General Terms and Conditions
of the crAIready Platform · codAIx GmbH · Version 3.10 · As at: 07.09.2026
Convenience translation. This English version is provided for information only. The German version is the legally binding one.
§ 1 Provider, scope of application and definitions
(1) The provider of the crAIready Platform is codAIx GmbH, c/o JULITH GmbH, Erlengasse 3, 8240 Thayngen, Switzerland, UID CHE-249.882.147, Commercial Register of the Canton of Schaffhausen (hereinafter “codAIx”).
(2) These General Terms and Conditions (“GTC”) apply to the use of the websites and services at craiready.com, craiready.ch, accounts.craiready.com, platform.craiready.ch, customer-specific tenant subdomains and any further domains designated by codAIx for crAIready.
(3) The standard offering is directed exclusively at businesses and legal entities under public law established in Germany or Switzerland. Businesses established in other countries cannot currently subscribe to the standard offering. Provision to affiliated companies or users established in the USA or Canada, as well as use of the Platform as a basis for meeting non-European regulatory requirements, require a prior express individual agreement in text form. Any subsequent opening to further countries is subject to the prior review of the contractual, tax and insurance-law requirements.
(4) Individually negotiated orders, service descriptions and service level agreements take precedence over these GTC. The Customer’s general terms and conditions of business or purchase do not apply, even if codAIx does not expressly object to them or performs services with knowledge of them; they become part of the contract only if codAIx expressly agrees to their application in text form. In all other respects, the order, the service description, these GTC and the data processing agreement (“DPA”) constitute the contract.
(5) “CRA” means Regulation (EU) 2024/2847 as amended from time to time. “AI Act” means Regulation (EU) 2024/1689 as amended from time to time.
(6) A “Product File” is the compliance record maintained in crAIready for a product with digital elements. Variants may be managed as a “Product Family” within one Product File if the manufacturer, intended purpose, core architecture, essential security features, support/update concept and CRA risk assessment are essentially the same. Where there are material differences, a separate Product File is required. The Customer documents and is responsible for the allocation.
(7) A project for an open-source software steward is priced in the same way as a Product File. Differing scopes of service and special obligations are set out in the order or in an individual agreement.
§ 2 Subject matter of the contract and delimitation of services
(1) codAIx provides crAIready as a web-based software-as-a-service platform for the structured support of CRA-related workflows. The specific scope of functions and use is determined by the selected plan and the service description.
(2) crAIready is a technical organisation and documentation tool. codAIx provides no legal, tax, certification or conformity advice and does not assume any manufacturer, importer, distributor, authorised representative, steward or authority function of the Customer. Content, calculations, classifications, deadline notices and draft documents must be reviewed and approved by the Customer from a technical and legal perspective.
(3) If the Customer requires technical support, it may contact codAIx. For legal questions, codAIx can, on request, put the Customer in touch with an independent law firm. codAIx does not promise any engagement, its acceptance, content, price or outcome.
(4) On-premise/self-hosted operation and a paid Quick Assessment are not part of the standard offering.
(5) crAIready supports CRA-related workflows for software products, embedded software and connected and IoT products. This includes in particular product set-up and product classification, SBOM and vulnerability management, documentation, roles and approvals, and the preparation of the required notifications and documents for the applicable conformity assessment route. The technical and legal review, the approvals and any legally required external conformity assessments remain with the responsible business or the competent external bodies. crAIready is neither a notified body nor a certification body.
§ 3 Provision, registration and Quick Check
(1) crAIready is provided on infrastructure operated by codAIx. Use requires internet access, a current browser and a user account.
(2) When registering and placing an order, the Customer provides complete and accurate information and keeps it up to date. Access credentials are personal, must be kept secret and must be protected against unauthorised use.
(3) The public Quick Check is a free, non-binding initial assessment without login. It does not replace the product-specific onboarding wizard on the Platform or any legal review.
(4) The public Quick Check is executed entirely on a rule-based basis in the browser. The individual answers entered are not transmitted to codAIx or the crAIready Platform and are not stored server-side. Technical server log data of the page request remain unaffected. After purchase, the Customer re-enters and confirms the product-specific information in the Platform’s onboarding wizard. Details are set out in the privacy policy.
(5) The contract is concluded when the Customer submits the product confirmation, accepts the linked GTC, enters into the DPA and codAIx accepts the order or activates access. The document version and the time of acceptance may be logged for evidentiary purposes.
§ 4 Logging, approvals and document status
(1) crAIready logs key processing and approval operations so that decisions and changes remain traceable. Product-related processing and approval logs are stored for the term of the contract and, after the end of the contract, are exported and deleted together with the other Customer data in accordance with the DPA. A complete capture of all technical system events, any particular technical immutability or a blanket ten-year retention is not owed.
(2) Reports, notifications, declarations and other documents generated by crAIready are drafts until their content has been reviewed and approved by the Customer. A “draft” marking may only be removed by an authorised user after review.
(3) The Customer is responsible for the accuracy, completeness, currency and approval of its inputs, decisions and documents.
§ 5 Roles and CRA responsibility
(1) The Platform supports the mapping of different economic operator and steward roles. codAIx does not undertake the legal classification of the Customer or its products.
(2) In particular, the Customer remains responsible for product classification, risk assessment, technical and organisational product measures, conformity assessment, CE marking, technical documentation, vulnerability handling, reporting and user information.
(3) crAIready can prepare deadlines, tasks and draft notifications. Notifications to authorities, ENISA or CSIRTs are made only after review and approval by the Customer; automatic or deadline-preserving transmission is not owed.
(4) For open-source software stewards, only the functions agreed in the individual service description apply. Full legal support under Article 24 CRA is not part of the standard plan.
§ 6 AI-assisted functions
(1) crAIready may offer local and selectable external AI functions for suggestions, structuring, triage and draft documents. Available providers and data flows are set out in the Platform and the privacy policy.
(2) AI outputs may be erroneous or incomplete. They are not binding decisions and must be reviewed by qualified persons. The Customer must not enter personal data, trade secrets or other confidential content unless this is necessary for the selected purpose and legally permissible.
(3) Where the Customer selects an external AI provider, this constitutes a documented instruction under the DPA, provided that codAIx processes the data on the Customer’s behalf.
§ 7 Permitted use and cooperation
(1) The Customer uses crAIready only lawfully, within the agreed scope and for its own business purposes. In particular, attacks, circumvention of protective measures, unauthorised access, resale of access and the processing of unlawful content are prohibited.
(2) The Customer designates authorised users, manages roles and revokes access without undue delay once it is no longer required. It maintains appropriate device, browser and access security.
(3) Special categories of personal data, criminal-offence data, production access credentials or secrets may only be entered after prior agreement and where an appropriate legal basis exists.
(4) The Customer informs codAIx without undue delay of suspected security incidents, abusive access and material malfunctions.
(5) crAIready must not be used as the sole or fully automated basis for legally or technically significant decisions, as a substitute for legally required examinations, or as a substitute for a required expert or legal assessment.
(6) crAIready is not a real-time control, protection, emergency or safety system and must not be used directly to control safety-critical installations, medical devices, vehicles, aviation systems, weapons, nuclear installations or comparable systems. Use for unlawful offensive cyber activities is prohibited. This restriction does not preclude the permissible documentation of CRA-relevant products from such sectors, provided that the Platform does not itself assume their operational safety function.
(7) Legally required external conformity assessments, approvals or certifications must not be replaced or circumvented by the use of crAIready. For important or critical products, the statutory evidence and procedural requirements of the applicable conformity assessment route additionally apply.
§ 8 Availability and support
(1) codAIx aims for a monthly availability of 99.5 %. This is a target value and not a binding service level. Excluded in particular are announced maintenance, force majeure, disruptions outside codAIx’s sphere of responsibility and outages caused by the Customer.
(2) For the Start, Build (“Aufbau”) and Scale (“Skalierung”) plans, support is offered Monday to Friday from 09:00 to 17:00 (local time at codAIx’s registered office), excluding local public holidays. Requests may be submitted at any time; they are processed during business hours according to urgency.
(3) In the Enterprise plan, extended service hours may be agreed individually. 24/7 on-call availability is not automatically included.
(4) On-call availability for events relevant under Article 14 CRA outside business hours is an additional service to be commissioned separately. Response times, reachability, the Customer’s cooperation, service limits and remuneration are agreed individually.
(5) Binding availability levels, response times, credits or other service levels apply exclusively where they are expressly set out in an individual agreement.
§ 9 Prices, currencies, taxes and payment
(1) The prices stated at the time of the order apply. All prices are net prices plus statutory taxes and duties.
(2) Customers established in Germany are invoiced in EUR; Customers established in Switzerland are invoiced in CHF. Unless otherwise stated in the offer, the numerical value of the respective plan price is the same in both currencies.
(3) The Customer provides complete and accurate information on its registered office, tax status and company, UID or VAT identification number. The tax treatment is governed by the applicable statutory rules. Where the Customer is required to withhold taxes, it provides the legal basis and evidence that can be used vis-à-vis the authorities.
(4) Payments may be processed via Stripe. Stripe processes payment data in accordance with its own data protection provisions and, where applicable, those governing processing on codAIx’s behalf; details are set out in the privacy policy.
(5) Recurring fees are due at the beginning of the respective billing period. Price changes take effect at the earliest for the next renewal period and are announced at least six weeks in advance; in the event of a material increase, the Customer may terminate the contract before the change takes effect.
§ 10 Term and termination
(1) Unless the order provides otherwise, the minimum term is twelve months and is renewed for successive periods of twelve months unless either party terminates with three months’ notice to the end of the term.
(2) The right to extraordinary termination for cause remains unaffected. Cause exists in particular in the event of substantial default in payment, serious abusive use or repeated material breach of contract after an unsuccessful warning.
(3) Notices of termination must be given in text form.
§ 11 Data export and deletion
(1) During the term of the contract, the Customer may export the data captured by the standard functions in the available formats.
(2) After the end of the contract, codAIx provides an appropriate export route for 30 days, unless access must be blocked for security reasons. Thereafter, Customer data is deleted or returned in accordance with the DPA. Statutory retention obligations remain unaffected.
(3) The CRA-related retention of technical documentation is the Customer’s responsibility. The Customer must secure the necessary exports in good time.
§ 12 Rights in software and content
(1) codAIx and its licensors retain all rights in the Platform, software, design, documentation, trade marks and templates. The Customer receives, for the term of the contract, a non-exclusive, non-transferable right of use within the agreed scope.
(2) Rights in the content uploaded by the Customer remain with the Customer. The Customer grants codAIx the rights required for operation, support, backup, export and processing in accordance with the contract.
(3) The Customer warrants that it holds the necessary rights in the content it uploads and that it does not thereby infringe any third-party rights.
§ 13 Data protection and processing on behalf of the Customer
(1) The processing of personal data is governed by the privacy policy and, to the extent that codAIx processes data on behalf of the Customer, by the DPA in the version incorporated at the time the contract is concluded.
(2) For the user account, contract, billing, abuse prevention and its own security logs, codAIx generally acts as controller. For personal content that the Customer processes in its Product File, codAIx generally acts as processor.
(3) The Customer is responsible for the lawfulness of its data processing, the legal bases, information provided to data subjects and instructions.
§ 14 Warranty
(1) codAIx warrants the provision of the Platform as agreed. Insignificant deviations, technically necessary adjustments and changes for security or legal compliance do not constitute a defect, provided that the purpose of the contract is not materially impaired.
(2) The Customer reports defects in a comprehensible manner and supports the error analysis. codAIx may, at its own discretion, remedy the defect or provide a reasonable workaround.
(3) No guarantee is given for CRA conformity, freedom from errors, completeness of legal information, official recognition or the outcome of external audits.
§ 15 Liability
(1) codAIx is liable without limitation in the event of intent and gross negligence, for injury to life, body or health, and under mandatory law.
(2) In the event of a slightly negligent breach of a material contractual obligation, liability is limited to the damage that is foreseeable and typical for this type of contract. Otherwise, liability for slight negligence is excluded to the extent permitted by law.
(3) To the extent that codAIx is liable under paragraph 2 for a slightly negligent breach of a material contractual obligation, liability for all damage caused in any one contract year is limited, in aggregate, to 100 % of the net fees paid or owed for the affected service in the twelve months preceding the event giving rise to the damage. If the contract has not yet been in existence for twelve months at that time, the net fee extrapolated to twelve months applies. The liability cap does not apply to the cases referred to in paragraph 1 or to the extent that mandatory law provides otherwise. Differing liability limits require an individual agreement.
(4) The standard offering does not include provision to affiliated companies or users established in the USA or Canada, nor any advice on or assurance of compliance with US or Canadian legal requirements. Deviations require a prior express individual agreement in text form. The limitation of the standard offering to Customers established in Germany and Switzerland pursuant to § 1 (3) remains unaffected.
(5) The limitations of liability apply accordingly in favour of codAIx’s corporate bodies, employees and vicarious agents.
§ 16 Confidentiality
(1) Both parties treat non-public technical, business and organisational information of the other party as confidential and use it solely for the performance of the contract.
(2) Excluded is information that is generally known, lawfully obtained from third parties, independently developed or required to be disclosed by law or official order.
(3) This obligation continues for five years after the end of the contract; trade secrets are protected for as long as they remain trade secrets.
§ 17 Changes to the service
(1) codAIx may further develop the Platform, adapt security measures and change functions, provided that the agreed principal purpose is preserved. Material adverse changes are announced in good time.
(2) Where a legal or security situation requires short-notice measures, codAIx may implement them without advance notice and informs the Customer appropriately.
§ 18 References and communication
(1) Any use of the Customer’s name, logo or trade marks as a reference requires the Customer’s prior consent.
(2) Contract-related communications may be sent to the e-mail address stored in the account. This does not entail a newsletter or voluntary advertising.
§ 19 Amendments to these GTC
(1) codAIx may amend these GTC for future contracts. Amendments to ongoing contracts are announced in text form at least six weeks in advance and apply only where a valid contractual basis exists or the Customer consents.
(2) Amendments affecting the scope of services, price, liability or material rights of the Customer do not become binding by silence alone, insofar as mandatory law or the individual agreement requires otherwise.
§ 20 Final provisions
(1) Swiss law applies, to the exclusion of the conflict-of-laws rules and the UN Convention on Contracts for the International Sale of Goods (CISG), unless mandatory law provides otherwise.
(2) The exclusive place of jurisdiction for merchants and legal entities under public law is Schaffhausen, Switzerland, to the extent permissible.
(3) Assignments by the Customer require codAIx’s prior consent; § 354a HGB (German Commercial Code) and mandatory law remain unaffected.
(4) Should individual provisions be or become invalid, the remainder of the contract remains valid. The invalid provision is replaced by the statutory provision.
Version 3.10 · As at: 07.09.2026 · codAIx GmbH, Thayngen (CH)