Terms of Service
Carl for Social Business
Introductory provisions
1. This document constitutes the full text of the terms and conditions (Terms) of Czech Video Center a.s., Czech company with ID No.: 09839194 (Provider or we) for the purpose of the Carl for Social Business application (Platform) provided by the Provider. These Terms constitute an integral part of the contract (Contract) concluded between the Provider and the Client within the meaning of Section 1751 of Act No. 89/2012 Coll., the Civil Code (Civil Code). The Provider operates the Platform and provides related services on the Platform (Services) solely to business customers (b2b), primarily brands and agencies (each such customer as Client). Clients may use the Platform and the Services in accordance with these Terms.
2. These Terms apply to all Clients using the Platform and Services, regardless of the method of acquisition. Specifically, these Terms apply to Clients that acquire access to the Platform and Services through the Provider's sales team (e.g., via a negotiated individual Order) and Clients that register and purchase the Services directly via the Provider's website or through the Platform's automated interface.
3. The objective of the Platform is to provide Clients with a tool to help monitor statistics and analyze content on social networks, and a platform to connect with the users of the Carl for Social App (CFS) through the Collab Centre.
Communication rules
1. Contact details of the Provider:
- Email address: hello@carldatacompany.com, or the address specified by the Provider
- Address for delivery: 1611/1 U garáží Street, Holešovice (Prague 7), 170 00 Prague
- Phone number: +420 724 443 632
2. The primary method of communication between the Provider and the Client is via email (exclusively via the above email address). If the Client communicates with the Provider via postal services (and exclusively via the above-mentioned delivery address), the Client bears the costs of such communication. If the Client provides its email address, the Provider reserves the right to reply via email in such a case.
Order and conclusion of the Contract
1. The Contract between the Provider and the Client is concluded through one of the following methods:
- Individual Order (Direct Sales). The Client orders the Services using a specific order form provided by the Provider's sales team upon request (Order). The Provider may contact the Client to negotiate detailed terms. In this case, the Contract is concluded upon the Provider's confirmation of the accepted Order form containing the agreed scope of Services.
- Platform Registration (Self-Service). The Client may enter into the Contract by registering an Account directly on the Provider's website or on the Platform. In this case, the Contract is concluded once the Client selects a specific Subscription Plan (Subscription Plan) and the Client pays the Fee as defined below.
2. By submitting an Order or completing the registration on the Platform, the Client confirms that it has read the current version of these Terms and agrees to be bound by them.
3. The specific scope and parameters of the Services are defined either in the confirmed Order or by the features of the Subscription Plan selected by the Client within the Platform.
Client's Cooperation and Delivery of Materials
1. The Client undertakes to provide the Provider with all necessary materials and information required for the proper commencement and provision of the Services as requested by the Provider or the Platform without undue delay.
2. If the Client fails to deliver the required materials on time or in the required quality, the Provider shall not be liable for any delay in the provision of the Services, and such delay shall not be considered a breach of the Contract by the Provider.
3. If, due to the Client's delay in delivering the materials, the Provider is unable to commence or continue providing the Services, the Provider is nevertheless entitled to payment of the Fee.
4. The Client is obliged to provide the Provider with all reasonably requested cooperation so that the Provider can properly provide the Services.
Operation of the Platform
1. The Platform provides analysis of the Clients' data from the connected Platforms. It aggregates the data in one place and provides basic statistics. Recommendations may be available on how to better work with the content on the Platforms. Other functionality of the Platform will always be described within the Platform or on the website of the Provider.
2. By using the Platform (and connecting their user accounts from such Platforms), the Client acknowledges that the Provider will have access to the Client's content and data available at the particular Platform. The Client also agrees that the Provider may download such content and data (in particular videos) and analyze it using artificial intelligence, machine processing and similar tools that may be provided by third parties. Such analysis may include uploading the content in question to such third party tools. The Provider will only use such content for the purposes of providing the Services.
3. Collab Centre:
- The Platform enables Clients and creators on Platforms to connect for the purpose of collaboration. Clients can post campaigns, and creators can apply to participate in them.
- The Provider is solely the operator of the technological interface.
- The Provider is not a party to any agreements or contracts entered into between a Client and a creator, even if such agreements are concluded directly within the Platform.
- The Client and the creator bear sole responsibility for fulfilling their mutual obligations, the quality of outputs, and compliance with legal regulations (e.g., proper advertising labeling).
- The Provider expressly disclaims liability for any damages arising in connection with these collaborations.
Fee for the Services and payment
1. For the Services, the Client is obliged to pay the Provider the price specified in the Order or as indicated within the Platform interface for the selected Subscription Plan (Fee).
2. Payment Methods:
- Payment via Invoice (Direct Sales). Unless otherwise stated in the Order, the Client shall pay the Fee based on an invoice issued by the Provider with a due date of 15 days from the date of issuance. The Client agrees to receive invoices exclusively in electronic form via email.
- Automated Payments (Self-Service). For Subscription Plans purchased directly via the Platform, payments of the Fee are processed through third-party payment providers or in-platform payment systems. The Client agrees that the Provider (or the payment provider) may automatically charge the Fee for the next period through the selected payment method.
3. Subscription Plan Renewal. Access to paid Subscription Plans works on a subscription basis for a predefined period (e.g., monthly or annually). The Subscription Plan automatically renews at the end of each period unless cancelled by the Client before the renewal date.
4. The Provider reserves the right to change the Fee of the Subscription Plan at any time. Any adjustment to the Fees shall take effect starting from the billing period immediately following the month in which the change was announced but not sooner than 30 days after the notification of such change. The Provider undertakes to notify the Client of such modifications via email or through a notification within the Platform. The current Fee of the Subscription Plan will be at all times accessible and visible on the Platform.
5. The Client agrees to receive invoices by email.
6. All payments are generally non-refundable, except where explicitly required by mandatory law or stated in the Provider's Refund Policy.
7. Unless explicitly stated otherwise, all amounts and prices are stated exclusive of VAT, which shall be added at the statutory rate where applicable.
Client's User Account
1. The Provider shall transmit the outputs of the Services to the Client through the User Account via the Platform's dashboard.
2. For the purpose of using the Platform, the Provider shall set up a user account for the Client, which is used in particular to view the outputs of the Services provided (User Account).
3. The User Account is accessible to the Client using the Client's email address and password.
4. The Client is obliged to update the data provided in the User Account in case of any change so that it always corresponds to reality. The Client is not entitled to allow any third parties to use the User Account and if this happens, the Client is liable for such use of the User Account as if the Client was acting alone.
5. Access to the User Account is secured by a username and password. The Client is obliged to maintain confidentiality regarding the information necessary to access its User Account and acknowledges that the Provider is not liable for any breach of this obligation by the Client.
6. The Provider may prevent the Client from using or cancel its User Account, especially when the Client violates its obligations towards the Provider.
Client's declarations and obligations
1. By registering into the Platform and by using the Platform, the Client represents and warrants that:
- the person acting on behalf of the Client is fully authorized to do so and is fully legally competent to use the Platform;
- they will not use the Platform in violation of the law or the terms of the connected Platforms;
- all information provided by them is true, complete and correct; and
- they have read the current version of these Terms and agree with them.
2. To ensure a safe environment, the Client strictly agrees NOT to use the Platform to:
- distribute or upload content that is illegal, hateful, discriminatory, or infringes on intellectual property rights;
- perform unauthorized data scraping or automated mining of creator data beyond the explicitly provided functions of the Platform; and
- attempt to circumvent the Platform's security, reverse engineer the source code, or use the Platform to build a competing product.
3. In the event of a violation of these rules by the Client or any of its personnel or persons acting on its behalf, the Provider may immediately terminate the User Account without a right to compensation.
Termination of the Contract
1. Cancellation of Subscription Plans (Self-Service). The Client may cancel the automatic renewal of a Subscription Plan at any time through the Account settings in the Platform or through device settings. The cancellation must be performed before the next renewal date. In such cases, the Subscription Plan will remain active until the end of the current paid period.
2. Termination for Breach. The Provider reserves the right to immediately terminate the Contract and cancel the Account (without any right to compensation or refund) if the Client materially violates its obligations, including non-payment or violation of Acceptable Use rules.
3. Termination of indefinite Contracts. In case of a repeated performance (updated analysis) ordered for an indefinite period, the Client may terminate the Contract always with effect at the end of the period following the period in which the notice was delivered. Period means the interval during which the analysis is updated.
Limitation of liability
1. The Provider is not liable for any business decisions made by the Client based on or in connection with the output from the Services. All risks associated with the implementation of the Service outputs remain solely with the Client.
2. To the fullest extent permitted by applicable law, the Provider shall not be liable for any indirect, incidental, or consequential damages, including but not limited to loss of profits, loss of revenues, loss of data, loss of goodwill, or other intangible losses.
3. The Provider's liability to the Client for any damage shall be limited to the amount corresponding to the total remuneration for the Services paid by the Client to the Provider in the last 12 months prior to the occurrence of such damage.
4. The Provider expressly disclaims any warranties, express or implied, regarding the continuous availability, uninterrupted functionality, or error-free operation of the Platform.
5. The Provider is not responsible for any damage or malfunction caused by third-party software, tools, or changes in the API/terms of the connected social media Platforms (e.g., Instagram, TikTok) which are beyond the Provider's control.
Intellectual property
1. The Platform, including its software, design, algorithms, and all content provided by the Provider, is the intellectual property of the Provider or its licensors.
2. The Client shall not modify, distribute or duplicate the content of the Platform or exercise any proprietary rights to the content of the Platform without the Provider's consent.
3. In particular, the Client is not entitled to:
- resell any content created within the Platform, license, rent or use it for any purpose other than publication on a Platform;
- attempt to circumvent the Platform's user interface and use it in a manner different from that implied by the user interface;
- attempt to modify, reverse engineer, decompile, disassemble or otherwise obtain the source code or algorithms of the Platform.
4. Unless otherwise agreed in writing, the Provider may use the Client's name and logo as a reference for marketing purposes. Similarly, the Client is entitled to state that it uses the Provider's Services in its promotional materials.
Confidentiality
1. Both the Provider and the Client agree to treat as confidential all non-public information, including but not limited to business, technical, financial, and strategic data, disclosed by the other party (Confidential Information).
2. Neither party shall disclose Confidential Information to any third party or use it for any purpose other than fulfilling their obligations under this Contract.
3. The confidentiality obligation shall not apply to information that (i) is publicly known without a breach of this Contract, (ii) was already known to the receiving party at the time of disclosure, or (iii) is required to be disclosed by law or a competent administrative authority.
Personal data protection
1. The relationship regarding the processing of personal data (where the Provider acts as a processor and the Client as a Controller) is governed by the Provider's DPA, which forms an annex to these Terms and is concluded by virtue of the conclusion of the Contract under these Terms.
Link to third party websites
1. The Provider may provide links to third party websites in the Platform. The Provider is not responsible for the functionality or content of these websites. If the Client accesses third-party websites, they do so at their own risk.
Final provisions
1. These Terms may be amended by the Provider at any time. The Client will be informed of such change, in particular via the Platform. The current Terms are also available online at https://carlforsocial.com/terms-of-service.
2. All legal relationships arising under or in connection with these Terms and any other use of the Platform shall be governed by the laws of the Czech Republic, regardless of where the Platform is accessed from. The Provider does not guarantee the compliance of these Terms with the laws of other countries. Any dispute arising out of or in connection with these Terms shall be submitted to the competent court for the district of Prague 1.
3. The Provider is entitled to use subcontractors when providing services. These will mostly be other companies from the Czech Video Center a.s. group. In such cases, however, the Provider is responsible for the Services provided in the same way as if it were providing them itself.
4. If any provision of the Terms is or becomes invalid or ineffective, such invalid provision shall be replaced by a provision whose meaning is as close as possible to the economic purpose of the invalid or ineffective provision. The invalidity or ineffectiveness of any provision shall not affect the validity and effectiveness of the other provisions. The invalidity or ineffectiveness of a provision only concerning a particular entity or group of entities shall not affect the validity and effectiveness of those provisions with other entities.
Annex – Data Processing Agreement
1. ANNEX TO CARL FOR SOCIAL BUSINESS TERMS – DATA PROCESSING AGREEMENT
2. Controller. Means the Client who entered into the Contract under the Terms of Use of the Carl for Social Business.
3. Processor. Czech Video Center a.s., with its registered office at U garáží 1611/1, Holešovice, 170 00 Prague 7, Czech Republic, Czech ID No.: 09839194, registered with the Municipal Court in Prague under B 26003.
4. Processing. The Processor provides services to the Controller in accordance with the framework agreement on the provision of services (Cooperation). The subject and nature of processing is the processing of personal data that takes place within the framework of the Cooperation. Categories of data subjects: influencers and other persons cooperating with the Controller in the field of marketing. Purpose of processing: fulfillment of the Processor's obligations towards the Controller within the Cooperation. Type of personal data: basic identification, contact, and descriptive data.
5. Approved sub-processors:
- Natural persons who, as contractors, provide services necessary to ensure Cooperation for the Processor
- Google Ireland Limited (Google Cloud Platform, Gemini)
- OpenAI
- PostHog, Inc. (PostHog)
- Intercom R&D Unlimited Company (Intercom)
- Functional Software, Inc. (Sentry)
6. The Processor is generally entitled to contractually oblige other persons (subcontractors) to fulfill its obligations to the extent necessary for the fulfillment of obligations arising from the Cooperation. The Processor shall ensure that these other processors have essentially the same obligations as the Processor itself, taking into account the nature of the processing on the part of the subcontractors and the personal data that will be made available to them.
7. Processing outside the EEA. Some of the tools used by the Processor may transfer personal data outside the European Economic Area (EEA). In such cases, the protection of personal data is ensured by Standard Contractual Clauses approved by the European Commission, which provide an adequate level of protection for the transfer of personal data to third countries.
8. Minimum technical and organizational measures. The Processor maintains and applies principles, standards, and processes for the protection of personal data, to which authorized persons have access. The measures listed below represent the minimum level of security. If the contract requires a higher level of security, the Processor will be bound by these conditions.
9. Security policy and standards. The Processor shall ensure security measures for employees and subcontractors with access to personal data. It shall conduct regular risk assessments and review and update its security procedures at least once a year (or in the event of a significant change).
10. Physical security. The Processor shall maintain adequate physical protection of the premises where systems containing personal data are located and restrict access to unauthorized persons.
11. Security within the organization. The Processor ensures the secure disposal or reuse of media containing personal data, the classification of sensitive information, incident management, and secure encryption of data during transmission, storage, and on portable devices. Personal data is processed separately according to its purpose.
12. Network security. The Processor ensures network security using commercially available equipment and standard techniques, including firewalls, intrusion detection and prevention systems.
13. Access control. Only a minimum number of authorized persons have access to the data, in accordance with the "minimum privilege" principle. Each authorized person has a unique access ID, and access rights are stored securely.
14. Virus and malware protection. The Processor's systems are protected by up-to-date antivirus and antimalware software and are monitored regularly.
15. Employees and other persons with access. Before accessing personal data, employees and other persons with access are trained by the Processor in security, are bound by confidentiality obligations, and have clearly defined roles and responsibilities.
16. Introduction. The Controller and the Processor are in a Cooperation relationship, whereby the Processor provides the Controller with the services specified in the documents or communication regarding the Cooperation. As part of the performance, the Processor works with personal data, the controller or processor of which for another controller is the Controller, and the Processor processes personal data for the Controller as its processor or sub-processor within the Cooperation. According to EU Regulation 2016/679 (GDPR), the Controller and the Processor must enter into this agreement.
17. For the purposes of this agreement, only personal data that the Processor processes for the Controller as a processor within the meaning of the GDPR is considered personal data. This does not affect the possibility for the Processor to also process the same personal data, in whole or in part, as a controller. This agreement does not apply to such processing.
18. Compliance with the GDPR. During the Cooperation, the Controller and the Processor are obliged to process personal data in accordance with legal regulations, in particular in accordance with the GDPR.
19. Controller's instructions. The Controller is obliged to determine the purpose of the processing of personal data (as specified above). The Controller is entitled to give the Processor instructions regarding the type, scope, and means of processing personal data. If the Processor believes that certain instructions or parts thereof are not in compliance with the GDPR, it shall inform the Controller thereof. The Controller undertakes to provide the Processor only with true and complete personal data of data subjects.
20. Notifications and cooperation – events and deadlines. The Processor shall notify the Controller immediately, but no later than within 48 hours, if it discovers or has reasonable grounds to believe that any of the following has occurred:
- non-compliance with the provisions of this agreement or the provisions of the GDPR or other data protection legislation, or
- a personal data breach.
21. Scope of notification. In the notification, the Processor shall provide the Controller with the following information:
- the date and time of the incident,
- description of the incident,
- the names of individuals whose personal data may be affected by the incident and the categories of personal data affected by the incident.
22. Cooperation. The Processor shall provide the Controller with full cooperation in investigating such cases, take appropriate corrective measures, and, at its own expense, in cooperation with the Controller, deliver all legally required notifications to the persons concerned and/or administrative authorities and make the necessary information available.
23. Requests and investigations. The Processor shall notify the Controller immediately, but no later than within 3 days, of any:
- complaints or requests from data subjects (e.g., for correction, deletion, and blocking of data) in relation to personal data, and
- notifications, orders, or requests from the relevant supervisory authorities or courts in relation to personal data.
24. In such cases, the Processor shall request instructions from the Controller.
25. Notification and cooperation of the Controller. To the extent that non-compliance with the contract or regulations, a security breach, complaint or request, or investigation could affect the rights and obligations of the Processor, the above rules in this section "Notification and Cooperation" shall apply mutatis mutandis to the Controller in relation to the Processor, except that the Controller shall not request instructions from the Processor, but the parties shall instead negotiate in good faith on the appropriate course of action.
26. Obligations of the Processor under Article 28 of the GDPR
27. (1) Processing only on the instructions of the Controller. The Processor shall process personal data only on the instructions of the Controller. Such instructions may include an order for services within the Cooperation or mutual communication within the Cooperation.
28. (2) Confidentiality. The Processor shall maintain confidentiality regarding personal data and shall ensure that persons authorized to process personal data under this agreement are bound by confidentiality or are subject to a statutory obligation of confidentiality.
29. (3) Security. The Processor shall take into account the state of the art, the costs of implementation, the nature, scope, context, and purpose of the processing, and the likelihood and severity of the risk to the rights and freedoms of natural persons, and shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures proposed in the introduction and the following measures:
- Access passwords to the system where personal data will be stored and processed, and access authorizations controlled at the individual level.
- Regular updating of IT systems and their backup.
- Locking of premises where personal data is physically stored (if applicable).
30. (4) Other processors. The Controller agrees that the Processor may engage the additional processors listed above. Each additional processor must be subject to at least the same obligations as the Processor under this agreement. If an additional processor fails to fulfill its data protection obligations, the Processor shall remain fully responsible to the Controller for the fulfillment of the obligations of the additional processor concerned.
31. (5) Cooperation in fulfilling information and other obligations towards data subjects. The Processor shall take into account the nature of the processing and shall assist the Controller, where possible, by appropriate technical and organizational measures, in fulfilling the Controller's obligation to respond to requests for the exercise of the rights of data subjects set out in Chapter III of the GDPR, in particular the right to information and other rights of data subjects.
32. (6) Cooperation in fulfilling security obligations and other measures. The Processor shall take into account the nature of the processing and the information available to it and shall assist the Controller in ensuring compliance with the obligations under Articles 32 to 36 of the GDPR, in particular the obligations to ensure security, report and notify security breaches, assess the impact on personal data protection, and consult with the Office for Personal Data Protection.
33. (7) Erasure. Upon termination of the Cooperation, the Processor shall, on the basis of the Controller's instructions, either erase the personal data or return it to the Controller and erase any copies, unless it has a legal obligation to retain such data.
34. (8) Audit. The Processor shall provide the Controller with all information necessary to demonstrate that the obligations set out in this agreement and the GDPR have been fulfilled, and shall allow and assist in audits carried out by the Controller or a person authorized by the Controller.
35. Final provisions – Duration. This agreement is concluded for the duration of the Cooperation and further for the period until the rights relating to the personal data provided or to the Cooperation expire.
36. Governing law. This agreement is governed by Czech law.
37. This Agreement is entered into by and between the Controller (Client) and the Processor (Provider) by virtue of the conclusion of the Contract under the Terms of Use of the Carl for Social Business platform.