These Business Terms govern the ShinobiOps services supplied by CORE DUMP CONSULTING LTD, incorporated in England and Wales with company number 12927321, trading as ShinobiOps (Provider, we, us), to the business identified in an Order (Customer, you). Registered office: 24 Palladian Gardens, London, England, W4 2ER. Contact: contact@shinobiops.ai. The applicable Order records the purchased Services and commercial terms.

BUSINESS USE ONLY. The Services are supplied only for purposes relating to a trade, business, craft or profession. They are not offered to consumers. An individual accepting these Terms confirms that they act for a business and have authority to bind it. If you are acting wholly or mainly outside a trade, business, craft or profession, do not create an account or use the Services and contact us before proceeding.

1. Formation, scope and contract documents

1.1 The Agreement takes effect when an authorised person affirmatively accepts these Terms through an acceptance control, or the parties sign or otherwise expressly agree an Order incorporating them. The Terms and incorporated documents must be available before acceptance. An Order includes an online checkout record or other agreed purchasing record; a separate signature is not required for each purchase. Browsing the website does not itself accept a paid subscription. The acceptance record identifies the Customer, accepting user, timestamp, document versions and agreed purchase. Existing customers remain subject to their accepted agreement until a change or migration validly takes effect under it.

1.2 The Agreement comprises the applicable Order, these Terms, the Acceptable Use Policy at /aup, the Fair Use and Usage Policy at /fair-use, the Data Processing Addendum at /dpa where applicable, and any SLA, security or product-specific schedule expressly incorporated into the Order. The Privacy and Cookie Notices describe processing practices and are not blanket consents to processing or independent service warranties.

1.3 Mandatory transfer clauses prevail within their scope. Otherwise the DPA prevails for Customer Personal Data, followed by the Order, any expressly agreed SLA or product-specific schedule, these Terms, and the AUP and Fair Use and Usage Policy. An Order overrides a standard provision only where it identifies the override expressly. Publication of a new policy or Documentation version does not bypass Clause 22 or retrospectively alter an accepted Order.

1.4 Demonstrations, examples, roadmaps, forecasts and coming-soon features describe illustrative or intended capabilities; the Customer purchases the entitlements identified in its Order. Future development is not guaranteed unless expressly committed in that Order. Nothing in this Clause excludes liability for fraud, an actionable misrepresentation or a misleading statement to the extent it cannot lawfully be excluded.

1.5 The person accepting for the Customer represents that they have authority to bind the Customer. That person does not assume personal liability merely because they accepted for the Customer, except in the case of fraud or where applicable law provides otherwise.

1.6 The Services are offered only to businesses. A sole trader, partner or other individual may contract only for purposes relating to their trade, business, craft or profession. Where a person acts wholly or mainly outside those purposes, or where the purpose is mixed and the business purpose is not predominant, the Provider may decline to contract and may suspend or terminate an account opened contrary to this Clause under Clauses 20 and 21, refunding prepaid fees for the unused period.

1.7 The Provider may use reasonable business-identity and authority checks, request further information, decline an application or suspend access pending verification. It may accept different verification methods for different customers or offerings. An email domain alone does not establish business purpose, and this Agreement does not guarantee access through any particular authentication provider.

2. Definitions

3. Subscriptions, accounts and authorised users

3.1 Subject to the Agreement and payment, the Provider grants the Customer a non-exclusive, non-transferable, non-sublicensable right during the subscription to use the purchased Services for its internal business purposes. Plans may include specified numbers or categories of officers or agents, unlimited access to an identified feature, or the ability to create, configure or deploy customer-defined agents. The Order or checkout description presented at purchase records the selected entitlements, Seats, limits, prices and Billing Period. Describing an available feature does not include it in every Plan. Resale, service-bureau operation or deployment for third parties requires express permission in an Order.

3.2 The Customer must provide accurate account and billing information, protect credentials, use multi-factor authentication where offered, manage its users and promptly report suspected compromise to contact@shinobiops.ai, with a security-report subject line. Do not send passwords, access tokens or confidential content in an initial email report.

3.3 Each Seat is for one named Authorised User and may not be shared. The Customer may reassign a Seat when an Authorised User permanently changes role or no longer requires access, subject to any reasonable anti-abuse limits disclosed in the Documentation.

3.4 The Customer is responsible for its Authorised Users, administrators, configurations, instructions, approvals and use of the Services. An administrator may access, configure, export or delete Customer Content and manage accounts on the Customer's behalf.

3.5 An Affiliate may use the Services only if identified in the Order or authorised by the Customer within the product. The Customer remains responsible for the Affiliate's compliance unless the Affiliate signs its own Order.

4. Services and service changes

4.1 The Provider will supply the Services with reasonable skill and care and materially perform the core functionality expressly purchased in the Order. The Services evolve: the Provider may add, modify, replace or retire features, interfaces, models, providers, routing, integrations and technical methods under this Clause. Documentation will reflect current functionality, subject to the Order and the change protections in Clause 22.

4.2 Changes that do not materially reduce purchased core functionality may be made without fresh acceptance. For a material adverse reduction during a prepaid committed term, the Provider will ordinarily give at least 30 days’ notice and may offer a reasonably equivalent replacement or remedy. Where the reduction remains material after a reasonable opportunity to remedy it, the Customer may terminate the affected Service within 30 days after notice or implementation, whichever is later, and receive prepaid fees for the unused affected period. Necessary security, legal or upstream-dependency changes may occur sooner, with notice as soon as reasonably practicable. Those reasons do not by themselves remove the stated remedy. New-customer offers may change at any time without changing existing Orders.

4.3 Availability targets, support response times, service credits, data residency and professional services apply only if expressly stated in an Order or SLA. Beta, preview and evaluation features are governed by Clause 16.

4.4 The Provider may use subcontractors and Third-Party Services to provide the Services. The Provider remains responsible for its contractual obligations, subject to the express provisions relating to Third-Party Services and the DPA.

5. Ai features, virtual officers and customer control

5.1 The names 'officer', 'executive team', 'partner', 'principal' and similar labels describe software functionality and presentation only. No AI Feature is a natural person, company officer, director, employee, fiduciary, professional adviser, representative or legal agent of either party. No AI Feature has authority to bind the Provider or the Customer except to perform a technical action expressly configured and authorised by the Customer.

5.2 AI Features produce drafts, analyses, recommendations and proposed actions by probabilistic processing. An Output may omit material context, contain factual or logical error, reflect bias, rely on stale information, resemble material supplied to another user or otherwise be inappropriate for the intended use. The Customer is responsible for choosing an appropriate level of review and verification for its use case, including checks of facts, sources, calculations, legal and regulatory implications and suitability. Where supported, the Customer may enable unattended execution under Clause 5.3, subject to the AUP and any applicable requirements for human review.

5.3 Customer authorisation and automation. The Customer determines how it uses and configures the Services, including its agents, integrations, permissions, instructions, approval requirements and automation settings. Authorisation may be given for an individual action, a defined batch, a recurring workflow or a category of actions within permissions and limits configured by an authorised administrator or user. Where supported and enabled by the Customer, actions may execute without further individual review or confirmation. These provisions apply equally to Provider-supplied and Customer-created agents.

5.4 Customer responsibility and controls. The Customer is responsible for selecting suitable use cases, testing its configurations, establishing appropriate supervision and review, monitoring results, and managing or revoking authorisations. The Provider does not undertake to review the business merits, accuracy, legality or suitability of each Customer instruction, Output or External Action. Approval, monitoring and other controls are available as described for the applicable Services and are not a guarantee that every error, unintended action or duplicate execution will be prevented. The Customer remains responsible for its decisions and use of the Services, including its decision to enable unattended execution. This allocation does not exclude the Provider’s responsibility for its own breach of the Agreement or liability that cannot lawfully be excluded; applicable liability remains subject to Clause 19.

5.5 The Services do not provide legal, tax, accounting, investment, medical, employment or other regulated professional advice. Output relating to finance, revenue, operations, marketing or strategy is general business-support material and must be reviewed by qualified personnel where the context requires.

5.6 The Customer must not use Generated Output as the sole basis for a High-Impact Decision and must not deploy the Services in a prohibited or high-risk use described in the AUP unless the Provider has expressly approved the use in writing and the parties have agreed any required safeguards or product-specific terms.

6. Customer instructions, integrations and external actions

6.1 The Customer authorises the Provider to access and process Customer Content and to interact with Third-Party Services only as necessary to provide the Services in accordance with the Customer's instructions, configuration and authorisations under Clause 5.3. Standing authorisation does not permit actions outside its configured scope or override the AUP, the DPA or applicable law.

6.2 The Customer is responsible for obtaining all rights, permissions, notices and lawful bases necessary for Customer Content, connected accounts, contact lists, communications and External Actions. The Customer must comply with the terms and policies applicable to each Third-Party Service.

6.3 The Customer must configure permissions according to least-privilege principles, review scopes before connecting a Third-Party Service, and revoke credentials when no longer required. The Provider may require reauthorisation or suspend an integration if credentials, scopes or upstream terms change.

6.4 Customer-selected Third-Party Services remain subject to their own availability, terms, fees and practices. The Provider may replace a supplier, model or integration where permitted by Clauses 4 and 22 and the DPA. The Provider is not responsible for failures caused solely by Customer-controlled services, permissions or systems, but remains responsible for its own contractual performance and its Subprocessors as required by the DPA. An upstream change is not a blanket exclusion of that responsibility.

7. Customer content, generated output and intellectual property

7.1 As between the parties, the Customer retains all right, title and interest in Customer Content that it supplies, including Inputs and Customer Data. The Customer grants the Provider and its subcontractors a worldwide, non-exclusive, limited licence during the Agreement to host, reproduce, transform, transmit and otherwise process Customer Content only to provide, secure, support and maintain the Services and to comply with law.

7.2 To the extent a transferable intellectual property right in Generated Output created specifically for the Customer vests in the Provider, that right is assigned to the Customer on creation, subject to the Customer's compliance with the Agreement and applicable law. The assignment does not extend to Provider technology, templates, models, prompts, workflows, know-how, Service Data or third-party material. To the extent Provider-owned material is embedded in that Output and necessary to use it, the Provider grants the Customer a perpetual, worldwide, non-exclusive, royalty-free licence to use, reproduce, modify and distribute that embedded material as part of the Output for the Customer's lawful business purposes. That licence does not grant access to underlying systems or a right to extract or commercialise Provider technology separately; third-party material remains subject to its applicable licence terms. The embedded-material licence survives expiry or termination, subject to the restrictions that apply to use of the Output.

7.3 Generated Output may fall outside copyright or other intellectual-property protection. Because generation is probabilistic and users may request overlapping material, another user may receive content that resembles an Output; that resemblance does not give the Customer rights in another user's material. The Provider does not warrant uniqueness, non-infringement or freedom from third-party rights, and the Customer must carry out appropriate clearance before commercial publication or use, including for names, branding, images, code and regulated content.

7.4 The Customer represents that it has all rights and permissions needed for the Customer Content and instructions it provides and that their processing as contemplated by the Agreement will not violate law, contract, confidentiality, privacy, intellectual property or other third-party rights.

7.5 The Provider and its licensors retain the Services, Provider-created prompts, templates, workflows, models, software, interface, Documentation, trademarks and improvements. Customer ownership of its supplied content, including its own agent configurations and instructions, is not transferred merely because that content is used with the platform. Rights to Provider material embedded in an Output are limited to Clause 7.2; no right to extract or commercialise underlying Provider technology is implied.

7.6 If the Customer voluntarily provides feedback, it grants the Provider a perpetual, worldwide, irrevocable, royalty-free licence to use it without restriction or attribution, provided that the Provider does not publicly identify the Customer without permission.

8. Use of content for service delivery and improvement

8.1 The Provider may process Customer Content to deliver requested functionality, maintain context and customer-specific memory, personalise the Customer's experience, prevent abuse, investigate incidents, provide support and comply with law. Customer-specific memory and adaptation will not be made available to another customer except at the Customer's instruction.

8.2 The Provider will not use Customer Content to train, fine-tune or improve a model made generally available to other customers or third parties under this Agreement. Customer-specific memory and calibration may support the Customer’s own Services. The Provider may use Service Data and genuinely aggregated or de-identified data to operate, secure, analyse and improve the Services, subject to confidentiality and Applicable Data Protection Law; this does not authorise general training using Customer Content. Any future general-training offering would require separate specific terms, required authorisation and information about retention, withdrawal and the limits of reversing completed training before it is enabled.

8.3 The Provider will impose corresponding no-general-training restrictions on model processors and processing intermediaries for Customer Content supplied through generation, embedding, research and fallback routes. Feature enablement or acceptance of an upstream policy does not waive this restriction. Supplier retention for disclosed service delivery or abuse monitoring does not authorise unrelated use.

9. Data protection

9.1 Each party will comply with Applicable Data Protection Law in relation to its own processing under the Agreement. The Provider acts as an independent controller for account administration, billing, security, fraud prevention, service communications and its own business records, as described in the Privacy Notice.

9.2 Where the Provider processes personal data contained in Customer Content on the Customer's behalf, the Customer is the controller or processor (as applicable), the Provider is its processor or subprocessor, and the DPA applies automatically to every Plan. The availability of legally required processor terms is not conditional on an Enterprise subscription.

9.3 The Customer determines the purposes and essential means of its processing, provides legally sufficient notices, identifies a lawful basis, responds to individuals, and ensures its instructions are lawful. The Provider processes Customer Personal Data only on documented instructions, subject to the DPA.

9.4 Unless an Order and the DPA expressly permit it, the Customer must not submit: (a) special category or sensitive personal data; (b) payment card data subject to PCI DSS beyond use of the authorised payment interface; (c) protected health information subject to HIPAA; (d) government identifiers; (e) precise geolocation; (f) biometric data; (g) children's data; or (h) data subject to professional secrecy or sector-specific localisation requirements.

9.5 International transfers of Customer Personal Data will use the mechanism specified in the DPA, which may include the UK International Data Transfer Agreement or UK Addendum, the European Commission's Standard Contractual Clauses and supplementary measures, as applicable.

9.6 The Customer must not rely on consent to international transfers merely through acceptance of these Terms. The parties will instead use the lawful transfer mechanism and assessment required by Applicable Data Protection Law.

10. Confidentiality

10.1 Confidential Information means non-public information disclosed by or for a party that is marked confidential or should reasonably be understood as confidential, including Customer Content, security information, pricing in a negotiated Order, technology and business plans. It excludes information that the recipient can demonstrate: (a) is public without breach; (b) was lawfully known without restriction; (c) was received lawfully from a third party without restriction; or (d) was independently developed without use of the discloser's information.

10.2 The recipient will use Confidential Information only to perform or exercise rights under the Agreement; protect it with at least reasonable care; and disclose it only to personnel, Affiliates, subcontractors and professional advisers who need to know it and are bound by confidentiality obligations no less protective in substance.

10.3 A recipient may disclose Confidential Information where required by law, provided it gives advance notice where legally permitted and reasonably assists the discloser to seek protective treatment. On termination or request, it will delete or return Confidential Information subject to legal retention, archival backups and the DPA.

11. Security, safety and abuse monitoring

11.1 The Provider will maintain technical and organisational measures appropriate to the processing risk, as described in the DPA and any agreed security schedule. Measures may evolve provided the overall level of protection is not materially reduced. No certification, particular control implementation, data residency, recovery objective or absolute security guarantee applies unless expressly stated in an applicable schedule.

11.2 The Provider may use automated controls and proportionate human review to detect fraud, abuse, security threats and AUP violations. Any access to Customer Content for this purpose will be limited to authorised personnel with a need to know, logged where appropriate, and subject to confidentiality and retention controls described in the Privacy Notice or DPA.

11.3 The Customer must maintain secure endpoints, user access controls, backups of source data, incident-response procedures and appropriate human oversight. The Services are not a substitute for the Customer's own business continuity, cyber security or record-keeping controls.

12. Acceptable use

12.1 The Customer and each Authorised User must comply with the Acceptable Use Policy. The Customer must not use the Services unlawfully, harmfully, deceptively, to infringe rights, to compromise systems or persons, or in a way that creates unacceptable safety, legal or reputational risk.

12.2 The Provider may update the AUP to address changes in law, threats, supported functionality or upstream requirements using the notice and change process in Clause 22. Proportionate protective measures already permitted by the Agreement may take effect sooner where necessary. Changes apply prospectively and do not retrospectively make previously permitted use a breach.

13. Fair use and resource consumption

13.1 The Fair Use and Usage Policy at /fair-use applies to every Plan. Limited Plans may enforce the allowance, scope, counting method, reset period and exhaustion behaviour disclosed in the Order. Unlimited applies only to the feature expressly described as unlimited; it does not remove disclosed operational controls or make every resource unlimited. Separately purchased capacity or a metered offering applies only if its quantity or measurement, rate and operation were affirmatively agreed. No undisclosed charge, forced upgrade or automatically added Seat is permitted.

13.2 The Provider may measure consumption and cost to operate, secure and manage the Services. For an Unlimited Plan, an internal budget is not a hidden fixed allowance. For a Limited Plan, only the disclosed agreed allowance may be used as its ordinary exhaustion limit. Protective controls may address abuse, instability or exceptional Customer-specific risk under the Fair Use and Usage Policy. Usage alone does not authorise a new charge or purchase; charging within a metered arrangement already expressly accepted by the Customer does not require a new acceptance for each measured unit.

14. Fees, billing, taxes and renewal

14.1 The Customer will pay the fees, currency and billing frequency shown in the Order. Unless the Order states otherwise, subscription fees are charged in advance at the start of each Subscription Term through the payment method provided by the Customer.

14.2 Unless the Order states otherwise, a subscription renews automatically for successive Billing Periods unless either party gives notice of non-renewal before renewal. The Customer may cancel through the available billing-management interface or contact@shinobiops.ai. Cancellation stops renewal and ordinarily leaves access until the paid period ends, subject to suspension or termination rights. Renewal changes are governed by Clauses 14.5 and 22. The Provider will not use a change to evade an express founding-price commitment.

14.3 Fees are non-cancellable and non-refundable except as expressly stated in the Agreement, required by law, or where the Provider agrees otherwise. The Customer remains entitled to any refund expressly provided for a material service reduction, Provider termination for convenience, or uncured Provider breach.

14.4 Fees exclude VAT, sales, use, withholding and similar taxes. The Provider will add, withhold or account for taxes where applicable law requires it. Where the Customer claims business-to-business place-of-supply or reverse-charge treatment outside the United Kingdom, it must provide a VAT registration number or other evidence reasonably satisfactory to the Provider; the parties will apply the treatment required by applicable law. If withholding is legally required, the Customer will gross up the payment so that the Provider receives the invoiced amount, except to the extent prohibited by law or expressly varied in the Order.

14.5 The Provider may change prices for new purchases at any time. Changes to an existing subscription’s renewal price or entitlements require at least 30 days’ prior notice specifying the change and renewal date, with an opportunity to cancel before that renewal. The change may apply at that renewal under the agreed change mechanism without a separate signature; if sufficient notice was not given, it must be deferred. Prepaid committed terms are not repriced retrospectively. Additional purchases during a term require affirmative agreement. Founding-price protection and negotiated Order terms prevail.

14.6 If the Order identifies the Customer as a 'Founding Operator', the recurring base subscription rate stated in that Order will remain unchanged for the life of the continuously maintained subscription, provided that: (a) the Customer does not cancel, allow the subscription to lapse, materially downgrade or fail to pay following any applicable notice and cure period; (b) the protection applies only to the Plan and number of Seats stated in that Order, so additional Seats, additional Plans, new products and add-ons require separate agreement at the disclosed price; and (c) taxes and statutory charges are excluded. A third-party pass-through cost may be charged separately only if its category and amount or calculation method were expressly accepted by the Customer in the Order or a later affirmative agreement before it is incurred. The exclusion for pass-through costs does not permit unilateral recovery of ordinary model, hosting or other supplier-cost increases. If the subscription lapses, the protection ends and does not revive on re-subscription. The Provider may withdraw the programme for new customers without affecting an existing protected rate.

14.7 If payment is overdue, the Provider may charge lawful interest at 4% above the Bank of England base rate, recover reasonable collection costs, and suspend the affected account after at least 7 days' notice, except in the case of fraud, chargeback or imminent loss where immediate restriction may be reasonable.

14.8 Trials, discounts, pilots and promotions are available only when expressly offered and accepted on their stated terms. Otherwise payment is due in advance from the first Billing Period. Any conversion from a trial or promotion to a paid subscription, including its timing, amount, billing frequency and cancellation route, must be clearly disclosed and agreed before conversion. This Clause does not itself offer a free trial.

15. Availability, support and maintenance

15.1 The Provider will use commercially reasonable efforts to make paid Services available, excluding planned maintenance, emergency maintenance, Customer systems, Third-Party Services and events beyond reasonable control. No 24/7 or uninterrupted availability commitment applies unless stated in an SLA.

15.2 Support channels and any response targets are described at /support or in the Order. Targets are not guaranteed response or resolution times unless an SLA expressly says so. Dedicated support, custom development, integrations and migration assistance are included only if expressly purchased. Necessary statutory or DPA assistance remains governed by those obligations.

15.3 The Provider may perform planned maintenance on reasonable notice where practicable and emergency maintenance without prior notice where necessary to protect the Services or users.

16. Beta and preview features

16.1 Beta, preview, pilot and evaluation features may be limited, changed or withdrawn at any time; may have additional disclosed technical controls or reduced capacity; may not be supported; and are provided for evaluation only. Where such a feature processes Customer Personal Data, the DPA and applicable security and data-protection obligations continue to apply. Beta or preview status does not exclude mandatory processor terms. The Provider must disclose and agree any materially different processing, supplier route or permitted-data scope before the feature is enabled and must not enable processing that it cannot lawfully support.

16.2 To the maximum extent permitted by law, beta and preview features are supplied 'as is' without warranty or SLA. The Customer must not use them for production, High-Impact Decisions, regulated data or business-critical activities unless the Provider expressly approves that use in writing.

17. Warranties and disclaimers

17.1 Each party warrants its authority to enter the Agreement. The Provider will supply the Services with reasonable skill and care and materially perform purchased core functionality. For a promptly notified material service failure, the Provider will have a reasonable opportunity to correct, re-perform or provide a reasonably equivalent substitute. If the material failure remains unresolved, the Customer may terminate the affected Service and receive unused prepaid fees. These are the contractual service-warranty remedies, subject to non-excludable rights, express DPA obligations and other remedies expressly preserved by the Agreement; monetary liability remains subject to Clause 19.

17.2 Except for the express warranties in the Agreement and to the maximum extent permitted by law, the Services, AI Features, Generated Output and Third-Party Services are provided 'as is' and 'as available'. The Provider disclaims implied terms concerning merchantability, satisfactory quality, fitness for a particular purpose, non-infringement and results, but only to the extent they may lawfully be excluded.

17.3 The Provider does not warrant that the Services or Generated Output will be uninterrupted, error-free, secure against every threat, accurate, complete, current, unique, legally compliant for the Customer's use, or capable of producing a particular commercial, financial, operational, marketing or strategic result.

18. Indemnities

18.1 The Customer will defend the Provider against a third-party claim to the extent it alleges that: (a) Customer Content, Customer instructions or a Customer-controlled External Action infringes rights or violates law; or (b) the Customer's use of the Services in material breach of the AUP caused harm to the claimant. The Customer will indemnify the Provider for damages and reasonable external costs finally awarded or agreed in a settlement approved under Clause 18.3.

18.2 No Provider intellectual-property indemnity is included solely because a Plan is called Enterprise or has another tier name. Such an indemnity applies only if an Order or negotiated schedule expressly grants it and states its scope, conditions and applicable cap. Any such indemnity is limited to its agreed scope and does not automatically cover Generated Output, Customer Content, Customer modifications, third-party combinations or use contrary to the Agreement.

18.3 An indemnified party must give prompt notice, reasonable cooperation and control of the defence to the indemnifying party. Delay relieves the indemnifying party only to the extent materially prejudiced. No settlement may admit fault by, impose non-monetary obligations on, or fail to fully release the indemnified party without its prior consent, not to be unreasonably withheld.

19. Limitation of liability

19.1 Nothing in the Agreement excludes or limits liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) wilful misconduct where it cannot lawfully be limited; (d) the Customer's obligation to pay fees; or (e) any liability that applicable law does not permit a party to exclude or limit.

19.2 Subject to Clause 19.1, neither party is liable for loss of profit, revenue, anticipated savings, business, opportunity or goodwill, or for indirect, special or consequential loss, arising from the Agreement, whether in contract, tort (including negligence), misrepresentation, restitution or otherwise. Business-interruption losses are excluded except for the direct costs expressly preserved in this Clause. These exclusions do not exclude reasonable, evidenced direct costs of restoring or reconstructing lost or corrupted Customer Data, investigating and remediating a personal data breach or confidentiality breach, making legally required breach notifications, or obtaining temporary substitute services to the extent reasonably necessary to mitigate a breach by the liable party. Those costs remain subject to causation, mitigation and the applicable cap. The exclusions do not apply to amounts payable under an indemnity for a third-party claim to the extent that indemnity applies.

19.3 Subject to Clauses 19.1 and 19.4, each party’s aggregate liability for claims attributable to events in a Contract Year is limited to 100% of the fees paid or payable for the affected Services during the 12 months immediately before the first event giving rise to those claims. A Contract Year is each successive 12-month period beginning on the Effective Date or its anniversary. If fewer than 12 months have elapsed, use only fees paid or payable for that elapsed period; future monthly payments are not annualised. An annual fee already paid for the affected Services is included. A series of related events is attributed to the Contract Year of its first event; later claims or termination do not create a new cap for the same series.

19.4 Subject to Clause 19.1, liability for breach of confidentiality or the DPA, a personal data breach caused by failure to comply with agreed security obligations, or an applicable indemnity is limited to 200% of the fee basis in Clause 19.3. That higher cap replaces the ordinary cap for those claims. There is no duplicate recovery for one loss; aggregate liability across both categories in a Contract Year must not exceed that 200% cap. A negotiated indemnity or Order may expressly specify a different cap. Neither cap limits statutory rights of individuals or liability that cannot lawfully be limited.

19.5 The parties intend these limitations to allocate risk in light of the fees and available insurance. Each limitation applies only to the extent it satisfies any applicable statutory reasonableness or fairness test, including the Unfair Contract Terms Act 1977, and will be interpreted to preserve the maximum lawful limitation rather than exclude a remedy in its entirety.

20. Suspension

20.1 The Provider may suspend or restrict the affected part of the Services where reasonably necessary because of: (a) a material AUP or Agreement breach; (b) an actual or reasonably suspected security threat, fraud or unauthorised access; (c) legal or regulatory requirement; (d) non-payment; (e) an upstream suspension that prevents supply; or (f) use creating a material risk to service stability, other customers or the Provider.

20.2 Where reasonably practicable, the Provider will give prior notice, explain the general basis, limit suspension to the affected access or feature, and give the Customer a reasonable opportunity to cure. It may act immediately where delay would increase security, legal, safety, financial or service-integrity risk.

20.3 The Provider will restore access promptly after the issue is resolved. Suspension does not excuse accrued fees, but the Provider will not charge undisclosed overages and will consider a fair service adjustment where suspension resulted solely from the Provider's error.

21. Term, termination and consequences

21.1 The Agreement begins on the Effective Date and continues until all Orders have expired or been terminated. Either party may terminate an Order for material breach if the breach is not cured within 30 days after detailed written notice, or immediately if the breach cannot be cured.

21.2 Either party may terminate immediately if the other enters insolvency proceedings that are not dismissed within 60 days, ceases business, or where continued performance would be unlawful. The Provider may withdraw or terminate a beta, preview, pilot or evaluation feature at any time in accordance with Clause 16.

21.3 The Provider may terminate a paid Order for convenience on at least 60 days' notice and will refund prepaid fees for the unused period after termination. This right does not permit termination for the purpose of avoiding a valid founding-price commitment while that commitment subsists.

21.4 On termination: access ends; unpaid accrued fees become due; each party returns or deletes Confidential Information subject to lawful retention; and provisions intended by nature to survive will survive, including ownership, confidentiality, fees, disclaimers, indemnities, liability, dispute and general provisions.

21.5 For 30 days after expiry or termination, the Customer may request a standard export of stored Customer Content in a reasonably available structured, machine-readable format, or instruct earlier deletion. This does not promise continued interactive access, perpetual export availability, bespoke reconstruction of historical derived artefacts or disclosure of Provider technology or another customer’s data. Where interactive access is unsafe, lawful return to a verified recipient will use a secure alternative. Bespoke migration or conversion work may be separately charged if agreed in advance and legally permitted. Personal-data return and deletion rights under the DPA are not restricted by the standard export window. Active copies will be deleted within 90 days after an earlier deletion instruction or completed return, and no later than 120 days after termination; corresponding backups expire within 90 days after active deletion and no later than 210 days after termination, subject only to the DPA’s limited legal-retention exception. Derived personal data and Subprocessor copies are included in deletion even where a bespoke artefact reconstruction is not included in standard export.

22. Changes to these terms

22.1 The Provider may update the Terms and incorporated operational policies to reflect changes to the Services, technology, security threats, applicable law, supplier requirements or reasonable administrative arrangements. Updates must be proportionate to their stated purpose. Routine improvements and clarifications that do not materially disadvantage the Customer may take effect when posted. Material changes require at least 30 days’ notice describing the change, reason, effective date and available exit right. Changes necessary for law or urgent security or service-integrity reasons may take effect sooner, with notice as soon as reasonably practicable. This power does not authorise unrestricted changes unrelated to these purposes.

22.2 The Customer may object to a materially adverse change before it takes effect or, for an urgent change, within 30 days after notice. The Provider may resolve the objection, maintain the prior terms for the committed period or allow termination of the affected Service with a refund of unused prepaid fees. Changes within this agreed mechanism may take effect on the notified date without a separate signature; mere browsing does not establish the original agreement or acceptance of a migration from different legacy terms. Renewal price and entitlement changes follow Clause 14.5. Additional purchases, new metered charging or general-training authorisation, and changes outside this mechanism require affirmative agreement or other legally valid authorisation. No change applies retrospectively to accrued claims, removes non-excludable rights or overrides an express negotiated Order or founding-price commitment. A new public catalogue alone does not amend an existing purchase.

23. Compliance with laws

23.1 Each party will comply with laws applicable to its own performance and business. The Customer is responsible for laws applicable to its industry, users, Customer Content, marketing communications, External Actions and use of Generated Output.

23.2 The Customer must not access or use the Services in violation of sanctions, export controls or trade restrictions applicable to it or the Provider, and represents that it is not a restricted person and will not make the Services available in an embargoed territory or for a prohibited end use.

23.3 Each party will comply with applicable anti-bribery and anti-corruption law. The Customer must not instruct an AI Feature to offer, promise, give, request or accept an improper advantage.

24. Publicity

24.1 Neither party may use the other's name, logo or trade marks in publicity without prior written consent, except to identify the parties internally or as legally required.

25. General

25.1 Notices. Legal notices to the Provider may be sent to contact@shinobiops.ai or its registered office, and notices to the Customer to the account administrator email or Order address. Notices are deemed received on delivery by hand, two Business Days after recorded post, or the next Business Day after email without a delivery-failure response, subject to any mandatory service rule. Material change notices must be sent directly to administrators; website posting alone is insufficient. Routine service communications may be in-product or by email.

25.2 Assignment. Neither party may assign the Agreement without the other's prior consent, not to be unreasonably withheld, except to an Affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets, provided the assignee can perform the obligations and is not a direct competitor of the other party. The Provider will give notice of an assignment affecting the contracting entity or data controller.

25.3 Force majeure. Neither party is liable for delay caused by events beyond its reasonable control, except for payment obligations. The affected party will mitigate and resume performance promptly. If material performance is prevented for more than 60 days, either party may terminate the affected Order and the Provider will refund prepaid unused fees.

25.4 Entire agreement. The Agreement constitutes the entire agreement about its subject matter and supersedes prior statements and agreements. Neither party relies on a statement not set out in the Agreement, but nothing excludes liability for fraud or fraudulent misrepresentation.

25.5 No waiver. Delay or failure to exercise a right is not a waiver. A waiver must be in writing and applies only to the stated instance.

25.6 Severability. If a provision is unlawful or unenforceable, it will be modified to the minimum extent necessary to make it enforceable or, if that is not possible, severed. The remainder remains effective.

25.7 Relationship. The parties are independent contractors. The Agreement does not create a partnership, joint venture, employment, fiduciary or agency relationship.

25.8 Third-party rights. A person who is not a party has no right to enforce the Agreement under the Contracts (Rights of Third Parties) Act 1999, except an Affiliate or indemnified person where the Agreement expressly grants a benefit. The parties may vary or terminate the Agreement without consent of a third party.

25.9 Counterparts and electronic signature. Orders may be accepted electronically and in counterparts, each of which is an original and together form one instrument.

25.10 Interpretation. 'Including' means including without limitation; singular includes plural; headings do not affect interpretation; a reference to law includes amendments and replacements; and an obligation not to do something includes not permitting it. Business Day means a day other than Saturday, Sunday or public holiday in London.

26. Governing law and disputes

26.1 Before formal proceedings, a party will give a written dispute notice and senior representatives will seek a resolution for 30 days. This does not prevent urgent injunctive relief, lawful recovery of undisputed overdue fees or proceedings necessary to preserve a limitation period.

26.2 The Agreement and any non-contractual obligations arising out of or in connection with it are governed by the law of England and Wales. The courts of England and Wales have exclusive jurisdiction.

Regional and regulated uses

Each party remains responsible for obligations imposed on it in its own role by applicable law. An Order may incorporate regional or sector schedules where needed; contractual selection does not determine territorial scope. The Services are not authorised for prohibited AI practices or regulated uses excluded by the AUP. The Provider may decline a territory or use case it cannot support lawfully.

Where applicable AI law requires disclosures, markings, human oversight, AI literacy or information about limitations, each party must fulfil its obligations in its actual role. Customers must preserve required disclosures and use the supplied controls. Creating or modifying an agent may affect statutory classification; a software label does not decide it. The Provider does not transfer its own statutory duties to the Customer.

United States deployments must comply with applicable state privacy, consequential-decision, employment, biometric, recording and communications requirements. Customer approval of an action does not waive those laws. An authorised regulated deployment may require a separate Order and safeguards. The English contracting entity and forum remain as stated unless an express Order lawfully provides otherwise.

Previous website Terms. Publication alone does not migrate an existing agreement.

← Back to home