These AI & Autonomous Systems Terms ("AI Terms") are Supplemental Terms governing Customer's access to and use of artificial-intelligence, machine-learning, generative, predictive, agentic, automated and Autonomous functionality made available by BACI LLC ("BACI").
These AI Terms allocate contractual responsibility for AI Inputs, Outputs, recommendations, tool use, connected systems, approvals and Autonomous Actions. They supplement the BACI Terms of Service and apply whenever Customer enables or uses covered AI functionality.
AI can materially increase the speed, scale and consequence of business activity. These AI Terms therefore distinguish intelligence from authority: a system's technical ability to recommend or perform an action does not itself establish legal or contractual authority to perform that action.
These AI Terms form part of the Agreement and BACI Legal Framework. For matters expressly concerning AI and Autonomous functionality, these AI Terms govern as applicable Supplemental Terms, subject to the Agreement's order of precedence.
The Data Processing Addendum ("DPA") remains authoritative for Processing Customer Personal Data on Customer's behalf. The Security Policy / Security Addendum governs contracted security obligations. The Responsible AI Policy establishes governance principles and does not reduce these contractual terms.
These AI Terms apply to BACI generative AI, predictive analytics, forecasting, scoring, classification, recommendation, retrieval-augmented generation, intelligent agents, orchestration, tool use, automated workflows and Autonomous functionality, including access through BACI APIs, applications, integrations and connected systems. Product-specific terms may supplement these AI Terms.
“AI Functionality” means functionality using artificial intelligence, machine learning, statistical models, generative models, predictive models, intelligent orchestration or comparable computational techniques.
“Autonomous Action” means an action performed through the Service without Customer approval immediately before that action.
“Authority Boundary” means a Customer-configured or contractually established limit on actions BACI may perform, including permissions, spending limits, approval thresholds, markets, jurisdictions, channels, categories, objectives, connected systems, action types, frequency, volume or other supported constraints.
“Input” means information, content, instructions, prompts, files, data, configurations or other material submitted or made available to AI Functionality.
“Output” means content, intelligence, analysis, recommendations, predictions, classifications, scores, reports, generated material or other results produced through AI Functionality.
“Tool” means a function, API, integration, application, database, communications channel, transaction system or other capability an AI system can invoke.
Other capitalised terms have the meanings in the Terms or DPA.
BACI may provide AI Functionality through Manual, Hybrid and Autonomous operating modes.
Manual: BACI may discover, analyse, organise, generate, prioritise, forecast or recommend; Customer decides whether to act.
Hybrid: BACI may perform Customer-authorised actions within defined parameters while designated decisions or actions remain subject to Customer approval.
Autonomous: BACI may perform authorised actions or processes without individual Customer approval immediately before each action, within Customer-established Authority Boundaries and supported Service controls.
Available functionality varies by Service, plan, configuration and jurisdiction.
Customer is responsible for selecting an operating mode appropriate to its use case, governance capacity, legal requirements and consequence tolerance. Customer must not select Autonomous operation where Applicable Law requires individual human approval that the configured workflow does not provide. BACI may restrict a mode based on Service capability, law, security or risk.
Customer authorises BACI to perform only Autonomous Actions falling within applicable Authority Boundaries. Customer is responsible for configuring those boundaries accurately and proportionately. BACI does not acquire unlimited authority merely because an integration technically permits broader action.
Customer may delegate only authority Customer lawfully possesses. Customer must not configure BACI to enter transactions, access systems, use data, make representations or perform actions that Customer lacks legal or contractual authority to perform. Technical execution does not cure lack of underlying authority.
Subject to the Agreement, commercial consequences of an Autonomous Action properly performed within Customer's configured Authority Boundaries remain Customer's responsibility, except to the extent the consequence results from BACI's breach, negligence, wilful misconduct or another matter for which liability cannot lawfully be excluded.
If BACI performs an Autonomous Action outside applicable Authority Boundaries because of a failure of BACI-controlled functionality, responsibility will be determined under the Agreement's warranties, indemnities, liability provisions and other applicable terms. AI or automation does not itself create unlimited liability. Customer must promptly report suspected unauthorised Autonomous Actions and reasonably mitigate continuing harm.
Where Hybrid functionality requires Customer approval, BACI may rely on approval from an Authorised User with apparent Service permissions unless BACI knows the approval is unauthorised. Customer is responsible for assigning approval permissions appropriately. Approval is not meaningful human oversight if the approver lacks sufficient authority, information or opportunity to review.
Customer must apply heightened oversight to actions that could materially affect legal rights, finances, employment, safety, access to essential services, regulatory obligations or similarly significant interests. BACI may require additional confirmation, approval, configuration, documentation or restrictions and may decline automation where available controls cannot appropriately govern the risk.
Customer must not use BACI AI as the sole basis for a decision where Applicable Law prohibits solely automated decision-making or requires meaningful human review. Where review is required, Customer must ensure the reviewer has authority, competence, information and practical ability to assess and override the outcome.
Customer is responsible for Inputs and represents that it has the rights, permissions and lawful basis necessary to provide them and instruct BACI to Process them. Customer must not submit material prohibited by the Agreement, Acceptable Use Policy or Applicable Law.
AI Outputs may be probabilistic, incomplete, inaccurate, outdated, ambiguous or unsuitable for Customer's purpose. Customer must evaluate Outputs proportionate to significance and consequence. BACI does not warrant Output uniqueness. Output rights are governed by the Terms, including retained rights in underlying BACI Technology and Third-Party Data.
Customer must not rely on an AI Output as the sole source of truth for a materially consequential decision where reasonable verification is practicable or required. Customer should verify material facts, eligibility criteria, deadlines, financial information, legal requirements, representations and external-source information before consequential action.
BACI AI and BACI Intelligence do not constitute legal, tax, accounting, medical, investment, fiduciary or other regulated professional advice unless BACI expressly contracts to provide a specifically authorised professional service. AI-generated analysis does not create a professional-client relationship with BACI.
BACI may provide financial, market, investor, funder or forecasting intelligence but does not guarantee investment returns, financing, funding, market performance or transaction outcomes. Customer remains responsible for securities, financial-promotion, suitability, fiduciary and other obligations applicable to Customer.
BACI may identify, analyse, prioritise, prepare or support procurement, bid and grant opportunities. Customer must verify eligibility, requirements, deadlines, certifications, representations, pricing, authority and final submission content and must not fabricate qualifications, certifications, past performance or supporting evidence.
A BACI match, score, recommendation or forecast does not establish endorsement, willingness to transact, legal eligibility, availability of capital or likelihood of funding. Customer is responsible for lawful outreach, solicitation, disclosure and transaction activity.
Customer must not use BACI to obtain trade secrets unlawfully, access private systems without authorisation, breach confidentiality, unlawfully intercept communications or circumvent access controls. BACI Intelligence does not create rights to use source information contrary to third-party rights.
Where BACI can generate, schedule, distribute or optimise communications, Customer is responsible for lawful recipient selection, consent, suppression, advertising and communications compliance. Autonomous communications must respect applicable opt-outs, frequency rules, channel restrictions and Customer policies.
Customer is responsible for reviewing generated content where appropriate to risk and must not knowingly publish material that unlawfully infringes intellectual property, defames, violates privacy or is materially deceptive. BACI does not guarantee generated content is free from all third-party claims.
Where law requires disclosure, labelling or provenance for AI-generated or materially manipulated content, Customer is responsible for compliance applicable to Customer's publication or use. Customer must not use BACI to falsify evidence, provenance or identity.
Customer retains Customer Data rights as provided by the Terms. AI Processing does not transfer ownership of Customer Data to BACI or an AI provider. Customer Personal Data processed on Customer's behalf is governed by the DPA.
Unless Customer expressly agrees in writing or affirmatively opts into a clearly identified programme, BACI will not use Customer Confidential Information, Customer Personal Data, private Inputs or private Outputs to train or fine-tune general-purpose or shared AI models for the benefit of other customers.
This restriction applies to BACI and relevant BACI-selected AI Subprocessors to the extent they Process such data on BACI's behalf. It does not prohibit operational Processing necessary to provide, secure, support, maintain, troubleshoot or follow Customer instructions.
Customer may separately authorise Customer-specific private training, fine-tuning, retrieval, indexing, embeddings or similar functionality under the applicable Order, DPA and Supplemental Terms. Customer-specific training material does not become general shared training material merely because BACI provides the service.
BACI may use third-party AI models, model hosts or AI infrastructure. Providers Processing Customer Personal Data on BACI's behalf are governed by BACI's DPA and Subprocessor framework. BACI may replace providers or models for capability, security, privacy, availability, cost, compliance or Service evolution, subject to contractual commitments. BACI will not promise provider terms it has not secured.
BACI may route tasks to different models, systems or providers according to complexity, consequence, capability, latency, availability, security, privacy, cost and other operational factors. A particular model or provider is not guaranteed unless an Order expressly commits to it.
BACI may change models, prompts, orchestration, retrieval methods and related AI components without treating every change as a new Service, provided applicable contractual commitments continue to be satisfied. An Order expressly fixing a model or capability controls.
Customer is responsible for authorising connected applications, data sources and operational systems, maintaining appropriate third-party rights and configuring permissions no broader than reasonably necessary. BACI is not responsible for independent third-party behaviour except as expressly provided in the Agreement.
AI Functionality may invoke Tools to retrieve information or perform actions. Customer authorises Tool use only within applicable Service configuration and Authority Boundaries. BACI may restrict or disable a Tool for security, safety, compliance, provider requirements or material reliability concerns.
Customer must protect credentials used by AI Functionality and provide no broader access than reasonably necessary. Customer must promptly revoke or rotate credentials reasonably believed compromised.
AI systems interacting with external content may encounter malicious or conflicting instructions. BACI may implement controls designed to reduce prompt injection, data exfiltration, unauthorised Tool use and privilege escalation, but no control eliminates all risk. Customer should apply stronger authority restrictions where untrusted content meets consequential Tools.
Where supported, Customer must configure appropriate financial limits and approval thresholds for Autonomous spending, purchasing, bidding, campaign expenditure or other financial actions. BACI may impose platform-level maximums, additional approvals or restrictions independent of Customer limits.
Where BACI can send offers, initiate outreach, submit forms, modify campaigns, create opportunities or perform other commercial actions, Customer must ensure the delegated action is lawful and consistent with Customer policy. Narrower permissions should be used for actions creating legal commitments or materially affecting third parties.
BACI AI has no inherent authority to bind Customer. An Autonomous system may form or accept a contract only where Customer expressly and lawfully delegates that authority and the applicable BACI Service supports it. Customer is responsible for defining who or what may create binding obligations on its behalf.
AI Functionality may initiate payment or transfer of value only where the Service expressly supports it and Customer has authorised the relevant method, amount limits and permissions. BACI may require additional authentication, confirmation or third-party payment controls.
Not every Autonomous Action can be reversed. Customer must account for irreversibility when configuring authority. BACI may provide pause, rollback, cancellation, staged execution or recovery functionality where supported but does not guarantee it for every action or third-party system.
Customer should use available intervention controls promptly upon material unexpected behaviour. BACI may independently pause, disable or restrict AI Functionality where reasonably necessary to address security, safety, legal, reliability or abuse risk.
BACI may maintain logs of AI activity, approvals, Tool calls, configuration, actions and other events appropriate to security, reliability, support and accountability. Availability and retention vary by Service and plan. Customer should not assume every internal model operation is reproducible or that private model reasoning will be available.
BACI may provide source references, material factors, workflow information, action history or other explanation features where technically appropriate. BACI does not warrant access to a model's private chain of thought or internal reasoning. Customer must determine whether available explanation functionality satisfies Customer-specific legal requirements.
Customer must not use BACI AI for unlawful discrimination. Where AI materially affects individuals, Customer is responsible for fairness and discriminatory-impact obligations applicable to Customer's deployment. BACI may restrict uses presenting material discrimination risk.
Customer must comply with laws governing automated employment decision tools, workplace monitoring, hiring, promotion, termination and worker profiling, including applicable notice, assessment, consent and human-review obligations. BACI AI is not an independently qualified employment decision-maker.
Customer must not use BACI AI as an unlawful substitute for legally required underwriting, eligibility, adverse-action, explanation, fairness or human-review processes. Such contexts may require product-specific authorisation and additional terms.
Unless expressly authorised through specialised terms, BACI AI is not a medical device and is not intended as sole operational control for safety-critical systems. Customer must not rely solely on ordinary BACI AI where failure could directly cause death, serious bodily injury or catastrophic physical damage.
Government and public-sector use may be subject to additional due-process, transparency, records, procurement, accessibility, civil-rights, human-oversight and accountability requirements. The Government & Public Sector Schedule may impose additional restrictions. Classified or specially controlled data must not enter an ordinary BACI environment unless expressly authorised.
Customer must not use AI Functionality for conduct prohibited by the Acceptable Use Policy, including unlawful activity, fraud, malicious cyber activity, unlawful privacy invasion, prohibited discrimination, exploitation or abuse, deceptive impersonation, sanctions violations, prohibited high-risk AI or circumvention of BACI safeguards.
Customer must not intentionally bypass, disable, defeat or manipulate BACI safety, security, usage, Authority Boundary, approval, monitoring or policy controls except where BACI expressly authorises testing. Customer must not use prompt engineering, API composition, multiple accounts or other techniques to evade restrictions on underlying activity.
Customer must not extract non-public model weights, system prompts, proprietary orchestration, protected training information, internal security controls or other BACI Technology except where expressly permitted. Ordinary use of Outputs does not grant a right to reconstruct BACI's systems.
BACI may evaluate AI Functionality for reliability, safety, security, misuse, fairness, task performance and Tool behaviour. Testing does not guarantee all errors or failure modes are identified. Customer should conduct Customer-specific validation where deployment risks are not reasonably observable to BACI.
Experimental, beta, preview or evaluation AI functionality may be less reliable, change more frequently or have additional restrictions. Unless an Order expressly states otherwise, beta or preview functionality is not subject to paid production Service Levels.
BACI may monitor AI Functionality for security, reliability, abuse, policy compliance, operational performance and system improvement as permitted by the Agreement. Monitoring does not create a duty to review every Input, Output or Autonomous Action.
Customer should promptly report material unexpected Autonomous Actions, significant harmful Outputs, suspected data exposure, safeguard failures or other serious AI incidents. BACI may investigate, contain, restrict, remediate or suspend affected functionality. The DPA governs notification where an event is a Security Incident involving Customer Personal Data.
BACI may restrict, suspend or disable AI Functionality where reasonably necessary for safety, security, law, provider requirements, sanctions, reliability or abuse. Where reasonably practicable, BACI will limit restriction to affected functionality.
Changes to permissions, Authority Boundaries, connected systems, objectives, modes, Tools or data sources may materially change AI behaviour and risk. Customer is responsible for reviewing consequential changes. BACI may require renewed approval or validation for certain material changes.
Inputs, Outputs, action logs and related information are retained according to the Agreement, DPA, Data Retention & Deletion Policy, Service configuration and Applicable Law. Retention does not expand BACI's model-training rights.
BACI may create Customer-specific embeddings, indexes or retrieval representations to provide contracted functionality. Such representations remain subject to applicable Customer Data protections where attributable to Customer Data. Deletion is governed by the Data Retention & Deletion Policy and Service architecture.
Customer rights in Inputs, Outputs and Customer Data are governed by the Terms. BACI retains all rights in BACI Technology, including models, algorithms, prompts, orchestration, methodologies, schemas, ontologies, taxonomies, scoring systems, workflows and underlying technology. No Output transfers ownership of underlying BACI Technology.
Outputs may contain or resemble material subject to third-party rights. Customer is responsible for evaluating intended use where intellectual-property, privacy, publicity, confidentiality or other rights may be implicated. Third-Party Data remains subject to applicable restrictions.
Customer Confidential Information processed through AI Functionality remains subject to the Agreement's confidentiality protections. BACI will not treat confidential Inputs or Outputs as public merely because an AI system processed them.
Personal Data processed through AI Functionality is subject to the Privacy Policy, DPA and Applicable Data Protection Law according to BACI's role. AI capability does not create an independent lawful basis for Processing Personal Data.
AI Functionality is subject to the Security Policy / Security Addendum. Customer is responsible for Customer-controlled endpoints, credentials, integrations, identity configuration and permissions. No AI system can be guaranteed free from every security vulnerability or adversarial technique.
International Processing through AI providers or other Subprocessors is governed by the DPA, Subprocessor Policy & List and International Data Transfer Addendum. BACI will not claim a transfer certification or framework unless it actually applies.
BACI may modify, restrict, geographically limit, require additional configuration for or discontinue AI Functionality where reasonably necessary to comply with Applicable Law or binding regulatory requirements. The Agreement governs remedies for material contractual changes affecting paid Services.
Customer is responsible for governance appropriate to its AI use, potentially including internal policies, authorised-use rules, approval structures, risk assessment, human oversight, recordkeeping, user training, incident escalation and periodic review. BACI controls do not replace Customer obligations.
Customer should ensure Authorised Users exercising material approval, configuration or Autonomous authority understand relevant AI limitations and responsibilities. BACI may provide documentation or guidance but does not assume Customer's organisational training obligations unless expressly agreed.
BACI does not guarantee revenue, growth, conversion, funding, procurement success, investment, market performance, competitive advantage or other business outcome from AI Functionality. BACI Intelligence supports decision-making; outcomes depend on factors outside BACI's control.
Warranties concerning the Services are those expressly stated in the Agreement. Except as expressly provided, BACI does not warrant AI Outputs will be error-free, unique, complete or suitable for every purpose. Non-excludable warranties remain unaffected.
Liability arising from AI Functionality and Autonomous Actions is governed by the Agreement, including applicable exclusions, caps, enhanced caps and non-excludable liabilities. Use of AI, a frontier model or Autonomous mode does not itself create a separate unlimited-liability regime.
Indemnity obligations relating to AI use, Customer Data, Inputs, Outputs, infringement, unlawful use or third-party claims are governed by the Agreement and applicable product-specific terms. These AI Terms do not create duplicative indemnities.
BACI may retain records reasonably necessary to demonstrate AI configuration, approvals, actions, security events, contractual compliance and legal obligations, subject to confidentiality, privacy, security and retention requirements. Customer is responsible for additional records required specifically for Customer's deployment.
Contractual audit rights are governed by the Agreement, DPA and security terms. BACI may provide appropriate AI-control documentation for enterprise assurance but is not required to disclose model weights, private chain-of-thought, proprietary system prompts, trade secrets, privileged material or security-sensitive information.
Termination of AI Functionality does not automatically terminate unrelated BACI Services unless the Agreement provides otherwise. Customer should disable relevant Customer-controlled connected-system credentials and Autonomous permissions. Data return and deletion are governed by the DPA, Data Retention & Deletion Policy and Agreement.
Customer responsibility, confidentiality, intellectual property, liability, records, accrued rights and provisions that by nature should survive continue to the extent provided by the Agreement. Data-protection obligations survive while BACI retains protected Customer Personal Data.
BACI may update these AI Terms to reflect changes in AI technology, Services, providers, Applicable Law, regulation, security or the BACI Legal Framework. BACI will not use a unilateral update to eliminate a higher-precedence contractual protection during an existing Service term where the Agreement prohibits that change.
These AI Terms preserve distinctions between recommendation, approval and Autonomous Action. “Autonomous” does not mean unbounded, exempt from governance or legally independent. “AI” does not imply legal personhood, independent authority or responsibility. Mandatory Applicable Law controls to the extent of inconsistency.
AI and Autonomous Systems contractual enquiries may be directed through BACI's applicable legal or Customer contact channel.
Privacy: privacy@bacihq.com Security: security@bacihq.com
MANUAL — BACI discovers, analyses, forecasts, generates, prioritises or recommends. Customer approves and executes material action unless separately instructed.
HYBRID — BACI analyses and performs defined Customer-authorised actions. Designated actions or thresholds require approval.
AUTONOMOUS — BACI performs authorised actions without individual approval immediately before each action, within configured Authority Boundaries.
Across every mode: technical capability does not equal authority; Applicable Law applies; prohibited use remains prohibited; and autonomy does not remove governance.
Supported controls may include action types; spending and transaction limits; approval thresholds; markets and countries; channels; categories; objectives; connected applications; accessible data sources; recipients; user and role permissions; time periods; frequency; volume; risk or confidence thresholds; escalation triggers; and pause or disable controls.
Not every Service supports every control. Customer must evaluate controls actually available before enabling consequential Autonomous activity.
Before enabling materially consequential AI or Autonomous functionality, Customer should assess intended outcome; legal authority; data access; Input rights; connected systems; possible actions; reversibility; financial and legal consequences; Authority Boundaries; human approvals; uncertainty handling; Output verification; monitoring; intervention; incident response; recordkeeping; and whether regulated-use or public-sector terms apply.
This checklist is governance guidance and does not replace Customer's legal analysis.
BACI is responsible for BACI-controlled AI functionality as provided under the Agreement, including operation materially within supported configured Authority Boundaries; BACI-selected Subprocessor governance; BACI security obligations; and BACI's contractual no-general-model-training-by-default commitment.
Customer is responsible for lawful Inputs and instructions; Customer-selected use cases; Customer-specific regulatory requirements; user permissions; connected-system authority; operating-mode selection; Authority Boundary configuration; approvals; consequential Output verification; and policies Customer chooses to implement.
Responsibility may be shared for integration security, deployment assessment, monitoring, incident coordination, data quality and regulated workflows. The Agreement controls where it expressly allocates responsibility differently.
Where BACI AI is lawfully used in a high-consequence context, appropriate controls may include documented purpose and legal authority; qualified human oversight; data-quality controls; fairness assessment; verification of material Outputs; explanation processes where required; approval thresholds; restricted Tool access; audit logging; intervention mechanisms; incident escalation; ongoing monitoring; user training; periodic reassessment; and additional contractual or product-specific safeguards.
BACI may require such controls as a condition of supporting a particular use case.
BACI AI & AUTONOMOUS SYSTEMS TERMS — VERSION 1.0 Effective 10 September 2026
We're listening.