OT Olyteck Trust Center →
Legal home Terms of Service Privacy Policy Cookie Policy Data Processing (DPA) Security overview Legal Notice

Terms of Service

Last updated: 19 June 2026

Please read these terms carefully. These Terms of Service govern your use of any Olyteck product (Olyteck Cyber, Olyteck Ask, Olyteck Studio, Olyteck Guard), each operated by Olyteck. By accessing or using a product you agree to be bound by these Terms. Product-specific particulars (what each product does, which Microsoft Graph scopes it uses, its AI stance, sub-processors and retention) are in that product's DPA Schedule and on its own site.

Table of Contents

  • 1. Introduction
  • 2. Eligibility
  • 3. Accounts & Microsoft consent
  • 4. Plans, trials & billing
  • 5. What the products do
  • 6. Your data
  • 7. Outputs & accuracy
  • 8. Acceptable use
  • 9. Intellectual property
  • 10. Sub-processors & data location
  • 11. Security expectations
  • 12. Service availability
  • 13. Termination
  • 14. Disclaimers & liability
  • 15. Indemnification
  • 16. Force majeure
  • 17. Assignment
  • 18. Notices
  • 19. Export controls & sanctions
  • 20. Order of precedence
  • 21. Changes to terms
  • 22. Governing law
  • 23. Severability
  • 24. Contact

1. Introduction

These Terms of Service ("Terms") govern your access to and use of the Olyteck products ("Service", "we", "us", "our"), operated by Olyteck. By signing in, granting Microsoft consent, or otherwise using a product, you agree to these Terms and to our Privacy Policy.

2. Eligibility

The Service is intended for organisations and their authorised users. You must be at least 18 years old and authorised by your organisation to configure the product (including, where applicable, granting Microsoft Graph admin consent). If you act on behalf of a company, you represent that you have authority to bind it to these Terms.

3. Accounts & Microsoft consent

3.1 Single sign-on with Microsoft

Access uses Microsoft Entra (Azure AD) for identity. We do not store passwords — authentication is performed by your Microsoft tenant, and we retain only the minimum profile information required to run the Service (see the Privacy Policy).

3.2 Admin consent & scope

Where a product reads data from Microsoft 365, an administrator grants admin consent to that product's Microsoft Graph application, which requests the scopes listed in the product's DPA Schedule (read-scoped by default for the security products). You choose the scope of data the product accesses, and you may revoke consent from your Microsoft tenant at any time, which stops processing.

3.3 Account responsibility

You are responsible for the actions of users you authorise. Notify us at [email protected] if you suspect unauthorised access.

4. Plans, trials & billing

4.1 Trials

A product may offer a free trial; the trial terms (length, card requirement, feature scope) are described on that product's pricing page. When a trial ends, the workspace either continues on a paid plan you select or moves to a read-only / paused state.

4.2 Subscriptions & renewal

Paid plans renew automatically at the end of each billing cycle unless cancelled. You can cancel at any time from the in-app settings or the Stripe customer portal; cancellation takes effect at the end of the current cycle. Payments are processed by Stripe Payments Europe, Ltd. — we never see or store your card data.

4.3 Taxes (EU VAT)

Prices are in euros (EUR), net of VAT. TVA non applicable, art. 293 B du CGI (franchise en base — not VAT registered). Where VAT becomes applicable it is added at checkout by Stripe Tax based on your billing country; for VAT-registered businesses in EU member states other than France, the reverse-charge mechanism applies where a valid VAT identification number is supplied. See the Legal Notice for the current position.

4.4 Refunds

Subscription fees are non-refundable for the current billing cycle. Any non-waivable consumer withdrawal right is preserved.

Automatic renewal: unless you cancel before the end of the current billing period, paid subscriptions renew automatically and you authorise us (via Stripe) to charge your payment method for the renewal term.

5. What the products do

Olyteck ships several products on a common EU-hosted, GDPR-aligned, data-minimising foundation ("counts findings, never files"):

  • Cyber — read-only Microsoft 365 security, asset-hygiene and storage scanner.
  • Ask — EU-hosted private AI that fills security questionnaires, RFPs and audits from your documents.
  • Studio — custom AI, automation and internal-tooling engagements.
  • Guard — Microsoft 365 email threat analysis, warning banners and opt-in response.

The exact functions, data accessed and processing model of each product are described on its own site and in its DPA Schedule.

6. Your data

6.1 Ownership

Your data, and the outputs a product produces about it (findings, answers, verdicts, reports), remain yours. You grant us only the limited licence needed to operate the product as configured; it ends when the data is deleted or you revoke access / close the workspace.

6.2 What we store

What each product stores — and what it never stores — is described in the Privacy Policy and the product DPA Schedule.

6.3 AI & training

We do not use your content to train our own models. Some products use third-party AI sub-processors under "no training on API data" terms (e.g. Ask, Cyber); others use none (e.g. Guard). Each product's DPA Schedule states its AI stance and lists any AI sub-processors.

6.4 Export & deletion

You can export your data where the product provides an export, and request deletion by emailing [email protected]. Deletion is processed within 30 days, except where French accounting law requires us to keep billing records for 10 years.

7. Outputs & accuracy

Olyteck products are aids, not guarantees. AI-generated outputs (e.g. drafted answers, reports) may contain errors and must be reviewed before reliance. Security detections (e.g. Guard's verdicts) produce both false negatives and false positives; no security product catches every threat. Outputs are not authoritative legal, financial or other professional advice.

It is the customer's responsibility to review outputs and configure the product before relying on it, and to maintain its own layered defences (including Microsoft's built-in protection).

Outputs may not be redistributed in a way that represents them as authored or certified by Olyteck.

8. Acceptable use

You agree not to:

  • Connect a product to a Microsoft 365 tenant, or to data, you are not authorised to administer.
  • Use a product in breach of applicable employment, works-council or privacy law.
  • Attempt to bypass the per-tenant isolation of the platform or access data that is not yours.
  • Resell or rent access outside your own organisation without a written reseller / MSP agreement.
  • Reverse-engineer or scrape the Service in a way that materially impacts other customers.
  • Use the Service to build a competing product (to benchmark, mirror or replicate it for resale).

We may suspend access immediately if we reasonably believe you have breached this section.

9. Intellectual property

9.1 Our IP

The Service — its source code, model frameworks, scoring/detection engines, UI design and brand — is owned by Olyteck or our licensors. Nothing here transfers ownership to you. Content and configuration you create in your tenant are yours.

9.2 Your licence

Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable licence to use the Service for your internal business purposes.

9.3 Outputs

You may use the outputs the Service produces for any lawful internal purpose and share them with your advisors, auditors and insurers. You may not republish them as a standalone commercial product or resell them as a service of your own.

10. Sub-processors & data location

Applications and databases run on EU-27 hosting in France (Paris, PAR1). Each product engages a small set of sub-processors listed, with its data categories and retention, in its DPA Schedule and summarised in the Trust Center. The DPA documents the obligations applied to each.

11. Security expectations

We operate the Service with a defined set of technical and organisational measures — encrypted transport, encrypted storage, Microsoft Entra SSO, strict tenant isolation, least-privilege staff access and audit logging. The full list is in the Security overview and contractually in DPA §5. No online service can promise absolute security; report suspected issues to [email protected].

12. Service availability

We aim to keep the Service available but do not commit to a specific uptime percentage on trial or standard plans, and no service-level credits apply to them. For Enterprise customers, any written uptime commitment and service-credit mechanism are set out in a separate Order Form or master agreement; absent such a signed document, no SLA is in effect. We may perform scheduled maintenance, with advance in-app notice where it is expected to affect availability.

13. Termination

13.1 By you

You may terminate at any time from the in-app settings or the Stripe customer portal, revoke any Microsoft Graph consent, and ask us to delete your data by emailing [email protected]. Deletion is processed within 30 days except where French accounting law requires longer retention of billing records.

13.2 By us

We may suspend or terminate access immediately for material breach, suspected fraud or abuse, a payment failure after a 7-day grace period, or where required by law. We may discontinue all or part of the Service with at least 30 days' notice.

13.3 Survival

Provisions that by their nature should survive termination (ownership, disclaimers, indemnity, limits of liability, governing law) will survive.

14. Disclaimers & limitation of liability

Disclaimer of warranties

The service is provided "as is" and "as available" without warranties of any kind, express or implied. To the fullest extent permitted by law, we disclaim all warranties, including implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. We do not warrant that the service will be uninterrupted, timely, secure or error-free, or that its outputs will be complete or free of false positives or false negatives.

Limitation of liability

To the maximum extent permitted by law, in no event shall we, our directors, employees, agents, partners, suppliers or affiliates be liable for any indirect, incidental, special, consequential or punitive damages, including loss of profits, data, goodwill or service interruption, or for losses arising from reliance on the service's outputs or from an incident the service did not detect, arising out of or in connection with these terms or your use of or inability to use the service.

In no event will our total liability arising out of or in connection with these terms or the use of or inability to use the service exceed the greater of (a) the amounts you paid us in the twelve (12) months preceding the event giving rise to the liability or (b) one hundred euros (€100).

15. Indemnification

You agree to defend, indemnify and hold harmless Olyteck, its affiliates and their respective officers, directors, employees and agents from any claims, liabilities, damages, losses and expenses (including reasonable attorneys' fees) arising out of: (a) your breach of these Terms; (b) your misuse of the Service; (c) your connecting a product to a tenant or data you were not authorised to administer; or (d) actions taken by users you authorised.

16. Force majeure

Neither party is liable for any delay or failure to perform (other than payment obligations) caused by events outside its reasonable control, including acts of God, war, terrorism, civil unrest, government action, labour disputes, pandemic, internet or telecommunications failure, denial-of-service attacks, or failure of an underlying sub-processor or hosting provider (including Microsoft 365 / Graph availability).

17. Assignment

You may not assign or transfer these Terms without our prior written consent. We may assign them without your consent in connection with a merger, acquisition, reorganisation or sale of all or substantially all of our assets, on written notice. Any attempted assignment in breach of this section is void.

18. Notices

Formal notices to us must be sent to [email protected] (or, for privacy / security matters, the addresses in §24). Notices to you are deemed delivered when sent to the workspace administrator's email on file or posted in-app. You are responsible for keeping that address current.

19. Export controls & sanctions

You represent that you are not located in, and will not use the Service from, a country or region subject to comprehensive EU, UK or US trade sanctions, and that you are not on any sanctioned-persons or denied-parties list maintained by the EU, UK, US or France. We may suspend or terminate access immediately if we reasonably believe these representations are no longer accurate.

20. Order of precedence

If a signed Order Form, Master Services Agreement or counter-signed Data Processing Agreement exists between you and us, any conflict is resolved in this order: (1) the signed Order Form / Master Services Agreement, (2) the counter-signed Data Processing Agreement on matters of personal-data processing, (3) these Terms, (4) the Privacy Policy and other published policies referenced from these Terms.

21. Changes to these Terms

We may update these Terms from time to time. We post changes here and update the "Last updated" date; where a change is material, we also post an in-app notice. Continued use of the Service after the change becomes effective constitutes your acceptance of the modified Terms.

22. Governing law & disputes

These Terms are governed by French law. Subject to any non-waivable consumer-protection rights in your country, the competent courts of France has exclusive jurisdiction. Before filing any claim, please contact us at [email protected] — we'll do our best to resolve it informally.

23. Severability

If any provision of these Terms is held unenforceable, it will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.

24. Contact

Email: [email protected]

Operator: Olyteck — SIRET 993 174 499 00018