DataCall Privacy Policy

Terms of Service

Effective date: June 19, 2026  ·  Last updated: June 19, 2026

Contents

  1. Agreement, Acceptance & Order of Precedence
  2. Definitions
  3. Customer-Controlled Data Model & Architecture
  4. Shared Responsibility & Customer Compliance Obligations
  5. Customer Representations & Warranties
  6. AI Output Disclaimer & No Professional Advice
  7. Healthcare — HIPAA, ePHI Routing & Business Associate Agreement
  8. Healthcare — 42 CFR Part 2 & HITECH Breach Posture
  9. Finance — Status Disclaimers & Customer Obligations
  10. Legal — No Practice of Law & Professional-Responsibility Duties
  11. Account, Eligibility & Authorized Users
  12. License Grant, Restrictions & Open-Model Pass-Through
  13. Acceptable Use
  14. Ownership, Outputs, Feedback & No-Training Commitment
  15. Fees, Payment, Taxes & Billing
  16. Service Levels, Support & Third-Party Process
  17. Data Protection, DPA & Sub-Processors
  18. Confidentiality
  19. Warranty Disclaimer (AS-IS / AS-AVAILABLE)
  20. Limitation of Liability
  21. Indemnification
  22. Term, Suspension, Termination & Data Handling
  23. Modifications to the Terms and the Service
  24. Governing Law, Arbitration, Class-Action & Jury Waiver
  25. Export Control & Sanctions
  26. Force Majeure
  27. Miscellaneous

These Terms of Service, which include an End User License Agreement, govern your access to and use of the DataCall private-AI workflow platform. DataCall is built on a simple idea: open-source language models run on infrastructure you control, so your operational data — patient records, privileged matter files, client portfolios, transactions — is processed inside your perimeter and, in the ordinary course, is never sent to DataCall or to any external AI provider (see Section 3 for the precise scope of this design and the limited Platform Account Data the control plane does process). Because of that design, the compliance outcomes you care about (HIPAA, FINRA, SEC, GLBA, your bar's rules of professional conduct, and the rest) are outcomes you own and configure — DataCall provides software designed to support them, not a guarantee that you meet them. Please read these Terms carefully; they include disclaimers, a limitation of liability, and an arbitration provision with a class-action waiver that affects your legal rights, along with a clearly-marked opt-out.

The shared-responsibility model, in one paragraph. You run the AI on infrastructure you control, and you are the data controller, covered entity, financial institution, law firm, or other responsible party for the Customer Workflow Data you process. You are solely responsible for the lawfulness of your data and use, for obtaining required consents and authorizations, for configuring retention, encryption, access controls, and your security program, and for keeping a qualified human in the loop to independently verify Outputs before relying on them. DataCall provides Software and a thin operated control plane that are designed to support — and can be configured to help — you meet your obligations; DataCall does not, and cannot, guarantee that your deployment makes you compliant with any law, rule, examination, or audit. Compliance is a shared-responsibility outcome you own.

1. Agreement, Acceptance & Order of Precedence

These Terms of Service (the "Terms") are a binding agreement between DataCall, Inc., a Delaware corporation ("DataCall", "we", "us") and the entity or person that accepts them ("Customer", "you").

You accept these Terms — and form a contract — by affirmatively clicking "I agree" (or a similar control) at account creation. Where no such click occurs, creating an account or accessing or using the Service also constitutes acceptance, as a fallback. Continued use of the Service after we post a modified version of these Terms re-accepts the modified Terms.

If you accept these Terms on behalf of an organization, you represent that you are authorized to bind that organization, and "Customer" means that organization. The organization is bound even where an employee, contractor, or agent clicked to accept or signed in. You also accept on behalf of your Affiliates that use the Service under your account.

Order of precedence

If there is a conflict between documents, the following order controls, from highest to lowest:

  1. a signed Business Associate Agreement ("BAA"), as to the electronic protected health information ("ePHI") it governs;
  2. a signed Data Processing Addendum ("DPA"), as to the personal data it governs;
  3. a signed Master Subscription Agreement, enterprise agreement, or executed Order Form;
  4. these Terms (which include the Acceptable Use provisions in Section 13);
  5. externally-published policies incorporated by reference, including the Privacy Policy and any standalone Acceptable Use Policy page.

The Privacy Policy is incorporated into these Terms by reference. The Acceptable Use provisions in Section 13 are part of these Terms; the tier above refers only to a separately-published policy document, if any. The parties intend that electronic acceptance of these Terms has the same legal effect as a handwritten signature, and consent to transact electronically under the E-SIGN Act and applicable UETA. Records of acceptance may be used as evidence of the agreement.

Use of the public marketing site (datacall.ai), including cookies, analytics, and sales-scheduling via third-party tools, is governed by the Privacy Policy and the cookie notice presented on that site, not by these Terms, which govern the Service.

2. Definitions

Capitalized terms have the meanings below.

  • "Customer Environment" means the infrastructure — hardware or a private cloud account — that the Customer owns or controls, and on which the Software and Open Models execute.
  • "Customer Workflow Data" means data the Customer processes through the Software inside the Customer Environment, including ePHI, patient records, individually identifiable health information, privileged matter files and client confidences, client portfolios, transaction data, and nonpublic personal information. It is distinct from Platform Account Data.
  • "Platform Account Data" means the limited data that DataCall-Operated Components necessarily process: account identity obtained via Google OAuth (email, name, profile picture); the workflow-request prompts a signed-in user submits to the Platform App and that are stored server-side; and request and access logs (IP address, user agent, timestamps).
  • "Outputs" means content generated by the AI/ML models in response to inputs.
  • "Open Models" means third-party open-source or open-weight models (for example, Llama and Mistral) made available for execution in the Customer Environment under their own upstream licenses.
  • "Software" means the DataCall-provided software the Customer deploys in the Customer Environment.
  • "DataCall-Operated Components" means the hosted control plane, the tenant-facing Platform App (platform.datacall.ai), the Gateway/edge (the public ingress, including NGINX and the ngrok edge), and related services that DataCall operates.
  • "Service" means the Software and the DataCall-Operated Components, collectively.
  • "Platform" means the Software, the DataCall-Operated Components, the Documentation, and all underlying technology, software, and intellectual property, collectively.
  • "Documentation" means the usage documentation, if any, DataCall makes generally available for the Service.
  • "Order Form" means an ordering document or online subscription describing the scope, plan, and fees.
  • "Authorized Users" means individuals the Customer permits to use the Service under its account.
  • "Affiliate" means an entity that controls, is controlled by, or is under common control with a party.
  • "Confidential Information" means non-public information disclosed by one party to the other that is marked or reasonably understood to be confidential.

3. Customer-Controlled Data Model & Architecture

The Software is architected so that AI runs on infrastructure the Customer controls, and Customer Workflow Data is created, received, maintained, processed, and stored within the Customer Environment.

In the ordinary course of providing the Software, DataCall does not access, store, receive, or transmit Customer Workflow Data, and does not route it to any external AI provider (for example, no Anthropic or OpenAI). The open-source models run on the Customer Environment; Customer Workflow Data stays there. This describes the design of the self-hosted architecture; it is not a warranty that every Customer configuration achieves this result. It is subject to the Warranty Disclaimer in Section 19 and depends on the Customer's configuration choices.

Honest carve-out — what the control plane does collect. The foregoing does not cover Platform Account Data that DataCall-Operated Components necessarily process — account identity (via Google OAuth), the workflow-request prompts a signed-in user voluntarily submits to the Platform App (which are stored server-side), and access logs. That data is governed by the Privacy Policy, the DPA in Section 17 where applicable, and, where applicable, a BAA. Our marketing statement "Data never leaves your perimeter" describes this ordinary-course architecture for Customer Workflow Data processed by self-hosted models; it is not a guarantee for every configuration you choose, and it does not refer to the separate Platform Account Data the Platform App collects.

The Customer is the data controller, covered entity, financial institution, or other responsible party for Customer Workflow Data. With respect to Platform Account Data, DataCall is at most a processor or, where a BAA applies, a business associate, and only to the extent applicable.

The Customer is responsible for configuring, securing, and operating the Customer Environment, including data retention, encryption at rest, access controls, and backups. The Customer is solely responsible for backing up, retaining, and preserving its own Customer Workflow Data and the encrypted audit trail; DataCall does not hold that data and cannot recover, restore, or produce data it does not hold. The encrypted audit trail that a workflow keeps is a Customer-operated control; DataCall does not warrant that it satisfies any specific regulatory recordkeeping standard.

No monitoring duty. DataCall does not monitor, pre-screen, or review Customer Workflow Data or Outputs and has no obligation or, in the ordinary course, ability to do so. DataCall's right to suspend for Acceptable-Use violations is a right, not a duty to monitor, and its exercise creates no obligation to detect future violations.

All marketing and architecture statements about the Service are subject to this Section and to the configuration and shared-responsibility terms of these Terms.

4. Shared Responsibility & Customer Compliance Obligations

Compliance is a shared-responsibility outcome the Customer owns. DataCall provides Software the Customer can configure and deploy, but the Customer is solely responsible for its own legal and regulatory compliance. Nothing in these Terms makes DataCall the Customer's privacy officer, security officer, supervisory principal, or compliance authority.

As applicable to its business, the Customer is solely responsible for compliance with, among others:

  • HIPAA and the HITECH Act; 42 CFR Part 2; and applicable state health-privacy laws;
  • GLBA, including the Safeguards Rule (16 CFR Part 314) and the Privacy Rule / Regulation P;
  • FINRA rules, the federal securities laws and SEC rules, and the Sarbanes-Oxley Act (SOX);
  • the FCRA and the ECOA / Regulation B;
  • state privacy laws (for example, CCPA/CPRA and analogous state statutes) and GDPR / UK GDPR; and
  • for legal-industry Customers, applicable rules of professional conduct, including ABA Model Rules 1.1 (competence), 1.6 (confidentiality), and 5.1 and 5.3 (supervision of lawyers and of nonlawyer assistance), and conflicts of interest.

The Customer is responsible for: the lawfulness of its data and use; obtaining all required consents, authorizations, and notices; determining its own regulatory status; configuring data retention, deletion, encryption, access control, and minimum-necessary settings; performing its own assessments and audits; and ensuring qualified human review of Outputs before reliance. The Customer is responsible for its Authorized Users' acts and omissions and for credential security.

The list is illustrative, not exhaustive. The foregoing list is illustrative and not exhaustive; the absence of any law, rule, or framework from these Terms does not transfer responsibility for it to DataCall.

The Service is designed to support and can be configured to help the Customer meet these obligations; it does not guarantee compliance, and DataCall does not assume any of these obligations.

5. Customer Representations & Warranties

The Customer represents and warrants, on an ongoing basis, that:

  • it has all rights, consents, authorizations, and lawful bases necessary to process the Customer Workflow Data through the Software;
  • its use of the Service complies with all laws, regulations, and professional-conduct rules applicable to it;
  • it will not route ePHI, 42 CFR Part 2 records, or nonpublic personal information through DataCall-Operated Components except as permitted by Sections 7 through 9;
  • it maintains the qualified human review required by Section 6 before relying on Outputs; and
  • it is authorized to accept these Terms and, where it accepts on behalf of an organization, to bind that organization.

These representations and warranties anchor the Customer's indemnity obligations in Section 21 and survive termination.

6. AI Output Disclaimer & No Professional Advice

Outputs are generated by AI/ML models and may be inaccurate, incomplete, outdated, biased, or fabricated ("hallucinated"), including fabricated citations, authorities, figures, or facts. The Customer must independently verify Outputs before relying on them.

Outputs are not medical, legal, financial, tax, accounting, or other professional advice. Use of the Service forms no physician-patient, attorney-client, fiduciary, broker-dealer, investment-adviser, or other advisory relationship with DataCall.

Human-in-the-loop is required. A qualified human professional must remain in the loop and exercise independent professional judgment. The Service is an assistive tool; it does not exercise clinical, legal, or financial judgment and does not replace a licensed professional. The Customer is solely responsible for decisions made and actions taken based on Outputs.

The Customer — not DataCall — is solely responsible for ensuring that its own use of Outputs does not constitute the unauthorized practice of medicine, law, or financial advice, or unlicensed advice to the Customer's own clients or patients.

DataCall does not control, and is not responsible for, the behavior, weights, or training data of the Open Models. Output quality depends on the model selected, the Customer's prompts, the configuration, and the Customer's data.

7. Healthcare — HIPAA, ePHI Routing & Business Associate Agreement

The Customer is solely responsible for determining its own status under HIPAA (covered entity, business associate, or hybrid entity) and for its HIPAA, HITECH, and state health-privacy compliance, including maintaining required administrative, physical, and technical safeguards on the infrastructure it controls.

The BAA controls for any ePHI

To the extent any DataCall-Operated Component would create, receive, maintain, or transmit ePHI on the Customer's behalf, DataCall will act as a business associate only under a separately executed written BAA. The Customer must request, and the parties must mutually execute, a BAA before any ePHI is routed through a DataCall-Operated Component; until a BAA is signed, no business-associate relationship exists. A signed BAA controls over any conflicting provision of these Terms or the Privacy Policy as to the ePHI it governs — including conflicting limitation-of-liability, warranty, and data-handling terms — and the BAA, not these Terms, governs permitted uses and disclosures, subcontractor flow-down, safeguards, and return or destruction of ePHI on termination.

No BAA, no ePHI through our components. Absent a signed BAA, the Customer must not route, submit, paste, or otherwise transmit ePHI through any DataCall-Operated Component — including workflow-request prompts to the Platform App, support channels, or logs. Those stores are account and operational metadata stores and are not designed to receive ePHI absent a BAA. To arrange a BAA, contact security@datacall.ai — we sign BAAs.

The architecture is designed to support deployments that can be configured to help covered entities and business associates meet their HIPAA obligations. There is no government HIPAA certification, and only HHS/OCR can determine compliance. DataCall makes no representation that the Service alone makes the Customer HIPAA-compliant, that it satisfies any specific Privacy Rule or Security Rule requirement, or that it is "HIPAA certified." HIPAA compliance is a Customer-owned outcome that depends on the Customer's policies, configuration, and use.

The Service is not a medical device and is not intended for use in the diagnosis, cure, mitigation, treatment, or prevention of disease. No clinical, diagnostic, or care decision should rest solely on Outputs. The Customer is solely responsible for any FDA Software-as-a-Medical-Device (SaMD) determination, and for obtaining any required clearance, approval, or registration, if it configures a workflow that meets the device definition, and for clinician supervision, professional judgment, and standard-of-care compliance.

8. Healthcare — 42 CFR Part 2 & HITECH Breach Posture

42 CFR Part 2 — substance use disorder records

Records subject to 42 CFR Part 2 (substance use disorder treatment records from Part 2 programs) carry consent and redisclosure restrictions that are separate from, and in respects more stringent than, HIPAA. The Customer is solely responsible for obtaining and managing Part 2-compliant consent before any Part 2 record is processed through the Service, for honoring revocations, and for ensuring Part 2 records are not used or disclosed in any proceeding against the patient absent the patient's consent or a qualifying court order. DataCall does not classify, segregate, or apply Part 2 handling to Customer data — that determination and segregation is the Customer's responsibility. Absent a signed BAA and the Customer's Part 2-compliant consents, the Customer must not route Part 2 records through any DataCall-Operated Component.

HITECH breach posture

Where DataCall is a business associate under a signed BAA and discovers a breach of unsecured ePHI within a DataCall-Operated Component, DataCall will notify the Customer as and when required by, and within the timeframe specified in, the signed BAA and applicable law. The BAA, not these Terms, governs the timing, content, and cooperation obligations for any such notification. The Customer, as covered entity, remains solely responsible for its own breach-risk assessment and for notifying affected individuals, HHS/OCR, and, where applicable, the media. Because ePHI is, in the ordinary course, processed inside the Customer Environment, breaches occurring within the Customer's own environment are the Customer's responsibility and outside DataCall's control or knowledge. Report security incidents to security@datacall.ai.

9. Finance — Status Disclaimers & Customer Obligations

What DataCall is not

DataCall is a software platform provider only. DataCall is not, and does not act as, a broker, dealer, broker-dealer, investment adviser (registered or exempt), bank, trust company, money services business, money transmitter, futures commission merchant, commodity trading advisor, insurance producer, mortgage originator, or consumer reporting agency. DataCall is not registered with, a member of, or supervised by the SEC, FINRA, the CFTC, the OCC, the Federal Reserve, the FDIC, FinCEN, state securities or banking regulators, or any self-regulatory organization. DataCall does not hold, custody, control, transmit, or have access to Customer funds, securities, or digital assets.

Outputs are not financial advice; no fiduciary relationship

Outputs are provided for informational and workflow-automation purposes only. They are not investment, tax, financial, accounting, or legal advice, not a recommendation to buy, sell, or hold any security or financial product, not an offer or solicitation, not a research report, and not a valuation or fairness opinion. No fiduciary, best-interest, suitability, custodial, or advisory relationship is created between DataCall and the Customer or any of the Customer's clients or investors. Where the Customer is a regulated firm, the Customer remains solely responsible for ensuring any Output presented to a client satisfies the Customer's own suitability, Reg BI best-interest, fiduciary, fair-dealing, and communications-with-the-public obligations, including required review, approval, and disclosures.

Books-and-records, supervision & Safeguards remain the Customer's

The Customer is solely responsible for creating, maintaining, preserving, supervising, and producing its own books and records under all applicable rules, including SEC Rules 17a-3 and 17a-4 and FINRA Rules 3110 (Supervision), 3120, and 4511 (Books and Records). DataCall's encrypted audit trail and access logs are operational and security features; they are not represented or warranted to constitute a compliant books-and-records, WORM, or audit-trail recordkeeping system under SEC Rule 17a-4 or FINRA Rule 4511, and the Customer must not rely on them as its system of record or designated third-party recordkeeping service. Any such recordkeeping arrangement, including any required regulator-access undertaking, must be separately agreed in writing.

Where the Customer is a "financial institution" under GLBA, the Customer is solely responsible for its written information security program, the FTC Safeguards Rule (16 CFR Part 314, including the security-event notification requirement), and the GLBA Privacy Rule / Regulation P, including consumer privacy notices and opt-outs. The Customer must not route nonpublic personal information to DataCall-Operated Components in a manner inconsistent with its own GLBA notices and consents.

No FCRA/ECOA determinations

DataCall does not assemble, evaluate, or furnish "consumer reports," is not a "consumer reporting agency," and is not a "creditor." DataCall makes no FCRA-permissible-purpose, credit, underwriting, pricing, eligibility, creditworthiness, or adverse-action determinations. Where the Customer uses the Service in connection with credit, lending, insurance, employment, housing, or other eligibility processes, the Customer is the decision-maker and is solely responsible for all FCRA and ECOA / Regulation B obligations, including any required adverse-action notices and statements of specific reasons, and for fair-lending compliance and the testing, validation, monitoring, and documentation of any model or Output used in such a process.

The Service is designed to support, and can be architected to help, the Customer meet these obligations; it does not assume them. DataCall does not represent that it holds any SOC 2 report or ISO 27001 certification unless separately stated in writing. Any reference to SOC 2, ISO 27001, or NIST frameworks, if made, describes a point-in-time or period auditor opinion on DataCall's own control environment, or a control framework a deployment can be architected to align with; it is not a certification of the Customer's deployment or a guarantee of the Customer's compliance.

10. Legal — No Practice of Law & Professional-Responsibility Duties

DataCall is a software platform provider, not a law firm or a lawyer, and does not engage in the practice of law in any jurisdiction. Nothing in the Service, its Outputs, the Documentation, or any communication constitutes legal advice, a legal opinion, or legal services. Use of the Service creates no attorney-client relationship, no fiduciary relationship, and no duty of care between DataCall and the Customer, its lawyers, or its clients. DataCall is not a lawyer-referral or legal-document-preparation service; the licensed attorney, not the tool, exercises professional judgment.

The Customer and its lawyers remain solely responsible for compliance with all applicable rules of professional conduct in every jurisdiction in which their lawyers are admitted, including:

  • confidentiality of client information (ABA Model Rule 1.6 and its technology comments);
  • technological competence — understanding the benefits and risks of the AI technology used (Rule 1.1, Comment 8);
  • supervision of subordinate lawyers and of nonlawyer assistance, including AI tools (Rules 5.1 and 5.3);
  • conflicts of interest (Rules 1.7–1.9), and the duties of diligence, communication, and candor to the tribunal (Rules 1.3, 1.4, and 3.3); and
  • obtaining any client or informed consent required before using a third-party AI tool on a matter.
Privilege and work-product are the firm's responsibility. The Service is designed so that privileged matter files and client confidences are processed inside the Customer Environment and, in the ordinary course, are not accessed by DataCall. DataCall does not guarantee, warrant, or represent that any communication, file, or Output is or remains protected by the attorney-client privilege or the work-product doctrine — preservation of privilege and work-product is the firm's sole responsibility. The firm must not route privileged or work-product material through any DataCall-Operated Component in a manner it has not independently determined preserves protection.

Because Outputs may include fabricated case citations, quotations, statutes, or authorities, the Customer's lawyers must independently confirm every authority, citation, and factual assertion before any Output is relied upon, filed, served, or delivered to a client or tribunal. DataCall is not responsible for any sanction, malpractice claim, disciplinary action, or adverse ruling arising from reliance on unverified Outputs.

11. Account, Eligibility & Authorized Users

The Service is for business and organizational use by entities and their Authorized Users. It is not intended for consumer or personal use and is not directed to children. Each Authorized User must be at least 18 years old (or the age of majority in their jurisdiction) and authorized by the Customer.

The age restriction governs users, not data subjects. The 18-and-over and not-directed-to-children requirements apply to Authorized Users of the Service, not to the data subjects (such as patients or minors) whose records the Customer may lawfully process. Processing pediatric or minors' records in a regulated workflow does not, by itself, violate these Terms, provided the Customer has the lawful basis and consents to do so.

Account identity is established via Google OAuth (email, name, and profile picture). The Customer is responsible for the security of its Google accounts and session credentials and for all activity under its account. The Customer must provide accurate registration information and must promptly notify security@datacall.ai of any suspected unauthorized access. DataCall may refuse, suspend, or terminate accounts for eligibility failures, sanctions or export reasons, or breach.

12. License Grant, Restrictions & Open-Model Pass-Through

Subject to these Terms and the applicable Order Form, DataCall grants the Customer a non-exclusive, non-transferable, non-sublicensable, revocable license to use the Software and the Service for the Customer's internal business purposes during the term.

Open-Model pass-through. Use of Open Models (for example, Llama and Mistral) is additionally subject to their upstream licenses (for example, the Llama Community License and Apache-2.0). The Customer is responsible for complying with those upstream licenses, including any acceptable-use and attribution terms. DataCall does not grant rights to the Open Models beyond their upstream licenses and does not warrant them.

Except where, and to the extent, applicable law prohibits the restriction, the Customer must not:

  • reverse engineer, decompile, or attempt to derive the source code or proprietary model weights of DataCall's proprietary Software (this restriction does not apply to the Open Models, which the Customer runs locally under, and is governed by, their upstream licenses);
  • copy, modify, or create derivative works of the Software beyond the license, or remove proprietary notices;
  • publish benchmarking, performance, or comparison results about the Service without DataCall's prior written consent;
  • circumvent license, usage, security, or rate controls, or use the Service to build a competing service;
  • sublicense, resell, rent, or timeshare the Service without authorization; or
  • use the Service unlawfully, to infringe third-party rights, or to introduce malware.

DataCall reserves all rights not expressly granted. The license terminates on the expiry or termination of the agreement.

13. Acceptable Use

The Customer and its Authorized Users must not use the Service to:

  • engage in unlawful, infringing, fraudulent, deceptive, harassing, or harmful conduct, or generate unlawful content;
  • unlawfully attempt to re-identify de-identified data;
  • use Outputs as the sole basis for a regulated decision (medical, legal, financial, or eligibility) without qualified human review;
  • probe, scan, or penetrate DataCall-Operated Components without authorization, or interfere with the control plane, the Gateway/edge, or other tenants; or
  • route ePHI or other regulated data through DataCall-Operated Components in violation of Sections 7 through 9.

DataCall may investigate suspected violations and may suspend or remove access. Report abuse to security@datacall.ai. The Customer remains responsible for its Authorized Users' compliance with this Section. These Acceptable Use provisions are part of these Terms.

14. Ownership, Outputs, Feedback & No-Training Commitment

As between the parties, the Customer owns its Customer Workflow Data and other Customer content, and owns the Outputs generated for it (subject to third-party and Open-Model rights and the non-uniqueness of AI Outputs). The Customer represents that it has the rights and consents necessary for the data it processes.

DataCall owns the Platform and all related intellectual property and improvements. No ownership transfers except for the license expressly granted. In the ordinary course DataCall does not receive Customer Workflow Data at all; the Customer grants no rights to its Customer Workflow Data beyond what is necessary to operate the Software it deployed.

No-training commitment. DataCall does not use Customer Workflow Data, or the workflow-request prompts a user submits to the Platform App, to train, fine-tune, or improve foundation models. Any service-operations metrics DataCall uses to operate and improve the Service expressly exclude Customer Workflow Data and the content of workflow-request prompts.

DataCall has a limited license to process Platform Account Data solely to provide, secure, and support the Service, consistent with the Privacy Policy, the DPA, and any BAA. DataCall may use aggregated metrics that do not identify any individual and contain no Customer Workflow Data — to operate and improve the Service. Where any such data is BAA-governed, any de-identification will meet the HIPAA de-identification standard (Safe Harbor or Expert Determination).

Feedback. If the Customer or its Authorized Users provide feedback or suggestions about the Service, the Customer grants DataCall a perpetual, irrevocable, worldwide, royalty-free license to use that feedback without restriction or obligation.

15. Fees, Payment, Taxes & Billing

The Customer will pay the fees stated in the applicable Order Form or subscription plan. Payment is processed through Stripe, and the Customer authorizes charges to its designated payment method. Payment-card data is handled by Stripe under its terms and is not stored by DataCall.

  • Fees are non-refundable except as expressly stated or required by law; prepaid fees are not pro-rated on a termination for the Customer's breach.
  • The Customer is responsible for all taxes (sales, use, VAT, GST, and withholding), except taxes on DataCall's net income.
  • Late payments may accrue interest at the lesser of 1.5% per month or the maximum permitted by law; non-payment is grounds for suspension or termination.
  • DataCall may change pricing on renewal with notice. Disputed charges must be raised within thirty (30) days of the invoice.

16. Service Levels, Support & Third-Party Process

No uptime, availability, or support commitment is provided except as expressly set out in an Order Form or a Master Subscription Agreement. Absent such a writing, the DataCall-Operated Components are provided without any service-level guarantee, and DataCall has no obligation to provide maintenance, updates, or support.

Government and regulator legal process. If DataCall receives legal process or a governmental or regulatory demand relating to the Customer or Platform Account Data, DataCall will, where legally permitted, notify the Customer so it may seek protective relief, and will disclose only what is legally required. Except as required by a signed BAA, DPA, or other written agreement, the Customer has no right to audit or inspect DataCall's systems; DataCall may instead provide available compliance documentation.

17. Data Protection, DPA & Sub-Processors

To the extent DataCall processes Platform Account Data that is personal data subject to GDPR, UK GDPR, or U.S. state privacy laws (for example, CCPA/CPRA), the parties will enter DataCall's Data Processing Addendum ("DPA"), which governs that processing, incorporates the Standard Contractual Clauses where required for international transfers, and addresses Article 28 processor obligations. The DPA is incorporated by reference and, as to such personal data, controls over conflicting terms.

DataCall's sub-processors for Platform Account Data include Google Cloud (hosting and OAuth identity), Stripe (billing), the ngrok edge (ingress), and HubSpot (sales scheduling). The DPA lists DataCall's sub-processors and the mechanism for notice of changes.

Service-provider commitment. With respect to Platform Account Data that constitutes personal information under U.S. state privacy laws, DataCall acts as a service provider / processor and will not retain, use, disclose, sell, or share it except as necessary to provide the Service or as permitted by law. DataCall certifies that it understands and will comply with these restrictions.

18. Confidentiality

Each party will protect the other's Confidential Information using at least reasonable care and will use it only to perform under the agreement. This obligation does not apply to information that is independently developed without use of the disclosing party's Confidential Information, was already known without a duty of confidentiality, is or becomes public without breach, or is rightfully received from a third party.

A party may disclose Confidential Information if legally compelled, provided it gives notice where legally permitted and discloses only what is required. Customer Workflow Data is the Customer's Confidential Information; DataCall does not receive it in the ordinary course and is not its custodian. Confidentiality obligations survive termination; on request, each party will return or destroy the other's Confidential Information, subject to legal-retention requirements and routine backups.

19. Warranty Disclaimer (AS-IS / AS-AVAILABLE)

Read this section carefully. THE SERVICE, THE SOFTWARE, AND THE OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE," WITH ALL FAULTS.

To the maximum extent permitted by law, DataCall disclaims all implied warranties, including merchantability, fitness for a particular purpose, title, non-infringement, and the accuracy or reliability of Outputs. DataCall does not warrant that the Service will be uninterrupted, error-free, or secure, that Outputs will be accurate, complete, or fit for any regulated decision, or that use of the Service will cause the Customer to be compliant with any law or standard. The architectural description in Section 3 is subject to this disclaimer and is not a warranty.

DataCall makes no warranty regarding third-party components, including the Open Models, Stripe, Google Cloud, ngrok, and HubSpot. Some jurisdictions do not allow certain warranty disclaimers; those limits apply only to the extent required by law. This Section is subject to a signed BAA as to the ePHI it governs and a signed DPA as to the personal data it governs.

20. Limitation of Liability

Read this section carefully — it limits DataCall's liability to you. TO THE MAXIMUM EXTENT PERMITTED BY LAW, DATACALL WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST DATA, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY. DATACALL'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF (A) THE FEES THE CUSTOMER PAID IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) US$100.

The exclusions and cap apply across all theories of liability (contract, tort, statute, or otherwise) and extend to DataCall's Affiliates, suppliers, and licensors. They apply notwithstanding any failure of essential purpose of a limited remedy. The allocation of risk reflected by this cap is a material basis of the bargain and of the pricing. This Section is subject to a signed BAA as to the ePHI it governs and a signed DPA as to the personal data it governs.

Enhanced cap for the marquee data-protection promises. DataCall's liability for a breach of the no-access architecture commitment in Section 3 (where caused by DataCall's act or omission), the no-training commitment in Section 14, or its confidentiality obligations in Section 18 is subject to an enhanced cap equal to the greater of (a) two (2) times the fees the Customer paid in the twelve (12) months preceding the event giving rise to the claim, or (b) US$50,000 — rather than the US$100 floor above — so these promises are not effectively nullified. The confidentiality and intellectual-property carve-outs in the paragraph below apply mutually.

These exclusions and the cap do not apply to liability that applicable law does not permit to be limited or excluded (for example, in cases of gross negligence or willful misconduct, certain non-excludable statutory liabilities, or death or personal injury where non-excludable). Nothing in this Section limits the Customer's payment obligations, the Customer's indemnification obligations, or either party's liability for breach of confidentiality or infringement of the other party's intellectual property.

21. Indemnification

By the Customer

The Customer will defend, indemnify, and hold harmless DataCall and its Affiliates from third-party claims arising out of or related to: (a) Customer Workflow Data; (b) the Customer's use of the Service; (c) the Customer's compliance failures or breach of its representations and warranties in Section 5 (including under HIPAA, financial-services, professional-conduct, and privacy laws); (d) the Customer's breach of these Terms or the Acceptable Use provisions; and (e) the Customer's violation of any Open-Model license or third-party right.

By DataCall (bounded IP indemnity)

DataCall will defend the Customer against a third-party claim that the unmodified Software, used in accordance with the Documentation, infringes a third party's United States patent, registered copyright, or trademark, or misappropriates a trade secret, and will pay resulting damages finally awarded or settled. DataCall may, at its option, repair, replace, or re-license the Software, or refund prepaid, unused fees. This obligation does not apply to (and DataCall provides no IP indemnity for) the Open Models or their weights, any open-source component, combinations with non-DataCall items, Customer modifications, use contrary to the Documentation or law, or Customer Workflow Data, inputs, or Outputs. This Section states DataCall's entire liability and the Customer's sole and exclusive remedy for any claim of intellectual-property infringement. DataCall's indemnity obligations are subject to the limitation of liability in Section 20.

Each indemnity is conditioned on the indemnified party giving prompt notice, granting the indemnifying party sole control of the defense and settlement, and providing reasonable cooperation. No settlement that admits fault or imposes a non-monetary obligation on the indemnified party may be entered without that party's consent.

22. Term, Suspension, Termination & Data Handling

These Terms apply for the term stated in the applicable Order Form and any renewals. Either party may terminate for the other's uncured material breach after written notice and a reasonable cure period. DataCall may suspend access immediately for non-payment, a security or legal risk, a sanctions or export issue, or a violation of the Acceptable Use provisions, with notice where practicable.

On termination, the license ends and the Customer must stop using the DataCall-Operated Components; the Customer's locally deployed Software license terminates per its terms.

Where your data lives matters at termination. Because Customer Workflow Data resides in the Customer Environment, the Customer controls its export, retention, and deletion. On the Customer's written request within a reasonable window after termination, DataCall will use commercially reasonable efforts to export or delete the limited Platform Account Data within its control — including stored workflow-request prompts and account identity it holds — subject to legal-retention requirements, security needs, and routine backups from which data is purged on the ordinary rotation cycle rather than immediately. DataCall cannot return or delete Customer Workflow Data it never held. Handling of any BAA-governed ePHI on termination follows the BAA.

The following survive termination: the Customer's representations, warranties, and indemnities (Sections 5 and 21); the AI Output Disclaimer and No-Professional-Advice terms (Section 6); the Acceptable Use provisions (Section 13); confidentiality (Section 18); ownership, intellectual-property, and feedback terms (Section 14); the no-training commitment; the warranty disclaimer (Section 19); the limitation of liability (Section 20); export-control and sanctions obligations (Section 25); the governing-law and dispute-resolution provisions; accrued payment obligations; and any other provision that by its nature should survive.

23. Modifications to the Terms and the Service

DataCall may modify these Terms by posting an updated version with a new "Last updated" date. For material changes, DataCall will provide reasonable advance notice (for example, by email or in-product notice). Continued use after the effective date constitutes acceptance; a Customer that objects may stop using the Service. A negotiated agreement (a Master Subscription Agreement, Order Form, BAA, or DPA) is amended only per its own change-control terms, not by posting.

DataCall may modify, improve, or discontinue features of the Service, and will avoid materially degrading core functionality during a paid term without notice.

24. Governing Law, Arbitration, Class-Action & Jury Waiver

These Terms are governed by the laws of the State of Delaware, USA, without regard to its conflict-of-laws rules. Subject to the arbitration provision below, the exclusive venue for disputes is the state and federal courts located in the State of Delaware, USA.

Please read — this affects how disputes are resolved. Except for the carve-outs below, any dispute arising out of or relating to these Terms or the Service will be resolved by binding individual arbitration, and not in court. You and DataCall waive the right to a jury trial and the right to participate in a class, collective, or representative action.
  • Carve-outs. Either party may bring an individual action in small-claims court, and either party may seek injunctive or other equitable relief in court to protect its intellectual property or Confidential Information.
  • Opt-out. You may opt out of this arbitration provision by sending written notice to legal@datacall.ai within thirty (30) days of first accepting these Terms. If you opt out, the governing-law and venue provisions above still apply.
  • Rules and forum. The arbitration will be administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules, and seated in the State of Delaware, USA. Fee allocation follows the applicable rules.
  • The arbitrator decides all issues of arbitrability, except that the enforceability of the class-action waiver is for a court to decide. If the class-action waiver is found unenforceable, the affected portion proceeds in court.

25. Export Control & Sanctions

The Customer must comply with all applicable export-control laws (including the U.S. Export Administration Regulations) and sanctions laws (including those administered by OFAC), and applicable foreign equivalents. The Customer represents that it and its Authorized Users are not on a denied, blocked, or sanctioned-party list and are not located in an embargoed jurisdiction. The Customer must not use the Service or the Open Models for any prohibited end-use or to provide access to a sanctioned party. DataCall may suspend or terminate access to comply with its export and sanctions obligations.

26. Force Majeure

Neither party is liable for any delay or failure to perform due to events beyond its reasonable control, including acts of God, war, terrorism, civil unrest, labor disputes, pandemics, governmental action, and internet, utility, or third-party cloud-provider failures, including failures of independent third-party providers DataCall depends on (such as Google Cloud, the ngrok edge, Stripe, and HubSpot). The affected party will use reasonable efforts to mitigate. Payment obligations for amounts already due are not excused. A prolonged force-majeure event may permit termination as stated in these Terms.

27. Miscellaneous

  • Assignment. The Customer may not assign these Terms without DataCall's prior written consent. DataCall may assign to an Affiliate or in connection with a merger, acquisition, or sale of assets.
  • Publicity. Neither party will use the other's name or logo without prior written consent, except that DataCall may identify the Customer as a customer where the Customer has separately consented in writing.
  • U.S. Government rights. If the Customer is a U.S. Government entity, the Software is "commercial computer software" and "commercial computer software documentation," and any use, duplication, or disclosure is subject to the restricted rights applicable to commercial items under the FAR and DFARS, as applicable.
  • Notices. Legal notices go to legal@datacall.ai; security matters to security@datacall.ai; privacy matters to privacy@datacall.ai; general matters to hello@datacall.ai. Notices are deemed received on confirmed delivery or, for email, one business day after sending absent a bounce.
  • Severability. If a provision is held unenforceable, it will be reformed to the minimum extent necessary or severed, and the remainder stays in effect.
  • Entire agreement. These Terms, together with the incorporated Privacy Policy and Acceptable Use provisions and any applicable Order Form, Master Subscription Agreement, BAA, and DPA, are the entire agreement and supersede prior understandings, resolved per the order of precedence in Section 1.
  • No waiver. A failure to enforce a provision is not a waiver; waivers must be in writing.
  • Relationship of the parties. The parties are independent contractors; these Terms create no agency or partnership and no third-party beneficiaries except the indemnified parties named in Section 21.

Questions about these Terms? Contact legal@datacall.ai.

Home Terms of Service Privacy Policy legal@datacall.ai
© 2026 DataCall, Inc. All rights reserved.