1. Agreement and eligibility
The binding version will form an agreement between the customer identified during signup or in an order form and the ulpi contracting entity identified in that version. A person accepting for an organisation represents that they are authorised to bind it. The service is intended for lawful business use by adults able to enter a contract. A version becomes operative only when ulpi publishes it as binding with an effective date; this review draft does not create contractual rights or obligations.
2. Accounts and customer authority
Customers must provide accurate account information, maintain authorised administrators, protect authentication factors, and promptly report suspected compromise. The customer controls its users, agents, budgets, integrations, provider credentials, and instructions, and is responsible for activity performed through its account except to the extent caused by ulpi's breach of the binding agreement. Accounts may not be transferred, shared outside the customer's organisation, or used to conceal the identity of the responsible operator.
3. The service and autonomous operation
ulpi lets a customer configure companies, goals, agents, tools, approvals, budgets, and verification criteria. Agents can take actions and create WorkProducts with limited human intervention. Features, models, connectors, and limits may differ by plan or deployment. The customer must set appropriate approval boundaries and independently review outputs before relying on them for legal, medical, financial, employment, safety-critical, or other high-impact decisions.
4. AI-generated output
Machine-generated output may be inaccurate, incomplete, offensive, non-unique, or subject to third-party rights. ulpi does not represent that an output is correct, fit for a particular purpose, or eligible for intellectual-property protection. The customer is responsible for evaluating output, verifying citations and code, obtaining required permissions, and deciding whether and how to publish or use it. Provider-specific terms may also apply when the customer selects or connects a model provider.
5. Customer content and instructions
The customer retains its rights in prompts, files, records, connector data, goals, instructions, and other material it submits or makes available to the service. The customer grants ulpi a limited right to host, copy, transmit, transform, and otherwise process that material only to provide, secure, support, and improve the contracted service and as required by law. The customer represents that it has all rights and notices needed to supply the material and instruct its processing.
6. Model providers, MCP connectors, and third-party services
The service can route customer-selected data and actions to model/API providers and MCP or other connectors. Those services are governed by their own terms and privacy practices, may change or become unavailable, and may process data in other countries. The customer authorises each connection it enables and is responsible for its third-party accounts, permissions, and charges. ulpi will identify contractual subprocessors separately; a connector's presence in the catalog does not itself mean that ulpi engages it as a subprocessor.
7. Acceptable use
A customer may not use the service to violate law or rights; mislead people about autonomous activity; generate or distribute malware; evade security controls; probe another tenant; exfiltrate credentials; facilitate fraud, harassment, exploitation, unlawful surveillance, or discrimination; operate prohibited weapons or safety-critical systems; or exceed provider, network, or rate limits. Customers must apply human review and any legally required disclosures when an agent communicates or acts externally.
8. Security and credentials
ulpi will maintain the security measures described in the binding DPA and security documentation. Customers must use reasonable access controls, keep secrets out of prompts and logs unless the designated secret mechanism requires them, limit connector scopes, remove departed users, and promptly cooperate with incident response. Credentials supplied for providers or connectors are used only through the configured service path and remain subject to the originating provider's controls.
9. Fees, usage, and taxes
The binding commercial terms will be the prices, included usage, billing interval, currency, and payment terms shown at checkout or in an order form. Usage, seats, model calls, sandbox time, and other stated meters may generate charges. Budget caps are operational controls and do not waive valid charges incurred before a pause. Unless the final terms or law say otherwise, fees are exclusive of taxes and the customer is responsible for applicable taxes other than taxes on ulpi's net income.
10. Renewal, cancellation, and payment failure
A paid subscription will renew only as stated at checkout or in an order form. The final binding version must specify cancellation cut-offs, refunds, credits, free-trial conversion, price-change notice, and payment-failure treatment. ulpi may use a payment processor, suspend paid features after notice for overdue undisputed amounts, and restore service after payment, subject to law and the final commercial terms.
11. Intellectual property and feedback
ulpi and its licensors retain rights in the platform, documentation, design, models or components supplied by ulpi, and improvements to them. Subject to payment and third-party restrictions, the final terms are intended to let the customer use generated WorkProducts for its business and to assign to the customer any rights ulpi may acquire in customer-specific output to the extent legally possible. Feedback may be used without restriction or identification, but customer confidential information may not be disclosed through that use.
12. Confidentiality
Each party must protect the other's non-public information with at least reasonable care and use it only to perform or exercise rights under the agreement. Confidential information excludes information lawfully known without restriction, independently developed, received lawfully from another source, or made public without breach. A compelled recipient may disclose only what is legally required and, where permitted, give advance notice and reasonable assistance.
13. Privacy and data processing
The Privacy Policy describes ulpi's handling of account and service data. When ulpi processes personal data in customer content on the customer's behalf, the binding DPA will apply. The customer is responsible for its privacy notices, lawful basis, instructions, data-subject communications, and any special-category or regulated data it chooses to submit. The customer must not submit data prohibited by the service documentation or an order form.
14. Suspension and service changes
ulpi may suspend affected access when reasonably necessary to prevent security harm, unlawful use, material breach, excessive risk to another tenant or provider, or continued non-payment. Where practicable, ulpi will limit the suspension, explain the reason, and allow remediation. ulpi may modify features and dependencies, but the binding terms should state notice and remedy for a material reduction in purchased core functionality during a committed term.
15. Termination, export, and deletion
Either party may terminate as permitted by the binding order and terms, including for uncured material breach and insolvency. Before termination takes effect, customers should export needed data using available tools. After the applicable retrieval period, ulpi will delete or render inaccessible customer data according to the approved retention schedule, legal holds, backup expiry, and DPA. Company deletion and global account erasure are distinct operations and require confirmation and durable deletion evidence.
16. Warranties and disclaimers
The final agreement should include a limited promise that the service will materially conform to its documentation and that ulpi will provide it using reasonable skill and care, with repair, re-performance, or termination as the agreed remedy. Any disclaimer of implied warranties, uninterrupted availability, third-party services, or generated output must be reviewed for the customer type and governing law before this section becomes binding.
17. Indemnities
The proposed allocation is that the customer defends claims arising from unlawful customer content, instructions, connected accounts, or prohibited use, while ulpi addresses qualifying claims that the unmodified paid platform infringes specified intellectual-property rights. The final scope, exclusions, remedies, control of defence, notice requirements, and any exceptions for model output or third-party components require founder and counsel approval.
18. Limitation of liability
No liability exclusion or cap is approved in this review draft. The binding version must set the aggregate cap, any enhanced or uncapped categories, excluded indirect damages, essential-purpose treatment, and mandatory-law carve-outs. Those choices must be consistent with the service price, insurance, security commitments, indemnities, and launch jurisdictions and must not purport to exclude liability that law does not allow to be excluded.
19. Governing law and disputes
The contracting entity, governing law, forum, dispute-escalation process, arbitration choice, and class-action or jury waivers have not been selected. The binding version must identify them expressly and preserve any non-waivable rights. Until that version is approved and accepted, this review section does not select a law or court.
20. Changes, notices, and contact
ulpi will version legal documents and require renewed acceptance when a material new version applies. The binding terms must state the notice method and advance-notice period. Operational notices may be delivered in-product or to an account email; legal notices require the addresses and delivery rules in the final terms. Draft questions may be sent to support@ulpi.io and security reports to security@ulpi.io; those addresses do not identify the contracting entity.