Legal
Terms of Service
Rules for using Modri collaborative sourcing memory (web app and Chrome extension).
§ 1. General Provisions
- These Terms and Conditions (hereinafter: the "Terms") set out the rules for using Modri (hereinafter: the "Application") and the services provided by the Provider.
- The Application is a professional tool that supports collaborative sourcing and prospecting workflows, in particular storing and organizing context about job applicants (candidates) and related recruiting activity across a team workspace, including via a Chrome browser extension on LinkedIn and Google Search.
- The Terms are the rules and regulations referred to in Article 8 of the Act of 18 July 2002 on the provision of services by electronic means (hereinafter: the "Electronic Services Act").
- The Application is owned by GC Ventures sp. z o.o. with its registered office in Kraków (Aleja Powstania Warszawskiego 15, 31-539 Kraków), KRS: 0001001861, NIP: 6751773409, REGON: 523642185, share capital PLN 5,000.00 paid in full (hereinafter: the "Provider").
- The Provider may be contacted by e-mail at: hello@modri.io.
- Within the scope of its activity, the Provider:
- provides Service Recipients and Users with account access to the Application;
- provides Service Recipients with Services within the Application (including the web app and, where available, the Chrome extension).
- The Service Recipient and the User must read the Terms before using the Application.
- Acceptance of the Terms constitutes acceptance of all conditions set out herein and a commitment to comply with them.
§ 2. Definitions
Capitalized terms used in the Terms have the following meanings:
- Service Recipient — an entrepreneur using the Services under these Terms, running a non-agricultural business activity on its own behalf.
- Account — a panel in the Application’s IT system enabling the User to use its functionalities.
- User — a person authorized to represent the Service Recipient and use the Application on their behalf (including workspace members).
- Terms — these Terms and Conditions.
- Service Agreement — the legal relationship between the Provider and the Service Recipient under which the Provider provides Services.
- Entrustment Regulations — Appendix 1 hereto, under which the Service Recipient (as controller) entrusts the Provider (as processor) with processing personal data of candidates, contacts, and other persons stored in a Workspace, to the extent needed to provide the Services.
- Civil Code — the Act of 23 April 1964 — the Civil Code.
- License — the license defined in § 7.
- Services — services provided by the Provider consisting in making the Application available and storing data entered by the Service Recipient or User in accordance with the Terms (including workspace, contacts, notes, activity, Boolean tools, and extension-assisted capture).
- Price list — pricing information published in the Application and/or at modri.io/pricing.
- Price offering — a commercial offer for using the Application (in particular per active seat / billing period).
- Provider — as defined in § 1(4).
- Electronic Services Act — as defined in § 1(3).
- Workspace — a team space in the Application where Users share sourcing memory under roles and entitlements configured by the Service Recipient.
- Chrome extension — the Modri browser extension for Chrome that overlays sourcing context on supported LinkedIn and Google Search pages when the User is signed in.
- Creem — Armitage Labs OÜ (and its affiliates), which acts as Merchant of Record for paid Services purchased through Creem checkout. Creem’s Buyer Terms of Service govern the payment transaction between the Service Recipient and Creem.
- Billing period — the prepaid interval selected for a subscription (monthly or annual), as shown on the Price list and at checkout.
- Active seat — an active Workspace member (including the owner) counted for subscription quantity.
§ 3. Technical Requirements
- To use the Services properly, the following are required jointly:
- a device with a screen;
- an Internet connection;
- a current version of a supported web browser (Chrome is required for the Chrome extension);
- an active e-mail address for Account access.
- Using viruses, bots, worms, or other harmful code, files, or programs (including unauthorized automation that violates third-party platform rules) in connection with the Application is prohibited.
- The Provider uses technical and organizational measures to protect electronic transmission and stored content (including TLS encryption and access controls). Absolute security of Internet services cannot be guaranteed.
- Despite those safeguards, using the Internet may involve malware or unauthorized access risks. The Provider recommends up-to-date security software and careful handling of credentials.
- The Provider decides which functions are available in the Application and may change functionality over time.
- Where the Application or parts of it are offered as early access, trial, or beta, the Provider does not guarantee the same stability as generally available paid Services. Trial and founding offers are described on the Price list or in the Application.
§ 4. General Principles of Service Provision
- The Service Recipient and the User must use the Services in accordance with applicable law, these Terms, and good practice.
- By creating an Account, the Service Recipient or User confirms that the data provided is accurate and will be updated as needed.
- The Service Recipient declares that use of the Service is professional and related to its business.
- Providing unlawful content is prohibited.
- The Service Recipient and the User must provide only data that is accurate. The Provider is not liable for consequences of false or incomplete data provided without a proper legal basis or required consents.
- The Service Recipient and the User are solely responsible for ensuring they have a lawful basis to use the Application and for providing any required information to persons whose personal data they process in connection with their use of the Services (in particular Articles 13 and 14 GDPR, where applicable).
- The Service Recipient is responsible for how it uses the Application in its recruiting processes and for compliance with third-party platform terms when using the web app or Chrome extension.
- The Provider may require evidence of authority to represent the Service Recipient. Acting without authority may trigger liability under the Civil Code.
- Notices under the Terms may be sent by e-mail unless a specific provision states otherwise.
- The Service Recipient or User may delete data they entered into the Application, subject to Workspace roles, retention required by law, and billing / audit constraints described in the Application.
§ 5. Service Agreement
- To conclude the Service Agreement it is necessary to:
- access the Application (including modri.io) and sign in or sign up:
- with e-mail and password, or
- via a third-party identity provider available on the sign-in screen (for example Google);
- where paid Services are used — complete checkout and pay fees in accordance with the Price list (or complete a trial / promotional path first).
- access the Application (including modri.io) and sign in or sign up:
- After an Account is created, the Service Recipient or User may complete profile and billing data to the extent provided by the Application (for example name, company name, address, VAT/NIP, e-mail).
- For paid Services, data required for invoicing is mandatory (including data requested at Creem checkout).
- Obtaining access to the Services constitutes conclusion of the Service Agreement between the Provider and the Service Recipient.
- With an Account, the Service Recipient / User may, in particular (depending on plan and entitlements):
- create and manage Workspaces and members;
- store and manage Workspace records and related activity entered by Users;
- use the Chrome extension to access Workspace features on supported pages;
- use forever-free tools (the Boolean builder, shared Boolean history, and local-only SERP visit timestamps in the extension);
- manage billing for paid Team seats.
- If Services are used unlawfully or in breach of the Terms, the Provider may terminate the Service Agreement with 7 (seven) days’ notice by e-mail. After the notice period the Account may be permanently deleted. During the notice period the Provider may block access where needed to stop further infringement.
- The Provider may verify Account data and refuse or suspend Service if data is incorrect.
§ 6. Payments, subscriptions, and Merchant of Record
- Paid Services are charged according to the Price list at modri.io/pricing (or the in-app billing screen). Current Team pricing is billed per Active seat, monthly or annually, as shown on the Price list.
- The Provider may grant early access, trials, founding codes, or other promotional arrangements.
- Forever-free tools (Boolean builder, shared Boolean history, and local SERP visit timestamps) do not by themselves include full Team collaborative features unless expressly stated. Their scope and limits are described in the Application or Price list.
- Trial. Where a free trial is offered, it is described in the Application. The current trial is 14 days of Team workspace access (collaborative profile memory), without a payment method. Message Stash stays limited to three personal templates until a paid plan is chosen. The trial clock starts when a User first saves a LinkedIn profile in the Workspace — not merely when an Account is created. If the Service Recipient chooses a paid plan before that first save, no trial starts. If the trial ends without a paid subscription, the Workspace becomes read-only as described in the Application. Saved Message Stash templates are not deleted.
- Merchant of Record. Paid subscriptions purchased through Creem checkout are sold by Creem as Merchant of Record (reseller). The Service Recipient buys the subscription from Creem; Creem collects payment, calculates and remits applicable VAT / sales tax / other indirect taxes, issues the invoice in its own name, and handles transaction refunds and chargebacks. Creem’s Buyer Terms govern the payment transaction (checkout, Customer Portal, invoices, taxes, and refunds processed by Creem). These Terms govern use of the Application and the Service Agreement with the Provider. If there is a conflict relating to the payment transaction, invoicing, taxes, or Creem checkout / Customer Portal, Creem’s Buyer Terms prevail for that subject matter.
- Completing Creem checkout constitutes acceptance of Creem’s Buyer Terms in addition to these Terms.
- After a trial ends (or when choosing a paid offering), the Service Recipient must select a Price offering and provide the billing / tax data requested at checkout if not already completed.
- Automatic renewal. Subscriptions renew automatically at the end of each Billing period (monthly or annual) until cancelled in accordance with this § 6. The Service Recipient authorises Creem to charge the then-current Price offering for the Active seat quantity at each renewal, plus applicable taxes displayed at checkout or on the invoice.
- Annual plans. An annual Price offering is prepaid for twelve (12) months. It is a commitment for that Billing period. Cancelling an annual subscription stops the next renewal; it does not end access early and does not create a right to a pro-rata refund of the prepaid year, except where mandatory law or Creem’s Buyer Terms require otherwise.
- Cancellation. The Workspace owner may cancel a subscription:
- from the Application (Settings → Billing — cancel at period end); and/or
- through the Creem Customer Portal (invoices, payment method, and subscription management). Cancellation takes effect at the end of the then-current paid Billing period. The Workspace stays fully usable until that period ends. The owner may undo cancellation in the Application before the period ends, where that option is offered. After the paid period ends, the Workspace becomes read-only until a new plan is chosen.
- Seats and proration. Checkout and renewals are charged for the current number of Active seats. If a new member takes the Workspace above the quantity already paid for the period, the extra seat is charged immediately for the remaining days of that period. If a member is removed, they lose access immediately; the next renewal is lower. There is no credit or refund for unused days of a removed seat in the current period. Seat quantity follows the net number of Active members once billing has caught up with Creem, as described in the Application.
- Failed payment. A failed renewal does not lock the Workspace immediately. The team may keep working while the owner updates the payment method in the Creem Customer Portal. If payment is not recovered, the Workspace becomes read-only. A full refund or a payment dispute makes the Workspace read-only right away; a partial refund does not.
- Refunds. Except where mandatory law or Creem’s Buyer Terms require otherwise, fees are non-refundable, including for unused time after cancellation, unused seats, downgrades, or non-use of the Services. Refunds that are processed are handled by Creem as Merchant of Record.
- Payment date (Creem). For purchases through Creem, payment is complete when Creem confirms the transaction. Payout from Creem to the Provider is a separate matter and does not determine whether the Service Recipient has paid.
- In individual cases, with the Provider’s prior consent, payment may be handled outside Creem (for example a manual invoice). In that case the Provider issues the invoice, the Service Recipient agrees to receive it electronically, and — unless otherwise stated on the invoice — amounts are due within 7 days of receipt. For those invoices only, the payment date is the date the Provider’s account is credited.
- Prices are shown as communicated on the Price list and at checkout (tax treatment as indicated there or on the Creem / Provider invoice).
- Price list changes are published in the Application / on the pricing page. A change does not alter fees already paid for a Billing period that started before publication. A Price list change is not automatically an amendment of these Terms. Renewals after publication are charged at the then-current Price list unless a different rate was agreed in writing.
§ 7. License
- Upon conclusion of the Service Agreement, the Provider grants the Service Recipient / User a non-exclusive license to use the Application under these Terms (the "License").
- The License lasts for the term of the Service Agreement.
- The License allows access to the Application and use of available functions (including installing and using the Chrome extension for the licensed Account).
- The License does not include the right to sublicense.
- Use of the Services in breach of the License may constitute infringement of the Provider’s rights and may lead to legal action.
§ 8. Personal Data and the Entrustment Regulations
- To provide the Services in line with data-protection law, the Provider processes personal data entrusted by the Service Recipient, and the Service Recipient entrusts that processing, under the Entrustment Regulations (Appendix 1). Those regulations form an integral part of the Terms and are the Article 28 GDPR processing agreement for Workspace candidate / contact content.
- The Entrustment Regulations apply for the duration of the Service Agreement and end when that agreement ends, subject to deletion / return duties in Appendix 1.
- Independently of the above, the Provider processes data of Service Recipients and Users as controller, as described in the Privacy Policy. That Account / User data is not entrusted data under Appendix 1.
§ 9. Provider's Intellectual Property
- All components of the Application — including its name, logos, graphics, interface, software, documentation, and databases — are protected under applicable intellectual property and unfair competition law (including Polish and EU law).
- Any use of the Provider’s intellectual property without prior express permission is prohibited, except as allowed by the License or mandatory law.
§ 10. Complaints about the Services
- The Service Recipient or User may lodge a complaint if the Provider provides Services inconsistently with the Terms.
- Complaints should be sent by e-mail to the address in § 1(5) and include:
- company name / name and surname;
- e-mail address;
- description of the issue;
- the request.
- The Provider responds within 30 (thirty) days of receiving a complete complaint. Failure to respond within that period means the complaint is accepted.
- The Provider responds by e-mail.
- The response to the complaint is final as between the parties for that complaint procedure (without prejudice to mandatory consumer rights where they apply).
- Payment, invoice, tax, and refund issues for Creem checkout should be raised first with the Provider at the address in § 1(5). If unresolved, they may also be raised with Creem under Creem’s Buyer Terms (Customer Portal or creem.io/contact).
§ 11. Provider's Liability
- The Provider provides the Services with due diligence.
- The Provider aims for continuous availability of paid Services, but does not commit to a service-level agreement (including any minimum monthly uptime) unless a separate written agreement or a specific paid plan expressly states otherwise. Temporary suspension for maintenance, upgrades, expansion, or circumstances beyond the Provider’s control may occur.
- Where practicable, scheduled maintenance will be announced in advance.
- The Provider is not liable for:
- inability to provide Services for reasons beyond its control (including force majeure or third-party acts, including LinkedIn, Google, hosting, or payment providers);
- lost profits of the Service Recipient;
- consequences of improper use of the Services, including use contrary to the Terms, platform rules of LinkedIn/Google, or good practice;
- damage from incorrect, incomplete, or false data entered by the Service Recipient or User;
- interruptions due to maintenance works.
- To the extent permitted by law, the Provider’s total liability toward the Service Recipient / User is limited to the fees paid by the Service Recipient for the last 3 (three) payment periods preceding the event giving rise to liability.
§ 12. Amendments to the Terms and Account Functionality
- The Provider may amend the Terms, for example when:
- the Provider’s business changes;
- Services are added, modified, or discontinued;
- technical changes require adaptation of the Terms;
- law requires changes;
- another justified reason requires an update.
- The Service Recipient / User is informed of amendments by publication of the new Terms in the Application / on the website.
- For planned changes, notice will be given at least 14 days before the new Terms take effect, where required.
- If the Service Recipient does not accept the new Terms, they may terminate the Service Agreement within 7 days of notice, by e-mail to the Provider or by registered letter to the Provider’s registered address. The Agreement then ends on the last day of the month in which the Provider received the notice. Prepaid fees for time after that date are handled under § 6 (and Creem’s Buyer Terms where the subscription was purchased through Creem).
- The Provider may change Account / Application functionality during the Agreement and will inform Users of material changes as appropriate.
§ 13. Final Provisions
- These Terms are governed by Polish law. Disputes shall be resolved by Polish courts of competent venue, unless mandatory law provides otherwise. This does not affect Creem’s Buyer Terms, which have their own governing-law and forum clauses for the payment transaction with Creem.
- The current version of the Terms is effective as of 17.08.2026.
Appendix No. 1 — Entrustment of the processing of personal data
(Article 28 GDPR processing agreement, modelled on the Commission’s controller–processor standard contractual clauses)
§ A1. General Provisions
- These regulations (the "Entrustment Regulations") define the terms on which the Service Recipient (the "Controller") entrusts personal data stored in a Workspace to the Provider (the "Processor") for the purpose of providing the Services.
- Providing the Services requires the Processor to process personal data within the meaning of Regulation (EU) 2016/679 (GDPR), giving rise to Article 28 GDPR obligations.
- These Entrustment Regulations constitute the written contract referred to in Article 28(3) GDPR. They are intended to cover the mandatory elements of that provision and are modelled on Commission Implementing Decision (EU) 2021/915 (standard contractual clauses between controllers and processors).
- Matters not regulated here are governed by the Terms. In case of conflict on a data-protection matter covered by Article 28 GDPR, these Entrustment Regulations prevail over the rest of the Terms.
- Capitalized terms have the meaning given in the Terms or GDPR unless stated otherwise.
§ A2. Roles and entrustment
- The Controller entrusts the Processor with processing personal data under Article 28 GDPR, within the scope of § A3.
- The Controller represents that it is the controller of the entrusted data, or a processor authorized to further entrust it to the Processor (in which case the Controller warrants that the original controller has authorized this further processing).
- Account, authentication, billing, and similar User data of Service Recipients and Users are processed by the Provider as controller under the Privacy Policy and are outside the subject matter of these Entrustment Regulations.
- Workspace candidate / contact content (and other content the Controller stores in a Workspace about third persons) is processed by the Provider as processor under these Entrustment Regulations.
§ A3. Subject matter, nature, purpose, and duration
- Entrusted personal data are processed by the Processor only on the Controller’s documented instructions and solely to provide the Services. Conclusion of the Service Agreement, configuration and ordinary use of the Application (including the Chrome extension) by the Controller’s Users, and these Entrustment Regulations are deemed documented instructions. Additional instructions may be given in writing (including e-mail).
- The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other Union or Member State data-protection provisions. The Processor is not obliged to provide legal advice.
- Description of the processing:
| Subject matter | Hosting and operation of Modri (web Application and Chrome extension) so the Controller can store and share sourcing memory in a Workspace |
| Nature of processing | Collection (as instructed via the Application / extension), recording, organisation, storage, retrieval, consultation, use, alignment, restriction, erasure, and disclosure by transmission to authorised Users of the Controller; including automated processing in IT systems |
| Purpose | Providing the Services — collaborative sourcing memory for the Controller’s recruiting / sourcing workflows |
| Duration | For the term of the Service Agreement, then deletion or return in accordance with § A12 |
| Location | Systems of the Processor and authorised sub-processors, including the Chrome extension acting as a client of the Application when a User is signed in |
- The entrusted data are personal data that the Controller or its Users store in a Workspace in the course of using the Services. Data subjects are the persons to whom that data relates. The Processor does not determine which data are stored; that follows from the Controller’s use of the Application. Further operational detail is set out in the Privacy Policy.
- Entrusted data under this Appendix are not intended to include special categories under Article 9 GDPR or data relating to criminal convictions under Article 10 GDPR. The Controller must not instruct the Processor to process such data in the Application and must not enter it.
- Processing is carried out using IT systems (including automated means) and may involve the Chrome extension as a client of the Application when the User is signed in.
§ A4. Security of processing
- The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks for data subjects (Article 32 GDPR).
- Those measures include, as a minimum:
- encryption of personal data in transit (TLS);
- access control, authentication, and authorisation (including workspace-scoped access / row-level security in the database);
- restriction of personnel access on a least-privilege, need-to-know basis;
- confidentiality undertakings for persons authorised to process the data;
- logging of security-relevant events;
- measures provided by infrastructure sub-processors for encryption at rest, backup, and availability.
- The Processor may update measures provided the overall security level is not reduced.
§ A5. Confidentiality
- The Processor shall ensure that persons authorised to process the entrusted data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- That obligation continues after the end of the engagement of those persons and after these Entrustment Regulations end.
§ A6. Assistance to the Controller
- Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising data-subject rights under Chapter III GDPR.
- The Processor shall, taking into account the nature of processing and the information available to it, assist the Controller in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification to the supervisory authority and to data subjects, data-protection impact assessment, and prior consultation).
- If a data subject addresses the Processor directly in relation to entrusted data, the Processor shall not respond (other than to redirect the request) unless the Controller has instructed it to do so or Union or Member State law requires otherwise. The Processor shall notify the Controller of the request without undue delay.
§ A7. Personal data breach
- The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting entrusted data, and where feasible within 24 hours of becoming aware.
- The notification shall include, to the extent then known: the nature of the breach; categories and approximate number of data subjects and records concerned; likely consequences; measures taken or proposed; and a contact point. The Processor shall provide further information as it becomes available.
- The Processor shall also notify the Controller without undue delay of:
- a legally binding disclosure request from a public authority concerning entrusted data, unless notification is legally prohibited;
- material supervisory-authority actions concerning the entrusted data.
§ A8. Documentation and compliance
- The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to confidentiality and security constraints.
§ A9. Sub-processors
- The Controller grants the Processor general written authorisation to engage sub-processors insofar as this is necessary to deliver the Services (in particular hosting, database, and related infrastructure).
- The Processor shall impose on each sub-processor data-protection obligations no less protective than those in these Entrustment Regulations, insofar as applicable to the subcontracted processing, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Where a sub-processor fails to fulfil its data-protection obligations, the Processor remains fully liable to the Controller for the performance of that sub-processor’s obligations.
- The Processor shall maintain an up-to-date list of material sub-processors in the Privacy Policy and/or on request at hello@modri.io.
- The Processor shall inform the Controller in writing (including by e-mail or by updating the list and notifying the Controller) of any intended addition or replacement of a sub-processor at least 14 days in advance, so the Controller may object. The Controller may object on reasonable data-protection grounds by written notice within 14 days of being informed.
- If the Controller objects and the parties cannot resolve the objection within 14 days, the Controller may terminate the Service Agreement with effect from the end of the then-current Billing period (or immediately if continuing would, in the Controller’s reasonable view, infringe data-protection law). Prepaid fees are handled under § 6 of the Terms.
- If a sub-processor must be replaced urgently for security or continuity reasons, the Processor may do so and shall inform the Controller without undue delay. The Controller’s right to object under section 4 then applies from that notice.
- Engaging a sub-processor in accordance with this § A9 is not an amendment of these Entrustment Regulations.
§ A10. International transfers
- The Processor shall not transfer entrusted data to a third country or an international organisation unless:
- the Controller has instructed or authorised it (including by agreeing these Entrustment Regulations and the sub-processor list);
- the transfer is covered by an adequacy decision under Article 45 GDPR, appropriate safeguards under Article 46 GDPR (including Standard Contractual Clauses), or a derogation under Article 49 GDPR; and
- the transfer is necessary to provide the Services.
- Further information on transfers is set out in the Privacy Policy.
§ A11. Controller’s obligations
- The Controller must maintain a lawful basis to process and entrust the data throughout the Service Agreement and must stop entrusting data for which the basis or entitlement is lost.
- The Controller is responsible for providing information to data subjects (Articles 13 and 14 GDPR) and for handling data-subject requests, with the Processor’s assistance under § A6.
- The Controller must not instruct processing that would violate law, these Entrustment Regulations, or other contractual obligations, and must not enter Article 9 or Article 10 GDPR data into the Application.
§ A12. Term, deletion, and return
- These Entrustment Regulations last for the duration of the Service Agreement and end when that agreement ends, without prejudice to duties that by their nature continue (including confidentiality, deletion, and audit of the deletion).
- At the choice of the Controller — exercised in the Application where that option is offered, or by written request — the Processor shall, within 14 business days after the Service Agreement ends, delete or return all entrusted personal data and delete existing copies, except where Union or Member State law requires storage.
- The Processor shall, on written request, confirm deletion in writing.
§ A13. Liability
If a party breaches these Entrustment Regulations, the GDPR, or other applicable law and causes damage to the other party, liability is limited to actual damage (excluding lost profits), to the extent permitted by law and subject to § 11 of the Terms. This does not limit liability that cannot be limited under GDPR or mandatory law (including Article 82 GDPR as regards data subjects).
§ A14. Amendments
§ 12 of the Terms applies accordingly to amendments of these Entrustment Regulations.