# Welcome to Compliance Center

In Diaflow's Compliance Center, you can easily find documents of Diaflow, such as:

{% content-ref url="/pages/MvJt5Qkps6OJiQz60vtv" %}
[Terms & Conditions](/general/terms-and-conditions)
{% endcontent-ref %}

{% content-ref url="/pages/inS92o3l8C2U86Sg5elM" %}
[Privacy Policy](/general/privacy-policy)
{% endcontent-ref %}

{% content-ref url="/pages/jAMLY6VuybaQSmtQ2uHO" %}
[Security Practices](/general/security-practices)
{% endcontent-ref %}

and more

{% content-ref url="/pages/IewgJUEBYHIWZMhi8V4V" %}
[Brand & Logo Guideline](/other/brand-and-logo-guideline)
{% endcontent-ref %}


# Terms & Conditions

These Terms and Conditions of Service (this "Agreement") constitute a legally binding contract between you and Diaflow Pte. Ltd. ("Diaflow," "we," "our," or "us"). This Agreement governs your access to and use of the Services, including all associated software, AI-powered features, APIs, integrations, and documentation.

THIS AGREEMENT TAKES EFFECT WHEN YOU CLICK "I ACCEPT," CREATE AN ACCOUNT, OR ACCESS OR USE THE SERVICES (THE "EFFECTIVE DATE"). BY DOING SO, YOU: (A) ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTAND THIS AGREEMENT; (B) REPRESENT AND WARRANT THAT YOU HAVE THE RIGHT, POWER, AND AUTHORITY TO ENTER INTO THIS AGREEMENT AND, IF ACTING ON BEHALF OF AN ORGANIZATION, THAT YOU HAVE THE LEGAL AUTHORITY TO BIND THAT ORGANIZATION; AND (C) ACCEPT THIS AGREEMENT AND AGREE TO BE LEGALLY BOUND BY ITS TERMS. IF YOU DO NOT AGREE, DO NOT ACCESS OR USE THE SERVICES.

### 1. Definitions

"Aggregated Statistics" means data and information related to Customer's use of the Services, used by Diaflow in an aggregated and anonymized manner, including to compile statistical and performance information related to the provision and operation of the Services.

"**Apple App Store Addendum**" means the supplementary EULA terms applicable to your use of the Services via a Licensed Application distributed through the Apple App Store, available at <https://compliance.diaflow.io/general/apple-app-store-eula-addendum>, as updated from time to time.&#x20;

"Arbitration Agreement" means the mandatory individual arbitration provision in Section 14(b).

"Authorized User" means Customer's employees, consultants, contractors, and agents who are authorized by Customer to access and use the Services under the rights granted pursuant to this Agreement and for whom access has been purchased hereunder.

"Class Action/Jury Trial Waiver" means the class action/jury trial waiver provision in Section 14(c).

"Confidential Information" means information about either party's business affairs, products, confidential intellectual property, trade secrets, third-party confidential information, and other sensitive or proprietary information, whether disclosed orally, in writing, electronically, or in any other form, whether or not marked as "confidential." Confidential Information does not include information that at the time of disclosure is: (a) in the public domain; (b) already known to the receiving party without obligation of confidentiality; (c) rightfully obtained from a third party on a non-confidential basis; or (d) independently developed by the receiving party without use of the disclosing party's Confidential Information.

"Credits" means the usage-based units allocated to a Customer Account that are consumed when the Customer accesses or uses certain features of the Services, including but not limited to AI-powered workflow executions, agent interactions, API calls, and other metered functionality. The number of Credits allocated and the rate of consumption may vary by account type and plan tier.

"Customer," "you," or "your" means the individual or entity that has agreed to this Agreement and its Authorized Users.

"Customer Account" means the account created by or on behalf of Customer to access and use the Services.

"Customer Content" means any content, including profile information, workflow configurations, agent definitions, prompts, data inputs, comments, questions, and other materials in any form or medium, that is submitted, posted, displayed, transmitted, or otherwise made available on the Services by or on behalf of Customer or any Authorized User. Output generated by the Services from Customer Content (including AI-generated outputs) is also Customer Content; provided, however, that Aggregated Statistics is not Customer Content.

"Documentation" means Diaflow's user manuals, handbooks, guides, FAQs, API references, instructional videos, and other materials relating to the Services, provided electronically and available at [www.diaflow.io](https://www.diaflow.io/) and [docs.diaflow.io](https://docs.diaflow.io/).

"Feedback" means any communications or materials sent to Diaflow through designated feedback channels (including in-product feedback forms, feature request portals, and emails explicitly labeled as feedback to <support@diaflow.io>) suggesting or recommending changes to the Services, including new features or functionality.

"Intellectual Property Rights" means all patent rights, copyright rights, mask work rights, moral rights, rights of publicity, trademark, trade dress and service mark rights, goodwill, trade secret rights, and other intellectual property rights as may now exist or hereafter come into existence, and all applications, registrations, renewals, and extensions thereof, under the laws of any jurisdiction.

"Diaflow IP" means: (i) the Services, including all materials therein such as software, AI models, algorithms, images, text, graphics, logos, patents, trademarks, service marks, copyrights, and other content; (ii) the Documentation; and (iii) all intellectual property provided to Customer in connection with the foregoing. Diaflow IP includes Aggregated Statistics and any data derived from Diaflow's monitoring of Customer's use of the Services, but does not include Customer Content.

"Privacy Policy" means Diaflow's privacy policy, available at [compliance.diaflow.io/general/privacy-policy](https://compliance.diaflow.io/general/privacy-policy), as updated from time to time. The Privacy Policy describes in detail how Diaflow collects, uses, shares, and protects personal data, including AI-specific data practices, cookie usage, international data transfers, and your privacy rights under applicable law (including GDPR, UK GDPR, CCPA/CPRA, and Singapore PDPA). To the extent any provision of this Agreement conflicts with the Privacy Policy on matters of personal data processing, the Privacy Policy shall prevail.

"Services" means the online and/or mobile services, websites, AI-powered workflow automation platform, agent builder, chat interface, APIs, integrations, and software provided by Diaflow under this Agreement, as detailed at [www.diaflow.io](https://www.diaflow.io/).

"Third-Party Products" means any products, content, services, information, AI models, APIs, websites, or other materials owned by third parties that are incorporated into or accessible through the Services.

"User" or "Users" means all visitors, users, and others who access the Services.

### 2. Access and Use

#### (a) Eligibility

You must read and agree to this Agreement before using the Services. You may use the Services only if you can form a binding contract with Diaflow and only in compliance with this Agreement and all applicable laws, rules, and regulations. Access to or use of the Services by anyone under 13 years of age is strictly prohibited. In the European Economic Area and the United Kingdom, access is restricted to individuals aged 16 or older. In South Korea, access is restricted to individuals aged 14 or older. In Brazil, individuals aged 12 to 17 may access the Services only with verifiable parental or guardian consent. The Services are not available to any Users previously removed or suspended by Diaflow.

#### (b) Grant of Access

Subject to and conditioned on your payment of applicable Fees and compliance with all terms of this Agreement, Diaflow grants you a revocable, non-exclusive, non-transferable, non-sublicensable, limited right to access and use the Services during the Term solely for your internal business operations by Authorized Users. Diaflow shall provide the necessary credentials to enable your access.

#### (c) Documentation License

Subject to this Agreement, Diaflow grants you a non-exclusive, non-sublicensable, non-transferable license for Authorized Users to use the Documentation during the Term solely for your internal business purposes in connection with the Services.

#### (d) Customer Accounts

Your Customer Account provides access to Services and functionality that we may establish and maintain at our sole discretion. We may maintain different account types with varying features and limitations. If you open an account on behalf of a company, organization, or other entity, "you" includes both you individually and that entity.

When creating your Customer Account, you must provide accurate and complete information and keep this information current. You are solely responsible for all activity on your Customer Account and must keep your credentials secure. You must notify Diaflow immediately of any unauthorized access. Diaflow will not be liable for losses caused by unauthorized use of your Customer Account.

By providing your email address, you consent to receiving Services-related notices electronically, including legally required notices. You may manage communication preferences in your account settings; however, opting out of certain communications may affect your ability to receive important updates. For details on how we collect and use your contact information, please refer to our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (e) Use Restrictions

You shall not, and shall not permit any Authorized User to:

(i) copy, distribute, sell, resell, or disclose any part of the Services;

(ii) use automated systems (robots, spiders, scrapers, etc.) to access the Services beyond what a human could reasonably produce using a standard web browser;

(iii) transmit spam, chain letters, or unsolicited communications;

(iv) attempt to interfere with, compromise, or decipher transmissions to or from the Services;

(v) impose an unreasonable load on our infrastructure;

(vi) upload viruses, malware, or other harmful code;

(vii) collect or harvest personally identifiable information from the Services;

(viii) use the Services for unauthorized commercial solicitation;

(ix) impersonate another person or entity;

(x) interfere with the proper working of the Services;

(xi) access content through unauthorized means;

(xii)bypass security or access-restriction measures;

(xiii) use the Services to develop a competing product or service, or to perform competitive analysis, benchmarking, or feature comparison for the benefit of a competing product or service;

(xiv) access, scrape, copy, reproduce, adapt, or otherwise use any Diaflow publicly available materials — including but not limited to pre-built workflow templates, prompt libraries, agent configurations, integration templates, documentation, tutorial content, UI designs, API schemas, and marketing materials (collectively, "Diaflow Public Materials") — for the purpose of developing, improving, training, benchmarking, or otherwise enhancing any competing product, service, or AI system, whether directly or through third parties;

(xv) use any automated or manual means to systematically collect, harvest, index, or aggregate Diaflow Public Materials or any data accessible through the Services for competitive intelligence purposes;

(xvi) reverse engineer, decompile, or disassemble any aspect of the Services; or

(xvii) use AI-generated outputs from the Services in any manner that violates applicable law, infringes third-party rights, or is intended to deceive or mislead.

#### (f) Aggregated Statistics

Diaflow may monitor Customer's use of the Services and compile Aggregated Statistics. All right, title, and interest in Aggregated Statistics belong exclusively to Diaflow. You agree that Diaflow may make Aggregated Statistics publicly available and use them as permitted by applicable law, provided that such statistics do not identify Customer or Customer's Confidential Information. The collection and use of data for Aggregated Statistics is further described in Section 3 (How We Use Your Information) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (g) Reservation of Rights

Diaflow reserves all rights not expressly granted under this Agreement. Nothing herein grants, by implication, waiver, estoppel, or otherwise, any intellectual property rights or other rights in or to the Diaflow IP.

#### (h) Suspension and Termination

Diaflow may, in its sole discretion, temporarily suspend or permanently terminate your access to the Services, provided that Diaflow shall use commercially reasonable efforts to provide prior written notice (including via email) at least five (5) business days before termination, except where immediate action is reasonably necessary to prevent harm. Grounds for suspension or termination include:

(xviii) there is a threat or attack on any Diaflow IP;

(xix) your use disrupts or poses a security risk to the Services or other customers;

(xx) you are using the Services for fraudulent or illegal activities;

(xxi) you have ceased business operations or become subject to insolvency proceedings;

(xxii) Diaflow's provision of the Services to you is prohibited by applicable law;

(xxiii) any third-party vendor has suspended Diaflow's access to required services; or

(xxiv) in accordance with Section 7 (Fees, Payment, and Credits).

Where Diaflow terminates your account without cause or for its own convenience, you shall be entitled to a pro-rata refund of any prepaid fees for the unused portion of the then-current subscription term, as further described in Section 7(c).

#### (i) Changes to the Services

We may modify, discontinue, or limit features of the Services. For material changes that Diaflow reasonably anticipates may reduce service quality or remove features on which customers materially rely, Diaflow shall provide at least thirty (30) days' advance notice through email or in-app notification. We may permanently or temporarily terminate or suspend your access without notice or liability if you violate any provision of this Agreement. Upon termination, you continue to be bound by the surviving provisions of this Agreement.

#### (j) Disputes with Other Users

You are solely responsible for your interactions with other Users. Diaflow reserves the right, but has no obligation, to monitor such disputes and shall have no liability for any User's action or inaction.

#### (k) App Store Distribution

If you access or use the Services through a Licensed Application obtained from the Apple App Store, your use is additionally governed by the Apple App Store Addendum, which is incorporated into and forms part of this Agreement. In the event of any conflict between this Agreement and the Apple App Store Addendum solely with respect to matters addressed in the Addendum, the Apple App Store Addendum shall control.

#### (l) Google Play Distribution

If you access or use the Services through an application obtained from the Google Play Store, your use is additionally governed by Google's Play Terms of Service and Developer Distribution Agreement between Diaflow and Google, to the extent applicable to end users. Depending on your platform and region, purchases may be processed through Google Play Billing, an alternative billing system, or another payment method designated by Diaflow, as described in Section 7(f).

### 3. AI-Specific Provisions

#### (a) Nature of AI Outputs

The Services incorporate artificial intelligence and machine learning technologies, including large language models provided by third-party providers. You acknowledge and agree that:

(xxv) AI-generated outputs may be inaccurate, incomplete, or unsuitable for any particular purpose;

(xxvi) you are solely responsible for reviewing, validating, and determining the appropriateness of any AI-generated outputs before relying upon or distributing them;

(xxvii) Diaflow does not guarantee the accuracy, reliability, or fitness for purpose of any AI-generated content; and

(xxviii) AI-generated outputs do not constitute professional advice of any kind.

#### (b) AI Model Changes

The AI models, algorithms, and underlying technologies used within the Services may be updated, replaced, or modified at any time. Where such changes materially affect the behavior, output quality, or capabilities of AI-powered features, Diaflow shall use commercially reasonable efforts to provide advance notice through release notes, in-app notifications, or email. Diaflow shall not be liable for any impact resulting from such changes, but will maintain a changelog accessible through the Documentation.

#### (c) Data Usage for AI Improvement

Unless you opt out by written notice to <privacy@diaflow.io>, Diaflow may use anonymized and aggregated data derived from your use of the Services to improve, train, fine-tune, or benchmark AI models and Services, provided that such data does not identify Customer or include Customer's Confidential Information. Diaflow will not use identifiable Customer Content to train AI models without your explicit prior consent. Opt-out requests will be processed within fifteen (15) business days of receipt. For further details on how AI interaction data is processed and retained, please refer to Section 4 (AI-Specific Data Practices) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (d) Prohibited AI Uses

You shall not use the AI-powered features of the Services to:

(xxix) generate content that is illegal, harmful, discriminatory, defamatory, or infringes upon any third-party rights;

(xxx) create deepfakes or deceptive synthetic media;

(xxxi) engage in unauthorized surveillance or profiling;

(xxxii) make automated decisions that produce legal effects or similarly significant effects on individuals without appropriate human oversight; or

(xxxiii) violate any applicable AI regulations or guidelines, including but not limited to the EU AI Act, where applicable.

#### (e) Third-Party AI Models

Certain features of the Services may rely on AI models provided by third parties. Your use of such features is subject to the terms and acceptable use policies of the respective third-party providers. Diaflow does not control and is not responsible for the performance, availability, or outputs of third-party AI models. You agree to comply with all applicable third-party terms when using features that incorporate such models. For information on how data is routed through third-party AI providers, please refer to Section 4 (AI-Specific Data Practices) and Section 5 (Sharing and Disclosure of Information) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

### 4. Intellectual Property Rights

#### (a) Customer Content Ownership

Diaflow claims no ownership rights over Customer Content. You retain all right, title, and interest in and to your Customer Content, including all Intellectual Property Rights therein.

#### (b) Limited License to Customer Content

By making Customer Content available through the Services, you grant Diaflow a non-exclusive, worldwide, royalty-free license to use, reproduce, modify, and process such Customer Content solely as necessary to provide, maintain, operate, and improve the Services during the Term of this Agreement. This license includes the right to:

(xxxiv) process Customer Content through AI models and workflow engines to generate outputs you have requested;

(xxxv) temporarily cache or store Customer Content as necessary for Service performance and reliability;

(xxxvi) create Aggregated Statistics derived from Customer Content, subject to Section 2(f); and

(xxxvii) display Customer Content back to you and your Authorized Users within the Services interface.

#### (c) License Limitations and Termination

The license granted in Section 4(b) is subject to the following limitations:

(xxxviii) Diaflow shall not use Customer Content for purposes unrelated to providing the Services, except as expressly permitted under Section 3(c) (Data Usage for AI Improvement) and subject to your opt-out rights therein;

(xxxix) Diaflow shall not sell, sublicense, or distribute Customer Content to third parties, except to sub-processors acting on Diaflow's behalf and subject to data processing agreements no less protective than this Agreement;

(xl) Diaflow shall not use identifiable Customer Content for marketing, advertising, or promotional purposes without your prior written consent;

(xli) upon termination of this Agreement, the license granted herein shall terminate, and Diaflow shall delete Customer Content in accordance with Section 9(d) and Section 6 (Data Retention) of the [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy); and

(xlii) notwithstanding the foregoing, Diaflow may retain Aggregated Statistics (which do not identify Customer) in perpetuity, and may retain Customer Content to the limited extent required by applicable law, regulation, or valid legal process.

#### (d) AI-Generated Outputs

Output generated by the Services from Customer Content (including AI-generated outputs) is Customer Content and is owned by you, subject to the following:

(xliii) AI-generated outputs may incorporate patterns, structures, or information derived from the AI models' training data, and Diaflow makes no representation that such outputs are original or non-infringing;

(xliv) you are solely responsible for reviewing AI-generated outputs for accuracy, appropriateness, and compliance with applicable law before use or distribution;

(xlv) Diaflow does not claim ownership of AI-generated outputs but retains the right to use anonymized and aggregated metadata about output patterns to improve the Services, subject to Section 3(c); and

(xlvi) identical or similar outputs may be generated for other customers using the same AI models, and such occurrence does not grant you exclusive rights to any particular output.

#### (e) Diaflow Property

Diaflow IP and all related Intellectual Property Rights are the exclusive property of Diaflow and its licensors. Nothing in this Agreement creates a license in or under any such Intellectual Property Rights except as expressly provided. You agree not to sell, license, rent, modify, distribute, copy, reproduce, transmit, publicly display, publicly perform, publish, adapt, edit, or create derivative works from any Diaflow IP. For the avoidance of doubt, Diaflow Public Materials (as defined in Section 2(e)) — including pre-built workflow templates, prompt libraries, agent configurations, integration templates, documentation, tutorial content, UI designs, and API schemas — constitute Diaflow IP regardless of whether they are made publicly accessible, and may not be used, reproduced, adapted, or incorporated into any competing product, service, or AI system without Diaflow's prior written consent. The public availability of any Diaflow materials does not constitute a waiver of Diaflow's Intellectual Property Rights therein or a grant of any license to use such materials for competitive purposes.

#### (f) Mutual IP Indemnification

By Diaflow. Diaflow shall defend, indemnify, and hold harmless Customer from and against any third-party claim alleging that the Services (excluding Customer Content, Third-Party Products, and third-party AI model outputs) infringe or misappropriate such third party's Intellectual Property Rights, and shall pay any final judgment or approved settlement arising therefrom. If the Services become, or in Diaflow's reasonable opinion are likely to become, the subject of an infringement claim, Diaflow may, at its option and expense: (i) procure the right for Customer to continue using the Services; (ii) modify the Services to make them non-infringing while maintaining substantially equivalent functionality; or (iii) if neither (i) nor (ii) is commercially practicable, terminate the affected portion of the Services and refund any prepaid fees for the unused portion of the Term.

By Customer. Customer shall defend, indemnify, and hold harmless Diaflow from and against any third-party claim alleging that Customer Content infringes or misappropriates such third party's Intellectual Property Rights, and shall pay any final judgment or approved settlement arising therefrom.

#### (g) Feedback

By submitting Feedback through designated feedback channels (in-product feedback forms, feature request portals, or emails explicitly labeled as feedback to <support@diaflow.io>), you agree that your disclosure is gratuitous, unsolicited, and without restriction. You hereby assign to Diaflow all right, title, and interest in any such Feedback, including all Intellectual Property Rights therein, and Diaflow is free to use such Feedback without compensation or attribution. For the avoidance of doubt, casual comments in support tickets, general correspondence, or conversations with Diaflow personnel do not constitute Feedback and are not subject to this assignment.

#### (h) DMCA Notice

Diaflow respects intellectual property rights and responds to notices of alleged copyright infringement that comply with the Digital Millennium Copyright Act of 1998 ("DMCA"). If you believe your copyrighted work has been infringed, you may submit a DMCA notice to our designated copyright agent at <legal@diaflow.io>, including:

(xlvii) a physical or electronic signature of the copyright owner or authorized representative;

(xlviii) identification of the copyrighted work;

(xlix) identification of the infringing material and its location;

(l) your contact information;

(li) a good faith statement that the use is not authorized; and

(lii) a statement under penalty of perjury that the information is accurate and you are authorized to act on behalf of the copyright owner.

Diaflow has adopted a policy of terminating, in appropriate circumstances, the accounts of repeat infringers.

### 5. Customer Responsibilities

#### (a) Acceptable Use Policy

You agree to comply with all terms of this Agreement, all applicable laws, and all guidelines, standards, and requirements posted on [www.diaflow.io](https://www.diaflow.io/) from time to time. The use restrictions set forth in Section 2(e) constitute the Acceptable Use Policy ("AUP") and are incorporated herein by reference.

#### (b) Account Responsibility

You are responsible and liable for all uses of the Services resulting from access provided by you, directly or indirectly, whether authorized or unauthorized. You are responsible for all acts and omissions of Authorized Users, and any breach by an Authorized User will be deemed a breach by you. You shall ensure all Authorized Users are aware of and comply with applicable provisions of this Agreement.

#### (c) Credentials Security

You are responsible for maintaining the confidentiality of all passwords, API keys, and access credentials associated with the Services. You shall not sell or transfer credentials to any unauthorized person. You must promptly notify Diaflow of any unauthorized access or suspected security breach.

#### (d) Third-Party Products

The Services may permit access to Third-Party Products, which are subject to their own terms and conditions. Diaflow does not endorse or assume responsibility for any Third-Party Products. You access Third-Party Products at your own risk. For information on how data flows to and from Third-Party Products, please refer to Section 5 (Sharing and Disclosure) and Section 12 (Third-Party Links and Integrations) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

### 6. Third-Party Integrations and Connected Accounts

#### (a) Connected Accounts and Authorization

The Services enable you to connect third-party applications, platforms, and services ("Connected Apps") through OAuth, API keys, access tokens, webhooks, or other authentication mechanisms. By connecting a Connected App to the Services, you expressly authorize Diaflow to access, retrieve, transmit, modify, and otherwise interact with data and functionality within that Connected App on your behalf, solely to the extent necessary to execute your configured workflows, automations, and agent tasks. You represent and warrant that you have all necessary rights, permissions, and authority to grant Diaflow such access and to use the Connected App in conjunction with the Services. For details on the types of data collected from Connected Apps, see Section 2.3 (Information from Third Parties) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (b) Customer Responsibility for Connected Apps

You are solely responsible for:

(liii) selecting and configuring the Connected Apps used within the Services;

(liv) ensuring that your use of Connected Apps through the Services complies with the respective third-party terms of service, acceptable use policies, API usage policies, rate limits, and any other applicable terms imposed by the Connected App provider;

(lv) maintaining valid and current API credentials, tokens, and authentication for each Connected App;

(lvi) reviewing and understanding the permissions and scopes granted when connecting a Connected App; and

(lvii) monitoring your usage to avoid exceeding rate limits, quotas, or usage thresholds imposed by Connected App providers.

#### (c) Data Flowing Through Integrations

Data transmitted between the Services and Connected Apps ("Integration Data") is subject to both this Agreement and the terms and privacy policies of the applicable Connected App provider. You acknowledge that:

(lviii) Diaflow acts as an intermediary facilitating data transfer and workflow execution between Connected Apps as directed by your configurations;

(lix) Diaflow does not independently verify, validate, or assume responsibility for the accuracy, legality, or appropriateness of Integration Data;

(lx) Integration Data may be processed and temporarily stored by Diaflow to the extent necessary to execute workflows, subject to the data security measures described in Section 9(c) and Section 7 (Data Security) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy); and

(lxi) you are solely responsible for ensuring that the transfer and processing of Integration Data complies with all applicable data protection laws, including obtaining any necessary consents from data subjects whose personal data may flow through integrations.

#### (d) No Guarantee of Third-Party Availability

Diaflow does not control and makes no representations or warranties regarding the availability, performance, reliability, security, or continued existence of any Connected App or its APIs. Connected App providers may, at any time and without notice to Diaflow:

(lxii) modify, deprecate, or discontinue their APIs or services;

(lxiii) change authentication requirements, rate limits, or data access scopes;

(lxiv) impose new fees or usage restrictions; or

(lxv) suspend or terminate Diaflow's or your access.

Diaflow shall not be liable for any disruption, data loss, workflow failure, or other impact arising from changes made by Connected App providers.

#### (e) Credential Security for Integrations

You are solely responsible for the security of all API keys, OAuth tokens, access credentials, and other authentication materials used to connect Connected Apps to the Services. You shall:

(lxvi) use the principle of least privilege when granting permissions and scopes;

(lxvii) regularly rotate credentials in accordance with security best practices;

(lxviii) immediately revoke and replace any credentials that may have been compromised; and

(lxix) promptly notify Diaflow of any suspected unauthorized access to your Connected Apps through the Services. Diaflow encrypts stored credentials using industry-standard encryption methods (as described in Section 7 (Data Security) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy)) but shall not be liable for unauthorized access resulting from your failure to maintain credential security.

#### (f) Workflow Execution and Automated Actions

You acknowledge that workflows and automations configured within the Services may perform actions in Connected Apps automatically and without further confirmation at the time of execution, including but not limited to creating, reading, updating, and deleting data; sending messages or communications; triggering processes; and invoking third-party APIs. You are solely responsible for:

(lxx) the design, configuration, and testing of all workflows before activation;

(lxxi) all actions performed by the Services in Connected Apps as a result of your workflow configurations;

(lxxii) any consequences arising from automated actions, including unintended data modifications, communications sent in error, or cascading effects across connected systems; and

(lxxiii) implementing appropriate safeguards, such as approval steps and error handling, within your workflows.

#### (g) Indemnification for Integration Use

Without limiting the general indemnification obligations in Section 11, you shall additionally defend, indemnify, and hold harmless Diaflow from and against any claims, damages, or liabilities arising from:

(lxxiv) your violation of any Connected App provider's terms of service or API usage policies;

(lxxv) unauthorized or improper use of third-party APIs through the Services;

(lxxvi) data breaches or privacy violations resulting from your integration configurations; or

(lxxvii) any third-party claims related to actions performed by the Services in Connected Apps pursuant to your workflow configurations.

### 7. Fees, Payment, and Credits

#### (a) Billing Policies

Certain aspects of the Services are provided for a fee. If you elect to use paid features, you agree to the Pricing and Payment Terms available at [www.diaflow.io/pricing](https://www.diaflow.io/pricing), as updated from time to time. Diaflow may add new services, features, or charges, and may amend fees for existing services, at any time in its sole discretion. Changes to pricing shall become effective in the billing cycle following at least thirty (30) days' notice to you.

#### (b) Credits and Usage

Diaflow allocates Credits to Customer Accounts based on the applicable plan tier. Credits are consumed when you use certain features of the Services, including AI workflow executions, agent interactions, and API calls. Credit allocation, consumption rates, and applicable limits are described in the Documentation and on the pricing page.

**Credit Types and Consumption Order**. The Services recognize three types of Credits: (a) Monthly Credits, which are obtained through your subscription and automatically refresh on the same calendar date each month based on your subscription start date; (b) Add-On Credits, which are purchased separately and expire twelve (12) months from the date of purchase; and (c) Free Credits, which are granted by Diaflow at its discretion (including through promotions, referral programs, or other initiatives) and expire twelve (12) months from the date of issuance. Credits are consumed in the following order of priority: Monthly Credits are consumed first, followed by Add-On Credits, and then Free Credits. This consumption order ensures that shorter-lived Credits are utilized before longer-lived Credits.

**Credit Expiration and Non-Accumulation**. Monthly Credits do not accumulate or roll over from one billing period to the next. Any unused Monthly Credits at the end of a billing cycle shall expire automatically and be forfeited without compensation, refund, or credit toward future billing periods. At the beginning of each new billing cycle, your Monthly Credit balance will be reset to the allocation specified by your then-current plan tier. Add-On Credits and Free Credits are not subject to monthly expiration but shall expire twelve (12) months from the date of purchase or issuance, respectively. Any unused Add-On Credits or Free Credits remaining after the twelve-month period shall be forfeited automatically without compensation or refund.

**Non-Combination of Credits Across Plans**. Credits are not transferable or combinable between plan tiers. Upon upgrading, downgrading, or otherwise changing your plan, only the Credit allocation associated with your new plan tier shall apply, effective as of the date the new plan becomes active. Any remaining Credits from your prior plan shall be forfeited and shall not be added to, combined with, or supplement the Credits allocated under the new plan. Diaflow shall not be liable for any loss of unused Credits resulting from a plan change.

**Modification of Basic Account Credits**. Diaflow reserves the right, in its sole and absolute discretion, to modify, reduce, increase, or otherwise adjust the number of Credits allocated to Basic (free-tier) accounts at any time and without prior notice to the Customer. Such modifications may include, but are not limited to, changes to the initial Credit allocation, periodic Credit refreshes, Credit consumption rates, and the types of features accessible using Credits. By using a Basic account, you acknowledge and agree that Credit allocations are subject to change at Diaflow's sole discretion, and that Diaflow shall have no obligation to provide advance notice of any such modifications. Continued use of the Services following any Credit modification constitutes your acceptance of the revised Credit terms. Diaflow shall not be liable for any loss, damage, or inconvenience arising from modifications to Credit allocations for Basic accounts.

#### (c) Refund Policy

You may cancel your Customer Account at any time. Refunds are subject to the following:

(lxxviii) Termination by Customer: No refunds shall be provided for voluntary cancellation. Your subscription will remain active until the end of the current billing period.

(lxxix) Termination by Diaflow for Customer Breach: No refund shall be provided where Diaflow terminates your account due to your violation of this Agreement.

(lxxx) Termination by Diaflow Without Cause: If Diaflow terminates your account for its own convenience or without cause, you shall be entitled to a pro-rata refund of any prepaid fees for the unused portion of the then-current subscription term.

(lxxxi) Credits: Unused Credits are non-refundable and non-transferable, except as expressly provided in an Enterprise agreement.

Where purchases are made through the Apple App Store or Google Play Store, refunds for such purchases are additionally subject to the applicable platform's refund policies and procedures, and may be requested directly through that platform in accordance with Section 4 (Warranty) of the Apple App Store Addendum or applicable Google Play policies, as relevant.

#### (d) Free Trials

We or our payment service providers may offer free trials. Upon expiration of a free trial, your payment method will be automatically charged for the applicable subscription fee unless you cancel before the trial ends. No notice of trial expiration will be provided.

#### (e) Automatic Renewal

IF YOU SUBSCRIBE TO A PAID PLAN, THE APPLICABLE FEES WILL AUTOMATICALLY RENEW ON A RECURRING BASIS UNLESS YOU CANCEL YOUR SUBSCRIPTION. CANCELLATION NOTICES MUST BE SUBMITTED THROUGH YOUR ACCOUNT SETTINGS OR IN WRITING TO [SUPPORT@DIAFLOW.IO](mailto:support@diaflow.io) AND WILL BE EFFECTIVE IN THE BILLING CYCLE FOLLOWING RECEIPT. YOU AUTHORIZE DIAFLOW OR ITS PAYMENT PROCESSOR TO CHARGE YOUR PAYMENT METHOD FOR RECURRING FEES AND APPLICABLE TAXES. WHERE YOU SUBSCRIBE THROUGH THE APPLE APP STORE OR GOOGLE PLAY STORE, CANCELLATION MUST INSTEAD BE MANAGED THROUGH YOUR APPLE ID OR GOOGLE ACCOUNT SETTINGS, IN ACCORDANCE WITH THE APPLICABLE PLATFORM'S SUBSCRIPTION MANAGEMENT TOOLS.

#### (f) Payment Information; Taxes

Payments for the Services are processed through Stripe or, where you access the Services via an application distributed through the Google Play Store or Apple App Store, through the payment processing system made available by the applicable platform (including Google Play Billing or Apple's in-app purchase system), as designated by Diaflow for that platform. By using the Services, you agree to be bound by the terms of the applicable payment processor, including Stripe's Services Agreement at <https://stripe.com/us/legal>, Google Play's Payments Policy, or Apple's Media Services Terms and Conditions, as applicable. All payment information must be accurate, complete, and current. You are responsible for all applicable taxes relating to your purchases and transactions. For details on how payment and financial data is processed and stored, see Section 2.1 (Information You Provide) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

### 8. Confidential Information

The receiving party shall not disclose the disclosing party's Confidential Information to any person or entity, except to employees, contractors, or advisors with a need to know who are bound by confidentiality obligations at least as protective as those herein. Either party may disclose Confidential Information to the limited extent required:

(lxxxii) to comply with a court order or applicable law, provided the receiving party: (A) promptly notifies the disclosing party in writing, to the extent not prohibited by law or court order; (B) reasonably cooperates with the disclosing party's efforts to seek a protective order or other appropriate remedy; and (C) discloses only that portion of Confidential Information that is legally required to be disclosed; or

(lxxxiii) to establish rights under this Agreement.

Obligations of non-disclosure are effective from the date of disclosure and expire five years thereafter, except for trade secrets, which remain protected for as long as they qualify as trade secrets under applicable law.

### 9. Data Protection and Privacy

#### (a) Privacy Policy

Diaflow processes personal data in accordance with its [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy). By using the Services, you acknowledge and accept our Privacy Policy as updated from time to time. The Privacy Policy provides comprehensive details on: (i) the categories of personal data collected (Section 2); (ii) purposes of processing (Section 3); (iii) AI-specific data practices including third-party AI provider data routing (Section 4); (iv) data sharing and disclosure (Section 5); (v) data retention periods (Section 6); (vi) security measures (Section 7); (vii) international data transfer safeguards (Section 8); and (viii) your privacy rights under GDPR, UK GDPR, CCPA/CPRA, and Singapore PDPA (Section 9). To the extent any provision of this Agreement conflicts with the Privacy Policy on matters of personal data processing, the Privacy Policy shall prevail.

#### (b) Data Processing

To the extent Diaflow processes personal data on your behalf as a data processor under applicable data protection laws (including the EU General Data Protection Regulation, the UK GDPR, and Singapore's Personal Data Protection Act), the parties shall enter into a Data Processing Agreement ("DPA") upon request. Customers may request a DPA by contacting <legal@diaflow.io>. Such DPA shall form part of this Agreement and shall include, at a minimum: (i) the subject matter, duration, nature, and purpose of processing; (ii) the types of personal data processed; (iii) the categories of data subjects; (iv) the obligations and rights of the controller and processor; and (v) sub-processor management procedures.

#### (c) Data Security

Diaflow implements and maintains commercially reasonable technical and organizational measures to protect Customer Content and personal data against unauthorized access, loss, or alteration, including encryption of data in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, regular security assessments, and incident response procedures. Details of our security practices are available at [compliance.diaflow.io/general/security-practices](https://compliance.diaflow.io/general/security-practices). See also Section 7 (Data Security) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (d) Data Breach Notification

In the event of a confirmed personal data breach (as defined under applicable data protection law) affecting Customer Content or personal data, Diaflow shall: (i) notify the affected Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach; (ii) provide reasonable details of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach; (iii) cooperate with Customer's own breach notification obligations under applicable law; and (iv) take commercially reasonable steps to contain and remediate the breach. Notification shall be delivered via the email address associated with the Customer Account and, where applicable, through in-app notification. Diaflow's notification obligations under this Section are in addition to, and do not limit, any obligations under applicable data protection law, including GDPR Articles 33 and 34, Singapore PDPA Section 26C, and applicable US state breach notification statutes. For information on Diaflow's incident response procedures, see Section 7 (Data Security) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (e) Data Retention and Deletion

Upon termination of this Agreement or your Customer Account, Diaflow will delete or anonymize Customer Content within thirty (30) days, unless a longer retention period is: (i) required by applicable law, regulation, or valid legal process; (ii) necessary to resolve pending disputes or enforce this Agreement; or (iii) required to maintain Aggregated Statistics in accordance with Section 2(f). During the thirty (30) day post-termination period, Customer may request an export of Customer Content in a machine-readable format through account settings or by contacting <support@diaflow.io>. After the thirty (30) day period, Diaflow shall have no obligation to retain or provide access to Customer Content. For active accounts, Diaflow retains Customer Content, including workflow execution logs, for the duration of the subscription term plus ninety (90) days. You may request deletion of specific Customer Content at any time through your account settings or by contacting <support@diaflow.io>, and Diaflow will process such requests within fifteen (15) business days, subject to the exceptions stated above. Specific retention periods for different data categories are set forth in Section 6 (Data Retention) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (f) International Data Transfers

The Services are operated from Singapore. If you are located outside Singapore, you acknowledge that your data may be transferred to, stored, and processed in Singapore or other jurisdictions where Diaflow or its sub-processors operate. Diaflow ensures appropriate safeguards for international transfers of personal data, including: (i) Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA; (ii) the UK International Data Transfer Agreement or UK Addendum to SCCs for transfers from the United Kingdom; (iii) data processing agreements with all sub-processors that include equivalent transfer safeguards; and (iv) compliance with the Personal Data Protection Act 2012 (Singapore) for transfers involving Singapore residents. For further details, see Section 8 (International Data Transfers) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (g) Data Portability and Workflow Export

You have the right to export your data from the Services at any time during the Term. Diaflow provides export functionality that enables you to retrieve:

(lxxxiv) Customer Content, including data inputs and outputs processed through the Services;

(lxxxv) workflow definitions and configurations, including trigger conditions, action sequences, branching logic, and node parameters, in a structured, commonly used, and machine-readable format (such as JSON);

(lxxxvi) agent configurations, including prompt templates, tool bindings, and behavioral parameters;

(lxxxvii) integration mappings, including Connected App configurations (excluding third-party credentials and tokens, which remain subject to the applicable Connected App provider's terms); and

(lxxxviii) execution history and logs, subject to the retention periods set forth in Section 9(e).

Diaflow shall make commercially reasonable efforts to maintain export formats that facilitate portability and interoperability. Export functionality is accessible through the Services' user interface and, where applicable, through the API. Upon termination of this Agreement, the export rights described in this section remain available during the thirty (30) day post-termination period specified in Section 9(e). These export rights are in addition to, and do not limit, your data portability rights under applicable data protection law as described in Section 9 (Your Privacy Rights) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy).

#### (h) Your Privacy Rights

Depending on your jurisdiction, you may have rights with respect to your personal data, including rights of access, rectification, erasure, restriction, portability, and objection, as well as the right to withdraw consent and the right to lodge a complaint with a supervisory authority. These rights are described in detail in Section 9 (Your Privacy Rights) of our [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy). To exercise any privacy right, contact <privacy@diaflow.io>. Diaflow will respond within the timeframe required by applicable law (typically 30 days).

### 10. Warranty Disclaimer

THE SERVICES, INCLUDING ALL AI-POWERED FEATURES AND OUTPUTS, ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DIAFLOW DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AND THOSE ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. DIAFLOW DOES NOT WARRANT THAT: (A) THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE; (B) AI-GENERATED OUTPUTS WILL BE ACCURATE, COMPLETE, OR FIT FOR ANY PURPOSE; (C) DEFECTS WILL BE CORRECTED; OR (D) THE SERVICES ARE FREE OF VIRUSES OR HARMFUL COMPONENTS. YOUR USE OF THE SERVICES AND RELIANCE ON ANY AI-GENERATED OUTPUTS IS AT YOUR SOLE RISK.

Where you access the Services through a Licensed Application distributed via the Apple App Store, the warranty terms of Section 4 (Warranty) of the Apple App Store Addendum shall apply in addition to this Section 10.

### 11. Indemnification

#### (a) By Customer

You shall defend, indemnify, and hold harmless Diaflow and its subsidiaries, affiliates, officers, directors, employees, contractors, agents, and licensors from and against any claims, damages, obligations, losses, liabilities, costs, or expenses (including reasonable attorneys' fees) arising from:

(lxxxix) your use of the Services;

(xc) your violation of this Agreement;

(xci) your violation of any third-party right, including Intellectual Property Rights or privacy rights;

(xcii) your violation of any applicable law;

(xciii) Customer Content, including AI-generated outputs derived from your inputs;

(xciv) your willful misconduct; or

(xcv) any third party's access to the Services using your credentials.

#### (b) By Diaflow

Diaflow's indemnification obligations with respect to Intellectual Property Rights are set forth in Section 4(f). In addition, Diaflow shall defend, indemnify, and hold harmless Customer from and against any third-party claims arising directly from Diaflow's gross negligence or willful misconduct in the provision of the Services, and shall pay any final judgment or approved settlement arising therefrom.

#### (c) Indemnification Procedures

The indemnified party shall: (i) promptly notify the indemnifying party in writing of any claim (provided that failure to provide prompt notice shall not relieve the indemnifying party of its obligations except to the extent materially prejudiced); (ii) grant the indemnifying party sole control of the defense and settlement of such claim; and (iii) provide reasonable cooperation at the indemnifying party's expense. The indemnifying party shall not settle any claim in a manner that imposes obligations on the indemnified party or admits fault on behalf of the indemnified party without the indemnified party's prior written consent.

### 12. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT WILL DIAFLOW BE LIABLE FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, ENHANCED, OR PUNITIVE DAMAGES; LOST PROFITS, REVENUES, BUSINESS, OR GOODWILL; LOSS OR CORRUPTION OF DATA; COST OF REPLACEMENT GOODS OR SERVICES; OR ANY DAMAGES ARISING FROM AI-GENERATED OUTPUTS, INCLUDING INACCURATE, INCOMPLETE, OR HARMFUL AI OUTPUTS, REGARDLESS OF WHETHER DIAFLOW WAS ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

DIAFLOW'S AGGREGATE LIABILITY UNDER THIS AGREEMENT SHALL NOT EXCEED THE GREATER OF: (A) THE TOTAL AMOUNTS PAID BY CUSTOMER TO DIAFLOW IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM; OR (B) FIFTY US DOLLARS (US$50.00). THIS LIMITATION APPLIES REGARDLESS OF THE LEGAL THEORY, INCLUDING CONTRACT, TORT, NEGLIGENCE, OR STRICT LIABILITY.

THE FOREGOING LIMITATIONS SHALL NOT APPLY TO: (A) EITHER PARTY'S INDEMNIFICATION OBLIGATIONS UNDER SECTIONS 4(f), 6(g), AND 11; (B) EITHER PARTY'S BREACH OF SECTION 8 (CONFIDENTIAL INFORMATION); (C) CUSTOMER'S PAYMENT OBLIGATIONS; OR (D) DAMAGES ARISING FROM EITHER PARTY'S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT.

Some jurisdictions do not allow the exclusion or limitation of certain damages. In such jurisdictions, the above limitations apply to the fullest extent permitted by applicable law.

### 13. Service Levels, Uptime, and Scheduled Maintenance

#### (a) Uptime Commitment

Diaflow shall use commercially reasonable efforts to maintain the availability of the Services at a rate of at least ninety-nine point nine percent (99.9%) uptime per calendar month, measured as the total number of minutes in the month minus the number of minutes of Downtime, divided by the total number of minutes in the month ("Uptime Percentage"). "Downtime" means any period during which the Services are materially unavailable or materially degraded for all or substantially all customers, as measured by Diaflow's monitoring systems. Downtime does not include:

(xcvi) Scheduled Maintenance as defined in Section 13(b);

(xcvii) unavailability caused by factors outside Diaflow's reasonable control, including Force Majeure events described in Section 15(h);

(xcviii) unavailability resulting from Customer's equipment, software, network connections, or other infrastructure;

(xcix) unavailability caused by third-party services, Connected Apps, or third-party AI model providers;

(c) unavailability resulting from Customer's actions or inactions in violation of this Agreement; or

(ci) brief periods of degradation lasting less than five (5) consecutive minutes.

#### (b) Service Credits

If the Services fail to meet the Uptime Percentage target in any calendar month, Customer shall be eligible for Service Credits as follows:

| Monthly Uptime Percentage | Service Credit (% of Monthly Fee) |
| ------------------------- | --------------------------------- |
| < 99.9% but ≥ 99.5%       | 10%                               |
| < 99.5% but ≥ 99.0%       | 15%                               |
| < 99.0% but ≥ 98.0%       | 20%                               |
| < 98.0% but ≥ 97.0%       | 25%                               |
| < 97.0%                   | 30%                               |

Service Credits are calculated as a percentage of the monthly fees actually paid by Customer for the affected calendar month. To receive Service Credits, Customer must submit a written request to <support@diaflow.io> within thirty (30) days of the end of the affected month, identifying the dates and times of the claimed Downtime. Diaflow will verify the claim against its monitoring data and, if validated, apply the Service Credit to Customer's next billing cycle. Service Credits are Customer's sole and exclusive remedy for Diaflow's failure to meet the Uptime Percentage. Service Credits may not be redeemed for cash, may not be transferred, and shall not exceed thirty percent (30%) of the applicable monthly fee in any given month. Service Credits expire if not claimed within ninety (90) days of the affected month.

#### (c) Scheduled Maintenance

Diaflow may perform scheduled or unscheduled maintenance on the Services to ensure the security, stability, and performance of the platform. Diaflow shall use commercially reasonable efforts to: (i) provide at least forty-eight (48) hours' advance notice of scheduled maintenance through in-app notifications or email; (ii) schedule routine maintenance during off-peak hours (between 00:00 and 06:00 SGT on weekdays, or during weekends) to the extent practicable; and (iii) minimize the duration and frequency of maintenance windows. Emergency maintenance required to address security vulnerabilities, critical bugs, or infrastructure failures may be performed without advance notice. Scheduled and emergency maintenance periods are excluded from Downtime calculations for purposes of the Uptime Percentage in Section 13(a).

#### (d) Incident Communication

During incidents resulting in material Downtime, Diaflow shall use commercially reasonable efforts to provide periodic updates through in-app notifications, email to affected account owners, or such other communication channels as Diaflow may designate. For incidents exceeding thirty (30) minutes, Diaflow shall notify affected account owners via email. Following resolution of any incident resulting in more than sixty (60) minutes of Downtime, Diaflow shall publish a post-incident summary within five (5) business days. Diaflow shall maintain a publicly accessible status page providing real-time information regarding the operational status of the Services.

#### (e) SLA for Enterprise Customers

Enterprise-tier customers may negotiate enhanced service level commitments, including custom uptime guarantees (up to 99.99%), dedicated support response times, priority incident escalation, and enhanced service credit arrangements, pursuant to a separate Enterprise Service Level Agreement. Such Enterprise SLA, if executed, shall supersede the applicable provisions of this Section 13 to the extent of any conflict.

### 14. Governing Law, Arbitration, and Class Action/Jury Trial Waiver

#### (a) Governing Law

This Agreement shall be governed by and construed in accordance with the laws of the Republic of Singapore, without regard to its conflict of laws principles. The application of the United Nations Convention on Contracts for the International Sale of Goods is expressly excluded. You agree to submit to the exclusive personal jurisdiction of the courts of Singapore for any actions not subject to arbitration.

#### (b) Arbitration

Any dispute, controversy, or claim arising out of or relating to this Agreement or the Services shall be resolved by binding arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the SIAC Rules then in effect. The arbitration shall be conducted in Singapore in English before a single arbitrator. Judgment on the arbitral award may be entered in any court of competent jurisdiction.

You may opt out of this Arbitration Agreement within thirty (30) days of accepting this Agreement by emailing <legal@diaflow.io> with your name and a clear statement of your intent to opt out. Opting out does not affect any other provision of this Agreement.

Before initiating arbitration, you agree to first contact Diaflow at <support@diaflow.io> and attempt to resolve the dispute informally for at least sixty (60) days.

#### (c) Jurisdictional Consumer Protections

Notwithstanding the foregoing, if you are a consumer residing in the European Economic Area, the United Kingdom, or any other jurisdiction whose mandatory consumer protection laws prohibit the enforcement of foreign arbitration clauses, the mandatory arbitration and class action waiver provisions of this Section 14 shall not apply to you, and disputes shall be resolved in the courts of your country of residence in accordance with applicable mandatory consumer protection law.

#### (d) Class Action/Jury Trial Waiver

ALL CLAIMS MUST BE BROUGHT IN THE PARTIES' INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, COLLECTIVE, OR REPRESENTATIVE PROCEEDING. THE ARBITRATOR MAY NOT CONSOLIDATE MORE THAN ONE PERSON'S CLAIMS. YOU AND DIAFLOW EACH WAIVE THE RIGHT TO A TRIAL BY JURY AND THE RIGHT TO PARTICIPATE IN A CLASS ACTION.

### 15. Miscellaneous

#### (a) Entire Agreement

This Agreement, together with the [Privacy Policy](https://compliance.diaflow.io/general/privacy-policy), the Apple App Store Addendum (where applicable), any applicable DPA, and any additional agreements entered into through the Services, constitutes the entire agreement between you and Diaflow concerning the Services and supersedes all prior agreements and understandings.&#x20;

#### (b) Modifications

Diaflow may modify this Agreement from time to time. We will notify you of material modifications through email or a prominent notice within the Services at least thirty (30) days before the changes take effect. Your continued use of the Services after the effective date of such modifications constitutes acceptance of the modified terms. If you do not agree to the modified terms, you may terminate this Agreement before the effective date of the changes.

#### (c) Severability

If any provision of this Agreement is found invalid or unenforceable, the remaining provisions shall remain in full force and effect. The invalid provision shall be modified to the minimum extent necessary to make it valid and enforceable while preserving the parties' original intent.

#### (d) Export Compliance

The Services may be subject to Singapore export control laws, including the Strategic Goods (Control) Act. You shall not export, re-export, or make the Services accessible from any jurisdiction in violation of applicable export laws. You shall obtain all necessary permits and approvals before any cross-border transfer.

#### (e) No Waiver

No failure or delay by Diaflow in exercising any right under this Agreement shall constitute a waiver of that right or any other right.

#### (f) Notices

Notices to Diaflow must be sent to: Diaflow Pte. Ltd., 114 Lavender Street, #11-83, CT Hub 2, Singapore 338729, or to <legal@diaflow.io>. Notices must be delivered in person, by certified mail, or by recognized courier service. Diaflow may provide notices to you electronically through the email address associated with your account or through the Services.

#### (g) Assignment

This Agreement is personal to you and may not be assigned or transferred without Diaflow's prior written consent. Diaflow may assign this Agreement or delegate its obligations without restriction, provided that the assignee agrees to be bound by the terms of this Agreement.

#### (h) Force Majeure

Neither party shall be liable for any failure or delay in performance to the extent caused by circumstances beyond its reasonable control ("Force Majeure Event"), including but not limited to: natural disasters (earthquakes, floods, hurricanes, volcanic eruptions); acts of government, sanctions, embargoes, or regulatory changes; pandemic, epidemic, or public health emergencies; war, armed conflict, terrorism, civil unrest, or acts of sabotage; labor disputes, strikes, or lockouts; power outages, electrical grid failures, or energy shortages; internet backbone failures, telecommunications outages, DNS failures, or distributed denial-of-service attacks; failures, outages, deprecations, or material changes to third-party services, including Connected App APIs, cloud infrastructure providers (such as AWS, Google Cloud, or Azure), third-party AI model providers, payment processors, and other upstream service dependencies; cyberattacks, ransomware, or security incidents affecting Diaflow's infrastructure or that of its critical vendors; or any other event of similar nature beyond the reasonable control of the affected party.

The affected party shall: (i) promptly notify the other party in writing of the Force Majeure Event and its expected duration; (ii) use commercially reasonable efforts to mitigate the impact of the Force Majeure Event; and (iii) resume performance as soon as reasonably practicable after the Force Majeure Event ceases. If a Force Majeure Event continues for more than sixty (60) consecutive days, either party may terminate this Agreement upon written notice to the other party, and such termination shall not give rise to any liability other than the obligation to pay fees accrued prior to the termination date and, where applicable, the pro-rata refund obligations set forth in Section 7(c). For the avoidance of doubt, outages or performance degradations of Connected Apps or third-party AI model providers that affect workflow execution through the Services shall be treated as Force Majeure Events, and Diaflow shall have no liability for failed, delayed, or incomplete workflow executions resulting therefrom.

#### (i) Contact

For questions regarding this Agreement, please contact us at <legal@diaflow.io>. For privacy-related inquiries, please contact <privacy@diaflow.io>. For data protection inquiries specific to the European Union, you may also contact our EU representative through the contact details above.


# Privacy Policy

## 1. Introduction

Welcome to Diaflow ("we," "us," "our"). Diaflow is an AI-native workflow automation platform operated by Diaflow Pte. Ltd. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at <https://diaflow.io>, use our platform at <https://platform.diaflow.app>, our APIs, AI agents, integrations, or any related services (collectively, the "Services").

By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree, please discontinue use of the Services.

## 2. Information We Collect

### 2.1 Information You Provide

We may collect the following personal data that you voluntarily provide:

* Identity Data: first name, last name, username, or similar identifier.
* Contact Data: email address, phone number, billing address, and business address.
* Account Data: login credentials (hashed and encrypted), account preferences, and profile information.
* Financial Data: payment card details, billing information, and transaction records (processed via third-party payment processors).
* User Content: workflow configurations, prompts, templates, agent configurations, and any data you submit through the platform.
* Communication Data: messages, feedback, support tickets, and correspondence with our team.

### 2.2 Information Collected Automatically

When you access our Services, we automatically collect certain data:

* Technical Data: IP address, browser type and version, time zone setting, operating system, device identifiers, and platform information.
* Usage Data: pages visited, features used, workflow execution logs, click patterns, session duration, referring URLs, and interaction data.
* AI Interaction Data: prompts submitted to AI agents, model outputs, execution metadata, and performance metrics related to workflow automations.
* Cookies and Tracking Technologies: we use cookies, web beacons, pixels, and similar technologies to collect analytics data and improve user experience.

### 2.3 Information from Third Parties

We may receive data from third-party sources, including:

* Authentication providers (e.g., Google, GitHub) when you use single sign-on (SSO).
* Third-party integrations that you connect to your Diaflow workflows.
* Business partners, resellers, and marketplace platforms (e.g., AppSumo).
* Publicly available sources and data enrichment services.

## 3. How We Use Your Information

We use your personal data for the following purposes:

* Service Delivery: to create and manage your account, provide and maintain our Services, execute workflows, and process transactions.
* AI Processing: to operate AI agents, process prompts, execute automations, and deliver intelligent workflow outputs on your behalf.
* Product Improvement: to analyze usage patterns, improve platform features, and develop new capabilities.
* Communication: to send account notifications, service updates, security alerts, technical notices, and respond to your inquiries.
* Marketing: to send promotional communications (with your consent where required), personalize content, and measure campaign effectiveness.
* Security and Fraud Prevention: to detect and prevent unauthorized access, abuse, and fraudulent activity.
* Legal Compliance: to comply with applicable laws, regulations, legal processes, and enforceable governmental requests.
* Credit and Usage Tracking: to manage platform credits, monitor resource consumption, enforce usage limits, and process billing.

## 4. AI-Specific Data Practices

As an AI-native platform, Diaflow processes data through large language models (LLMs) and autonomous AI agents. The following practices apply:

* Prompt Data: prompts and inputs you provide to AI agents are processed to generate outputs. We do not use your proprietary prompts to train our models without your explicit consent.
* Workflow Execution Data: data processed during workflow executions is handled according to the data handling settings of your workspace and subscription tier.
* Third-Party AI Providers: Diaflow may route AI processing through third-party LLM providers (e.g., OpenAI, Anthropic, Google). Data sent to these providers is subject to their respective privacy policies and data processing agreements.
* Data Retention for AI: AI interaction data is retained only as long as necessary to provide the Services and may be anonymized for aggregate analytics.

## 5. Sharing and Disclosure of Information

We do not sell your personal data. We may share your information in the following circumstances:

* Service Providers: with trusted third-party vendors who perform services on our behalf, including cloud hosting, payment processing, analytics, email delivery, and customer support.
* AI Model Providers: with third-party AI/LLM providers to process your workflow requests, subject to data processing agreements.
* Integration Partners: when you connect third-party services to your workflows, data is shared as necessary to execute those integrations.
* Business Transfers: in connection with any merger, acquisition, reorganization, asset sale, or financing, your data may be transferred as a business asset.
* Legal Requirements: when required by law, regulation, court order, or governmental authority, or when necessary to protect our rights, safety, or property.
* With Your Consent: in any other circumstances where you provide explicit consent.

## 6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods include:

* Account data: retained for the duration of your account and for a reasonable period thereafter for legal and audit purposes.
* Workflow execution data: retained according to your subscription tier settings and workspace configuration.
* Financial records: retained as required by applicable tax and accounting regulations.
* AI interaction logs: retained for up to 90 days for service quality and debugging, unless you configure a shorter period.

Upon account deletion, we will delete or anonymize your personal data within 30 days, except where retention is required by law.

## 7. Data Security

We implement industry-standard technical and organizational measures to protect your personal data, including:

* Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
* Regular security assessments, penetration testing, and vulnerability scanning.
* Role-based access controls and principle of least privilege.
* Secure development practices and code review processes.
* Incident response and breach notification procedures.

For more information, you can learn more at: <https://compliance.diaflow.io/general/security-practices>

While we strive to protect your data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.

## 8. International Data Transfers

Diaflow is headquartered in Singapore and operates globally with presence in the United States, European Union, and Vietnam. Your data may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards for international transfers through:

* Standard Contractual Clauses (SCCs) approved by the European Commission.
* Data processing agreements with all sub-processors.
* Compliance with applicable data transfer frameworks and regulations.

## 9. Your Privacy Rights

### 9.1 General Rights

Depending on your jurisdiction, you may have the following rights:

* Access: request a copy of the personal data we hold about you.
* Rectification: request correction of inaccurate or incomplete data.
* Erasure: request deletion of your personal data, subject to legal retention requirements.
* Restriction: request that we limit how we process your data.
* Portability: request your data in a structured, machine-readable format.
* Objection: object to processing based on legitimate interests or for direct marketing.
* Withdraw Consent: where processing is based on consent, you may withdraw it at any time.

### 9.2 European Economic Area and United Kingdom

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR) and UK GDPR, including the right to lodge a complaint with your local supervisory authority.

### 9.3 California Residents

California residents have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete, and the right to opt out of the sale or sharing of personal information. We do not sell personal information.

### 9.4 Exercising Your Rights

To exercise any of your privacy rights, please contact us at <support@diaflow.io>. We will respond to your request within the timeframe required by applicable law (typically 30 days).

## 10. Cookies and Tracking Technologies

We use the following types of cookies and similar technologies:

* Essential Cookies: required for core platform functionality, authentication, and security.
* Analytics Cookies: help us understand how users interact with our Services to improve performance and features.
* Marketing Cookies: used to deliver relevant advertisements and measure campaign effectiveness.

You can manage cookie preferences through your browser settings or our cookie consent banner. Disabling certain cookies may affect platform functionality.

## 11. Children’s Privacy

Our Services are not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child under 16, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us immediately.

## 12. Third-Party Links and Integrations

Our Services may contain links to or integrations with third-party websites, applications, and services. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party service before providing your data.

## 13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by:

* Posting the updated policy on our website with a revised effective date.
* Sending an email notification to registered users for significant changes.
* Displaying an in-platform notification upon your next login.

Your continued use of the Services after any changes constitutes your acceptance of the updated Privacy Policy.

## 14. Google API Data Practices

This section specifically governs how Diaflow accesses, uses, stores, and protects data obtained through Google APIs and Google user accounts, in accordance with Google’s API Services User Data Policy.

### 14.1 Data Accessed

When you connect your Google account to Diaflow, our application may access the following types of Google user data, depending on the integrations and workflows you configure:

* Google Account Profile: name, email address, and profile picture (via Google OAuth/SSO).
* Gmail Data: email messages, metadata, labels, and drafts (only when you explicitly enable Gmail integration in a workflow).
* Google Calendar: calendar events, attendees, and scheduling information (only when you explicitly enable Google Calendar integration in a workflow).
* Google Drive: files, folders, documents, and spreadsheets (only when you explicitly enable Google Drive integration in a workflow).
* Google Sheets & Docs: spreadsheet and document content for reading and writing (only when you explicitly enable these integrations in a workflow).

We request only the minimum scopes necessary to perform the functions you have enabled. You may review and revoke granted permissions at any time via your Google Account settings at myaccount.google.com.

### 14.2 Data Usage

Google user data accessed through our integrations is used exclusively to provide the specific workflow automation functionality you have requested. In particular:

* Google data is processed solely to execute the automations and AI workflows you configure within Diaflow.
* We do not use Google user data to train AI or machine learning models, develop new products or features, target advertising, or for any purpose unrelated to the specific service you requested.
* Google data is not read, analyzed, or used by humans except as needed to provide or improve user-facing features or as required by law, and only with your explicit permission.
* Our use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

### 14.3 Data Sharing

We do not sell, rent, or share Google user data with third parties for advertising, marketing, or any other commercial purpose. Google user data may be shared only in the following limited circumstances:

* Infrastructure & Hosting Providers: data may be processed by our cloud infrastructure providers (e.g., AWS) strictly to operate and deliver our Services, under data processing agreements that prohibit independent use of your data.
* AI Model Providers: where you have configured an AI workflow that processes Google data, that data may be passed to third-party LLM providers (e.g., OpenAI, Anthropic, Google) solely to execute your requested automation. These providers are bound by their own privacy policies and data processing agreements.
* Legal Requirements: when required by applicable law, court order, or governmental authority.

In all cases, third parties receiving Google user data are contractually prohibited from using that data for purposes other than providing services to Diaflow.

### 14.4 Data Storage & Protection

Google user data is protected using industry-standard security measures consistent with our overall data security practices described in Section 7, and additionally:

* Encryption: all Google user data is encrypted in transit using TLS 1.2 or higher, and encrypted at rest using AES-256.
* OAuth Token Security: OAuth tokens used to access Google APIs are stored securely with encryption and are never exposed in logs or to unauthorized personnel.
* Access Controls: access to Google user data is restricted to authorized personnel and systems on a need-to-know basis, enforced through role-based access controls.
* Security Audits: we conduct regular security assessments and vulnerability scanning to protect all user data, including Google user data. Diaflow maintains SOC 2 Type 2 certification.

### 14.5 Data Retention & Deletion

Google user data is retained only for as long as necessary to provide the service you have requested and as described below:

* Workflow Execution Data: Google user data processed during workflow executions is retained for up to 90 days in execution logs, after which it is automatically deleted or anonymized.
* OAuth Tokens: OAuth access tokens and refresh tokens are deleted immediately upon disconnecting your Google account from Diaflow or upon account deletion.
* Account Deletion: upon deleting your Diaflow account, all Google user data associated with your account will be permanently deleted within 30 days.

To request deletion of your Google user data at any time, you may: (1) disconnect your Google account within your Diaflow workspace settings or (2) delete your Diaflow account entirely.

## 15. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

**Diaflow Pte. Ltd.**

114 Lavender Street, #11-83, CT-Hub 2, Singapore (338729)

Email: <support@diaflow.io>

Website: <https://diaflow.io>

&#x20;

For data protection inquiries specific to the European Union, you may also contact our EU representative through the contact details above.


# Security Practices

Diaflow is committed to protecting your data with enterprise-grade security. We are **SOC 2 Type II certified**, **HIPAA compliant**, and **GDPR compliant**, ensuring that your workflows, AI agents, and data meet the highest standards of security, availability, and privacy.

You can view our certifications and compliance status in real time on our [Trust Portal](https://trust.diaflow.io/).

If you have additional questions regarding security, please contact <security@diaflow.io> and we will respond promptly.

### 1. Compliance & Certifications

View our live compliance status and request documentation via the [Diaflow Trust Portal](https://trust.diaflow.io/).

#### SOC 2 Type II

Diaflow has achieved SOC 2 Type II certification, audited by an independent third-party firm. Unlike Type I (a point-in-time snapshot), SOC 2 Type II evaluates the **operational effectiveness** of our security controls over a continuous observation period (minimum 3 months). This certification covers the Trust Services Criteria for Security, Availability, and Confidentiality.

Our SOC 2 Type II report is available to customers and prospects under NDA. You can request a copy through our [Trust Portal](https://trust.diaflow.io/) or by contacting <security@diaflow.io>.

#### HIPAA

Diaflow is HIPAA compliant, enabling healthcare organizations and business associates to use our platform for workflows involving Protected Health Information (PHI). Our HIPAA program includes:

* Administrative, technical, and physical safeguards aligned with the HIPAA Security Rule
* Business Associate Agreements (BAAs) available for qualifying customers
* Encryption of PHI both in transit (TLS 1.2+) and at rest (AES-256)
* Access controls and audit logging for all PHI interactions
* Workforce training on HIPAA requirements
* Incident response procedures specific to PHI breaches

#### GDPR

Diaflow is fully compliant with the General Data Protection Regulation (GDPR). We serve as a Data Processor on behalf of our customers (Data Controllers) and uphold the following commitments:

* **Lawful Basis for Processing**: We process personal data only as instructed by our customers
* **Data Processing Agreement (DPA)**: Available to all customers upon request
* **Data Subject Rights**: We support customers in fulfilling data subject access, rectification, erasure, and portability requests
* **Cross-Border Data Transfers**: Transfers outside the EEA are governed by Standard Contractual Clauses (SCCs) or equivalent safeguards
* **Data Protection Officer**: Designated contact for GDPR-related inquiries
* **Breach Notification**: We notify affected customers within 72 hours of becoming aware of a personal data breach, in line with Article 33

### 2. Hosting, Architecture & Infrastructure

#### Cloud Infrastructure

Diaflow's cloud-based services run on a multi-tenant architecture hosted by **Amazon Web Services (AWS)**. Our infrastructure is designed to segregate and restrict access to customer workspaces, workflows, and AI agent configurations. AWS provides foundational security controls, and information about their security posture is available at the [AWS Security website](https://aws.amazon.com/security/) and [AWS Compliance website](https://aws.amazon.com/compliance/).

Key infrastructure controls include:

* Multi-availability zone deployments for high availability
* Virtual private cloud (VPC) isolation with strict network segmentation
* Infrastructure-as-code for consistent, auditable environment provisioning
* Immutable infrastructure patterns to reduce configuration drift

#### Database, Query & Workflow Configurations

You and your users may submit data and content to your Workspace — for example by querying a database, configuring AI agents, or automating workflows. You have the option to build and use Workspaces without connecting them to any external database, or alternatively, connect to your own databases, third-party databases, or databases hosted by Diaflow.

#### Storage of Data

When you connect a Workspace to a Diaflow-hosted database, your data is stored using AWS infrastructure with encryption at rest. When you connect to your own database or a third party's, Diaflow **may or may not store your data**but rather proxies requests and applies credentials server-side. This architecture prevents end-user browsers from requiring direct database access, eliminating the need to provision individual user credentials and reducing credential exposure risk.

When query or workflow caching is enabled, Diaflow temporarily stores data for the cache duration you configure. You can clear the cache or disable caching entirely at any time.

### 3. Confidentiality & Security Controls

#### Confidentiality

Diaflow enforces strict controls over employee access to customer Workspaces and associated data. Access is limited to personnel who require it for operational purposes (e.g., troubleshooting a reported issue), and all such access is subject to:

* Principle of least privilege enforcement
* Role-based access controls (RBAC)
* Comprehensive audit logging of all access events
* Mandatory confidentiality agreements for all employees and contractors

#### Data Encryption

Diaflow uses industry-standard encryption for data protection:

* **In Transit**: TLS 1.2 or higher for all data transmissions. We support the latest recommended cipher suites and actively deprecate weak protocols.
* **At Rest**: AES-256 encryption for all stored data, including database backups and logs.
* Encryption keys are managed through AWS Key Management Service (KMS) with automatic key rotation.

#### Access Management

* **Multi-Factor Authentication (MFA)**: Required for all Diaflow internal systems and available for customer accounts.
* **Single Sign-On (SSO)**: Enterprise SSO via SAML 2.0 and OpenID Connect.
* **Session Management**: Configurable session timeout policies and the ability for administrators to remotely revoke user sessions.
* **Granular Permissions**: Role-based access controls enabling administrators to define precise access levels per user or team.

#### Network Security

* Firewalls configured per industry best practices using AWS Security Groups
* Network segmentation between production, staging, and development environments
* Real-time intrusion detection and prevention systems (IDS/IPS)
* DDoS protection via AWS Shield
* All server access requires two-factor authentication
* Continuous network monitoring and alerting 24/7

#### Host & Endpoint Security

* Automated vulnerability scanning and malware detection on all production hosts and employee endpoints
* Mandatory full disk encryption on all company devices
* Enforced screen lock policies
* Centralized endpoint management with remote wipe capabilities
* Prompt triage and remediation of identified vulnerabilities

#### Application Security

* Security review process for all new features, significant functionality changes, and design modifications
* Automated static analysis (SAST) and dynamic analysis (DAST) integrated into the CI/CD pipeline
* Mandatory peer code review before production deployment
* Regular penetration testing by external security firms
* Dependency vulnerability scanning with automated alerts
* Security bug bounty program enabling security researchers worldwide to report vulnerabilities

#### AI-Specific Security Controls

Given Diaflow's AI-native architecture, we implement additional controls specific to AI and agentic workflows:

* **Model Data Isolation**: Customer data used within AI agent workflows is logically isolated and not used to train models for other customers
* **Prompt & Output Logging**: Configurable audit trails for AI agent interactions, supporting compliance requirements
* **Third-Party LLM Governance**: When workflows connect to third-party LLM providers, Diaflow enforces data handling policies and supports customer-managed API keys to maintain data sovereignty
* **Agent Permission Boundaries**: AI agents operate within defined permission scopes set by workspace administrators

### 4. Business Continuity & Disaster Recovery

#### Reliability & Availability

Diaflow is designed for high availability with fault-tolerant infrastructure across multiple AWS Availability Zones. Our operations team maintains 24/7 on-call coverage and regularly tests disaster recovery procedures.

* **Uptime Target**: 99.9% availability SLA for enterprise plans
* **Automated Failover**: Multi-AZ deployment ensures automatic failover in case of infrastructure failure
* **Regular DR Testing**: Disaster recovery plans are tested at least quarterly

#### Backup & Recovery

* Automated daily backups of all customer data, Workspaces, and source code
* Backups stored redundantly across multiple geographic locations
* 7-day backup retention with the ability to restore from any point
* Backup integrity verified through full restoration testing at least every 90 days
* Recovery Time Objective (RTO) and Recovery Point Objective (RPO) documented and tested

### 5. Incident Management

Diaflow maintains comprehensive security incident management policies and procedures, aligned with SOC 2, HIPAA, and GDPR requirements:

* **Detection**: 24/7 automated monitoring with real-time alerting for anomalous or suspicious activity
* **Response**: Defined incident response plan with escalation procedures and designated incident commanders
* **Notification**: Customers are notified without undue delay of any unauthorized disclosure of their data, typically via email. For HIPAA-covered incidents, notification timelines comply with the Breach Notification Rule. For GDPR-covered incidents, notification occurs within 72 hours.
* **Post-Incident Review**: Root cause analysis and corrective action plans documented for all material incidents

### 6. Monitoring, Auditing & Logging

#### Security Audits

Diaflow undergoes regular security assessments, including:

* Annual SOC 2 Type II audits by independent third-party firms
* Periodic penetration testing by external security consultants
* Continuous automated scanning of our web platform and APIs
* Internal security reviews facilitated by the security team

#### Intrusion Detection & Monitoring

* All Diaflow services and endpoints are monitored continuously
* Endpoint detection and response (EDR) with malware and anomaly detection
* Cloud environment logs monitored and alerted 24/7
* Manual log review at minimum every 90 days
* Centralized logging environment capturing security, access, availability, and performance metrics

#### Audit Logging

Detailed audit logs are available on-demand for customer review, including:

* Account sign-in events with device type and IP address
* Workflow execution history
* Data access and modification events
* Administrative actions and permission changes
* AI agent interaction logs (configurable)

### 7. Data Lifecycle Management

#### Data Portability

During the term of a subscription, administrators can import and export Workflows in JSON format. Technical constraints may apply to subsequent compatibility and utility.

#### Data Retention & Return

Within 30 days of contract termination, you may request the return of your Workspace data stored by Diaflow (to the extent not already deleted by you).

#### Data Deletion

Administrators can delete Workflows and all associated Workspace data at any time during the subscription term:

* **Hard Deletion**: Within 24 hours of administrator-initiated deletion, data is removed from production systems
* **Backup Purge**: Backups containing deleted data are destroyed within 30 days
* **GDPR Erasure**: Deletion requests under GDPR Article 17 are processed within the same timelines
* **HIPAA Disposal**: PHI is disposed of in accordance with HIPAA requirements, with documented verification

### 8. Personnel Security

#### Hiring & Training

* Background checks conducted on all employees prior to employment
* Comprehensive security and privacy training during onboarding
* Annual security awareness training with specific modules for HIPAA and GDPR
* All employees sign information security policies covering the security, availability, and confidentiality of Diaflow services

#### Acceptable Use & Access

* Strict acceptable use policies for all systems and data
* Access provisioned on a need-to-know basis with regular access reviews
* Prompt deprovisioning upon role change or termination
* Mandatory reporting of security incidents or suspected vulnerabilities

### 9. Subprocessors & Third Parties

Diaflow maintains a list of subprocessors that process customer data on our behalf. This list is available upon request and is updated in advance of any changes, with customers notified per the terms of our DPA.

All subprocessors are subject to:

* Due diligence and security assessment prior to engagement
* Contractual obligations for data protection aligned with SOC 2, HIPAA, and GDPR requirements
* Periodic review and reassessment

### 10. Requesting Security Documentation

Contact <security@diaflow.io> or visit our [Trust Portal](https://trust.diaflow.io/) to submit your request.


# Apple App Store EULA Addendum

This Apple App Store EULA Addendum (this "Addendum") supplements and forms part of the Diaflow Terms and Conditions of Service, available at [compliance.diaflow.io/general/terms-and-conditions](https://compliance.diaflow.io/general/terms-and-conditions) (the "Agreement"). This Addendum applies only to your download, installation, and use of the Diaflow mobile application (the "Licensed Application") obtained through the Apple App Store. In the event of any conflict between this Addendum and the Agreement solely with respect to matters addressed in this Addendum, this Addendum shall control for App Store-distributed use of the Licensed Application.

Capitalized terms not defined in this Addendum have the meanings given to them in the Agreement.

### 1. Parties to This Addendum

You and Diaflow acknowledge that this Addendum is concluded between you and Diaflow only, and not with Apple Inc. ("Apple"), and that Diaflow, not Apple, is solely responsible for the Licensed Application and its content. This Addendum does not provide for usage rules that conflict with the Apple Media Services Terms and Conditions in effect as of the date you accept this Addendum, and you acknowledge you have had the opportunity to review those terms.

### 2. Scope of License

Diaflow grants you a limited, non-transferable, non-exclusive license to use the Licensed Application on any Apple-branded products that you own or control, and as permitted by the Usage Rules set forth in the Apple Media Services Terms and Conditions, except that the Licensed Application may be accessed and used by other accounts associated with you via Family Sharing or volume purchasing, to the extent applicable. All other terms of Section 2 (Access and Use) of the Agreement continue to apply.

### 3. Maintenance and Support

Diaflow is solely responsible for providing maintenance and support for the Licensed Application, as described in the Agreement or as required by applicable law. You and Diaflow acknowledge that Apple has no obligation whatsoever to furnish any maintenance or support services with respect to the Licensed Application.

### 4. Warranty

Diaflow is solely responsible for any product warranties, whether express or implied by law, to the extent not effectively disclaimed in the Agreement. In the event of any failure of the Licensed Application to conform to any applicable warranty, you may notify Apple, and Apple will refund the applicable purchase price for the Licensed Application to you. To the maximum extent permitted by applicable law, Apple has no other warranty obligation whatsoever with respect to the Licensed Application, and any other claims, losses, liabilities, damages, costs, or expenses attributable to a failure to conform to any warranty are Diaflow's sole responsibility, as further set out in Section 10 (Warranty Disclaimer) of the Agreement.

### 5. Product Claims

You and Diaflow acknowledge that Diaflow, not Apple, is responsible for addressing any claims by you or any third party relating to the Licensed Application or your possession and/or use of it, including but not limited to: (i) product liability claims; (ii) any claim that the Licensed Application fails to conform to an applicable legal or regulatory requirement; and (iii) claims arising under consumer protection, privacy, or similar law. Nothing in this Addendum or the Agreement limits Diaflow's liability to you beyond what is permitted by applicable law.

### 6. Intellectual Property Claims

You and Diaflow acknowledge that, in the event of any third-party claim that the Licensed Application or your possession and use of it infringes that third party's intellectual property rights, Diaflow, not Apple, is solely responsible for the investigation, defense, settlement, and discharge of any such claim, consistent with Section 4(f) of the Agreement.

### 7. Legal Compliance

By using the Licensed Application, you represent and warrant that: (i) you are not located in a country subject to a U.S. Government embargo, or that has been designated by the U.S. Government as a "terrorist-supporting" country; and (ii) you are not listed on any U.S. Government list of prohibited or restricted parties.

### 8. Developer Contact Information

Diaflow's name and contact information for any questions, complaints, or claims regarding the Licensed Application are:

Diaflow Pte. Ltd. 114 Lavender Street, #11-83, CT Hub 2, Singapore 338729 Email: <support@diaflow.io>

### 9. Third-Party Terms

Your use of the Licensed Application must comply with any applicable third-party agreements. For example, if you access the Licensed Application over a cellular data connection, you must not be in violation of your wireless data service agreement when doing so.

### 10. Third-Party Beneficiary

You and Diaflow acknowledge and agree that Apple and Apple's subsidiaries are third-party beneficiaries of this Addendum, and that, upon your acceptance of this Addendum, Apple will have the right (and will be deemed to have accepted the right) to enforce this Addendum against you as a third-party beneficiary of it.

### 11. External Services

The Licensed Application may enable access to Diaflow's and/or third-party services, including Connected Apps and Third-Party Products as described in Sections 5(d) and 6 of the Agreement (collectively, "External Services"). You agree to use External Services at your sole risk. Diaflow is not responsible for examining or evaluating the content or accuracy of any third-party External Services and is not liable for such External Services. Data displayed by the Licensed Application or any External Service is for general informational purposes only and is not guaranteed by Diaflow.


# Terms & Conditions (Model Gateway)

These Terms and Conditions (“Terms”) govern your access to and use of the Diaflow Model Gateway (the “Service”), operated by Diaflow Pte. Ltd., a company incorporated in the Republic of Singapore (“Diaflow,” “we,” “us,” or “our”). The Service is accessible at <https://gateway.diaflow.io> and provides access to third-party artificial intelligence models supplied by BytePlus Pte. Ltd. (“Byteplus”) through the Diaflow API.

By registering for, accessing, or using the Service, you (“User,” “you,” or “your”) acknowledge that you have read, understood, and agree to be bound by these Terms. If you are using the Service on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these Terms.

## 1. Definitions

“Account” means the registered account created by the User to access and use the Service, including all associated settings, profile information, and preferences configured through the Settings page.

“API” means the application programming interface provided by Diaflow through which Users access the Model Gateway and the underlying BytePlus models.

“API Key” means the unique authentication credential generated within the User’s Account that is required to make authorized API calls to the Service. Each API Key is linked to the User’s Account and Credit Balance.

“Credits” or “Credit Balance” means the prepaid monetary balance (denominated in US Dollars) held in the User’s wallet within the Service, which is consumed when API calls are made. The Credit Balance is displayed on the Dashboard and Billing pages of the Service.

“Model Gateway” or “Service” means the Diaflow platform accessible at <https://gateway.diaflow.io> that facilitates User access to BytePlus’s AI models via the Diaflow API, including the Dashboard, Models catalog, API Key management, Usage History, Billing, Settings, model playground, integration documentation, and all associated features, tools, and interfaces.

“Byteplus Models” means the artificial intelligence and machine learning models made available by BytePlus Pte. Ltd. through the Service, including but not limited to ByteDance-Seedance, Seedream, Seed-series models, and any future models added to the Models catalog.

“Workspace” means the organizational unit within the Service under which one or more Users may operate, identified by company name and Reference ID as configured in the Settings page.

“Workspace Administrator” means the User who created the Workspace or who has been designated administrative privileges, and who is responsible for managing the Workspace’s Credit Balance, API Keys, and member access.

## 2. Eligibility and Account Registration

2.1. You must be at least eighteen (18) years of age or the age of majority in your jurisdiction, whichever is greater, to use the Service.

2.2. During registration, you must provide accurate and complete information, including your email address, name, company name (if applicable), Reference ID, use case designation (Personal or Team/Business), and location. You agree to keep this information current and accurate at all times through the Settings page.

2.3. You are responsible for maintaining the confidentiality of your Account credentials and for all activities that occur under your Account. You must notify Diaflow immediately at <legal@diaflow.io> of any unauthorized use of your Account.

2.4. Diaflow reserves the right to refuse registration, suspend, or terminate any Account at its sole discretion and without prior notice.

## 3. Service Description

3.1. The Model Gateway provides Users with programmatic access to BytePlus’s AI models through the Diaflow API. Diaflow acts as an intermediary facilitating access to these third-party models and does not own, develop, or directly control the underlying AI models.

3.2. The Service includes the following features and functionalities:

(a) Dashboard: An overview of the User’s total requests, Credit Balance, total cost incurred, and active API Keys;

(b) Models Catalog: A browsable catalog of available BytePlus Models with per-model pricing, capability descriptions, and an interactive playground for testing API calls;

(c) API Key Management: Tools to create, view, and revoke API Keys used to authenticate API requests;

(d) Usage History: A detailed log of all API requests made, including the provider, model name, timestamp, unit price, quantity consumed, and total cost per request;

(e) Billing: A summary of monthly usage, Credit Balance, the ability to add Credits, and a downloadable invoice history; and

(f) Settings: Account profile management including email, name, company name, Reference ID, use case type, and location.

3.3. The availability, performance, features, pricing, and capabilities of BytePlus Models are subject to change at any time without notice. Diaflow shall not be liable for any modifications, discontinuations, or performance variations in the BytePlus Models.

3.4. Diaflow may, at its sole discretion, add, modify, or remove models, features, or functionalities from the Service at any time, including changes to the Models catalog and supported model versions.

## 4. API Keys and Access

4.1. To make API calls to the Service, Users must generate an API Key through the API Keys page. API Keys are unique to each Account and must not be shared with unauthorized parties.

4.2. Confidentiality. You are solely responsible for safeguarding your API Keys. You must not share, publish, embed in client-side code (including browsers, mobile applications, or publicly accessible repositories), or otherwise expose your API Keys. Diaflow reserves the right to immediately deactivate any API Key that becomes publicly exposed, without notice or liability.

4.3. All API calls made using your API Key shall be deemed authorized by you and shall be charged against your Credit Balance, regardless of whether such calls were made by you or by a third party who obtained access to your API Key.

4.4. Diaflow may impose rate limits, request quotas, or other technical restrictions on API usage at its sole discretion to ensure fair use and platform stability.

## 5. Credits, Payment, and Pricing

5.1. Prepaid Credit Model. The Service operates on a prepaid credit system. Users must purchase Credits in advance by clicking “Add credits” on the Billing page. Credits are denominated in US Dollars and are consumed as API calls are made, with consumption rates varying by model, request type, token quantity, and output format (e.g., text, image, video with audio).

5.2. Per-Model Pricing. Each model listed in the Models catalog displays its pricing on a per-unit basis (e.g., USD per 1 million tokens). The applicable rate is determined at the time the API call is processed. Users can review per-model pricing on the model detail page and verify consumption in the Usage History.

5.3. Credit Purchase. Credits may be purchased through the payment methods made available on the Service. All payments must be made in US Dollars unless otherwise specified. The User is responsible for all applicable taxes, duties, levies, and fees associated with the purchase of Credits, including any withholding taxes or value-added taxes imposed by the User’s jurisdiction.

5.4. Credit Expiration. All purchased Credits expire twelve (12) months from the date of purchase (the “Expiration Period”). Any unused Credits remaining after the Expiration Period shall be automatically forfeited without compensation, notice, or refund. It is the User’s sole responsibility to monitor Credit Balance through the Dashboard and Billing pages and to utilize Credits before expiration. Diaflow is under no obligation to remind Users of upcoming Credit expiration.

5.5. Non-Refundable. ALL CREDIT PURCHASES ARE FINAL AND NON-REFUNDABLE. Under no circumstances shall Diaflow issue refunds, rebates, credits, or payment reversals for purchased Credits, whether used or unused, expired or unexpired. This no-refund policy applies regardless of the reason for the request, including but not limited to:

(a) dissatisfaction with the Service, model quality, or output results;

(b) Account suspension or termination, whether initiated by the User or by Diaflow;

(c) changes in pricing, Credit consumption rates, or per-model unit pricing;

(d) discontinuation, modification, or unavailability of specific models or features in the Models catalog;

(e) service outages, interruptions, downtime, or degraded performance;

(f) the User’s failure to use Credits before the Expiration Period;

(g) deactivation or revocation of API Keys;

(h) changes to these Terms or any other Diaflow policies; or

(i) any force majeure event or circumstance beyond Diaflow’s control.

5.6. Pricing Changes. Diaflow reserves the right to modify Credit pricing, per-model consumption rates, and packaging at any time. Changes to pricing shall apply to future purchases and future API calls only and shall not retroactively affect Credits already purchased. Diaflow will make reasonable efforts to provide advance notice of material pricing changes through the Service or via email.

5.7. No Credit Transfers. Credits are non-transferable and may not be sold, traded, gifted, or otherwise transferred to any other User, Account, or Workspace, except as expressly permitted by Diaflow in writing.

5.8. Invoices. Billing records and invoices are available for download on the Billing page. Users are responsible for maintaining their own records for tax and accounting purposes. Diaflow provides invoices as a convenience and does not warrant their suitability for any particular tax or regulatory requirement.

## 6. Workspace and Team Usage

6.1. Users who select the “For Team or Business” option during registration or in Settings may operate under a shared Workspace. Each Workspace is identified by a company name and Reference ID.

6.2. Workspace Administrator Responsibility. The Workspace Administrator is solely responsible for: (a) managing and controlling access to the Workspace, including the invitation and removal of team members; (b) monitoring the Workspace’s Credit Balance and usage; (c) ensuring that all team members comply with these Terms; and (d) all charges incurred by team members under the Workspace’s Credit Balance.

6.3. Credits purchased for a Workspace are shared among all authorized team members. The Workspace Administrator acknowledges that API calls made by any team member will be charged against the Workspace’s Credit Balance, and that Diaflow shall not be responsible for resolving internal disputes regarding Credit usage among team members.

6.4. The Workspace Administrator may revoke a team member’s access at any time. Revocation of access does not entitle the Workspace or any team member to a refund of Credits consumed.

## 7. Acceptable Use

7.1. You agree to use the Service only for lawful purposes and in compliance with all applicable laws, regulations, and these Terms. You shall not:

(a) use the Service to generate, distribute, or facilitate content that is illegal, harmful, threatening, abusive, defamatory, obscene, or otherwise objectionable;

(b) attempt to reverse-engineer, decompile, disassemble, or otherwise derive the source code, algorithms, model weights, or architecture of the Service, the API, or the BytePlus Models;

(c) use the Service to develop a competing product or service, or to benchmark or evaluate the Service for competitive purposes without Diaflow’s prior written consent;

(d) resell, sublicense, or redistribute access to the Service or the BytePlus Models to any third party without Diaflow’s prior written consent;

(e) circumvent, disable, or otherwise interfere with any security, authentication, rate-limiting, or access-control features of the Service, including attempts to use revoked or expired API Keys;

(f) use automated means (including bots, scrapers, or crawlers) to access the Service in a manner that exceeds reasonable usage or imposes an unreasonable load on the infrastructure;

(g) transmit any malware, viruses, or other harmful code through the Service;

(h) use the Service in any manner that infringes upon the intellectual property rights or privacy rights of any third party;

(i) share, publish, or expose API Keys in any publicly accessible medium, including source code repositories, client-side applications, or online forums;

(j) attempt to manipulate or falsify usage data, billing records, or Credit Balances; or

(k) use the Service in violation of BytePlus’s acceptable use policies, as communicated by Diaflow from time to time.

7.2. Diaflow reserves the right to suspend or terminate access to the Service, deactivate API Keys, and forfeit unused Credits without refund if it determines in its sole discretion that a User has violated this Section 7.

## 8. Intellectual Property

8.1. Diaflow and its licensors retain all rights, title, and interest in and to the Service, the API, the platform (including the Dashboard, Models catalog, API Key management system, Usage History, Billing system, and all user interfaces), and all related documentation, trademarks, and intellectual property. Nothing in these Terms grants the User any ownership rights in the Service.

8.2. The BytePlus Models and related intellectual property remain the property of BytePlus Pte. Ltd. and its licensors. Access to these models through the Service does not transfer any ownership or licensing rights to the User beyond the limited right of use granted herein.

8.3. The User retains ownership of any input data submitted to and output data generated through the Service, subject to the rights and licenses granted in these Terms, any applicable BytePlus usage policies, and the limitations set out in Section 9 (Disclaimers).

## 9. Service Availability and Disclaimers

9.1. THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. DIAFLOW EXPRESSLY DISCLAIMS ALL WARRANTIES, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ACCURACY.

9.2. Diaflow does not warrant that: (a) the Service will be uninterrupted, timely, secure, or error-free; (b) the results, outputs, or content generated by the BytePlus Models will be accurate, reliable, complete, or suitable for any particular purpose; (c) the quality, speed, or availability of any model in the Models catalog will meet your expectations or remain consistent; or (d) the BytePlus Models will remain available in the catalog or perform at any particular level.

9.3. Diaflow does not endorse, verify, or guarantee the accuracy of any output generated by the BytePlus Models. Users are solely responsible for evaluating and verifying all model outputs before relying on them for any purpose.

9.4. Diaflow may perform scheduled or unscheduled maintenance that may result in temporary service interruptions. Diaflow shall not be liable for any such interruptions and no Credit refunds or extensions shall be granted for downtime.

## 10. Data Privacy and Security

10.1. Diaflow processes personal data in accordance with its Privacy Policy and applicable data protection laws, including the Singapore Personal Data Protection Act (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).

10.2. Users acknowledge that input data submitted to the Service may be transmitted to and processed by BytePlus’s infrastructure in accordance with BytePlus’s own data processing practices. Users are responsible for ensuring that they have obtained all necessary consents and authorizations before submitting any personal data to the Service.

10.3. Users shall not submit any data to the Service that they are not authorized to process, including but not limited to sensitive personal data, protected health information, or classified government data, unless expressly permitted under a separate written agreement with Diaflow.

10.4. Diaflow implements commercially reasonable technical and organizational security measures to protect the Service. However, Diaflow does not warrant that the Service will be completely secure or free from vulnerabilities.

10.5. Diaflow may collect and retain usage metadata, including request logs, model usage patterns, API call frequency, and Credit consumption data (as displayed in the Dashboard, History, and Billing pages), for the purposes of service operation, billing, analytics, and improvement.

## 11. Limitation of Liability

11.1. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL DIAFLOW, ITS DIRECTORS, OFFICERS, EMPLOYEES, AGENTS, AFFILIATES, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, REVENUE, DATA, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR IN CONNECTION WITH THE SERVICE OR THESE TERMS, REGARDLESS OF THE THEORY OF LIABILITY.

11.2. WITHOUT LIMITING THE FOREGOING, DIAFLOW SHALL NOT BE LIABLE FOR ANY DAMAGES ARISING FROM: (A) THE ACCURACY, QUALITY, OR RELIABILITY OF OUTPUTS GENERATED BY BYTEPLUS MODELS; (B) UNAUTHORIZED ACCESS TO OR USE OF YOUR ACCOUNT OR API KEYS; (C) THE EXPIRATION OR FORFEITURE OF UNUSED CREDITS; (D) MODIFICATIONS TO OR DISCONTINUATION OF ANY MODEL IN THE MODELS CATALOG; OR (E) ANY ACTIONS TAKEN BY BYTEPLUS WITH RESPECT TO ITS MODELS OR INFRASTRUCTURE.

11.3. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DIAFLOW’S TOTAL AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE AMOUNT PAID BY THE USER TO DIAFLOW IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

11.4. The limitations in this Section 11 shall apply even if a remedy fails of its essential purpose and regardless of whether Diaflow has been advised of the possibility of such damages.

## 12. Indemnification

12.1. You agree to indemnify, defend, and hold harmless Diaflow, its directors, officers, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (a) your use of the Service; (b) your violation of these Terms; (c) your violation of any applicable law or regulation; (d) your infringement of any third-party rights; (e) any content or data you submit to or generate through the Service; (f) your failure to safeguard your API Keys; or (g) any claim by a third party arising from outputs generated through your use of the Service.

## 13. Term and Termination

13.1. These Terms are effective from the date you first access or use the Service and remain in effect until terminated.

13.2. You may terminate your Account at any time by contacting Diaflow at <legal@diaflow.io>. Termination of your Account does not entitle you to a refund of any unused Credits. All remaining Credits shall be immediately forfeited upon Account termination.

13.3. Diaflow may suspend or terminate your Account and access to the Service at any time, with or without cause, and with or without notice. In the event of termination for any reason, all unused Credits shall be immediately forfeited without refund.

13.4. Upon termination: (a) all API Keys associated with your Account will be immediately deactivated; (b) your access to the Dashboard, Usage History, Billing records, and all other Service features will be revoked; and (c) Diaflow may delete your Account data in accordance with its data retention policies.

13.5. Upon termination, Sections 5.5 (Non-Refundable), 8 (Intellectual Property), 9 (Disclaimers), 11 (Limitation of Liability), 12 (Indemnification), 14 (Governing Law), and 15 (General Provisions) shall survive.

## 14. Governing Law and Dispute Resolution

14.1. These Terms shall be governed by and construed in accordance with the laws of the Republic of Singapore, without regard to its conflict of laws principles.

14.2. Any dispute arising out of or in connection with these Terms, including any question regarding its existence, validity, or termination, shall be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre (“SIAC”) in accordance with the Arbitration Rules of the SIAC for the time being in force.

14.3. The seat of the arbitration shall be Singapore. The language of the arbitration shall be English. The tribunal shall consist of one (1) arbitrator.

## 15. General Provisions

15.1. Entire Agreement. These Terms, together with the Privacy Policy and any other policies referenced herein, constitute the entire agreement between you and Diaflow with respect to the Service and supersede all prior agreements and understandings.

15.2. Amendments. Diaflow reserves the right to modify these Terms at any time. Material changes will be communicated through the Service or via the email address associated with your Account. Your continued use of the Service after such notification constitutes acceptance of the modified Terms. If you do not agree to the modified Terms, you must stop using the Service and terminate your Account.

15.3. Severability. If any provision of these Terms is found to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall remain in full force and effect.

15.4. Waiver. No failure or delay by Diaflow in exercising any right or remedy under these Terms shall constitute a waiver of such right or remedy.

15.5. Assignment. You may not assign or transfer these Terms or any rights or obligations hereunder without Diaflow’s prior written consent. Diaflow may assign these Terms freely, including in connection with a merger, acquisition, or sale of assets.

15.6. Force Majeure. Diaflow shall not be liable for any failure or delay in performance due to causes beyond its reasonable control, including but not limited to natural disasters, acts of government, pandemics, war, terrorism, labor disputes, internet or telecommunications failures, cyberattacks, or actions or omissions of third-party service providers (including BytePlus).

15.7. Notices. Notices to Diaflow shall be sent to <legal@diaflow.io>. Notices to Users shall be sent to the email address associated with the User’s Account as configured in the Settings page.

15.8. Third-Party Beneficiaries. These Terms do not create any third-party beneficiary rights, except that BytePlus Pte. Ltd. is an intended third-party beneficiary of the provisions relating to the BytePlus Models, acceptable use, intellectual property, disclaimers, and limitation of liability.

15.9. No Agency. Nothing in these Terms shall be construed to create a partnership, joint venture, agency, or employment relationship between you and Diaflow.

15.10. Electronic Communications. You consent to receiving communications from Diaflow electronically, including emails and notifications through the Service. You agree that all agreements, notices, disclosures, and other communications that Diaflow provides electronically satisfy any legal requirement that such communications be in writing.

&#x20;

Contact Information

For questions about these Terms, please contact us at: <legal@diaflow.io>


# Privacy Policy (Model Gateway)

## 1. Introduction

This Privacy Policy (“Policy”) describes how Diaflow Pte. Ltd. (“Diaflow,” “we,” “us,” or “our”), a company incorporated in the Republic of Singapore, collects, uses, stores, shares, and protects personal data in connection with the Diaflow Model Gateway (the “Service”), accessible at <https://gateway.diaflow.io>.

The Service provides Users with API-based access to artificial intelligence models supplied by BytePlus Pte. Ltd. (“Byteplus”). This Policy applies to all Users of the Service, including individuals and organizations accessing the Service through personal or team/business Accounts.

By creating an Account and using the Service, you acknowledge that you have read and understood this Policy and consent to the collection, use, and processing of your personal data as described herein.

## 2. Data Controller

The data controller responsible for the processing of your personal data under this Policy is:

Diaflow Pte. Ltd.

Singapore

Email: <privacy@diaflow.io>

## 3. Personal Data We Collect

We collect and process the following categories of personal data in connection with your use of the Service:

### 3.1. Account Registration Data

When you create an Account through the Settings page, we collect the following information:

<table data-header-hidden><thead><tr><th width="176.83203125" valign="top">Data Element</th><th valign="top">Description</th><th valign="top">Purpose</th></tr></thead><tbody><tr><td valign="top">Email address</td><td valign="top">Your registered email</td><td valign="top">Account identification, authentication, communications</td></tr><tr><td valign="top">Name</td><td valign="top">Your display name or workspace name</td><td valign="top">Account identification</td></tr><tr><td valign="top">Company name</td><td valign="top">Your organization name (if applicable)</td><td valign="top">Workspace setup, billing</td></tr><tr><td valign="top">Reference ID</td><td valign="top">A unique identifier for your account/workspace</td><td valign="top">Account management, support</td></tr><tr><td valign="top">Use case type</td><td valign="top">Personal or Team/Business designation</td><td valign="top">Service configuration, analytics</td></tr><tr><td valign="top">Location</td><td valign="top">Country and city</td><td valign="top">Tax compliance, localization, regulatory obligations</td></tr></tbody></table>

&#x20;

### 3.2. API and Usage Data

When you use the Service, we automatically collect:

<table data-header-hidden><thead><tr><th width="183.4296875" valign="top">Data Category</th><th valign="top">Details</th></tr></thead><tbody><tr><td valign="top">API Key metadata</td><td valign="top">Key name, creation date, last used date, and masked key identifiers (we do not store full API keys in plaintext after initial generation)</td></tr><tr><td valign="top">API request logs</td><td valign="top">Provider name, model name, timestamp, unit price, token quantity consumed, and total cost per request (as displayed in the History page)</td></tr><tr><td valign="top">Dashboard metrics</td><td valign="top">Total requests (all time), Credit Balance, total cost incurred, number of active API Keys</td></tr><tr><td valign="top">Billing data</td><td valign="top">Monthly usage amounts, Credit Balance, billing transaction history (invoice number, date, amount, payment status)</td></tr></tbody></table>

&#x20;

### 3.3. Input and Output Data

When you make API calls to the BytePlus Models (including through the model playground), we may process:

(a) Input data: Prompts, text, image URLs, and any other data you submit as part of an API request;

(b) Output data: Text, images, videos, audio, and any other content generated by the BytePlus Models in response to your requests; and

(c) Request parameters: Model selection, size specifications, duration settings, and other configuration parameters.

### 3.4. Payment Data

When you purchase Credits through the Billing page, our third-party payment processor collects payment information (such as credit card details or bank account information) on our behalf. Diaflow does not directly store or have access to your full payment card details. We retain only transaction records including invoice numbers, dates, amounts, and payment status.

### 3.5. Technical Data

We automatically collect technical data when you access the Service, including IP address, browser type and version, device type, operating system, referral URLs, access timestamps, and pages visited within the Service.

## 4. How We Use Your Personal Data

We use the personal data we collect for the following purposes:

<table data-header-hidden><thead><tr><th valign="top">Purpose</th><th valign="top">Data Used</th><th valign="top">Legal Basis (GDPR)</th></tr></thead><tbody><tr><td valign="top">Providing and operating the Service</td><td valign="top">Account data, API data, input/output data</td><td valign="top">Performance of contract</td></tr><tr><td valign="top">Billing, invoicing, and credit management</td><td valign="top">Account data, billing data, payment data</td><td valign="top">Performance of contract</td></tr><tr><td valign="top">API Key authentication and access control</td><td valign="top">API Key metadata, account data</td><td valign="top">Performance of contract</td></tr><tr><td valign="top">Usage monitoring and rate limiting</td><td valign="top">API request logs, technical data</td><td valign="top">Legitimate interest</td></tr><tr><td valign="top">Service improvement and analytics</td><td valign="top">Usage data, technical data, dashboard metrics</td><td valign="top">Legitimate interest</td></tr><tr><td valign="top">Security and fraud prevention</td><td valign="top">Technical data, API Key metadata, request logs</td><td valign="top">Legitimate interest</td></tr><tr><td valign="top">Customer support and communications</td><td valign="top">Account data, usage data</td><td valign="top">Performance of contract / Legitimate interest</td></tr><tr><td valign="top">Legal and regulatory compliance</td><td valign="top">All categories as required</td><td valign="top">Legal obligation</td></tr><tr><td valign="top">Tax compliance and financial reporting</td><td valign="top">Location, billing data, account data</td><td valign="top">Legal obligation</td></tr></tbody></table>

&#x20;

## 5. Data Sharing and Third-Party Processing

We may share your personal data with the following categories of recipients:

### 5.1. BytePlus Pte. Ltd.

When you make API calls to BytePlus Models through the Service, your input data (prompts, images, parameters) is transmitted to BytePlus’s infrastructure for processing. BytePlus processes this data in accordance with its own privacy policy and data processing practices. Diaflow does not control how BytePlus processes, stores, or retains the input and output data once it is transmitted to BytePlus’s systems. Users are responsible for reviewing BytePlus’s privacy practices before submitting personal data through the Service.

### 5.2. Payment Processors

We use third-party payment processors to handle Credit purchases. These processors collect and process your payment information under their own privacy policies. We do not have access to or store your full payment card details.

### 5.3. Infrastructure and Hosting Providers

We use third-party cloud infrastructure providers to host and operate the Service. These providers process data on our behalf under data processing agreements that require them to protect your data in accordance with applicable law.

### 5.4. Professional Advisors

We may share personal data with our lawyers, accountants, auditors, and other professional advisors as necessary for the provision of their services.

### 5.5. Law Enforcement and Legal Requirements

We may disclose personal data if required to do so by law, regulation, legal process, or governmental request, or if we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation; (b) protect the rights, safety, or property of Diaflow, our Users, or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) enforce our Terms and Conditions.

### 5.6. Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your personal data may be transferred as part of the transaction. We will notify you of any such transfer and any choices you may have regarding your data.

## 6. International Data Transfers

Diaflow is based in Singapore. Your personal data may be transferred to and processed in countries other than your country of residence, including Singapore and the countries where BytePlus operates its infrastructure. These countries may have data protection laws that differ from your jurisdiction.

Where we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, we will implement appropriate safeguards, such as Standard Contractual Clauses approved by the European Commission, to ensure your data is protected.

By using the Service, you acknowledge and consent to the transfer of your personal data to Singapore and other jurisdictions as described in this Policy.

## 7. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes for which it was collected and to comply with our legal obligations:

<table data-header-hidden><thead><tr><th width="180.6796875" valign="top">Data Category</th><th valign="top">Retention Period</th></tr></thead><tbody><tr><td valign="top">Account registration data</td><td valign="top">Duration of account plus 12 months after account deletion or termination</td></tr><tr><td valign="top">API request logs and usage history</td><td valign="top">36 months from the date of the request, or longer if required for billing disputes or legal compliance</td></tr><tr><td valign="top">Billing and invoice records</td><td valign="top">7 years from the date of the transaction (for tax and financial reporting obligations)</td></tr><tr><td valign="top">Input and output data</td><td valign="top">Transient processing only — not retained after the API response is delivered, unless required for abuse detection or legal compliance. Note: BytePlus may apply its own retention policies to data processed on its infrastructure.</td></tr><tr><td valign="top">Technical and log data</td><td valign="top">12 months from the date of collection</td></tr><tr><td valign="top">Payment transaction records</td><td valign="top">7 years from the date of the transaction</td></tr></tbody></table>

&#x20;

After the applicable retention period, personal data will be securely deleted or anonymized. Aggregated, anonymized data that cannot be used to identify you may be retained indefinitely for analytics and service improvement purposes.

## 8. Data Security

We implement commercially reasonable technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

(a) Encryption of data in transit using TLS/SSL protocols;

(b) Secure storage of API Keys with masked display in the user interface (only partial key identifiers are shown after initial generation);

(c) Access controls and authentication mechanisms for Account access;

(d) Regular security assessments and monitoring of the Service infrastructure;

(e) Logical separation of User data across Accounts and Workspaces; and

(f) Incident response procedures for security breaches.

While we take reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your personal data.

## 9. Your Rights

Depending on your jurisdiction, you may have the following rights with respect to your personal data:

### 9.1. Rights Under the GDPR (EEA, UK, and Switzerland)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have the right to:

(a) Access: Request a copy of the personal data we hold about you;

(b) Rectification: Request correction of inaccurate or incomplete personal data;

(c) Erasure: Request deletion of your personal data, subject to legal retention requirements;

(d) Restriction: Request that we restrict the processing of your personal data;

(e) Portability: Receive your personal data in a structured, commonly used, machine-readable format;

(f) Objection: Object to the processing of your personal data based on legitimate interests; and

(g) Withdrawal of consent: Where processing is based on consent, withdraw your consent at any time.

You also have the right to lodge a complaint with your local supervisory authority.

### 9.2. Rights Under the PDPA (Singapore)

If you are located in Singapore, you have the right under the Personal Data Protection Act 2012 (PDPA) to: (a) request access to personal data we hold about you; (b) request correction of personal data that is inaccurate; and (c) withdraw consent to the collection, use, or disclosure of your personal data (subject to legal or contractual restrictions and reasonable notice).

### 9.3. Rights Under Other Jurisdictions

If you are located in another jurisdiction with applicable data protection laws (including but not limited to the California Consumer Privacy Act, Vietnam’s Decree on Personal Data Protection, or other regional frameworks), you may have additional rights. Please contact us at <privacy@diaflow.io> to make a request under your applicable law.

### 9.4. Exercising Your Rights

To exercise any of the above rights, please contact us at <privacy@diaflow.io>. We will respond to your request within thirty (30) days or within the timeframe required by applicable law. We may request additional information to verify your identity before processing your request.

## 10. Cookies and Tracking Technologies

The Service may use cookies, local storage, and similar tracking technologies to maintain session state, authenticate Users, remember preferences, and analyze usage patterns. We use the following categories of cookies:

(a) Strictly necessary cookies: Required for the Service to function, including session management and authentication;

(b) Functional cookies: Used to remember your preferences and settings; and

(c) Analytics cookies: Used to collect aggregated information about how Users interact with the Service to help us improve it.

You can manage cookie preferences through your browser settings. Please note that disabling certain cookies may impair the functionality of the Service.

## 11. Children’s Privacy

The Service is not directed to individuals under the age of eighteen (18) or the age of majority in their jurisdiction, whichever is greater. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected personal data from a child, we will take steps to delete such data promptly. If you believe a child has provided us with personal data, please contact us at <privacy@diaflow.io>.

## 12. Third-Party Links and Services

The Service may contain links to third-party websites or services, including BytePlus documentation and integration endpoints. This Policy does not apply to third-party websites or services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.

## 13. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, the Service, or applicable law. Material changes will be communicated through the Service or via the email address associated with your Account. The “Effective Date” at the top of this Policy indicates when it was last updated. Your continued use of the Service after any changes constitutes your acceptance of the revised Policy.

## 14. Data Protection Officer

If you have any questions, concerns, or requests regarding this Policy or our data protection practices, you may contact our Data Protection Officer:

Data Protection Officer

Diaflow Pte. Ltd.

Email: <privacy@diaflow.io>

## 15. Supplemental Notices

### 15.1. For Users in the European Economic Area

Where we rely on legitimate interest as a legal basis for processing, we have conducted a balancing assessment to ensure our interests do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time.

### 15.2. For Users in Singapore

We comply with the obligations under the Personal Data Protection Act 2012 (PDPA) of Singapore. For data-related complaints, you may also contact the Personal Data Protection Commission (PDPC) of Singapore.

### 15.3. For Users in California (USA)

Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California residents may have additional rights including: the right to know what personal information is collected and how it is used; the right to delete personal information; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination for exercising privacy rights. Diaflow does not sell your personal data. To exercise your rights, contact us at <privacy@diaflow.io>.

***

### Contact Information

For privacy-related inquiries, please contact us at: <privacy@diaflow.io>


# Brand & Logo Guideline

Download the Diaflow symbol, logo and logotype for digital and print usage in a variety of colours and languages. Check the guidelines for how and when to use the logo and symbol.

## Instruction and guideline

For use in all territories except when specified

<figure><img src="https://content.gitbook.com/content/5ysyuK06EewcyEzJ4Z1A/blobs/MCHilZiettuoxcnFRSUm/Diaflow%20Logo%20Guideline%203%20(1).jpg" alt=""><figcaption><p>Logo Specifications</p></figcaption></figure>

<figure><img src="https://content.gitbook.com/content/5ysyuK06EewcyEzJ4Z1A/blobs/sWDNrsTKw9VAr1lj7Ko3/Diaflow%20Logo%20Guideline%20(1).jpg" alt=""><figcaption><p>Logo Guideline &#x26; Color</p></figcaption></figure>

<figure><img src="https://content.gitbook.com/content/5ysyuK06EewcyEzJ4Z1A/blobs/ZdZ117lU89rYfvfAuScE/Diaflow%20Logo%20Guideline%202%20(1).jpg" alt=""><figcaption><p>Don't and Do</p></figcaption></figure>

## Download logo

You can download our materials here: <https://drive.google.com/drive/folders/1HYF47ADG4lBm48Y1_SQ5EM1vs9LcTlcR?usp=share_link>&#x20;


