This text is drafted in full and describes how the platform works today. It is awaiting final review and sign-off by the company and its legal advisers, so its wording may still change before the version adopted as definitive. While this notice is showing, the page is not indexed and must not be submitted for external review.
Terms of Service
Language: English Español
Acceptance of terms
These Terms govern access to and use of M1M (the “platform”), a dashboard for operating AI agents provided by MARTINUKA2220, SOCIEDAD LIMITADA (“Martinuka2220, S.L.”), Spanish tax ID B72816911, with registered offices at Carretera de Miñano Mayor s/n, Etxabarri-Ibiña, Álava (01196), Vitoria-Gasteiz, Spain, registered at the Registro Mercantil de Álava, volume 1757, folio 8, sheet VI-21090, entry 1 (“M1M”, “we”, “us”).
Three names, one party responsible. M1M is an application created from Hutrit, and Hutrit is the trading name under which Martinuka2220, S.L. operates: that is why that name appears in our contact address and attached to the computing services that run the application. The party that answers legally towards you is Martinuka2220, S.L., the company identified above, and it is the party you contract with when you accept these Terms.
By creating an account, accessing or using the platform you accept these Terms in full. If you do not agree with any of them, do not use the platform.
If you accept these Terms on behalf of a company or organization, you represent that you have authority to bind it, and “you” refers to that organization. Whoever administers an organization’s account is responsible for ensuring that the people they grant access to comply with these Terms.
The Privacy Policy is an integral part of this agreement: by accepting these Terms you also accept how we process data as described there.
The platform is intended exclusively for people over 18 and is designed for professional or business use. It is not directed at minors.
If you are acting as a consumer. The previous version of these Terms declared that this “is not a consumer service”. We have removed that sentence, because it does not depend on us saying so: consumer status is determined by law from the actual purpose for which you use the service, and a prior waiver of the rights consumer law grants would be void. The platform is used today both by people working for companies and by self-employed professionals, so we state precisely what applies to whom:
- You are a consumer if you use the platform for a purpose outside your business or professional activity. Whether you are one depends on the use, not on the box you tick.
- A self-employed professional using the platform for their activity is not, as a general rule, a consumer, even when contracting in a personal capacity. If your use is mixed, the predominant purpose governs.
- If you are a consumer, your rights remain intact and no clause of these
Terms can cut them down. In particular, and we acknowledge this expressly here:
- Withdrawal: 14 calendar days. You may withdraw from this contract within 14 calendar days of entering into it, without giving a reason and without any penalty. Simply write to empresa@hutrit.com with an unequivocal statement that you are withdrawing — or use the standard withdrawal form set out in the law itself — and we will close your account. Since the service is free of charge today, there is no amount to refund and no charge for you to bear: withdrawal amounts to closing the account at no cost. If you contract a paid plan in the future, you will be informed of the right and its effects before contracting. We do not ask you to waive this right, not even where performance begins immediately.
- Governing law. Choosing Spanish law cannot deprive you of the protection afforded by the mandatory rules of your country of habitual residence.
- Jurisdiction. The courts of your own domicile will have jurisdiction, as stated under “Governing law and jurisdiction”.
- Notices. The deemed-receipt rule described in that same section does not apply to you: our communications will take effect when you can effectively access them.
- Automatic renewal and liability limits. They will not be enforceable against you to the extent consumer law does not allow.
- Whatever your status, closing your account is always free and you may do it whenever you wish, as set out under “Suspension and termination”.
Service description
M1M is a dashboard from which an organization can create, configure, operate and supervise AI agents: chat with them, delegate tasks, schedule recurring work, organize projects and files, connect them to third-party applications and measure their usage and cost.
What this means, plainly:
- The AI models are not ours. The platform sends your instructions to the model provider you configure for each agent and returns its response. Which providers are involved and what each one receives is set out in the Privacy Policy.
- A model’s answers are probabilistic and can be wrong. We do not warrant that they are accurate, complete, current or fit for any particular purpose. You must not rely on them as legal, medical, tax, financial or any other professional advice, nor make decisions with significant legal or financial effects without human supervision.
- An agent acts with the access you give it. If you connect an application to it, it will be able to read from or write to that application within the scope you authorized. You decide that scope and you are responsible for what the agent does with it.
- Anything not described here falls outside the service. In particular, we do not operate the third-party services you connect, we do not guarantee any business outcome, and we do not provide consulting services absent a separate written agreement.
The service evolves: we add, change and retire features as described under “Availability and changes”.
Prices, billing and taxes. The platform is provided free of charge today: we charge nothing for access and issue no invoices for its use. Free of charge does not mean free of cost, and you should know this before you start: most model providers run on an account and a key that you supply, so that model usage is billed to you directly by the provider, at its own rates and under its own contract with you. We play no part in that charge, we do not collect it and we do not pass it on.
What follows are the default terms that will govern only if you contract a paid plan in the future, and only from that moment. The fee will then be the one agreed with your organization in the order, proposal or plan contracted, and that document will prevail over this section as regards price, term and payment method. Unless stated otherwise: prices are quoted exclusive of taxes, and VAT and any other applicable tax will be added; billing is in advance for each period; payment terms are 30 days from the invoice date; contracted periods renew automatically for equal periods unless either party gives notice to the contrary 30 days before expiry — if you contract as a consumer, that renewal will only operate as far as consumer law allows; and amounts already accrued are non-refundable unless the law requires otherwise. We may change prices for renewal periods on at least 30 days’ notice; if you do not accept the new price, you may choose not to renew. Non-payment may lead to suspension of the service under “Suspension and termination”.
Accounts and authorized access
Access to the platform is restricted to authorized accounts. There is no open public sign-up: an account can only be created if the email address is already on the authorized access list, either because your organization requested it or because we invited you. We may decline any access request without having to state a reason.
About your account:
- The information you provide when registering must be truthful and kept up to date.
- You can sign in two ways, and they do not offer the same level of verification: (a) federated sign-in, with your Google or Microsoft account, which requires resolving the second authentication factor that provider asks for; or (b) classic sign-in, with your platform email and password plus your 32-character personal access token. To be precise: that token is an additional credential, but it does not constitute a second factor in the strict sense, and the classic route does not require two-step verification. Two-step verification is mandatory for the platform’s administration accounts.
- Anti-downgrade protection. If your account has ever used federated sign-in, the platform rejects classic sign-in for that account, so that nobody can lower your level of verification by falling back to the password.
- Your credentials — the platform’s or those of the identity provider you use — are personal and non-transferable: do not share them, do not reuse them on other services, and do not let a third party use your account.
- You are responsible for all activity carried out with your credentials, including that of the agents you operate with them, unless you can show unauthorized use not attributable to you.
- If you suspect that your account or any of your credentials has been compromised, tell us immediately at empresa@hutrit.com.
- In an organization account, the administrator can grant and withdraw access to members of their team and can see the activity of that organization’s agents. It is the organization’s responsibility to inform its team of this.
Acceptable use
You undertake to use the platform in accordance with the law and with these Terms. In particular, the following is not permitted:
- Using the platform or its agents for unlawful, fraudulent or deceptive activities, or to infringe third-party rights (intellectual property, privacy, reputation, data protection).
- Generating or distributing harmful content: malware, phishing, spam, harassment, discriminatory material, child sexual abuse material, or content designed to impersonate a real person or organization.
- Attempting to access data, agents or conversations belonging to another organization, or circumventing the platform’s isolation, authentication, permission or usage-limit controls.
- Reverse-engineering the platform or subjecting it to load testing, vulnerability scanning or intrusion testing without our prior written consent.
- Reselling, sublicensing or granting access to the platform to third parties outside your organization without our consent.
- Deliberately entering special categories of personal data (Art. 9 GDPR: health, ethnic origin, political opinions, religion, sexual orientation, biometrics) or data relating to criminal convictions and offences, without a valid legal basis and without having signed the appropriate processing agreement with us.
That last prohibition deserves an honest clarification: it refers to data you deliberately enter. A source you connect — a calendar holding medical appointments, a document repository — may incidentally contain data of those categories, without either you or us having entered it, and prohibiting that would be unrealistic. What we ask in that case is that you weigh whether the connection is appropriate for your activity and that you take particular care when choosing that agent’s model provider, in line with the next point.
Responsible vulnerability disclosure. The prohibition on subjecting the platform to scanning or intrusion testing without authorization is not meant to stop you telling us about a security flaw, and we do not want anyone to stay quiet about one for fear of that clause. If you believe you have found one, write to empresa@hutrit.com with “Security” in the subject line and the information needed to reproduce it. In return we ask three things: that you do not access another organization’s data beyond what is strictly needed to demonstrate the flaw, that you do not disclose it publicly while we work on fixing it, and that you neither degrade nor interrupt the service. We will acknowledge receipt of your report and will not take legal action against anyone researching in good faith who abides by these conditions.
You also accept that:
-
You are responsible for the instructions you give your agents and for their consequences. Supervise irreversible actions in particular (sending messages, deleting or modifying files, executing payments or operations in third-party systems).
-
You are responsible for regulatory compliance in your own activity. With respect to the personal data you enter or that your agents process on your behalf, you act as the controller and we act as the processor. Art. 28 GDPR requires that processing to be set out in a written contract and today we have none signed with any customer: we are preparing it so it can be incorporated into these documents. If your organization needs it signed sooner, write to us at empresa@hutrit.com and we will sort it out with you.
-
Protection of content coming from connected applications. If you connect a Google application to an agent, or any other source holding confidential content or third-party personal data, you must configure that agent with a model provider that offers a contractual no-training guarantee. So that the obligation is determinate rather than an empty formula, the providers meeting it as at the date of these Terms are:
- Anthropic (Claude models), under its commercial API terms;
- Google, in its enterprise AI service (Gemini models contracted by us for the platform).
We will keep this list up to date in the Privacy Policy and will tell you if it changes. Practical effect, put plainly: since the platform works by default with credentials you supply, connecting Gmail, Drive or Calendar to an agent leaves very few admissible providers for that agent — today, the two above. You must not route that content through model aggregators or through provider accounts you supply that do not offer such a guarantee.
-
Instructions hidden in content (prompt injection). An agent reading documents, web pages or messages from the channels you connect may come across text written by a third party that contains instructions aimed at the agent itself — a document asking it to send something to an address or delete a file, for instance. A language model cannot reliably tell the content it is meant to process from an instruction embedded inside it: this is a risk inherent to the technology, not a defect we can remove. Before connecting an agent to a source that receives third-party content, weigh that risk, grant the narrowest scope that works and require human supervision for irreversible actions. How liability is allocated in this case is set out under “Limitation of liability”.
-
When an agent acts towards third parties, it acts on your account. The messages it sends — today an agent does not send email to third parties: that is a planned feature and not yet live, but that text can leave through any other channel you connect — the events it creates and the operations it performs in outside systems are carried out with your credentials and in your name: to the recipient, you are the sender and the author, and you answer for their content and their effects as if you had done it personally. An agent does not represent us and has no power to bind us: it cannot issue statements, offers or commitments on our behalf, and nothing it writes binds us. If you are going to let an agent communicate with third parties or act on outside systems, make sure you hold the necessary authorization and that you comply with the rules applicable to that communication.
-
Transparency of AI-generated content. Agents generate synthetic text that can reach people who do not know they are reading something produced by an AI: today an agent does not send email to third parties — that is a planned feature and not yet live — but that text does leave through any channel you connect. The platform embeds no automatic machine-readable marking of that content; while it does not, it is you who must tell the recipient when a communication comes from an agent and that is not obvious. Regulation (EU) 2024/1689 (the AI Act) imposes transparency obligations on this content, on its own application timetable and with an allocation of roles that depends on your use case; we will tell you when the platform adds that marking.
Content and intellectual property
What is yours stays yours. You retain all rights to the content you put into the platform (instructions, files, data, configuration) and to the results your agents generate from it, to the extent those results are capable of protection.
To deliver the service we need a minimal licence: you grant us a non-exclusive, royalty-free and limited licence to store, transmit, process and display your content, and to transmit it to the providers strictly necessary to carry out the operation you requested. This licence is granted solely to deliver the service to you and never covers using your content to train or improve AI models of our own. It terminates over each item when you delete it, and over all your content when the relationship ends — save to the extent strictly necessary to keep it and hand it over to you until it is deleted under the Privacy Policy — and without prejudice to any residue that may survive in backups until those are overwritten.
What is ours stays ours. The platform, its software, design and documentation belong to us or to our licensors. On the names it is worth being exact, because claiming more would simply be false: neither “M1M” nor “Hutrit” is registered, either as a trade mark or as a trade name. They are unregistered trading names of Martinuka2220, S.L., whose only registration is that of the company itself at the Registro Mercantil de Álava. We claim no registered trade mark rights over those names — only whatever may arise from their use and protection against unfair competition. These Terms grant you no rights over any of the above beyond using the service.
On AI-generated results: they may be neither original nor exclusive — another user with similar instructions may obtain similar results — and their legal protection varies from country to country. Before putting them to commercial use, check that they do not infringe third-party rights.
If you send us suggestions, ideas or feedback about the product, we may use them freely and without compensation to improve the platform. This permission covers the idea, not your content: if to illustrate a suggestion you attach a conversation, a file or personal data, that remains work content and is governed by the Privacy Policy, not by this paragraph.
Third-party services you connect
The platform lets you connect external applications and services so your agents can work with them. When you do:
- You also accept that third party’s terms and privacy policy. Your relationship is with them, not with us.
- We neither operate nor control those services. We are not liable for their availability, their security, changes to their interfaces or the content they return. If a third party changes or withdraws its service, the connection may stop working and we cannot prevent it.
- You authorize a specific scope and can revoke it at any time, both from the platform and from your account with the provider itself. Some of those permissions are, by the provider’s own design, broader than the specific task you give the agent; the real scope of each one and what we do with it are set out in the Privacy Policy.
- You must be entitled to connect that account. If the account or the data belongs to your organization or to a third party, you are responsible for having the necessary authorization.
Google data. For Google applications the following declaration also applies, which we reproduce in its official wording:
“The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.”
Details of which Google data we request, what it is used for and what we never do with it are set out in the Privacy Policy.
Availability and changes
We work to keep the platform continuously available and to ship improvements without interrupting your operation, but the service is provided “as is” and “as available”. Unless we have signed a separate service level agreement with you, we do not commit to a specific availability percentage.
- Maintenance. Where foreseeable work may affect the service, we will give reasonable advance notice through the usual channels.
- Service evolution. We may add, modify or retire features. If a material change significantly disadvantages you, we will give 30 days’ notice wherever possible.
- Usage limits. We apply usage limits and quotas — including per-user consumption caps and automatic cut-offs on anomalous usage — to protect the stability of the service and your own budget. Reaching a limit may temporarily suspend agent execution.
- Changes to these Terms. We may amend them. We will notify you by email or through the platform at least 30 days in advance, unless the change is imposed by law or concerns security, in which case it may take effect immediately. If you keep using the platform after the effective date, we take it that you accept the new version; if you disagree, you may close your account at no cost.
Limitation of liability
To the fullest extent permitted by Spanish law:
- We are not liable for indirect damages, loss of profit, loss of business, loss of opportunity, reputational harm, or loss or corruption of data not directly attributable to us.
- We are not liable for decisions you make based on a model’s output, nor for actions an agent performs following your instructions or those of the people you have granted access to. This extends to actions an agent performs on the basis of instructions embedded by a third party in content you gave it access to (prompt injection): the risk is inherent to this technology, it materializes within the scope you granted, and we warn you about it expressly under “Acceptable use”. What this exclusion does not cover is harm caused by our wilful misconduct or gross negligence, or liability arising from data protection law, in line with the final paragraph of this section.
- We are not liable for the third-party services you connect, nor for loss or alteration of data occurring within them.
- Cap. Our aggregate liability for any claim arising out of these Terms is limited to the amount actually paid by you in the twelve months preceding the triggering event or, if the service is provided to you free of charge, to one hundred euros (EUR 100).
These limits do not apply — and are not intended to apply — to wilful misconduct, gross negligence, damage to life or personal integrity, liability arising from data protection law, or any other case that the law does not allow to be excluded or limited. And if you are acting as a consumer, they apply only as far as consumer law allows, in line with “Acceptance of terms”.
You undertake to hold us harmless against third-party claims arising from use of the platform in breach of these Terms or of the law.
Suspension and termination
- By you. You may stop using the platform and request closure of your account at any time by writing to empresa@hutrit.com.
- Suspension by us. We may suspend access in whole or in part if we detect a security risk, a breach of these Terms, anomalous consumption, non-payment — only if you contract a paid plan in the future — or if a competent authority requires it. Except in urgent cases we will give advance notice and explain how to resolve it; we will restore access once the cause has ceased.
- Termination. We may terminate the agreement for serious or repeated breach not cured within a reasonable period, or on discontinuation of the service, in which case we will give at least 60 days’ notice.
- Effects. On closure of the account, access ceases and agents are stopped. Authorizations granted to third-party applications are not revoked by the closure on their own: you must revoke them yourself from the platform before closing the account and also withdraw the permission from your account with the provider — for Google, at myaccount.google.com/permissions. When we carry out the deletion of an account we delete those connections’ credentials from the secret store by hand, and if you can no longer sign in you can ask us to at empresa@hutrit.com. Content is not deleted merely by the closure either: its deletion is a process carried out on request, which we perform when you or your organization ask for it, on the terms of the Privacy Policy. You may request a copy of your content before closure and during the 30 days following it; after that period we will still honour the request, but we do not guarantee the format or the turnaround.
- Survival. The clauses on intellectual property, limitation of liability, indemnity, governing law and jurisdiction, and any other clause that by its nature should survive, remain in force after termination.
Governing law and jurisdiction
These Terms are governed by Spanish law, unless a mandatory rule provides otherwise — in particular, where you qualify as a consumer, this choice cannot deprive you of the protection afforded by the mandatory rules of your country of habitual residence.
For any dispute concerning their interpretation or performance, the parties submit to the Courts of Vitoria-Gasteiz (Álava, Spain), waiving any other forum that might apply, unless a mandatory rule provides otherwise — in particular, where the user qualifies as a consumer, the courts of their domicile will have jurisdiction.
If a court declares any clause void or unenforceable, the remaining Terms stay in force and that clause will be replaced by a valid one of equivalent effect.
Force majeure. Neither party will be liable for failing to perform its obligations — other than payment obligations already accrued — where this is due to causes beyond its reasonable control: natural disasters, armed conflict, acts of authority, widespread power or telecommunications outages, large-scale cyberattacks or prolonged failures of essential providers. The affected party will give notice without delay and will do what is reasonable to limit the impact.
Assignment. You may not assign these Terms or the rights arising from them without our prior written consent. We may assign them to a group company or to an acquirer in the context of a corporate transaction, maintaining the obligations assumed here and in the Privacy Policy, and giving you prior notice.
Notices. Ours will reach you by email at the address associated with your account or by a notice in the platform, and will be deemed received the day after they are sent. Yours should be addressed to empresa@hutrit.com. Keep your address up to date: a notice sent to an outdated address is deemed validly given. None of this applies if you are acting as a consumer: in that case our communications will take effect only when you can effectively access them, as set out under “Acceptance of terms”.
Entire agreement. These Terms, together with the Privacy Policy and, where applicable, the order or proposal signed with your organization, constitute the entire agreement between the parties on their subject matter and supersede any prior communication or agreement. In case of conflict, the signed order or proposal prevails first, then these Terms, and lastly the Privacy Policy — except on data protection matters, where the latter always prevails. Our failure to exercise a right at any time is not a waiver of that right.
These Terms are available in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version prevails.
Contact
For any matter relating to these Terms:
- Provider: MARTINUKA2220, SOCIEDAD LIMITADA (“Martinuka2220, S.L.”)
- Tax ID (CIF): B72816911
- Registered office: Carretera de Miñano Mayor s/n, Etxabarri-Ibiña, Álava (01196), Vitoria-Gasteiz, Spain
- Commercial Registry: Registro Mercantil de Álava (Portal de Castilla 7 bajo, 01005 Vitoria-Gasteiz), volume 1757, folio 8, sheet VI-21090, entry 1
- Phone: +34 640296736
- Email: empresa@hutrit.com