Terms of Use and Sale
Last updated: April 5, 2026
1. Purpose
These terms of use (hereinafter "Terms") govern access to and use of the service ward-ai.io (hereinafter "the Service") published by KRP. Use of the Service implies full and unconditional acceptance of these Terms.
2. Description of the Service
The Service provides a conversational AI specialized in European regulatory compliance (DORA, NIS2, ISO 27001, SOC 2, GDPR, NIST CSF). It includes:
- a conversational agent with retrieval-augmented generation (RAG) over a curated knowledge base of official sources;
- a document analysis feature (OCR + summarization);
- an embeddable JavaScript widget for client websites;
- an authenticated REST API;
- a management dashboard (usage, billing, security).
3. Account and Authentication
Access to the Service requires the creation of an account by a client administrator. The client is responsible for maintaining the confidentiality of their credentials and for all activity conducted through their account. Enabling two-factor authentication (TOTP) is strongly recommended and mandatory for sensitive actions.
4. Pricing Model — Prepaid Credits
The Service operates on a prepaid model. The client purchases credits (internal unit) that are consumed on usage. Current rates and pricing are available on the pricing simulator on the main page. Prices may be adjusted at any time; the rates displayed on the pricing simulator at the time of purchase apply.
Purchased credits do not expire as long as the account remains active. They are neither refundable nor transferable between accounts, except where required by law (consumer right of withdrawal).
Payment is processed via Stripe. Invoices are generated automatically and accessible from the client dashboard. Displayed prices are exclusive of taxes. The applicable VAT (Value Added Tax) is calculated automatically based on the client's country of tax residence and added to the invoice amount, in accordance with applicable regulations.
5. Acceptable Use
The client agrees not to:
- use the Service for illegal or fraudulent purposes;
- attempt to circumvent security mechanisms (rate limiting, IP whitelist, quotas);
- engage in scraping, reverse engineering, or bulk extraction of the knowledge base;
- submit defamatory, abusive, discriminatory content, or content that infringes the rights of third parties;
- resell or redistribute the Service without prior written consent.
6. Client Data and Confidentiality
Questions submitted by the client's end users, as well as documents they submit for analysis, are processed on behalf of the client. KRP acts as a data processor within the meaning of Article 28 GDPR. A Data Processing Agreement (DPA) is annexed to these Terms and signed electronically upon subscription.
Uploaded documents are stored temporarily with a configurable retention period (TTL) set by the client administrator. The client may purge all uploaded files at any time from the dashboard.
7. Intellectual Property
The source code, interface, aggregated knowledge base, and proprietary developments remain the exclusive property of KRP. AI-generated responses are royalty-free for the client's internal use; external republication (e.g., for third-party commercial use) requires an explicit attribution to the Service as the source.
8. Availability and Maintenance
KRP targets a monthly uptime of 99.5%, excluding scheduled maintenance windows (announced 48 hours in advance). No guarantee of uninterrupted availability is provided.
9. Liability
The Service is a decision-support tool. It does not replace qualified legal, regulatory, or technical advice. Responses are provided "as is," and the client remains solely responsible for their interpretation and implementation.
KRP's total liability, for all causes combined, is limited to the amounts actually paid by the client during the twelve (12) months preceding the event giving rise to the claim, except in cases of gross negligence or willful misconduct.
KRP shall not be held liable for any indirect, consequential, or incidental damages, including loss of revenue, data, or business opportunities.
10. Termination
The client may terminate their account at any time from the client dashboard. KRP reserves the right to suspend or terminate any account in the event of a breach of these Terms, with prior notice except in cases of urgency or threats to the security of the Service.
Upon termination, client data is retained for 30 days and then irreversibly destroyed (excluding data subject to legal retention obligations: invoices, audit logs).
11. Governing Law — Jurisdiction
These Terms are governed by the laws of the Hong Kong Special Administrative Region. Any dispute shall be subject to the exclusive jurisdiction of its courts.
12. Contact
contact@ward-ai.io — for any questions regarding these Terms.