Terms of Use
Published on 14 Sep 2026 | Effective date: 1 Oct 2026
These Terms of Use together with any Service Order and the1. Definitions
2. Access to the Product
2.1. Subject to the terms and conditions of these Terms of Use and Service Order, if any, Company is granted access to the Product during the Term and we hereby grant Company a limited, non-exclusive, non-transferrable, revocable license during the Term, without rights to sublicense, to access, install and use the Product and any related add-ons or updates.2.2 Access to the Product is restricted to Users only. Each assigned seat is assigned to a single, designated user and may not be used by multiple individuals. The Product is licensed for use by the Company’s Users, who must be natural persons only, and may not be accessed or utilized by automated systems, bots, scripts, or third-party services without prior written authorization. Limitations to the Product applies as described in Fair Use Policy and Documentation.2.3. Company is responsible for compliance with the provisions of the Service Order and these Terms of Use by all its Users. Company is also responsible for determining whether the Product is suitable for specific uses in light of any regulations or restrictions Company might be subject to.2.4. Company is solely responsible for obtaining the authorizations, licenses and consents, if and as required by any applicable law, to submit Company Data to the Product and that the use of the Product by Company will not violate any applicable law, any third-party Intellectual Property Rights, license terms that apply to open-source software, all applicable Data Protection Legislation, publicity, or other rights. If the Company integrates API keys for external third-party services contracted by the Company into the Product, the Company represents and warrants that it holds all necessary rights, licenses, and permissions, including any required sublicensing rights, to allow such third-party APIs to be accessed and used via the Product. The Company shall remain solely responsible and liable for its use of any third-party services and for compliance with the applicable third-party terms.2.5. Notwithstanding anything to the contrary in the Service Order and/or these Terms of Use and subject to the limitations provided in the applicable regulations, we expressly disclaim any and all liability related to or arising from Company’s use of information, guidance or any other output obtained through the Product. Company acknowledges and agrees that it is its own sole responsibility to assess, verify, and ensure the appropriateness, accuracy, and suitability of output obtained from the Product for its specific applications, Products, or processes.3. Acceptable Use
3.1. Company represents and warrants that the administrator signing, registering or otherwise accepting these Terms of Use and / or using the Product with administrator rights on behalf of the Company (Administrator) has been duly authorized to enter into these Terms of Use and legally bind the Company and act for the Company. 3.2. Company is solely and fully liable for Company Data and any and all activity that takes place on its Product account. We shall have no responsibility or liability whatsoever for Company Data and other materials and copyrightable materials such as, but not limited to, literary works, text, images, photos, videos, and any other materials, which may have been submitted to the Product by Users.3.3. We are not responsible for the way Company uses the Product. We reserve the right to immediately terminate, without notice, the use of the Product by Company in the event of detection of fraudulent, illegal or, according to us, Company’s use of the Product in a manner that is not compliant with the4. Third Party Services; Third-Party Components
4.1. The Product uses and/or includes third party software, files, large language models (LLM’s) and components that may also be subject to open source and other third-party license terms (“Third-Party Components”). Company acknowledges that the use of such Third-Party Components may be subject to separate terms and is responsible for ensuring its use of the Product complies with any applicable third-party license terms. We are not the author, owner or licensor of such Third-Party Components, and we make no warranties or representations, express or implied, as to the quality, capabilities, operations, performance or suitability of Third-Party Components and we are not liable for any Third-Party Components. 4.2. You may purchase the Services through authorized partners, such as distributors or resellers (“Authorized Partner”). If a Company purchased the Services through an Authorized Partner, then Company’s use of the Services is subject to these Terms of Use. Any terms agreed between Company and the Authorized Partner that are in addition to or inconsistent with these Terms of Use are solely between Company and the Authorized Partner. No agreement between Company and an Authorized Partner is binding on us, nor will it have any force or effect with respect to the use of the Services.4.3. The Product enables the Company and its Users to access third-party AI models made available by their respective providers ("Model Providers") through a unified interface. Access to and use of each such model may be subject to the applicable terms, acceptable use policies, and usage restrictions of the relevant Model Provider ("Model Terms"). The Company acknowledges and agrees that: (i) it is solely responsible for reviewing, and for ensuring that it and all of its Users comply with, the Model Terms applicable to each model it selects and uses; (ii) it is responsible for determining whether the applicable Model Terms permit its and its Users' intended use of the Product, Inputs, and Outputs, including for any regulated, high-risk, or customer-facing use; and (iii) it is responsible for all acts and omissions of its Users in connection with any model and the applicable Model Terms. Where the Company incorporates the Product, or any Output, into products or services made available to its own customers or other third parties, the Company shall procure that such customers and third parties comply with the applicable Model Terms to the extent required by the relevant Model Provider.4.4 Model Terms may be modified, supplemented, or replaced by the relevant Model Provider from time to time, and Model Providers may add, remove, restrict, suspend, or discontinue availability of any model at any time, with or without notice to us or to the Company. We may suspend, restrict, or disable the Company's or any User's access to any model where we reasonably believe that the Company or a User has violated, or may violate, applicable Model Terms, or where we are required or requested to do so by the relevant Model Provider. We shall have no liability for any suspension, restriction, disablement, unavailability, degradation, or modification of any model arising from or related to the Model Terms or the acts or omissions of any Model Provider.5. Confidentiality
5.1. Each party (i) shall treat as confidential all Confidential Information of the other party, (ii) shall not use such Confidential Information except to exercise its rights and perform its obligations under these Terms of Use, (iii) shall not disclose such Confidential Information to any third party (other than employees, any employees of any affiliates, and professional advisers with a need to know, in all cases provided such employees and advisers are bound by confidentiality terms no less protective than the terms in these Terms of Use), and (iv) shall use at least the same degree of care it uses to prevent the disclosure of its own Confidential Information of similar importance. The recipient may disclose Confidential Information pursuant to an order or requirement of a court, administrative agency, or other governmental body, provided that recipient provides prompt, advance written notice thereof to disclosure to enable disclosure to seek a protective order or other similar relief. 5.2. All Confidential Information related to the Product shall remain the sole and exclusive property of us, and no license or other right to such Confidential Information or our Intellectual Property Rights is granted or implied hereby to the receiving party.6. Fees and Payment
6.1. We shall invoice Fees on a monthly basis unless agreed otherwise. All Fees due and payable to us shall be paid to the bank account indicated by us and shall be paid and received by us in cleared funds within thirty (30) days following the invoice date. Company explicitly agrees that we may email invoices to Company in PDF format to a Company provided email address and shall be deemed received by Company the same day. Company shall pay all Fees due to us under the Service Order without any set-off, counterclaim and/or any other deductions or withholding of monies.6.2. We reserve the right to change Fees at our discretion for any renewal or extension of the Term. To the extent Fees are set by Third-Party Components, we have the right to increase such Fees as the Third-Party Components fees are increased. We may require prepayment for the Services all of which are subject to our supplemental Credit Use Policy. We may charge for any additional Services. 6.3. Notwithstanding any other rights of us, in the event of late payment by Company, we shall be entitled to interest on the amount owing but unpaid at an annual rate equal to one and half percent (1.5%) per month compounded daily (or the highest interest rate permitted by applicable law) from the date due until paid in full.6.4. The Fees are exclusive of all taxes. Company agrees to pay and/or reimburse us all amounts (whether fees, charges or otherwise) payable to us without set off and without deduction for any taxes (“Deduction”). All such taxes (exclusive of any taxes based upon our income) shall be assumed by and paid for by Company, regardless of whether such taxes are included in any invoice sent to Company by us. Accordingly, if Company is at any time required by any applicable law to make a Deduction from any payment or reimbursement due to us, then the amount due by Company to us shall be increased by such amount as will result, notwithstanding the making of such Deduction, in our receipt ultimately on the due date for payment of the amount that we would have received if Company had not been required to make such Deduction.6.5. If Company is required by law to make any withholding from any sum payable to us, Company shall send notice to us at least thirty (30) days prior to the payment due date, detailing the payment amount due. Company shall provide us with a copy of the completed certificate of withholding and/or any other document issued by the relevant tax authority demonstrating any payment of withholding taxes, within up to thirty (30) days after making such payment. Company shall not make any withholding for liabilities arising from acts or omissions including, without limitation, late or incorrect withholding amounts.6.6. You may purchase our Product directly through us on our website, by providing a valid payment method accepted on our website (such as a credit or debit card). Parties agree that a payment service provider, which handles such payments, will be used subject to additional terms.7. Refunds
7.1. Eligibility for a Refund. Company is eligible to claim a refund under the following conditions: (i) Where applicable, a refund request is made within 14 (fourteen) calendar days of your initial purchase date for our Services. Initial purchase means the first-time purchase and the earliest created order; (ii) Any Refund shall apply only to the unused portion of Product. Accordingly, if the Product have been fully consumed, no amount will be refundable, even where the refund request is made within the 14 (fourteen) calendar day period; (iii) Refunds will not be provided for any additional services, features, add-ons, or renewals purchased during the Term or used consumption fees. 7.2. Refund Process. To request a refund, please follow these steps: (i) Send a message to our chat support within the Product or via email at [email protected]; (ii) Provide your refund request Our team will review your request. Refunds will be processed back to the original method of payment, subject to any currency exchange fluctuations, fees, or deductions as required by the payment provider, all of which shall be borne by the Company. 7.3. Exceptions to Refunds. Refunds shall not be provided in the following situations: (i) If your account was suspended or terminated due to a violation of our Terms of Use; (ii) For payments made using cryptocurrency, prepaid cards, or gift cards; (iii) For the Services purchased through Authorized Partners. Any refund requests for such purchases should be under the terms and conditions of the Authorized Partner.8. Service Levels
8.1. The parties agree that the provisions of the Service Level Agreement attached as Schedule C shall govern the availability of the Product pursuant to these Terms of Use.9. Data Protection
9.1. The parties agree that the provisions of the Data Processing Agreement attached as Schedule D shall govern the processing of the Personal Data in connection with Company’s use of the Product pursuant to these Terms of Use.10. Intellectual Property
10.1. Company acknowledges that we (or our licensors) are and shall continue to be the sole owner of all Intellectual Property Rights in and to the Product, and any modifications, improvements and/or derivatives thereof (“Improvements”). 10.2. Company shall not: modify or create derivative works of the Product; reverse engineer, reverse assemble, reverse compile, decompile, translate, engage in model extraction or stealing attacks, or otherwise attempt to discover the source code or underlying components of models, algorithms, and systems of the Product to the extent such restrictions are not contrary to applicable mandatory law; use the Product to develop solutions that compete with the Product; and try to extract data from the Product in any way other than specifically permitted under these Terms of Use;10.3. Company exclusively owns and reserves all rights, titles, and interest to Company Data, subject to our worldwide, non-exclusive and royalty-free right to process, disclose and transfer Company Data only as necessary to maintain and improve the Product and/or otherwise permitted by the Terms of Use. Company hereby grants us a limited worldwide license to use any Company Data and corresponding Intellectual Property which its Users submit to the Product as may be necessary and which is required to run and optimize the Product.10.4. The Parties agree that we may use Company Data and/or information about the use of the Product to provide support, maintain and improve, including optimization of infrastructure and the algorithms that are used in the software, provided such use does not result in direct identification of the Company or any individual, unless we must use the Company Data in a manner that does identify the Company or any individual for example to provide support. Where the Product enables Company to access third-party LLMs or models that may use inputs for training, re-training, or fine-tuning, such use is subject to the respective third-party terms. We provide Company with controls to enable or disable the use of such models within the Product. The Company is solely responsible for its choice to use models that may incorporate inputs into training.10.5. Any Intellectual Property which might be created by Company with the help of the Product would be owned by Company.10.6. As between the Company and us, and subject to the rights of Model Providers under the applicable Model Terms and to any limitations of Intellectual Property Rights in respect of AI-generated content, the Company owns the Output generated through its and its Users' use of the Product. We claim no ownership of Output. The Company's ownership of, and rights to use, any Output may be subject to, conditioned upon, or limited by the applicable Model Terms, and the Company is solely responsible for reviewing and complying with those terms. We make no representation or warranty that any Output is accurate, complete, non-infringing, or suitable for any particular purpose, and, without prejudice to Clause 2.5, the Company is solely responsible for evaluating Output and for implementing appropriate human review and safeguards before relying on or using any Output.11. Indemnity
11.1. We shall indemnify Company against third party claims that the use of the Product (excluding output) as specified in, and fully in accordance with these Terms of Use, infringes any Intellectual Property Right of such third party ("Intellectual Property Infringement Claim"), provided that Company: (i) gives notice to us of any Intellectual Property Infringement Claim promptly after becoming aware of it; (ii) gives us sole control over the conduct of the defense to any claim or action in respect of any Intellectual Property Infringement Claim and does not, at any time, admit liability or otherwise attempt to settle or compromise said Claim or action except upon the express instructions of us; and (iii) acts in accordance with the reasonable instructions of us and gives to us such assistance as it shall reasonably require in respect of the conduct of the defense.11.2. In addition to the foregoing, in the event that the use of the Product for any activity contemplated under these Terms of Use is recognized by us or by a final and unappealable order of a competent court as infringing any Intellectual Property Right belonging to a third party, we shall at our option: (i) use reasonable efforts to modify the Product, if this is reasonably possible from both a technical and economic perspective; or (ii) procure for Company a license to continue using the Product or the infringing component thereof, on reasonable terms and conditions corresponding to standard industry practice in this field.11.3. The foregoing provisions of this Clause 12 state our entire liability with regard to the Intellectual Property Infringement Claims, subject always to the provisions of Clause 14 of these Terms of Use.12. Trade Controls
12.1. Company represents and warrants that in its activities with respect to the Service Order and these Terms of Use, it, including its Affiliates, officers, employees, and other agents, shall comply with Trade Controls, and that it shall not cause us, directly or indirectly, to be in violation of, or to be exposed to penalties, sanctions, or other adverse consequences under, Trade Controls.12.2. Company represents and warrants that it and its Affiliates, officers, employees, and other agents, are not Restricted Persons and that, in their activities, they shall not cause or permit, directly or indirectly, any export, reexport, transfer (including in-country transfer), retransfer, disclosure, or provision of commodities, software, technology, source code, or services to or for the benefit of a Restricted Person.12.3. Company represents and warrants that in its use of the Product, it, including its Affiliates, officers, employees, and other agents, shall not upload or otherwise transfer to us or seek provision from us of any technical data, technology, software, or code that are subject to applicable Trade Controls, including but not limited to items or services controlled under military or dual-use export control regulations.13. Liability
13.1. Subject to Clause 13.4, our total aggregate liability (whether contractual, in tort or otherwise) in respect of all claims arising under or in connection with the Service Order and these Terms of Use shall be for direct losses only and shall not exceed the amount of fees paid to us by Company under the respective Service Order during the twelve (12) months period immediately preceding the date when such liability arises, or EUR 1.000 (one thousand euro), whichever is higher.13.2. In no event shall we be liable under the Service Order and these Terms of Use for any consequential damages resulting from the use of the Product, including but not limited to, damages for loss of profits, goodwill, use, business, revenues, data or other intangible losses.13.3. In no event shall we be liable for damages or fines imposed by any regulator or court on Company for a breach by Company of any applicable Data Protection Legislation or AI Legislation (including the EU AI Act), as a result of Company's use of the Product unless and solely to the extent resulting from our breach of applicable Data Protection or AI Legislation (including the EU AI Act), the terms of the Data Processing Agreement attached as Schedule D or any other supplemental agreement. 13.4. We do not exclude or limit our liability to Company for damages arising from our management's willful intent or gross negligence.14. Term and Termination
14.1. These Terms of Use shall enter into force upon the Effective Date. The Terms of Use will automatically renew (i) for the same time period as the expiring Term: for subscriptions with a fixed term, the Company may terminate by providing us with at least 30 days’ prior written notice before the end of the then-current Term (email notice is sufficient). To the extent Company has been granted any term and/or renewal related discount, any such discount will have to be reimbursed if these Terms of Use terminate before the end of the period over which such discount has been calculated. (i) for month-to-month subscriptions, the Company may terminate these Terms of Use at any time by cancelling the nexos.ai subscription via the platform. The subscription will remain active until the end of the current billing period, and no refunds will be provided for any unused portion of the period. If the subscription is not cancelled, it will automatically renew at the pricing in effect on nexos.ai at the time of renewal.14.2. These Terms of Use or any Service Order thereunder may be terminated by written notice to the other party: (i) by any party in the event of a material breach of these Terms of Use or a Service Order by the other party which remains uncured for a period of thirty (30) days after receipt of written notice of such breach is provided to the breaching party, provided that the cure period for a failure to pay amounts due shall be ten (10) days; (ii) as may be set forth in the applicable Service Order or other appendices to these Terms of Use; and/or (iii) immediately upon written notice to the other party, in the event the other party (a) makes an assignment for the benefit of creditors; (b) files a voluntary bankruptcy petition; (c) acquiesces to any involuntary bankruptcy petition; (d) is adjudicated bankrupt; or (e) ceases to do business.14.3. Notwithstanding any provision of these Terms of Use, we may suspend its performance of its obligations under the Service Order and/or Terms of Use or terminate the Service Order and/or Terms of Use with immediate effect without obligations or adverse consequences to us if Company has breached any provisions of Clause 12 or if we determine that to perform any of its obligations under the Service Order and/or Terms of Use constitutes or could constitute a violation of or conflict with, or expose it to sanctions, penalties, or other adverse consequences under, any Trade Controls, including if Company becomes a Restricted Person.14.4. Upon the expiration or termination of these Terms of Use: (i) all Service Orders shall terminate; (ii) Company shall immediately cease using the Product, and shall, at our option, delete the Product and/or return all items received under the Service Order and/or these Terms of Use to us; (iii) all licenses granted by us hereunder shall terminate with immediate effect, and (iv) Company shall immediately pay all obligations that have accrued prior to the effective date of termination.14.5. In the event of termination due to Company’s breach of these Terms of Use and/or applicable Service Order, Company agrees that all Fees that would otherwise be due by Company for the remainder of the Term shall be accelerated and due and payable to us immediately.15. General
15.1. If any term or provision of these Terms of Use is invalid, illegal, or unenforceable in any jurisdiction, such invalidity, illegality, or unenforceability shall not affect any other term or provision of these Terms of Use or invalidate or render unenforceable such term or provision in any other jurisdiction.15.2. We may, at our discretion, modify or update these Terms of Use from time to time. Any such modifications shall become effective upon notice to the Company or upon publication on our website, whichever happens earlier. Continued use of the Product after such modifications constitutes acceptance of the updated Terms of Use.15.3. Company may not assign this Service Order and/or these Terms of Use without our prior written consent, which shall not be unreasonably withheld.15.4. The Service Order and/or these Terms of Use and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws of the Netherlands. Applicability of the United Nations Convention on Contracts for the International Sale of Goods 1980 is hereby expressly excluded. 15.5. Any claims, disputes, disagreements or other matters in question arising out of or relating to the Service Order and these Terms of Use shall be primarily resolved amicably by mediation within thirty (30) days of the receipt of a notice by one party to the other of the existence of a claim, despite or disagreement. In the event a dispute cannot be resolved amicably, the parties irrevocably agree that the Chamber for International Commercial Matters (Netherlands Commercial Court or NCC) of the court of Amsterdam, the Netherlands shall have the exclusive jurisdiction to settle any dispute or claim that arises out of, or in connection with, the Service Order and/or these Terms of Use or its subject matter or formation (including non-contractual disputes or claims). Such proceedings shall be in the English language.16. Annexes:
16.1. Schedule A – Product Description16.2. Schedule B – API Access (applicable only if API is provided)16.3. Schedule C – Service Level Agreement16.4. Schedule D – Data Processing AgreementAnnex 1: Details of Processing of Personal DataAnnex 2: Technical and Organisational MeasuresSchedule A – Product Description
nexos.ai Product Description
1. Overview of the Product
nexos.ai is a software-as-a-service (SaaS) platform and large language model aggregator that enables users to access and interact with a variety of third-party AI models through a unified interface. The platform facilitates the routing of user requests to supported third-party application programming interfaces (APIs), supports usage tracking, and includes access control and configuration options.2. Functional Components
As of the Effective Date, the Product includes the following functional components:- Model Access Integration: Enables users to submit requests to supported third-party AI models via a unified interface. Nexos.ai does not guarantee the availability of any model and provides access on an “as-available” basis. Models are subject to provider-specific terms and conditions.
- Routing and Load Distribution: Supports the smart routing of user requests across different AI models based on configurable parameters, which may include provider, availability, or usage thresholds.
- Monitoring and Logs (Observability): Captures certain metadata associated with User activity on the platform, which may include request timestamps, selected model endpoints, and usage volume. Logging of prompts may be available on an opt-in basis and may be available on an opt-in basis and may be configured by the Administrator.
- Team and Access Management: Provides features for assigning roles, permissions, and access policies (including single sign-on (SSO)) to users within an organization or team structure.
- Cost Management: The Service may offer various tools that allow Customers to optimize, configure and monitor budget thresholds at the organization and team level.
- Workspace and agent configuration: Enables administrators to create and configure custom AI agents or assistants within the dedicated workspaces, including setting system prompts, selecting underlying models and defining agent-specific behaviours and constraints.
- Integrations and tool use: ensures connections to external tools, data sources and third-party services enabling models to retrieve information or perform pre-defined actions.
3. Beta Services
We may at our own discretion make available to Company services or features of the Product identified as alpha, beta, preview, early access, evaluation, preliminary, or a similar description, that are still under development and may not be fully functional or error-free (“Beta Services”). Company understands that the use of Beta Services is at its own risk, services levels are not applicable, and no warranties are provided regarding performance, functionality, or fitness for a particular purpose. We shall to the fullest extent permitted by applicable law not be liable for any damages, losses, or costs arising from the use of the Beta Services, including but not limited to direct, indirect, incidental, or consequential damages.4. Product Modifications
The Product is subject to continuous development and improvement. nexos.ai reserves the right to add, modify, or remove features at its discretion.Schedule B – API Access (applicable only if API is provided)
1. Definitions
2. Access to the API
2.1. We agree to provide You, on the terms and conditions of these Terms of Use, with access to the API for the purpose of enabling You to access the Product as specified in the Service Order, or, if the Product is purchased online without a separate Service Order, as specified in the online purchase process and the Documentation (“Purpose”).2.2. You agree to use the API solely in connection with the Product and for the Purpose only. You also agree to the following limitations. You will not: (a) access or use the APIs in violation of any applicable law, regulation and policies, including but not limited to our Fair Use Policy; (b) access the API in any manner that (i) compromises, breaks or circumvents any of our technical processes or security measures associated with the Product, (ii) poses a security vulnerability to other customers or users of the Products, or (iii) tests the vulnerability of our systems or networks.2.3. You acknowledge and agree that we may modify or discontinue the API at any time in its sole discretion.3. License to Use the API
3.1. We grant You a non-exclusive, non-transferable, revocable license for the Term to use the API for the Purpose only and any related purposes determined in the Service Order or Terms of Use.3.2. You agree not to copy, modify, distribute, sell, or lease the API or any portion thereof, or to use the API to develop a competing Product or service to the Product.4. Transparency and privacy
4.1. If You use the API in the context of offering Products and services to individuals outside Your organization, like users, consumers or other individuals You must maintain a user agreement and privacy policy for Your application, which is prominently identified or located where users download or access Your application. Your privacy policy must meet applicable legal standards and describe the collection, use, storage and sharing of data in clear, understandable and accurate terms. If the API project involves uses such as conversational AI and chatbots, such interactions must disclose to users that they are interacting with an AI system. Accordingly, these requirements apply if the use of the API requires the processing of Personal Data of users within Your organization.4.2. In the event that we will have access to and/or otherwise process Personal Data being Your external users or customers, as part of the provision of the API for the Purpose, we will be considered a data processor within the meaning of the GDPR and the processing of such Personal Data shall be subject to the provisions of Schedule D – Data Processing Agreement. Each Service Order or when the Product is purchased online without a separate Service Order, the online purchase documentation or associated product description, shall specify the required details of processing of Personal Data that is necessary in connection with these Terms of Use.5. Documentation
5.1. We will give You access to Documentation related to the API.5.2. You agree to use the Documentation solely in connection with your use of the API in accordance with the Purpose.6. Intellectual Property
6.1. The API and Documentation are Intellectual Property Rights of us (or our licensors).6.2. You acknowledge and agree You acquire no rights in the API or Documentation other than the limited license granted in this Schedule B.6.3. You agree to use the API and Documentation only as authorized by us.7. Termination
7.1. Any breach of this Schedule B – API Access by You will be deemed a material breach of Clause 14 of the Terms of Use Clause 14.7.2. Upon termination of this Schedule B or Terms of Use – API Access and/or the Service Order, You shall immediately cease all use of the API and Documentation and shall return or destroy all copies of the Documentation.Schedule C – Service Level Agreement (“SLA”)
1. Definitions
2. Service Levels
2.1. We will use commercially reasonable efforts to maintain an Availability Commitment of 99.9%.2.2. In the event the product does not meet the Availability Commitment, Company will receive a Service Credit toward the following month’s fees as Company's sole and exclusive remedy. To request a Service Credit, Company must notify us within 30 days after the month in which the Service Credit was earned.| Availability Commitment | Service Credit Percentage |
|---|---|
| < 99.9% and ≥ 99.0% | 10% |
| < 99.0% | 20% |
Schedule D – Data Processing Agreement
This Data Processing Agreement ("DPA") governs spectra tech, UAB as the Processor to process Personal Data of the Company as Controller in relation to the Personal Data provided by the Controller through nexos.ai API or any nexos.ai services for businesses.1. Definitions
1.1. All definitions of the Terms of Use apply for the purposes of this DPA and unless otherwise defined in this DPA, additional terms used in this DPA that are given a particular meaning in Data Protection Legislation (as applicable) shall be interpreted in accordance with such meaning or the meaning of equivalent terms, such as “process/processing”, “data subject”, “(data) processor”/“provider”, “(data) controller”/“business”, “personal data/ personally identifiable) information”, “(personal) data breach”, “data protection impact assessment”, etc.;2. Processing of the Personal Data
2.1. Processor shall process Personal Data only (i) on Controller’s behalf for the purpose of providing and supporting the Product, (ii) in compliance with the documented instructions as set forth in the Terms of Use and (iii) if the processing is required by EU or Member State law to which Processor is subject, in which case Processor shall to the extent permitted by such law inform the Controller of that legal requirement before processing that Personal Data. The parties acknowledge and agree that the Product operates as a unified interface and routing layer through which the controller and its users submit inputs to third-party models and tools. The routing and transmission of such inputs and corresponding outputs to the model providers, tools and other subprocessors selected or configured by the controller or its users shall constitute processing on the Controller’s documented instructions for the purposes of this DPA. 2.2. The details of the processing operations, in particular the categories of Personal Data and the purposes of processing for which the Personal Data is processed on behalf of the Controller, are specified in Annex I of this DPA (Details of Processing of Personal Data).3. Obligations of Controller
3.1. Controller shall comply with all requirements in applicable Data Protection Legislation.3.2. Controller represents, warrants and covenants that it has and shall maintain throughout the term all necessary rights, consents and authorizations to provide the Personal Data to Processor and to authorize Processor to use, disclose, retain and otherwise process Personal Data as contemplated by this DPA, the Terms of Use and/or other written instructions provided to Processor.3.3. Without prejudice to Processor’s security obligations in Clause 4 of this DPA, Controller acknowledges and agrees that it, rather than Processor, is responsible for certain configurations and design decisions for the services and that Controller, and not Processor, is responsible for implementing those configurations and design decisions in a secure manner that complies with applicable Data Protection Legislations.4. Security
4.1. Processor will maintain reasonable and appropriate organizational and technical security measures as required in GDPR, including those measures described in Annex II to this DPA (including with respect to personnel, facilities, hardware and software, storage and networks, access controls, monitoring and logging, vulnerability and breach detection, incident response, and encryption) to protect against unauthorized or accidental access, loss, alteration, disclosure or destruction of Personal Data and to protect the rights of the subjects of that Personal Data;4.2. Processor shall take appropriate steps to confirm that Processor personnel are protecting the security, privacy and confidentiality of Personal Data consistent with the requirements of this DPA.5. Subprocessing
5.1. As of the Effective Date, the Controller authorizes the Processor to engage the Subprocessors listed at6. Data Subject Rights and Law Enforcement Requests
6.1. Processor shall promptly, and in any case within ten (10) working days, notify the Controller if it receives a request from a data subject whose Personal Data is processed by Processor on behalf of the Controller and shall provide full details of that request. The Processor shall not respond to the request itself, unless specifically authorised do so by the Controller.6.2. To the extent the Controller, in its use of the Product, does not have the ability to address a data subject request, the Processor shall, upon Controller’s request, provide commercially reasonable efforts to assist Controller in responding to such data subject request, to the extent the response to such data subject request is required under Data Protection Legislation.6.3. Taking into account the nature of the processing, Processor shall make commercially reasonable efforts to co-operate as requested by the Controller to enable the Controller to comply with any assessment, enquiry, notice or investigation under any Data Protection Legislation in respect of Personal Data or this DPA.6.4. The Processor agrees to promptly notify the Controller if it receives a legally binding request from a public authority, including judicial authorities for the disclosure of Personal Data or if it becomes aware of any direct access by public authorities to such Personal Data. The notification will include all information available to the Processor about the request or access. If the Processor is prohibited from notifying the Controller under applicable laws, the Processor agrees to use its best efforts to obtain a waiver of the prohibition, with a view to communicating as much information as possible, as soon as possible. If the Processor concludes that there are reasonable grounds to consider that the request is unlawful it will pursue possibilities of appeal and/or seek interim measures, so as to, where feasible, only fulfil the request after the competent judicial authority has decided on its merits. In any case, the Processor undertakes to narrowly interpret all such valid requests, providing only the minimum amount of information required.7. Incident Management
7.1. In the event of a personal data breach, the Processor shall use reasonable efforts to cooperate with and assist the Controller in complying with the Controller’s obligations under the applicable Data Protection Legislation, taking into account the nature of processing and the information available to the Processor.8. Data Protection Impact Assessment and Prior Consultation
8.1. Processor shall provide commercially reasonable assistance to the Controller with any data protection impact assessments, supervisory authority prior consultations or similar assessments, where such are required under Data Protection Legislation, taking into account the information available to the Processor and the nature of its processing of Personal Data.9. Deletion of Personal Data
9.1. At the choice of the Controller, the Processor shall delete or return all personal data to the controller after the end of the provision of services, and delete existing copies upon termination or expiry of the Agreement within maximum of 90 days, unless applicable law requires the Processor to retain copies. In such cases, the Processor will isolate and protect that Personal Data from any further processing except to the extent required by applicable laws. This remains without prejudice to the Processor’s right to process non-personal data related to the use of the Product. This period may not be applicable for all subprocessors.10. Compliance and Audit Rights
10.1. The Processor shall deal promptly and adequately with inquiries from the Controller about the processing of Personal Data in accordance with this DPA.10.2. The Processor shall make available to the Controller on request all information reasonably necessary to demonstrate compliance with this DPA and the obligations that stem directly from the GDPR. Controller will take into account the relevant certifications held by the Processor.10.3. If such relevant certifications are not sufficient to demonstrate compliance with the processing of Personal Data under this DPA, Company may, upon reasonable notice and appropriate confidentiality agreements, request that Processor cooperate with assessments, audits, or other steps performed by or on behalf of Company. These assessments, audits, or other steps shall be conducted at Company’s sole expense and in a manner that is minimally disruptive to Processor’s business, and are necessary to confirm that Processor is processing Company Data in a manner consistent with this DPA. The results of any such assessments, audits or other steps, as well as the summaries of third-party audits or certification reports, shall be the confidential Information of the Processor.11. International Data Transfers
11.1. The Processor will process the Personal Data provided by the Controller in the EEA, unless otherwise selected by the Controller. To the extent that the Processor transfers Personal Data to Subprocessors in third countries without an adequacy decision issued by the European Commission under article 45 GDPR, Processor is only able to transfer the data in accordance with chapter V of the GDPR, including the use of the Standard Contractual Clauses set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 or other appropriate safeguards as required. Upon request the Processor shall provide a copy thereof to the Controller. The Parties acknowledge that, in connection with the routing functionality of the Product, personal data contained in inputs and outputs may be transmitted to model providers and other subprocessors in real time, and each such transmission to a recipient in a third country shall constitute a transfer under the applicable regulations.12. Miscellaneous
12.1. Subject to Clause 12.3, the parties agree that this DPA shall terminate automatically upon termination of the Terms of Use.ANNEX 1: DETAILS OF PROCESSING OF PERSONAL DATA
Subject matter
Duration of the processing of personal data
Processing purpose
Data subjects
Personal data categories
Subject matter
Personal data is processed for the purposes of making the service available, maintaining or improving it.The performance of the services described in the Terms of Use to which this exhibit is attached.Duration of the processing of personal data
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis) - continuous basis.During the Term.Processing purpose
Personal Data is processed for the purposes of making the Product available, and maintaining or improving it in accordance with this DPA, including performance optimization, support and diagnostics.Data subjects
Users of the Service.Personal data categories
Name, contact information, demographic information, or other information provided by the user of the Company in unstructured data.Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.No sensitive data is intended to be processed unless the user of the Company includes it unexpectedly in unstructured data.ANNEX 2: TECHNICAL AND ORGANISATIONAL MEASURES
Internal Access Management
- Access is secured via Single Sign-On (SSO) with enforced Multi-Factor Authentication (MFA) through the identity provider;
- Role Based Access Controls (RBAC);
- Periodic audits to ensure internal access remains limited to the minimum necessary for the job roles;
- Established procedures for promptly revoking access rights upon employee separation or detection of compromised credentials;
- Established procedures for identity verification during credential resets and replacements;
Customer Access Management
nexos.ai provides the following measures to secure customer access to the product:
1. Support for customer-configured Single Sign-On (SSO) and password-based login securely stored using industry-standard cryptographic protections;2. Multi-tenant architecture ensuring the logical separation of Customer Data and user accounts via unique identifiers;Data Access Control
- Internal access is limited to authorized employees via the principle of least privilege, restricted to those strictly required for Product delivery and support;
- Strict logical and physical separation between production, staging, and development environments to protect the Customer Data;
- Deployment of primary backend resources behind a VPN and encryption of data both at rest and in transit;
- Mandatory full-disk encryption and management controls on corporate devices;
- Centralized security monitoring, automated logs, audit trails, and regular vulnerability assessments to ensure data integrity.
Availability Control
- Implementation of security solutions, including anti-malware protection and intrusion detection mechanisms where appropriate;
- Real-time monitoring and alerting for system faults, performance issues, and security anomalies;
- Robust system restoration capabilities, including regular backups and formal disaster recovery mechanisms.
Risk Management
- Regular risk assessment and treatment activities;
- Integrated security testing and issue remediation processes
- A vulnerability management process appropriate to the product’s architecture and risk exposure.
Personnel
- Background checks (where legally permissible);
- Mandatory confidentiality and non-disclosure agreements;
- Annual and supplemental security training.
Physical Access Control
- Multi-layered physical access barriers including key cards, mobile credentials, and 24/7 security personnel;
- Continuous video monitoring and formal logging of all facility entries and exits;
- Formal protocols for visitor authorization.
Third Party Risk Management
- Pre-onboarding vendor risk assessments to evaluate vendor’s security posture and compliance;
- Formal agreements incorporating specific security, privacy, and data protection requirements;
- Periodic reviews to ensure sustained compliance.
Monitoring & Incident Response
- Security Operations Center (SOC) oversight, utilizing centralized log aggregation for real-time threat detection and response;
- Established procedures for the containment, investigation, and remediation of security anomalies;
- Notification to affected Customers of any Personal Data Breach in accordance with the timelines and requirements of the DPA.
Security Evaluations & Continuous Improvement
- Regular independent assessments to maintain compliance with ISO 27001, ISO 42001, and SOC 2 standards;
- Periodic vulnerability scanning and external penetration testing to evaluate the integrity of the Product;
- Continuous monitoring and refinement of security controls to ensure alignment with industry best practices and evolving risks.
Corporate Identity, Authentication, and Authorization Control
Processor maintains industry best practices for authenticating and authorizing internal employee and service access, including the following measures:- Single sign-on (SSO) to authenticate to third-party services used in the delivery of the Product. Role Based Access Controls (RBAC) are used when provisioning internal access to the Product;
- Mandatory multi-factor authentication is used for authenticating to identity provider;
- Unique login identifiers are assigned to each user;
- Periodic access audits designed to ensure access levels are appropriate for the roles each user performs;
- Established procedures for promptly revoking access rights upon employee separation;
- Established procedures for reporting and revoking compromised credentials (such as passwords and API keys); and
- Established password reset procedures, including procedures designed to verify the identity of a user prior to a new, replacement, or temporary password.
Customer Identity, Authentication, and Authorization Controls
nexos.ai maintains industry best practices for authenticating and authorizing customers to the Product, including the following measures:1. Support for both third-party identity access management (e.g., Single Sign-On) and direct username/password authentication, depending on Customer configuration;2. Secure storage of authentication credentials where applicable, including the use of hashing and other security measures to protect user-provided passwords;3. Logically separating Personal Data organization account using unique identifiers. Within an organization account, unique user accounts are supported.4. Cloud Infrastructure and Network Security. nexos.ai maintains industry best practices for securing and operating its cloud infrastructure, including the following measures:- Separate production and non-production environments;
- Primary backend resources are deployed behind a VPN.
- The Product is routinely audited for security vulnerabilities.
- Network security policies and firewalls are configured for least-privilege access against a pre-established set of permissible traffic flows. Non-permitted traffic flows are blocked; and
- Product logs are monitored for security and availability.
Data Access Control
nexos.ai maintains industry best practices for preventing authorized users from accessing data beyond their authorized access rights and for preventing the unauthorized input, reading, copying, removal, modification, or disclosure of data. Such measures include the following:- Employee access to the Product follows the principle of least privilege. Only employees whose job function involves supporting the delivery of Product are credentialed to the Product environment; and Company Data submitted to the Product is only used in accordance with the terms of the DPA, Agreement, and any other applicable contractual agreements in place with Customer.
Disclosure control
nexos.ai uses industry best practices to prevent unauthorized access, alteration, or removal of data during transfer, and to secure and log all transfers. Measures include: (i) Encryption of data in transit, (ii) Audit trails for data access requests, (iii) Full-disk encryption and device management controls on corporate workstations.Availability Control
nexos.ai ensures service functionality through:- System restoration capabilities such as backups and recovery mechanisms;
- Monitoring and alerting for system faults and performance issues;
- Implementation of security solutions, including anti-malware protection and basic intrusion detection where appropriate.
Segregation Control
nexos.ai separates data processing for different purposes through:- Logical segregation of Company Data;
- Role-based access restrictions;
- Segregation of business information system functions and environments.
Risk Management
nexos.ai manages cybersecurity risks with:- Risk assessment and prioritization activities;
- Security testing and issue remediation processes;
- A vulnerability management process appropriate to its size and risk exposure.
Personnel
nexos.ai vets, trains, and manages personnel with: Background checks (where legally permissible) and annual and supplemental security training.Physical Access Control
nexos.ai prevents unauthorized physical access with:- Locked doors and gates;
- 24-hour security guard staffing and video surveillance;
- Access control systems utilizing key cards, mobile credentials, and secure authentication methods;
- Visitor protocols and logging of facility entries/exits.
Third Party Risk Management
nexos.ai manages third-party security risks through:- Written contracts with security safeguards;
- Formal vendor security assessments.
Security Incident Response
nexos.ai has a plan for responding to security incidents, including:- Aggregating system logs for detection and response;
- Notifying Customer of Personal Data Breaches in accordance with the DPA.
Security Evaluations
nexos.ai conducts regular security and vulnerability testing to evaluate the effectiveness of key controls, ensure alignment with industry standards and internal policies, and maintain compliance with applicable legal, regulatory, and contractual obligations regarding the security of Personal Data and the integrity of its information systems.