AI & Security Addendum
Use of Artificial Intelligence and additional cybersecurity arrangements
Article 1Purpose
- This addendum governs the use of Artificial Intelligence and additional cybersecurity arrangements within Qteco's services and supplements the General Terms and Conditions.
Article 2AI Services
Qteco may make use of:
- generative AI;
- machine learning;
- AI assistants;
- Copilot solutions;
- AI automations;
- AI analytics platforms.
Article 3Responsibility and Human Oversight
- AI results are supportive in nature.
- Decision-making remains at all times the responsibility of the Client; meaningful human oversight of AI output remains safeguarded.
Article 4No Warranty
Qteco does not warrant that AI output:
- is free of errors;
- is complete;
- is legally correct;
- is free from bias;
- is suitable for a specific purpose.
Article 5Data, Confidentiality and Training
- Qteco does not use the Client's data to train its own or third-party AI models without prior Written consent.
- Where AI vendors offer the option, Qteco opts for business configurations in which input data is not used for model training.
- The Client is responsible for not entering special categories of personal data or strictly confidential information into AI applications, unless arrangements have been made In Writing.
Article 6EU AI Act and Allocation of Roles
- Depending on the specific service, Qteco may qualify as a provider or as a deployer within the meaning of the EU AI Act (Regulation (EU) 2024/1689).
- The Parties shall reasonably cooperate to comply with the obligations incumbent on them under the EU AI Act, in proportion to their role.
- The Client remains ultimately responsible for a permissible and lawful use of the AI output within its organisation.
Article 7Security Baseline
For managed environments, the following applies as a minimum:
- Multi-Factor Authentication;
- Endpoint Protection;
- Patch Management;
- Backup strategy;
- Security Monitoring.
If the Client deviates from this baseline, Qteco's liability for the damage associated therewith lapses.
Article 8Cyber Incident Response
In the event of serious incidents, Qteco may take immediate measures, including:
- blocking accounts;
- isolating systems;
- disabling access;
- emergency patching.
insofar as necessary to limit damage. Qteco shall inform the Client as soon as possible of the measures taken.
Article 9NIS2 and Compliance
- If the Client is subject to NIS2 or comparable regulations, the Client remains ultimately responsible for compliance with the statutory obligations.
- Where agreed, Qteco provides support with technical measures and reporting.
Article 10Limitation of Liability
Cyber threats evolve continuously. Qteco therefore cannot guarantee absolute security against, among others:
- ransomware;
- phishing;
- zero-day exploits;
- supply-chain attacks;
- insider threats;
- advanced persistent threats (APTs).
unless otherwise agreed In Writing. The liability arrangement in the General Terms and Conditions applies mutatis mutandis to liability under this addendum.