
Terms and Conditions
Last edit: 07/01/2026
These Terms apply where they are incorporated into an Order Form or otherwise accepted by the Customer. If Mindflow and the Customer execute a separate negotiated subscription agreement or other written terms, those executed terms prevail to the extent of any inconsistency.
These Terms are entered into between MINDFLOW, a French société par actions simplifiée registered with the Paris Trade and Companies Register under number 893 124 511, with registered office at 128 rue La Boétie, 75008 Paris, France (the “COMPANY” or “Mindflow”), and the customer identified in the applicable Order Form (the “CUSTOMER” or “Customer”).
Mindflow is a French company that provides the Mindflow enterprise hyperautomation platform, enabling customers to automate, orchestrate and augment security, IT and business operations across their networks and information systems. The Platform combines workflow automation, integrations, data processing capabilities and artificial intelligence features, including AI-assisted capabilities and AI agents.
1. Interpretation
1.1. Definitions
Title or fully capitalized terms shall have the meaning designated to them in the paragraph in which it is written between quotation marks. The following capitalized terms, whether in the singular or the plural, shall have the meaning assigned below:
Affiliate: Any company that Controls, is Controlled by or is under common Control with a signatory of the Agreement.
Agreement: These Terms, the applicable Order Form, the Data Processing Agreement, the Service-level Agreement, the Security Notice and any other documents expressly incorporated or agreed in writing by the Parties. The Privacy Policy is provided for information and does not form part of the Agreement unless expressly incorporated in writing.
Applicable Data Protection Legislation: Any data protection regulation that may apply in the context of the Agreement, including, where applicable, (i) the Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“GDPR”) and the laws and regulations adopted to implement the GDPR and (ii) any other laws or regulations relating to the Processing of Personal Data.
Business Day: A day other than a Saturday, Sunday, French public holiday or other day on which commercial banks are generally closed in France.
Confidential Information: Any information of a non-public, confidential or proprietary nature, whether of commercial, financial or technical nature, which is related to the CUSTOMER, the COMPANY, Platform or otherwise, and which is disclosed orally or by way of any medium by either Party (the “Disclosing Party”) to the other Party (the “Receiving Party”).
CUSTOMER Configurations: Workflows, prompts, agent instructions, forms, automation logic and other configurations created by or for the CUSTOMER through the Services, excluding Mindflow Technology.
CUSTOMER Data: All data and information relating to the CUSTOMER and its operations, facilities, customers, suppliers, personnel, assets and programs, in whatever form that information may exist and whether entered into, stored, generated, collected, transmitted, retrieved, hosted, processed or produced by or through the Services.
Data: The information being processed and ingested throughout the workflows, such as the input data used for each API call, any data generated or modified by the workflows, and any sensitive or personally identifiable information (PII) that may be included in the data. It also includes any configuration data needed to run the workflows, such as API credentials or other authentication information.
Order: The contractual commitment between the CUSTOMER and the COMPANY for the performance of Services through an Agreement.
Order Form: Contractual document or electronic form, signed, accepted or submitted by the CUSTOMER, specifying the terms and conditions of the purchase order for the Services, including type and quantity of Services ordered, price or fees, delivery date, and payment terms between the CUSTOMER and the COMPANY for the performance of Services.
Services: The Platform and the associated and ancillary services and support described in the applicable Order Form, these Terms and documents incorporated by reference.
Subcontractor/Subprocessor: A member of the COMPANY’s direct or indirect sub-tier supply chain that provides goods and/or services in connection with the performance of the Services.
Steps: Includes the unconfigured API calls created from pre-built API call templates made available on the platform, the unconfigured HTTP requests created by the User, as well as any other unconfigured step present in a workflow.
Users: All individuals who are designated by the CUSTOMER, whether or not they are employees of the CUSTOMER.
Workflows: A collection of Steps interconnected by an automation logic: sequential calls, conditional linkages, and iterative calls, through which a process transitions from an initial status to completion.
1.2. Interpretation
For purposes of interpretation: (i) the words includes or including shall be construed as meaning “including or includes without limitation” (i.e. the list is not exhaustive); and, (ii) Article headings and captions are for convenience only.
2. Purpose of the Agreement
The purpose of this Agreement is to provide the general terms and conditions governing the applicable commitments for the access and use of the Services.
This Agreement sets out the terms and conditions under which the CUSTOMER orders, accesses and uses the Services, and the COMPANY provides the Services and related support.
3. Agreement – Contractual documents — Order of precedence
A binding agreement is created when the Customer accepts an Order Form or otherwise accepts these Terms and Mindflow accepts the corresponding order.
The Agreement may include the following contractual documents:
These Terms and Conditions;
The applicable Order Form;
The Data Processing Agreement;
The Service-level Agreement;
The Security Notice;
The Privacy Policy, which is provided for information only and does not form part of the Agreement unless expressly incorporated in writing; and
Any negotiated amendments or additional terms agreed in writing.
In the event of any conflict or inconsistency, the following order of precedence applies: (i) any negotiated subscription agreement or amendment executed by the Parties; (ii) the applicable Order Form; (iii) these Terms; and (iv) the Service-level Agreement and other documents incorporated by reference. Notwithstanding the foregoing, the Data Processing Agreement prevails for matters concerning the processing of CUSTOMER Personal Data.
4. Ordering procedure
The COMPANY shall only accept Order Forms that comply with the Agreement.
5. Fees – invoicing – payment terms
5.1. Fees
The Subscription Fees and other charges are set out in the applicable Order Form.
The fixed Subscription Fees set out in the Order Form shall remain unchanged during the initial Subscription Term. This does not prevent charges for additional usage, AI overages, Add-On Services, additional entitlements or third-party pass-through costs expressly permitted under the Agreement or the Order Form.
5.2. Invoicing
Invoicing terms are specified in the applicable Order Form or invoice. Any Subscription Period started is due in full unless otherwise stated.
5.3. Payment Terms
Unless otherwise specified in the Order Form, the Customer shall pay undisputed invoices within thirty (30) days of receipt by bank transfer using the payment details stated on the relevant invoice.
5.4. Default or Delay in Payment
If the CUSTOMER fails to pay an undisputed amount when due, that amount shall be in arrears and immediately payable from the next Business Day following the due date. The COMPANY may:
Notwithstanding Article 22 [Temporary Suspension of Services], suspend the Services until full payment of the undisputed amounts due;
Reclaim an interest on arrears equal to 3 (three) times the legal interest rate, based on the amount of the sums not paid on the due date and a fixed indemnity of 40 (forty) euros for collection costs, without prejudice to additional compensation if the collection costs actually incurred exceed this amount.
6. Right to access and use
The COMPANY grants to the CUSTOMER and its authorized Users, during the term of the Agreement, a right to remotely access and use the COMPANY services listed in the relevant Order Form in accordance with this Agreement.
7. Provision of the service — Support
The COMPANY shall provide the Services and support in accordance with the Agreement and any Service-level Agreement (“SLA”) expressly applicable to the relevant Subscription Plan. Unless expressly stated in the applicable Order Form or online plan terms, no SLA, guaranteed availability, Service Level Credits or committed support response or resolution times apply to free, trial, Community Edition, beta, preview, sandbox or other non-production Services.
8. Security measures and audit
The COMPANY implements appropriate technical and organizational measures, internal controls, and information security routines to maintain a sufficient level of security with regard to the applicable laws and regulations and international standards, such as ISO27001. These measures, controls, and information security routines may be subject to changes during the Agreement. Substantial changes will be notified to the CUSTOMER.
At the CUSTOMER’s reasonable request, the COMPANY shall provide information concerning its compliance, which may include relevant audit reports, certification reports, penetration-test summaries, remediation information and bridge letters. Such information shall constitute Confidential Information. Any request for additional information must be reasonably motivated and proportionate.
For the purposes of this Agreement, a “Security Incident” means a confirmed unauthorized access to, acquisition, disclosure, alteration or destruction of CUSTOMER Data within systems under the COMPANY’s control, or a confirmed material compromise of the security of the production Services. A Security Incident does not include unsuccessful attempts or activities that do not compromise CUSTOMER Data or the Services.
The COMPANY shall notify the CUSTOMER without undue delay after becoming aware of a Security Incident materially affecting the CUSTOMER.
The COMPANY shall provide information reasonably available to it concerning the nature and known impact of the Security Incident and the measures taken or planned to contain, investigate and remediate it, and shall provide reasonable updates as additional material information becomes available.
The COMPANY shall take reasonable measures to contain, investigate and remediate the Security Incident and to reduce the risk of recurrence. Notifications under this Article shall not constitute an admission of fault or liability. Personal Data Breaches involving CUSTOMER Personal Data shall also be handled in accordance with the DPA.
9. Additional features and services
The Parties may agree to include additional features and services (“Add-On Service”). The Agreement will apply for such add-on services which will be subject to a quotation sent by the COMPANY to the CUSTOMER. Specific terms may apply for the individual add-on service that will be provided by the COMPANY.
9.1. AI and Agentic Services
The Services may include features that use artificial intelligence models and technologies, including AI-assisted workflow creation, AI agents, AI-powered analysis, generation and reasoning (the “AI Features”).
AI Providers. Certain AI Features may rely on artificial intelligence models or services provided by third-party providers (the “AI Providers”). The AI Providers and models available through the Services may evolve from time to time.
Amazon Bedrock. Where an AI model is made available through Amazon Bedrock, Amazon Web Services EMEA SARL is the relevant Sub-processor for that AI processing. The underlying model developer is not separately identified as a Sub-processor to the extent that it does not receive or have access to CUSTOMER AI Inputs or AI Outputs. Any AI Provider engaged directly by the COMPANY outside Amazon Bedrock shall be identified in the COMPANY’s then-current sub-processor list.
Customer AI Accounts. Where supported by the Services, the CUSTOMER may connect its own account, API key or credentials for an AI Provider (a “Customer AI Account”). The CUSTOMER is responsible for maintaining that account and for the charges, terms, configurations, data-use and retention settings, regions and rate limits applicable between the CUSTOMER and the relevant AI Provider. The CUSTOMER authorizes the COMPANY to transmit AI Inputs and other relevant data to the selected AI Provider as necessary to provide the requested AI Feature. To the extent that an AI Provider is selected and contracted directly by the CUSTOMER, that AI Provider’s processing is governed by the CUSTOMER’s agreement and settings with that provider and it shall not be deemed a Sub-processor engaged by the COMPANY solely by reason of the technical connection.
Mindflow AI Credits. AI Credits may be included in the CUSTOMER’s Subscription Plan and may also be purchased in additional blocks, as specified in the Order Form or Platform. Each call to an AI model constitutes an “AI Execution” and consumes the number of AI Credits displayed for the selected model at the time of the call. Where a workflow, agent or interaction invokes several AI calls, each call is counted separately. Unless otherwise specified, monthly allocations reset at the end of each monthly allocation period and unused AI Credits do not roll over. Applicable allocations, consumption rates, rate limits and additional credit prices shall be specified in the Order Form or displayed in the Platform. Certain AI-powered enablement or support features may be made available without consuming AI Credits where indicated in the Platform. The COMPANY may update prospective consumption rates or limits to reflect changes in available models, functionality or third-party costs, with reasonable advance notice of material changes where practicable. Continuity buffer and blocking. To reduce the risk of abrupt interruption of active or critical workflows, the COMPANY may make available a limited temporary continuity buffer after the CUSTOMER’s available AI Credits have been exhausted. The size, duration and applicable price of the continuity buffer shall be specified in the Order Form or displayed in the Platform. AI Executions processed within the continuity buffer may be invoiced at the applicable additional-credit or overage rate. The COMPANY shall provide usage visibility and use reasonable efforts to notify the CUSTOMER as its allocation approaches exhaustion, when the continuity buffer begins and before it is exhausted. Unless additional AI Credits are purchased, a new allocation becomes available or another continuity arrangement has been agreed, the COMPANY may block further AI Executions that consume AI Credits once the continuity buffer is exhausted. Such blocking shall not, by itself, suspend the remaining non-AI Services or AI Features that do not consume AI Credits. The CUSTOMER may select a hard usage limit that blocks chargeable AI Executions immediately upon exhaustion of its available AI Credits, where supported by the applicable Subscription Plan.
Customer choice and configuration. The CUSTOMER determines which available AI Providers, models, tools, integrations, permissions it enables and uses within the Services.
AI Inputs and Outputs. The CUSTOMER retains its rights in data, prompts, instructions and other content submitted to AI Features (“AI Inputs”). Subject to applicable law, third-party rights and applicable AI Provider terms, the CUSTOMER may use outputs generated through the AI Features (“AI Outputs”) for its business purposes.
Model training. The COMPANY does not train artificial intelligence models in-house using CUSTOMER Data, AI Inputs, AI Outputs or Customer Configurations. Except where the CUSTOMER expressly opts in in writing, the COMPANY will not use such information to train or fine-tune a general-purpose artificial intelligence model. Where the CUSTOMER uses a Customer AI Account, the AI Provider’s terms and account settings selected by the CUSTOMER shall govern the provider’s use and retention of such information.
AI limitations. The CUSTOMER acknowledges that AI technologies may produce outputs that are probabilistic, non-deterministic, incomplete or inaccurate. The CUSTOMER shall apply appropriate judgment and validation having regard to the nature and potential impact of the relevant use case.
Agentic Actions. Certain AI Features may be configured to interact with third-party systems or perform actions through tools and integrations. The Services provide configurable controls, including authorization of tools and actions, human approval steps and activity or audit logs where supported. The CUSTOMER is responsible for configuring the scope of access, credentials, permissions and approval or oversight mechanisms appropriate to its intended use, and for reviewing AI Outputs and actions where the nature or potential impact of the use case requires it.
Documentation, transparency and AI literacy. The COMPANY shall make available documentation reasonably describing the intended purpose, main capabilities and known limitations of the AI Features, the supported AI Providers and models, and the available human oversight controls. The CUSTOMER is responsible for making relevant documentation available to its Users and for ensuring an appropriate level of AI literacy, information and training for personnel using AI Features, having regard to their role and the context of use.
AI Compliance. Each Party shall comply with the laws and regulations applicable to it in connection with the provision or use of AI Features, including, where applicable, Regulation (EU) 2024/1689 (the “EU AI Act”). Each Party is responsible for the obligations applicable to its actual role and activities under applicable AI laws.
Intended use and CUSTOMER responsibilities. Unless expressly agreed in an Order Form or other written agreement, the AI Features are not designed or offered for use as a high-risk AI system or as a safety component under applicable AI laws. The CUSTOMER is responsible for assessing its intended use of the AI Features, including whether that use is subject to specific transparency, human oversight, AI literacy, high-risk or sector-specific obligations. The CUSTOMER shall not use the AI Features for a prohibited practice, or deploy them as a high-risk AI system or safety component, without first informing the COMPANY and agreeing any necessary additional conditions in writing.
The Parties shall reasonably cooperate and exchange information available to them where necessary to support compliance with applicable AI laws. The CUSTOMER shall not use the AI Features for practices prohibited by applicable AI laws.
Modifications and improvements
The COMPANY reserves its right to implement enhancements, introduce new features, or adjust and rectify any deficiencies within the Services. Throughout the duration of the prevailing Subscription Term, the COMPANY warrants that it shall not significantly diminish the primary functionalities for which the CUSTOMER has subscribed. In the event of a substantial discontinuation that impacts the CUSTOMER's operations, the COMPANY shall endeavor to provide prior notification whenever feasible.
Freshly developed modules, products, or specialized capabilities may be presented as Add-On Services, potentially involving supplemental pricing, specific usage thresholds, or distinct contractual conditions. The introduction of such novel functionality does not automatically grant inclusion within the CUSTOMER's current Subscription Plan, unless explicitly designated in a relevant Order Form or verified by the COMPANY. Upon activation, these supplemental features shall be subject to the provisions of this Agreement and the associated Order Form.
Acceptable use
The COMPANY shall provide the Services with due care and in accordance with the Agreement. Except for any express service level or commitment stated in the Agreement, the COMPANY is subject to an obligation of means and does not guarantee a particular business result.
The COMPANY uses commercially reasonable efforts to provide the Services. It performs regular checks of the operation and accessibility of the Services and may carry out scheduled maintenance under the conditions set out in the SLA. The COMPANY may limit or suspend access to the Services where reasonably necessary to carry out maintenance.
However, the COMPANY is not responsible for any difficulties or temporary impossibility of access to the Services and due to (including but not limited to):
circumstances outside of its network;
the failure of equipment, cabling, services or networks not included in the Services or which are not under its responsibility;
interruption of the Services by telecom operators or internet service providers;
the CUSTOMER’s own acts, errors, or omissions;
force majeure.
11.2. Users
The Service(s) is made available for use by the Users.
The CUSTOMER shall remain the contracting party and remain responsible for all Users compliance under the Agreement.
11.3. Use of the Services
The CUSTOMER is responsible for its own use of the Services and any information that it may share in connection therewith. The CUSTOMER agrees that the Services will be used exclusively by itself and/or authorized Users, who are subject to the same obligations as the CUSTOMER in their use of the Services.
The CUSTOMER undertakes to comply with the applicable laws when using the Services.
The CUSTOMER shall only use the Services for its intended and internal business purposes and shall not (including but not limited to):
resell, distribute, sublicense, or otherwise transfer any right in and to the Service to others;
modify, translate, reverse engineer, decompile or disassemble any part of the Services, or otherwise attempt to derive source code from or create derivative works of the Services;
copy, modify or misappropriate any of the COMPANY’s property or concepts used by the COMPANY in connection with the Services;
adopt any conduct that interferes with or hijacks the COMPANY’s computer systems or breaches its computer security measures;
infringe the COMPANY’s financial, commercial or moral rights and interests;
give any third party (other than Users) access to the Services for any reason whatsoever;
market, transfer or otherwise provide access to the Services, the information hosted on it.
11.4. Misuse of the Services
The CUSTOMER shall not misuse the Services for purposes other than those for which they were designed, and in particular for (including but not limited to):
practice illegal or fraudulent activity;
harm public order and morality;
infringe on third parties or their rights;
violate any contractual provision;
violate any legal, jurisprudential, or regulatory provision;
carrying out any activity that may interfere with a third party's computer system, in particular for the purpose of violating its integrity or security;
carry out any operation aimed at promoting its services and/or sites or those of a third party;
assist or incite a third party to commit one or more of the acts or activities listed above;
use the Services in a manner that impacts the availability, performance, reliability, or stability of the Services.
The Parties expressly agree the COMPANY shall not be held liable for any misuse of the Services stipulated in this Article 11.4 [Misuse of the Services].
In the event that the CUSTOMER is required to appear before a Court due to actions during the use of the Services specified in this Article 11.4 [Misuse of the Services], the COMPANY shall not be held liable, in whole or in part, and shall not bear any costs or expenses ordered by the court.
11.5. Accounts
Once the CUSTOMER signs the Order Form, the COMPANY shall open an account on behalf of the CUSTOMER to access the Services (the "CUSTOMER Account").
11.6. Log-in Details
The CUSTOMER is solely responsible for maintaining the confidentiality of Users’ connection identifiers and/or passwords. The CUSTOMER undertakes to ensure that Users do not allow any third party to use them in their place or on their behalf, unless they bear full responsibility for doing so.
If the CUSTOMER becomes aware of any unauthorized use of connection identifiers, passwords or User accounts, or any other security breach affecting its account, it shall promptly notify the COMPANY. The COMPANY may take any reasonable action necessary to protect the Services and the CUSTOMER Account.
11.7. Fair Use of the Services
The CUSTOMER may use the Services within the usage entitlements and limits set out in the applicable Subscription Plan and Order Form, including any applicable limits for executions, flows, operations, users or AI Credits. The COMPANY may apply reasonable technical measures where usage materially exceeds the applicable entitlements or threatens the security, availability or performance of the Services. Where additional usage is available for purchase, the COMPANY shall inform the CUSTOMER of the applicable conditions.
11.8. Payment for Unauthorized Use
The COMPANY may review relevant usage logs to verify compliance with the applicable usage entitlements and acceptable use requirements. The CUSTOMER shall reasonably cooperate to clarify compliance. In case of repeated, intentional or material excess usage, the COMPANY may restrict the affected usage or invoice additional usage at the applicable rates after informing the CUSTOMER, without prejudice to its other rights under the Agreement.
11.9. APIs and Integrations
The Services may, depending on the CUSTOMER’s Subscription Plan, contain features designed to integrate with third-party applications. The COMPANY depends on third parties for such integrations and cannot guarantee their continued availability or quality. The COMPANY is not responsible for disruption or degradation caused by a third-party integrated service.
12. Customer responsabilities and obligations
The CUSTOMER represents that the information provided to the COMPANY is accurate and undertakes to keep it up to date. The CUSTOMER is responsible for maintaining the confidentiality and security of its Users’ login details as stated in Article 11.6 [Log-in Details] and accepts that the COMPANY may take appropriate action to address a breach of that Article.
It is the responsibility of the CUSTOMER to ensure that the following conditions are met and that it does so with no cost to the COMPANY.
Specify to the COMPANY the selected users with access to the Services according to Article 11.5 [Accounts];
Have an internet connection with adequate bandwidth to ensure proper implementation and quality of the service;
Report incidents or issues through the support channels described in the SLA;
Use anti-virus software with definitions updated daily at a minimum.
Make every effort to be available to the COMPANY to resolve a Services-related incident or a request.
13. Customer data
13.1. Ownership of Customer Data
The CUSTOMER Data is and shall remain the exclusive property of the CUSTOMER and the CUSTOMER has sole responsibility for the data of and the right to use the CUSTOMER Data.
13.2. Rights to Use Customer Data
The Customer grants Mindflow, for the duration of the Agreement, a limited, non-exclusive right to host, reproduce, process and use Customer Data and Customer Configurations, directly or through authorised Subprocessors, solely as necessary to provide, maintain, secure and support the Services and to comply with the Customer’s documented instructions.
13.3. No Sale of Data
The COMPANY will not sell, rent, or lease the CUSTOMER Data to any third party or otherwise receive any value in exchange for the CUSTOMER Data.
Processing of customer personal data
14.1. Mindflow Acting as Controller
The COMPANY undertakes to comply with all legal and regulatory obligations with regards personal data protection, in particular with Applicable Data Protection Legislation.
14.2. Mindflow Acting as Processor
In order to perform the Agreement, the COMPANY may process CUSTOMER Personal Data on documented instructions from the CUSTOMER. The applicable conditions are set out in the Data Processing Agreement (“DPA”).
Subcontracting
The COMPANY may use Subcontractors to provide the Services. The COMPANY remains responsible for the performance of its obligations under the Agreement notwithstanding its use of Subcontractors, subject to the exclusions and limitations of liability set out in the Agreement. Any Subprocessor processing CUSTOMER Personal Data is governed by the DPA.
Intellectual Property rights
16.1. Ownership
Each Party retains all right, title and interest in and to the intellectual property owned or developed by it independently of this Agreement.
The COMPANY owns and shall retain all intellectual property rights in and to the Platform, Services, software, infrastructure, APIs connectors, generic components, templates, documentation, technology, methodologies, know-how and any improvements or developments thereof (the “Mindflow Technology”).
The CUSTOMER retains all rights in and to CUSTOMER Data and Customer Configurations.
Where the COMPANY assists the CUSTOMER in creating a Customer Configuration, the CUSTOMER retains ownership of the CUSTOMER-specific configuration logic, excluding Mindflow Technology and any pre-existing, generic or reusable components, templates, connectors, tools, methodologies, know-how and improvements, all of which remain the property of the COMPANY.
The COMPANY may reuse general ideas, methods, patterns, know-how and non-customer-specific elements developed in connection with such assistance, provided that it does not disclose or reuse CUSTOMER Data or CUSTOMER Confidential Information.
The COMPANY may use aggregated and de-identified information relating to the use and performance of the Services to operate, secure and improve the Services, provided that such information does not identify the CUSTOMER or disclose CUSTOMER Confidential Information.
16.2. Community and Shared Content
From time to time, the Parties may agree in writing to share agents, templates, workflows or other reusable configuration logic developed through the Services (the “Shared Content”).
Shared Content shall never contain CUSTOMER Data, Personal Data, credentials, secret values, files, execution data, logs, payloads, Confidential Information or third-party data. For the purposes agreed by the Parties, the COMPANY may adapt and make the Shared Content available to other users.
16.3. Customer Reference
Unless the CUSTOMER notifies the COMPANY otherwise in writing, the COMPANY may identify the CUSTOMER as a customer and use the CUSTOMER’s name and logo in customer lists, on the COMPANY’s website and in sales, corporate and investor materials during the Term and for three (3) years thereafter, in accordance with any reasonable brand guidelines communicated by the CUSTOMER.
Any press release, public announcement, detailed case study, testimonial or quotation attributed to the CUSTOMER, or public disclosure of the CUSTOMER’s commercial terms, shall require the CUSTOMER’s prior written approval.
16.4. Data
Without prejudice to Article 13, the CUSTOMER retains all rights in and to CUSTOMER Data. The COMPANY shall process CUSTOMER Personal Data in accordance with the DPA and shall not be responsible for the lawfulness, accuracy or quality of CUSTOMER Data supplied or controlled by the CUSTOMER.
16.5. Submissions
The CUSTOMER may provide questions, comments, suggestions, ideas or other feedback regarding the Services (“Feedback”). The COMPANY may use Feedback without restriction or obligation to the CUSTOMER, provided that it does not identify the CUSTOMER or disclose CUSTOMER Confidential Information.
17. Confidentiality
17.1. Non-use and Non-disclosure
Neither party shall use or disclose any Confidential Information of the other Party for any purpose except in relation to its performance under this Agreement. Each Party shall use its best efforts to mark “confidential” all Confidential Information disclosed in writing. Failure to do so will not affect the confidential nature of the information and the Parties obligations to protect such information.
17.2. Disclosure to Employees
A receiving Party shall only disclose the disclosing Party's Confidential Information to its directors, officers and employees on a need-to-know basis. Prior to such disclosure, the receiving Party shall inform each such person of the confidential nature of the Confidential Information. Notwithstanding due observance of this obligation, the receiving Party shall be liable for any breach of the provisions on confidentiality under the Agreement by such persons.
17.3. General Limitations
The receiving Party shall not use the Confidential Information of the disclosing Party for purposes other than in direct relation with the Agreement. The receiving Party shall treat the Disclosing Party's Confidential Information with at least the same degree of care as it would use in respect of its own Confidential Information of similar importance, but in any event shall use a reasonable level of care. The receiving Party shall not disclose, disseminate or make accessible any part of the disclosing Party’s Confidential Information, in any way or form, to any third party.
17.4. Limitations on the Duty of Non-disclosure
Confidential Information does not include any information or material that (i) is or becomes publicly known other than through violation of this Agreement by the receiving party, (ii) was already in the receiving party's possession or was available to the receiving party on a non-confidential basis before disclosure, (iii) is obtained by the receiving party from a third party that is not bound to separate confidentiality obligations to the other party, (iv) was later communicated by a third party to the receiving party without any confidentiality obligation, or (v) is independently developed by the receiving party without use of or reference to the discloser's Confidential Information.
17.5. Disclosures Required by Law
The Recipient may disclose Confidential Information to the extent required by law, provided that the receiving Party gives the disclosing Party prompt written notice of such requirement prior to such disclosure and assistance in obtaining an order protecting the information from public disclosure.
17.6. Return or Destroy
Upon the request of the disclosing Party, the receiving Party shall without delay, at the disclosing Party’s choice, (i) return all copies, samples and extracts of, and all other physical media containing, the disclosing Party’s Confidential Information, and/or (ii) delete or destroy all electronic data containing the disclosing Party’s Confidential Information. Upon request, the receiving Party shall confirm in writing its compliance with this Article.
17.7. Survival and Remedies
The obligations of each Receiving Party under this Article 17 [Confidentiality] shall survive for 5 (five) years after the termination of the Agreement. Each party agrees that any violation or threatened violation of this section may cause irreparable injury to the Disclosing party, entitling the Disclosing party to seek injunctive relief in addition to all legal remedies.
Term and termination
18.1. Initial Subscription Term
The Agreement begins on the date stated in the applicable Order Form or, for Services made available without an Order Form, when the CUSTOMER first accepts these Terms or accesses the Services. The initial Subscription Term is the period stated in the applicable Order Form or online plan terms presented at ordering or activation. If no period is stated, a paid Subscription has an initial term of twelve (12) months, while a free, trial or Community Edition continues until terminated in accordance with this Article.
18.2. Renewal Term
A paid fixed-term Subscription automatically renews for successive terms equal in length to the expiring Subscription Term, unless otherwise stated in the applicable Order Form or online plan terms (each a “Renewal Term”). For Services purchased online or on a self-service basis, the billing frequency and renewal conditions displayed at ordering or activation apply. A free, trial or Community Edition does not create a fixed renewal commitment and continues until terminated.
18.3. Non-renewal
For a paid fixed-term Subscription, the CUSTOMER may give notice of non-renewal in accordance with Article 24.7 [Notices] at least three (3) months before expiry of the then-current Term, unless a different period is stated in the applicable Order Form or online plan terms. A self-service Subscription may be cancelled using the method and within the notice period displayed for the applicable plan. The CUSTOMER may terminate a free, trial or Community Edition at any time. The COMPANY may modify, suspend or discontinue a free, trial or Community Edition, with reasonable notice where practicable, or immediately where required for security, abuse-prevention, legal or technical reasons.
18.4. Multi-year Subscription Term
Where the Order Form provides for a multi-year Subscription Term, the CUSTOMER may not terminate the Agreement for convenience before the expiry of that Subscription Term. If the CUSTOMER ceases using the Services or purports to terminate the Agreement before such expiry, other than as a result of the COMPANY’s uncured material breach under Article 18.5 [Termination for breach], all committed fees for the remainder of the Subscription Term shall remain due and payable. Fees already paid are non-refundable, subject in each case to mandatory applicable law.
18.5. Termination for Breach
Either Party may terminate the Agreement for a material breach if the breaching Party fails to cure that breach within fifteen (15) calendar days after receiving written notice describing the breach. Termination shall be effective upon written notice following expiry of the cure period.
If the CUSTOMER terminates this Agreement pursuant to this Article as a result of the COMPANY’s uncured material breach, the COMPANY shall refund the portion of any prepaid recurring Subscription Fees reasonably allocable to the terminated Services for the period following the effective termination date.
No refund shall be due in respect of onboarding, implementation, configuration, training, professional services, connector development or other one-time or front-loaded services to the extent already performed or delivered, usage or AI Credits already consumed, non-cancellable third-party costs incurred for the CUSTOMER, or any other Fees already accrued.
Where Subscription Fees include both recurring access to the Services and onboarding, implementation or other front-loaded elements without a separate allocation in the Order Form, the refundable amount shall be determined by deducting the reasonable value of such elements before calculating the unused prepaid recurring portion.
Either party may terminate this Agreement with immediate effect if the other party takes or suffers any action for insolvency in any jurisdiction.
18.6. Refund Policy
Except as expressly provided in Article 18.5 [Termination for Breach] or required by mandatory law, all Fees paid by the CUSTOMER are non-refundable. The CUSTOMER is not entitled to a refund where it ceases using the Services or seeks to terminate before the end of the then-current Subscription Term without a contractual right to do so.
18.7. Effect of Termination
Upon expiration or termination of this Agreement for any reason: (i) except for the limited retrieval rights set out in Article 18.8, all access rights will cease; (ii) subject to Article 18.8, the DPA, applicable law and normal backup-retention cycles, each Party shall return, delete or destroy the other Party’s Confidential Information in accordance with Article 17.6; and (iii) all invoiced and non-invoiced undisputed Fees owed by the CUSTOMER shall become immediately due and payable.
18.8. Data Export and Exit
During the Subscription Term, the CUSTOMER may use the export capabilities made available through the Services to retrieve available CUSTOMER Data and exportable Customer Configurations.
In particular, where supported by the relevant functionality, the CUSTOMER may export its workflows in a structured, commonly used and machine-readable JSON format. Workflow exports may include workflow logic, API steps, data transformation steps, configuration structure and non-sensitive metadata, but shall not include credential or secret values, CUSTOMER Data processed during executions, execution payloads, files, logs, audit records or elements constituting Mindflow Technology. References to credentials or external resources may be represented by non-sensitive identifiers or placeholders.
Upon expiration or termination of the Agreement, the CUSTOMER shall have a reasonable period, and in any event no less than thirty (30) days unless otherwise agreed or required by applicable law, to retrieve available CUSTOMER Data and exportable Customer Configurations.
Upon request, the COMPANY will provide reasonable assistance to facilitate the CUSTOMER’s transition from the Services. Standard export functionality is included in the Services. Material bespoke transition assistance may be subject to additional fees agreed between the Parties, except to the extent prohibited by applicable law.
Following the applicable retrieval and retention period, the COMPANY may delete CUSTOMER Data in accordance with the Agreement, the DPA and its applicable backup and retention policies.
Nothing in this Article requires the COMPANY to disclose or transfer Mindflow Technology, trade secrets, internal systems or information that is not CUSTOMER Data or an exportable Customer Configuration. The COMPANY shall comply with any additional switching or portability requirements applicable to it under mandatory law.
Representations and warranties
Each Party represents and warrants that the representing party has full power and authority to execute, deliver and perform this Agreement, that this Agreement has been duly and validly executed and delivered by the representing party and that it constitutes the legal, valid, and binding obligation of the representing party, enforceable against it in accordance with its terms.
20. Disclaimers
The Services are provided “as is”, without warranty of any kind, express or implied. The COMPANY does not warrant that the CUSTOMER’s use of the Service will be uninterrupted or error-free. The CUSTOMER assumes the risk of the use, quality, performance, accuracy and completeness of any data produced by the service.
Except as expressly provided in this Agreement, either party disclaims any and all warranties, express, implied, or statutory, relating in any way to the Service.
Limitations on liability
21.1. Exclusion of Indirect and Consequential Damages
In no event shall the COMPANY be liable for lost profits, business interruption, goodwill or special, indirect, incidental, consequential damages of any kind, even if advised in advance of the possibility thereof.
21.2. Limitation of Total Liability
IN NO EVENT SHALL THE AGGREGATE LIABILITY (ALL FAULTS & DAMAGES AGGREGATED) OF THE COMPANY RELATED TO THIS AGREEMENT (INCLUDING THE SERVICE LEVEL AGREEMENT AND THE DATA PROCESSING AGREEMENT) EXCEED THE AMOUNT OF FEES RECEIVED BY THE COMPANY DURING THE TWELVE (12) CALENDAR MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE LIABILITY. THE FOREGOING LIMITATION WILL APPLY REGARDLESS OF THE NATURE OF THE ACTION INTENDED.
ANY PROCEDURE AGAINST THE COMPANY MUST BE STARTED WITHIN TWELVE (12) CALENDAR MONTHS FOLLOWING THE DAMAGE CONCERNED.
NOTHING IN THIS AGREEMENT EXCLUDES OR LIMITS EITHER PARTY’S LIABILITY FOR ITS GROSS NEGLIGENCE (FAUTE LOURDE), WILFUL MISCONDUCT (DOL), OR ANY OTHER LIABILITY THAT CANNOT BE EXCLUDED OR LIMITED UNDER APPLICABLE LAW.
Temporary suspension of services
The COMPANY may temporarily suspend the Service if the CUSTOMER is in breach of the Agreement and such breach is not cured within 30 (thirty) calendar days after the CUSTOMER’s receipt of Notice thereof. Suspension will last until the breach has been cured by the CUSTOMER.
Indemnification
23.1. By Mindflow
The COMPANY shall defend, indemnify and hold harmless the CUSTOMER from and against any losses, costs, expenses (including reasonable outside attorneys’ fees and costs) and finally awarded damages against the CUSTOMER resulting from a final judicial decision brought against the CUSTOMER by a third-party alleging that the Service used in accordance with this Agreement infringes a valid intellectual property right of such third-party within the limit mentioned in the Agreement.
23.2. By the Customer
The CUSTOMER shall defend, indemnify and hold harmless the COMPANY and its officers, directors, employees, and agents, from and against any losses, costs, expenses (including reasonable outside attorneys’ fees and costs) and finally awarded damages against the COMPANY resulting from a substantiated claim, demand, suit, action or proceeding brought against the COMPANY by a third party alleging that any CUSTOMER Data, or the use of the Services in combination with a non-company application provided by the CUSTOMER, infringes a valid intellectual property right of such third party in the jurisdictions in which the CUSTOMER uses or accesses the Services.
23.3. Process
To receive the foregoing indemnifications the indemnified party must give the indemnifying party prompt written notice of the claim, give indemnifying party sole control of the defense and settlement of the claim (except that indemnifying party may not settle any claim unless it unconditionally releases indemnified party of all liability), and give indemnifying party all reasonable assistance at indemnifying party’s expense.
23.4. Mindflow Remedies
If the COMPANY receives information about an infringement claim, the COMPANY may at its sole discretion either (i) obtain a license for CUSTOMER’s continued use of the applicable part of the Service in accordance with this Agreement, or (ii) replace or modify the applicable part of the Services so that it is no longer claimed to infringe a third party right. If the COMPANY reasonably determines that the foregoing options are not commercially available, the COMPANY may terminate the CUSTOMER subscription for relevant part of the Services.
23.5. Sole Remedies
The rights granted under this Section shall be the indemnified party’s sole and exclusive remedy for any alleged infringement covered by this section.
Miscellaneous provisions
24.1. Compliance
The COMPANY provides a standard service that can be accessed via a web interface. The COMPANY shall provide the Services in accordance with those laws in the country the COMPANY is registered that are applicable to the COMPANY’s provision of its Services in general without regard for CUSTOMER’s particular use of the Services. The CUSTOMER is responsible for its own use of the Services, all activities that occur under User’s account, and that such use is compliant with legal requirements applicable for their business and any local laws that may impact its right to import, export or use the Services.
The CUSTOMER shall not access or use the Services in violation of applicable export-control, trade-sanctions or embargo laws, including applicable European Union, United Nations and United States restrictions.
24.2. Assignment
This Agreement may not be assigned by either party without the prior written consent of the non-assigning party. Consent is not required in the context of merger, acquisition, or sale of all or substantially all the assigning party’s stock or assets, provided that the assigning party provides advance written notice thereof to the non-assigning party. Subject to the foregoing, the Agreement shall continue to the benefit of and be binding upon the parties’ respective permitted successors and assigns.
24.3. Force Majeure
In accordance with the provisions of article 1218 of the French Civil Code, no Party may be held liable for a failure to perform its contractual obligations if this failure is due to an event beyond the control of the Parties and constitutes force majeure. The force majeure’s interpretation shall be the one retained by the French Court of Cassation.
24.4. Entire Agreement
The Agreement constitutes the entire agreement between the parties and supersedes all other agreements, proposals, or representations, whether electronic, written, or oral, between the parties concerning its subject matter.
24.5. Severability
If any provision of this Agreement is held to be ineffective, unenforceable, or illegal for any reason, such decision shall not affect the validity or enforceability of any of the remaining portions thereof.
24.6. Amendment
Amendment or modification of the Agreement shall only be valid or binding upon the parties if made in writing and signed by a legal representative of each Party.
24.7. Notices
All notices and other communications required or permitted under this Agreement shall be in writing and sent to the notice addresses specified in the Order Form, as updated by notice under this Article. Notices may be delivered by registered mail with acknowledgment of receipt or by email. A notice delivered by mail shall be deemed received on delivery. A notice sent by email shall be deemed received when expressly acknowledged by the recipient or, provided that no delivery failure message is received, at the opening of business on the next Business Day for the recipient.
24.8. Survival
Expiration or termination of this Agreement will not relieve either Party from its obligations arising hereunder prior to such expiration or termination. Rights and obligations which by their nature should survive will remain in effect after termination or expiration of this Agreement.
24.9. Electronic Signatures
It is agreed between the Parties that the Agreement may be signed by any electronic means, the Parties recognising the reliability of the process, thus giving it the same legal value as a handwritten signature within the meaning of the law.
24.10. Language
Regardless of any language into which this Agreement may be translated, the official, controlling and governing version of this Agreement shall be exclusively the English language version.
24.11. Governing Law and Jurisdiction
The Agreement shall be construed and interpreted in accordance with and governed by French Law without regard to its conflict of law rules.
In the event of a dispute between the Parties concerning its validity, interpretation or execution, the Parties shall endeavor to settle their dispute amicably. In the absence of an amicable agreement within 2 (two) months following the first notification sent by one Party to the other concerning the dispute concerned, the dispute shall be subject to the exclusive jurisdiction of the courts of Paris (France), unless mandatory procedural rules to the contrary exist.
24.12. Insurance
During the Subscription Term, the COMPANY shall maintain, with reputable insurers, professional liability (responsabilité civile professionnelle) and cyber-risk insurance policies appropriate to the nature of the Services. Upon reasonable written request, the COMPANY shall provide the CUSTOMER with certificates evidencing such coverage. Nothing in this Article increases, extends or otherwise modifies the COMPANY’s liability under Article 21 [Limitation on Liability].