HYPO.RAIL← Back to site

Legal centre · version 1.0

The operating agreement.

These Terms of Service and Privacy Notice explain how HYPO.RAIL is provided, how workspace data is handled, and the rights that remain yours under applicable law.

ProviderBURO OPS AS
Organisation number832 405 612 MVA
Registered addressUllevålsveien 12, 0171 Oslo, Norway

Effective 24 August 2026 · Applies to HYPO.RAIL

Terms of Service

1. Agreement and Service

These Terms are the agreement between you or the organisation you represent (the Customer) and BURO OPS AS, organisation number 832 405 612 MVA ("BURO OPS", "we", "us"), for HYPO.RAIL (the Service). If you use the Service for an organisation, you confirm that you have authority to accept these Terms for it.

HYPO.RAIL is a workspace for planning, recording and analysing controlled experiments and supporting evidence. It may work with third-party services through APIs, MCP clients or customer-authorised tools. We provide the Service as a tool; we do not act in a third-party account unless the Customer expressly initiates and authorises that action through its configured workflow.

2. Accounts and acceptable use

You must provide accurate account information, protect credentials, and promptly report suspected unauthorised access. Workspace owners are responsible for their users, permissions, connections and Customer Data. You must not use the Service to break the law, violate rights, upload malware, probe or disrupt the Service, bypass controls, submit unlawful or infringing material, or process personal data without the required lawful basis and notices.

Do not place secrets, payment-card data, special-category personal data, or children’s data in HYPO.RAIL unless you have separately confirmed suitability and put all legally required safeguards in place.

3. Customer Data

You retain ownership of Customer Data: data, content, experiment records, instructions and materials submitted by you or your users. You grant BURO OPS the limited rights necessary to host, secure, back up, operate, improve reliability, and support the Service under these Terms and the Privacy Notice. You are responsible for the data’s accuracy, legality, and any permissions, notices, consents or other lawful bases needed to use it.

Results, analysis and recommendations are information and decision support, not legal, financial, medical, employment or other professional advice.

4. Privacy roles and third parties

For Customer Data containing personal data processed on a Customer’s documented instructions, the Customer is normally the controller and BURO OPS the processor. The parties must enter into an Article 28 GDPR-compliant data processing agreement where required. For account administration, billing, security, support and our website, BURO OPS is controller as described below.

Third-party services, their availability, permissions, content, terms and data handling remain the responsibility of their providers and the Customer. Enable an integration only when authorised. We are not responsible for a third-party service or action taken under credentials you provide or authorise.

5. Fees and subscription

Paid plans, seats, fees and billing intervals are shown before checkout. By subscribing, you authorise recurring charges for the selected plan and allocated seats until cancellation. You may manage cancellation and seat changes through Settings → Billing; cancellation takes effect at the end of the current paid period unless mandatory law requires otherwise. Fees are payable in advance and non-refundable except where law or a written order says otherwise. Applicable tax, including VAT, is handled as shown at checkout.

6. Security, suspension and termination

We use reasonable technical and organisational security measures, but no online service is completely secure or uninterrupted. We may modify, suspend or discontinue a feature when reasonably necessary for security, maintenance, legal compliance or operation. We may suspend access to protect the Service, investigate a suspected breach, stop unlawful activity, or comply with law; where practical, we will give notice and a reasonable opportunity to cure.

Either party may terminate for a material breach not cured within 30 days of written notice, unless it cannot be cured or faster action is needed. On termination, access ends and Customer Data is handled under the applicable retention and deletion terms. Export any data you need before access ends.

7. Intellectual property and liability

BURO OPS and its licensors own the Service, software, documentation, designs and brands, excluding Customer Data. During the subscription, we grant authorised users a limited, non-exclusive, non-transferable, non-sublicensable right to use the Service. You may not copy, rent, sell, reverse engineer or create a competing service from it except where mandatory law permits.

Nothing excludes liability that cannot lawfully be limited. Subject to that, neither party is liable for indirect or consequential losses, including lost profit, revenue, goodwill or data, except where caused by intentional misconduct or gross negligence to the extent Norwegian law does not permit the exclusion. BURO OPS’ aggregate liability in the 12 months before the event is limited to fees paid or payable for the Service in that period. This does not apply where unlawful.

8. Consumers, law and disputes

HYPO.RAIL is designed for professional and organisational use. If you are a consumer, mandatory consumer protections prevail over conflicting terms. Nothing limits rights under the Norwegian Digital Content Act (digitalytelsesloven), Right of Withdrawal Act (angrerettloven), or other mandatory law. Any loss of withdrawal rights for digital content or services requires the express consent and acknowledgement required by law; these Terms alone are not that consent.

These Terms are governed by Norwegian law. Courts in Oslo have jurisdiction for business disputes unless mandatory law provides otherwise. Consumers may use mandatory complaint and dispute-resolution rights, including the Norwegian Consumer Council (Forbrukerrådet) where relevant.

Effective 24 August 2026 · GDPR / Norwegian Personal Data Act

Privacy Notice

This notice explains how BURO OPS AS processes personal data when providing HYPO.RAIL. It does not replace a Customer’s own privacy notice for personal data the Customer controls.

1. Controller and contact

BURO OPS AS, Ullevålsveien 12, 0171 Oslo, Norway, org. no. 832 405 612 MVA, is controller for the processing described here. Contact hello@hyporail.com with “Privacy” in the subject to exercise a right or ask a question.

2. Data, purpose and basis

PurposeDataBasis
Accounts and workspacesName, email, password hash, organisation/workspace and role details, login/session recordsContract; legitimate interest in security
BillingBilling contact, plan, seats, invoices and payment status. Payment cards are handled by Stripe, not stored by HYPO.RAIL.Contract; accounting/tax duties
Service deliveryCustomer Data, experiment records, evidence, configurations and authorised integration resultsNormally processor on documented Customer instructions
Security and supportAccess logs, IP/device and event metadata, audit records, support messagesLegitimate interests; legal obligations where applicable
EnquiriesContact details and submitted messageConsent where requested; otherwise legitimate interest in replying

3. Processors, recipients and transfers

For personal data in Customer Data, the Customer normally determines the purposes and means. We process it only on documented instructions unless law requires otherwise and reasonably assist Customers where GDPR requires it and our agreement provides for it.

We disclose data only to authorised personnel and providers needed to operate the Service, such as hosting, infrastructure, email, support and payment providers, under appropriate contractual safeguards. If data is transferred outside the EEA, we use an applicable transfer mechanism, such as an adequacy decision or European Commission standard contractual clauses, and supplementary measures where required. Ask us for information relevant to your processing.

4. Retention and security

We keep account and workspace information while an account is active and after that only as necessary for operations, security, disputes, backups and legal duties. Billing and accounting records are retained for legally required periods. Customer Data is deleted or returned under the Customer agreement and operational backup cycles. Audit and security records may be retained longer where needed for incidents, rights or legal obligations. We do not retain personal data longer than necessary for its purpose.

We use measures designed to protect confidentiality, integrity and availability, including access controls, role permissions, credential controls, audit logging and appropriate safeguards in transit and at rest. You must protect account credentials and configure integrations carefully. We handle any personal-data breach under applicable law and notify affected Customers or individuals where required.

5. Your rights

Subject to GDPR conditions and limits, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where it is the basis, without affecting earlier processing. We may verify identity and normally respond without undue delay and within one month, subject to lawful extensions. You may complain to Datatilsynet or your local supervisory authority.

6. Cookies and children

HYPO.RAIL uses strictly necessary technologies, such as authentication and security cookies, to operate and protect accounts. We do not use advertising cookies in the Service. If we introduce non-essential analytics or marketing technologies, we will give notice and obtain consent where required. The Service is not directed to children; do not create an account or submit a child’s data without a valid lawful basis and all required authorisations.

Contact & complaints

For legal, privacy, billing or service questions, email hello@hyporail.com. Include your workspace name and enough detail to locate the issue, but do not send passwords, API keys or unnecessary sensitive information by email.

Postal address: BURO OPS AS, Ullevålsveien 12, 0171 Oslo, Norway. Organisation number: 832 405 612 MVA.

Changes

We may update these Terms or Privacy Notice when the Service, law or processing changes. For material changes, we will give reasonable advance notice through the Service or email where appropriate. The effective date identifies the current version. Continued use means acceptance only to the extent permitted by law; you may stop using the Service and cancel before a material change takes effect.

Important: This is HYPO.RAIL’s public legal baseline. Enterprise or regulated Customers may need a signed data processing agreement, security schedule or other written terms before processing sensitive or high-risk data.