Terms & Conditions
Article 01Introductory provisions
1.1 These Terms & Conditions govern the relationship between 4Cyber s.r.o., Company ID: 22094458, with its registered office at Zelený pruh 95/97, Braník, 140 00 Prague 4 (the “provider”), and a business customer using the 4Cyber platform, including its 4CyberCity learning area and GRC.
1.2 A customer is a legal entity or a self-employed individual acting in the course of their business. The offering is intended for business customers.
1.3 These terms form part of the contract if they have been made available to the customer and their application was agreed when the contract was concluded. Visiting the website or requesting a platform demo does not itself create a contract.
1.4 An individual contract and expressly agreed deviations take precedence over these terms. Processing personal data on the customer’s instructions is governed by a data processing agreement. The application and precedence of any specific product terms must be expressly agreed.
Article 02Description of services
2.1 The provider develops and provides the 4Cyber platform, which connects training and human cyber risk management (4CyberCity / HRM / LMS) with risk and compliance management (GRC).
2.2 Depending on the agreed modules, services include cybersecurity and safe AI training, phishing simulations, custom learning content creation, reporting, integrations and AI-powered GRC tools. The licence scope and features provided are specified in the contract or confirmed order.
2.3 AI outputs are proposals intended for the customer’s review and approval; they do not, on their own, confirm the organisation’s regulatory compliance or replace professional assessment.
2.4 Learning content is preventive and informational in nature. The provider may continuously update the platform; changes must not unilaterally remove the agreed core service without an appropriate contractual procedure.
Article 03Orders and contract formation
3.1 An order may be placed through an agreed order form, by email or in writing. A contract is formed when the provider confirms the order or when the contract is signed. A non-binding contact form submission or demo request does not itself constitute an order.
3.2 The provider may reject an order before a contract is concluded.
3.3 The contract or confirmed order specifies, in particular, the modules, licence scope, number of users, price and service period. Licence renewal, support and any SLA are governed by the parties’ express agreement.
3.4 Termination is governed by the agreed terms and applicable legislation. The return or deletion of personal data after termination is governed by the data processing agreement; options and procedures for exporting other customer data depend on the agreed service scope.
Article 04Pricing and payment terms
4.1 Prices exclude VAT unless stated otherwise. The price and billing period are specified in the contract or confirmed order.
4.2 Payment is made by bank transfer or through an agreed payment gateway.
4.3 Access to the service is activated upon receipt of payment unless otherwise agreed.
4.4 Changing the price of an already agreed service requires agreement between the parties, unless a valid price-change mechanism has been agreed for recurring services. In that case, the provider will notify the customer of the proposed change and its reason at the agreed contact email sufficiently in advance, at least 30 days before it takes effect. The customer may reject the change and terminate the obligation on that basis under the agreed procedure, with sufficient time to obtain an equivalent service and without a special penalty for such termination.
Article 05User account
5.1 The customer or its users obtain access through unique login credentials.
5.2 The customer is responsible for protecting these credentials and for all actions performed through its account.
5.3 Sharing login credentials or using an account without authorisation is prohibited.
5.4 The provider may suspend access where account misuse or a breach of these terms is suspected.
Article 06Intellectual property
6.1 The provider’s software and proprietary content are protected by intellectual property law. The rights of the provider and other lawful rights holders remain reserved.
6.2 Unless otherwise agreed, the licence to the application and the provider’s content is non-exclusive, non-transferable and limited to the agreed licence period. Copying, modifying, distributing or making content publicly available beyond the licence scope requires the relevant authorisation.
6.3 Provisions concerning the provider’s rights do not apply to documents, courses or other content uploaded by the customer. Rights to this content remain with the customer or the respective rights holders.
6.4 The customer authorises the provider to process this content to the extent necessary to perform the contract. The customer is responsible for ensuring it is entitled to upload the content and use it in the agreed manner.
Article 07Liability and limitations of warranties
7.1 The provider delivers the agreed platform features. Their use does not guarantee complete protection against cyber threats or automatic compliance with all of the customer’s legal obligations.
7.2 The provider is not liable for damage to the extent caused by the customer’s incorrect or unauthorised use, incorrect customer evidence, or circumstances for which the provider is not responsible under the contract and applicable legislation. This clause does not itself exclude liability for data loss or an outage caused by a breach of the provider’s obligations.
7.3 The customer reviews learning and AI outputs before using them and decides on subsequent measures. An AI output does not replace professional or legal assessment of a specific situation.
7.4 Availability, maintenance and any SLA are governed by the agreed service scope. This does not exclude the customer’s rights concerning defective or undelivered agreed services.
7.5 Unless individually agreed otherwise, compensation is limited to the price actually paid for the service to which the damage relates, only to the extent permitted by applicable legislation.
7.6 No provision of these terms excludes or limits liability where such exclusion or limitation is prohibited by mandatory law, particularly for harm caused intentionally or through gross negligence, harm to a person’s natural rights, or where the law protects the weaker party’s right to compensation.
Article 08Complaints
8.1 A complaint may be submitted in writing to info@4cyber.cz. Include a description of the issue and the details needed to identify it.
8.2 The provider will resolve a complaint within 14 days unless the parties agree otherwise.
8.3 The assessment of an outage or service limitation is governed by the agreed terms, including any SLA, and applicable legislation. Maintenance or third-party intervention does not itself automatically exclude the customer’s rights where the agreed service has not been delivered.
Article 09Personal data protection and cookies
9.1 Personal data is processed in accordance with the GDPR and Czech Act No. 110/2019 Coll. The provider acts as controller for its own purposes, such as managing business relationships and invoicing. When processing employee and other personal data on the customer’s documented instructions, it acts as processor under the data processing agreement.
9.2 The platform’s operational servers for Czech customers are in the Czech Republic at the Algotech data centre. When AI is used, customer data is processed by a closed AI agent on an internal server and is not sent to public AI services. The US parent company, 4Cyber Technologies Inc., has no access to Czech customers’ data.
9.3 Details of purposes, recipients and rights are provided in the privacy policy. Optional cookies are governed by the applicable consent settings and cookie information.
Article 10Final provisions
10.1 A new version of these terms applies to new contracts where properly incorporated. Existing contracts may be amended by agreement or under a validly agreed change mechanism. Such a mechanism must specify, in accordance with applicable legislation, a reasonable scope and grounds for changes, the notification method, and the customer’s right to reject changes and terminate the obligation. The provider will notify the customer of the change and its reason at the agreed contact email sufficiently in advance, at least 30 days before it takes effect. Termination due to a rejected change must not carry a special penalty, and the termination period must allow the customer to obtain an equivalent service.
10.2 The legal relationship is governed by Czech law. Disputes are resolved by the court having jurisdiction under applicable legislation unless the parties have validly agreed on a different jurisdiction.
10.3 This version is effective from 4 October 2026. Publication of this version does not automatically amend existing contracts. The version agreed for those contracts remains applicable until properly amended.
Questions about this document?
Contact us at info@4cyber.cz.