SUCH MUCH AI TERMS OF SERVICE

Effective Date: 21 August 2026

These Terms of Service (the “Terms”) govern access to and use of the websites located at https://suchmuchai.com/ and related domains, the application available at https://app.suchmuchai.com/, and the related software, APIs, dashboards, exports, support, documentation, and professional services made available under the Such Much AI brand (collectively, the “Services”).

UAB Such Much AI, a private limited liability company incorporated in Lithuania, company code 306405204, registered address Bukčių g. 6-38, Vilnius, LT-04127, Lithuania, VAT number LT100017966319, is the principal operating company of the Such Much AI brand and the primary operator and administrator of the Services (the “Platform Operator”).

Depending on the Customer’s location, procurement arrangement, and applicable Order Form, an Authorized Supplier may also market, sell, resell, supply, invoice, or support the Services, including SIA “Such Much AI” and Such Much AI, Inc. The legal entity identified as the supplier or service provider in the applicable Order Form is the Customer’s Contracting Entity.

The Platform Operator and each Authorized Supplier are separate legal persons. No Such Much AI entity becomes a party to an Order Form or assumes liability for another Such Much AI entity’s obligations merely because it operates under the same brand, is affiliated with that entity, provides technical infrastructure or assists with performance of the Services, except where expressly agreed in writing or required by mandatory law.

By creating an Account, placing an order, signing or accepting an Order Form, clicking to accept these Terms, or otherwise accessing or using the Services, the Customer agrees to these Terms with the applicable Contracting Entity. A person accepting these Terms on behalf of an organization represents and warrants that they have authority to bind that organization.

1. Definitions

1.1 “Account” means a registered profile used to access the Services.

1.2 “Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a party. “Control” means direct or indirect ownership of more than 50% of the voting interests or the legal power to direct the management of the entity.

1.3 “Authorized Supplier” means a legal entity authorized to market, sell, resell, supply, invoice or support the Services, including:

  1. SIA “Such Much AI”, registration number 40203701469, registered address Ropažu iela 7–8, Rīga, Latvia;
  2. Such Much AI, Inc., a corporation incorporated in the State of Delaware, United States; and
  3. another entity expressly identified as an authorized supplier or reseller in an applicable Order Form.

1.4 “Contracting Entity” means the legal entity expressly identified as the supplier or service provider in the applicable Order Form. If no Contracting Entity is identified in an Order Form or during the applicable online ordering process, the Contracting Entity is UAB Such Much AI.

1.5 “Customer” means the legal entity, public authority, organization or other person that enters into these Terms or an Order Form and, where relevant, its authorized users.

1.6 “Customer Data” means any data, text, files, documents, prompts, instructions, images, audio or video recordings, inputs and other content submitted to the Services by or on behalf of the Customer, including personal data contained in that content.

1.7 “Documentation” means the user guides, instructions for use, product descriptions, technical documentation, API documentation, onboarding materials and other materials describing the intended use, operation and limitations of the Services made available by or on behalf of Such Much AI.

1.8 “DPA” means the Data Processing Terms in Annex 1 and any additional data-processing agreement incorporated into or attached to an applicable Order Form.

1.9 “Group Company” means UAB Such Much AI, SIA “Such Much AI”, Such Much AI, Inc., and any of their respective Affiliates.

1.10 “Order Form” means an ordering document, signed proposal, procurement agreement, purchase order, statement of work, subscription confirmation or other written or electronic ordering instrument that identifies the applicable Services and incorporates or references these Terms.

1.11 “Output” means content generated, returned, suggested, transformed or exported by the Services based on Customer Data or user instructions.

1.12 “Platform Operator” means UAB Such Much AI in its capacity as the principal operator and administrator of the Services.

1.13 “Policies” means the then-current policies referenced by these Terms, including the Privacy Policy and any acceptable-use, security, support or similar policies made available through the Services or Such Much AI websites.

1.14 “Professional Services” means consulting or services described in an applicable Order Form or statement of work, including custom templates, integrations, onboarding, training, workflow configuration and related implementation services.

1.15 “Services” has the meaning given in the introductory section of these Terms.

1.16 “Term” means the period during which these Terms and the applicable Order Form remain in effect.

References in these Terms to “Such Much AI”, “we”, “us” or “our” mean the applicable Contracting Entity. Where the context concerns technical operation, hosting, security or administration of the platform, those references may also include the Platform Operator solely in its capacity as Platform Operator or authorized subprocessor.

2. Intended Customer Type; B2B/B2G Positioning; Consumer Rights

2.1 Intended Customer Type. The Services are designed and offered primarily for business, professional, institutional, and public-sector use (B2B/B2G). We do not actively market paid plans as consumer services.

2.2 Business-Use Representation. By entering into these Terms or using paid Services, the Customer represents that it acts in the course of trade, business, profession or public administration and that the person accepting these Terms has authority to act on its behalf.

2.3 Consumer Fallback. If a natural person uses the Services outside their trade, business, profession or public function, mandatory consumer-protection rules may apply. Provisions of these Terms that conflict with non-waivable consumer rights will apply only to the extent permitted by law.

3. Contract Formation and Order of Precedence

3.1 Contracting Party. The contract for the Services is entered into solely between the Customer and the Contracting Entity. The entity that issues an invoice does not replace a different Contracting Entity already identified in a signed Order Form unless the parties expressly agree otherwise in writing.

3.2 Separate Responsibility. Each Contracting Entity contracts separately and is responsible for its own obligations. No other Group Company assumes liability for those obligations solely because of common branding, ownership, management or operational cooperation.

3.3 Platform Operations. The Customer acknowledges that the Contracting Entity may use the Platform Operator and other authorized subcontractors or subprocessors to operate and provide the Services. Such use does not change the identity of the Contracting Entity.

3.4 Order of Precedence. If documents forming the parties’ agreement conflict, the following order of precedence applies, from highest to lowest:

  1. a specifically negotiated procurement agreement, service agreement, Order Form or statement of work;
  2. the DPA, for data-protection matters only;
  3. these Terms; and
  4. the Policies and Documentation.

A document will prevail only regarding the subject matter of the conflicting provision. Mandatory law always prevails to the extent it cannot be contractually modified.

4. Accounts; Access; Permitted Use

4.1 Accounts. The Customer is responsible for all activity under its Accounts and for ensuring that its users comply with these Terms. The Customer must keep credentials confidential and promptly notify us of any suspected unauthorized access or misuse.

4.2 Access Right. Subject to these Terms, the applicable Order Form and payment of applicable fees, the Contracting Entity grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable and revocable right during the Term to access and use the Services for the Customer’s internal lawful business, professional, institutional or public-administration purposes.

4.3 Authorized Users. The Customer may permit its personnel and other users authorized under the applicable Order Form to use the Services on its behalf. The Customer remains responsible for their compliance with these Terms.

4.4 Eligibility and Technical Requirements. The Customer is responsible for ensuring that its users, devices, browsers, integrations and systems satisfy the technical requirements reasonably specified in the Documentation.

4.5 Changes to the Services. We may modify, update, or enhance the Services from time to time. We will not materially reduce the core paid functionality during a committed subscription term except where required by law, security, third-party dependency changes, or measures necessary to address misuse or material risk.

5. Restrictions; Acceptable Use

5.1 Restrictions. The Customer will not, and will not permit any third party to:

  1. reverse engineer, decompile, disassemble or attempt to derive source code, underlying models or non-public components of the Services, except to the extent such restriction is prohibited by mandatory law;
  2. bypass usage limits, access restrictions, authentication measures or security controls;
  3. use the Services to develop, train, benchmark for publication or provide a competing product or service without our prior written consent;
  4. scrape, spider, crawl or otherwise access the Services by automated means except as expressly permitted in writing or through documented APIs;
  5. introduce malware, harmful code, denial-of-service traffic or material that may disrupt, damage or impair the Services or third-party systems;
  6. use the Services in violation of law, third-party rights, procurement rules, confidentiality obligations or binding professional duties;
  7. use the Services for prohibited AI practices or unlawful manipulation, deception, discrimination or rights-infringing content;
  8. use the Services to make fully automated decisions producing legal or similarly significant effects on natural persons without appropriate human review and any safeguards required by law;
  9. submit special categories of personal data under Article 9 GDPR, criminal-offense data under Article 10 GDPR, classified information or data subject to heightened professional-secrecy obligations unless expressly agreed in writing and appropriate safeguards are in place; or
  10. represent Outputs as reviewed, approved or endorsed by a human expert when that is not true.

5.2 Service-Protection Measures. We may apply reasonable technical controls, including rate limits, concurrency limits, storage limits, fair-use controls, anti-abuse measures and fraud-prevention checks, to protect the security, integrity and stability of the Services.

6. AI-Specific Terms; Intended Purpose; Human Oversight

6.1 Nature of the Services. The Services use probabilistic machine-learning and software techniques to assist with drafting, transforming, organizing, transcribing, summarizing and exporting content. Outputs may be incomplete, inaccurate, outdated, biased or otherwise unsuitable without review.

6.2 Intended Purpose. Unless an Order Form states otherwise, the Services are intended as drafting, transcription and document-processing assistance tools within the scope described in the Documentation. They are not offered as autonomous legal, tax, procurement, medical, employment, credit, law-enforcement, biometric or other high-risk decision systems.

6.3 Use Outside the Intended Purpose. Use outside the documented intended purpose, including use that materially changes the legal, operational or risk profile of the Services, is at the Customer’s risk unless separately assessed and expressly agreed in writing.

6.4 Human Oversight. The Customer is responsible for reviewing, validating, and approving Outputs before use, publication, filing, or reliance, including compliance with procurement, administrative, regulatory, and sector-specific requirements. The Services do not provide legal, tax, procurement, accounting, medical or other regulated professional advice.

6.5 Similarity of Outputs. Because of the nature of machine-learning systems, Outputs generated for different users may occasionally be similar or identical.

6.6 References and Citations. References, sources or citations generated by the Services may be incomplete, outdated, incorrect or mismatched. The Customer must independently verify material citations and legal or factual references before relying on them.

7. Transparency; AI Marking; Downstream Publication

7.1 Technical Marking. The Services may embed machine-readable indicators, metadata or similar technical markers identifying files or Outputs as AI-generated or AI-assisted where technically feasible and appropriate.

7.2 Marker Limitations. Technical markers may not survive copy-paste, OCR, extraction, format conversion, editing, re-authoring, external processing or downstream publication workflows.

7.3 Downstream Transparency. The Customer is responsible for any disclosure, labeling or transparency measures required by law for its final use or publication of Outputs, including where technical markers have been removed or do not persist.

8. Professional Services

8.1 Scope. Professional Services are limited to the configuration, implementation, onboarding, training and support described in the applicable Order Form and performed within the existing documented functional scope of the Services.

8.2 No Intended-Purpose Change. Professional Services do not change the intended purpose or legal classification of the Services unless the parties expressly agree otherwise after an appropriate assessment.

8.3 Dependencies and Cooperation. The Customer will provide timely access, information, decisions and cooperation reasonably required for Professional Services. Customer-caused delays may affect timelines, scope and fees.

8.4 Acceptance. Unless an Order Form provides specific acceptance criteria, Professional Services deliverables are deemed accepted when delivered. Where an Order Form states acceptance criteria or an acceptance procedure, that Order Form governs.

8.5 Third-Party Systems. Integrations may depend on third-party systems, APIs, credentials, licenses or vendors. We are not responsible for third-party downtime, changes, incompatibility, access revocation or discontinuation except to the extent expressly agreed in an Order Form.

8.6 AI Literacy and Training. The Customer is responsible for ensuring that its personnel and persons using the Services on its behalf have an appropriate level of AI literacy and competence for their roles and context of use. Training or Documentation we provide supplements, but does not replace, the Customer’s responsibility to ensure appropriate human oversight and lawful use.

9. Fees; Billing; Plans; Credits; Taxes

9.1 Fees. The Customer will pay the fees stated in the applicable Order Form or selected plan.

9.2 Billing Cadence. Fees may be billed monthly, annually, or as otherwise specified in the applicable Order Form. Unless stated otherwise, subscription fees are billed in advance.

9.3 Credits and Usage Entitlements. Credits and other usage entitlements may be subject to reset periods, plan limits and fair-use controls. Unless an Order Form states otherwise, unused credits do not roll over.

9.4 Overages. We may charge for usage exceeding plan limits at the rates stated in the applicable Order Form or published pricing where applicable.

9.5 Payment Terms. The Customer will pay undisputed invoices by the stated due date. Overdue amounts may accrue statutory late-payment interest and legally recoverable collection costs.

9.6 Suspension for Non-Payment. We may suspend access to paid Services for overdue payment after reasonable notice, unless prohibited by the applicable Order Form or mandatory law.

9.7 Taxes. Fees exclude taxes unless stated otherwise. The Customer is responsible for applicable taxes, including VAT, unless a reverse-charge or other mechanism applies and the Customer provides the information reasonably required to apply it.

9.8 Refunds. Fees are non-refundable except where required by mandatory law or expressly stated in an applicable Order Form.

9.9 Trials and Free Services. Free trials, pilots, beta access and other free Services may be modified, suspended, limited or withdrawn at any time and are provided without warranties to the fullest extent permitted by law.

9.10 Invoicing Entity. An Authorized Supplier or other Group Company may issue or administer invoices on behalf of the Contracting Entity where stated in the applicable Order Form or invoice. Invoicing administration alone does not make that entity the Contracting Entity or jointly liable for the Services.

10. Term; Renewal; Suspension; Termination

10.1 Term. These Terms begin when the Customer first accepts them or first uses the Services and continue while an Account or Order Form remains active.

10.2 Subscription Term. Paid subscriptions continue for the term stated in the applicable Order Form. Unless the Order Form states otherwise, subscriptions renew for successive periods equal to the initial term.

10.3 Non-Renewal. Either party may prevent renewal by giving notice before the deadline stated in the Order Form or, if no deadline is stated, at least 20 days before the next renewal date.

10.4 Suspension. We may suspend access where reasonably necessary to:

  1. address a material security risk, abuse, fraud or service-integrity issue;
  2. comply with law or a binding instruction from a competent authority;
  3. prevent material harm to us, the Customer, other customers or third parties; or
  4. address the Customer’s material breach, including non-payment.

Where reasonably practicable, we will notify the Customer before suspension and limit the suspension to the affected Services or Accounts.

10.5 Termination for Cause. Either party may terminate an Order Form for material breach that is not cured within 30 days after written notice. If the breach cannot be cured or immediate termination is required by law or necessary to prevent material harm, termination may be immediate.

10.6 Effect of Termination. Upon termination or expiry:

  1. the Customer’s access rights end, subject to any agreed export period;
  2. accrued and outstanding fees become due to the extent permitted by law and the applicable Order Form;
  3. we will provide reasonable export access to Customer Data for 30 days unless the Order Form or DPA provides otherwise; and
  4. Customer Data will thereafter be returned, deleted or rendered inaccessible in accordance with the DPA and applicable legal obligations.

10.7 Survival. Provisions that by their nature should survive termination will survive, including provisions concerning accrued fees, confidentiality, intellectual property, limitations of liability, indemnities, data return and deletion, and dispute resolution.

11. Intellectual Property; Customer Data; Outputs

11.1 Service Rights. The Platform Operator, Contracting Entity, and their respective licensors retain all right, title, and interest in and to the Services, including software, source code, models, algorithms, workflows, templates, user interfaces, Documentation, APIs, configurations, know-how, improvements, and related intellectual-property rights. No rights are granted except as expressly stated in these Terms or an Order Form.

11.2 Customer Data. As between the parties, the Customer retains all rights in Customer Data. The Customer grants the Contracting Entity, Platform Operator and authorized subprocessors a limited, non-exclusive right to host, process, transmit, reproduce, display and otherwise use Customer Data solely as necessary to provide, secure, maintain and support the Services for the Customer, perform Professional Services, comply with documented instructions, enforce the parties’ agreement and comply with law.

11.3 Outputs. As between the parties, the Customer owns Outputs to the extent ownership is recognized under applicable law. To the extent transferable rights in Outputs vest in the Contracting Entity or Platform Operator, the relevant entity assigns those rights to the Customer upon payment of applicable fees. This does not transfer any rights in the Services, underlying technology, templates, workflows, Documentation or pre-existing materials. The Customer remains responsible for its use, publication, filing and reliance on Outputs.

11.4 Feedback. If the Customer provides suggestions, ideas or feedback concerning the Services, the Platform Operator and Contracting Entity may use them without restriction or compensation, provided that doing so does not disclose Customer Data or the Customer’s Confidential Information.

11.5 No Training Without Opt-In. We do not use Customer Data or Outputs to train models for other customers or for general model improvement unless the Customer expressly opts in through a specific written agreement describing the scope, purposes and safeguards.

11.6 Aggregated and De-Identified Data. Unless prohibited by an Order Form, we may generate and use aggregated, statistical, and de-identified information to operate, secure, and support the Services, provided that it does not identify the Customer, any individual, or disclose Customer Data. This Section does not authorize use of Customer Data for AI-model training.

11.7 No Sale of Customer Data. We do not sell Customer Data as a separate data asset.

12. Data Protection; DPA; Security

12.1 Roles. For personal data contained in Customer Data, the Customer acts as controller, and the Contracting Entity acts as processor unless otherwise expressly agreed in writing. Where the Contracting Entity is not UAB Such Much AI and the Platform Operator processes Customer Data to operate the Services, UAB Such Much AI acts as an affiliated subprocessor. UAB Such Much AI is not a subprocessor where it is itself the Contracting Entity.

For account administration, contracting, billing, taxation, customer-relationship management, support communications and similar data processed for an entity’s own legitimate business or legal purposes, the relevant Group Company acts as a separate controller as described in the Privacy Policy.

12.2 DPA Incorporation. Annex 1 forms part of these Terms and applies whenever the Contracting Entity processes personal data in Customer Data on the Customer’s behalf. An additional DPA or data-protection schedule in an Order Form prevails to the extent it provides more specific requirements.

12.3 Hosting. Customer Data is hosted in the European Economic Area by default unless otherwise expressly agreed in writing.

12.4 Security. We implement appropriate technical and organizational measures designed to protect the confidentiality, integrity and availability of Customer Data, taking into account the nature and risks of the processing. The baseline measures are described in Annex 1.

12.5 Subprocessors. The Contracting Entity may use the Platform Operator, Microsoft Azure and other authorized subprocessors to provide the Services in accordance with Annex 1. A Group Company does not receive access to Customer Data solely because it is affiliated with the Contracting Entity.

12.6 Incidents. We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data and provide available information reasonably necessary for the Customer to fulfill its notification and documentation obligations.

12.7 No Unauthorized Group Access. Access by Such Much AI, Inc. or any other Group Company outside the EEA is not authorized merely by that entity’s status as a Group Company or Authorized Supplier. Any such access must be necessary for the Services, permitted by the applicable Order Form and DPA, and protected by a lawful transfer mechanism.

13. Confidentiality

13.1 Confidential Information. Each party may receive non-public information from the other party that is marked confidential or reasonably should be understood as confidential given its nature and the circumstances of disclosure (“Confidential Information”). Confidential Information includes Customer Data, security information, non-public product information, pricing, business plans and trade secrets.

13.2 Obligations. The receiving party will:

  1. use Confidential Information only to perform or exercise rights under the parties’ agreement;
  2. protect it using at least reasonable care and no less care than it uses for its own similar information; and
  3. disclose it only to personnel, Group Companies, subprocessors, contractors or professional advisers who need to know it for an authorized purpose and are bound by appropriate confidentiality obligations.

13.3 Exclusions. Confidentiality obligations do not apply to information that the receiving party can demonstrate:

  1. is or becomes public without breach of the parties’ agreement;
  2. was lawfully known without restriction before disclosure;
  3. is lawfully received from a third party without a confidentiality restriction; or
  4. is independently developed without using the disclosing party’s Confidential Information.

13.4 Required Disclosure. A party may disclose Confidential Information where required by law, court order or competent authority, provided that it gives prior notice where legally permitted and reasonably cooperates to limit the disclosure.

13.5 Survival. Confidentiality obligations survive for five years after termination. Trade secrets and personal data remain protected for as long as required by applicable law or while they retain their protected status.

14. Warranties; Disclaimers

14.1 Authority. Each party warrants that it has authority to enter into the parties’ agreement.

14.2 Service Standard. We warrant that paid Services will be provided in substantial conformity with the applicable Documentation under normal use, subject to the limitations stated in these Terms and the Order Form.

14.3 Availability. Unless an Order Form states a specific service level, we do not guarantee uninterrupted or error-free operation. Maintenance, updates, security measures and third-party dependencies may cause temporary interruptions.

14.4 Outputs. Outputs are assistive drafts. The Customer is responsible for reviewing, validating and approving them and deciding whether to use or rely on them.

14.5 General Disclaimer. Except as expressly stated in these Terms or an Order Form, the Services, Outputs, beta features, trials and Professional Services are provided “as is” and “as available”. To the maximum extent permitted by law, we disclaim implied warranties, including merchantability, fitness for a particular purpose and non-infringement.

14.6 No Professional Advice. The Services and Outputs do not constitute legal, tax, procurement, accounting, employment, medical or other regulated professional advice.

14.7 Beta and Preview Features. Features identified as beta, preview, pilot or experimental may be modified or discontinued and may be subject to additional limitations.

15. Indemnities

15.1 IP Indemnity. Subject to this Section, the Contracting Entity will defend the Customer against a third-party claim alleging that the unmodified paid Services, as provided and used in accordance with these Terms, directly infringe a third party’s copyright, trademark or EU/EEA patent, and will pay finally awarded damages or settlement amounts approved by the Contracting Entity, provided that the Customer:

  1. promptly notifies the Contracting Entity;
  2. allows the Contracting Entity to control the defense and settlement; and
  3. reasonably cooperates at the Contracting Entity’s expense.

15.2 Exclusions. Section 15.1 does not apply to the extent a claim arises from:

  1. Customer Data or Outputs;
  2. use outside the Documentation or intended purpose;
  3. modification by the Customer or a third party;
  4. combination with products, services or data not provided or approved by us; or
  5. continued use of a non-current version after notice, where the claim would have been avoided by using the current version.

15.3 Remedies. If an infringement claim is made or appears likely, we may:

  1. modify the affected Services to be non-infringing;
  2. obtain the right for the Customer to continue using them;
  3. replace the affected component; or
  4. terminate the affected Services and refund prepaid fees for the unused terminated portion.

15.4 Customer Indemnity. To the extent permitted by applicable law, the Customer will defend and indemnify the Contracting Entity and Platform Operator against third-party claims arising from:

  1. Customer Data;
  2. the Customer’s unlawful, misleading or rights-infringing use of the Services or Outputs;
  3. publication, filing or operational use of Outputs without appropriate review; or
  4. the Customer’s material breach of these Terms or third-party rights.

16. Limitation of Liability

16.1 Non-Excludable Liability. Nothing in these Terms excludes or limits liability that cannot be excluded or limited under mandatory law, including liability for fraud or intentional misconduct and other liability that applicable law expressly prohibits the parties from limiting.

16.2 Aggregate Cap. To the maximum extent permitted by law, the total aggregate liability of the Contracting Entity, Platform Operator and all other Group Companies arising out of or relating to the Services, an Order Form, Professional Services or these Terms will not exceed the total fees paid or payable by the Customer under the affected Order Form during the 12 months preceding the event giving rise to the claim. This is one aggregate cap and is not multiplied by the number of claims or Group Companies involved.

16.3 Excluded Damages. To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, exemplary, punitive or consequential damages, or for lost profits, lost revenue, lost business, loss of goodwill or business interruption.

16.4 Output-Related Allocation. Without limiting Section 16.2, we are not liable for decisions, filings, publications, procurement actions, legal positions or operational actions taken by the Customer or a third party based on Outputs, except to the extent directly caused by our breach of an express contractual obligation.

16.5 Data-Protection Liability. This Section does not limit liability to the extent the GDPR or other mandatory data-protection law prohibits such limitation.

16.6 Allocation Across Group Companies. The protections, exclusions and limitations in this Section apply to the Contracting Entity, Platform Operator, their Affiliates, licensors, subcontractors and personnel to the extent a claim arising from the Services is made against any of them.

17. Export Controls; Sanctions

The Customer will comply with applicable export-control and sanctions laws. We may suspend or terminate access to the extent reasonably necessary to comply with such laws or binding authority instructions.

18. Public Sector; Procurement; Mandatory Law

18.1 Public-Sector Customers. If the Customer is a public authority, contracting authority, state-owned entity, municipal entity or other public-sector body subject to mandatory public-law or procurement requirements, these Terms apply only to the extent consistent with those requirements and the applicable procurement agreement.

18.2 Mandatory Adjustments. A provision conflicting with non-waivable public-law, procurement or regulatory requirements will be modified only to the minimum extent necessary. The remaining provisions will remain in effect.

18.3 Authorized Instructions. Operational requests and documented instructions from a public-sector Customer must be issued by persons authorized under the applicable Order Form or the Customer’s notified governance arrangements.

19. Changes to the Terms

19.1 Updates. We may update these Terms from time to time.

19.2 Notice. For material changes, we will provide notice through the Services, by email, or both, and specify the effective date.

19.3 Committed Terms. Changes will not retroactively modify a signed Order Form during its committed term unless required by law or security needs, or expressly agreed in writing.

19.4 Continued Use. Where legally permitted and where no committed Order Form prevents the change, continued use after the effective date constitutes acceptance of the updated Terms.

20. Governing Law; Dispute Resolution

20.1 Order Form. The governing law and competent courts specified in the applicable Order Form apply.

20.2 Default Rules. If the Order Form does not specify governing law and jurisdiction:

  1. where the Contracting Entity is UAB Such Much AI, these Terms are governed by Lithuanian law and the courts of Vilnius, Lithuania, have exclusive jurisdiction;
  2. where the Contracting Entity is SIA “Such Much AI”, these Terms are governed by Latvian law and the courts of Riga, Latvia, have exclusive jurisdiction; and
  3. where the Contracting Entity is Such Much AI, Inc., these Terms are governed by the laws of the State of Delaware, excluding its conflict-of-laws rules, and the competent state or federal courts located in Delaware have exclusive jurisdiction.

20.3 Good-Faith Negotiations. Before filing a claim, the parties will attempt in good faith to resolve the dispute through negotiations for 30 days, except for claims requiring urgent injunctive or interim relief.

20.4 Mandatory Rules. Mandatory consumer, data-protection, public-sector, procurement and jurisdiction rules remain applicable regardless of this Section.

21. Notices

21.1 Operational Notices. We may send operational notices to the email address associated with the Customer’s Account or specified in the applicable Order Form.

21.2 Formal Notices to the Contracting Entity. Formal legal notices must be sent to the Contracting Entity at the address specified in the applicable Order Form. If the Order Form does not specify an address:

  1. notices to UAB Such Much AI must be sent to Bukčių g. 6-38, Vilnius, LT-04127, Lithuania;
  2. notices to SIA “Such Much AI” must be sent to Ropažu iela 7–8, Rīga, Latvia; and
  3. notices to Such Much AI, Inc. must be sent to the address specified in the applicable Order Form, invoice or subscription confirmation. If none is specified, a formal notice may be sent to info@suchmuchai.com with “Legal Notice — Such Much AI, Inc.” in the subject line.

A copy may be sent to info@suchmuchai.com. Email alone constitutes formal notice only where the applicable Order Form permits it, or the receiving entity acknowledges receipt in writing.

21.3 Notices to the Customer. The Customer must maintain current postal and email contact details. Formal notices may be sent to the address specified in the Account or applicable Order Form.

22. Miscellaneous

22.1 Assignment. The Customer may not assign its rights or obligations without the Contracting Entity’s prior written consent, except to an Affiliate or in connection with a merger, reorganization or sale of substantially all relevant assets, provided the assignee agrees in writing to be bound. The Contracting Entity may assign an Order Form to an Affiliate or successor in connection with a reorganization, merger, financing or sale of the relevant business, subject to mandatory law and without reducing the Customer’s material rights.

22.2 Subcontracting and Group Performance. The Contracting Entity may use the Platform Operator, Group Companies and other subcontractors to perform the Services. Such delegation is not an assignment and does not relieve the Contracting Entity of obligations for which it remains responsible under the parties’ agreement or applicable law.

22.3 No Partnership or Agency. The parties are independent contractors. These Terms do not create a partnership, joint venture, employment, fiduciary or agency relationship between the Customer and any Such Much AI entity, or among the Such Much AI entities themselves.

22.4 Severability. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable. The remaining provisions remain in effect.

22.5 No Waiver. Failure or delay in enforcing a provision is not a waiver.

22.6 Entire Agreement. These Terms, the applicable Order Form, the DPA and incorporated Policies constitute the entire agreement between the Customer and the Contracting Entity regarding the Services and supersede prior discussions on that subject.

22.7 Language. The English version governs unless the applicable Order Form or mandatory law requires another language to prevail.

22.8 Electronic Contracting. The parties agree that Terms, Order Forms, acceptances, notices and related records may be formed, signed, stored and evidenced electronically to the extent permitted by law.

22.9 Force Majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, excluding payment obligations. The affected party will use reasonable efforts to mitigate the impact and resume performance.

22.10 Contact. Questions concerning these Terms may be sent to info@suchmuchai.com.

ANNEX 1 — DATA PROCESSING TERMS (ARTICLE 28 GDPR)

These Data Processing Terms (the “DPA”) apply where the Contracting Entity processes personal data contained in Customer Data on behalf of the Customer. This DPA forms part of the Terms and the applicable Order Form.

1. Roles and Scope

1.1 For personal data contained in Customer Data, the Customer is the controller and the Contracting Entity is the processor unless the parties expressly agree otherwise in writing.

1.2 Where the Contracting Entity is not UAB Such Much AI and UAB Such Much AI operates or administers the Services on its behalf, UAB Such Much AI acts as an affiliated subprocessor. UAB Such Much AI is not a subprocessor where it is itself the Contracting Entity.

1.3 Each party will comply with the data-protection obligations applicable to its role. The allocation of roles in this DPA does not change the legal classification that follows from the parties’ actual processing activities under applicable data-protection law.

2. Subject Matter and Duration

2.1 The subject matter is the processing of personal data necessary to provide, secure, maintain and support the Services and Professional Services described in the applicable Order Form.

2.2 Processing continues for the duration of the applicable Services term and any agreed post-termination export, return or deletion period, unless applicable law requires longer retention.

3. Nature and Purpose of Processing

Processing may include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, transcription, summarization, generation, transmission, export, alignment, restriction, deletion and other operations necessary to:

  1. provide, operate and secure the Services;
  2. process Customer instructions and generate, transform or export Outputs;
  3. provide support and Professional Services;
  4. detect, prevent and address abuse, fraud and security incidents; and
  5. comply with applicable law.

The processor will not process Customer Data for its own independent purposes except where expressly permitted by the Order Form or required by law.

4. Processing Details

The categories of data subjects, types of personal data, processing frequency and other processing details are described in Schedule 1 and may be supplemented by an applicable Order Form.

5. Documented Instructions

5.1 The processor will process personal data only on the Customer’s documented instructions, including instructions reflected in these Terms, the applicable Order Form, the Customer’s authorized use of the Services and documented support requests.

5.2 If Union or Member State law requires processing outside the Customer’s instructions, the processor will inform the Customer of that legal requirement before processing unless the law prohibits such notice on important grounds of public interest.

5.3 The processor will promptly inform the Customer if, in its reasonable opinion, an instruction infringes the GDPR or other applicable data-protection law. The processor may suspend the affected processing until the instruction is confirmed, modified or withdrawn.

5.4 The Customer is responsible for ensuring that its instructions are lawful, that it has an appropriate legal basis for processing, and that required information is provided to data subjects.

6. Confidentiality

The processor will ensure that persons authorized to process personal data are subject to contractual or statutory confidentiality obligations and receive access only to the extent necessary for their duties.

7. Security

7.1 Taking into account the state of the art, implementation costs and the nature, scope, context, purposes and risks of processing, the processor will implement appropriate technical and organizational measures in accordance with Article 32 GDPR.

7.2 The baseline measures are described in Schedule 2. The processor may update those measures where the update does not materially reduce the overall level of security during the applicable Services term.

7.3 The Customer is responsible for securely configuring its Accounts, managing user access, protecting credentials and using available security features appropriately.

8. Subprocessors

8.1 Specific Authorization. The Customer specifically authorizes the Contracting Entity to engage:

  1. UAB Such Much AI as the Platform Operator and affiliated subprocessor where UAB Such Much AI is not itself the Contracting Entity; and
  2. the Microsoft entity providing Microsoft Azure services as a cloud-infrastructure and, where applicable, AI-services subprocessor.

8.2 General Authorization. The Customer grants general written authorization for other subprocessors identified in the applicable Order Form or current subprocessor list made available to the Customer.

8.3 Subprocessor Obligations. The processor will impose written data-protection obligations on each subprocessor that provide at least the protection required by this DPA, taking into account the nature of the subprocessor’s services.

8.4 Responsibility. The processor remains responsible for the performance of its subprocessors’ data-protection obligations to the extent required by Article 28(4) GDPR.

8.5 Changes. The processor will provide at least 30 days’ prior notice of a material addition or replacement of a subprocessor where reasonably practicable. A shorter notice period may apply where an urgent change is required for security, legal compliance or service continuity.

8.6 Objections. The Customer may object to a new subprocessor within 14 days after notice on reasonable and substantiated data-protection grounds. The parties will work in good faith to address the objection. If no reasonable solution is available, either party may terminate the affected Services, subject to payment of fees accrued before termination.

9. Assistance With Data-Subject Rights

9.1 Taking into account the nature of the processing, the processor will provide reasonable assistance through appropriate technical and organizational measures to enable the Customer to respond to requests concerning data-subject rights.

9.2 If the processor receives a request relating to Customer Data directly from a data subject, it will refer the requester to the Customer and will not respond substantively unless instructed by the Customer or required by law.

10. Security Incidents and Compliance Assistance

10.1 Personal-Data Breaches. The processor will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data.

10.2 Incident Information. The processor will provide information reasonably available to it concerning the nature of the breach, affected data and data subjects, likely consequences and mitigation measures, and will provide reasonable updates as further information becomes available.

10.3 Customer Notifications. The Customer remains responsible for determining whether notification to a supervisory authority or data subjects is required and for making those notifications.

10.4 Additional Assistance. Taking into account the nature of processing and information available to the processor, the processor will reasonably assist the Customer with compliance under Articles 32–36 GDPR, including security assessments, breach documentation, data-protection impact assessments and prior consultations where required.

11. Information and Audits

11.1 The processor will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA.

11.2 The Customer may conduct or mandate an audit no more than once per year, except where required by a supervisory authority, applicable law or a reasonably substantiated security incident or material compliance concern.

11.3 Audits must be subject to reasonable prior notice, confidentiality, proportionality, security restrictions and minimal disruption. An auditor must not be a competitor of the processor and must be bound by confidentiality.

11.4 Where appropriate, the processor may satisfy an audit request by providing recent independent audit reports, certifications, security summaries, questionnaires or equivalent evidence. An on-site inspection may be conducted where such evidence is reasonably insufficient.

11.5 The Customer bears its audit costs. The processor may charge reasonable costs for assistance beyond information ordinarily made available, unless the audit identifies a material breach by the processor.

12. International Transfers

12.1 Customer Data is hosted in the EEA by default unless otherwise agreed in writing.

12.2 The processor will not transfer Customer Data outside the EEA, or permit access from outside the EEA, unless the transfer is authorized by the applicable Order Form or the Customer’s documented instructions and is protected by a lawful GDPR Chapter V mechanism.

12.3 Status as a Group Company or Authorized Supplier does not, by itself, authorize access to Customer Data from outside the EEA.

13. Return and Deletion

13.1 Upon termination of the relevant Services, the processor will, at the Customer’s choice, return or delete Customer Data and delete existing copies unless applicable law requires retention.

13.2 The Customer must communicate its return or deletion choice no later than the end of the agreed export period. Unless otherwise agreed, the processor will provide a 30-day export period.

13.3 If the Customer does not communicate a choice, the processor may delete Customer Data from active systems after the 30-day export period. Unless an Order Form states otherwise, residual copies in backups will be deleted through ordinary backup rotation within 90 days thereafter.

13.4 Where Union or Member State law requires continued storage, or where the Customer provides a lawful documented retention instruction, the retained data will remain protected under this DPA and will not be processed for any other purpose.

14. Special Categories and Restricted Data

The Customer must not submit special categories of personal data, criminal-offense data, classified information or similarly restricted data unless expressly agreed in writing and appropriate safeguards are implemented. If the parties authorize such processing, the applicable Order Form must describe the relevant data and additional safeguards.

15. Records, Cooperation and Regulatory Requests

15.1 Each party will maintain records required by applicable data-protection law for its processing activities.

15.2 The processor will reasonably cooperate with competent supervisory authorities in accordance with applicable law.

15.3 Unless prohibited by law, the processor will notify the Customer of a binding authority request specifically concerning Customer Data before disclosure and will disclose only the information legally required.

16. Liability and Priority

16.1 Liability arising under this DPA is subject to Section 16 of the Terms, except to the extent a limitation is prohibited by applicable data-protection law or the applicable Order Form provides otherwise.

16.2 If this DPA conflicts with the main body of the Terms regarding personal-data processing, this DPA prevails. A specifically negotiated data-protection provision in an Order Form prevails over this DPA.

17. Contact

Data-protection questions relating to this DPA may be sent to info@suchmuchai.com or to the contact specified in the applicable Order Form.

SCHEDULE 1 — DETAILS OF PROCESSING

1. Subject Matter

Provision of the Services and Professional Services described in the applicable Order Form, including AI-assisted document generation, document processing, knowledge-base functionality, audio or video transcription, summarization, workflow configuration, support and related platform administration.

2. Duration

For the term of the applicable Order Form and the limited post-termination export, return and deletion period described in the DPA, unless law requires longer retention.

3. Nature and Purpose

Hosting, organizing, retrieving, transcribing, analyzing, transforming, generating, exporting, securing, supporting and deleting Customer Data as necessary to provide the Services on the Customer’s documented instructions.

4. Categories of Data Subjects

Depending on Customer Data submitted by the Customer, data subjects may include:

  • the Customer’s employees, officials, contractors, advisers and authorized users;
  • meeting, interview, hearing or event participants;
  • customers, suppliers, bidders, applicants and business contacts;
  • residents, citizens, correspondents and other members of the public;
  • persons identified or discussed in documents, recordings or communications; and
  • other persons whose data the Customer lawfully submits to the Services.

5. Types of Personal Data

Depending on Customer Data submitted by the Customer, personal data may include:

  • names and identification information;
  • work and personal contact information;
  • professional, employment and organizational information;
  • user-account, role and access information;
  • voice, audio, video and meeting-participation information;
  • communications, statements, opinions and document contents;
  • procurement, administrative and case-related information;
  • technical, usage and security information; and
  • other personal data included in Customer Data.

6. Special Categories

Special categories of personal data under Article 9 GDPR and criminal-offense data under Article 10 GDPR are not authorized unless expressly identified and approved in writing in the applicable Order Form with appropriate safeguards.

7. Processing Frequency

Continuous or occasional, depending on the Customer’s use of the Services during the Term.

SCHEDULE 2 — BASELINE TECHNICAL AND ORGANIZATIONAL MEASURES

The processor maintains measures appropriate to the nature and risk of the processing. The baseline measures include:

1. Governance and Confidentiality

  • documented allocation of security and data-protection responsibilities;
  • confidentiality obligations for persons authorized to access personal data; and
  • access to Customer Data limited to persons requiring it for authorized operational or support purposes.

2. Access Control

  • individual user Accounts and authentication controls;
  • role-based or equivalent authorization controls;
  • least-privilege access principles for administrative access; and
  • procedures for granting, changing, and revoking access.

3. Encryption and Transmission Security

  • encrypted transmission between user devices and the Services using current transport-encryption protocols; and
  • encryption at rest using appropriate cloud-platform capabilities where supported and appropriate to the relevant data and service component.

4. Hosting and Data Separation

  • EEA hosting for Customer Data by default;
  • logical separation of customer organizations and access permissions; and
  • controls designed to prevent unauthorized cross-customer access.

5. Logging and Monitoring

  • logging of relevant authentication, administrative, security and system events;
  • monitoring designed to identify material operational or security anomalies; and
  • retention of logs for periods proportionate to security, operational and legal requirements.

6. Availability, Backup and Recovery

  • backup and recovery processes appropriate to the Services;
  • measures designed to support availability and restoration following an operational incident; and
  • periodic review of business-continuity and recovery arrangements.

7. Secure Maintenance

  • security updates, patching and dependency management appropriate to the relevant systems;
  • vulnerability assessment and remediation processes proportionate to identified risks; and
  • change-management and testing practices designed to reduce security risks.

8. Incident Management

  • procedures for identifying, assessing, containing and responding to security incidents;
  • internal escalation and documentation processes; and
  • procedures supporting notification and cooperation obligations under the DPA.

9. Subprocessor and Personnel Controls

  • due diligence appropriate to the services and risks before engaging material subprocessors;
  • contractual confidentiality, security and data-protection obligations; and
  • appropriate security and data-protection awareness for personnel with relevant responsibilities.

10. Retention and Deletion

  • procedures for deletion or rendering inaccessible Customer Data following termination or documented instructions;
  • controlled backup-rotation periods; and
  • retention beyond standard periods only where required by law or by a lawful documented Customer instruction.

The processor may replace or update individual measures as technology and risks evolve, provided that the overall level of protection is not materially reduced during the applicable Services term.