the consulting and support services included in the chosen plan.
Authorised Users: the natural persons (employees, collaborators or consultants of the Customer) to whom the Customer grants access to the Platform.
Attachments: the files and documents that Authorised Users upload to the Platform through the document archive feature.
Customer Content: the Attachments and any other data or material entered into the Platform by the Customer or its Authorised Users.
Outputs: the analyses, reports, recommendations and outputs generated by the Platform, including by means of artificial intelligence systems.
Data Protection Law: Regulation (EU) 2016/679 (“GDPR”), Legislative Decree 196/2003 and the measures of the supervisory authority.
DPA: the agreement on the processing of personal data pursuant to Art. 28 GDPR, set out in Annex A, which forms an integral part of the Terms.
2. Scope, contractual documents and online conclusion of the contract
2.1 Scope. The Terms apply to Customers who subscribe to the Platform online. For Customers who have signed a contract or an offer with the Provider, they apply on a supplementary basis, insofar as compatible, with regard to the Attachments feature and other subsequent features; in the event of conflict, the signed contract prevails.
2.2 Contractual documents. The contract consists of the order form or the plan chosen at registration, these Terms and the DPA. In the event of conflict, the following order of precedence applies: the DPA (for the protection of personal data), the plan or offer, the Terms.
2.3 Registration and conclusion. The contract is concluded when the Customer completes the registration procedure, selects the plan, declares acceptance of the Terms and the DPA by ticking a dedicated box that is not pre-ticked, and confirms the order; the Provider sends confirmation by email to the address provided, with a copy of the Terms and the DPA in a downloadable and storable format. Before confirmation, the Customer may review and correct the data entered. The Provider keeps a record of the acceptance (date, time, version of the documents, user identifier). The contract is concluded in the Italian language.
2.4 Customer representations. The person registering represents and warrants: (a) that they act on behalf of a party operating in the course of a business or professional activity and not as a consumer; (b) that they have the authority to represent the Customer and to bind it; (c) that the data provided at registration are true and up to date.
3. Account and Authorised Users
3.1 The Customer designates the Authorised Users and manages their access permissions. Under the CORE plan, the Customer may enable up to 5 Authorised Users, with an administrator or read-only role, exclusively using email addresses on its own corporate domain. Credentials are personal and non-transferable; the Customer is responsible for keeping them safe and for all activity carried out with them, and shall inform the Provider without delay of any suspected unauthorised use.
3.2 The Customer informs its Authorised Users that the Provider processes their personal data (professional details, credentials, access logs) as controller, in accordance with the Privacy Policy published on the Provider's website, and makes the link to it available to them.
4. Services, fees and payments
4.1 The Services, usage limits and fees are those of the CORE plan, available for purchase online, or of the Select, Premiere and Signature plans set out in the offer. Fees are stated exclusive of VAT.
4.2 Payment is due in advance, on a monthly basis, using the payment methods made available on the Platform by the service of Stripe Payments Europe Limited (“Stripe”) (payment card, Google Pay, Apple Pay and PayPal), which operates under its own terms. The Provider does not store full payment card details. By registering and choosing the plan, the Customer authorises the automatic, recurring charging of the fees at the end of each period and of renewals pursuant to Art. 4.3. Except for the trial period under Art. 4.6, the service is activated after the first payment has been successfully completed. The Provider issues an electronic invoice to the billing details provided by the Customer, who guarantees their accuracy. Refusal or reversal of a charge is equivalent to non-payment under Art. 4.5. In the event of late payment, default interest under Legislative Decree 231/2002 is due.
4.3 The plan renews automatically for monthly periods unless cancelled, which may be done at any time through the Platform or by certified email (PEC), with effect from the end of the current monthly period. Fees for the current period are not refunded, except as provided in Art. 15 or by mandatory provisions of law.
4.4 The Provider ensures the availability of the Platform with a commitment of reasonable diligence, except for scheduled maintenance notified with reasonable advance notice and force majeure events. Faults that prevent the proper use of the Platform, reported through the support system, are taken in charge within 24 hours of the ticket being opened. The Provider communicates significant limitations, errors and interruptions of the service transparently.
4.5 In the event of non-payment, once the automatic charging attempts have been exhausted, the Provider may suspend the running of analyses and limit access to read-only, retaining the Customer Content for the period referred to in Art. 9.
4.6 Trial period. On first subscribing to the CORE plan, the Customer may benefit from a free 14-day trial period, once per corporate domain, subject to the limitations indicated on the Platform (a single login, data export disabled, limited number of Activations that can be generated). Unless cancelled from the Platform before expiry, on the fourteenth day the trial automatically converts into the paid plan and the Provider charges the first fee, after notifying the Customer.
5. Attachments feature
5.1 The Attachments feature is available to Customers who have subscribed to it in the offer and is not included in the CORE plan. The Platform allows Authorised Users to upload, organise, consult and retrieve Attachments, which are stored persistently in the Provider's storage for the duration of the contract, unless deleted by the Customer.
5.2 The Customer retains all rights in the Customer Content and grants the Provider a limited, non-exclusive licence, valid for the duration of the contract, for the sole purpose of providing the service (storage, indexing, backup, security, support), in accordance with the Customer's instructions.
5.3 The Customer warrants that it has all the rights, title and legal basis necessary to upload the Attachments and to have them processed by the Provider, that it has provided the required information notices to data subjects and that it has adopted the measures required by Data Protection Law as controller. The Customer is responsible for assessing the lawfulness of the upload and, where necessary, for carrying out a data protection impact assessment (Art. 35 GDPR).
5.4 Formats and maximum sizes permitted for upload: text documents and tabular files, up to a maximum of 3 files per request, each no larger than 20 MB and with an overall limit of 25 MB per request. The Provider may change these with 30 days' notice.
6. Permitted use and prohibited content
6.1 The Customer undertakes not to upload or process on the Platform:
– unlawful content or content infringing third-party rights (intellectual property, confidentiality, trade secrets) or to which it has no title;
– malware, malicious code or files intended to compromise the security of the Platform or of third parties;
– special categories of personal data under Art. 9 GDPR (data concerning health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, sex life) and data relating to criminal convictions and offences under Art. 10 GDPR, unless there is a specific written agreement with the Provider defining additional safeguards and measures;
– payment card data, third-party authentication credentials and identity documents not necessary for the purposes of the service;
– personal data of minors, unless strictly necessary and the Customer has fulfilled its legal obligations.
6.2 The Provider does not carry out any prior review of the content of the Attachments and assumes no responsibility for their substance. The Provider may suspend access to one or more Attachments, or to the account, in the event of a breach of this article, a request from an authority or a security risk, notifying the Customer as soon as possible.
7. Protection of personal data
7.1 Roles. With regard to personal data contained in the Attachments and in the Customer Content, the Customer is the controller and the Provider is the processor under Art. 28 GDPR, on the terms of the DPA. With regard to the data of Authorised Users, access logs and the data necessary to manage the contractual relationship, the Provider acts as an independent controller.
7.2 Use of content. The Provider does not use the Customer Content for its own purposes or to train artificial intelligence models. Each Customer's knowledge base is isolated: one Customer's data are never used to enrich, train or influence the analyses of other customers, not even in aggregated or anonymised form, unless expressly authorised by contract.
7.3 Third-party models. The content of the Attachments is sent to the third-party artificial intelligence models integrated into the Platform only when the Authorised User uses it in the conversational feature, on the Customer's instructions, through providers bound by data processing agreements under Art. 28 GDPR. Zero data retention and blocking the use of data for model training can be activated at the Customer's request.
8. Security
8.1 The Provider has adopted an Information Security Policy and an information security management system certified to UNI CEI EN ISO/IEC 27001:2024 (Dasa-Rägister S.p.A., certificate no. IIS-0726-03, valid from 20 July 2026), and applies the technical and organisational measures described in Appendix 2 of the DPA, including encryption of data at rest and in transit, access control, isolation of customer data, daily backup with 30-day retention, file versioning and access logging.
8.2 The Customer adopts appropriate measures for the security of its own systems and of the Authorised Users' credentials, and configures permissions consistently with the principle of least privilege.
9. Retention, deletion, return and switching provider
9.1 Attachments are retained for the duration of the contract. The Customer may delete them at any time; deletion entails removal from the active archive and the actual, not merely logical, erasure of the residual copies (previous versions and backups) at the latest at the end of the 30-day backup retention cycle.
9.2 Switching provider and data export. The Customer may withdraw from the contract and/or request switching to another data processing service provider or to its own systems with a maximum notice period of two months. The Provider makes the exportable data available (Customer Content and Outputs generated for the Customer, in a structured, commonly used and machine-readable format: Excel (XLSX) for data and Outputs, original format for Attachments) during a 30-day transition period from the end of the notice period, with reasonable assistance and ensuring continuity of service and a high level of security. Export is not available during the trial period. After the switch has been completed, the Customer has a data retrieval period of at least 30 days, after which the data are actually and irreversibly erased, subject to legal obligations. Any switching charges are limited to the direct costs actually incurred and, from 12 January 2027, are not payable. The categories of exportable data and any exceptions are set out in the Platform documentation.
9.3 The Provider does not engage in lock-in practices and communicates the conditions for exiting the service transparently.
10. Artificial intelligence features and Outputs
10.1 Outputs are generated, among other means, by artificial intelligence systems and are informative in nature and intended to support decisions; every recommendation is explainable and traceable, and no fully automated decisions without human oversight are envisaged. The Provider does not warrant that the Outputs are error-free or complete. The Customer remains responsible for the use of the Outputs and for the decisions taken on their basis.
10.2 Each party complies, within its own remit, with the obligations of Regulation (EU) 2024/1689 (AI Act) applicable to its role, including those on AI literacy (Art. 4). The Provider, as provider of the AI system (limited risk under Art. 50), discloses to Users that the Outputs are generated by AI systems and marks them in accordance with applicable law; the related measures are being implemented. The Customer does not use the Platform for prohibited practices or for purposes that qualify as high-risk under the same Regulation, unless otherwise agreed in writing.
11. Intellectual property
The Platform, the software, the models, the trademarks and the documentation remain the exclusive property of the Provider or its licensors. The Provider may also supply the service to brands and businesses that compete with the Customer; no exclusivity is granted. No right other than the right of use provided for in the Terms is transferred to the Customer. The Customer remains the owner of the Customer Content; unless otherwise agreed, the Outputs may be used by the Customer for its own internal purposes.
12. Confidentiality
Each party treats as confidential the non-public information of the other party learned in performing the contract, uses it only for such performance and discloses it only to those employees, collaborators and suppliers who need it and are bound by equivalent obligations. The obligation continues for 5 years after termination of the contract.
13. Liability and indemnity
13.1 The Customer is responsible for the lawfulness, accuracy and legitimacy of the Customer Content and for compliance with the Terms by the Authorised Users, and shall hold the Provider harmless from third-party claims, penalties and damages arising from a breach by the Customer of Arts. 5 and 6 or of Data Protection Law.
13.2 Except in cases of wilful misconduct or gross negligence, the Provider's aggregate liability to the Customer on any ground connected with the contract shall not exceed the amount of the fees paid by the Customer in the 12 months preceding the event. The Provider is not liable for indirect damages, loss of profit or loss of opportunity. For breaches of the personal data protection obligations set out in Annex A (DPA), this amount is raised to an amount equal to 18 months of fees paid by the Customer.
13.2-bis Neither party is liable for delays or failures to perform due to force majeure (natural disasters, wars, acts of authority, epidemics, unavailability of telecommunications or energy networks not attributable to the party), which must be promptly notified to the other party. If the cause lasts more than 90 days, either party may withdraw by written notice, without any obligation to pay compensation.
13.3 Nothing in the Terms excludes or limits liability that cannot be excluded or limited by law.
14. Term, withdrawal and termination
14.1 The contract lasts for the duration of the chosen plan and renews in accordance with Art. 4.3. The Customer may withdraw in accordance with Arts. 4.3 and 9.2.
14.2 Either party may terminate the contract for serious breach by the other party not remedied within 30 days of a written notice to remedy.
14.3 On termination, the provisions of Art. 9 apply; Articles 11, 12, 13, 17 and 18 survive.
15. Amendments
The Provider may amend the Terms for regulatory or security reasons or to reflect the evolution of the service, with at least 30 days' written notice, by communication via email and on the Platform. If the amendment is detrimental to the Customer, the Customer may withdraw within that period without penalty, with a pro rata refund of fees paid in advance. Amendments to the DPA affecting data processing are subject to Art. A.4 as regards sub-processors and otherwise to the agreement of the parties.
16. Code of Ethics and reporting
The Provider operates in accordance with its Code of Ethics, published on its website, which the Customer declares it has read. Conduct by the Customer contrary to the Code of Ethics or to Legislative Decree 231/2001 may constitute a breach. Reports of unlawful conduct or conduct contrary to the Code of Ethics may be sent to etica@searchbridge.ai. The internal reporting channel required by Legislative Decree 24/2023 is being implemented.
17. Notices
Contractual notices are given in writing (including by certified email (PEC) or email) to the contact details provided at registration and to those of the Provider set out at the beginning of these Terms. Notices relating to data protection are sent to privacy@searchbridge.ai.
18. Governing law and jurisdiction
The Terms are governed by Italian law and are drafted in Italian. The Court of Bologna has exclusive jurisdiction over any dispute.
Specific approval pursuant to Arts. 1341 and 1342 of the Italian Civil Code
The Customer declares that it has read and specifically approves, by means of a dedicated box separate from that for general acceptance, the following articles: 4.3 (automatic renewal and no refund for the current period), 4.5 and 6.2 (suspension), 4.6 (automatic conversion of the trial period), 13 (liability and indemnity), 15 (amendments), 18 (exclusive jurisdiction).
Annex A – Data processing agreement
pursuant to Art. 28 of Regulation (EU) 2016/679
Between the Customer, as data controller (the “Controller”), and Search Bridge s.r.l. SB, as data processor (the “Processor”). This DPA is accepted by the Customer by accepting the Terms at registration.
A.1 Subject matter, duration, nature and purpose
The Processor processes on behalf of the Controller the personal data contained in the Attachments and in the other Customer Content, for the sole purpose of providing the Services and the Platform's document archive feature (storage, indexing, organisation, consultation, retrieval, contextualisation of the analyses requested by the Controller, backup, security and technical support). The processing lasts as long as the contract, subject to Art. A.9.
A.2 Categories of data and data subjects
The content of the Attachments is determined by the Controller and may concern any category of data subjects and of ordinary data (e.g. employees, customers, suppliers, contacts). Special categories of data (Art. 9 GDPR) and judicial data (Art. 10 GDPR) are excluded, unless there is a specific written agreement under Art. 6.1 of the Terms. The Controller is responsible for verifying that the uploaded content complies with this limit.
A.3 Obligations of the Processor
The Processor undertakes to:
– process the data only on documented instructions from the Controller, which are deemed to be given by the Terms, the chosen plan and the use of the Platform by the Authorised Users; inform the Controller if it considers that an instruction infringes Data Protection Law;
– ensure that persons authorised to process the data are bound by confidentiality and have received appropriate instructions and training;
– adopt the security measures set out in Appendix 2 (Art. 32 GDPR);
– comply with the conditions on sub-processors set out in Art. A.4;
– assist the Controller, by appropriate technical and organisational measures, in responding to data subject requests (Arts. 15-22) and in fulfilling the obligations under Arts. 32-36 (security, breaches, impact assessment, prior consultation), forwarding to the Controller without delay any requests received directly and responding to the Controller's requests for assistance within 5 working days;
– delete or return the data at the end of the service, in accordance with Art. 9 of the Terms and Art. A.9;
– make available to the Controller the information necessary to demonstrate compliance with Art. 28 and allow audits in accordance with Art. A.8;
– keep a record of the processing activities carried out as processor (Art. 30(2) GDPR).
A.4 Sub-processors
4.1 The Controller grants general authorisation to engage sub-processors. The Processor imposes on them, by written contract, obligations equivalent to those of this DPA and remains liable to the Controller for their performance.
4.2 The Processor informs the Controller of any addition or replacement with at least 30 days' notice, by email and by updating the list of sub-processors, available on request at privacy@searchbridge.ai. The Controller may object on reasonable data protection grounds within 15 days; in the event of an unresolved objection, the parties shall seek a solution in good faith and, failing that, the Controller may withdraw from the contract without penalty.
4.3 Sub-processors authorised at the date of this DPA:
Sub-processor
Service
Data location
Non-EU safeguards
Laif S.r.l. (ISO/IEC 27001 certified)
System administration, software development and management of the Platform's databases (access to data for technical purposes)
Italy / EU
Not applicable
Amazon Web Services EMEA SARL (sub-processor of Laif S.r.l.)
File hosting and storage (Amazon S3), backup
EU (eu-west-1 region, Ireland)
Not applicable for storage in the EU; DPA signed through Laif
OpenRouter (USA), with sub-providers OpenAI, Google (Gemini) and Perplexity
Access to language models for the Platform's analyses and for the GENius conversational feature, which may receive the content of Attachments used by the User in chat
Requests (prompts) may transit through the USA. Routing takes place, depending on the model, on the infrastructure of different providers (e.g. Microsoft Azure, AWS, Google), in the EU or the USA. Zero data retention and EU-only routing can be activated at the Controller's request
Standard contractual clauses (Module 3, processor-to-processor, for content processed on behalf of the Controller; Module 2 for data of which the Provider is controller) or DPF where the provider is certified, with a transfer assessment; zero data retention is a supplementary measure
Providers that do not access the Attachments (for example administrative management systems, consultants, website analytics tools) are not sub-processors under this DPA.
A.5 Transfers to third countries
The Processor stores the Attachments within the European Union. It does not transfer personal data to third countries except on the Controller's instructions or where required by law, and in any case only with the safeguards of Arts. 44-49 GDPR (adequacy decision, such as the EU-U.S. Data Privacy Framework, standard contractual clauses or another appropriate safeguard). Access to data from third countries for support purposes is not envisaged.
A.6 Personal data breaches
The Processor informs the Controller without undue delay and, where possible, within 24 hours of becoming aware of a personal data breach affecting it, providing the information available (nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed) to enable the Controller to fulfil Arts. 33 and 34 GDPR. The Processor documents breaches and cooperates in investigations. The notifications required by the legislation applicable to the Controller on the security of network and information systems (Legislative Decree 138/2024, transposing the NIS2 Directive) remain unaffected, where the Controller is an obliged entity.
A.7 Confidentiality of personnel
Access to the Attachments by the technical staff of the Processor and of Laif S.r.l. is limited to maintenance, security and support purposes, to the staff who need it, and is logged.
A.8 Audits and inspections
The Controller may verify compliance with the DPA once a year, with at least 15 working days' notice, by requesting the available information, documentation and certifications (e.g. evidence from the information security management system) and, if these are not sufficient, by an on-site or remote audit during working hours, without prejudice to confidentiality towards other customers and at the Controller's expense, unless a material breach is found.
A.9 Deletion and return
At the end of the contract, the Processor, at the Controller's choice, returns the Attachments in a commonly used format and/or deletes them, in accordance with Art. 9 of the Terms (retrieval period of at least 30 days; actual erasure of residual copies, with backups and versions deleted within the 30-day retention cycle), subject to legal retention obligations. The Processor certifies in writing that the return or deletion has taken place within 30 days of its completion.
A.10 Liability
Each party is liable in accordance with Art. 82 GDPR. The limitations of liability in Art. 13 of the Terms remain unaffected to the extent permitted by law.
Appendix 1 – Description of the processing
Element
Description
Nature of the processing
Persistent storage, indexing, organisation, consultation, use to contextualise the requested analyses, backup and deletion of files uploaded by the Controller.
Purpose
Provision of the Services and of the Platform's document archive feature.
Categories of data subjects
Determined by the Controller; cannot be predetermined (free content).
Categories of data
Ordinary data, determined by the Controller; Art. 9 and Art. 10 GDPR data excluded unless agreed in writing.
Duration
Duration of the contract, plus the retrieval and deletion period (Art. A.9).
Instructions
The Terms, the chosen plan and the operations carried out by Authorised Users through the Platform.
Appendix 2 – Technical and organisational measures
Area
Measure
Governance
Information Security Policy and management system certified to UNI CEI EN ISO/IEC 27001:2024, with a management system manager, risk analysis and periodic management review; privacy by design and by default.
Encryption
Encryption of data at rest (Amazon S3 and databases, with AWS KMS, AES-256) and in transit (TLS 1.2 and 1.3).
Access control
Access to files limited to the Controller's Authorised Users according to the permissions set; access by staff of the Processor and of sub-processors limited to maintenance and support, under the principle of least privilege, with letters of appointment and designation of the system administrator; administrative access to the infrastructure via AWS SSO with mandatory multi-factor authentication.
Isolation
Isolation of each customer's data by means of a dedicated virtual network (VPC), separate security groups and access roles, and role-based access control in the application.
Backup and continuity
Daily backup with 30-day retention, replicated across multiple availability zones in the EU region; storage-level versioning of previous file versions with 30-day expiry; disaster recovery based on multi-zone redundancy.
Deletion
Actual, not merely logical, deletion; propagation to previous versions and backups within the 30-day cycle; deletion operations logged in the infrastructure records.
Traceability
Logging of access and operations on the infrastructure (CloudWatch and CloudTrail), with application logs retained for at least 90 days and no longer than 12 months.
Organisation
Confidentiality obligations and staff training, incident management, supplier assessment, antivirus and firewall, media handling and change management procedures.



