New: turn your website into today’s ranked growth actions
Legal · Terms

Terms of service

The terms that govern your use of BIU, written for business and professional customers. By creating an account or using the service, you agree to these terms. This page is written in plain language and is not legal advice.

On this page

Effective Date: July 18, 2026

These Terms of Service (the “Terms”) are a binding agreement between TCQ AI, LLC, a Delaware limited liability company doing business as BIU (“BIU,” “we,” “us,” or “our”), and the Customer accepting these Terms (“Customer,” “you,” or “your”). “Customer” means the business, organization, or individual acting solely in a business or professional capacity that accepts these Terms. If no separate business or organization is identified in the Account or Order Form, the accepting individual is Customer.

By clicking an acceptance button, creating or administering an account, executing an Order Form that references these Terms, or accessing or using the Service, you agree to these Terms. The individual accepting these Terms represents that the individual has authority to bind Customer. If the individual lacks that authority, the individual may not accept these Terms or use the Service on Customer's behalf.

1. Business use, eligibility, and agreement structure

1.1 Business and professional use only

The Service is offered solely for business and professional use. It is not offered for personal, family, or household use. Each Authorized User must be at least 18 years old or the age of legal majority where that person resides.

1.2 Contracting entity

The contracting entity is:

TCQ AI, LLC d/b/a BIU
Email: hello@biu.ai

1.3 Components of the Agreement

The “Agreement” consists of:

  1. each Order Form accepted by the parties;
  2. these Terms, including Appendix A, the Data Processing Addendum;
  3. any service-specific terms expressly incorporated by an Order Form; and
  4. policies expressly incorporated by these Terms.

BIU's Privacy Policy describes BIU's privacy practices but is not incorporated as a contractual warranty except to the extent applicable law requires or an Order Form expressly states otherwise.

1.4 Order of precedence

If Agreement documents conflict, the following order controls, unless an Order Form expressly and specifically states that it overrides a named provision:

  1. Appendix A for the processing of Customer Personal Data;
  2. the applicable Order Form;
  3. these Terms; and
  4. other incorporated policies.

A Customer purchase order, vendor portal term, onboarding form, or similar document does not modify the Agreement, even if BIU acknowledges or processes it, unless an authorized BIU representative expressly agrees in a signed writing.

1.5 Changes to these Terms

BIU may update these Terms prospectively. The updated version will state its effective date. We will provide reasonable notice of a material change by email, in-product notice, or another reasonable method. Except where a change is required sooner by law, security, provider requirements, or to prevent abuse, a materially adverse change to a paid subscription will ordinarily take effect at the next renewal. Continued use after the applicable effective date constitutes acceptance to the extent permitted by law. A change will not retroactively alter an accrued claim.

2. Definitions

In the Agreement:

  • “Account” means an account used to access the Service.
  • “Administrator” means an Authorized User whom Customer authorizes to administer an Account or workspace.
  • “API” means an application programming interface, webhook, software development kit, command-line interface, model context protocol interface, or similar developer interface provided by BIU.
  • “Authorized User” means an employee, contractor, agent, or other individual Customer authorizes to use the Service on its behalf.
  • “BIU Technology” means the Service, software, APIs, documentation, interfaces, workflows, designs, methods, models owned by BIU, prompts and orchestration owned by BIU, databases, compilations, know-how, and technology provided by or for BIU, including improvements and derivative works, but excluding Customer Content and third-party components.
  • “Customer Content” means information, files, prompts, instructions, credentials, configuration, code, text, images, data, and other materials submitted to, connected to, transmitted through, or generated within Customer's workspace by or for Customer. Customer Content includes Customer's rights in Output but excludes BIU Technology, Usage Data, and third-party materials.
  • “Customer Data” means Customer Content and other information BIU processes on Customer's behalf to provide the Service.
  • “Customer Personal Data” has the meaning given in Appendix A.
  • “Documentation” means BIU's then-current user documentation for the generally available Service.
  • “Output” means content, code, recommendations, scores, forecasts, drafts, reports, citations, classifications, or other material generated by the Service in response to Customer Content or Customer instructions.
  • “Order Form” means an ordering document, online checkout record, statement of work, or other ordering instrument accepted by BIU that identifies a Service, plan, term, quantity, or fee.
  • “Public Source” means a website, page, repository, search result, public API, public profile, or other source accessible without Customer-provided authentication, subject to applicable law, rights, technical restrictions, and provider terms.
  • “Service” means BIU's hosted software, website, APIs, AI features, agents, integrations, support, and related services identified in an Order Form or made available under an Account.
  • “Subscription Term” means the period during which Customer is entitled to use a paid Service.
  • “Third-Party Service” means a product, model, platform, website, API, data source, or service controlled by a party other than BIU.
  • “Usage Data” means telemetry and technical data about configuration, performance, operation, and use of the Service that does not include Customer Content in intelligible form. Usage Data includes metering, latency, feature-use, error, and security-event data. BIU will not treat personal information as Usage Data merely by relabeling it.

3. The Service and license

3.1 Service functions

BIU is an AI-powered SaaS platform that may provide website and technical analysis, SEO and AI-search visibility tools, content generation, competitor monitoring, analytics, recommendations, workflows, integrations, APIs, and AI agents. Features vary by plan, configuration, geography, provider availability, and release stage.

3.2 License to Customer

Subject to the Agreement and payment of applicable fees, BIU grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable Subscription Term to permit Authorized Users to access and use the Service for Customer's internal business purposes and in accordance with the Documentation.

3.3 No implied rights

BIU and its licensors reserve all rights not expressly granted. No right is granted to obtain source code, model weights, system prompts, private datasets, internal evaluations, security architecture, or other nonpublic BIU Technology.

3.4 Documentation and feature descriptions

Documentation, demonstrations, and descriptions explain intended operation but do not create a warranty or service level unless an Order Form expressly identifies the commitment. Beta, preview, experimental, roadmap, and “coming soon” descriptions are not commitments to deliver a feature, date, performance level, or continued availability. Customer should not rely on future functionality when purchasing the Service.

4. Accounts, administrators, and security responsibilities

4.1 Accurate information

Customer will provide accurate, current account, billing, and organization information and keep it updated.

4.2 Authorized Users

Customer is responsible for Authorized Users and for activity through its Accounts, credentials, API keys, integrations, and configured automations, except to the extent caused by BIU's breach of the Agreement. Customer will ensure that each Authorized User complies with the Agreement.

4.3 Credentials

Customer will:

  • keep credentials, tokens, and API keys confidential;
  • avoid sharing individual credentials among users;
  • use reasonable account-security measures, including available multifactor authentication;
  • promptly remove access for people who no longer require it;
  • limit permissions to those reasonably necessary; and
  • notify BIU without undue delay at hello@biu.ai of suspected unauthorized access, credential compromise, or misuse.

Customer may not transfer, sell, lease, or assign an Account or credential to another person without BIU's written consent.

4.4 Administrator authority

Administrators may add or remove users; assign roles; access, export, restrict, or delete Customer Content; connect integrations; configure agents and workflows; view usage and billing; and otherwise control the workspace. Customer is responsible for selecting Administrators and for their actions.

If an Account uses an organization-controlled email domain, BIU may, after reasonable verification, permit the organization to claim administrative control. An individual using an employer or client workspace should not expect personal control over that workspace or its content.

4.5 Account communications

Customer consents to receive electronic notices relating to the Agreement, security, billing, subscriptions, policy updates, and the Service. Customer will maintain a monitored administrator email address. Marketing choices are governed by the Privacy Policy.

5. Customer Sources, Public Sources, and crawling

5.1 Customer-controlled sources

Customer may direct BIU to access websites, repositories, accounts, systems, files, APIs, and other sources Customer owns or controls (“Customer Sources”). Customer represents and warrants that it has all rights, permissions, notices, legal bases, and authority necessary for BIU to access and process Customer Sources as contemplated by the Agreement.

5.2 Public third-party sources

Customer may configure BIU to analyze Public Sources that Customer does not own, including competitor websites, search results, public repositories, public profiles, citations, and community content. Customer need not own a Public Source merely to request analysis of lawfully accessible material. Customer remains responsible for selecting and using sources in compliance with applicable law, third-party rights, and provider terms.

5.3 Prohibited access methods

Customer will not direct or use BIU to:

  • bypass authentication, paywalls, CAPTCHAs, access controls, or technical restrictions;
  • obtain information through stolen, shared, or unauthorized credentials;
  • access a nonpublic source without authorization;
  • evade an IP block, provider ban, robots rule that BIU elects to honor, rate limit, or source restriction;
  • collect personal information unlawfully or for unlawful surveillance; or
  • impose unreasonable load or disruption on another system.

5.4 BIU discretion concerning sources

BIU may decline, limit, pause, or stop accessing a source where BIU reasonably believes access creates legal, security, operational, reputational, or third-party-platform risk. BIU does not warrant that a source will remain available, that its content is accurate, that a crawl is complete, or that a provider will permit continued access.

5.5 Source content and prompt injection

Public Sources and connected systems are untrusted inputs. They may contain malware, false information, confidential information, personal information, or instructions designed to manipulate an AI system. Customer must review results and maintain safeguards appropriate to the risk. BIU may filter, isolate, ignore, or refuse source content but does not warrant that every malicious or misleading instruction will be detected.

6. Integrations and Third-Party Services

6.1 Authorization

When an Authorized User enables a Third-Party Service, Customer authorizes BIU to access, receive, store, transmit, and act on data within the permissions and scopes displayed in the authorization or setup flow. Customer represents that the user granting access has authority to do so.

6.2 Tokens and permissions

BIU may store access tokens, refresh tokens, webhook secrets, or similar credentials in protected form as needed to maintain the integration. Customer is responsible for reviewing scopes, using least privilege, and revoking access that is no longer required.

Disconnection ordinarily stops future access after the revocation becomes effective but does not automatically remove previously imported data, action logs, security records, or backups. Those materials are handled under the Agreement's retention terms.

6.3 Third-party terms and conduct

Third-Party Services are controlled by third parties and are subject to their own terms, privacy practices, fees, quotas, and technical requirements. BIU does not control and is not responsible for their:

  • availability, security, accuracy, content, or data practices;
  • API, pricing, scope, or policy changes;
  • account suspensions, rate limits, content removals, or enforcement decisions;
  • acts or omissions; or
  • continued compatibility with the Service.

Customer will comply with applicable third-party terms. BIU may modify or discontinue an integration where reasonably necessary because of provider changes, law, security, or commercial feasibility.

6.4 Google services

Customer's use of Google integrations is subject to applicable Google terms and policies. Customer authorizes only the scopes displayed in the Google authorization flow. BIU will use and transfer Google User Data in accordance with the Privacy Policy and applicable Google API Services User Data Policy, including Limited Use requirements where applicable.

6.5 Third-party fees

Customer is responsible for fees charged by Third-Party Services unless an Order Form expressly states otherwise.

7. AI features and Output

7.1 Probabilistic systems

The Service uses probabilistic systems. Output may be inaccurate, incomplete, outdated, biased, offensive, insecure, non-unique, or unsuitable. Output may include fabricated facts, sources, citations, calculations, measurements, forecasts, code, or recommendations and may include or resemble material subject to third-party rights.

7.2 Required human review

Customer must independently review and verify Output before relying on, publishing, deploying, distributing, merging, or acting on it. Review must be proportionate to the potential impact and include, as applicable:

  • checking facts, sources, citations, calculations, and assumptions;
  • reviewing advertising, endorsement, consumer-protection, and platform requirements;
  • confirming copyrights, trademarks, licenses, privacy, publicity, and confidentiality rights;
  • testing code for functionality, licensing, vulnerabilities, secrets, and security effects;
  • reviewing SEO, redirect, schema, robots, canonical, analytics, and site changes;
  • confirming the intended account, destination, audience, timing, and permissions; and
  • obtaining professional advice where appropriate.

7.3 No professional advice

Output is not legal, financial, tax, accounting, medical, employment, cybersecurity, or other regulated professional advice. BIU does not act as Customer's lawyer, fiduciary, financial adviser, security auditor, publisher, or platform representative.

7.4 No outcome guarantee

BIU does not guarantee:

  • search rankings, indexing, traffic, conversions, engagement, citations, or revenue;
  • inclusion, prominence, or accuracy in AI-generated answers;
  • acceptance, publication, distribution, or continued availability of content;
  • the accuracy of attribution, forecasting, competitive analysis, or scoring;
  • that Output is copyrightable, exclusive, or non-infringing; or
  • that recommendations will improve a website, business, campaign, or account.

Scores, forecasts, estimates, recommendations, and attribution reports are directional analytical outputs based on available data, selected assumptions, and model behavior. They are not audited measurements or promises of future performance.

7.5 Similar output

AI systems may produce the same or similar Output for multiple users. Customer receives no exclusivity in an idea, fact, style, method, phrase, or other element that is not independently protectable.

7.6 Model and provider changes

BIU may add, remove, substitute, fine-tune, route among, or change AI models and providers. Model changes may affect style, accuracy, latency, availability, safety behavior, and reproducibility. BIU does not warrant that prior Output can be reproduced.

7.7 High-impact and regulated uses

Customer may not use the Service or Output as the sole or determinative basis for a decision producing legal or similarly significant effects concerning an individual in employment, worker management, housing, education, credit, lending, insurance, healthcare, legal services, essential services, government benefits, law enforcement, immigration, or another high-impact context unless BIU has expressly authorized the use in a signed Order Form and the parties have implemented legally required safeguards.

Customer remains solely responsible for its compliance obligations as a deployer, user, operator, controller, or decision-maker under applicable AI, privacy, discrimination, consumer-protection, employment, accessibility, and sector-specific laws.

7.8 AI disclosure

Customer will provide disclosures or labels required when people interact with an AI system or receive AI-generated or manipulated content, including disclosures concerning synthetic media, endorsements, impersonation, or public-interest communications.

8. Approvals, agents, workflows, and automated actions

8.1 Default approval model

In the Service's default configuration, BIU generally requires an Authorized User to approve an external action before BIU transmits or executes it. Availability and exact behavior vary by feature.

8.2 Optional standing authorization

Certain agent, scheduling, publishing, integration, code, or workflow features may execute actions without item-by-item approval after an Administrator separately enables the feature and configures its scope, credentials, destinations, schedules, rules, limits, and permissions.

Enabling such a feature constitutes Customer's standing instruction and authorization for BIU to act within the configured scope. An action performed within that scope is treated as Customer's action and instruction, subject to BIU's obligations under the Agreement.

8.3 Customer controls and responsibilities

Customer is responsible for:

  • selecting authorized Administrators and destinations;
  • configuring least-privilege permissions, budgets, limits, schedules, and approval rules;
  • reviewing previews, diffs, source material, and action history;
  • maintaining backups and change-control procedures;
  • monitoring automated activity and third-party accounts;
  • promptly disabling an agent, key, or integration that is no longer appropriate; and
  • addressing actions already transmitted to or executed by a Third-Party Service.

8.4 Residual automation risk

Automated actions may be delayed, duplicated, rejected, partially completed, misdirected, or affected by provider behavior, retries, software errors, compromised credentials, malicious source content, or incorrect configuration. Some actions may be difficult or impossible to reverse. No preview, approval, audit log, limit, or technical control eliminates every risk.

8.5 BIU protective controls

BIU may impose limits, require renewed approval, disable an integration or agent, or block an action where reasonably necessary for security, law, provider policy, abuse prevention, or service integrity. Such controls do not transfer Customer's responsibility for its instructions or approved actions to BIU.

8.6 Code actions

Unless an Enterprise Order Form expressly states otherwise, BIU may prepare code, commits, branches, or pull-request drafts but is not authorized to merge directly into a protected production branch. Customer is responsible for code review, testing, backups, deployment controls, and repository permissions.

9. Customer Content and instructions

9.1 Customer responsibility

Customer is responsible for Customer Content, instructions, configurations, approvals, and use of Output. Customer represents and warrants that:

  • it has all rights, permissions, notices, consents, legal bases, and authority necessary for BIU to process Customer Content and follow Customer instructions;
  • Customer Content and instructions do not violate law, third-party rights, or the Agreement;
  • Customer will not submit regulated or highly sensitive information except as expressly authorized in an Order Form; and
  • Customer's use, publication, deployment, and distribution of Output will comply with law and third-party terms.

9.2 License to process Customer Content

Customer grants BIU and its subprocessors a non-exclusive, worldwide license during the applicable retention period to host, copy, transmit, transform, display, and otherwise process Customer Content only to:

  1. provide, support, secure, maintain, and meter the Service;
  2. follow Customer's instructions and enabled configurations;
  3. prevent fraud, abuse, or security threats;
  4. comply with law and enforce the Agreement; and
  5. perform another use expressly authorized by Customer.

This license does not authorize generalized-model training except through a separate affirmative opt-in or signed Order Form.

9.3 Removal and preservation

BIU may remove, quarantine, or restrict Customer Content where BIU reasonably believes it violates the Agreement, law, third-party rights, or provider requirements or creates security or operational risk. BIU may preserve information where required by law or reasonably necessary for an investigation or claim.

9.4 No duty to monitor

BIU may use automated or human measures to investigate abuse, security, or support issues but does not undertake a general duty to monitor, pre-screen, verify, or approve Customer Content or Output.

10. Acceptable Use Policy

Customer will not, and will not permit any person to, use the Service directly or indirectly to do any of the following.

10.1 Illegal or rights-violating conduct

  • Violate applicable law, regulation, court order, sanctions, or export controls.
  • Infringe, misappropriate, or violate intellectual property, privacy, publicity, confidentiality, contractual, consumer, employment, or other rights.
  • Defame, harass, stalk, threaten, dox, exploit, or unlawfully discriminate against a person or group.
  • Collect, infer, expose, or use personal information unlawfully.

10.2 Security abuse

  • Introduce malware, ransomware, spyware, destructive code, or malicious payloads.
  • Phish, steal credentials, impersonate authentication flows, or facilitate unauthorized access.
  • Probe, scan, penetrate, or test the Service or a third-party system without written authorization.
  • Interfere with, overload, disrupt, or degrade the Service or another system.
  • Circumvent authentication, permissions, quotas, rate limits, safety controls, or technical restrictions.
  • Extract or attempt to reveal system prompts, model weights, private datasets, secrets, or nonpublic security information.

10.3 Deceptive content and platform manipulation

  • Send spam or unsolicited communications in violation of law or platform rules.
  • Create or disseminate fake reviews, fabricated testimonials, undisclosed endorsements, astroturfing, deceptive personas, or manipulated engagement.
  • Impersonate a person or organization or falsely suggest affiliation, authorization, or endorsement.
  • Generate or distribute materially deceptive synthetic media without required disclosure.
  • Evade platform enforcement or help another person violate a Third-Party Service's terms.

10.4 Harmful and exploitative content

  • Create, solicit, store, or distribute child sexual abuse material, sexual exploitation, non-consensual intimate imagery, or content that facilitates trafficking or abuse.
  • Facilitate credible threats, violent wrongdoing, self-harm assistance, or illegal weapon or controlled-substance activity.
  • Exploit children or vulnerable persons or use manipulative techniques prohibited by applicable AI law.

10.5 High-impact and surveillance uses

  • Conduct unlawful surveillance, biometric identification, emotion recognition, social scoring, or sensitive-trait profiling.
  • Make or materially assist prohibited or unauthorized high-impact decisions described in Section 7.7.
  • Use the Service for law-enforcement, intelligence, immigration, critical-infrastructure, weapons, or military decision-making without BIU's prior written approval and applicable safeguards.
  • Use Google User Data or other integration data for advertising, creditworthiness, data brokerage, or surveillance in violation of provider policy.

10.6 Competitive and commercial misuse

  • Reverse engineer, decompile, or disassemble the Service except to the limited extent a restriction is prohibited by law.
  • Systematically extract Output, prompts, metadata, or functionality to train, benchmark, or improve a competing model or service.
  • Scrape the Service, create unauthorized datasets, or use automated means to access interfaces not documented for that purpose.
  • Resell, sublicense, timeshare, or provide the Service on a service-bureau basis unless an Order Form expressly permits it.
  • Remove proprietary notices or misrepresent the source of BIU Technology.
  • Publish nonpublic benchmark or security-test results without BIU's written consent.

10.7 Restricted data

Unless a signed Enterprise Order Form expressly permits it, Customer will not submit protected health information, payment-card data, financial-account credentials, government identifiers, biometric templates, precise geolocation, children's data, special-category data, criminal-offense data, export-controlled technical data, or information subject to heightened sector-specific obligations.

10.8 Enforcement

BIU may investigate suspected violations and take proportionate protective action, including blocking content or actions, limiting a feature, revoking a key, suspending access, preserving evidence, or terminating the Agreement. BIU will provide notice where reasonably practicable and legally permitted but may act immediately where delay could create harm or exposure.

11. API and technical-use terms

11.1 API credentials

API keys and tokens are confidential. Customer may use them only for the Account and purposes for which they were issued. Customer will not embed secret keys in publicly distributed code or expose them to unauthorized persons.

11.2 Documentation and limits

Customer will use APIs only as documented and within applicable quotas, rate limits, concurrency limits, payload limits, and usage rules. BIU may use technical controls to enforce limits and may reject or delay requests exceeding them.

11.3 Monitoring and metering

BIU may monitor API use to secure the Service, enforce limits, calculate usage, support Customer, and improve reliability. Usage records generated by BIU's systems control billing absent manifest error.

11.4 Versions and deprecation

BIU may change or discontinue an API version. Where reasonably practicable, BIU will provide advance notice of a material deprecation of a generally available paid API. BIU may act without advance notice for urgent security, legal, provider, or operational reasons.

11.5 No unauthorized caching or redistribution

Customer may cache or redistribute data obtained through the Service only as permitted by the Agreement, Documentation, applicable law, source rights, and Third-Party Service terms.

12. Ownership and intellectual property

12.1 BIU Technology

As between the parties, BIU and its licensors retain all right, title, and interest in BIU Technology, including intellectual property rights. Third-party models, software, data, and open-source components remain subject to their owners' rights and applicable license terms.

12.2 Customer Content

As between the parties, Customer retains the rights it already holds in Customer Content. Submitting, connecting, or analyzing material does not give Customer ownership of a website, public source, third-party content, provider data, or other material Customer does not otherwise own.

12.3 Output

Subject to applicable law, third-party rights, and Customer's compliance with the Agreement, BIU assigns to Customer any right, title, and interest BIU may have in Output generated specifically for Customer. This assignment does not:

  • transfer rights in BIU Technology, prompts, methods, templates, models, or underlying third-party materials;
  • establish that Output is copyrightable, patentable, protectable, exclusive, accurate, or non-infringing;
  • restrict BIU from providing similar functionality or producing similar output for others; or
  • grant rights that BIU does not possess.

12.4 Usage Data and deidentified information

BIU may collect and use Usage Data to operate, secure, support, meter, analyze, and improve the Service. BIU may use deidentified or aggregated information for lawful business purposes if BIU takes reasonable measures designed to prevent association with an individual or Customer and does not attempt to reidentify it.

12.5 Feedback

Customer grants BIU a perpetual, irrevocable, worldwide, transferable, sublicensable, royalty-free right to use and exploit feedback, ideas, and suggestions without restriction or attribution. BIU will not publicly identify Customer as the source without permission.

12.6 Trademarks and publicity

Neither party receives a license to use the other party's names, logos, or trademarks except as necessary to identify the Service in ordinary account administration. BIU will not use Customer's name or logo in public marketing without Customer's prior consent. Customer may accurately state that it uses BIU but may not imply endorsement or partnership.

13. Customer-data training rule

13.1 No generalized training by default

Under the standard Service, BIU will not use Customer Content, prompts, Output, integration data, or Google User Data to train generalized AI models for BIU or a third party. BIU will not authorize its standard model providers to use that information for generalized-model training.

13.2 Optional improvement programs

A customer may opt into a separate improvement or training program only through a distinct affirmative control or signed Order Form that describes the covered data, purpose, recipients, retention, withdrawal method, and effect of withdrawal. A general acceptance of these Terms is not consent to such a program.

13.3 Service evaluation

The restriction above does not prevent BIU from using:

  • deidentified or aggregated Usage Data;
  • synthetic test data;
  • feedback Customer intentionally provides for improvement;
  • data BIU lawfully obtains independently of Customer; or
  • limited Customer Content solely to resolve a specific support request or conduct an evaluation Customer specifically authorizes,

in each case subject to applicable law, confidentiality, the Privacy Policy, and the Agreement and without using that Customer Content for generalized-model training unless Section 13.2 applies.

14. Confidentiality

14.1 Definition

“Confidential Information” means nonpublic information disclosed by or on behalf of a party (“Discloser”) to the other party (“Recipient”) that is identified as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances. Customer Content is Customer Confidential Information. Nonpublic BIU Technology, security information, pricing, product plans, and model or system details are BIU Confidential Information.

14.2 Exclusions

Confidential Information does not include information that Recipient can document:

  • is or becomes public without Recipient's breach;
  • was lawfully known to Recipient without confidentiality restriction before disclosure;
  • is received lawfully from a third party without confidentiality duty; or
  • is independently developed without use of the Confidential Information.

14.3 Protection and use

Recipient will:

  • use Confidential Information only to perform or exercise rights under the Agreement;
  • protect it with at least reasonable care and no less care than Recipient uses for its own similar information;
  • disclose it only to personnel, affiliates, contractors, professional advisers, and subprocessors who need to know it and are bound by confidentiality obligations at least as protective; and
  • remain responsible for those recipients to the extent required by the Agreement.

14.4 Compelled disclosure

Recipient may disclose Confidential Information where required by law if, to the extent legally permitted, Recipient gives prompt notice and reasonable assistance so Discloser may seek protection. Recipient will disclose only the portion legally required.

14.5 Duration and remedies

These duties continue for five years after disclosure. Duties concerning trade secrets continue while the information remains a trade secret under applicable law; duties concerning Customer Personal Data continue for as long as required by Applicable Data Protection Law and Appendix A; and Confidential Information retained after the general period remains protected until it is lawfully deleted or no longer confidential through no breach by Recipient. Unauthorized disclosure may cause irreparable harm for which monetary damages are inadequate; Discloser may seek appropriate injunctive relief without waiving other remedies.

14.6 No residuals license

Recipient receives no right to use information retained in unaided memory to avoid the confidentiality obligations or intellectual-property restrictions in the Agreement.

15. Privacy and data protection

15.1 Privacy Policy

BIU processes personal information as described in the Privacy Policy at /privacy. Customer will provide legally sufficient notices and obtain required consents, authorizations, and legal bases for Customer's collection and use of personal information through the Service.

15.2 Data Processing Addendum

Appendix A applies when BIU processes Customer Personal Data as a processor, service provider, contractor, or data intermediary on Customer's behalf. It is automatically incorporated without a separate signature.

15.3 Customer instructions and regulated data

Customer will not instruct BIU to process personal information in violation of law. Customer is responsible for determining whether the Service is appropriate for its data and use case. Unless an Order Form expressly states otherwise, the Service is not designed to satisfy sector-specific requirements such as HIPAA, GLBA, PCI DSS merchant storage, FERPA, CJIS, ITAR, or equivalent regulated-data regimes.

15.4 Privacy requests

If BIU receives a request concerning Customer Personal Data, BIU may refer the requester to Customer and will assist as required by Appendix A. Customer is responsible for responding as controller or business.

16. Security

16.1 BIU safeguards

BIU maintains administrative, technical, and organizational safeguards reasonably designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Appendix A, Schedule 2 describes baseline measures.

16.2 No absolute security

No system, model, network, transmission, or storage method is completely secure. BIU does not warrant that the Service will be immune from every vulnerability, attack, error, or security incident.

16.3 Customer security duties

Customer will:

  • secure its endpoints, networks, Accounts, credentials, and integrations;
  • configure roles, agents, and permissions appropriately;
  • maintain independent copies of Customer Content appropriate to its risk;
  • promptly install or adopt security updates under its control;
  • review logs and alerts made available by the Service; and
  • notify BIU promptly of suspected unauthorized use.

16.4 Security testing

Customer may not conduct penetration tests, vulnerability scans, red-team exercises, or other security testing against the Service without BIU's prior written authorization and compliance with BIU's testing rules. Good-faith vulnerability reports may be submitted through the method stated at /security.

16.5 System of record and backups

Unless an Order Form expressly states otherwise, the Service is not Customer's sole system of record or backup. Customer is responsible for maintaining independent copies of material data and configuration.

17. Fees, subscriptions, and payment

17.1 Fees

Customer will pay the fees stated at checkout or in an Order Form. Fees are quoted and payable in the stated currency. Except as expressly provided, commitments are non-cancellable during the applicable Subscription Term.

17.2 Billing in advance

Subscription fees are billed in advance at the beginning of each billing period. Usage-based or overage fees, if expressly enabled or stated in an Order Form, may be billed in arrears or as otherwise disclosed.

17.3 Automatic renewal

A paid subscription begins on the date shown at checkout or in the Order Form and continues for the initial monthly, annual, or other selected term. Unless Customer cancels before the end of the then-current term, the subscription automatically renews for successive periods of the same length, and Customer authorizes BIU or its payment processor to charge the then-applicable fees and taxes using the payment method on file.

Before enrollment, BIU will display the recurring price, billing frequency, renewal term, minimum commitment, trial conversion terms, material usage limits, and cancellation method and will obtain affirmative consent required by applicable law.

17.4 Cancellation

Customer may turn off automatic renewal through the account billing settings (Settings → Billing → Manage billing, which opens the Stripe customer portal) or another method BIU is legally required to provide. For a subscription purchased online, BIU will provide an online cancellation method that is reasonably accessible without unnecessary steps.

Cancellation takes effect at the end of the then-current paid term unless the Order Form or applicable law states otherwise. Customer remains able to use the paid Service through that date, subject to the Agreement. BIU will provide a retainable cancellation confirmation.

Closing an Account, deleting an application, revoking an integration, stopping use, or sending an informal message does not by itself cancel a subscription unless BIU confirms cancellation, the available cancellation flow records it, or applicable law requires the request to be treated as effective.

17.5 Trials and promotions

If a trial or promotional period converts to a paid subscription, checkout will disclose the trial or promotion length, conversion date, post-conversion price, billing frequency, and cancellation deadline before enrollment. Customer authorizes the post-trial charge only through the affirmative consent captured at checkout.

Customer must cancel before the stated deadline to avoid the next charge. BIU may limit eligibility, end a trial, or restrict repeat trials. Required reminders will be sent where applicable.

17.6 Renewals and reminders

BIU will send renewal, annual, long-term, trial, promotional, material-change, and price-change notices where required by applicable law or an Order Form. Customer is responsible for maintaining a valid administrator email address and reviewing notices.

17.7 Price changes

BIU may change fees prospectively. A price change will not apply retroactively to a prepaid period. BIU will provide notice required by law and, for an ordinary paid self-service subscription, will generally apply a material price increase at the next renewal. Customer may cancel before the increase becomes effective.

17.8 Upgrades and downgrades

An upgrade may take effect immediately and may result in a prorated charge or reset usage entitlements as disclosed in the interface. A downgrade ordinarily takes effect at the next renewal and may reduce features, limits, storage, or retention. Customer is responsible for exporting data or changing configuration before a downgrade causes loss of access.

17.9 Payment authorization and processor

Customer authorizes BIU and its payment processor to charge the payment method on file for fees, usage charges expressly authorized, taxes, and other amounts due. The payment processor may receive and process billing information under its own terms and privacy notice. BIU ordinarily does not store full payment-card numbers.

17.10 Failed payments

If a payment fails or is overdue, BIU may retry the charge, request another payment method, suspend or downgrade access after reasonable notice, and recover reasonable collection costs to the extent permitted by law. Customer remains responsible for undisputed amounts.

17.11 Billing disputes

Customer must notify BIU of a good-faith billing dispute within 30 days after the charge or invoice, with reasonable detail. Customer will pay undisputed amounts when due. A chargeback does not resolve the underlying payment obligation and may result in suspension while investigated.

17.12 Refunds

Except where an Order Form, an express refund offer, or applicable law provides otherwise, fees are non-refundable and non-creditable, including for partial periods, unused features, unused credits, downgrades, suspension based on Customer conduct, or termination by Customer before the end of a committed term.

Nothing in this section limits a mandatory statutory refund, withdrawal right, or remedy that cannot lawfully be waived. BIU's voluntary issuance of a refund or credit in one instance does not create an obligation in another.

17.13 Taxes

Fees exclude sales, use, value-added, goods-and-services, withholding, and similar taxes, duties, and assessments, except taxes based on BIU's net income. Customer is responsible for applicable taxes and will provide a valid exemption certificate where relevant. If Customer must withhold tax, Customer will provide documentation and, unless prohibited by law or an Order Form, gross up payment so BIU receives the amount it would have received without withholding.

17.14 No setoff

Customer may not set off or withhold amounts due except where law prohibits this restriction.

18. Credits, usage limits, and fair use

18.1 Credits

A plan may include credits or other usage entitlements. Credits are contractual service entitlements, not money, deposits, securities, gift cards, or stored value. They have no cash value, are non-transferable, and may be used only within the issuing Account.

18.2 Consumption

The pricing page, checkout, Documentation, or in-product meter identifies the actions that consume credits and the amount or method of consumption. Different models, skills, agents, crawls, reports, API calls, or resource-intensive operations may consume different amounts.

18.3 Expiration and rollover

Unless the applicable plan expressly states otherwise, monthly credits expire at the end of the billing cycle and do not roll over. Annual or promotional credits expire as stated when issued. Expired or unused credits are not refundable except where required by law.

18.4 Usage measurement

BIU's metering systems control usage calculation absent manifest error. Usage displays may be delayed and are informational. Customer is responsible for monitoring consumption and configuring available limits.

18.5 Overage

BIU will not impose a separately priced overage unless the plan, Order Form, or an authorized Administrator expressly enables or accepts it. Otherwise, BIU may pause or limit the affected feature when entitlements are exhausted.

18.6 Fair use and protective limits

BIU may apply reasonable limits to prevent abuse, excessive load, credential sharing, denial of service, or use materially inconsistent with the purchased plan. BIU will not use an undisclosed “fair use” limit to retroactively impose a fee. Material recurring limits will be disclosed in the plan or Documentation.

19. Free, beta, preview, and evaluation services

A free, trial, beta, preview, experimental, or evaluation feature (“Preview Service”) may be incomplete, change materially, contain defects, or lack some redundancy, assurance, or support features available for a generally available Service, and may be discontinued at any time. Preview Services are provided for evaluation and testing, not production-critical use, and are not subject to an SLA, service credit, support commitment, warranty, or indemnity unless an Order Form expressly states otherwise. Appendix A continues to apply to Customer Personal Data processed through a Preview Service.

Customer will not submit highly sensitive or production-critical information to a Preview Service unless BIU expressly authorizes it. BIU may delete Preview Service data after reasonable notice or when the preview ends. To the maximum extent permitted by law, BIU's aggregate liability for all Preview Services is included within, and does not increase, the liability cap in Section 27.

20. Support, availability, and changes

20.1 Support

BIU will provide the support, if any, identified in the applicable plan or Order Form. Target response times are goals unless expressly identified as binding in an Order Form.

20.2 No default SLA

Unless an Order Form expressly includes a service level agreement, the Service is not subject to a guaranteed uptime, response time, recovery time, recovery point, resolution time, or service credit.

20.3 Maintenance and interruptions

The Service may be unavailable because of maintenance, updates, capacity, security events, Third-Party Services, utility or internet failures, or events outside BIU's reasonable control. BIU may perform emergency maintenance without advance notice.

20.4 Status information

BIU does not currently offer a public status page. Any operational or status information BIU chooses to provide is for convenience only and is not an SLA or an admission of cause or liability.

20.5 Feature changes and discontinuation

BIU may modify, replace, limit, or discontinue features, models, APIs, integrations, plans, or Documentation. Where reasonably practicable, BIU will provide advance notice of a material discontinuation of a generally available paid feature during a current term. BIU may act immediately for security, legal, provider, abuse, or operational reasons.

If BIU permanently discontinues the core paid Service during a prepaid term for reasons other than Customer breach or an event outside BIU's reasonable control, Customer's exclusive remedy is a prorated refund of prepaid unused fees for the discontinued core Service.

21. Suspension

21.1 Grounds

BIU may limit or suspend access where reasonably necessary to address:

  • overdue undisputed amounts;
  • suspected unauthorized access or credential compromise;
  • a security, legal, or operational threat;
  • a violation of Section 10 or another material Agreement term;
  • a Third-Party Service restriction;
  • unusually excessive use creating service risk; or
  • a lawful request or regulatory obligation.

21.2 Scope and notice

BIU will use reasonable efforts to limit suspension to the affected Account, user, integration, action, or feature where practicable. BIU will provide notice and an opportunity to cure where reasonably practicable and legally permitted but may act immediately where delay could create harm or exposure.

21.3 Effect

Suspension does not relieve Customer of payment obligations for a committed term unless the suspension is caused solely by BIU's uncured material breach. BIU will restore access after the basis is resolved, subject to law, security, provider restrictions, and payment of amounts due.

22. Term and termination

22.1 Term

These Terms begin when Customer first accepts them and continue while Customer has an Account or an Order Form remains in effect.

22.2 Termination for breach

Either party may terminate the affected Agreement for a material breach if the breach remains uncured 30 days after written notice. A party may terminate immediately for a breach incapable of cure, unlawful conduct, insolvency to the extent permitted by law, or an urgent security or rights violation.

22.3 Free Accounts

BIU may terminate a free, inactive, or Preview Service on reasonable notice, or immediately for breach, law, security, or abandonment. BIU may define and enforce an inactivity period disclosed in the Service or Documentation.

22.4 Effect of termination

On expiration or termination:

  • Customer's right to use the affected Service ends;
  • Customer must stop using BIU Technology and delete locally held confidential BIU materials;
  • accrued payment obligations remain due;
  • enabled agents and integrations may be disabled; and
  • each party remains responsible for actions and content transmitted before termination.

22.5 Export period

Unless an Order Form states otherwise, Customer may use available export tools for 30 days after expiration or termination, provided access is not prohibited by law, an urgent security risk, or unresolved unauthorized activity. BIU may condition export of business records on payment of undisputed overdue fees but will not condition an individual's non-waivable privacy rights on payment.

22.6 Deletion

After the export period, BIU may delete Customer Content from active systems. Protected backups may retain residual copies for up to 90 additional days before ordinary rotation removes them. BIU may retain limited records as required for security, fraud prevention, legal compliance, billing, claims, and enforcement. Appendix A governs Customer Personal Data.

22.7 Survival

Sections concerning payment, ownership, confidentiality, restrictions, disclaimers, indemnification, liability, disputes, general terms, accrued rights, and any provision that by its nature should survive will survive expiration or termination.

23. Customer warranties

Customer represents and warrants that:

  1. it has the legal capacity and authority to enter into the Agreement;
  2. the accepting individual has authority to bind it;
  3. it has rights and permissions required for Customer Content, Customer Sources, integrations, instructions, and external actions;
  4. its use of the Service will comply with law, the Agreement, and Third-Party Service terms; and
  5. it will not make a representation about the Service or Output that is false, misleading, or inconsistent with BIU's Documentation.

24. Warranty disclaimer

TO THE MAXIMUM EXTENT PERMITTED BY LAW, EXCEPT FOR AN EXPRESS WARRANTY IN AN ORDER FORM:

  1. THE SERVICE, OUTPUT, BIU TECHNOLOGY, PREVIEW SERVICES, DOCUMENTATION, AND THIRD-PARTY SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE”;
  2. BIU AND ITS LICENSORS DISCLAIM ALL EXPRESS, IMPLIED, AND STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, QUIET ENJOYMENT, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE;
  3. BIU DOES NOT WARRANT THAT THE SERVICE OR OUTPUT WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, ACCURATE, COMPLETE, CURRENT, COMPATIBLE, OR SUITABLE FOR CUSTOMER'S PURPOSE, OR THAT DEFECTS, SECURITY EVENTS, OR DATA LOSS WILL BE PREVENTED OR CORRECTED;
  4. BIU DOES NOT WARRANT THIRD-PARTY SERVICES, PUBLIC SOURCES, MODEL PROVIDERS, SEARCH ENGINES, EXTERNAL PLATFORMS, OR THEIR ACTS, DATA, OR DECISIONS; AND
  5. CUSTOMER ASSUMES THE RISK OF RELYING ON, PUBLISHING, DEPLOYING, OR ACTING ON OUTPUT.

Nothing in the Agreement excludes a warranty or remedy that applicable law does not permit the parties to exclude.

25. Customer indemnification

25.1 Covered claims

To the extent permitted by law, Customer will defend, indemnify, and hold harmless BIU, its affiliates, and their respective members, managers, directors, officers, employees, contractors, agents, licensors, and service providers (“BIU Indemnified Parties”) from and against any third-party claim, demand, investigation, action, proceeding, damage, judgment, settlement, penalty, fine, cost, and reasonable legal fee arising out of or relating to:

  • Customer Content, Customer Sources, or Customer instructions;
  • Customer's or an Authorized User's use, approval, publication, deployment, or distribution of Output;
  • Customer's websites, products, services, campaigns, code, repositories, or external actions;
  • Customer's connected accounts, credentials, integrations, agents, or automation configuration;
  • Customer's violation of law, third-party rights, Third-Party Service terms, or Section 10;
  • a representation Customer makes about BIU or Output; or
  • Customer's material breach of the Agreement.

25.2 Procedure

BIU will provide reasonably prompt notice of a covered claim and reasonable cooperation at Customer's expense. Failure to provide prompt notice relieves Customer only to the extent materially prejudiced. Customer may control the defense with counsel reasonably acceptable to BIU, but may not settle a claim in a manner that:

  • admits fault or liability by a BIU Indemnified Party;
  • imposes a non-monetary obligation on a BIU Indemnified Party;
  • requires payment by a BIU Indemnified Party; or
  • fails to provide a complete release,

without BIU's prior written consent. BIU may participate with its own counsel at its own expense.

25.3 BIU indemnity

The public self-service Service does not include an indemnity from BIU. Any BIU intellectual-property or other indemnity must be expressly stated in a signed Enterprise Order Form and is subject to its exclusions, procedures, remedies, and liability limits.

26. Exclusion of damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, BIU AND ITS AFFILIATES, LICENSORS, AND SERVICE PROVIDERS WILL NOT BE LIABLE FOR:

  • INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES;
  • LOSS OF PROFITS, REVENUE, BUSINESS, OPPORTUNITY, ANTICIPATED SAVINGS, OR GOODWILL;
  • LOSS, CORRUPTION, OR INABILITY TO USE DATA;
  • COST OF SUBSTITUTE SERVICES;
  • THIRD-PARTY PLATFORM ACTIONS;
  • SEARCH, TRAFFIC, CITATION, ENGAGEMENT, OR REVENUE OUTCOMES; OR
  • UNAUTHORIZED OR UNINTENDED EXTERNAL ACTIONS RESULTING FROM CUSTOMER CONFIGURATION, APPROVAL, CREDENTIALS, OR THIRD-PARTY CONDUCT,

IN EACH CASE ARISING OUT OF OR RELATING TO THE AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY AND REGARDLESS OF THE THEORY OF LIABILITY.

27. Limitation of liability

27.1 Aggregate cap

TO THE MAXIMUM EXTENT PERMITTED BY LAW, BIU'S AND ITS AFFILIATES', LICENSORS', AND SERVICE PROVIDERS' TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE AFFECTED SERVICE DURING THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY.

IF CUSTOMER USED ONLY A FREE OR PREVIEW SERVICE, THE TOTAL AGGREGATE LIABILITY WILL NOT EXCEED US$100.

MULTIPLE CLAIMS, EVENTS, ACCOUNTS, OR THEORIES WILL NOT INCREASE THE CAP.

27.2 Scope

The exclusions and cap apply to contract, tort, negligence, strict liability, statutory claims, misrepresentation, restitution, and every other theory, and apply even if a limited remedy fails of its essential purpose.

27.3 Customer obligations

The limitations in Sections 26 and 27 do not limit Customer's payment obligations, Customer's indemnification obligations, or liability arising from Customer's infringement or misappropriation of BIU's intellectual property, breach of Section 10, or unauthorized use or disclosure of BIU Confidential Information.

27.4 Non-excludable liability

Nothing excludes or limits liability to the extent it cannot lawfully be excluded or limited. Any non-excludable liability is limited to the minimum extent permitted by law.

27.5 Time to bring claims

To the extent permitted by law, a claim arising out of or relating to the Agreement must be filed within one year after the claim accrued, except a claim for unpaid fees, infringement or misappropriation of intellectual property, breach of confidentiality, indemnification, or a claim subject to a non-waivable statutory period.

27.6 Basis of bargain

The parties agree that the fees reflect the allocation of risk in the Agreement and that BIU would not provide the Service on the same economic terms without these limitations.

27.7 Non-recourse

Customer agrees that BIU's obligations are solely corporate obligations of TCQ AI, LLC. To the maximum extent permitted by law, no member, manager, officer, director, employee, contractor, investor, affiliate, or service provider of BIU has personal liability for an obligation or claim arising out of the Agreement solely by reason of that status. This Section does not limit liability that applicable law imposes directly on a person for that person's own fraud, willful misconduct, or other non-waivable conduct.

28. Compliance, export controls, and sanctions

Customer will comply with applicable anti-bribery, anti-corruption, export-control, import, and sanctions laws. Customer represents that it is not, and is not owned or controlled by, a sanctioned person and is not located in or ordinarily resident in a territory where provision of the Service is prohibited.

Customer will not use the Service for a prohibited end use or permit access by a prohibited person. BIU may screen Accounts and suspend or terminate access where reasonably necessary to comply with law or provider obligations.

Customer is responsible for industry-specific, professional, accessibility, advertising, records-management, and regulatory obligations applicable to its business and use of Output.

29. Intellectual-property complaints

29.1 Complaints

A person who believes material available through the Service infringes intellectual property may send a detailed notice to:

Email: hello@biu.ai

The notice should identify the protected work, the allegedly infringing material and its location, contact information, a good-faith statement, a statement under penalty of perjury concerning accuracy and authority, and a physical or electronic signature.

29.2 Response

BIU may remove or restrict material, notify the affected customer, request additional information, and terminate repeat infringers in appropriate circumstances. BIU may process a valid counter-notice as permitted by applicable law.

29.3 No false claims

A person submitting a complaint or counter-notice is responsible for material misrepresentations and should obtain legal advice before submitting one.

30. Governing law and disputes

30.1 Informal resolution

Before filing a claim, each party will give the other written notice describing the dispute and requested relief and will attempt in good faith to resolve it for 30 days. This requirement does not prevent a party from seeking emergency injunctive relief or filing to preserve a limitation period.

30.2 Governing law

The Agreement is governed by the laws of the State of Delaware, without regard to conflicts-of-law principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

30.3 Exclusive courts

Except for a claim seeking emergency injunctive relief in another court of competent jurisdiction, each party irrevocably submits to the exclusive jurisdiction and venue of the state and federal courts located in Delaware for a dispute arising out of or relating to the Agreement.

30.4 Jury-trial waiver

TO THE EXTENT PERMITTED BY LAW, EACH PARTY KNOWINGLY AND IRREVOCABLY WAIVES TRIAL BY JURY IN AN ACTION ARISING OUT OF OR RELATING TO THE AGREEMENT.

30.5 Class and representative actions

TO THE EXTENT PERMITTED BY LAW, EACH PARTY MAY BRING A CLAIM ONLY IN ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, OR REPRESENTATIVE IN A PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION.

30.6 Mandatory rights

Nothing in this section deprives a party of a protection, remedy, or forum that applicable law prohibits the party from waiving. Because the Service is business-only, Customer represents that it is not accepting the Agreement as a consumer.

31. General terms

31.1 Assignment

Customer may not assign or transfer the Agreement, by operation of law or otherwise, without BIU's prior written consent. BIU may assign the Agreement to an affiliate or in connection with a merger, financing, reorganization, change of control, or sale of all or substantially all assets relating to the Service. An unauthorized assignment is void.

31.2 Force majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, war, terrorism, civil unrest, labor disruption, epidemic, government action, utility or telecommunications failure, internet disruption, cyberattack by a third party, cloud or provider outage, or shortage of critical resources. This section does not excuse payment obligations for Services already provided or fees already due.

31.3 Notices

Legal notices to BIU must be sent by email to hello@biu.ai. If BIU has provided a mailing address for legal notice on request or in an Order Form, notices may also be sent by nationally recognized courier or certified mail to TCQ AI, LLC, Attn: Legal, at that address. BIU may send notices to the Administrator email, through the Service, or to an Order Form contact. Notice is effective on confirmed delivery, except an in-product or email notice concerning ordinary Service administration is effective when sent.

31.4 Independent contractors

The parties are independent contractors. The Agreement does not create an agency, partnership, joint venture, fiduciary, employment, franchise, or exclusive relationship. Customer's authorization for BIU to perform configured actions does not make BIU Customer's general agent.

31.5 Third-party beneficiaries

Except for BIU Indemnified Parties and BIU's licensors and service providers concerning provisions that expressly protect them, the Agreement has no third-party beneficiaries.

31.6 No waiver

A waiver must be in writing and signed by the waiving party. Failure or delay in exercising a right is not a waiver.

31.7 Severability and reformation

If a provision is unenforceable, it will be enforced to the maximum lawful extent and modified only as necessary to make it enforceable, while the remaining provisions remain in effect.

31.8 Entire agreement and reliance

The Agreement is the entire agreement concerning its subject and supersedes prior or contemporaneous proposals, communications, and agreements. Customer acknowledges that it has not relied on a statement, promise, forecast, or representation not expressly included in the Agreement.

31.9 Headings and interpretation

Headings are for convenience. “Including” means “including without limitation.” The singular includes the plural. A reference to “written” or “writing” includes electronic form unless a signature is expressly required. The Agreement will not be construed against a party merely because that party drafted it.

31.10 English language

The English version controls to the extent permitted by law. A translation is provided for convenience unless mandatory law requires otherwise.

31.11 United States government users

The Service is commercial computer software and commercial computer software documentation developed exclusively at private expense. United States government use is subject to the rights customarily provided to the public under the Agreement and applicable procurement law.

31.12 Contact

Questions about these Terms may be sent to hello@biu.ai.


Appendix A — Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Agreement between Customer and BIU when BIU processes Customer Personal Data on Customer's behalf. It is effective on the later of the Agreement's effective date or the date BIU first processes Customer Personal Data.

A1. Definitions

For this DPA:

  • “Applicable Data Protection Law” means a law applicable to BIU's processing of Customer Personal Data under the Agreement, including, as applicable, the GDPR, UK GDPR, United Kingdom Data Protection Act 2018 as amended, California Consumer Privacy Act, Canadian private-sector privacy law, Australian Privacy Act, Singapore Personal Data Protection Act, and successor or implementing law.
  • “Controller” includes a “business,” organization, or other entity that determines the purposes and means of processing.
  • “Customer Personal Data” means personal data, personal information, or equivalent regulated information contained in Customer Data that BIU processes on Customer's behalf as a Processor under the Agreement. It excludes information BIU processes as an independent Controller for account administration, billing, security, legal compliance, and BIU's own business operations as described in the Privacy Policy.
  • “Data Subject” means an identified or identifiable individual to whom Customer Personal Data relates.
  • “EEA” means the European Economic Area.
  • “GDPR” means Regulation (EU) 2016/679.
  • “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in BIU's possession or control. It does not include unsuccessful attempts or incidents that do not affect Customer Personal Data.
  • “Process,” “Processing,” “Controller,” “Processor,” and “Supervisory Authority” have the meanings under applicable law.
  • “Restricted Transfer” means a transfer of personal data requiring a transfer mechanism under the GDPR, UK GDPR, or applicable Swiss law.
  • “SCCs” means the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914.
  • “Subprocessor” means a third party engaged by BIU to process Customer Personal Data on Customer's behalf.
  • “UK Addendum” means the then-current International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner's Office.
  • “UK GDPR” has the meaning under United Kingdom data-protection law.

A2. Scope and roles

A2.1 Roles

Customer is the Controller of Customer Personal Data or, where Customer acts for another Controller, a Processor authorized to appoint BIU as a Subprocessor. BIU is a Processor or Subprocessor, as applicable.

The parties acknowledge that BIU independently determines purposes and means for limited Controller processing described in the Privacy Policy, including account administration, billing, security, legal compliance, and business operations. This DPA does not convert that independent processing into Processor activity.

A2.2 Processing details

The subject matter, duration, nature, purpose, data categories, and Data Subject categories are described in Schedule 1 and the applicable Order Form.

A2.3 Customer authority

Customer represents that it has authority to provide instructions and Customer Personal Data to BIU and that its instructions comply with Applicable Data Protection Law. If Customer is a Processor, Customer represents that the relevant Controller authorized BIU's appointment and the instructions.

A3. Documented instructions

A3.1 Instructions

BIU will process Customer Personal Data only:

  1. to provide, support, secure, and operate the Service;
  2. as configured or instructed by Customer through the Service, APIs, support requests, or an Order Form;
  3. as stated in this DPA; or
  4. as required by applicable law.

The Agreement, Customer's use and configuration, and written support instructions constitute Customer's documented instructions.

A3.2 Legally required processing

If law requires BIU to process Customer Personal Data beyond Customer's instructions, BIU will inform Customer before processing unless law prohibits notice.

A3.3 Unlawful instructions

BIU will inform Customer if BIU reasonably believes an instruction infringes Applicable Data Protection Law and may suspend the affected processing until the parties resolve the issue. BIU is not required to provide legal advice or independently audit Customer's compliance.

A4. Customer obligations

Customer will:

  • comply with Applicable Data Protection Law as Controller or Processor;
  • provide legally sufficient notices and establish a valid legal basis;
  • obtain required consents and authorizations;
  • respond to Data Subjects and regulators;
  • configure the Service consistent with data minimization, retention, access, and security requirements;
  • avoid submitting restricted or special-category data unless expressly authorized; and
  • ensure its instructions do not cause BIU to violate law or third-party rights.

A5. Confidentiality and personnel

BIU will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty and receive privacy and security training appropriate to their roles. BIU will limit access to persons who need it for permitted processing.

A6. Security

A6.1 Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing and risk to individuals, BIU will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. Baseline measures are described in Schedule 2.

A6.2 Changes

BIU may update security measures provided the update does not materially reduce the overall protection of Customer Personal Data during a paid Subscription Term.

A6.3 Customer responsibilities

Customer acknowledges that security is shared. Customer is responsible for its systems, endpoints, credentials, user access, configurations, integrations, backups, and use of available security controls.

A7. Personal Data Breaches

A7.1 Notice

BIU will notify Customer without undue delay after becoming aware that a Personal Data Breach affecting Customer Personal Data has occurred. Notice will be sent to the Administrator or security contact associated with the Account unless Customer designates another contact.

A7.2 Information

To the extent information is reasonably available, BIU's notice will describe:

  • the nature of the breach;
  • categories and approximate volume of affected Data Subjects and records;
  • likely consequences;
  • measures taken or proposed to address and mitigate it; and
  • a contact for follow-up.

BIU may provide information in phases. Notice is not an admission of fault or liability.

A7.3 Cooperation

BIU will take reasonable steps to contain, investigate, and mitigate a Personal Data Breach and will reasonably assist Customer with legally required notifications, considering the nature of processing and information available. Customer is responsible for determining whether and how to notify regulators, Data Subjects, customers, or others unless law places that duty directly on BIU.

A7.4 Unsuccessful events

BIU is not required to notify Customer of unsuccessful attacks, pings, scans, blocked login attempts, or similar events that do not result in a Personal Data Breach, unless an Order Form expressly states otherwise.

A8. Subprocessors

A8.1 General authorization

Customer gives BIU general written authorization to engage Subprocessors. BIU's current list is available on request by emailing hello@biu.ai and identifies each Subprocessor's function and processing location.

A8.2 Flow-down terms

BIU will enter a written agreement with each Subprocessor imposing, in substance, the same data-protection obligations required of BIU for the relevant processing, including applicable confidentiality, security, deletion, and third-party-beneficiary protections required by the SCCs. BIU remains responsible for its Subprocessors' performance to the extent required by Applicable Data Protection Law and the Agreement.

A8.3 Changes and notice

BIU will provide at least 15 days' advance notice of a new Subprocessor through the Subprocessor List subscription mechanism or another reasonable method, except where urgent replacement is necessary for security, legal, or service-continuity reasons. In an urgent case, BIU will provide notice as soon as reasonably practicable.

A8.4 Objection

Customer may object to a new Subprocessor within the notice period by sending a detailed, reasonable data-protection objection to hello@biu.ai. The parties will work in good faith to address the concern. If BIU cannot provide a commercially reasonable alternative and the objection is based on a demonstrable data-protection risk, Customer may terminate the affected Service before the Subprocessor begins processing and receive a prorated refund of prepaid unused fees for that affected Service. This is Customer's sole remedy for the objection.

A9. Data Subject requests

A9.1 Referral

If BIU receives a request from a Data Subject concerning Customer Personal Data, BIU will ordinarily direct the person to Customer and will not respond substantively except on Customer's documented instruction or as required by law.

A9.2 Assistance

Taking into account the nature of processing, BIU will provide reasonable technical and organizational assistance to help Customer respond to requests for access, correction, deletion, restriction, objection, portability, or information concerning automated processing.

A9.3 Costs

Ordinary self-service tools and reasonable assistance are included in the Service. BIU may charge reasonable fees for unusually burdensome, repetitive, or customized assistance to the extent permitted by law, after providing an estimate.

A10. Compliance assistance

Taking into account the nature of processing and information available, BIU will reasonably assist Customer with:

  • security obligations;
  • Personal Data Breach assessments and notices;
  • data-protection impact assessments;
  • prior consultation with a regulator; and
  • information reasonably necessary to demonstrate BIU's compliance with this DPA.

Customer remains responsible for its own assessments, records, legal conclusions, and regulator communications.

A11. Return and deletion

A11.1 During the term

Customer may access, export, or delete Customer Personal Data using available Service features. Customer is responsible for exporting needed data before termination.

A11.2 End of processing

At the end of the applicable Service, BIU will, at Customer's choice expressed through available controls or written instruction, return or delete Customer Personal Data, unless law requires retention. If Customer gives no contrary instruction, BIU will follow the deletion periods in Section 22.6.

Residual copies may remain in protected backups for up to 90 days after deletion from active systems and will remain protected and unavailable for ordinary use. BIU may retain limited information required by law, security, fraud prevention, billing, or legal claims and will process it only for those purposes.

A12. Audits and information

A12.1 Standard evidence

On reasonable request and subject to confidentiality, BIU will make available information reasonably necessary to demonstrate compliance, which may include current independent audit reports, certifications, penetration-test summaries, security documentation, or questionnaire responses available for the relevant Service.

A12.2 Additional audit

If standard evidence is insufficient to satisfy a requirement under Applicable Data Protection Law, Customer may request an audit no more than once in a 12-month period, except after a Personal Data Breach or regulator request. The audit must:

  • be conducted by an independent qualified auditor;
  • occur on reasonable advance notice during normal business hours;
  • avoid access to other customers' data, BIU trade secrets, or information that would create security risk;
  • comply with BIU's reasonable security and confidentiality rules;
  • not unreasonably disrupt operations; and
  • be at Customer's expense unless the audit identifies a material uncured breach by BIU.

The parties will first attempt to satisfy the request through remote review. BIU may require the auditor to sign a nondisclosure agreement and may object reasonably to a competitor as auditor.

A12.3 Regulator audits

Nothing restricts a Supervisory Authority's lawful powers.

A13. International transfers

A13.1 General

BIU may process Customer Personal Data in the United States and other countries identified in the Subprocessor List. BIU will use a lawful transfer mechanism where Applicable Data Protection Law requires one.

A13.2 EEA SCCs

For a Restricted Transfer subject to the GDPR from Customer to BIU, the SCCs are incorporated by reference and completed as follows:

  1. Module Two applies where Customer is a Controller and BIU is a Processor.
  2. Module Three applies where Customer is a Processor and BIU is a Subprocessor.
  3. Clause 7, the docking clause, applies.
  4. For Clause 9, Option 2 applies and the notice period is the period stated in Section A8.3.
  5. The optional language in Clause 11 does not apply.
  6. For Clause 17, Option 1 applies and the governing law is the law of Ireland.
  7. Under Clause 18, the courts of Ireland have jurisdiction.
  8. Annexes I through III are completed by Schedules 1 through 3 of this DPA, the applicable Order Form, and the Subprocessor List.
  9. If and to the extent a competent authority requires another EU Member State's law or courts for enforceability, that qualifying law and forum will apply to the minimum extent necessary.

A13.3 United Kingdom transfers

For a Restricted Transfer subject to the UK GDPR, the United Kingdom International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, template B.1.0 in force 21 March 2022, is incorporated and completed as follows:

  1. Table 1: The parties, addresses, roles, and key contacts are those stated in the Agreement, the applicable Order Form, and Schedule 3. The Addendum's start date is the date the relevant Restricted Transfer begins. The parties' electronic acceptance of the Agreement constitutes signature to the extent legally effective.
  2. Table 2: Modules Two and Three apply as specified in Section A13.2; Clause 7 applies; Clause 11 does not apply; Clause 9 uses general written authorization with the notice period in Section A8.3; and the remaining selections are those in Section A13.2.
  3. Table 3: The Appendix Information is in Schedules 1 through 3, the applicable Order Form, and the Subprocessor List.
  4. Table 4: Neither Party may end the Addendum under Section 19 solely because the ICO issues a revised Approved Addendum.
  5. The following Alternative Part 2 Mandatory Clauses are incorporated by reference: “Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.”

If the ICO replaces or revises the approved Addendum, the incorporated Addendum will update as its mandatory clauses provide. The parties will cooperate to complete or amend information reasonably necessary to preserve a lawful transfer mechanism.

A13.4 Switzerland

For a Restricted Transfer subject to Swiss data-protection law, references in the SCCs to the GDPR and EU will be interpreted to include applicable Swiss law and Switzerland; references to a Supervisory Authority will mean the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may enforce rights under the SCCs as applicable. The SCCs' governing law and forum will be interpreted to preserve enforceability under Swiss law.

A13.5 Alternative mechanisms

If BIU or a Subprocessor is validly certified under an applicable adequacy or transfer framework and the certification covers the processing, BIU may rely on that mechanism. If a mechanism becomes invalid or unavailable, the parties will cooperate to implement another lawful mechanism. The SCCs or UK Addendum prevail for the Restricted Transfer to the extent required.

A13.6 Transfer assessments

On reasonable request, BIU will provide information reasonably available to assist Customer with a transfer impact or similar assessment, subject to confidentiality, legal restrictions, and security limitations.

A14. United States service-provider and contractor terms

Where the California Consumer Privacy Act or a similar United States law applies and BIU acts as a service provider, contractor, or processor, BIU will:

  1. process Customer Personal Data only for the limited and specified business purposes in the Agreement and Customer's documented instructions;
  2. not sell or share Customer Personal Data;
  3. not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the permitted purposes;
  4. not combine Customer Personal Data with personal information received from another person or collected from BIU's own interaction with an individual except as permitted by applicable law;
  5. provide the same level of privacy protection required of service providers or contractors under applicable law;
  6. notify Customer if BIU determines it can no longer meet an applicable obligation;
  7. permit Customer to take reasonable and appropriate steps to help ensure compliant use, consistent with Section A12; and
  8. cooperate with reasonable steps to stop and remediate unauthorized use.

Customer discloses Customer Personal Data to BIU only for the limited and specified purposes in the Agreement and not in exchange for money or other valuable consideration.

A15. Canada, Australia, Singapore, and other jurisdictions

Where applicable, BIU will use Customer Personal Data only for the purposes for which Customer transferred it; apply safeguards appropriate to sensitivity; assist Customer with access, correction, complaints, and breach obligations; and use contractual protections for cross-border processing intended to provide the level of protection required by applicable law.

Where BIU acts as a data intermediary under Singapore law, BIU will comply with obligations directly applicable to that role. Where Australian law applies to an overseas disclosure, the parties will cooperate concerning reasonable steps and accountability requirements. Customer remains responsible for determining the laws applicable to its disclosure and instructions.

A16. Conflicts, liability, and termination

A16.1 Conflicts

This DPA controls over conflicting Agreement terms concerning the processing of Customer Personal Data. The SCCs or UK Addendum control to the extent required for a Restricted Transfer.

A16.2 Liability

Liability arising under this DPA is subject to the exclusions and aggregate cap in Sections 26 and 27 of the Terms, except to the extent the SCCs, UK Addendum, or non-waivable law requires otherwise. This DPA does not create a separate or additional liability cap.

A16.3 Term

This DPA remains effective while BIU processes Customer Personal Data. Duties that by their nature should survive, including confidentiality, deletion, audit evidence, transfer, and liability provisions, survive for the applicable period.


Schedule 1 — Processing Details

1. Subject matter

Provision of the Service, including website analysis, SEO and technical SEO, AI-search visibility, content generation, competitor monitoring, analytics, recommendations, workflows, integrations, APIs, support, and AI agents selected or configured by Customer.

2. Duration

For the Subscription Term and the deletion and backup periods stated in the Agreement, unless Customer instructs earlier deletion or law requires longer retention.

3. Nature and purpose

Collection, receipt, access, hosting, storage, organization, retrieval, consultation, analysis, classification, scoring, generation, transformation, transmission, synchronization, publication or other customer-authorized action, support, security, deletion, and return, solely to provide and secure the Service and follow Customer's instructions.

4. Data Subject categories

Depending on Customer's use:

  • Authorized Users, administrators, employees, contractors, and business contacts;
  • Customer's website users, prospects, customers, authors, and community participants;
  • employees or representatives of competitors, partners, vendors, and public-source publishers;
  • repository contributors and account holders associated with connected services; and
  • other individuals whose information Customer submits, connects, or directs BIU to analyze.

5. Personal data categories

Depending on Customer's use:

  • identifiers and business contact information;
  • account, organization, role, and permission information;
  • website, content, prompt, chat, file, and document information;
  • analytics, search-performance, CMS, repository, code, social, publishing, messaging, and integration data;
  • public professional, authorship, community, and source information;
  • device, usage, diagnostic, audit, and security data;
  • derived classifications, scores, recommendations, and inferences; and
  • any other personal data Customer lawfully submits under the Agreement.

6. Sensitive data

The standard Service is not intended for special-category, biometric, health, precise-location, government-identifier, children's, criminal-offense, payment-card, or similarly sensitive data. Customer may not submit such data unless an Order Form expressly authorizes it and states appropriate safeguards. Those safeguards may include stricter purpose limitation, access restrictions, encryption, logging, personnel controls, retention limits, and incident procedures appropriate to the data and risk.

Account authentication information and private communications may be processed where necessary to provide an approved feature.

7. Processing frequency

Continuous or intermittent, depending on Customer configuration, user actions, schedules, monitoring, integrations, and agents.

8. Retention

As described in Sections 22.5 and 22.6 of the Terms, Section A11, the Privacy Policy, and any Order Form. Default: active term; up to 30 days for post-termination export and active-system deletion; and up to 90 additional days for protected backup rotation, subject to legal and security exceptions.


Schedule 2 — Baseline Technical and Organizational Measures

BIU maintains measures appropriate to the Service, processing, and risk. Specific implementation may evolve, provided the overall level of protection is not materially reduced during a paid Subscription Term.

1. Security governance

  • Written information-security policies and assigned security responsibilities.
  • Periodic risk assessment and review of safeguards.
  • Security and privacy training appropriate to personnel roles.
  • Confidentiality obligations for personnel with access to Customer Personal Data.

2. Identity and access management

  • Role-based and least-privilege access to production systems.
  • Unique workforce identities and authentication controls.
  • Multifactor authentication or an equivalent strong-authentication control for privileged production access.
  • Access review and prompt deprovisioning following role change or departure.
  • Controlled, logged support access where reasonably practicable.

3. Encryption and communications security

  • Encryption of Customer Personal Data in transit over public networks using current industry-standard protocols.
  • Encryption at rest for production data stores and backups containing Customer Personal Data, where technically applicable.
  • Protected handling of secrets, tokens, and keys, with access limited by role.
  • Network and service controls designed to restrict unauthorized connectivity.

4. Application and development security

  • Change-management and code-review practices proportionate to risk.
  • Separation of development and production environments where reasonably practicable.
  • Dependency, secret, and vulnerability scanning appropriate to the technology stack.
  • Testing and remediation processes for material vulnerabilities.
  • Controls designed to prevent unauthorized code deployment.

5. Vulnerability and threat management

  • Monitoring of relevant security advisories and dependencies.
  • Risk-based remediation of identified vulnerabilities.
  • Malware protection or equivalent endpoint safeguards for relevant systems.
  • A process for receiving and evaluating good-faith vulnerability reports.

6. Logging, monitoring, and detection

  • Logging of material authentication, administrative, security, and service events.
  • Monitoring designed to identify suspicious activity, misuse, and service degradation.
  • Protected access to logs and retention proportionate to security and legal needs.
  • Alerting and escalation procedures for material events.

7. Incident response

  • Documented incident-response roles and procedures.
  • Processes for triage, containment, investigation, remediation, recovery, and notification.
  • Preservation of relevant evidence where appropriate.
  • Post-incident review for material incidents.

8. Availability, continuity, and recovery

  • Backups or replication appropriate to the Service architecture.
  • Recovery and continuity procedures proportionate to business risk.
  • Periodic testing or validation of relevant recovery procedures.
  • Capacity and availability monitoring.

No recovery-time or recovery-point commitment applies unless an Order Form expressly states one.

9. Data minimization, retention, and deletion

  • Collection and processing limited to disclosed and authorized purposes.
  • Retention settings and deletion processes aligned with the Agreement.
  • Protected backup rotation and restrictions on ordinary use of deleted backup data.
  • Processes to address Customer deletion and export instructions.

10. Tenant and environment protection

  • Logical controls designed to prevent unauthorized cross-customer access.
  • Authorization checks for workspace and organization resources.
  • Segregation appropriate to the multitenant architecture.

11. Vendor and Subprocessor management

  • Security and privacy review proportionate to the provider and data risk.
  • Written data-protection and confidentiality terms.
  • Monitoring of material provider changes where reasonably practicable.
  • Maintenance of a Subprocessor inventory.

12. Physical security

BIU relies primarily on established cloud and infrastructure providers for physical data-center security and reviews relevant assurance information where reasonably available. BIU maintains reasonable physical safeguards for its own offices, devices, and work locations.

13. Testing and assurance

  • Periodic review of control effectiveness.
  • Independent assessments, penetration testing, certifications, or assurance reports as BIU makes available for the relevant Service.
  • Remediation tracking for material findings.

Schedule 3 — SCC Annex Information

Annex I.A — Parties

Data exporter: Customer, as identified in the Account or Order Form.
Address: The address in the Order Form or Customer account.
Contact: Customer's Administrator, privacy contact, or contact in the Order Form.
Role: Controller or Processor, depending on Customer's role.
Relevant activities: Selecting and using the Service; submitting, connecting, administering, and instructing processing of Customer Personal Data.

Data importer: TCQ AI, LLC d/b/a BIU.
Address: Provided in the applicable Order Form or on request to hello@biu.ai
Contact: hello@biu.ai
Role: Processor or Subprocessor.
Relevant activities: Hosting, analyzing, generating, transmitting, securing, supporting, deleting, and otherwise processing Customer Personal Data to provide the Service under Customer's instructions.

Signature and date: The parties' electronic acceptance of the Agreement constitutes signature of the SCCs and UK Addendum to the extent legally effective. The execution date is the date Customer accepts the Agreement or the applicable Order Form, and the transfer starts when the relevant Restricted Transfer begins.

Annex I.B — Transfer description

The categories of Data Subjects, personal data, sensitive data, processing operations, purposes, frequency, and retention are described in Schedule 1 and the applicable Order Form.

Annex I.C — Supervisory authority

For Module Two or Module Three transfers under the GDPR, the competent Supervisory Authority is determined under Clause 13 of the SCCs. Where the exporter is not established in the EEA but is subject to the GDPR and has appointed a representative, the authority associated with the representative applies; otherwise, the authority of the Member State where relevant Data Subjects are located applies as provided by the SCCs.

Annex II — Security measures

The measures are described in Schedule 2.

Annex III — Subprocessors

Customer gives general authorization under Section A8. The current Subprocessor List, including functions and processing locations, is available on request by emailing hello@biu.ai.