General Terms of Use for Medical Institutions
Convenience translation. This English version of the terms of use for institutions is provided for convenience only and is not legally binding. Only the German version (Allgemeine Nutzungsbedingungen für medizinische Institutionen) is authoritative and governs the contractual relationship. In the event of any discrepancy or conflict between the German version and this English translation, the German version shall prevail.
Including an integrated data processing agreement pursuant to Article 28 GDPR
Last updated: 3 August 2026, 11:35 p.m. CEST
Part A. General Institutional Terms
1. Provider, Scope and Contractual Structure
1.1 These terms apply between CONUS Medical Solutions GmbH, Alte Ziegelei 2 - 4, 51491 Overath, Germany, registered in the commercial register of the Local Court of Cologne, HRB 110987, represented by the Managing Director Vincent Paffrath, hereinafter "CONUS", and the medical institution or educational institution that applies for or activates institutional use, hereinafter "Institution".
1.2 These terms do not apply to paid manufacturer licenses. Separate manufacturer license agreements apply to medical device manufacturers.
1.3 Natural persons use CONUS via personal user accounts and additionally accept the General Terms of Use for Users and the Medical Use and Safety Notice.
1.4 Individual agreements and separate service offers take precedence.
2. Conclusion of Contract and Authority to Represent
2.1 The institutional agreement is concluded as soon as a duly authorized representative accepts these terms including Part B and CONUS activates the institutional area.
2.2 The accepting person warrants that they are authorized to represent the Institution or to conclude the institutional agreement.
2.3 CONUS may request evidence of identity, function and authority to represent.
2.4 The respective accepted version, the point in time, the Institution and the accepting person are documented.
3. Subject Matter of Services and Intended Purpose
3.1 CONUS Basic provides a digital information, documentation and research platform for medical, scientific, product-related and institutional information.
3.2 Depending on activation, the Institution may in particular provide product portfolios, SOPs, internal contact persons, organizational information and further institutional content.
3.3 CONUS Intelligence may be available as an additional AI-supported information and research function.
3.4 CONUS does not define a medical purpose within the meaning of Article 2 number 1 of Regulation (EU) 2017/745. CONUS is not intended for patient-specific decisions on diagnosis, therapy, dosage, indication, contraindication or product selection.
3.5 CONUS does not replace any instructions for use, mandatory training, clinical approval, binding service instruction, SOP or independent professional decision.
3.6 An interface to hospital information systems, patient records or patient-managing systems is not part of regular institutional use.
4. Free Provision and Future Offers
4.1 CONUS Basic is currently provided to medical institutions free of charge within the respective activated scope.
4.2 The free provision does not entail any minimum usage, procurement volumes, product decisions, manufacturer preferences, reference calls or other operational consideration.
4.3 There is no entitlement to free provision for an unlimited period, to an unchanged scope of functions or to the permanent continuation of individual functions.
4.4 CONUS may change, restrict or discontinue free services with 30 days' notice. In the event of security risks, legal requirements, abuse, discontinuation of external services or unreasonable operating expense, a short-term or immediate change is permitted.
4.5 CONUS may offer the Institution a continuation or extension on paid terms. A payment obligation arises exclusively through express acceptance of a separate offer.
4.6 If the Institution does not accept a paid offer, the previous free service may be terminated at the announced time.
5. Institutional Administration and User Management
5.1 The Institution designates at least one administrator.
5.2 Administrators may invite users, assign roles, manage master data and view invitation and activation status.
5.3 The Institution is responsible for ensuring that invitations are sent only to authorized persons and that it has a sufficient legal basis for transmitting the contact details.
5.4 The Institution must remove or block authorizations without undue delay if a person is no longer authorized.
5.5 CONUS may block authorizations if specific security, legal or abuse risks exist.
5.6 A person-related evaluation of search terms, accessed content, prompts, AI responses, usage duration, work performance or behavior is not provided to the Institution in the regular product.
6. Obligations and Internal Responsibility of the Institution
6.1 The Institution ensures that CONUS is used exclusively in the intended information and research context.
6.2 The Institution informs its users of the prohibition on entering patient data and personal health data.
6.3 The Institution is responsible for the professional review, approval, versioning, currency and lawfulness of its institutional content.
6.4 The Institution ensures that uploaded content does not violate third-party rights, confidentiality obligations, data protection requirements or other statutory obligations.
6.5 The Institution is responsible for the necessary internal approvals, involvement of employee representatives, information security reviews and the definition of its internal usage rules.
6.6 The Institution cooperates appropriately in the investigation of security, data protection and legal violations.
7. Institutional Content and Rights of Use
7.1 The Institution remains the holder of its rights in SOPs, contact persons, organizational information and other institutional content.
7.2 For the duration of the contract, the Institution grants CONUS a simple, non-exclusive, royalty-free right, sublicensable to engaged processors, to store, reproduce, transmit, technically process, format, structure, tag, index, translate and summarize the institutional content to the extent necessary, to generate embeddings and search indexes and to make it accessible to authorized users of the Institution within the CONUS Software.
7.3 Institutional content is not used to train general proprietary or external AI models and is not used across institutions for responses to other institutions.
7.4 Technically privileged CONUS employees may only access content insofar as this is necessary for operation, security, maintenance, support, troubleshooting or statutory obligations. Access is limited by roles, confidentiality obligations and logging.
7.5 During the term of the contract, the Institution may export its content in a common format provided or reasonably supported by CONUS, insofar as the technical structure permits.
7.6 After the end of the contract, CONUS deletes institutional content from productive systems within 30 days. Backup copies are overwritten within 90 days at the latest, unless statutory obligations or legitimate evidentiary purposes preclude this.
8. Roles Under Data Protection Law
8.1 CONUS processes data of personal user accounts as well as authentication, security, billing, support and general platform data generally under its own responsibility under data protection law.
8.2 Insofar as CONUS processes institutional content, initial invitation data or other personal data exclusively in accordance with documented instructions and for the purposes of the Institution, CONUS acts as a processor.
8.3 Part B of these terms applies to this processing.
8.4 The Institution remains responsible for lawfulness, transparency, purpose specification, data minimization, accuracy and safeguarding data subject rights within its area of responsibility.
9. Usage Data, Statistics and Protection Against Employee Monitoring
9.1 CONUS may process usage and operating data under its own responsibility under data protection law for provision, security, abuse prevention, error analysis, product development and capacity planning.
9.2 CONUS may generate anonymized and sufficiently aggregated statistics from lawfully processed data and use them without time limit for product development, benchmarking, research, market analysis, sales planning, commercial evaluations and corporate communication.
9.3 Re-identification of persons or individual medical institutions is excluded.
9.4 Manufacturers do not receive any personal or institution-related usage data.
10. Manufacturer Financing, Product Content and Neutrality
10.1 CONUS is financed, among other things, by paid digital services for medical device manufacturers.
10.2 On the basis of a business relationship, manufacturers do not receive access to the Institution's product portfolio, individual employees, search queries, accessed content, AI histories or institution-related usage data.
10.3 Manufacturers do not receive any information about competitor products used in the respective facility.
10.4 Manufacturers cannot acquire preferential sorting of individual products through payments.
10.5 CONUS decides on presentation and search logic according to technical, editorial, content-related and user-related criteria.
10.6 Manufacturer information is made identifiable as such insofar as its origin is not already unambiguous. The presentation is not a recommendation and does not influence the Institution's procurement decisions.
10.7 Manufacturers cannot contact users directly via CONUS. General events may be presented on manufacturer pages. Targeted commercial messages require the necessary consent of the user concerned.
10.8 Following its own review, CONUS may communicate specific product-related safety information, recalls and field safety notices.
11. Availability, Maintenance and Support
11.1 Free institutional services are provided without any promised minimum availability, response time, recovery time or service level.
11.2 CONUS may carry out maintenance and restrict access in the event of disruptions, security risks, capacity limits, force majeure or failures of external service providers.
11.3 The Institution is responsible for suitable devices, operating systems, internet connections, device security and internal usage rules.
11.4 Support is provided according to available capacity unless a separate support agreement exists.
12. Reference Naming and Use of Name and Logo
12.1 By accepting these terms, the Institution grants CONUS, for the duration of the contract, a simple, geographically unrestricted and royalty-free right to use its name and logo exclusively for the factual designation as a participating or using institution.
12.2 The reference provision is displayed to the Institution separately and prominently during the acceptance process.
12.3 Use is permitted in particular in general customer, partner and reference lists, on the website, in presentations, pitch decks, sales documents and vis-à-vis business partners, financiers and investors.
12.4 The reference naming must not create the impression of a medical recommendation, exclusive partnership, product approval or support of individual manufacturers.
12.5 Independent press releases, campaigns, case studies, quotations or prominent social media communication require separate coordination.
12.6 The Institution may object to further reference naming at any time in text form. CONUS will discontinue use within a reasonable technical implementation period.
13. Confidentiality and Trade Secrets
13.1 Both parties treat non-public commercial, technical, organizational and institutional information as confidential.
13.2 Disclosure to employees, advisors, affiliated companies and service providers is permitted insofar as they require the information for the performance of the contract and are appropriately bound to confidentiality.
13.3 The intended display of institutional content to authorized users remains unaffected.
13.4 Statutory disclosure obligations remain unaffected. Where permissible, the other party is informed in advance.
13.5 The confidentiality obligation continues to apply after the end of the contract. For trade secrets, it applies as long as the statutory requirements for a trade secret exist.
14. Warranty and Professional Responsibility
14.1 CONUS provides the software as a platform.
14.2 CONUS assumes no professional responsibility for manufacturer content, institutional content, third-party sources or automatically generated AI outputs.
14.3 CONUS does not owe any professional review or approval of institutional SOPs and no monitoring of whether manufacturers have provided all changes, recalls or documents.
14.4 Mandatory statutory warranty rights for expressly agreed paid services remain unaffected.
15. Liability
15.1 CONUS is liable without limitation in cases of intent and gross negligence, for damages arising from injury to life, body or health, in the event of fraudulent concealment, for assumed guarantees and under mandatory statutory liability provisions.
15.2 In cases of simple negligence, CONUS is liable only for the breach of an essential contractual obligation. Liability is limited to the foreseeable damage typical for the contract.
15.3 For free services, liability in cases of simple negligence is additionally limited to EUR 10,000 per incident of damage and EUR 20,000 per contract year, insofar as this is legally permissible.
15.4 To the extent permitted by law, CONUS is not liable for professional decisions based on content that was unverified, used incorrectly or applied contrary to the intended purpose.
15.5 CONUS is not liable for the loss of institutional content insofar as the damage could have been avoided by appropriate backup or a reasonable export.
15.6 The limitations of liability also apply for the benefit of the officers, employees and vicarious agents of CONUS.
16. Indemnification
16.1 The Institution indemnifies CONUS against third-party claims based on a culpable breach of these terms by the Institution or its administrators.
16.2 This applies in particular to unauthorized invitations, unlawful institutional content, infringements of third-party rights, missing internal authorizations and the entry of patient data.
16.3 The indemnification covers reasonable costs of legal defense. CONUS informs the Institution and enables appropriate participation.
17. Term, Blocking and Termination
17.1 The contract runs for an indefinite period.
17.2 The Institution may terminate the free institutional use at any time in text form.
17.3 CONUS may terminate the free institutional use with 30 days' notice.
17.4 The right to immediate blocking or extraordinary termination for good cause remains unaffected.
17.5 Good cause exists in particular in the event of security risks, legal violations, unauthorized use, repeated entry of patient data, false eligibility information or unreasonable operating expense.
17.6 Personal user accounts may continue as individual accounts after the end of the institutional assignment, insofar as no institutional content or rights continue to exist.
18. Changes
18.1 CONUS may adapt these terms in the event of changes to laws, case law, administrative practice, technology, security requirements, functions or the business model.
18.2 Material changes are communicated at least 30 days before they take effect, unless a short-term change is necessary for legal or security-related reasons.
18.3 Insofar as express consent is required, CONUS will obtain it. CONUS may make the continuation of institutional use conditional on consent to the updated version.
18.4 Changes do not apply retroactively.
19. Choice of Law, Place of Jurisdiction and Final Provisions
19.1 German law applies, excluding the UN Convention on Contracts for the International Sale of Goods.
19.2 The exclusive place of jurisdiction is the registered office of CONUS, insofar as the Institution is a merchant, a legal entity under public law or a special fund under public law.
19.3 Should any provision be or become invalid, the remaining provisions remain effective. The statutory provision replaces the invalid provision.
Part B. Integrated Data Processing Agreement Pursuant to Article 28 GDPR
20. Subject Matter and Duration of the Processing
20.1 CONUS processes personal data on behalf of the Institution insofar as this is necessary for the storage, administration, indexing and provision of institutional content, for the management of initial invitations or for the provision of expressly agreed institutional functions.
20.2 The processing begins with the transmission of the relevant data and ends with its return, deletion or anonymization after the end of the contract.
21. Nature, Purpose and Scope
21.1 The processing comprises collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transmission to authorized users, restriction and erasure.
21.2 The purposes are the technical provision of the institutional area, role-based display, search, indexing, embeddings, support, security, maintenance and troubleshooting.
21.3 Processing for CONUS's own professional purposes or for cross-institutional model training does not take place.
22. Categories of Data Subjects and Data
22.1 Data subjects are in particular employees, agents, administrators and contact persons of the Institution.
22.2 Data types may include names, business e-mail addresses, roles, departments, institutional contact persons, invitation status and personal information contained in institutional documents.
22.3 Patient data and personal health data are not subject to the agreed processing and may not be transmitted.
23. Instructions
23.1 The documented instructions result from Part A, the use of the administration functions and supplementary instructions in text form.
23.2 CONUS informs the Institution if, in the opinion of CONUS, an instruction violates data protection law. CONUS may suspend execution until the matter is clarified.
23.3 Additional instructions going beyond the agreed scope of services may be remunerated according to effort.
24. Obligations of CONUS
24.1 CONUS processes commissioned data only on documented instruction, unless a statutory obligation exists.
24.2 CONUS obliges persons authorized to access the data to maintain confidentiality.
24.3 CONUS implements appropriate technical and organizational measures. These include in particular role and authorization concepts, encryption in transit, tenant separation, data backup, logging of privileged access, patch and vulnerability management and procedures for handling security incidents.
24.4 Taking into account the nature of the processing, CONUS supports the Institution with data subject requests, data protection impact assessments, consultations and notification obligations, insofar as the data concerned is processed within the Institution's area of responsibility.
24.5 CONUS informs the Institution without undue delay of a breach of the protection of commissioned data as soon as CONUS becomes aware of it and insofar as a notification obligation or a material risk may exist.
25. Sub-Processors
25.1 The Institution grants CONUS general authorization to engage sub-processors.
25.2 The current list of sub-processors results from the privacy policy or a current service provider list linked there.
25.3 CONUS informs about material changes. The Institution may object within 14 days for important reasons under data protection law.
25.4 If no reasonable solution can be found, CONUS may discontinue the function concerned or the Institution may terminate the institutional agreement.
25.5 CONUS contractually obliges sub-processors to at least the obligations required under Article 28 GDPR.
26. Transfers to Third Countries
26.1 Transfers outside the European Economic Area take place only if the requirements of Articles 44 et seq. GDPR are met.
26.2 CONUS uses in particular adequacy decisions, standard contractual clauses and the necessary supplementary technical and organizational protective measures.
26.3 Insofar as the Institution activates CONUS Intelligence with institutional content, content required for the requested processing may be processed by individual AI service providers named in the privacy policy outside the European Economic Area. Infrastructure and document services operated regionally within the European Union remain unaffected.
27. Evidence and Audits
27.1 Upon request, CONUS provides the Institution with appropriate information to demonstrate compliance. CONUS may use certifications, audit reports, TOM documentation and standardized information.
27.2 On-site audits are permitted only if document-based evidence is insufficient, there is a specific cause or a supervisory authority requires it.
27.3 Audits must be announced in good time, be limited to the necessary areas and must not unreasonably impair business operations, security interests, trade secrets and the rights of other customers.
27.4 The Institution bears the costs of audits without specific cause or going beyond the standard evidence, insofar as this is legally permissible.
28. Return and Deletion
28.1 After the end of the processing, CONUS deletes the commissioned data from productive systems within 30 days, unless a return has been agreed or statutory retention is required.
28.2 Backup copies are overwritten within 90 days at the latest. During the technical run-on period they are not used productively.
28.3 Anonymized data that no longer allows any reference to persons or institutions is not commissioned data and remains unaffected.
29. Responsibility of the Institution
29.1 The Institution is responsible for the lawfulness, transparency, purpose specification, data minimization and accuracy of the commissioned data.
29.2 The Institution ensures that no patient data is transmitted and that its administrators act lawfully.
29.3 The Institution informs CONUS without undue delay if it identifies an impermissible transmission or processing.