This summary is a plain English version of the terms of using Thought Industries' AEO and Conversational AI Learning Features. You can find the legally binding terms and conditions below this summary.
These Terms of Service and Software as a Service (SaaS) Agreement (the "Agreement") is made and is effective upon the date of your acceptance of these terms (the "Effective Date") by and between Thought Industries, Inc., a company incorporated under the laws of Massachusetts (USA) with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109 ("TI" or "we" or "us"), and you, the customer as identified in the applicable purchase terms via TI's website ("Customer" or "you"). The terms of this Agreement shall govern your use of and access to Thought Industries' AEO and Conversational AI Learning Features.
WHEREAS TI is the owner and licensor of the following AI-powered features (collectively, the "Services" herein), each a proprietary Software as a Service-based capability with processing provided by generative AI technology:
WHEREAS the Customer desires to be granted a non-exclusive right to access and use the Services for the purposes described in this Agreement, and TI is willing to grant Customer such rights under the terms and conditions set forth herein.
NOW, THEREFORE, the parties hereby agree as follows:
TO THE PROVIDER'S TERMS AND CONDITIONS FOUND AT https://openai.com/enterprise-privacy/.
TI shall be the sole owner of any Intellectual Property Rights in the compilation(s) of data derived from the Services, including Service-algorithm-generated compilations and derivatives of data (but excluding any data provided by Customer and Outputs (defined below) generated by the Services for Customer). Nothing in this Agreement shall constitute a waiver of TI's Intellectual Property Rights under any law. All Intellectual Property Rights in Customer's data shall remain with Customer. Customer shall own all Intellectual Property Rights in the Outputs (defined below) generated by the Services exclusively for Customer.
Subscription Fees. Customer shall pay the subscription fees set forth in the applicable Ordering Document in accordance with the pricing and payment terms governed by their Ordering Document or if applicable, a separate master services agreement or similar agreement between the parties ("MSA").
Feature Fees. Customer may enable certain optional features within its account, including the Conversational AI Learning and AEO features (as described above). The pricing for each such feature shall be as set forth in Customer’s account. To enable a feature, Customer must provide valid credit card payment information via TI’s Stripe integration. Customer may disable any feature at any time, subject to the payment obligations set forth herein. TI shall provide Customer with at least thirty (30) days’ advance written notice of any price increases for Feature Fees. Following receipt of such notice, Customer may opt out of the applicable feature at any time by disabling it in Customer’s account.
(a) Conversational AI Learning Feature Terms.
(i) Billing. The pricing for the Conversational AI Learning Feature shall be as set forth in Customer’s account. Customer will be charged in arrears for Conversational AI Learning usage monthly on the first of every month.
(ii) Opt-Out. Customer may opt out of the Conversational AI Learning feature at any time by disabling it in Customer’s account. Upon disabling the feature, Customer will only be charged for usage incurred prior to disablement.
(iii) Fraudulent Activity. TI reserves the right to immediately suspend or terminate Customer’s access to the Conversational AI Learning feature if TI reasonably determines that Customer’s use of the feature involves fraudulent activity or abuse.
(b) AEO Feature Terms.
(i) Monthly Fee. The pricing for the AEO Feature shall be as set forth in Customer’s account and or contract. Customer shall pay a monthly or annual fee upfront for access to the AEO feature on the 1st of the month. If Customer disables the AEO feature during a calendar month, Customer shall pay for the remainder of that month, and the AEO feature subscription will not renew for the subsequent month.
GENERAL TERMS of the Agreement:
Overview; Binding Agreement. This Evaluation Agreement (the "Agreement") is made by and between and applies to Thought Industries, Inc. ("TI", "we", or "us" herein), and the customer/user ("Customer", or "you" herein) accepting the terms of this Agreement and accessing or using the AEO and/or Conversational AI Learning Features. By accepting these terms and accessing or using the AI Features, you agree to be bound by this Agreement. If you do not agree to this Agreement, you are not allowed to access or use the AI Features. The "Effective Date" of this Agreement is the date you first access or use any aspect of the AI Features. TI reserves the right to change or modify this Agreement at any time upon notice to you. For the purposes of this Agreement: (i) "AI Features" means the TI-proprietary SaaS AEO and/or Conversational AI Learning Feature(s) that you will be allowed to use and access during the Evaluation Period; (ii) the "Evaluation Period" means up to one hundred twenty (120) days from the Effective Date (unless set forth otherwise in an applicable Ordering Document); and (iii) the "Ordering Document" is the order form or other ordering document completed by the Customer identifying the applicable AI Feature(s) to be evaluated.
Evaluation License; Restrictions. Subject to the terms of this Agreement and the AI Features Terms of Service which are incorporated herein by reference, TI grants you a revocable, limited, non-exclusive, nontransferable, non-sublicensable right to access and use the AI Feature(s) during the Evaluation Period, solely for the purpose of internally evaluating whether to purchase a paid subscription, and not for any other purpose or use. Unless otherwise set forth in the Ordering Document, there is no fee associated with this grant of access during the Evaluation Period. You agree not to: (i) sublicense, sell, rent, assign, or distribute the AI Features to third parties; (ii) allow any third party to access or use the AI Features under the rights granted to you herein; (iii) host the AI Features for the benefit of third parties; (iv) modify the AI Features, or any proprietary rights notices therein; or (v) disassemble, decompile, or reverse engineer the AI Features.
Term and Termination. Unless terminated as provided for herein, this Agreement will continue in effect throughout the Evaluation Period. This Agreement will automatically terminate without the requirement of notice at the end of the Evaluation Period unless the parties mutually agree in writing to an extension. Customer can terminate this Agreement at any time with written notice to TI. TI can terminate this Agreement immediately upon written notice in the event you breach the terms of this Agreement. When this Agreement terminates or expires: (i) the Evaluation Period will end; and (ii) you will no longer have the right to access or use the AI Features. The following provisions will survive: Restrictions; No Warranty; Disclaimer; Confidentiality; Limitation of Liability; Miscellaneous.
No Warranty; Disclaimer; Limitation of Liability. You acknowledge and agree that the AI Features are being provided "AS-IS" and without warranty of any kind, express or implied. WE HEREBY SPECIFICALLY DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD
PARTY FOR DAMAGES OF ANY KIND, INCLUDING, WITHOUT LIMITATION, DIRECT, INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THIS AGREEMENT.
Customer Warranty. When you access or use the AI Features you represent and warrant as follows: (i) that you will not use the AI Features for any purpose other than the limited evaluation set forth herein; and (ii) that your use of the AI Features will comply with all applicable laws and regulations.
Confidentiality. For the purposes of this Agreement, "Confidential Information" means any business or technical information that either party discloses to the other pursuant to this Agreement. The AI Features and associated documentation will be deemed to be TI Confidential Information. Neither party will use the other party's Confidential Information, except as permitted under this Agreement. Each party agrees to maintain in confidence and protect the other party's Confidential Information using at least the same degree of care as it uses for its own information of a similar nature, but in all events at least a reasonable degree of care. Any personal data processed on your behalf during the Evaluation Period by the AI Features is subject to the terms of our DPA found herein.
Miscellaneous. The English version of this document will prevail over any translation. You agree to indemnify, defend, and hold TI harmless from and against any third-party claims arising out of or relating to your access to or use of the AI Features not in accordance with the terms of this Agreement. This Agreement will be governed by the laws of the Commonwealth of Massachusetts. Any legal action or proceeding arising under this Agreement will be brought exclusively in the appropriate federal or state courts located in Suffolk County, Massachusetts. Neither party may assign this Agreement without the other party's written consent. This Agreement (including the agreements incorporated herein) is the entire agreement of the parties with respect to its subject matter.
This Acceptable Use Policy ("AUP") is designed to mitigate potential risks of using the AEO and Conversational AI Learning Features in inappropriate, unintended, and unacceptable settings or in industries that are unaligned with the true purpose and contractually permitted use of these features. This AUP will be subject to on-going revision and updating as further refinements are implemented.
Thought Industries, Inc. ("TI") currently has no staff dedicated to overseeing and enforcing this policy and potential violations will be handled reactively; further, it is the duty of each TI customer to provide this AUP to its authorized users of the AEO and Conversational AI Learning Features and provide reasonably necessary instructions and prohibitions to its users.
The Policy below assumes the AEO and Conversational AI Learning Features are provided primarily on a B2B-basis, with TI's customers operating as organized businesses, which then permit their authorized users to access and use the AI Features.
Policy: You (and your authorized users) agree not to use the AEO or Conversational AI Learning Features for the following activities and use cases. This list is representative and non-exhaustive; TI retains the right to revise and update this Policy.
The scope and applicability of this Data Processing Agreement ("DPA") applies to Thought Industries, Inc., a Massachusetts corporation, with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109, ("TI") and its processing of Personal Data on your behalf; you (TI's customer) are the "Controller" under this DPA and TI is the "Processor" in connection with the provision of TI's AEO and Conversational AI Learning Features specified in the applicable TI Terms of Service and Software as a Service (SaaS) Agreement (the "Agreement"); and more specifically, the processing of "User Information" and "Customer Data PII" under the terms of the Agreement. Unless otherwise expressly stated in the Agreement, this DPA shall be effective and remain in force for the full term of the Agreement.
"Applicable Data Protection Laws" — means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time.
"Controller Affiliate" — means an affiliate of Controller who is a beneficiary to the Agreement.
"Covered Data" — means Personal Data that is provided by or on behalf of Controller to Processor in connection with the Services.
"Data Subject" — means a natural person whose Personal Data is Processed.
"Deidentified Data" — means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.
"EEA" — means the European Economic Area including the European Union ("EU").
"GDPR" — means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR" as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 or, where applicable, the equivalent provision under Swiss data protection law.
"Instruction" — means any documented instruction, submitted by Controller to Processor, directing Processor to perform a specific action with regard to Covered Data.
"Personal Data" — means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise "personal data," "personal information," "personally identifiable information," or similarly defined data or information under Applicable Data Protection Laws.
"Processing" — means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means.
"Security Incident" — means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Covered Data.
"Services" — means the AEO and Conversational AI Learning Features to be provided by Processor pursuant to the Agreement.
"Standard Contractual Clauses" or "SCCs" — means Module Two (controller to processor) and/or Module Three (processor to processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, dated June 4, 2021.
"Sub-processor" — means an entity appointed by Processor to Process Covered Data on its behalf.
"US Data Protection Laws" — means, to the extent applicable, federal and state laws relating to data protection and privacy in force in the United States, including (but not limited to) the CCPA, CPRA, Colorado
Privacy Act, Connecticut Personal Data Privacy and Online Monitoring Act, Utah Consumer Privacy Act, Virginia Consumer Data Protection Act, Texas Data Privacy and Security Act, and Oregon Consumer Privacy Act.
This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data. Controller acknowledges that Processor's Services are not designed, intended, or provided for the purpose of making predictions regarding any Data Subject, determining creditworthiness, or any other manner of automated decision-making regarding Data Subject(s). The scope of Processor's Services is set forth in the Agreement, and Controller shall not permit any authorized user to utilize the Services for any other purpose.
For the purposes of this DPA, and for purposes of the GDPR, Processor acts as "processor" or "sub-processor" as determined by the then-applicable function of Controller. For the purposes of US Data Protection Laws, Processor will act as a "service provider" or "processor" as defined in US Data Protection Laws.
Controller grants Processor the general authorisation to engage Sub-processors, subject to the requirements below, as well as Processor's current Sub-processors listed in the Sub-Processors Schedule as of the Effective Date. Processor will: (i) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than Processor's obligations under this DPA; and (ii) remain liable for each Sub-processor's compliance. Processor will provide Controller with at least fifteen (15) days' notice of any proposed changes to Sub-processors. Controller may object to a new Sub-processor based upon reasonable data privacy and data security concerns within ten (10) days of notice.
As between the Parties, Controller will have sole discretion and responsibility in responding to rights asserted by individuals in relation to Covered Data under Applicable Data Protection Laws. Processor will forward to Controller promptly any Data Subject Request received and will provide Controller with reasonable assistance as necessary for Controller to fulfil its obligations.
Processor will implement and maintain appropriate technical and organizational data protection and security measures designed to ensure security of Covered Data, including protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. Audits will be conducted: (i) upon reasonable written notice; (ii) only once per year; (iii) only during Processor's normal business hours; and (iv) in a manner that does not disrupt Processor's business. Controller will bear the costs for any audit initiated by Controller.
Processor will notify Controller in writing without undue delay after becoming aware of any Security Incident, in any event within forty-eight (48) hours and reasonably cooperate in any obligation of Controller pursuant to Applicable Data Protection Laws to make any notifications. Processor will take reasonable steps to contain, investigate, and mitigate any Security Incident.
Processor will, within forty-five (45) days of the date of termination or expiry of the Agreement: (a) if requested to do so by Controller, return a copy of all Covered Data; and (b) delete all other copies of Covered Data Processed by Processor or any Sub-processors. Processor shall not retain Covered Data for any purpose for more than sixty (60) days; unless stated otherwise in the Agreement, Processor shall automatically delete or anonymize all Covered Data within ninety (90) days following termination.
This DPA will remain in effect for the duration of the Agreement, and shall remain in effect until, and automatically expire upon, Processor's deletion of all Covered Data as described in this DPA.
The Parties agree that the terms of the Standard Contractual Clauses Module Two (Controller to Processor) and Module Three (Processor to Processor) are hereby incorporated by reference and will apply to any transfers of Covered Data falling within the scope of the GDPR. The governing law for SCCs will be the law of the Republic of Ireland. UK and Swiss Addenda apply as specified in Schedule 3.
If Processor receives Deidentified Data from or on behalf of Controller, Processor will: (a) take reasonable measures to ensure the information cannot be associated with a Data Subject; (b) publicly commit to Process the Deidentified Data solely in deidentified form; and (c) contractually obligate any recipients to comply with Applicable Data Protection Laws.
Processor has implemented the following technical and organizational measures to ensure an appropriate level of security:
Sub-processors
Name |
Address |
Business Category |
Location of Processing |
Data Processed |
Purpose of Processing |
Retention (Company Specific) |
FiveTran |
1221 Broadway, Suite 2400, Oakland, CA 94612, United States |
ETL / Data Pipelines |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Moving data between data sources. |
Typically <24 hours for pipelined data, connection credentials may be retained up to 30 days |
Neon |
209 Orange Street, City of Wilmington, County of New Castle, Delaware 19801 |
Serverless Postgres Database |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Product serverless databases with autoscaling |
TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
Inngest |
600 California Street |
Cloud Job Processing |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
AI code to handle the backend infra, queueing, scaling, concurrency, throttling, rate limiting, and observability |
TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
Clerk |
660 King Street |
Cloud Authentication and Authorization |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Product user authentication and management |
TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days |
Vercel Frontend Cloud |
650 California St |
Serverless Application Hosting |
Global CDN for Assets |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Managed Infrastructure (AWS) |
Logs are stored for 1 day |
OpenAI API Platform |
3180 18th St. |
LLM Inference |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Customer data processing |
No data retention |
Anthropic API (Claude) |
500 Howard Street San Francisco, CA 94105 |
LLM Inference |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference |
Customer data processing |
Deleted within 30 days (exceptions may apply; ZDR available by agreement) |
Google Cloud Vertex AI |
1600 Amphitheatre Pkwy Mountain View, CA 94043 |
LLM Inference |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference |
Customer data processing |
By default, in-memory caching (not at-rest) with ~24-hour TTL; configurable/disable-able; ZDR-related controls available |
Databricks, Inc. |
160 Spear St, 15th Floor San Francisco, CA 94105 |
Data analytics / ETL / warehousing (customer data processing platform) |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent to TI. |
Customer data processing |
Retained for the term of the agreement and any period after termination during which Databricks processes the data per the agreement |
Cloudflare |
101 Townsend St, San Francisco, CA 94107, United States |
DDoS/Bot Protection, Proxying, SSL Certificate Management. |
United States |
Domains/Urls, IP, Location, Browser info |
DDoS/Bot protection |
Up to 30 Days |
Sentry |
45 Fremont Street, 8th Floor, San Francisco, CA 94105 |
Data Logging |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Logging for application improvement, security, and analytics purposes |
Logs retained for 90 Days |
Stripe |
354 Oyster Point Boulevard, South San Francisco, CA 94080 |
Ecommerce / Payment Processing |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer, Card Data |
Payment processing |
Varies depending on legal and regulatory obligations. See Stripe Security And Retention |
Google Analytics |
1600 Amphitheatre Parkway, Mountain View, CA 94043, USA |
Product Analytics |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Product Analytics |
Retained for the term of the agreement and any period after termination per the agreement |
Posthog |
2261 Market Street, Suite 4008, San Francisco, CA 94114, United States |
Product Analytics |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Product Analytics |
Retained for the term of the agreement and any period after termination per the agreement |
Data Dog |
620 8th Ave 45th Floor |
Data Logging |
United States |
Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer |
Logging for application improvement, security, and analytics purposes |
Logs retained for 90 Days |
©2026 Thought Industries, Inc. All rights reserved.