Bloodhound terms
1. Provider, scope and contract
Bloodhound is provided by Qunevo GmbH, Oestervenn 16, 33758 Schloß Holte-Stukenbrock, Germany, registered with the Local Court of Bielefeld, HRB 46010, represented by Dr. Felix Johannes Grumbach and Stefan Görlitz. Contact: info@qunevo.com, +49 5207 957 3619.
The service is offered exclusively to businesses within section 14 of the German Civil Code (BGB), legal entities under public law and special funds under public law. Consumer contracts for private use are not offered. Anyone acting for an organization must have authority to enter into and administer the contract.
These Bloodhound terms apply independently; the general Qunevo terms are not incorporated in addition. Individual agreements prevail. The DPA is included as an annex on this page. The agreed DPA takes precedence on data protection matters; its parties and deployment annexes must be completed before such processing. The German version is the contractual version; this English version is provided for information.
A free usage contract is formed through expressly confirmed registration and provision of the account. Purchasing credit is a separate transaction governed by the specific offer, disclosed total price including applicable taxes, credit currency and our order confirmation or provision of credit. Registration alone does not create a purchase. Custom integrations, hosting arrangements and service levels require a separate agreement.
2. Service
Bloodhound provides browser-based workspaces with invitations, text conversations, document context, audio/video communication and optional AI assistance. Depending on enabled features it transcribes speech, structures information, answers questions and produces drafts, diagrams and documents. The agreed feature description at contract formation defines the service.
Personal AI help answers application questions using the provided documentation. Its history is separate from meeting knowledge. Authorized users can connect selected room data to their own systems through revocable, time-limited API read tokens. Their current permissions continue to apply; customers are responsible for the purpose, disclosure, retention and deletion of their own exported copies.
A supported current browser and suitable internet connection are required. We owe the agreed functionality, but do not guarantee a particular business outcome, invariably accurate AI output or a specific availability percentage without a separate agreement. Necessary maintenance takes account of customers' legitimate interests and is announced where possible. Statutory defect remedies and our responsibility for persons engaged to perform our obligations remain unaffected.
3. Credit and usage charges
Purchased credit is redeemable exclusively for Bloodhound services supplied by Qunevo. It is not a means of payment to third parties or an interest-bearing deposit, and is not offered for trading or transfer to unrelated organizations. Free promotional or starter credit is distinguished from paid top-ups; separately agreed promotion conditions apply only to that free credit.
There is no base fee, no automatic top-up and no minimum spend. Every top-up requires an express order. Usage is charged to organization credit at the rates displayed or agreed when ordered. Reservations for specific tasks may temporarily reduce available credit and are released when no longer needed after reconciliation. Estimates are identified as such. Subsequent tariff changes do not increase the price of services already performed.
Displayed usage charges approximate measured units (such as tokens, audio or connection duration) using the applicable Bloodhound tariffs. They include Bloodhound remuneration and are not individual pass-through invoices from the AI provider. Later provider statements serve internal comparison and do not change earlier customer charges. After technical interruptions, only evidenced partial consumption is charged; Qunevo bears any unknown remainder. New billing starts only on activation, without charging earlier free usage. Exhausted credit stops the organization’s active rooms and AI jobs; backend access remains available to arrange a top-up.
Credit and usage are recorded in euros (EUR), excluding VAT. A top-up is an advance payment for future Bloodhound services. German VAT of currently 19% is added to the selected net credit: €10.00 of credit results in a card charge of €11.90. The net amount, tax and gross amount to be charged are shown before purchase. Qunevo bears its payment provider's fees; they are not deducted from purchased net credit. Bloodhound uses automatically retrieved ECB reference rates for costs recorded internally in US dollars. The rate recorded for a booking is not changed by later exchange-rate movements.
Online top-ups are currently available only to businesses established and billed within the German VAT territory; Heligoland and Büsingen are excluded. The customer confirms these conditions and supplies complete billing details for the selected organization under “Credit & payment”. Each top-up can purchase €1 to €1,000 of net credit. These purchase limits do not restrict use of existing small credit balances.
Card payment takes place on Stripe's external checkout page. The displayed gross amount is charged in EUR; credit is provided only after successful payment is confirmed. Bloodhound does not store full card details. After payment, Bloodhound generates a PDF advance invoice showing the net amount and VAT, sends it to the configured billing email and sends an accounting copy to invoice@qunevo.com. The customer agrees to this electronic invoice delivery. Later changes to billing details do not alter previously issued invoices. A refund reverses the corresponding net credit and generates an invoice correction document.
There is no ordinary contractual right to cash out unused credit. Paid remaining credit remains genuinely redeemable for Bloodhound. No additional minimum top-up or room-entry threshold may permanently block small positive balances. Individual tasks may be limited to services covered by available credit. If a residual balance cannot technically be consumed meaningfully, Qunevo will provide usable proportional service or an appropriate adjustment on request, without requiring another top-up. Paid credit does not automatically expire solely due to inactivity.
Statutory reversal, refund, price-reduction and damages claims remain unaffected, including unauthorized charges, payments not owed and services we can no longer supply. This policy does not waive those claims. Pure B2B contracts do not carry the statutory consumer withdrawal right.
4. Accounts, content and customer duties
Customers administer authorized users, roles and invitations, protect credentials and promptly report suspected misuse. They may submit and process only content for which they hold the necessary rights and legal basis. They inform participants about transcription, AI processing and possible feedback sharing, and obtain any required consents. Browser microphone permission does not replace those duties.
Illegal content, infringement of third-party rights, bypassing access or billing controls, malicious software and material disruption are prohibited. Mandatory statutory rights, including interoperability rights, remain unaffected. Special-category data under Article 9 GDPR and Article 10 data require a separate agreement on suitable protections before use.
5. AI output and human review
AI output may be inaccurate, incomplete, outdated, biased or subject to third-party rights. Sources and calculations also need verification. Bloodhound does not replace professional, legal, medical or other expert review and is not intended for safety-critical control without a separate suitability agreement.
Customers review output before adopting, publishing or using it for decisions. We do not promise copyright eligibility or uniqueness; other users may receive similar output. These notices do not restrict agreed functionality, defect remedies or liability under section 9.
6. Rights and confidentiality
Customers retain rights in their submitted content and grant Qunevo only the rights needed to store, process, transmit and deliver it for the contract. To the extent Qunevo holds rights in individually generated output, customers receive a perpetual worldwide right to use, edit and commercially exploit it, subject to third-party rights. Bloodhound software, general templates and infrastructure remain with Qunevo or their respective owners.
Both parties protect the other's confidential information and restrict access to persons and providers authorized for the agreed purpose. Qunevo may not freely analyze room content for its own purposes. Human inspection for support requires documented express customer authorization, subject to mandatory legal obligations and notice where permitted. Automated processing to perform a requested AI task is distinct from human support access.
Stored room content such as transcripts, chats, files, working states and results is encrypted using room-specific keys. A separate key service checks current permissions and authorized processing tasks. Authorized server services decrypt content needed for requested features; AI providers receive the data submitted for those features. Qunevo manages the keys and infrastructure, so privileged administrative access remains technically possible; the contractual restriction on human inspection continues to apply. Account, organization, billing and operational metadata are separate from room encryption. See the security information.
7. Voluntary product feedback and privacy
Separate organization settings govern anonymous categories, product feedback text and technical diagnostic cases. The existing setting, enabled by default for new organizations, shares fixed technical categories and coarse frequencies after month end with contributions from at least five organizations. It does not authorize text sharing. Existing choices are preserved.
An authorized owner can additionally enable product feedback text explicitly. Qunevo then automatically receives short descriptions limited to the product issue or suggestion from new feedback by signed-in participants, without per-report approval. Full conversations, documents and evidence excerpts are not provided through the feedback feed. Removing known names, contact information and context labels does not guarantee anonymity. Organizations inform external participants too and establish the necessary legal basis. Individual objections are respected. The setting does not replace any required consent or permit general-purpose model training.
Disabling text sharing removes existing copies from operator access and prevents new releases. Otherwise access and use end after 30 days and the hourly cleanup removes expired copies. Re-enabling does not release contributions made while sharing was disabled. Previously released, genuinely anonymous categories are separate.
The privacy notice explains actual data categories and recipients. A DPA must be agreed before processing personal customer data on the customer's behalf. Acknowledging the privacy notice does not replace any separately required consent.
8. Duration, changes and termination
The usage contract has no fixed end date. Customers may terminate at any time in text form and delete operational rooms or organizations using the provided controls. Export needed content first. Deletion does not erase legally required billing evidence or valid claims. Customers may use remaining credit before final closure; closure does not waive mandatory reversal rights.
Qunevo may terminate on at least 30 days' notice. Serious misuse or other good cause may justify proportionate suspension or extraordinary termination. Where reasonable, we first provide reasons and an opportunity and time to remedy the issue. If Qunevo discontinues service, paid credit that can no longer be redeemed must not simply be forfeited; applicable statutory refund claims remain.
Material reductions of agreed functionality, new payment duties or changes to these terms do not become binding merely through silence or continued use. They require a valid agreement. Security updates and reasonable improvements preserving the agreed service remain possible. New rates are disclosed before application and apply only to subsequently ordered services.
9. Defects and liability
Report defects with a reproducible description to info@qunevo.com and allow a reasonable opportunity to remedy them. Statutory remedies where remediation fails remain available.
Qunevo's liability is unlimited for intent or gross negligence, death or injury to body or health, within an expressly assumed guarantee, fraudulent concealment and mandatory statutory liability, including product liability. Mandatory GDPR rights of affected individuals are not limited.
For ordinary negligence otherwise, Qunevo is liable only for breach of an essential contractual duty whose performance enables proper execution of the contract and on whose observance customers may ordinarily rely. Liability is then limited to foreseeable damage typical of the contract at formation. Other ordinary-negligence liability is excluded. These limitations also benefit our legal representatives and persons engaged in performance.
No base fee or low historical usage reduces this liability to zero. Contributory fault is assessed under applicable law. Reasonable customer backup of available exports does not replace our own data-security or other essential contractual duties.
For unlawful content culpably supplied by the customer, the customer reimburses necessary, reasonable costs of justified third-party claims insofar as Qunevo is not itself responsible. Qunevo promptly informs the customer, permits reasonable participation in the defense and does not acknowledge claims at the customer's expense without consultation.
10. Final provisions
German law applies excluding the UN Convention on Contracts for the International Sale of Goods. Bielefeld is the exclusive forum where the customer is a merchant, a legal entity or special fund under public law, or such agreement is otherwise legally permissible. Mandatory jurisdiction remains unaffected. German is the contract language. Statutory provisions replace unenforceable clauses.
Annex: Data processing agreement (DPA)
Template for execution in text form. Viewing or downloading this document does not execute a DPA. Before processing personal customer data, the parties must complete and confirm the party information, actual provider/location register and deletion/backup periods in Annex 3. Authorized organization owners can request execution at info@qunevo.com. The German contractual text controls; this is an English information version.
1. Parties, subject and precedence
Processor: Qunevo GmbH, Oestervenn 16, 33758 Schloß Holte-Stukenbrock, Germany, represented by Dr. Felix Johannes Grumbach and Stefan Görlitz; info@qunevo.com.
Customer: the organization identified in the execution confirmation by legal name, address, organization ID, authorized representative and privacy contact. Where the customer is itself a processor, it ensures appropriate instructions and authorization from its controller.
This agreement implements Article 28(3) GDPR for Bloodhound and prevails on data protection over usage terms. Mandatory law and applicable Standard Contractual Clauses retain priority. Processing starts on the confirmed date and continues through the main agreement and the agreed return or deletion period.
2. Instructions and customer duties
The customer determines purposes, legal bases, data scope, authorized users and retention, informs individuals and supplies lawfully processable data. Instructions arise from agreed application use or documented text. Authorized instructing contacts are recorded in Annex 3.
Qunevo processes customer personal data only on documented instructions, including international transfers, unless legally required otherwise. Qunevo informs the customer beforehand where permitted. If it considers an instruction unlawful, it informs the customer without delay and suspends affected processing pending clarification. Purpose or scope changes require appropriate instructions and, where necessary, a contract amendment.
3. Confidentiality and security
Qunevo ensures authorized persons are bound by confidentiality or an equivalent statutory duty, with permissions limited to necessary work. Human support inspection requires documented express customer authorization specifying purpose, scope, persons and duration. It is revocable. Mandatory legal access is reserved but may not serve as general support authority.
Qunevo implements appropriate Article 32 technical and organizational measures based on processing nature, scope, circumstances and risk. Annex 2 describes the evidenced application design; additional operational measures and evidence must be specified in Annex 3. Changes must not reduce agreed protection. This agreement asserts neither certification nor an already implemented technical impossibility of operator access.
4. Assistance, incidents and authorities
Taking account of processing and available information, Qunevo assists with individual rights, security, Articles 33/34 notifications, impact assessments and prior consultations under Articles 35/36. Direct requests concerning customer data are forwarded promptly and not independently answered unless instructed or legally required.
Qunevo notifies the designated contact of a personal-data breach without undue delay after becoming aware, providing available information about nature, scope, affected data/people, likely consequences, contact point and measures taken or recommended. Missing information follows without undue delay. Qunevo assists with evidence, containment and remediation. The controller's 72-hour deadline is not a processor waiting period.
Qunevo informs the customer of official measures, attachment or other threats to customer data where permitted and cooperates with competent authorities.
5. Subprocessors and international transfers
Execution authorizes only the actual subprocessors confirmed in Annex 3. Qunevo gives at least 30 days' written notice of proposed replacements/additions, including provider, activity, countries and safeguards. Customers may object on reasonable data-protection grounds. The parties seek a suitable alternative; failing a lawful solution, affected service may be terminated before new processing begins. Paid services no longer usable are reversed under applicable statutory and contractual rules.
Qunevo imposes substantially equivalent protection duties on subprocessors and remains responsible for their performance to the customer. Transfers follow documented instructions and Articles 44 et seq. GDPR. Applicable Standard Contractual Clauses, transfer assessments and supplementary safeguards are made available, with reasonable protection of unrelated trade secrets that does not defeat evidence rights.
6. Evidence and audits
Qunevo provides information necessary to demonstrate Article 28 compliance and permits reasonable audits, including inspections by the customer or its auditor. Scope, timing and protection of other customers are coordinated. Necessary audits following an incident, grounded suspicion or authority request must not be defeated by rigid annual limits or unreasonable advance notice. Fees must not effectively exclude statutory audit rights.
7. Return, deletion and termination
At the customer's choice, Qunevo returns personal customer data in an agreed common format or deletes it and copies after processing ends, unless statutory retention requires otherwise. Formats and periods for active systems, backups and subprocessors are agreed before processing in Annex 3. Retained data is restricted to the statutory purpose. Qunevo confirms completion on request.
After a restore, access denials from the separate deletion ledger are reapplied before application access is enabled. Physical provider backups and external exports are handled separately under the agreed periods. Confidentiality and protection duties continue until deletion is complete. Billing records for which Qunevo acts as controller are retained separately under applicable law.
8. Liability and execution
The main agreement's liability provisions apply only insofar as they do not restrict mandatory privacy duties or individual rights. Article 82 GDPR remains unaffected. This agreement and annexes can be executed electronically in text form. An unsigned website view or cookie acknowledgement does not substitute identification and confirmation of the parties.
Annex 1 — Processing description
- Purpose: shared workspaces, communication, transcription, AI analysis, personal application help, an authorized read API and requested work products.
- Operations: collection through user input and media permissions, storage, organization, extraction, association, transmission to approved providers, delivery, export and deletion.
- Data: participant/contact data, roles, invitations, schedules, communications, media streams, transcripts, documents, topics, insights, tasks, results, personal help dialogs, API permissions and necessary technical metadata.
- Individuals: users, employees, guests, contacts and others lawfully mentioned in customer content.
- Sensitive data: Articles 9/10 data is not intended without a separate protective agreement.
- Duration/scope: main contract, selected functions and documented instructions; no independent use of room content by Qunevo for general model training. The preceding classification and anonymization of technical feedback for Qunevo's own improvement purposes is described separately in the organization setting and privacy notice.
Annex 2 — Technical and organizational measures
Access and separation: authenticated accounts with password hashing, email verification for protected account use, limited sessions, server-side role and room checks, revocable invitations and API read permissions, and checks before publishing AI results. Web, processing and key services use distinct database roles. The two content services hold no root key and cannot directly read wrapped keys from the database.
Content and media encryption: authenticated AES-256-GCM encryption of registered room texts, original files, preparation, results and histories with separate room and organization keys; separate keys for private help. Record binding and database checks reject plaintext writes and swapped content references. Protected requests and responses between browser/SDK and processing service are additionally encrypted and replay-protected. HTTPS secures public connections. Audio, video and screen sharing are encrypted against the relaying LiveKit media server; authorized participants and the instructed speech service can decrypt them. Media access revocation denies previous key generations.
Erasure and restore: durable erasure operations, access denial and removal of attributable originals, derivatives and private help; a separate signed deletion ledger is applied before allowing application access after database restoration. Unattributed mentions, statutory retention and external copies remain subject to separate review. API integrations receive content-free change notifications for clearing their own copies.
Optional feedback: monthly categories require at least five organizations per category. Separate, default-off text and diagnostics permissions apply to future activity, honor personal objections and source deletion, and limit operator copies to 30 days. Private help dialogs are excluded.
Protection boundary: instructed processing decrypts necessary content in the processing service and transmits selected data to AI providers. Qunevo manages infrastructure and keys; privileged administrative access remains technically possible. Account identities, organization design, billing and operational metadata are separate from room encryption. Human support inspection remains subject to documented express authorization.
Operational detail: Annex 3 records infrastructure administration and strong authentication, confidentiality commitments and training, support approvals, patch and vulnerability management, key custody and recovery, storage and backup protection, tested backup/restore procedures, incident contacts, effectiveness reviews and binding deletion periods. Application tests do not replace deployment-specific operational evidence.
Annex 3 — Deployment record to complete
The execution confirmation must contain the following. Unconfirmed entries are not technical or legal assurances.
| Item | Required confirmation |
|---|---|
| Customer/instructions | Legal entity, address, organization ID, authorized representatives/instructing persons, privacy and incident contacts |
| Start/scope | Start date, enabled features, data types and special requirements |
| Railway | Application services and database: US-West (SFO, United States). Confirm contracting entity, backup locations and retention, subprocessors, DPA and transfer basis. |
| OpenAI | Exact entity, APIs including search/audio, regions, retention, DPA and transfer basis |
| LiveKit | Exact entity, media/signaling regions, metadata retention, DPA and transfer basis |
| Resend | Plus Five Five, Inc., United States; delivery of invitations and other instructed communications, including attachments. Sending region US East (us-east-1), data storage in the United States; open and click tracking disabled. Provider DPA with EU Standard Contractual Clauses. Confirm contractual records, subprocessors and plan-specific retention for the deployment. |
| Other services | Only actual additional subprocessors, activities, locations, safeguards and approvals |
| Return/deletion | Maximum periods for active data, logs, mail queues, backups and provider data; export format and evidence procedure |
| Operational security | Evidence of at-rest encryption, key access, administrative rights, support approvals, backup/restore tests and incident contacts |
| Execution | Date, contract version and both parties' confirmation in text form including the completed deployment record |
Stripe payment processing and Qunevo's own invoicing serve Qunevo's contract administration and accounting purposes described in section 7 of the privacy notice. They do not make Stripe a subprocessor of customer room content.