Terms of Service

TietAI Hydra Platform
hip.tiet.ai

Version: 1.1
Effective date: February 1st, 2026
Last updated: July 1st, 2026

These Terms of Service govern business and professional use of the TietAI Hydra Platform. The Platform is not offered to consumers.

1. TietAI and scope of these Terms

These Terms of Service (the “Terms”) govern access to and use of the TietAI Hydra Platform, including Hydra Connect, Hydra Studio, Hydra Govern, agent runtimes, APIs, software development kits, connectors, documentation, hosted environments, customer-controlled deployments, support and related professional services ordered by Customer (collectively, the “Platform” or the “Services”).

The Platform is provided by Tiet AI S.L., a company incorporated under the laws of Spain, with registered office at Calle FUENTERRABIA, Número 9, puerta 6, 28014 Madrid, Spain, registered with the Commercial Registry of Madrid under [REGISTRY DETAILS], and tax identification number [NIF] (“TietAI”, “we”, “us” or “our”).

The Platform is intended exclusively for organisations, public bodies, healthcare providers, research organisations, technology companies and other professional customers acting in the course of their business or professional activity.

By signing an Order Form, creating an organisational account or accessing the Platform on behalf of an organisation, the person accepting these Terms confirms that they have authority to bind that organisation. That organisation is referred to as “Customer” or “you”.

These Terms do not create any contractual relationship between TietAI and Customer’s patients, employees, users, clients or other third parties.

2. Contract documents and order of precedence

Customer may purchase the Services under an order form, statement of work, master services agreement or other written agreement signed by the parties.

Unless the applicable Customer Agreement expressly states otherwise, the following order of precedence applies:

  1. the signed master services agreement or other individually negotiated agreement;

  2. the applicable Order Form or Statement of Work;

  3. the Data Processing Agreement;

  4. the Service Level Agreement;

  5. the Security Schedule;

  6. these Terms;

  7. the Documentation.

The Data Processing Agreement prevails only in relation to the processing of personal data. The Service Level Agreement prevails only in relation to availability, service levels, support and service credits.

Where no separately signed agreement exists, these Terms and the applicable Order Form constitute the entire agreement governing Customer’s use of the Platform.

3. Definitions

In these Terms:

“Applicable AI Laws” means laws and regulations governing the development, provision, deployment or use of artificial intelligence systems, including Regulation (EU) 2024/1689, as amended or replaced, and any applicable implementing or national legislation.

“Authorised User” means an employee, contractor, consultant or other individual authorised by Customer to use the Platform under Customer’s account.

“Customer Agent” means any agent, multi-agent system, workflow, pipeline, application, automation or other solution created, configured, trained, adapted, deployed or operated by or for Customer using the Platform.

“Customer Agreement” means any master services agreement, Order Form, Statement of Work or other written agreement entered into between TietAI and Customer.

“Customer-Controlled Deployment” means a deployment installed within infrastructure, a cloud tenancy or a technical environment controlled by Customer.

“Customer Data” means data, records, documents, messages, images, signals, files, database content, personal data and other information submitted to, transmitted through or processed using the Platform by or on behalf of Customer.

“Customer Materials” means prompts, instructions, configurations, schemas, ontologies, workflows, code, policies, evaluation cases, templates and other materials created or provided by Customer.

“Documentation” means the technical and user documentation made available by TietAI for the Platform.

“Output” means content, predictions, classifications, summaries, transformations, messages, actions or other results generated by a Customer Agent or by AI-enabled functionality made available through the Platform.

“Order Form” means an ordering document specifying the Services, deployment model, subscription period, fees, usage limits and other commercial terms.

“Patient Data” means personal data concerning an identified or identifiable patient, including data concerning health.

“Third-Party Service” means any external model, API, database, cloud service, application, connector, software library or other service not owned and operated by TietAI.

“TietAI Cloud Deployment” means a hosted deployment operated by TietAI or its authorised infrastructure providers.

4. Nature of the Platform

4.1 Technology platform

Hydra is a technology platform for data integration, workflow orchestration, agent development, AI governance, observability and execution.

Depending on the Services ordered, the Platform may enable Customer to:

a. connect and exchange data between systems;

b. transform, map, route, validate or normalise information;

c. create and configure agents and multi-agent workflows;

d. connect Customer Agents to models, APIs, databases and external tools;

e. define prompts, policies, permissions, approval gates and human review processes;

f. test, evaluate, monitor and audit agents and workflows;

g. deploy agents within TietAI-hosted or Customer-controlled environments; and

h. create and operate data spaces, interoperability services and governed data workflows.

4.2 Hydra Connect

Hydra Connect provides integration, transport, interoperability, mapping, routing and transformation capabilities. It may support healthcare and other industry standards, including HL7, FHIR, DICOM, CDA, X12, OMOP and customer-specific formats.

Hydra Connect does not independently determine the meaning, accuracy, clinical relevance or lawful use of the information transported through it.

4.3 Hydra Studio

Hydra Studio provides development and orchestration tools through which Customer may design, configure, test and deploy Customer Agents, workflows and pipelines.

Customer controls the intended purpose, system instructions, prompts, connected models, tools, data sources, permissions, deployment environment and operating parameters of Customer Agents.

4.4 Hydra Govern

Hydra Govern provides governance, observability, policy management, evaluation, traceability, access control and audit capabilities.

Governance functionality assists Customer in implementing its own governance framework. It does not constitute legal, regulatory, clinical, security or compliance advice and does not guarantee compliance with any particular law, regulation or standard.

5. No medical device or healthcare service

5.1 No medical device

The Platform is not placed on the market by TietAI as:

a. a medical device;

b. software as a medical device;

c. an in vitro diagnostic medical device;

d. a diagnostic or treatment system;

e. a clinical decision support product; or

f. a substitute for professional medical judgement.

The Platform is not intended by TietAI to diagnose, prevent, monitor, predict, prognose, treat or alleviate disease, injury or disability.

The fact that the Platform can process healthcare information, connect healthcare systems or be used by healthcare organisations does not change the Platform’s intended purpose.

5.2 No healthcare provider relationship

TietAI does not provide healthcare services, practise medicine, deliver clinical care or assume responsibility for the treatment of any patient.

TietAI does not establish a clinician-patient, hospital-patient or other healthcare professional relationship with Customer, any Authorised User or any patient.

5.3 Customer-developed regulated use cases

Customer may use the Platform to create Customer Agents for its own professional or operational purposes.

Customer is solely responsible for determining whether a Customer Agent or its intended use is subject to medical device, pharmaceutical, clinical research, artificial intelligence, healthcare, professional practice or other sector-specific regulation.

Customer shall not represent that TietAI is the manufacturer, provider, sponsor, healthcare provider or regulated operator of a Customer Agent unless TietAI has expressly accepted that role in a separate written agreement signed by an authorised representative of TietAI.

Unless expressly agreed under a separate written agreement, Customer shall not use the Platform or any Output:

a. as the sole basis for a patient-specific diagnosis or treatment decision;

b. to autonomously prescribe, modify or discontinue treatment;

c. to autonomously perform clinical triage;

d. to communicate life-critical or time-critical clinical information without an independently validated fallback mechanism;

e. to directly interact with patients for diagnostic or therapeutic purposes without appropriate professional oversight; or

f. in any manner that requires the Platform itself to be certified or authorised as a medical device.

Where Customer uses Customer Agents in a healthcare workflow, Customer shall ensure that appropriately qualified healthcare professionals review all information relevant to patient care and retain final authority over clinical decisions.

6. Access rights and subscription

6.1 Right to use

Subject to Customer’s payment of the applicable fees and compliance with the Customer Agreement, TietAI grants Customer a limited, non-exclusive, non-transferable and non-sublicensable right during the subscription term to access and use the Services specified in the Order Form for Customer’s internal business purposes.

Customer may permit Authorised Users to use the Platform on its behalf but remains responsible for their acts and omissions.

6.2 Usage limits

Usage may be subject to limits specified in the Order Form, including limits relating to users, environments, executions, API calls, compute resources, storage, tokens, connectors, data volume or model consumption.

TietAI may apply reasonable technical controls to enforce agreed usage limits.

6.3 Accounts and credentials

Customer shall:

a. provide accurate account information;

b. maintain an accurate list of Authorised Users;

c. assign permissions according to least-privilege principles;

d. protect credentials, API keys, certificates and tokens;

e. prohibit credential sharing;

f. promptly revoke access when no longer required; and

g. notify TietAI without undue delay of any suspected unauthorised access.

Customer is responsible for activity conducted through its accounts unless caused by TietAI’s breach of its security obligations.

6.4 Affiliates

Customer affiliates may use the Platform only where expressly identified in an Order Form or where otherwise agreed in writing.

Customer remains responsible for the compliance of its participating affiliates unless the relevant affiliate has entered into a separate agreement with TietAI.

7. Customer Agents and Customer responsibility

7.1 Customer control

Customer acknowledges that the behaviour and risk profile of a Customer Agent depend materially on decisions made by Customer, including:

a. its intended purpose;

b. the prompts and system instructions used;

c. the models selected;

d. the tools and external systems connected;

e. the Customer Data provided;

f. the actions the agent is authorised to perform;

g. the degree of autonomy assigned;

h. the review and approval controls configured; and

i. the production environment in which it is deployed.

7.2 Validation before production

Customer shall evaluate and test each Customer Agent before production use.

Testing must be proportionate to the foreseeable impact of an incorrect, incomplete, biased, misleading, delayed or unauthorised Output or action.

Customer shall not assume that performance observed in a demonstration, development environment or limited dataset will be reproduced in production.

7.3 Human oversight

Customer shall implement human review and intervention controls proportionate to the risks of each Customer Agent.

Customer shall not disable or circumvent approval gates, access controls, confidence thresholds, audit logging or other safeguards required by Customer’s own policies, the Documentation, the applicable Order Form or applicable law.

7.4 Permissions and external actions

Customer is responsible for determining which systems, tools and data sources a Customer Agent may access and which actions it may execute.

Customer shall apply appropriate controls to prevent Customer Agents from:

a. accessing information beyond their authorised scope;

b. altering source records without approval;

c. executing unauthorised transactions;

d. escalating their own permissions;

e. sending communications to third parties without appropriate controls; or

f. taking actions that may materially affect a person’s rights, health, safety, employment, credit, access to services or legal position without appropriate human review.

7.5 Monitoring

Customer shall monitor production Customer Agents, investigate material anomalies and suspend or modify any Customer Agent that presents an unacceptable risk.

Customer shall notify TietAI without undue delay of any Platform defect, security event or unexpected Platform behaviour that has caused or could reasonably cause material harm.

8. Artificial intelligence regulation

8.1 Regulatory roles

The legal status of each party under Applicable AI Laws is determined by the facts, including who develops, places on the market, puts into service, deploys, substantially modifies or defines the intended purpose of a particular AI system.

Contractual labels do not override roles imposed by applicable law.

TietAI is the provider of the Platform and of any embedded AI functionality expressly identified as a TietAI AI system in the applicable Documentation or Order Form.

TietAI is not, merely by supplying the Platform, the provider of every Customer Agent created or configured using it.

8.2 Customer assessment

Customer is responsible for assessing the legal classification of each Customer Agent and its use.

Where applicable, Customer shall determine whether it acts as provider, deployer, importer, distributor, product manufacturer or another regulated operator in relation to a Customer Agent.

8.3 Customer compliance

To the extent applicable to Customer or a Customer Agent, Customer shall:

a. maintain appropriate AI governance and risk management procedures;

b. define and document the intended purpose of the Customer Agent;

c. maintain appropriate technical and operational documentation;

d. establish appropriate data governance controls;

e. implement human oversight;

f. retain logs and records for the legally required period;

g. provide required information or transparency notices;

h. assess accuracy, robustness, cybersecurity and foreseeable misuse;

i. monitor the Customer Agent after deployment;

j. investigate and report incidents where required; and

k. conduct any required fundamental rights, data protection, conformity or impact assessment.

8.4 Cooperation

Where reasonably required for Customer to comply with Applicable AI Laws, TietAI will provide available information concerning the Platform’s technical characteristics, security controls, logs and operation.

Unless otherwise stated in an Order Form or Statement of Work, TietAI is not responsible for preparing Customer’s regulatory classification, conformity assessment, technical documentation, impact assessment or regulatory submission.

Additional regulatory assistance may be provided as professional services under a separate Statement of Work.

8.5 Prohibited representations

Customer shall not state or imply that:

a. TietAI has approved or certified a Customer Agent;

b. a Customer Agent is compliant merely because it was created using Hydra Govern;

c. the Platform guarantees compliance with the AI Act or any other law; or

d. TietAI accepts legal responsibility for Customer’s intended purpose or deployment decisions.

9. Acceptable use

Customer shall not, and shall not permit any person to:

a. use the Platform unlawfully or in breach of third-party rights;

b. use the Platform to facilitate discrimination, harassment, fraud, deception, exploitation or unlawful surveillance;

c. use the Platform to make decisions prohibited by Applicable AI Laws;

d. create or deploy malware, ransomware or malicious code;

e. conduct prompt injection, model manipulation, data poisoning or adversarial attacks other than authorised internal testing in an isolated environment;

f. interfere with the integrity, availability or performance of the Platform;

g. circumvent access controls, rate limits, licence restrictions or usage limits;

h. gain access to another customer’s systems or data;

i. reverse engineer, decompile or disassemble the Platform except where such restriction is prohibited by mandatory law;

j. attempt to extract source code, system prompts, proprietary datasets, model weights or non-public architecture;

k. use the Platform or its non-public materials to build a substantially competing platform;

l. resell, sublicense, rent or provide the Platform as a service bureau without written authorisation;

m. conduct penetration tests or vulnerability scans against TietAI-hosted infrastructure without prior written authorisation;

n. submit data that Customer is not legally entitled to process;

o. use trial, beta or evaluation functionality in production or safety-critical workflows; or

p. represent the Platform as a medical device, diagnostic product or healthcare service.

TietAI may investigate suspected violations and suspend affected access where reasonably necessary to protect customers, individuals, the Platform or third parties.

10. Third-Party Services and models

10.1 Customer-selected services

Customer may connect the Platform to Third-Party Services, including external AI models, cloud platforms, electronic record systems, databases, messaging services and business applications.

Customer is responsible for:

a. selecting and authorising Third-Party Services;

b. maintaining the necessary licences and accounts;

c. configuring credentials and access permissions;

d. accepting applicable third-party terms;

e. assessing the security and regulatory suitability of those services; and

f. determining whether Customer Data may lawfully be transmitted to them.

10.2 Third-party terms

Third-Party Services are governed by their own terms and privacy practices.

TietAI does not control and is not responsible for the continued availability, functionality, pricing, output, security or regulatory status of a Third-Party Service.

10.3 Changes and discontinuation

A Third-Party Service may change or discontinue an API, model, feature or commercial term.

TietAI may modify or discontinue a related connector where continued support is not technically, legally or commercially reasonable.

TietAI will provide reasonable notice where practicable.

10.4 Pass-through consumption

Where TietAI purchases model, cloud or API consumption on Customer’s behalf, the applicable Order Form may include pass-through charges, usage allowances or provider-specific restrictions.

11. Data protection

11.1 Compliance

Each party shall comply with the data protection laws applicable to its own processing activities.

Customer is responsible for determining the lawful basis, purposes and scope of its processing of Customer Data, including Patient Data.

Where required, Customer shall obtain all necessary authorisations, notices, approvals, consents, ethics opinions or research permissions.

11.2 TietAI Cloud Deployment

Where TietAI processes personal data on Customer’s documented instructions in a TietAI Cloud Deployment:

a. Customer acts as controller or processor, as applicable;

b. TietAI acts as processor or sub-processor, as applicable; and

c. the Data Processing Agreement applies.

The parties’ actual legal roles prevail over any incorrect contractual description.

11.3 Customer-Controlled Deployment

In a Customer-Controlled Deployment, Customer controls the deployment environment and the Customer Data processed within it.

Where TietAI does not access personal data, the licensing and provision of the Platform does not, by itself, make TietAI a processor of that personal data.

Where TietAI accesses personal data for support, maintenance, incident response, implementation or another agreed service, the Data Processing Agreement applies to that access.

11.4 TietAI as independent controller

TietAI acts as an independent controller for personal data processed for its own legitimate business purposes, including:

a. account administration;

b. contract and relationship management;

c. billing and payment;

d. corporate security;

e. fraud and abuse prevention;

f. service communications;

g. compliance with legal obligations; and

h. establishment, exercise or defence of legal claims.

Such processing is governed by TietAI’s applicable privacy notice.

11.5 Support access

Where support access may expose TietAI personnel to Customer Data, access shall be:

a. limited to authorised personnel;

b. based on a legitimate support need;

c. time-bound where technically practicable;

d. protected through appropriate authentication;

e. logged; and

f. subject to confidentiality obligations.

11.6 Sub-processors

TietAI may use sub-processors to deliver the Services.

The current list of sub-processors is available at [SUB-PROCESSOR URL].

TietAI shall provide notice of material additions or replacements and permit objections on reasonable data protection grounds in accordance with the Data Processing Agreement.

11.7 International transfers

Where TietAI transfers personal data outside the European Economic Area, it shall use a lawful transfer mechanism and implement supplementary safeguards where required.

Available data residency options, where any, are specified in the Order Form or Documentation.

11.8 Data minimisation

Customer shall not submit personal data that is unnecessary for the relevant workflow.

Customer shall configure Customer Agents, prompts, logs and connected tools to minimise the disclosure of Patient Data and other sensitive information.

12. Customer Data, Outputs and service improvement

12.1 Customer ownership

As between the parties, Customer retains all right, title and interest in Customer Data and Customer Materials.

Customer grants TietAI a non-exclusive, worldwide and limited licence to host, copy, transmit, transform, process and display Customer Data and Customer Materials solely as necessary to:

a. provide and secure the Services;

b. provide support requested by Customer;

c. prevent abuse;

d. comply with Customer’s documented instructions; and

e. comply with applicable legal obligations.

12.2 Customer responsibility for data

Customer warrants that it has all rights and lawful bases required to provide Customer Data and Customer Materials to TietAI and to authorise their processing under the Customer Agreement.

12.3 Outputs

As between TietAI and Customer, and to the extent permitted by applicable law and applicable Third-Party Service terms, Customer may use Outputs generated for Customer through the Platform.

Customer acknowledges that:

a. Outputs may not qualify for intellectual property protection;

b. similar or identical Outputs may be generated for other users;

c. Outputs may incorporate or resemble third-party material;

d. TietAI does not guarantee that Outputs are unique or non-infringing; and

e. Customer must review Outputs before relying on or distributing them.

12.4 No training on Customer Data without authorisation

TietAI shall not use identifiable Customer Data, Customer Materials or confidential Customer content to train, fine-tune or improve a general-purpose or shared AI model without Customer’s prior written authorisation.

This restriction does not prevent TietAI from:

a. processing Customer Data to provide the Services;

b. performing customer-specific evaluations or configurations requested by Customer;

c. using security signals to detect fraud, abuse or attacks;

d. using operational telemetry that does not reveal Customer Data; or

e. using data that has been lawfully anonymised so that individuals and Customer cannot reasonably be identified.

12.5 Aggregated operational information

TietAI may generate aggregated operational statistics concerning service performance, reliability, security, usage patterns and infrastructure capacity.

TietAI shall not disclose aggregated information in a manner that identifies Customer or an individual.

12.6 Retention and deletion

Customer Data shall be retained and deleted in accordance with the Customer Agreement, the Data Processing Agreement and the applicable retention configuration.

TietAI may retain limited records where required by law, for security purposes or for the establishment, exercise or defence of legal claims.

13. Security

13.1 TietAI security obligations

TietAI shall maintain appropriate technical and organisational measures designed to protect Customer Data within TietAI’s control against unauthorised access, accidental loss, destruction, alteration or disclosure.

The applicable measures are described in the Security Schedule at [SECURITY URL] and, where personal data is processed, in the Data Processing Agreement.

TietAI may update its security measures provided that the overall level of protection is not materially reduced.

13.2 Shared responsibility

Security responsibilities depend on the deployment model.

In a Customer-Controlled Deployment, Customer is responsible for:

a. infrastructure and network security;

b. identity and access management;

c. operating systems and runtime configuration;

d. secrets and key management;

e. backup and recovery;

f. logging and monitoring;

g. patch deployment;

h. connected systems; and

i. security of Customer Agents and Customer-developed code.

TietAI remains responsible for vulnerabilities in the unmodified Platform software supplied by TietAI, subject to Customer applying supported security updates.

13.3 Security incidents

TietAI shall notify Customer without undue delay after confirming a security incident affecting Customer Data within TietAI’s control.

Where the incident constitutes a personal data breach, notification and cooperation obligations are governed by the Data Processing Agreement.

Customer shall notify TietAI without undue delay of any security incident, compromised credential, vulnerability or misuse that may affect the Platform or other customers.

13.4 Security updates

TietAI may issue security patches, updates or remediation instructions.

Customer shall apply critical security updates within the timeframe specified by TietAI or otherwise take appropriate mitigating measures.

TietAI may suspend an affected component where continued operation creates a material security risk.

13.5 Security testing

Customer may conduct security testing of Customer-controlled components.

Testing of TietAI-hosted infrastructure requires prior written authorisation and must comply with TietAI’s responsible disclosure and security testing policies.

14. Availability, support and Platform changes

14.1 Service levels

Availability commitments, support hours, severity definitions and response targets are specified in the applicable Service Level Agreement.

Where no Service Level Agreement applies, TietAI shall provide the Services using commercially reasonable efforts.

14.2 Maintenance

TietAI may perform scheduled maintenance and shall provide reasonable advance notice where the maintenance is expected to materially affect availability.

Emergency maintenance may be performed without advance notice where necessary to address a security, legal, operational or infrastructure risk.

14.3 Platform updates

TietAI may update, enhance, replace or modify the Platform.

TietAI shall not materially reduce the core functionality purchased by Customer during the current subscription term without providing reasonable notice, except where required to address:

a. a security vulnerability;

b. an unlawful use;

c. a third-party dependency;

d. a regulatory requirement; or

e. a material risk to the Platform or its users.

14.4 Deprecation

TietAI shall provide reasonable advance notice before discontinuing a generally available material feature.

The applicable notice period may be specified in the Order Form or Documentation.

14.5 Beta and preview functionality

Features identified as alpha, beta, preview, experimental or evaluation functionality:

a. may be incomplete;

b. may change or be discontinued without notice;

c. may not be covered by service levels;

d. must not be used in production or safety-critical workflows unless expressly authorised; and

e. are provided without warranties except where mandatory law provides otherwise.

15. Fees and payment

15.1 Fees

Fees, billing metrics, included usage and subscription periods are specified in the applicable Order Form.

Unless expressly stated otherwise, fees are exclusive of VAT and other applicable taxes.

15.2 Invoicing

Invoices are payable within [30] days from the invoice date unless the Order Form states otherwise.

Customer shall provide accurate billing and purchase order information.

15.3 Usage charges

Where Services are usage-based, Customer is responsible for charges generated through its accounts, Customer Agents and connected environments.

TietAI may provide usage dashboards or alerts, but Customer remains responsible for monitoring its own consumption.

15.4 Late payment

Overdue undisputed amounts may accrue interest at the rate permitted by applicable law.

TietAI may suspend Services for material non-payment after providing written notice and a reasonable opportunity to cure.

15.5 Renewal

Unless the Order Form states otherwise, TietAI may change fees upon renewal by providing at least [60] days’ advance notice.

15.6 Refunds

Fees are non-refundable except as expressly stated in the Customer Agreement or required by applicable law.

16. Intellectual property

16.1 TietAI technology

TietAI and its licensors retain all right, title and interest in:

a. the Platform;

b. TietAI software, APIs and SDKs;

c. runtime and orchestration technology;

d. TietAI connectors and templates;

e. TietAI models and algorithms;

f. Documentation;

g. improvements and derivative works of the foregoing; and

h. all associated intellectual property rights.

No rights are granted except the limited rights expressly set out in the Customer Agreement.

16.2 Customer Agents and configurations

As between the parties, Customer owns Customer Materials and Customer-specific configurations created by Customer.

Where a Customer Agent incorporates TietAI software, templates, components or proprietary technology, the underlying TietAI materials remain owned by TietAI.

Customer’s ownership of a configuration does not grant Customer ownership of the Platform used to execute that configuration.

16.3 Professional services

Ownership of deliverables created under professional services shall be governed by the applicable Statement of Work.

Unless the Statement of Work states otherwise:

a. Customer owns deliverables created uniquely for Customer, excluding TietAI Background Technology; and

b. TietAI retains ownership of pre-existing materials, generic components, know-how, tools, methods, frameworks and reusable technology.

16.4 Feedback

Customer may provide suggestions or feedback concerning the Platform.

TietAI may use feedback without restriction or payment, provided that it does not disclose Customer’s confidential information or Customer Data.

17. Confidentiality

17.1 Confidential information

Each party may receive confidential information from the other.

Confidential information includes non-public technical, commercial, financial, security, product, customer and business information, Customer Data and the non-public operation of the Platform.

17.2 Protection

The receiving party shall:

a. use confidential information only for purposes of the Customer Agreement;

b. protect it with at least reasonable care;

c. disclose it only to personnel, affiliates and subcontractors with a need to know and equivalent confidentiality obligations; and

d. not disclose it to third parties except as permitted by these Terms.

17.3 Exclusions

Confidential information does not include information that the receiving party can demonstrate:

a. is publicly available without breach;

b. was lawfully known before disclosure;

c. was received lawfully from a third party without confidentiality restriction; or

d. was independently developed without use of the disclosing party’s confidential information.

17.4 Required disclosure

A party may disclose confidential information where required by law or a competent authority, provided that it gives advance notice where legally permitted and reasonably cooperates in seeking confidential treatment.

17.5 Duration

Confidentiality obligations continue for five years following termination.

Obligations concerning trade secrets, credentials, security information and personal data continue for as long as the information remains protected or confidential by its nature or applicable law.

18. Warranties and disclaimers

18.1 TietAI warranty

TietAI warrants that, during the subscription term:

a. the Services will be provided with reasonable skill and care;

b. the Platform will materially conform to the applicable Documentation; and

c. TietAI will not knowingly introduce malicious code into the Platform.

Customer’s exclusive remedy for breach of this warranty is correction, re-performance or, where TietAI cannot materially remedy the breach, termination of the affected Service and refund of prepaid fees for the unused affected period.

18.2 Customer warranties

Customer warrants that:

a. it has authority to enter into the Customer Agreement;

b. it has all necessary rights and lawful bases for Customer Data and Customer Materials;

c. it will use the Platform in accordance with applicable law;

d. it will not misrepresent the regulatory status of the Platform; and

e. it will implement appropriate review, testing, security and governance for Customer Agents.

18.3 AI limitations

Customer acknowledges that AI systems and probabilistic models may generate Outputs that are:

a. inaccurate;

b. incomplete;

c. misleading;

d. inconsistent;

e. biased;

f. outdated;

g. inappropriate for the relevant context; or

h. different when the model, prompt, data or environment changes.

Customer is responsible for independently reviewing Outputs and determining whether they are appropriate for the intended use.

18.4 No compliance guarantee

The Platform may provide tools that support governance, security, audit, interoperability and regulatory processes.

TietAI does not warrant that use of the Platform, Hydra Govern, a template, an evaluation or a policy configuration will, by itself, make Customer or a Customer Agent compliant with any law, regulation, standard or contractual requirement.

18.5 General disclaimer

Except for the express warranties in the Customer Agreement, and to the maximum extent permitted by law, the Services are provided without additional express or implied warranties.

TietAI does not warrant that:

a. the Platform will be uninterrupted or error-free;

b. every defect will be corrected;

c. every Third-Party Service will remain available;

d. every Output will be accurate, unique or suitable;

e. a Customer Agent will achieve Customer’s intended outcome; or

f. the Platform will satisfy requirements not expressly agreed in writing.

19. Indemnities

19.1 TietAI intellectual property indemnity

TietAI shall defend Customer against a third-party claim alleging that Customer’s authorised use of the unmodified Platform infringes that third party’s intellectual property rights and shall indemnify Customer against damages finally awarded or agreed in a settlement approved by TietAI.

TietAI has no obligation to the extent a claim arises from:

a. Customer Data or Customer Materials;

b. a Customer Agent;

c. a Third-Party Service;

d. modification not made by TietAI;

e. use contrary to the Documentation or Customer Agreement;

f. continued use after TietAI has provided a non-infringing replacement; or

g. combination with items not supplied or approved by TietAI where the combination caused the claim.

TietAI may modify or replace the affected Service, obtain continued usage rights or terminate the affected Service and refund prepaid fees for the unused affected period.

19.2 Customer indemnity

Customer shall defend and indemnify TietAI against third-party claims arising from:

a. Customer Data or Customer Materials;

b. a Customer Agent’s intended purpose, configuration, Output or action;

c. Customer’s violation of applicable law;

d. Customer’s infringement of third-party rights;

e. an unauthorised regulatory or medical claim made by Customer;

f. Customer’s failure to implement appropriate human oversight; or

g. Customer’s use of the Platform in breach of clause 5 or clause 9.

Customer is not responsible to the extent the claim was caused by TietAI’s breach, negligence, wilful misconduct or an unmodified defect in the Platform.

19.3 Procedure

An indemnity is conditional on:

a. prompt notice of the claim;

b. the indemnifying party controlling the defence and settlement;

c. reasonable cooperation by the indemnified party; and

d. no admission or settlement by the indemnified party without consent.

No settlement may require the indemnified party to admit wrongdoing, make a payment or accept a continuing obligation without its consent.

20. Limitation of liability

20.1 Liability that cannot be limited

Nothing in the Customer Agreement excludes or limits liability for:

a. fraud or fraudulent misrepresentation;

b. wilful misconduct;

c. death or personal injury caused by negligence; or

d. any liability that cannot lawfully be excluded or limited.

20.2 Excluded losses

Subject to clause 20.1, neither party is liable for:

a. indirect or consequential loss;

b. loss of profit;

c. loss of revenue;

d. loss of anticipated savings;

e. loss of goodwill;

f. loss of business opportunity; or

g. business interruption,

except to the extent such loss forms part of damages payable to a third party under an indemnified claim.

20.3 General liability cap

Subject to clauses 20.1 and 20.4, each party’s total aggregate liability arising out of or in connection with the Customer Agreement shall not exceed the total fees paid or payable by Customer for the affected Services during the twelve months immediately preceding the event giving rise to the claim.

20.4 Enhanced liability cap

Liability arising from:

a. breach of confidentiality;

b. TietAI’s breach of its data protection obligations;

c. Customer’s breach of clause 9;

d. infringement or misappropriation of the other party’s intellectual property rights; or

e. obligations under clause 19,

shall be subject to an aggregate cap equal to [TWO TIMES THE GENERAL CAP / AGREED AMOUNT].

20.5 Allocation of risk

The limitations in this clause reflect the allocation of risk between the parties and apply regardless of the legal basis of the claim, including contract, tort, negligence, statutory duty or otherwise.

21. Suspension and termination

21.1 Term

The Customer Agreement begins on the effective date stated in the applicable Order Form and continues for the agreed subscription term.

21.2 Suspension

TietAI may suspend all or part of the Services where reasonably necessary to address:

a. a material security threat;

b. an unlawful use;

c. a breach of clause 9;

d. material non-payment;

e. a risk to other customers or the Platform;

f. a binding request from a competent authority; or

g. use outside the agreed scope that may expose TietAI to regulatory liability.

Where practicable, TietAI shall provide notice and an opportunity to remedy the issue before suspension.

TietAI shall limit the suspension to the affected Services and restore access when the reason for suspension has been resolved.

21.3 Termination for breach

Either party may terminate the Customer Agreement for material breach where the breach is not remedied within thirty days after written notice.

A shorter cure period may apply where the breach creates an immediate security, legal or data protection risk.

21.4 Insolvency

Either party may terminate immediately where the other party becomes insolvent, enters liquidation or becomes subject to an equivalent procedure, except where prohibited by applicable insolvency law.

21.5 Effect of termination

Upon termination:

a. Customer’s right to use the Platform ends;

b. Customer shall stop accessing TietAI Cloud Deployments;

c. Customer shall stop using and remove Platform software from Customer-Controlled Deployments, unless otherwise agreed;

d. outstanding fees become payable; and

e. each party shall return or delete confidential information as required by the Customer Agreement.

21.6 Data export and transition

For a TietAI Cloud Deployment, Customer may export Customer Data using the available export functionality during the subscription term and for [30/90] days following termination.

TietAI shall provide reasonable information and assistance required by applicable law to enable Customer to switch to another service or to Customer-controlled infrastructure.

Additional transition, migration or professional services may be subject to reasonable fees unless such fees are prohibited by applicable law.

21.7 Deletion

Following the applicable export period, TietAI shall delete or return Customer Data in accordance with the Data Processing Agreement, subject to legally required retention and normal backup deletion cycles.

21.8 Survival

Clauses concerning payment, intellectual property, confidentiality, disclaimers, indemnities, liability, data return, governing law and any provisions intended by their nature to survive shall continue after termination.

22. Compliance and cooperation

22.1 Customer environment

Customer is responsible for compliance obligations arising from:

a. its industry;

b. its Customer Agents;

c. its processing purposes;

d. its connected systems;

e. its professional activities; and

f. the jurisdictions in which it operates.

22.2 Regulatory requests

Each party shall reasonably cooperate with the other in responding to lawful requests from competent authorities that relate directly to the Services or Customer Data.

Cooperation shall be subject to confidentiality, data minimisation, security, professional secrecy and applicable law.

22.3 Audit

Audit rights relating to personal data are governed by the Data Processing Agreement.

Where Customer reasonably requires security assurance, TietAI may provide available independent audit reports, certifications, summaries or questionnaires.

On-site audits shall be limited to circumstances where documentary assurance is insufficient, required by applicable law or agreed in writing.

22.4 No public disclosure of security information

Customer shall not publicly disclose confidential security findings without first giving TietAI a reasonable opportunity to investigate and remediate them, except where disclosure is legally required.

23. Changes to these Terms

TietAI may amend these Terms from time to time.

Material changes will take effect after at least sixty days’ notice, unless a shorter period is required to:

a. comply with law;

b. address a security risk;

c. prevent abuse; or

d. reflect a mandatory change imposed by a Third-Party Service.

Where a material amendment materially reduces Customer’s contractual rights during a current paid subscription term, Customer may terminate the affected Services before the amendment takes effect and receive a pro rata refund of prepaid fees for the unused affected period.

Changes do not retroactively alter an individually negotiated Customer Agreement unless agreed in writing.

24. General provisions

24.1 Assignment

Neither party may assign the Customer Agreement without the other party’s prior written consent, except to an affiliate or in connection with a merger, reorganisation or sale of substantially all relevant assets.

An assignment does not release the assigning party from obligations accrued before assignment.

24.2 Subcontracting

TietAI may use subcontractors to provide the Services and remains responsible for their performance to the extent required by the Customer Agreement.

Sub-processing of personal data is governed by the Data Processing Agreement.

24.3 Force majeure

Neither party is liable for delay or failure caused by circumstances beyond its reasonable control, including natural disaster, war, civil disorder, epidemic, widespread telecommunications failure, government action or failure of critical third-party infrastructure.

Force majeure does not excuse payment obligations already due.

24.4 Export controls and sanctions

Each party shall comply with applicable export control and sanctions laws.

Customer shall not use or make the Platform available in a jurisdiction or to a person where doing so would cause TietAI to violate applicable restrictions.

24.5 Notices

Formal notices to TietAI shall be sent to [LEGAL EMAIL] and to its registered office.

Formal notices to Customer shall be sent to the administrative or legal contact specified in the applicable Order Form.

Operational and service notices may be sent by email or through the Platform.

24.6 Independent contractors

The parties are independent contractors.

Nothing in the Customer Agreement creates a partnership, joint venture, fiduciary relationship, agency, employment relationship or healthcare provider relationship.

24.7 Third-party rights

Except where expressly stated, the Customer Agreement does not grant enforceable rights to any third party.

24.8 Severability

If a provision is held invalid or unenforceable, the remaining provisions continue in effect.

The invalid provision shall be interpreted or replaced to reflect its commercial purpose as closely as legally possible.

24.9 Waiver

Failure or delay in exercising a right does not waive that right.

24.10 Entire agreement

The Customer Agreement constitutes the entire agreement between the parties concerning its subject matter and supersedes prior proposals, discussions, statements and representations.

24.11 Electronic execution

The Customer Agreement may be accepted or executed electronically and in counterparts.

25. Governing law and jurisdiction

25.1 Governing law

The Customer Agreement is governed by the laws of Spain, excluding conflict-of-laws principles and the United Nations Convention on Contracts for the International Sale of Goods.

25.2 Jurisdiction

The courts of Madrid, Spain shall have exclusive jurisdiction over disputes arising from the Customer Agreement.

Either party may seek urgent injunctive or protective relief before any competent court.

25.3 Public sector customers

Where Customer is a public body and mandatory procurement, administrative law or jurisdictional rules apply, those mandatory rules prevail to the minimum extent required.

Any alternative governing law or dispute forum must be stated in the applicable Order Form or Customer Agreement.

26. Language

These Terms are drafted in English.

Where a translation is provided, the English version prevails unless mandatory law or an applicable public procurement requirement provides otherwise.

27. Contact

Tiet AI S.L.
Calle FUENTERRABIA, Número 9, puerta 6
28014 Madrid, Spain

Legal: legal@tiet.ai
Privacy and data protection: privacy@tiet.ai
Security: security@tiet.ai
Support: support@tiet.ai