typesafe

   
 

Last updated September 19, 2026

This Master Customer Agreement is between TypeSafe AI, Inc. (“TypeSafe”) and the entity identified as “Customer” in the order executed by TypeSafe and Customer, the checkout page on TypeSafe’s website, or the confirmation email generated by TypeSafe referencing this Agreement (the “Order”). This Agreement allows Customer to purchase access to certain of TypeSafe’s services specified in the Order. The term “Agreement” refers to the body of this Master Customer Agreement and the Order, collectively. TypeSafe and Customer are each individually a “Party” and together, the “Parties.” Acceptance of this Agreement is a condition to accessing and using the Services (defined below) or any part thereof. The Parties hereto agree as follows:

PLEASE READ THE FOLLOWING TERMS CAREFULLY:

BY ACCEPTING THE AGREEMENT, EITHER BY CLICKING A BOX INDICATING YOUR ACCEPTANCE, EXECUTING AN ORDER THAT REFERENCES THIS MASTER CUSTOMER AGREEMENT, USING (OR MAKING ANY PAYMENT FOR) ANY SERVICES, OR OTHERWISE AFFIRMATIVELY INDICATING YOUR ACCEPTANCE OF THE AGREEMENT, YOU: (A) AGREE TO THE AGREEMENT ON BEHALF OF YOURSELF AS AN INDIVIDUAL, UNLESS YOU ARE USING THE SERVICES ON BEHALF OF AN ORGANIZATION, COMPANY, OR OTHER LEGAL ENTITY, IN WHICH CASE YOU AGREE TO THIS AGREEMENT ON BEHALF OF SUCH ENTITY FOR WHICH YOU ACT; AND (B) REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND CUSTOMER TO THE AGREEMENT. IF YOU DO NOT HAVE SUCH AUTHORITY, OR IF YOU DO NOT AGREE WITH THE AGREEMENT, YOU MUST NOT ACCEPT THE AGREEMENT AND MAY NOT ACCESS OR USE ANY SERVICES. IF YOU ARE ACCEPTING THIS AGREEMENT ON BEHALF OF A COMPANY OR OTHER ENTITY AND AN AUTHORIZED REPRESENTATIVE OF THE ENTITY HAS ALREADY ACCEPTED THIS AGREEMENT ON BEHALF OF THE ENTITY OR ENTERED INTO A SEPARATE WRITTEN AGREEMENT REGARDING THE USE OF THE SERVICES (“SEPARATE AGREEMENT”) THAT IS IN EFFECT AS OF THE DATE ON WHICH YOU ACCEPT THIS AGREEMENT, THEN (I) THIS AGREEMENT WILL NOT APPLY TO YOU AND (II) YOUR AND SUCH ENTITY’S RIGHTS AND OBLIGATIONS WITH RESPECT TO THE SERVICES WILL REMAIN GOVERNED BY, AND SUBJECT TO, THE SEPARATE AGREEMENT.

ARBITRATION NOTICE. Except for certain kinds of disputes described in Section 15, Customer agrees that disputes arising under this Agreement will be resolved by binding, individual arbitration, and BY ACCEPTING THIS AGREEMENT, CUSTOMER AND TYPESAFE ARE EACH WAIVING THE RIGHT TO A TRIAL BY JURY OR TO PARTICIPATE IN ANY CLASS ACTION OR REPRESENTATIVE PROCEEDING.

1. Overview.

Subject to the terms and conditions of this Agreement, TypeSafe will make available to Customer the TypeSafe-hosted web interface available at https://console.typesafe.ai (the “Web Interface”) and the TypeSafe-hosted application programming interface made available by TypeSafe to Customer (the “API,” and together with the Web Interface, the “Services”).

2. Services

2.1. License.

Subject to the terms and conditions of this Agreement and Customer’s continued compliance therewith, including Customer’s compliance with the usage limits set forth in the Order (“Usage Limits”), TypeSafe grants to Customer a limited, non-exclusive, non-transferable, non-sublicensable license during the Term to: (a) access and use the Services in accordance with the applicable documentation made available by TypeSafe from time to time (“Documentation”); and (b) integrate the API with one or more Customer Applications in accordance with Section 2.2 (Customer Applications).

2.2. Customer Applications.

The license set forth in Section 2.1 (License) includes the right to include the API into one or more software applications developed and operated by Customer for the benefit of Customer’s end users (“End Users”) in accordance with the Documentation and the terms of this Agreement (each, a “Customer Application”). Customer shall ensure that each Customer Application complies with applicable laws and regulations (“Laws”) and does not violate or infringe third-party rights.

2.3. License Restrictions.

Customer will not do (and will not attempt to do), and will not allow Customer Applications, or any of Customer’s directors, officers, employees, agents or contractors to do, any of the following: (a) sell, lease, loan, distribute, sublicense, disclose, or otherwise offer or make the Services available as a standalone service; (b) use the Services or any Output (defined below) to perform model distillation, train a model to imitate the output of the Services, or develop (or to facilitate the development of) a similar or competing product or service; (c) reverse engineer, decompile, disassemble, or attempt to access or derive the source code or underlying data with respect to the Services, including the underlying ideas, algorithms, structure, or organization with respect to any of the foregoing; (d) modify or create derivative works of the Services; (e) remove or obscure any proprietary notices in or on the Services; (f) interfere with the operation of the Services; (g) bypass, avoid, remove, deactivate, or otherwise circumvent: (1) any access restrictions; or (2) any other software protection mechanisms in the Services, including any such mechanism used to restrict or control the functionality of any of the foregoing, or conduct any security or vulnerability test with respect to any of the foregoing; (h) transmit any viruses or other harmful materials to or through the Services; (i) take any action that risks harm to others or to the security, availability, or integrity of the Services; (j) exceed any Usage Limits; (k) access the Services other than as expressly permitted in this Agreement in accordance with the Documentation; (l) access or use the Services in a manner that violates TypeSafe’s Acceptable Use Policy (located at typesafe.ai/legal/aup); or (m) access or use the Services or Output in a manner that violates any Law or third-party rights, or otherwise in violation or non-conformity with any terms or conditions of this Agreement or the Documentation.

2.4. Access Credentials; Customer Users.

Customer and its personnel may only access the Services through the mechanisms designated by TypeSafe, including an API key (in the case of the API) and a username and password (in the case of the Web Interface) (collectively, “Access Credentials”). Customer will not authorize or enable any person or entity who is not an employee or independent contractor of Customer (“Customer User”) to access or use the Web Interface. Customer will ensure that each Customer User keeps the Access Credentials confidential and does not share them with anyone else. Customer is responsible for all actions taken in connection with, or through an account associated with, Access Credentials (excluding misuse of Access Credentials caused by TypeSafe’s breach of the Agreement). Customer will promptly notify TypeSafe if it becomes aware of any compromise of any Access Credentials. TypeSafe may collect, access, view, use, disclose, transfer, transmit, store, host, or otherwise process (“Process”) the Access Credentials in connection with TypeSafe’s provision of the Services or for TypeSafe’s internal business purposes. Customer will be responsible for the acts and omissions of Customer Users in connection with this Agreement as though such acts and omissions were Customer’s own.

2.5. Updates.

Customer acknowledges and agrees that TypeSafe may from time to time update the Services, and that such changes may result in the API’s becoming incompatible with a Customer Application. TypeSafe will use commercially reasonable efforts to provide advance notice of any updates to the API that TypeSafe believes will materially and adversely impact Customer’s ability to integrate the API with Customer Applications.

3. Support.

During the Term, TypeSafe will use commercially reasonable efforts to support the Services in accordance with its standard support policies designed to ensure the Services operate in accordance with the applicable Documentation (“Support”). Customer may email TypeSafe at support@typesafe.ai to request Support.

4. Data

4.1. Use of Customer Data.

Customer hereby grants TypeSafe a non-exclusive, worldwide, royalty-free, fully paid-up, non-sublicensable (except to service providers), non-transferable (except as set forth in Section 16.1 (Assignment)) right to use, copy, store, disclose, transmit, transfer, display, modify, create derivative works from, and otherwise Process (a) during the Term, any data, files, queries, and other materials that Customer (including Customer Users or End Users) inputs or makes available to TypeSafe, including through the Services or any Customer Application integrated therewith (collectively, “Input”) solely to perform its obligations set forth in the Agreement, including to generate outputs from the Services that are delivered to Customer (such outputs, “Output,” and, collectively with Input, “Customer Data”), (b) during the Term, any Customer Data to provide the Services and calculate Fees, and (c) in perpetuity, any Customer Data (i) to derive and generate Telemetry, (ii) to monitor for fraud and abuse of the Services, and (iii) as necessary to comply with applicable Laws. The foregoing license does not grant TypeSafe the right to, and TypeSafe will not, include Customer Data in a dataset used to train (i.e., to modify the model weights of) any artificial intelligence or machine learning models without Customer’s prior consent.

4.2. Output.

As between Customer and TypeSafe and to the extent permitted by Laws, TypeSafe does not claim ownership of Input and TypeSafe disclaims ownership of Output. TypeSafe hereby assigns to Customer all of its right, title, and interest, if any, in the Output.

4.3. Telemetry.

“Telemetry” means information generated in connection with the Services, such as technical logs, hashes, summary statistics and classifications, metrics, and learnings related to Customer’s use of the Services. TypeSafe may Process Telemetry without restriction, including to improve the Services or TypeSafe’s other products and services.

4.4. DPA.

The terms of the Data Processing Agreement currently available at https://typesafe.ai/data-processing are incorporated herein by reference.

5. Customer Obligations.

Customer is responsible for Input, including its content and accuracy, and will comply with Laws when using the Services. Customer represents, warrants, and covenants that it has made all disclosures, has provided all notices, and has obtained (and will maintain) all rights, consents, and permissions necessary for TypeSafe to exercise the rights granted to it in this Agreement (including the rights granted with respect to Input) without violating or infringing Laws or third-party rights. Customer is responsible for the acts and omissions of Customer Users and End Users in connection with the Agreement as though such acts and omissions were Customer’s own.

6. Suspension of Services.

TypeSafe may immediately suspend Customer’s access to any or all of the Services if: (a) Customer breaches or otherwise violates Section 2.3 (License Restrictions), Section 2.4 (Access Credentials; Customer Users), Section 5 (Customer Obligations), or Section 8.2(b) (Promotional Credits); (b) any payments required under this Agreement are overdue by 30 days or more; (c) changes to Laws or new Laws require that TypeSafe suspend a Service or otherwise may impose additional liability on the part of TypeSafe; or (d) Customer’s actions risk harm to any of TypeSafe’s other customers or the security, availability, or integrity of the Services or any TypeSafe systems, products, or services. Where practicable, TypeSafe will use commercially reasonable efforts to provide Customer with prior notice of the suspension (email sufficing). If the issue that led to the suspension is resolved, TypeSafe will restore Customer’s access to the Services.

7. Third-Party Platforms.

The Services may support integration with third-party platforms, add-ons, services, or products not provided by TypeSafe (“Third-Party Platforms”). Use of any Third-Party Platforms integrated with or made available through the Services is subject to Customer’s agreement with the relevant provider and not this Agreement. TypeSafe does not control and has no liability for Third-Party Platforms, including their security, functionality, operation, availability, or interoperability with the Services. By enabling a Third-Party Platform to interact with the Services, Customer authorizes TypeSafe to access and exchange Customer Data with such Third-Party Platform on Customer’s behalf.

8. Fees and Payment

8.1. Payment Terms.

All fees, charges, and all other amounts due pursuant to the Order (“Fees”) will be paid in US dollars unless otherwise set forth in the Order. Unless otherwise set forth in the Order, all Fees are due within 30 days after the invoice date.

8.2. Credits.

In order to generate Output or otherwise use the Services, Customer must obtain TypeSafe-managed credits that are consumed by each Input submitted to the Services through Customer’s account (each, a “Credit”). Credits include Credits purchased by Customer in accordance with Section 8.2(a) (“Purchased Credit”) and Credits that TypeSafe, at its sole discretion, issues to Customer at no cost to Customer as described in Section 8.2(b) (“Promotional Credits”). The rate at which Credits are consumed may vary based on account settings, including the model used by Customer to generate Output, as may be indicated to Customer on the Services. Customer may view Customer’s current Credit balance in Customer’s account. Credits (y) are not redeemable, refundable, transferable, or legal tender or currency, and (z) do not constitute or confer upon Customer any personal property right.

(a) Purchased Credits.

Unless otherwise set forth in the Order, (i) Purchased Credits expire on the earlier of (y) the end of the Term and (z) the date that is 12 months after the purchase date, and (ii) if Customer’s Credit balance reaches zero (or falls below the applicable threshold) or Customer submits Input through the Services after all Credits have been consumed, then (y) if Customer has opted in to automatic Purchased Credit refills, TypeSafe will automatically add to Customer’s Credit balance a number of Credits equal to the refill dollar amount of Purchased Credits that Customer selected at the time of the opt in, or (z) if Customer has not opted in to automatic Purchased Credit refills, TypeSafe may decline to generate Output in response to Customer’s submission of Input.

(b) Promotional Credits.

TypeSafe may, but has no obligation to, issue Promotional Credits to Customer. Promotional Credits are subject to any additional terms made available to Customer by TypeSafe at the time of issuance, including terms with respect to expiration, revocation, or other limitations on Promotional Credits. If Customer has Promotional Credits, then such Promotional Credits will be consumed prior to the consumption of any of Customer’s then-available Purchased Credits. Customer will not, and will not permit any Customer User to, create more than one account for the purpose of receiving additional Promotional Credits or avoiding any restriction or obligation in this Agreement.

8.3. Late Payments.

Late Fees are subject to a service charge of 1.5% per month or the maximum amount allowed by Laws, whichever is less.

8.4. Taxes.

Customer is responsible for any sales, use, GST, value-added, withholding, or similar taxes or levies that apply to Fees, whether domestic or foreign, other than TypeSafe’s income tax (“Taxes”). Fees are exclusive of all Taxes.

9. Warranties and Disclaimers

9.1. Service Warranty.

TypeSafe warrants to Customer that the Services will perform materially as described in its Documentation (“Service Warranty”). The Service Warranty does not apply to: (a) issues caused by Customer’s or Customer Users’ misuse of the Services; (b) issues in or caused by Third-Party Platforms or other third-party systems; or (c) use of the Services other than in accordance with the Documentation.

9.2. Service Warranty Remedy.

If TypeSafe breaches the Service Warranty during the Term and Customer makes a reasonably detailed written warranty claim to TypeSafe within 30 days of discovering a breach of the Service Warranty, then TypeSafe will use reasonable efforts to correct the non-conformity. If TypeSafe cannot do so within 30 days of receipt of Customer’s warranty claim, either Party may terminate the Agreement without penalty and TypeSafe will then refund to Customer any pre-paid, unused Fees for the incomplete portion of the Term. This Section sets forth Customer’s exclusive remedy and TypeSafe’s entire liability for breach of the Service Warranty.

9.3. Disclaimer.

EXCEPT AS EXPRESSLY PROVIDED IN SECTION 9.1 (SERVICE WARRANTY), THE SERVICES AND DOCUMENTATION ARE PROVIDED “AS IS” AND “AS AVAILABLE”. TYPESAFE, ON ITS OWN BEHALF AND ON BEHALF OF ITS SUPPLIERS AND LICENSORS, MAKES NO OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NONINFRINGEMENT. TYPESAFE DOES NOT WARRANT THAT CUSTOMER’S USE OF THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE, THAT TYPESAFE WILL REVIEW CUSTOMER DATA FOR ACCURACY, OR THAT IT WILL MAINTAIN CUSTOMER DATA WITHOUT LOSS. TYPESAFE IS NOT LIABLE FOR DELAYS, FAILURES, OUTAGES, DECREASED FUNCTIONALITY, NON-PERFORMANCE, UNAVAILABILITY OF THE SERVICES, OR OTHER PROBLEMS: (A) INHERENT IN USE OF THE INTERNET AND ELECTRONIC COMMUNICATIONS OR OTHER SYSTEMS OUTSIDE TYPESAFE’S CONTROL; OR (B) DIRECTLY OR INDIRECTLY ARISING OUT OF OR RELATED TO ANY CUSTOMER ACCESS OR USE OF ANY SERVICES IN VIOLATION OR NON-CONFORMITY WITH THIS AGREEMENT (INCLUDING SECTION 2.3 (LICENSE RESTRICTIONS) OR SECTION 2.4 (ACCESS CREDENTIALS; CUSTOMER USERS)), ANY USAGE LIMITS OR TYPESAFE ENFORCEMENT THEREOF, OR APPLICABLE LAWS. CUSTOMER MAY HAVE OTHER STATUTORY RIGHTS, BUT ANY STATUTORILY REQUIRED WARRANTIES WILL BE LIMITED TO THE SHORTEST LEGALLY PERMITTED PERIOD. WITHOUT LIMITING THE FOREGOING, CUSTOMER ACKNOWLEDGES AND AGREES THAT: (I) THE SERVICES MAY PRODUCE INACCURATE OR ERRONEOUS OUTPUT; (II) CUSTOMER IS RESPONSIBLE FOR INDEPENDENTLY EVALUATING THE OUTPUT; AND (III) DUE TO THE NATURE OF THE SERVICES AND ARTIFICIAL INTELLIGENCE TECHNOLOGIES GENERALLY, OUTPUT MAY NOT BE UNIQUE AND OTHER USERS OF THE SERVICES MAY RECEIVE OUTPUT FROM THE SERVICES THAT IS SIMILAR OR IDENTICAL TO THE OUTPUT (AND, NOTWITHSTANDING ANYTHING TO THE CONTRARY, SUCH SIMILAR OR IDENTICAL OUTPUT WILL NOT BE UNDERSTOOD TO BE OUTPUT HEREUNDER).

10. Term and Termination

10.1. Term.

This Agreement will be effective beginning on the start date specified in the Order and will remain in effect until the Order expires in accordance with its terms, unless earlier terminated pursuant to the terms of this Agreement (the “Term”).

10.2. Termination.

Either Party may terminate this Agreement and the Order if the other Party: (a) fails to cure a material breach of this Agreement (including a failure to pay Fees, or any violation of Section 2.3 (License Restrictions) or Section 2.4 (Access Credentials; Customer Users)) within 30 days after notice; (b) ceases operation without a successor; or (c) seeks protection under a bankruptcy, receivership, trust deed, creditors’ arrangement, composition, or comparable proceeding, or if such a proceeding is instituted against that Party and not dismissed within 60 days.

10.3. Effect of Termination.

Upon expiration or termination of this Agreement: (a) the license granted pursuant to Section 2.1 (License) will terminate; (b) Customer will immediately cease all use of the Services; and (c) TypeSafe will have no obligation to provide any compensation or refund for any prepaid amounts not consumed as of the effective date of such termination or expiration. For avoidance of doubt, both during the Term, and following the date of expiration or earlier termination of the Agreement, TypeSafe will be under no obligation to store or retain Customer Data and may delete Customer Data at any time in its sole discretion. Customer Confidential Information may be retained in TypeSafe’s standard backups notwithstanding any obligation to delete the applicable Confidential Information but will remain subject to this Agreement’s confidentiality restrictions.

10.4. Survival.

These Sections survive expiration or termination of this Agreement: 2.3 (License Restrictions), 4.1 (Use of Customer Data), 4.3 (Telemetry), 5 (Customer Obligations), 8 (Fees and Payment), 9 (Warranties and Disclaimers), 10.3 (Effect of Termination), 10.4 (Survival), 11 (Ownership), 12 (Limitations of Liability), 13 (Indemnification), 14 (Confidentiality), 15 (Dispute Resolution and Arbitration), and 16 (General Terms). Except where an exclusive remedy is provided in this Agreement, exercising a remedy under this Agreement, including termination, does not limit other remedies a Party may have.

11. Ownership.

Neither Party grants the other any rights or licenses not expressly set out in this Agreement. Except as expressly provided in this Agreement, as between the Parties, Customer retains all intellectual property rights in its Input provided to TypeSafe hereunder. Except for the limited license granted pursuant to Section 2.1 (License), TypeSafe and its licensors retain all intellectual property rights and other rights in and to the Services, Documentation, Telemetry, and TypeSafe technology, processes, methodologies, and ideas. If Customer provides TypeSafe with feedback, bug reports, or suggestions regarding the Services or other TypeSafe technology, TypeSafe may use and exploit the feedback or suggestions without restriction or obligation.

12. Limitations Of Liability

12.1. Consequential Damages Waiver.

EXCEPT FOR EXCLUDED CLAIMS (AS DEFINED BELOW) AND TO THE FULLEST EXTENT PERMITTED BY LAWS, NEITHER PARTY (NOR ITS SUPPLIERS OR LICENSORS) WILL HAVE ANY LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT FOR ANY LOSS OF USE, LOST DATA, LOST PROFITS, FAILURE OF SECURITY MECHANISMS, INTERRUPTION OF BUSINESS, OR ANY INDIRECT, SPECIAL, INCIDENTAL, RELIANCE, OR CONSEQUENTIAL DAMAGES OF ANY KIND, EVEN IF INFORMED OF THEIR POSSIBILITY IN ADVANCE.

12.2. Liability Cap.

EXCEPT FOR EXCLUDED CLAIMS, AND TO THE FULLEST EXTENT PERMITTED BY LAWS, EACH PARTY’S (AND ITS SUPPLIERS’ AND LICENSORS’) ENTIRE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED IN AGGREGATE THE GREATER OF (A) THE AMOUNTS PAID OR PAYABLE BY CUSTOMER TO TYPESAFE PURSUANT TO THIS AGREEMENT DURING THE 12 MONTHS PRIOR TO THE DATE ON WHICH THE APPLICABLE CLAIM GIVING RISE TO THE LIABILITY AROSE UNDER THIS AGREEMENT AND (B) $50 USD.

12.3. Excluded Claims.

“EXCLUDED CLAIMS” MEANS: (A) CUSTOMER’S FAILURE TO PAY AMOUNTS DUE UNDER SECTION 8 (FEES AND PAYMENT); (B) CUSTOMER’S BREACH OF SECTION 2.3 (LICENSE RESTRICTIONS), SECTION 2.4 (ACCESS CREDENTIALS; CUSTOMER USERS) OR SECTION 5 (CUSTOMER OBLIGATIONS); OR (C) A PARTY’S PAYMENT OBLIGATIONS UNDER THE INDEMNITY SET FORTH IN SECTION 13 (INDEMNIFICATION).

12.4. Nature of Claims and Failure of Essential Purpose.

The waivers and limitations in this Section 12 (Limitations of Liability) apply regardless of the form of action, whether in contract, tort (including negligence), strict liability or otherwise and will survive and apply even if any limited remedy in this Agreement fails of its essential purpose.

13. Indemnification

13.1. Indemnification by TypeSafe.

TypeSafe will defend Customer against any third-party claim alleging that the Services, as delivered to Customer, infringe or misappropriate a third-party’s U.S. patent, copyright, trademark, or trade secret, and will indemnify and hold harmless Customer against any damages and costs awarded against Customer (including reasonable attorneys’ fees) or agreed in a settlement by TypeSafe, resulting from the claim.

13.2. Indemnification by Customer.

Customer will defend TypeSafe from and against any third-party claim to the extent (a) relating to Input, (b) relating to Customer Applications and not resulting from a breach by TypeSafe of this Agreement, (c) arising out of or resulting from facts or circumstances that, if true, would result in Customer’s breach of Section 2.3 (License Restrictions), Section 2.4 (Access Credentials; Customer Users), or Section 5 (Customer Obligations), or (d) brought by an End User and related to the subject matter of this Agreement, and, in each case of (a) through (d), will indemnify and hold harmless TypeSafe against any damages and costs awarded against TypeSafe (including reasonable attorneys’ fees) or agreed in a settlement by Customer resulting from the claim.

13.3. Procedures.

The indemnifying Party’s obligations in this Section 13 (Indemnification) are subject to it receiving: (a) prompt written notice of the claim; (b) the exclusive right to control and direct the investigation, defense, and settlement of the claim; and (c) all reasonably necessary cooperation of the indemnified Party, at the indemnifying Party’s expense for reasonable out-of-pocket costs. The indemnifying Party may not settle any claim without the indemnified Party’s prior consent if settlement would require the indemnified Party to admit fault or take or refrain from taking any action (other than relating to use of the Services, when TypeSafe is the indemnifying Party). The indemnified Party may participate in a claim with its own counsel at its own expense.

13.4. Mitigation.

In response to an actual or potential infringement or misappropriation claim or otherwise relating to violation of intellectual property rights, if required by settlement or injunction or as TypeSafe determines necessary to avoid material liability, TypeSafe may at its option: (a) procure rights for Customer’s continued use of the Services; (b) replace or modify the allegedly infringing portion of the Services to avoid infringement or misappropriation without reducing the Services’ overall functionality; or (c) terminate the Agreement and the Order and refund to Customer any pre-paid, unused Fees for the terminated portion of the Term.

13.5. Exceptions.

TypeSafe’s obligations in this Section 13 (Indemnification) do not apply: (a) to infringement or misappropriation resulting from Customer’s use of the Services in combination with items not provided by TypeSafe (including Third-Party Platforms); (b) to unauthorized access to or use of the Services, or other use in non-conformity in any respect, with this Agreement; (c) if Customer settles or makes any admissions about a claim without TypeSafe’s prior consent; (d) with respect to any claim, directly or indirectly, in whole or in part, arising from, based on, or involving any fault, negligence, misconduct, default, violation of applicable Law or third-party right of Customer or its affiliates, directors, officers, employees, agents, or contractors; or (e) Output.

13.6. Exclusive Remedy.

THIS SECTION 13 (INDEMNIFICATION) SETS OUT CUSTOMER’S EXCLUSIVE REMEDY AND TYPESAFE’S ENTIRE LIABILITY REGARDING INFRINGEMENT OR MISAPPROPRIATION OF THIRD-PARTY INTELLECTUAL PROPERTY RIGHTS.

14. Confidentiality

14.1. Definition.

“Confidential Information” means information disclosed to the receiving Party (“Recipient”) under this Agreement that is designated by the disclosing Party (“Discloser”) as proprietary or confidential or that should be reasonably understood to be proprietary or confidential due to its nature and the circumstances of its disclosure. Notwithstanding anything to the contrary, including Section 14.3 (Exclusions), TypeSafe’s Confidential Information includes the Access Credentials, Documentation, Customer’s Fees and all pricing information, the terms and conditions of this Agreement, and other non-public information with respect to the Services or any other TypeSafe product or service.

14.2. Obligations.

As Recipient, each Party will: (a) hold Confidential Information in confidence and not disclose it to third parties except as permitted in this Agreement, including Section 4.1 (Use of Customer Data); and (b) only use Confidential Information to fulfill its obligations and exercise its rights in this Agreement. Recipient may disclose Confidential Information to its employees, agents, contractors, and other representatives having a legitimate need to know (including, where TypeSafe is Recipient, the subcontractors referenced in Section 16.10 (Subcontractors)), provided it remains responsible for their compliance with this Section 14 (Confidentiality) and they are bound to confidentiality obligations no less protective than this Section 14 (Confidentiality).

14.3. Exclusions.

These confidentiality obligations do not apply to information that Recipient can document: (a) is or becomes public knowledge through no fault of the receiving Party; (b) it rightfully knew or possessed prior to receipt under this Agreement; (c) it rightfully received from a third party without breach of confidentiality obligations; or (d) it independently developed without using Confidential Information.

14.4. Remedies.

Unauthorized use or disclosure of Confidential Information may cause substantial harm for which damages alone are an insufficient remedy. Each Party may seek appropriate equitable relief, in addition to other available remedies, for breach or threatened breach of this Section 14 (Confidentiality).

14.5. Required Disclosures.

Nothing in this Agreement prohibits either Party from making disclosures, including of Customer Data and other Confidential Information, if required by Law, subpoena, or court order, provided (if permitted by Law) it notifies the other Party in advance and cooperates in any effort to obtain confidential treatment.

15. Dispute Resolution and Arbitration

15.1. Generally.

Except as described in Section 15.2 (Exceptions), the Parties agree that every dispute arising in connection with this Agreement, the Services, or communications between the Parties will be resolved through binding arbitration. Arbitration uses a neutral arbitrator instead of a judge or jury, is less formal than a court proceeding, may allow for more limited discovery than in court, and is subject to very limited review by courts. This agreement to arbitrate disputes includes all claims whether based in contract, tort, statute, fraud, misrepresentation, or any other legal theory, and regardless of whether a claim arises during or after the termination of this Agreement. Any dispute relating to the interpretation, applicability, or enforceability of this binding arbitration agreement will be resolved by the arbitrator. CUSTOMER UNDERSTANDS AND AGREES THAT, BY ENTERING INTO THIS AGREEMENT, CUSTOMER AND TYPESAFE ARE EACH WAIVING THE RIGHT TO A TRIAL BY JURY OR TO PARTICIPATE IN A CLASS ACTION.

15.2. Exceptions.

Although the Parties are agreeing to arbitrate most disputes between them, nothing in this Agreement will be deemed to waive, preclude, or otherwise limit the right of either Party to: (a) bring an individual action in small claims court; (b) pursue an enforcement action through the applicable federal, state, or local agency if that action is available; (c) seek injunctive relief in a court of law in aid of arbitration; or (d) file suit in a court of law to address an intellectual property infringement claim.

15.3. Arbitrator.

This arbitration agreement, and any arbitration between TypeSafe and Customer, is subject to the Federal Arbitration Act and will be administered by the JAMS (a) if Customer is an individual, then under the rules applicable to consumer disputes and (b) if Customer is a business, then under the JAMS Comprehensive Arbitration Rules and Procedures (as applicable, the “JAMS Rules”) as modified by this Agreement. The JAMS Rules and filing forms are available online at www.jamsadr.com, by calling the JAMS at +1-800-352-5267 or by contacting TypeSafe.

15.4. Commencing Arbitration.

Before initiating arbitration, a Party must first send a written notice of the dispute to the other Party by certified U.S. Mail or by Federal Express (signature required) or, only if that other Party has not provided a current physical address, then by electronic mail (“Notice of Arbitration”). TypeSafe’s address for Notice is: TypeSafe AI, Inc., 255 California St, Suite 1300, San Francisco, CA 94117. The Notice of Arbitration must: (a) identify the name or account number of the party making the claim; (b) describe the nature and basis of the claim or dispute; and (c) set forth the specific relief sought (“Demand”). The Parties will make good faith efforts to resolve the claim directly, but if the Parties do not reach an agreement to do so within thirty (30) days after the Notice of Arbitration is received, Customer or TypeSafe may commence an arbitration proceeding. The payment of all fees will be governed by the JAMS Rules.

15.5. Arbitration Proceedings.

Any arbitration hearing will be conducted by telephone, based on written submissions, video conference, or in person in The City and County of San Francisco, California unless the Parties agree otherwise. During the arbitration, the amount of any settlement offer made by Customer or TypeSafe must not be disclosed to the arbitrator until after the arbitrator makes a final decision and award, if any. Regardless of the manner in which the arbitration is conducted, the arbitrator must issue a reasoned written decision sufficient to explain the essential findings and conclusions on which the decision and award, if any, are based.

15.6. Arbitration Relief.

Except as provided in Section 15.7 (No Class Actions), the arbitrator can award any relief that would be available if the claims had been brought in a court of competent jurisdiction. The arbitrator’s award shall be final and binding on all Parties, except (a) for judicial review expressly permitted by law or (b) if the arbitrator’s award includes an award of injunctive relief against a Party, in which case that Party shall have the right to seek judicial review of the injunctive relief in a court of competent jurisdiction that shall not be bound by the arbitrator’s application or conclusions of law. Judgment on the award may be entered in any court having jurisdiction.

15.7. No Class Actions.

CUSTOMER AND TYPESAFE AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN CUSTOMER’S OR TYPESAFE’S INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.

15.8. Enforceability.

If Section 15.7 (No Class Actions) or the entirety of this Section 15 (Dispute Resolution and Arbitration) is found to be unenforceable, then the entirety of this Section 15 (Dispute Resolution and Arbitration) will be null and void and, in that case, the exclusive jurisdiction and venue described in Section 16.2 (Governing Law; Jurisdiction and Venue) will govern any action arising out of or related to this Agreement.

16. General Terms

16.1. Assignment.

Neither Party may assign this Agreement without the prior consent of the other Party, except that TypeSafe may assign this Agreement in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all its assets or voting securities. Any non-permitted assignment is void. This Agreement will bind and inure to the benefit of each Party’s permitted successors and assigns.

16.2. Governing Law, Jurisdiction and Venue.

This Agreement is governed by the laws of the State of California and the United States without regard to conflicts of laws provisions that would result in the application of the laws of another jurisdiction and without regard to the United Nations Convention on the International Sale of Goods. The jurisdiction and venue for actions related to this Agreement will be the state and United States federal courts located in The City and County of San Francisco, California and both Parties submit to the personal jurisdiction of those courts for resolution of any lawsuit or court proceedings permitted under this Agreement.

16.3. Attorneys’ Fees and Costs.

The prevailing Party in any action to enforce this Agreement will be entitled to recover its attorneys’ fees and costs in connection with such action.

16.4. Publicity.

Nothing in this Agreement grants either Party the right to use the name, brand, or logo of the other Party, and neither Party may publicly announce that the Parties have entered into the Agreement, except with the other Party’s prior consent or as required by Laws; provided, however, that TypeSafe may use the name, brand, or logo of Customer (or Customer’s parent company) for the purpose of identifying Customer as a licensee or customer on TypeSafe’s website or in other promotional materials, or as part of a list of TypeSafe’s customers in a press release or other public relations materials announcing Customer’s use of the Services. TypeSafe will cease further use of such assets at Customer’s written request.

16.5. Notices.

Except as set out in this Agreement, any notice or consent under this Agreement must be in writing and sent to 255 California St, Suite 1300, San Francisco, CA 94117 or sales@typesafe.ai if to TypeSafe or to the address or email address specified on the Order if to Customer, and will be deemed given: (a) upon receipt if by personal delivery; (b) upon receipt if by certified or registered U.S. mail (return receipt requested); (c) one day after dispatch if by a commercial overnight delivery service; or (d) upon the earlier of the receipt of a confirmation email or one day after sending if by email. Either Party may update its address with notice to the other Party pursuant to this Section. TypeSafe may also send operational notices to Customer by email or through the Services.

16.6. Entire Agreement.

This Agreement (which includes the Order) is the Parties’ entire agreement regarding its subject matter and supersedes any prior or contemporaneous agreements regarding its subject matter. In this Agreement, headings are for convenience only and “including” and similar terms are to be construed without limitation.

16.7. Amendments.

Except as expressly set forth herein, any amendments, modifications, or supplements to this Agreement must be in writing and signed by each Party’s authorized representatives or, as appropriate, agreed through electronic means provided by TypeSafe. The terms in any Customer purchase order or business form will not amend or modify this Agreement and are expressly rejected by TypeSafe; any of these Customer documents are for administrative purposes only and have no legal effect. Notwithstanding the foregoing, TypeSafe may from time to time notify Customer of updates to this Agreement (including by displaying a notification on the Services). Unless a later date is specified by TypeSafe, such updated version of this Agreement will become effective on a going forward basis on the date that is at least 60 days after the date on which TypeSafe provided such notice to Customer.

16.8. Waivers and Severability.

Waivers must be signed by the waiving Party’s authorized representative and cannot be implied from conduct. If any provision of this Agreement is held invalid, illegal, or unenforceable, it will be limited to the minimum extent necessary so the rest of this Agreement remains in effect.

16.9. Force Majeure.

TypeSafe is not liable for any delay or failure to perform any obligation under this Agreement due to events beyond its reasonable control, such as a strike, blockade, war, pandemic, act of terrorism, riot, Internet or utility failures, refusal of government license, or natural disaster.

16.10. Subcontractors.

TypeSafe may use subcontractors and permit them to exercise TypeSafe’s rights, but TypeSafe remains responsible for their compliance with this Agreement and for its overall performance under this Agreement.

16.11. Independent Contractors.

The Parties are independent contractors, not agents, partners, or joint venturers.

16.12. Export.

Customer will comply with all relevant U.S. and foreign export and import Laws in using the Services. Customer: (a) represents and warrants that it is not listed on any U.S. government list of prohibited or restricted parties or located in (or a national of) a country that is subject to a U.S. government embargo or that has been designated by the U.S. government as a “terrorist supporting” country; (b) agrees not to access or use Services in violation of any U.S. export embargo, prohibition, or restriction; and (c) will not submit to the Services any information controlled under the U.S. International Traffic in Arms Regulations.

16.13. Government End-Users.

Elements of the Services may include commercial computer software. If Customer or Customer Users are an agency, department, or other entity of the United States Government, then the use, duplication, reproduction, release, modification, disclosure, or transfer of the Services or any related documentation of any kind, including technical data and manuals, is restricted by the terms of this Agreement in accordance with Federal Acquisition Regulation 12.212 for civilian purposes and Defense Federal Acquisition Regulation Supplement 227.7202 for military purposes. The Services were developed fully at private expense. All other use is prohibited.

16.14. Conflicts in Interpretation.

If there are inconsistencies or conflicts between the terms of the body of this Agreement and the Order, the terms of the Order will control to the extent of the conflict.

 

Last updated November 19, 2025

This privacy policy (“Privacy Policy”) describes the types of personal data that Typesafe AI, Inc. (“TypeSafe,” “we,” “our,” and/or “us”) collects, uses, and discloses from individuals (“you” or “your”) our website at https://www.typesafe.ai along with our web-based interface(s) (the “Playground”), application programming interfaces (“APIs”), and other services that link to this Privacy Policy (collectively, the “Services”).

As used in this Privacy Policy, “personal data” means any information relating to an identified or identifiable individual and includes any information that constitutes "personally identifiable information," “personal data,” or "personal information" under applicable privacy or data protection laws or regulations.

You acknowledge the collection, use, disclosure, procedures, and other processing described in this Privacy Policy.

Personal Data We Collect

We may collect a variety of personal data from or about you or your devices from various sources, as described below. Where applicable, we indicate whether and why you must provide us with your personal data, as well as the consequences of failing to do so. If you do not provide your personal data when requested, you may not be able to use the full extent of the Services if that personal data is necessary to provide you with the Services or if we are legally required to collect it.

Personal Data You Provide to Us

Account Information. We collect the personal data you provide to create, update, or manage your Services account, including, for example, your name and email address.

Services. We collect the personal data you provide when you use the Services, including your prompts, data, instructions, and other input (“Input”). We will not train or fine tune any artificial intelligence or machine learning models on your prompts or other Input.

Contact Information. We may collect your personal data when you inquire about us, the Services, or when you otherwise interact with us. This data may include your name, email address, and any data you choose to provide to us.

Communications. If you contact us directly, we may receive personal data about you, such as your name, email address, the contents of a message or attachments that you may send to us. When you sign up for news and updates, we will collect your email address and other personal data. When you communicate with us online, our third-party vendors may receive and store these communications on our behalf.

When we send you emails, we may use embedded pixels or other technologies to track information about your receipt and interaction with our emails, such as whether and when you open them, whether you access any links included in our emails, how long you read our emails, whether you forward our emails and to whom, your Location Information (described below), and your Device Information (described below), to learn how to deliver a better user experience and improve the Services.

Careers. If you decide that you wish to apply for a job with us, you may submit your contact information and your resume online. We will collect the information you choose to provide on your resume, such as your education and employment experience.

Payment Information. If you make a payment to us, your payment-related information, such as credit card or other financial information, may be collected by our third-party payment processor on our behalf.

Personal Data We Collect When You Use Our Services

Location Information. We may collect and infer your general location information, including, for example, by collecting and using your internet protocol (IP) address.

Device Information. We may receive information about your device and software, including IP address, device type, device identifiers, web browser type and version, and operating system version.

Usage Information. We automatically receive data about your interactions with the Services, such as the dates and times of your use of the Services Information from Cookies and Similar Technologies. We and our third-party partners may collect information using cookies, beacons, invisible tags, and similar technologies (collectively “Cookies”) to provide functionality and to distinguish you from other users of the Services.

How We Use the Personal Data We Collect

We use the personal data we collect:

• To provide, maintain, improve, debug, administer, and enhance the Services;

• To understand your preferences and analyze how you use the Services and develop new products, services, and technology;

• To communicate with you, provide you with relevant updates and other information, provide information that you request, respond to comments and questions, and otherwise provide customer support;

• For marketing and advertising purposes, such as developing and providing promotional and advertising materials that may be relevant, valuable or otherwise of interest to you;

• To generate anonymized or aggregated data that we may use for lawful purposes;

• To facilitate transactions and payments;

• To find and prevent fraud and abuse, resolve disputes, or respond to trust and safety issues;

• For compliance purposes, including enforcing our contracts or other legal rights, or as may be required by applicable laws and regulations or requested by any judicial process or governmental agency; and

• For other purposes for which we provide notice at the time the information is collected.

We (1) will not train or fine tune any artificial intelligence or machine learning models on Input, and (2) will not disclose any Input to a third party other than our service providers.

How We Disclose the Personal Data We Collect

We do not “sell” personal data nor “share” personal data for cross-contextual behavioral advertising.

Affiliates. We may disclose personal data we receive to our subsidiaries and affiliates for the purposes described in this Privacy Policy.

Vendors and Service Providers. We may disclose personal data we receive to vendors and service providers that help us provide the Services.

Partners. We use analytics services such as Google Analytics to collect and process analytics data. These services may also collect information about your use of other websites, apps, and online resources. You can learn more about Google’s practices by visiting https://www.google.com/policies/privacy/partners/.

As Required By Law and Similar Disclosures. We may access, preserve, and disclose personal data if we believe doing so is required or appropriate to:

• Comply with law enforcement requests and legal process, such as a court order or subpoena;

• Respond to your requests;

• Protect your, our, or others’ rights, property, or safety;

• Protect against legal liability; or

• Investigate fraud or other unlawful activity.

For the avoidance of doubt, the disclosure of personal data may occur if you input any objectionable content on or through with the Services.

Merger, Sale, or Other Asset Transfers. We may transfer your personal data to service providers, advisors, potential transactional partners, or other third parties in connection with the consideration, negotiation, or completion of a corporate transaction in which we are acquired by or merged with another company or we sell, liquidate, or transfer all or a portion of our assets.

Consent. We may also disclose your personal data with your permission.

Your Choices

Marketing Communications. You can unsubscribe from our promotional emails via the link provided in the emails. Please note that if you opt out of receiving promotional messages from us, you will continue to receive administrative messages from us.

Do Not Track. There is no accepted standard on how to respond to “Do Not Track” signals, and we do not respond to such signals.

Third Parties

The Services may contain links to other websites, products, or services that we do not own or operate or permit you to integrate with third-party services. We are not responsible for the privacy practices of these third parties. Please be aware that this Privacy Policy does not apply to your activities on these third-party services or any data you disclose to these third parties. We encourage you to read their privacy policies before providing any data to them.

Retention

We retain personal data about you for as long as reasonably necessary to provide you with the Services, or otherwise in support of our business or commercial purposes. When you request that we do so, we take measures to delete your personal data or keep it in a form that does not permit identifying you when this personal data is no longer reasonably necessary for the purposes for which we process it, unless we are required by law to keep this data for a longer period.

Security

We make reasonable efforts to protect your data by using security measures designed to safeguard the data we maintain. However, because no electronic transmission or storage of data can be entirely secure, we can make no guarantees as to the security or privacy of your data.

Children’s Privacy

We do not knowingly collect, maintain, or use personal data from children under 18 years of age, and no part of the Services is directed to children. If you learn that a child has provided us with personal data in violation of this Privacy Policy, then you may alert us at privacy@typesafe.ai.

International Visitors

The Services are hosted in the United States (“U.S.”). If you choose to use the Services from the EEA, the UK or other regions of the world with laws governing data collection and use that may differ from U.S. law, then please note that you are transferring your personal data outside of those regions to the U.S. for storage and processing.

Changes to this Privacy Policy

We will post any adjustments to the Privacy Policy on this page, and the revised version will be effective when it is posted.

Contact Information

If you have any questions, comments, or concerns about our processing activities, please email us at privacy@typesafe.ai.

 
Download
 

TypeSafe AI, Inc.

Data processing addendum

Last updated

Apr 24, 2026

This Typesafe Data Processing Addendum (“DPA”) forms part of the Agreement by and between Customer and Typesafe. All capitalized terms not defined in this DPA will have the meanings set forth in the Agreement.

1. Scope

1.1. Roles of Parties. With respect to Customer Data that constitutes “personal data,” “personal information,” “personally identifiable information,” or any analogous term under applicable Data Protection Law (“Customer Personal Data”), (a) Customer is the “controller” and “business” (as such terms are defined under applicable Data Protection Law), and Typesafe is the “processor” and “service provider” (as such terms are defined under applicable Data Protection Law). Each Party will comply with its respective obligations under applicable privacy and data protection law (“Data Protection Law”) in connection with the Services and Customer Personal Data.

1.2. Scope of Processing. The subject matter, nature, and purpose of Typesafe’s Processing of Customer Personal Data, the types of Customer Personal Data Processed by Typesafe, and categories of applicable data subjects are set out in Schedule I.

1.3. Conflicts in Interpretation. If there is any inconsistency or conflict between terms of this DPA and the other terms of the Agreement, the terms of this DPA will control to the extent of such inconsistency or conflict.

2. Customer Personal Data

2.1. Customer Personal Data Processing. Typesafe will only Process Customer Personal Data to provide the Services and in accordance with Customer’s documented instructions, which are set forth in this DPA, the Agreement, or otherwise provided by Customer to Typesafe in writing (“Documented Instructions”). Unless prohibited by applicable law, Typesafe will inform Customer if Typesafe is subject to a legal obligation that requires Typesafe to Process Customer Personal Data in contravention of Customer’s Documented Instructions.

2.2. Typesafe Responsibilities: Typesafe will not (a) “sell” or “share” (as such terms are defined in the California Consumer Privacy Act (“CCPA”)) Customer Personal Data, (b) retain, use, or disclose Customer Personal Data for any purpose other than in accordance with the Documented Instructions, (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Typesafe, nor (d) except as otherwise permitted under applicable Data Protection Law, combine Customer Personal Data with personal data that Typesafe receives from or on behalf of any third party.

3. Subprocessors

3.1. Authorization. Customer provides general authorization for Typesafe to engage the following subprocessors as described in https://trust.typesafe.ai/subprocessors (“Subprocessors”). Typesafe will (a) enter into a contractual agreement with each Subprocessor that imposes data protection obligations that are substantially as protective as Typesafe’s obligations under this DPA to the extent applicable to the nature of the services provided by such Subprocessor and (b) remain responsible for the acts and omissions of the Subprocessors’ Processing of Customer Personal Data under this DPA, consistent with the limitation of liability provided in the Agreement.

3.2. Notice of New Subprocessors. Typesafe will provide Customer reasonable advance notice prior to appointing any new Subprocessor prior to giving the Subprocessor access to Customer Personal Data. Customer may object to the appointment of such new Subprocessor within 15 days of the date of such notice on reasonable privacy or security grounds by providing Typesafe written notice of its objection. In the event that Customer objects to Typesafe’s appointment of a new Subprocessor, Customer and Typesafe will work together in good faith to address any such objection.

4. Assistance

4.1. Data Subject Rights. Typesafe will (a) promptly forward to Customer any request it receives from “data subjects” or “consumers” (as such terms are defined under applicable Data Protection Law) to exercise their rights under applicable Data Protection Law relating to Customer Personal Data, (b) advise such data subjects and consumers to submit such requests directly to Customer, and (c) provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Laws to respond to such requests.

4.2. Cooperation. Taking into account the nature of the Processing, Typesafe will provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Laws, including to conduct data protection impact assessments and, where necessary, consultations with regulatory authorities with jurisdiction over such Processing, if such consultation is required by Data Protection Laws. Typesafe may charge Customer a reasonable fee for such assistance under this Section 4.2.

5. Security

5.1. Security Measures. Typesafe has implemented and will maintain reasonable and appropriate technical and organization security measures designed to protect the security of Customer Personal Data (“Security Measures”). The Parties acknowledge that the Security Measures provide an appropriate level of security for the risks of the Processing of Customer Personal Data under the Agreement. Typesafe may update or modify the Security Measures provided that such updates and modifications do not materially decrease the overall security of the Services.

5.2. Security Incident. Typesafe will notify Customer without undue delay and in any case within 72 hours after becoming aware of any accidental or unauthorized access to, or disclosure or use of, Customer Personal Data (“Security Incident”). Typesafe will assist Customer in complying with Customer’s obligations under applicable Data Protection Law by making reasonable efforts to provide Customer with information relating to the Security Incident. Typesafe will also use reasonable efforts to investigate the Security Incident and mitigate the effects and remediate the causes of the Security Incident.

5.3. Audits. Upon Customer’s written request, no more than once every 12 months, Typesafe will permit Customer to audit Typesafe’s controls applicable to its Processing of Customer Personal Data and compliance with this DPA (“Audit”), provided that such Audit is (a) conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate confidentiality agreement with Typesafe, (b) conducted at Customer’s sole cost, (c) during normal business hours, (d) in a manner that causes minimal disruption, and (e) in accordance with mutually agreed upon scope and terms, including the start date, scope and duration of, and security and confidentiality controls applicable to, such audit. Customer may use the results of an Audit only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA.

6. International Data Transfers

6.1. Data Transfers. Customer authorizes Typesafe to conduct transfers of Customer Personal Data to countries deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority on the basis of adequate safeguards in accordance with Data Protection Law or pursuant to (a) the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time (“EU SCCs”) or (b) the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time (“UK Addendum”).

6.2. EU Data Transfers. For transfers of Customer Personal Data from the European Union, Typesafe and Customer conclude Module 2 (controller-to-processor) of the EU SCCs and, if Customer is a processor on behalf of a third-party controller, Module 3 (Processor-to-Subprocessor) of the EU SCCs, which are incorporated herein and completed as follows: (a) the “data exporter” is Customer, (b) the “data importer” is Typesafe, (c) the optional docking clause in Clause 7 is implemented, (d) option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 3.2, (e) the optional redress clause in Clause 11(a) is struck, (f) option 1 in Clause 17 is implemented, (g) the governing law is the law of Ireland and the courts in Clause 18(b) are the Courts of Dublin, Ireland, and (h) Annex I and Annex II to Module 2 and 3 of the EU SCCs are Schedule I and the Security Measures respectively. For transfers of Customer Personal Data from Switzerland, any dispute arising from these EU SCCs relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland and data subjects who have their habitual residence in Switzerland may bring claims under the EU SCCs before the courts of Switzerland.

6.3. UK Data Transfers. For transfers of Customer Personal Data from the United Kingdom, Typesafe and Customer conclude the UK Addendum, which is incorporated herein and completed as follows: (a) in Table 1, the “Exporter” is Customer and the “Importer” is Typesafe, their details are set forth in this DPA and the Agreement, (b) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCCs referred to in Section 6.2, (c) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Schedule I and the Security Measures respectively; and (d) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.

Schedule I

Description of Processing

1. List of Parties
Data exporter:

Name: Customer.

Activities relevant to the data transferred under these Clauses: Customer receives the Services as described in the Agreement and Typesafe provides Customer Personal Data to Typesafe in that context.

Role (controller/processor): Controller.

Data importer:

Name: Typesafe.

Activities relevant to the data transferred under these Clauses: Typesafe provides the Services to Customer as described in the Agreement and Processes Customer Personal Data on behalf of Customer in that context.

Role (controller/processor): Processor on behalf of Customer.

2. Categories of Data Subjects

Customer and Customer’s users.

3. Categories of Personal Data Transferred

Customer Personal Data, the content of which is determined and controlled by Customer.

4. Sensitive Data Transferred (If Applicable)

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.

5. Frequency of the Transfer

The frequency of the International Data Transfer (e.g. whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.

6. Nature of the Processing

The Customer Personal Data will be processed and transferred as described in the Agreement and DPA.

7. Purpose(S) of the International Data Transfer and Further Processing

The Customer Personal Data will be transferred and further processed for the provision of the Services as described in the Agreement and DPA.

8. Duration of Processing

The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Customer Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.

9. Sub-Processor Transfers

For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the Processing: For the subject matter and nature of the Processing, reference is made to the Agreement and DPA. The Processing will take place for the duration of the Agreement.

10. Competent Supervisory Authority

The competent authority for the Processing of Customer Personal Data relating to data subjects located in the EEA is the Supervisory Authority of Ireland.

The competent authority for the Processing of Customer Personal Data relating to data subjects located in the UK is the UK Information Commissioner.

The competent authority for the Processing of Customer Personal Data relating to data subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.

11. Technical and Organizational Measures

Typesafe will implement security safeguards designed to protect the security, confidentiality and integrity of Personal Data as described on Typesafe’s Trust Center at https://trust.typesafe.ai/.

TypeSafe AI © 2026

X

hello@typesafe.ai

 

Last updated April 24, 2026

This Typesafe Data Processing Addendum (“DPA”) forms part of the Agreement by and between Customer and Typesafe. All capitalized terms not defined in this DPA will have the meanings set forth in the Agreement.

1. Scope

1.1. Roles of Parties. With respect to Customer Data that constitutes “personal data,” “personal information,” “personally identifiable information,” or any analogous term under applicable Data Protection Law (“Customer Personal Data”), (a) Customer is the “controller” and “business” (as such terms are defined under applicable Data Protection Law), and Typesafe is the “processor” and “service provider” (as such terms are defined under applicable Data Protection Law). Each Party will comply with its respective obligations under applicable privacy and data protection law (“Data Protection Law”) in connection with the Services and Customer Personal Data.

1.2. Scope of Processing. The subject matter, nature, and purpose of Typesafe’s Processing of Customer Personal Data, the types of Customer Personal Data Processed by Typesafe, and categories of applicable data subjects are set out in Schedule I.

1.3. Conflicts in Interpretation. If there is any inconsistency or conflict between terms of this DPA and the other terms of the Agreement, the terms of this DPA will control to the extent of such inconsistency or conflict.

2. Customer Personal Data

2.1. Customer Personal Data Processing. Typesafe will only Process Customer Personal Data to provide the Services and in accordance with Customer’s documented instructions, which are set forth in this DPA, the Agreement, or otherwise provided by Customer to Typesafe in writing (“Documented Instructions”). Unless prohibited by applicable law, Typesafe will inform Customer if Typesafe is subject to a legal obligation that requires Typesafe to Process Customer Personal Data in contravention of Customer’s Documented Instructions.

2.2. Typesafe Responsibilities: Typesafe will not (a) “sell” or “share” (as such terms are defined in the California Consumer Privacy Act (“CCPA”)) Customer Personal Data, (b) retain, use, or disclose Customer Personal Data for any purpose other than in accordance with the Documented Instructions, (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Typesafe, nor (d) except as otherwise permitted under applicable Data Protection Law, combine Customer Personal Data with personal data that Typesafe receives from or on behalf of any third party.

3. Subprocessors

3.1. Authorization. Customer provides general authorization for Typesafe to engage the following subprocessors as described in https://trust.typesafe.ai/subprocessors (“Subprocessors”). Typesafe will (a) enter into a contractual agreement with each Subprocessor that imposes data protection obligations that are substantially as protective as Typesafe’s obligations under this DPA to the extent applicable to the nature of the services provided by such Subprocessor and (b) remain responsible for the acts and omissions of the Subprocessors’ Processing of Customer Personal Data under this DPA, consistent with the limitation of liability provided in the Agreement.

3.2. Notice of New Subprocessors. Typesafe will provide Customer reasonable advance notice prior to appointing any new Subprocessor prior to giving the Subprocessor access to Customer Personal Data. Customer may object to the appointment of such new Subprocessor within 15 days of the date of such notice on reasonable privacy or security grounds by providing Typesafe written notice of its objection. In the event that Customer objects to Typesafe’s appointment of a new Subprocessor, Customer and Typesafe will work together in good faith to address any such objection.

4. Assistance

4.1. Data Subject Rights. Typesafe will (a) promptly forward to Customer any request it receives from “data subjects” or “consumers” (as such terms are defined under applicable Data Protection Law) to exercise their rights under applicable Data Protection Law relating to Customer Personal Data, (b) advise such data subjects and consumers to submit such requests directly to Customer, and (c) provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Laws to respond to such requests.

4.2. Cooperation. Taking into account the nature of the Processing, Typesafe will provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Laws, including to conduct data protection impact assessments and, where necessary, consultations with regulatory authorities with jurisdiction over such Processing, if such consultation is required by Data Protection Laws. Typesafe may charge Customer a reasonable fee for such assistance under this Section 4.2.

5. Security

5.1. Security Measures. Typesafe has implemented and will maintain reasonable and appropriate technical and organization security measures designed to protect the security of Customer Personal Data (“Security Measures”). The Parties acknowledge that the Security Measures provide an appropriate level of security for the risks of the Processing of Customer Personal Data under the Agreement. Typesafe may update or modify the Security Measures provided that such updates and modifications do not materially decrease the overall security of the Services.

5.2. Security Incident. Typesafe will notify Customer without undue delay and in any case within 72 hours after becoming aware of any accidental or unauthorized access to, or disclosure or use of, Customer Personal Data (“Security Incident”). Typesafe will assist Customer in complying with Customer’s obligations under applicable Data Protection Law by making reasonable efforts to provide Customer with information relating to the Security Incident. Typesafe will also use reasonable efforts to investigate the Security Incident and mitigate the effects and remediate the causes of the Security Incident.

5.3. Audits. Upon Customer’s written request, no more than once every 12 months, Typesafe will permit Customer to audit Typesafe’s controls applicable to its Processing of Customer Personal Data and compliance with this DPA (“Audit”), provided that such Audit is (a) conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate confidentiality agreement with Typesafe, (b) conducted at Customer’s sole cost, (c) during normal business hours, (d) in a manner that causes minimal disruption, and (e) in accordance with mutually agreed upon scope and terms, including the start date, scope and duration of, and security and confidentiality controls applicable to, such audit. Customer may use the results of an Audit only for the purposes of meeting Customer’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA.

6. International Data Transfers

6.1. Data Transfers. Customer authorizes Typesafe to conduct transfers of Customer Personal Data to countries deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority on the basis of adequate safeguards in accordance with Data Protection Law or pursuant to (a) the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time (“EU SCCs”) or (b) the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time (“UK Addendum”).

6.2. EU Data Transfers. For transfers of Customer Personal Data from the European Union, Typesafe and Customer conclude Module 2 (controller-to-processor) of the EU SCCs and, if Customer is a processor on behalf of a third-party controller, Module 3 (Processor-to-Subprocessor) of the EU SCCs, which are incorporated herein and completed as follows: (a) the “data exporter” is Customer, (b) the “data importer” is Typesafe, (c) the optional docking clause in Clause 7 is implemented, (d) option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 3.2, (e) the optional redress clause in Clause 11(a) is struck, (f) option 1 in Clause 17 is implemented, (g) the governing law is the law of Ireland and the courts in Clause 18(b) are the Courts of Dublin, Ireland, and (h) Annex I and Annex II to Module 2 and 3 of the EU SCCs are Schedule I and the Security Measures respectively. For transfers of Customer Personal Data from Switzerland, any dispute arising from these EU SCCs relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland and data subjects who have their habitual residence in Switzerland may bring claims under the EU SCCs before the courts of Switzerland.

6.3. UK Data Transfers. For transfers of Customer Personal Data from the United Kingdom, Typesafe and Customer conclude the UK Addendum, which is incorporated herein and completed as follows: (a) in Table 1, the “Exporter” is Customer and the “Importer” is Typesafe, their details are set forth in this DPA and the Agreement, (b) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCCs referred to in Section 6.2, (c) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Schedule I and the Security Measures respectively; and (d) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.

Schedule I

Description of Processing

1. List of Parties

Data exporter:

Name: Customer.

Activities relevant to the data transferred under these Clauses: Customer receives the Services as described in the Agreement and Typesafe provides Customer Personal Data to Typesafe in that context.

Role (controller/processor): Controller.

Data importer:

Name: Typesafe.

Activities relevant to the data transferred under these Clauses: Typesafe provides the Services to Customer as described in the Agreement and Processes Customer Personal Data on behalf of Customer in that context.

Role (controller/processor): Processor on behalf of Customer.

2. Categories of Data Subjects

Customer and Customer’s users.

3. Categories of Personal Data Transferred

Customer Personal Data, the content of which is determined and controlled by Customer.

4. Sensitive Data Transferred (If Applicable)

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.

5. Frequency of the Transfer

The frequency of the International Data Transfer (e.g. whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.

6. Nature of the Processing

The Customer Personal Data will be processed and transferred as described in the Agreement and DPA.

7. Purpose(S) of the International Data Transfer and Further Processing

The Customer Personal Data will be transferred and further processed for the provision of the Services as described in the Agreement and DPA.

8. Duration of Processing

The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Customer Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.

9. Sub-Processor Transfers

For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the Processing: For the subject matter and nature of the Processing, reference is made to the Agreement and DPA. The Processing will take place for the duration of the Agreement.

10. Competent Supervisory Authority

The competent authority for the Processing of Customer Personal Data relating to data subjects located in the EEA is the Supervisory Authority of Ireland.

The competent authority for the Processing of Customer Personal Data relating to data subjects located in the UK is the UK Information Commissioner.

The competent authority for the Processing of Customer Personal Data relating to data subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.

11. Technical and Organizational Measures

Typesafe will implement security safeguards designed to protect the security, confidentiality and integrity of Personal Data as described on Typesafe’s Trust Center at https://trust.typesafe.ai/.

 
 
 

image

 

   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
   
posted @ 2026-09-21 15:59  aiplus  阅读(19)  评论(0)    收藏  举报
悬浮按钮示例