Terms of Service
Business to Business SaaS Master Agreement
// Donna OS · Individual Entrepreneur Vladislav Verin (Georgia, ID 322783225)
Business to Business SaaS Master Agreement
These Terms of Service govern business access to and use of Donna OS. They form a binding agreement between the Customer and the Provider when the Customer accepts an Order Form, completes checkout, creates an account, or accesses the Service. The Service is offered for business and professional use only.
IMPORTANT NOTICE. The Customer should read these Terms together with the applicable Order Form and any addendum presented for a subscribed module. The person accepting the Agreement confirms that they have authority to bind the Customer. If that person lacks authority, they must not accept the Agreement or use the Service.
Contents
1 Agreement and Acceptance
2 Definitions
3 The Service
4 Order Forms and Agreement Priority
5 Subscription Terms
6 Accounts and Authorized Users
7 Access Rights
8 Customer Responsibilities
9 Acceptable Use and Restrictions
10 Implementation and Professional Services
11 APIs and Integrations
12 Artificial Intelligence Features
13 Business Decisions and Regulated Activities
14 Customer Data
15 Usage Data and Deidentified Data
16 Privacy and Data Processing
17 Security
18 Confidentiality
19 Intellectual Property
20 Fees Billing and Taxes
Contents Continued
21 Trials Free Features and Beta Services
22 Renewal Cancellation and Refunds
23 Suspension
24 Termination
25 Data Export Retention and Deletion
26 Service Changes and Deprecation
27 Third Party Services
28 Availability Support and Maintenance
29 Warranties
30 Disclaimers
31 Indemnification
32 Limitation of Liability
33 Compliance with Laws
34 Publicity
35 Changes to the Agreement
36 Notices
37 Governing Law and Disputes
38 General Terms
Schedule 1 Module Specific Terms
Schedule 2 Order Form Requirements
Schedule 3 Data Lifecycle on Termination
1 Agreement and Acceptance
1.1 Binding agreement. These Terms of Service, each Order Form, and each applicable addendum, policy, schedule, or product-specific term that is expressly incorporated by reference form the agreement between the Customer and the Provider concerning the Service, collectively the Agreement.
1.2 Provider. The Provider is Individual Entrepreneur Vladislav Verin, identification number 322783225, registered in Georgia, trading under the Donna OS name. References to Donna OS, Provider, we, us, or our mean that person and any permitted successor or assignee identified in an Order Form.
1.3 Customer. Customer, you, and your mean the legal entity identified in the applicable Order Form, checkout record, invoice, or account registration. If no legal entity is identified, Customer means the business or organization for whose benefit the account is created or the Service is used.
1.4 Methods of acceptance. The Customer accepts the Agreement by signing or electronically accepting an Order Form, clicking an acceptance control, completing a purchase, creating or activating an account after being presented with these Terms, or accessing or using the Service. Electronic acceptance has the same effect as a handwritten signature to the extent permitted by Applicable Law.
1.5 Authority. Each person who accepts the Agreement or administers the Service for a Customer represents that they have legal authority to bind the Customer and its participating Affiliates. The Customer is responsible for determining who has authority to accept commercial terms, configure the account, assign roles, and issue instructions to the Provider.
1.6 Business use only. The Service is offered only to legal entities and individuals acting for purposes relating to their trade, business, craft, profession, public function, or organizational activity. The Service is not intended for personal, family, or household use. A person who intends to use the Service as a consumer must not purchase or use it.
1.7 No employment or agency relationship. Use of the Service does not create an employment, partnership, joint venture, fiduciary, franchise, agency, or representative relationship between the Provider and the Customer, an Authorized User, an employee, a candidate, a contractor, or any other Data Subject.
2 Definitions
3 The Service
3.1 Purpose. Donna OS is a modular business operating system designed to help organizations manage business records, workflows, communications, analysis, documents, employees, customers, financial operations, requests, attendance, forecasts, and related administrative processes. The exact functionality available to the Customer depends on the subscribed modules, plan, configuration, region, and Order Form.
3.2 Modular service. The Customer may subscribe to one or more modules. A reference to the Service includes only the modules, usage allowances, environments, support level, and other components included in the Customer's subscription. Access to one module does not include a right to use another module.
3.3 Configuration. The Service may offer configurable fields, calculations, workflows, templates, permissions, notifications, dashboards, and integrations. The Customer is responsible for selecting and validating configurations appropriate to its business, workforce, contracts, tax position, accounting policies, and legal obligations.
3.4 No transfer of software. The Service is provided as hosted software. Except for permitted client applications, exports, or Documentation, the Provider is not required to deliver source code, object code, database copies, deployment scripts, model weights, infrastructure definitions, or other software components to the Customer.
3.5 Affiliates. A Customer Affiliate may use the Customer's tenant only if the Order Form permits that use and the Customer remains responsible for the Affiliate. An Affiliate that requires a separate tenant, separate billing relationship, or independent control of Customer Data must enter into its own Order Form unless the Provider agrees otherwise in writing.
3.6 Languages and localization. The Service may be available in multiple languages or include localized presets. Translations and presets are provided for convenience unless an Order Form expressly identifies a supported legal localization. The Customer must verify that labels, calculations, templates, and workflows satisfy requirements in each jurisdiction where it uses the Service.
4 Order Forms and Agreement Priority
4.1 Contents of an Order Form. An Order Form may identify modules, plan level, Subscription Term, renewal type, billing cycle, Fees, currency, usage metrics, minimum commitments, implementation services, support level, service region, special commercial terms, and participating Affiliates. An electronic checkout record may serve as an Order Form.
4.2 Agreement hierarchy. If documents conflict, the following order applies unless an Order Form expressly states a different order: first, a signed amendment; second, the Data Processing Agreement for matters concerning Personal Data; third, applicable module-specific or feature-specific addenda for the subject they regulate; fourth, the Order Form for commercial and subscription-specific terms; fifth, these Terms; and sixth, Documentation and policies. A purchase order or procurement form issued by the Customer does not amend the Agreement, even if accepted for administrative convenience.
4.3 Order Form limitations. An Order Form changes these Terms only if it identifies the provision being changed and clearly states the agreed replacement. A statement in an Order Form that its terms prevail is not sufficient by itself to amend unrelated legal terms.
4.4 Additional services. A new module, add-on, user package, storage package, professional service, or usage allowance may be added by a new Order Form, through an authorized administrator, or through in-product purchase controls. The Customer authorizes administrators with billing permissions to place such orders on its behalf.
5 Subscription Terms
5.1 Commencement. A subscription begins on the start date stated in the Order Form. If no start date is stated, it begins when the subscription is activated or the Customer first receives production access, whichever occurs first.
5.2 Monthly subscription. A monthly subscription continues for successive one-month periods until cancelled in accordance with Section 22. Cancellation takes effect at the end of the then-current paid monthly period. The Customer remains entitled to use the Service until that time, subject to the Agreement.
5.3 Annual subscription. An annual subscription continues for the committed annual term stated in the Order Form and is non-cancellable during that term except for an uncured material breach by the Provider or where Applicable Law requires otherwise. Annual Fees are non-refundable and remain payable for the committed term. The subscription automatically renews for successive twelve-month periods unless either party gives notice of non-renewal at least sixty days before the end of the then-current annual term.
5.4 Coterminous additions. Unless the parties agree otherwise, a module or add-on purchased during an existing annual term will be prorated for the remainder of that term and will renew with the principal subscription. A module purchased under a monthly plan begins when activated and renews monthly.
5.5 Minimum commitments. If an Order Form states a minimum number of employees, records, users, entities, modules, transactions, or other units, Fees will not fall below that minimum during the committed term. Usage above the minimum may increase Fees according to the Order Form or then-current applicable rates.
5.6 No implied exclusivity. The Agreement does not grant either party exclusivity. The Provider may offer the Service to other customers, including organizations that compete with the Customer, while complying with its confidentiality and data protection obligations.
6 Accounts and Authorized Users
6.1 Account information. The Customer must provide accurate registration, billing, and administrative information and keep it current. The Provider may rely on instructions from the account owner, organization owner, billing administrator, and other administrators identified in the Service.
6.2 User management. The Customer controls Authorized User invitations, roles, permissions, access periods, and account removal. The Customer must grant least-privilege access appropriate to each user role and promptly disable access for users who no longer require it.
6.3 Credentials. Credentials are personal to the assigned Authorized User and must not be shared. The Customer and each Authorized User must protect passwords, authentication factors, recovery codes, API keys, and access tokens. Where multi-factor authentication is available, the Customer must enable it for administrators and any other roles reasonably designated by the Provider.
6.4 Account activity. The Customer is responsible for activity under its account and for acts and omissions of Authorized Users as if they were acts and omissions of the Customer. This responsibility does not apply to activity caused solely by the Provider's breach of the Agreement.
6.5 Compromise notice. The Customer must notify the Provider without undue delay after discovering suspected unauthorized access, credential compromise, role misuse, or other account security incident. The Provider may reset credentials, revoke sessions, restrict access, or require additional verification when reasonably necessary to protect the Service or Customer Data.
6.6 Administrator disputes. The Provider may use reasonable verification procedures to resolve requests to change an account owner or administrator. The Provider is not required to adjudicate internal corporate, employment, ownership, or authority disputes and may temporarily restrict administrative changes until the Customer provides satisfactory evidence of authority.
7 Access Rights
7.1 Limited right of access. During the Subscription Term and subject to the Agreement, the Provider grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable right to permit Authorized Users to access and use the subscribed Service for the Customer's internal business operations.
7.2 Documentation. The Customer may use and make reasonable internal copies of Documentation solely to support authorized use of the Service. The Customer must preserve proprietary notices and may not publish or commercially distribute Documentation without written permission.
7.3 Contractors. The Customer may permit its contractors and professional advisers to access the Service when necessary to provide services to the Customer, provided that they are bound by confidentiality and use restrictions at least as protective as the Agreement. The Customer remains responsible for their use.
7.4 No implied rights. The Provider reserves all rights not expressly granted. No license is granted by implication, estoppel, exhaustion, or otherwise to Provider technology, trademarks, models, methods, data structures, or other intellectual property.
8 Customer Responsibilities
8.1 Lawful instructions and basis. The Customer must ensure that its use of the Service, its instructions to the Provider, and its collection and disclosure of Customer Data comply with Applicable Law. The Customer must have all rights, notices, consents, authorizations, and lawful bases needed for the Provider and its subprocessors to process Customer Data as contemplated by the Agreement.
8.2 Accuracy and completeness. The Customer is responsible for the accuracy, quality, legality, integrity, and completeness of Customer Data. The Service may propagate inaccurate source data into documents, calculations, dashboards, notifications, AI Output, payroll estimates, forecasts, or other results. The Customer must review material outputs before relying on them.
8.3 Internal policies. The Customer must establish appropriate internal policies for account administration, access control, records retention, employee notices, monitoring, acceptable use, approvals, segregation of duties, and review of automated outputs. The Service does not replace those policies.
8.4 Systems and connectivity. The Customer is responsible for compatible devices, browsers, internet access, endpoint security, email security, and any systems it connects to the Service. The Customer must maintain reasonable protection against malware, credential theft, and unauthorized access.
8.5 Cooperation. The Customer must provide timely information, decisions, access, and personnel reasonably required for implementation, support, incident response, and performance of professional services. Delays caused by the Customer may extend delivery dates and do not excuse Fees.
8.6 Backups and exports. The Provider maintains operational resilience measures for the Service but the Customer should periodically export records that it must retain independently for legal, tax, payroll, employment, audit, or business continuity purposes. The Service is not the Customer's sole records retention system unless expressly agreed in an Order Form.
9 Acceptable Use and Restrictions
9.1 Prohibited conduct. The Customer must not, and must not permit any person to, use the Service to engage in unlawful, fraudulent, deceptive, abusive, discriminatory, harassing, defamatory, infringing, or harmful conduct; violate another person's rights; distribute malware; facilitate unauthorized surveillance; or process information in a manner prohibited by Applicable Law.
9.2 Technical restrictions. Except to the extent a restriction is prohibited by Applicable Law, the Customer must not reverse engineer, decompile, disassemble, discover source code, derive model weights, bypass technical limitations, defeat security controls, conduct unauthorized penetration tests, interfere with the Service, scrape the Service, or use automated means to access the Service outside documented interfaces.
9.3 Competitive use. The Customer must not access the Service to build, train, benchmark for publication, or improve a competing product or service; copy protected user interface elements or workflows; resell or sublicense the Service; provide time-sharing or service-bureau access; or represent that the Service is the Customer's product. This does not prevent ordinary internal competitive evaluation before purchase.
9.4 Excessive use. The Customer must not use the Service in a manner that imposes an unreasonable or disproportionately large load, circumvents usage limits, generates abusive traffic, or materially degrades service for others. The Provider may apply reasonable rate limits, storage limits, concurrency limits, and anti-abuse controls.
9.5 Restricted data. Unless the applicable Order Form and Documentation expressly authorize it, the Customer must not submit payment card authentication data, full card numbers, government-classified information, medical records subject to specialized health-data regimes, biometric templates used for identification, criminal-offence data, or other categories requiring controls the Service does not support. The Customer must not use a test or demo environment for live Personal Data.
9.6 Investigation. The Provider may investigate suspected misuse and preserve relevant evidence. The Provider may remove or restrict access to content only when reasonably necessary to comply with law, enforce the Agreement, protect rights or safety, or preserve the security and integrity of the Service. Where lawful and practicable, the Provider will notify the Customer of material action affecting its account.
10 Implementation and Professional Services
10.1 Scope. Implementation, migration, configuration, training, consulting, and other professional services are provided only if stated in an Order Form or statement of work. Each such document should identify deliverables, assumptions, Customer dependencies, timing, acceptance criteria if any, and Fees.
10.2 Customer dependencies. The Provider may rely on Customer Data, instructions, mappings, decisions, and approvals supplied by the Customer. The Customer must validate imported records, calculations, permissions, templates, workflows, and reports before production use. A successful technical import does not establish legal, accounting, payroll, or factual accuracy.
10.3 Acceptance. Unless an Order Form states another process, a professional-services deliverable is accepted when the Customer uses it in production, confirms acceptance, or does not report a material nonconformity within ten business days after delivery. The Provider will use commercially reasonable efforts to correct a timely reported nonconformity with the agreed scope.
10.4 Reusable materials. The Provider retains ownership of pre-existing materials, general methods, templates, code, connectors, know-how, and improvements used or developed while providing professional services. The Customer receives a non-exclusive right to use deliverables within the Service for its internal business purposes during the Subscription Term. Customer-specific data and branding remain Customer Data.
11 APIs and Integrations
11.1 Authorized access. The Customer may use an API, webhook, import, export, or integration only as documented and within applicable limits. API keys and tokens are credentials and must be protected accordingly. The Customer is responsible for applications, scripts, and data flows created by or for it.
11.2 Permissions. The Customer must configure scopes and permissions appropriate to each integration and ensure that the integration provider is authorized to receive the affected Customer Data. Enabling an integration constitutes an instruction to transmit data as required for that integration.
11.3 Changes. The Provider may modify APIs to improve security, reliability, or functionality. For a material backward-incompatible change to a generally available API, the Provider will use commercially reasonable efforts to give advance notice or maintain a transition period, unless urgent security, legal, or third-party requirements make notice impracticable.
11.4 Abuse and limits. The Provider may throttle, restrict, rotate credentials for, or suspend an API connection that exceeds documented limits, threatens security, creates instability, or violates the Agreement. The Provider is not responsible for errors introduced by Customer code or a Third Party Service.
12 Artificial Intelligence Features
12.1 Scope. AI Features may include Donna Brief, Ask Donna, document assistance, classification, summaries, recommendations, search, forecasting support, anomaly detection, or other automated functionality. AI Features may be provided by the Provider or through approved model and infrastructure providers acting as subprocessors or independent Third Party Services, as applicable.
12.2 Customer control. The Customer decides whether and how to use AI Features, subject to plan availability and administrator controls. The Customer is responsible for determining whether an AI Feature is appropriate for a particular workflow, category of data, jurisdiction, and decision.
12.3 AI Input. The Customer represents that it has the rights and lawful basis necessary to submit AI Input and instruct its processing. The Customer must minimize Personal Data in prompts and must not submit secrets, special-category Personal Data, regulated information, or third-party confidential information unless the relevant feature, Documentation, Data Processing Agreement, and the Customer's authorization permit that processing.
12.4 AI Output. AI Output may be incomplete, inaccurate, outdated, misleading, biased, non-unique, or unsuitable for the Customer's purpose. Similar or identical output may be generated for other users. The Customer must independently review material AI Output, verify source records, and apply qualified human judgment before using it.
12.5 Human oversight. The Customer must not use AI Output as the sole basis for a decision that produces legal or similarly significant effects for an individual, including hiring, rejection, promotion, discipline, termination, compensation, access to benefits, credit, insurance, housing, healthcare, or another consequential decision. The Customer must provide meaningful human review and any notice, explanation, appeal, consultation, or assessment required by Applicable Law.
12.6 Prohibited AI uses. The Customer must not use AI Features to infer highly sensitive traits where prohibited; create unlawful employment profiles; rank persons using protected characteristics; manipulate or exploit vulnerable persons; generate unlawful discriminatory criteria; impersonate a person deceptively; or create content that infringes rights or facilitates harm.
12.7 No cross-customer training commitment. The Provider will not use identifiable Customer Data, AI Input, or AI Output to train a general-purpose model for the benefit of other customers without the Customer's express agreement. This restriction does not prevent processing required to provide the AI Feature, detect abuse, ensure security, evaluate performance using appropriately protected data, or improve a model dedicated to the Customer where agreed.
12.8 Ownership and license. As between the parties, the Customer retains its rights in AI Input and owns or receives the Provider's rights in AI Output to the extent permitted by Applicable Law. The Customer grants the Provider a limited license to process AI Input and AI Output to provide, secure, support, and maintain the Service. The Provider does not warrant that AI Output is protectable by intellectual property rights or does not overlap with content produced for others.
12.9 Feature-specific terms. An AI Addendum or Documentation may impose additional restrictions, identify supported uses, describe model providers, or allocate responsibilities for a specific AI Feature. If the Customer uses that feature, the applicable additional terms form part of the Agreement.
13 Business Decisions and Regulated Activities
13.1 Customer decisions. The Service supports administrative and analytical workflows but does not make employment, legal, accounting, tax, financial, credit, eligibility, safety, or other regulated decisions for the Customer. The Customer retains control of and responsibility for every such decision and for communications made to affected persons.
13.2 Employment practices. The Customer is solely responsible for its recruitment, assessment, onboarding, scheduling, attendance, compensation, performance, discipline, termination, workforce planning, and other employment practices. The Provider is not the employer, joint employer, recruiter, payroll employer, professional employer organization, or employer of record of any person recorded in the Service.
13.3 Payroll and taxes. Payroll and tax features provide configurable calculations, records, reports, and export tools unless an Order Form expressly includes managed payroll or filing services. The Customer must validate rates, thresholds, taxable bases, currencies, benefits, deductions, exchange rates, filing periods, and outputs; approve each payroll; make payments; submit filings; and obtain professional advice where appropriate.
13.4 Finance and forecasting. Financial dashboards, budgets, cash-flow views, forecasts, scenarios, classifications, and reports are informational tools based on Customer Data and assumptions. They are not audited financial statements, investment advice, lending advice, valuation opinions, guarantees, or promises of future performance.
13.5 Legal and document features. Legal workflows, clause libraries, templates, generated documents, reminders, and summaries are administrative tools and do not constitute legal advice or create an attorney-client relationship. The Customer must have qualified counsel review documents and legal decisions where appropriate. The Provider does not warrant that a generated document is valid, enforceable, complete, or suitable in a particular jurisdiction.
13.6 Electronic signatures. If the Service enables electronic signatures, the Provider supplies technical functionality only and is not a party to the signed document. The Customer is responsible for selecting documents legally eligible for electronic signature, obtaining consent, verifying signatory authority, preserving required records, and determining enforceability under Applicable Law.
13.7 Government and public-sector use. Public-sector and B2G customers must determine whether procurement, public records, localization, security, records retention, accessibility, audit, sovereign immunity, and other mandatory requirements apply. No public-sector term binds the Provider unless expressly accepted in a signed Order Form or amendment.
14 Customer Data
14.1 Ownership. As between the parties, the Customer retains all right, title, and interest in Customer Data. The Agreement does not transfer ownership of Customer Data to the Provider.
14.2 Processing license. The Customer grants the Provider and its authorized subprocessors a worldwide, non-exclusive, limited license during the Agreement to host, copy, transmit, display, modify, index, calculate, back up, and otherwise process Customer Data only as reasonably necessary to provide, secure, support, maintain, and improve the Service; comply with the Customer's instructions; prevent fraud or abuse; and comply with Applicable Law.
14.3 Customer instructions. The Agreement, the Customer's configuration, Authorized User actions, support requests, and documented use of the Service constitute the Customer's instructions for processing Customer Data. The Provider will not materially expand processing of Personal Data beyond those instructions without a lawful basis and, where required, the Customer's authorization.
14.4 Content removal. The Provider is not required to monitor Customer Data for legality or accuracy. If the Provider reasonably believes particular content violates Applicable Law, the Agreement, or third-party rights, it may request removal, restrict access, or take other proportionate action. The Provider will notify the Customer where legally permitted and reasonably practicable.
14.5 Legal requests. If the Provider receives a binding request for Customer Data from a governmental or judicial authority, it may disclose data as legally required. Where permitted, the Provider will give the Customer reasonable notice and an opportunity to seek protection. The Provider may challenge a request it reasonably considers unlawful or disproportionate but is not obligated to litigate at its own expense.
15 Usage Data and Deidentified Data
15.1 Usage Data. The Provider may collect and use Usage Data to operate, secure, troubleshoot, support, analyze, and improve the Service; manage capacity; calculate usage; develop features; prevent abuse; and understand product adoption. Usage Data may include event timestamps, feature interactions, device and browser information, performance metrics, error logs, and aggregated account statistics.
15.2 Deidentified data. The Provider may create and use aggregated or deidentified information derived from Customer Data or Usage Data only if reasonable measures are used to prevent identification of the Customer and individuals. The Provider will not attempt to reidentify such information except to test and improve deidentification methods or as required by law.
15.3 Benchmarking. The Provider may produce generalized benchmarks or insights that do not identify the Customer, an Authorized User, or a Data Subject. The Provider will not publicly attribute a benchmark to the Customer without written permission.
16 Privacy and Data Processing
16.1 Roles. For Personal Data contained in Customer Data, the Customer generally acts as controller or equivalent decision maker and the Provider acts as processor or service provider on the Customer's behalf. Each party may act as an independent controller for business contact data, account administration, billing, fraud prevention, legal compliance, and its own legitimate operational records.
16.2 Data Processing Agreement. Where Data Protection Laws require a processor agreement, the Donna OS Data Processing Agreement accepted by the parties applies and is incorporated into the Agreement. The parties must complete any required transfer mechanism, security appendix, or processing details before processing that requires it.
16.3 Customer notices and rights. The Customer is responsible for providing privacy notices to employees, candidates, contractors, customers, leads, and other Data Subjects; responding to their requests; defining retention periods; and ensuring a lawful basis for each processing purpose. The Provider will provide reasonable assistance as required by the applicable Data Processing Agreement and Applicable Law.
16.4 Subprocessors. The Provider may use subprocessors to host, secure, communicate, support, analyze, process payments for, or otherwise provide the Service. The Provider will maintain contractual protections appropriate to their processing and will remain responsible for subprocessor performance to the extent required by the Data Processing Agreement.
16.5 International transfers. Customer Data may be processed in countries other than the Customer's country. Where Data Protection Laws restrict international transfers, the parties will use an applicable legal transfer mechanism and supplementary safeguards described in the Data Processing Agreement.
16.6 Provider privacy notice. The Provider's privacy notice governs Personal Data the Provider collects for its own purposes from website visitors, prospects, billing contacts, administrators, and support contacts. The privacy notice does not replace the Customer's obligations for Personal Data contained in Customer Data.
17 Security
17.1 Security program. The Provider will maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. Safeguards will be appropriate to the nature of the Service, the information processed, and the risks reasonably known to the Provider.
17.2 Shared responsibility. Security is a shared responsibility. The Provider secures the systems under its control. The Customer secures its endpoints, networks, identities, credentials, administrator choices, integrations, exports, and Customer-controlled systems. A security measure made available by the Provider does not relieve the Customer from configuring and using it appropriately.
17.3 Security incident. After confirming a security incident affecting Personal Data in Customer Data, the Provider will notify the Customer without undue delay and provide information reasonably available concerning the nature of the incident, affected data categories, likely consequences, and mitigation measures, to the extent required by Applicable Law. Notification is not an admission of fault or liability.
17.4 Incident cooperation. Each party will reasonably cooperate in investigating and mitigating an incident for which it is responsible. The Customer remains responsible for notifications to Data Subjects, employees, regulators, customers, or other persons unless Applicable Law assigns that duty to the Provider.
17.5 Security testing. The Customer must not conduct security testing without prior written authorization. The Provider may offer a responsible disclosure process. Reports must be made confidentially and must not involve social engineering, disruption, persistence, extraction of Customer Data, or access to another customer environment.
17.6 No absolute guarantee. No online service can eliminate all security risk. The Provider does not warrant that the Service is immune from every attack, vulnerability, interruption, or unauthorized act. This clause does not reduce any security obligation expressly stated in the Agreement or required by Applicable Law.
18 Confidentiality
18.1 Protection duty. Each receiving party will protect the disclosing party's Confidential Information using at least reasonable care and no less than the care it uses for its own information of similar sensitivity. The receiving party will use Confidential Information only to perform or exercise rights under the Agreement.
18.2 Permitted recipients. A receiving party may disclose Confidential Information to its Affiliates, personnel, contractors, subprocessors, auditors, insurers, financing sources, and professional advisers who need to know it and are bound by confidentiality obligations or professional duties. The receiving party remains responsible for disclosures made on its behalf.
18.3 Exclusions. Confidential Information does not include information that the receiving party can document was lawfully known without restriction before disclosure, becomes public without breach, is received lawfully from a third party without a confidentiality duty, or is independently developed without use of the disclosing party's Confidential Information.
18.4 Compelled disclosure. A receiving party may disclose Confidential Information when required by law or binding legal process. Where permitted, it will provide prompt notice and reasonable assistance so the disclosing party may seek a protective order. The receiving party will disclose only the portion legally required.
18.5 Injunctive relief. Unauthorized disclosure or use of Confidential Information may cause harm that money alone cannot adequately remedy. A party may seek interim, injunctive, or equitable relief in addition to other remedies, subject to Applicable Law.
18.6 Duration. Confidentiality obligations continue for five years after disclosure, except that obligations for trade secrets and Customer Data continue for as long as the information remains protected as a trade secret or retained by the receiving party, as applicable.
19 Intellectual Property
19.1 Provider technology. The Provider and its licensors own all right, title, and interest in the Service, Documentation, Provider APIs, user interface, workflows, software, models, algorithms, databases, schemas, templates supplied by the Provider, designs, trademarks, know-how, improvements, and related intellectual property, excluding Customer Data and third-party materials.
19.2 Customer materials. The Customer retains ownership of its names, logos, templates, policies, documents, data structures, and other materials submitted to the Service. The Customer grants the Provider a limited license to use such materials to provide the Service and, where separately authorized, display the Customer's name and logo under Section 34.
19.3 Feedback. If the Customer or an Authorized User provides suggestions, ideas, requests, or feedback concerning the Service, the Provider may use them without restriction or payment, provided it does not disclose the Customer's Confidential Information. The Customer is not required to provide feedback.
19.4 Third-party materials. Third-party software, open-source components, datasets, fonts, or content may be subject to separate license terms. Those terms apply to the relevant component and do not expand the Customer's rights in the remainder of the Service.
19.5 Brand use by Customer. The Customer may accurately identify itself as a Donna OS customer during the Subscription Term but may not imply endorsement, partnership, certification, or sponsorship. Use of Donna OS marks must follow any brand guidelines the Provider makes available.
20 Fees Billing and Taxes
20.1 Fees. The Customer will pay Fees stated in the Order Form or checkout. Except as expressly provided in the Agreement, payment obligations are non-cancellable and Fees paid are non-refundable. Fees are due in the currency and on the schedule stated in the Order Form.
20.2 Merchant of Record. The Provider may appoint Paddle or another authorized reseller or Merchant of Record to sell subscriptions, issue invoices, collect payments, calculate and remit transaction taxes, manage renewals, and administer payment-related refunds. Where a Merchant of Record is the seller identified at checkout or on the invoice, the Customer's purchase transaction is also subject to that seller's buyer terms. These Terms continue to govern access to and use of Donna OS.
20.3 Payment authorization. The Customer authorizes the applicable seller and payment processor to charge the selected payment method for Fees, renewals, usage charges, overages, and applicable taxes. The Customer must maintain valid billing details and sufficient funds and must promptly update expired or invalid payment information.
20.4 Invoices and disputes. Unless an Order Form states otherwise, invoices are due upon receipt. The Customer must raise a good-faith billing dispute within thirty days after the invoice date and pay undisputed amounts when due. The parties will work reasonably to resolve a timely dispute. Failure to dispute an invoice within that period does not waive rights that cannot lawfully be waived.
20.5 Late payment. Overdue undisputed amounts may accrue interest at the lower of one and one-half percent per month or the maximum lawful rate, plus reasonable collection costs. The Provider may suspend access under Section 23 after giving the required notice. The Customer remains responsible for Fees during a suspension caused by its breach or non-payment.
20.6 Taxes. Fees exclude taxes unless the checkout or invoice states otherwise. The Customer is responsible for taxes, duties, levies, and similar governmental charges arising from the purchase or use of the Service, excluding taxes based on the Provider's net income. If the Customer claims an exemption, it must provide valid documentation before the charge. A Merchant of Record may calculate, collect, and remit taxes under its own legal obligations.
20.7 Withholding. If the Customer must withhold tax from a payment made directly to the Provider, it must provide official evidence of withholding and, unless prohibited by law or agreed in the Order Form, gross up the payment so the Provider receives the amount it would have received without withholding.
20.8 Usage and headcount changes. If Fees depend on employees, users, records, storage, transactions, messages, AI consumption, entities, or another usage metric, the Provider may calculate charges from Service records. The Customer must not delete, deactivate, or reclassify records solely to evade committed Fees or measurement rules. The Order Form controls any true-up process.
20.9 Price changes. For monthly subscriptions, the Provider may change recurring prices by giving at least thirty days notice, with the change taking effect on a later renewal. For annual subscriptions, a price change takes effect only on renewal and the Provider will use commercially reasonable efforts to give at least sixty days notice. Usage-based rates may change as stated in the Order Form or applicable pricing page. The Customer may prevent renewal by cancelling within the applicable notice period.
21 Trials Free Features and Beta Services
21.1 Trials. A trial is available only for the period, modules, and usage limits stated at sign-up. The Provider may end or restrict a trial at any time. Unless checkout clearly states that a trial converts automatically to a paid subscription and the Customer supplies a payment method, access ends when the trial expires.
21.2 Free features. The Provider may offer free features or plans subject to usage limits. Free access may be changed or discontinued on reasonable notice and does not include any service-level commitment, data retention commitment, or support obligation beyond Applicable Law.
21.3 Beta Services. Beta, preview, pilot, early-access, experimental, or evaluation features may be incomplete, unstable, inaccurate, changed, or discontinued without notice. They are provided as is for testing and evaluation, may not be suitable for production, and may be subject to additional terms and lower or different security, support, availability, or data residency commitments disclosed before use.
21.4 Test data. The Customer must not use live Personal Data, confidential production data, or regulated data in a test environment or Beta Service unless the Provider expressly authorizes that use and confirms applicable safeguards.
22 Renewal Cancellation and Refunds
22.1 Automatic renewal. Subscriptions renew automatically as described in Section 5 unless either party gives timely notice of non-renewal. The Customer is responsible for monitoring renewal dates and maintaining current billing and notice contacts.
22.2 Monthly cancellation. The Customer may cancel a monthly subscription at any time through the available account or billing portal or by sending notice through an accepted support channel. Cancellation takes effect at the end of the current paid monthly period. No prorated refund or credit is issued for unused time in that period unless required by law.
22.3 Annual non-renewal. The Customer may stop an annual subscription from renewing by giving notice at least sixty days before the end of the current annual term, unless the Order Form permits a shorter period. The annual subscription continues through the end of the committed term and all Fees for that term remain due.
22.4 Partial cancellation. Cancelling a module, add-on, user package, or other component may end a bundle discount or change the price of remaining components at the next permitted billing event. An annual component may not be removed during a committed term unless the Order Form expressly permits it.
22.5 Refunds. Except where Applicable Law requires a refund or the Agreement expressly provides one, transactions are non-refundable. If the Customer terminates an annual subscription because the Provider materially breaches the Agreement and fails to cure within thirty days after detailed written notice, the Provider will refund prepaid Fees allocable to the unused period after termination. This is the Customer's exclusive monetary remedy for that termination, without limiting non-waivable rights.
22.6 Chargebacks. The Customer must contact the applicable seller in good faith before initiating a chargeback for a disputed transaction. A chargeback does not terminate the subscription or eliminate amounts properly due. The Provider may suspend access while a chargeback or payment reversal is investigated.
23 Suspension
23.1 Grounds. The Provider may suspend all or part of the Service if the Customer materially breaches the Agreement; undisputed payment is overdue; use creates a material security, legal, or operational risk; the Provider reasonably suspects fraud or unauthorized access; a governmental authority or Third Party Service requires suspension; or continued provision could expose the Provider or another person to liability or harm.
23.2 Notice and cure. Where the issue is capable of cure and urgent action is not required, the Provider will give notice and a reasonable opportunity to cure. For non-payment, that opportunity will ordinarily be at least ten days after notice. The Provider may suspend immediately where necessary to address an active security threat, unlawful conduct, sanctions risk, material harm, or a binding legal requirement.
23.3 Scope and restoration. The Provider will seek to limit suspension to the affected account, user, feature, integration, content, or activity where reasonably possible. The Provider will restore access after the grounds are resolved and the Customer has paid applicable overdue amounts and reasonable reactivation costs, if any.
23.4 No liability for proper suspension. To the extent permitted by Applicable Law, the Provider is not liable for losses resulting from a suspension carried out in accordance with this Section. Suspension does not waive either party's termination rights or the Customer's payment obligations.
24 Termination
24.1 Termination for cause. Either party may terminate the Agreement or an affected Order Form if the other party materially breaches it and does not cure the breach within thirty days after receiving written notice that describes the breach in reasonable detail. The cure period does not apply to a breach that cannot reasonably be cured.
24.2 Immediate termination. A party may terminate immediately if the other party becomes insolvent, enters liquidation, ceases business without a successor, makes an assignment for the benefit of creditors, or becomes subject to a comparable proceeding that is not dismissed within sixty days. The Provider may terminate immediately for unlawful use, deliberate security compromise, repeated material breaches, sanctions restrictions, or infringement that creates material risk.
24.3 Effect. On the effective date of termination or expiration, the Customer's right to access the Service ends, except for a data export period under Section 25. The Customer must stop using the Provider's confidential materials and pay all accrued and committed Fees. Termination of one Order Form does not terminate another unless the notice says so or the remaining Service cannot reasonably operate independently.
24.4 Survival. Provisions that by their nature should survive will survive, including provisions concerning accrued payment, data ownership, confidentiality, intellectual property, disclaimers, indemnification, liability limits, dispute resolution, effect of termination, and general interpretation.
25 Data Export Retention and Deletion
25.1 Export period. For thirty days after ordinary expiration or termination, the Customer may request or perform a standard export of available Customer Data using supported formats, provided the Customer has paid undisputed amounts and access is not prohibited by law or a security risk. The Provider is not required to recreate deleted data or build a custom export unless separately agreed.
25.2 Administrative assistance. If the Customer requests migration or a custom export that requires professional services, the Provider may charge reasonable Fees and require a statement of work. The Customer should request assistance before the Subscription Term ends.
25.3 Deletion. After the export period, the Provider may disable the tenant and begin deletion of Customer Data from active systems. Unless Applicable Law, a DPA, an Order Form, or a documented retention setting requires another period, the Provider will use commercially reasonable efforts to delete production Customer Data within ninety days after the export period ends.
25.4 Backups and legal retention. Residual copies may remain in encrypted backups, immutable security logs, financial records, or legal archives until overwritten or deleted under ordinary retention cycles. Such data remains protected by the Agreement and will not be restored except for disaster recovery, legal compliance, or security purposes.
25.5 Customer responsibility. The Customer is responsible for exporting Customer Data it needs before the export period expires. After deletion, the Provider has no obligation to retain or recover Customer Data. This Section does not require deletion of Usage Data or properly deidentified data.
26 Service Changes and Deprecation
26.1 Continuous development. The Provider may update, enhance, redesign, replace, or modify the Service. The Provider will not materially reduce the core functionality of a paid module during a committed annual term without providing a commercially reasonable alternative, except where a change is required for security, law, third-party dependency, or prevention of abuse.
26.2 Feature deprecation. For material removal of a generally available paid feature, the Provider will use commercially reasonable efforts to give advance notice appropriate to the impact. Notice may be shorter or unavailable for urgent security issues, legal requirements, discontinued third-party services, or beta features.
26.3 No reliance on future features. The Customer's purchase is based on the Service available at the time of the Order Form and not on future features, release dates, roadmap statements, marketing plans, or public comments. Any roadmap is informational and may change.
27 Third Party Services
27.1 Optional services. The Service may link to or interoperate with Third Party Services selected by the Customer. Unless identified as a Provider subprocessor, a Third Party Service is governed by its own terms, privacy notices, security practices, availability, and fees. The Provider does not control that service.
27.2 Customer authorization. When the Customer enables a Third Party Service, it authorizes the Provider to exchange Customer Data with that service as necessary for the integration. The Customer is responsible for reviewing the third party's terms, permissions, data practices, and continued suitability.
27.3 Dependency changes. A Third Party Service may change or discontinue an interface or functionality. The Provider is not liable for resulting interruption or loss of integration functionality but will use commercially reasonable efforts to communicate a material known impact and, where practical, offer an alternative.
27.4 Merchant of Record services. Payment services supplied by a Merchant of Record are Third Party Services for payment and transaction purposes. The Provider may exchange order, subscription, account, and support information with that provider as necessary to complete sales, prevent fraud, administer subscriptions, and support the Customer.
28 Availability Support and Maintenance
28.1 Availability. The Provider will use commercially reasonable efforts to make paid production Services available continuously, excluding planned maintenance, emergency maintenance, Customer-caused issues, Third Party Services, internet failures, and events beyond reasonable control. No specific uptime commitment applies unless stated in an Order Form or Service Level Agreement.
28.2 Maintenance. The Provider may perform maintenance and deploy updates. Where practical, the Provider will schedule planned maintenance to reduce disruption and provide advance notice of maintenance expected to materially affect availability. Emergency maintenance may occur without advance notice.
28.3 Support. Standard support channels, hours, languages, response targets, and exclusions are described in the applicable plan, Documentation, or Order Form. Response targets are goals unless expressly identified as binding service levels. Support does not include legal, tax, accounting, HR, data-entry, custom development, or third-party administration services unless purchased separately.
28.4 Customer support duties. The Customer must provide sufficient information to reproduce and diagnose an issue, including relevant timestamps, user roles, steps, expected behavior, and non-sensitive screenshots or logs. The Customer must cooperate with reasonable troubleshooting and test proposed corrections in an appropriate environment.
29 Warranties
29.1 Mutual authority. Each party represents that it has authority to enter into the Agreement and perform its obligations.
29.2 Service warranty. The Provider warrants that, during a paid Subscription Term, the Service will perform materially in accordance with the applicable Documentation under normal authorized use. The Customer must notify the Provider of a material nonconformity with reasonable detail. The Provider will use commercially reasonable efforts to correct it.
29.3 Professional services warranty. The Provider warrants that professional services will be performed with reasonable skill and care consistent with generally accepted industry practice. The Customer must report a breach within thirty days after the affected service is performed. The Provider will reperform the nonconforming service as the primary remedy.
29.4 Exclusions. The warranties do not apply to issues caused by unauthorized use, the Customer's configuration, unsupported modification, Customer Data, a Third Party Service, failure to follow Documentation, use outside stated limits, or a free, trial, or Beta Service.
30 Disclaimers
30.1 General disclaimer. Except for the express warranties in Section 29 and to the maximum extent permitted by Applicable Law, the Service, Documentation, AI Features, Beta Services, templates, reports, and professional services are provided as is and as available. The Provider disclaims implied warranties and conditions of merchantability, satisfactory quality, fitness for a particular purpose, title, non-infringement, accuracy, and those arising from course of dealing or usage of trade.
30.2 No uninterrupted or error-free service. The Provider does not warrant that the Service will be uninterrupted, entirely secure, error-free, compatible with every system, or that every defect will be corrected. The Provider does not warrant that Customer Data or third-party data is accurate, complete, lawful, or current.
30.3 No professional advice. The Provider does not provide legal, employment, accounting, tax, investment, audit, medical, or other regulated professional advice through the Service. Information, templates, calculations, AI Output, alerts, and reports must not be treated as a substitute for qualified professional advice.
30.4 No guaranteed outcome. The Provider does not guarantee recruitment outcomes, employee retention, legal compliance, revenue, profit, cost savings, tax results, forecast accuracy, collection of receivables, successful litigation, funding, or any other business result.
30.5 Essential basis. The Customer acknowledges that the allocation of risk in the Agreement is reflected in the Fees and is an essential basis of the parties' bargain. Nothing in the Agreement excludes a warranty or remedy that cannot lawfully be excluded.
31 Indemnification
31.1 Customer indemnity. The Customer will defend the Provider, its Affiliates, and their personnel against a third-party claim to the extent arising from Customer Data, AI Input, the Customer's instructions, the Customer's products or services, employment or contractor decisions, the Customer's violation of Applicable Law, or the Customer's use of the Service in breach of the Agreement. The Customer will pay damages, settlements, and reasonable external legal fees finally awarded or approved under Section 31.4.
31.2 Provider intellectual property indemnity. The Provider will defend the Customer against a third-party claim alleging that authorized use of the paid Service infringes that third party's copyright, patent, or trademark, and will pay damages, settlements, and reasonable external legal fees finally awarded or approved under Section 31.4.
31.3 Provider options and exclusions. If an infringement claim is made or likely, the Provider may obtain the right to continue use, modify or replace the affected Service, or terminate the affected component and refund prepaid Fees allocable to its unused period. The Provider has no obligation for a claim arising from Customer Data, the Customer's instructions, unauthorized modification, combination with items not supplied by the Provider, continued use after notice to stop, or use outside the Agreement. This Section states the Customer's exclusive remedy for third-party intellectual property claims.
31.4 Procedure. The indemnified party must promptly notify the indemnifying party, give it sole control of the defense and settlement, and provide reasonable cooperation at the indemnifying party expense. Delay in notice relieves the indemnifying party only to the extent materially prejudiced. A settlement may not admit fault by, impose non-monetary obligations on, or restrict the business of the indemnified party without its prior written consent, not to be unreasonably withheld.
32 Limitation of Liability
32.1 Excluded damages. To the maximum extent permitted by Applicable Law, neither party is liable under or in connection with the Agreement for lost profits, lost revenue, lost savings, loss of goodwill, business interruption, loss of opportunity, loss or corruption of data, or any indirect, incidental, special, exemplary, punitive, or consequential damages, even if advised that such damages were possible.
32.2 General cap. To the maximum extent permitted by Applicable Law, each party's aggregate liability arising out of or relating to the Agreement will not exceed the Fees paid or payable by the Customer for the affected Service during the twelve months immediately preceding the first event giving rise to the liability. If the event occurs during a free or trial service, the Provider's aggregate liability will not exceed one hundred United States dollars or the equivalent in the billing currency.
32.3 Carve outs. The exclusions and cap do not apply to the Customer's payment obligations; a party's fraud, wilful misconduct, or gross negligence to the extent liability cannot be limited; the Customer's infringement or misappropriation of the Provider's intellectual property; a party's indemnification obligations; or liability that Applicable Law prohibits the parties from limiting. Confidentiality and data protection liability remains subject to the general cap unless an Order Form expressly states a separate cap or Applicable Law requires otherwise.
32.4 Allocation among claims. The liability cap applies in aggregate across all claims, Order Forms, theories of liability, and causes of action relating to the same Agreement and is not multiplied by the number of incidents, claimants, Authorized Users, or modules.
32.5 Time limit. To the extent permitted by Applicable Law, a claim must be brought within one year after the claimant knew or reasonably should have known the facts giving rise to it. This contractual period does not apply where Applicable Law requires a longer non-waivable period.
33 Compliance with Laws
33.1 Each party responsibility. Each party will comply with Applicable Law in performing its own obligations. The Provider is responsible for laws generally applicable to providing the Service. The Customer is responsible for laws applicable to its industry, workforce, Customer Data, configurations, decisions, communications, and use of the Service.
33.2 Employment and discrimination law. The Customer must configure and use the Service consistently with employment, labor, equality, anti-discrimination, accessibility, works council, employee monitoring, payroll, tax, and records laws applicable to it. The Provider does not monitor the Customer's compliance or approve its employment practices.
33.3 Export controls and sanctions. The Customer must not access, use, export, re-export, transfer, or provide the Service in violation of applicable export controls, trade sanctions, or restricted-party rules. Each party represents that it is not a prohibited party and will notify the other if that status changes. The Provider may block access where reasonably necessary for compliance.
33.4 Anti-bribery. Neither party will offer, authorize, request, or accept an improper payment or advantage in connection with the Agreement. The Customer must not use the Service to conceal, facilitate, or record unlawful payments.
33.5 Records and audit. The Customer must maintain records reasonably necessary to demonstrate compliance with subscription metrics and restrictions. If the Provider reasonably suspects material underpayment or prohibited resale, it may request a written certification or conduct a limited audit on reasonable notice, no more than once annually, subject to confidentiality and minimal disruption. The Customer will pay audit costs only if an underpayment greater than five percent is confirmed.
34 Publicity
34.1 Customer identification. Unless the Customer opts out in writing, the Provider may identify the Customer by name and logo in a factual customer list during the Subscription Term. The Provider will follow brand guidelines supplied by the Customer and will not publish a case study, testimonial, performance claim, or press release without separate approval.
34.2 Revocation. The Customer may revoke logo permission by written notice. The Provider will remove the logo from new digital materials within a commercially reasonable period but is not required to recall materials already printed or distributed.
35 Changes to the Agreement
35.1 Non-material changes. The Provider may update these Terms to clarify language, improve administration, address new features, reflect operational changes, or comply with law. Non-material changes take effect when posted or on the date stated in the notice.
35.2 Material changes. For a material change that adversely affects an existing paid Customer, the Provider will give at least thirty days notice. For a monthly subscription, the change takes effect on the first renewal after the notice period. For an annual subscription, the change takes effect on the next renewal unless the change is required earlier by Applicable Law, addresses abuse or security, or applies only to a new feature the Customer elects to use.
35.3 Rejection of changes. If the Customer does not agree to a material change effective on renewal, its remedy is to prevent renewal and stop using the affected Service at the end of the current term. Continued use after the effective date constitutes acceptance. No update retroactively changes accrued rights or liability for earlier events.
36 Notices
36.1 Operational notices. The Provider may send operational, security, billing, renewal, and product notices to the account, billing, or administrator email address, through the Service, or through the billing portal. The Customer must keep those contacts current. An email notice is deemed received on the first business day after sending unless the sender receives a permanent delivery failure.
36.2 Legal notices to the Provider. A legal notice to the Provider must be sent to support@donna-os.com with the subject Legal Notice and must include the Customer's legal name, account identifier, sender authority, and a detailed description. If an Order Form identifies a different legal notice address, that address controls.
36.3 Legal notices to the Customer. A legal notice to the Customer will be sent to the legal or billing contact stated in the Order Form or, if none, to the account owner. The Customer is responsible for ensuring that such notices reach authorized personnel.
37 Governing Law and Disputes
37.1 Governing law. The Agreement and any non-contractual obligations arising from it are governed by the laws of Georgia, without regard to conflict-of-laws rules that would apply another jurisdiction law. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
37.2 Good faith resolution. Before filing a claim, a party must give written notice describing the dispute and requested relief. Authorized representatives will attempt in good faith to resolve it for at least thirty days. This requirement does not prevent a party from seeking urgent interim relief, preserving a limitation period, pursuing undisputed debt, or reporting a matter to a competent authority.
37.3 Courts. The courts of Tbilisi, Georgia have exclusive jurisdiction over disputes arising out of or relating to the Agreement, and each party submits to those courts. If exclusive jurisdiction is not enforceable for a particular claim, this clause does not prevent proceedings in another court that has mandatory jurisdiction.
37.4 Individual relief. To the extent permitted by Applicable Law, each party will bring claims only in its individual capacity and not as a plaintiff or class member in a class, collective, representative, or consolidated proceeding. This clause does not prevent joinder required by law or coordinated proceedings agreed by the parties.
38 General Terms
38.1 Entire agreement. The Agreement is the entire agreement between the parties concerning its subject and supersedes prior or contemporaneous proposals, statements, negotiations, and agreements on that subject. The Customer acknowledges that it has not relied on a statement not expressly included in the Agreement, without limiting liability for fraud.
38.2 Amendment. Except for updates permitted by Section 35, an amendment must be in writing and accepted by authorized representatives of both parties. An email may constitute a writing if it clearly records an agreed amendment and is sent by authorized representatives.
38.3 Assignment. The Customer may not assign or transfer the Agreement, in whole or part, without the Provider's prior written consent, not to be unreasonably withheld. The Provider may assign the Agreement to an Affiliate or in connection with a merger, reorganization, financing, sale of substantially all relevant assets, or transfer of the Donna OS business, provided the assignee assumes the Provider's obligations. Any prohibited assignment is void to the extent permitted by law.
38.4 Subcontracting. The Provider may use subcontractors to perform the Service and remains responsible for their performance as required by the Agreement. Subprocessors handling Personal Data are governed by the Data Processing Agreement.
38.5 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, epidemic, war, terrorism, civil unrest, government action, labor disruption, utility or telecommunications failure, internet routing failure, cyberattack by a third party, or failure of a critical supplier, provided the affected party uses reasonable efforts to mitigate. Force majeure does not excuse accrued payment obligations.
38.6 Waiver. A waiver must be express and in writing. Failure or delay to exercise a right does not waive it. A waiver for one event does not waive a later event.
38.7 Severability. If a provision is held invalid or unenforceable, it will be enforced to the maximum lawful extent and modified only as necessary to reflect the original commercial purpose. The remaining provisions remain in effect.
38.8 Independent contractors. The parties are independent contractors. Neither party may bind the other or incur an obligation on the other behalf without express written authority.
38.9 No third-party beneficiaries. The Agreement does not confer enforceable rights on any person other than the parties and their permitted successors and assigns, except indemnified persons solely for purposes of Section 31.
38.10 Interpretation. Headings are for convenience and do not affect interpretation. Including and similar words are illustrative and not limiting. Singular includes plural where context requires. A reference to writing includes permitted electronic communications. The Agreement will not be interpreted against a party solely because it drafted a provision.
38.11 Language. The English version controls. A translation is provided only for convenience unless an Order Form expressly states that another language version controls.
38.12 Counterparts and electronic records. An Order Form or amendment may be executed in counterparts and by electronic signature or acceptance. Electronic records and copies are admissible to the same extent as originals, subject to Applicable Law.
Schedule 1 Module Specific Terms
This Schedule applies only to modules and features included in the Customer's subscription. It supplements the main Terms. If a provision in this Schedule directly conflicts with the main Terms for a specific module, this Schedule controls only for that module.
S1.1 Donna Brief and Ask Donna
S1.1.1 Responsibility. Donna Brief and Ask Donna may summarize Customer Data, identify records that appear to require attention, answer questions, and suggest actions. Results depend on data quality, configuration, permissions, and model behavior.
S1.1.2 Responsibility. The Customer must verify each alert, summary, source reference, calculation, recommendation, and proposed action. A missing alert does not mean no action is required, and an alert does not establish that the underlying event has occurred.
S1.1.3 Responsibility. Donna Brief and Ask Donna do not have authority to bind the Customer, approve transactions, communicate externally, change employee status, make payments, file documents, or take another consequential action unless a separately enabled workflow requires an Authorized User approval or the Customer expressly configures permitted automation.
S1.2 Human Resources and Employee Management
S1.2.1 Responsibility. The Customer controls employee records, roles, documents, leave rules, approvals, performance information, and employment workflows. The Customer must provide legally required notices and limit access to sensitive employment information.
S1.2.2 Responsibility. The Service does not determine worker classification, employment status, statutory entitlement, disciplinary fairness, termination grounds, accommodation, protected leave, or compliance with collective agreements. The Customer must obtain qualified advice where necessary.
S1.2.3 Responsibility. Any retention, risk, performance, engagement, or similar indicator is informational. The Customer must not treat an indicator as verified fact or use it as the sole basis for an employment decision.
S1.3 Document Generation
S1.3.1 Responsibility. Document templates and generated documents depend on Customer-selected variables and source records. The Customer must review names, dates, amounts, governing law, authority, required disclosures, and signature formalities before issue.
S1.3.2 Responsibility. The Provider does not warrant that a template reflects current law or the Customer's circumstances. Generated text is not legal advice and may require localization and professional review.
S1.3.3 Responsibility. The Customer is responsible for signed copies, evidence of delivery, legal retention, and determining whether a document may be executed electronically.
S1.4 Customer Relationship Management
S1.4.1 Responsibility. The Customer must have a lawful basis for prospect and customer data, marketing, profiling, call records, and communications. It must honor consent, objection, suppression, and opt-out requirements.
S1.4.2 Responsibility. Pipeline stages, lead scores, reminders, and forecasts are business tools, not guarantees that a transaction will close or a customer will pay.
S1.4.3 Responsibility. The Customer must configure access so that commercially sensitive customer and deal data is available only to appropriate Authorized Users.
S1.5 Legal Management
S1.5.1 Responsibility. Legal matter records, contract repositories, clause extraction, deadline reminders, and obligation tracking are administrative tools. The Customer must verify deadlines, legal status, privilege, confidentiality, and completeness.
S1.5.2 Responsibility. Use of the module does not create an attorney-client relationship, preserve legal privilege automatically, or substitute for a lawyer docketing or records system.
S1.5.3 Responsibility. A reminder may fail because of incorrect dates, missing data, notification configuration, delivery failure, or service interruption. The Customer must maintain independent controls for critical limitation periods, court dates, filings, and contractual notices.
S1.6 Finance
S1.6.1 Responsibility. The Customer must validate chart-of-account mappings, categories, exchange rates, opening balances, invoices, payments, accruals, and reports. The Service is not an audited accounting ledger unless expressly agreed.
S1.6.2 Responsibility. Invoice generation does not guarantee delivery, acceptance, collectability, tax validity, or payment. The Customer remains responsible for collection and reconciliation.
S1.6.3 Responsibility. Financial metrics and scenarios are informational and must be reconciled to authoritative accounting and banking records before reporting or decision-making.
S1.7 Payroll and Taxes
S1.7.1 Responsibility. Unless an Order Form expressly states otherwise, the module calculates and exports payroll information but does not hold funds, initiate salary or tax payments, act as tax agent, or submit filings.
S1.7.2 Responsibility. Presets may not reflect every location, worker type, exemption, benefit, deduction, retroactive adjustment, or legislative change. The Customer must validate each payroll period and lock or approve it using appropriate segregation of duties.
S1.7.3 Responsibility. The Customer remains responsible for timely payment, filings, payslips, employee notices, corrections, statutory retention, and professional review.
S1.8 Employee Workspace and Requests
S1.8.1 Responsibility. The Customer controls which records employees can view or change and which requests they may submit. A submitted request is not approved unless the configured workflow records approval by an authorized person.
S1.8.2 Responsibility. The Customer is responsible for response deadlines, appeal routes, accessibility, employee communications, and keeping authoritative policies available.
S1.8.3 Responsibility. Employee self-service changes may require verification or supporting documents. The Customer must review changes before using them for payroll, tax, benefits, or legal purposes.
S1.9 Attendance and Time
S1.9.1 Responsibility. Attendance, schedule, and time records depend on the Customer's configuration and user input. The Customer must validate working-time rules, overtime, breaks, rest periods, time zones, rounding, travel, remote work, and lawful monitoring.
S1.9.2 Responsibility. The Service does not determine whether a person is exempt, whether time is compensable, or whether an attendance action is lawful.
S1.9.3 Responsibility. The Customer must maintain correction and approval processes and provide employees access to records where required.
S1.10 Analytics and Chief Executive Dashboard
S1.10.1 Responsibility. Dashboards and metrics are derived from configured definitions and available Customer Data. Different definitions, filters, currencies, time periods, and data completeness can materially change results.
S1.10.2 Responsibility. The Customer must identify authoritative sources, document metric definitions, and validate material reports before presenting them to management, investors, authorities, or third parties.
S1.10.3 Responsibility. Benchmarks are informational and may not be statistically representative of the Customer's industry, geography, size, or circumstances.
S1.11 Forecasting
S1.11.1 Responsibility. Forecasts and scenarios are estimates based on assumptions, historical data, and model choices. Actual outcomes may differ materially.
S1.11.2 Responsibility. The Customer must review assumptions, confidence, sensitivity, missing variables, and the consequences of error before relying on a forecast.
S1.11.3 Responsibility. The Provider does not guarantee headcount, revenue, cost, cash, demand, attrition, or other forecast accuracy.
S1.12 Organization and Position Register
S1.12.1 Responsibility. Organization charts, reporting lines, positions, vacancies, grades, and headcount plans are administrative representations created from Customer Data. They do not by themselves create employment authority, delegation, budget approval, or a legal position.
S1.12.2 Responsibility. The Customer must control effective dates and approvals and reconcile the register with employment contracts, budgets, and payroll records.
S1.12.3 Responsibility. Historical reporting may change if the Customer edits records retroactively. The Customer must preserve snapshots or exports needed for audit.
S1.13 Notifications and Reminders
S1.13.1 Responsibility. Notifications are a convenience and may be delayed, filtered, blocked, misdirected, or not delivered. The Customer must not rely exclusively on notifications for statutory deadlines, contract expiry, payments, filings, safety matters, or other critical obligations.
S1.13.2 Responsibility. The Customer is responsible for accurate contact information, notification settings, escalation paths, and independent controls for critical deadlines.
S1.14 Imports Exports and Bulk Actions
S1.14.1 Responsibility. The Customer must review file structure, mappings, encoding, duplicates, identifiers, effective dates, and permission consequences before an import or bulk action.
S1.14.2 Responsibility. The Customer should test material migrations in a non-production environment using non-sensitive data and retain a validated source copy.
S1.14.3 Responsibility. Exports may contain sensitive Customer Data. The Customer is responsible for secure storage, transfer, access control, and deletion after export.
S1.15 Administration and Audit Logs
S1.15.1 Responsibility. Administrative controls and audit logs support governance but do not guarantee detection or prevention of every unauthorized act. The Customer must review privileged access and material changes regularly.
S1.15.2 Responsibility. Log retention and available event detail depend on plan and configuration. The Customer must export or preserve logs needed for legal, audit, or security purposes before the applicable retention period expires.
Schedule 2 Order Form Requirements
Each Order Form should identify the commercial terms necessary to determine what the Customer purchased. An omitted item is governed by these Terms and the then-current plan description.
Schedule 3 Data Lifecycle on Termination
This Schedule summarizes the ordinary data lifecycle after expiration or termination. Section 25 controls if this summary conflicts with the main Terms.
Contact Information
Questions about the Service or this Agreement may be sent to support@donna-os.com. Legal notices must follow Section 36. The Provider may publish updated business contact information on the Donna OS legal page or in an applicable Order Form.
End of Donna OS Terms of Service