Client agreement.
Read how the subscription, ownership, support and leaving arrangements work.
Client service agreement
1. Who agrees, and what makes up the agreement
This agreement is between Simone's Kitchen BV, trading as AI Smith, Breughelstraat 32, 2018 Antwerpen, Belgium, company and VAT number BE 0649.403.122 ("AI Smith", "we" or "us"), and the organisation identified in the order form ("client" or "you"). The legal name must be confirmed before signing. Each signatory confirms authority to bind their organisation.
The agreement comprises the signed order, this version of the service agreement, the completed data-processing schedule and any expressly attached service or custom-work schedule. It takes effect when both parties sign. Browsing the website, trying a demo or submitting an enquiry does not create a service contract. Payment alone does not add an unagreed scope.
Mandatory law takes priority. The processing schedule prevails for personal-data processing. An expressly identified, signed variation prevails for its stated subject; otherwise this agreement governs and the order supplies the client-specific details. No variation may remove mandatory protections. A later website edit does not change an existing signed agreement.
2. What we provide
We provide and operate the Website, Hub, Mobile app and connections selected in your order, within the documented capabilities and limits agreed there. A branded Mobile app requires the Hub. Your order records any dependencies, delivery stages, account responsibilities and services awaiting a separate confirmed delivery date. An unselected option is not included.
The subscription includes self-service configuration, supported standard imports, operation, maintenance, shared software improvements and ordinary product support. There is no per-user fee. Your permitted use, storage and other technical limits, if applicable, must be disclosed in the order; we will not introduce undisclosed overage charges.
Preparing or cleaning source material, custom migration, bespoke code, private-network work, custom integration and other human services require a separate written scope and quote that you accept before work starts. Reporting a product fault is not purchased custom work. Standard interface languages recorded in the order are included. AI translation of content uses AI resources; human translation is not included.
We perform our services with reasonable professional skill and care. We remain responsible for our agreed work when we use subcontractors. This is not a promise that every third-party system will be uninterrupted or that every requested feature will be delivered.
3. Setup, delivery and your participation
Before accepting an order we identify the deliverable service, required permissions, supported connections and any unresolved prerequisites. A demo or selectable website option is not proof that an integration is compatible with your systems.
The order defines the core service, delivery date and practical acceptance checks. We notify you when that service is available and provide the agreed checks. You promptly report material non-conformities; we investigate and correct failures within our responsibility. Silence alone does not waive a defect. A live service being used is not acceptance of an undelivered feature.
You nominate an administrator, supply lawful content and accurate instructions, protect account credentials, maintain your own third-party subscriptions and provide reasonably required access. You review content and authorise publication and consequential actions. We explain delays caused by missing inputs and agree a revised timetable, rather than silently changing delivery.
If we cannot deliver the agreed core service by the order's final delivery date, you may cancel the undelivered part and receive its prepaid fees back. The order must explain how dependent parts are treated. A date extension requires written agreement.
4. Fees and payment
Your order fixes the subscription price, selected components, billing cadence, VAT treatment, amount due and first-year total. Prices are in euros excluding VAT unless expressly stated otherwise. An annual rate displayed per month is a monthly equivalent charged yearly.
The initial commitment is 12 months under either annual or monthly billing. Monthly billing does not mean monthly cancellation during that initial term. The service start date and any advance payment are stated in the order. Invoice payment time is 14 calendar days.
Third-party subscriptions, usage and store-account charges identified in the order are separate. We may not buy chargeable extras on your behalf without your authority. Human-service fees are invoiced only under their separate accepted quote. We correct billing errors and discuss genuinely disputed charges promptly; you pay undisputed amounts when due.
The agreed price stays fixed for the committed period. Proposed changes take effect only at a renewal, with at least 60 calendar days' written notice and the opportunity not to renew. Statutory tax changes apply as required by law. We do not silently reprice an existing order because the public price changes. Any late-payment interest or recovery costs must be lawful, proportionate and disclosed; no additional contractual penalty is set by this draft.
5. AI and outside services
Your subscription includes a one-off USD 20 AI starter allowance. After that, AI usage is paid through your own OpenRouter account and is separate from the subscription. The order records how the allowance is delivered and what happens when it is exhausted. We do not assume authority to create an unlimited spend or silently pay usage on your behalf.
Selected information may be sent to the external AI providers used for your requests. The approved processing schedule and provider settings govern personal-data handling. Your choice of a model does not itself approve a new subprocessor or international transfer. AI Smith does not use client material to train general-purpose models for its own benefit. External providers' actual retention and training settings must be recorded, not assumed.
AI output may be incomplete, inaccurate or unsuitable. You review it before relying on it, publishing it or sending it to others. It does not replace professional judgment. We remain responsible for our service obligations; requiring your review does not excuse our own fault. Regulated or high-impact automated decision-making is outside this standard scope unless separately assessed and expressly agreed with the necessary safeguards.
Connections to Claude, ChatGPT, accounting tools or other services require supported accounts, permissions and provider terms. Features can depend on those providers. If a material dependency changes, we explain the effect and propose an agreed alternative or an appropriate remedy for the affected service. We do not promise that every provider is interchangeable without work.
6. Support, maintenance and changes
Support is written product support in English or Dutch on Belgian business days, 09:00-17:00 Europe/Brussels, excluding Belgian public holidays. The target for an initial human response is two business days; it is not a guaranteed fix time. The order names the working channel and incident contact. There is no implied 24-hour staffed service or numerical uptime SLA. Any required SLA belongs in an expressly accepted schedule.
We investigate faults, maintain the agreed service and communicate material incidents and planned disruptive maintenance. Reasonable emergency measures may be taken to protect the service or data, with notice as soon as practicable. A requested improvement may be considered for a shared update; a request alone is not a promise to build it.
You may make supported configuration and content changes. Code, schema and integration changes follow the agreed review process. Additional chargeable work needs your approval. We do not materially reduce contracted functionality during a paid period without agreement or an appropriate remedy. Hosting, backup frequency, retention and recovery objectives must be specified in the completed technical schedule; code history is not a backup of client data.
7. What you own and may continue to use
Your data, supplied content, organisation identity and client-specific work created for you belong to you from creation. To the extent rights initially vest in AI Smith, we assign the transferable economic rights in that client-specific work to you as they arise, including rights to reproduce, adapt and operate it worldwide for their full legal duration. The order identifies that work; the agreed fees include consideration for these rights. Any formalities required for a valid assignment must be completed before signature.
Pre-existing and generally reusable AI Smith components remain AI Smith's property. For every such component included in your delivered system, we grant you a perpetual, worldwide, non-exclusive, royalty-free right to use, copy, maintain and modify it to operate your system, and to let a replacement operator do so for you. This right survives termination and includes the source needed to exercise it. It is not an exclusive right over our shared product or a licence to resell the shared platform as your own separate product.
Open-source and other third-party components remain subject to their disclosed licences. The order or handover inventory identifies material restrictions. We cannot assign rights we do not hold. Your rights in AI-generated output are only those available under applicable law and provider terms; exclusive copyright in every output is not guaranteed.
You grant us only the rights needed to deliver, secure and support your services. We do not publish your name, logo, work or data as a case study without your written permission. Ownership does not depend on remaining a subscriber. Payment disputes do not automatically revoke the continuing rights granted for the delivered system.
8. Confidentiality and personal data
Each party protects the other's non-public business, technical and personal information with appropriate care, uses it only for this agreement and shares it only with people who need it and owe confidentiality. The duty does not cover information lawfully public, independently developed or lawfully received without restriction. A legally compelled disclosure is limited to what is required, with prior notice where lawful. Duties survive termination while the information remains confidential; trade secrets remain protected while legally qualifying.
For client-controlled personal data, the completed processing schedule governs our processor role. Each party remains responsible for personal data it processes as an independent controller, such as its own statutory invoicing records. No blanket ownership statement displaces the rights of individuals or either party's legal duties.
9. Term, renewal, suspension and termination
The first year begins on the agreed service start date, when the core service is made available. After that year, the renewal period matches the chosen billing period: one month or one year. Either party may give at least 30 calendar days' notice before renewal. We send an annual-renewal reminder at least 45 days before it occurs. If we miss that reminder, you may cancel within 30 days after it is eventually sent and receive prepaid unused renewal fees back.
You may request a transfer at any time, including during the first year. For an early exit for convenience during that year, the financial obligation is the remaining committed fees less demonstrably avoided costs, subject to mandatory law. Monthly instalments keep their agreed dates unless both parties agree a settlement. There is no additional exit penalty. No first-year balance is charged where you validly terminate for our material unremedied breach; prepaid unused service fees are refunded. Mandatory switching rights prevail.
Either party may terminate for a material breach not remedied within 30 calendar days after written notice identifying it, or immediately where the breach cannot reasonably be remedied and termination is lawful. Any shorter statutory remedy period remains available.
We may suspend only the affected access where reasonably necessary to address an imminent security threat, unlawful use or materially overdue undisputed fees. For non-payment we first give written warning and at least 14 calendar days to remedy. Urgent protective suspension must be proportionate and explained promptly. We restore service promptly when its reason is resolved. Suspension does not permit destruction of data or obstruction of lawful retrieval.
If we end service for convenience, notice is at least 90 calendar days and not before the initial term expires. We cooperate with transfer and refund prepaid fees for service we will not provide. Insolvency and mandatory continuity rights remain governed by applicable law.
10. Leaving and the working-system handover
You may move to your own infrastructure or another operator. We provide the client repository and relevant history, database and file exports, configuration, dependency/licence inventory and a practical runbook. We transfer dedicated provider projects and domains where the provider permits; where direct account transfer is unavailable, we agree a migration and restore path that preserves the agreed working system. Shared credentials and other clients' resources are excluded; we identify and replace dependencies required for your system to continue.
The order identifies accounts you must hold, the destination, secure credential rotation and the checks used to confirm handover. It also records known portability limits before purchase. You or your new operator becomes responsible for ongoing hosting, provider bills, security and maintenance after the agreed handover point. Our future support and updates stop then, except for the agreed handover support. We remain responsible for breaches occurring before it.
The standard transfer is included, with reasonable assistance and a target completion within 30 calendar days of a valid request and required destination access. Any mandatory switching timetable prevails. We notify you promptly of impediments and agree lawful extensions; we cannot extend indefinitely by asking for unnecessary information. At least 30 calendar days of retrieval access after the agreed transition and 30 calendar days for handover questions are included. New development at the destination is separately quoted, not disguised as a mandatory transfer fee. We impose no standard switching or data-egress charge.
Fees already lawfully owed remain payable, but we do not withhold essential data retrieval or handover solely because an invoice is disputed. We preserve confidentiality and security during the transition. Data deletion follows your documented choice and the processing schedule.
The continuity annex must establish an independently usable route to obtain the necessary code, data, access and instructions if AI Smith stops operating. It must name the responsible contacts, lawful access mechanism and last successful recovery test. A promise in this agreement alone is not a substitute for that mechanism; do not sign with this annex incomplete.
11. Responsibility and limits
Each party is responsible for losses caused by its breach, subject to applicable law, causation and the other party's reasonable duty to mitigate. Neither party warrants uninterrupted service or a particular business outcome. This does not remove the obligation to deliver the agreed service with reasonable skill and care or the client's contractual remedies.
The aggregate limit for a party's ordinary contractual liability is the greater of EUR 5,000 or the fees paid or payable under the affected order for the 12 months preceding the event. For an event during the first year, use the agreed first-year fees. The limit for confidentiality or personal-data protection breaches is twice that amount instead. Related claims arising from the same cause are treated together. Counsel must settle the aggregation period and interaction between categories before this draft can be used.
No limit applies to fraud, intentional misconduct, gross negligence, death or personal injury, or liability that cannot lawfully be limited. Nothing restricts data subjects' statutory rights or a regulator's powers. Payment of lawfully due fees and the continuing IP rights are not extinguished by a damages cap. These limits have commercial approval and require counsel and insurance review; this draft makes no claim that they are enforceable or appropriate for every client.
12. Notices, unexpected events and disagreements
Send contractual notices to the addresses in the order; email is sufficient if delivered and retained, except where law requires another form. The receiving party acknowledges significant termination or incident notices promptly. A failed delivery must be followed up through an agreed alternative contact. Changes to the agreement require an authorised written agreement.
A party affected by an event beyond its reasonable control must notify the other, mitigate the effect and resume performance. Such an event does not automatically excuse preventable security or backup failures, remove data-protection duties or cancel accrued obligations. If a material service cannot be restored within 30 calendar days, either party may end the affected part and unused prepaid fees for undelivered services are refunded, subject to mandatory rights.
The parties first try to resolve a disagreement through their named contacts. Belgian law governs. Subject to mandatory jurisdiction rules, disputes go to the competent courts of Antwerp. If a clause is invalid, the rest continues where legally possible; neither party may rewrite the invalid clause unilaterally. Neither party may transfer its obligations to a new provider without the other's consent, except as permitted by mandatory law. Subcontracting does not release AI Smith from its responsibilities.
Signatures and the incorporated document versions are recorded in the order form.
Client order form
Parties and contacts
| Field | Agreed entry |
|---|---|
| Order reference and issue date | [complete] |
| Supplier legal name | Simone's Kitchen BV, trading as AI Smith; confirm registered name before signature |
| Supplier registered address and VAT number | Breughelstraat 32, 2018 Antwerpen, Belgium; BE 0649.403.122 |
| Client legal name, address, registration and VAT number | [complete] |
| Client business/organisational purpose | [complete]; confirm this is not a consumer purchase |
| Authorised signatories and roles | [complete] |
| Client administrator and support contact | [complete] |
| Each party's contractual notice email and alternative contact | [complete] |
| Each party's security/privacy contact | [complete] |
Your selected setup
| Service | Included configuration, scope, limits and dependencies |
|---|---|
| Website | [complete: standalone or with Hub; domains; content responsibilities] |
| Hub | [complete: work tracks, supported features, assistant tasks, interfaces] |
| Branded Mobile app | [complete: Hub dependency, stores, publisher-account owner, approval stages] |
| Standard connections | [complete: each category, actual provider, supported functions and account requirements] |
| Database connection | [complete: database, read-only scope, approved tables/fields, refresh, network path and tested limits] |
| Interface languages | [complete: supported starting language and any separately confirmed languages] |
| Included imports and self-service setup | [complete: formats, limits and help available] |
| Storage, usage or other service limits | [complete: measured scope, handling of capacity warnings; no undisclosed fees] |
| Separately quoted human work | [complete: accepted scope/quote references, or none] |
| Explicit exclusions and later phases | [complete: no uncertain item silently counted as delivered] |
Price and commitment
Use a dated, checked quote from the current pricing configuration. Do not incorporate a changing website rate by reference as the price of this signed order. App pricing includes its required Hub dependency; do not charge a standalone Website price again for Website-with-Hub.
| Field | Agreed amount or date |
|---|---|
| Billing cadence | [complete: annual or monthly] |
| Selected component prices before VAT | [complete: itemise] |
| Annual charge, or monthly instalment | EUR [complete] |
| First-year total before VAT | EUR [complete] |
| VAT rate, treatment and amount | [complete: verify, do not assume exemption] |
| First amount due including applicable VAT | EUR [complete] |
| Advance payment and what happens if delivery fails | [complete] |
| Core service availability/start date | [complete] |
| Initial 12-month term end date | [complete] |
| Renewal period, reminder and notice deadlines | [complete: approved renewal terms] |
| Early-exit calculation and example | [complete: approved early-exit terms, including avoided costs and instalment treatment] |
| Agreed payment method and invoice due date | [complete] |
| Separately invoiced human-service fees | [complete: reference accepted quote; not bundled into subscription total] |
| External subscriptions and store-account fees | [complete: who contracts, who pays, known estimates and source date] |
No per-user fee. One-off USD 20 AI starter allowance: [complete: funding mechanism, timing, usage tracking and exhaustion behaviour]. Client OpenRouter account and billing owner: [complete]. Do not enter API keys or payment-card details in this document.
Delivery and service schedule
- Core deliverables and acceptance checks: [complete].
- Dependencies and client inputs, responsible person and dates: [complete].
- Delivery date, final delivery deadline and dependency/refund treatment: [complete].
- Support channel, staffed hours, response target and escalation contact: [complete].
- Hosting region, provider roles and account ownership: [complete].
- Backup coverage, frequency, retention, encryption and last restore-test evidence: [complete].
- Recovery point/time objectives, whether targets or guarantees, and exclusions: [complete].
- Maintenance notice, incident communication and any agreed SLA: [complete].
- Approved human-work scope, deliverables and change approval: [complete].
Ownership and continuity schedule
- Client-specific deliverables and rights assigned: [complete].
- Shared AI Smith components and continuing licence: [complete; apply approved ownership and verify rights].
- Material third-party licences and restrictions: [complete].
- Account inventory: repository, hosting, database, domains, AI and app stores: [complete].
- Transfer method, export formats, metadata/files included, and known restrictions: [complete].
- Independently usable continuity mechanism if AI Smith stops, authorised contacts and last successful recovery exercise: [complete]. No shared passwords in the agreement.
- Standard transfer dates, retrieval period and handover-question support: [complete].
- Destination responsibilities, credential rotation and completion checks: [complete].
- Return/deletion selection and backup expiry: [complete; align with processing annex].
- Approved liability terms and relevant insurance confirmation: [complete; apply approved liability and complete legal review].
Documents accepted and signatures
| Incorporated document | Fixed version/date or attached reference |
|---|---|
| Client service agreement | [complete: final approved version, not draft 0.2] |
| Completed data-processing schedule and annexes | [complete] |
| Custom work, SLA or other schedules | [complete, or none] |
| Express negotiated variations and affected clauses | [complete, or none] |
Each party receives a retainable copy of the complete agreed documents before signing. Website terms and general marketing statements do not replace these documents. This does not exclude remedies for misleading statements or other mandatory rights.
For AI Smith: name [complete]; role [complete]; signature [complete]; date [complete].
For the client: name [complete]; role [complete]; signature [complete]; date [complete].
Data-processing schedule
This schedule forms part of the client agreement and applies where the client determines the purposes and means of processing personal data and AI Smith processes it on the client's behalf. It is bespoke draft wording, not the European Commission's standard contractual clauses and not, by itself, an international-transfer mechanism.
1. Scope, roles and instructions
The parties and contacts are identified in the signed order. Annex A defines the subject, duration, purpose and nature of processing, data types and categories of individuals. The client gives documented lawful instructions through the agreed services and authorised contacts. AI Smith processes only those instructions, including instructions about transfers, unless Union or Member State law requires otherwise. In that case AI Smith informs the client before processing unless that law prohibits notice on important public-interest grounds.
AI Smith promptly tells the client if an instruction appears to infringe data-protection law and pauses the affected instruction while it is clarified. The client is responsible for the lawful basis, accuracy, notices and necessary permissions for its processing. This does not remove AI Smith's own legal obligations.
If the client itself acts as a processor, the parties must document the upstream controller's authorisation and instructions and adapt this schedule before processing starts. AI Smith's independent-controller processing, such as statutory invoice records, is outside these processor instructions and must have its own lawful basis, retention and transparency information.
2. Confidentiality and security
AI Smith restricts access to authorised people who need it for the service and are bound by confidentiality or an appropriate statutory duty. It implements appropriate technical and organisational measures under GDPR Article 32, as specifically recorded in Annex B, taking account of the data, risk, technology and processing context.
Measures must cover access control, confidentiality, integrity, availability, resilience, restoration and regular effectiveness assessment as appropriate. Material changes must not reduce the agreed overall protection. The schedule does not assert that a named cloud product, encryption feature or configuration is present merely because it is technically available.
3. Other processors and international transfers
The approved authorisation model is specific prior written approval. Only the legal entities and processing activities approved in Annex C may be used as subprocessors. AI Smith seeks written approval before adding or replacing one and provides enough information for the client to assess it. No consent is inferred from silence or an employee selecting a new AI model.
AI Smith binds each subprocessor to equivalent applicable data-protection obligations and remains fully liable to the client for that subprocessor's performance of those obligations. The client may request relevant terms or evidence, with lawful redactions that do not prevent assessment. A client-owned vendor account does not alone determine the vendor's legal role.
Transfers outside the EEA, including relevant remote access, require documented instructions and a valid GDPR Chapter V basis recorded in Annex C. Where required, complete applicable transfer clauses, assessment and supplementary measures before the transfer. This schedule does not supply an adequacy decision or guarantee every provider processes only in the EU.
4. Assistance and individual requests
Taking account of the nature of processing, AI Smith assists the client by appropriate measures with requests from individuals to exercise their GDPR rights. It forwards requests received directly without undue delay and does not respond substantively unless instructed or legally required. It assists with security obligations, breach assessment and notifications, impact assessments and prior consultation, taking account of available information.
Ordinary assistance is part of the agreed service. Any exceptional additional work is discussed and costed in advance where lawful; a fee discussion may not delay urgent statutory assistance or shift the cost of remedying AI Smith's own breach to the client.
5. Personal-data breaches
AI Smith notifies the client's incident contact without undue delay after becoming aware of a personal-data breach affecting the client's data. Approved operational target: initial notice within 24 hours of awareness; this is not permission to delay earlier notice or a claim that a 24-hour response has been operationally proven.
The notice describes known facts: nature of the breach, affected individuals and records where possible, likely consequences, contact point, containment and proposed corrective measures. Incomplete information is supplied in phases without undue further delay. AI Smith investigates, preserves relevant evidence, mitigates harm and cooperates with the client's legal duties. The client decides its controller notifications, without limiting any independent legal duty of AI Smith. AI Smith does not contact the client's affected individuals on its behalf without instructions unless legally required.
6. Evidence and audits
AI Smith makes available information necessary to demonstrate compliance with this schedule and Article 28 and allows and contributes to audits, including inspections, by the client or an auditor it mandates. The parties coordinate reasonable notice, security and confidentiality to protect other clients. Urgency, suspected serious non-compliance and regulator requests may require shorter notice or additional access. There is no blanket annual cap, report-only restriction or fee that prevents a necessary lawful audit. AI Smith informs the client if an audit instruction appears unlawful.
7. Return, deletion and duration
Processing continues only for the service and the limited, documented transition/retention periods in Annex A. On ending the processing service, the client chooses return or deletion of its personal data, with existing copies deleted unless Union or Member State law requires retention. Annex A records the choice, formats, active-system deletion deadline and backup expiry. It must preserve any applicable retrieval period and agreed handover rights.
Until deletion, retained copies remain protected and are used only for the documented limited purpose. Backups awaiting expiry are isolated from ordinary use; if restoration is necessary, the deletion instructions are reapplied. Any legally required retention is identified with its legal basis and scope. AI Smith provides confirmation of completion. No indefinite "backup exception" or reuse for unrelated analytics or model training is authorised.
Annex A. Processing particulars and retention
Complete for the actual deployment before signature. Do not put real client personal data in this template to illustrate a category.
| Required particular | Agreed entry |
|---|---|
| Order and controller identity | [complete] |
| Subject matter and service duration | [complete] |
| Purposes and processing operations | [complete: for example storage, retrieval, extraction, draft generation, support, return/deletion] |
| Categories of individuals | [complete] |
| Personal-data categories | [complete: necessary fields only] |
| Special-category or criminal-offence data | [complete: excluded unless expressly assessed, authorised and safeguarded] |
| Authorised instruction contacts | [complete] |
| Controller privacy and incident contacts | [complete] |
| AI Smith privacy and incident contacts | [complete] |
| AI input/output/log retention and model-training settings | [complete for each approved path] |
| Active data, support-log and security-log retention | [complete with purpose] |
| Return or deletion choice; export formats | [complete] |
| Retrieval period and active-system deletion deadline | [complete] |
| Backup expiry and deletion-confirmation process | [complete] |
| Legally required retention, if any | [complete: legal basis, data and period] |
Annex B. Actual security and recovery measures
For each row record the deployed measure, responsible party and verification date/evidence. "Available from provider" is not implementation evidence. Secrets do not belong here.
| Area | Measure, owner and evidence |
|---|---|
| Identity, privileged access and MFA | [complete] |
| Organisation isolation and permission enforcement | [complete] |
| Encryption in transit/at rest and key responsibilities | [complete] |
| Hosting, storage and administrative-access locations | [complete] |
| Backup scope, frequency, retention and restoration test | [complete] |
| Recovery targets, dependencies and continuity exercise | [complete] |
| Logs, monitoring and incident response | [complete] |
| Patching, vulnerability handling and change review | [complete] |
| Staff/contractor confidentiality and access removal | [complete] |
| Secure exports, transfer and deletion verification | [complete] |
| Periodic effectiveness review and review date | [complete] |
Annex C. Approved recipients and subprocessors
Create a completed entry for every actual processing recipient and identify its role. Relevant candidates to investigate include hosting, database/storage, email delivery, support tools, AI routing and downstream model providers. A brand or model name is not a legal entity.
| Legal entity and service | Role and purpose | Data accessed | Locations and remote access | Transfer basis and safeguards | Approval and terms reference |
|---|---|---|---|---|---|
| [complete] | [complete] | [complete] | [complete] | [complete] | [complete] |
Client-controlled external services also require a documented data flow and division of duties. Where they are not AI Smith subprocessors, state why and identify the applicable agreement. Do not assume OpenRouter covers all downstream providers, or that a model change leaves this annex unchanged. The parties sign or otherwise expressly approve this completed schedule as part of the versioned order.