KESTREL ADVANCED SYSTEMS PTE. LTD.
MASTER TERMS OF SERVICE
Effective Date: 4 October 2026
Last Updated: 4 October 2026
IMPORTANT NOTICE
These Master Terms of Service (the “Terms”) constitute a legally binding agreement between Kestrel Advanced Systems Pte. Ltd., a private limited company incorporated in Singapore (“Kestrel”, “we”, “us” or “our”), and the organisation identified in an applicable Order Form, registration process or other accepted ordering document (“Customer”, “you” or “your”).
These Terms govern access to and use of Kestrel’s enterprise artificial-intelligence governance, security, runtime-control, assurance, audit and related software, APIs, gateways, dashboards, documentation, services and associated functionality.
KESTREL IS A BUSINESS-TO-BUSINESS SERVICE. IT IS NOT OFFERED FOR PERSONAL, FAMILY, HOUSEHOLD OR OTHER CONSUMER USE.
The individual accepting these Terms on behalf of Customer represents and warrants that the individual has authority to bind Customer.
By executing an Order Form referring to these Terms, clicking an acceptance mechanism presented with these Terms, accessing the Platform following an authorised enterprise registration, or otherwise affirmatively agreeing to these Terms, Customer agrees to be bound by them.
If the individual accepting these Terms does not have authority to bind the relevant organisation, that individual must not accept these Terms or use the Service on that organisation’s behalf.
SCHEDULE 1
KESTREL CONTRACT PARTICULARS
1. Corporate Information
Legal Entity: Kestrel Advanced Systems Pte. Ltd.
Country of Incorporation: Singapore
Entity Type: Private company limited by shares
UEN / Company Registration Number: 202644596C
Registered Office / Business Address:
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
General Contact Email: contact@kestreladvanced.com
Legal Notices Email: legal@kestreladvanced.com
Privacy / Data Protection Email: privacy@kestreladvanced.com
2. Kestrel Online Properties
Primary Website: https://kestreladvanced.com
Platform / Dashboard Domain: https://kestreladvanced.com/admin
API / Gateway Domain(s): Customer-specific API and gateway domains will be specified in the applicable Order Form or deployment documentation.
Privacy Policy URL: https://kestreladvanced.com/privacy
Data Processing Addendum: Available upon request from legal@kestreladvanced.com until a public URL is deployed.
Security Information / Security Addendum: Available upon request from legal@kestreladvanced.com until a public URL is deployed.
Subprocessor List: To be published. Until publication, current subprocessor information is available upon request from privacy@kestreladvanced.com.
3. Contracting Entity
Unless an applicable Order Form expressly states otherwise, the contracting entity for the Service is:
Kestrel Advanced Systems Pte. Ltd.
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
General enquiries: contact@kestreladvanced.com
Legal notices: legal@kestreladvanced.com
Privacy and data-protection enquiries: privacy@kestreladvanced.com
4. Authorised User Minimum Age
Default: 18 years.
No person below 18 years of age may establish or administer a Kestrel Account.
5. Production Subscription Term
Default: monthly subscription automatically renewing for successive one-month periods until Customer cancels before the next renewal date.
An executed Order Form may establish a longer committed Subscription Term.
6. Enterprise Volume Subscription Term
Default: annual committed contract unless the applicable Order Form states otherwise.
7. Payment Due Date
Default: fourteen (14) calendar days from invoice date for standard subscriptions. A negotiated enterprise Order Form may provide Net 30 or another expressly stated period.
8. Late Payment Interest
Default: 1.0% per month, or the maximum amount permitted by Applicable Law if lower.
9. Billable Request Rule
Unless an Order Form states otherwise:
- a Billable Request is a Request accepted past authentication and basic protocol validation and processed by Kestrel’s runtime-control infrastructure;
- a Request that Kestrel subsequently allows, audits, redacts, transforms, holds or blocks remains billable because Kestrel processing was performed;
- Requests rejected before substantive processing because of invalid authentication or malformed protocol data are not billable;
- Requests that fail solely because of a verified Kestrel internal service error are not billable;
- a customer-initiated retry that is separately processed constitutes another Request;
- a streaming request constitutes one Request unless Documentation expressly identifies another metering method; and
- batch operations may be metered by individual processed item where identified in the Documentation.
► ENGINEERING MUST VERIFY THIS MATCHES ACTUAL METERING BEFORE PUBLICATION.
10. Customer Content and Model Training
Customer Content is not used to train general-purpose Kestrel models or models made available to other customers.
Kestrel may use appropriately aggregated and de-identified operational and Usage Data for security, reliability, analytics, abuse prevention and product improvement in accordance with Section 17.
11. Pilot Production Data
Production traffic or live personal data may be used in a Pilot only where expressly permitted by the applicable Order Form, appropriate technical safeguards are active, and any required Data Processing Addendum is effective.
12. Customer Data Export Following Termination
Default: thirty (30) days after termination or expiry, unless legal, security or technical restrictions apply.
13. Data Deletion / Backup Cycle
Following the thirty-day export period, Kestrel will begin deleting Customer Data from active production systems within thirty (30) days, subject to legal holds and other retention required by Applicable Law.
Customer Data remaining solely in backups is intended to expire or be deleted through Kestrel's backup lifecycle within thirty (30) days after removal from active production systems, subject to legal holds and documented recovery-integrity constraints. Customer Data retained solely in backups will not be restored to active use except for disaster recovery, security, legal or continuity purposes.
► PUBLICATION GATE: Infrastructure must implement and verify the thirty-day production backup lifecycle before this commitment is published or accepted.
14. Service Level Agreement
Default: Kestrel provides no contractual uptime percentage or service-credit commitment unless an Order Form expressly incorporates an SLA.
This does not prevent Kestrel from maintaining internal availability objectives.
15. Support
Support channel: support@kestreladvanced.com and the authenticated Kestrel dashboard where available.
Standard support hours: Monday to Friday, 09:00 to 18:00 Singapore time, excluding Singapore public holidays.
Critical incidents: Customer should mark the matter as critical and report it through support@kestreladvanced.com and the authenticated Kestrel dashboard where available.
Guaranteed response targets: None for standard plans. Published or communicated response times are targets only unless an applicable Order Form expressly incorporates an SLA.
16. Automated Enforcement Defaults
Customer-configured policies may cause Kestrel to allow, audit, hold, deny, redact, transform or otherwise control activity.
► ENGINEERING / PRODUCT TO VERIFY: default fail-open/fail-closed behaviour, emergency behaviour and available override mechanisms.
17. Regulated and High-Impact Uses
Default contractual position: regulated industries are not categorically prohibited merely because they are regulated, but Customer must obtain written Kestrel approval before relying on the Service as a material control in a use case involving safety-critical systems or automated decisions that directly determine an individual’s legal rights or access to healthcare, credit, insurance, employment, education, housing, essential public services or comparable high-impact outcomes.
An applicable Order Form or sector-specific addendum may impose additional requirements.
18. Territorial Restriction
Subject to applicable sanctions, export controls and other legal restrictions, Kestrel is available for purchase and deployment worldwide, including by organisations in the United States and California, except that Kestrel is not currently available for deployment within the European Union or European Economic Area.
Unless Kestrel expressly agrees otherwise in writing, this restriction concerns the location of Customer’s Kestrel deployment, governed AI infrastructure and controlled production systems. Mere access to Kestrel’s public website from the EU or EEA does not, by itself, constitute a prohibited deployment.
A Customer headquartered in the EU or EEA may not assume that its non-EU deployment is permitted without Kestrel confirming the proposed architecture.
19. Professional Services
Professional Services are available only where described in a mutually executed Order Form or Statement of Work.
20. Publicity
Default: Kestrel may not publish Customer’s name, trademarks or logo as a customer reference without Customer’s prior written consent.
PART I — GENERAL CONTRACT TERMS
1. DEFINITIONS
1.1 Defined Terms
In these Terms:
“Account” means the Customer-specific account, tenant, workspace or environment through which Customer accesses the Service.
“Affiliate” means, with respect to an entity, another entity that directly or indirectly controls, is controlled by, or is under common control with that entity, where “control” means ownership or control of more than fifty percent (50%) of the voting interests or equivalent power to direct management.
“Applicable Law” means any law, regulation, legally binding governmental requirement, court order or regulatory obligation applicable to the relevant party, activity or jurisdiction.
“AUP” means the Acceptable Use Policy in Schedule 2.
“Authorised User” means an employee, contractor, service account or other individual or system authorised by Customer to use the Service within Customer’s Account.
“Billable Request” has the meaning stated in Schedule 1.
“Confidential Information” has the meaning set out in Section 21.
“Customer Content” means prompts, instructions, messages, files, datasets, configuration values, system messages, tool inputs, model outputs, personal data, records or other content submitted to, transmitted through, stored in or otherwise processed by the Service on Customer’s behalf.
“Customer Data” means Customer Content together with other data relating specifically to Customer or its Authorised Users, excluding Kestrel Technology and properly Aggregated Data.
“Documentation” means Kestrel’s then-current technical documentation, integration instructions and other documentation designated by Kestrel as governing authorised use of the Service.
“Effective Date” means the date on which the applicable agreement between Kestrel and Customer becomes effective.
“Feedback” means suggestions, comments, recommendations or other feedback voluntarily provided concerning Kestrel products or services.
“Fees” means amounts payable to Kestrel under an applicable Order Form, pricing arrangement or these Terms.
“Kestrel Technology” means the Service and all software, APIs, gateways, code, algorithms, classifiers, policy systems, methods, designs, templates, documentation, workflows, models, interfaces, inventions, architectures and technology owned or controlled by Kestrel, including modifications and improvements.
“Model Provider” means an external provider of artificial-intelligence models, inference APIs or related services.
“Order Form” means an ordering document, quotation, subscription page, statement of work or other mutually accepted document identifying the Service purchased by Customer.
“Output” means an output, decision, classification, score, alert, finding, recommendation, transformed response or other result generated, transmitted or surfaced through the Service.
“Pilot” means a time-limited evaluation subscription governed by Schedule 4.
“Platform” means Kestrel’s enterprise AI governance and control-plane platform.
“Professional Services” means implementation, onboarding, training, advisory, configuration, migration or similar services expressly purchased by Customer.
“Request” means an individual transaction, call, message or other processing event submitted to Kestrel for evaluation or processing.
“Security Incident” means a confirmed breach of security resulting in unauthorised access to, acquisition of, disclosure of, alteration of or destruction of Customer Data in Kestrel’s possession or control, excluding unsuccessful attempts or incidents occurring exclusively within Customer Systems.
“Service” means the Platform and any purchased software, API, gateway, dashboard, documentation, support or related service provided by Kestrel.
“Subscription Term” means the period during which Customer is authorised to access the applicable Service.
“Subprocessor” means a third party engaged by Kestrel to process personal data on Customer’s behalf as further addressed in the DPA.
“Supported Integration” means a third-party service or technical interface identified in current Documentation as supported by Kestrel.
“Third-Party Service” means any product, network, model, software, infrastructure, tool, platform, dataset, service or system not owned by Kestrel.
“Tool Action” means an action proposed or performed by an AI system, agent, service or workflow through an external tool, API, application or system.
“Usage Data” means service telemetry and information concerning operation and use of the Service, including request volumes, latency, system performance, security events, feature utilisation and technical metadata.
“Website” means Kestrel’s public websites identified in Schedule 1.
1.2 Interpretation
Unless context requires otherwise:
(a) “including” and similar expressions mean “including without limitation”;
(b) references to a statute include amendments, replacements and subordinate legislation;
(c) references to writing include legally valid electronic communications;
(d) the singular includes the plural and vice versa;
(e) headings are for convenience only;
(f) references to days are calendar days unless expressly stated otherwise; and
(g) no rule of construction requiring ambiguity to be resolved against the drafting party applies merely because Kestrel prepared these Terms, to the extent permitted by Applicable Law.
2. CONTRACT FORMATION AND AUTHORITY
2.1 Methods of Acceptance
Customer may accept these Terms through:
(a) execution of an Order Form;
(b) electronic signature;
(c) affirmative clickwrap acceptance;
(d) an authorised online ordering process; or
(e) another method that objectively demonstrates agreement.
2.2 Electronic Transactions
The parties agree that electronic records, electronic signatures, electronically accepted Order Forms and automated electronic systems may be used for contract formation and administration to the extent permitted by Applicable Law.
2.3 Authority
The individual accepting these Terms represents and warrants that:
(a) the individual has legal authority to bind Customer;
(b) Customer is entering the agreement for business purposes; and
(c) information supplied during registration is materially accurate.
2.4 No Consumer Contract
The Service is offered exclusively for business and organisational use.
Customer must not purchase or use the Service primarily for personal, family or household purposes.
2.5 Unauthorised Acceptance
Kestrel may request reasonable evidence of authority.
If an acceptance appears fraudulent, unauthorised or erroneous, Kestrel may suspend activation while investigating.
2.6 Electronic Errors
Where an obvious clerical, pricing, configuration or electronic transmission error occurs, Kestrel may correct the error promptly, provided Customer is not deprived of amounts properly paid for Services already lawfully provided.
3. ORDER OF PRECEDENCE
In the event of inconsistency, the following order applies unless a document expressly states otherwise:
- a mutually executed amendment expressly modifying the conflicting provision;
- the applicable Order Form;
- the Data Processing Addendum, but only for personal-data processing matters;
- an applicable product-specific schedule;
- an expressly incorporated SLA;
- these Master Terms;
- the AUP;
- Documentation; and
- general Website materials.
Marketing materials, presentations, demonstrations and sales discussions do not override an executed Order Form or these Terms.
Purchase orders issued by Customer are for administrative convenience only and do not modify this Agreement even if Kestrel accepts, references or processes the purchase order.
4. SUBSCRIPTION AND ACCESS RIGHTS
4.1 Subscription Grant
Subject to Customer’s compliance with the Agreement and payment of Fees, Kestrel grants Customer during the Subscription Term a limited, non-exclusive, non-transferable and non-sublicensable right to access and use the purchased Service for Customer’s internal business purposes.
4.2 Authorised Users
Customer may permit its Authorised Users to use the Service within the scope purchased by Customer.
Customer remains responsible for compliance by its Authorised Users.
4.3 Affiliates
An Affiliate may use Customer’s Account only where the Order Form permits such use.
An Affiliate entering its own Order Form becomes a separate Customer unless the applicable Order Form expressly provides otherwise.
4.4 Contractors
Customer may permit contractors to access the Service solely to perform services for Customer, provided:
(a) their use is within Customer’s purchased scope;
(b) Customer remains responsible for their conduct;
(c) appropriate confidentiality obligations apply; and
(d) access is terminated when no longer necessary.
4.5 APIs, Gateways and Service Accounts
The subscription may include API credentials, gateway credentials and machine identities.
Customer must use them only as documented and within purchased limits.
4.6 No Source-Code Rights
No source-code licence, ownership interest, patent licence or right to Kestrel Technology is transferred except as expressly stated.
4.7 Rights Reserved
Kestrel reserves all rights not expressly granted.
5. ACCOUNT ADMINISTRATION AND SECURITY
Customer must:
(a) maintain accurate registration, administrative and billing information;
(b) designate appropriate administrators;
(c) promptly disable access for departed or unauthorised personnel;
(d) protect passwords, API keys, signing materials, access tokens, certificates and other credentials;
(e) maintain appropriate endpoint and identity security;
(f) configure roles and permissions appropriately;
(g) avoid sharing individual credentials;
(h) promptly notify Kestrel of suspected unauthorised access;
(i) maintain reasonable controls to prevent unauthorised use; and
(j) cooperate reasonably in investigating credible security events.
Customer is responsible for activity performed through its Account using valid Customer credentials except to the extent such activity results directly from Kestrel’s breach of the Agreement.
Kestrel may revoke or rotate credentials and impose reasonable temporary safeguards where necessary to respond to suspected compromise.
6. CUSTOMER SYSTEMS AND INTEGRATION
6.1 Customer Architecture
Customer controls its deployment architecture and is responsible for ensuring that AI traffic intended to be governed by Kestrel is routed through applicable Kestrel control points.
6.2 Bypassed Traffic
Kestrel cannot inspect, govern, audit or control traffic that does not pass through an integrated Kestrel control point.
Customer acknowledges that direct model access, alternative credentials, unsupported routes or bypass mechanisms may render Kestrel controls ineffective.
6.3 Customer Responsibilities
Customer is responsible for:
(a) Customer Systems;
(b) network connectivity;
(c) certificates and endpoints;
(d) upstream and downstream applications;
(e) identity-provider configuration;
(f) model-provider credentials;
(g) prompts and system messages;
(h) datasets;
(i) tool permissions;
(j) model settings;
(k) schemas;
(l) quotas;
(m) integration testing;
(n) business continuity; and
(o) prevention of unintended bypass.
6.4 Technical Changes
Kestrel may modify interfaces, APIs and technical requirements to maintain, improve or secure the Service.
Kestrel will use commercially reasonable efforts to provide advance notice of material breaking changes where practicable.
Immediate changes may be made to address security vulnerabilities, legal requirements, provider changes or urgent operational risks.
PART II — AI GOVERNANCE AND RUNTIME CONTROL
7. NATURE OF THE SERVICE
Kestrel is an enterprise AI governance, security and runtime-control layer designed to assist organisations in governing interaction between enterprise AI applications, agents, models, datasets and tools.
Depending on configuration and technical availability, functionality may include:
(a) prompt inspection;
(b) response inspection;
(c) Tool Action evaluation;
(d) authentication of agents and service identities;
(e) intent classification;
(f) data-sensitivity classification;
(g) personal-data detection and redaction;
(h) prompt-injection and adversarial-technique detection;
(i) contextual and multi-turn risk assessment;
(j) policy enforcement;
(k) allow, audit, hold or deny decisions;
(l) tenant-, organisation-, team-, role- or agent-scoped policy;
(m) policy simulation and shadow mode;
(n) AI-system, model, dataset, vendor, agent and tool inventories;
(o) risk and lifecycle workflows;
(p) assurance observations and findings;
(q) evidence collection;
(r) audit and integrity records;
(s) cryptographic receipts and checkpoints;
(t) executive reporting;
(u) operational metrics;
(v) SIEM or webhook integrations; and
(w) related functionality identified in current Documentation.
The precise Service purchased by Customer is determined by the applicable Order Form and current Documentation.
8. NO GUARANTEE OF AI SAFETY OR COMPLIANCE
Customer acknowledges that artificial-intelligence, cybersecurity and automated-classification systems are inherently probabilistic and imperfect.
Kestrel does not warrant or represent that the Service:
(a) will identify every threat;
(b) will identify every prompt-injection or jailbreak technique;
(c) will detect every item of personal, confidential or sensitive information;
(d) will prevent every unauthorised disclosure;
(e) will prevent every harmful model response;
(f) will eliminate false positives or false negatives;
(g) will prevent all attacks;
(h) will make Customer legally compliant;
(i) will satisfy every regulator, auditor or certification body;
(j) will produce error-free classifications;
(k) will ensure desired model behaviour;
(l) will eliminate the need for human oversight;
(m) will make an AI system safe for a particular purpose; or
(n) will eliminate Customer’s need for independent security, privacy, legal, compliance or risk controls.
Kestrel is a risk-control and decision-support system, not a substitute for Customer’s judgment or legal obligations.
9. AUTOMATED CONTROL DECISIONS
9.1 Automated Processing
Kestrel may make automated decisions based on:
(a) Customer-configured rules;
(b) policy configuration;
(c) patterns and signatures;
(d) classifiers;
(e) confidence thresholds;
(f) session context;
(g) risk state;
(h) security signals; and
(i) other configured or documented factors.
9.2 Possible Actions
Depending on configuration, Kestrel may:
(a) allow activity;
(b) record activity;
(c) redact information;
(d) transform content;
(e) delay activity;
(f) hold activity for review;
(g) deny activity;
(h) require escalation; or
(i) produce another documented policy result.
9.3 Probabilistic Results
Automated classifications and security conclusions may be incomplete or incorrect.
9.4 Customer Decision
Customer remains responsible for deciding:
(a) which policies to deploy;
(b) thresholds;
(c) escalation rules;
(d) whether human review is required;
(e) whether Customer permits overrides;
(f) how downstream systems react; and
(g) how Customer uses Kestrel outputs.
9.5 Operational Consequences
Customer acknowledges that restrictive configuration may cause legitimate activity to be blocked, delayed, redacted or held.
Customer is responsible for designing appropriate fallback procedures, exception handling, continuity arrangements and human review.
10. MODEL OUTPUTS
Kestrel does not originate or independently verify every output generated by Third-Party Services.
Customer is responsible for independently validating any model output where the output may materially affect:
(a) safety;
(b) finances;
(c) legal rights;
(d) regulatory obligations;
(e) health;
(f) employment;
(g) security;
(h) critical operations; or
(i) other significant decisions.
No Kestrel classification, recommendation or risk score constitutes legal, financial, medical, investment, accounting or other regulated professional advice.
11. PERSONAL-DATA REDACTION
Where enabled, Kestrel may identify, mask, tokenise, redact or otherwise transform detected personal or sensitive data.
These functions reduce risk but cannot guarantee that every relevant value will be identified.
Customer must independently determine whether its data-handling architecture satisfies Applicable Law and contractual obligations.
12. AUDIT RECORDS, RECEIPTS AND CRYPTOGRAPHIC EVIDENCE
Kestrel may generate audit records, hashes, linked records, signatures, receipts, Merkle checkpoints, integrity proofs and related evidence.
These mechanisms are designed to support integrity verification and tamper evidence.
They do not, by themselves, establish:
(a) the factual truth of the underlying event;
(b) completeness of all events;
(c) legal admissibility;
(d) regulatory acceptance;
(e) identity beyond the properties actually cryptographically verified;
(f) absence of all tampering;
(g) compliance with any legal evidentiary standard; or
(h) that an auditor, regulator, insurer, tribunal or court will regard the evidence as sufficient.
Customer remains responsible for evidence preservation required by law.
13. HUMAN OVERSIGHT
Customer must implement human oversight appropriate to the nature and risk of its AI systems.
Customer must not knowingly configure the Service so that a materially consequential automated decision is treated as unquestionably correct merely because Kestrel generated or approved a classification.
PART III — CUSTOMER RESPONSIBILITIES
14. RESPONSIBILITY FOR CUSTOMER AI SYSTEMS
Customer retains responsibility for:
(a) its AI systems;
(b) its models;
(c) model-provider selection;
(d) prompts and system messages;
(e) datasets and training data;
(f) agents;
(g) tools;
(h) action permissions;
(i) business processes;
(j) policies;
(k) end-user notices;
(l) legal bases for processing;
(m) consents;
(n) human oversight;
(o) validation;
(p) risk acceptance;
(q) incident response;
(r) regulatory submissions;
(s) business continuity;
(t) backups; and
(u) decisions made using AI Outputs.
15. CUSTOMER AUTHORITY OVER DATA
Customer represents and warrants that it has all rights, permissions, notices, consents and lawful authority necessary to provide Customer Content to Kestrel and to instruct Kestrel to process that Customer Content.
Customer must not submit data where doing so violates:
(a) Applicable Law;
(b) intellectual-property rights;
(c) privacy rights;
(d) confidentiality obligations;
(e) contractual restrictions; or
(f) applicable Model Provider requirements.
16. THIRD-PARTY PROVIDER TERMS
Customer is responsible for complying with terms applicable to Model Providers and Third-Party Services selected, supplied or contracted directly by Customer.
Kestrel is not responsible for Customer’s breach of those terms.
PART IV — DATA AND PRIVACY
17. CUSTOMER CONTENT
17.1 Ownership
As between Kestrel and Customer, Customer retains its ownership rights in Customer Content.
17.2 Processing Licence
Customer grants Kestrel and authorised Subprocessors a limited, non-exclusive licence during the Agreement to host, receive, copy, transmit, inspect, analyse, classify, redact, transform, secure, store, log, display and otherwise process Customer Content solely as reasonably necessary to:
(a) provide the Service;
(b) enforce Customer policies;
(c) secure the Service;
(d) investigate abuse;
(e) provide support;
(f) comply with Applicable Law; and
(g) perform other processing expressly authorised under the Agreement and DPA.
17.3 No Sale of Customer Content
Kestrel does not acquire ownership of Customer Content merely because it processes Customer Content.
17.4 Model Training
Kestrel’s permitted use of Customer Content for training or evaluation purposes is governed by the position specified in Schedule 1 and the applicable DPA.
17.5 Aggregated Data
Kestrel may create statistical, aggregated or de-identified information derived from operation of the Service, provided the resulting information does not reasonably identify Customer, an Authorised User or an individual.
Kestrel may use such information for:
(a) service analytics;
(b) capacity planning;
(c) security research;
(d) abuse detection;
(e) reliability;
(f) product development;
(g) benchmarking of Kestrel’s own systems; and
(h) business operations.
Kestrel will not intentionally re-identify properly de-identified data except to test the effectiveness of de-identification or where legally required.
18. PRIVACY AND DATA PROCESSING
18.1 Kestrel’s Own Processing
Personal data processed by Kestrel for its own business purposes is governed by Kestrel’s Privacy Policy.
18.2 Customer Personal Data
To the extent Kestrel processes personal data on Customer’s behalf as a processor, data intermediary or equivalent role, the Data Processing Addendum applies.
18.3 Customer Responsibilities
Customer remains responsible for:
(a) determining lawful grounds for its processing;
(b) providing required notices;
(c) obtaining required consent;
(d) responding to data-subject rights;
(e) data minimisation;
(f) determining retention periods;
(g) determining whether transfers are lawful; and
(h) determining whether Customer’s proposed AI deployment is permitted.
18.4 Subprocessors
Kestrel may use Subprocessors as identified through the Subprocessor List or DPA.
Kestrel remains responsible for Subprocessors to the extent required under the DPA and Applicable Law.
19. SECURITY
19.1 Kestrel Safeguards
Kestrel will maintain reasonable administrative, organisational and technical safeguards appropriate to the Service and risk, as further described in its Security Addendum or Documentation.
19.2 No Absolute Security
No internet-connected or software-based system can be guaranteed completely secure.
19.3 Security Incident
Kestrel will notify Customer of a confirmed Security Incident in accordance with the applicable DPA, Security Addendum and Applicable Law.
19.4 Exclusions
Events are not Security Incidents attributable to Kestrel merely because they involve:
(a) Customer credentials compromised outside Kestrel;
(b) Customer Systems;
(c) Customer misconfiguration;
(d) Customer-authorised activity;
(e) unsupported integrations;
(f) Customer bypass of security controls; or
(g) third-party systems outside Kestrel’s responsibility,
except to the extent Kestrel’s breach materially contributed to the event.
PART V — INTELLECTUAL PROPERTY
20. KESTREL TECHNOLOGY
20.1 Ownership
Kestrel and its licensors retain all right, title and interest in and to the Kestrel Technology.
This includes:
(a) software;
(b) gateway technology;
(c) APIs;
(d) dashboards;
(e) source code;
(f) object code;
(g) architecture;
(h) policy engines;
(i) classifiers;
(j) detection logic;
(k) templates;
(l) control frameworks;
(m) workflows;
(n) documentation;
(o) interfaces;
(p) designs;
(q) models;
(r) inventions;
(s) know-how;
(t) improvements; and
(u) derivative works.
20.2 Customer Configurations
Customer owns Customer Content incorporated into Customer-created policies and configurations.
Kestrel retains ownership of underlying Kestrel Technology, templates, schema, engines and generic methods used to implement them.
20.3 Reports and Exports
Subject to payment of applicable Fees, Customer may internally use reports and evidence exports generated specifically for Customer.
Such rights do not transfer ownership of Kestrel’s underlying technology, report architecture or generic templates.
20.4 Feedback
Customer grants Kestrel a perpetual, worldwide, irrevocable, transferable, sublicensable, royalty-free right to use and incorporate voluntary Feedback without restriction.
Kestrel will not exercise this right in a manner that intentionally publicly identifies Customer or discloses Customer Confidential Information without permission.
21. CONFIDENTIALITY
21.1 Confidential Information
“Confidential Information” means non-public information disclosed by one party to the other that a reasonable recipient would understand to be confidential.
It includes:
(a) Customer Content;
(b) non-public security information;
(c) source code;
(d) product architecture;
(e) vulnerabilities;
(f) business plans;
(g) pricing;
(h) non-public roadmaps;
(i) financial information;
(j) trade secrets; and
(k) confidential commercial information.
21.2 Obligations
The receiving party must:
(a) use Confidential Information only to perform or exercise rights under the Agreement;
(b) protect it using at least reasonable care;
(c) disclose it only to personnel, professional advisers, Affiliates and subcontractors with a legitimate need to know and appropriate confidentiality obligations; and
(d) not disclose it to another person except as authorised.
21.3 Exclusions
Confidential Information does not include information that the receiving party establishes:
(a) became public without breach;
(b) was lawfully known without confidentiality restriction before receipt;
(c) was independently developed without use of the disclosing party’s Confidential Information; or
(d) was lawfully received from another source without confidentiality obligation.
21.4 Compelled Disclosure
A party may disclose Confidential Information where legally compelled, provided it gives advance notice where legally permitted and reasonably cooperates with protective measures.
21.5 Security Information
Customer must not publicly disclose non-public vulnerabilities, penetration-test results or detailed security architecture in a manner that creates material security risk.
Nothing in this Section prevents lawful reporting to regulators, law enforcement, professional advisers or protected whistleblowing channels.
21.6 Injunctive Relief
Unauthorised disclosure of Confidential Information may cause harm not adequately compensated by damages.
The affected party may seek injunctive or equitable relief where legally available.
21.7 Survival
Confidentiality obligations survive for five (5) years following termination, except trade secrets and Customer Content remain protected for so long as they qualify for protection under Applicable Law or another contractual obligation requires longer protection.
PART VI — ACCEPTABLE USE AND RESTRICTIONS
22. ACCEPTABLE USE
Customer and Authorised Users must comply with Schedule 2.
23. RESTRICTIONS
Except to the limited extent Applicable Law makes a restriction unenforceable, Customer must not:
(a) reverse engineer, decompile or disassemble the Service;
(b) attempt to obtain Kestrel source code;
(c) circumvent authentication, tenant boundaries or access controls;
(d) disable or defeat metering;
(e) remove proprietary notices;
(f) resell or sublicense the Service unless expressly authorised;
(g) operate the Service as a service bureau for unrelated third parties unless expressly authorised;
(h) white-label the Service without permission;
(i) use the Service to develop a substantially competing product through systematic extraction of non-public functionality;
(j) conduct unauthorised penetration testing;
(k) access another tenant’s data;
(l) interfere with infrastructure;
(m) intentionally overload systems; or
(n) violate the AUP.
24. COMPETITIVE ANALYSIS AND BENCHMARKING
Customer may conduct ordinary internal testing of its purchased Service.
Customer may not, without Kestrel’s prior written consent:
(a) access the Service primarily to reverse engineer competitive functionality;
(b) systematically benchmark Kestrel for the principal purpose of developing or marketing a competing service; or
(c) publish non-public security or performance testing in a materially misleading manner.
This Section does not prohibit lawful independent research that cannot legally be restricted.
PART VII — THIRD-PARTY SERVICES
25. MODEL PROVIDERS AND THIRD-PARTY SERVICES
25.1 Dependencies
The Service may interoperate with Model Providers and Third-Party Services.
25.2 Independent Terms
Third-Party Services may have independent:
(a) terms;
(b) pricing;
(c) retention rules;
(d) privacy practices;
(e) usage limits;
(f) availability;
(g) content restrictions; and
(h) security practices.
25.3 Customer-Supplied Accounts
Where Customer supplies its own third-party account, licence, API key or credential, Customer is responsible for the applicable relationship with that provider.
25.4 Provider Changes
Third parties may modify APIs, models or services.
Kestrel is not liable for a third party’s independent decision to discontinue or materially alter a Third-Party Service, but Kestrel will use commercially reasonable efforts to mitigate material effects on Supported Integrations where appropriate.
25.5 Suspension of Integration
Kestrel may suspend an integration that creates a credible security, legal, compliance or operational risk.
PART VIII — FEES AND COMMERCIAL TERMS
26. FEES
Customer must pay all Fees specified in the applicable Order Form, pricing arrangement or Schedule 3.
Unless expressly stated otherwise, all Fees are denominated in United States dollars (USD).
27. STANDARD PLAN PRICING
Subject to an Order Form and future prospective pricing changes:
27.1 Pilot
Platform Fee: USD 500 per month
Included Requests: 100,000 Requests per month
Usage Cap: 100,000 Requests per month
Maximum Pilot Term: three months
27.2 Production
Platform Fee: USD 2,500 per month
Included Requests: the first 1,000,000 Requests per monthly billing period
Usage pricing:
- Requests above 1,000,000 through 10,000,000 per monthly billing period: USD 1.00 per 1,000 additional Requests; and
- Requests above 10,000,000 per monthly billing period: USD 0.60 per 1,000 additional Requests.
27.3 Enterprise Volume
Platform Fees, usage pricing, commitments and other commercial terms are established by Order Form.
The standard Enterprise Volume Subscription Term is annual.
28. BILLING
Unless an Order Form states otherwise:
(a) recurring platform Fees are invoiced in advance;
(b) measured usage is invoiced in arrears;
(c) Customer must pay invoices within the period specified in Schedule 1;
(d) payment obligations are non-cancellable during a committed Subscription Term except where the Agreement expressly provides otherwise; and
(e) Fees are non-refundable except as expressly stated in the Agreement or required by Applicable Law.
29. METERING
Kestrel’s service records constitute the initial basis for determining usage.
Customer may dispute an invoice in good faith by providing reasonably detailed information identifying the disputed amount.
Kestrel will investigate genuine metering disputes and correct verified errors.
30. TAXES
Fees exclude applicable GST, VAT, sales, use, withholding and similar taxes unless expressly stated otherwise.
Customer is responsible for taxes arising from its purchase, excluding taxes imposed on Kestrel’s net income.
Where Customer is legally required to withhold tax, Customer must provide appropriate official documentation.
The parties will cooperate reasonably concerning available treaty relief or exemptions.
31. OVERDUE AMOUNTS
Undisputed overdue amounts may accrue interest at the rate specified in Schedule 1.
Kestrel may recover reasonable lawful collection costs.
32. NON-PAYMENT SUSPENSION
Kestrel may suspend Service for materially overdue undisputed amounts after giving reasonable notice and an opportunity to cure.
Kestrel may act more quickly where there is credible evidence of fraud, payment abuse or material credit risk.
33. NO SET-OFF
Customer may not withhold or set off amounts owed to Kestrel except where required by Applicable Law or expressly agreed in writing.
34. PRICE CHANGES
Kestrel may change public pricing prospectively.
A price change does not retroactively alter Fees committed under an existing fixed-term Order Form.
For an automatically renewing subscription, Kestrel will provide reasonable advance notice before materially increasing recurring Fees.
PART IX — SERVICE OPERATION
35. AVAILABILITY
Unless an Order Form expressly incorporates an SLA:
KESTREL DOES NOT PROVIDE A CONTRACTUAL UPTIME PERCENTAGE OR SERVICE-CREDIT COMMITMENT.
Kestrel will nevertheless use commercially reasonable efforts to operate and maintain the Service in a manner suitable for the purchased subscription.
36. MAINTENANCE
Kestrel may perform:
(a) scheduled maintenance;
(b) emergency maintenance;
(c) security updates;
(d) upgrades; and
(e) infrastructure changes.
Where practicable, Kestrel will provide advance notice of maintenance expected to cause material disruption.
37. SUPPORT
Support is provided in accordance with Schedule 1, the applicable Order Form or an incorporated Support Schedule.
Unless expressly designated as contractual response commitments, response targets are operational goals and not guarantees of resolution.
38. CHANGES TO SERVICE
Kestrel may modify and improve the Service.
Kestrel will use commercially reasonable efforts to avoid materially reducing the core functionality purchased under a committed Order Form during its committed term.
If Kestrel permanently removes material paid functionality and that removal substantially impairs Customer’s purchased use case, Kestrel may, as appropriate:
(a) provide substantially equivalent functionality;
(b) provide a workaround;
(c) adjust the affected subscription; or
(d) permit termination of the materially affected Service with a pro-rata refund of prepaid unused Fees.
This does not apply to changes necessary because of:
(a) Applicable Law;
(b) urgent security risks;
(c) third-party deprecation beyond Kestrel’s reasonable control;
(d) Customer’s unsupported configuration; or
(e) free, beta or preview functionality.
39. ROADMAPS AND FUTURE FEATURES
Roadmap statements, demonstrations, mock-ups, screenshots, anticipated features and estimated release dates are informational only.
Customer must not base a purchasing obligation on a future feature unless the applicable Order Form expressly identifies delivery of that feature as a contractual commitment.
PART X — BETA AND PREVIEW FEATURES
40. BETA SERVICES
Kestrel may offer functionality designated “beta”, “preview”, “experimental”, “early access”, “developer preview” or similar.
Unless otherwise stated:
(a) participation is optional;
(b) the feature may contain defects;
(c) functionality may change;
(d) Kestrel may discontinue it;
(e) it is not subject to an SLA;
(f) it must not be relied on for safety-critical or essential production functions;
(g) support may be limited; and
(h) Kestrel may request Feedback.
Kestrel will not designate established production functionality “beta” merely to evade commitments expressly made for that functionality.
PART XI — PROFESSIONAL SERVICES
41. PROFESSIONAL SERVICES
Professional Services require an Order Form or Statement of Work identifying applicable:
(a) scope;
(b) deliverables;
(c) dependencies;
(d) responsibilities;
(e) timing;
(f) Fees;
(g) expenses;
(h) acceptance criteria; and
(i) change-control procedures.
Implementation guidance does not constitute legal or regulatory advice.
Customer is responsible for determining whether configurations ultimately selected by Customer satisfy Customer’s legal and business requirements.
Delays caused by Customer’s failure to provide required access, personnel, information or decisions may extend applicable timelines.
PART XII — WARRANTIES
42. MUTUAL AUTHORITY WARRANTY
Each party warrants that it has authority to enter into the Agreement.
43. KESTREL LIMITED SERVICE WARRANTY
For paid production Services, Kestrel warrants that the Service will, under normal authorised use, materially conform to the applicable Documentation.
Customer must notify Kestrel of a material non-conformity with sufficient information for Kestrel to reproduce or investigate it.
Kestrel’s obligation is to use commercially reasonable efforts to:
(a) correct the non-conformity;
(b) provide a reasonable workaround; or
(c) re-perform the affected Service.
If Kestrel cannot remedy a material non-conformity within a reasonable period and it substantially defeats the principal purpose of the affected Service, Customer may terminate the materially affected portion and receive a pro-rata refund of prepaid Fees covering the unused terminated period.
44. WARRANTY EXCLUSIONS
The warranty in Section 43 does not apply where a problem results from:
(a) Customer Systems;
(b) unauthorised modification;
(c) unsupported integration;
(d) misuse;
(e) Customer configuration contrary to Documentation;
(f) Model Provider behaviour;
(g) third-party systems outside Kestrel’s control;
(h) Customer’s failure to implement required updates;
(i) Beta Services; or
(j) force majeure.
45. DISCLAIMERS
EXCEPT FOR EXPRESS WARRANTIES IN THE AGREEMENT AND TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED WITHOUT OTHER EXPRESS, IMPLIED, STATUTORY OR COLLATERAL WARRANTIES OR CONDITIONS.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, KESTREL DISCLAIMS IMPLIED WARRANTIES OR CONDITIONS OF:
(a) MERCHANTABILITY;
(b) SATISFACTORY QUALITY;
(c) FITNESS FOR A PARTICULAR PURPOSE;
(d) NON-INFRINGEMENT, EXCEPT TO THE EXTENT ADDRESSED BY SECTION 48;
(e) UNINTERRUPTED AVAILABILITY;
(f) ERROR-FREE OPERATION; AND
(g) PARTICULAR RESULTS.
Nothing in these Terms excludes a warranty or liability that cannot lawfully be excluded.
PART XIII — INDEMNITIES
46. CUSTOMER INDEMNITY
Subject to Section 50, Customer will defend Kestrel and its officers, directors and employees against a third-party claim to the extent arising from:
(a) Customer Content allegedly violating intellectual-property, privacy, publicity or confidentiality rights;
(b) Customer’s unlawful AI system or deployment;
(c) Customer’s material violation of the AUP;
(d) Customer’s use of Kestrel in an expressly prohibited regulated use;
(e) Customer’s fraud or wilful misconduct;
(f) Customer’s unauthorised use of another person’s credentials or data;
(g) Customer’s tools, datasets, products or services; or
(h) Customer instructions that Kestrel executes as authorised and that create the claimed violation.
The indemnity applies only to the extent the claim is attributable to Customer and not Kestrel’s own breach, negligence or misconduct.
47. KESTREL INTELLECTUAL-PROPERTY INDEMNITY
Kestrel will defend Customer against a third-party claim alleging that the unmodified paid Service, when used by Customer as authorised, directly infringes that third party’s copyright, patent or registered trademark, and will pay damages finally awarded against Customer or settlement amounts approved by Kestrel.
This indemnity does not apply to a claim resulting from:
(a) Customer Content;
(b) Customer modification;
(c) use contrary to Documentation;
(d) combination with items not supplied by Kestrel where the combination causes the infringement;
(e) continued use after Kestrel gives notice to stop;
(f) an unsupported or obsolete version where a non-infringing replacement was made available; or
(g) compliance with Customer-specific designs or instructions.
48. IP REMEDIES
If the Service becomes, or Kestrel reasonably believes it is likely to become, subject to an infringement claim, Kestrel may:
(a) procure continued rights;
(b) modify the Service;
(c) replace affected functionality with substantially equivalent functionality; or
(d) terminate the affected Service and refund prepaid unused Fees for the terminated period.
This Section states Customer’s exclusive contractual remedy for third-party intellectual-property infringement claims relating to the Service, except where Applicable Law prohibits such limitation.
49. INDEMNITY PROCEDURE
An indemnified party must:
(a) provide reasonably prompt notice of the claim;
(b) provide reasonable cooperation at the indemnifying party’s expense; and
(c) permit the indemnifying party to control defence and settlement.
Delay in notice reduces obligations only to the extent the delay materially prejudices the defence.
The indemnifying party may not settle a claim in a manner that:
(a) admits wrongdoing by the indemnified party;
(b) imposes non-monetary obligations on the indemnified party;
(c) materially restricts the indemnified party’s business; or
(d) requires payment by the indemnified party,
without prior written consent, not to be unreasonably withheld.
PART XIV — LIMITATION OF LIABILITY
50. LIABILITY FRAMEWORK
THE PARTIES AGREE THAT THE LIMITATIONS IN THIS PART ALLOCATE COMMERCIAL RISK BETWEEN SOPHISTICATED BUSINESS PARTIES AND ARE REFLECTED IN THE FEES CHARGED.
THE LIMITATIONS APPLY ONLY TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW.
51. EXCLUDED LOSSES
Subject to Section 54, neither party is liable to the other for:
(a) indirect loss;
(b) consequential loss;
(c) incidental loss;
(d) special loss;
(e) exemplary or punitive damages;
(f) loss of anticipated profit;
(g) loss of anticipated revenue;
(h) loss of anticipated savings;
(i) loss of goodwill;
(j) loss of business opportunity;
(k) loss of anticipated contracts; or
(l) indirect business interruption,
to the extent such categories are legally excludable and are not direct losses recoverable notwithstanding their label.
52. ORDINARY AGGREGATE LIABILITY CAP
Subject to Sections 53 and 54, each party’s aggregate liability arising out of or relating to an affected Order Form will not exceed:
For a Production or Enterprise subscription:
the Fees paid or payable to Kestrel under the affected Order Form during the twelve (12) months immediately preceding the event giving rise to liability.
For a claim arising during the first twelve months, the cap will be the Fees paid and contractually payable under the affected Order Form through the first anniversary of its Effective Date.
For a Pilot:
the greater of:
(a) all Fees paid or payable for that Pilot; and
(b) USD 5,000.
53. SUPER-CAP
Subject to Section 54, aggregate liability for:
(a) breach of confidentiality obligations;
(b) Kestrel’s IP indemnity;
(c) material breach of the DPA; and
(d) a Security Incident caused by a material breach of Kestrel’s expressly agreed security obligations,
will not exceed two (2) times the applicable ordinary liability cap in Section 52.
54. LIABILITY NOT LIMITED BY THE CONTRACTUAL CAPS
Nothing in the Agreement excludes or limits liability to the extent such exclusion or limitation is prohibited by Applicable Law.
Without limiting that principle, the contractual caps do not limit:
(a) Customer’s obligation to pay properly due Fees;
(b) either party’s fraud or fraudulent misrepresentation;
(c) death or personal injury caused by negligence to the extent liability cannot lawfully be excluded;
(d) deliberate infringement or misappropriation of the other party’s intellectual property;
(e) wilful misconduct where exclusion would be unlawful; or
(f) any other liability that Applicable Law prohibits the parties from limiting.
55. REGULATORY FINES
Neither party assumes responsibility for fines, penalties or enforcement measures imposed because of the other party’s independent legal violation.
Where a fine results from conduct attributable to both parties, responsibility will be allocated according to their respective responsibility to the extent permitted by Applicable Law.
56. THIRD-PARTY AND CUSTOMER-CONTROLLED EVENTS
In determining Kestrel’s liability, Kestrel is not responsible for loss caused solely by:
(a) Customer Systems;
(b) bypassed traffic;
(c) Customer’s configuration;
(d) Customer overrides;
(e) Customer credentials compromised outside Kestrel;
(f) unsupported integrations;
(g) Customer-selected Model Provider behaviour;
(h) Customer instructions; or
(i) events otherwise outside Kestrel’s reasonable control.
This Section does not excuse Kestrel from its own contractual breach merely because a third party was involved.
57. DUTY TO MITIGATE
Each party must take reasonable steps to mitigate recoverable loss.
58. CLAIM PERIOD
Except for claims involving fraud, deliberate concealment, unpaid Fees, intellectual-property ownership or another matter for which Applicable Law does not permit contractual shortening, a party should provide written notice of a contractual claim promptly after becoming aware of it.
Nothing in this Section eliminates a claim solely because preliminary notice was delayed unless the delay materially prejudices the responding party or a valid limitation period has expired.
59. NO PERSONAL LIABILITY
To the maximum extent permitted by law, no Kestrel director, officer, employee, shareholder, contractor or agent incurs personal contractual liability to Customer solely because that person performed obligations on Kestrel’s behalf.
PART XV — SUSPENSION
60. SUSPENSION RIGHTS
Kestrel may suspend affected access where reasonably necessary because of:
(a) credible security risk;
(b) unauthorised access;
(c) material AUP violation;
(d) legal prohibition;
(e) sanctions restrictions;
(f) material risk to other customers or infrastructure;
(g) repeated abuse;
(h) materially overdue undisputed payment;
(i) provider restriction; or
(j) imminent risk of material harm.
61. EMERGENCY SUSPENSION
Where delay would create material security, legal or operational risk, Kestrel may suspend immediately.
Kestrel will provide notice as soon as reasonably practicable where legally permitted.
62. PROPORTIONALITY
Where reasonably practicable, Kestrel will limit suspension to the affected Account, credential, integration, function or traffic rather than suspending unrelated Services.
63. RESTORATION
Kestrel will restore suspended access after the underlying issue is reasonably remedied, subject to continuing legal or security restrictions.
PART XVI — TERM AND TERMINATION
64. TERM
These Terms begin on the Effective Date and continue until all applicable subscriptions have expired or been terminated.
65. SUBSCRIPTION TERMS
Subscription terms are determined by:
(a) Schedule 1;
(b) Schedule 3;
(c) Schedule 4; and
(d) an applicable Order Form.
An Order Form controls where it expressly provides different terms.
66. TERMINATION FOR MATERIAL BREACH
Either party may terminate an affected Order Form if the other party materially breaches the Agreement and fails to cure the breach within thirty (30) days after written notice describing the breach.
67. IMMEDIATE TERMINATION
A party may terminate immediately where:
(a) a material breach is incapable of cure;
(b) the other party commits fraud materially affecting the Agreement;
(c) continued performance becomes unlawful;
(d) the other party commits severe intentional security abuse;
(e) continued use would violate sanctions or export restrictions; or
(f) termination is otherwise expressly permitted by the Agreement.
68. INSOLVENCY
To the extent permitted by Applicable Law, either party may terminate where the other:
(a) ceases substantially all business;
(b) enters liquidation other than a solvent restructuring;
(c) becomes subject to a winding-up order; or
(d) enters an equivalent insolvency proceeding that is not dismissed within a reasonable period.
69. TERMINATION FOR CONVENIENCE
Month-to-Month Production
If Schedule 1 establishes month-to-month Production subscriptions, Customer may prevent renewal by cancelling in accordance with the specified cancellation process.
Committed Terms
A committed Order Form is not terminable for convenience unless that Order Form expressly permits it.
Kestrel
Kestrel may elect not to renew a subscription by providing reasonable advance notice.
Kestrel will not terminate a fully prepaid committed subscription for convenience mid-term merely to charge Customer a higher price.
70. EFFECT OF TERMINATION
Upon termination:
(a) Customer’s right to access the terminated Service ends;
(b) accrued payment obligations remain due;
(c) Kestrel may issue a final usage invoice;
(d) Customer must cease using Kestrel Technology except as expressly permitted;
(e) Customer may export available Customer Data during the period stated in Schedule 1;
(f) Kestrel may subsequently delete Customer Data in accordance with the DPA and retention architecture; and
(g) provisions intended by their nature to survive remain effective.
71. SURVIVAL
Without limitation, provisions concerning:
(a) Fees;
(b) confidentiality;
(c) intellectual property;
(d) Feedback;
(e) indemnities;
(f) liability;
(g) dispute resolution;
(h) data retained pursuant to law;
(i) audit evidence; and
(j) interpretation
survive to the extent necessary to give them effect.
PART XVII — TERRITORIAL, REGULATORY AND LEGAL COMPLIANCE
72. GENERAL COMPLIANCE
Each party must comply with Applicable Law governing its own performance.
Customer is responsible for laws governing Customer’s:
(a) AI deployment;
(b) business sector;
(c) models;
(d) end users;
(e) regulated decisions;
(f) datasets;
(g) notices;
(h) licences;
(i) human-review processes; and
(j) records.
73. NO REGULATORY GUARANTEE
Purchase or use of Kestrel does not mean that:
(a) Customer is compliant with any AI law;
(b) Customer satisfies a regulator;
(c) Customer has completed a legally required risk assessment;
(d) Customer has satisfied cybersecurity obligations;
(e) a Kestrel control satisfies a mandatory industry control; or
(f) Kestrel has certified Customer’s compliance.
Any such commitment must be expressly stated in a signed Order Form or regulatory addendum.
74. EUROPEAN UNION AND EUROPEAN ECONOMIC AREA
Kestrel is not currently available for deployment within the European Union or European Economic Area as we continue our work toward supporting applicable requirements under the EU Artificial Intelligence Act. EU and EEA availability will be introduced once the necessary compliance requirements have been addressed.
Customer must not deploy the Service contrary to the territorial restriction described in Schedule 1.
Customer must promptly notify Kestrel if its proposed deployment location changes in a manner that may make the restriction applicable.
This restriction does not represent that no European law could ever apply to activity occurring outside the EU or EEA.
In particular, nothing in these Terms should be interpreted as stating that the EU Artificial Intelligence Act, GDPR or any other European legislation can never have extraterritorial effect.
75. SANCTIONS AND EXPORT CONTROLS
Customer must not access, export, re-export, transfer or use the Service in violation of applicable sanctions, export-control or strategic-goods laws.
Customer represents that it will not knowingly use the Service:
(a) on behalf of a prohibited or restricted person where unlawful;
(b) for a prohibited end use;
(c) in violation of applicable embargo restrictions; or
(d) to transfer controlled technology unlawfully.
Kestrel may conduct reasonable compliance screening and request information reasonably necessary to assess legal restrictions.
76. ANTI-BRIBERY AND CORRUPTION
Each party must comply with anti-bribery and anti-corruption laws applicable to its conduct relating to the Agreement.
No party may offer or accept an improper payment on behalf of the other.
PART XVIII — AUDIT AND VERIFICATION
77. USAGE VERIFICATION
Kestrel may use its service records to verify:
(a) usage limits;
(b) Account scope;
(c) licensing;
(d) territorial restrictions;
(e) request volumes; and
(f) AUP compliance.
Kestrel will not use this Section as a general right to inspect unrelated Customer Systems.
78. CUSTOMER SECURITY REVIEWS
Where Customer reasonably requires information concerning Kestrel security or privacy, Kestrel may initially satisfy the request through:
(a) security documentation;
(b) questionnaires;
(c) available audit reports;
(d) certifications;
(e) penetration-test summaries; or
(f) other reasonable evidence.
Any additional audit rights are governed by the DPA, Security Addendum or Order Form.
Audits must not unreasonably interfere with Kestrel operations or compromise other customers’ confidentiality or security.
PART XIX — PUBLICITY
79. CUSTOMER NAME AND LOGO
Kestrel will not publicly identify Customer as a Kestrel customer or use Customer’s trademarks for promotional purposes without prior written consent.
An Order Form may grant specific publicity rights.
80. ANONYMISED STATISTICS
Kestrel may publish aggregate statistics that do not reasonably identify Customer or disclose Customer Confidential Information.
PART XX — WEBSITE AND MARKETING MATERIALS
81. ILLUSTRATIVE CONTENT
Website screenshots, simplified UI, example metrics, animations, diagrams and mock-ups may be illustrative.
They do not necessarily represent the exact interface, configuration or functionality available to every Customer.
82. PRODUCT DESCRIPTION
The applicable Order Form and current Documentation determine the Service purchased.
Marketing materials do not constitute a guarantee that:
(a) every depicted feature is available;
(b) every integration is supported;
(c) every feature works identically for every architecture; or
(d) unreleased functionality will be delivered.
83. WEBSITE INFORMATION
Kestrel attempts to maintain accurate Website information but may correct errors and update descriptions.
Website pricing is subject to an executed Order Form and prospective pricing changes.
PART XXI — DISPUTE RESOLUTION
84. GOOD-FAITH ESCALATION
Before commencing ordinary arbitration proceedings, a party must provide written notice describing the dispute.
The parties will attempt in good faith to resolve the dispute through representatives with settlement authority for at least thirty (30) days.
This requirement does not prevent a party from seeking urgent interim, injunctive or protective relief.
85. GOVERNING LAW
The Agreement and any non-contractual obligations arising out of or relating to it are governed by the laws of the Republic of Singapore, without regard to conflict-of-law principles that would require application of another jurisdiction’s laws.
86. SIAC ARBITRATION
Any dispute, controversy or claim arising out of or relating to the Agreement, including any question concerning its existence, validity, interpretation, performance, breach or termination, that is not resolved under Section 84 will be finally resolved by arbitration administered by the Singapore International Arbitration Centre (“SIAC”) in accordance with the SIAC Rules in force when the arbitration is commenced, which Rules are deemed incorporated into this Section.
The seat of arbitration is Singapore.
The language of arbitration is English.
Unless the parties agree otherwise:
(a) disputes with an amount in controversy below USD 5,000,000 will be determined by one arbitrator; and
(b) disputes with an amount in controversy of USD 5,000,000 or more will be determined by three arbitrators,
subject to any mandatory or applicable power under the SIAC Rules concerning tribunal constitution.
The parties may use any streamlined, expedited, emergency or other procedure available under the applicable SIAC Rules where its requirements are satisfied.
87. INTERIM RELIEF
Nothing prevents a party from seeking urgent interim, conservatory or injunctive relief from:
(a) an emergency arbitrator;
(b) the arbitral tribunal; or
(c) a court of competent jurisdiction,
where necessary to protect confidentiality, intellectual property, security, access credentials, evidence or other rights pending arbitration.
Seeking such relief does not waive arbitration.
88. CONFIDENTIALITY OF DISPUTES
To the extent permitted by law and applicable SIAC Rules, the parties will maintain the confidentiality of arbitration proceedings, evidence and awards except where disclosure is reasonably necessary for:
(a) enforcement;
(b) legal obligations;
(c) regulators;
(d) insurers;
(e) auditors;
(f) professional advisers; or
(g) protection of legal rights.
PART XXII — GENERAL
89. INDEPENDENT CONTRACTORS
The parties are independent contractors.
Nothing creates:
(a) a partnership;
(b) joint venture;
(c) fiduciary relationship;
(d) employment relationship;
(e) franchise; or
(f) agency,
except where expressly agreed in writing.
Neither party may bind the other without authority.
90. ASSIGNMENT
Customer may not assign the Agreement without Kestrel’s prior written consent, not to be unreasonably withheld in connection with a bona fide corporate reorganisation that does not materially increase Kestrel’s risk.
Kestrel may assign the Agreement:
(a) to an Affiliate; or
(b) in connection with a merger, reorganisation, sale of substantially all relevant assets or change of control,
provided the assignee assumes applicable contractual obligations.
Neither party may assign the Agreement to a direct competitor of the other in a manner reasonably likely to compromise Confidential Information without consent.
91. SUBCONTRACTORS
Kestrel may use contractors and subcontractors to perform the Service.
Kestrel remains responsible for contractual obligations to the extent stated in the Agreement.
Processing of personal data by Subprocessors remains subject to the DPA.
92. FORCE MAJEURE
Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, including:
(a) natural disaster;
(b) fire;
(c) flood;
(d) epidemic;
(e) war;
(f) terrorism;
(g) civil disorder;
(h) governmental action;
(i) widespread internet failure;
(j) electrical-grid failure;
(k) telecommunications failure;
(l) labour disruption not limited to the affected party’s own workforce;
(m) major cloud infrastructure failure;
(n) widespread third-party provider failure; or
(o) comparable events beyond reasonable control.
The affected party must use commercially reasonable efforts to mitigate the impact.
Force majeure does not excuse Customer’s obligation to pay Fees already accrued for Services received.
If a force-majeure event materially prevents performance for more than sixty (60) consecutive days, either party may terminate the materially affected Service.
93. NOTICES
Legal notices must be sent to the notice details specified in Schedule 1 and, for Customer, to the address or email stated in the applicable Order Form.
Notices concerning ordinary Service operations may be provided:
(a) by email;
(b) through the Platform;
(c) through administrative notifications; or
(d) through documented support channels.
A legal notice is deemed received when delivery is confirmed electronically or, for physical delivery, when delivered according to recognised courier records, subject to Applicable Law.
94. CHANGES TO THESE TERMS
Kestrel may update these Terms prospectively.
For material adverse changes affecting an existing paid subscription, Kestrel will provide reasonable notice before the change becomes effective.
Kestrel will publish an updated version on the Website and, where a change is material, will also provide notice by email or through the authenticated Platform dashboard.
A unilateral online update will not retroactively modify a negotiated Order Form or separately executed amendment.
If Customer continues a renewable subscription after properly notified revised Terms become effective, the revised Terms may govern the renewed period.
95. ENTIRE AGREEMENT
The Agreement constitutes the entire agreement between the parties concerning its subject matter and supersedes prior proposals, representations and communications concerning that subject matter.
Nothing in this Section excludes liability for fraud or fraudulent misrepresentation or another representation that Applicable Law prohibits the parties from excluding.
96. WAIVER
Failure to enforce a provision is not a waiver.
A waiver must be specific and does not waive future rights unless expressly stated.
97. SEVERABILITY
If a provision is held invalid or unenforceable, it will be enforced to the maximum extent lawfully possible and, where appropriate, modified only to the minimum extent required to make it enforceable.
The remaining provisions remain effective.
98. THIRD-PARTY RIGHTS
Except as expressly stated in relation to Kestrel indemnified parties or permitted successors, a person who is not a party to the Agreement has no right under the Contracts (Rights of Third Parties) Act 2001 to enforce a term of the Agreement.
The parties may amend or terminate the Agreement without obtaining consent from any third party unless Applicable Law or an expressly granted third-party right requires otherwise.
99. COUNTERPARTS AND ELECTRONIC SIGNATURES
Order Forms and amendments may be executed in counterparts and using electronic signatures.
Each counterpart forms part of the same instrument.
100. FURTHER ASSURANCES
Each party will execute documents and perform reasonable acts necessary to give effect to expressly agreed rights and obligations.
101. LANGUAGE
The controlling language of the Agreement is English.
Any translation is provided for convenience unless expressly agreed otherwise.
102. NO EXCLUSIVITY
Nothing creates exclusivity or a most-favoured-customer obligation unless expressly stated in an executed Order Form.
103. NO ROADMAP COMMITMENT
Kestrel has no obligation to develop or release future functionality merely because it was discussed, demonstrated or included in a roadmap.
104. PROCUREMENT TERMS
Customer procurement portals, purchase orders, vendor forms or policies do not modify the Agreement solely because Kestrel interacts with, uploads information to or acknowledges them.
Additional terms bind Kestrel only where expressly accepted in writing by an authorised Kestrel representative.
SCHEDULE 2
ACCEPTABLE USE POLICY
This Acceptable Use Policy forms part of the Agreement.
Customer must not, and must not permit any person to, use the Service:
1. Illegal Activity
for illegal, fraudulent, deceptive or rights-infringing activity;
2. Unauthorised Access
to gain or attempt to gain unauthorised access to:
- accounts;
- systems;
- credentials;
- networks;
- tenants;
- data;
- devices; or
- services;
3. Malicious Code
to create, distribute, deploy or operate malware, ransomware, credential theft, destructive payloads or comparable malicious code, except authorised defensive-security testing expressly approved by Kestrel;
4. Circumvention
to bypass, disable, evade or defeat:
- authentication;
- rate limits;
- tenant isolation;
- policy controls;
- evidence mechanisms;
- billing controls;
- usage limits; or
- security protections;
5. Disruption
to conduct denial-of-service activity, excessive automated access, resource exhaustion or other activity intended to materially disrupt the Service;
6. Unauthorised Testing
to conduct penetration testing, vulnerability scanning or exploit testing against Kestrel infrastructure without prior written authorisation;
7. Credential Sharing
to disclose credentials or access to unauthorised persons;
8. Unlawful Data
to provide data Customer lacks legal authority to process or disclose;
9. Exploitation and Abuse
for child sexual abuse material, human trafficking, terrorist activity or other serious unlawful exploitation;
10. Credential Harvesting
for unlawful phishing, credential harvesting, impersonation or account theft;
11. Unlawful Surveillance
for unlawful interception, stalking or surveillance;
12. Discriminatory Decisions
to facilitate unlawful discrimination or unlawful automated decision-making;
13. Deceptive Impersonation
to impersonate another person unlawfully or deceive persons concerning material identity or authority;
14. Restricted Territories
in violation of Section 74 or applicable sanctions or export restrictions;
15. Intellectual Property Abuse
to materially infringe or misappropriate third-party intellectual property;
16. Competitive Extraction
to systematically copy non-public Kestrel functionality for the principal purpose of building a competing product in violation of the Agreement;
17. Benchmark Publication
to intentionally publish materially misleading non-public security or performance results without giving Kestrel a reasonable opportunity to verify disputed technical facts;
18. Highly Sensitive Data
to process categories of extremely sensitive data expressly prohibited by an applicable Order Form, Documentation or DPA.
AUP ENFORCEMENT
Where Kestrel reasonably believes a violation has occurred, Kestrel may:
(a) investigate;
(b) request information;
(c) require remediation;
(d) impose proportionate technical controls;
(e) suspend affected access; or
(f) terminate for serious or repeated violations.
Kestrel will provide notice and an opportunity to respond where practicable.
Immediate action may be taken where Kestrel reasonably believes delay would create significant legal, security, infrastructure or human-safety risk.
Customer may contact Kestrel through the legal or support contact in Schedule 1 to dispute an enforcement decision.
SCHEDULE 3
COMMERCIAL PLAN TERMS
1. PILOT
Platform Fee
USD 500 per month.
Included Usage
100,000 Requests per monthly billing period.
Maximum Usage
100,000 Requests per monthly billing period.
Pilot usage does not continue automatically beyond the stated cap unless Kestrel expressly authorises additional capacity in writing.
Maximum Term
Three months.
Purpose
Evaluation, validation and limited real-environment testing.
SLA
No contractual SLA unless expressly stated in the applicable Order Form.
Conversion
A Pilot does not automatically convert into Production unless Customer affirmatively purchases or accepts a Production subscription.
2. PRODUCTION
Platform Fee
USD 2,500 per month.
Included Requests
The first 1,000,000 Requests per monthly billing period.
Usage
1,000,001 through 10,000,000 Requests:
USD 1.00 per 1,000 additional Requests.
Above 10,000,000:
USD 0.60 per 1,000 additional Requests.
Kestrel may contact Customer to establish Enterprise Volume pricing where usage materially exceeds standard Production bands.
3. ENTERPRISE VOLUME
Enterprise Volume terms are individually contracted.
They may include:
(a) committed volume;
(b) annual Fees;
(c) minimum spend;
(d) custom usage tiers;
(e) true-ups;
(f) support commitments;
(g) SLA;
(h) security terms;
(i) professional services;
(j) implementation terms; and
(k) other enterprise-specific requirements.
The applicable Order Form controls.
4. FEATURE AVAILABILITY
Where Kestrel publicly states that platform capabilities are included in a plan, that statement means Customer is not intentionally required to purchase another feature tier merely to unlock generally released core capabilities unless clearly disclosed.
However, functionality remains subject to:
(a) technical availability;
(b) supported integrations;
(c) customer configuration;
(d) release status;
(e) Documentation;
(f) capacity;
(g) lawful territorial availability;
(h) technical prerequisites; and
(i) the applicable Order Form.
“Included” does not mean every capability is technically compatible with every Customer architecture.
SCHEDULE 4
PILOT AND EVALUATION TERMS
These terms supplement the Agreement for a Pilot.
1. Evaluation Purpose
Pilot subscriptions are designed to allow Customer to evaluate Kestrel before broader production adoption.
2. Three-Month Maximum
A standard Pilot may not exceed three months unless Kestrel expressly agrees otherwise in writing.
3. Request Cap
Pilot usage is capped at 100,000 Requests per monthly billing period.
4. Cap Behaviour
Once the applicable cap is reached, Kestrel may:
(a) stop accepting additional Pilot Requests;
(b) require Customer to wait for the next billing period;
(c) offer migration to Production; or
(d) agree to another arrangement in writing.
Kestrel is not required to permit overage usage at Pilot pricing.
5. Critical Operations
Unless an Order Form expressly states otherwise, Customer must not rely on a Pilot as the sole control protecting safety-critical, mission-critical or legally required functions.
6. Live Data
Live production data may be processed only in accordance with Schedule 1 and any applicable DPA.
7. No SLA
A Pilot has no contractual uptime SLA unless expressly stated otherwise.
8. Support
Pilot support may be more limited than support available under a negotiated Production or Enterprise arrangement.
9. Evaluation Results
Customer is responsible for evaluating whether Kestrel is appropriate for Customer’s proposed deployment.
Successful Pilot results do not guarantee identical performance under different:
(a) traffic volumes;
(b) models;
(c) configurations;
(d) datasets;
(e) infrastructure;
(f) attack patterns; or
(g) production conditions.
10. End of Pilot
At Pilot expiry, Customer must:
(a) purchase an applicable Production or Enterprise subscription;
(b) enter another written arrangement with Kestrel; or
(c) cease use.
There is no automatic paid conversion unless Customer affirmatively accepts it.
SCHEDULE 5
AI AND RUNTIME CONTROL PRODUCT TERMS
1. Control-Point Dependency
Kestrel governs only traffic and actions reaching supported Kestrel control points.
2. Model Provider Independence
Kestrel does not control independent Model Provider behaviour.
3. Security Detection
Threat detection is probabilistic and may produce false positives and false negatives.
4. Policy Enforcement
Customer is responsible for policy design and approval.
5. Personal-Data Detection
PII detection and redaction reduce risk but cannot guarantee complete removal of sensitive data.
6. Multi-Turn Analysis
Risk accumulated across a session may depend on session continuity and availability of required context.
7. Tool Actions
Kestrel may evaluate proposed Tool Actions but cannot control actions performed outside supported control points.
8. Evidence
Cryptographic records establish only the technical properties actually verified by the applicable mechanism.
9. Shadow Mode
Shadow-mode or simulation results do not themselves enforce policy unless enforcement is enabled.
10. Assurance
Assurance scores, indicators, findings and recommendations are decision-support information and are not certifications of legal compliance.
11. Inventory and Governance Records
Customer is responsible for ensuring inventory, ownership, classification and lifecycle information supplied to Kestrel remains materially accurate.
12. Customer Overrides
Where Customer overrides, bypasses, disables or weakens a control, Customer accepts responsibility for the consequences of that decision except to the extent caused independently by Kestrel’s breach.
SCHEDULE 6
WEBSITE USE TERMS
The following provisions apply to use of Kestrel’s public Website before a subscription is established.
1. Informational Purpose
Website content is provided for general business information and does not itself constitute a binding offer to provide a particular Service.
2. No Reliance on Roadmaps
Future features and timelines are not contractual commitments.
3. Website Intellectual Property
Website text, graphics, software, designs, trademarks and other proprietary materials are owned by or licensed to Kestrel.
Visitors may view them for legitimate informational and business-evaluation purposes.
4. Prohibited Website Conduct
Visitors must not:
(a) attack the Website;
(b) attempt unauthorised access;
(c) distribute malicious code;
(d) scrape the Website at a rate that materially burdens infrastructure;
(e) evade technical restrictions;
(f) reproduce substantial proprietary content for competing commercial use; or
(g) misrepresent an affiliation with Kestrel.
5. Third-Party Links
External links may be provided for convenience.
Kestrel does not control third-party websites merely because it links to them.
6. Privacy
Website personal-data processing is governed by Kestrel’s Privacy Policy and applicable Cookie Policy.
7. Website Availability
Kestrel does not guarantee uninterrupted public Website availability.
8. Enterprise Agreements Control
These Website provisions do not override an executed enterprise Order Form, DPA, MSA or negotiated amendment.
ACKNOWLEDGEMENT
BY ACCEPTING THESE TERMS ON BEHALF OF CUSTOMER, THE ACCEPTING PERSON REPRESENTS THAT:
- CUSTOMER IS ENTERING INTO A BUSINESS-TO-BUSINESS AGREEMENT;
- THE ACCEPTING PERSON HAS AUTHORITY TO BIND CUSTOMER;
- CUSTOMER HAS REVIEWED THESE TERMS;
- CUSTOMER UNDERSTANDS THAT AI AND SECURITY CONTROLS ARE NOT INFALLIBLE;
- CUSTOMER RETAINS RESPONSIBILITY FOR ITS AI SYSTEMS AND LEGAL OBLIGATIONS; AND
- CUSTOMER AGREES TO THE GOVERNING LAW AND DISPUTE-RESOLUTION PROVISIONS ABOVE.
KESTREL ADVANCED SYSTEMS PTE. LTD.
Blk 31, #01-16C
535 Clementi Road
Singapore 599489
Website: kestreladvanced.com
General enquiries: contact@kestreladvanced.com
Legal notices: legal@kestreladvanced.com
Privacy and data-protection enquiries: privacy@kestreladvanced.com
© 2026 Kestrel Advanced Systems Pte. Ltd. All rights reserved.