Preamble

This Master Services Agreement, together with the Terms of Service, any Order Form, and any incorporated policies including the Privacy Policy and Data Processing Addendum (collectively, the "Agreement"), is entered into by and between:

TFALKE PRIVATE LIMITED, a company incorporated under the laws of India, with its registered office in India ("TFALKE", "we", "us", or "the Company"); and

The Customer identified in the applicable Order Form, sign-up flow, or account registration ("Customer", "you", or "Client"),

each individually a "Party" and collectively the "Parties", governing Customer's access to and use of TFALKE's zero-polling, real-time endpoint management platform, associated software, dashboards, APIs, and any natural-language AI agent made available as part of the Service (collectively, the "Service").

BY CLICKING "I AGREE," EXECUTING AN ORDER FORM, OR ACCESSING OR USING THE SERVICE, CUSTOMER ACCEPTS AND AGREES TO BE BOUND BY THIS AGREEMENT IN FULL. IF CUSTOMER DOES NOT AGREE, CUSTOMER MUST NOT ACCESS OR USE THE SERVICE.

1. Definitions

  • "AI Agent" means the optional natural-language automation feature of the Service that interprets Customer instructions and issues corresponding commands to Customer's managed Endpoints via a Third-Party LLM Provider.
  • "Connection Metadata" means the minimal technical data strictly necessary to establish and maintain a live connection between an Endpoint and the Service, such as device identifiers, connection timestamps, IP address, agent version, and session status.
  • "Customer Data" means any data, content, configuration, credentials, or information that Customer or its Endpoints transmit to, through, or in connection with the Service, excluding Connection Metadata and Billing Information.
  • "Endpoint(s)" means any device, virtual machine, server, or system enrolled by Customer into the Service for management.
  • "Third-Party LLM Provider" means any independent third-party large language model or generative AI provider (including without limitation OpenAI, Anthropic, or any other provider) whose API Customer elects to connect to the AI Agent under the BYOK Architecture defined in Section 3.
  • "Customer API Key" means any API key, access token, or credential issued to Customer by a Third-Party LLM Provider and configured by Customer within the Service.
  • "Billing Information" means the minimum data required to process payment and administer Customer's subscription, such as name, business contact details, and payment instrument tokens processed via a third-party payment processor.
  • "Data Protection Laws" means all applicable laws relating to the processing of personal data, including without limitation the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and India's Digital Personal Data Protection Act, 2023 ("DPDPA"), in each case to the extent applicable.
  • "Losses" means any and all losses, damages, liabilities, costs, and expenses (including reasonable legal fees).

2. Scope of Services

2.1 Description

TFALKE provides a zero-polling, real-time endpoint management platform enabling Customer to monitor, configure, and remediate Endpoints. Features, availability, and functionality may be modified, added, or discontinued by TFALKE from time to time in its sole discretion, provided that TFALKE will not materially reduce core functionality during a paid subscription term without reasonable notice or a corresponding fee adjustment.

2.2 Customer Responsibilities

Customer is solely responsible for: (a) the lawful configuration and administration of its Endpoints and the Service; (b) the accuracy, legality, and appropriateness of all commands, policies, and configurations issued through the Service, whether issued manually or via the AI Agent; (c) maintaining adequate independent backups, disaster recovery procedures, and business continuity plans for all Endpoints and data, independent of the Service; and (d) the security of its own credentials, accounts, and network environment.

2.3 No Guarantee of Uninterrupted Operation

Customer acknowledges that endpoint management software operates within Customer's own IT environment, over networks and infrastructure not controlled by TFALKE, and that Endpoint downtime, connectivity loss, misconfiguration, or data loss may result from causes entirely outside TFALKE's control, including but not limited to Customer's network conditions, Customer error, third-party infrastructure, or Customer's own configuration choices.

3. AI Agent - "Bring Your Own Key" (BYOK) Architecture

3.1 Customer-Controlled AI Infrastructure

The AI Agent is an optional feature that operates exclusively using a Customer API Key supplied, owned, and controlled by Customer. TFALKE does not provide, sell, sublicense, resell, or act as an intermediary for any Third-Party LLM Provider's services, and TFALKE holds no account, billing relationship, or contractual privity with any Third-Party LLM Provider on Customer's behalf. Customer is solely responsible for obtaining and maintaining a valid, properly licensed, and adequately provisioned Customer API Key and for complying with the applicable Third-Party LLM Provider's terms of service, acceptable use policy, and data processing terms.

3.2 No Responsibility for Third-Party LLM Costs or Availability

As between the Parties, TFALKE bears no responsibility whatsoever for, and Customer assumes all risk arising from:

  • any API usage fees, token consumption, overage charges, or billing disputes arising from Customer's use of its own Customer API Key;
  • rate limits, quota exhaustion, throttling, downtime, deprecations, model changes, or service interruptions imposed or caused by any Third-Party LLM Provider;
  • suspension or termination of Customer's Customer API Key by the Third-Party LLM Provider for any reason; and
  • any change in pricing, functionality, or availability of any Third-Party LLM Provider's models or APIs.

3.3 Mandatory Confirmation Step for Destructive or High-Risk Commands

Before the AI Agent executes any command classified within the Service as destructive or high-risk (including, without limitation, any command that deletes, wipes, disables, reformats, encrypts, or performs a mass configuration change to an Endpoint) (each, a "High-Risk Command"), the Service will present Customer's Authorized User with the proposed High-Risk Command in plain language and require the Authorized User to affirmatively Accept or Reject that specific command before it is transmitted to the Endpoint for execution. No High-Risk Command is executed on Rejection, and the Service logs the timestamp, the content of the proposed command, and the Accept/Reject decision for each such event. TFALKE will retain each such log entry for not less than thirty-six (36) months following the date it is created, or such longer period as required to resolve a pending dispute or claim relating to that entry, and will produce relevant log entries to Customer upon reasonable request in connection with a dispute arising under Section 3.4.

3.4 Allocation of Liability for AI Outputs and Actions

Customer expressly acknowledges that generative AI systems, including the underlying models accessed via the AI Agent, may produce inaccurate, incomplete, biased, or unexpected outputs ("AI Hallucinations"), and may propose automated actions on Endpoints based on natural-language instructions that do not match Customer's actual intent. Accordingly, as between the Parties, and to the fullest extent permitted by applicable law:

  • where a High-Risk Command was presented to and Accepted by Customer's Authorized User under Section 3.3, Customer bears full responsibility and liability for that command and its consequences, including any resulting Endpoint downtime, data loss, unauthorized access, or business interruption, regardless of whether the underlying AI Hallucination, prompt injection, or unexpected output originated from the Third-Party LLM Provider, Customer's own prompt, or Customer's configuration;
  • where the Service executes a High-Risk Command without first presenting the Accept/Reject confirmation required under Section 3.3, or executes a command materially different from the command actually Accepted by the Authorized User, TFALKE is liable for the resulting Losses under Section 8, and this outcome is not excluded by Section 8.1 or 8.2, subject only to the cap in Section 8.3 and the savings clause in Section 8.3A;
  • for any command that is not a High-Risk Command (i.e., does not require confirmation under Section 3.3), Customer remains solely responsible for reviewing and validating AI Agent proposals before broader reliance, and bears responsibility for any AI Hallucination, unintended action, or prompt injection outcome affecting such non-High-Risk commands, except where TFALKE's own command-execution logic - independent of any Third-Party LLM Provider output, prompt content, or Customer configuration - misclassified a command that should have been treated as High-Risk under TFALKE's own internal classification logic, records of which TFALKE will produce to Customer upon reasonable request in connection with a dispute under this Section 3.4;
  • Customer is solely responsible for implementing additional safeguards appropriate to its environment, including staging environments and permission scoping, before enabling the AI Agent to act on production Endpoints, in addition to the confirmation mechanism TFALKE provides under Section 3.3; and
  • TFALKE's role is limited to providing the interface, the confirmation mechanism, and command-relay infrastructure; TFALKE does not train, fine-tune, control, or guarantee the outputs of any Third-Party LLM Provider's models.

3.5 Data Passed to Third-Party LLM Providers

Customer acknowledges and agrees that any prompt, instruction, or contextual data Customer elects to send to the AI Agent is relayed by the Service's backend infrastructure, using Customer's own Customer API Key, to the applicable Third-Party LLM Provider under that provider's own data handling, retention, and processing terms, and that the Service also stores such data as described in Section 3.5A. TFALKE does not control, and makes no representation regarding, how any Third-Party LLM Provider uses, stores, retains, or processes such data once relayed to it. Customer is solely responsible for reviewing the applicable Third-Party LLM Provider's privacy policy and data processing terms, and for ensuring that its use of the AI Agent complies with Data Protection Laws applicable to Customer's own data, including obtaining any consents or executing any data processing agreements directly with the Third-Party LLM Provider as required.

3.5A Storage of AI Agent Session Data

The Service caches AI Agent messages, commands, and command output (including standard-output and standard-error text) for up to twenty-four (24) hours to support an active session, and separately retains a permanent session record of the same content in TFALKE's primary database to allow Customer's Authorized Users to resume a troubleshooting session, until deleted by TFALKE at Customer's request or in accordance with the Data Processing Agreement. Notwithstanding the foregoing, the Accept/Reject decision record described in Section 3.3 (the timestamp, proposed command content, and Accept/Reject decision for each High-Risk Command) is retained for the minimum period specified in Section 3.3 regardless of any earlier deletion of the broader session record under this Section 3.5A, as necessary for the establishment, exercise, or defense of legal claims. This data is processed and stored as described in, and subject to the terms of, the Data Processing Agreement.

4. Zero-Tracking & Minimal Data Collection Principle

4.1 No Tracking Cookies or Behavioral Analytics

TFALKE operates the Service on a strict minimal-data-collection model. TFALKE does not deploy tracking cookies, does not collect or process user behavioral analytics, does not harvest usage or interaction metrics for advertising or profiling purposes, and does not sell or share personal data with third parties for cross-context behavioral advertising.

4.2 No Ingestion of Sensitive Endpoint Payloads

Except for AI Agent Session Data described in Section 3.5A, TFALKE does not ingest, store, index, or otherwise process the substantive content of Customer's Endpoint payloads, files, organizational data, or business records. Outside of the AI Agent, the Service is architected to operate on Connection Metadata only, sufficient to maintain live device connectivity and management functionality.

4.3 Data Actually Collected

TFALKE collects and processes only the following categories of data, strictly limited to what is necessary to operate, secure, and bill for the Service:

  • Connection Metadata, as defined in Section 1;
  • Billing Information, as defined in Section 1, processed via a PCI-compliant third-party payment processor; and
  • Account administration data (e.g., administrator name, business email, authentication credentials).

4.4 Retention and Deletion

TFALKE retains Connection Metadata and Billing Information only for so long as reasonably necessary to provide the Service, comply with legal and tax obligations, and resolve disputes, after which such data is deleted or anonymized in accordance with TFALKE's data retention schedule, made available on request.

5. GDPR Compliance (European Users)

5.1 Roles of the Parties

Where Customer or its end users are located in the European Economic Area or United Kingdom and personal data is processed in connection with the Service, the Parties agree that:

  • Customer is the Data Controller (or, where applicable, Processor acting on behalf of its own controller) with respect to any Customer Data and any data transmitted to a Third-Party LLM Provider via the AI Agent; and
  • TFALKE acts as a Data Processor (or "service provider"/"processor" under equivalent terminology) solely with respect to the limited categories of Connection Metadata and Billing Information described in Section 4.3, processed strictly to provide the Service.

5.2 Data Processing Addendum

The Parties agree that TFALKE's standard Data Processing Addendum ("DPA"), incorporated by reference and available at TFALKE's Trust & Privacy portal, forms part of this Agreement and governs the processing of personal data within Connection Metadata and Billing Information, including provisions on sub-processors, international transfers (via Standard Contractual Clauses or an equivalent lawful transfer mechanism), security measures, and breach notification.

5.3 Scope Limitation as a Compliance Control

Because the Service's architecture minimizes the personal data categories processed by TFALKE (Section 4), TFALKE's obligations as Processor are correspondingly narrow. TFALKE does not process special category data, does not conduct profiling or automated decision-making producing legal effects on data subjects, and does not act as Processor for any data Customer elects to transmit directly to a Third-Party LLM Provider using Customer's own API Key, which remains solely within Customer's controller relationship with that provider.

5.4 Data Subject Rights

TFALKE will provide Customer with reasonable technical and organizational assistance to respond to verified data subject requests (access, rectification, erasure, restriction, portability, objection) to the extent such requests relate to data processed by TFALKE as Processor, consistent with Article 28(3)(e) GDPR. Nothing in this Agreement limits any data subject's non-waivable statutory rights under GDPR.

6. CCPA / CPRA Compliance (California Users)

6.1 Business and Service Provider Roles

Where Customer or its personnel qualify as California "consumers" under the CCPA/CPRA, Customer acts as the "Business" and TFALKE acts as a "Service Provider" with respect to the limited Connection Metadata and Billing Information processed under Section 4.3.

6.2 No Sale or Sharing of Personal Information

TFALKE does not sell or share (as those terms are defined under the CCPA/CPRA) personal information collected in connection with the Service. TFALKE processes personal information solely for the business purposes of providing, securing, and billing for the Service, and not for any purpose outside the direct business relationship between the Parties.

6.3 Restrictions on Use of Service Provider Data

TFALKE certifies that it will not retain, use, or disclose personal information received from Customer for any purpose other than the specific business purposes set out in this Agreement, and will not combine such information with personal information received from other sources except as permitted under the CCPA/CPRA.

7. Warranty Disclaimer - Service Provided "As Is"

EXCEPT AS EXPRESSLY SET OUT IN THIS AGREEMENT, THE SERVICE, INCLUDING THE AI AGENT AND ALL RELATED SOFTWARE, DOCUMENTATION, AND OUTPUTS, IS PROVIDED STRICTLY "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, TFALKE EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO:

  • any implied warranties of merchantability, fitness for a particular purpose, title, non-infringement, or quiet enjoyment;
  • any warranty that the Service will be uninterrupted, timely, secure, error-free, or free of harmful components;
  • any warranty regarding the accuracy, reliability, or completeness of any output generated by the AI Agent or any Third-Party LLM Provider; and
  • any warranty arising from course of dealing, course of performance, or usage of trade.

No advice or information, whether oral or written, obtained by Customer from TFALKE or through the Service creates any warranty not expressly stated in this Agreement.

Nothing in this Section 7 excludes or limits any statutory warranty, guarantee, or protection that cannot lawfully be excluded or limited under mandatory consumer-protection law applicable to Customer, including where Customer is an individual acting in a personal, non-business capacity (see Section 11.4).

8. Limitation of Liability

8.1 Exclusion of Consequential Damages

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL TFALKE BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY, ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICE, REGARDLESS OF THE THEORY OF LIABILITY (CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE) AND EVEN IF TFALKE HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

8.2 Specific Exclusions

Without limiting the generality of Section 8.1, and to the maximum extent permitted by applicable law, TFALKE will have no liability whatsoever for:

  • Endpoint downtime, connectivity loss, or degraded performance, however caused;
  • data loss, corruption, or unauthorized access affecting Customer's Endpoints, networks, or systems;
  • business interruption of any kind;
  • system misconfiguration, whether performed manually by Customer or via the AI Agent; and
  • any matter identified in Section 3 (BYOK AI Architecture) as being within Customer's sphere of responsibility, including AI Hallucinations, prompt injection, and Third-Party LLM Provider conduct.

8.3 Aggregate Liability Cap

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, TFALKE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT, OR OTHERWISE, WILL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY CUSTOMER TO TFALKE FOR THE SERVICE IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

8.3A Savings Clause - Failure of Essential Purpose

If, in any jurisdiction, the limitation in Section 8.3 is found to have failed of its essential purpose such that Customer is left without any meaningful remedy for a claim that Section 8 would otherwise permit, TFALKE's liability for that claim is limited instead to the greater of (a) the fees paid by Customer in the twelve (12) months preceding the event giving rise to the claim, or (b) USD 25,000 (or the equivalent in local currency), it being the Parties' intent that a court or arbitrator applying this Section 8.3A should have a defined, minimum floor to apply rather than declining to enforce any limitation at all.

8.4 Non-Excludable Liability (Carve-Outs Required by Law)

Nothing in this Agreement excludes or limits either Party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) gross negligence or willful misconduct, where such exclusion is not permitted by applicable law; or (d) any other liability which cannot lawfully be excluded or limited under the mandatory law of the jurisdiction applicable to Customer. Sections 8.1-8.3 apply to the fullest extent permitted by law and are automatically read down, on a jurisdiction-by-jurisdiction basis, to the maximum limitation actually enforceable in Customer's jurisdiction, without invalidating the remainder of this Section 8.

8.5 Consumer Protection

Where Customer is an individual acting in a personal, non-business capacity, this Section 8 applies to Customer only to the extent permitted under mandatory consumer-protection law applicable to Customer's jurisdiction of residence, and does not exclude or limit any right or remedy that such law does not permit to be excluded or limited. This Section 8.5 does not narrow the scope of Section 8 as applied to Customer where Customer is a business entity.

9. Indemnification

9.1 Indemnification by Customer

Customer will defend, indemnify, and hold harmless TFALKE, its officers, directors, employees, and agents from and against any and all third-party claims, Losses, and liabilities arising out of or relating to:

  • Customer's use of the AI Agent, including any AI Hallucination, unintended automated action, or prompt injection outcome;
  • Customer's Customer API Key, including any billing dispute, rate-limit violation, or terms-of-service breach with any Third-Party LLM Provider;
  • any Endpoint management decision, configuration, or command issued by Customer or on Customer's behalf, whether manually or via the AI Agent;
  • Customer's breach of this Agreement or violation of applicable law; and
  • Customer's Data Protection Laws obligations as Data Controller/Business, including any obligations arising from data Customer transmits directly to a Third-Party LLM Provider.

9.2 Indemnification by TFALKE

TFALKE will defend, indemnify, and hold harmless Customer from third-party claims alleging that the Service, as provided by TFALKE and used in accordance with this Agreement, directly infringes a third party's registered intellectual property rights, excluding any claim arising from the AI Agent's outputs, Third-Party LLM Provider models, Customer's configurations, or Customer's combination of the Service with other products.

9.3 Indemnification Procedure

The indemnified Party will promptly notify the indemnifying Party of any claim, grant the indemnifying Party sole control of the defense and settlement (subject to the indemnified Party's consent for any settlement imposing liability on it), and provide reasonable cooperation at the indemnifying Party's expense.

10. Term and Termination

10.1 Term

This Agreement commences on the date Customer first accesses the Service and continues for the subscription term specified in the applicable Order Form, automatically renewing unless either Party provides notice of non-renewal as specified therein.

10.2 Termination for Cause

Either Party may terminate this Agreement immediately upon written notice if the other Party materially breaches this Agreement and fails to cure such breach within thirty (30) days of receiving notice thereof.

10.3 Effect of Termination

Upon termination, Customer's access to the Service will cease, Customer remains liable for all fees accrued prior to termination, and Sections 1, 3, 4-9, 10.3, and 11-12 survive termination.

11. Governing Law and Dispute Resolution

11.1 Governing Law

This Agreement is governed by and construed in accordance with the laws of India, without regard to its conflict-of-laws principles, regardless of Customer's location or the location of any Endpoint.

11.2 Mandatory Arbitration

Any dispute, controversy, or claim arising out of or relating to this Agreement, including its existence, validity, interpretation, performance, breach, or termination, will be referred to and finally resolved by arbitration administered under the Arbitration and Conciliation Act, 1996 (India), as amended. The arbitration will be conducted by a sole arbitrator appointed by mutual agreement of the Parties (or, failing agreement within thirty (30) days, appointed in accordance with the Act), seated in Ernakulam (Kochi), Kerala, India, conducted in the English language. The arbitral award will be final and binding on the Parties, and judgment thereon may be entered in any court of competent jurisdiction.

11.3 Class Action and Jury Trial Waiver

To the maximum extent permitted by applicable law, all disputes will be resolved on an individual basis only, and Customer waives any right to participate in a class, collective, or representative action, and waives any right to a jury trial where such waiver is legally permitted.

11.4 Data Subject and Consumer Rights Carve-Out

Notwithstanding Section 11.2, nothing in this Agreement limits, waives, or is intended to limit or waive: (a) the right of any individual data subject to bring proceedings before the courts of their habitual residence or the relevant supervisory authority under Article 79 or Article 82 GDPR (or equivalent provisions of the UK GDPR or other applicable data protection law), regardless of whether that individual is a signatory to this Agreement; or (b) the right of any party that qualifies as a consumer under applicable mandatory law to invoke non-waivable consumer protections, including the right to bring proceedings in their jurisdiction of residence where mandatory law so requires. This Section 11.4 applies only to the extent such rights cannot lawfully be limited by agreement, and does not otherwise narrow the scope of Sections 11.1-11.3 as between TFALKE and Customer.

11.5 Customer's Business-Use Representation

Where Customer is a business entity, Customer represents and warrants that it is entering into this Agreement in the course of its trade, business, or profession, and that all Authorized Users access the Service as Customer's employees, contractors, or agents acting in that capacity and not in a personal or consumer capacity. Where Customer is an individual acting in a personal, non-business capacity, this Section 11.5 does not apply to Customer, and Section 11.4 governs the extent to which Section 11 applies.

11.6 Injunctive Relief

Notwithstanding the foregoing, either Party may seek interim or injunctive relief from a court of competent jurisdiction to prevent irreparable harm pending the outcome of arbitration.

12. General Provisions

12.1 Severability

If any provision of this Agreement is held invalid or unenforceable, that provision will be limited or eliminated to the minimum extent necessary, consistent with Section 8.4, and the remaining provisions will remain in full force and effect.

12.2 Force Majeure

Neither Party is liable for any failure or delay in performance due to causes beyond its reasonable control, including acts of God, internet or telecommunications failures, government action, or third-party infrastructure or LLM provider outages.

12.3 No Third-Party Beneficiaries

This Agreement does not confer any rights or remedies on any person other than the Parties, including any Third-Party LLM Provider.

12.4 Assignment

Customer may not assign this Agreement without TFALKE's prior written consent. TFALKE may assign this Agreement in connection with a merger, acquisition, or sale of substantially all its assets.

12.5 Entire Agreement; Amendment

This Agreement, together with any Order Form, the Privacy Policy, and the DPA, constitutes the entire agreement between the Parties and supersedes all prior agreements. TFALKE may update this Agreement from time to time by posting a revised version and providing reasonable notice; continued use of the Service after the effective date of any update constitutes acceptance.

12.6 Notices

Notices under this Agreement must be in writing and delivered to the addresses specified in the applicable Order Form or account registration.

12.7 Sanctions and Export Control Compliance

TFALKE represents that, to the best of its knowledge, it is not owned or controlled by, and does not knowingly provide the Service to, any person, entity, or jurisdiction subject to comprehensive trade sanctions administered by the United Nations, the European Union, the United Kingdom, the United States, or India. TFALKE will use commercially reasonable efforts not to knowingly provide the Service in violation of applicable export control or sanctions law. This Section 12.7 does not limit Customer's own compliance obligations under Section 4.2 of the Acceptable Use Policy.