Terms of Service

1. About These Terms

These Terms of Service ("Terms") govern access to and use of Construct, a software-as-a-service HR modelling, workforce analytics and decision-support platform (the "Platform") operated by Formation HR B.V., a company incorporated under the laws of the Netherlands, with registered office at Bosruiter 54, 5658CM Eindhoven, the Netherlands, Chamber of Commerce (KVK) No. 99067978 ("Provider", "we", "us", "our").

Construct is currently made available exclusively through individually negotiated pilot and early-access engagements. These Terms set out the baseline conditions of use that apply to every Authorised User of the Platform. Commercial terms — including fees (if any), service levels, duration, and the specific data-processing arrangements for a given engagement — are set out exclusively in the separate, individually signed agreement between the Provider and the Customer (a "Pilot Agreement", "Order Form", or equivalent, the "Individual Agreement") and its accompanying Data Processing Agreement ("DPA").

Where an Individual Agreement and DPA have been signed between the Provider and a Customer, those documents prevail over these Terms in the event of any conflict on commercial, technical, or data-protection matters. These Terms do not, by themselves, create any commercial or payment obligation, and are not an offer to sell or license the Platform on a standalone basis.

2. Definitions

TermMeaning
"Platform" / "Construct"the Construct software-as-a-service application, including its web application, APIs, orchestration layer, and reporting features, operated by the Provider.
"Customer"the legal entity that has entered into an Individual Agreement with the Provider to access the Platform.
"Authorised User"an individually named employee, contractor, or agent of the Customer granted access to the Platform by the Customer.
"Customer Data"any data, including personal data of the Customer's workforce, business data, or other information uploaded to, processed through, or generated within the Platform by or on behalf of the Customer.
"Connected AI Model"any third-party or internal AI/machine-learning model that the Customer connects to the Platform under the Bring-Your-Own-Model architecture described in Section 6.
"Output"any insight, score, prediction, model, simulation, report, or recommendation generated by the Platform (including via a Connected AI Model) from Customer Data.
"Personal Data", "Processing", "Controller", "Processor", "Data Subject"have the meanings given in Regulation (EU) 2016/679 ("GDPR").
"EU AI Act"Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence.

3. Eligibility and Accounts

3.1 The Customer must be a legal entity operating in a jurisdiction where the Platform may lawfully be offered. The Platform is intended for business use only and is not directed at, and may not be used by, natural persons acting in a personal or consumer capacity.

3.2 Use of the Platform is prohibited for any Customer located in, or for any purpose involving, a jurisdiction subject to sanctions imposed by the European Union, the United Nations, or other applicable sanctions regimes.

3.3 Access is provided exclusively through individually named Authorised User accounts. Generic, shared, or role-based accounts are not permitted. All Authorised Users must be at least 18 years of age.

3.4 The individual accepting these Terms on behalf of the Customer represents that they have authority to bind the Customer.

4. Google Sign-In and Account Authentication

4.1 Purpose. Construct offers “Sign in with Google” (Google OAuth 2.0) as a login method for Authorised Users. We use this integration solely to verify an Authorised User's identity when they log in to the Platform. It is an authentication mechanism, not a data-import feature.

4.2 Scope of access. The Google sign-in integration requests only basic identity scopes — openid, .../auth/userinfo.email and .../auth/userinfo.profile — to obtain the Authorised User's name, email address, Google account identifier, and profile picture. We do not request or access Gmail, Google Calendar, Google Drive, Google Contacts, Google Directory, Google Admin Reports, or any other Google Workspace data through this integration. Should a future Platform feature require any additional Google API scope, we will request fresh, specific, and informed consent from the Customer and update this Section and our Google API disclosures before doing so.

4.3 Google API Services User Data Policy. Our use and transfer of information received through Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (a) we do not use data obtained via Google Sign-In for advertising or retargeting purposes; (b) we do not sell such data, and do not transfer it to third parties except as strictly necessary to provide the login functionality described in this Section or as required by law; (c) we do not use such data to develop, train, or improve generalised AI or machine-learning models; and (d) human access to such data by our personnel is restricted, logged, and limited to what is necessary for security, support, or legal compliance.

4.4 Provider as independent controller. With respect to the authentication tokens and identity data exchanged with Google during the sign-in flow, the Provider acts as an independent Data Controller under the GDPR — not as a Processor on the Customer's behalf. This authentication data is a separate data stream from, and is not combined with, Customer Data processed within the Platform (see Sections 6 and 10, and our Privacy Policy).

4.5 Account security. Each Authorised User must enable two-factor authentication on the Google account used to sign in to Construct, and must not share their login credentials, authentication tokens, or active session with any other person. Access performed using a given Authorised User's credentials is deemed to have been performed by that individual.

4.6 Revocation. The Customer or any Authorised User may revoke Construct's Google access at any time via https://myaccount.google.com/permissions or via the Platform's account settings. Upon revocation, we will cease accessing the relevant Google account and will delete any locally stored authentication tokens within seven (7) days, subject to any retention obligation under law.

4.7 No unauthorised scope expansion. We will not request Google API scopes broader than those disclosed in this Section and on the Google OAuth consent screen without first obtaining the Customer's fresh, informed consent.

5. Licence to Use the Platform

5.1 Subject to these Terms and the applicable Individual Agreement, the Provider grants the Customer a non-exclusive, non-transferable, non-sublicensable, limited right to access and use the Platform for the Customer's internal business purposes during the term of that Individual Agreement.

5.2 The Customer shall not, and shall not permit any Authorised User or third party to:

6. AI Functionality — Bring Your Own Model (“BYOM”)

6.1 Standard architecture. Construct's standard architecture operates on a Bring-Your-Own-Model basis. Each Customer connects its own contracted AI model or API — independently selected and licensed by the Customer from a third-party AI provider of its choice, or an internal model of the Customer — to the Platform (the “Connected AI Model”). The Customer is solely responsible for its contractual relationship with, and the data-processing terms of, the provider of the Connected AI Model, including any Chapter V GDPR restricted-transfer compliance (such as Standard Contractual Clauses and a Transfer Impact Assessment) applicable to data sent to that model.

6.2 Provider's role. The Provider's role with respect to the Connected AI Model is limited to that of a technical conduit and orchestration layer within the Platform. The Provider does not select, own, operate, host, or control the Connected AI Model, and does not warrant the accuracy, availability, reliability, or fitness for any particular purpose of the Connected AI Model or the Outputs it generates.

6.3 Pilot exception. Where, exceptionally, the Provider makes available its own integrated AI service for a specific pilot engagement (for example, at no additional charge), the terms of that specific arrangement — including any applicable data-minimisation or anonymisation controls — are set out exclusively in the applicable Individual Agreement and DPA, and Section 6.1 does not apply to that specific arrangement for its duration.

6.4 No training on Customer Data. The Provider does not use Customer Data or Output to train, fine-tune, or improve any generalised or commercially available AI model — whether the Provider's own or a third party's — without the Customer's prior written consent.

6.5 Customer inputs. The Customer shall not submit to the Platform, or cause to be transmitted to a Connected AI Model, any special category personal data (Article 9 GDPR), classified information, legally privileged material, or third-party trade secrets, without first assessing whether such transmission is lawful and permissible under its own arrangement with the relevant AI provider.

7. Decision-Support Only — No Automated Decision-Making

7.1 Construct is a decision-support tool. It generates insights, scores, models, simulations, and recommendations intended to inform decisions made by human beings employed by or acting for the Customer. Construct does not itself make, and is not designed to make, decisions that produce legal or similarly significant effects on individuals.

7.2 The Customer shall not use, and shall not permit any Authorised User to use, Outputs as the sole or automated basis for any decision producing legal or similarly significant effects on a natural person — including hiring, promotion, compensation, disciplinary, or termination decisions — without meaningful human review.

7.3 Where Outputs inform or contribute to profiling or automated decision-making within the meaning of Article 22 GDPR, the Customer, as Data Controller, is responsible for ensuring: (a) meaningful human review is applied before any such decision is acted upon; (b) affected individuals have the ability to obtain human review of, and contest, the decision; and (c) affected individuals are informed of the existence of such processing and the logic involved, in accordance with Articles 13, 14, and 22 GDPR.

8. EU AI Act — Roles and Permitted Use

8.1 Role allocation. Where Construct's AI-supported functionality is used in a context within scope of the EU AI Act, the Provider's role is generally that of the provider of the software component that applies a Connected AI Model (which, under the standard BYOM architecture, remains the Customer's own) to a specific analytical function within the Platform. The Customer determines the actual purpose and operational context of use (for example, recruitment, performance evaluation, or workforce planning) and is responsible for its own classification of, and compliance with, its obligations under the EU AI Act for that specific use case — including any applicable Annex III high-risk classification for employment and worker-management use cases, and any obligations arising as deployer (and, where applicable, as provider) of an AI system.

8.2 Provider support. On reasonable request, the Provider will make available to the Customer such technical documentation, instructions for use, and information about the Platform's logging and human-oversight design features as are reasonably necessary to support the Customer's own EU AI Act compliance obligations (including, as applicable, Articles 13, 14, 26, and 29).

8.3 Prohibited uses. The Customer shall not use the Platform, whether directly or via a Connected AI Model, to:

8.4 High-risk use notice. If the Customer intends to use the Platform for a use case that may constitute a high-risk AI system under Annex III of the EU AI Act (for example, recruitment, task allocation, or performance monitoring, evaluation, or termination decisions), the Customer shall notify the Provider in advance so that the parties may agree, in the applicable Individual Agreement, any additional technical or documentation measures reasonably necessary to support the Customer's compliance obligations.

9. Customer Data and Intellectual Property

9.1 Customer Data ownership. As between the Provider and the Customer, the Customer retains all right, title, and interest in and to Customer Data. These Terms do not transfer to the Provider any intellectual property rights in Customer Data.

9.2 Limited processing licence. The Customer grants the Provider a limited, non-exclusive licence to access, host, and process Customer Data solely to: (a) provide the Platform to the Customer; (b) maintain and improve the Platform in ways that do not involve using identifiable Customer Data to train generalised AI models; and (c) comply with legal obligations.

9.3 Provider intellectual property. The Platform — including its software, user interface, orchestration logic, and underlying technology (but excluding any Connected AI Model, which remains the property of its respective provider) — is and remains the exclusive intellectual property of the Provider. No rights are granted to the Customer except as expressly set out in these Terms.

9.4 Output ownership. Subject to Section 9.3, the Customer may use, reproduce, and act upon Outputs generated for it through the Platform for its own internal business purposes.

9.5 Feedback. Feedback, suggestions, or observations the Customer provides about the Platform may be used by the Provider without restriction or compensation, unless otherwise agreed in writing.

9.6 Customer-Built Configurations — purpose. Where the Platform provides development tools enabling the Customer to build custom algorithms, scoring models, job/role frameworks, weighting schemes, or workflows (“Customer-Built Configurations”), enabling Customers to do so is part of the Platform's core functionality, and a general purpose of offering these tools is to allow the Provider to learn from effective Customer-Built Configurations and incorporate analogous methodologies into the Platform as core functionality, for the benefit of the wider Construct customer base.

9.7 Commercialisation licence. By using the Platform's development tools to create a Customer-Built Configuration, the Customer grants the Provider a non-exclusive, worldwide, royalty-free, perpetual, and irrevocable licence to use, reproduce, adapt, merge, and incorporate the underlying “Configuration Logic” of that Customer-Built Configuration — meaning its algorithmic logic, parameters, weighting schemes, calculation methodology, and workflow structure, considered independently of and separated from any Customer Data — into the Platform, for the development, improvement, and commercialisation of the Platform. This licence arises automatically on creation of a Customer-Built Configuration, survives termination or expiry of the applicable Individual Agreement, applies in identical, adapted, or generalised form, and does not require royalty or compensation.

9.8 Data-stripping and non-attribution. The Provider shall exercise the licence in Section 9.7 only after the retained Configuration Logic has been fully stripped of Customer Data and any information capable of identifying the Customer, its personnel, or the specific engagement. The Provider shall not identify the Customer as the source or origin of any Configuration Logic incorporated into the Platform, and shall not disclose the Customer's Confidential Information — including its identity or specific Customer Data — to other Platform customers. For the avoidance of doubt, retained Configuration Logic held in this stripped, abstracted form does not constitute continued processing of Customer Data or personal data.

9.9 Scope limits. Sections 9.6–9.8 grant the Provider rights only in the abstract Configuration Logic described above. They do not grant the Provider any rights in Customer Data itself (Section 9.1), and do not limit the Customer's own right to continue using, adapting, and independently developing its Customer-Built Configurations, within or outside the Platform, for its own purposes. Where a given engagement warrants a different allocation of these rights (for example, exclusivity or additional consideration), the parties may agree bespoke terms in the applicable Individual Agreement, which will prevail over this Section 9 to the extent of any conflict.

9.10 Extraction restriction. Independently of Sections 9.6–9.9, and without limiting Section 5.2, the Customer shall not design a Customer-Built Configuration with the primary purpose of replicating Provider technology or methodology for use outside the Platform, or systematically probe the Platform's APIs to reverse-engineer the Provider's underlying models or scoring logic.

10. Data Protection

10.1 Roles of the parties. As between the Provider and the Customer, the Customer is the Data Controller of Customer Data (including any personal data of its workforce processed through the Platform) and is responsible for identifying and documenting a lawful basis for that processing under Article 6 GDPR, completing any required Data Protection Impact Assessment, and providing required transparency to Data Subjects. The Provider acts as Data Processor with respect to Customer Data, processing it only on the Customer's documented instructions, as set out in the DPA. Where the Provider processes personal data for its own purposes — such as account and authentication data (Section 4), billing, or security — the Provider acts as an independent Data Controller for those activities, as further described in our Privacy Policy.

10.2 Data Processing Agreement. Processing of personal data within Customer Data is governed by a separate, individually executed DPA between the Provider and the Customer, which forms part of the Individual Agreement. The DPA addresses, among other matters: the subject matter, duration, nature, and purpose of processing; technical and organisational security measures (Article 32 GDPR); sub-processor disclosure and change notification; Data Subject rights assistance; personal data breach notification (Articles 33–34 GDPR); cross-border transfer safeguards (Chapter V GDPR); and deletion or return of personal data on termination.

10.3 Customer responsibility for lawful basis. The Customer is solely responsible for identifying a valid lawful basis for processing Customer Data through the Platform, for any required works council or employee consultation under applicable national employment law, and for ensuring that special category data (Article 9 GDPR) is uploaded only on a valid Article 9(2) basis and, where required under the DPA, with the Provider's prior written consent.

10.4 International transfers. Where personal data is transferred outside the European Economic Area, such transfers are made only where adequate safeguards are in place, as further specified in the DPA (for example, EU Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms).

10.5 Deletion scope. On termination or expiry, the Provider will delete or return Customer Data in accordance with the DPA. This deletion obligation does not extend to Configuration Logic retained under Section 9.7, which by that point has been stripped of Customer Data and identifying information in accordance with Section 9.8 and therefore does not constitute personal data.

11. Security

The Provider implements and maintains appropriate technical and organisational measures designed to protect Customer Data, including: encryption of data in transit and at rest; role-based access controls operating on a principle of least privilege; multi-factor authentication for Provider systems; logical isolation controls for Customer Data hosted on shared infrastructure; audit logging of access to Customer Data; vulnerability management and periodic security testing; and an incident-response process, including prompt notification of any personal data breach in accordance with the DPA and Articles 33–34 GDPR. The complete, current set of technical and organisational measures applicable to a Customer's engagement is set out in the DPA.

12. Sub-processors

The Provider engages a limited number of sub-processors to help deliver the Platform. A current, publicly available register is maintained at formation.hr/sub-processors and Customers are notified of new sub-processor engagements in accordance with the DPA. As of the effective date of these Terms, sub-processors used for hosting and infrastructure include the following:

Sub-processorPurposeLocationTransfer safeguard
UpcloudDatabase hosting, compute, object storage, backups, network infrastructureEU/EEAEEA — no transfer mechanism required
Functional Software, Inc. (Sentry.io)Application performance monitoring and error tracking (pseudonymised technical data only)USAEU Standard Contractual Clauses (Module 2)

A Connected AI Model that a Customer connects to the Platform under the BYOM architecture (Section 6) is not the Provider's sub-processor; it is engaged and contracted directly by the Customer.

13. Confidentiality

13.1 Each party agrees to hold in strict confidence all non-public technical, commercial, and operational information disclosed by the other party, and not to disclose it to any third party without prior written consent, except as required by law, regulation, or court order.

13.2 Confidentiality obligations survive termination of the relevant Individual Agreement for five (5) years, except with respect to trade secrets, for which such obligations survive indefinitely.

14. Warranties and Disclaimers

14.1 The Provider warrants that it has the legal right and authority to enter into these Terms and will process personal data in accordance with applicable data protection law.

14.2 To the maximum extent permitted by applicable law, the platform and all outputs are provided on an “as is” and “as available” basis. The provider makes no warranty regarding the accuracy, completeness, or reliability of outputs, whether generated by the platform or by a connected ai model selected and operated by the customer. Outputs do not constitute professional legal, financial, HR, or employment advice. The customer assumes sole responsibility for decisions made on the basis of outputs, consistent with section 7.

15. Limitation of Liability

15.1 Neither party shall be liable to the other for indirect, incidental, special, consequential, or punitive damages, including loss of profit, revenue, goodwill, or data, arising out of or in connection with these Terms, except as set out in an Individual Agreement.

15.2 Specific liability caps and allocations of risk applicable to a given engagement are set out exclusively in the applicable Individual Agreement, reflecting its particular commercial terms (including, where applicable, that the Platform is provided free of charge during a pilot).

15.3 Nothing in these Terms or an Individual Agreement limits or excludes: (a) either party's liability for death or personal injury caused by its negligence; (b) either party's liability for fraud or fraudulent misrepresentation; (c) a party's liability to a Data Subject under Article 82 GDPR, or exposure to an administrative fine or regulatory sanction under Article 83 GDPR, in each case to the extent such liability cannot as a matter of law be limited or excluded by agreement between the Provider and the Customer; or (d) any other liability that cannot be limited or excluded under mandatory Netherlands law.

15.4 Inter-party data-protection claims. Claims between the Provider and the Customer arising from a party's breach of its own obligations under data protection law or the DPA (for example, a claim by the Customer against the Provider for failure to implement the security measures required by Article 32 GDPR or the DPA, including where this results in a regulatory fine or Data Subject claim against the Customer) are not within the scope of the carve-outs in Section 15.3, and remain subject to a separate, higher liability cap (a "super-cap") for claims of this nature, as set out in the applicable Individual Agreement. In the absence of a super-cap specified in the Individual Agreement, such claims remain subject to the general cap set out in Section 15.2.

16. Term, Suspension, and Termination

16.1 An Authorised User's access to the Platform is governed by the term of the applicable Individual Agreement between the Provider and the Customer.

16.2 The Provider may suspend or terminate access to the Platform, in whole or in part, immediately and without prior notice where: (a) the Customer or an Authorised User is in material breach of these Terms; (b) continued access poses a security risk to the Platform or other customers; (c) required by law or a competent authority; or (d) as otherwise set out in the applicable Individual Agreement.

16.3 On termination or expiry of the applicable Individual Agreement, the Provider will cease processing Customer Data (except as required by law), revoke Platform access, and delete or return Customer Data in accordance with the DPA.

17. Governing Law and Dispute Resolution

17.1 These Terms are governed by the laws of the Netherlands, without regard to its conflict-of-laws provisions.

17.2 Any dispute shall first be subject to good-faith negotiation between the parties for thirty (30) days. If unresolved, disputes shall be submitted to the exclusive jurisdiction of the competent courts of the Netherlands, unless the applicable Individual Agreement provides otherwise.

18. General Provisions

18.1 Entire agreement. For a given Customer, these Terms, the Privacy Policy, the DPA, and the applicable Individual Agreement together constitute the entire agreement between the parties regarding use of the Platform; where a conflict exists on commercial or data-protection matters, the Individual Agreement and DPA prevail.

18.2 Amendments. The Provider may amend these Terms by providing at least thirty (30) days' notice via the Platform or email. Continued use after the effective date of a change constitutes acceptance; material changes affecting data-protection rights require affirmative consent where required by law.

18.3 Assignment. Neither party may assign these Terms without the other's prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets.

18.4 Severability. If any provision is found invalid or unenforceable, it will be modified to the minimum extent necessary, and the remaining provisions shall continue in full force.

18.5 Force majeure. Neither party is liable for delay or failure to perform due to causes beyond its reasonable control, provided it gives prompt notice and takes reasonable mitigation steps.

18.6 Survival. Sections 9 (Customer Data and Intellectual Property), 13 (Confidentiality), 14 (Warranties and Disclaimers), and 15 (Limitation of Liability) survive termination or expiry of the applicable Individual Agreement.

19. Contact

Formation HR B.V.

Bosruiter 54, 5658CM Eindhoven, the Netherlands

Chamber of Commerce (KVK) No. 99067978

Email: dpo@formation.hr

This document is a baseline Terms of Service for the Construct pilot/early-access platform. It is designed to accompany, not replace, the individually signed Pilot Agreement/Order Form and Data Processing Agreement executed with each Customer, and to serve as the publicly accessible Terms of Service required for Google API/OAuth verification of Construct's “Sign in with Google” integration.