Skip to content
Get to know alluvo

Modules

  • Product All modules at a glance
  • Sales Find clients, maintain contacts
  • Recruiting Win and hire applicants
  • Staffing & Contracts Shift plan, contracts, portal
  • People & Time Employee record, hours, employee app
  • Payroll Salaries and bank details
  • Invoicing Invoices and dunning
  • Controlling Contribution margin and forecasts
  • Service & Inbox Tickets, team inboxes, web chat

Platform

  • Apps Client portal, time tracking and more
  • Integrations Microsoft 365, Google Workspace, Claude and more

AI & automation

  • alluvo operator The AI plugin: 81 tools on request
  • Free AI plugin Set it up in Claude and ChatGPT
  • alluvo agents Agent Studio, skills, runs
  • Self enhancement Gets better every day. On its own.
  • alluvo and Claude Why it is not either-or
  • Second Brain The memory of your business

Compliance & security

  • Security The leash, the guardrails, GDPR
  • GDPR & data protection Hosting, rights, AI, evidence
Pricing Changelog About us
Start for free

Modules

  • Product
  • Sales
  • Recruiting
  • Staffing & Contracts
  • People & Time
  • Payroll
  • Invoicing
  • Controlling
  • Service & Inbox

Platform

  • Apps
  • Integrations

AI & automation

  • alluvo operator
  • Free AI plugin
  • alluvo agents
  • Self enhancement
  • alluvo and Claude
  • Second Brain

Compliance & security

  • Security
  • GDPR & data protection
  • Pricing
  • Changelog
  • About us
Get to know alluvo

Legal

  • Imprint
  • Privacy
  • Terms of use

On this page

  • 1Scope
  • 2Subject matter of the contract
  • 3Registration and access
  • 4Beta status
  • 5Your obligations
  • 6Prices and fees
  • 7Availability and changes
  • 8Data protection and data processing
  • 9Liability
  • 10Term and termination
  • 11Final provisions
  • A1Data processing agreement
  • A2Technical and organisational measures
  • A3Sub-processors

Terms

Terms of use

The German version is the binding one. You can find the German original here.

These terms of use govern how you use the platform alluvo as a business customer or invited beta participant. This English text is a reading version. The German version is legally binding.

Version 2 — as of: 1. Oktober 2026

1. Scope

These terms of use apply to the use of the website, the platform and the related services of alluvo. The provider is OpsAgent UG (haftungsbeschränkt), Clausewitzstr. 21, 42389 Wuppertal.

The offering is aimed exclusively at businesses within the meaning of § 14 of the German Civil Code (BGB) and at organisations and professional users. It is not offered to consumers.

2. Subject matter of the contract

alluvo provides a software platform for collaboration in employee management. This may include in particular functions for communication, coordination of assignments and requests, documentation, approvals, organisational data, operational control and AI-supported assistance.

The specific scope of services follows from the product state activated for you, the current beta phase or individual agreements with the customer.

3. Registration and access

Use of protected areas requires registration or an invitation. When registering you provide complete and correct information and keep it up to date.

You treat your access credentials as confidential. You are responsible for all activity through your account, insofar as you are answerable for it.

4. Beta status

Note: This section is currently being revised.

alluvo may be provided in whole or in part as an early private beta. In this phase features may be changed, restricted, extended or removed. There is no entitlement to a particular scope of features or to uninterrupted availability.

We may use feedback from using the beta to develop the product further. Your rights to your content and data remain unaffected.

5. Your obligations

You use alluvo only within the framework of the applicable laws, these terms of use and any contractual agreements. In particular, you will

  • not post unlawful, misleading or abusive content,
  • not gain unauthorised access to data or accounts,
  • only process data for whose use there is a legal basis,
  • maintain appropriate internal permission and security structures.

6. Prices and fees

The amounts are on the pricing page. The amounts shown there at the time of contract conclusion or at the last renewal apply, unless agreed otherwise. All prices are plus statutory VAT.

6.1 Price per employee on assignment

You pay a price per calendar month for each employee on assignment. An employee on assignment is someone who was on a running assignment at one of your clients on at least one day in the billing month. The price includes all modules and features of the platform. Employees on the bench, candidates, users and storage cost nothing, and there is no minimum.

For departed employees who no longer receive pay and whose record you leave archived in alluvo, we charge the archive price of the pricing page per month.

6.2 Payment method and billing

You pay monthly or yearly. With monthly payment we bill every month in arrears. With annual payment you pay the employees on assignment twelve months in advance at the start of the term, at the annual price. If employees on assignment are added during the term, we bill them afterwards for the months in which they are on assignment, likewise at the annual price.

You pay by invoice. On request we collect the amounts by SEPA direct debit. We do not charge a dunning fee.

6.3 Onboarding

Onboarding comprises setup, migration of your existing data and training of your team. With annual payment it is free. With monthly payment we charge it once, at the price of the pricing page, with the first invoice.

6.4 Credits

Every employee on assignment brings the number of credits stated on the pricing page into a shared pool of your company each month. Credits apply when agents take over work: every result of an agent costs a fixed number of credits as stated on the pricing page. Agents you build yourself consume credits according to the tokens actually processed. Workflows, contracts, invoices, dunning, shift plans and other automations without agents are free; if a workflow calls an agent, its result costs credits.

Credits are valid for three months from being credited and expire afterwards. If the pool is not enough, you buy more credits in packs at the price of the pricing page. Consumption that the pool does not cover at month end we bill with the monthly invoice, rounded up to whole packs. Your contract is not upgraded as a result.

6.5 Included in the price

Support, training, webinars with recordings, form adjustments and data recovery are included in the price. Via API, MCP server and CLI, requests up to the number per day stated on the pricing page are included.

Ads and other paid reach with third parties, such as on Meta or on job boards, you book and pay directly with the respective provider, through your own account or your own contract. We do not bill these costs. alluvo supports you with management, for example steering and evaluating campaigns.

6.6 Price changes

During a running paid term we do not change your price. We announce a price change at least 60 days in advance, by an email you cannot unsubscribe from and with a notice in alluvo.

With annual payment the new price applies from the next renewal, with monthly payment from the first full billing month after the notice period has expired. On renewal you pay at most the list price shown on the pricing page at that time. If you do not agree to the change, you can terminate at the point at which it would take effect.

6.7 Individual agreements

Individual agreements take precedence over these rules. This includes the switching offer: employees on assignment whom you bring along when switching from another provider cost nothing until the end of your term there, if we have agreed this with you. For the duration of the early private beta, access may be free of charge.

7. Availability and changes

We strive for high availability of the platform. However, uninterrupted use at all times cannot be guaranteed technically.

We are entitled to adjust features, user interfaces, technical structures and processes insofar as this serves further development, security, stability or legal requirements and is reasonable for you.

8. Data protection and data processing

The processing of personal data follows our privacy policy and, where applicable, separate agreements on processing on behalf.

Insofar as you process personal data of third parties in alluvo, you are responsible for the lawfulness of this processing within your area of responsibility.

The processing of personal data on behalf takes place on the basis of the data processing agreement in Annex 1, which forms part of these terms of use. Separate signature is not required; Art. 28 (9) GDPR expressly permits the electronic format.

If you want to file the data processing agreement, including Annex 2 (technical and organisational measures) and Annex 3 (sub-processors), for your records of processing, you will find it here as a closed document: data processing agreement as PDF.

9. Liability

We are liable without limitation for intent, gross negligence and for damage from injury to life, body or health.

In the case of slightly negligent breach of material contractual obligations we are only liable for the typical, foreseeable damage. Otherwise liability is excluded, insofar as legally permissible.

We accept no warranty for failures or restrictions of third-party providers, interfaces or external services over which we have no influence.

10. Term and termination

With monthly payment the contract runs for an indefinite period. Either side can terminate it at the end of any calendar month.

With annual payment the contract runs for twelve months and renews each time for a further twelve months unless either side terminates it with one month's notice to the end of the term. Termination in text form, for example by email, is sufficient.

Without a paid contract, for example in the early private beta, the use relationship runs for an indefinite period and can be ended by either side with reasonable notice.

The right to extraordinary termination for good cause remains unaffected. For us there is good cause in particular if you breach material obligations of these terms.

11. Final provisions

German law applies, excluding the UN Convention on Contracts for the International Sale of Goods. The place of jurisdiction, insofar as legally permissible, is Wuppertal.

Should individual provisions of these terms of use be or become invalid, the validity of the remaining provisions remains unaffected.

We reserve the right to change these terms of use insofar as this is necessary for a factual reason. We will inform you of material changes in good time. For price changes, 6.6 applies.

Annex 1: Data Processing Agreement (DPA) pursuant to Art. 28 GDPR

Version 1.0 — as of: September 2026

This annex governs the processing of personal data on behalf of the controller pursuant to Art. 28 GDPR. The principal and controller under data protection law is the customer; the processor is OpsAgent UG (haftungsbeschränkt) as the operator of alluvo. The provisions of this annex take precedence over the other provisions of these Terms of Use insofar as they concern processing on behalf. This English text is a reading version; the German version is legally binding.

The annex comes into being with the use relationship and does not require separate signature; Art. 28 (9) GDPR expressly permits the electronic format. We provide a version ready for signature on request at gdpr@alluvo.ai.

1. Subject matter and duration of the processing

The subject matter of the processing is the provision and operation of the alluvo platform for the controller. Processing begins with the provision of access and ends with the termination of the use relationship; the obligations to delete and return data under section 10 remain unaffected.

alluvo is multi-tenant software with which the controller maps the administration of its employees and its operating business. The scope of services includes in particular:

  • keeping master, contract and employment data of employees, including the associated documents;
  • planning of assignments, shifts and absences, and recording and approval of working hours;
  • management of clients, assignment sites and contacts, including framework and individual contracts;
  • applicant management and filling of open positions;
  • communication with employees, applicants and clients through the channels connected in the platform;
  • creation, dispatch and filing of documents and reports on the operating business;
  • AI-supported assistance for all of the above areas in accordance with section 2.

The term of this annex corresponds to the term of the use relationship. A separate termination of this annex is excluded for as long as the use relationship continues; without an effective agreement on processing on behalf, the platform could not be operated.

2. Nature and purpose of the processing

The processor processes personal data exclusively for the purpose of providing the contractually agreed services. Processing for its own purposes does not take place.

Nature of the processing operations. Collecting, recording, organising, structuring, storing, adapting, altering, retrieving, consulting, using, disclosing by transmission to the recipients designated by the controller, combining, restricting, erasing and destroying.

Purposes by functional area.

  • Employee administration: keeping the digital employee master file, mapping employment relationships, managing associated documents and evidence.
  • Assignment and time management: planning assignments and shifts, recording and approving working hours, managing absences.
  • Client and order management: maintaining clients and assignment sites, initiating and handling orders, preparing contracts and billing.
  • Applicant management: recording and processing applications, matching qualifications against open positions, communication in the application process.
  • Communication: sending and receiving messages by email, telephony and the connected messaging channels, documenting correspondence.
  • Documentation and reporting: generating documents, logging processes, reports on the controller's operating business.
  • Operation and security: provision, maintenance, error analysis, backup and protection of the platform.

Scope of AI-supported processing. To support the above purposes, the processor uses language models, in particular to read out and classify documents, to draft texts and replies, to convert speech to text, to search using vector embeddings and to develop proposals for planning and staffing. The providers used for this are named in Annex 3.

The following applies to this processing: the content transmitted is processed exclusively to provide the respective service and is not used to train the models of the providers used. Automated individual decision-making including profiling under Art. 22 GDPR does not take place; the results of AI-supported processing are proposals, and the controller decides on their implementation.

3. Categories of personal data

The following categories of data are the subject of the processing, insofar as the controller keeps them in the platform:

  • Master data: name, date and place of birth, nationality, address, gender, photo, personnel number.
  • Contact data: business and private telephone numbers, email addresses, details of emergency contacts.
  • Employment and contract data: start and end date, function and position, place of assignment, working time model, fixed terms, pay and surcharge data, bank details, social security and tax characteristics.
  • Qualification data: vocational qualifications, permits and driving licences, training and further education, instructions, professional experience.
  • Assignment, time and absence data: shift and assignment plans, recorded and approved working hours, vacation, leave and other absences including their type.
  • Application data: application documents, résumé details, status of the procedure and notes on the application process.
  • Communication content and documents: emails, messages, call notes and recordings, uploaded and generated documents, contract documents and certificates.
  • Usage and log data: user accounts, roles and permissions, login data, logs of access and changes.
  • Contract and billing data of the controller: contacts, terms, invoice and payment data.
  • Special categories of personal data under Art. 9 GDPR. The platform processes health data insofar as the controller keeps periods of incapacity for work or stores certificates of incapacity for work as a document. Details of a severe disability may also arise insofar as the controller keeps them to fulfil its obligations under employment law. The stricter measures under Annex 2, section 8 apply to this data.

4. Categories of data subjects

  • Employees of the controller, including temporary workers;
  • applicants;
  • contacts at clients, assignment sites and prospects;
  • contacts at suppliers and other business partners;
  • users of the platform on the controller's side;
  • other persons whose data the controller keeps in the platform in the course of its business, such as emergency contacts of employees.

5. Binding instructions

The processor processes personal data exclusively on documented instructions from the controller, including with regard to transfers to third countries, unless it is required to process by Union or Member State law. In that case it informs the controller of that legal requirement before processing, unless the law concerned prohibits this on important grounds of public interest.

Instructions are given in text form. The controller's use of the platform and the settings it makes count as instructions within the agreed scope of services. If the processor considers that an instruction infringes applicable data protection law, it informs the controller without undue delay and may suspend execution until confirmation.

6. Confidentiality

The processor only uses persons for processing who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The obligation continues after the activity ends.

Only persons who need this access to perform their tasks receive access to personal data.

7. Security of processing

The processor takes the technical and organisational measures required under Art. 32 GDPR to ensure a level of protection appropriate to the risk. The measures are subject to technical progress; the processor may adapt them as long as the agreed level of protection is not undercut. The measures are described in Annex 2.

8. Sub-processors

The controller grants the processor general authorisation to engage further processors. The sub-processors in use at the time of the conclusion of the contract are listed in Annex 3.

The processor obliges every sub-processor to a level of data protection corresponding to this annex and remains responsible to the controller for its services.

If the processor intends to engage or replace a sub-processor, it informs the controller in text form before the change in accordance with the procedure described in Annex 3. The controller may object to the change within the period stated there for an important reason under data protection law. If the objection cannot be resolved by an amicable solution, the controller has a special right of termination for the affected services.

9. Support for the controller

The processor supports the controller with appropriate technical and organisational measures in responding to requests from data subjects for access, rectification, erasure, restriction, data portability and objection. If a data subject contacts the processor directly, it forwards the request to the controller without undue delay.

It further supports the controller in complying with its obligations under Art. 32 to 36 GDPR, in particular regarding security of processing, data protection impact assessments and prior consultation with the supervisory authority, in each case taking into account the nature of the processing and the information available to it.

The processor reports personal data breaches to the controller without undue delay after becoming aware of them, and at the latest within 48 hours, and provides the information required for notification under Art. 33 GDPR.

10. Deletion and return

After completion of the services, the processor deletes all personal data or returns it at the controller's choice, unless there is a statutory obligation to store it. Existing copies are deleted insofar as the same exception does not apply.

Before final deletion the controller is given a reasonable period to export its data in a common format.

11. Evidence and audits

The processor makes available to the controller all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allows for audits, including inspections.

Evidence can be provided by current certifications, audit reports from recognised bodies or a suitable self-disclosure. On-site audits take place after timely notice, during normal business hours and without avoidable disruption to operations.

12. Order of precedence

In the event of conflicts between this annex and the other provisions of these Terms of Use, the provisions of this annex take precedence insofar as they concern the processing of personal data on behalf. In all other respects the Terms of Use remain unaffected.

Annex 2: Technical and organisational measures (TOMs)

Version 1.0 — as of: September 2026

This annex describes the measures under Art. 32 GDPR with which the processor ensures a level of protection appropriate to the risk.

1. Encryption

Transmission between end device and platform takes place exclusively over transport-encrypted connections in line with the state of the art (TLS). Unencrypted requests are redirected to the encrypted connection.

Databases, object storage and backups are kept encrypted at rest. Access credentials for connected services and users' security features are not stored in plain text; passwords are stored only as a hash using a recognised method.

2. Access control

Access to the platform requires a personal user account. In addition, two-step login using time-based one-time passwords is available, which the controller can make mandatory for its users.

Access to data is controlled through a role and permission concept. Permissions are assigned per role and limited to what the respective task requires. The controller assigns and withdraws the roles of its users itself.

Administrative access by the processor to the production environment is limited to a group of named persons, takes place through personal accounts and is logged.

3. Logging

Changes to personal data records are logged in an audit-proof way. The log records which user changed which value and when, and for this stores the time, the calling address and the access route used. The logs can be viewed by the controller.

4. Separation of tenant data

Each tenant receives its own database. Separation therefore does not rely on a marker within shared tables alone but takes place at the level of the data set itself; access across tenant boundaries is excluded by design. Derived stores such as caches and queues are also kept separate per tenant.

Test and development environments are separate from the production environment. Real personal data is not used there.

5. Backup and recoverability

The data set is backed up automatically and regularly. Backups are encrypted and retained for a defined period; restoration is described procedurally and tested. Backups are subject to the same access restrictions as the production data set.

6. Availability and resilience

Operation and storage take place in a data centre within the Federal Republic of Germany (Frankfurt am Main). Physical access to the data centres is the responsibility of the hosting provider, which is certified to recognised standards for this; corresponding audit reports are provided on request.

Availability and error states of the platform are monitored continuously. Incidents are handled under a defined procedure; security-relevant updates are applied promptly.

7. Procedure for review and evaluation

The effectiveness of the measures is reviewed and evaluated regularly and as occasion requires, in particular on significant changes to the platform, on engaging a new sub-processor and after a security-relevant incident. Changes to the measures must not undercut the agreed level of protection.

8. Additional measures for special categories

For data under Art. 9 GDPR, in particular periods of incapacity for work and stored certificates, the following also apply:

  • Access is limited to the roles that need it to perform their tasks; it is not granted by default with a general user role.
  • Access to stored certificates is logged separately.
  • Such documents are not transmitted to AI providers unless the requested function strictly requires it and the controller has triggered it.

Annex 3: Sub-processors

Version 1.0 — as of: September 2026

This annex lists the sub-processors in use. It is maintained continuously and reflects the current state.

1. Sub-processors in use

Company Purpose Registered office / place of processing
Amazon Web Services EMEA SARL Operation, storage and provision of the platform Luxembourg / Frankfurt am Main, Germany (region eu-central-1)
Anthropic PBC Language models for assistant, agent and knowledge functions San Francisco, USA / USA
OpenAI Ireland Ltd. Transcription, audio processing and vector embeddings for search Dublin, Ireland / USA
Twilio Ireland Limited Sending and receiving messages and telephony Dublin, Ireland / USA
LiveKit Inc. Real-time voice connections for telephony in the platform San Francisco, USA / USA
Vapi Labs Inc. Voice dialogue for automated telephone assistance San Francisco, USA / USA
Stripe Payments Europe Ltd. Processing of payments and billing Dublin, Ireland / EEA and USA

Stripe processes payment data in part as an independent controller under the regulatory requirements applicable to payment service providers. To that extent no processing on behalf takes place.

2. Interfaces to services of the controller

alluvo offers interfaces to third-party services, such as calendars, mailboxes, messaging channels, customer management or accounting systems. If the controller establishes such a connection, the processor transmits to that service the data required for the activated function. Without the connection no transmission takes place; when it is disconnected, it ends.

The provider of a service connected in this way is not a sub-processor within the meaning of this annex. It does not process on behalf of the processor but on the instructions of the controller, either as the controller's own processor or under its own responsibility. The transmission takes place as disclosure to a recipient designated by the controller under section 5 of Annex 1.

This gives the division of tasks: before activation the controller checks which permissions it grants, ensures the legal basis for the transmission and, where necessary, concludes its own agreement under Art. 28 GDPR with the provider. The processor transmits only what the activated function requires, keeps the existing connections visible in the platform settings and ends the transmission as soon as a connection is disconnected. It is not responsible for the processing by the connected service.

These services are therefore deliberately not listed in section 1. Their number is open and changes with every connection a controller establishes; a list would be incomplete on the day it is published and would assert a responsibility that the processor does not bear.

3. Transfers to third countries

Where a sub-processor processes personal data outside the European Economic Area, the processor bases the transfer on the instruments of Chapter V GDPR: on the adequacy decision on the EU-US Data Privacy Framework insofar as the recipient is certified there, otherwise on the standard contractual clauses under Art. 46 (2) (c) GDPR, supplemented by additional safeguards such as transport and storage encryption.

The processor demonstrates to the controller on request at gdpr@alluvo.ai which instrument applies to which sub-processor.

4. Procedure for changes

The processor informs the controller of the engagement or change of a sub-processor in text form before the change. The following procedure applies:

  • Channel of information. By email to the address for data protection matters stored by the controller in the account, supplemented by a notice in the platform. The controller keeps this address up to date.
  • Period until effective. The change takes effect at the earliest 30 days after the information.
  • Objection. The controller may object to the change in text form within 14 days after the information, for an important reason under data protection law.
  • Consequences of an objection. The parties first seek an amicable solution, for example through additional safeguards or by doing without the affected function. If none is reached within 30 days, the controller has a special right of termination for the affected services. Until it is resolved, the processor does not use the objected sub-processor for the controller, insofar as it can do so without giving up the service.

A change that is unavoidable to avert an immediate threat to the security or availability of the platform may take place immediately. In that case the processor informs the controller without undue delay afterwards; the right to object remains unaffected.

The AI-native platform for staffing agencies.

Pages

  • Product
  • Apps
  • Integrations
  • Staffing software
  • Guides
  • Blog
  • Pricing
  • Changelog
  • About us

Free tools

  • Assignment calculator
  • Billing rate calculator
  • Bench cost calculator
  • Payment term cash-flow calculator
  • Cost per hire calculator
  • Free DACH lead list
  • All tools

Legal

  • Imprint
  • Privacy
  • Terms of use

Contact

  • info@alluvo.ai
  • Get to know alluvo
  • Careers
Language: International · English
  • Deutschland · Deutsch
  • Österreich · Deutsch
  • Schweiz · Deutsch
  • Polska · Polski
  • France · Français
  • Italia · Italiano
  • International · English
© 2026 alluvo.
Imprint Privacy