KIST / LEGAL
Terms of service
[TBD — date on publication]
1. Who these terms are between
These terms are between Grapeworks Ltd, company number SC782424, registered office Studio One, 89 Middlesex Street, Glasgow, G41 1EE, and the business that signs up for Kist. Where an agency buys Kist to serve its own clients, the agency is the customer under these terms, and its client relationships are the agency’s own.
Data protection sits in a separate data processing agreement, and that agreement takes precedence over these terms on anything to do with personal data.
2. What Kist is
Kist takes the marketing and business data a company already has, spread across advertising platforms, analytics, search, a CRM and an accounting system, puts it in one place, and produces analysis a person can act on.
It is an internal tool made available to businesses that want the same thing. Access is per account, on credentials we issue.
3. What Kist is not
Worth stating plainly, because these are the assumptions that cause arguments later.
- It is not a replacement for your own record-keeping. It reads from your platforms; it is not the system of record for anything.
- It is not advice. Kist produces recommendations. Whether to act on one is a commercial decision that stays with you.
- It is not a guarantee of a result. We can work through the data faster than a person can and surface things a person would miss. Nobody can promise what your market does next.
- It is not an audit or an assurance service, and nothing it produces is a regulated opinion.
4. Your account
You are responsible for who you give access to and for what they do with it. Tell us promptly if an account is compromised.
You must not attempt to circumvent the isolation between accounts, probe the service for vulnerabilities without our written agreement, resell access unless we have signed a separate reseller agreement with you, or use the service to process data you have no lawful basis to process.
We may suspend an account immediately where continuing would breach the law or put other customers’ data at risk. For anything short of that, we will tell you what the problem is and give you a reasonable chance to fix it before we suspend anything.
5. Fees
Charges, billing period and notice are set in your order form or engagement letter, which sits alongside these terms. Fees are exclusive of VAT. Where a charge depends on usage, the measure is stated in the order form rather than here.
Price changes take effect at the next renewal and are notified in advance.
[TBD — no price]
No price may appear on the Kist site or in these terms until a row exists in the decided-claims register. This is a hard gate from the Phase 23 scope, not a formatting note.
6. Connecting your data
You give us access to your platforms, or your client’s, using credentials you delegate. You confirm that you are entitled to do that.
Where you are an agency connecting a client’s data, you confirm three things, and they are the precondition of us being lawfully engaged at all: that you hold a compliant data processing agreement with that client, that the client has authorised sub-processing, and that our data processing agreement with you is signed before the first connection.
No client data moves before that agreement is signed. The connector step is the gate.
You can disconnect a source at any time. We return or delete the data within thirty days and confirm in writing.
7. What we owe you on the service
We will run the service with reasonable skill and care, keep the security measures described in the privacy policy and the data processing agreement, give you thirty days notice before we add or replace a sub-processor, and tell you about planned maintenance that will interrupt the service.
[TBD — uptime commitment]
We do not commit to an uptime percentage. A service level here is a promise we have to be able to keep and to measure. Recommendation on file: none in v1, with honest incident communication instead. Euan’s call.
8. Intellectual property
Your data stays yours. We claim no ownership of anything you connect or upload.
Kist, its software, models, and the analysis logic stay ours. You get a non-exclusive, non-transferable right to use the service for the term.
Reports and outputs Kist produces for you are yours to use in your business and with your clients.
We may use aggregated, anonymised information about how the service is used to improve it. This never includes your client data and never produces a figure attributable to you or your clients.
9. Warranties
Solicitor scope. What we mean: the service is provided as described, we will run it with reasonable skill and care, and beyond that we do not warrant that the analysis is correct, complete or fit for a particular decision. Because Kist produces recommendations from third-party data we do not control, an implied fitness-for-purpose warranty is the exposure that matters. Draft the exclusion so it survives the Unfair Contract Terms Act 1977 reasonableness test in a business-to-business contract under Scots law.
10. Liability
Solicitor scope, and the priority section on the page. What we mean: a cap tied to fees paid in the preceding twelve months, no liability for indirect or consequential loss, no liability for loss of profit or anticipated savings arising from a commercial decision the customer took on the back of an analysis, and nothing excluded that cannot lawfully be excluded (death or personal injury from negligence, fraud, ICO administrative fines).
The specific question that needs answering, and it is the one the reseller agreement turns on too: who eats a loss when an agency’s client sues the agency over something Kist produced? That allocation needs to be consistent across these terms, the data processing agreement and the reseller agreement. Three documents, one answer, and today there is no answer in any of them.
[TBD — liability cap figure]
Set once and referenced from the services agreement, not restated here. No figure exists yet.
11. Indemnities
Solicitor scope. What we mean: the customer indemnifies us where it connected data it had no right to connect, or instructed us to do something that breached data protection law after we told them it would. We indemnify on our own breach of confidentiality or security. The shape is standard; the interaction with section 10’s cap is not, and that is the bit to get right.
12. Term and ending it
The term is set in your order form. Either side can end it for material breach that is not fixed within thirty days of written notice, or immediately on insolvency.
On termination your access stops, and we return or delete your data within thirty days and confirm in writing.
Sections that should outlive the contract do: confidentiality, the data protection obligations, intellectual property, and whatever the solicitor settles in sections 9 to 11.
13. Confidentiality
Each side keeps the other’s confidential information confidential and uses it only for the contract. This does not cover information that is already public, was already known without obligation, or has to be disclosed by law.
14. Audit
You may audit our compliance with the data processing agreement once in any twelve-month period, on thirty days written notice, at your cost, and without disrupting other customers. Shorter notice applies where there has been a breach or a regulator asks. We may answer with a recent third-party report or a completed security questionnaire where that genuinely covers the question.
15. Changes to these terms
We will give reasonable notice of a change and will not make a material change mid-term without telling you. If a change materially disadvantages you, you can end the contract at that point without penalty.
16. General
Neither side may assign without the other’s consent, except to a successor of the whole business.
No third party has rights under these terms. For the avoidance of doubt in the reseller chain, an agency’s client is not a third-party beneficiary of this contract and takes its rights against the agency, not against us.
[TBD — third-party rights exclusion, Scots law]
The Contract (Third Party Rights) (Scotland) Act 2017 is the relevant statute and the drafting differs from the English equivalent. Solicitor to confirm the correct exclusion.
Force majeure applies to events genuinely outside a party’s control, and does not cover a failure to pay.
Notices go to euan@grapeworks.ai and to the address on your order form.
17. Governing law
Scots law, exclusive jurisdiction of the Scottish courts.