"Kendri" is a product and trading name of Techytal Ltd, a company incorporated in England and Wales, company number [COMPANY NUMBER], whose registered office is at [REGISTERED ADDRESS] ("Techytal", "the Company", "we", "us", "our").
"Customer" means the institution or organisation purchasing the Services.
"Authorised Users" means individuals authorised by the Customer to administer or use the Services.
"End User" means an individual who interacts with the Ask Kendri chat widget on an authorised Customer website.
"Customer Content" means content, data, materials, text, documents, pages and other information supplied by or on behalf of the Customer, or collected from Customer-authorised websites, for use with the Services.
"End-User Data" means personal data submitted by an End User through the Services.
"Services" means Kendri's hosted software platform, website crawler, the Ask Kendri chat widget, the administrative dashboard, APIs, and related services.
"Sub-Processor" means a third party engaged by the Company to process personal data on behalf of the Customer, as listed in the then-current Sub-Processor List.
The Customer grants the Company a limited, non-exclusive, worldwide licence, for the duration of the subscription term, to access Customer-authorised websites; crawl and retrieve their publicly available content; reproduce and process that content; store copies and technical representations of it; create indexes and vector representations of it; retrieve relevant portions of it in response to End User questions; generate responses to End Users using it; and otherwise process it as reasonably necessary to provide the Services.
This licence does not transfer ownership of Customer Content to the Company. The Customer represents that it has sufficient rights and permissions to authorise the foregoing processing.
The Customer is responsible for the legality, accuracy and currency of its website content; determining which websites and pages are authorised for use with the Services; ensuring it has the necessary rights to authorise crawling and processing of that content; maintaining accurate administrator information; configuring appropriate institutional escalation recipients; monitoring escalated questions in a timely manner; maintaining its own safeguarding and emergency procedures independently of the Services; and ensuring its employees and administrators use the Services appropriately and in accordance with the Acceptable Use Policy.
The Customer acknowledges that responses delivered through Ask Kendri are generated using artificial intelligence and may contain errors, omissions or inaccuracies. The Services are intended to provide informational assistance based on Customer-authorised content and are not a substitute for authoritative institutional decisions or professional advice.
The Customer should independently verify, and should advise End Users to independently verify, any information of significant consequence obtained through the Services, including deadlines, admissions requirements, fees, eligibility requirements, legal requirements, health information, financial matters, safeguarding information, and emergency information.
The Company does not warrant that every response will be correct, complete, current, or suitable for a particular End User's circumstances.
The Ask Kendri widget will display a clear notice substantially equivalent to the following, and the Company may update this wording from time to time provided it remains clear that responses are AI-generated and should not automatically be treated as authoritative:
"Kendri uses AI to answer questions using information provided by [Institution Name]. Responses may occasionally be inaccurate. Please verify important information with the institution."
The Services include an automated, best-efforts classification mechanism designed to identify certain messages that may indicate a welfare, safety, or safeguarding concern. The Customer acknowledges that this classification is probabilistic and may produce false positives, false negatives, or delayed or unsuccessful escalation.
This feature is provided on a best-efforts basis only and is not an emergency response service, crisis intervention service, medical service, counselling service, or safeguarding service. The Customer remains solely responsible for maintaining and operating its own safeguarding and emergency-response procedures, and for ensuring designated staff monitor the relevant escalation channel. The Company does not guarantee that any End User message will be identified, escalated, or reviewed within any particular period.
The Ask Kendri widget will display a corresponding notice substantially equivalent to:
"If your message suggests you may need urgent help, it may be shared with designated staff at [Institution Name]. Kendri is not an emergency service."
The Services must not be represented or relied upon as a means of obtaining emergency assistance. Where an End User appears to require immediate emergency assistance, the Customer is responsible for providing appropriate emergency-information routing through its own website or other institutional channels.
The parties acknowledge that, for End-User Data processed through the Services, the Customer generally acts as Controller and the Company as Processor. A Data Processing Agreement, incorporated by reference into these Terms, governs such processing and is available at kendri.co.uk/dpa.
The Customer authorises the Company to engage the Sub-Processors listed on the Company's then-current Sub-Processor List, available at kendri.co.uk/subprocessors. The Company will maintain this list, notify the Customer of material additions or replacements, and provide a mechanism for objection where required by law. Where a Sub-Processor is engaged, the Company will impose appropriate data-protection obligations on it.
Where the Company makes a restricted international transfer of personal data subject to UK GDPR, it will use an appropriate lawful transfer mechanism, which may include an applicable adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism recognised by applicable data protection law. The parties will cooperate in completing any required transfer risk assessment.
The Company will maintain appropriate technical and organisational measures proportionate to the risk of the processing, including logical tenant separation, authentication controls, least-privilege access, encryption in transit and (where supported) at rest, secrets management, access and administrative audit logging, vulnerability management, backups, incident-response procedures, secure development practices, and controlled production access.
The Company will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, targeting notification no later than 24 hours after confirming or reasonably determining that a qualifying breach has occurred. The Company will provide reasonably available information on the nature of the incident, categories of affected data, likely consequences, containment and remediation measures, and incident-coordination contact details, and will reasonably assist the Customer in meeting its own regulatory notification obligations.
The Company will provide reasonable assistance to the Customer in responding to data subject access, rectification, erasure, restriction, objection, and portability requests, as further specified in the Data Processing Agreement, which may specify reasonable costs for unusually burdensome assistance.
The Company's default retention periods are as follows, subject to legal retention obligations, active disputes, security investigations, documented Customer instructions, or specific contractual arrangements:
Backups may retain deleted information for up to 90 days through normal backup rotation, after which it is no longer available for ordinary operational use.
Unless expressly agreed otherwise in writing, the Company will not use Customer Content, End-User Data, End-User questions, conversation history, or other Customer personal data to train, fine-tune, or improve general-purpose artificial intelligence models. The Company may use aggregated or appropriately de-identified service metrics for operational and commercial purposes, provided this does not permit identification of the Customer or any End User.
The Services are provided on a commercially reasonable efforts basis unless a separate Service Level Agreement applies, in which case the SLA takes precedence over this section. The Company may perform maintenance and upgrades from time to time.
Fees are charged according to the Customer's applicable Subscription Plan. Usage-based plans may measure questions or other defined usage units. The Company may enforce technical usage limits and may suspend or restrict usage where contractual quotas are exceeded.
A free trial may be offered without requiring payment card details. The Company may restrict the number of connected pages, impose question or usage limits, apply a maximum trial duration, and suspend use if fair-use or cost limits are exceeded. A trial will not automatically convert to a paid subscription unless the Customer expressly elects to purchase a paid plan.
For monthly subscriptions, the Customer may cancel before the next renewal date; unless otherwise agreed, cancellation takes effect at the end of the then-current billing period. For annual plans, fees are generally non-refundable following commencement except where required by law or expressly agreed in an Order Form. The Company may suspend or terminate the Services for non-payment, material breach, unlawful use, security risk, misuse, attempted compromise of the Services, infringement of applicable rights, or repeated violation of the Acceptable Use Policy.
Following termination, the Customer will have 30 days to export available Customer Data, subject to technical limitations. After this export period, the Company will delete Customer Data from active production systems in accordance with its retention and deletion procedures, subject to legal retention requirements and backup rotation.
The Company retains all rights in its software, platform architecture, APIs, databases and system architecture, generic models, prompts and system logic, documentation, branding, and platform-generated technical metadata. The Customer retains all rights in its own Customer Content. No provision of these Terms transfers ownership of any content merely because it is processed or displayed through the Services.
Each party will protect the other's confidential information using reasonable measures. Confidentiality obligations survive termination for an appropriate period, with trade secret information protected for as long as it remains legally confidential.
The Company seeks protection against claims arising from the Customer's unlawful content, the Customer's lack of rights to its website content, the Customer's unauthorised instructions, or the Customer's misuse of the Services. [Final indemnity structure and wording to be settled by counsel, including review against indemnities available from upstream AI vendors.]
Subject to final review by counsel, the Company's proposed aggregate general liability cap is the fees paid or payable by the Customer in the 12 months preceding the event giving rise to liability, with separate treatment for liabilities that cannot lawfully be limited and possible higher caps for confidentiality, data protection, security, IP and indemnity liabilities. Nothing in these Terms seeks to exclude liability that cannot lawfully be excluded.
The Company intends to maintain insurance appropriate to the nature and scale of the Services, including cyber liability, technology/professional indemnity, and public liability cover as commercially appropriate. Contractual insurance commitments will not exceed the Company's actual policies.
Subject to any mandatory applicable law, these Terms and any dispute arising from them are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, subject to any mandatory rights of another jurisdiction.
These Terms, together with the incorporated Data Processing Agreement, Privacy Notice, Acceptable Use Policy, Sub-Processor List, Security Schedule, and AI and Safety Disclosure, constitute the entire agreement between the parties in respect of the Services for self-service customers. [Standard variation, assignment, severability, and notices clauses to be finalised by counsel.]