The agreement contains critical privacy gaps. While the company promises to use commercially reasonable efforts to maintain security, it explicitly disclaims liability for unauthorized access unless caused by gross negligence or willful misconduct. No privacy policy is referenced, no data retention periods are specified, and no user consent mechanisms are described. Free services data receives no privacy protection and can be used for any business purpose. This fails to meet basic GDPR, CCPA, or state privacy law standards.
For paid services, changes require mutual written agreement from both parties. For free services, the company reserves unilateral modification rights with only notice via email or reasonable means. No minimum notice period is specified, and customers cannot reject changes other than by ceasing to use the service. The clause creates significant asymmetry between paid and free tiers.
The agreement addresses account termination and suspension but has significant gaps in consumer protection. For material breaches, the company provides a 30-day cure period and must use good faith efforts to resolve service degradation issues. However, there is no explicit appeal process for suspension or termination, and the company can suspend immediately for payment delinquency without notice. Data export services are available but are billed at standard company rates.
The limitation of liability clause is exceptionally broad and problematic. It explicitly excludes liability for data loss, bugs, and viruses regardless of company fault, and caps direct damages at fees paid in the prior 12 months. For free users, this cap is effectively zero. The clause lacks any carve-out for gross negligence or willful misconduct outside the indemnification section. Combined with Section 7's disclaimer for unauthorized access breaches, this leaves customers with virtually no remedies.
Payment terms are clearly disclosed, with annual invoicing in advance and 30-day payment windows. Auto-renewal occurs with 30-day notice before expiration. However, the agreement lacks consumer protections: all fees are non-refundable regardless of circumstances, no proration is offered for early cancellation, and no easy online cancellation method is specified. Overage charges apply automatically if usage limits are exceeded.
The indemnification clause is relatively balanced and fault-based, limited to customer's breach of terms, infringement claims regarding customer data, or violation of law. The company must be the target of third-party claims (not first-party losses). However, the clause lacks any cap on liability and contains no carve-out for company negligence or breach. The broad indemnified-parties list includes affiliates, contractors, and suppliers.
Users retain ownership of their uploaded data, but the company reserves exceptionally broad usage rights, particularly for free services. Free Services Data can be freely used for any business purpose including AI model training. Customer feedback is entirely assigned to the company with no compensation or attribution. The company may modify customer data and has unlimited rights to commercialize aggregated data from free services.
The document clearly establishes acceptance through either mutual execution of an Order Form or access to free services. The scope is defined as the Services specified in the Order Form or credentials provided. However, the acceptance mechanism for free services relies on browsing or accessing without explicit clickwrap consent. Age requirements are not addressed, and no plain-language summary is provided.
The agreement contains no mandatory arbitration, class-action waivers, or jury-trial waivers, preserving the customer's right to pursue court claims. Governing law is clearly specified as New York state law. However, exclusive venue is fixed in New York courts regardless of customer location, potentially making litigation prohibitively expensive for distant consumers. No small-claims carve-out is provided, and no alternative dispute resolution mechanisms are offered.