AI Capabilities Terms & Conditions

Business & Legal Terms Summary

This summary is a plain English version of the terms of using Thought Industries' AEO and Conversational AI Learning Features. You can find the legally binding terms and conditions below this summary.

  • Terms: You can cancel the AEO and Conversational AI Learning Features and this Agreement at any time.
  • Customer Data: You own your data in the AEO and Conversational AI Learning Features; on your request, Thought Industries will export the data to you or delete it for you at any time.
  • Services/Outputs: You own all the Outputs generated by the AEO and Conversational AI Learning Features provided to you.
  • Personal Information: Any personal information of users provided by you directly, and any personal information processed by the AEO and Conversational AI Learning Features (e.g., name, email, location) will only be used for provision of the Service to you, and not for any other purpose, and will never be sold, rented or shared with any third parties.
  • Information Security: Your data in the AEO and Conversational AI Learning Features shall be encrypted and Thought Industries adheres to industry security standards.
  • Confidentiality: Customer data processed in the AEO and Conversational AI Learning Features will be kept confidential.
  • Liability: You are not liable for any potential damages to Thought Industries above what you have paid in the previous three (3) months.
  • IP Infringement: Thought Industries will defend intellectual property infringement claims arising from your use of the AEO and Conversational AI Learning Features.
  • Third-Party AI Provider: Your use of the AEO and Conversational AI Learning Features requires additional processing by Thought Industries' third-party AI provider(s), and your use of the Service is subject to the AI provider's policies.

Terms of Service and Software as a Service (SaaS) Agreement

These Terms of Service and Software as a Service (SaaS) Agreement (the "Agreement") is made and is effective upon the date of your acceptance of these terms (the "Effective Date") by and between Thought Industries, Inc., a company incorporated under the laws of Massachusetts (USA) with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109 ("TI" or "we" or "us"), and you, the customer as identified in the applicable purchase terms via TI's website ("Customer" or "you"). The terms of this Agreement shall govern your use of and access to Thought Industries' AEO and Conversational AI Learning Features.

WHEREAS TI is the owner and licensor of the following AI-powered features (collectively, the "Services" herein), each a proprietary Software as a Service-based capability with processing provided by generative AI technology:

  • AEO (Answer Engine Optimization): A feature designed to help Customers optimize their learning content so that it is accurately surfaced, cited, and represented by AI-powered answer engines, large language models, and AI-driven search tools. AEO analyzes existing Customer content and provides recommendations and outputs to improve content discoverability and accuracy within AI-generated responses.
  • Conversational AI Learning: A chat-based learning experience feature that enables learners to interact with course content, learning materials, and knowledge bases through natural language conversations. Conversational AI Learning is designed to deliver contextually relevant responses, guide learner journeys, and support learner engagement within the Customer's learning platform.

WHEREAS the Customer desires to be granted a non-exclusive right to access and use the Services for the purposes described in this Agreement, and TI is willing to grant Customer such rights under the terms and conditions set forth herein.

NOW, THEREFORE, the parties hereby agree as follows:

  1. Software as a Service. Subject to the terms and conditions of this Agreement, including Customer's payment of the Fees set forth herein, TI hereby grants Customer a non-exclusive, non-sublicensable, non-transferable, and limited licensed right throughout the applicable subscription period to access and use the Services, for the Customer's internal business purposes. Use of and access to the Services shall be licensed only as permitted herein, and strictly limited to the AEO and Conversational AI Learning features, functionalities and subscription time period.
  2. SPECIAL LICENSE TERMS. Your use of and access to the AEO and Conversational AI Learning Features is expressly subject to the terms and conditions set forth in the Acceptable Use Policy found in this Agreement; and further governed by the Data Processing Agreement (DPA) also found in this Agreement. THE AEO AND Conversational AI Learning FEATURES' INTEGRATED, THIRD-PARTY GENERATIVE ARTIFICIAL INTELLIGENCE PROVIDER'S LICENSED TECHNOLOGY SHALL BE PROVIDED TO CUSTOMER SUBJECT

TO THE PROVIDER'S TERMS AND CONDITIONS FOUND AT https://openai.com/enterprise-privacy/.

  1. Intellectual Property Rights. "Intellectual Property Rights" for the Services (excluding the Intellectual Property Rights of third-party providers licensed to TI, which are and shall remain the property of such third-party providers, properly licensed to TI) means all intangible legal rights, titles and interests evidenced by or embodied in all: (i) inventions (regardless of patentability and whether or not reduced to practice), improvements thereto, and patents, patent applications, and patent disclosures, together with all reissuances, continuations, continuations in part, revisions, extensions, and reexaminations thereof; (ii) trademarks, service marks, trade dress, logos, trade names, and corporate names, together with translations, adaptations, derivations, and combinations thereof, including goodwill associated therewith, and applications, registrations, and renewals in connection therewith; (iii) any work of authorship, regardless of copyright ability, copyrightable works, copyrights (including moral rights) and applications, registrations, and renewals in connection therewith; (iv) trade secrets and Confidential Information; and (vi) all rights associated with the foregoing and all other proprietary rights and any other similar rights, in each case on a worldwide basis, and copies and tangible embodiments thereof, in whatever form or medium. All Intellectual Property Rights in the Services including any and all compilations of data, derivatives, changes and improvements (including updates thereof) and any suggestions, ideas, enhancement requests, or recommendations provided by Customer or any third party relating to the Services, lie exclusively with TI.

TI shall be the sole owner of any Intellectual Property Rights in the compilation(s) of data derived from the Services, including Service-algorithm-generated compilations and derivatives of data (but excluding any data provided by Customer and Outputs (defined below) generated by the Services for Customer). Nothing in this Agreement shall constitute a waiver of TI's Intellectual Property Rights under any law. All Intellectual Property Rights in Customer's data shall remain with Customer. Customer shall own all Intellectual Property Rights in the Outputs (defined below) generated by the Services exclusively for Customer.

  1. Restrictions of Use. Customer shall (i) not attempt to infiltrate or hack the Services, or any part thereof or reverse engineer, de-compile, disassemble, or otherwise reduce to human-perceivable form the Services' source code; (ii) not represent that it possesses any proprietary interest in the Services; (iii) not directly or indirectly, take any action to contest TI's Intellectual Property Rights or infringe them in any way; (iv) except as specifically permitted by TI in writing, not use the name, trademarks, trade-names, and logos of TI; (vi) except as expressly provided in this Agreement, not use the Services to provide third parties with managed services or any other services; (vii) not make copies of any TI documentation for any third party.
  2. Customer Data and Outputs. By providing your data to TI for processing under the terms of this Agreement, you grant, and you represent and warrant that you have the right to grant, to TI an irrevocable, perpetual license to host, process, use, copy, reproduce, archive, store, cache, reformat, translate, excerpt (in whole or in part), and distribute such data, solely for the purpose of providing you with the Services, and improving the Services, as set forth in this Agreement, and for no other purpose. Your data shall not be used by TI or any integrated third-party provider (including TI's generative artificial intelligence provider) to train any artificial intelligence algorithms or any other machine learning models; and will only be used for providing you with, and improving your use of, your instance of the Services. TI does not assert any rights, Intellectual Property Rights or ownership over your data; and TI does not assert any rights, Intellectual Property Rights or ownership over the Outputs provided to you through the Services. "Outputs" shall mean the responses, recommendations, content, and results provided and displayed in your AEO and/or Conversational AI Learning application(s). For purposes of clarity, Outputs shall not include any Customer data or the proprietary technology used to generate Outputs. You retain full ownership of all Customer data and the Outputs generated by the Services exclusively for you.
  3. Data Protection; User Information and Customer Data. Customer's use of the Services will require that Customer provide TI with certain information regarding its authorized users of the Services, such as name, email, location, employer, IP address (collectively "User Information" herein) for the sole purpose of providing the Services; all of which may be subject to data protection and privacy rules, laws and regulations in multiple jurisdictions. TI's processing of all such User Information shall be governed by the DPA, referenced above. Customer's use of the Services will require that Customer provide TI with access to Customer data and certain databases within the custody or control of Customer, which may include personal data, as defined under applicable data privacy laws (collectively "Customer Data PII") all of which may be subject to data protection and privacy rules, laws and regulations in multiple jurisdictions. TI's processing of all such Customer Data PII shall also be governed by the DPA. To the extent TI will process User Information and Customer Data PII, as personal data defined under applicable privacy laws, TI shall only do so strictly in accordance with the documented instructions received by Customer, as governed by the applicable terms in the DPA.
  4. Service Fees. Customer shall pay TI the following service fees for the use of the Services (collectively, the “Fees”):

Subscription Fees. Customer shall pay the subscription fees set forth in the applicable Ordering Document in accordance with the pricing and payment terms governed by their Ordering Document or if applicable, a separate master services agreement or similar agreement between the parties ("MSA").

Feature Fees. Customer may enable certain optional features within its account, including the Conversational AI Learning and AEO features (as described above). The pricing for each such feature shall be as set forth in Customer’s account. To enable a feature, Customer must provide valid credit card payment information via TI’s Stripe integration. Customer may disable any feature at any time, subject to the payment obligations set forth herein. TI shall provide Customer with at least thirty (30) days’ advance written notice of any price increases for Feature Fees. Following receipt of such notice, Customer may opt out of the applicable feature at any time by disabling it in Customer’s account.

(a) Conversational AI Learning Feature Terms.

(i) Billing. The pricing for the Conversational AI Learning Feature shall be as set forth in Customer’s account. Customer will be charged in arrears for Conversational AI Learning usage monthly on the first of every month.

(ii) Opt-Out. Customer may opt out of the Conversational AI Learning feature at any time by disabling it in Customer’s account. Upon disabling the feature, Customer will only be charged for usage incurred prior to disablement.

(iii) Fraudulent Activity. TI reserves the right to immediately suspend or terminate Customer’s access to the Conversational AI Learning feature if TI reasonably determines that Customer’s use of the feature involves fraudulent activity or abuse.

(b) AEO Feature Terms.

(i) Monthly Fee. The pricing for the AEO Feature shall be as set forth in Customer’s account and or contract. Customer shall pay a monthly or annual fee upfront for access to the AEO feature on the 1st of the month. If Customer disables the AEO feature during a calendar month, Customer shall pay for the remainder of that month, and the AEO feature subscription will not renew for the subsequent month.

  1. Billing and Payment Terms.
    • (a) Payment Terms. TI shall invoice Customer for Fees at the billing cadence set forth in the applicable Ordering Document or, for Feature Fees, as set forth in Section 7. All Fees are non-refundable except as expressly set forth in the Ordering Document or existing MSA with TI or this Aagreement.
    • (b) Payment Methods; Credit Card Surcharge. Customer may pay Fees by credit card or ACH. If Customer elects to pay by credit card, TI may charge Customer a processing surcharge to the extent permitted by applicable law.
    • © (c) Nonpayment and Chargebacks. If Customer fails to pay any Fees when due, Customer will receive notice of such nonpayment. If Customer fails to cure such nonpayment within seven (7) days following receipt of such notice (the “Cure Period”), TI may, at its option: (i) suspend Customer’s access to the Services until all outstanding amounts are paid in full. In the event of a chargeback or payment dispute initiated by Customer’s payment provider, TI may immediately suspend Customer’s access to the Services pending resolution of the dispute. Customer shall be responsible for any costs incurred by TI in connection with collecting past-due amounts, including reasonable attorneys’ fees and collection costs.
    • (d) Repeated Nonpayment for Feature Fees. Notwithstanding the foregoing, if Customer fails to pay Feature Fees when due on two (2) or more occasions (whether or not cured within the applicable Cure Period), TI may, in its sole discretion, suspend Customer’s access to the applicable feature(s).
  2. Taxes. Customer is solely responsible for payment of any applicable sales tax or other tax that may be due in connection with the purchase of the Services.
  3. Disclaimer. TI PROVIDES ACCESS AND USAGE OF THE SERVICES TO CUSTOMERS ON AN "AS IS" BASIS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTY OF MERCHANTABILITY, NON-INFRINGEMENT, AND FITNESS FOR PARTICULAR PURPOSE OR ACCURACY. NOTWITHSTANDING ANYTHING TO THE CONTRARY HEREIN, TI DOES NOT WARRANT THAT THE SERVICES OR ANY INFORMATION OR SERVICES RELATED THERETO WILL BE DELIVERED OR PERFORMED ERROR-FREE OR WITHOUT INTERRUPTION.
  4. Indemnification by TI. TI shall defend, indemnify, and hold harmless Customer from and against any claims, losses, costs, damages, fees or expenses (including reasonable legal fees and expenses) (collectively, "Losses") to the extent resulting directly from third-party claims, actions, suits or proceedings of any kind brought by a third party alleging that the Services infringe intellectual property rights of such third party. As a condition to the defense set forth above, Customer shall (i) give TI prompt notice of any such claim made against it, (ii) grant TI sole control of the defense and settlement of any such claim; and (iii) provide TI with all reasonable information and assistance, at TI's expense. TI's indemnification obligations shall not extend or apply to any such claims arising from Customer's acts or omissions. TI's intellectual property indemnification obligations shall not extend or apply to any information, data, output, responses or the like, provided by third-party artificial intelligence providers integrated within the Services.
  5. Indemnification By Customer. Customer shall defend, indemnify and hold harmless TI and its affiliates from and against any and all Losses to the extent resulting from any claims, actions, suits or proceedings brought by a third party (i) alleging that data provided by the Customer (including User Data and Customer Data PII) processed by the Services, was collected or obtained in violation of any applicable law or regulation; and/or (ii) Customer has violated the terms of this Agreement. TI shall give Customer prompt notice of any such claim made against it, and grant Customer sole control of the defense of any such claim, suit or proceeding, including appeals, negotiations and any settlement or compromise thereof, provided any resolution or settlement of any claim(s) shall require the reasonable consent of TI.
  1. Limitation of Liability. IN NO EVENT SHALL EITHER PARTY'S LIABILITY UNDER, ARISING OUT OF OR RELATING TO THIS AGREEMENT, EXCEED THE AMOUNT OF FEES ACTUALLY PAID TO TI UNDER THIS AGREEMENT IN THE THREE (3) MONTH PERIOD PRECEDING THE EVENT THAT GAVE RISE TO THE CLAIM. IN NO EVENT WILL TI BE LIABLE FOR LOST PROFITS, LOSS OF USE, LOSS OF DATA, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR ANY FOR ANY SPECIAL, INCIDENTAL, INDIRECT, OR CONSEQUENTIAL DAMAGES, HOWEVER CAUSED, AND ON ANY THEORY OF LIABILITY, WHETHER FOR BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE AND STRICT LIABILITY), OR OTHERWISE, WHETHER OR NOT TI HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
  2. Confidential Information. Either party may from time to time during the Term of this Agreement disclose (the "Disclosing Party") to the other party (the "Receiving Party") certain information regarding the Disclosing Party's business, including technical, marketing, financial, pricing information, employee, customer, and other confidential or proprietary information, including without limitation any information either party marks as confidential ("Confidential Information"). Regardless of whether so marked or identified, any information that may be reasonably understood, under the circumstances to be considered confidential or proprietary or a trade secret, including but not limited to the terms and conditions of this Agreement, will be considered Confidential Information of the Disclosing Party.
  3. Protection of Confidential Information. The Receiving Party will not use any Confidential Information of the Disclosing Party for any purpose not expressly permitted by this Agreement, and will disclose the Confidential Information of the Disclosing Party only to the employees and agents of the Receiving Party who need to know such Confidential Information for the purpose of this Agreement and who are under a duty of confidentiality no less restrictive than the Receiving Party's duty hereunder. The Receiving Party will protect the Disclosing Party's Confidential Information from unauthorized use, access, or disclosure in the same manner as the Receiving Party protects its own confidential or proprietary information of a similar nature and with no less than reasonable care.
  1. Confidential Information Exceptions. The Receiving Party's obligations under this Section shall not apply to if such information: (a) was already lawfully known to the Receiving Party at the time of disclosure by the Disclosing Party; (b) was disclosed to the Receiving Party by a third party who had the right to make such disclosure without any confidentiality restrictions; (c) is, or through no fault of the Receiving Party has become, generally available to the public; or (d) was independently developed by the Receiving Party without access to, or use of, the Disclosing Party's Confidential Information.
  2. Publicity. Only upon written agreement of the parties shall either party's name and logo be used or presented on any website or any promotional and marketing activities.
  3. Term and Termination. This Agreement shall be in force and effect as of the Effective Date through the applicable subscription period purchased by Customer. Customer may terminate this Agreement at any time. TI may terminate this Agreement in the event Customer breaches the terms of this Agreement, including non-payment of Fees due herein. No refunds will be made in case of termination by the Customer prior to the expiration of the then current Subscription Period.

GENERAL TERMS of the Agreement:

  1. Governing Law. This Agreement shall be governed by the laws of the Commonwealth of Massachusetts, without reference to its conflict of laws rules. The competent state and federal courts in Massachusetts shall have the exclusive jurisdiction over any dispute arising under this Agreement.
  2. Assignment. This Agreement and any rights under this Agreement may not be assigned by Customer; provided, however, Customer may assign this Agreement with the written consent of TI. Customer may assign this Agreement in case of a sale of all or substantially all of its assets or shares to a third party, or in the event of merger, acquisition or divestiture, as the case may be, provided that prior written notice is delivered to TI with respect to such assignment, no less than ninety (90) days prior to any such assignment; and the assignee agrees in writing to be subject to the terms of this Agreement.
  3. Severability. If any provision of this Agreement will be held to be invalid, that provision shall be replaced with a valid provision implementing the intent of the parties at the time of the signing of this Agreement.
  4. Force Majeure. Except for Customer's obligation to pay amounts due under this Agreement, neither party hereto shall be liable for any loss, damage, or penalty resulting from such party's failure to perform its obligations hereunder when such failure is due to events beyond its reasonable control, including, without limitation, flood, earthquake, fire, acts of God, military insurrection, civil riot, or labor strikes.
  5. Entire Agreement. This Agreement (and exhibits attached thereto) unless subject to an Evaluation or Trial Period Agreement, constitutes the entire agreement between TI and Customer and supersedes any previous agreements or representations, either oral or written. This Agreement may be amended, terminated, or altered only by an instrument in writing signed by individuals of appropriate authority of both parties.
  6. Notices. Any notice or report required or permitted by this Agreement shall be deemed given if (i) delivered personally to an officer of the other party, (ii) sent by first class mail, postage prepaid, to the address given in this Agreement, or (iii) sent by email to the email address provided by either party.

AI Features Evaluation Agreement

Summary of AI Features Evaluation Agreement:

  • Customer is provided the opportunity to access and use the AEO and/or Conversational AI Learning Features to evaluate the service for a period based on their agreement with their AMs.
  • Customer can elect to enter into said paid features, or not, after the Evaluation Period.
  • Customer can terminate this Agreement at any time. If not terminated by the parties, this Agreement will terminate at the end of the Evaluation Period without any liability to the Customer.
  • This Agreement is subject to TI's Terms of Service found herein.
  • TI will protect Customer's data as confidential information.

Overview; Binding Agreement. This Evaluation Agreement (the "Agreement") is made by and between and applies to Thought Industries, Inc. ("TI", "we", or "us" herein), and the customer/user ("Customer", or "you" herein) accepting the terms of this Agreement and accessing or using the AEO and/or Conversational AI Learning Features. By accepting these terms and accessing or using the AI Features, you agree to be bound by this Agreement. If you do not agree to this Agreement, you are not allowed to access or use the AI Features. The "Effective Date" of this Agreement is the date you first access or use any aspect of the AI Features. TI reserves the right to change or modify this Agreement at any time upon notice to you. For the purposes of this Agreement: (i) "AI Features" means the TI-proprietary SaaS AEO and/or Conversational AI Learning Feature(s) that you will be allowed to use and access during the Evaluation Period; (ii) the "Evaluation Period" means up to one hundred twenty (120) days from the Effective Date (unless set forth otherwise in an applicable Ordering Document); and (iii) the "Ordering Document" is the order form or other ordering document completed by the Customer identifying the applicable AI Feature(s) to be evaluated.

Evaluation License; Restrictions. Subject to the terms of this Agreement and the AI Features Terms of Service which are incorporated herein by reference, TI grants you a revocable, limited, non-exclusive, nontransferable, non-sublicensable right to access and use the AI Feature(s) during the Evaluation Period, solely for the purpose of internally evaluating whether to purchase a paid subscription, and not for any other purpose or use. Unless otherwise set forth in the Ordering Document, there is no fee associated with this grant of access during the Evaluation Period. You agree not to: (i) sublicense, sell, rent, assign, or distribute the AI Features to third parties; (ii) allow any third party to access or use the AI Features under the rights granted to you herein; (iii) host the AI Features for the benefit of third parties; (iv) modify the AI Features, or any proprietary rights notices therein; or (v) disassemble, decompile, or reverse engineer the AI Features.

Term and Termination. Unless terminated as provided for herein, this Agreement will continue in effect throughout the Evaluation Period. This Agreement will automatically terminate without the requirement of notice at the end of the Evaluation Period unless the parties mutually agree in writing to an extension. Customer can terminate this Agreement at any time with written notice to TI. TI can terminate this Agreement immediately upon written notice in the event you breach the terms of this Agreement. When this Agreement terminates or expires: (i) the Evaluation Period will end; and (ii) you will no longer have the right to access or use the AI Features. The following provisions will survive: Restrictions; No Warranty; Disclaimer; Confidentiality; Limitation of Liability; Miscellaneous.

No Warranty; Disclaimer; Limitation of Liability. You acknowledge and agree that the AI Features are being provided "AS-IS" and without warranty of any kind, express or implied. WE HEREBY SPECIFICALLY DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING BUT NOT LIMITED TO WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT. IN NO EVENT WILL WE BE LIABLE TO YOU OR TO ANY THIRD

PARTY FOR DAMAGES OF ANY KIND, INCLUDING, WITHOUT LIMITATION, DIRECT, INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THIS AGREEMENT.

Customer Warranty. When you access or use the AI Features you represent and warrant as follows: (i) that you will not use the AI Features for any purpose other than the limited evaluation set forth herein; and (ii) that your use of the AI Features will comply with all applicable laws and regulations.

Confidentiality. For the purposes of this Agreement, "Confidential Information" means any business or technical information that either party discloses to the other pursuant to this Agreement. The AI Features and associated documentation will be deemed to be TI Confidential Information. Neither party will use the other party's Confidential Information, except as permitted under this Agreement. Each party agrees to maintain in confidence and protect the other party's Confidential Information using at least the same degree of care as it uses for its own information of a similar nature, but in all events at least a reasonable degree of care. Any personal data processed on your behalf during the Evaluation Period by the AI Features is subject to the terms of our DPA found herein.

Miscellaneous. The English version of this document will prevail over any translation. You agree to indemnify, defend, and hold TI harmless from and against any third-party claims arising out of or relating to your access to or use of the AI Features not in accordance with the terms of this Agreement. This Agreement will be governed by the laws of the Commonwealth of Massachusetts. Any legal action or proceeding arising under this Agreement will be brought exclusively in the appropriate federal or state courts located in Suffolk County, Massachusetts. Neither party may assign this Agreement without the other party's written consent. This Agreement (including the agreements incorporated herein) is the entire agreement of the parties with respect to its subject matter.

Acceptable Use Policy for AEO and Conversational AI Learning Features

Context:

This Acceptable Use Policy ("AUP") is designed to mitigate potential risks of using the AEO and Conversational AI Learning Features in inappropriate, unintended, and unacceptable settings or in industries that are unaligned with the true purpose and contractually permitted use of these features. This AUP will be subject to on-going revision and updating as further refinements are implemented.

Thought Industries, Inc. ("TI") currently has no staff dedicated to overseeing and enforcing this policy and potential violations will be handled reactively; further, it is the duty of each TI customer to provide this AUP to its authorized users of the AEO and Conversational AI Learning Features and provide reasonably necessary instructions and prohibitions to its users.

Scope:

The Policy below assumes the AEO and Conversational AI Learning Features are provided primarily on a B2B-basis, with TI's customers operating as organized businesses, which then permit their authorized users to access and use the AI Features.

Policy: You (and your authorized users) agree not to use the AEO or Conversational AI Learning Features for the following activities and use cases. This list is representative and non-exhaustive; TI retains the right to revise and update this Policy.

  • Adult industries or sexually explicit content and services;
  • Bullying, harassment, or threatening behavior;
  • Controlled and illegal substances (e.g. drugs, pharmaceuticals, etc.);
  • Deceptive, fraudulent, or misleading practices and services (e.g. comment and review generation, impersonation, multi-level marketing and pyramid schemes, plagiarism, spam, etc.);
  • Discrimination, hate speech, and hateful content;
  • Automated decision making regarding natural persons;
  • Gambling, lending, trading, or other financial activities;
  • Tracking, locating or monitoring any natural person; queries of natural persons;
  • Financial decision making or creditworthiness of any natural person;
  • Health, medical, or therapy applications for natural persons;
  • Inappropriate or invasive use of confidential or personal information;
  • Influencing campaigns, elections, or other political activities;
  • Interfering with or negatively impacting the AEO and/or Conversational AI Learning Features;
  • Malware, phishing, or viruses; SPAM and marketing email;
  • Products and services infringing on the intellectual property or rights of others;
  • Products, services, or activities that violate applicable laws and regulations;
  • Violence or harm against persons, animals, or property (including encouragement, facilitation, or support);
  • Violent extremism or terrorism (including encouragement, facilitation, or support);
  • Weapons, explosives, and dangerous materials; and
  • Using the AI Features in violation of any natural person's rights, including privacy rights as defined in applicable, global privacy laws.

Data Processing Agreement (DPA)

The scope and applicability of this Data Processing Agreement ("DPA") applies to Thought Industries, Inc., a Massachusetts corporation, with its principal place of business at 6 Liberty Square, #6099, Boston, MA 02109, ("TI") and its processing of Personal Data on your behalf; you (TI's customer) are the "Controller" under this DPA and TI is the "Processor" in connection with the provision of TI's AEO and Conversational AI Learning Features specified in the applicable TI Terms of Service and Software as a Service (SaaS) Agreement (the "Agreement"); and more specifically, the processing of "User Information" and "Customer Data PII" under the terms of the Agreement. Unless otherwise expressly stated in the Agreement, this DPA shall be effective and remain in force for the full term of the Agreement.

DEFINITIONS


"Applicable Data Protection Laws" — means all applicable laws, rules, regulations, and governmental requirements relating to the privacy, confidentiality, or security of Personal Data, as they may be amended or otherwise updated from time to time.

"Controller Affiliate" — means an affiliate of Controller who is a beneficiary to the Agreement.

"Covered Data" — means Personal Data that is provided by or on behalf of Controller to Processor in connection with the Services.

"Data Subject" — means a natural person whose Personal Data is Processed.

"Deidentified Data" — means data created using Covered Data that cannot reasonably be linked to such Covered Data, directly or indirectly.

"EEA" — means the European Economic Area including the European Union ("EU").

"GDPR" — means Regulation (EU) 2016/679 (the "EU GDPR") or, where applicable, the "UK GDPR" as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the UK European Union (Withdrawal) Act 2018 or, where applicable, the equivalent provision under Swiss data protection law.

"Instruction" — means any documented instruction, submitted by Controller to Processor, directing Processor to perform a specific action with regard to Covered Data.

"Personal Data" — means any data or information that: (a) is linked or reasonably linkable to an identified or identifiable natural person; or (b) is otherwise "personal data," "personal information," "personally identifiable information," or similarly defined data or information under Applicable Data Protection Laws.

"Processing" — means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means.

"Security Incident" — means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Covered Data.

"Services" — means the AEO and Conversational AI Learning Features to be provided by Processor pursuant to the Agreement.

"Standard Contractual Clauses" or "SCCs" — means Module Two (controller to processor) and/or Module Three (processor to processor) of the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, dated June 4, 2021.

"Sub-processor" — means an entity appointed by Processor to Process Covered Data on its behalf.

"US Data Protection Laws" — means, to the extent applicable, federal and state laws relating to data protection and privacy in force in the United States, including (but not limited to) the CCPA, CPRA, Colorado

Privacy Act, Connecticut Personal Data Privacy and Online Monitoring Act, Utah Consumer Privacy Act, Virginia Consumer Data Protection Act, Texas Data Privacy and Security Act, and Oregon Consumer Privacy Act.

Interaction with the Agreement

This DPA is incorporated into and forms an integral part of the Agreement. This DPA supplements and (in case of contradictions) supersedes the Agreement with respect to any Processing of Covered Data. Controller acknowledges that Processor's Services are not designed, intended, or provided for the purpose of making predictions regarding any Data Subject, determining creditworthiness, or any other manner of automated decision-making regarding Data Subject(s). The scope of Processor's Services is set forth in the Agreement, and Controller shall not permit any authorized user to utilize the Services for any other purpose.

Role of the Parties

For the purposes of this DPA, and for purposes of the GDPR, Processor acts as "processor" or "sub-processor" as determined by the then-applicable function of Controller. For the purposes of US Data Protection Laws, Processor will act as a "service provider" or "processor" as defined in US Data Protection Laws.

Detail of Data Processing

    • Covered Data will only be Processed on behalf of and under the Instructions of Controller and in accordance with Applicable Data Protection Laws.
    • Processor is prohibited from: (a) selling Covered Data; (b) sharing Covered Data for cross-context behavioural advertising; (c) retaining, using, or disclosing Covered Data for any purpose other than the business purposes specified in the Agreement; (d) retaining, using, or disclosing Covered Data outside of the direct business relationship between the Parties; and (e) combining Covered Data with Personal Data received from other persons, except as permitted by Applicable Data Protection Laws.
    • Processor will ensure that personnel are subject to obligations reasonably consistent with the terms of this DPA.
    • Processor will reasonably cooperate and provide Controller with information to enable Controller to conduct and document any data protection assessments required under Applicable Data Protection Laws.
    • Controller will have the right to take reasonable and appropriate steps to ensure that Processor uses Covered Data in a manner consistent with Controller's obligations under Applicable Data Protection Laws.
    • Processor is permitted to anonymize Covered Data through a reliable state of the art anonymization procedure and use such anonymized data for its internal business purposes.

Sub-processors


Controller grants Processor the general authorisation to engage Sub-processors, subject to the requirements below, as well as Processor's current Sub-processors listed in the Sub-Processors Schedule as of the Effective Date. Processor will: (i) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than Processor's obligations under this DPA; and (ii) remain liable for each Sub-processor's compliance. Processor will provide Controller with at least fifteen (15) days' notice of any proposed changes to Sub-processors. Controller may object to a new Sub-processor based upon reasonable data privacy and data security concerns within ten (10) days of notice.

Data Subject Rights Requests


As between the Parties, Controller will have sole discretion and responsibility in responding to rights asserted by individuals in relation to Covered Data under Applicable Data Protection Laws. Processor will forward to Controller promptly any Data Subject Request received and will provide Controller with reasonable assistance as necessary for Controller to fulfil its obligations.

Security and Audits

Processor will implement and maintain appropriate technical and organizational data protection and security measures designed to ensure security of Covered Data, including protection against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. Audits will be conducted: (i) upon reasonable written notice; (ii) only once per year; (iii) only during Processor's normal business hours; and (iv) in a manner that does not disrupt Processor's business. Controller will bear the costs for any audit initiated by Controller.

Security Incidents

Processor will notify Controller in writing without undue delay after becoming aware of any Security Incident, in any event within forty-eight (48) hours and reasonably cooperate in any obligation of Controller pursuant to Applicable Data Protection Laws to make any notifications. Processor will take reasonable steps to contain, investigate, and mitigate any Security Incident.

Deletion and Return

Processor will, within forty-five (45) days of the date of termination or expiry of the Agreement: (a) if requested to do so by Controller, return a copy of all Covered Data; and (b) delete all other copies of Covered Data Processed by Processor or any Sub-processors. Processor shall not retain Covered Data for any purpose for more than sixty (60) days; unless stated otherwise in the Agreement, Processor shall automatically delete or anonymize all Covered Data within ninety (90) days following termination.

DPA Contract Period

This DPA will remain in effect for the duration of the Agreement, and shall remain in effect until, and automatically expire upon, Processor's deletion of all Covered Data as described in this DPA.

Standard Contractual Clauses

The Parties agree that the terms of the Standard Contractual Clauses Module Two (Controller to Processor) and Module Three (Processor to Processor) are hereby incorporated by reference and will apply to any transfers of Covered Data falling within the scope of the GDPR. The governing law for SCCs will be the law of the Republic of Ireland. UK and Swiss Addenda apply as specified in Schedule 3.

Deidentified Data

If Processor receives Deidentified Data from or on behalf of Controller, Processor will: (a) take reasonable measures to ensure the information cannot be associated with a Data Subject; (b) publicly commit to Process the Deidentified Data solely in deidentified form; and (c) contractually obligate any recipients to comply with Applicable Data Protection Laws.

Schedule 2: Technical and Organizational Measures

Processor has implemented the following technical and organizational measures to ensure an appropriate level of security:

  1. Organizational management and dedicated staff responsible for the development, implementation, and maintenance of Processor's information security program.
  2. Audit and risk assessment procedures for periodic review and assessment of risks, monitoring and maintaining compliance with Processor's policies and procedures.
  3. Utilization of commercially available and industry standard encryption technologies for Covered Data transmitted over public networks or when stored at rest.
  4. Data security controls including logical segregation of data, logical access controls based on authority levels and job functions, use of unique IDs and passwords, and periodic review.
  5. Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords.
  6. System audit or event logging and related monitoring procedures to proactively record user access and system activity for routine review.
  7. Physical and environmental security of data center, server room facilities and other areas containing Personal Data.
  8. Operational procedures and controls for configuration, monitoring and maintenance of technology and information systems, including secure disposal.
  9. Change management procedures and tracking mechanisms designed to test, approve, and monitor all changes to Processor's technology and information assets.
  10. Incident/problem management procedures designed to allow Processor to investigate, respond to, mitigate, and notify of events related to Processor's technology and information assets.
  11. Network security controls including firewall systems and other traffic and event correlation procedures designed to protect systems from intrusion.
  12. Vulnerability assessment, patch management and threat protection technologies and scheduled monitoring procedures.
  13. Business resiliency/continuity plan and procedures designed to maintain service and/or recovery from foreseeable emergency situations or disasters.

Sub-processors

Name
Address
Business Category
Location of Processing
Data Processed
Purpose of Processing
Retention (Company Specific)
FiveTran

1221 Broadway, Suite 2400, Oakland, CA 94612, United States

ETL / Data Pipelines

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Moving data between data sources.

Typically <24 hours for pipelined data, connection credentials may be retained up to 30 days

Neon

209 Orange Street, City of Wilmington, County of New Castle, Delaware 19801

Serverless Postgres Database

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Product serverless databases with autoscaling

TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days

Inngest

600 California Street
Suite 1200
San Francisco, CA 94109

Cloud Job Processing

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

AI code to handle the backend infra, queueing, scaling, concurrency, throttling, rate limiting, and observability

TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days

Clerk

660 King Street
Unit 345
San Francisco, California, 94107

Cloud Authentication and Authorization

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Product user authentication and management

TI controls this retention = duration of services and up to 45 days post churn. Backups age off after 90 days

Vercel Frontend Cloud

650 California St
San Francisco, CA 94108

Serverless Application Hosting

Global CDN for Assets
United States-Generated Content

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Managed Infrastructure (AWS)

Logs are stored for 1 day

OpenAI API Platform

3180 18th St.
San Francisco, CA 94110

LLM Inference

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Customer data processing

No data retention

Anthropic API (Claude)

500 Howard Street

San Francisco, CA 94105

LLM Inference

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference

Customer data processing

Deleted within 30 days (exceptions may apply; ZDR available by agreement)

Google Cloud Vertex AI 

1600 Amphitheatre Pkwy

Mountain View, CA 94043

LLM Inference

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent for inference

Customer data processing

By default, in-memory caching (not at-rest) with ~24-hour TTL; configurable/disable-able; ZDR-related controls available

Databricks, Inc.

160 Spear St, 15th Floor

San Francisco, CA 94105

Data analytics / ETL / warehousing (customer data processing platform)

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other customer-provided data sent to TI.

Customer data processing

Retained for the term of the agreement and any period after termination during which Databricks processes the data per the agreement

Cloudflare

101 Townsend St, San Francisco, CA 94107, United States

DDoS/Bot Protection, Proxying, SSL Certificate Management. 

United States

Domains/Urls, IP, Location, Browser info

DDoS/Bot protection 

Up to 30 Days

Sentry

45 Fremont Street, 8th Floor, San Francisco, CA 94105

Data Logging

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Logging for application improvement, security, and analytics purposes

Logs retained for 90 Days

Stripe

354 Oyster Point Boulevard, South San Francisco, CA 94080

Ecommerce / Payment Processing

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer, Card Data

Payment processing

Varies depending on legal and regulatory obligations. See Stripe Security And Retention

Google Analytics

1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

Product Analytics

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Product Analytics

Retained for the term of the agreement and any period after termination per the agreement

Posthog

2261 Market Street, Suite 4008, San Francisco, CA 94114, United States

Product Analytics

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Product Analytics

Retained for the term of the agreement and any period after termination per the agreement

Data Dog

620 8th Ave 45th Floor
New York, NY 10018 USA

Data Logging

United States

Customer info, company name, personal name, email address, location, order history, order information, and any other salesforce data provided by the customer

Logging for application improvement, security, and analytics purposes

Logs retained for 90 Days