Enterprise Terms

Last Updated : August 27, 2026

Enterprise Terms

These Enterprise Terms, effective as of the effective date of a signed order form (each, an "Order Form") or the date on which you otherwise begin using the Services (such date, the "Effective Date") is by and between Collaborative Intelligence, Inc. dba Brade AI ("Company"), and the customer set forth on the Order Form or the customer that otherwise begins using the Services ("Customer"). In the event of any conflict between these Enterprise Terms and the terms of any Order Form (if any), the terms of the Order Form shall control.

1. Order Forms; Access to Services

Upon mutual execution, each Order Form shall be incorporated into and form a part of the Agreement. For each Order Form, subject to Customer's compliance with the terms and conditions of this Agreement (including any limitations and restrictions set forth on the applicable Order Form), Company grants Customer a nonexclusive, limited, nonsublicensable, nontransferable right and license to provide access and use of the Company product(s) and/or service(s) specified in such Order Form (collectively, the "Services") during the applicable Order Form Term (as defined below) for the internal business purposes of Customer, only as provided herein and only in accordance with Company's applicable official user documentation for such Services (the "Documentation").

2. Implementation

Upon payment of any applicable fees set forth in each Order Form, Company agrees to use reasonable commercial efforts to provide standard implementation assistance for the Services only if and to the extent such assistance is set forth on such Order Form ("Implementation Assistance"). If Company provides Implementation Assistance in excess of any agreed-upon hours estimate, or if Company otherwise provides additional services beyond those agreed in an Order Form, Customer will pay Company at its then-current hourly rates for consultation.

3. Support Services

Subject to Customer's payment of all applicable fees, Company shall use commercially reasonable efforts to provide the Services in accordance with the Service Level Agreement attached as Exhibit A.

4. Updates; Pre-Release Products

From time to time, Company may provide upgrades, patches, enhancements, or fixes for the Services to its customers generally without additional charge ("Updates"), and such Updates will become part of the Services and subject to this Agreement; provided that Company shall have no obligation under this Agreement or otherwise to provide any such Updates. Customer understands that Company may make improvements and modifications to the Services at any time in its sole discretion; provided that Company shall use commercially reasonable efforts to give Customer reasonable prior notice of any major change that might adversely impact Customer's use of the Services.

5. Fees; Payment

Customer shall pay Company the fees as set forth in each Order Form ("Fees"). Unless otherwise specified in an Order Form, all fees shall be invoiced annually in advance and all invoices issued under this Agreement are payable in U.S. dollars within thirty (30) days from date of invoice. Support and maintenance fees shall be invoiced monthly as incurred or as otherwise set forth in an Order Form. Past due invoices are subject to interest on any outstanding balance of the lesser of 1.5% per month or the maximum amount permitted by law. Customer shall be responsible for all taxes associated with the Services (excluding taxes based on Company's net income). All Fees paid are non-refundable and are not subject to set-off.

6. Ownership; Feedback

As between the parties, Company retains all right, title, and interest in and to the Services, and all software, products, works, and other intellectual property and moral rights related thereto or created, used, or provided by Company for the purposes of this Agreement, including any copies and derivative works of the foregoing. Any software which is distributed or otherwise provided to Customer hereunder (including without limitation any software identified on an Order Form) shall be deemed a part of the "Services" and subject to all of the terms and conditions of this Agreement. No rights or licenses are granted except as expressly and unambiguously set forth in this Agreement. Customer may (but is not obligated to) provide suggestions, comments or other feedback to Company with respect to the Services ("Feedback"). Company acknowledges and agrees that all Feedback is provided "AS IS" and without warranty of any kind. Notwithstanding anything else, Customer shall, and hereby does, grant to Company a nonexclusive, worldwide, perpetual, irrevocable, transferable, sublicensable, royalty-free, fully paid-up license to use and exploit the Feedback for any purpose. Nothing in this Agreement will impair Company's right to develop, acquire, license, market, promote or distribute products, software or technologies that perform the same or similar functions as, or otherwise compete with any products, software or technologies that Customer may develop, produce, market, or distribute.

7. Restrictions

Except as expressly set forth in this Agreement, Customer shall not (and shall not permit any third party to), directly or indirectly: (a) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of the Services (except to the extent applicable laws specifically prohibit such restriction); (b) modify, translate, or create derivative works based on the Services; (c) copy, rent, lease, distribute, pledge, assign, or otherwise transfer or encumber rights to the Services; (d) use the Services for the benefit of a third party; (e) remove or otherwise alter any proprietary notices or labels from the Services or any portion thereof; (f) use the Services to build an application or product that is competitive with any Company product or service (including the Services); (g) interfere or attempt to interfere with the proper working of the Services or any activities conducted on the Services; or (h) bypass any measures Company may use to prevent or restrict access to the Services (or other accounts, computer systems or networks connected to the Services). Customer is responsible for all of Customer's activity in connection with the Services, including but not limited to uploading Customer Data (as defined below) onto the Services. Customer is responsible for the use of the Services by any person to whom Customer has given access to the Services. Customer (i) shall use the Services in compliance with all applicable local, state, national and foreign laws, treaties and regulations in connection with Customer's use of the Services (including those related to data privacy, international communications, export laws and the transmission of technical or personal data laws), and (ii) shall not use the Services in a manner that violates any third-party intellectual property, contractual or other proprietary rights.

8. Customer Data

For purposes of this Agreement, "Customer Data" shall mean any data, information or other material provided, uploaded, or submitted by Customer to the Services in the course of using the Services. Customer shall retain all right, title and interest in and to the Customer Data, including all intellectual property rights therein. Customer, not Company, shall have sole responsibility for the accuracy, quality, integrity, legality, reliability, appropriateness, and intellectual property ownership or right to use of all Customer Data. Customer represents and warrants that it has all rights necessary to provide the Customer Data to Company as contemplated hereunder, in each case without any infringement, violation or misappropriation of any third-party rights (including, without limitation, intellectual property rights and rights of privacy) and in compliance with all applicable laws. Notwithstanding anything to the contrary, Customer acknowledges and agrees that Company may (a) internally use and modify (but not disclose) Customer Data for the purposes of (i) providing the Services to Customer and (ii) generating Aggregated De-Identified Data (as defined below), and (b) freely use, retain and make available Aggregated De-Identified Data for Company's business purposes (including without limitation, for purposes of improving, testing, operating, promoting and marketing Company's products and services). "Aggregated De-Identified Data" means data submitted to, collected by, or generated by Company in connection with Customer's use of the Services, but only in aggregate, de-identified form which can in no way be linked specifically to Customer. Company owns all right, title and interest in and to Aggregated De-Identified Data. Customer agrees and acknowledges that Customer Data may be irretrievably deleted if Customer's account is ninety (90) days or more delinquent.

(b) AI Model Training Restrictions

Company shall not:

  • (i) use Customer Data, including any prompts, inputs, outputs, or feedback, to train, fine-tune, or otherwise improve any general-purpose or third-party AI or machine-learning model;
  • (ii) permit an AI provider to use Customer Data to train its general-purpose models where the applicable business or API service terms and available account settings prohibit that use; or
  • (iii) use Customer Data for benchmarking, evaluation datasets, or aggregate model improvement unless the data has first been de-identified so that it cannot reasonably be linked to Customer or a natural person.

AI providers may temporarily process or retain Customer Data as necessary to provide and secure their services, subject to the provider terms, configuration, and data-processing agreement applicable to the service in use.

9. Privacy; Data Security

Company shall use commercially reasonable efforts to comply with the terms of the U.S. Privacy Law Addendum attached hereto as Exhibit B. If Customer believes Customer Data may include the personal information of natural persons that is subject to (a) the General Data Protection Regulation (Regulation (EU) 2016/679), (b) the Swiss Federal Act on Data Protection, (c) the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018; (d) the UK Data Protection Act 2018; or (e) the Privacy and Electronic Communications (EC Directive) Regulations 2003, the Company's Data Processing Addendum ("DPA"), available at brade.ai/dpa, is incorporated into the Agreement. The DPA applies to Company's processing of Personal Data on Customer's behalf and may be executed as described in the DPA.

10. Artificial Intelligence

Customer acknowledges and agrees that: (a) certain output from the Services will be generated by artificial intelligence or machine learning; (b) artificial intelligence and machine learning are rapidly evolving fields, and use of the Services may in some situations result in incorrect or inaccurate output; (c) Customer must verify the accuracy and appropriateness of any output from the Services before relying on any such output; (d) relying upon any output from the Services without first verifying accuracy with a qualified human could cause harm, including but not limited to legal, financial, and physical harm; and (e) Customer has no rights to any information generated through the Services by or for other customers of Company, regardless of any level of similarity to information provided to Customer. Company cannot control, and has no duty to take any action, regarding how Customer may interpret, rely on, or use any output from the Services or what actions Customer may take as a result of having been exposed to output, and Customer hereby releases Company from all liability for Customer having acquired or not acquired output through the Services, except to the extent liability cannot be released under applicable law.

In addition, Company shall:

  • (f) Data Minimization. Limit the Personal Data transmitted to AI models to data reasonably necessary to fulfill the processing purpose, applying available filtering, redaction, or tokenization where technically feasible and appropriate;
  • (g) Pseudonymization. Apply pseudonymization or anonymization techniques to Personal Data before AI processing where technically feasible and where the processing purpose can be achieved without direct identifiers;
  • (h) Model Provenance. Maintain and, upon Customer's written request, make available documentation of each AI model used in the Services, including model name, version, provider, and a description of the data categories processed by the model;
  • (i) Security Updates. Address identified security vulnerabilities in AI integrations according to risk, available remediations, and Company's vulnerability-management process, and notify Customer of a Personal Data Breach as required by the DPA; and
  • (j) AI Safeguards. Maintain reasonable application and access controls designed to reduce unauthorized disclosure of Customer Data through AI features.

11. Confidentiality

For purposes of this Agreement, "Confidential Information" shall mean to the extent previously, presently or subsequently disclosed by or for either party (the "Disclosing Party") to the other party (the "Receiving Party") all financial, business, legal and technical information of the Disclosing Party or any of its affiliates, suppliers, customers and employees (including information about research, development, operations, marketing, transactions, regulatory affairs, discoveries, inventions, methods, processes, articles, materials, algorithms, software, specifications, designs, drawings, data, strategies, plans, prospects, know-how and ideas, whether tangible or intangible, and including all copies, abstracts, summaries, analyses and other derivatives thereof), that is marked or otherwise identified as proprietary or confidential at the time of disclosure, or that by its nature would be understood by a reasonable person to be proprietary or confidential. Confidential Information shall not include any information that (a) was rightfully known to the Receiving Party without restriction before receipt from the Disclosing Party, (b) is rightfully disclosed to the Receiving Party without restriction by a third party, (c) is or becomes generally known to the public without violation of this Agreement by the Receiving Party, or (d) is independently developed by the Receiving Party or its employees without access to or reliance on such information. The pricing information set forth in an applicable Order Form, Documentation and Feedback are Company's Confidential Information, and the Customer Data is Customer's Confidential Information. Each party shall treat as confidential all Confidential Information of the other party, shall not use such Confidential Information except as set forth in this Agreement, and shall not disclose such Confidential Information to any third party except as expressly permitted herein without the Disclosing Party's written consent. The Receiving Party shall use at least the same degree of care which it uses to prevent the disclosure of its own confidential information of like importance to prevent the disclosure of the Disclosing Party's Confidential Information, but in no event less than reasonable care. The Receiving Party shall promptly notify the Disclosing Party of any actual or suspected misuse or unauthorized disclosure of any of the Confidential Information. In the event of any termination or expiration of this Agreement, the Receiving Party will either return or, at the Disclosing Party's request, destroy the Confidential Information of the Disclosing Party; provided however, that the Receiving Party may retain copies of the Disclosing Party's Confidential Information for routine backup and archival purposes subject to the confidentiality obligations set forth herein. The Receiving Party may make disclosures required by law or court order provided that, if permissible pursuant to applicable law, the Receiving Party shall promptly notify the Disclosing Party of any disclosure requirement and provide reasonable assistance to the Disclosing Party in the Disclosing Party's efforts to prevent and/or limit the disclosure.

12. Third-Party Services

Customer acknowledges and agrees that the Services may operate on, with or using application programming interfaces (APIs) and/or other services operated or provided by third parties ("Third-Party Services"), including without limitation through integrations or connectors to such Third-Party Services that are provided by Company. Company is not responsible for the operation of any Third-Party Services nor the availability or operation of the Services to the extent such availability and operation is dependent upon Third-Party Services. Customer is solely responsible for procuring any and all rights necessary for it to access Third-Party Services (including any Customer Data or other information relating thereto) and for complying with any applicable terms or conditions thereof. Company does not make any representations or warranties with respect to Third-Party Services or any third-party providers. Any exchange of data or other interaction between Customer and a third-party provider is solely between Customer and such third-party provider and is governed by such third-party provider's terms and conditions.

13. Term; Termination

This Agreement shall commence upon the date of the first Order Form, and, unless earlier terminated in accordance herewith, shall last until the expiration of all Order Form Terms. Each Order Form shall specify the Initial Term, Renewal Term (if any), and terms applicable to each. The Initial Term and each Renewal Term (if any) are collectively referred to herein as the "Term." In the event of a material breach of this Agreement by either party, the non-breaching party may terminate this Agreement by providing written notice to the breaching party, provided that the breaching party does not materially cure such breach within thirty (30) days of receipt of such notice. Without limiting the foregoing, Company may suspend or limit Customer's access to or use of the Services if (a) Customer's account is more than sixty (60) days past due, or (b) Customer's use of the Services results in (or is reasonably likely to result in) damage to or material degradation of the Services, which interferes with Company's ability to provide access to the Services to other customers; provided that in the case of subsection (b): (i) Company shall use reasonable good faith efforts to work with Customer to resolve or mitigate the damage or degradation in order to resolve the issue without resorting to suspension or limitation; (ii) prior to any such suspension or limitation, Company shall use commercially reasonable efforts to provide notice to Customer describing the nature of the damage or degradation; and (iii) Company shall reinstate Customer's use of or access to the Services, as applicable, if Customer remediates the issue within thirty (30) days of receipt of such notice. All provisions of this Agreement which by their nature should survive termination shall survive termination, including, without limitation, accrued payment obligations, ownership provisions, warranty disclaimers, confidentiality, indemnity and limitations of liability. For clarity, any termination or transition assistance services provided by Company to Customer, including any assistance in exporting the Customer Data, shall be billable at Company's standard rates then in effect.

14. Indemnification

a. Company Indemnification

Company will indemnify, defend and hold Customer, its officers, directors, consultants, employees, agents, successors and assigns harmless from any and all amounts actually paid to any third party in connection with claims, liabilities, damages, costs and expenses (including, but not limited to, reasonable attorneys' fees) (collectively, "Losses") relating to any claim that the Services, as provided by Company to Customer under this Agreement and used within the scope of this Agreement, infringe or misappropriate any intellectual property right of such third party (each, an "Infringement Claim"). In the event of any such Infringement Claim, Company may, at its option: (i) obtain a license to permit Customer the ability to continue using the Services; (ii) modify or replace the relevant portion(s) of the Services with a non-infringing alternative having substantially equivalent performance within a reasonable period of time; or (iii) terminate this Agreement by providing notice to Customer, and provide Customer with a refund of any prepaid, unearned Fees (prorated on a daily basis for the then-current billing period), if any. Notwithstanding the foregoing, Company will have no liability for any Infringement Claim to the extent that it results from: (1) modifications to the Services made by a party other than Company or its agents, or otherwise not approved by Company or its agents or allowed under this Agreement; (2) the combination, operation or use of the Services with equipment, devices, data (including Customer Data) or software not provided or approved by Company; (3) Customer's failure to use updated or modified versions of the Services provided by Company to avoid a claim; or (4) Customer's use of the Services other than in accordance with this Agreement ((1) through (4), collectively, the "Excluded Claims"). The indemnification obligations set forth in this Section 14(a) are Company's sole and exclusive obligations (and Customer's sole and exclusive remedies) with respect to infringement or misappropriation of intellectual property rights of any kind.

b. Customer Indemnification

Customer will indemnify and hold Company, its officers, directors, consultants, employees, agents, successors and assigns harmless from any and all Losses relating to any claim caused by (i) any of the Excluded Claims, (ii) Customer's breach of any representation, warranty or obligation under this Agreement, and (iii) any claim that Customer Data or the use of Customer Data in connection with the Services may violate any law, rule, or regulation or infringe or violate the rights of a third party. If Company receives any notice or claim that Customer Data may violate any law, rule, or regulation or infringe or violate the rights of a third party, Company may (but is not required to) suspend the Services hereunder with respect to such Customer Data.

c. Indemnification Procedures

Any claim for indemnification hereunder is contingent upon the indemnified party providing (i) prompt written notice of the liability, (ii) reasonable cooperation, information, and assistance in connection therewith, and (iii) the indemnifying party with the sole control and authority to defend, settle or compromise such liability, provided that the indemnified party may participate in such defense at its sole cost. The indemnifying party will not make any settlement that requires a materially adverse act or admission by the indemnified party without the indemnified party's written consent (such consent not to be unreasonably delayed, conditioned or withheld). The indemnifying party will not be liable for any settlement made without its prior written consent.

15. Warranties and Disclaimers

a. Mutual Warranties

Each party represents and warrants that (i) it is duly organized and validly existing under the laws of the jurisdiction in which it is organized, (ii) it has full power and authority, and has obtained all approvals, permissions and consents necessary, to enter into this Agreement and to perform its obligations hereunder, (iii) this Agreement is legally binding upon it, and (iv) the execution, delivery and performance of this Agreement does not and will not conflict with any agreement to which it is a party.

b. Disclaimers

EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" AND ARE WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF TITLE, NON-INFRINGEMENT, MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, AND ANY WARRANTIES IMPLIED BY ANY COURSE OF PERFORMANCE, USAGE OF TRADE, OR COURSE OF DEALING, ALL OF WHICH ARE EXPRESSLY DISCLAIMED.

16. Limitation of Liability

IN NO EVENT SHALL EITHER PARTY, OR ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, PARTNERS, SUPPLIERS OR LICENSORS, BE LIABLE UNDER CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE OR ANY OTHER LEGAL OR EQUITABLE THEORY WITH RESPECT TO THE SUBJECT MATTER OF THIS AGREEMENT (A) FOR ANY LOST PROFITS, DATA LOSS, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR SPECIAL, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES OF ANY KIND WHATSOEVER, SUBSTITUTE GOODS OR SERVICES (HOWEVER ARISING), (B) FOR ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE (REGARDLESS OF THE SOURCE OF ORIGINATION), OR (C) FOR ANY DIRECT DAMAGES IN EXCESS OF (IN THE AGGREGATE) THE FEES PAID (OR PAYABLE) BY CUSTOMER TO COMPANY HEREUNDER IN THE TWELVE (12) MONTHS PRIOR TO THE EVENT GIVING RISE TO A CLAIM HEREUNDER.

17. Publicity

Customer hereby consents to inclusion of its name and logo in Company's public-facing client lists and marketing materials that may be published as part of its marketing and promotional efforts, including on Company's website. Customer also agrees that Company may (but is under no obligation to) issue press releases and publish testimonials and case studies with statements attributed to a named employee of Customer.

18. Force Majeure

In no event shall either party be liable to the other party, or be deemed to have breached this Agreement, for any failure or delay in performing its obligations under this Agreement (except for any obligations to make payments), if and to the extent such failure or delay is caused by any circumstances beyond such party's reasonable control, including but not limited to acts of God, flood, fire, earthquake, explosion, war, terrorism, invasion, riot or other civil unrest, strikes, labor stoppages or slowdowns or other industrial disturbances, or passage of law or any action taken by a governmental or public authority, embargoes or blockades occurring after the date of this Agreement, or national or regional emergency, in each case, which effects could not have been avoided through reasonable business continuity planning (each of the foregoing, a "Force Majeure Event"). In the event of such Force Majeure Event, the affected party shall provide a prompt notice to the other party, stating the period of time the occurrence is expected to continue, and the affected party uses diligent efforts to end the failure or delay and minimize the effects of such Force Majeure Event. Notwithstanding the foregoing, Customer shall not be excused from its payment obligations as a result of the occurrence or persistence of such Force Majeure Event.

19. Miscellaneous

This Agreement (including all Order Forms) represents the entire agreement between Customer and Company with respect to the subject matter hereof, and supersedes all prior or contemporaneous communications and proposals (whether oral, written or electronic) between Customer and Company with respect thereto. In the event of any conflict between these Terms and an Order Form, the Order Form shall control. The Agreement shall be governed by and construed in accordance with the laws of the state of Delaware, excluding its conflicts of law rules, and the parties consent to exclusive jurisdiction and venue in the state and federal courts located in New Castle County, Delaware. All notices under this Agreement shall be in writing and shall be deemed to have been duly given when received, if personally delivered or sent by certified or registered mail, return receipt requested; when receipt is electronically confirmed, if transmitted by facsimile or e-mail; or the day after it is sent, if sent for next day delivery by recognized overnight delivery service. Notices must be sent to the contacts for each party set forth on the Order Form. Either party may update its address set forth above by giving notice in accordance with this section. Except as otherwise provided herein, any provision of this Agreement may be amended or waived only by a writing executed by both parties. Neither party may assign any of its rights or obligations hereunder without the other party's consent; provided that (a) either party may assign all of its rights and obligations hereunder without such consent to a successor-in-interest in connection with a sale of all or substantially all of such party's assets or stock, and (b) Company may utilize subcontractors in the performance of its obligations hereunder. No agency, partnership, joint venture, or employment relationship is created as a result of this Agreement and neither party has any authority of any kind to bind the other in any respect. In any action or proceeding to enforce rights under this Agreement, the prevailing party shall be entitled to recover costs and attorneys' fees. If any provision of this Agreement is held to be unenforceable for any reason, such provision shall be reformed only to the extent necessary to make it enforceable. The failure of either party to act with respect to a breach of this Agreement by the other party shall not constitute a waiver and shall not limit such party's rights with respect to such breach or any subsequent breaches.

Exhibit A - Service Level Agreement

This Service Level Agreement sets forth the policies and procedures with respect to the Services provided by Company to Customer pursuant to the Agreement.

Summary

As further described below, Company will use commercially reasonable efforts to (a) provide Customer with 99% availability to the Services (the "Services Availability"); and (b) provide standard support to Customer. For clarity, "Services Availability" refers solely to the availability of Customer's ability to access and use the Services, and does not include or constitute any representation, warranty, or guarantee regarding the accuracy, completeness, quality, reliability, or fitness for any particular purpose of any outputs, recommendations, analyses, or other results generated by or through any artificial intelligence, machine learning models, algorithms, or similar technologies incorporated into or used as part of the Services.

Availability

If the Services become substantially unavailable to Customer due to defects with the Services, Company will respond to Customer (a) within eight (8) hours from Customer's notification to Company of such unavailability, if during normal business hours (Monday-Friday, 9:00 am to 6:00 pm Eastern) or (b) within eight (8) hours of the start of the next business day, if outside of normal business hours. Company's obligation to initiate a response shall not be construed or deemed to constitute any commitment, representation, or warranty that any issue, error, or request will be resolved within any particular timeframe or by any specific deadline and refers solely to the time period within which Company is required to initiate such response.

The Services Availability will be measured on a monthly basis, with all hours weighted equally, but the Services Availability measurement will exclude reasonable scheduled downtime for: (a) system maintenance as well as any downtime or performance issues resulting from third party connections, services or utilities (including third-party artificial intelligence or machine learning model providers); (b) any API rate limits, outages, interruptions, or changes imposed by such third parties; (c) the quality, completeness, formatting, configuration, or structure of any data, inputs, or instructions provided or controlled by Customer or any third parties; or (d) any other reason beyond Company's control (including without limitation, acts of God, acts of government, flood, fire, earthquakes, civil unrest, acts of terror, strikes or other labor problems (other than those involving Company employees), computer, telecommunications, Internet service provider or hosting facility failures or delays involving hardware, software or power systems not within Company's possession or reasonable control, and denial of service attacks).

If the Services are unavailable to Customer due to defects with the Services beyond the Services Availability metric, then, as Customer's sole and exclusive remedy (and Company's sole liability), Company will provide Customer a credit for the subsequent Services billing cycle as follows:

Availability Credit
97% to 99% 5%
95% - 97% 10%
< 95% 20%

In order to receive downtime credit, Customer must notify Company support within seventy-two (72) hours from the time of downtime, and failure to provide such notice will forfeit the right to receive downtime credit. All credits provided hereunder are nonrefundable. No service credits will be issued in connection with, or as a result of, any matter relating to the correctness, accuracy, completeness, reliability, or usefulness of any AI-generated outputs, provided that the Services are otherwise available in accordance with the Service Availability commitment. If Customer elects not to renew the Agreement, such that the above credit cannot be applied, Customer will have the option to receive up to one free month of access to the Services as its sole remedy in lieu of such credit.

Support

Company will provide support to customer for defects with the Services via telephone and email support during Company's normal business hours ("Support"). Support will only include assistance with issues which are exclusively due to an error with the Services. Customer may designate up to 2 support contacts ("Designated Support Contacts"), and all support requests must come through the Designated Support Contacts. Customer may update the Designated Support Contacts by providing notice to Company. Any assistance outside the scope of the Support will be provided by Company on a time and materials basis.

Exhibit B - United States Privacy Law Addendum

This United States Privacy Law Addendum (the "Addendum") supplements the Agreement and includes the terms of the Agreement. Any capitalized terms that are used but not defined herein shall have the definitions set forth in the Agreement. Where there is a conflict between the Agreement and this Addendum, this Addendum will control.

1. Definitions

  • Authorized Subprocessor means a third-party party entity engaged by Company to process Personal Data in order to provide the Services and that has been approved by Customer in accordance with Section 6.
  • Company Account Data means personal data that relates to Company's relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer's account and billing information of individuals that Customer has associated with its account.
  • Company Usage Data means usage data collected and processed by Company in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and similar data.
  • Consumer means a natural person whose Personal Data is protected by Privacy Laws.
  • Consumer Request means a request from a Consumer to exercise their rights over Personal data afforded pursuant to Privacy Laws.
  • Controller means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing Personal Data. "Controller" includes the term "Business" or equivalent term under Privacy laws.
  • Personal Data means any information provided to Company by or on behalf of Customer in connection with the Services that relates to an identified or identifiable Consumer and constitutes "personal data," "personal information," or equivalent term under Privacy Laws.
  • Privacy Laws means any applicable laws and regulations in any relevant jurisdiction relating to the processing of Personal Data. Privacy Laws includes but are not limited to, U.S. state comprehensive privacy laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the "CCPA"), in each case as updated, amended or replaced from time to time. The terms "affiliates," "business purpose," "Controller," "Personal Data Breach," "Processor," "process" or "processing," "sell," or "share," shall have the meaning set forth for that or any equivalent term under Privacy Laws. For the avoidance of doubt, the terms "Controller" and "Processor" include "Business" and "Service Provider," respectively, as defined in the CCPA.

2. Description of Processing

  • Nature and Purpose of Processing: Except with respect to Company Account Data and Company Usage Data, Company shall process Personal Data provided by Customer under the Agreement as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this Addendum, and in accordance with Customer's instructions as set forth in this Addendum. Such purposes shall include the provision of an AI-enabled software platform designed for industrial distributors and manufacturers.
  • Duration of Processing: Company shall process Personal Data provided by Customer as long as required (i) to provide the Services to Customer under the Agreement, or (ii) by applicable law or regulation.
  • Categories of Consumers: Company may process Personal Data relating to the following categories of Consumers: Customer's users.
  • Categories of Personal Data: Company may process the following categories of Personal Data: Customer's user name and business contact information (such as name, email address, physical address, phone number, company name, title, role, IP address, and device information).

3. Customer's Obligations

Customer shall, in its use of the Services, at all times process Personal Data, and provide instructions for the processing of Personal Data, in compliance with Privacy Laws. Customer shall ensure that the processing of Personal Data in accordance with Customer's instructions will not cause Company to be in breach of the Privacy Laws. Customer is solely responsible for the accuracy, quality, and legality of (a) the Personal Data provided to Company by or on behalf of Customer, (b) the means by which Customer acquired any such Personal Data, and (b) the instructions it provides to Company regarding the processing of such Personal Data. Customer shall not provide or make available to Company any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services, and shall indemnify Company from all claims and losses in connection therewith.

4. Use of Personal Data

Company shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data outside of Company's direct business relationship with Customer or for any purpose other than to perform the Services and other obligations under the Agreement, which constitutes a business purpose under the Privacy Laws, except as otherwise permitted in Agreement or by Privacy Laws; and (c) combine Personal Data received from, or on behalf of, Customer with Personal Data that it receives from, or on behalf of, another party or person, except as necessary to provide the Services or as otherwise instructed by Customer.

4A. AI Processing and Automated Decision-Making

To the extent applicable under the Privacy Laws:

  • (a) Company shall not use Personal Data received from Customer to train or fine-tune a general-purpose AI model and shall use AI service offerings and available account settings that prohibit the provider from using Customer Personal Data to train its general-purpose models;
  • (b) Company shall provide Customer, upon written request, with meaningful information about the logic involved in any automated processing of Personal Data, including the categories of data processed, the purpose of the processing, and the general functionality of the AI system;
  • (c) Company shall implement measures to allow Customer to fulfill Data Subject requests related to automated decision-making, including the right to obtain human intervention, to express a point of view, and to contest a decision, where such rights are provided under applicable Privacy Laws; and
  • (d) Company shall conduct and document assessments of any AI processing that involves profiling or automated decision-making that produces legal or similarly significant effects on Data Subjects, and shall make summaries of such assessments available to Customer upon reasonable written request.

5. Audit

To the extent required by applicable Privacy Laws, and upon Customer's written request at reasonable intervals, and subject to reasonable confidentiality controls, Company shall either (a) make available for Customer's review copies of certifications or reports demonstrating Company's compliance with prevailing data security standards applicable to the processing of Personal Data provided by Customer under the Agreement, or (b) if the provision of reports or certifications pursuant to (a) is not reasonably sufficient under the applicable Privacy Laws, allow Customer or Customer's independent third party representative to conduct an audit or assessment of Company's policies and technical and organizational measures using an appropriate and accepted control standard or framework and assessment procedure for such assessments, that (i) Customer provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Company's business; (ii) such audit shall only be performed during business hours and occur no more than once per calendar year; and (iii) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Company for any time expended for on-site audits. To the extent permitted under Privacy Laws, if Customer determines that Company is processing Personal Data in an unauthorized manner, Customer may, taking into account nature of Company's processing and the nature of the Personal Data processed by Company on behalf of Customer, and upon providing prior written notice, take commercially reasonable and appropriate steps to stop and remediate such unauthorized processing.

6. Authorized Subprocessors

  • A list of Company's current Authorized Subprocessors (the "List") is attached hereto as Table A. Such List may be updated by Company from time to time. Company may provide a mechanism to subscribe to notifications of new subprocessors and Customer agrees to subscribe to such notifications where available. At least ten (10) days before enabling any third party other than existing Authorized Subprocessors to access or participate in the processing of Personal Data, Company will add such third party to the List and notify Customer via email. Customer may object to such an engagement by informing Company within ten (10) days of receipt of the aforementioned notice to Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. If Customer does not object during this period, that third party will be deemed an Authorized Subprocessor. Customer acknowledges that certain subprocessors are essential to providing the Services and that objecting to the use of a subprocessor may prevent Company from offering the Services to Customer.
  • If Customer reasonably objects to an engagement in accordance with Section 6(a), and Company cannot provide a commercially reasonable alternative within a reasonable period of time, Customer may discontinue the use of the affected Service by providing written notice to Company. Discontinuation shall not relieve Customer of any fees owed to Company under the Agreement.
  • Company will enter into a written agreement with the Authorized Subprocessor imposing on the Authorized Subprocessor data protection obligations comparable to those imposed on Company under this Addendum with respect to the protection of Personal Data. In case an Authorized Subprocessor fails to fulfill its data protection obligations under such written agreement with Company, Company will remain liable to Customer for the performance of the Authorized Subprocessor's obligations under such agreement.

7. Confidentiality and Security of Personal Data

  • Company shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Company's confidentiality obligations in the Agreement. Customer agrees that Company may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this Addendum, the Agreement, or the provision of Services to Customer.
  • Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Company shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data.

8. Personal Data Breach

  • In the event of a Personal Data Breach, Company shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as Company in its sole discretion deems necessary and reasonable to remediate such Personal Data Breach, to the extent that remediation is within Company's reasonable control.
  • In the event of a Personal Data Breach, Company shall, taking into account the nature of the processing and the information available to Company, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under Privacy Laws with respect to notifying (i) the relevant regulatory agency and (ii) Consumers affected by such Personal Data Breach without undue delay.
  • The obligations described in Sections 8(a) and 8(b) shall not apply in the event that a Personal Data Breach results from the actions or omissions of Customer. Company's obligation to report or respond to a Personal Data Breach under Sections 8(a) and 8(b) will not be construed as an acknowledgement by Company of any fault or liability with respect to the Personal Data Breach.

9. Data Protection Assessments

Taking into account the nature of Company's processing and the information available to Company, Company shall reasonably cooperate with Customer to conduct any data protection or privacy impact assessments as required by Privacy Laws, including by providing Customer with information and documents necessary for such assessments that Customer cannot otherwise obtain without Company's assistance. Notwithstanding the foregoing, Customer and Company each remain responsible only for the measures respectively allocated to them under Privacy Laws pertaining to any such assessment.

10. Consumer Request

Company shall, to the extent permitted by Privacy Laws, notify Customer upon receipt of a Consumer Request. If Company receives a Consumer Request in relation to Personal Data, Company will advise the Consumer to submit their request to Customer and Customer will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Customer is solely responsible for ensuring that Consumer Requests communicated to Company, and, if applicable, for ensuring that a record of consent to processing is maintained with respect to each Consumer.

11. Return or Destruction of Personal Data

Upon the termination or expiration of the Agreement, at Customer's choice, Company shall return or delete Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Company shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control.

12. Company's Role as a Controller

The parties acknowledge and agree that with respect to Company Account Data and Company Usage Data, Company is an independent controller, not a joint controller with Customer. Company will process Company Account Data and Company Usage Data as a controller (a) to manage the relationship with Customer; (b) to carry out Company's core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (c) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Customer; (d) for identity verification purposes; (e) to comply with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Company is subject; and (f) as otherwise permitted under Privacy Laws and in accordance with this DPA and the Agreement. Company may also process Company Usage Data as a controller to provide, optimize, and maintain the Services, to the extent permitted by Privacy Laws. Any processing by Company as a controller shall be in accordance with Company's privacy policy.

Table A - Authorized Subprocessors

Name of Authorized Subprocessor Address Contact Person Description of Processing Country
Microsoft Azure Microsoft Enterprise Service Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052
USA
Microsoft Enterprise Service Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052 USA
PaaS hosting (App Service, Static Web App, PostgreSQL, Key Vault, Application Insights) and Azure AI Foundry model inference (Kimi K2.6, published by MoonshotAI, within Azure) EU
Microsoft 365 / Entra ID (Azure AD) Microsoft Enterprise Service Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052
USA
Microsoft Enterprise Service Privacy
Microsoft Corporation
One Microsoft Way
Redmond, Washington 98052 USA
Identity management, authentication, email UK
WorkOS, Inc. United States support@workos.com User authentication, organization identity, and single sign-on USA
Twilio Inc. (SendGrid) 101 Spear Street, Suite 500,
San Francisco, CA 94105
privacy@twilio.com Transactional email delivery USA
Stripe, Inc. 354 Oyster Point Blvd,
South San Francisco, CA 94080
privacy@stripe.com Payment processing for subscriptions and invoices USA
Agent Paid Limited (Paid.ai) 161 Farringdon Road,
London, EC1R 3AL, United Kingdom
hello@paid.ai Usage metering, billing, and invoicing USA
Functional Software, Inc. (Sentry) 45 Fremont Street, 8th Floor,
San Francisco, CA 94105
compliance@sentry.io Error monitoring and performance tracking USA
Google LLC (Google Analytics and Gemini) 1600 Amphitheatre Parkway,
Mountain View, CA 94043
privacy@google.com Product/usage analytics and AI model inference through the Gemini Developer API USA
Google Cloud (Document AI) Google LLC
1600 Amphitheatre Parkway,
Mountain View, CA 94043
privacy@google.com OCR processing for PDF and email attachments (europe-west2) UK
Anthropic, PBC 548 Market St, PMB 90375,
San Francisco, CA 94104,
USA
privacy@anthropic.com AI model inference (LLM processing for document analysis, conversation) USA
OpenAI, LLC 3180 18th St,
San Francisco, CA 94110,
USA
privacy@openai.com AI model inference (LLM processing for document analysis, quote generation) USA