DemandSpark — Terms and Conditions of Service
Version: 1.0 Effective date: 4 August 2026 Provider: FluentForward Ltd
IMPORTANT — PLEASE READ
These Terms contain provisions that limit our liability to you (clause 17), require you to indemnify us (clause 16), and disclaim warranties in relation to AI-generated outputs (clauses 9 and 15). Clause 9 in particular sets out your responsibilities in relation to artificial intelligence outputs generated through the Service. Please read it carefully.
The Service is provided for business purposes only. It is not offered to consumers.
1. Agreement and Parties
1.1 These Terms and Conditions ("Terms") govern your access to and use of the DemandSpark platform and related services (the "Service"), made available at demandspark.ai and associated domains and subdomains.
1.2 The Service is provided by FluentForward Ltd, a company incorporated in England and Wales with company number 07965202, whose registered office is at North View, Farrington Road, Paulton, Bristol, BS39 7LP, United Kingdom ("Provider", "we", "us", "our").
1.3 These Terms form a binding agreement between the Provider and the legal entity or individual acting in the course of a business that registers for, accesses or uses the Service ("Customer", "you", "your"). Together, the "Parties"; each a "Party".
1.4 By clicking to accept these Terms, creating an Account, commencing a Trial, or otherwise accessing or using the Service, you agree to be bound by these Terms. If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have authority to bind that entity, and "Customer" refers to that entity.
1.5 Business use only. The Service is offered exclusively to persons acting for purposes relating to their trade, business, craft or profession. You confirm that you are not a consumer and are not entering into this agreement wholly or mainly for personal use. If you are a consumer, you may not use the Service.
1.6 Age and capacity. You must be at least 18 years old and have full legal capacity to enter into contracts.
2. Structure of the Agreement and Order of Precedence
2.1 The agreement between the Parties (the "Agreement") comprises, in descending order of precedence in the event of conflict:
(a) any Order Form or written enterprise agreement executed by both Parties expressly referring to and varying these Terms;
(b) the Data Processing Addendum at Schedule 2;
(c) these Terms;
(d) the Acceptable Use Policy at Schedule 1;
(e) any Service Level Agreement applicable to your Plan;
(f) any documentation, plan descriptions, pricing pages or policies referenced in or linked from these Terms.
2.2 Purchase orders, vendor terms, supplier onboarding portals, standard procurement conditions and similar documents issued by the Customer have no contractual effect and are expressly excluded, notwithstanding any acknowledgement, signature or acceptance by us of such a document.
3. Definitions
In these Terms, the following expressions have the following meanings:
"Account" means the Customer's account for the Service, including all Workspaces within it.
"Affiliate" means, in relation to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with that Party.
"AI Provider" means a third-party supplier of artificial intelligence, machine learning or large language model services used in the provision of the Service.
"Business Day" means a day other than a Saturday, Sunday or public holiday in England.
"Applicable Data Protection Law" means all laws relating to data protection and privacy applicable to a Party's processing of Personal Data under the Agreement, including the UK GDPR, the Data Protection Act 2018, the Data (Use and Access) Act 2025, the EU GDPR (Regulation (EU) 2016/679), the Privacy and Electronic Communications Regulations 2003, and any equivalent legislation in other jurisdictions.
"Confidential Information" has the meaning given in clause 14.
"Customer Data" means all data, content, materials, text, images, configurations, prompts, instructions, brand assets and other information uploaded to, submitted to, generated within, or transmitted through the Service by or on behalf of the Customer, including Prospect Data and Outputs.
"Documentation" means the user guides, help articles, technical documentation and plan descriptions we make generally available in relation to the Service.
"Effective Date" means the date on which the Customer first accepts these Terms.
"Fees" means the subscription charges, usage charges and any other amounts payable by the Customer for the Service.
"Intellectual Property Rights" means patents, utility models, rights to inventions, copyright and neighbouring and related rights, trade marks, business names and domain names, rights in get-up, goodwill, rights in designs, database rights, rights in confidential information (including know-how and trade secrets), and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply for and be granted renewals or extensions, and all similar or equivalent rights subsisting now or in the future in any part of the world.
"Output" means any content, analysis, score, recommendation, summary, classification, tag, text, structured data or other material generated by or through the Service using artificial intelligence, machine learning or automated reasoning, including Spark conversations, Result Experiences, reasoned lead scores, context summaries, segmentation tags and recommended next actions.
"Personal Data", "Controller", "Processor", "Data Subject", "Processing" and "Personal Data Breach" have the meanings given in Applicable Data Protection Law.
"Plan" means the subscription tier selected by the Customer (including, as at the Effective Date, Spark, Ignite and Ember), as described on our pricing page or in an Order Form.
"Prospect" means an individual or organisation that accesses, interacts with, or completes a Spark published by the Customer.
"Prospect Data" means Customer Data comprising information relating to Prospects, including responses submitted during a Spark, contact details, and Outputs relating to that Prospect.
"Result Experience" means the personalised, interactive web experience delivered to a Prospect on completion of a Spark, and any interrogation or follow-up interaction with it.
"Service" has the meaning given in clause 1.1 and includes all Sparks, Workspaces, dashboards, integrations, APIs, Outputs and Documentation made available to the Customer.
"Spark" means an AI-driven prospect experience configured and published by the Customer using the Service, including the conversational interaction, the Result Experience, and any associated playbooks, outreach or lifecycle engagement.
"Subscription Term" has the meaning given in clause 6.
"Trial" means a free evaluation period granted under clause 5.
"User" means an individual authorised by the Customer to access the Service under the Customer's Account, including the Customer's employees, contractors and agents.
"Workspace" means a discrete environment within the Account containing Sparks, Prospects, settings and data.
References to a statute or statutory provision include that statute or provision as amended, extended or re-enacted from time to time. "Including", "in particular" and similar expressions are without limitation. Clause headings do not affect interpretation.
4. Account Registration and Users
4.1 To use the Service, you must register an Account and provide accurate, complete and current information. You must keep that information up to date.
4.2 You are responsible for:
(a) maintaining the confidentiality of all Account credentials;
(b) all activity occurring under your Account, whether or not authorised by you;
(c) ensuring that each User complies with these Terms, and you are liable for any act or omission of a User as if it were your own;
(d) notifying us promptly at security@demandspark.ai if you become aware of any unauthorised access to or use of your Account.
4.3 Where your Plan includes a limited number of seats, each seat is for a single named individual. Seats may be reassigned when a User permanently leaves your organisation or changes role, but may not be shared or used concurrently by multiple individuals.
4.4 You may not permit any third party to access the Service except (a) Prospects interacting with published Sparks in the ordinary course, and (b) where your Plan expressly permits white-label or client delivery, your clients on whose behalf you build Sparks — in which case you remain fully responsible for their compliance with these Terms.
5. Free Trial
5.1 We may make a free Trial of the Service available. Unless otherwise stated, the Trial provides access at the Ignite tier for 14 days from the date of Account creation.
5.2 Trials are provided "as is", without any warranty, indemnity, service level commitment or support obligation of any kind, to the maximum extent permitted by law. Notwithstanding any other provision of these Terms, our total aggregate liability arising out of or in connection with a Trial shall not exceed £100, save in respect of the matters listed in clause 17.1.
5.3 We may modify, suspend, limit or withdraw a Trial, or impose usage restrictions during a Trial, at any time.
5.4 Trials are limited to one per Customer and per organisation. Creating multiple Accounts to obtain additional Trials is a material breach of these Terms.
5.5 At the end of a Trial, unless you subscribe to a paid Plan, your access will cease and we may delete all Customer Data in the Account after 30 days. You are responsible for exporting any data you wish to retain before that date.
6. Subscription, Term and Renewal
6.1 Your subscription commences on the date you first subscribe to a paid Plan and continues for the billing period selected (monthly or annual) (each, a "Subscription Term").
6.2 Automatic renewal. Each Subscription Term renews automatically for a further period of the same length at the then-current list price, unless either Party gives notice of non-renewal:
(a) for monthly subscriptions, at any time before the end of the current Subscription Term;
(b) for annual subscriptions, at least 30 days before the end of the current Subscription Term.
6.3 You may cancel renewal through your Account settings or by notice to billing@demandspark.ai. Cancellation takes effect at the end of the current Subscription Term. No refunds are given for partial periods.
6.4 Upgrades and downgrades. You may upgrade your Plan at any time, effective immediately, with Fees prorated for the remainder of the Subscription Term. Downgrades take effect at the start of the next Subscription Term. Downgrading may result in loss of access to features, data or capacity, and we accept no liability for such loss.
7. Provision of the Service and Licence
7.1 Subject to your compliance with the Agreement and payment of Fees, we grant you a non-exclusive, non-transferable, non-sublicensable, revocable licence during the Subscription Term to access and use the Service for your internal business purposes and — where your Plan permits — for the delivery of services to your clients.
7.2 We will provide the Service with reasonable skill and care and substantially in accordance with the Documentation.
7.3 Evolving service. The Service is under active and continuous development. We may add, modify, deprecate or remove features, models, integrations, Output formats and functionality at any time. We will use reasonable efforts to give notice of any change that we assess as materially and adversely affecting core functionality of your Plan, but we do not warrant that any particular feature, model, integration or behaviour will remain available.
7.4 Availability. Unless a Service Level Agreement expressly applies to your Plan, the Service is provided without any uptime or availability commitment. We may suspend access for scheduled or emergency maintenance and will use reasonable efforts to give advance notice of planned maintenance.
7.5 Usage limits. Your Plan includes limits on Sparks, lead volume, seats and other resources. We may throttle, suspend or charge for usage in excess of those limits, and may apply fair-use restrictions to any resource described as "unlimited" where usage is materially disproportionate to typical usage by comparable customers or is such as to impair the Service for others.
8. Customer Responsibilities
8.1 You are responsible for:
(a) all Customer Data, including its accuracy, quality, legality and the means by which you acquired it;
(b) the configuration, testing, review, publication and ongoing operation of every Spark you deploy;
(c) obtaining and maintaining all consents, permissions, licences and lawful bases required for the collection, processing and use of Prospect Data;
(d) ensuring that your use of the Service and each published Spark complies with all laws applicable to you and to your Prospects, in every jurisdiction in which you publish, promote or distribute a Spark;
(e) providing your own privacy notice, cookie notice and terms to Prospects, and ensuring these accurately describe the processing carried out through the Service;
(f) all equipment, internet connectivity, browsers and third-party accounts required to access the Service;
(g) maintaining your own backups of Customer Data that you would need in the event of loss.
8.2 You are the publisher. Every Spark and Result Experience is published under your brand, at your direction, to an audience you select. As between you and us, and as between you and any Prospect, regulator or third party, you are the publisher of, and are solely responsible for, each Spark and each Output it produces. We have no editorial control over, and do not review, approve or endorse, any Spark or Output.
8.3 Marketing and outreach compliance. Where you use the Service to send, schedule or facilitate outreach, marketing or lifecycle communications, you are solely responsible for compliance with all applicable direct marketing, anti-spam and electronic communications laws, including the UK Privacy and Electronic Communications Regulations 2003, the EU ePrivacy Directive as implemented, the US CAN-SPAM Act and the Telephone Consumer Protection Act, Canada's Anti-Spam Legislation, and any applicable telephone, SMS or messaging consent requirements. This includes obtaining valid consent where required, honouring opt-outs, and maintaining suppression lists.
8.4 You must not misrepresent the Service, its capabilities, or its Outputs to any Prospect or third party.
9. Artificial Intelligence, Outputs and Human Oversight
This clause is fundamental to the Agreement. The Fees payable reflect the allocation of risk set out in this clause.
9.1 Nature of the Service
The Service uses artificial intelligence, large language models and automated reasoning — including models supplied by third-party AI Providers — to conduct conversations with Prospects, evaluate their responses, generate scores and produce Result Experiences. These technologies are probabilistic and non-deterministic. Identical or similar inputs may produce different Outputs on different occasions.
9.2 No warranty as to Outputs
To the maximum extent permitted by law, we make no representation or warranty that any Output will be:
(a) accurate, complete, current, reliable, appropriate, or fit for any purpose;
(b) free from error, omission, bias, hallucination, fabrication or offensive, misleading or inappropriate content;
(c) consistent, reproducible, or unique to you or to any Prospect;
(d) free from infringement of the rights of any third party;
(e) compliant with any law, regulation, professional standard, industry code or contractual obligation applicable to you or to any Prospect.
Outputs may include statements that are plausible in form but factually incorrect. Outputs must not be relied upon without independent verification.
9.3 No professional advice
Outputs are informational only. They do not constitute, and must not be presented by you as, legal, financial, investment, tax, accounting, medical, health, psychological, employment, immigration, safety or any other form of regulated or professional advice. You must not configure a Spark in a way that holds out an Output as such advice, and you must ensure that any professional disclaimers required by your own regulator, professional body or insurer are presented to Prospects.
9.4 Human oversight
You must:
(a) test each Spark thoroughly before publication, including reviewing sample Outputs across a representative range of Prospect responses;
(b) maintain meaningful human oversight of published Sparks, including periodic review of Outputs actually delivered to Prospects;
(c) not use the Service as the sole basis for any decision that produces a legal effect concerning a person, or that similarly significantly affects a person, without implementing the safeguards required by clause 9.6;
(d) promptly unpublish or correct any Spark producing Outputs that are inaccurate, unlawful, misleading, discriminatory or otherwise harmful.
9.5 Prohibited and high-risk uses
You must not use the Service, and must not configure any Spark, for any purpose listed as prohibited in the Acceptable Use Policy at Schedule 1. Without limiting that Schedule, you must not use the Service to make, materially inform or automate decisions concerning:
(a) eligibility for, or terms of, credit, lending, insurance or financial services;
(b) recruitment, hiring, promotion, task allocation, performance evaluation or termination of employment or contractor engagement;
(c) access to, or evaluation within, education or vocational training;
(d) eligibility for essential public or private services, benefits or healthcare;
(e) any matter falling within Annex III of Regulation (EU) 2024/1689 (the EU AI Act) or equivalent "high-risk" classification under any applicable law;
(f) emotion recognition, biometric categorisation, or inference of special category personal data.
If you wish to use the Service for any such purpose, you must obtain our prior written consent and enter into a separate written agreement with us.
9.6 Automated decision-making
Where an Output is used by you to make, or to substantially inform, a decision about a Prospect that produces legal effects concerning that Prospect or similarly significantly affects them, you are the controller of that decision. You are solely responsible for determining whether Articles 22A to 22D of the UK GDPR, Article 22 of the EU GDPR, or any equivalent provision applies, and for implementing the required safeguards, including providing information about the logic involved, enabling the Prospect to make representations, obtaining meaningful human intervention, and enabling the Prospect to contest the decision.
9.7 AI transparency obligations
(a) We provide technical means within the Service by which Prospects are informed that they are interacting with an artificial intelligence system, and by which AI-generated content may be marked or labelled. You must not disable, remove, obscure, circumvent or misrepresent these means.
(b) Where you are a "deployer" of an AI system for the purposes of the EU AI Act or any equivalent law, you are responsible for your own obligations as deployer, including the transparency obligations under Article 50 of the EU AI Act (in force from 2 August 2026), disclosure of AI interaction, disclosure of AI-generated content, and any registration, notification, human oversight, monitoring or AI-literacy obligations applicable to you.
(c) You must not represent to any Prospect or third party that an Output was created by a human, or that a Spark conversation was conducted by a human.
(d) Where you operate in a jurisdiction with additional AI disclosure requirements (including, without limitation, US state chatbot-disclosure laws), you are responsible for compliance.
9.8 Prompts, inputs and third-party content
You must not submit to the Service, or configure a Spark to solicit, any content that:
(a) infringes any third party's Intellectual Property Rights;
(b) constitutes special category personal data, criminal offence data, or data relating to children, unless you have a valid lawful basis and have notified us in advance in writing;
(c) is unlawful, defamatory, obscene, harassing or otherwise in breach of Schedule 1.
9.9 Third-party AI Providers
The Service depends on AI Providers. We are not responsible for, and expressly disclaim liability arising from, any act, omission, model change, deprecation, content policy, rate limit, outage, price change or discontinuation by any AI Provider, or any degradation in Output quality resulting from any of the foregoing. We may substitute AI Providers or models at any time without notice.
9.10 Acknowledgement
You acknowledge that:
(a) you have independently satisfied yourself that the Service is suitable for your purposes;
(b) you are not relying on any statement, representation, assurance or warranty about Outputs that is not expressly set out in these Terms;
(c) the limitations and exclusions in this clause 9 and in clauses 15 to 17 are reasonable having regard to the nature of the technology, the Fees payable, the availability of insurance to you, and your ability to inspect and test Outputs before publication.
10. Intellectual Property
10.1 Our IP. We and our licensors own all Intellectual Property Rights in and to the Service, including all software, models, prompts, architecture, agent logic, schema registries, templates, rendering layers, designs, documentation, and the DemandSpark and FluentForward names, logos and branding. Nothing in the Agreement transfers any such rights to you. All rights not expressly granted are reserved.
10.2 Your IP. You retain all Intellectual Property Rights in and to Customer Data. You grant us a worldwide, non-exclusive, royalty-free licence to host, store, copy, transmit, display, modify, process and otherwise use Customer Data to the extent necessary to (a) provide, maintain, secure and support the Service; (b) prevent or address technical or security problems; (c) comply with law; and (d) exercise our rights under clause 10.4. This licence terminates on deletion of the Customer Data, subject to clause 19.6.
10.3 Outputs. As between the Parties, and subject to clause 10.1 and to our and our licensors' underlying rights, you own all Intellectual Property Rights in Outputs generated through your Account, to the extent such rights subsist. You acknowledge that (a) AI-generated material may not attract copyright or other protection in some or all jurisdictions; (b) Outputs are not necessarily unique and substantially similar Outputs may be generated for other customers; and (c) we give no warranty of title, originality or non-infringement in respect of any Output.
10.4 Aggregated and de-identified data. We may collect, generate and use technical, statistical and usage data relating to the operation of the Service, and may create aggregated and de-identified datasets derived from Customer Data, in each case for the purposes of operating, securing, analysing, benchmarking and improving the Service and developing new products. Such data will not identify you, any User, any Prospect or any Data Subject, and will not be published or disclosed in a form that identifies you.
10.5 No training on Customer Data by AI Providers. We will not use Customer Data to train foundation or general-purpose AI models, and will use commercially reasonable efforts to contract with AI Providers on terms that prohibit them from using Customer Data submitted through the Service to train their models.
10.6 Feedback. If you provide suggestions, feature requests, or other feedback relating to the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free, sublicensable licence to use and exploit that feedback for any purpose, without obligation or attribution.
10.7 Restrictions. You must not, and must not permit any person to:
(a) copy, modify, adapt, translate, reverse engineer, decompile or disassemble any part of the Service, or attempt to derive its source code, model weights, prompts or system instructions, except to the extent expressly permitted by law and only after giving us written notice and a reasonable opportunity to provide the information sought;
(b) use the Service, any Output, or any interaction with the Service to develop, train, fine-tune, benchmark or improve any competing product or model;
(c) extract prompts, system instructions or agent configurations, including by prompt injection, jailbreaking or adversarial input;
(d) resell, sublicense, rent, lease or otherwise make the Service available to third parties, except as expressly permitted by your Plan;
(e) scrape, crawl or use automated means to access the Service except through documented APIs;
(f) circumvent or attempt to circumvent any usage limit, access control, authentication, rate limit or security measure;
(g) remove, obscure or alter any proprietary notice.
11. Data Protection
11.1 Each Party will comply with Applicable Data Protection Law in respect of its processing of Personal Data under the Agreement.
11.2 Roles. In respect of Prospect Data and other Personal Data processed by us on your behalf in providing the Service, you are the Controller and we are the Processor. In respect of Personal Data relating to your Users and billing contacts that we process to administer the Account, market to you and comply with our own legal obligations, we act as an independent Controller.
11.3 The Data Processing Addendum at Schedule 2 applies to all processing by us as Processor and forms part of the Agreement.
11.4 You warrant that you have, and will maintain throughout the Subscription Term, a valid lawful basis for all processing of Prospect Data carried out through the Service, and that you have provided all notices and obtained all consents required by Applicable Data Protection Law.
11.5 Our processing of Personal Data as Controller is described in our Privacy Policy at https://demandspark.ai/privacy.
12. Third-Party Services and Integrations
12.1 The Service may integrate with third-party services, including CRM platforms, messaging channels, payment providers, calendar providers and analytics tools ("Third-Party Services").
12.2 Third-Party Services are provided by their respective providers under their own terms. Your use of a Third-Party Service is between you and that provider. We do not control, endorse or accept responsibility for any Third-Party Service, including its availability, security, accuracy, terms, pricing or data handling.
12.3 By enabling an integration, you authorise us to access, transmit and exchange Customer Data with the relevant Third-Party Service as reasonably necessary to operate the integration, and you confirm you have authority to grant that authorisation.
12.4 We may modify, suspend or discontinue any integration at any time, including where a Third-Party Service changes or withdraws its API or terms. We are not liable for any loss arising from such a change.
13. Fees, Payment and Taxes
13.1 Fees. You will pay the Fees for your Plan as set out on our pricing page or in an Order Form, in advance, without set-off, counterclaim or deduction.
13.2 Payment method. You authorise us and our payment processor to charge your nominated payment method for all Fees on each renewal date, and for any usage-based or overage charges as incurred. You must keep your payment details current.
13.3 Currency. Fees are quoted and payable in pounds sterling (GBP) unless expressly stated otherwise. Where we make an alternative currency available, the exchange rate applied is that determined by our payment processor at the time of the transaction. You are responsible for any bank charges, card issuer fees or currency conversion costs.
13.4 Taxes. All Fees are exclusive of VAT, GST, sales, use, consumption and similar taxes, which will be added at the applicable rate. You are responsible for all such taxes other than taxes on our net income. Where you are established outside the United Kingdom and the reverse charge or an equivalent mechanism applies, you must provide a valid tax registration number; if you do not, we may charge UK VAT. You must notify us promptly of any change to your place of establishment or tax status.
13.5 Withholding. If you are required by law to withhold or deduct any amount from a payment, the sum payable will be increased so that, after the withholding or deduction, we receive the amount we would have received had no withholding or deduction been required.
13.6 Late payment. If any amount is not paid when due, we may:
(a) charge interest at 4% per annum above the Bank of England base rate from time to time, accruing daily from the due date until payment, or, where the Late Payment of Commercial Debts (Interest) Act 1998 applies, at the statutory rate together with fixed sums and reasonable recovery costs under that Act;
(b) suspend your access to the Service under clause 18 on 7 days' notice;
(c) recover all reasonable costs of collection, including debt recovery agency fees and legal costs.
13.7 Failed payments. If a payment fails, we may re-attempt collection. If payment remains outstanding 14 days after the due date, we may suspend or terminate the Account.
13.8 Price changes. We may change our Fees. Any increase takes effect from the start of your next Subscription Term, provided we give you at least 30 days' notice (for monthly Plans) or 60 days' notice (for annual Plans) before the renewal date. If you do not accept the increase, you may cancel renewal in accordance with clause 6.2.
13.9 No refunds. Except where expressly stated in these Terms or required by law, all Fees are non-refundable. No refund or credit is given for partial periods, unused capacity, downgrades, or periods during which you did not use the Service.
13.10 Disputes. You must notify us in writing of any disputed invoice within 15 days of the invoice date, giving reasons. You must pay all undisputed amounts when due. Failure to notify within that period is deemed acceptance of the invoice.
14. Confidentiality
14.1 "Confidential Information" means any information disclosed by one Party ("Discloser") to the other ("Recipient") that is designated as confidential or that a reasonable person would understand to be confidential, including business plans, pricing, technical information, product roadmaps, security information, Customer Data and the terms of any Order Form.
14.2 The Recipient will (a) keep the Confidential Information confidential; (b) use it only to perform its obligations or exercise its rights under the Agreement; and (c) disclose it only to those of its employees, contractors, professional advisers and Affiliates who need to know it and who are bound by obligations of confidentiality no less protective than these.
14.3 These obligations do not apply to information that is or becomes public other than through breach of this clause, was lawfully known to the Recipient before disclosure, is independently developed without use of the Confidential Information, or is lawfully obtained from a third party without restriction.
14.4 The Recipient may disclose Confidential Information to the extent required by law, regulation or court order, provided that (where lawful) it gives the Discloser prompt notice and reasonable assistance to seek protective relief.
14.5 This clause survives termination for five (5) years, save that Confidential Information constituting a trade secret remains protected for so long as it retains that status.
15. Warranties and Disclaimers
15.1 Each Party warrants that it has full power and authority to enter into and perform the Agreement.
15.2 You warrant and undertake that:
(a) you will comply with the Agreement and all laws applicable to your use of the Service;
(b) you own or have all necessary rights in Customer Data and its use through the Service will not infringe any third party's rights;
(c) you have all necessary consents, notices and lawful bases in respect of Prospect Data;
(d) you are not, and are not owned or controlled by, a person subject to sanctions administered by the UK, EU, US or United Nations, and you are not located in, and will not use the Service from or for the benefit of, a sanctioned or embargoed territory;
(e) your use of the Service complies with all applicable export control laws.
15.3 DISCLAIMER. Except as expressly set out in the Agreement, and to the maximum extent permitted by law:
(a) the Service, all Outputs and all Documentation are provided "AS IS" and "AS AVAILABLE";
(b) all conditions, warranties, terms and undertakings, express or implied, statutory or otherwise, including any implied terms as to satisfactory quality, fitness for a particular purpose, accuracy, non-infringement, title, or arising from a course of dealing or usage of trade, are excluded;
(c) we do not warrant that the Service will be uninterrupted, timely, secure, error-free, or free from viruses or other harmful components, or that defects will be corrected;
(d) we do not warrant that the Service will produce any particular commercial result, including any level of lead generation, completion rate, conversion, qualification accuracy or pipeline value;
(e) we are not responsible for any loss or corruption of Customer Data, and you are responsible for maintaining your own backups.
15.4 Nothing in this clause excludes or limits any liability that cannot lawfully be excluded or limited.
16. Indemnities
16.1 Customer indemnity. You will indemnify, defend and hold harmless the Provider, its Affiliates, and their respective officers, directors, employees, contractors and agents (each an "Indemnified Person") from and against all claims, demands, actions, proceedings, investigations, fines, penalties, losses, damages, liabilities, costs and expenses (including reasonable legal and professional fees) arising out of or in connection with:
(a) any Spark, Result Experience, Output or other content published, distributed, relied upon or acted upon by you or on your behalf, or delivered to any Prospect through your Account, including any claim that it is inaccurate, misleading, defamatory, discriminatory, unlawful, or that reliance on it caused loss;
(b) any claim by or on behalf of a Prospect, User, client of yours, or any other third party arising out of your use of the Service or of any Output;
(c) any Customer Data, including any claim that it infringes Intellectual Property Rights or breaches confidence or privacy;
(d) your breach of clause 8 (Customer Responsibilities), clause 9 (Artificial Intelligence, Outputs and Human Oversight), clause 11 (Data Protection), clause 15.2 (warranties), or Schedule 1 (Acceptable Use Policy);
(e) any actual or alleged breach by you of Applicable Data Protection Law, direct marketing or anti-spam law, consumer protection law, advertising or financial promotion rules, professional conduct rules, the EU AI Act or any equivalent AI law, or any sanctions or export control law;
(f) any regulatory investigation, enforcement action, monetary penalty or claim brought against an Indemnified Person by any supervisory authority, regulator or Data Subject to the extent arising from your acts or omissions;
(g) your use of the Service for any purpose prohibited by clause 9.5;
(h) any dispute between you and a Prospect, a client of yours, or a User.
16.2 This indemnity is uncapped and is not subject to the limitations in clause 17.2.
16.3 Conduct of claims. We will notify you of any claim to which the indemnity applies without undue delay. We may, at our option, control the defence and settlement of any such claim using counsel of our choosing, at your cost; alternatively we may permit you to assume the defence, in which case you will not settle any claim in a manner that imposes any obligation or admission on an Indemnified Person without our prior written consent. You will provide all reasonable co-operation.
16.4 No Provider IP indemnity. We do not indemnify you against any claim that the Service or any Output infringes the Intellectual Property Rights of any third party.
17. Limitation of Liability
17.1 Unlimited liability. Nothing in the Agreement limits or excludes either Party's liability for:
(a) death or personal injury caused by its negligence;
(b) fraud or fraudulent misrepresentation;
(c) any other liability that cannot lawfully be limited or excluded.
17.2 Cap on liability. Subject to clauses 17.1 and 17.4, each Party's total aggregate liability arising out of or in connection with the Agreement, whether in contract, tort (including negligence), breach of statutory duty, restitution or otherwise, is limited to the greater of (a) £5,000 and (b) 100% of the total Fees paid or payable by the Customer under the Agreement in the twelve (12) month period immediately preceding the first event giving rise to liability.
17.3 Excluded loss. Subject to clause 17.1, neither Party is liable for any of the following, whether direct or indirect and whether or not foreseeable:
(a) loss of profits, revenue, sales, business or contracts;
(b) loss of anticipated savings;
(c) loss of or damage to goodwill or reputation;
(d) loss of, corruption of, or inability to use data;
(e) loss of opportunity, pipeline or expected leads;
(f) wasted expenditure or wasted management time;
(g) any indirect, special, consequential or punitive loss.
17.4 Carve-outs from the cap. The cap in clause 17.2 does not apply to:
(a) the Customer's obligation to pay Fees;
(b) the Customer's indemnity obligations under clause 16;
(c) the Customer's breach of clause 10.7 (restrictions), clause 15.2(d) or (e) (sanctions and export control), or Schedule 1 (Acceptable Use Policy);
(d) either Party's breach of clause 14 (Confidentiality).
17.5 Trial liability. Liability arising in connection with a Trial is limited as set out in clause 5.2.
17.6 Single cap. The cap in clause 17.2 is a single aggregate cap across all claims. Multiple claims do not increase it.
17.7 Reasonableness. The Parties acknowledge that the allocation of risk in clauses 9, 15, 16 and 17 is a fundamental basis of the Agreement, is reflected in the level of the Fees, and is reasonable in all the circumstances, having regard to the availability of insurance to the Customer, the Customer's ability to test and review Outputs before publication, and the nature of the technology.
17.8 Time limit. Except in respect of a claim under clause 17.1 or a claim for unpaid Fees, neither Party may bring any claim under the Agreement more than twelve (12) months after the date on which the claiming Party became, or ought reasonably to have become, aware of the facts giving rise to it.
17.9 Non-Party claims. You will not bring any claim arising out of the Agreement or the Service against any of our officers, employees, contractors, Affiliates or licensors personally; all claims must be brought against the Provider.
18. Suspension
18.1 We may suspend your access to the Service, or to any part of it, immediately and without liability, where:
(a) any Fee is overdue, subject to clause 13.6(b);
(b) we reasonably suspect a breach of clause 10.7, clause 9.5, or Schedule 1;
(c) we reasonably believe suspension is necessary to protect the security, integrity or availability of the Service or the data of any person;
(d) we are required to do so by law, court order, regulator or an AI Provider;
(e) your use materially exceeds Plan limits or fair use.
18.2 We will use reasonable efforts to give notice before suspending and to limit suspension to the affected part of the Service, unless doing so would compromise security, breach a legal duty, or risk harm.
18.3 Suspension does not relieve you of the obligation to pay Fees for the suspended period where the suspension arises from your breach.
18.4 We may unpublish, disable or remove any individual Spark or Output that we reasonably believe breaches the Agreement or applicable law, without notice.
19. Termination and Consequences
19.1 Termination for convenience. Either Party may terminate the Agreement at the end of a Subscription Term by giving notice of non-renewal in accordance with clause 6.2.
19.2 Termination for cause. Either Party may terminate the Agreement immediately by written notice if the other Party:
(a) commits a material breach that is irremediable, or, if remediable, fails to remedy it within 14 days of written notice requiring it to do so;
(b) becomes insolvent, enters administration, liquidation, receivership, a voluntary arrangement, or ceases or threatens to cease to carry on business, or anything analogous occurs in any jurisdiction.
19.3 Our additional termination rights. We may terminate the Agreement immediately by written notice if:
(a) you breach clause 9.5, clause 10.7, clause 15.2(d) or (e), or Schedule 1;
(b) your use of the Service exposes us to material legal, regulatory or reputational risk;
(c) we cease to make the Service generally available, in which case we will give you at least 60 days' notice and refund a pro-rata portion of any Fees paid in advance for the unexpired part of the Subscription Term.
19.4 Effect of termination. On termination or expiry:
(a) all licences granted to you terminate immediately and you must cease all use of the Service;
(b) all published Sparks will cease to function and all Result Experience URLs will cease to resolve;
(c) all Fees accrued up to the effective date of termination become immediately due;
(d) each Party will return or destroy the other's Confidential Information on request, subject to clause 19.6.
19.5 Data export. For 30 days after termination or expiry, we will make Customer Data available for export using the export functionality within the Service, provided all Fees have been paid. After that period, we may delete Customer Data. You are solely responsible for exporting your data within that window. Where we terminate under clause 19.3(a), we may delete Customer Data immediately.
19.6 Retention. We may retain Customer Data (a) in routine backups until those backups expire in the ordinary course, (b) where required by law or for the establishment, exercise or defence of legal claims, and (c) in aggregated and de-identified form under clause 10.4. Retained data remains subject to Schedule 2.
19.7 Survival. Clauses 1.5, 3, 8.2, 9, 10, 13 (in respect of accrued sums), 14, 15.3, 16, 17, 19.4 to 19.7, 21, 22 and 24 to 26, and Schedule 2 to the extent applicable, survive termination.
20. Force Majeure
20.1 Neither Party is liable for any failure or delay in performing its obligations (other than payment obligations) to the extent caused by an event beyond its reasonable control, including act of God, flood, fire, epidemic or pandemic, war, terrorism, civil unrest, cyber attack, industrial action, failure of utilities, telecommunications or internet infrastructure, failure or discontinuation of a Third-Party Service or AI Provider, government action, sanctions, or change in law.
20.2 If such an event continues for more than 60 consecutive days, either Party may terminate the Agreement on written notice without liability.
21. Assignment, Novation and Change of Provider Entity
21.1 Our rights. We may at any time, without your consent and without notice to you (save as set out in clause 21.2), assign, novate, transfer, subcontract, charge, declare a trust over, or deal in any other manner with all or any of our rights and obligations under the Agreement to:
(a) any Affiliate;
(b) any successor entity established by, for, or in connection with the DemandSpark business, including any entity established to operate the DemandSpark business separately from the Provider's other activities;
(c) any person acquiring all or substantially all of the assets, business or shares of the Provider, or of the DemandSpark business or product line, whether by sale, merger, reorganisation, group restructuring or otherwise.
21.2 Advance consent to novation. You irrevocably consent in advance to the novation of the Agreement to any entity described in clause 21.1, on identical terms, with effect from the date specified in a notice given to you. On novation, that entity assumes all of the Provider's rights and obligations under the Agreement and the Provider is released from them. You agree, at our reasonable request and cost, to execute any document reasonably required to give effect to such a novation; and you appoint us as your attorney to execute any such document on your behalf if you fail to do so within 10 Business Days of request.
21.3 Notice. We will give you written notice of any novation or transfer under this clause within a reasonable period, which may be given by email or by notice within the Service. A change in the identity of the Provider under this clause does not give rise to any right of termination, refund, renegotiation or claim.
21.4 Continuity. Any transfer or novation under this clause will not adversely affect the Service or your rights under the Agreement in any material respect. The transferee entity will be bound by Schedule 2 and will remain subject to the same obligations in respect of Customer Data.
21.5 Your rights. You may not assign, novate, transfer, subcontract or otherwise deal with any of your rights or obligations under the Agreement without our prior written consent, not to be unreasonably withheld. A change of control of the Customer to a competitor of the Provider entitles us to terminate on 30 days' notice.
21.6 Subcontracting. We may subcontract the performance of any of our obligations, but remain responsible for the acts and omissions of our subcontractors as if they were our own, subject to Schedule 2 in respect of sub-processors.
22. Publicity and References
22.1 We may identify you as a customer and use your name and logo on our website, in investor and partner materials, and in sales collateral, in each case in accordance with any brand guidelines you provide.
22.2 You may opt out of clause 22.1 at any time by written notice to hello@demandspark.ai, and we will cease such use within a reasonable period.
22.3 Neither Party may issue a press release or make any other public statement about the other Party or the Agreement without the other's prior written consent, other than as permitted by clause 22.1.
23. Changes to These Terms
23.1 We may amend these Terms and the Schedules from time to time, including to reflect changes in law, regulation, the Service, our AI Providers, or our business.
23.2 For changes that we reasonably assess as materially adverse to you, we will give at least 30 days' notice by email or in-Service notification before the change takes effect. Other changes take effect on posting.
23.3 If you object to a materially adverse change, you may terminate the Agreement by written notice before the change takes effect, and we will refund a pro-rata portion of any Fees paid in advance for the unexpired part of the Subscription Term. Continued use of the Service after the change takes effect constitutes acceptance.
23.4 Clause 23.2 does not apply to changes required by law or necessary for security, which may take effect immediately.
24. Notices
24.1 Notices to us must be sent to legal@demandspark.ai and, for formal notices of termination or legal proceedings, also by post to our registered office.
24.2 Notices to you may be sent to the email address associated with your Account or given by in-Service notification, and are deemed received on the day of sending (or the next Business Day if sent after 5.00pm UK time or on a non-Business Day).
24.3 It is your responsibility to keep your Account email address current.
25. General
25.1 Entire agreement. The Agreement constitutes the entire agreement between the Parties and supersedes all prior agreements, representations and understandings, whether written or oral, relating to its subject matter. Each Party acknowledges that it has not relied on, and has no remedy in respect of, any statement, representation, assurance or warranty not expressly set out in the Agreement. Nothing limits liability for fraudulent misrepresentation.
25.2 Variation. Save as permitted by clause 23, no variation is effective unless in writing and signed by both Parties.
25.3 Waiver. No failure or delay in exercising a right is a waiver of it. No single or partial exercise prevents further exercise.
25.4 Severance. If any provision is or becomes invalid, illegal or unenforceable, it will be deemed modified to the minimum extent necessary to make it valid and enforceable, or, if that is not possible, deleted. The remainder of the Agreement is unaffected.
25.5 No partnership or agency. Nothing in the Agreement creates a partnership, joint venture, agency or employment relationship.
25.6 Third-party rights. Save as expressly provided (including for Indemnified Persons under clause 16 and persons protected by clause 17.9), a person who is not a Party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term. The Parties may vary or rescind the Agreement without the consent of any third party.
25.7 Counterparts and electronic acceptance. Acceptance of these Terms by electronic means, including by clicking to accept, has the same effect as a signed written agreement.
25.8 Anti-bribery and modern slavery. Each Party will comply with the Bribery Act 2010 and the Modern Slavery Act 2015 and will maintain adequate policies and procedures to ensure compliance.
25.9 Language. The English language version of the Agreement governs. Any translation is for convenience only.
26. Governing Law and Jurisdiction
26.1 The Agreement, and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it, its subject matter or formation, is governed by and construed in accordance with the laws of England and Wales.
26.2 The Parties irrevocably agree that the courts of England and Wales have exclusive jurisdiction to settle any such dispute or claim.
26.3 The United Nations Convention on Contracts for the International Sale of Goods does not apply.
26.4 Escalation. Before commencing proceedings (other than for injunctive relief or recovery of unpaid Fees), the Parties will attempt in good faith to resolve any dispute by escalation to senior representatives for a period of 30 days.
26.5 Nothing in this clause prevents either Party from seeking urgent injunctive or other interim relief in any court of competent jurisdiction.
SCHEDULE 1 — ACCEPTABLE USE POLICY
This Acceptable Use Policy ("AUP") forms part of the Agreement. Capitalised terms have the meanings given in the Terms. Breach of this AUP is a material breach of the Agreement and entitles us to suspend or terminate immediately under clauses 18 and 19.3.
1. General principle
You must use the Service lawfully, honestly, and in a manner that does not harm Prospects, third parties, us, or the integrity of the Service.
2. Prohibited content and conduct
You must not use the Service, and must not configure, publish or distribute any Spark, to create, transmit, solicit, store or distribute content or conduct activity that:
2.1 Unlawful and harmful
(a) is unlawful in any jurisdiction in which the Spark is published or accessed; (b) is defamatory, libellous, threatening, harassing, abusive, or invasive of privacy; (c) is obscene, pornographic, or sexually explicit; (d) depicts, sexualises, exploits or endangers children, or is otherwise directed at persons under 18; (e) promotes, incites or facilitates violence, terrorism, self-harm, suicide, eating disorders, or the commission of any criminal offence; (f) promotes or facilitates discrimination or hatred on the basis of any protected characteristic; (g) constitutes or facilitates fraud, deception, phishing, impersonation or social engineering; (h) infringes any Intellectual Property Rights, breaches confidence, or misappropriates trade secrets.
2.2 Deception and misrepresentation
(a) misrepresents your identity, your organisation, your qualifications, regulatory status, or your affiliation with any person; (b) represents an Output or Spark conversation as having been produced or conducted by a human; (c) impersonates any individual or organisation, or produces synthetic likenesses, voices or content depicting real people without their documented consent; (d) makes claims about results, earnings, health outcomes, or investment returns that are unsubstantiated, misleading or unlawful under applicable advertising, consumer protection or financial promotion rules.
2.3 Regulated and high-risk applications
You must not use the Service to make, materially inform or automate any decision or assessment concerning:
(a) creditworthiness, credit scoring, lending, debt collection, insurance underwriting or pricing; (b) recruitment, candidate screening, hiring, promotion, performance management, disciplinary action or termination; (c) admission to, placement within, or assessment in education or vocational training; (d) eligibility for healthcare, medical diagnosis, treatment, triage, mental health assessment, or any clinical purpose; (e) eligibility for public benefits, housing, essential utilities or emergency services; (f) immigration, asylum, border control, visa or migration status; (g) criminal justice, law enforcement, risk of offending, or judicial decision-making; (h) biometric identification, biometric categorisation, emotion recognition, or inference of race, ethnicity, political opinions, religious beliefs, trade union membership, health, sex life or sexual orientation; (i) any use classified as prohibited under Article 5, or high-risk under Annex III, of Regulation (EU) 2024/1689 (the EU AI Act), or equivalent classification under any applicable law.
2.4 Special categories of person and data
(a) You must not direct any Spark at, or knowingly collect data from, individuals under the age of 18. (b) You must not use the Service to process special category personal data, criminal offence data, or data of vulnerable individuals, without our prior written consent and a documented lawful basis. (c) You must not use the Service to process payment card data, government identification numbers, or financial account credentials.
2.5 Marketing and communications
(a) sending unsolicited communications in breach of applicable anti-spam or direct marketing law; (b) purchasing, renting or using contact lists obtained without a valid lawful basis; (c) failing to honour an opt-out, unsubscribe or objection request; (d) obscuring the sender's identity or failing to provide a valid opt-out mechanism.
2.6 Technical abuse
(a) introducing malware, viruses, worms, logic bombs or other harmful code; (b) attempting to gain unauthorised access to the Service, any Account, or any connected system; (c) probing, scanning, penetration testing or load testing the Service without our prior written consent; (d) interfering with or disrupting the Service or its infrastructure, including through denial-of-service or excessive request volume; (e) prompt injection, jailbreaking, adversarial prompting, or any attempt to cause the Service to act outside its intended boundaries, disclose system prompts, or produce content prohibited by this AUP; (f) using the Service or Outputs to train, fine-tune, benchmark or evaluate any competing AI system or product; (g) circumventing usage limits, rate limits, authentication or access controls; (h) automated scraping or bulk extraction of data other than via documented APIs.
2.7 Commercial misuse
(a) reselling, sublicensing or providing the Service to third parties other than as expressly permitted by your Plan; (b) sharing Account credentials or seats; (c) creating multiple accounts to circumvent Plan limits or obtain additional Trials.
2.8 Sanctions and export control
Using the Service in or for the benefit of any territory or person subject to UK, EU, US or UN sanctions, or in breach of any applicable export control law.
3. Your obligations
3.1 Transparency to Prospects. Every Spark must clearly disclose, before or at the point of first interaction, that the Prospect is interacting with an AI system, and must identify you as the publisher.
3.2 Privacy notice. Every Spark must link to a privacy notice that accurately describes what data is collected, why, on what lawful basis, how long it is retained, and how the Prospect can exercise their rights.
3.3 Testing. You must test every Spark before publication and review Outputs periodically thereafter.
3.4 Disclaimers. Every Result Experience must carry a disclaimer, appropriate to your sector and regulatory status, making clear that the Output is AI-generated, informational, and not professional advice.
3.5 Contact route. You must provide Prospects with a means of contacting you to raise concerns, request correction, or exercise data protection rights.
4. Reporting and enforcement
4.1 Report suspected violations to abuse@demandspark.ai.
4.2 We may, but are not obliged to, monitor use of the Service for compliance with this AUP. We may investigate suspected breaches and, in doing so, access Customer Data to the extent reasonably necessary.
4.3 Where we identify or reasonably suspect a breach, we may, at our discretion and without liability: issue a warning; unpublish or disable a Spark or Output; suspend or restrict the Account; terminate the Agreement; retain evidence; and report the matter to law enforcement or a regulator.
4.4 We may act without notice where we consider it necessary to prevent harm, comply with law, or protect the Service or any person.
4.5 We may update this AUP in accordance with clause 23 of the Terms.
SCHEDULE 2 — DATA PROCESSING ADDENDUM
This Data Processing Addendum ("DPA") forms part of the Agreement and applies to the Processing of Personal Data by the Provider as Processor on behalf of the Customer as Controller.
1. Definitions and interpretation
1.1 Capitalised terms not defined here have the meanings given in the Terms. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in Applicable Data Protection Law.
1.2 "UK GDPR" means Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, as amended, including by the Data (Use and Access) Act 2025.
1.3 "EU SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
1.4 "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner under section 119A of the Data Protection Act 2018.
1.5 In the event of conflict between this DPA and the Terms in relation to Processing of Personal Data, this DPA prevails.
2. Roles and scope
2.1 The Parties acknowledge that, in relation to Customer Personal Data (as described in Annex 1), the Customer is the Controller and the Provider is the Processor.
2.2 Where the Customer acts as a processor on behalf of its own client, the Customer warrants that it has all necessary authority from that client to appoint the Provider as a sub-processor on these terms, and references to "Controller" apply to the Customer as if it were the Controller.
2.3 The Provider acts as an independent Controller in respect of: User account and billing data; usage and telemetry data; data processed for security, fraud prevention, service improvement and legal compliance; and aggregated and de-identified data under clause 10.4 of the Terms. Such Processing is governed by the Provider's Privacy Policy and not by this DPA.
3. Customer obligations
3.1 The Customer warrants and undertakes that:
(a) it has a valid lawful basis under Applicable Data Protection Law for all Processing it instructs;
(b) it has provided all required privacy notices to Data Subjects, including in respect of AI processing and any automated decision-making;
(c) its instructions to the Provider will not cause the Provider to breach Applicable Data Protection Law;
(d) it will not instruct the Processing of special category personal data, criminal offence data, or children's data through the Service without the Provider's prior written consent;
(e) it has carried out any data protection impact assessment required by Applicable Data Protection Law in respect of its use of the Service;
(f) it is solely responsible for determining whether its use of Outputs constitutes automated decision-making producing legal or similarly significant effects, and for implementing the safeguards required by Articles 22A to 22D of the UK GDPR, Article 22 of the EU GDPR, or equivalent provisions.
3.2 The Customer will maintain a complaints procedure meeting the requirements of section 164A of the Data Protection Act 2018 (as inserted by the Data (Use and Access) Act 2025) in respect of Prospect Data.
4. Provider obligations
The Provider will:
4.1 Documented instructions. Process Customer Personal Data only on the Customer's documented instructions, which comprise the Agreement, the Customer's configuration and use of the Service, and any further written instructions agreed by the Parties, unless required to do otherwise by law (in which case the Provider will notify the Customer before Processing, unless the law prohibits such notification).
4.2 Notification of unlawful instructions. Notify the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. The Provider may suspend Processing of the affected instruction pending resolution.
4.3 Confidentiality. Ensure that all persons authorised to Process Customer Personal Data are bound by an appropriate obligation of confidentiality and have received appropriate training.
4.4 Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk, in accordance with Article 32 of the UK GDPR and EU GDPR. The Provider may update these measures provided the level of protection is not materially reduced.
4.5 Sub-processors. Comply with clause 5.
4.6 Data subject rights. Taking into account the nature of the Processing, provide reasonable assistance by appropriate technical and organisational measures, insofar as possible, to enable the Customer to respond to requests from Data Subjects to exercise their rights. Where the Provider receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively (other than to direct the Data Subject to the Customer) and will notify the Customer without undue delay.
4.7 Assistance. Provide reasonable assistance to the Customer, at the Customer's cost (save where the need for assistance arises from the Provider's breach), with data protection impact assessments, prior consultations with Supervisory Authorities, and the Customer's obligations under Articles 32 to 36 of the UK GDPR and EU GDPR, taking into account the nature of Processing and the information available to the Provider.
4.8 Personal Data Breach. Notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide such information as is reasonably available to enable the Customer to meet its notification obligations. The Provider's notification is not an acknowledgement of fault or liability.
4.9 Deletion or return. At the Customer's option, delete or return all Customer Personal Data at the end of the provision of Services, in accordance with clauses 19.5 and 19.6 of the Terms, save where retention is required by law.
4.10 Records and audit. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. The Customer may audit compliance not more than once in any 12-month period (or more frequently following a Personal Data Breach or where required by a Supervisory Authority), on 30 days' written notice, during business hours, subject to reasonable confidentiality and security requirements, at the Customer's cost, and without access to the data of other customers. The Provider may satisfy an audit request by providing a current third-party audit report, security questionnaire response, or certification where available.
5. Sub-processors
5.1 The Customer grants the Provider general written authorisation to engage sub-processors, including AI Providers, hosting providers, payment processors, communications providers and support tooling providers.
5.2 A current list of sub-processors is maintained at https://demandspark.ai/terms#annex-3-sub-processors and, as at the date of this DPA, is set out in Annex 3.
5.3 The Provider will give the Customer at least 30 days' notice of the addition or replacement of a sub-processor, by email or by updating the sub-processor list where the Customer has subscribed to notifications. The Customer may object on reasonable data protection grounds within 14 days of notice. If the Parties cannot resolve the objection within a further 30 days, the Customer's sole remedy is to terminate the affected part of the Service (or the Agreement) on written notice, with a pro-rata refund of prepaid Fees for the unexpired term.
5.4 The Provider will impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor's obligations.
5.5 The Provider may engage a sub-processor without prior notice where necessary to address an emergency or security incident, and will notify the Customer as soon as reasonably practicable.
6. International transfers
6.1 The Provider is established in the United Kingdom. The Customer acknowledges that the European Commission renewed its adequacy decision in respect of the United Kingdom on 19 December 2025, effective until 27 December 2031, such that transfers of Personal Data from the EEA to the Provider in the UK do not require an additional transfer mechanism for so long as that decision remains in force.
6.2 Customer Personal Data may be transferred to, and Processed in, countries outside the UK and EEA, including the United States, where sub-processors are located.
6.3 Where such a transfer requires a transfer mechanism, the Provider will ensure that an appropriate mechanism is in place, being (in order of preference): an adequacy decision or adequacy regulations; the EU SCCs (Module Three, processor-to-processor, or Module Two where applicable) for transfers subject to the EU GDPR; the EU SCCs as supplemented by the UK Addendum, or the ICO's International Data Transfer Agreement, for transfers subject to the UK GDPR; or another lawful mechanism.
6.4 Where the EU SCCs apply directly between the Parties, they are incorporated into this DPA by reference and are completed as follows: the Customer is the data exporter and the Provider the data importer; Annex 1 to this DPA populates Annexes I.A and I.B; Annex 2 populates Annex II; the optional docking clause applies; Clause 9 option 2 (general authorisation) applies with the notice period in clause 5.3; Clause 11 optional independent dispute resolution does not apply; Clause 17 governing law is the law of Ireland (or, under the UK Addendum, England and Wales); Clause 18(b) forum is the courts of Ireland (or, under the UK Addendum, England and Wales).
6.5 The Provider will notify the Customer if it becomes subject to a legally binding request from a public authority for disclosure of Customer Personal Data, unless prohibited by law, and will challenge any request it considers unlawful.
7. Liability
7.1 Each Party's liability under or in connection with this DPA is subject to the limitations and exclusions in clause 17 of the Terms, save to the extent such limitation is prohibited by Applicable Data Protection Law.
7.2 Where a Supervisory Authority imposes a fine, or a Data Subject obtains compensation, in circumstances where both Parties bear responsibility, each Party bears the portion attributable to its own acts or omissions.
7.3 Nothing in this DPA limits the rights of Data Subjects under Applicable Data Protection Law.
8. Term
This DPA takes effect on the Effective Date and continues until the Provider ceases to Process Customer Personal Data.
ANNEX 1 — DETAILS OF PROCESSING
Data exporter / Controller: The Customer, as identified in the Account.
Data importer / Processor: FluentForward Ltd (or its successor under clause 21 of the Terms), North View, Farrington Road, Paulton, Bristol, BS39 7LP, United Kingdom. Contact: privacy@demandspark.ai.
Subject matter of Processing: Provision of the DemandSpark platform, comprising AI-driven prospect experiences, lead qualification, scoring, result delivery, outreach and lifecycle engagement.
Duration: For the term of the Agreement, plus the retention periods in clauses 19.5 and 19.6 of the Terms.
Nature and purpose of Processing: Collection, recording, organisation, structuring, storage, retrieval, analysis (including AI inference and reasoned scoring), generation of derived content, transmission to third-party integrations nominated by the Customer, hosting, backup, erasure and destruction — in each case for the purpose of enabling the Customer to generate, qualify and engage demand.
Categories of Data Subject:
- Prospects who access, interact with or complete a Spark
- The Customer's Users and administrators
- Contacts within the Customer's imported or connected lists
- Where the Customer delivers services to its own clients, individuals associated with those clients
Categories of Personal Data:
- Identity data: name, job title, organisation
- Contact data: email address, telephone number, messaging identifiers, postal address
- Professional and business data: role, company size, sector, revenue band, business challenges, goals, budget indicators
- Content data: free-text responses submitted during a Spark conversation, and any Personal Data volunteered within them
- Derived data: reasoned lead scores, context summaries, segmentation tags, recommended next actions, and other Outputs
- Technical data: IP address, device and browser information, timestamps, session and interaction data, referral source, campaign attribution
- Communications data: outreach messages, delivery, open and response data
Special category data: Not permitted without the Provider's prior written consent (see DPA clause 3.1(d)). The Customer must configure Sparks so as not to solicit special category data. The Customer acknowledges that free-text fields may result in Data Subjects volunteering such data unprompted, and is responsible for its lawful handling.
Frequency of transfer: Continuous, for the duration of the Agreement.
Sensitivity and safeguards: Business contact and professional profiling data. Safeguards as set out in Annex 2.
Competent Supervisory Authority (for EU SCC purposes): the Supervisory Authority of the Customer's main establishment or, where applicable, its representative.
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES
Encryption
- Data in transit encrypted using TLS 1.2 or above (HTTPS enforced at the edge)
- Platform-managed encryption at rest for managed database and volumes
- Sensitive credentials (including OAuth tokens) encrypted at application level using AES-256-GCM
- Secrets and credentials held in a managed secrets store (Fly.io secrets)
Access control
- Role-based access control with least-privilege principles (Workspace roles and platform administration)
- Authenticated access to the Service via Firebase Authentication
- Production deploy and secrets access limited to authorised operators via Fly.io and CI/CD credentials
- Access revoked promptly on role change or departure
- Logical separation of customer data by Workspace and Account
Infrastructure
- Hosting on Fly.io, primary region
lhr(London, United Kingdom) - Managed PostgreSQL in the United Kingdom (
lhr) - Managed Redis for queues and ephemeral workload state
- Network isolation between application components on the Fly.io platform
Resilience and continuity
- Managed database service with operator-accessible backup and restore capabilities
- Application and infrastructure monitoring
- Documented restoration procedures for production incidents
Development and change management
- Version control with peer review of changes (GitHub)
- Automated CI/CD pipeline with test gating before production deploy
- Separation of development and production environments
- Dependency and vulnerability scanning where configured in the pipeline
Monitoring and incident response
- Application error tracking and infrastructure logging
- Uptime monitoring for production services
- Personal Data Breach notification within 48 hours (DPA clause 4.8)
Personnel
- Confidentiality obligations in employment and contractor agreements
- Data protection and security awareness for personnel with access to Customer Personal Data
Sub-processor governance
- Data protection terms imposed on sub-processors
- AI Providers contracted on terms prohibiting training on Customer Data where commercially available
- Periodic review of sub-processor security posture
Data minimisation and deletion
- Retention periods configurable by the Customer where the Service permits
- Deletion on request and on termination in accordance with clauses 19.5 and 19.6 of the Terms
ANNEX 3 — SUB-PROCESSORS
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Fly.io | Application hosting, TLS termination, and managed PostgreSQL | United Kingdom (lhr); United States (control plane) |
| Upstash (via Fly.io) | Managed Redis for queues and ephemeral state | United Kingdom / Fly platform regions |
| Anthropic | Large language model inference, agent reasoning, and Output generation | United States (Anthropic API) |
| Resend | Transactional and outreach email delivery | United States |
| Stripe | Payment processing and subscription billing | Ireland, United States |
| Google (Firebase Authentication) | User authentication for Studio and related apps | Global (Google Cloud / Firebase) |
| Sentry | Application error tracking and diagnostics | United States, European Union |
| Better Stack | Uptime monitoring and status page | European Union / United States |
| GitHub | Source control and CI/CD (incidental access only) | United States |
Where the Customer enables an integration with a CRM, advertising, content, or other Third-Party Service (for example HubSpot, LinkedIn, Meta Ads, Google, or similar), that provider is a recipient nominated by the Customer, not a sub-processor of the Provider.
An up-to-date list is maintained at https://demandspark.ai/terms#annex-3-sub-processors.
DemandSpark Terms and Conditions v1.0 — FluentForward Ltd