IQTEC

Privacy Policy

Data Processing Agreement, Privacy, AI

Data Processing Agreement (DPA)

These Data Processing Terms apply to the extent that Service Provider has access to, or otherwise Processes, Client Data for, or on behalf of, Client. Parties enter into a data processing agreement ‘DPA’ with standard contractual clauses as required under Privacy Act 1988 (Cth) including the Australian Privacy Principles (APPs). Said data processing agreement is hereby incorporated and be deemed a part of this Agreement.
Definitions

For purposes of this DPA, the following terms shall apply:

  • Applicable Data Protection Law means any and all federal, state, and local laws, statutes, and regulations applicable to the Processing of Client Data.
  • Client means any individual or entity that accesses, visits, or otherwise engages with the Service Provider, including via the website or digital services.
  • Client Data means Personal Data, in any form or format, that Service Provider has access to, or otherwise Processes, for, or on the behalf of, Client pursuant to the Agreement and Services rendered thereunder.
  • Data Subject means the natural person whose Personal Data is Processed by Service Provider.
  • Documented Instructions means the Processing terms and conditions set forth in the Agreement and this DPA.
  • Information System means any information or telecommunication system, network, equipment, hardware, or software employed or otherwise used with respect to the Processing of Client Data.
  • Personal Data means any information or data that, alone or in combination with other information or data, can be used to reasonably identify a particular individual, household, or device, and is subject to, or otherwise afforded protection under, an applicable Data Protection Law.
  • Process means any action performed on Client Data, including collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transfer or otherwise making available, alignment or combination, restriction, deletion, or destruction.
  • Security Event means a compromise to the security, confidentiality, availability, or integrity of Client Data, or to the security measures used to safeguard Client Data, including any actual or reasonably suspected unauthorized access to, or unauthorized loss, use, acquisition, exfiltration, or
    disclosure of Client Data.
  • Sale and Share shall be ascribed the meaning set forth in the in the law applicable to Client Data.
  • Services means the professional, technology, or consulting services, or other products, goods, or services that Service Provider furnishes to Client pursuant to the Agreement.
  • Subprocessor means any third party engaged by Service Provider to Process Client Data on its behalf.

Data Protection

General Obligations. As between the parties, Client shall, at any and all times, retain all rights, title, and interest in Client Data. Client hereby appoints Service Provider to Process Client Data on Client’s behalf and grants Service Provider a limited, revocable, nonexclusive right to Process Client Data in accordance with the Documented Instructions. Service Provider acknowledges and agrees that it shall only Process Client Data in accordance with the Documented Instructions and applicable Data Protection Law, and to the minimal extent necessary to provide the Services. In the event Service Provider is compelled by law to Process Client Data beyond, or in conflict with, the Documented Instructions, Service Provider shall notify Client of the same prior to such Processing, unless such prior notification is expressly prohibited by law. Service Provider shall, promptly and without delay, notify Client if (i) Service Provider cannot comply with, or is not in compliance with, the Documented Instruction, or (ii) in Service Provider’s reasonable judgment, the Documented Instructions infringe upon any applicable Data Protection Law.

Disclaimer. Each party acknowledges and agrees that the disclosure of Client Data to the other does not constitute, and is not the intent of either party for such disclosure to constitute, a sale or sharing of Client Data, and if valuable consideration, monetary or otherwise, is being provided by either party, such valuable consideration, monetary or otherwise, is being provided for the rendering of Services and not for the disclosure of Client Data. Service Provider (i) shall not collect, retain, use, or disclose Client Data for any purpose (including for any commercial purpose) other than for the specific purpose of performing the Services, unless otherwise required by law, (ii) shall not Sell or Share Client Data, except as necessary to satisfy its obligations under the Agreement, (iii) shall not collect, retain, use, or disclose Client Data outside the direct business relationship between Service Provider and Client, unless expressly permitted by law, (iv) shall not combine the Client Data that the Service Provider receives from, or on behalf of, Client with Personal Data that Service Provider receives from, or on behalf of, another party, or collects from its own interaction with a Data Subject, except to the extent reasonably necessary to provide the Services and as expressly permitted by law, and (v) shall, at Client’s reasonable request, cease any unauthorized Processing of Client Data and grant Client authorization to assess and remediate any such unauthorized Processing. This DPA is the Service Provider’s certification, to the extent any applicable Data Protection Law requires such a certification, that Service Provider understands and will comply with the Processing limitations with respect to Client Data that are set forth in the Documented Instructions. The parties acknowledge and agree that the Service Provider shall Process Client Data only for the specific “business purpose” of performing the Services set forth in the Agreement.

Confidentiality and Information Security

Confidentiality. Service Provider shall (i) maintain the confidentiality of all Client Data and ensure that all individuals who are authorized to Process Client Data on its behalf have committed themselves to confidentiality, (ii) limit access to Client Data to only those individuals who have a business need for such access, and (iii) take reasonable steps to ensure the reliability of all individuals who have access to Client Data.

Information Security. Service Provider shall implement and maintain commercially reasonable technical, physical, and administrative security controls to protect and safeguard Client Data, including written policies that describe such security controls and set forth responsibilities and obligations applicable to individuals who have access to an Information System (“Information Security Program”). Without limiting the generality of the foregoing, Service Provider shall designate a senior employee to be responsible for the overall management of Service Provider’s Information Security Program. Service Provider may update, amend, or otherwise alter its Information Security Program at any time and without notice to Client, provided that any such update, amendment, or alteration does not degrade the operability or functionality of the Services, increase the likelihood of a Security Event, or cause the Information Security Program to not meet the minimum standards set forth herein. Service Provider shall, at least quarterly, conduct a risk assessment to identify any and all reasonably foreseeable vulnerabilities, threats and risks to Client Data in its custody or control and undertake commercially reasonable measures to mitigate any material or significant vulnerabilities, threats and risks identified therein.

Notwithstanding the foregoing, Service Provider agrees to abide by any additional or higher security standards that may be set forth by applicable Data Protection Law. The Service Provider shall comply with Client’s information security policies, which may be amended from time to time, regarding access to, and acceptable use of, the Client’s IT Environment (as defined below), to the extent that such policies and been made known and available to the Service Provider.

To the extent the Service Provider processes personally identifiable information for and on the behalf of the Client, and such processing occurs in a third-party IT Environment (not Client’s IT Environment), then the parties shall, cooperate in good faith, to execute a data processing agreement or similar contractual terms governing the processing of such personally identifiable information.

Client’s IT Environment

Access. For the duration of the Agreement and to the extent necessary to provide the Services, Client grants to Service Provider a non-exclusive, non-transferable, revocable, limited right, to access, use, and perform activities on and/or within, Client’s information technology networks, systems, software, programs, and equipment (collectively or individually, “IT Environment”) solely for the purposes of providing the Services set forth in the Agreement, provided the parties separately agree to the manner (i.e., technical configuration) in which Service Provider shall be authorized to access Client’s IT Environment.

Service Provider Personnel. Client and Service Provider shall approve, in writing, all Service Provider personnel who are authorized to access Client’s IT Environment (each, an “Authorized User”). Service Provider shall immediately (and within forty-eight (48) hours) provide written notice to Client if an Authorized User is terminated or no longer requires access to Client’s IT Environment to perform the Services set forth in this Agreement. Client may, in its sole discretion, prevent or terminate access to its IT Environment. Service Provider shall (i) ensure each Authorized User is aware of, understands, and complies with the terms and conditions set forth in this Agreement, (ii) be fully liable to Client for any harm or damage to Client’s IT Environment that arises from an Authorized User’s violation of the terms and conditions set forth in this Agreement, and (iii) accept all responsibility and liability for all activities authorised and undertaken by the Service Provider that occur under a username created by Client to enable an Authorized User access to Client’s IT Environment.

Monitoring. Service Provider acknowledges and agrees that Authorized Users do not have any expectation of privacy with respect to Client’s IT Environment and Client may, in its sole discretion, monitor, intercept, analyze, assess, or evaluate any and all activity or communications occurring on or within Client’s IT Environment.

Security. Authorized Users shall, at any and all times, exercise commercially reasonable care to protect the security, operability, and functionality of the Client’s IT Environment and shall not (without prior written approval from Client) undertake any of the following: (i) use Client’s IT Environment for non-business, personal purposes, (ii) gain or attempt to gain access to portions or segments of Client’s IT Environment to which access has not been granted, (iii) distribute or attempt to distribute malicious software to Client’s IT Environment, (iv) unless authorized to do so by Client, install or attempt to install spyware or other unauthorized monitoring or surveillance tools to Client’s IT Environment, (v) use Client’s IT Environment to download, store, or distribute materials in violation of Client or any third party’s copyright or intellectual property rights, (vi) create undue security risks or negatively impact the performance of Client’s IT Environment, (vii) install software in Client’s IT Environment without Client’s advanced written consent, or (viii) copy, decompile, recompile, disassemble, reverse engineer, modify, combine, or otherwise commercially exploit any software within Client’s IT Environment. For the avoidance of doubt, Authorized Users shall not exfiltrate, export, or transfer any data or information from Client’s IT Environment, unless approved separately in writing by Client or as part of specified Service Agreement between the Client and the Service Provider.

Remote Access; Security Policies. Client and Service Provider shall agree, in writing, to the manner and technical configuration in which Authorized Users shall be granted remote access to Client’s IT Environment. In the event an Authorized User is granted a username and password to enable access to Client’s IT Environment, an Authorized User must implement and maintain commercially reasonable measures to safeguard and protect said username and password, refrain from providing said username and password to any third party, and immediately (and within forty-eight (48) hours) provide written notification to Client in the event the confidentiality of said username and password is compromised. To the extent Service Provider has access to Client’s IT Environment, Service Provider shall comply with Client’s information security policies, which may be amended from time to time, regarding access to, and acceptable use of, Client’s IT Environment.

Cooperation and Assistance; Return of Client Data

General Assistance. Service Provider shall provide reasonable assistance to Client to enable Client to (i) comply with its obligations and responsibilities under any applicable Data Protection Law, including with respect to Data Subjects exercising their rights and privileges under applicable Data Protection Laws, (ii) undertake data protection impact assessments, and (iii) comply with requests or demands from supervisory authorities.

Data Notice and Response. Service Provider shall, immediately and without delay, refer to Client any correspondence, inquiry, complaint, request, or demand (collectively or individually, a “Data Notice”) concerning the Processing of Client Data and shall not respond to any such Data Notice unless otherwise required by law. Notwithstanding the foregoing, in response to any such Data Notice, Service Provider may furnish Client’s email contact information and request the Data Notice be submitted directly to Client. Upon written request from Client, Service Provider shall promptly (and in any event within ten (10) business days) provide access to, amend, correct, delete, or cease Processing, Client Data in its custody or control.

Return or Destruction of Client Data. Upon termination of the Services, Service Provider shall, within a maximum period of sixty (60) calendar days and at Client’s choice:

(i) return to Client all Client Data and all copies thereof by secure file transfer in such a format as required by Client, or (ii) destroy, and certify the destruction of, all other copies of Client Data within three (3) days of Client’s request, unless storage of such data is required by law. Notwithstanding the foregoing, Service Provider may destroy Client Data that is stored in a back-up or archived format in accordance with its normal retention schedule, provided such Client Data is otherwise retained in accordance with this DPA.

Security Event Procedures.

Service Provider shall provide written notice to Client of any Security Event within seventy-two (72) hours after becoming aware of, or otherwise discovering, the Security Event, and this written notification shall, to the greatest extent possible, include a description of

  1. the nature of the Security Event,
  2. the categories of Client Data affected by the Security Event,
  3. the approximate number of individuals affected by the Security Event,
  4. any potential legal or regulatory consequences that may arise from the Security Event, and
  5. the measures taken or proposed to be taken to address the Security Event.

In the event of a Security Event, Service Provider shall designate a senior employee to serve as Service Provider’s single point of contact from whom Client can obtain more information about the Security Event. Service Provider shall provide reasonable assistance to Client to investigate or otherwise respond to a Security Event, and enable Client to meet any legal obligation it may have to give notice of the Security Event to any affected Data Subject, a governmental or regulatory authority, or any other individual or entity.

Notwithstanding any other provision in the Agreement or herein, Service Provider shall defend, indemnify and hold harmless Client and its affiliates, and their respective officers, directors, employees and agents, from and against any and all claims, suits, causes of action, liability, loss, costs and damages, including reasonable attorneys’ fees, arising from or relating to a Security Event.

Audits.

Service Provider shall (i) upon request (but not more frequently than annually) respond to questionnaires and similar requests for information provided by Client to demonstrate Service Provider’s compliance with Service Provider’s obligations under this DPA, (ii) use independent external auditors to verify the adequacy of its written Information Security Program and, at least annually, provide Client with its most recent third-party attestations, certifications, and reports relevant to the establishment, implementation, and effectiveness of Service Provider’s Information Security Program.If the information and reports described in the foregoing (i) and (ii) do not demonstrate, in Client’s reasonable judgment, Service Provider’s compliance with its obligations and responsibilities set forth in this DPA, Client may conduct an inspection, test (including a penetration test), or audit of Service Provider’s business operations, or have the same conducted by a qualified third party subject to a nondisclosure agreement, provided:
  1. Client furnishes Service Provider at least thirty (30) days’ advanced written notice,
  2. the inspection, test, or audit is conducted during Service Provider’s regular business hours, and
  3. the inspection, test, or audit is conducted in a manner that does not materially interrupt Service Provider’s business operations. Client shall be solely responsible for all reasonable costs and fees associated with the inspection, test, or audit described herein, unless the results demonstrate Service Provider’s non-compliance with this DPA.
Client shall immediately provide the results or conclusions of any inspection, test, or audit conducted to Service Provider, and, unless otherwise agreed to in writing, Service Provider shall have thirty (30) business days from receipt of the results or conclusion to remediate or resolve any significant or material vulnerability or deficiency identified therein.

Subprocessing; Localization

Subprocessors. Client hereby acknowledges and agrees that Service Provider may authorize the use of Subprocessors to assist with its provision of Services to Client upon Client’s prior written consent, provided Service Provider executes with any such Subprocessor a written agreement that contains terms and conditions that are substantially the same as, and in any event no less stringent than, the terms and conditions set forth in this Agreement. Service Provider shall undertake all reasonable efforts to ensure that any such Subprocessor can comply, and is in compliance, with the terms and conditions set forth in this DPA. Service Provider shall, at any and all times, remain liable to Client for any and all acts or omissions of a Subprocessor. For the avoidance of doubt, Service Provider shall ensure that any and all obligations and responsibilities applicable to Service Provider pursuant to this DPA shall apply to any and all Subprocessors.

Localization. Client and Service Provider shall agree in writing on the location of Information Systems that retain Client Data .

AI Services Terms and Definitions

“AI Services” refers to the artificial intelligence-based services provided by the Provider under this Agreement, including but not limited to AI-driven analytics, process automation, Client interaction services, and AI application development.

“AI-Generated Outputs” means any data, content, analyses, or other materials generated by the AI Services as a result of processing Client’s data or through interactions with Client’s systems.

“AI Models” refers to the computational models developed or used by the Provider that simulate human intelligence processes, including machine learning models, neural networks, and algorithms.

“Client Data” means any data, information, or material provided by Client to the Provider for the purpose of receiving the AI Services, including but not limited to operational data, Client information, and business intelligence.

“Data Sources” refers to the origins of data used by the AI Services, which may include Client Data, publicly available data, and data from third-party providers.

“Implementation Support” encompasses the services provided by the Provider to assist Client in integrating and deploying the AI Services within Client’s operational environment, including vendor and technology selection, proof of concept development, and implementation oversight.

“Innovation Workshops” are collaborative sessions conducted by the Provider with Client’s teams to explore potential AI use cases, innovative applications, and strategic planning for AI deployment.

“Machine Learning” is a subset of AI that involves the development of algorithms allowing computers to learn and make decisions based on data, without being explicitly programmed for each specific task.

“Strategic AI Consulting” involves advisory services provided by the Provider aimed at evaluating Client’s readiness for AI integration, developing AI strategies aligned with business objectives, and facilitating innovation workshops.

“Third-Party Components” means software, data, or services not developed or owned by the Provider but used in the delivery of the AI Services, including open source software and third-party APIs.

Additional Client Responsibilities if subscribing to AI Services

These Client Responsibilities are in addition to those specified in the Managed Service Agreement.

Provision of Information
Client shall provide all necessary information regarding its current systems, software, and hardware that the Service Provider deems necessary for the provision of AI services. Client agrees to promptly disclose any changes in operational processes, technology infrastructure, or business objectives that might impact the services provided by the Service Provider.

 

Access and Assistance
Client shall grant the Service Provider and its authorized personnel access to its facilities, systems, and information as required for the purpose of delivering the services. Client agrees to offer reasonable assistance, including the availability of Client’s personnel, for consultations, meetings, and implementation activities related to the services.

 

Data Provision and Quality
Client is responsible for providing data necessary for the AI services. The data must meet the quality standards specified by the Service Provider, including accuracy, completeness, and relevancy. Client shall ensure that it has the right to use and provide such data to the Service Provider for the purpose of delivering the services, adhering to applicable data protection and privacy laws.

 

Compliance with Laws
Client is responsible for ensuring that its use of the AI services complies with all applicable laws, regulations, and industry standards. This includes data protection and privacy laws, intellectual property rights laws, and any specific regulations governing Client’s industry.

 

Security and Confidentiality
Client shall implement reasonable security measures to protect access to its systems and the data used in conjunction with the AI services. Client agrees to maintain the confidentiality of any proprietary information or tools provided by the Service Provider as part of the services.

 

Cooperation and Coordination
Client will cooperate with the Service Provider in good faith and coordinate internally to facilitate the effective delivery and implementation of the AI services. This includes timely feedback and decision-making to support project timelines.

 

Ethical Use of AI
Client agrees to use the AI services and any related technologies ethically, in a manner that respects privacy rights, avoids discrimination, and complies with ethical guidelines provided by the Service Provider.

 

Notification of Issues
Client shall promptly notify the Service Provider of any issues, concerns, or malfunctions related to the AI services. Client agrees to provide detailed information about such issues to aid in their resolution.

C.11 DISCLAIMER OF WARRANTIES if subscribing to AI Services

As-Is – Service Provider furnishes all AI-driven services, including but not limited to AI models, algorithms, software, and any AI-generated content or data, on an “as is” and “as available” basis. Service Provider expressly disclaims all warranties, whether express, implied, statutory, or otherwise, including but not limited to implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranties arising out of the course of dealing or usage of trade.
No Guarantee of Results – Service Provider makes no warranty that the AI services will meet Client’s requirements or achieve any intended results. Due to the experimental nature of AI technologies, the performance of AI services can be unpredictable, and Client acknowledges that the services are provided without any guarantee of accuracy, completeness, or reliability of AI-generated outputs.

 

Third-Party Components – Service Provider disclaims any warranty related to third-party components, data, or materials used in conjunction with the AI services, including any warranty of accuracy, reliability, or effectiveness of such third-party components.
No Warranty of Uninterrupted Use – Service Provider does not warrant that the provision of AI services will be uninterrupted, timely, secure, or error-free; nor does it make any warranty as to the results that may be obtained from the use of the AI services.
Client Responsibility – Client acknowledges that it assumes full responsibility for the selection of the AI services to achieve its intended results and for the use and results obtained from the AI services. Client further acknowledges that it must regularly review and validate AI-generated outputs for accuracy and appropriateness for the intended use.

Service Provider Obligations

Compliance and Standards
Service Provider shall ensure that all services are performed in compliance with applicable laws, regulations, and industry standards, particularly those relating to data protection, privacy, and AI ethics. Service Provider agrees to maintain all necessary licenses, certifications, and authorizations required to perform the services.

 

Data Protection and Security
Service Provider will implement and maintain robust security measures to protect Client’s data against unauthorized access, disclosure, alteration, or destruction. Service Provider will notify Client promptly of any data breaches or security incidents that impact Client’s data.

 

Customization and Integration
Service Provider shall work with Client to customize and integrate AI-driven services into Client’s existing systems and workflows as necessary to meet Client’s business needs. Service Provider will reasonably assist Client with required system modifications or integrations related to the service delivery. There may be an additional charge for these services.

 

Performance Monitoring and Reporting
Service Provider will monitor the performance of the AI-driven services and provide Client with periodic reports detailing usage, performance metrics, and insights into potential improvements.

 

Issue Resolution and Escalation
Service Provider shall establish an issue resolution and escalation process to promptly address any service-related issues or concerns raised by Client.

 

Innovation and Advice
Service Provider will advise Client on emerging AI technologies and innovations that could enhance Client’s business operations or offer new opportunities for growth and efficiency.

Exclusions to Service Provider Obligations for AI Service Subscription

Service Provider is not responsible for failures to provide Services that are caused by the existence of any of the following conditions:

  1. Third-Party Services and Products – Service Provider is not responsible for issues resulting from third-party services or products not directly supplied or controlled by Service Provider.
  2. Client’s Failure to Follow Recommendations – Failures or performance issues resulting from Client’s disregard for Service Provider’s recommendations or instructions.
  3. Pre-existing Conditions -Issues pre-dating the Agreement or unrelated to the provided services are excluded from Service Provider’s responsibilities.
  4. Compliance with Laws – Ensuring compliance with all applicable laws and regulations remains Client’s obligation, excluding the Service Provider from related liabilities.
  5. Bias and Fairness – Outcomes influenced by biases inherent in AI models or data are excluded from Service Provider’s liabilities.
  6. AI Hallucinations – Inaccuracies or fabrications (“hallucinations”) produced by AI models.
  7. Model Interpretability – Lack of detailed explanations for AI model decisions due to the “black box” nature of some AI technologies.
  8. Unpredictable AI Behaviour – Unforeseen or unpredictable AI system behaviours that result in unintended outcomes.
  9. Data-Driven Limitations – Limitations arising from inadequate or poor-quality data supplied by Client or inherent in used datasets.
  10. Ethical Use and Compliance – Client is solely responsible for ensuring the ethical use and legal compliance of AI-driven outputs.
  11. Continuous Learning Changes – Changes in AI behaviour due to continuous learning processes, not directly managed by the Service Provider.
  12. Intellectual Property Claims from AI Outputs – Claims of intellectual property infringement arising from AI-generated content or outputs.
  13. Disruption of Data Sources – Any interruption or cessation of access to essential data sources or third-party services required for the operation of AI services due to reasons outside of Service Provider’s control, including but not limited to, discontinuation of services, changes in terms of service, or access restrictions imposed by data Service Providers.
  14. AI Model Failure – Any sudden failure, degradation, or unpredicted P of AI models that significantly impacts service delivery, where such issues cannot be promptly resolved through reasonable efforts due to the complex and “black box” nature of certain AI technologies.
  15. Regulatory or Legal Changes – Any changes in laws, regulations, or government policies that directly prohibit, restrict, or impose additional burdens on the deployment, operation, or use of AI technologies and services contemplated by this Agreement.

Intellectual Property

Ownership of Pre-Existing Intellectual Property
Each party retains all right, title, and interest in and to its pre-existing intellectual property, including without limitation any software, data, or material owned by either party prior to the execution of this Agreement.

Client grants the Service Provider a non-exclusive, worldwide, royalty-free license to use Client’s pre-existing intellectual property solely for the purpose of performing the services under this Agreement.

AI-Generated Outputs
Client shall own the intellectual property rights in any data, content, or materials generated by AI services specifically for Client’s use under this Agreement, subject to any third-party rights in the underlying data or algorithms.

Use of Outputs: Client is responsible for ensuring that the use of AI-generated outputs complies with applicable laws, including copyright, patent, and trademark laws, and does not infringe upon the intellectual property rights of third parties.

Custom Developments
Any developments, including custom AI models, algorithms, or applications, specifically created by Service Provider for Client under this Agreement, shall be owned by Client, provided that Client pays all fees associated with such development as agreed upon. Service Provider shall retain the right to use general knowledge, skills, and experience, including non-Client-specific developments, gained during the performance of this Agreement.

Third-Party Materials and Open-Source Software
Service Provider may use third-party materials, including open-source software, in the development or delivery of AI services. Service Provider shall ensure that such use complies with the respective licenses and does not impose any unagreed obligations on Client. Service Provider shall inform Client of the use of any third-party materials that require attribution or impose restrictions on the use of AI-generated outputs.

Licenses to Service Provider
Client grants the Service Provider a non-exclusive, worldwide, royalty-free license to use, reproduce, modify, display, and distribute any Client data and AI-generated outputs as necessary to perform the services under this Agreement and to improve Service Provider’s AI technologies and services, subject to the confidentiality obligations of this Agreement.

Intellectual Property Indemnification
Service Provider agrees to indemnify Client against any claims, damages, losses, and expenses arising from a breach of intellectual property rights related to the Services provided, except where such claims arise from Client’s data or use of AI-generated outputs beyond the scope of this Agreement.
Client agrees to indemnify the Service Provider against any claims, damages, losses, and expenses arising from Client’s use of AI-generated outputs in violation of third-party intellectual property rights.

Data Rights and Ownership
For purposes of this Service Attachment, “AI Data” shall include all data, information, and material provided by Client to Service Provider for the purpose of receiving AI Services (“Client AI Data”), as well as all data, content, and materials generated by the AI Services as a result of processing Client AI Data or through interactions with Client’s systems (“AI-Generated data”).

 

Ownership of Client AI Data

  1. Client retains all right, title, and interest in and to Client AI Data.
  2. Service Provider acknowledges that it has no ownership rights over Client AI Data.
  3. Client grants the Service Provider a non-exclusive, worldwide, royalty-free license to access, use, process, and display Client AI Data solely for the purpose of performing the AI Services under this Service Attachment.

Ownership of AI-Generated Data
AI-Generated Data shall be owned by Client, subject to any underlying rights of third parties in the data or content from which such AI-Generated Data is derived. Client grants to Service Provider a non-exclusive, royalty-free right to use AI-Generated Data for the purposes of improving Service Provider’s AI Services, conducting research and development, and enhancing the AI models, subject to the confidentiality obligations and data protection provisions of this Agreement.

Data Usage Rights
Client grants to Service Provider the right to use aggregated and anonymized data derived from Client AI Data and AI-Generated Data for analytics, benchmarking, and to improve Service Provider’s services, provided such use does not reveal the identity of Client, any of its employees, clients, or Clients. Service Provider acknowledges that it shall not sell, lease, or otherwise provide access to Client AI Data or AI-Generated Data to any third party, except as permitted by this Agreement or with Client’s prior written consent.

Scroll to Top