← Back to Home

Taskora Customer Agreement

This Taskora Customer Agreement (this "Agreement") is between Taskora, Inc., a Delaware corporation ("Company," "Taskora," "we," or "us"), and the customer entity identified in an Order Form or accepting these terms ("Customer," "you"). This Agreement governs Customer's access to and use of Taskora's software, platform, and services (the "Services").

Acceptance. This Agreement takes effect on the earlier of (a) Customer's acceptance by clicking "I agree" (or a similar control) at signup or in-product (the "Click-Through" or "self-serve" method), or (b) Customer's or Company's signature on an Order Form that references this Agreement (the "Order Form" method). By accepting, the individual represents they are authorized to bind Customer. If you do not agree, do not access or use the Services.

Structure. This Agreement governs all Customers. Most Taskora customers use Agent Services — autonomous AI agents that act in the systems you connect — so these terms are written around that product. Provisions that apply only to Agent Services are identified by their subject matter (Agents, Agent Actions, Customer Credentials, Playbooks, and the like); Section 20 explains how the Agreement applies to a Customer that uses only the Compliance Assistant. Your Order Form (or, for self-serve, the in-product checkout and plan selection) sets pricing and the commercial terms. The Privacy Policy at gettaskora.com/terms/privacy-policy and the Acceptable Use Policy at gettaskora.com/terms/aup are incorporated by reference. If terms conflict, Section 21.2 controls.

1. Definitions

1.1 "Authorized User" means anyone Customer authorizes to access or use the Services on its behalf. Customer is responsible for their use.

1.2 "Customer Data" means all data, information, and materials submitted to or processed by the Services on behalf of Customer, excluding SOP Content and de-identified or aggregated data.

1.3 "SOP Content" means Customer's standard operating procedures, compliance rules, checklists, playbooks, templates, and related documentation (a) provided or made available to Company by or on behalf of Customer, or (b) generated by an Agent in the course of performing work on Customer's behalf ("Agent-Generated SOP Content"). For the avoidance of doubt, Agent-Generated SOP Content (including Playbooks) is SOP Content and receives the full protections of Section 11.

1.4 "Aggregated Learnings" means generic, de-identified insights Company derives from use of the Services (such as common workflow patterns, failure modes, and factual information about how third-party platforms operate) and uses only to operate, analyze, build, and improve the Services, as set out in Section 10.5(b). Aggregated Learnings never include, reveal, or are traceable to any Customer's SOP Content, credentials, data, communications, or personal information. Factual information about how a third-party platform's own interface operates is not any Customer's Proprietary Information. The operative restrictions on Aggregated Learnings, and Customer's right to opt out, are set out in Section 10.5(b).

1.5 "Software" means Company's proprietary software applications and platforms, including any updates, upgrades, or new versions.

1.6 "Order Form" means the ordering document (or, for self-serve customers, the in-product checkout and plan selection record) that specifies the Services purchased, the applicable Usage Unit and Fees, the Term, and any service-level tier.

1.7 "Usage Unit" means a unit of metered usage specified in the applicable Order Form. The Services are metered on two units: Completed Tasks (Section 1.8) and AI compute (the AI model and inference usage required to perform Customer's work). Pricing, included or committed amounts, rates, and caps for each Usage Unit are specified in the Order Form.

1.8 "Completed Task" means the unit by which task usage is metered: (a) for Agent Services, each successful Agent run of a Playbook or task — a looping Playbook records one Completed Task per pass, and a bulk or single-execution action is one Completed Task; and (b) for the Compliance Assistant, the first successful run of a compliance Task on a unique record (re-runs or retries on the same record are not additional Completed Tasks). Unsuccessful runs are not billed.

1.9 "Intellectual Property Rights" means all patents, trademarks, copyrights, trade secrets, and other intellectual property rights worldwide, whether registered or unregistered.

1.10 "Fees" means all fees payable by Customer under an Order Form — including per-Agent subscription fees, usage charges (Completed Tasks and AI compute), any minimum commitment, and Professional Services fees — but excluding taxes (Section 14.3).

1.11 "Agent" — an autonomous AI software process provisioned by Company that performs work on Customer's behalf, including multi-step workflows, browser automation, data extraction, and communications.

1.12 "Agent Action" — any action performed by an Agent (navigating platforms, submitting forms, extracting data, sending communications, creating or modifying records, executing scheduled tasks).

1.13 "Agent Session" — a discrete period of Agent execution from task initiation through completion.

1.14 "Customer Credentials" — login credentials, API keys, access tokens, or other authentication materials Customer provides for Agents to access third-party platforms on Customer's behalf.

1.15 "Permitted Actions" — Agent Actions directed or authorized by Customer by (a) assigning a task via a supported channel, (b) approving and publishing a Playbook, or (c) configuring scheduled tasks; including incidental navigation actions necessary to fulfill an assignment. Providing Customer Credentials enables access but does not by itself authorize all possible actions.

1.16 "Playbook" — a structured workflow document authored by an Agent that codifies a repeatable process. Playbooks are Agent-Generated SOP Content (Section 1.3) and receive Section 11.2 protections.

1.17 "Third-Party Platform" — any third-party platform, application, or service the Services integrate with or depend on, or that Customer connects to through the Services, including any system an Agent accesses using Customer Credentials (see Section 9).

1.18 "Self-Serve Plan" means a plan Customer subscribes to through online checkout or in-product acceptance (the Click-Through method) rather than by signing an Order Form. For a Self-Serve Plan, the in-product checkout and plan-selection record is the Customer's Order Form (Section 1.6), and the Customer accepts this Agreement by the Click-Through method and is a "Click-Through Customer" (Section 21.9(b)).

1.19 "Effective Date" means the date of last signature on an Order Form or, for a Self-Serve Plan, the date of Customer's Click-Through acceptance.

2. Access & License

2.1 License. Subject to Customer's compliance with this Agreement and payment of Fees, Company grants Customer a non-exclusive, non-transferable, limited right to access and use the Services for Customer's internal business purposes during the Term.

2.2 Restrictions. Customer will not, and will not permit any Authorized User or third party to: (a) reverse engineer, decompile, or attempt to derive the source code or underlying structure of the Services; (b) modify, translate, or create derivative works of the Services except as expressly permitted; (c) use the Services for timesharing, service-bureau, or other third-party benefit; (d) rent, lease, lend, sell, sublicense, or distribute the Services; (e) remove proprietary notices; (f) use the Services for competitive analysis or to build a competing product; or (g) use the Services in violation of any law or the Acceptable Use Policy. Customer is responsible for all acts and omissions of its Authorized Users.

2.3 Customer Responsibilities. Customer is responsible for obtaining and maintaining the equipment, connectivity, and account security (including passwords and administrative credentials) needed to use the Services, and for all use of its account, with or without its knowledge.

3. Services, Support & Service Levels

3.1 Subject to this Agreement, Company will use commercially reasonable efforts to provide the Services described in the applicable Order Form.

3.2 Service Availability. Company will use commercially reasonable efforts to keep the Services available and operational. A committed 99.5% monthly availability target applies only where the applicable Order Form provides it (for example, the Fleet plan); on other plans the Services are provided on a commercially-reasonable-efforts basis with no committed uptime percentage. Any committed target excludes scheduled maintenance and Force Majeure Events, and — for Agent Services — also excludes outages or rate-limiting of Third-Party Platforms or sub-processor services; it concerns infrastructure availability (whether the Agent environment is operational), not agent performance (whether any given Agent Action succeeds, which depends on Third-Party Platforms and model behavior outside Company's control). Service credits, if any, are as set in the Order Form.

3.3 Support. Company provides support for the Services on a commercially-reasonable-efforts basis. A contractual support commitment — including a named account manager and a severity-based response-time service level — applies only where the applicable Order Form provides it (for example, the Fleet plan), as set out in the applicable Support & SLA Exhibit. Any such commitment covers response times only (a first human response within the stated time), not resolution times, during the business hours stated in the Exhibit. For plans without a contractual support commitment, Company aims to respond within its internal targets but does not commit to a specific response time. Service credits, if any, attach only to the availability commitment in Section 3.2, not to support response times.

3.4 Remedies. Service credits apply only where the applicable Order Form provides a committed availability target under Section 3.2 (for example, the Fleet plan). Where a committed target applies, Customer's sole and exclusive remedy for Company's failure to meet it is service credits, calculated as a percentage of the monthly equivalent fee, capped at one (1) month's equivalent per contract year, requested in writing within thirty (30) days of the incident. Plans without a committed availability target carry no uptime commitment and no service-credit remedy.

3.5 Professional Services. Company may provide professional services for set-up and tuning as described in an Order Form ("Professional Services"). Prepaid Professional Services hours expire at the end of the Term and are non-refundable. Rescheduling or cancellation with less than five (5) business days' notice may be charged.

3.6 Pilot Subscriptions. An Order Form may designate a "Pilot Subscription" — a limited-term evaluation engagement that does not auto-renew and concludes at the end of the Pilot Term unless the parties execute a subsequent Order Form. Commercial specifics (duration, fees, included usage) are set in the Order Form. To continue after the Pilot Term, Customer executes a new Order Form, which is governed by the version of this Agreement then in effect (Section 21.12). Usage during the Pilot Term does not count toward any usage commitment or Completed Task bands under a later subscription.

4. Acceptable Use

Customer will use the Services only in compliance with the Acceptable Use Policy (incorporated by reference, and which Company may update by posting), all applicable laws, and Company's published policies then in effect. Customer is solely responsible for ensuring that its use of the Services — including all Agent Actions and all access to Third-Party Platforms — is lawful, authorized, and consistent with the terms of any third party whose systems it directs the Services to access. Company may suspend, limit, or terminate access that it reasonably believes violates this Section, the Acceptable Use Policy, or applicable law, or that games a free trial or usage allowance; where practicable Company will provide notice and an opportunity to cure, except in cases of imminent risk to security, third parties, or the Services. Company may require each Authorized User to accept the Acceptable Use Policy (or to acknowledge that their use of the Services is governed by this Agreement and the Acceptable Use Policy) as a condition of access; such acceptance by an Authorized User does not change the version of this Agreement governing an Order Form Customer under Section 21.12.

5. Agent Authorization & Customer Responsibilities

This Section applies to Customers that subscribe to Agent Services.

5.1 Credential Authorization. Customer represents and warrants it has authority to provide Customer Credentials (see Section 5.2 for the related third-party-platform authorization warranty).

5.2 Third-Party Platform Compliance. Customer is solely responsible for ensuring that Agent access to third-party platforms is permitted under Customer's agreements with those platforms, and represents and warrants that it is permitted under each such platform's own terms to authorize automated, agent-driven access on its behalf (cross-referencing Section 9.3). Upon request, Company will provide technical documentation describing the nature and scope of Agent access (including browser automation and session recording) to help Customer evaluate compliance. Company is not liable for any violation of third-party terms of service resulting from Agent Actions performed using Customer Credentials, and Customer's indemnity in Section 17.2(c) applies.

5.3 Authorized Users & Scope of Authority. Customer is responsible for managing access and for all Agent Actions resulting from its task assignments, published Playbooks, and configured schedules. By directing an Agent, Customer represents it has all rights and permissions necessary for the Agent to perform the directed actions.

5.4 Playbook Review. Playbooks require human review and approval before publication; the platform requires explicit user action to publish. Customer is solely responsible for reviewing and approving Playbook content for operational use.

5.5 How Customer Authorizes Agent Actions. Customer authorizes Agent Actions by directing the Agent — including by instructing or assigning a task through a supported channel (whether or not a Playbook exists), approving and publishing a Playbook under Section 5.4, or configuring a scheduled task (Section 1.15). Agents may act on Customer's interactive instructions before any Playbook is drafted or published; publishing a Playbook is one way to authorize a repeatable process, not a precondition to Agent Action. Company may offer optional controls to require additional human approval for specified steps; Customer configures those and remains solely responsible for all Agent Actions regardless of configuration.

5.6 Emergency Suspension. Either party may immediately suspend Agent Services on written notice if an Agent Action poses an imminent risk of material harm, with reason provided within twenty-four (24) hours. Company provides a dashboard control to halt all active Agent Sessions.

5.7 Per-Connection Reaffirmation. Each time Customer connects a set of Customer Credentials for a system, Customer reaffirms, with respect to that system, the representations and warranties in Sections 9.3 and 5.2 — including that Customer is permitted under that system's own terms to authorize automated, agent-driven access on its behalf. These reaffirmations are presented at the point of connection (and again if the credentials or the Agent's scope of action on that system materially change) and are recorded. Company does not identify, review, vet, or monitor the systems Customer connects or their terms of use. Customer is solely responsible for determining whether a given system permits automated, agent-driven access and for not connecting any system that prohibits it.

5.8 Customer Authorization; Prohibited Systems; Right to Decline.

(a) Authorization to Act on Customer's Behalf. Customer grants Company permission and authority to access the systems Customer connects, using Customer Credentials, and to perform the Agent Actions Customer directs, on Customer's behalf and at Customer's direction. As between the parties, such Agent Actions are Customer's actions, taken using Customer's own access rights. This authorization is a grant of permission to operate the Services at Customer's direction; it does not make Company Customer's agent, fiduciary, or representative (see Section 21.3).

(b) Covenant. Customer will not direct or configure an Agent to access any system that prohibits automated or agent-driven access under that system's terms.

(c) Right to Decline. Company may, without liability, suspend or decline Agent access to any system if it receives notice from or on behalf of the system's operator, or otherwise reasonably believes such access is not permitted. Company is not obligated to monitor for, or investigate, the terms of the systems Customer connects.

(d) Restricted Systems. Company may, in its discretion and without liability, designate any system or category of systems as unavailable for Agent access — for example, systems that prohibit automated access or that Company elects not to support — and may block, suspend, or decline Agent access to them. Company is not obligated to support any particular system, and may maintain and update a list of unavailable systems.

6. Autonomous Action; Oversight; Adversarial Content

This Section applies to Customers that subscribe to Agent Services.

6.1 Supplementing Section 15, Customer acknowledges Agent Actions are performed autonomously without real-time human supervision and may produce incomplete, inaccurate, or unintended results. Company does not guarantee the accuracy, completeness, or reliability of any Agent Action.

6.2 Human Oversight. Customer is responsible for periodically reviewing Agent outputs and activity logs, approving Playbooks before recurring use, and intervening when Agent Actions do not meet its requirements. Company provides observability tools (activity feeds, session replay, real-time status).

6.3 Internet, Email, and Messaging Access. To perform Customer's tasks, Agents may browse and search the public internet (for example, to locate documentation or reference information) and will navigate to the destinations Customer's instructions require. Agents access the systems Customer connects using the Customer Credentials Customer provides. Agents do not have access to Customer's email, messaging (such as Slack or Teams), or SMS accounts, and will not send or receive communications through any such channel unless Customer connects and configures it. On some plans, Company may provide controls that let Customer limit the domains an Agent may access. Customer is responsible for the instructions it gives and the destinations it directs Agents to, and assumes responsibility for the consequences of the access it enables.

6.4 Adversarial Content. Agent behavior can be influenced by adversarial content (e.g., prompt injection) encountered during a Session. Company will implement commercially reasonable safeguards to mitigate this risk but does not guarantee all such manipulation will be detected or prevented. Customer acknowledges this residual risk. If Company becomes aware of an exploited vulnerability affecting Customer, it will promptly notify Customer and cooperate to mitigate.

6.5 Limitation. Company is liable for damages arising from Permitted Actions only if (a) a bug in the Agent Services platform makes an Agent do something Customer did not direct — for example, sending to the wrong recipient, acting on the wrong record, or duplicating an execution — or (b) the damages arise from Company's gross negligence or willful misconduct. Company is not liable when an Agent correctly does what Customer configured, when a limitation is inherent to AI output (Section 15.2), or when a Third-Party Platform causes the problem. Where Company is liable under clause (a), Customer's sole and exclusive remedy is re-performance of the affected Agent Services and a refund of fees for the affected Agent Sessions, and this remedy controls over the general warranty remedy in Section 15.1. Section 16 applies to all claims under this Agreement, including the rule that its caps survive even if a remedy fails its essential purpose.

6.6 No Assumption of Responsibility. The approval controls, observability tools, rate limits, and other safeguards Company provides help Customer oversee Agent Actions, but they do not make Company responsible for the permissibility, accuracy, legality, or consequences of any Agent Action, which remain Customer's responsibility. Agents act solely as a tool executing Customer's instructions on systems Customer selects and connects (see Section 21.3).

7. Session Recording & Observability

This Section applies to Customers that subscribe to Agent Services.

7.1 Agent Sessions involving browser automation are recorded (navigation, clicks, form interactions, page content). Recordings containing Customer Data or personal information are treated as Customer Data.

7.2 Retention & Early Deletion. Recordings are kept thirty (30) days by default (or the period stated in the applicable Order Form or plan), then deleted. Customer may request earlier deletion of specific recordings, which Company will honor within a reasonable time, unless it must retain them to comply with law. Recordings are included in the data export under Section 10.4.

7.3 Consent. Customer consents to recording for audit, support, debugging, and security, and is solely responsible for obtaining any consent required from third parties whose platforms are accessed and recorded.

8. Communications Compliance

This Section applies to Customers that subscribe to Agent Services.

Where an Agent sends a communication, it is transmitted from the Customer's own connected account or system, at the Customer's direction; Company's infrastructure does not send external commercial email or messages on its own behalf. Customer is solely responsible for ensuring that the content, recipients, and timing of communications sent by Agents on its behalf comply with applicable laws (including CAN-SPAM, TCPA if SMS is used, and applicable AI-transparency / bot-disclosure laws), including obtaining any required consents, providing any required sender identification and disclosures (including any required disclosure that a communication is sent by an automated agent), and honoring opt-outs. Any operational safeguards Company may make available (such as rate limiting or loop protection) are provided on an as-available basis, do not make Company the sender of, or responsible for the legal compliance of, any communication, and do not relieve Customer of responsibility for the volume, cadence, recipients, and content of the communications it directs.

9. Third-Party Platforms

9.1 The Services may integrate with or depend on Third-Party Platforms. Company does not control and is not responsible for the availability, functionality, security, or changes to any Third-Party Platform, and disclaims all liability arising from them. Customer's use of a Third-Party Platform is governed by that platform's own terms.

9.2 Customer Determines and Bears the Risk of Third-Party Access. Customer determines which Third-Party Platforms are accessed and connected to through the Services, and bears the entire risk of such use. Customer represents and warrants that it has all rights, authorizations, and permissions necessary to connect the Services to, and to submit or process data through, any Third-Party Platform it directs the Services to access, and that such use complies with all terms and conditions of the applicable third-party provider. Customer is solely responsible for the legality of its use of the Services and of the data and systems it accesses. Company does not control or own any Third-Party Platform.

9.3 Agent Automation Authorization. (Applies to Agent Services; see also Section 5.) Where an Agent accesses a Third-Party Platform using Customer Credentials, Customer represents and warrants that it is permitted under that Third-Party Platform's own terms to authorize automated, agent-driven access on its behalf, and that such access will not violate the platform's terms, anti-bot or unauthorized-access rules, or applicable law. Customer is solely responsible for compliance with Third-Party Platform terms and for the consequences of Agent Actions taken using Customer Credentials. Customer makes this representation on a per-connection basis as described in Section 5.7.

10. Customer Data, Privacy & CCPA

10.1 Ownership. Customer owns all right, title, and interest in Customer Data and SOP Content (including Agent-Generated SOP Content). As between the parties, Customer owns all outputs and results the Services generate for Customer (including the outputs of Agent Actions), subject to Company's rights in the Services and Software.

10.2 Privacy. Company's handling of personal information is described in the Privacy Policy. The Services are offered in the United States; Company processes personal information in accordance with applicable U.S. law.

10.3 CCPA Service-Provider Terms. With respect to personal information (as defined by the California Consumer Privacy Act, as amended, "CCPA") that Company processes on Customer's behalf, Company is a "service provider." Company shall not: (a) sell or share such personal information; (b) retain, use, or disclose it except to perform the Services and as permitted by CCPA; or (c) combine it with personal information from other sources except as CCPA permits. Company will: enumerate the categories of personal information and business purposes for processing (as further described in the Privacy Policy); retain personal information only as long as needed to provide the Services and per the stated retention schedule; require its sub-processors to provide the same level of CCPA protection; notify Customer if it determines it can no longer meet these obligations; reasonably assist Customer in responding to verifiable consumer requests; once a year, with reasonable notice, permit Customer to take reasonable steps to confirm Company is meeting these privacy commitments; and upon Customer's notice of unauthorized use of personal information, take reasonable and appropriate steps to stop and remediate such use. The specific business purposes for which Company processes personal information are identified in the Privacy Policy and the applicable Order Form. Company certifies it understands and will comply with these restrictions.

10.4 Data Export & Deletion. Upon termination, Company will, on Customer's request made within thirty (30) days, provide Customer Data, SOP Content, and (for Agent Services) Agent conversation history and session recordings in a commercially reasonable, machine-readable format; thereafter Company may delete it in accordance with its standard retention practices and applicable law. This Section does not limit Company's service-provider obligations under Section 10.3 or Customer's ownership of SOP Content under Section 10.1.

10.5 De-Identified Data & Aggregated Learnings.

10.5(a) Telemetry. Company may collect and use de-identified, aggregated operational and security telemetry (e.g., performance metrics, error rates, system logs) to operate, secure, and improve the Services, provided such data cannot reasonably be used to reconstruct or identify any SOP Content, Customer, or individual. This subsection does not permit Company to use the content of Customer Data, session recordings, or Agent conversations to train or improve AI models; use of such content in identifiable form is governed by Sections 11.2, 11.4, and 11.5, and Company's separate right to derive de-identified Aggregated Learnings is set out in Section 10.5(b).

10.5(b) Aggregated Learnings. Company may create and use Aggregated Learnings to operate, analyze, build, and improve the Services — including to develop and improve Company's models, features, and automation, and to improve generic starter templates and the generic robustness of Company's technology — and for no other purpose. Company will not disclose Aggregated Learnings in any form that could reasonably identify Customer, its Authorized Users, or any individual. Company may derive Aggregated Learnings from Customer's use of the Services, but only in de-identified, aggregated form that neither identifies nor is traceable to any single Customer and that does not reveal the substance of any Customer's SOP Content, Customer Data, session-recording or Agent conversation content, Customer Credentials, or personal information; that content, in identifiable form, remains governed by Sections 11.2, 11.4, and 11.5. Company will not create any Aggregated Learning that is substantially derived from, or traceable to, any single Customer. Customer may opt out of contributing its usage to Aggregated Learnings at any time by contacting Company or via an in-product control (or as set out in the Order Form). If Customer opts out, Company will not use Customer's usage to derive Aggregated Learnings, and Customer will not receive the benefit of enhancements derived from other customers' Aggregated Learnings (Customer continues to receive the Services at the then-current baseline). Opting out does not affect subsection 10.5(a).

10.5(c) De-Identification Standard. With respect to de-identified data and Aggregated Learnings, Company will: (i) take reasonable measures to prevent the data from being used to infer information about, or be linked to, a particular natural person or household; (ii) maintain and use the data only in de-identified form and not attempt to re-identify it, except solely to test the de-identification process; and (iii) contractually obligate any recipient or sub-processor to comply with the same requirements.

11. Intellectual Property; SOP, Playbook & Credential Protections

11.1 Company IP. Company owns and retains all right, title, and interest in the Services, Software, all improvements, and all related Intellectual Property Rights. No rights are granted except as expressly stated. Customer's access is licensed, not sold.

11.2 SOP Content Protections. Company keeps your SOP Content, session recordings, and Agent conversations confidential and logically isolated to your account. Company will not: (a) disclose them to any other customer; (b) use them in the prompts, context, or retrieval served to any other customer; or (c) use them, in any form that identifies you or reveals their substance, to build, train, or fine-tune any model or feature made available to any other customer. Company sends this content to its AI providers only under terms that do not permit those providers to train their models on it. These protections apply equally to Agent-Generated SOP Content (including Playbooks). Nothing in this Section restricts Company's creation and use of de-identified Aggregated Learnings under Section 10.5(b), which do not identify you or reveal the substance of your SOP Content or other content.

11.3 Feedback. If Customer sends Company suggestions about the Services, Company may use them freely to improve the Services.

11.4 Playbook Protections. (Agent Services.) Playbooks and other Agent-Generated SOP Content are SOP Content and receive the Section 11.2 protections in full, subject only to Company's use of de-identified Aggregated Learnings under Section 10.5(b). Customer retains all right, title, and interest in Playbook content.

11.5 Credential Security. (Agent Services.) Company encrypts Customer Credentials at rest and decrypts them only server-side, inside Customer's isolated, per-Customer execution environment, solely to log into the systems Customer connects. During operation an Agent may read a credential value within that isolated environment only to authenticate on Customer's behalf. Credentials are not shared with other customers, not written to logs, and not stored as text in AI model prompts or conversation history; MFA/one-time-passcode seeds are handled separately and fetched on demand. (Company's current technical security measures are described in the security summary referenced in Section 13.6.) Customer may delete Customer Credentials at any time through the dashboard. If Company ceases operations, winds down, or makes a general assignment for the benefit of creditors, it will promptly delete or return Customer Credentials and destroy the associated encryption keys.

12. Confidentiality

Each party will keep the other's non-public information ("Proprietary Information") confidential, protect it with reasonable care, and use it only to perform under this Agreement. This does not cover information that is public, already known, independently developed, or received without restriction, or disclosure required by law. These duties last five (5) years, and for trade secrets and SOP Content, as long as the law protects them.

13. Infrastructure, Security & Breach Notification

13.1 (Agent Services.) Company provides access to Agent Services enabling Agents to perform multi-step workflows autonomously, communicating via supported channels and producing Playbooks.

13.2 Tenant Isolation. (Agent Services.) Company logically isolates each Customer's Agent data, conversation history, Customer Credentials, and Playbooks from other customers' data, using technical and organizational access controls designed to prevent cross-tenant access.

Sections 13.4–13.6 apply to all Customers; where they reference Customer Credentials, that reference applies only to Customers that subscribe to Agent Services.

13.3 Sub-Processors. Company uses third-party service providers (sub-processors) to help provide the Services. The categories of sub-processors and the purposes for which they process data are described in the Privacy Policy, and Company will provide its current list of sub-processors to Customer on request. Company requires its sub-processors, by contract, to provide CCPA service-provider protections consistent with Section 10.3 and to protect Customer Data and Customer Credentials, and Company remains responsible for its sub-processors' performance of the obligations Company delegates to them.

13.4 Security Measures. Company will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Data and Customer Credentials.

13.5 Breach Notification. Company will notify Customer without undue delay, and within seventy-two (72) hours, after discovering unauthorized access to or acquisition of Customer Data or Customer Credentials, describing the nature of the incident, the data affected, measures taken, and a contact point, and will reasonably cooperate in Customer's investigation and mitigation. Each party remains responsible for its own obligations under applicable U.S. state and federal breach-notification laws.

13.6 Security Documentation. On reasonable prior written request, and no more than once per twelve (12) months, Company will provide Customer with its then-current summary of security measures (and any third-party security assessments or attestations if and when Company obtains them). Formal third-party attestation (e.g., SOC 2) is on Company's roadmap and not currently available.

14. Fees & Payment

14.1 Fees and metering. Customer will pay the Fees set forth in the applicable Order Form or plan. Fees may include: (a) subscription fees (for example, a per-Agent monthly or annual fee); (b) usage fees, metered on Completed Tasks (Section 1.8) and on AI compute (the AI model and inference usage required to perform Customer's work); (c) any minimum commitment for a Term; and (d) Professional Services fees. The rates, included or committed amounts, usage bands, any AI-compute budget, and usage caps are set in the applicable Order Form or plan. AI compute is metered on usage and, except where an Order Form provides for monthly invoicing, is funded from a prepurchased balance that Customer maintains and that may automatically replenish, by the payment method on file, at thresholds Customer controls. Prepurchased and minimum amounts are non-refundable except as expressly stated. Usage caps, allotment resets, rollover, and any behavior when a cap or budget is reached (for example, pause or continue) are as set out in the applicable Order Form or plan.

14.2 Changes to Fees. Company may change Fees or introduce new charges effective at the end of the then-current Term or, for Self-Serve Plans, on prospective billing periods, upon thirty (30) days' notice (which may be by email). For annual Order Forms, renewal pricing for equivalent usage shall not increase by more than the lesser of (a) 10% above the prior term or (b) Company's then-current standard pricing.

14.3 Billing, Taxes & Delinquency. Company may bill by invoice or charge a payment method on file. Customer is responsible for all applicable sales, use, and similar taxes (other than taxes on Company's net income); Company may charge or collect such taxes where it determines it is required to do so. Company may suspend Services for payment more than thirty (30) days delinquent; unpaid amounts accrue a 1.5%/month finance charge (or the legal maximum, if lower). Self-Serve Plans are billed in advance; unused allotments are not refundable. Billing disputes must be raised within sixty (60) days.

15. Warranties & Disclaimers

15.1 Company will use reasonable efforts consistent with industry standards to maintain the Services and will perform Professional Services in a professional and workmanlike manner. For breach of this warranty, Customer's sole and exclusive remedy is, at Company's option, re-performance of the affected Services or a refund of the fees for the affected Services, subject to Section 16. The Services rely on third-party platforms; Company is not responsible for their outages, changes, or discontinuation (see Section 9).

15.2 AI Output Disclaimer. Outputs generated by the Services — including any produced using artificial intelligence or machine-learning models, and any actions or outputs of Agents — are provided for informational and decision-support purposes. Customer remains solely responsible for independently reviewing and validating all outputs and Agent Actions, and for all final business, legal, compliance, and operational decisions. Company does not represent or warrant that any AI-generated output or Agent Action will be accurate, complete, current, or fit for Customer's particular use case or regulatory requirements. The Services do not provide legal, regulatory, or compliance certification.

15.3 EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES AND PROFESSIONAL SERVICES ARE PROVIDED "AS IS," AND COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE.

16. Limitation of Liability

(a) General cap. Except as stated below, and except for bodily injury, EACH PARTY'S TOTAL LIABILITY UNDER ANY THEORY IS LIMITED TO THE FEES PAID OR PAYABLE BY CUSTOMER TO COMPANY FOR THE SERVICES IN THE 12 MONTHS BEFORE THE ACT GIVING RISE TO THE LIABILITY. This cap also protects Company's suppliers, officers, affiliates, and employees.

(b) Excluded and indirect damages. Neither party is liable for indirect, exemplary, incidental, special, or consequential damages (including lost profits), for error or interruption of use, loss or corruption of data, cost of substitute goods or services, or loss of business, or for any matter beyond its reasonable control. However, reasonable costs of breach notification, forensic investigation, credit monitoring, and regulatory response arising from a security or credential breach are recoverable as direct damages, up to the applicable cap.

(c) Higher cap for security and credential breaches. For a party's breach of its confidentiality or data-security obligations (including Company's obligations to safeguard Customer Credentials and Customer Data), the data-loss exclusion in (b) does not apply, and the cap in (a) is replaced by a cap equal to the greater of (x) $50,000 or (y) two times the Fees paid or payable by Customer to Company for the Services in the 12 months before the act giving rise to the liability.

(d) Minimum you can recover (self-serve). For a Click-Through Customer (Section 21.9(b)), the cap in (a) will not be less than five thousand dollars ($5,000), so the remedies in this Agreement are not illusory.

(e) Caps survive essential-purpose failure. If any exclusive or limited remedy in this Agreement is held to fail of its essential purpose, the remaining limitations and the caps in this Section 16 continue to apply and govern the parties' liability.

(f) Carve-outs; maximum liability. The cap in (a) and the exclusion in (b) do not apply to, and the following remain uncapped: (i) Customer's indemnification obligations under Section 17.2; (ii) either party's liability for bodily injury or death; and (iii) either party's fraud. For every other claim — including a party's gross negligence or willful misconduct and Company's indemnification obligations under Section 17.1 — the cap in Section 16(c) is each party's maximum aggregate liability under this Agreement, except to the extent a limitation of liability is unenforceable under applicable law.

17. Indemnification

17.1 By Company. Company will defend Customer against third-party claims that the Services, as provided by Company, infringe a U.S. patent, copyright, or trademark or misappropriate a trade secret, and will pay resulting damages finally awarded, provided Customer promptly notifies Company and gives it sole control of defense and settlement. This does not apply to claims arising from: components not supplied by Company; Customer specifications; modifications after delivery; combination with non-Company materials; continued use after notice; or use not in accordance with this Agreement. If the Services become, or in Company's reasonable opinion are likely to become, the subject of an infringement claim, Company may, at its option and expense, (i) procure for Customer the right to continue using the Services, (ii) modify or replace the Services to make them non-infringing while preserving materially equivalent functionality, or (iii) if neither (i) nor (ii) is commercially reasonable, terminate the affected Services and refund prepaid, unused fees. These options are in addition to, and do not limit, Company's obligations under this Section 17.1 to defend the claim and to pay damages finally awarded or amounts in settlement.

17.2 By Customer. Customer will defend and indemnify Company against third-party claims, damages, and expenses (including reasonable attorneys' fees) arising from: (a) Customer Data, or Customer's use of the Services in violation of this Agreement, the Acceptable Use Policy, or applicable law; (b) Customer's breach of its representations and warranties, including the authorization warranties in Sections 9.3 and 5.2; and (c) for customers using Agent Services, any claim by a third-party platform operator or other third party arising from Agent Actions performed using Customer Credentials or from Customer's authorization of automated access to a third-party platform — including claims under the platform's terms of service, anti-bot or unauthorized-access rules, or computer-fraud statutes — Customer acknowledging that it determines which platforms are accessed and bears the entire risk of such access (Section 9.2). Customer's obligations under this Section 17.2 do not apply to the extent a claim is finally determined by a court or arbitrator of competent jurisdiction to arise from Company's gross negligence or willful misconduct; until such final determination, Customer's defense and indemnity obligations continue, and if Company is so determined to have acted with gross negligence or willful misconduct, Company will reimburse Customer for defense costs and indemnified amounts fairly allocable to that conduct. Because Customer determines which platforms are accessed and bears that risk under Section 9.2, this indemnity applies even where Company's ordinary negligence is alleged to have contributed to the claim; only Company's gross negligence or willful misconduct (as finally determined) reduces it. If the extension of this indemnity to Company's ordinary negligence is held unenforceable, it is severed and the remainder of this Section 17.2 — including Customer's indemnity for third-party-platform and computer-fraud claims arising from Customer-authorized access — remains in effect.

17.3 The party being indemnified must promptly notify the other and reasonably cooperate. The indemnifying party controls the defense but may not settle in a way that admits the other party's fault, imposes obligations on it, or fails to release it, without that party's consent. The indemnitee may join with its own counsel at its own expense. This does not change Company's sole control of infringement claims under Section 17.1.

17.4 Agent Indemnification. (Agent Services.) This Section 17 applies to Agent Services, including Customer's indemnity for third-party-platform / terms-of-service / computer-fraud claims arising from Agent Actions performed using Customer Credentials (Section 17.2(c)). Company's only indemnity obligation is for IP-infringement claims under Section 17.1; Company's liability for its own gross negligence or willful misconduct is governed by Sections 6.5 and 16.

18. Term & Termination

18.1 Term. This Agreement runs for the Initial Term in the Order Form and auto-renews for successive one-year Renewal Terms unless either party gives thirty (30) days' notice of non-renewal. Self-Serve Plans renew per the billing cadence selected at checkout and may be canceled per the in-product flow. For Self-Serve Plans, auto-renewal disclosures, any required consent, renewal reminders, and a same-channel online cancellation mechanism are provided at checkout and in-account in accordance with applicable automatic-renewal laws. Pilot Subscriptions do not auto-renew.

18.2 Termination for Cause. Either party may terminate on thirty (30) days' notice (or without notice for nonpayment) for an uncured material breach (thirty (30) days to cure), or immediately if the other party becomes insolvent, ceases business operations, or makes a general assignment for the benefit of creditors. If Customer terminates for Company's uncured material breach, Company refunds prepaid, unused fees pro rata.

18.3 Effect; Survival. On termination, Customer pays for Services through the last day provided, and Section 10.4 (export/deletion) applies. Sections that by nature survive — including accrued payment, confidentiality, SOP Content protections (11.2), CCPA service-provider terms (10.3), de-identified-data and Aggregated-Learnings restrictions (10.5), warranty disclaimers (15.2, 15.3), limitation of liability (16), indemnification (17), third-party-platform risk allocation (9) and the related authorization warranties, security and breach-notification obligations (13.4–13.6), and governing law, jurisdiction and venue (21.9) — survive termination.

18.4 Agent-Specific Survival. (Agent Services.) In addition, Sections 5 (Agent Authorization & Customer Responsibilities), 6 (Autonomous Action; Oversight; Adversarial Content), 7 (Session Recording & Observability), 8 (Communications Compliance), and 11.4–11.5 (Playbook & Credential Protections) survive termination, along with any other provision that by its nature should survive.

19. Force Majeure

19.1 Neither party is liable for any failure or delay (other than payment obligations) caused by events beyond its reasonable control, including acts of God, natural disasters, epidemics, war, civil unrest, governmental action, labor disputes, failures of internet/cloud/telecom/utilities, cyber-attacks, or outages or changes in Third-Party Platforms (each, a "Force Majeure Event"). Customer's payment obligations are not excused. The affected party will mitigate and resume performance as soon as practicable. If a Force Majeure Event continues more than thirty (30) consecutive days, either party may terminate the affected Services on written notice, and Company will refund any prepaid, unused fees for the terminated Services on a pro-rata basis. (Agent-specific clarification at Section 19.2.)

19.2 Agent Force Majeure Clarification. (Agent Services.) For the avoidance of doubt, partial or incomplete Agent Actions resulting from a Force Majeure Event (Section 19.1) — for example, where an Agent completes some but not all scheduled actions during an infrastructure or sub-processor outage — do not constitute a defect in the Agent Services platform under Section 6.5(a). Company will use commercially reasonable efforts to identify and notify Customer of Agent Sessions interrupted by a Force Majeure Event.

20. Compliance Assistant

20.1 The Compliance Assistant. The Compliance Assistant is Taskora's compliance-review product — for example, reviewing work orders, invoices, or similar records against Customer's rules. For the Compliance Assistant, Completed Tasks are counted as described in Section 1.8(b).

20.2 Application to Compliance-Only Customers. Provisions of this Agreement that by their terms govern Agent Services, Agents, Agent Actions, Agent Sessions, Customer Credentials, or Playbooks apply only to Customers that subscribe to Agent Services. A Customer that uses only the Compliance Assistant, and does not subscribe to Agent Services, is not subject to those provisions; all other provisions of this Agreement apply to it. For clarity, a Compliance-Assistant-only Customer remains protected by the general provisions of this Agreement, including Customer Data ownership and privacy (Section 10) and security and breach notification (Sections 13.4–13.6).

20.3 Compliance Assistant Data. When Customer uses the Compliance Assistant, its browser extension observes record data on the platforms that the Authorized User elects to review and transmits that data to Company only on a user-initiated action, to perform the compliance review. Such record data is Customer Data (Section 1.2) and is handled under Sections 10 (Customer Data, Privacy & CCPA) and 13.4–13.6 (security and breach notification); Customer may request deletion of specific captured records, which Company will honor within a reasonable time unless it must retain them to comply with law. Customer authorizes Company and the extension to observe and transmit that record data for compliance review, and represents it is permitted to do so under the applicable platform's terms (Section 9.2). Customer's uploaded or configured compliance rules are SOP Content (Section 1.3) and receive the Section 11.2 protections.

21. Miscellaneous; Dispute Resolution

21.1 Entire Agreement & Supersession. This Agreement, together with the applicable Order Form and incorporated policies, is the entire agreement and supersedes, for new and renewing customers, the prior Taskora Master Services Agreement, End User License Agreement, and Agent Services Pilot Addendum. Customers with an existing signed agreement or Pilot Addendum remain governed by it until they execute a new Order Form or renew, at which point this Agreement applies.

21.2 Order of Precedence. In a conflict, the order is: (1) the Order Form, solely as to commercial terms (fees, dates, scope, usage unit, SLA tier); (2) this Agreement; (3) incorporated policies. An Order Form changes the IP (Section 11), liability (Section 16), or indemnity (Section 17) sections only if it specifically says so and is signed by both parties.

21.3 Relationship of the Parties. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment, agency, or fiduciary relationship; neither party may bind the other.

21.4 No Third-Party Beneficiaries. This Agreement is for the benefit of the parties only. No third party — including any Third-Party Platform operator, data subject, or end user — has any right, claim, or cause of action under this Agreement, except that Company's suppliers, officers, affiliates, and employees are intended third-party beneficiaries of the warranty disclaimers in Section 15 and the limitations in Section 16, solely for purposes of invoking those protections.

21.5 Assignment. Neither party may assign this Agreement without the other's consent, except in a merger or sale of substantially all assets. Any assignee must assume Company's credential-security and confidentiality obligations. Any non-permitted assignment is void, and the Agreement binds the parties' permitted successors.

21.6 Export & Sanctions. Each party will comply with applicable U.S. export-control and economic-sanctions laws (including OFAC). Customer represents it is not, and will not use the Services to act for anyone, on a U.S. restricted-party or sanctioned-party list, and will not direct Agents to perform actions that would violate such laws.

21.7 Electronic Acceptance. Acceptance by clicking "I agree" (or a similar control) and electronic signatures and records are valid and enforceable under the U.S. E-SIGN Act and UETA. Company's records of acceptance (including the version accepted and the time of acceptance) are admissible evidence of this Agreement.

21.8 Notices. Notices must be in writing and are effective when received; email to the address on the Order Form or account is permitted for routine notices. Legal notices to Company go to legal@gettaskora.com.

21.9 Governing Law; Venue; Dispute Resolution. This Agreement is governed by the laws of the State of Delaware, without regard to conflict-of-laws rules.

(a) Order Form Customers — Courts. For Customers that accepted this Agreement by a signed Order Form, any dispute arising out of or relating to this Agreement will be brought exclusively in the state or federal courts located in Delaware, and each party consents to the exclusive jurisdiction and venue of such courts.

(b) Click-Through Customers — Individual Arbitration; Class Waiver. For Customers that accepted this Agreement by click-through or other online acceptance and not by a signed Order Form ("Click-Through Customers"), the following applies instead of subsection (a):

(i) Binding individual arbitration. Any dispute arising out of or relating to this Agreement or the Services will be resolved by final and binding arbitration administered by JAMS under its then-current commercial rules, before a single arbitrator, seated in Delaware (or conducted by videoconference); judgment on the award may be entered in any court of competent jurisdiction. Either party may instead bring an individual claim in small-claims court, and either party may seek injunctive or equitable relief in court to protect its intellectual property or Proprietary Information.

(ii) Class/collective waiver. Disputes will be arbitrated only on an individual basis. Customer and Company each waive any right to bring or participate in a class, collective, consolidated, or representative action. The arbitrator may not consolidate more than one party's claims or preside over any class or representative proceeding. If this waiver is finally held unenforceable as to a particular claim, that claim (and only that claim) will proceed in the Delaware courts under subsection (a). Nothing in this subsection (b) waives any right to seek public injunctive relief in court to the extent such a waiver would be unenforceable under applicable law.

(iii) 30-day opt-out. A Click-Through Customer may reject this subsection (b) by emailing legal@gettaskora.com within thirty (30) days of first accepting this Agreement; rejection leaves subsection (a) as the sole dispute-resolution provision and does not affect the rest of this Agreement.

21.10 General. Severability; no waiver of a right by failure to enforce it; the prevailing party in any action to enforce this Agreement may recover reasonable attorneys' fees (subject to Section 16); headings are for convenience only.

21.11 Beta / Early Access. Features designated as beta, preview, or early access are provided "AS IS," may change or be withdrawn, and carry no warranty or service-level commitment.

21.12 Updates to this Agreement. Company may update this Agreement from time to time.

(a) Order Form Customers. For a Customer that accepted this Agreement by a signed Order Form, the version of this Agreement in effect on that Order Form's Effective Date governs for that Order Form's then-current Term; an updated version applies on renewal (or earlier if the parties agree in writing). Company may, however, apply an update earlier to the extent required by applicable law or where the update does not materially reduce Customer's rights. Any in-product notice or acceptance prompt shown to an Order Form Customer does not change the version of this Agreement governing that Customer during its then-current Term; the version in effect on the Effective Date continues to govern until renewal.

(b) Click-Through Customers. For a Customer that accepted this Agreement by Click-Through, Company may update this Agreement on notice (by email or in-product, which may include a renewed acceptance prompt). The updated version takes effect on its stated effective date, and Customer's continued use of the Services after that date constitutes acceptance; if Customer does not agree, its sole remedy is to stop using and cancel the Services. Company will make material changes available with reasonable advance notice.

Fee changes are governed by Section 14.2.