hyperlakeDiscuss a deployment ↗
Legal

Terms of Service and End User Licence Agreement

This page updated

Last updated: October 7, 2026

1. Agreement and Definitions

1.1 Parties. These Terms of Service and End User Licence Agreement (the "Terms") are a binding agreement between Ockham Labs Inc., a corporation incorporated under the laws of Canada ("Ockham", "we", "us"), and the person or entity that accepts them ("Customer", "you"). Ockham Labs Inc.'s registered address is 4222 Dixie Rd, Unit #145, Mississauga, Ontario L4W 1M6, Canada, and its legal notices email is hello@ockhamlabs.ai.

1.2 What the Terms cover. The Terms apply to Hyperlake, available at hyperlake.cloud, and to every related service, website, API, command-line tool, agent, connector, template, software and document that we make available under the Hyperlake, TerraLake, SaaS Lake or Kory names (together, the "Services"). Section 4 describes them. Other Ockham products have their own terms. The Services run on a common Ockham platform that is shared with other Ockham products. Your sign-in, workspace, team, billing, credits, support and the underlying systems may be shared across them, and features of another product may appear in your Account. If you use another Ockham product, its terms govern that use.

1.3 Acceptance. You accept the Terms by (a) ticking the box or clicking the button that says you agree, (b) signing an Order Form that refers to them, (c) installing or using any Hyperlake software, or (d) accessing or using the Services, whichever happens first. We keep a record of the version you accepted and when. If you accept for an organization, you confirm that you have authority to bind it, and "Customer" means that organization.

1.4 Business use only. The Services are for businesses and professionals. You confirm that you will use them only for business, commercial or professional purposes, and that you are not a consumer under any consumer protection Law. If you cannot confirm that, do not use the Services.

1.5 Order of precedence. If documents conflict, this order applies: (a) a written agreement signed by Ockham that expressly replaces these Terms; (b) an Order Form; (c) these Terms; (d) the Documentation and policies.

1.6 Changes to the Terms. We may update the Terms at any time by posting the new version or notifying you. A change takes effect on the date stated. For a change that materially reduces your rights, that date will be at least 14 days after posting, unless the change is required by Law or addresses a security or legal risk. If you do not agree, your only remedy is to stop using the Services and cancel under section 9. Using the Services after the effective date means you accept the update.

1.7 Definitions. In these Terms:

  • "AI Feature" means any feature that uses a machine-learning or generative model, including copilots, assistants, agents, goal planners, semantic model generation, AI-assisted SQL, code and policy generation, embeddings, fine-tuning and diagnostics.
  • "AI Output" means anything an AI Feature produces.
  • "Authorized User" means an individual or automated account that uses the Services through your Account, including employees, contractors, team members, collaborators, service accounts and AI agent accounts.
  • "Beta Feature" means any feature we label beta, preview, experimental, early access or similar, or make available for evaluation.
  • "Cloud Account" means an account you hold with a third-party cloud, infrastructure or software provider, such as AWS, Google Cloud, OVH, Cloudflare, GitHub, a container registry, a Kubernetes cluster or a data source.
  • "Customer Content" means all data, files, queries, code, container images, charts, manifests, configurations, policies, prompts, models and other content that you or your Authorized Users submit to, connect to, or create through the Services, excluding Usage Data.
  • "Customer Credentials" means any password, key, token, role, certificate, secret or other access credential that you give to or store in the Services.
  • "Customer Environment" means any cluster, namespace, catalog, database, network, application, job or other resource that the Services create, connect to or manage for you, in your Cloud Accounts or ours.
  • "Documentation" means the guides and specifications we publish for the Services.
  • "Law" means any statute, regulation, rule, order or other binding requirement of a governmental authority.
  • "Order Form" means an order, quote, online checkout or plan selection that identifies the Services, fees and term.
  • "Personal Information" means information about an identifiable individual.
  • "Software" means any command-line tool, agent, connector, script, chart, template or other code that we provide for download or for installation in a Customer Environment.
  • "Third-Party Service" means any product, service, model, platform, connector, tool or content that Ockham does not own and operate, including those in Schedule 2 and those you choose to connect.
  • "Usage Data" means technical and operational data about use and performance of the Services, such as logs, traces, device details, IP addresses, approximate location, resource metrics and billing events.

1.8 Interpretation and language. "Including" means "including without limitation". The Terms will not be read against us because we drafted them. The parties have expressly required that these Terms be drawn up in English. Les parties ont expressément exigé que les présentes conditions soient rédigées en anglais.

2. Accounts

2.1 Eligibility. You must be at least 18 years old and able to form a binding contract. You may not use the Services if any Law, including sanctions and export control Law, bars you from doing so.

2.2 Registration. You must give accurate registration details and keep them current. You may not create accounts by automated means.

2.3 Authorized Users. You may let Authorized Users use the Services within the limits of your plan or Order Form. You are responsible for every Authorized User and for everything done through your Account, whether or not you authorized it.

2.4 Access credentials. You are solely responsible for protecting passwords, API keys, personal access tokens, OAuth clients and secrets, SSO configuration, CLI sessions and any other means of accessing your Account. You must use multi-factor authentication where we offer it, grant only the access that is needed, and remove access promptly when it is no longer needed. Tell us as soon as you suspect unauthorized access.

2.5 Service accounts and agents. A service account, API client, OAuth application, AI agent account or automation that you create is part of your Account. You are responsible for its actions and for the permissions you grant it.

2.6 Your administrators. Your administrators may view, manage, act as, suspend or remove Authorized Users in your Account and their content. You are responsible for your internal rules on that access and for telling Authorized Users about it.

3. Licence and Restrictions

3.1 Licence to the Services. Subject to these Terms and payment of applicable fees, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence during the term to access and use the Services for your internal business purposes and, where section 4.15 applies, to deliver your own products to your End Customers.

3.2 Licence to Software. Subject to the same conditions, we grant you a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence during the term to install and run the Software, in object or script form, only to use the Services and only on systems and in Customer Environments that you control. The Software is licensed, not sold. You may make copies only as needed for that use and for backup. The licence ends when these Terms end, and you must then uninstall and delete the Software.

3.3 Restrictions. You will not, and will not allow anyone else to:

  • copy, modify, translate or create derivative works of the Services or Software, except as section 3.2 allows;
  • rent, lease, lend, sell, sublicense, white-label, resell, or offer the Services or Software to third parties as a managed or hosted service, unless section 4.15 or an Order Form expressly permits it;
  • reverse engineer, decompile, disassemble or try to obtain the source code, model weights, prompts or underlying configuration of the Services or Software, except to the extent Law does not allow this restriction;
  • use the Services, Software or AI Outputs to build, train or improve a competing product or model;
  • access the Services by automated means other than the APIs, CLI and tools we provide for that purpose;
  • bypass, probe or test the security, quotas, rate limits, isolation, access controls or billing of the Services, or run load, penetration or vulnerability tests against them, without our prior written consent;
  • publish benchmark or performance results of the Services without our prior written consent;
  • remove or alter any proprietary notice; or
  • use the Services or Software in breach of Schedule 1 or any Law.

3.4 High-risk uses. The Services are not designed for uses where failure could lead to death, personal injury, or serious property or environmental damage, such as medical care, emergency response, aviation, or the control of critical infrastructure. You will not use them for those purposes.

3.5 Beta Features. Beta Features are provided for evaluation. They may contain errors, may change or disappear at any time, and are provided "as is" with no warranty, service commitment or support. Do not rely on them in production or for important data.

3.6 Open-source and third-party components. The Services and Software include and deploy open-source and third-party components, such as query engines, table formats, orchestration, networking, observability and security tools. Each is licensed to you under its own licence, not these Terms, and we give no warranty for it. Where an open-source licence gives you rights that these Terms restrict, the open-source licence governs that component.

3.7 Updates. We may update, replace or remove the Services and Software at any time, and may require you to use the current version. Updates may be applied automatically, including to Customer Environments.

3.8 Reservation of rights. We and our licensors keep all rights not expressly granted in these Terms.

4. The Hyperlake Services

4.1 What Hyperlake does. Hyperlake lets you provision and operate data and AI infrastructure and work with the data in it. Depending on your plan, this includes: managed query engines and lakehouse clusters; Kubernetes clusters and node pools; catalogs and connectors to databases, object storage, vector databases, logs and software services; SQL and Python workbenches; semantic models; dashboards, checks and data assets; applications, charts, templates and custom jobs; private networking, access rules and identity for deployed applications; security and diagnostic scans; model operations; goals, agents, tools, workflows, APIs and a command-line tool that automate these; and tools for packaging and delivering software and services into environments that you or your customers control.

4.2 Deployment models. Hyperlake runs in one of these ways, as your setup or Order Form shows:

  • Customer-Cloud. We provision and manage resources in your Cloud Accounts with your Customer Credentials. You pay the cloud provider directly.
  • Ockham-Managed. We run resources in cloud accounts that we hold, and charge you under your plan or Order Form.
  • Shared (SaaS Lake). You use a namespace and connectors on infrastructure shared with other customers. Separation is logical, not physical, and performance is not guaranteed.
  • Connected. You connect a cluster or engine that you already run, and we act on it with the credentials you give.

4.3 Permission to act in your accounts. In Customer-Cloud and Connected modes you authorize us, and the automations you configure, to create, change, scale, connect to and destroy resources in your Cloud Accounts. These include clusters, networks, node pools, storage, identities and roles, secrets, DNS records, peering connections, registries, jobs and applications. Use credentials with the least access that works. Everything deployed there is yours. You are responsible for its cost, security, patching, network exposure, backups and legal compliance.

4.4 Defaults are not recommendations. Default settings are for convenience. Some defaults allow access from any IP address until you set restrictions. You are responsible for reviewing and setting network, admin, ingress, role and policy settings before you put data in an environment.

4.5 Archive, delete and destroy. Actions named archive, delete, remove, uninstall or destroy on a project, cluster, catalog, application or environment may permanently destroy infrastructure and data, immediately and without a further prompt. Take your own backups first. We cannot recover what has been destroyed.

4.6 Code and workloads you run. The Services let you run SQL, Python, container images, Helm charts, Kubernetes manifests, scripts, functions and scheduled jobs, including images and charts from registries and catalogs we do not control. You are solely responsible for them, for their licences, and for what they do. Some run on infrastructure we operate, with time, size and row limits that we set and may change, and we may stop any workload at any time. You will not use any of them to attack, scan, overload or gain access to any system, including ours, other customers' environments, or internal network addresses.

4.7 Query and access controls are aids. Read-only checks, catalog and row-level policies, policy rules, IP allowlists, isolation between tenants and similar controls are tools for you to configure and test. They are not a guarantee against writes, data leaving your environment, or unauthorized access. Give database and catalog credentials the least privilege that works. Scheduled maintenance, materialized views and similar jobs that you set up will change data without a further prompt.

4.8 Connectors and data sources. You are responsible for your right to connect each source, and to extract, store and analyze its data, including the source's terms of use, API terms and rate limits. For connectors to security, identity, vulnerability, breach or threat-intelligence sources, you must be authorized to query every system and to hold the data returned. Credentials you put in a catalog may be passed to and stored in the engine that serves it.

4.9 Applications, charts, templates and marketplace items. Items published by other users or third parties are not reviewed, tested or endorsed by us, even where we approve their listing. You use them at your own risk. A template may be deployed with credentials that its publisher holds. You will not deploy with credentials that you are not authorized to use, and publishers are responsible for what their credentials are used for.

4.10 Networking, domains and identity. Private networking, peering, DNS, custom domains, single sign-on and OAuth or OpenID Connect sign-in for deployed applications depend on your configuration and on Third-Party Services. You must control any domain you connect. You are responsible for who can sign in to applications you deploy and for the access tokens and clients you issue.

4.11 Scans, diagnostics and estimates. Security scans, cluster diagnostics, health checks, recommendations, sizing and cost estimates are indicative only. They may miss issues, report issues that do not exist, or be out of date. They are not an audit, a certification or advice. A health check may mark an environment as failed or archived.

4.12 Model operations. If you fine-tune, benchmark, host or call models through the Services, you are responsible for your rights in the training and evaluation data, for the licence of each model, and for the outputs. We do not promise that a model or its weights will be kept or can be exported.

4.13 Supported environments. Cloud providers, regions, versions and components are supported only where the Documentation says they are available. An option shown in a menu or API is not a promise of support. We may add or withdraw support at any time.

4.14 Backups and availability. Backup, snapshot and restore features are optional tools that you must configure, pay for and test. We do not back up Customer Environments for you, and we make no promise about availability, recovery time or recovery point.

4.15 Delivering your own software to others. Where your plan allows, you may use the Services to package, deploy, operate and update your own software, data products or services in environments held by your own customers ("End Customers"), or to give End Customers access to environments you run. If you do:

  • you are the provider to your End Customers, and we are not. We have no contract with them and owe them no duty, support or warranty;
  • you must have each End Customer's written authorization for everything you and the Services do in its accounts, and must use only credentials it has properly given you;
  • you must bind each End Customer to terms that protect Ockham at least as much as sections 3, 5, 9 and 10 and Schedule 1 do, and that make no promise on our behalf;
  • you are responsible for your software, its licences, its security and its updates, for support, and for any personal or regulated data it handles; and
  • you are responsible for your End Customers' acts as if they were your own.

You may not offer the Services themselves as a standalone product.

4.16 Installing a publisher's software. If you install software or a template from another user or vendor (a "Publisher") through the Services, your contract for it is with the Publisher. The Publisher, not Ockham, is responsible for it. Installing it may give the Publisher, and the automations it defines, access to resources in your Customer Environment and Cloud Accounts. Review the access you grant before you approve it, and remove it when it is no longer needed.

4.17 Versions, upgrades and end of life. We may make new versions of engines, Kubernetes, components and Software available, and may stop supporting old ones. Unless an Order Form says we do it for you, you are responsible for applying upgrades and patches to Customer Environments and for testing compatibility with your workloads. Upgrades can cause downtime or data loss. We have no obligation to support, secure or fix a version that is out of date or that its maintainer no longer supports.

4.18 Shared responsibility. In short: we are responsible for operating the Hyperlake control plane with the care section 5.6 describes. You are responsible for everything you put in, connect to or run on the Services, and for how it is configured. That includes Cloud Accounts, credentials, network exposure, access rights, data, workloads, applications, backups, upgrades, costs and legal compliance, in every deployment model.

4.19 Governance and compliance tools. Catalog, lineage, policy, audit-log, access-review and similar governance features help you manage your data. They do not make you compliant with any Law, standard or contract, and their records may be incomplete.

5. Customer Content, Privacy and Security

5.1 Ownership and licence. As between you and Ockham, you own Customer Content. You grant Ockham and its service providers a non-exclusive, worldwide, royalty-free licence, during the term and for the periods in section 5.10, to host, store, copy, transmit, display and process Customer Content as needed to provide, secure, support and bill for the Services, to enforce these Terms, and to comply with Law.

5.2 You are responsible for Customer Content. You are solely responsible for Customer Content and for all results, conclusions, decisions and actions based on the Services. You confirm that you have all rights, notices and consents needed to connect, collect and process Customer Content through the Services, and that doing so does not violate any Law or third-party right.

5.3 Privacy roles. As between you and Ockham, you are the organization that is accountable for, and in control of, any Personal Information in Customer Content. Ockham processes it as your service provider, on your instructions, which are these Terms, your configuration of the Services, and your use of them. In Customer-Cloud and Connected modes, data in your Cloud Accounts stays in your custody, and we access it only as the Services need.

5.4 Content you must not submit. Unless an Order Form signed by us says otherwise, you will not use the Services to store or process: protected health information; payment card data; government-issued identification numbers; biometric identifiers; Personal Information of children; or any data that Law requires be held to a security, residency or certification standard that we have not agreed to in writing.

5.5 Privacy Policy. Our Privacy Policy at https://hyperlake.cloud/privacy describes how we handle Personal Information that we collect for ourselves, such as account, billing, login and Usage Data. Personal Information in Customer Content is handled under this section 5.

5.6 Security efforts. We will use commercially reasonable administrative, technical and physical safeguards that we consider appropriate for the Customer Content we hold. We do not promise that any safeguard will be effective, that the Services are secure, or that Customer Content or Customer Credentials will not be accessed, lost, altered or disclosed without authorization. We make no statement about any certification, audit, encryption standard or isolation guarantee unless it is in an Order Form signed by us.

5.7 Your security responsibilities. You are responsible for the security of your Account, Customer Credentials, Cloud Accounts, Customer Environments, data sources, networks and devices, and for the configuration choices in section 4. You must rotate any credential you believe is exposed.

5.8 Data location and transfers. The Services use cloud and Third-Party Services that may store or process data in Canada, the United States and other countries. Control-plane data, such as Account details, configurations, metadata, query text, logs and stored Customer Credentials, may be held in a different place from the region you choose for a Customer Environment. You agree to those locations and transfers, and you are responsible for any notice or consent that Law requires. We will keep data in a specific country only if an Order Form signed by us says so.

5.9 Security incidents. If we confirm that Customer Content or Customer Credentials in our control have been accessed or disclosed without authorization, and Law requires us to notify you, we will do so without undue delay by email to your Account or notice contact, with the information we then have. Our notice or help is not an admission of fault or liability. You are responsible for deciding whether to notify regulators, individuals and others, for the cost of doing so, and for your own incident records.

5.10 Retention, export and deletion.

  • During the term, we keep Customer Content as the Services are configured to keep it.
  • After your Account ends, you may export Customer Content for 30 days, unless the Account was suspended for breach, non-payment, or a security or legal risk.
  • After those 30 days we may delete Customer Content and destroy any Customer Environment that we operate. We have no obligation to keep or return either.
  • Copies in backups, logs, archives and Third-Party Services may remain for up to 90 days after deletion from active systems, or longer where Law requires.
  • Resources in your own Cloud Accounts are not deleted by us unless you instruct it. You are responsible for removing them.

5.11 Disclosure required by Law. We may disclose Customer Content where we believe in good faith that Law, a court order, a warrant or a regulator requires it. Where permitted, we will tell you.

5.12 Usage Data. We collect and use Usage Data, including login records, IP addresses and approximate location, to operate, secure, support, bill for, analyze and improve the Services and to detect abuse. Usage Data is ours, subject to our Privacy Policy.

5.13 Support and operational access. You consent to our personnel accessing your Account, Customer Environments and Customer Content (a) when your administrator or user approves a support access request, for the window approved, and (b) as needed to operate, secure and fix the Services, prevent abuse and comply with Law.

5.14 Data processing terms. If Law requires a data processing agreement between us, we will enter into our standard one on request. It forms part of these Terms, and its liability terms are subject to section 10.

6. AI Features, Agents and Automation

6.1 How AI Features work. AI Features use models run by us or by Third-Party Services. When you use one, the prompts, files, query text, schema and catalog metadata, retrieved data and other Customer Content it needs are sent to the model provider that runs it. Schedule 2 lists the providers we use now. Where you supply your own model key or choose a provider, that provider's terms and charges apply to you directly.

6.2 Outputs may be wrong. AI Outputs are generated automatically. They may be inaccurate, incomplete, insecure, inefficient, infringing, or the same as outputs given to others. They are not professional, security, engineering or legal advice. You must review all AI Outputs before you rely on them or run them, including generated SQL, code, manifests, policies, semantic models, plans, diagnoses and recommendations.

6.3 Agents, goals, tools and workflows act for you. The Services let you set up copilots, agents, goals, tools, workflows, triggers, MCP and API connections, CLI commands and scheduled jobs. These can read, create, change, send and delete data and resources in the Services, in Customer Environments, in your Cloud Accounts and in Third-Party Services. A goal or agent may keep working over many steps until it finishes or exhausts its budget. Everything an agent or automation does under your configuration is your act. You are solely responsible for the permissions, scopes and budgets you grant, and for every consequence, including data loss, exposure, outages and charges.

6.4 Approvals. Some features offer a confirmation or human-approval step, and many actions run without one. You are responsible for deciding where approval is needed and for turning it on. You must require approval for any destructive, irreversible, access-changing or high-cost action. AI-generated or AI-edited access policies must be reviewed and approved by you before they are activated.

6.5 Tools and servers you connect. If you connect a tool, MCP server, webhook or external agent, your data and credentials may be sent to it and to the model provider that calls it. We do not review or control those tools. Paid tools published by others may charge your credits and may run under the publisher's own credentials.

6.6 Model providers. We do not control how Third-Party Services retain, use or train on the data they receive. Their terms govern. We may change, replace or remove models and providers at any time.

6.7 Decisions about people. You will not use AI Outputs as the sole basis for a decision that has a legal or similarly significant effect on an individual. Any such decision needs meaningful human review by you.

7. Third-Party Services and Customer Credentials

7.1 Third-Party Services. The Services depend on and connect to Third-Party Services, including cloud infrastructure, model, payment, email, DNS, monitoring and data-source providers, and anything you choose to connect. Their own terms govern them, and you must follow those terms. We do not control them, are not responsible for them, and make no promise about their availability, security, accuracy, pricing or continued support.

7.2 Subprocessors. You authorize us to use the service providers in Schedule 2 and to add or replace service providers at any time. We will update Schedule 2 from time to time. Our responsibility for them is limited as section 10 says.

7.3 Customer Credentials. When you give us Customer Credentials, you authorize us, and the agents and automations you configure, to use them to do what you or they request. That includes creating, changing, connecting to, scaling and deleting resources in your Cloud Accounts, and reading from and writing to your data sources. You confirm that you are entitled to share each credential, and that doing so breaches no agreement or Law. You are responsible for granting only the access you intend, for rotating and revoking credentials, and for every action taken with them. We may send you a notice when your credentials are used, but are not obliged to.

7.4 Your Cloud Accounts and costs. Resources in your Cloud Accounts are billed to you by the provider. We are not responsible for any charge, overage, quota, tax, penalty or suspension imposed by a provider. That includes charges caused by misconfiguration, autoscaling, automation, agents, code you run, unauthorized use of your credentials, or resources left running after the Services end.

7.5 Provider actions. If a cloud or other provider suspends, limits or closes your account or ours, or changes or withdraws a service, the Services may stop working. We are not liable for that.

8. Fees, Credits and Payment

8.1 Fees. You will pay the fees in your Order Form, plan or pricing page, in the currency shown there. Fees are non-refundable unless these Terms expressly say otherwise. Usage-based fees, overages and add-ons are charged as incurred.

8.2 Subscriptions and renewal. Subscriptions renew automatically for successive terms of the same length, at the then-current price, unless you cancel before the renewal date in the Account settings or by written notice. Cancellation takes effect at the end of the current term.

8.3 Credits. Some Services, including AI Features, agents, paid tools and managed environments, are charged in credits. Free credits have no cash value and expire on the date shown, which is 30 days after issue unless we say otherwise. Paid credits are non-refundable, non-transferable, and expire 12 months after purchase. Credits are used when a task starts and are not returned if it fails or is cancelled, unless we choose to return them. We may change credit prices and the credits a feature uses, for future use, at any time.

8.4 Managed infrastructure. In Ockham-Managed and Shared modes, you pay for the infrastructure and usage as your plan or Order Form sets out, including for resources left running. We may set and change limits on size, nodes, storage, compute and egress, and may charge for use above them.

8.5 Your own cloud costs. In Customer-Cloud and Connected modes, you pay your providers directly and section 7.4 applies. Cost estimates in the Services are indicative only.

8.6 Price changes. We may change prices on 30 days' notice. A change applies from your next renewal or billing period. If you do not accept it, you may cancel before it takes effect.

8.7 Payment and taxes. Payment is by the methods we offer, processed by third-party payment providers. You authorize us and them to charge your payment method for all fees when due and to retry failed payments. Fees do not include taxes. You will pay all sales, use, value-added, goods and services, harmonized sales and similar taxes, other than taxes on our income.

8.8 Late payment. Overdue amounts bear interest at 1% per month (12% per year), from the due date until paid, and you will pay our reasonable costs of collection, including legal fees. We may suspend the Services under section 9 if any amount is overdue.

9. Suspension, Changes and Termination

9.1 Our right to suspend. We may suspend, limit or disable all or part of the Services, or any Account, Authorized User, Customer Environment, workload, agent, workflow, integration, token or credential, at any time, immediately, and with or without notice, if we decide in our discretion that it is appropriate. Reasons include: a suspected breach of these Terms or Schedule 1; non-payment; a security, fraud or abuse risk; a request or order from a court, regulator or law enforcement; an action by a cloud or other provider; risk to the Services, other customers or third parties; unusual cost or load; or operational or legal reasons. We will try to give notice where practicable, but need not. Suspension may stop running clusters, queries, jobs, agents and applications, and may make Customer Content unreachable.

9.2 Our right to change and discontinue. We may change, replace, limit or stop any Service, feature, deployment model, cloud or region, connector, model, plan, quota or Beta Feature at any time. If we discontinue a paid Service entirely, we will give at least 30 days' notice, unless a shorter period is needed for legal, security or third-party reasons, and we will refund prepaid fees for the period after discontinuation. That refund is your only remedy.

9.3 Term. These Terms start when you accept them and continue until your last Account or Order Form ends.

9.4 Termination by you. You may stop using the Services and cancel your Account at any time in the Account settings or by notice to us. You remain liable for fees through the end of the current term, and fees paid are not refunded.

9.5 Termination by us. We may terminate these Terms, an Order Form, or your access to any Service (a) for any reason or no reason on 30 days' notice, with a refund of prepaid fees for the period after termination, or (b) immediately on notice if you breach these Terms or Schedule 1, fail to pay when due, become insolvent, or if we believe continuing creates a legal, security or reputational risk.

9.6 Effect of termination. On termination, your licences end, and you must stop using the Services and uninstall the Software. We may stop and destroy Customer Environments that we operate, and delete Customer Content under section 5.10. Resources in your own Cloud Accounts are not removed by us and may keep running and incurring charges. Removing them, and removing Software and components installed in them, is your responsibility. Sections 5.10, 7.4, 9.6, 9.7 and 10 to 12, and any other terms that by their nature continue, survive.

9.7 No liability. We are not liable to you or anyone else for any suspension, change, discontinuation or termination made in line with these Terms, or for any resulting loss of data, access, revenue or business.

10. Disclaimers and Limitation of Liability

10.1 "As is". TO THE FULLEST EXTENT PERMITTED BY LAW, THE SERVICES, SOFTWARE, AI OUTPUTS, DOCUMENTATION, BETA FEATURES AND ALL OTHER MATERIALS WE PROVIDE ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITH ALL FAULTS. WE AND OUR LICENSORS AND SERVICE PROVIDERS DISCLAIM ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING ANY OF MERCHANTABILITY, MERCHANTABLE QUALITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT AND ACCURACY, AND ANY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

10.2 No promise of results, security or availability. WITHOUT LIMITING 10.1, WE DO NOT WARRANT THAT THE SERVICES, SOFTWARE OR AI OUTPUTS WILL MEET YOUR REQUIREMENTS, BE AVAILABLE AT ANY TIME OR WITHOUT INTERRUPTION, BE SECURE, ACCURATE, COMPLETE OR ERROR-FREE, BE FREE OF HARMFUL CODE, OR WORK WITH ANY SYSTEM. WE DO NOT WARRANT THAT ANY CUSTOMER ENVIRONMENT WILL BE PROVISIONED, PERFORM, SCALE, STAY RUNNING OR BE RECOVERABLE; THAT ANY CUSTOMER CONTENT OR CUSTOMER CREDENTIAL WILL BE PRESERVED OR KEPT FROM LOSS, CORRUPTION, ACCESS OR DISCLOSURE; OR THAT ANY ISOLATION, ACCESS CONTROL, POLICY, ENCRYPTION OR READ-ONLY RESTRICTION WILL PREVENT ANY ACCESS OR ACTION. NO SERVICE LEVEL, UPTIME COMMITMENT, SUPPORT OR RESPONSE TIME APPLIES UNLESS AN ORDER FORM SIGNED BY US SAYS SO.

10.3 Third parties. WE MAKE NO WARRANTY ABOUT THIRD-PARTY SERVICES, CLOUD PROVIDERS, MODELS, CONNECTORS, OPEN-SOURCE COMPONENTS, MARKETPLACE ITEMS OR TELECOMMUNICATIONS, OR ABOUT THE ACTS OF OTHER USERS.

10.4 Excluded losses. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER OCKHAM NOR ANY OF ITS AFFILIATES, LICENSORS, SERVICE PROVIDERS OR SUBCONTRACTORS, NOR ANY OF THEIR DIRECTORS, OFFICERS, EMPLOYEES OR AGENTS (TOGETHER, THE "OCKHAM PARTIES") WILL BE LIABLE FOR ANY OF THE FOLLOWING, EVEN IF ADVISED OF THE POSSIBILITY OR IF IT WAS FORESEEABLE, AND WHETHER THE CLAIM IS IN CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, STATUTE OR OTHERWISE:

  • (a) LOSS OF REVENUE, PROFIT, BUSINESS, CONTRACTS, GOODWILL, REPUTATION OR ANTICIPATED SAVINGS;
  • (b) LOSS, CORRUPTION, DESTRUCTION OR UNAVAILABILITY OF, OR UNAUTHORIZED ACCESS TO OR DISCLOSURE OF, DATA, CUSTOMER CONTENT, CUSTOMER CREDENTIALS OR CUSTOMER ENVIRONMENTS;
  • (c) COSTS OF NOTIFYING INDIVIDUALS OR REGULATORS, CREDIT MONITORING, FORENSIC OR LEGAL SERVICES, AND ANY FINE, PENALTY OR REGULATORY ORDER;
  • (d) CHARGES, OVERAGES OR LOSSES IN YOUR CLOUD ACCOUNTS OR AT THIRD-PARTY SERVICES, AND COSTS OF REPLACEMENT SERVICES;
  • (e) DOWNTIME, INTERRUPTION, DELAY, OR ANY SUSPENSION, CHANGE, DISCONTINUATION OR TERMINATION UNDER THESE TERMS;
  • (f) ANY RESULT OF AI OUTPUTS, AGENTS, GOALS, AUTOMATIONS, WORKFLOWS, QUERIES, CODE, WORKLOADS, TEMPLATES OR TOOLS;
  • (g) CLAIMS BY YOUR CUSTOMERS, AUTHORIZED USERS, DATA SUBJECTS OR OTHER THIRD PARTIES; OR
  • (h) ANY INDIRECT, CONSEQUENTIAL, INCIDENTAL, SPECIAL, AGGRAVATED, PUNITIVE OR EXEMPLARY DAMAGES.

10.5 Cap. TO THE FULLEST EXTENT PERMITTED BY LAW, THE TOTAL AGGREGATE LIABILITY OF THE OCKHAM PARTIES FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS, THE SERVICES AND THE SOFTWARE, UNDER ANY LEGAL THEORY, WILL NOT EXCEED THE AMOUNT YOU ACTUALLY PAID TO US FOR THE SERVICES IN THE THREE (3) MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY, OR CAD $100 IF YOU PAID NOTHING OR LESS THAN THAT AMOUNT. AMOUNTS YOU PAID TO CLOUD PROVIDERS OR OTHER THIRD PARTIES DO NOT COUNT. THE CAP IS ONE CUMULATIVE LIMIT FOR ALL CLAIMS TOGETHER, NOT A LIMIT PER CLAIM OR PER EVENT.

10.6 What the limits do not cover. Sections 10.4 and 10.5 do not limit liability that Law does not allow to be limited or excluded, including liability for fraud or wilful misconduct. Where a Law prevents part of this section from applying, the rest applies to the fullest extent that Law permits.

10.7 Exclusive remedy. For a failure of the Services, your sole and exclusive remedy, and our entire liability, is, at our option, to correct the failure or to refund the fees you paid us for the affected Service for the period of the failure.

10.8 Time limit. Any claim against an Ockham Party must be started within one (1) year after the cause of action arises, or it is barred, to the full extent Law permits.

10.9 Protection of others. The Ockham Parties who are not parties to these Terms are intended third-party beneficiaries of sections 7 and 9 to 11, and may rely on and enforce them.

10.10 Risk allocation. You acknowledge that this section 10 is a reasonable allocation of risk, that our fees reflect it, that you can protect yourself with backups, least-privilege credentials, approval steps and insurance, and that we would not provide the Services without it. You have not relied on any statement by us that is not in these Terms.

11. Indemnity, Intellectual Property and Confidentiality

11.1 Your indemnity. You will defend, indemnify and hold harmless the Ockham Parties from and against all claims, demands, investigations and proceedings brought by a third party or governmental authority, and all resulting losses, damages, liabilities, settlements, fines, penalties, costs and expenses (including reasonable legal fees), arising out of or relating to: (a) Customer Content, or our processing of it as these Terms permit; (b) your Customer Credentials, Cloud Accounts, Customer Environments and data sources; (c) code, workloads, images, charts, templates, tools and automations that you run or publish; (d) your use of AI Outputs, agents, goals and workflows; (e) your End Customers and anything you deliver to them; (f) your collection, use or disclosure of Personal Information; (g) your breach of these Terms, Schedule 1 or any Law; or (h) a dispute between you and a Third-Party Service or Publisher. This section is not subject to the limits in section 10.

11.2 Procedure. We will give you prompt notice of a claim. A delay relieves you only to the extent it materially prejudices you. You will control the defence and settlement, but may not settle in a way that admits fault for us or imposes obligations on us without our written consent, which we will not unreasonably withhold. We may take part with our own lawyers at our own expense.

11.3 Our indemnity. We give no indemnity under these Terms.

11.4 Our IP. Ockham and its licensors own all rights in the Services, the Software, the Documentation, and our models, prompts, templates, blueprints, semantic models and tooling, and in all improvements and derivatives of them, whoever suggests or makes them. Nothing in these Terms transfers any of that to you.

11.5 Your IP. You keep ownership of Customer Content and of the software, data products and configurations that you bring to or build on the Services. We may use them only as needed to provide the Services to you.

11.6 Feedback. If you give us suggestions or other feedback about the Services, we may use it for any purpose, without payment, credit or confidentiality, under a perpetual, irrevocable, worldwide, royalty-free licence that you now grant.

11.7 Aggregated and de-identified data. We may create aggregated or de-identified data from Usage Data and from metadata about your use of the Services, and use it for any lawful purpose, including to operate, secure, benchmark and improve the Services, as long as it does not identify you or any individual. We own that data.

11.8 Content you publish. If you publish a template, chart, tool, connector or other item for other users, you grant us and those users a non-exclusive, worldwide, royalty-free licence to use, copy, deploy, adapt and display it, unless you specify other terms when publishing. You confirm that you have the right to publish it. We may review, reject, remove or change the visibility of any item at any time.

11.9 Confidentiality. Each party will use the other's non-public information that is marked or reasonably understood to be confidential only to exercise its rights and perform its obligations under these Terms, will protect it with reasonable care, and will share it only with personnel, service providers and advisers who need it and are bound to protect it. This does not apply to information that is public through no fault of the recipient, already known to it, received from a third party without restriction, or developed independently. A party may disclose where Law requires, after notice where permitted. These duties last three years after the Terms end, and longer for trade secrets. Our handling of Customer Content is governed by section 5.

11.10 Publicity. We may identify you as a customer by name and logo unless you tell us in writing not to.

12. Governing Law, Disputes and General Terms

12.1 Governing law. These Terms are governed by the laws of the Province of Ontario and the federal laws of Canada that apply there, without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

12.2 Informal resolution. Before starting a proceeding, each party will give the other written notice of the dispute and try in good faith to resolve it for 30 days.

12.3 Arbitration. Any dispute not resolved under 12.2 will be finally resolved by binding arbitration before one arbitrator in Toronto, Ontario, in English, under the Arbitration Act, 1991 (Ontario) or, where it applies, the International Commercial Arbitration Act, 2017 (Ontario). If the parties cannot agree on an arbitrator within 10 days of notice, either may ask the Ontario Superior Court of Justice to appoint one. The arbitrator sets the procedure, may award costs, and must give written reasons. The award is final and binding, with no appeal. The arbitration is confidential, except as needed to enforce the award or as Law requires.

12.4 Individual claims only. Each party may bring claims only in its own capacity, and not as a plaintiff or class member in any class, collective or representative proceeding.

12.5 Courts. Either party may go to the courts of Ontario for an injunction or other urgent relief to protect its intellectual property or confidential information, and to enforce an award. Each party submits to the exclusive jurisdiction of those courts for those purposes.

12.6 Force majeure. Neither party is liable for a failure or delay caused by something beyond its reasonable control, including natural disaster, war, labour dispute, government action, power or network failure, failure of a cloud provider or Third-Party Service, or cyberattack. This does not excuse a payment obligation.

12.7 Assignment. You may not assign or transfer these Terms without our written consent. We may assign or transfer them, in whole or in part, to an affiliate or to a successor in a merger, acquisition, reorganization, financing or sale of assets.

12.8 Notices. We may give you notice by email to the address on your Account, by posting in the Services, or on our website. You may give us notice at hello@ockhamlabs.ai. Email notices are treated as received on the next business day after sending.

12.9 Export and sanctions. You will comply with all export control and sanctions Law. You confirm that you are not on any restricted-party list and will not use or deploy the Services or Software for a prohibited end use or in a prohibited jurisdiction.

12.10 Electronic records. These Terms, Order Forms and notices may be accepted, signed and delivered electronically, and our records of your acceptance are evidence of it.

12.11 Entire agreement and severability. These Terms, the Schedules and any Order Form are the entire agreement about the Services and replace all earlier discussions and agreements about them, except a signed agreement under section 1.5(a). If a provision is found unenforceable, it will be read down as far as needed, and the rest stays in effect.

12.12 Waiver and relationship. A waiver is effective only if it is in writing and signed. A delay in enforcing a right is not a waiver. The parties are independent contractors.

12.13 Third parties. Except for the Ockham Parties under section 10.9, no one other than the parties has any right under these Terms. End Customers have none.

12.14 Contact. Questions about these Terms: hello@ockhamlabs.ai. Privacy questions: our privacy officer at hello@ockhamlabs.ai.

Schedule 1: Acceptable Use Policy

You will not, and will not allow anyone else to, use the Services or Software to:

  • break any Law, or infringe or violate any intellectual property, privacy or other right;
  • connect to, query, scan or collect from any account, system, network or data source that you are not authorized to access;
  • scan, probe, test or attack any system, including ours, other customers' environments, cloud metadata services or internal network addresses, or use workflows, API calls, jobs, functions or containers to reach them;
  • try to break out of a namespace, container, sandbox or tenant boundary, or to read another customer's data, credentials or workloads;
  • distribute malware, or run command-and-control, phishing, spam, proxy, relay or anonymizing infrastructure;
  • mine cryptocurrency, or run workloads unrelated to your use of the Services on infrastructure that we operate or pay for;
  • store or process the kinds of content that section 5.4 says not to submit;
  • deploy software that you have no licence to run, or publish items that you have no right to publish;
  • use credentials that are stolen, shared without permission, or that belong to a publisher or other person who has not authorized that use;
  • degrade the Services for others through excess load, queries, storage, egress or automation;
  • get around quotas, rate limits, credits, billing, access controls, approval steps or safety features, or create multiple accounts to do so;
  • use the Services for weapons development, for unlawful surveillance, or for any use that sanctions or export control Law prohibits; or
  • help or encourage anyone else to do any of the above.

We may investigate suspected violations, stop workloads, remove content, and report unlawful activity to authorities. A violation allows us to act under section 9.

Schedule 2: Subprocessors and Third-Party Services

We use the providers below to deliver the Services and may add or change providers under section 7.2. Which of them receive your data depends on the deployment model, features and connectors you use. Where these providers store or process data is described in section 5.8.

Provider Used for Data involved
Amazon Web Services Hosting of the control plane; provisioning jobs; functions that run workbench code; storage; Ockham-Managed and Customer-Cloud environments Account data, configurations, Customer Credentials used for provisioning, query text and results, logs
Google Cloud Ockham-Managed and Customer-Cloud environments; sign-in Infrastructure metadata, workloads, sign-in identity
OVHcloud Ockham-Managed and Customer-Cloud environments; container registry Infrastructure metadata, workloads, images
Cloudflare DNS, network access rules, storage of workbench results Domain and network records, query results
OpenAI AI Features: copilot, AI-assisted SQL and explanations, goal planning, embeddings Prompts, files, schema and catalog metadata, retrieved data
Microsoft Azure (Azure OpenAI) AI Features Prompts and related content
Anthropic AI transform tasks in workflows Workflow data sent in prompts
Modal Hosting of Ockham AI services: semantic models, model operations Schema metadata, semantic definitions, chat messages, fine-tuning and evaluation data
Model providers you select for agents Hosted AI agents Chat content, agent configuration, keys you supply
Stripe Payments and billing Billing and payment details
Postmark, SendGrid Email delivery Names, email addresses, message content
Pusher Real-time copilot messages Copilot messages
Datadog Performance monitoring and tracing Usage Data and traces
Zoho CRM Ockham's own customer records Account holder name, email, sign-up and credit information
ipwho.is Location lookup for login records Account holders' IP addresses
Produktly In-app guidance Usage Data
Integration and tool providers you connect Connections to your business systems, MCP tools, repositories and secret stores Data and credentials you route through them

Start with a workload. Build the environment around it.

Tell us what you need to deploy, whose environment it must run in, and what it needs to connect to.