Terms and Conditions

Effective Date: May 28, 2026

These Terms and Conditions ("Terms") govern your access to and use of the PAF (Prompt Application Firewall) service provided by Farfatech Inc. ("we", "our", or "us"). By accessing or using the Service, you agree to be bound by these Terms.

If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms, and "you" and "your" will refer to that organization.


Acceptance of Terms

By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by these Terms and our Privacy Policy. If you do not agree with these Terms, you must not access or use the Service.

We may update these Terms from time to time in accordance with the Updates to These Terms section below. Your continued use of the Service after any changes constitutes your acceptance of the revised Terms.


Definitions

  • "Service" means the PAF (Prompt Application Firewall) platform, including all features, functionality, documentation, and related services provided by us.
  • "Customer" means the organization or individual that has entered into a subscription agreement with us for the Service.
  • "User" means any individual authorized by the Customer to access and use the Service on the Customer's behalf.
  • "Prompts" means any text, code, data, or other content submitted by a User to the Service for processing.
  • "AI Responses" means the outputs generated by the Service in response to Prompts.
  • "PAF Topic Filtering" means the optional feature that trains per-customer isolated topic classifiers using Customer Prompts to improve filtering accuracy.
  • "AI Provider" means any third-party artificial intelligence service that you use independently of the Service (e.g., OpenAI, Anthropic, Google). PAF does not proxy, forward, or transmit your Prompts or AI Responses to any AI Provider.

Early Beta

The Service is currently in early beta. This means:

  • The Service is under active development and may change significantly at any time, including features, functionality, pricing, and availability.
  • You may encounter bugs, errors, inaccuracies, incomplete features, or unexpected behavior.
  • We may add, modify, or remove features, APIs, or functionality without prior notice.
  • Filtering accuracy, detection rates, and response times may vary and are not guaranteed to meet any specific standard.
  • Data retention policies, processing pipelines, and integrations may change as the Service evolves.
  • We may suspend or discontinue the Service, in whole or in part, at any time without prior notice.

By using the Service during its early beta phase, you acknowledge that the Service is not production-ready and that you use it at your own risk. We encourage you to maintain independent safeguards and not rely solely on the Service for security-critical use cases during this phase.

We welcome feedback and bug reports at [email protected], which help us improve the Service for all users.


Service Description

PAF (Prompt Application Firewall) is an AI-powered security service that you call before sending Prompts to an AI provider. The Service inspects, filters, and analyzes Prompts to detect prompt injection attacks and other adversarial inputs, returning a result that you use to decide whether to proceed with sending the Prompt to your AI provider.

The Service also analyzes AI Responses that you submit to it for inspection, helping you identify harmful or policy-violating outputs.

PAF does not proxy, forward, or transmit your Prompts or AI Responses to any AI provider.

You are responsible for your own relationship with AI providers, including compliance with their terms of service. PAF is a pre-call inspection and post-response analysis service — it does not replace or modify your direct integration with any AI provider.

The Service includes:

  • Prompt inspection and filtering to detect and block prompt injection attempts before you send Prompts to an AI provider.
  • Response analysis to identify harmful or policy-violating AI outputs after you receive them from an AI provider.
  • PAF Topic Filtering (optional) to train per-customer isolated classifiers that improve filtering accuracy for your organization's specific use cases.
  • Analytics and reporting on prompt and response processing.

We do not guarantee that the Service will detect or prevent all prompt injection attacks or harmful outputs.

The Service is provided as a security layer to reduce risk, not as a guarantee of security. Given the early beta status of the Service, detection accuracy and reliability are expected to improve over time and should not be relied upon as the sole security measure.


Third-Party AI Providers

PAF is a pre-call inspection and post-response analysis service. It does not proxy, forward, or transmit your Prompts or AI Responses to any AI provider. You maintain a direct and independent relationship with any AI providers you use.

You acknowledge and agree that:

  • Your responsibility: You are solely responsible for your use of any AI provider, including compliance with that provider's terms of service, acceptable use policies, and data processing practices.
  • No endorsement: Our ability to inspect, filter, or analyze Prompts and AI Responses does not constitute an endorsement, certification, or guarantee of the safety, legality, or quality of any AI provider or its outputs.
  • No liability for AI providers: We are not liable for any acts, omissions, errors, outages, policy changes, data practices, or terms of any AI provider. This includes but is not limited to AI provider downtime, rate limiting, content moderation decisions, data retention, or changes to terms of service.
  • No agency: Nothing in these Terms creates an agency, partnership, or joint venture between us and any AI provider. We do not act on behalf of any AI provider and have no control over their services or policies.
  • AI provider terms: Your use of any AI provider is governed solely by that provider's terms. If your use of PAF in connection with an AI provider violates that provider's terms, you are solely responsible for any resulting consequences, and we disclaim all liability arising from such violations.

Account and Access

Registration

To use the Service, you must register for an account. You may register using a third-party identity provider (e.g., GitHub, Google, Microsoft). When you authenticate via a third-party provider, we collect the identifier and profile information returned by that provider, as described in our Privacy Policy.

Authorized Users

You are responsible for all Users who access the Service through your account. You must ensure that all Users comply with these Terms. You are liable for any breach of these Terms by your Users.

Account Security

You are responsible for maintaining the security of your account credentials. You must notify us immediately at [email protected] if you become aware of any unauthorized access to your account.

Organizations

The Service is organized around organizations. An organization is a logical grouping of Users who share access to the Service under a single subscription. You may create, rename, or delete organizations through the Service. A User may belong to multiple organizations.

The User who creates an organization is automatically assigned the Administrator role for that organization. Deleting an organization is permanent and cannot be undone. Upon deletion, all data associated with the organization — including Prompts, AI Responses, memberships, and invitations — will be deleted in accordance with our retention policies.

Roles and Permissions

Each organization member is assigned one of the following roles:

  • Administrator: Can manage members and invitations, change roles, configure organization settings, and delete the organization.
  • User: Has limited access to organization management features. Users cannot manage members, change roles, or delete the organization.

Administrators may change a member's role at any time through the Service.

Invitations and Membership

Administrators may invite new Users to an organization by email address and assign them a role (Administrator or User) at the time of invitation. Invitations may be accepted or rejected by the recipient. Pending invitations may be revoked by an Administrator at any time.

By accepting an invitation, the invited User becomes a member of the organization and is bound by these Terms. The inviting organization's Administrator is responsible for ensuring that invited Users are authorized to access the Service.

Administrators may remove a member from an organization at any time. A removed member's access to the organization's data and settings is revoked immediately.


Ownership and Intellectual Property

Customer Content

You retain all right, title, and interest in and to your Prompts and AI Responses. Nothing in these Terms transfers ownership of your content to us.

License Grant

By submitting Prompts and AI Responses to the Service, you grant us a limited, non-exclusive, non-transferable license to process your Prompts and AI Responses solely for the purpose of providing the Service, including:

  • Inspecting, filtering, and analyzing Prompts and AI Responses for security and policy compliance.
  • Returning filtering results and analysis to you.
  • If PAF Topic Filtering is enabled, training per-customer isolated topic classifiers using your Prompts (subject to the PAF Topic Filtering section below).
  • Using anonymized data derived from detected attack vectors to improve the Service's detection capabilities, subject to the opt-in or opt-out terms specified in your service agreement.

This license terminates when we delete your content in accordance with our retention policies or upon termination of your account. The license to use anonymized data for Service improvement survives termination, as such data is no longer attributable to you.

Service IP

We own all right, title, and interest in and to the Service, including all software, algorithms, models (excluding per-customer topic classifiers), documentation, and branding. Models and detection capabilities may incorporate anonymized data derived from attack vectors as described in the License Grant above. No intellectual property rights in the Service are transferred to you under these Terms.

Per-Customer Topic Classifiers

Topic classifiers trained through PAF Topic Filtering are isolated to your organization. You own the configuration and training data that produces your classifiers. We retain ownership of the underlying model architecture and general Service infrastructure.


Acceptable Use Policy

You must not use the Service, and must not permit any User to use the Service, to:

  • Submit Prompts that contain illegal content, including content that violates applicable criminal law in Quebec, Canada, or any jurisdiction where you or your Users are located.
  • Generate malware, ransomware, exploits, or any other harmful software or code intended to damage, disrupt, or gain unauthorized access to systems.
  • Facilitate or encourage harassment, threats, hate speech, discrimination, or violence against any individual or group.
  • Attempt prompt injection attacks against the Service itself or use the Service to craft prompt injection attacks against other systems or services.
  • Circumvent, disable, or interfere with the Service's security features, filtering mechanisms, or access controls.
  • Reverse engineer, decompile, disassemble, or otherwise attempt to extract the source code, algorithms, or models underlying the Service.
  • Use the Service to process personal information in violation of applicable data protection laws.
  • Use the Service in any manner that could damage, disable, overburden, or impair our infrastructure or that of any AI provider.
  • Resell, sublicense, redistribute, white-label, or otherwise commercially exploit access to the Service or any of its features without our prior written agreement. This includes offering the Service as part of a competing product or service, embedding the Service in a product that is resold to third parties, or providing access to the Service to third parties on a commercial basis without our express written consent.

We reserve the right to suspend or terminate access to any User or Customer who violates this Acceptable Use Policy, with or without prior notice. If we become aware of Prompts or other content that may violate applicable law, we may suspend the offending account immediately and cooperate with relevant law enforcement and regulatory authorities as required by law.


PAF Topic Filtering

The PAF Topic Filtering feature is an optional service that uses your Prompts to train topic classifiers specific to your organization. By enabling PAF Topic Filtering, you agree to the following:

  • Per-Customer Isolation: Topic classifiers trained using your Prompts are isolated to your organization and are never shared with, sold to, or used by other customers or third parties.
  • Opt-In Consent: PAF Topic Filtering requires separate, explicit opt-in consent as described in our Privacy Policy. It is not enabled by default and cannot be bundled with other consents.
  • Right to Withdraw: You may disable PAF Topic Filtering at any time through your account settings. Disabling the feature will stop the use of your Prompts for classifier training. Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
  • Commercial Purpose: PAF Topic Filtering is used for commercial purposes to improve the Service for your organization.
  • Data Retention: Prompts used for PAF Topic Filtering are subject to the retention periods described in our Privacy Policy.

Billing and Payment

Subscription Fees

You agree to pay the subscription fees and usage-based charges as set forth in your subscription agreement or order form. Fees include:

  • Base Subscription: A recurring fee billed monthly or annually, depending on your plan.
  • Usage-Based Charges: Overage charges based on the volume of Prompts processed beyond the limits included in your base subscription.

Payment Terms

  • Payment is due within 30 days of the invoice date unless otherwise specified in your subscription agreement.
  • All fees are quoted in US dollars (USD) unless otherwise stated.
  • You are responsible for all taxes, duties, and other governmental charges imposed in connection with the fees, excluding taxes on our net income.
  • Taxes are calculated automatically at checkout based on your billing address. If you are exempt from tax or require a specific tax treatment, you must provide a valid Tax ID through the Service or contact us at [email protected] before your subscription is processed. We are not responsible for incorrect tax calculations resulting from inaccurate or missing Tax ID information.

Payment Processing

We use Stripe, Inc. ("Stripe") as our payment processor to handle billing transactions. By submitting payment information through the Service, you agree to Stripe's Terms of Service and Privacy Policy.

Stripe collects and processes your payment details (such as credit card numbers, billing address, and transaction information) directly. Farfatech does not collect or store full credit card numbers. Stripe's processing of your payment data is governed by Stripe's own terms and privacy policy.

Suspension for Non-Payment

We may suspend your access to the Service if payment is not received within 15 days after the due date. We will provide notice before suspension. Suspension does not relieve you of your obligation to pay outstanding fees.

Fee Changes

We may change our fees with 30 days' prior written notice. Continued use of the Service after the effective date of a fee change constitutes acceptance of the new fees.


Data Processing

Our collection, use, and disclosure of personal information in connection with the Service is governed by our Privacy Policy, which is incorporated into these Terms by reference.

Key points:

  • Retention: Prompts and AI Responses are retained for 30 days by default, customizable per Customer. Account information is retained for the duration of the contract plus one year. See the Privacy Policy for full retention details.

  • Cross-Border Transfers: Your data may be processed in Canada, Switzerland, and the USA. See the Privacy Policy for transfer mechanisms and safeguards.

  • Subprocessors: We use PostHog (USA), Cloudflare (USA), Cloudflare R2 (USA), GitHub (USA), Google (USA), Microsoft (USA), Stripe (USA), and Proton Mail (Switzerland) as subprocessors. Hosting is operated by Farfatech in Canada and is not a subprocessor. See the Privacy Policy for details.

  • Anonymized Data for Service Improvement: When the Service detects a successful attack vector, the anonymized data may be used to improve our detection capabilities. Whether this is opt-in or opt-out depends on your service agreement. See the Privacy Policy for details.

  • Data Subject Rights: You and your Users have rights under applicable data protection laws. See the Privacy Policy for a full list of rights by jurisdiction.

  • Data Security: Customer data is protected with encryption in transit (TLS) and encryption at rest, on Farfatech-operated infrastructure in Canada. See the Privacy Policy for full security measure details.


Security Incident Notification

Definition

A "Security Incident" means any confirmed unauthorized access to, disclosure of, or loss of Customer data stored in or processed by the Service, or any compromise of the Service's security that could affect the confidentiality, integrity, or availability of Customer data.

Notification

We will notify you of a Security Incident without undue delay and in any case within 72 hours of becoming aware of it, by sending an email to the account administrator on file. The notification will include:

  • A description of the Security Incident, including the nature and scope of the data affected.
  • The measures we have taken or plan to take to address the Security Incident and mitigate its effects.
  • Contact information for a person who can provide further details.

If we are unable to provide full details within 72 hours due to an ongoing investigation, we will provide an initial notification with the information available and supplement it as we learn more.

Your Obligations

You are responsible for notifying your Users and any applicable regulators of a Security Incident as required by law. We will cooperate with you in meeting your notification obligations to the extent reasonably possible.

Limitations

Our obligation to notify you of a Security Incident does not constitute an acknowledgment of fault or liability. Nothing in this section creates an obligation for us to notify you of incidents that do not involve Customer data or that affect third-party services (including AI providers) over which we have no control.


Data Processing Addendum

Our processing of personal information in connection with the Service is governed by the Privacy Policy and, where applicable, by a separate Data Processing Addendum ("DPA").

Availability

A DPA is available upon request for Customers who require one to comply with applicable data protection laws. To request a DPA, contact us at [email protected].

Scope

The DPA supplements these Terms and the Privacy Policy and addresses:

  • The roles of the parties as controller and processor with respect to personal information processed through the Service.
  • The categories of personal information processed and the purposes of processing.
  • Our obligations regarding data security, confidentiality, and subprocessing.
  • Your rights to audit, data portability, and deletion.
  • Cross-border data transfer mechanisms, including Standard Contractual Clauses where applicable.
  • Data breach notification procedures (supplementing the Security Incident Notification section above).
  • Obligations upon termination of the DPA, including data return and deletion.

Subprocessors

We currently use the following subprocessors to process Customer data:

SubprocessorPurposeLocation
PostHog, Inc.Product analyticsUSA
Cloudflare, Inc.CDN and securityUSA
Cloudflare, Inc. (R2)Database backupsUSA
GitHub, Inc.Authentication (Login with GitHub)USA
Google LLCAuthentication (Login with Google)USA
Microsoft CorporationAuthentication (Login with Microsoft)USA
Stripe, Inc.Payment processingUSA
Proton AGEmail delivery (SMTP)Switzerland

We will provide you with at least 30 days' written notice before adding or replacing a subprocessor that processes Customer data. An up-to-date list of subprocessors is available in our Privacy Policy.


Conflict

In the event of any conflict between the DPA and these Terms with respect to data processing, the DPA will prevail.


Service Availability

The Service is provided on a best-effort basis. As the Service is in early access, availability may be lower and interruptions more frequent than a production-ready service. We do not guarantee any specific uptime, availability, or response time.

  • We will use commercially reasonable efforts to make the Service available, but we do not provide a Service Level Agreement (SLA) or uptime guarantee.
  • We may perform scheduled maintenance with reasonable prior notice. We will attempt to schedule maintenance during low-usage periods.
  • We may release features, changes, or fixes incrementally as part of the early access program, which may result in temporary instability or unexpected behavior.
  • We are not liable for any downtime, service interruptions, or delays caused by factors beyond our control, including but not limited to AI provider outages, internet disruptions, or force majeure events.

Limitation of Liability

Disclaimer of Warranties

The Service is in early beta and is provided "as is" and "as available" without warranties of any kind, whether express, implied, or statutory, including but not limited to implied warranties of merchantability, fitness for a particular purpose, and non-infringement.

We do not warrant that:

  • The Service will be uninterrupted, error-free, or secure.
  • The Service will detect or prevent all prompt injection attacks or harmful AI outputs.
  • The results obtained from the Service will be accurate, reliable, or complete.
  • The Service is suitable for production use or any particular purpose.
  • Any features, functionality, or APIs will remain available or unchanged.

Limitation of Liability

To the maximum extent permitted by applicable law:

  • Our total aggregate liability arising out of or related to these Terms or the Service shall not exceed the total fees paid by you to us in the 12 months preceding the claim.
  • We shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including but not limited to loss of profits, data, business opportunities, or goodwill, regardless of the cause of action or the theory of liability.

Exceptions

Nothing in these Terms excludes or limits liability that cannot be excluded or limited under applicable law, including liability for death or personal injury caused by negligence, fraud, or willful misconduct.


No Security Guarantee

The Service is a security tool designed to reduce risk. It does not eliminate risk. You acknowledge and agree that:

  • No guarantee of security: Use of the Service does not guarantee that your systems, Prompts, AI Responses, or AI provider integrations are secure. The Service is one layer in a defense-in-depth strategy and must not be treated as a sole or sufficient security measure.
  • No certification or endorsement: The Service does not constitute a security certification, audit, endorsement, or attestation of any kind. Using PAF does not certify compliance with any security standard, framework, or regulation.
  • False negatives and false positives: The Service may fail to detect prompt injection attacks, harmful outputs, or policy violations (false negatives). The Service may also incorrectly flag legitimate Prompts or AI Responses as malicious or policy-violating (false positives). Neither outcome gives rise to liability on our part.
  • Evolving threat landscape: Prompt injection techniques, adversarial inputs, and AI attack vectors are constantly evolving. The Service's detection capabilities may not address novel or previously unknown attack patterns.
  • Your responsibility: You remain solely responsible for your overall security posture, including the security of your AI provider integrations, the handling of AI Responses, and the implementation of appropriate safeguards beyond the Service. You are solely responsible for how you implement and act on the Service's filtering results.
  • Not a substitute for independent assessment: You should not rely solely on the Service for security-critical decisions. Independent security assessments, audits, and reviews of your AI integrations are recommended.
  • No liability for implementation failures: We are not liable for any security incidents arising from your failure to follow our recommendations, integrate the Service properly, or act on its filtering results.

Assumption of Risk

You acknowledge that the Service is in early beta and that its use involves inherent risks, including but not limited to:

  • Security risks: The Service may not detect all prompt injection attacks, adversarial inputs, or harmful AI outputs, leaving your systems and data exposed to potential threats.
  • Operational risks: The Service may experience downtime, errors, or performance issues that could disrupt your operations or delay your use of AI providers.
  • False positives/negatives: The Service may incorrectly flag legitimate Prompts or AI Responses as malicious (false positives) or fail to detect actual threats (false negatives), either of which could impact your workflows or security.
  • Evolving threats: The Service's detection capabilities may not keep pace with new or emerging attack techniques, requiring you to implement additional safeguards.
  • Data processing risks: Your Prompts and AI Responses are processed by the Service and its subprocessors, which may involve cross-border data transfers and associated legal or regulatory risks.

By using the Service, you assume all risks associated with its use, including any reliance on its filtering results or recommendations. You agree that you will not hold us liable for any damages, losses, or claims arising from these risks, and that you use the Service at your own risk.


Vulnerability Disclosure

We are committed to the security of the Service and welcome reports of potential vulnerabilities from security researchers and users. If you discover a potential security vulnerability in the Service, please report it to us as follows:

  • Contact: Send an email to [email protected] with the subject line Security Vulnerability Report.
  • Details: Include a detailed description of the vulnerability, steps to reproduce it, and any supporting evidence (e.g., proof of concept, screenshots).
  • Acknowledgment: We will acknowledge receipt of your report within 7 days and provide a timeline for investigation and resolution.
  • Coordination: We will work with you to validate and address the vulnerability. You must not publicly disclose any vulnerability, including its existence, details, or proof of concept, until we have confirmed that it has been remediated. Public disclosure before this period without our written consent is a violation of these Terms and may result in legal action.
  • No Legal Action: We will not pursue legal action against you for reports made in good faith and in accordance with this section, provided you do not exploit the vulnerability, access or exfiltrate data beyond what is necessary to demonstrate the issue, use the vulnerability to extort or coerce us, or violate applicable law.
  • No Compensation: We do not offer compensation, bug bounties, or rewards for vulnerability reports.

This policy does not authorize or permit the testing of vulnerabilities on systems or services that are not owned or operated by us. Unauthorized testing of third-party systems (including AI providers) is prohibited and may violate applicable law.


Audit Rights

Upon your written request, we will provide reasonable documentation to demonstrate our compliance with these Terms and applicable data protection laws, including:

  • Security practices: Documentation of our security measures, policies, and procedures relevant to the Service.
  • Subprocessor compliance: Proof of our subprocessors' compliance with data protection agreements and applicable law.
  • Data processing records: Logs or summaries of data processing activities performed on your behalf, to the extent they do not compromise the security or confidentiality of other Customers' data.

Requests must be sent to [email protected], subject to confidentiality and security constraints. We reserve the right to charge a reasonable fee for requests that are excessive, repetitive, or burdensome.

This section does not grant you the right to conduct on-site audits or inspections of our facilities, systems, or subprocessors.


Indemnification

You agree to indemnify, defend, and hold us harmless from and against any claims, damages, losses, and expenses (including reasonable attorneys' fees) arising out of or related to:

  • Your or your Users' violation of these Terms or the Acceptable Use Policy.
  • Your or your Users' violation of applicable law.
  • Your Prompts, AI Responses, or other content submitted to the Service that infringe the intellectual property or other rights of a third party.

Marketing

We may use your organization's name, logo, and brand marks to identify you as a customer of the Service in our marketing materials, website, and promotional content. If you wish to opt out, you may notify us in writing at [email protected].


Term and Termination

Term

These Terms are effective from the date you first access the Service and continue for the duration of your subscription, unless terminated earlier in accordance with this section. Upon termination, the provisions that by their nature should survive will remain in effect, including Ownership and Intellectual Property, Limitation of Liability, Indemnification, Confidentiality, Dispute Resolution, and Governing Law. We will retain and process your personal information in accordance with the retention periods described in our Privacy Policy, which may extend beyond the termination of your subscription.

Termination for Cause

Either party may terminate these Terms upon written notice if the other party:

  • Materially breaches these Terms and fails to cure the breach within 30 days of receiving notice.
  • Becomes subject to bankruptcy, insolvency, or similar proceedings.

We may terminate these Terms immediately upon written notice if you or any User violates the Acceptable Use Policy.

Termination for Convenience

Either party may terminate these Terms for convenience with 30 days' written notice.

Effect of Termination

  • Upon termination, your right to access and use the Service will immediately cease.
  • We will delete your Prompts, AI Responses, and other Customer data in accordance with our retention periods described in the Privacy Policy, unless you request earlier deletion.
  • You may request a data export of your content within 30 days of termination by contacting [email protected]. After 30 days, we are not obligated to retain or provide your data.

Data Portability & Deletion

  • Export format: Data exports will be provided in JSON format, unless otherwise agreed.
  • Export timeline: We will provide your data export within 14 days of your request, provided the request is made within 30 days of termination.
  • Deletion timeline: Your Prompts and AI Responses will be deleted within 30 days of termination, unless we are required by law to retain them for a longer period. Anonymized data derived from attack vectors that has already been incorporated into our training data is not subject to deletion, as it is no longer attributable to you.
  • Early deletion: You may request earlier deletion of your data by contacting [email protected]. We will delete your data within 7 days of your request, unless we are required by law to retain it. The early deletion obligation does not apply to anonymized data that has already been incorporated into our training data.

Confidentiality

Definition

"Confidential Information" means any information disclosed by one party to the other that is marked as confidential or that should reasonably be understood to be confidential given the nature of the information and the circumstances of disclosure.

Obligations

Each party agrees to:

  • Hold the other party's Confidential Information in confidence and not disclose it to any third party without prior written consent.
  • Use the other party's Confidential Information only for the purposes of these Terms.
  • Protect the other party's Confidential Information using the same degree of care it uses to protect its own confidential information, but in no event less than reasonable care.

Exceptions

Confidential Information does not include information that:

  • Is or becomes publicly available without breach of these Terms.
  • Was known to the receiving party before disclosure.
  • Is independently developed by the receiving party without reference to the Confidential Information.
  • Is required to be disclosed by law or court order, provided the receiving party gives prompt notice to the disclosing party.

Dispute Resolution

Good-Faith Negotiation

In the event of any dispute arising out of or related to these Terms, the parties agree to first attempt to resolve the dispute through good-faith negotiation. Either party may initiate this process by providing written notice to the other party describing the dispute. The parties will negotiate in good faith for a period of 90 days from the date of the notice.

Arbitration

If the dispute is not resolved through negotiation within 90 days, either party may submit the dispute to binding arbitration administered under the National Arbitration Rules of the ADR Institute of Canada (ADRIC). The arbitration will be conducted in English or French, in Montreal, Quebec, Canada, by a single arbitrator appointed in accordance with the ADRIC rules. The arbitrator's decision will be final and binding and may be enforced in any court of competent jurisdiction.

If you are located outside Canada and the mandatory arbitration or forum selection in Montreal would be unenforceable under the mandatory laws of your jurisdiction, then disputes will be resolved in the courts of your jurisdiction that have subject-matter jurisdiction, and the laws of your jurisdiction will apply to the extent required by those mandatory laws. In all other cases, Quebec law and Montreal arbitration apply.

Exceptions

Either party may seek injunctive or equitable relief in any court of competent jurisdiction for breaches of confidentiality, intellectual property rights, or the Acceptable Use Policy.


Governing Law

These Terms are governed by and construed in accordance with the laws of the Province of Quebec and the federal laws of Canada applicable therein, without regard to conflict of law principles.

Any arbitration or court proceedings arising from these Terms will be conducted in Montreal, Quebec, Canada.


General Provisions

Entire Agreement

These Terms, together with our Privacy Policy and any applicable subscription agreement or order form, constitute the entire agreement between you and us regarding the Service and supersede all prior or contemporaneous agreements, representations, and understandings. If you have a separate commercial agreement with us, that agreement will prevail over these Terms to the extent of any conflict for the sections it covers.

Amendments

We may amend these Terms by posting the updated version on our website with a new effective date and providing you with reasonable notice. Material changes will be communicated via email to the account administrator. Your continued use of the Service after the effective date of any amendment constitutes acceptance of the amended Terms.

Notices

All notices under these Terms must be in writing and sent to:

  • Us: [email protected] or Farfatech Inc.
  • You: The email address associated with your account.

Assignment

You may not assign or transfer these Terms or your rights under them, in whole or in part, without our prior written consent. We may assign these Terms to any affiliate or successor without your consent.

Force Majeure

Neither party will be liable for any failure or delay in performing its obligations under these Terms due to causes beyond its reasonable control, including but not limited to natural disasters, war, terrorism, riots, pandemics, government actions, internet outages, or AI provider outages.

Severability

If any provision of these Terms is held to be invalid, illegal, or unenforceable, the remaining provisions will remain in full force and effect. The invalid provision will be modified to the minimum extent necessary to make it valid and enforceable, while preserving the parties' original intent.

Waiver

No waiver of any provision of these Terms will be effective unless made in writing and signed by the waiving party. The failure of either party to enforce any right under these Terms will not constitute a waiver of that right.

Independent Contractors

The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship between the parties.


Contact: If you have any questions about these Terms, please contact us at [email protected].

back to login