Skip to content
Unomed

Unomed® general terms and conditions

Unomed AG GTC — version 1.3, dated 3 February 2026. Non-binding translation — only the German version is legally binding.

1. Scope and order of precedence

1.1 These general terms and conditions (GTC) govern the use of the cloud-based services of Unomed AG (the provider) by business customers (the customer).

1.2 Terms of the customer that deviate from or add to these GTC apply only if the provider agrees to them in writing.

1.3 Order of precedence: (i) the individual quotation/order/main agreement, (ii) these GTC, (iii) the ABV (data processing agreement). On questions of data protection and commissioned data processing, the ABV takes precedence over these GTC in so far as it governs those matters; deviations in the main agreement or the quotation apply only if they are expressly designated as a deviation from the ABV and are permissible under data protection law.

2. Services and modules

2.1 The provider supplies software-as-a-service offerings, in particular (without limitation):

  • Unomed Basic & Pro (messenger, directory, cloud storage, free cloud PACS)
  • Cloud PACS including DICOM viewer, cloud connector and optionally integrable viewer extensions
  • ICD-10 coding (suggestions/support, transfer into practice software/PIS)
  • AI assistant (administrative support, experimental)
  • Voice-to-text (v2t) / Ambient (experimental)

2.2 The specific scope of services follows from the respective order/quotation, the activated package and the functions available in the platform.

2.3 The provider may develop and change its services (e.g. UI, workflows, technical components) provided the contractual purpose is not materially impaired.

2.4 Third-party services and components: where the provider integrates or resells services of third parties (e.g. certified viewer components, integrations, communication or infrastructure services), additional usage or licence terms of those third parties may apply. The customer takes note of them and complies with them in so far as this is necessary for use.

2.5 Availability and changes to third-party services: services of third parties may be changed, restricted or discontinued outside the provider's sphere of influence. To the extent permitted by law, the provider is not liable for disruptions or changes to such third-party services. The provider endeavours to make equivalent alternatives available where this is economically and technically reasonable.

2.6 Payment processing: payments are processed by an external payment service provider. The provider does not supply payment services; it merely provides the technical integration. The terms of the payment service provider may apply.

3. Medical use, diagnostic reading and third-party viewers

3.1 The Unomed platform and the DICOM viewer included by default (e.g. OHIF) are not intended for diagnostic reading or diagnosis and are not approved as diagnostic viewers.

3.2 If the customer requires diagnostic reading functions, it may obtain a certified diagnostic viewer from a third party separately. The provider may supply and technically integrate such a viewer as a reseller.

3.3 The respective third party, as manufacturer, is responsible for the intended purpose, conformity, certification, instructions for use, updates and vigilance obligations of the certified diagnostic viewer.

3.4 The provider does not render any medical service. The customer remains responsible for professional assessment and for compliance with the professional and regulatory obligations applicable to it. Output of AI, v2t, Ambient or coding functions is support only and must be reviewed by the customer on the merits. Such output is probabilistic support; the customer verifies it before any further use (in particular in documentation, coding or the patient record).

4. Test and experimental functions

4.1 Functions marked as experimental (in particular the AI assistant, v2t and Ambient) may vary in quality, availability and behaviour and may be adjusted or discontinued without notice.

4.2 Experimental functions do not give rise to any warranties or SLA.

5. Conclusion of the contract, access, organisations

5.1 A contract is concluded by (i) signing a quotation/main agreement, (ii) activation/ordering in the platform, or (iii) use of the services.

5.2 Certain modules (in particular cloud PACS/connector) require an organisation to be set up in the platform.

5.3 The customer may run several organisations. Additional organisations may trigger additional costs.

6. The customer's duties to cooperate

6.1 The customer provides in good time: the responsible contacts (clinical/IT), access to the necessary systems, the required DICOM and network parameters, network/firewall clearances, a stable internet connection and test cases/test studies in so far as these are needed for commissioning.

6.2 Third-party components and customer systems (e.g. modalities, DICOM licences, practice network/firewall, local IT including the devices on which the UCC runs, PIS, Swiss-MR or other integrations) are the customer's responsibility (maintenance, availability, operating system updates).

6.3 The customer is responsible for user administration, roles/permissions, accuracy of data, medical documentation and statutory retention obligations.

6.4 The customer ensures that there is a sufficient legal basis for processing patient data (in particular the necessary consent of the patients or a statutory permission) and that data subject rights and information obligations are fulfilled.

7. Permitted use and prohibited conduct

7.1 The customer uses the services only within the scope of the contract and in accordance with applicable law, in particular data protection law and obligations of professional secrecy.

7.2 The customer is prohibited from:

  • a) using the services unlawfully or infringing the rights of third parties;
  • b) circumventing security measures or accessing systems, accounts or data without authorisation;
  • c) distributing malicious code, malware, spam or other harmful content;
  • d) disrupting or overloading the services (e.g. by automated queries/scraping, mass uploads or circumvention of rate limits);
  • e) decompiling, disassembling or reverse engineering software or interfaces, unless mandatory law permits this;
  • f) carrying out penetration tests, vulnerability scans or similar security tests without the provider's prior written consent.

7.3 The customer is responsible for the content and data that it or its users place in or transmit through the platform (in particular messenger/uploads), and for addressing recipients correctly.

7.4 Security vulnerabilities and security-relevant incidents must be reported to the provider without delay at support@unomed.ch. The customer refrains from exploitation and public disclosure and agrees any disclosure with the provider in advance.

8. Accounts, organisations, admin rights and access security

8.1 Within each organisation the customer designates at least one person as org admin/owner. Vis-à-vis the provider, the org admin/owner is authorised to issue organisational and usage-related instructions within the organisation (e.g. user administration, roles, permissions, booking of modules/packages), unless the provider has objective grounds to doubt that authority.

8.2 The customer is responsible for administering users (creation, modification, blocking/deactivation), roles and permissions, and for offboarding employees and third parties (in particular on departure, change of role or change of function).

8.3 Access credentials must be kept confidential and must not be shared or made available to third parties. The customer ensures that its users use secure passwords and adequately protect their devices.

8.4 Where technically available and reasonable, the customer must activate MFA for org admins/owners and for users with elevated rights; otherwise MFA is recommended.

8.5 The customer informs the provider without delay of suspected or actual security incidents on the customer's side, in particular compromised credentials, unauthorised access, loss/theft of devices or other circumstances that may impair the security of accounts or data.

8.6 Actions carried out in the platform using valid credentials are deemed attributable to the customer or its users, unless the provider is responsible for those actions.

9. Prices and pricing basis

9.1 The prices set out on the provider's website under Pricing apply, unless a deviating quotation or individual agreement exists.

9.2 The provider may adjust prices with 30 days' notice with effect from the start of a new billing period. If the customer continues to use the services after the change takes effect, the new prices apply. If the customer does not accept them, it may terminate before the change takes effect.

9.3 All prices are in CHF and exclusive of VAT (where applicable). Any foreign taxes, duties, withholding taxes or reverse charge obligations are borne by the customer. Payments must be made without deduction; bank charges are at the customer's expense.

10. Billing, billing models, payment portal

10.1 The customer chooses a billing period in accordance with the platform or an individual agreement. The packages/modules activated in the platform or the quotation are decisive.

10.2 User-based billing: billing follows the contractually relevant number of users shown in the platform for the billing period.

10.3 Modules/add-ons and additional capacity: cloud PACS and further add-ons are billed as booked. Additional storage/tokens are billed according to the additional package booked or according to actual use.

10.4 Payment and payment portal: billing is automated through the integrated payment system. The customer registers a valid means of payment (e.g. credit card) and ensures that it remains valid and covered.

10.5 If a charge fails or the customer falls into default, the provider informs the customer. If payment is not made within a reasonable grace period, the provider may restrict or block access proportionately until all amounts due have been settled. Default interest under the OR (Swiss Code of Obligations) is reserved.

11. Term and termination

11.1 The contract enters into force upon signature or upon use/initial commissioning. Billing starts from commissioning or in accordance with the platform or an individual agreement.

11.2 The customer may terminate at any time in the payment portal. Termination takes effect at the end of the current billing period. No further periods are started thereafter. Access remains fully available until the end of the current period.

11.3 No refunds: refunds of fees already due or charged for billing periods rendered or started (including in part) are excluded to the extent permitted by law.

11.4 If termination through the payment portal is not possible for technical reasons, the customer may terminate by email to support@unomed.ch.

12. Support, maintenance, availability

12.1 Support and operation are provided on a best-effort basis in principle. There are no guaranteed response or recovery times unless agreed in writing. The provider endeavours to operate the services securely and stably.

12.2 Maintenance windows and temporary restrictions are permitted in so far as they are necessary for operation, security or further development. Maintenance is carried out outside usual practice hours where possible, or announced in advance where reasonable. Interruptions caused by disruptions at hosting or cloud providers lie outside the provider's sphere of influence; liability is excluded to the extent permitted by law.

12.3 Updates and local components: updates for cloud components are provided automatically. For locally operated components (e.g. cloud connector) the provider makes updates available for download or self-service. The customer is responsible for installing local updates as instructed. Where support from the provider is required (remote support or on-site attendance), it is charged on a time and materials basis at the current hourly rate.

13. Onboarding, integration, migration, training

13.1 Onboarding, integration (e.g. PIS/network/DICOM), maintenance, migrations and training are chargeable additional services in principle and are quoted and billed separately.

13.2 For such additional services the provider may call in external partners. Depending on what is agreed, the service is either (i) rendered and billed by the provider (where applicable with partner support) or (ii) rendered directly by a partner. In case (ii) the customer concludes the contract directly with the partner; the partner's prices and terms apply.

13.3 If an agreed additional service is postponed, cancelled or broken off at short notice, effort already incurred and non-cancellable third-party or partner costs may be charged.

14. Data, data security, data protection and hosting

14.1 The provider processes data in order to render the services and operate the platform. In so far as the provider processes personal data on behalf of the customer, in particular patient data, it does so as commissioned processing under the Swiss DSG (Federal Act on Data Protection, FADP).

14.2 The details of the commissioned processing (subject matter, duration, nature/purpose, categories of data, TOMs, sub-processors, notifications, duties to assist, etc.) are governed by the data processing agreement (ABV), which forms an integral part of the contractual relationship where patient data or other particularly sensitive personal data are processed.

14.3 In addition, a privacy policy of the provider may apply to its own processing (e.g. website, marketing, account administration); it is published on the website.

14.4 Hosting: data are hosted primarily in Switzerland. The use of sub-processors in Switzerland or in states with a comparable level of data protection is reserved; the details (including categories of sub-processors and any locations) are governed by the ABV.

14.5 The provider may engage sub-processors where necessary. The data protection requirements applying to sub-processors are set out in the ABV.

15. Backups and restoration

15.1 The provider creates backups for operational purposes and to support restoration after technical disruptions. The provider determines their scope and frequency at its own discretion.

15.2 Backups do not replace the customer's own backups and do not give rise to a claim to restoration in every individual case (e.g. where the customer deletes data inadvertently), to the extent permitted by law.

15.3 On request the provider may support the customer with local backup concepts/exports for a fee.

16. Data export, archiving obligations, end of contract, deletion

16.1 The customer is responsible for securing data at all times, and in particular before the end of the contract, using the export options provided. The provider does not guarantee that data will still be available after the end of the contract.

16.2 Archiving and retention obligations (in particular in healthcare) rest exclusively with the customer. The provider assumes no obligation to archive data long term unless expressly agreed in writing.

16.3 Once termination has taken effect and the billing period has expired, access to the platform is generally no longer possible. If the customer wishes to retain access and data storage, it must continue to book the corresponding packages/modules; termination is at the customer's own responsibility.

16.4 The provider will delete data within a reasonable period after the end of the contract. The customer has no claim to any particular retention period after the end of the contract.

16.5 After the end of the contract, deletion may be delayed for technical or organisational reasons. The provider may therefore hold data briefly, solely in order to wind up the contract. This gives rise to no obligation to retain or restore data; the data are not used for other purposes (in particular no AI training).

16.6 Data migration, provision of data beyond the standard export options and restorations are carried out only for a fee (separate quotation) and only in so far as technically possible.

16.7 Free package (e.g. Unomed Basic including PACS Free): after at least 9 months of inactivity (no login) the provider may delete data upon prior notification by email with 30 days' notice. During that period the provider enables the customer to export its data.

17. Rights in the software, rights of use, content

17.1 The software and trade mark rights remain with the provider or its licensors.

17.2 For the term of the contract the customer receives a non-exclusive, non-transferable, non-sublicensable right of use within the agreed scope.

17.3 The customer remains the owner of its content/data. It grants the provider the rights to process, transmit and store them that are necessary to render the services.

18. Open source

18.1 The services may contain open source components. The customer accepts the applicable open source licence terms.

18.2 The provider may make notices and licence texts available in the platform or as an annex/link (“open source notices”). In the event of a conflict, mandatory open source licence terms prevail.

19. Confidentiality, professional secrecy, auxiliary persons

19.1 Both parties treat information of the other party that is not publicly known as confidential.

19.2 In so far as patient data or other information subject to professional secrecy are processed in the course of rendering the services, the customer is responsible for ensuring that the provider and the persons it engages may be called in as auxiliary persons.

19.3 The provider obliges its employees and engaged third parties who may obtain access to such information in the course of performing the contract to observe confidentiality corresponding to professional secrecy and to the contractual obligations. Access takes place only in so far as this is necessary for operation, support, maintenance or contractually agreed additional services.

20. Use as a reference

The provider may name the customer (name/logo) as a reference. The customer may object at any time by email to support@unomed.ch.

21. Warranty

21.1 The provider renders the services with the care customary in the industry, but does not owe any particular result.

21.2 Warranties as to quality and title are excluded to the extent permitted by law. In particular, no assurance is given of uninterrupted availability or freedom from defects. For third-party software and services the respective terms of the third-party providers apply; the provider gives no warranty for these, to the extent permitted.

22. Liability

22.1 The provider is liable only for damage that it causes intentionally or through gross negligence. For slight negligence it is liable only in so far as this is mandatory by law.

22.2 To the extent permitted by law, liability is limited in amount to the fees paid by the customer in the last 12 months, but to a maximum of CHF 5,000. The lower amount is decisive.

22.3 To the extent permitted by law, indirect and consequential damage is excluded (e.g. lost profit, loss of data, business interruption).

22.4 The customer is responsible for backing up its data, for correct configuration, permissions, organisational measures and statutory archiving obligations.

22.5 Mandatory statutory liability (in particular for personal injury) is reserved.

23. Indemnification

The customer indemnifies the provider against claims of third parties arising from unlawful use of the services, from the customer's content/data, from missing legal bases/consents or from breaches of professional secrecy or data protection by the customer, and bears reasonable costs of legal defence.

24. Blocking in the event of breaches and security risks

24.1 The provider may temporarily block or restrict access if there are concrete indications of (i) breaches of clause 7, (ii) misuse, (iii) security risks or (iv) infringements of law, in so far as this is proportionate.

24.2 Where reasonable, the provider informs the customer in advance or without delay afterwards. In urgent cases the provider may take measures immediately.

25. Force majeure

25.1 Neither party is liable for delays or non-performance in so far as these are caused by events of force majeure (e.g. natural events, war, terrorism, pandemics, strikes, official orders, failure of power or telecommunications networks, network outages, disruptions at hosting or cloud providers).

25.2 The affected party informs the other party of the duration and effects where possible. Performance obligations are suspended for the duration and to the extent of the force majeure. Statutory payment obligations for services already rendered are reserved.

26. Notices

26.1 Notices from the provider to the customer may be given by email to the contact address stored in the account, through in-app notifications or through the payment portal, and are deemed delivered as soon as they have been sent or displayed. The customer ensures that the stored email address is current and that notices can be received.

26.2 Legally relevant notices from the customer to the provider (e.g. termination under clause 11.4, complaints, legal notices) must be sent by email to support@unomed.ch or to a legal address designated by the provider.

26.3 Support communication and technical queries do not create legally binding commitments without the provider's express confirmation.

27. Changes to the GTC

27.1 The provider may change these GTC. Changes are announced to the customer in a suitable form (e.g. email or notice in the platform) 30 days in advance.

27.2 If the customer objects before the changes take effect, the previous GTC continue to apply until the end of the current billing period. Both parties may terminate the contractual relationship with effect from the end of the current billing period. If the customer continues to use the services from the beginning of the next billing period, the changes are deemed accepted.

28. Final provisions

28.1 The provider may transfer rights and obligations to affiliated companies or legal successors.

28.2 Should individual provisions be invalid, the remainder of the contract remains effective; in place of the invalid provision, a permissible rule that comes closest to its purpose applies.

28.3 Swiss law applies (excluding the CISG and conflict of laws rules). The place of jurisdiction is Zurich, Switzerland.

Contact

Unomed AG
Tramstrasse 9
8050 Zurich
Email: support@unomed.ch