Sparset Terms of Service
Effective date: September 9, 2026
Last updated: September 9, 2026
Contracting entity: Ora Holdings Corporation, doing business as Sparset
These Terms of Service (the "Terms") govern the business services provided by Ora Holdings Corporation, a Delaware corporation doing business as Sparset ("Sparset," "we," "us," or "our"). They form an agreement with the business or other organization accepting them ("Customer" or "you").
By signing an order that incorporates these Terms or affirmatively accepting them through an acceptance mechanism presented with a link to them, you agree to the Agreement. The individual accepting represents that they have authority to bind Customer. If you lack that authority, you may not activate the Services for that organization. Authorized users must be at least 18 and act within their organization's permissions.
The Services are offered for business and organizational use. These Terms do not waive any rights that applicable law makes non-waivable. Merely visiting a public marketing page does not create a paid subscription or authorize infrastructure access. Our Privacy Policy explains personal information handling; accepting these Terms is not consent to optional marketing or cookies.
1. Agreement structure and definitions
1.1 Agreement documents
The "Agreement" consists of these Terms, their Schedules A and B, and each mutually accepted order form, statement of work, or electronic service order ("Order"). An expressly agreed service-level agreement ("SLA"), security schedule, or other addendum also forms part of the Agreement.
Mandatory law and any applicable executed international transfer clauses take priority. For personal-data processing, Schedule B or a separately executed Data Processing Addendum ("DPA") controls over inconsistent commercial provisions. Subject to that rule, a mutually signed negotiated agreement or addendum controls, followed by the applicable Order, these Terms and Schedule A, and incorporated Documentation. An Order can change a DPA obligation only if it expressly identifies the change and the change is lawful.
The Privacy Policy is a transparency notice and does not expand our contractual rights to use Customer Content. Purchase-order boilerplate or procurement portal terms do not change the Agreement unless expressly accepted in writing by both parties.
1.2 Definitions
- "Services" means Sparset's autonomous inference planning, optimization, compilation, testing, deployment, monitoring, recovery, software, management interfaces, APIs, and related hosting or support expressly included in an Order.
- "Authorized User" means a person Customer permits to use the Services. An "Authorized Administrator" is a user Customer designates to approve deployment plans, production changes, access, and spending within that person's assigned scope.
- "Customer Content" means Customer's models and weights, datasets, prompts, inputs, outputs, files, application data, and other workload content supplied to or processed by the Services. It excludes Sparset Technology and third-party materials as such, without removing Customer's rights in its own contributions.
- "Deployment Environment" means the customer-controlled or expressly agreed hosted infrastructure in which a customer's workload operates, including its authorized test and production resources.
- "Operational Data" means necessary deployment, performance, usage, cost, security, and action metadata. It excludes prompt and output bodies, model weights, datasets, secret values, and content-bearing traces. It may still be confidential or personal information.
- "Sparset Technology" means our agents, orchestration, optimization methods, compiler, runtime, kernels, libraries, management software, interfaces, Documentation, and related technology, including improvements, excluding Customer Content and third-party materials.
- "Documentation" means the service specifications and technical documentation identified in the Order, as updated consistently with the Agreement. Marketing claims and future roadmaps are not independently purchased service commitments.
- "Production Change" means a change that affects a live workload's model, configuration, software, infrastructure, routing, capacity, security, or behavior.
- "Recovery Runbook" means the documented, customer-approved conditions and limited actions for recovering from specified faults, including permitted resources, versions, limits, rollback, and escalation.
2. Scope of the Services
Sparset helps Customer run supported AI models efficiently and reliably on Customer's infrastructure or agreed hosting. Depending on the Order, agents assess a model and target hardware; propose a plan; prepare and optimize an execution configuration; run agreed evaluations; deploy approved changes; monitor operational information; propose further improvements; and perform authorized recovery.
Each Order must identify the purchased scope, Deployment Environment, hosting responsibility, pricing, and any particular evaluation, support, availability, or security commitments. Future products and research objectives are not included unless expressly identified as deliverables. No consumer model catalog, desktop subscription, or unreleased product is included by implication.
A performance improvement depends on the model, hardware, workload, software, and evaluation conditions. Compression, quantization, compilation, batching, caching, and scheduling changes can affect quality, determinism, latency, throughput, compatibility, or cost. We do not guarantee a particular compression ratio, accuracy level, cost saving, hardware fit, or competitor comparison unless a signed Order defines the test and express commitment.
3. Accounts and security responsibilities
Customer must provide accurate account and billing information, appoint Authorized Administrators, protect credentials, and promptly remove access that is no longer appropriate. Customer is responsible for users it authorizes and systems it controls, except to the extent an issue is caused by Sparset's breach or wrongful acts.
Sparset must use granted access only for the authorized service scope, protect credentials entrusted to it, and apply appropriate access restrictions. We will not treat every action using a credential as conclusively authorized where there is evidence of compromise or a service error. Both parties must promptly notify the other of suspected unauthorized access affecting the Services and reasonably cooperate in containment.
Customer must grant only access it is legally and contractually entitled to provide. Credentials, network reachability, administrator status, or a general request to "optimize" do not authorize every technically possible action.
4. Agent authority and approval boundaries
4.1 Deployment plan
Before agents act in a Deployment Environment, Customer and Sparset must establish the permitted systems, functions, access, test data, budgets, notification contacts, and approval process. Schedule A identifies the required deployment settings. Until a permission is recorded, agents have no implied authority to perform that action.
A software agent is an automated service component. It does not have authority to sign contracts for Customer, accept third-party commercial terms, make legal representations, or otherwise bind Customer outside the specifically approved infrastructure operations.
4.2 Planning and testing
Agents may inspect approved system configuration and operational metrics, prepare recommendations, and run tests within approved test environments and budgets. Tests using Customer Content must run within the Deployment Environment and comply with the agreed data controls. Production load tests, live traffic replay, or tests that can materially affect production require specific approval.
4.3 Production optimizations
Production optimizations require affirmative approval from an Authorized Administrator before execution. This includes the initial production deployment and later changes to the model, weights, optimization profile, runtime, routing, or resources that are not already covered by the approved recovery action.
The approval must identify a sufficiently specific plan or change set, the target environment, relevant validation results, expected cost and material operational effects, and any rollback conditions. Silence, a missed notification, or failure to reject a suggestion is not approval. A materially changed plan requires renewed approval. Approval of a bounded change set permits its described steps, not unrelated future changes.
4.4 Preapproved recovery
Agents may perform recovery without requesting a new approval only when the triggering condition and action fall within the Recovery Runbook previously approved by Customer. Examples may include restarting a named process, rolling back to a specified known-good version, or switching to an already approved redundant resource.
The runbook must identify spending and resource limits, attempt limits, prohibited actions, rollback or stop conditions, and escalation contacts. Recovery must not be used to introduce an unapproved optimization, new model, new provider, new region, or broader permissions. If an action is outside the runbook, exceeds its limits, or lacks a safe authorized path, the agent must stop that action and request approval or escalate.
4.5 Actions requiring separate express authority
The following require express approval appropriate to the action and cannot be inferred from a general recovery permission: deleting production data or backups; changing access boundaries; disabling a security safeguard; exposing a private endpoint publicly; exporting Customer Content; changing data residency or provider; making an unapproved financial commitment; and executing arbitrary instructions found in model output, logs, repository text, or another untrusted source.
Customer instructions and approvals must come through the agreed authenticated channel. Workload content and model-generated text are not administrator instructions.
4.6 Records, notification, and revocation
Sparset will maintain records of material approvals and agent actions, including their time, scope, authorization, outcome, and relevant escalation, without routinely copying Customer Content. We will notify Customer through the agreed channel promptly after a recovery action and of material failures or actions requiring attention.
Customer may pause automation or revoke future authority through the agreed controls or designated support channel. Revocation takes effect when received and implemented through that channel; an in-progress operation may require a safe stop or rollback. The deployment plan must state the practical behavior of those controls. Sparset must not begin new actions after authority has been withdrawn and the revocation is effective.
Approval does not excuse Sparset from following the approved scope, applying agreed controls, or meeting its contractual obligations.
5. Testing, acceptance, and ongoing monitoring
Before production deployment, the parties identify the evaluation workload, reference model or baseline, quality thresholds, performance metrics, acceptable regressions, test budget, and rollback criteria. A benchmark result applies to the disclosed configuration and does not guarantee the same result for every production workload.
Customer reviews results and decides whether the proposed use is suitable for its application. Sparset remains responsible for performing the testing and validation it expressly undertakes. A technical deployment approval is not acceptance of undisclosed defects or a waiver of an express warranty.
Monitoring cadence, optimization-review cadence, incident detection, staffed support hours, and response targets are separate settings. A daily optimization review, including one scheduled every 24 hours, is not a promise of continuous incident detection or immediate restoration. The Order must state the included cadence and escalation service. Agents can act only while required access, connectivity, resources, and dependencies are available.
We use commercially reasonable efforts to diagnose and recover covered faults within the agreed authority. "Autonomous" does not mean infallible, uninterrupted, or guaranteed to fix every outage. Only an express SLA establishes an uptime percentage, response deadline, restoration commitment, or service credit.
6. Infrastructure and hosting
6.1 Customer-contracted infrastructure
Where Customer contracts directly with a hosting or data-center provider, Customer maintains that account and is responsible for that provider's charges, terms, and infrastructure responsibilities. Sparset remains responsible for the actions it performs and the service responsibilities assigned to it. Customer's provider is not automatically Sparset's subprocessor merely because Sparset manages software there.
6.2 Sparset-arranged hosting
Where Sparset procures or resells hosting, the Order must identify the provider or agreed selection process, region, capacity, pricing basis, included resources, backup responsibility, support allocation, and any minimum commitment or cancellation charge. Providers we engage to process customer personal data are governed by Schedule B or the separately executed DPA. We remain responsible for obligations we undertake and for our subprocessors as required by that DPA and law.
Hosted infrastructure remains a Deployment Environment even when physically operated by a third party. It is not a representation that content never leaves Customer's premises or that a host cannot process or store content.
6.3 Resource controls and continuity
No agent may create additional resources or incur additional commitments beyond the approved scope and budget. A budget alert is not a hard spending cap unless the Order expressly defines it as one. The Order must distinguish alerts, authorization limits, technically enforced caps, already-running usage, and unavoidable provider commitments.
Existing resources may continue to accrue charges while a new action is awaiting approval or an agent is paused. The deployment plan must specify whether workloads are stopped at a cap and the resulting availability tradeoff. Sparset will not charge Customer for incremental resource consumption caused solely by Sparset acting outside its authorized scope; authorized resource charges remain payable under the Order.
Moving to a new provider or region requires customer approval and applicable data-protection steps. Neither party may assume a provider's continued price, supply, or compatibility is guaranteed. Any approved substitution must respect the Agreement's change and refund provisions.
7. Fees, invoicing, and subscription terms
Fees, currency, billing intervals, metering units, minimum commitments, and payment method are stated in the Order. These may include setup, optimization, software subscription, managed operations, GPU or other compute, storage, bandwidth, and support charges. Hosting is included only if the Order says so. A free software pilot does not waive separately disclosed and accepted infrastructure charges.
Unless the Order states otherwise, undisputed invoices are due 30 days after receipt. Customer must raise an invoice dispute with reasonable detail promptly, preferably within 30 days; a delay does not validate a billing error or waive a non-waivable right. The parties will cooperate on reconciliation, and Customer must pay undisputed amounts when due. Usage records are evidence of consumption, subject to reasonable verification and correction.
Fees exclude applicable transaction taxes unless stated otherwise. Customer is responsible for those taxes, excluding taxes on Sparset's net income. Each party handles legally required withholding and provides reasonably necessary tax documentation.
Subscriptions renew automatically only if the accepted Order clearly states the renewal term, price or pricing mechanism, and cancellation method. If automatic renewal is not expressly agreed, the subscription ends at its stated term. Unless the Order specifies another period, an agreed auto-renewal may be stopped by either party on at least 30 days' written notice before renewal. A future renewal price increase requires at least 30 days' notice before Customer's non-renewal deadline and any additional legally required notice.
We do not increase fixed fees during a committed term without agreement. Variable provider charges may change only according to the pricing mechanism Customer accepted. Fees are otherwise non-refundable except as expressly provided in the Agreement or required by law. No automatic paid conversion of a trial occurs without Customer's express agreement to the paid terms.
8. Software license and permitted customer applications
Subject to the Agreement and payment of applicable fees, Sparset grants Customer a limited, non-exclusive license during the purchased term to install and use the supplied Sparset Technology in approved environments for Customer's business operations and to provide the customer applications identified in the Order.
Customer may allow its own end users to access those applications through Customer's application interfaces. This does not permit end users to administer Sparset's platform, obtain Sparset software or credentials, or receive a sublicense to Sparset Technology. Customer remains responsible for its application and end-user relationship.
Customer may not copy, distribute, sublicense, resell, modify, or make derivative works of Sparset Technology except as expressly authorized; remove proprietary notices; evade access, license, or usage controls; or reverse engineer non-public Sparset Technology except where applicable law or an applicable open-source license permits it. These restrictions do not limit Customer's rights in its own models, data, and application code or rights independently granted by third-party licenses.
Updates affecting production remain subject to Section 4. Emergency security measures taken to protect Sparset's own service do not grant unrestricted authority to change Customer's infrastructure. Supported-version requirements and end-of-support dates will be communicated with reasonable notice, subject to urgent security or legal requirements.
9. Ownership and use of information
9.1 Customer models, data, and outputs
As between the parties, Customer retains its rights in Customer Content, including its models, weights, training data, fine-tunes, and application code. Using the Services or optimizing a model does not transfer those underlying rights to Sparset. Third-party models remain subject to their owners' rights and licenses.
To the extent Sparset acquires transferable rights in inference outputs generated specifically for Customer, Sparset assigns those rights to Customer, excluding Sparset Technology and third-party materials. Outputs may not be unique or legally protectable and may be subject to third-party rights.
9.2 Sparset technology and optimized artifacts
Sparset retains its rights in Sparset Technology and improvements to that technology. An optimized deployment package may combine Customer's model with Sparset's runtime, compiled execution components, kernels, or other technology. Ownership is allocated by component: Customer retains its underlying model and content rights; Sparset retains its technology rights. We do not claim ownership of Customer's model merely because a transformation was performed.
The Order must identify deliverable artifacts and whether Customer receives a term license or an express continuing license to any embedded Sparset components. Without an express continuing license, termination ends the right to execute embedded Sparset Technology, but does not transfer or extinguish Customer's rights in its own model or data. Customer may use those independently with other technology, subject to applicable licenses.
9.3 Limited processing permission
Customer authorizes Sparset to access and process Customer Content only as necessary to carry out documented service instructions within the Deployment Environment, perform separately authorized support, and meet a specific legal obligation. This includes approved technical transformations necessary to optimize or execute Customer's model. Any compelled processing is limited to what law requires, with notice where permitted.
This permission is limited to the service purpose and duration, including agreed return/deletion and mandatory retention. It is not a general license to collect content into our management systems, sell it, disclose it to unrelated parties, publish it, or use it for independent research, shared datasets, or model development.
9.4 No training and operational information
Sparset will not use Customer Content to train or fine-tune its own or third-party models or improve models for other customers. Customer-specific training requires a separate written agreement specifying the model, data, purpose, and rights. External AI planning services must not receive Customer Content under the standard configuration.
We may process Operational Data to deliver, bill, secure, troubleshoot, and maintain the Services, subject to confidentiality and the applicable privacy roles. We may use aggregated or properly de-identified operational statistics for service improvement and capacity planning, provided they do not reveal Customer Content, identify Customer or a person, or disclose Customer's confidential information. Identifiable deployment metrics are not automatically ours to publish as benchmarks.
9.5 Feedback and publicity
Customer may voluntarily provide suggestions. Customer grants Sparset a non-exclusive, perpetual, royalty-free right to use those suggestions to improve its services. That permission excludes Customer Content, personal information, and confidential information embedded in the feedback unless separately authorized for that use.
Neither party may publish the other's name, logo, non-public deployment results, or case study without prior written permission. A free pilot does not itself grant a case-study or publicity license.
10. Privacy, confidentiality, and security
10.1 Data handling
The standard service keeps Customer Content inside the Deployment Environment and transmits only necessary Operational Data and service administration information to Sparset's management systems. Content-bearing diagnostics, remote human inspection, or content transfer require separately documented authorization identifying purpose, scope, access, location, and retention. Approval of an infrastructure action is not approval for content export.
Content may be stored or processed inside the Deployment Environment by its runtime, host, caches, and agreed backups. No global "zero retention," exclusive customer access, or geographic guarantee is implied. Any stricter commitment must identify its covered systems, data, exceptions, and providers in writing. Processing personal data is governed by Schedule B or the separately executed DPA, including where a provider processes content without Sparset retaining a separate copy.
10.2 Mutual confidentiality
"Confidential Information" means non-public information disclosed or accessed in connection with the Agreement that is marked confidential or reasonably understood to be confidential, including Customer Content, credentials, operational configurations, non-public technology, security information, and negotiated business terms.
The recipient will use it only to perform the Agreement or exercise rights under it, protect it with at least reasonable care, and disclose it only to people and providers with a need to know who are subject to appropriate confidentiality duties. Information is excluded only if the recipient can show it was lawfully known without restriction, independently developed without using the information, lawfully received without a duty of confidence, or became public without breach.
Legally compelled disclosure is permitted only to the extent required, with advance notice where lawful and reasonable assistance in seeking protection. Ordinary confidentiality duties continue for three years after termination; protection of trade secrets continues while they remain trade secrets, and protections for personal information and retained Customer Content continue for as long as the information is retained.
10.3 Security and incidents
Each party maintains safeguards appropriate to its responsibilities and the risks. Sparset's processor security obligations are in Schedule B and the agreed security schedule. Customer manages its own identity assignments, lawful data use, infrastructure not assigned to Sparset, and downstream application security. No responsibility assigned to Customer excuses a breach by Sparset.
Sparset will notify Customer without undue delay after becoming aware of a personal data breach affecting data processed on Customer's behalf, and meet any stricter applicable legal or agreed deadline. It will not delay initial notice until an investigation is complete. Material service-security incidents without a personal data breach will be communicated promptly where relevant to Customer's protection or service continuity.
Security contact: security@sparset.ai
11. Customer obligations and acceptable use
Customer must have the rights, notices, consents, and other lawful basis needed for its models, data, instructions, and application. Customer must comply with applicable model licenses and identify material restrictions that affect optimization, hosting, commercial use, redistribution, or access.
Customer must not use or permit use of the Services for unlawful activity; infringement or misappropriation; fraud or deceptive impersonation; child sexual exploitation or non-consensual intimate imagery; terrorism or unlawful weapons activity; unauthorized surveillance; credential theft, malware, or unauthorized intrusion; unlawful discrimination; or evasion of access, security, or resource controls. Authorized defensive security work is permitted within a written scope that protects other customers and the service.
Customer must not authorize agents to control weapons or safety-critical physical systems where a failure could reasonably cause death or serious injury. The standard Services are not a substitute for qualified human decisions or required safeguards in healthcare, employment, credit, insurance, housing, education, legal matters, or other consequential applications. Any permitted regulated use requires applicable testing, oversight, notices, review mechanisms, and legal compliance.
Protected health information subject to HIPAA, payment-card authentication data, classified information, controlled technical data, and similarly regulated workloads require our prior written agreement and any required additional contracts and controls. A health-related model or an isolated server does not by itself establish HIPAA compliance. Other sensitive or children's data must be identified in the processing schedule and authorized with appropriate safeguards before processing.
Each party is responsible for laws applicable to its actual activities, including privacy, AI, export controls, and sanctions. Neither party is relieved of statutory provider, deployer, processor, or other obligations by the labels in this Agreement. Customer must identify a regulated intended use; material model or system changes must be assessed for resulting obligations before deployment. The Services may not be used in a prohibited transaction or supplied to a prohibited party under applicable sanctions or export laws.
12. Third-party materials
Models, open-source components, drivers, repositories, and customer-selected integrations may carry separate terms. Those terms govern the relevant component and any independently granted rights. Sparset will make applicable notices available for third-party components it supplies; Customer must provide relevant notices for materials it supplies.
Neither party may authorize use beyond the rights it holds. If a material license or provider restriction prevents an agreed use, the parties will seek an authorized alternative. A change of model, provider, or deployment configuration remains subject to approval. If Sparset cannot continue a material paid service and no mutually acceptable substitute is available, Customer may terminate the affected service and receive a refund of prepaid unused service fees, subject to lawful, previously approved, non-cancelable third-party commitments.
We do not give warranties on an independent third-party model or Customer-contracted provider. This does not excuse Sparset's own obligations, its selection or management duties expressly assumed in an Order, or its subprocessor responsibilities.
13. Trials, pilots, and experimental features
A trial or pilot has the duration, scope, production permissions, and infrastructure charges stated in its Order. Beta and experimental features are for evaluation unless production use is expressly agreed. They may be less reliable and carry no performance warranty or SLA unless expressly agreed.
The approval boundaries, limited data-use permissions, confidentiality, applicable security duties, and DPA continue to apply to free and experimental services. No special training or publicity rights arise from free use.
14. Service changes, suspension, and remediation
We may improve the Services, provided changes do not materially reduce purchased functionality, security commitments, or agreed data protections during a committed term. We will give reasonable advance notice of a material discontinuation, except where urgent legal or security circumstances require shorter notice. If a material paid function is removed without a substantially equivalent acceptable replacement, Customer may terminate the affected service and receive a refund of prepaid unused fees.
Sparset may proportionately suspend affected access when reasonably necessary to address an immediate security risk, unlawful use, a binding legal requirement, or a material breach. For nonpayment of undisputed amounts, we will give at least 10 days' written notice and an opportunity to pay before suspension. A good-faith billing dispute alone does not justify suspension if undisputed amounts are paid.
We will give prior notice and an opportunity to resolve the issue where reasonably practicable, limit suspension to the necessary scope and duration, and restore service promptly when the basis is resolved. Suspension does not authorize deletion of Customer's models or data, destructive action on its infrastructure, or undisclosed ongoing spending. Any continuing approved hosting costs and available export arrangements must be explained.
15. Term, termination, and transition
The Agreement begins on acceptance; each service term is stated in its Order. Either party may terminate for the other's material breach if it remains uncured 30 days after written notice, or after 10 days for nonpayment of undisputed amounts. An incurable material breach or legally prohibited service may justify immediate termination. Any termination for insolvency applies only to the extent permitted by law.
Customer may stop renewal under Section 7. Early convenience termination of a committed Order is available only if that Order permits it. If Customer terminates because of Sparset's uncured material breach, Sparset refunds prepaid fees for the unused portion of the affected service. Accrued, properly authorized charges remain payable; disputed charges remain subject to resolution.
At termination, Sparset will stop new agent actions, cooperate on a safe shutdown or agreed handoff, and revoke its access when no longer needed. Customer must stop using term-licensed Sparset Technology, except during an expressly agreed transition period or under continuing license rights. Customer retains its own models, data, and independently licensed components.
Unless a different period is agreed or law requires earlier deletion, Sparset will offer 30 days after termination to retrieve Customer Content and customer-specific configuration or action records held by Sparset in an available standard format, subject to identity verification and the DPA. This is an export opportunity, not free production hosting or a right to Sparset source code. Any hosting necessary to retain an environment during transition requires an agreed charge and authorization; absent that agreement, export must be arranged before the hosting ends. Customer data already on Customer's systems remains under its control.
Sparset will return or delete customer personal data as directed under Schedule B. The Order must address any continuing host contract, storage, backup cycle, and decommissioning responsibility. We will not delete customer-owned infrastructure or original models merely because a software license ends. Additional migration work may be separately priced and accepted.
Provisions concerning accrued payment, ownership, confidentiality, permitted retention and deletion, indemnification, liability, disputes, and other provisions that reasonably need to survive will survive termination.
16. Warranties and remedies
Each party represents that it has authority to enter the Agreement. Sparset warrants that paid, generally available Services will materially conform to the agreed Documentation and that professional services will be performed with reasonable skill and care. Customer must provide reasonable details of a claimed nonconformity.
Sparset will use commercially reasonable efforts to correct a verified breach or reperform the affected service. If it cannot do so within 30 days after notice, or a different reasonable period the parties agree, Customer may terminate the affected service and receive a refund of prepaid unused fees. This is the exclusive remedy for that performance-warranty breach, but does not limit separate data-protection, confidentiality, unauthorized-action, or other obligations, or remedies that cannot lawfully be limited. Any SLA identifies how service credits interact with other remedies; there is no double recovery for the same loss.
The warranty excludes problems caused by unauthorized Customer modifications, misuse, unsupported configurations, or independent components outside Sparset's responsibility, only to the extent those causes produced the problem. Trial and experimental services have no performance warranty unless agreed.
17. Disclaimers
Except for express commitments in the Agreement and to the extent law permits, the Services and third-party materials are provided "as is" and "as available." Sparset disclaims implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
AI outputs and agent recommendations may be inaccurate, incomplete, non-unique, or unsuitable. We do not warrant that the Services will be uninterrupted, every fault will be detected or resolved, or every optimization will preserve all model behavior. Customer must apply appropriate evaluation and human oversight to its application. These disclaimers do not authorize Sparset to exceed an approval, disregard the Recovery Runbook, or avoid its express security and data-protection commitments.
Nothing excludes a warranty, duty, or remedy that cannot lawfully be excluded.
18. Third-party claims
18.1 Customer indemnity
Customer will defend Sparset against third-party claims that Customer-supplied content infringes intellectual-property rights or that Customer's unlawful or Agreement-breaching use of the Services violates a third party's rights, and pay resulting damages finally awarded or settlements Customer approves. This obligation excludes claims to the extent caused by Sparset's breach, unauthorized processing or modification, negligence, or willful misconduct.
18.2 Sparset indemnity
For paid Services, Sparset will defend Customer against third-party claims that Sparset Technology, used as authorized, infringes a patent, copyright, or trademark, or misappropriates a trade secret, enforceable in the United States, Canada, the UK, or the EEA, and pay resulting damages finally awarded or settlements Sparset approves.
This obligation excludes claims arising from Customer Content, independent third-party materials, modifications not made or authorized by Sparset, combinations not supplied or required by Sparset, use outside the Agreement, or continued infringing use after Sparset provides notice and a reasonably adequate non-infringing alternative, in each case only to the extent the claim would not otherwise arise. It does not cover a claim merely because an inference output is generated by a third-party model.
If a claim is likely, Sparset may obtain continued rights, provide a materially equivalent non-infringing replacement, or terminate the affected service and refund prepaid unused fees. A production replacement still requires approval. Customer may terminate with that refund if the offered replacement materially reduces the agreed service.
18.3 Procedure
The party requesting protection must give prompt notice, reasonable assistance at the defending party's expense, and control of the defense to that party. Late notice reduces the obligation only to the extent it materially prejudices the defense. No settlement may admit fault, impose non-monetary obligations, or leave liability on the protected party without its written consent, not unreasonably withheld. These obligations are subject to Section 19 unless a signed Order expressly changes that allocation.
19. Limits on liability
19.1 Excluded losses
To the extent permitted by law and subject to Section 19.4, neither party is liable for indirect, consequential, special, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or anticipated savings, arising out of the Agreement. Reasonable direct costs of investigating an incident, restoring affected data or systems, and giving required breach notices are not excluded solely because they relate to a security or data incident; they remain subject to the applicable cap. Amounts payable to a third party under Section 18 are not excluded solely because the third party's award includes a listed category.
19.2 General cap
Each party's aggregate liability arising out of or relating to the Agreement will not exceed the fees paid or payable under the affected Order during the 12 months preceding the first event giving rise to the claim. If services have been provided for fewer than 12 months, the cap is the fees paid or payable for the first 12 months of that Order, or its entire shorter stated term. For a wholly free trial with no paid Order, the cap is US $1,000.
19.3 Higher cap
For breach of confidentiality, data-protection or security obligations, and indemnity obligations under Section 18, a combined aggregate cap of twice the general cap applies. Claims within the general cap count toward this higher cap; the caps do not stack. Different limits may be agreed in a signed Order.
19.4 Exceptions and mandatory rights
The caps and exclusions do not limit Customer's properly payable fees, either party's fraud or fraudulent misrepresentation, willful misconduct or gross negligence, death or personal injury caused by negligence where liability cannot be limited, deliberate infringement or misappropriation of the other party's intellectual property, or any liability that cannot lawfully be excluded or limited. These Terms do not limit an individual's statutory rights or override liability and rights under applicable international transfer clauses.
The limitations apply across legal theories and related claims, subject to mandatory law. Each party must take reasonable steps to mitigate its losses. The agreed fees and limits reflect the parties' allocation of commercial risk.
20. Governing law and disputes
The Agreement is governed by Delaware law, excluding conflict-of-laws rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
Before bringing a contractual claim, each party will give written notice and attempt in good faith to resolve it for 30 days. This does not prevent urgent interim relief, a filing needed to preserve a legal deadline, a regulatory complaint, or exercise of non-waivable rights.
Subject to mandatory law and any controlling transfer clauses, the state courts located in Delaware and the United States District Court for the District of Delaware have exclusive jurisdiction, and each party consents to jurisdiction and venue. There is no contractual shortening of statutory claim periods. No mandatory arbitration or class-action waiver is imposed by these Terms.
21. Changes to the Agreement
The version accepted for an Order governs its committed term unless the parties agree a change or a narrowly necessary change is required by law. Website updates alone do not rewrite a negotiated Order or expand data-use rights. We will notify Customer of a legally required change and its scope promptly.
For a renewal or a new Order, we may propose updated Terms with at least 30 days' notice before Customer's applicable non-renewal deadline for material changes. We will obtain acceptance where required. New processing purposes, broader production authority, and content export are subject to their own authorization requirements and are not authorized merely by continued use.
22. General provisions and notices
Neither party may assign the Agreement without consent, not unreasonably withheld, except to a successor in a merger, reorganization, or sale of substantially all relevant assets if the successor assumes the obligations and the assignment does not materially reduce agreed protections. The assigning party must notify the other. An assignment does not expand permitted use of Customer Content.
The parties are independent contractors. Neither is the other's general agent, partner, employer, or fiduciary. Except for expressly protected third parties in Section 18 and mandatory rights under data-protection instruments, no third party acquires contractual enforcement rights.
Neither party is responsible for a delay caused by an event beyond its reasonable control if it promptly notifies the other and uses reasonable mitigation efforts. A preventable security failure, failure to fund resources, or failure to implement an agreed redundancy is not excused merely because a third party is involved. Payment for services already provided remains due. If a force-majeure interruption continues for 30 days, either party may terminate the affected service; prepaid unused fees will be refunded, subject to disclosed, accepted, non-cancelable provider commitments and applicable law.
If a provision is unenforceable, it is severed or limited only to the extent law allows, and the remainder continues. Failure to enforce a provision is not a waiver. The Agreement is the complete agreement for its subject matter and supersedes prior proposals on that subject, without excluding liability for fraud or rights that cannot be excluded. Electronic acceptance and signatures may form binding agreements.
We provide notices to Customer's designated administrator or contractual contact. Legal notices to Sparset must be sent to the contact below. Email notice is effective when received; automated failure messages are not receipt. For material contract notices, the sender must use another agreed delivery method if delivery fails. Routine service notifications may use the agreed operational channel.
Ora Holdings Corporation, doing business as Sparset
Attn: Legal
Mailing address: 16192 Coastal Hwy, Lewes, DE 19958
Legal notices: legal@sparset.ai
Privacy requests: privacy@sparset.ai
Schedule A — Deployment and authorization requirements
This Schedule is part of the Agreement. Complete the applicable details in the Order or a versioned deployment plan accepted by both parties before production access. An omitted permission is not granted; an omitted paid feature or SLA is not promised.
| Required item | What the parties must record |
|---|---|
| Model and intended use | Model and version; source and license; Customer's rights; intended application; material restrictions or regulated use |
| Environment and hosting | Test and production resource identifiers; provider; region; who contracts with the provider; who controls accounts, encryption keys, backups, and network access |
| Service scope | Planning, optimization, testing, deployment, monitoring, recovery, and support functions purchased; exclusions and deliverables |
| Access | Permitted users, service identities, secrets handling, least-privilege scope, remote-access method, and access expiry or revocation |
| Data boundary | Content processed inside the environment; Operational Data fields allowed to leave; destinations; external planner inputs; human access; support authorization; retention and deletion |
| Validation | Baseline and workload; quality and performance thresholds; regression limits; production-test authorization; acceptance evidence |
| Production approval | Authorized approvers and authenticated channel; specific change set; target version; approval expiry if applicable; notification recipients |
| Recovery Runbook | Fault triggers; permitted actions and versions; retry limits; prohibited actions; resource and spending limits; rollback, stop, and escalation conditions |
| Cost | Units and rates; spending authorization; alert thresholds versus hard caps; effect on running workloads; pass-through charges and minimum commitments |
| Monitoring and support | Health-check frequency; daily or other optimization-review cadence; incident detection; support hours; response targets only if expressly purchased; escalation contacts |
| Pause and continuity | How automation is paused; how in-flight operations stop; fallback access; backup and restoration duties; behavior during connectivity loss |
| Exit and artifacts | Deliverables; embedded technology licenses; export format and window; host cancellation; handoff and decommissioning responsibilities |
| Privacy schedules | DPA processing details; security measures; initial subprocessor list; locations; any required transfer documentation |
Schedule B — Data Processing Addendum
B1. Scope and roles
This DPA applies whenever Sparset processes personal data on Customer's behalf in providing the Services ("Customer Personal Data"), including relevant content, operational records, and support data. "Applicable Data Protection Law" means the privacy and data-protection laws applicable to that processing, including the GDPR, UK GDPR and applicable UK legislation, applicable Canadian federal or provincial law, and applicable US state privacy law.
Customer is controller and Sparset processor, or Customer is a processor acting under a controller's authority and Sparset its subprocessor, as applicable. Customer must have authority for its instructions. Independent controller activities described in the Privacy Policy are outside this DPA; data collected on Customer's behalf cannot be reclassified to avoid these restrictions.
This DPA governs processing that actually occurs; it neither authorizes prohibited content collection nor assumes every software deployment makes Sparset a processor. A separately executed DPA supersedes this Schedule only to its stated extent.
B2. Documented instructions and purpose restrictions
Sparset processes Customer Personal Data only on documented instructions in the Agreement, the completed deployment and processing schedules, and properly authorized service or support requests, unless a binding law requires otherwise. Sparset will inform Customer before legally required processing unless that law prohibits notice. If Sparset believes an instruction infringes Applicable Data Protection Law, it will inform Customer promptly and suspend that instruction pending clarification where appropriate.
Sparset will not sell or share Customer Personal Data, use it for targeted advertising or its own model training, or retain, use, or disclose it outside the specified service purposes and direct business relationship except as law permits or requires. It will not combine it with personal data from other customers or unrelated sources except where expressly permitted by applicable service-provider law and consistent with the Agreement. Generic feedback or improvement provisions do not override these limits.
B3. Personnel and safeguards
Sparset will ensure that personnel with access are bound by confidentiality obligations and have access only as necessary for their assigned duties. It will implement appropriate technical and organizational measures under Applicable Data Protection Law and the specific security schedule completed under B12. Measures will account for the nature, scope, context, purpose, and risks of processing.
Sparset will not materially reduce agreed protections during the service term. Customer remains responsible for safeguards assigned to Customer; that allocation does not waive Sparset's own duties.
B4. Subprocessors
Customer grants general written authorization for subprocessors identified in a current list supplied before relevant processing begins. The list must identify each entity, function, processing location, and relevant data. No unidentified initial provider is approved merely because this DPA refers to a list.
Sparset will give at least 30 days' advance written notice of a proposed new or replacement subprocessor before that provider processes Customer Personal Data. Customer may object within that period on reasonable data-protection grounds. The parties will seek a reasonable alternative; if none is available, Customer may terminate the affected service before the change and receive prepaid unused fees for that service. An urgent need does not dispense with authorization required by law; a shorter process requires appropriate specific written authorization.
Sparset will impose data-protection obligations on subprocessors that provide the protection required by this DPA and applicable law, and remain responsible for their performance of those obligations. Customer-contracted providers are not Sparset subprocessors unless Sparset separately engages them in that capacity.
B5. Requests and assistance
Sparset will promptly refer requests relating to Customer Personal Data to Customer, unless law requires otherwise, and not independently respond substantively without instructions. Taking into account the nature of processing and information available, Sparset will reasonably assist Customer with access, correction, deletion, portability, objection, restriction, and other applicable individual rights.
Sparset will also provide reasonable assistance with security obligations, impact assessments, prior regulatory consultation, and required notifications. The parties may agree reasonable fees in advance for extraordinary assistance not caused by Sparset's breach, but fees must not prevent compliance with a mandatory deadline or obligation.
B6. Personal data breaches
A "Personal Data Breach" is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Sparset or its subprocessors.
Sparset will notify Customer without undue delay after becoming aware of a Personal Data Breach and within any stricter lawful or agreed deadline. Initial notice may be supplemented in phases and will not await final confirmation of every fact. It will provide known details of the incident, affected data and individuals where reasonably ascertainable, likely consequences, mitigation, and a contact for updates.
Sparset will take reasonable measures to contain, investigate, and remediate the breach, preserve relevant evidence, and assist Customer. Customer determines its regulatory and individual notifications, without restricting Sparset's own mandatory duties. A notification is not itself an admission of liability.
B7. Return, deletion, and retention
At Customer's choice, Sparset will return or delete Customer Personal Data at the end of the service or on a valid instruction, and delete existing copies unless law requires retention. Timing, format, and any necessary export period must be documented under B11 and coordinated with Section 15. Backup copies remain protected, unavailable for ordinary use, and are removed within the documented maximum backup period. A restore must reapply deletion instructions before ordinary use.
Legally retained data is limited to the required data and purpose and deleted when retention is no longer required. Sparset will confirm completion on request. Data solely in Customer-controlled systems is deleted by Customer unless Customer expressly instructs and authorizes Sparset to do it.
B8. Information, audits, and remediation
Sparset will make available information reasonably necessary to demonstrate compliance and allow and contribute to audits, including inspections, by Customer or its authorized independent auditor. Existing security documentation may satisfy a routine request where sufficient; it does not replace an audit required by law or justified by credible evidence of a material issue.
Routine audits may be coordinated on reasonable notice during business hours and generally limited to one per year. That administrative limit does not apply to a regulator's request, a relevant material breach, or another audit required by law. Confidentiality, scope, security, and non-disruption arrangements must protect other customers without preventing meaningful verification. Each party bears its own ordinary costs; Sparset bears reasonable additional audit costs attributable to its material breach.
Where applicable, Customer may take reasonable and appropriate steps to verify lawful use and stop and remediate unauthorized use. Sparset will promptly notify Customer if it can no longer meet its obligations, cooperate on remediation, and stop affected processing if lawful compliance cannot be restored. Sparset certifies, where required by applicable service-provider law, that it understands and will comply with these restrictions.
B9. International transfers
Processing locations and remote-access countries must be identified in the processing schedule and subprocessor list. Neither an Order nor this DPA by itself establishes a lawful restricted international transfer.
Before a transfer that requires safeguards begins, the parties will put the appropriate mechanism in place. Where relying on European Commission Standard Contractual Clauses, the applicable module, parties, competent authority, governing-law and forum selections, processing annex, and technical measures must be completed. Relevant UK transfers require a valid UK instrument, such as the applicable UK Addendum to those clauses or an International Data Transfer Agreement. Required transfer assessments and supplementary measures must also be completed.
The official transfer clauses control over inconsistent commercial terms. Until an applicable lawful mechanism is in place, Sparset must not initiate the restricted transfer, including remote access that constitutes such a transfer. A contractual residence preference, a link to the clauses, or an incomplete annex is not a substitute.
For Canadian data, Sparset will provide the contractual and other protections required for entrusted information, disclose agreed foreign processing locations, and reasonably assist with applicable assessments. It will notify Customer of legally binding access requests where permitted and limit disclosure to what is legally required.
B10. Duration and priority
This DPA applies while Sparset or its subprocessors process Customer Personal Data, including any permitted retention after termination. It prevails on data-protection matters as specified in Section 1. Liability allocation between the parties is governed by the Agreement only to the extent consistent with Applicable Data Protection Law and controlling transfer instruments. Nothing limits an individual's or regulator's statutory powers or rights.
B11. Processing particulars — complete before processing
The parties must record the following particulars in the Order or attached processing schedule. No unspecified sensitive category or new processing purpose is authorized by this table.
| Particular | Required description |
|---|---|
| Parties and contacts | Customer legal entity, address, controller/processor role, upstream authority if relevant, and privacy/security contacts; Sparset legal entity and contact details from Section 22 |
| Subject matter | Purchased autonomous inference management and any expressly authorized hosting, evaluation, diagnostics, or support |
| Nature and purpose | Exact activities: in-environment execution and optimization; operational monitoring and action recording; authorized hosting or access; specific support activity where approved |
| Duration and frequency | Service term and actual processing frequency; authorized support period; active deletion, return, and backup-deletion deadlines |
| Data subjects | Applicable groups, such as Customer personnel, contractors, application users, and customers; identify others actually included |
| Personal-data types | Actual administrative and operational fields; workload personal-data types processed inside the environment; separately approved support data |
| Sensitive information | Either none authorized, or exact categories, lawful instructions, additional controls, access restrictions, and retention |
| Systems and geography | Environment, management systems, remote-access locations, data flows, initial subprocessors, and permitted countries |
| Customer rights and duties | Instructions, lawful basis and transparency, user permissions, safeguards for Customer-controlled systems, and the rights in this DPA |
| Transfer safeguards | Applicable mechanism and completed official documents or documented reason no restricted transfer occurs |
B12. Security schedule — minimum commitments and implementation particulars
Sparset will maintain the following baseline measures for processing within its responsibility. Before processing, the parties must attach deployment-specific implementation details sufficient to assess the safeguards; the descriptions below are not assertions of a particular certification or a completed transfer annex.
| Control | Baseline commitment and particulars to document |
|---|---|
| Access and personnel | Least-privilege access, role separation where appropriate, confidentiality, access review, and prompt removal; document privileged authentication, including MFA where supported, and approval owners |
| Data boundaries | Keep Customer Content in the agreed environment; exclude it from management telemetry; document allowed fields, destinations, redaction, and support exceptions |
| Encryption and secrets | Protect data in transit and stored data within Sparset-managed systems with encryption appropriate to risk; document protocols, storage coverage, key control, secret storage, and rotation |
| Tenant and network protection | Separate customer access and workloads as appropriate; restrict management endpoints; document host isolation and network responsibility |
| Change control | Enforce production approval, bounded runbooks, budget checks, scoped identities, and action records; document pause, rollback, retry, and escalation behavior |
| Secure development | Apply proportionate review, testing, dependency management, vulnerability intake, and remediation; document patch responsibility and response process |
| Incident handling | Maintain detection, escalation, containment, investigation, notice, and recovery processes; document contacts and any contracted deadlines |
| Resilience | Document backup scope, recovery responsibilities, restoration testing, and dependencies; no unpurchased workload backup service is implied |
| Retention and disposal | Apply agreed active and backup periods, access revocation, deletion, and restore handling; document maximum periods |
| Provider oversight | Assess relevant providers, obtain processing contracts, control changes, and maintain current locations and access information |
| Verification | Review measures periodically and after material changes; document the actual assessment process without implying an unheld certification or unaudited standard |
Related document: Privacy Policy.