Terms of Service
These Terms of Service (the "Terms") govern access to and use of DatumOS, a hosted software service that puts AI agents to work inside an organisation's operations and engineering workflows. They form a contract between the customer organisation (the "Customer", "you") and [COMPANY LEGAL NAME], [legal form], with its registered seat at [REGISTERED ADDRESS], registered under [REGISTRATION NUMBER], VAT ID [VAT ID] (the "Provider", "we"). By signing an Order Form, accepting these Terms in writing or using the Service, the Customer agrees to them. A separate written agreement signed by both parties prevails over these Terms where they conflict.
1. Definitions
- Service: the DatumOS software, the dedicated Instance operated for the Customer, the administration panel, the public API, the command-line tool, the Terraform provider, the MCP server, the satellite software and related documentation and support.
- Instance: the isolated deployment of DatumOS operated for one Customer, with its own database, storage and encryption key, reachable under a host name in the
datumos.iodomain or a custom domain agreed in the Order Form. - Organisation: the Customer's tenant inside the Instance; Space: a team-level partition of the Organisation with its own data, integrations and access rules.
- Account: a user identity that signs in to the Instance through the Customer's identity provider (Microsoft 365 / Entra ID or another OpenID Connect provider) or, where agreed, through credentials issued by the Provider.
- Customer Data: all data the Customer or its users submit to, generate in or connect to the Instance, including cases, sessions, attachments, configuration, knowledge bases and the content the agent reads from connected systems.
- Connected Systems: third-party services the Customer connects to the Instance (for example Microsoft Teams, Outlook, GitHub, Jira, Salesforce, VictorOps, Confluence) and machines on which the Customer runs the satellite software.
- Model Provider: a third party whose large language models the agent uses (currently Anthropic and OpenAI), under the Customer's own subscription or API key unless the Order Form says otherwise.
- Order Form: the document, quote or written exchange in which the parties agree the plan, fees, term, hosting region and any special conditions.
- Trial: a period during which the Service, or part of it, is provided free of charge for evaluation.
2. The Service
2.1. The Provider prepares and operates a dedicated Instance for the Customer, hosted on Amazon Web Services in the European Union (region eu-central-1, Frankfurt) unless a different AWS region is agreed in the Order Form. The Provider keeps the Instance updated and monitors its health.
2.2. During early access the Provider sets up the Instance together with the Customer: identity provider connection, the first channel and the first Spaces. Onboarding scope and timelines are set out in the Order Form.
2.3. The Service includes AI agents that read Customer Data and content from Connected Systems, run commands inside isolated execution environments, prepare changes and answer in the channel where they were asked. What the agent may do without a person's approval is a configuration the Customer controls per Space (the "autonomy level"). Actions with consequences outside the Instance are, by design, either reversible or subject to a human approval step; the Customer decides which effects require approval within the options the Service offers.
2.4. The Provider may improve, extend or change features of the Service. A change that materially reduces core functionality of a paid plan is announced at least 30 days in advance, except where required for security or by law.
3. Trial
3.1. Where the Provider grants a Trial, the Service is provided "as is" for evaluation, without service levels, for the period stated in the Order Form or in the Provider's written confirmation.
3.2. At the end of a Trial the Customer may enter a paid plan. If it does not, the Instance is suspended and, after the export window in section 10, destroyed together with its database, storage and encryption key.
4. Accounts, administrators and members
4.1. The Customer designates at least one Organisation administrator, who manages Spaces, integrations, access policies, autonomy levels and credentials. The Customer is responsible for all activity under its Accounts and for keeping its identity provider, credentials and API keys secure.
4.2. Users must be employees or contractors of the Customer or of its affiliates, or other persons the Customer authorises. The Customer ensures that they comply with these Terms.
4.3. The Customer must notify the Provider without undue delay at sales@datumos.ai of any suspected unauthorised access to the Instance or its credentials.
5. Fees, billing and taxes
5.1. Fees, the billing period, the payment method and the plan's limits (such as the number of Spaces or included usage) are set out in the Order Form. Unless stated otherwise, fees are quoted in EUR, exclusive of VAT and other taxes, and invoiced in advance for each billing period.
5.2. Card payments, where offered, are processed by a payment processor named in the Order Form; the Provider does not store full card numbers.
5.3. Model usage is billed by the Customer's Model Provider directly to the Customer under the Customer's own subscription or API key. The Provider adds no markup to model usage. Where the Order Form provides for Provider-issued model access, its pricing is stated there.
5.4. Invoices are due within 14 days of issue unless the Order Form says otherwise. If an invoice remains unpaid 14 days after a written reminder, the Provider may suspend the Instance until payment; the export window in section 10 applies before any destruction of data.
5.5. Prices may change at the end of a committed term with at least 60 days' written notice.
6. Acceptable use
6.1. The Customer may use the Service only for its own internal business purposes and in compliance with applicable law, including data protection, employment, export control and intellectual property law.
6.2. The Customer must not: (a) use the Service to attack, probe or gain unauthorised access to any system, including through the agent; (b) direct the agent to act on systems the Customer is not authorised to operate; (c) grant the agent credentials or access broader than the task requires where the Service offers a narrower option; (d) use the Service to generate or distribute unlawful, infringing or harmful content; (e) resell the Service or provide it to third parties as a service bureau; (f) reverse engineer or copy the Service except as permitted by law; (g) circumvent usage limits, security controls or approval steps.
6.3. The agent processes content from Connected Systems that may be untrusted (for example incoming e-mail, tickets or pull requests). The Customer acknowledges that such content may attempt to influence the agent, that the Service is designed with this risk in mind, and that approval steps and autonomy levels are the Customer's primary control over consequences. The Customer configures them in line with its own risk appetite.
6.4. Where the Customer runs the satellite software on its own machines, the Customer is responsible for those machines, their network access and the systems reachable from them. The satellite connects outbound only, to the Instance and to the Model Provider.
6.5. The Provider may suspend an Account, a Space or the Instance where continued operation would, in the Provider's reasonable judgement, cause harm to the Service, to third parties or to the Customer, and will inform the Customer as soon as practicable.
7. Customer Data
7.1. Customer Data belongs to the Customer. The Customer grants the Provider the right to host, process and transmit Customer Data solely to provide, secure and support the Service and as instructed by the Customer.
7.2. For personal data in Customer Data the Provider acts as processor and the Customer as controller; the Data Processing Agreement forms part of these Terms. Personal data the Provider processes as controller (for example contract and billing contacts) is described in the Privacy Policy.
7.3. The Provider does not use Customer Data to train machine-learning models. Prompts and outputs exchanged with the Model Provider are governed by the Customer's agreement with that Model Provider where the Customer uses its own subscription or key.
7.4. The Customer can export Customer Data at any time through the panel or the API: cases, sessions, attachments and configuration. Configuration exports allow moving a Space between Instances.
7.5. The Provider may collect technical and usage telemetry about the operation of the Instance (such as run counts, durations, error rates and feature usage) to operate, secure and improve the Service. Such telemetry is not used to profile individual users beyond what the Service displays to the Customer itself.
8. Third-party services and Model Providers
8.1. Connected Systems and Model Providers are chosen, licensed and configured by the Customer. Their availability, terms and pricing are outside the Provider's control. The Provider is not liable for their acts or omissions, except to the extent it has engaged them as sub-processors under the Data Processing Agreement.
8.2. The Customer is responsible for holding valid licences for the Model Providers it connects, and for configuring which Model Providers may process the data of each Space.
8.3. Output of large language models may be inaccurate or incomplete. The Service presents the agent's work for human review; the Customer remains responsible for decisions taken on the basis of the agent's output and for the approvals it grants.
9. Availability, support and security
9.1. The Provider aims to keep the Instance available around the clock, with planned maintenance announced in advance where it may affect availability. Service levels, response times and support hours for paid plans are set out in the Order Form.
9.2. Support requests are made by e-mail to the address in the Order Form. During early access the Provider replies within two business days.
9.3. The Provider maintains the technical and organisational measures described in the Data Processing Agreement, including one Instance per Customer, encryption at rest and in transit with a key per Customer, isolated execution environments for the agent, and a credentials vault that keeps connector secrets out of the agent's reach except through pre-authorised tools with the access a task requires.
10. Term, termination and offboarding
10.1. The agreement starts on the date of the Order Form and runs for the term stated there. Unless terminated with at least 30 days' notice before its end, it renews for successive periods of the same length.
10.2. Either party may terminate for material breach if the breach is not cured within 30 days of written notice. The Provider may terminate immediately if the Customer's use threatens the security of the Service or of third parties.
10.3. After termination or expiry the Instance is suspended and the Customer has 30 days to export Customer Data (the "export window"). On request the Provider assists with the export at its then-current professional services rates. After the export window the Provider destroys the Instance, its database, storage and encryption key within a further 30 days, except for backups that expire under the Provider's backup schedule and data the Provider must retain by law.
10.4. Sections 5 (as to unpaid amounts), 7, 11, 12, 13 and 14 survive termination.
11. Intellectual property
11.1. The Provider and its licensors own all rights in the Service. The Customer receives a non-exclusive, non-transferable right to use the Service for the term of the agreement.
11.2. The Customer owns the configuration it creates (Flows, routines, prompts, knowledge bases) and the outputs the agent produces for it, subject to the rights of third parties and the Model Provider's terms.
11.3. The Provider may use feedback from the Customer to improve the Service without obligation.
12. Confidentiality
Each party keeps the other party's non-public information confidential, uses it only for the purposes of the agreement and protects it with at least reasonable care, for the term of the agreement and five years after. This does not apply to information that is public, independently developed, lawfully received from a third party or required to be disclosed by law, in which case the disclosing party informs the other party where permitted.
13. Warranties, liability and indemnities
13.1. The Provider warrants that it will provide the Service with reasonable skill and care and substantially in accordance with its documentation. Except as expressly stated, the Service is provided without other warranties, and the Provider does not warrant that the agent's output will be accurate, complete or fit for a particular purpose.
13.2. Neither party is liable for indirect or consequential loss, loss of profit, loss of data caused by the other party's failure to export within the export window, or business interruption, except in cases of intent, gross negligence, death or personal injury, or where liability cannot be limited by law.
13.3. Subject to 13.2, each party's total liability under the agreement in any 12-month period is limited to the fees paid or payable by the Customer for the Service in that period.
13.4. The Provider defends the Customer against third-party claims that the Service, as provided by the Provider, infringes that party's intellectual property rights, and pays resulting damages and settlements, provided the Customer notifies the Provider promptly and cooperates. The Customer defends the Provider against claims arising from Customer Data, from the Customer's use of Connected Systems or Model Providers in breach of their terms, or from instructions the Customer gave to the agent.
14. General
14.1. Changes to these Terms. The Provider may update these Terms with at least 30 days' notice by e-mail to the Organisation administrators or a notice in the panel. If a change materially disadvantages the Customer, the Customer may terminate with effect from the date the change takes effect and receives a pro-rata refund of prepaid fees.
14.2. Governing law and disputes. These Terms are governed by the laws of [COUNTRY OF THE PROVIDER'S REGISTERED SEAT], excluding its conflict-of-law rules. The courts of [CITY, COUNTRY] have exclusive jurisdiction, without prejudice to mandatory consumer or public-procurement rules that may apply to the Customer.
14.3. Assignment. Neither party may assign the agreement without the other's consent, except to an affiliate or a successor in a merger or acquisition, with notice.
14.4. Notices are given in writing by e-mail to the addresses in the Order Form; notices to the Provider go to sales@datumos.ai until a legal notices address is published.
14.5. Entire agreement. The Order Form, these Terms, the Data Processing Agreement and the documentation referenced in them form the entire agreement and supersede prior discussions. If a provision is invalid, the rest remains in force.