THESE TERMS AND CONDITIONS (THE “TERMS”) FORM A LEGAL AGREEMENT BETWEEN THE INDIVIDUAL OR ENTITY IDENTIFIED IN ANY ORDER FORM (“CUSTOMER”) AND Fluent Ventures Inc. d/b/a OZZY AI (“OZZY” OR “PROVIDER”). BY (A) CLICKING TO ACCEPT THESE TERMS, (B) EXECUTING AN ORDER FORM THAT REFERENCES THESE TERMS, OR (C) ACCESSING OR USING THE SERVICES, CUSTOMER AGREES TO BE BOUND BY THESE TERMS. IF CUSTOMER PURCHASES THE SERVICES THROUGH AN AUTHORIZED PROVIDER PARTNER OR RESELLER, THE ORDER FORM MAY BE ENTERED INTO BETWEEN CUSTOMER AND SUCH PARTNER, BUT CUSTOMER’S USE OF THE SERVICES REMAINS SUBJECT TO THESE TERMS AND ANY ADDITIONAL TERMS AGREED BETWEEN CUSTOMER AND THE PARTNER. IF CUSTOMER DOES NOT ACCEPT THESE TERMS, CUSTOMER MAY NOT ACCESS OR USE THE SERVICES. IF AN INDIVIDUAL ACCEPTS THESE TERMS ON BEHALF OF AN ORGANIZATION, SUCH INDIVIDUAL REPRESENTS AND WARRANTS THAT THEY HAVE AUTHORITY TO BIND THAT ORGANIZATION.
In consideration of the mutual covenants and agreements contained herein, the parties agree as follows:
1. Definitions
1.1 The following terms have the meanings set out below:
1.1.1 “Aggregated Data” means data or information generated or derived from Customer’s use of the Services in de-identified or anonymized form that does not identify Customer, any Authorized User, or any individual.
1.1.2 “Authorized Users” means individuals who Customer authorizes to access and use the Services on Customer’s behalf.
1.1.3 “Confidential Information” has the meaning given in Section 9.
1.1.4 “Customer Data” means data, content, or information submitted by or on behalf of Customer into the Services. Customer Data does not include Aggregated Data or any data generated by Provider through the operation of the Services.
1.1.5 “Customer Marks” means Customer’s name and logo as provided by Customer for use as permitted under these Terms.
1.1.6 “Customer Personal Information” means any Personal Information within Customer Data that is processed by Provider on Customer’s behalf.
1.1.7 “Data Processing Addendum” or “DPA” means the data processing addendum attached as Exhibit A to these Terms (or otherwise made available by Provider) governing Provider’s processing of Customer Personal Information.
1.1.8 “Fees” means the fees payable for the Services as set out in an Order Form.
1.1.9 “Force Majeure Event” has the meaning set out in Section 11.3.
1.1.10 “Order Form” means an ordering document, online checkout, or similar record specifying the Services purchased by Customer, including pricing, term, and any applicable usage limits.
1.1.11 “Personal Information” means information about an identified or identifiable individual, including information defined as “personal information,” “personal data,” or similar terms under applicable laws.
1.1.12 “Sensitive Personal Information” (or “Sensitive Data”) means any category of Personal Information that is subject to heightened or special protection under applicable privacy laws, including, as applicable, health or medical information, biometric identifiers, financial account or payment card numbers, precise geolocation, information about children or minors, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, genetic data, and any other category of Personal Information defined as “sensitive” under applicable privacy laws.
1.1.13 “Services” means Provider’s cloud-based AI voice receptionist platform for the security, fire, and alarm industry, comprising the Ozzy Dashboard and the Sadie voice runtime (and any other Provider offerings described in the applicable Order Form), together with any related documentation, websites, APIs, and support services.
1.1.14 “Subprocessor” means any third party engaged by Provider to process Customer Data in connection with the Services, including hosting providers, voice runtime providers (including Sadie), AI model providers, telephony carriers, and email delivery providers. Provider’s current Subprocessors are identified in the DPA or otherwise made available to Customer on request.
1.1.15 “Terms” means these Terms of Service, together with all applicable Order Forms and referenced documents.
1.2 Incorporation of Order Forms and Additional Documents. Order Forms and any additional documents referenced in an Order Form will form part of these Terms. In the event of a conflict, the following order of precedence applies: (1) the applicable Order Form; (2) the Data Processing Addendum (Exhibit A); (3) these Terms; and (4) any additional documents referenced in an Order Form.
2. Provision of Services
2.1 Provision of Access. Provider will make the Services available to Customer as described in one or more Order Forms. Each Order Form will specify the applicable services, features, and duration (including any subscription term, project term, or usage period).
2.2 Right of Use. Subject to Customer’s compliance with these Terms and payment of all applicable Fees, Provider grants Customer a limited, non-exclusive, non-transferable right for Authorized Users to access and use the Services and related documentation solely for Customer’s internal business purposes, in accordance with the usage limits, features, and scope described in the applicable Order Form. Customer may not sublicense, resell, distribute, or commercially exploit the Services, except as expressly permitted in an Order Form.
2.3 Support Services. Provider will provide standard technical support and maintenance for the Services in accordance with its then-current Support Policy. Support includes access to Provider’s help desk, knowledge base, and reasonable assistance in troubleshooting service issues. Unless expressly stated in an Order Form or separate service-level agreement, Provider does not guarantee any specific response times, resolutions, or service levels. Support does not include custom development, configuration, integration work, or training unless purchased separately.
2.4 Updates and Enhancements. Provider may update or modify the Services from time to time, including patches, improvements, and changes to features or interfaces. Provider will not materially reduce core functionality during a service term without reasonable notice. Nothing in this Section obligates Provider to make any particular feature or functionality available unless expressly stated in an Order Form. Any custom enhancements or development requested by Customer may be subject to additional fees.
2.5 Temporary Limitations or Disruptions. The Services may experience scheduled or unscheduled downtime. Provider will use commercially reasonable efforts to minimize disruptions and provide advance notice where practicable. Unless expressly stated in an Order Form or separate service-level agreement, Provider does not guarantee uninterrupted service or any specific availability level.
2.6 Beta or Trial Services. Provider may offer features on a beta or trial basis (“Beta Features”). Beta Features are provided “as is” without warranties or service commitments and may be modified or discontinued at any time.
2.7 Subcontractors and Affiliates. Provider may use affiliates and subcontractors to deliver the Services and remains responsible for their performance.
2.8 Professional Services. Any implementation, configuration, integration, training, data migration, or other professional services are not included in the Services unless expressly stated in an Order Form or statement of work. Any such services will be provided for the fees and on the terms set out in the applicable Order Form or statement of work.
2.9 Compliance with Laws. Provider will comply with laws applicable to its role as a SaaS provider. Provider shall not be required to take any action under these Terms that would cause it to violate any applicable law or regulation.
3. Customer Obligations
3.1 Customer Systems and Cooperation. Customer is responsible for maintaining all systems, equipment, software, and network connections required to access and use the Services. Customer will provide Provider with any cooperation, information, and access reasonably required for Provider to deliver the Services. Customer acknowledges that Provider’s ability to perform the Services depends on Customer’s timely cooperation. Any delay or failure by Customer to provide required cooperation, information, or access may impact the Services, will extend Provider’s performance timelines accordingly, and will not constitute a breach by Provider. Customer will promptly notify Provider of any issues affecting its ability to access or use the Services. Provider is not responsible for delays, failures, or non-performance caused by Customer’s acts, omissions, or failure to meet its obligations under these Terms.
3.2 Use Restrictions. Customer and its Authorized Users must use the Services only as permitted in these Terms and the applicable Order Form. Customer must not, and must ensure Authorized Users do not:
(a) copy, modify, translate, or create derivative works of the Services or documentation;
(b) sublicense, resell, rent, lease, loan, or otherwise make the Services available to third parties except as expressly permitted;
(c) reverse engineer, decompile, disassemble, or attempt to access the source code of the Services;
(d) bypass, disable, or interfere with security or access controls;
(e) upload or transmit malicious code, harmful materials, or unlawful content;
(f) use the Services in a manner that violates third-party rights or applicable laws;
(g) send spam or unsolicited communications;
(h) process or store unlawful, harmful, or infringing content;
(i) upload, transmit, or store any Sensitive Personal Information in the Services unless expressly permitted in an Order Form or otherwise agreed in writing by Provider;
(j) interfere with or disrupt the performance or integrity of the Services; or
(k) use the Services, or any knowledge, data, outputs, or insights gained through use of the Services, to design, develop, train, or assist in the creation of any product or service that competes with the Services or Provider’s business.
3.3 Account Security and Unauthorised Use. Customer is responsible for maintaining the confidentiality and security of all account credentials, passwords, access tokens, API keys, and other access methods issued to Customer or its Authorized Users. Customer must ensure that each Authorized User uses unique credentials and does not share or reuse credentials. Customer is responsible for all activity under its accounts, whether authorized or unauthorized, except to the extent caused by Provider’s breach of these Terms. Customer must promptly notify Provider of any actual or suspected unauthorized access to or use of the Services, Customer accounts, or Customer Data, and must take reasonable steps to stop and mitigate such activity, including disabling or re-securing compromised accounts or credentials. Customer is responsible for ensuring that its Authorized Users comply with these Terms and for all actions taken through Customer’s accounts.
3.4 Suspension and Cooperation. Provider may suspend access if an account is compromised, misused, or poses a risk. Access will be restored once the issue is resolved. Customer will cooperate in any investigation.
3.5 Security Testing and Audits. Customer must not conduct, or permit any third party to conduct, penetration testing, vulnerability scanning, or similar security testing of the Services without Provider’s prior written consent. Provider may approve such testing subject to reasonable conditions to protect the security and stability of the Services.
3.6 Compliance with Laws and Policies. Customer must use the Services in compliance with all applicable laws, regulations, and government requirements, including those relating to privacy, data protection, anti-spam, and export control. Customer is responsible for ensuring that its collection and use of Customer Data complies with applicable laws and any applicable internal policies. Customer must not export, re-export, or transfer the Services or any related technical data in violation of applicable export laws.
3.7 Call Recording and Consent. The Services may record, monitor, transcribe, and analyze telephone and voice communications. As between the parties, Customer is solely responsible for determining whether recording, monitoring, or transcription is enabled and for compliance with all applicable laws governing the recording, interception, monitoring, or disclosure of communications, including all applicable federal, state, provincial, and foreign wiretapping, eavesdropping, all-party- and two-party-consent, and electronic-communications and privacy laws. Customer will obtain and maintain all consents, and provide all notices, disclosures, and announcements (including any call-recording notification at the outset of a call), required for the lawful recording, monitoring, transcription, and processing of communications through the Services. Provider makes the Services available as a tool and does not control the manner of Customer’s deployment or the individuals or jurisdictions Customer engages; Provider is not responsible for Customer’s compliance with such laws.
3.8 Outbound Calling. Where Customer configures or enables outbound calling through the Services, Customer is solely responsible for the composition, accuracy, and legal compliance of any Customer Data, contact lists or data sources used to initiate outbound calls, including lists sourced from Customer’s own systems or third-party integrations. Customer represents and warrants that outbound calls initiated through the Services will only be made to individuals with whom Customer has an existing business relationship or who have otherwise provided prior express consent to be contacted. Customer represents and warrants that such lists were lawfully obtained, it has obtained all required consents, permissions, and legal bases to contact each individual on its lists, and that all outbound calling activity complies with applicable laws, including the Telephone Consumer Protection Act (TCPA), Canada’s Anti-Spam Legislation (CASL), CRTC Unsolicited Telecommunications Rules, and all applicable state and provincial telemarketing laws. Provider acts solely as a technical conduit for outbound calls and has no responsibility for who Customer contacts, the source or legality of Customer’s contact lists, or the content or purpose of any outbound call.
4. Rights and Intellectual Property
4.1 Customer Marks and Content. Customer grants Provider a limited, non-exclusive, royalty-free license to use Customer’s Marks solely to identify Customer as a user of the Services in Provider’s customer lists, websites, and marketing materials. Any other use of Customer Marks, including case studies or testimonials, requires Customer’s prior written approval. Provider will use Customer Marks in accordance with Customer’s reasonable brand guidelines. All rights in the Customer Marks remain with Customer.
4.2 Artificial Intelligence and Machine Learning. Customer instructs and authorizes Ozzy to use Personal Data and Service Data (meaning data generated by the Services about their operation and Customer’s use of them, such as configuration, usage, and performance logs, but excluding the content of Customer Data) to improve, optimize, and refine the Services, including by adjusting prompts, call handling logic, and response patterns, and by fine-tuning models through Provider’s third-party AI providers, and to improve the Sadie voice runtime and the Services.
4.3 AI Output Accuracy. The Services use AI Technologies, and outputs generated by the Services (including transcriptions, summaries, call classifications, and automated responses) may be inaccurate, incomplete, inconsistent, or otherwise unreliable, and may not reflect the most current or correct information. AI Technologies can produce erroneous or fabricated content (sometimes called “hallucinations”). Provider does not warrant the accuracy, completeness, or reliability of any AI-generated output. Customer is solely responsible for reviewing, verifying, and validating outputs before relying on or acting upon them, and must not rely on the Services as the sole basis for any decision that has legal, financial, safety, or similarly significant consequences.
4.4 Feedback. If Customer or any Authorized User provides feedback, suggestions, or ideas relating to the Services (“Feedback”), Provider may use, disclose, reproduce, modify, and otherwise exploit such Feedback without restriction or obligation to Customer. Feedback is not considered Customer’s Confidential Information.
4.5 Reservation of Rights. Provider retains all rights in and to the Services and related technology. All rights not expressly granted to Customer under these Terms are reserved by Provider.
5. Data and Security
5.1 Ownership of Customer Data. Nothing in these Terms transfers ownership of Customer Data to Provider. Customer is responsible for the accuracy, quality, and legality of Customer Data and for obtaining all rights and consents necessary for Customer Data to be used in connection with the Services.
5.2 Processing of Customer Data. Provider will process Customer Data only to provide, maintain, support, and improve the Services and to perform its obligations under these Terms, and in accordance with Customer’s documented instructions. Where Provider processes Customer Personal Information on Customer’s behalf, the DPA governs that processing and is incorporated into these Terms by reference.
5.3 Customer Representations and Consents. Customer represents and warrants that it has obtained all notices, consents, and permissions required under applicable laws for Provider to receive, use, store, and process Customer Data as described in these Terms. Customer is solely responsible for the legality, accuracy, and means by which it collects, uses, or discloses Customer Data, including Customer Personal Information. Customer must not provide Customer Data that is unlawful, infringes third-party rights, or that Customer is not legally permitted to provide to Provider.
5.4 License to Use Customer Data. Customer grants Provider a limited, non-exclusive, worldwide, royalty-free license to host, copy, use, process, transmit, display, and store Customer Data solely to provide, maintain, support, and improve the Services and to perform Provider’s obligations under these Terms. This license includes the right to share Customer Data with Provider’s affiliates and subcontractors solely as required to provide the Services, subject to confidentiality and security obligations.
5.5 Aggregated and Statistical Data. Provider may generate, use, and disclose aggregated, anonymized, or de-identified data derived from Customer’s use of the Services (“Aggregated Data”) for analytics, benchmarking, research, and to improve and develop the Services. Aggregated Data will not identify Customer, any Authorized User, or any individual. All right, title, and interest in Aggregated Data belongs to Provider.
5.6 Data Retention and Deletion. During the term of the applicable Order Form, Provider will retain Customer Data in accordance with Provider’s then-current retention policies and for the retention period set out in the Data Processing Addendum (Appendix A) or the applicable Order Form. Provider is not obligated to store, retain, or return Customer Data beyond the period required by applicable law or Provider’s standard retention policies. Customer may request an export of Customer Data for a period of thirty (30) days following termination. Data export requests must be submitted in writing and may be subject to reasonable fees for Provider’s time, resources, and technical costs. After this period, Provider may delete or anonymize Customer Data in accordance with its retention practices, unless otherwise required by law.
5.7 Information Security Program. Provider will maintain an information security program with administrative, technical, and physical safeguards appropriate to the nature of the Services and the Customer Data processed within them.
5.8 Notice of Security Incident. Provider will notify Customer without undue delay of confirmed unauthorized access to Customer Personal Information within the Services.
5.9 Subprocessors. Provider may engage Subprocessors to process Customer Data in connection with the Services. Provider remains responsible for the acts and omissions of its Subprocessors to the same extent as if performed by Provider. Provider’s current Subprocessors include, without limitation: (a) Sadie (voice runtime, operated by Provider’s affiliate); (b) Fly.io (application hosting, Toronto, Canada region); (c) Neon (PostgreSQL database hosting for Customer Data, United States region); (d) Anthropic (LLM API for automated call quality evaluation); (e) Twilio (telephony carrier, accessed through Sadie); and (f) Provider’s SMTP email delivery provider for authentication emails. Provider’s agreements with each Subprocessor require confidentiality and data-protection obligations no less protective than those in these Terms and the DPA. Provider will provide notice of new Subprocessors as described in the DPA. The Services’ application layer is hosted in Canada (Fly.io), Customer Data is stored in the United States (Neon), and the Sadie voice runtime processes Personal Information in the United States, Ireland, or Australia (collectively, the approved hosting regions), each as further described in the DPA (Appendix A). Ozzy will not materially change the approved hosting regions without prior notice as required by the DPA.
6. Third Party Services and Integrations
6.1 Third Party Services. The Services may enable access to or integration with third-party products, applications, websites, or services (“Third-Party Services”). Provider does not control, endorse, or assume responsibility for Third-Party Services or how they handle Customer Data. Customer’s use of Third-Party Services is governed solely by the terms and policies of the applicable third-party provider.
6.2 Customer Responsibility and Provider Rights. Customer is solely responsible for any Customer Data it shares with Third-Party Services and for any integrations it develops or configures. Provider is not liable for any disclosure, loss, or modification of Customer Data resulting from Customer’s use of Third-Party Services or customer-managed integrations. Provider may suspend or disable an integration if it poses a security, legal, or operational risk, violates these Terms, or is no longer supported. Additional fees for integrations may apply as set out in the Order Form.
7. Fees and Payment
7.1 Fees. Customer will pay the fees set out in the applicable Order Form (“Fees”). All Fees are payable in the currency specified in the Order Form and are non-refundable unless otherwise stated in these Terms. If no currency is specified, Fees are payable in U.S. dollars.
7.2 Invoicing and Payment Terms. Provider will invoice Customer as stated in the applicable Order Form. Unless otherwise specified, invoices are due thirty (30) days from the invoice date. Late payments may incur interest at the rate specified in the Order Form or, if none is stated, 1.5% per month (18% per annum) or the maximum amount permitted by law. Customer must pay all Fees without set-off, except as required by law.
7.3 Taxes. Fees exclude all taxes, duties, and similar charges. Customer is responsible for all such amounts imposed on the Services, except for taxes based on Provider’s income. If Customer claims a tax exemption, it must provide valid exemption documentation. If Customer is required to withhold taxes, Customer must gross-up payments so that Provider receives the full amount that would have been paid absent such withholding.
7.4 Fee Adjustments. Provider may adjust Fees at the start of each renewal term by providing at least sixty (60) days’ prior notice, unless otherwise stated in the Order Form.
7.5 Late Payments. In addition to late payment interest, if Provider retains a collection agency or attorney to collect any overdue amounts, Customer will pay all costs of collection, including without limitation reasonable attorneys’ fees, collection agency fees, court costs, and other expenses incurred by Provider in collecting the overdue amounts. These collection costs are in addition to, and not in lieu of, any other remedies available to Provider under these Terms or applicable law.
8. Term and Termination
8.1 Term.
8.1.1 Term of the Terms. These Terms will remain in effect until all Subscription Terms under all Order Forms have expired or been terminated, unless earlier terminated in accordance with this Section 8.
8.1.2 Subscription Terms. Each Order Form will specify its own subscription term or service term (“Subscription Term”). Each Subscription Term begins on the start date set out in the applicable Order Form and continues for the duration specified in that Order Form. For clarity, neither party has the right to terminate for convenience during any Subscription Term.
8.1.3 Renewal. Unless otherwise stated in an Order Form, each Subscription Term will automatically renew for successive periods equal to the then-current Subscription Term unless either party gives at least sixty (60) days’ prior written notice of non-renewal.
8.2 Termination. Either party may terminate these Terms or an applicable Order Form with written notice if the other party: (a) materially breaches these Terms and fails to cure within thirty (30) days after written notice, or (b) becomes insolvent, ceases business operations, or becomes subject to bankruptcy or similar proceedings.
8.3 Suspension of Services. Provider may suspend or restrict access to the Services if: (a) Customer fails to pay undisputed Fees when due and does not cure within ten (10) days of notice; (b) Customer’s or an Authorized User’s use of the Services poses a security, legal, or operational risk; or (c) suspension is required to comply with applicable law. Provider will restore access once the issue is resolved.
8.4 Effect of Termination. Upon termination or expiration of this Terms or any Order form:
(a) all rights and licenses granted to Customer under the terminated Order Form(s) end immediately;
(b) Customer must stop using the Services;
(c) Customer must pay all Fees accrued up to the effective date of termination;
(d) If Customer terminates these Terms or any Order Form for any reason other than Provider’s uncured material breach or insolvency, Customer must pay the Fees that would have been payable for the remainder of the applicable Subscription Term (less any amounts already paid) as a reasonable estimate of Provider’s actual damages;
(e) any Fees that have been invoiced but remain unpaid will become immediately due;
(f) Provider may delete or anonymize Customer Data in accordance with these Terms;
(g) termination does not affect any rights, remedies, or obligations that accrued before the effective date of termination; and
(h) Provider has no obligation to refund any prepaid fees, except as expressly stated in these Terms or an applicable Order Form.
8.5 Survival. Sections relating to Fees, Confidentiality, Intellectual Property, Warranty Disclaimers, Indemnities, Limitations of Liability, Data and Security, and any other provisions intended to survive termination will remain in effect.
9. Confidentiality
9.1 Definition of Confidential Information. “Confidential Information” means non-public information disclosed by one party to the other that is identified as confidential or should reasonably be understood to be confidential given its nature and the circumstances of disclosure. Confidential Information does not include Customer Data, or information that is publicly available without breach, already known to the receiving party, received from a third party without restriction, or independently developed without use of the other party’s Confidential Information. For the avoidance of doubt, Provider’s Confidential Information includes, without limitation, the Services’ underlying system architecture, source code, prompts and prompt configurations, voice workflows and call flows, model configurations and parameters, and related methods, designs, and technical know-how, in each case whether or not marked or designated as confidential.
9.2 Obligations. The receiving party must: (a) use Confidential Information only to perform its obligations or exercise its rights under these Terms; (b) protect Confidential Information using at least the same degree of care it uses to protect its own similar information, but no less than reasonable care; and (c) not disclose Confidential Information except to its personnel, affiliates, subcontractors, or advisers who need to know it and are bound by confidentiality obligations no less protective than those in these Terms.
9.3 Required Disclosure. If the receiving party is required by law or legal process to disclose Confidential Information, it may do so but must provide prompt notice to the disclosing party (where legally permitted) and limit disclosure to what is legally required.
9.4 Return or Destruction. Upon written request, the receiving party will return or delete the disclosing party’s Confidential Information, except that the receiving party may retain copies as required by law or in routine backups, provided such information remains subject to this Section.
9.5 Survival of Confidentiality Obligations. Confidentiality obligations survive termination of these Terms for three (3) years, except that trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
10. Risk Management
10.1 Mutual Representations. Each party represents and warrants that it has the legal authority to enter into these Terms and to perform its obligations under them.
10.2 Limited Warranty; Disclaimer. PROVIDER WARRANTS THAT IT WILL PROVIDE THE SERVICES IN A PROFESSIONAL AND WORKMANLIKE MANNER CONSISTENT WITH GENERALLY ACCEPTED INDUSTRY STANDARDS. EXCEPT FOR THIS LIMITED WARRANTY, THE SERVICES AND ALL RELATED MATERIALS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, OR THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE OF HARMFUL COMPONENTS.
10.3 No Life-Safety or Emergency Service. The Services are an AI voice receptionist tool and are not a life-safety system, alarm monitoring service, or emergency notification, dispatch, or response service, and are not a substitute for professional monitoring or for emergency services such as 911 or local emergency responders. Customer acknowledges that the Services may fail to answer, detect, interpret, prioritize, route, or escalate any call, including a call involving an emergency, and may be unavailable due to factors within or outside Provider’s control (including telephony, network, power, hardware, or third-party service failures). Customer must not rely on the Services to detect, report, or respond to any emergency or life-safety situation and must maintain separate, independent, and adequate means to contact emergency services and to handle such situations. Customer is solely responsible for implementing appropriate emergency and life-safety policies and procedures. TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER WILL HAVE NO LIABILITY FOR ANY DEATH, PERSONAL INJURY, PROPERTY DAMAGE, OR OTHER LOSS OR HARM ARISING OUT OF OR RELATING TO ANY EMERGENCY OR LIFE-SAFETY SITUATION, INCLUDING ANY FAILURE, DELAY, ERROR, INTERRUPTION, OR MISHANDLING BY THE SERVICES IN CONNECTION WITH SUCH A SITUATION.
10.4 Indemnification by Provider. Provider will defend and indemnify Customer against any third-party claim alleging that Customer’s authorized use of the Services infringes a third party’s intellectual property rights, and will pay any damages or costs finally awarded, provided that Customer promptly notifies Provider of the claim and cooperates in the defense. Provider may resolve such claims by (a) modifying the Services, (b) obtaining a right for Customer to continue using them, or (c) terminating the affected Services and refunding any prepaid Fees for the unused portion of the applicable term. This Section does not apply to claims arising from: (i) Customer Data; (ii) use of the Services in combination with products not provided by Provider; (iii) unauthorized use; or (iv) modifications not made by Provider. THIS SECTION SETS FORTH PROVIDER’S ENTIRE LIABILITY AND CUSTOMER’S EXCLUSIVE REMEDY FOR ANY THIRD-PARTY CLAIM ALLEGING INFRINGEMENT OR MISAPPROPRIATION OF INTELLECTUAL PROPERTY RIGHTS RELATING TO THE SERVICES.
10.5 Indemnification by Customer. Customer will defend and indemnify Provider, its affiliates, and their personnel from and against any third-party claim, and all related losses, arising from: (a) Customer Data (including any allegation that Customer Data is unlawful, inaccurate, infringes third-party rights, or was collected without required notices or consents); (b) Customer’s or any Authorized User’s use of the Services in violation of these Terms or applicable law; (c) any integrations, configurations, scripts, or systems not provided by Provider; or (d) Customer’s modification or combination of the Services with non-Provider products. Provider will promptly notify Customer of any such claim and will reasonably cooperate in the defense.
10.6 Limitation of Liability. TO THE MAXIMUM EXTENT PERMITTED BY LAW:
10.6.1 NO INDIRECT DAMAGES. NEITHER PARTY IS LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, BUSINESS, OR ANTICIPATED SAVINGS, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
10.6.2 AGGREGATE CAP. EACH PARTY’S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS WILL NOT EXCEED THE FEES PAID AND PAYABLE BY CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. FOR SERVICES PROVIDED AT NO CHARGE, PROVIDER’S TOTAL LIABILITY WILL NOT EXCEED ONE HUNDRED (100) DOLLARS OR THE AMOUNT REQUIRED BY APPLICABLE LAW TO RENDER THIS LIMITATION VALID AND ENFORCEABLE IN THE JURISDICTION WHERE THE CLAIM IS BROUGHT.
10.6.3 Exceptions. These limitations do not apply to: (i) indemnification obligations; (ii) Customer’s payment obligations; (iii) breaches of Section 9 (Confidentiality) or intellectual property rights; (iv) fraud or willful misconduct; or (v) liability that cannot be limited by law.
10.6.4 Basis of Bargain. The parties acknowledge that the limitations and exclusions in this Section are an essential basis of their agreement and apply even if any limited remedy fails of its essential purpose.
10.6.5 Outbound calls. Provider shall not be liable for any outbound call initiated through the Services using Customer’s contact lists, configurations, or integrated systems, including any claim by a call recipient or regulatory action arising from Customer’s outbound calling activity, the source or content of Customer’s contact lists, or Customer’s failure to obtain required consents.
10.7 Equitable Relief. Nothing in these Terms limits either party’s right to seek urgent or equitable relief, including injunctive relief, to prevent actual or threatened misuse of its intellectual property or Confidential Information.
10.8 Insurance. Provider will maintain insurance coverage appropriate to its business and the Services, which may be maintained by Provider or its affiliates. Provider will provide evidence of such coverage upon reasonable request.
11. Miscellaneous
11.1 Entire Agreement. These Terms and the applicable Order Forms constitute the complete agreement between the parties regarding the Services and supersede all prior or contemporaneous agreements on the same subject matter. Any terms or conditions in a purchase order, vendor portal, confirmation, or other document issued by Customer that conflict with or supplement these Terms or an Order Form are void and will not apply, even if Provider accepts or performs under such document.
11.2 Notices. All notices under these Terms must be in writing and delivered (a) by email, or (b) to the notice address specified in the Order Form. A notice is deemed received on the next business day after it is sent, unless the sender receives a delivery failure notice. Either party may update its notice address or email by providing notice to the other party.
11.3 Force Majeure. Neither party is liable for any delay or failure to perform its obligations (other than payment obligations) due to events beyond its reasonable control, including natural disasters, acts of God, fire, flood, earthquake, war, terrorism, civil unrest, labor disputes, failures of utilities or telecommunications, or government actions (“Force Majeure Event”). The affected party will promptly notify the other party of the Force Majeure Event and use commercially reasonable efforts to resume performance as soon as practicable.
11.4 Amendments, Modifications, and Waivers. Except as otherwise provided herein, any amendment or waiver must be in writing and agreed to by both parties. A waiver applies only to the specific instance and does not constitute a continuing waiver. Failure to enforce any provision is not a waiver of that provision. Notwithstanding the foregoing, Provider may update these Terms from time to time by posting a revised version to its website. Updated Terms take effect for new customers upon posting. For existing customers, Provider will provide at least thirty (30) days’ prior written notice of any material changes, and continued use of the Services after the notice period constitutes acceptance of the updated Terms. If Customer does not accept the updated Terms, Customer may terminate the applicable Order Form(s) by written notice before the end of the notice period without liability for early termination fees.
11.5 Severability and Interpretation. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable. Headings are for convenience only. “Including” means “including without limitation.”
11.6 Assignment. Neither party may assign these Terms, in whole or in part, without the other party’s prior written consent, except that Provider may assign these Terms without consent to an (a) affiliate (b) a successor in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of Provider’s business or assets; or (c) an entity acquiring control of Provider. Any attempted assignment in violation of this Section is void. These Terms bind the parties and their permitted successors and assigns.
11.7 Relationship of the Parties. The parties are independent contractors. These Terms do not create any partnership, joint venture, employment, agency, or fiduciary relationship. No third party has rights under these Terms except that Provider’s affiliates and subcontractors may rely on the disclaimers and limitations set out in these Terms.
11.8 Non-Solicitation of Personnel. During the term of these Terms and for twelve (12) months after their expiration or termination, Customer will not, directly or indirectly, solicit for employment or engagement, or hire or engage, any employee or contractor of Provider or its affiliates with whom Customer had contact or who was involved in providing the Services, in each case without Provider’s prior written consent. This restriction does not prohibit Customer from (a) making general solicitations for employment that are not specifically directed at Provider’s personnel (including general advertisements or job postings), or hiring any person who responds to such a general solicitation; or (b) hiring or engaging any person who approaches Customer on his or her own initiative without any prohibited solicitation, or whose employment or engagement with Provider or its affiliates ended at least six (6) months earlier.
11.9 Compliance. Each party will comply with all applicable laws and regulations, including export-control, trade sanctions, anti-corruption, and anti-bribery laws. Customer must not use the Services in violation of such laws or allow access by prohibited persons. Customer is responsible for ensuring that its use of the Services, including its collection and processing of Customer Data, complies with all laws applicable to its business, operations, and industry, including privacy, consumer protection, and data-security laws. Customer must not use the Services for any unlawful purpose.
11.10 Governing Law and Jurisdiction. These Terms and any dispute, controversy, or claim arising out of or relating to them will be governed by the laws of the Province of QUEBEC and the federal laws of Canada applicable therein, without regard to conflict-of-laws principles. Each party irrevocably submits to the exclusive jurisdiction and venue of the courts located in that Province and waives any objection to venue or inconvenient forum. Each party waives any right to a jury trial and agrees that any dispute must be brought on an individual basis and not as a class or representative action, to the maximum extent permitted by law. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
11.11 Costs and Attorney’s Fees. In any legal action or proceeding arising out of or relating to these Terms, the prevailing party is entitled to recover its reasonable attorneys’ fees, costs, and expenses from the non-prevailing party, in addition to any other relief awarded.
11.12 Electronic Acceptance. Electronic acceptance or execution of these Terms or any Order Form—including via click-acceptance, electronic signature, or use of the Services—constitutes a valid and binding agreement between the parties.
11.13 Language. The Parties have required that these Terms and all deeds, documents and notices relating to these Terms be drawn up in the English language. Les parties aux présentes ont exigé que le présent contrat et tous autres contrats, documents ou avis afférents aux présentes soient rédigés en langue anglaise.
Exhibit A — Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Agreement between Fluent Ventures Inc. d/b/a Ozzy AI ("Ozzy") and the party that has agreed to the applicable Order Form and Terms and Conditions (hereinafter “Terms” or “Agreement”) ("Customer") and governs Ozzy's Processing of Personal Data on behalf of Customer. Capitalized terms not defined here have the meanings given in the Agreement. If there is a conflict between this DPA and the Agreement, this DPA controls for the Processing of Personal Data.
1. Definitions
1.1 "Applicable Privacy Laws" means all privacy and data-protection laws applicable to the Processing of Personal Data under this DPA, including, to the extent applicable, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws (including Quebec's Law 25), applicable U.S. state privacy laws, and any successor or substantially similar laws.
1.2 "Controller," "Processor," and "Data Subject" have the meanings given under Applicable Privacy Laws. Customer is the Controller (or a processor acting for a third-party controller) and Ozzy is the Processor.
1.3 "Personal Data" means Personal Information within the Customer Data that Ozzy Processes on behalf of Customer, including audio, transcripts, caller identifiers, contact details, device and usage data, and metadata.
1.4 "Customer Data" means data submitted by or on behalf of Customer to the Services; it excludes aggregated or de-identified data.
1.5 "Services" means Ozzy's cloud-based AI voice receptionist platform, comprising the Ozzy Dashboard and the Sadie voice runtime, as described in the Agreement.
1.6 "Sub-processor" means a third party engaged by Ozzy to Process Personal Data. "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data (excluding unsuccessful attempts).
2. Roles and Processing Instructions
2.1 Roles. Customer is the Controller and determines the purposes and means of Processing. Ozzy acts solely as Customer's Processor and Processes Personal Data only on Customer's documented instructions, which comprise the Agreement, this DPA, and Customer's configuration and use of the Services.
2.2 Compliance and Customer Responsibilities. Each party will comply with Applicable Privacy Laws. Customer is responsible for the lawfulness of the Personal Data it provides and its instructions, and for providing all notices to, and obtaining all consents from, individuals required by law in connection with the Services (including notice that calls are handled by an AI system and any recording or biometric consents). Ozzy will inform Customer if it believes an instruction violates Applicable Privacy Laws.
2.3 Purpose Limitation. Ozzy will Process Personal Data only to provide and improve the Services and as permitted by this DPA, and will not sell or share Personal Data or Process it for its own unrelated purposes.
2.4 Model Training and Service Improvement. Customer instructs and authorizes Ozzy to use Personal Data and Service Data (meaning data generated by the Services about their operation and Customer's use of them, such as configuration, usage, and performance logs, but excluding the content of Customer Data) to improve, optimize, and refine the Services, including by adjusting prompts, call handling logic, and response patterns, and by fine-tuning models through Provider's third-party AI providers, and to improve the Sadie voice runtime and the Services, provided that (a) Ozzy's third-party AI model providers are prohibited from using Personal Data submitted through the Services to train their own foundation models, and (b) any Sensitive Data remains subject to Applicable Privacy Laws. Ozzy may use de-identified and aggregated data for any lawful purpose.
2.5 Confidentiality. Ozzy will ensure personnel with access to Personal Data are bound by confidentiality obligations and access it on a least-privilege basis.
3. Security
3.1 Ozzy will maintain, and will ensure its Sub-processors maintain, technical and organizational measures appropriate to the nature of the Personal Data, including access controls, encryption of Personal Data in transit and at rest where technically feasible, network security, and monitoring. Because the Services run on third-party infrastructure, certain measures are implemented by Ozzy's Sub-processors (including cloud hosting providers). On reasonable request and subject to confidentiality, Ozzy will make available a summary of its or its Sub-processors' security posture, including its Sub-processors' SOC 2 reports where available.
4. Sub-processors
4.1 Customer authorizes Ozzy to engage Sub-processors. Ozzy remains responsible for its Sub-processors' Processing to the same extent as for its own and will impose data-protection terms on each Sub-processor no less protective than this DPA.
4.2 Ozzy's current Sub-processors are: Sadie (voice runtime and real-time voice processing; operated by Ozzy's affiliate); Fly.io (application hosting); Neon (postgreSQL database server hosting); Anthropic (LLM API for automated call-quality evaluation); Twilio (telephony, accessed through Sadie); and Ozzy's email delivery (SMTP) provider.
4.3 Ozzy will give Customer prior notice of any new Sub-processor and a reasonable opportunity to object on reasonable data-protection grounds.
5. Data Subject Requests
5.1 Taking into account the nature of the Processing, Ozzy will provide reasonable assistance to enable Customer to respond to Data Subject requests. If Ozzy receives a request directly, it will forward it to Customer and will not respond except to confirm receipt.
6. Security Incidents
6.1 Ozzy will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting Personal Data, will provide the information reasonably available to help Customer meet its legal obligations, and will take reasonable steps to contain and remediate the incident.
7. Return and Deletion
7.1 On termination or expiration of the Agreement, or on Customer's written request, Ozzy will return or delete Personal Data, except to the extent retention is required by law or data is held in routine backups (which remain protected and are overwritten on the normal backup cycle).
8. International Transfers
8.1 The Services' application layer is hosted in Canada (by Ozzy's Sub-processor Fly.io), and Customer Data is stored in the United States (by Ozzy's Sub-processor Neon). Personal Data is also transferred to Ozzy's Sub-processor, Sadie, for real-time voice Processing in the United States, Ireland, or Australia. For Personal Data originating in Canada, these transfers outside Canada are governed by PIPEDA and, for Personal Data subject to Quebec's Law 25, by Law 25. Ozzy will (a) make available information sufficient for Customer to inform individuals that their Personal Data is stored and Processed in the United States and Canada and, where applicable, Ireland or Australia, and may be subject to the legal process of those jurisdictions; (b) remain accountable for, and ensure by written contract a comparable level of protection for, Personal Data transferred to its Sub-processors; and (c) where Personal Data subject to Law 25 is transferred outside Quebec, conduct or assist Customer with a privacy impact assessment before the transfer.
8.2 If Customer's Processing involves Personal Data protected by the EU/EEA GDPR or the UK GDPR, the parties will enter into the EU Standard Contractual Clauses and UK Addendum for any restricted transfer of such data. Unless and until such data is Processed, those clauses do not apply.
9. Assistance and Cooperation
9.1 Taking into account the nature of the Processing and the information available to it, Ozzy will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required by Applicable Privacy Laws.
10. Audit
10.1 On reasonable prior notice and no more than once per year (absent a Security Incident or a regulator requirement), Ozzy will make available information reasonably necessary to demonstrate compliance with this DPA, primarily through questionnaires, audit summaries, and third-party reports or certifications (e.g., Sub-processor SOC 2 reports), subject to confidentiality.
11. Customer Indemnity
11.1 Customer will indemnify Ozzy against third-party claims arising from Customer's failure to provide the notices or obtain the consents required under Section 2.2, except to the extent caused by Ozzy's breach of this DPA, gross negligence, or willful misconduct.
12. Liability, Conflict, and Term
12.1 The liability limitations in the Agreement apply to this DPA, except to the extent not permitted under Applicable Privacy Laws. This DPA controls over the Agreement for the Processing of Personal Data, and Applicable Privacy Laws prevail in case of conflict. This DPA applies for as long as Ozzy Processes Personal Data on behalf of Customer and forms an integral part of the Agreement.
Appendix A — Description of Processing
Subject matter, nature, and purpose: Processing to provide, maintain, secure, and improve the AI voice receptionist Services, including hosting, transmission, real-time voice processing, transcription, analytics, customer support, and model improvement as permitted by this DPA.
Duration: For the term of the Agreement and as long as Ozzy Processes Personal Data on behalf of Customer.
Types of Personal Data: caller telephone number / caller ID; audio stream content (processed in real time); transcripts and outputs; contact details submitted through the Services; call and event metadata; and any other Personal Data Customer submits. The Services are not designed to Process Sensitive Data (including health data); Customer should not submit it unless expressly agreed in writing.
Categories of Data Subjects:Customer's callers and end users, employees, contractors, and contacts.
Retention: Where recording is enabled (the default), audio recordings are retained for up to ninety (90) days and then deleted, unless earlier deletion is requested or longer retention is required by law. Transcripts and other data derived from audio recordings may be retained for the duration of the Agreement term and for a reasonable period thereafter for quality evaluation, billing, security, audit, compliance, and service improvement purposes. Where recording is disabled, audio is processed in real time and not retained.
Approved regions: Canada (application hosting Fly.io); the United States (Customer Data storage Neon, and Sadie voice processing).