Cutova Software-as-a-Service Agreement
Version 2.4. This version takes effect for a new Customer when accepted during account onboarding. For an existing Customer, it applies only through the notice and acceptance process in Section 17 or a signed amendment. Publication alone does not replace an existing agreement.
The agreement at a glance
Cutova connects your chosen AI assistant to your Epicor environment. These terms explain what each party is responsible for.
- Your work stays yours. You retain your data and your rights in the BAQs, Functions, dashboards and customizations you create. Section 4 explains the rights in existing platform and pack components.
- Our commitments. We provide the limited service warranty in Section 10.2, the security safeguards in Section 8 and the permanent no-training commitment in Section 3.7.
- Your controls. You choose the tools, permissions and AI provider. Review generated work according to its intended use, and test changes before production use.
- Paid subscriptions renew automatically until cancelled. Cancel through the administration console or by email before the next renewal. Sections 7 and 9 explain notice, cancellation and refunds.
- Responsibility has financial limits. Section 11 sets general and enhanced liability caps and excludes certain losses. Free-tier use has separate limits under Section 7.11. Section 12 contains limited third-party defense obligations for each party.
- Disputes. Sections 14 and 15 require informal resolution, then mediation and Florida courts. Both parties waive jury trials and class or representative actions to the extent permitted by law.
This overview does not replace the provisions below. By clicking “I Agree”, you accept this Agreement, including Schedule A where applicable.
This Software-as-a-Service Agreement (this “Agreement”) is entered into on the Effective Date,
By and Between
The Customer, the individual or entity that accepts this Agreement and is identified in the Customer’s Cutova account (name, organization, and billing details as provided during registration) (“Customer”); and
Lens Software LLC, a limited liability company organized under the laws of the State of Florida, with its principal place of business at 12234 Meadowcrest Lane, Jacksonville, FL 32246 (“Company”). Cutova is a product of Lens Software LLC.
“Effective Date” means the date on which the Customer first accepts this Agreement by clicking to accept during account onboarding.
The Company and the Customer are referred to collectively as the “Parties” and individually as a “Party.”
This Agreement is a business-to-business agreement. The Customer represents that it is entering into this Agreement for business purposes and not as a consumer for personal, family or household use.
The Parties agree that the following terms and conditions apply to the Services provided under this Agreement and to all Orders placed under it.
TERMS OF THE AGREEMENT
1. DEFINITIONS
(a) “Affiliate” means, with respect to a Party, any entity that directly or indirectly controls, is controlled by, or is under common control with that Party, where “control” means ownership of more than fifty percent (50%) of the voting interests.
(b) “AI Client” means any third-party artificial-intelligence application, assistant, agent, model or platform that the Customer connects to the Service, including without limitation Claude, ChatGPT, Microsoft Copilot Studio, Gemini, LibreChat, VS Code, Cursor, Windsurf and Codex, together with the models and providers behind them.
(c) “Authorized User” means an individual whom the Customer permits to access or use the Service, including the Customer’s employees, contractors, agents and Affiliates.
(d) “Confidential Information” has the meaning given in Section 13.1.
(e) “Customer Content” means all data, text, sound, video, image files, files, configurations and software that the Customer or any Authorized User provides to, transmits through, or makes accessible to the Company in connection with the Services. For clarity, Customer Content includes the Customer’s Epicor® data accessed, transmitted or returned through the Services and the Epicor connection credentials the Customer provides to the Company.
(f) “Documentation” means the written or electronic release notes, user guides, online help, training materials and other published technical documentation about the applicable Service that the Company provides to the Customer, together with access to the Service. The Company’s Documentation is published at https://cutova.ai/docs.
(g) “Epicor Environment” means the Customer’s Epicor® Kinetic or Epicor® Classic installation, whether on-premise or hosted, together with the Customer’s Epicor licenses, users, configurations and data.
(h) “Gateway” means the optional on-premise agent that the Company makes available for installation on the Customer’s network so that the Service can reach an Epicor server behind the Customer’s firewall over an outbound connection.
(i) “Order” means any ordering document between the Customer and the Company that specifies the Service being purchased. For self-service subscriptions, the subscription tier the Customer selects during onboarding or in the administration console, together with the pricing then published by the Company at https://cutova.ai/pricing, constitutes the Order. An “Enterprise Order” is an Order in the form of a written agreement signed by both Parties, rather than accepted self-service, which may vary specific provisions of this Agreement as described in Section 5.8.
(j) “Output” means any response, answer, summary, table, chart, record, recommendation, code, file or other result that is generated, retrieved, assembled or displayed through the Service or through an AI Client connected to the Service, including results derived from the Customer’s Epicor data.
(k) “Personal Information” means information that identifies or is reasonably capable of being associated with an identified or identifiable natural person, as defined under applicable data protection law, including Fla. Stat. § 501.171.
(l) “Prohibited Data” has the meaning given in Section 3.4.
(m) “Service” or “Services” means the Company’s internet-accessible service made available by access to and use of software products hosted by the Company to which the Customer has subscribed under the relevant Order, including the Documentation, updates, upgrades, support, the Gateway and associated content. The Service is marketed under the name Cutova.
(n) “Software” means the object code version of any software to which the Customer has been provided access as part of the Service, including all updates and new versions.
(o) “Subscription Term” means the period specified in the applicable Order during which the Customer has access to the Service, together with each renewal period. The Subscription Term automatically renews as described in Section 7.2.
(p) “Usage Data” means technical and operational data generated by or in connection with the Customer’s use of the Service, including metadata such as request counts, tool names, response sizes, row counts, timestamps, error codes and performance metrics, excluding the substantive contents or values of Customer Content and Outputs.
Additional terms are defined where they first appear, including “Enterprise Order” (Section 1(i)), “Feedback” (Section 4.3), “Skill Pack” (Section 5.7(d)), “Fees” (Section 7.1), “Company Indemnified Party” (Section 12.1), “Discloser” and “Recipient” (Section 13.1), and “Notice of Dispute” (Section 14.1).
2. LICENSE GRANT AND RESTRICTIONS
2.1 Grant. During the Subscription Term, and subject to the Customer’s compliance with this Agreement and payment of all Fees, the Company grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right to access and use the Services solely for the Customer’s internal business operations, within the limits of the subscription tier stated in the applicable Order.
2.2 Services, Not Software Delivery. The Customer acknowledges that this Agreement is a services agreement and that the Company does not deliver copies of the Software to the Customer as part of the Services. For the avoidance of doubt, the Gateway is provided as part of the Services and remains subject to this Agreement; making the Gateway available is not a delivery, sale or license of the hosted Software.
2.3 Reservation of Rights. All rights not expressly granted in this Agreement are reserved by the Company and its licensors. No license is granted by implication, estoppel or otherwise.
2.4 Authorized Users.
The Customer may permit Authorized Users to use the Service within its subscription limits. The Customer is responsible for their compliance with this Agreement and for securing the accounts and credentials it controls. The Customer is responsible for unauthorized use to the extent caused by its failure to meet those obligations.
These responsibilities do not make the Customer liable to the extent a loss results from the Company’s breach of this Agreement, negligence or software defect. Each party’s liability remains subject to Sections 11 and 12.
2.5 Restrictions. The Customer shall not, and shall not permit any Authorized User or third party to:
(a) use the Service to reproduce, post, transmit or distribute any material in violation of any third party’s copyright, privacy, publicity or other intellectual property right;
(b) provide false identity information to gain access to or use the Service;
(c) reverse engineer, disassemble, decompile, translate or otherwise attempt to derive the source code, structure or algorithms of the Software or Service, except and only to the extent such activity is expressly permitted by applicable law notwithstanding this restriction;
(d) access the Services or use the Documentation in order to build, train or improve a similar or competitive product or service, or for competitive analysis or benchmarking;
(e) rent, lease, lend, sell, sublicense, resell, time-share, or operate the Service as a service bureau or on behalf of any third party, except that the Customer may permit its own Affiliates to use the Service as Authorized Users within its licensed limits;
(f) remove, obscure or alter any proprietary notice, mark or attribution;
(g) circumvent or attempt to circumvent any usage limit, seat count, instance count, tool count, metering, rate limit, authentication mechanism, tenant boundary or other technical restriction of the Service;
(h) use the Service to transmit malware, conduct penetration testing or vulnerability scanning without the Company’s prior written consent, or otherwise interfere with or disrupt the integrity or performance of the Service or the data of any other customer;
(i) publish or disclose to any third party any benchmark or performance test of any beta, preview or pre-release feature, or any material the Company has designated as confidential, without the Company’s prior written consent; or
(j) use the Service in violation of applicable law or in violation of the Customer’s agreements with Epicor Software Corporation.
Nothing in this Section 2.5 restricts the Customer’s right to publish an honest review or evaluation of the Service.
3. CUSTOMER RESPONSIBILITIES AND ACCEPTABLE USE
3.1 General. In connection with its use of the Services, the Customer shall: (a) comply with all applicable laws; (b) comply with any codes of conduct, acceptable-use policies or other notices provided by the Company; (c) immediately notify the Company if the Customer becomes aware of a security breach, credential compromise or unauthorized access related to the Service; and (d) keep the account, billing and notice information in its Cutova account complete, accurate and current.
3.2 Epicor Environment. The Customer shall maintain a validly licensed Epicor® Kinetic or Epicor® Classic environment, supply and safeguard its own Epicor connection credentials and service account, and ensure that its use of the Services complies with the Customer’s agreements with Epicor Software Corporation. The Company is independent of, and is not affiliated with, endorsed by, sponsored by, or certified by Epicor Software Corporation. Epicor® and Kinetic® are trademarks of their respective owners. The Customer manages the availability, licensing, configuration, security and data integrity of its Epicor Environment. This does not exclude the Company’s responsibility for its own breaches or software defects under Sections 6.3 and 11.
3.3 Configuration and Scope.
The Customer selects the tools, resources, users and Epicor permissions available through the Service. It is responsible for those choices, including reviewing write-enabled tools and applying its internal controls.
The Company is responsible for operating the Service in accordance with its express obligations. Customer configuration responsibilities do not excuse the Company’s breach, negligence or software defects. Sections 6, 10 and 11 govern responsibility for affected operations.
3.4 Prohibited Data. Unless the Parties agree otherwise in a signed writing, the Customer shall not knowingly transmit through, or make accessible to, the Service any of the following (“Prohibited Data”): (a) protected health information subject to HIPAA; (b) cardholder data subject to PCI DSS; (c) government classified or controlled unclassified information; (d) biometric identifiers; or (e) personal information of children under 13. If the Customer needs to transmit any of the foregoing, it should contact the Company before doing so; the Company will say plainly whether it can support that data. The Customer is solely responsible for any consequence of transmitting Prohibited Data, and the Company may suspend the Service under Section 9.3 if it reasonably believes Prohibited Data is being transmitted. Inadvertent transmission is not a breach of this Section 3.4 if the Customer, promptly on becoming aware of it, disables the affected tool or resource and notifies the Company.
3.5 Rights in Customer Content. The Customer represents and warrants that it owns or has all rights, consents and authorizations necessary to provide the Customer Content to the Company, to permit the Company to process it as contemplated by this Agreement, and to permit the transmission of Customer Content and Outputs to the AI Clients the Customer chooses to connect.
3.6 License from Customer. Subject to the terms of this Agreement, the Customer grants the Company a limited, non-exclusive, non-transferable, worldwide, royalty-free license to host, copy, transmit, process, reproduce, modify and display Customer Content solely as necessary to provide, secure, support and maintain the Services for the Customer. This license does not extend to the Customer’s Epicor connection credentials or service-account credentials, which the Company is licensed only to store in encrypted form and to use to authenticate to the Customer’s Epicor Environment as described in Section 5.1.1.
3.7 No Training on Customer Content, Permanent. The Company will not, at any time during or after the term of this Agreement, use Customer Content to train, fine-tune, evaluate or otherwise develop or improve any artificial-intelligence or machine-learning model, and will not sell, rent or license Customer Content to any third party. The Company will not permit any subprocessor it engages to do so. This commitment is perpetual and irrevocable, survives the expiration or termination of this Agreement for any reason, and no other provision of this Agreement limits or qualifies the commitment itself. Any claim for breach of this Section 3.7 remains subject to Section 11. For the avoidance of doubt, this Section 3.7 governs the Company and its subprocessors only. It does not and cannot govern any AI Client that the Customer chooses to connect to the Service; data the Customer transmits to an AI Client is handled under that provider’s terms as described in Section 6.5.
4. OWNERSHIP; FEEDBACK; USAGE DATA
4.1 Customer Content and Customer Work.
As between the Parties, the Customer retains all rights in its Customer Content. It also retains its rights in BAQs, Epicor Functions, dashboards, customizations, code, configurations and other work it creates or generates using the Service (“Customer Work”). To the extent the Company acquires transferable rights in Customer Work, it assigns those rights to the Customer, excluding the materials reserved in Section 4.2.
The Customer may retain, use and modify Customer Work after termination. Third-party rights and licenses still apply. The Company does not warrant that AI-generated work is unique, copyrightable or free of third-party rights.
4.2 Company Intellectual Property.
The Company and its licensors retain their rights in the platform, Software, Gateway, Documentation, Cutova-built Skill Packs and their pre-existing tools, templates and other materials. This includes improvements to those materials, but excludes Customer Content and Customer Work under Section 4.1.
If Company-owned materials are incorporated into Customer Work by the Service or an authorized Skill Pack workflow, the Company grants a perpetual, non-exclusive, royalty-free license to use and modify them as part of that work for the Customer’s internal business operations. This license does not permit standalone redistribution of those materials or continued access to the hosted Service after the subscription ends. Third-party and separately agreed licenses remain applicable.
4.3 Feedback.
The Customer may voluntarily provide suggestions about the Service (“Feedback”). The Company may use that feedback to improve its products without payment or attribution. This permission does not transfer ownership of Customer Content or Customer Work, or authorize disclosure of the Customer’s Confidential Information.
4.4 Usage Data. The Company may collect and use Usage Data to operate, secure, support, analyze, meter, bill for and improve the Services, and may publish or disclose Usage Data in aggregated and de-identified form that does not identify the Customer, any Authorized User, or any natural person.
4.5 Third-Party Technology. Third-party technology that may be appropriate or necessary for use with the Service is specified in the Documentation or the applicable Order. The Customer’s right to use such third-party technology is governed by the applicable third-party license or subscription agreement and not by this Agreement. Such third-party technology includes, without limitation, the Customer’s Epicor Environment and any AI Client the Customer chooses to connect to the Service. The Customer is solely responsible for obtaining, paying for and complying with its own licenses and subscriptions for that technology.
5. THE SERVICE
5.1 Core Functionality. Cutova is a multi-tenant, hosted Model Context Protocol (MCP) server that connects AI Clients to the Customer’s Epicor Environment. Subject to the subscription tier stated in the applicable Order, the Service includes:
(a) discovery and execution of Epicor data and operations as MCP tools and resources, including Business Activity Query (BAQ) data retrieval, direct business-object read and write operations, and Epicor business functions;
(b) interactive MCP Apps, including grid, record, chart and natural-language “ask” experiences;
(c) support for both Epicor Classic and Epicor Kinetic environments, whether on-premise or hosted;
(d) the optional Gateway;
(e) a web-based administration console for managing the Customer’s organization, users and invitations, Epicor instances, tools and resources, gateways, and subscription; and
(f) file upload and download workflows, curated-tool refresh and export/import, and a billing and access-grant audit trail.
The specific limits available to the Customer, the number of active Epicor users, the number of Epicor instances, and the number of enabled tools, are determined by the subscription tier in the applicable Order.
5.1.1 Authentication and Identity. Access to the Service is authorized using OAuth 2.1. The Company authenticates to the Customer’s Epicor Environment using the Epicor service account that the Customer configures and supplies. Every operation invoked through the MCP endpoint is executed under Epicor’s impersonation of the individual signed-in Authorized User, so that the Epicor permissions assigned to that user, and not the broader permissions of the service account, govern the operation, and Epicor records the operation against that user. Operations performed in the administration console, including connection validation, tool and resource discovery and refresh, gateway registration, and organization, user and subscription management, are executed under the service account and are recorded by Epicor against that service account. The Customer is solely responsible for the Epicor permissions it assigns to the service account and to each Authorized User, and for reviewing those permissions before enabling tools. The Company does not verify, and makes no representation regarding, the appropriateness of the permissions the Customer configures.
5.2 Support and Maintenance. The Company will provide technical support, updates and maintenance at the level corresponding to the Customer’s subscription tier in the applicable Order, ranging from community support on the free tier to email and priority-email support, an onboarding session, and, for the highest tier, a named contact and shared support channel. The Company applies updates and maintenance to the hosted Service on the Customer’s behalf.
5.3 Service Availability. The Company will use commercially reasonable efforts to make the Service available, except during scheduled maintenance, which the Company will communicate to the Customer in advance in writing where practicable, and except for events described in Section 16. The Company does not offer a numeric uptime commitment, service level agreement, service credit or response-time guarantee on any self-service tier. Any specific uptime or service-level commitment applies only if expressly agreed in a signed Enterprise Order.
5.4 System of Record and Backups.
Cutova provides access and integration services. It is not a system of record, backup or disaster-recovery service. The Customer maintains its Epicor records and current, tested backups. The Company’s limited processing and retention are described in Section 8.
This allocation does not exclude liability expressly preserved in Section 11.2.1.
5.5 Changes to the Service. The Company may modify, enhance, add to, or discontinue features of the Service from time to time. The Company will not materially degrade the core functionality of a paid subscription tier during a Subscription Term the Customer has prepaid; if the Company does materially degrade that core functionality, the Customer’s sole and exclusive remedy is to cancel under Section 7.3 and receive, notwithstanding Section 7.9, a pro-rata refund of prepaid, unused Fees for the remainder of the then-current Subscription Term.
5.6 Beta and Preview Features.
Features clearly designated as beta, preview, evaluation, experimental or early access may change or be withdrawn. They are provided as is and as available, without the service warranty, support commitments or IP defense applicable to paid production features. The Company’s data protection, confidentiality and no-training obligations remain applicable. Section 11 governs liability.
5.7 Limitations and Exclusions. The Service does not include: (a) the Epicor® software, environment or user licenses, which the Customer must license and maintain independently; (b) any AI Client, model or its subscription, and any tokens, credits or usage fees charged by the AI Client provider; (c) the Customer’s network connectivity, hardware or infrastructure, including the machine on which the Gateway is installed; (d) additional Epicor instances, additional seats, third-party “Skill Packs” (a “Skill Pack” being an optional package of curated tools, prompts or configurations described at https://cutova.ai/pricing; every Cutova-built Skill Pack, by contrast, is included with a paid subscription at no additional charge), or other add-ons, except as separately ordered and paid for; and (e) professional services, custom development, implementation, training or data migration except as separately agreed in writing. Any additional services required by the Customer are subject to separate terms and charges.
5.8 Enterprise Orders. The Company and a Customer may agree in a signed Enterprise Order to vary specific provisions of this Agreement. In the event of a conflict, a signed Enterprise Order controls over this Agreement solely as to the provisions it expressly varies. Absent a signed Enterprise Order, this Agreement governs in full.
5.9 Additional Services. Any service description not provided for under this Agreement must be separately agreed to by the Parties in writing as an annex or supplement to this Agreement.
6. ARTIFICIAL INTELLIGENCE, OUTPUTS AND THIRD-PARTY AI CLIENTS
6.1 How the Service Works.
The Service exposes the Epicor tools and resources selected by the Customer and transmits requests and results to its chosen AI Client. Some Outputs are retrieved Epicor records or results assembled by the Service. Others are generated or interpreted by third-party AI models, using Customer prompts and any tools or instructions available to them.
The Company does not independently validate every Output or control third-party model behavior. It remains responsible for its own retrieval, transmission and execution software under the express commitments and limits in this Agreement.
6.2 Review of AI-Generated Work.
AI-generated or interpreted Outputs can be inaccurate, incomplete or misleading. The Company does not guarantee their accuracy or suitability for a particular business decision.
The Customer must apply review appropriate to the intended use and potential consequences. It must verify material facts and calculations before consequential financial, operational, regulatory or safety decisions. It must review generated code and test changes in a suitable non-production environment before production use. These responsibilities do not excuse defects in the Company’s own software under Section 6.3.
6.3 Write Operations and Automated Actions.
Enabled tools can create, update or delete Epicor records. Some changes may be difficult or impossible to reverse. The Customer chooses which tools to enable, sets permissions and approval controls, and maintains backups.
The Customer is responsible for operations it or its AI Client requests, including errors in its instructions or business decisions. The Company does not assume liability for those decisions merely because the Service carries out the request.
This exclusion does not cover a defect in the Company’s own software that causes an unrequested operation or executes a requested operation contrary to the Documentation. Sections 10.2, 11.1 and 11.2.1 govern such claims.
6.4 Third-Party AI Clients.
AI Clients and their models are supplied by independent providers selected by the Customer. The Company is not responsible for their availability, pricing, policies, outputs, security practices or suspension of the Customer’s provider account.
A failure attributable solely to that provider does not constitute a Company breach or create a right to damages or service credits. If it materially prevents use of the Service for more than thirty (30) consecutive days and no reasonably usable supported alternative is available, either party may terminate the affected subscription. The Company will refund prepaid, unused Fees. This refund is the sole remedy for that third-party event. The Company’s own subprocessors remain governed by Section 8.4.
6.5 The Customer’s Relationship With Its AI Client Provider. The Customer’s use of any AI Client is governed solely by the Customer’s own agreement with that provider. The Customer is responsible for reading and complying with the AI Client provider’s terms, including its terms governing what that provider may do with data the Customer transmits to it. When the Customer uses the Service, Customer Content and Outputs are transmitted to the AI Client the Customer has chosen, and from that point are handled under that provider’s terms and privacy practices, not the Company’s.
6.6 No Professional Advice.
Outputs can support the Customer’s work but do not replace qualified professional judgment. The Company does not act as the Customer’s accountant, lawyer, auditor, medical provider, safety adviser or fiduciary. The Customer remains responsible for obtaining professional advice where its use requires it.
6.7 Customer AI Governance. The Customer is responsible for adopting and enforcing its own policies governing the use of artificial intelligence within its organization, including human-in-the-loop review, disclosure obligations, record-keeping, and compliance with any law or regulation applicable to its use of automated systems.
7. FEES, RENEWAL AND PAYMENT
7.1 Fees. The Customer agrees to pay the Company the fees (the “Fees”) for a paid subscription expressly confirmed by an authorized Customer administrator or as otherwise stated in the applicable Order. Selecting a no-card trial during onboarding does not authorize payment. Current list pricing is published at https://cutova.ai/pricing. The free tier is provided at no charge. Fees are based on the subscription tier and its metered limits, the number of active Epicor users, the number of Epicor instances, the number of enabled tools, and any add-ons such as additional Epicor instances, additional seats or third-party Skill Packs, and are invoiced or charged monthly or annually as stated in the applicable Order.
7.1(a) No-Card Trials. An eligible new organization may start one fourteen (14) day trial of Starter, Team, Company or Company Plus when it completes signup and accepts this Agreement. No credit card is required. Enterprise is contact-led. The trial includes the selected plan’s product capacity and pack access, but excludes paid add-ons, custom development and separately arranged human services.
Starting the trial does not authorize a charge or automatic conversion to a paid subscription. Continued paid access requires an expressly confirmed subscription or an approved billing arrangement. The Customer receives the price and first charge date before confirming payment. Selecting another plan does not restart the trial.
Without that confirmation or arrangement, the organization returns to Free at expiry. Saved configuration remains, subject to applicable retention terms, but Free capacity and pack restrictions apply. Trial expiry does not itself create a bill.
7.2 Automatic Renewal.
Paid subscriptions automatically renew for the same billing period until cancelled: monthly subscriptions renew monthly, and annual subscriptions renew annually. The Company charges the payment method on file or issues an invoice at renewal.
Cancel before the end of the current billing period to stop the next renewal. Cancellation takes effect at that period’s end. Section 7.3 explains how to cancel; Sections 7.4 and 7.5 govern renewal reminders and price changes. Refunds are available only as expressly provided in this Agreement.
7.3 HOW TO CANCEL. The Customer may cancel its subscription at any time, by the same means and in the same manner in which the Customer accepted this Agreement, by either of the following methods:
(a) online, in the Cutova administration console, under Subscription → Cancel Subscription; or
(b) by email to support@cutova.ai from the email address on the account, stating that the Customer wishes to cancel.
A cancellation submitted by either method before the end of the then-current billing period stops the next renewal. The Company will confirm the cancellation by email. No telephone call, retention conversation, written letter or other additional step is required to cancel.
7.4 Renewal Reminder for Annual Subscriptions. For any Subscription Term of twelve (12) months or longer that will automatically renew, the Company will send the Customer a written reminder by email to the address on the Customer’s account not less than thirty (30) days and not more than sixty (60) days before the cancellation deadline for that renewal. The reminder will state that the subscription will automatically renew unless cancelled, the renewal date, the then-current Fees, and how to cancel.
7.5 Price Changes. The Company may adjust the Fees on thirty (30) days’ prior written notice to the Customer. A price change takes effect only at the start of the Customer’s next billing period following the notice period and never during a billing period the Customer has already paid for. If the Customer does not accept a price change, the Customer’s sole and exclusive remedy is to cancel under Section 7.3 before the change takes effect.
7.6 Tier Limits and Add-ons.
Active users are counted by actual use within a rolling seven (7) day window. If use exceeds the selected tier’s limits, the Company may enforce those limits and notify the Customer of the available upgrade or add-on.
The Company will not automatically add charges or upgrade the Customer’s paid tier without approval by an authorized Customer administrator. Before approval, the Customer will receive the price, any proration and the effective date. Existing, expressly approved recurring add-ons may renew under Section 7.2.
The Customer may raise a good-faith usage or billing dispute under Section 7.8. The Company will provide reasonably sufficient usage records to explain the charge.
7.7 Payment Terms. Where the Company invoices the Customer, payment is due upon receipt of the invoice unless otherwise stated in the Order. Where the Customer has provided a payment method, the Company charges that method on the renewal date. All Fees are exclusive of taxes, duties, levies and withholdings, all of which are the Customer’s responsibility, excluding taxes on the Company’s net income.
7.8 Late Payment. If any undisputed amount is not paid when due, the Company may (a) charge interest on the overdue amount at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by Florida law, accruing from the due date until paid, (b) recover its reasonable costs of collection, including reasonable attorney’s fees, and (c) suspend or terminate the Service, as and when permitted by Section 9.3(d) or Section 9.4(b)(i). The Customer must notify the Company in writing of any good-faith dispute over an invoice within thirty (30) days of the invoice date, and must pay all undisputed amounts when due. An amount properly disputed within that period is not “overdue” for purposes of Section 9.3(d) or Section 9.4(b)(i) while the Parties are resolving the dispute in good faith.
7.9 No Refunds. All Fees are non-refundable and are paid in advance. Except where this Agreement expressly provides for a pro-rata refund, namely Sections 5.5, 6.4, 8.4, 9.2(b), 10.2, 12.2, 16.3 and 17.3, together with the fee relief in Section 9.3, the Company does not provide refunds, credits or proration for partial billing periods, unused seats, unused tools, downgrades, periods of non-use, or cancellation mid-period.
7.10 Payment Processing. Payment card processing is performed by a third-party payment processor under its own terms. The Customer authorizes the Company and that processor to charge the payment method on file for all Fees, taxes and applicable add-ons. The Customer is responsible for keeping a valid payment method on file.
7.11 Free Tier.
The free tier is provided without charge. It is provided as is and as available, without the service warranty, support or availability commitments applicable to paid subscriptions. The Company recommends a test or pilot Epicor environment for evaluating write-enabled tools. The Customer chooses whether to enable writes and must apply the review and backup practices in Section 6.
For free-tier use, the Company excludes liability for loss or alteration of Epicor data through write operations, including operations affected by a software defect. The paid-tier restoration remedy in Section 11.2.1(b) does not apply. This does not exclude direct damages arising from the Company’s breach of security or confidentiality obligations under Section 11.2.1(a).
The general aggregate cap for free-tier claims is US$5,000. For security or confidentiality claims under Section 11.2.1(a), the aggregate cap is US$10,000. These caps are not cumulative: all free-tier claims together cannot exceed US$10,000, and ordinary claims remain subject to the US$5,000 sublimit. These specific caps control over Section 11.1 for free-tier claims. Liabilities that cannot lawfully be excluded or limited remain unaffected under Section 11.4.
The no-training, confidentiality and data protection commitments continue to apply. Changes and discontinuation are subject to Sections 9.2 and 17.
8. DATA PROTECTION, SECURITY, RETENTION AND DELETION
8.1 Roles. As between the Parties, the Customer is the controller (or business) of any Personal Information contained in Customer Content, and the Company acts as a processor (or service provider) that processes Customer Content only on the Customer’s documented instructions, which consist of this Agreement, the applicable Order, and the configuration choices the Customer makes in the Service. The Customer is responsible for the lawfulness of the Customer Content and for providing any notices and obtaining any consents required for the Company to process it.
8.2 Data Handling and Retention.
The Company stores account and organization records, user identities, connection configuration, encrypted Epicor service-account credentials, tool definitions, gateway registrations, subscription records and Usage Data.
The Service processes Epicor results to complete requests. It does not maintain an ERP record repository, search index or analytics copy. The Company excludes request values and credentials from diagnostic logging and redacts sensitive error details. Operational logs are access-controlled and retained for no more than thirty (30) days. Uploaded and generated files are temporary; the Company will delete them within thirty (30) days, or sooner where the Documentation specifies a shorter period.
The pages at https://cutova.ai/security and https://cutova.ai/privacy describe implementation details. The binding baseline is stated in this Section 8 and Schedule A. Informational changes to those pages do not reduce that baseline.
8.3 Security Baseline.
The Company will maintain commercially reasonable administrative, physical and technical safeguards designed to protect Customer Content against unauthorized access, use, disclosure, alteration and destruction. The contractual baseline includes:
(a) encryption in transit and encryption at rest for stored Epicor service-account credentials;
(b) controls designed to separate customer tenants and restrict personnel access to legitimate operational needs;
(c) credential protection and diagnostic-log controls described in Section 8.2;
(d) reasonable vulnerability management and security-incident investigation and response procedures; and
(e) confidentiality obligations for personnel with access to Customer Content.
The Company will not materially reduce this baseline during a prepaid Subscription Term. No security measure eliminates every risk. No third-party certification or numeric availability guarantee applies unless expressly agreed in a signed Enterprise Order. Liability for breach remains governed by Section 11.
8.4 Subprocessors.
The Company may use subprocessors to provide the Service and will impose appropriate written data protection obligations on them. It remains responsible for their performance of this Section 8. Section 16 does not excuse that responsibility.
The Company publishes its subprocessor list at https://cutova.ai/security. It will give at least thirty (30) days’ advance email notice before a new or replacement subprocessor processes Customer Content. A replacement required urgently for security, legal or service-continuity reasons may take effect sooner, with notice as soon as practicable.
The Customer may object on reasonable data protection grounds within thirty (30) days of notice. The Parties will work in good faith to resolve the objection. If they cannot, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused Fees.
AI Client providers chosen and engaged directly by the Customer are not Company subprocessors. A provider engaged by the Company to process Customer Content for a Company-operated feature is a subprocessor, even if that provider also offers AI Clients.
8.5 Security Incidents. A “Security Incident” means a confirmed unauthorized access to, or acquisition of, Customer Content in the Company’s possession, or of the Customer’s Epicor connection or service-account credentials. The Company will notify the Customer’s designated contact by email without undue delay, and in any event within seventy-two (72) hours, after the Company determines that a Security Incident has occurred. The Company will promptly investigate events that may be a Security Incident, and will contain and mitigate any Security Incident and provide the Customer with the information reasonably necessary for the Customer to meet its own notification obligations. Where the Company is acting as a third-party agent within the meaning of Fla. Stat. § 501.171, notice will in no event be later than ten (10) days after the Company determines that a Security Incident occurred or has reason to believe it occurred, as that statute requires. The Customer, as the covered entity and controller of its data, is responsible for determining whether any notification to individuals, regulators or other parties is required and for making any such notification. Notification of a Security Incident is not an admission of fault or liability.
8.6 Retention and Deletion. The Customer may export its configured tool definitions at any time during the Subscription Term through the administration console. Following termination or expiration of this Agreement, the Company will retain the Customer’s account and configuration data for thirty (30) days, after which the Company will delete it, subject to the retention exceptions below. The Company may retain (a) Usage Data and aggregated or de-identified data, (b) billing, tax and audit-trail records for as long as required by law, and (c) data held in routine, non-targeted backups until those backups expire in the ordinary course.
8.7 Customer Backups.
The Customer must maintain current, tested backups of its Epicor Environment. Cutova does not provide a backup or recovery service, and the Customer cannot rely on Cutova to reconstruct its ERP records.
This provision does not exclude the Company’s express security, confidentiality or retention obligations, or the direct damages and restoration costs preserved by Section 11.2.1.
8.8 Deletion Requests. The Customer may request deletion of its account data at any time by emailing support@cutova.ai. The Company will action the request within thirty (30) days, subject to the retention exceptions in Section 8.6. Deletion is irreversible.
8.9 Data Processing Addendum.
Schedule A is the Data Processing Addendum (DPA) for this version of the Agreement. It automatically applies when the Company processes Personal Information in Customer Content on the Customer’s behalf. No separate signature is required. The same standard form is displayed at https://cutova.ai/dpa.
Schedule A controls conflicts concerning that processing, subject to its liability provisions and Section 20.2. A separately signed DPA may replace Schedule A as expressly agreed. Publication of a later DPA does not amend an accepted version; Section 17 governs changes.
9. TERM, SUSPENSION AND TERMINATION
9.1 Term. The term of this Agreement begins on the Effective Date and continues until all Subscription Terms have expired or been cancelled and this Agreement is terminated in accordance with this Section 9. Each Subscription Term automatically renews as set out in Section 7.2.
9.2 Cancellation and Termination for Convenience.
(a) Customer cancellation. The Customer may cancel at any time under Section 7.3, effective at the current billing period’s end. Section 7.9 governs refunds.
(b) Paid subscriptions. The Company may terminate a paid subscription for convenience, or discontinue the paid Service or tier, on at least sixty (60) days’ advance email notice. It will refund prepaid, unused Fees from the termination date. That refund is the remedy for termination for convenience and does not waive claims for an independent breach.
(c) Free subscriptions. The Company may discontinue a free tier or terminate a free account on at least five (5) days’ advance email notice. Sections 9.3 and 9.4 still permit suspension or termination for the reasons specified there. Section 9.5 governs exports.
9.3 Suspension. The Company may immediately suspend the Customer’s access to all or part of the Service, without liability and without prior notice where prior notice is impracticable, if the Company reasonably determines that: (a) the Customer’s use poses a security, integrity, legal or availability risk to the Service, to the Company, or to any third party; (b) the Customer or any Authorized User is violating Section 2.5 (Restrictions) or Section 3.4 (Prohibited Data); (c) affected processing must be stopped to contain Prohibited Data, including an inadvertent transmission; (d) any undisputed Fee is more than ten (10) days overdue after notice of non-payment; (e) suspension is required by law, by a governmental authority, or by the Company’s agreements with a subprocessor; or (f) the Customer’s Epicor agreements or Epicor Environment have been terminated, suspended or found to be out of compliance. Suspension will be limited to the scope and duration reasonably necessary. An inadvertent transmission addressed under Section 3.4 is not grounds for termination for breach. The Company will restore access promptly after the cause for suspension is resolved. Suspension does not relieve the Customer of its obligation to pay Fees for the suspended period unless the suspension was caused solely by the Company’s error.
9.4 Termination for Cause.
(a) Either Party may terminate this Agreement immediately upon written notice if the other Party commits a material breach that has not been cured within thirty (30) days after receipt of written notice describing the breach in reasonable detail.
(b) The Company may terminate this Agreement immediately upon written notice, without any further cure period, if: (i) the Customer fails to pay an undisputed invoiced amount and that failure continues for ten (10) days after the Company notifies the Customer of the failure; (ii) the Customer breaches Section 2.5 (Restrictions), Section 3.4 (Prohibited Data), or Section 13 (Confidentiality); or (iii) the Customer becomes insolvent, makes an assignment for the benefit of creditors, or has a receiver, trustee or bankruptcy petition filed by or against it that is not dismissed within sixty (60) days.
(c) If the Company terminates for cause under this Section 9.4, no refund of any kind is due, and all unpaid Fees for the remainder of the then-current Subscription Term become immediately due and payable.
9.5 Effect of Termination.
(a) The Customer shall immediately pay the Company all amounts outstanding as of the effective date of termination and all amounts that become due as a result of termination.
(b) Rights to access the hosted Service terminate, subject to the surviving Customer Work rights in Sections 4.1 and 4.2, and the Customer and all Authorized Users shall immediately cease all use of the Service, except that the Customer retains read-only access to export its tool definitions from the administration console for the retrieval period described in Section 9.5(c). AI Clients will no longer be able to reach the Customer’s Epicor Environment through Cutova.
(c) The Customer will have thirty (30) days from the effective date of termination to export any tool definitions it wishes to keep, after which the Company will delete the Customer’s account and configuration data in accordance with Section 8.6. The Customer’s ERP data itself resides in the Customer’s own Epicor Environment and is unaffected by termination of this Agreement.
(d) The Customer shall promptly uninstall and delete any Gateway from its systems.
(e) Upon termination, the Company shall cease using the Customer’s name and marks for marketing purposes on request, and each Party shall return or destroy the other’s Confidential Information in accordance with Section 13.5.
9.6 Survival. Sections 1, 2.3, 2.5, 3.4, 3.5, 3.6, 3.7 (perpetually), 4, 5.4, 6, 7 (as to amounts accrued), 8.2, 8.3, 8.4, 8.5, 8.6, 8.7, 8.9, 9.5, 9.6, 10.3, 11, 12, 13, 14, 15, 18, 19 and 20, together with any other provision that by its nature should survive, survive the expiration or termination of this Agreement.
10. WARRANTIES AND DISCLAIMERS
10.1 Mutual. Each Party represents and warrants that it has the full right, power and authority to enter into and perform this Agreement, and that the individual accepting this Agreement on its behalf is duly authorized to bind it.
10.2 Limited Service Warranty.
The Company warrants that paid production Services will perform substantially in accordance with the applicable Documentation. The Customer must promptly report a material non-conformity with sufficient detail to investigate it. The Company will use commercially reasonable efforts to correct it.
If correction is not possible within a commercially reasonable time, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused Fees. This is the exclusive remedy for failure to meet this service warranty, except that it does not limit claims expressly preserved in Section 11.2.1 or liabilities addressed in Section 11.4. There is no duplicate recovery for the same loss.
The warranty does not cover non-conformity to the extent caused by Customer Content, customer-controlled systems or configuration, third-party AI Clients, unauthorized modifications, or beta or free-tier features.
10.3 Disclaimer of Other Warranties.
Except for the express warranty in Section 10.2, the authentication statements in Section 5.1.1, and the Company’s express data protection, confidentiality and no-training obligations, the Service is provided as is and as available. To the maximum extent permitted by law, the Company and its licensors disclaim other express, implied and statutory warranties, including merchantability, fitness for a particular purpose, title and non-infringement. Section 12.2 separately states the Company’s IP defense obligation.
The Company does not guarantee uninterrupted or error-free operation, correction of every error, or the accuracy or suitability of AI-generated Outputs. It does not warrant customer-controlled Epicor systems or independently selected AI providers. These disclaimers do not override express commitments elsewhere in this Agreement.
10.4 Customer Warranties.
The Customer warrants that it has the rights needed to provide Customer Content and authorize the processing described in this Agreement. It will comply with applicable law and its Epicor and AI-provider agreements. Its obligations concerning Prohibited Data are subject to the inadvertent-transmission exception in Section 3.4.
11. LIMITATION OF LIABILITY
11.1 Company Liability Caps.
To the maximum extent permitted by law, the Company’s aggregate liability under or relating to this Agreement is limited to direct damages and the following caps. The caps in this Section and exclusions in Section 11.2 also protect its affiliates, members, managers, officers, employees, contractors, partners, licensors and suppliers. They share the same aggregate caps with the Company. They apply across legal theories, including contract, tort, negligence, warranty and indemnity.
(a) General cap for paid Services: the greater of Fees paid in the twelve (12) months before the first event giving rise to the claim or US$5,000.
(b) Enhanced cap for paid Services: claims described in Section 11.2.1 are subject to the greater of ten (10) times those Fees or US$250,000. This is a separate category limit, not an additional amount added to the general cap.
(c) Free-tier claims: Section 7.11 exclusively sets their caps and treatment. A later upgrade does not convert a claim arising from free-tier use into a paid-tier claim.
Section 11.5 governs aggregate application. Section 11.4 preserves liabilities that cannot lawfully be limited.
11.2 Excluded Losses.
Subject to Sections 11.2.1 and 11.4, the Company is not liable for indirect, incidental, special, exemplary, punitive or consequential damages. It also excludes lost profits, revenue, business opportunity, goodwill and anticipated savings; business interruption; and substitute-service costs, whether characterized as direct or indirect.
Loss, corruption or alteration of Epicor data, losses from reliance on AI Outputs, and losses caused by customer-requested operations or independently selected third-party systems are excluded except to the extent Section 11.2.1 expressly preserves direct damages. These exclusions apply even if such losses were foreseeable.
11.2.1 Preserved Direct Damages.
Section 11.2 does not exclude:
(a) direct damages from the Company’s breach of Section 8.3 (Security) or Section 13 (Confidentiality); or
(b) for paid-tier use only, reasonable and documented costs of restoring the Customer’s Epicor data to its state immediately before an operation affected by a Company software defect described in Section 6.3.
The enhanced cap in Section 11.1(b) applies to these paid-tier claims. Section 7.11 applies to free-tier claims. These exceptions control any conflicting data-loss or exclusive-remedy wording in Sections 3, 5, 6, 8 and 10. They do not create a general backup service or compensation for lost profits or business interruption.
11.3 Allocation of Risk. The Customer acknowledges that the limitations and exclusions in this Section 11, in Section 6 and in Section 10 are a fundamental basis of the bargain between the Parties, that the Fees charged for the Service are set in reliance on them and would be substantially higher without them, and that the Company would not enter into this Agreement without them. These limitations apply even if any limited remedy in this Agreement is found to have failed of its essential purpose.
11.4 Exclusions From the Cap. For the avoidance of doubt, Sections 11.1 and 11.2 limit the liability of the Company and the other persons named in them only, and do not limit: (a) the Customer’s obligation to pay Fees; (b) the Customer’s indemnification obligations under Section 12.1, which are separately capped by Section 12.1.1; (c) the Customer’s breach of Section 2.5 (Restrictions) or Section 3.4 (Prohibited Data); or (d) any liability that, as a matter of applicable law, cannot be limited or excluded by agreement, which, under Florida law, includes liability for fraud, gross negligence and willful misconduct. Nothing in this Section is intended to create, expand or concede any claim that applicable law would not otherwise allow.
11.5 Aggregate Application.
Multiple claims, users or Customer Affiliates do not increase the applicable caps. General paid-tier claims together remain within the general cap. All paid-tier claims together remain within the enhanced cap if an enhanced-cap claim exists, otherwise within the general cap. The caps are not cumulative. Section 7.11 governs free-tier claims; free and paid caps do not stack for the same loss. No party may recover twice for the same loss.
11.6 Insurance. The Company will maintain technology errors and omissions and cyber liability insurance with an aggregate limit of not less than one million U.S. dollars (US$1,000,000) while providing paid Services under this Agreement, and will furnish a certificate of insurance on the Customer’s written request. This insurance does not increase the Company’s liability beyond the limits in this Section 11.
12. INDEMNIFICATION
12.1 Customer Third-Party Defense.
The Customer will defend the Company and its affiliates, members, managers, officers, directors, employees, contractors, successors and permitted assigns (each a “Company Indemnified Party”) against third-party claims to the extent caused by:
(a) Customer Content that infringes intellectual property rights or violates privacy rights, excluding Company materials and AI-generated material merely because it is an Output;
(b) the Customer’s or its Authorized Users’ unlawful use of the Service or material breach of this Agreement; or
(c) their intentional misuse of tools, permissions or credentials, including knowing transmission of Prohibited Data contrary to Section 3.4.
The Customer will pay covered damages finally awarded or agreed in an authorized settlement, and reasonable defense costs, subject to Sections 12.1.1 and 12.3. A claim based only on ordinary permitted use, an AI error or an operation does not trigger this obligation without a covered cause above.
The obligation does not apply to the extent a claim results from the Company’s or another protected party’s breach, negligence, willful misconduct or software defect. Responsibility is reduced in proportion to that party’s contribution. The inadvertent-transmission exception in Section 3.4 applies.
12.1.1 Customer Indemnity Cap.
The Customer’s total aggregate liability under Section 12.1 is limited to the greater of five (5) times the Fees paid in the twelve (12) months before the claim or US$50,000. This cap does not apply to knowing transmission of Prohibited Data in breach of Section 3.4 or intentional misuse in breach of Section 2.5. An inadvertent transmission addressed under Section 3.4 does not remove this cap or independently trigger indemnity.
12.2 Company Intellectual Property Defense.
The Company will defend the Customer against third-party claims that the Service, as supplied and used in accordance with this Agreement, infringes a United States copyright or trademark. It will pay covered damages finally awarded or agreed in an authorized settlement.
This obligation excludes claims to the extent caused by Customer Content, AI-generated Outputs, third-party products, unauthorized modifications, or combinations outside documented intended use. The exclusion applies only where the claim would not arise without the excluded material or activity. Use with Epicor and a compatible AI Client as documented does not, by itself, remove this protection. The Company does not assume responsibility for infringement inherent in those third-party products. Free-tier and beta features are excluded.
If a claim arises or appears likely, the Company may obtain continued usage rights, modify or replace the affected functionality, or terminate the affected subscription and refund prepaid, unused Fees. Protection does not extend to avoidable claims caused by continued infringing use after a suitable non-infringing alternative or instruction to stop is provided.
This Section states the Company’s entire liability and the Customer’s exclusive remedy for infringement claims, subject to the general cap in Section 11.1 and the procedure in Section 12.3.
12.3 Procedure. The Party seeking indemnification shall: (a) promptly notify the indemnifying Party in writing of the claim (provided that a delay in notice relieves the indemnifying Party only to the extent it is materially prejudiced); (b) give the indemnifying Party sole control of the defense and settlement of the claim; and (c) provide reasonable cooperation at the indemnifying Party’s expense. The indemnified Party may participate in the defense at its own expense with counsel of its choosing. The indemnifying Party shall not settle any claim in a manner that imposes any non-indemnified liability, admission of fault, or ongoing obligation on the indemnified Party without that Party’s prior written consent, not to be unreasonably withheld.
13. CONFIDENTIALITY
13.1 Definition. “Confidential Information” means any non-public information disclosed by one Party (the “Discloser”) to the other (the “Recipient”) in connection with this Agreement that is designated as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. The Company’s Confidential Information includes the Software, the Service architecture and non-public functionality, the Documentation not published publicly, security details, pricing not publicly listed, and roadmaps. The Customer’s Confidential Information includes the Customer Content.
13.2 Exclusions. Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the Recipient; (b) was rightfully known to the Recipient without restriction before disclosure; (c) is rightfully received from a third party without restriction; or (d) is independently developed by the Recipient without use of or reference to the Discloser’s Confidential Information.
13.3 Obligations. The Recipient shall: (a) use the Discloser’s Confidential Information only as necessary to perform this Agreement; (b) not disclose it to any third party except to its employees, contractors, subprocessors and professional advisors who have a need to know and who are bound by confidentiality obligations at least as protective as these; and (c) protect it using at least the degree of care it uses for its own confidential information of like importance, and in no event less than reasonable care. At no time shall either Party use Confidential Information obtained through this relationship, directly or indirectly, for personal benefit or for the benefit of any third party.
13.4 Compelled Disclosure. The Recipient may disclose Confidential Information to the extent required by law, regulation, subpoena or court order, provided that (where legally permitted) it gives the Discloser prompt written notice and reasonable cooperation to seek protective treatment.
13.5 Return or Destruction. Upon the Discloser’s written request following termination, the Recipient shall return or destroy the Discloser’s Confidential Information, except for copies retained in routine backups or as required by law, which remain subject to this Section 13.
13.6 Duration. The obligations in this Section 13 continue for three (3) years after termination of this Agreement, and indefinitely with respect to any information that constitutes a trade secret under applicable law for so long as it remains a trade secret.
14. DISPUTE RESOLUTION; WAIVERS
14.1 Informal Resolution.
Before mediation or litigation, the party raising a dispute must send a written Notice of Dispute describing the issue and requested relief. Email to legal@cutova.ai is sufficient notice to the Company; no postal copy is required. Notice to the Customer goes to its designated account email. The Parties will negotiate in good faith for thirty (30) days after receipt, subject to Section 14.4.
14.2 Mandatory Mediation. If the dispute is not resolved within that thirty (30) day period, the Parties shall submit the dispute to non-binding mediation before a single mediator as a condition precedent to filing suit. The mediation shall be conducted in Jacksonville, Duval County, Florida, or by videoconference at either Party’s request, before a mediator certified as a circuit civil mediator by the Supreme Court of Florida or, if the Parties agree, a mediator appointed by the American Arbitration Association. The Parties shall share the mediator’s fees and administrative costs equally, and each Party shall bear its own attorney’s fees and expenses for the mediation. If the dispute is not resolved within sixty (60) days after the mediator is appointed, or if the other Party fails to participate in good faith, either Party may proceed under Section 14.3.
14.3 Litigation. Any dispute not resolved under Sections 14.1 and 14.2 shall be resolved exclusively by litigation in the courts identified in Section 15.2.
14.4 Exceptions. Sections 14.1 and 14.2 do not apply to, and either Party may immediately seek relief in the courts identified in Section 15.2 for: (a) an application for a temporary restraining order, preliminary injunction or other equitable relief to prevent or stop actual or threatened infringement or misappropriation of intellectual property, unauthorized access to systems or data, or breach of Section 13 (Confidentiality); or (b) an action by the Company to collect Fees due and unpaid.
14.5 WAIVER OF JURY TRIAL.
EACH PARTY KNOWINGLY, VOLUNTARILY AND INTENTIONALLY WAIVES, TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, ANY AND ALL RIGHT TO A TRIAL BY JURY IN ANY ACTION, PROCEEDING OR COUNTERCLAIM ARISING OUT OF OR RELATED TO THIS AGREEMENT, THE SERVICE, OR THE RELATIONSHIP BETWEEN THE PARTIES, WHETHER SOUNDING IN CONTRACT, TORT OR OTHERWISE. EACH PARTY ACKNOWLEDGES THAT IT HAS HAD THE OPPORTUNITY TO CONSULT COUNSEL REGARDING THIS WAIVER AND THAT THIS WAIVER IS A MATERIAL INDUCEMENT FOR THE OTHER PARTY TO ENTER INTO THIS AGREEMENT.
14.6 CLASS ACTION AND REPRESENTATIVE ACTION WAIVER.
EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY IN ITS INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF, CLASS MEMBER OR CLASS REPRESENTATIVE IN ANY PURPORTED CLASS, COLLECTIVE, CONSOLIDATED, PRIVATE ATTORNEY GENERAL OR OTHER REPRESENTATIVE PROCEEDING. NO COURT MAY CONSOLIDATE OR JOIN THE CLAIMS OF MORE THAN ONE CUSTOMER, AND NO COURT MAY PRESIDE OVER ANY FORM OF CLASS OR REPRESENTATIVE PROCEEDING UNDER THIS AGREEMENT. IF THIS SECTION 14.6 IS FOUND UNENFORCEABLE AS TO ANY CLAIM, THAT CLAIM SHALL BE SEVERED AND STAYED PENDING RESOLUTION OF ALL INDIVIDUAL CLAIMS.
14.7 Prompt Notice and Tolling.
A party should notify the other promptly after learning of a claim. A delay does not forfeit the claim or shorten any statutory limitation period. It relieves the other party of an affected obligation only to the extent the delay materially prejudices that party, as permitted by law.
To the extent permitted by law, limitation periods are tolled from delivery of a Notice of Dispute until thirty (30) days after the procedures in Sections 14.1 and 14.2 conclude. Either party may make a protective filing to preserve a claim before a deadline and request a stay while those procedures continue.
14.8 Attorney’s Fees. Except (a) as provided in Section 12.1 with respect to third-party claims, and (b) in an action by the Company to collect Fees due and unpaid, each Party shall bear its own attorney’s fees, expert fees and costs in any mediation, action or proceeding arising out of or related to this Agreement, regardless of outcome.
15. GOVERNING LAW AND VENUE
15.1 Governing Law. This Agreement, and all disputes arising out of or related to it or to the Service, are governed by the laws of the State of Florida, without regard to its conflict-of-laws principles. The United Nations Convention on Contracts for the International Sale of Goods and the Uniform Computer Information Transactions Act do not apply.
15.2 Exclusive Venue. The Parties irrevocably agree that the exclusive venue and jurisdiction for any action permitted under Section 14.3 or Section 14.4 is the state courts located in Duval County, Florida, or the United States District Court for the Middle District of Florida, Jacksonville Division. Each Party irrevocably consents to the personal jurisdiction of those courts, waives any objection based on lack of personal jurisdiction, improper venue or forum non conveniens, and agrees to accept service of process by certified mail or by email to the notice addresses in Section 19.
15.3 Consistency. Sections 14 and 15 are intended to operate together: mediation is a condition precedent under Section 14.2, and any dispute that is not resolved in mediation, or that falls within Section 14.4, is resolved by litigation in the courts identified in Section 15.2. There is no arbitration requirement under this Agreement.
16. FORCE MAJEURE
16.1 The Company’s Excuse. The Company shall not be liable for, and shall not be considered in breach of this Agreement on account of, any delay or failure to perform resulting from any cause beyond its reasonable control, including without limitation: acts of God; fire; flood; hurricane; earthquake; epidemic or pandemic; war, terrorism, civil unrest or sabotage; strike or labor dispute; act, order, embargo or sanction of any public authority; failure, interruption, degradation or discontinuation of the internet, telecommunications networks, electrical power, cloud infrastructure providers, hosting providers or payment processors; cyberattack, denial-of-service attack, ransomware or other malicious act of a third party; failure, unavailability, degradation, throttling, policy change or discontinuation of any AI Client, model or model provider; and failure, unavailability or misconfiguration of the Customer’s Epicor Environment, network or hardware.
16.2 Payment Not Excused. This Section 16 does not excuse, delay or diminish the Customer’s obligation to pay any Fees when due.
16.3 Extended Events. If a force majeure event materially prevents the Company from providing the Service for more than thirty (30) consecutive days, either Party may terminate the affected subscription on written notice, and the Company will refund the pro-rata portion of prepaid, unused Fees, which is the Customer’s sole and exclusive remedy. This Section 16.3 does not apply to any event described in Section 6.4 (failure, degradation, change or discontinuation of an AI Client, model or model provider), which is governed by the limits and termination/refund right in Section 6.4.
17. CHANGES TO THIS AGREEMENT
17.1 Negotiated Amendments. No amendment negotiated between the Parties is effective unless in writing and signed by both Parties.
17.2 Prospective Updates.
The Company may publish updated terms with a version and effective date. It will send direct email notice of any material adverse change at least thirty (30) days before it may take effect. Website posting alone is insufficient notice of such a change. Other updates may be notified by email or within the Service. Section 17.4 protects the current Subscription Term.
17.3 Acceptance and Cancellation.
Updates apply only after the notice required by Section 17.2 and subject to Section 17.4. Acceptance may be recorded when the Customer expressly agrees, or through continued use after the notified effective date where permitted by law. Publication alone does not establish acceptance. If the Customer does not agree, it may cancel before the update applies and receive a pro-rata refund of prepaid, unused Fees. This is the remedy for rejecting an update; it does not waive claims for an independent breach.
17.4 No Mid-Term Adverse Changes. Any update that materially and adversely affects the Customer’s rights takes effect no earlier than the start of the Customer’s next Subscription Term. The version of this Agreement in effect when a Subscription Term begins governs that Subscription Term. A signed Enterprise Order may fix the version of this Agreement applicable to that Customer for the duration of its committed term.
18. ASSIGNMENT
18.1 By the Customer. The Customer may not assign, delegate or transfer this Agreement or any right or obligation under it, by operation of law, change of control, merger or otherwise, without the Company’s prior written consent, which shall not be unreasonably withheld. Any purported assignment in violation of this Section is void.
18.2 By the Company. The Company may assign this Agreement, in whole or in part, without the Customer’s consent, to an Affiliate or in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of its assets or of the Cutova business. The Company may use subcontractors and subprocessors to perform its obligations, and remains responsible for their performance.
18.3 Binding Effect. This Agreement binds and benefits the Parties and their permitted successors and assigns.
19. NOTICES
19.1 Notices to the Company.
Notices, including dispute, breach and termination notices, may be sent to legal@cutova.ai. Email alone is sufficient if the sender retains evidence of transmission and receives no delivery-failure notice. Alternatively, notices may be delivered by certified mail, personal delivery or recognized overnight courier to Lens Software LLC, 12234 Meadowcrest Lane, Jacksonville, FL 32246. Subscription cancellations may also use the methods in Section 7.3.
19.2 Notices to the Customer.
The Company will send notices of material adverse terms changes, price changes, annual renewals, security incidents and planned termination to the Customer’s designated account email. It may also display them within the Service. Other routine notices may be delivered within the Service. Email notice is given when sent without a delivery-failure notice; a known delivery failure requires a reasonable attempt through another available contact method.
19.3 Customer’s Obligation. The Customer is solely responsible for maintaining a current, monitored email address on its account. The Company is not responsible for any consequence of the Customer’s failure to receive a notice, including a renewal reminder or a notice of a change in terms or price, because the email address on the account was outdated, inaccurate, or filtered by the Customer’s systems.
19.4 Electronic Communications. The Customer consents to receive all notices, disclosures, agreements and other communications from the Company electronically, and agrees that electronic delivery satisfies any legal requirement that such communications be in writing.
20. GENERAL PROVISIONS
20.1 Entire Agreement.
This Agreement, including Schedule A where applicable, the applicable Order and the Documentation form the agreement between the Parties. They replace prior discussions and proposals concerning the same subject, subject to Section 17 and any applicable signed agreements.
20.2 Order of Precedence.
Conflicts are resolved in this order:
(a) a signed Enterprise Order or separately signed DPA, only for provisions it expressly varies;
(b) Schedule A for the processing of Personal Information, subject to the liability rules stated there;
(c) this Agreement;
(d) the applicable Order; and
(e) the Documentation.
The security and privacy pages provide implementation information; Sections 8 and Schedule A establish the contractual baseline. Customer purchase orders and vendor-portal forms do not amend this Agreement unless an authorized Company representative expressly agrees to the amendment in a signed writing.
20.3 Statements Outside the Agreement.
The Customer purchases the current Service described in this Agreement, its Order and applicable Documentation. Roadmaps, demonstrations and estimates are illustrative, and do not guarantee future functionality or identical results. Additional commitments must be expressly agreed in writing. Nothing in this Section excludes liability for fraud or misrepresentation that cannot lawfully be excluded.
20.4 Severability and Reformation. If any provision of this Agreement is held invalid, illegal or unenforceable by a court of competent jurisdiction, that provision shall be modified and interpreted so as to best accomplish the objectives of the original provision to the fullest extent permitted by law, and the remaining provisions shall remain in full force and effect. If the provision cannot be so modified, it shall be severed and the remainder of this Agreement shall continue in effect.
20.5 No Waiver. No failure or delay by a Party in exercising any right under this Agreement operates as a waiver of that right. No waiver is effective unless in writing and signed by the waiving Party, and a waiver on one occasion is not a waiver on any other occasion.
20.6 Independent Contractors. The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, employment or fiduciary relationship between the Parties.
20.7 No Third-Party Beneficiaries. Except for the Company Indemnified Parties under Section 12.1 and the parties protected by the limitations in Sections 11.1 and 11.2, this Agreement confers no rights or remedies on any person other than the Parties and their permitted successors and assigns.
20.8 Export Control and Sanctions. The Customer represents that it is not, and is not owned or controlled by, and is not acting on behalf of, any person that is the subject of economic sanctions or is located in, organized under the laws of, or ordinarily resident in any embargoed or comprehensively sanctioned jurisdiction. The Customer shall comply with all applicable export control, sanctions and anti-boycott laws, and shall not export, re-export or make the Service available in violation of them.
20.9 Anti-Corruption. Each Party shall comply with the U.S. Foreign Corrupt Practices Act and all other applicable anti-bribery and anti-corruption laws.
20.10 U.S. Government End Users. The Service and Documentation are “commercial products” and “commercial computer software” as defined in 48 C.F.R. § 2.101. Any use, duplication or disclosure by the U.S. Government is subject solely to the terms of this Agreement.
20.11 Publicity.
The Company may identify the Customer by name or logo, or publish a customer case study, only with the Customer’s prior written consent. Consent may be withdrawn by email; the Company will remove the material from marketing channels it controls within thirty (30) days. Neither Party may issue a press release naming the other without prior written consent.
20.12 Epicor Trademarks. Epicor® and Kinetic® are trademarks or registered trademarks of Epicor Software Corporation. Claude® is a trademark of Anthropic PBC. ChatGPT® is a trademark of OpenAI. All other marks are the property of their respective owners. Use of these marks is nominative and does not imply any affiliation, endorsement or sponsorship.
20.13 Headings and Construction. Headings are for convenience only and do not affect interpretation. “Including” means “including without limitation.” This Agreement shall not be construed against either Party as the drafter.
20.14 Counterparts and Electronic Signature. This Agreement may be accepted electronically, and electronic acceptance has the same force and effect as a handwritten signature under the Florida Uniform Electronic Transaction Act, Fla. Stat. § 668.50, and the federal E-SIGN Act, 15 U.S.C. § 7001 et seq.
20.15 Language. This Agreement is executed in the English language, which governs in the event of any translation.
20.16 Legal and Binding. This Agreement is legal and binding between the Parties. Each Party represents that it has the authority to enter into this Agreement.
ACCEPTANCE
By clicking “I Agree” (or an equivalent control) during account onboarding, the individual accepting this Agreement represents and warrants that they are at least eighteen (18) years of age, are authorized to bind the Customer to this Agreement, and have read and understood it, including the highlighted provisions in Sections 6, 7.2, 10, 11, 12 and 14, which limit the Company’s liability, disclaim warranties, automatically renew the subscription, require indemnification, and waive jury trial and class actions. Acceptance is recorded electronically in lieu of a handwritten signature and has the same legal effect as a handwritten signature under the Florida Uniform Electronic Transaction Act, Fla. Stat. § 668.50, and the federal E-SIGN Act, 15 U.S.C. § 7001 et seq.
At the time of acceptance, the Company records, as evidence of acceptance: the accepting user’s account identity (name and email), the Customer organization, the date and time of acceptance, the version of this Agreement accepted, and the originating IP address. The Customer agrees that this electronic record is admissible in any proceeding and is sufficient evidence of the Parties’ agreement to these terms.
Cutova is a product of Lens Software LLC, Jacksonville, Florida. Version 2.4.
Schedule A: Data Processing Addendum
Data Processing Addendum
Version 2.4. Schedule A to the Cutova Software-as-a-Service Agreement, Version 2.4.
This Data Processing Addendum (“DPA”) supplements the Cutova Software-as-a-Service Agreement (the “Agreement”) between Lens Software LLC (“Company”) and the customer that accepts it (“Customer”). It applies to the Company’s processing of Personal Information contained in Customer Content on the Customer’s behalf.
This DPA forms Schedule A of Agreement Version 2.4. It applies automatically when the Company processes Personal Information in Customer Content on the Customer’s behalf. No separate signature is required. Existing separately signed agreements remain governed by their terms.
Capitalized terms not defined here have the meaning given in the Agreement.
1. Definitions
(a) “Data Protection Laws” means all privacy and data protection laws applicable to the Company’s processing of Personal Information under the Agreement, including the Florida Digital Bill of Rights, the California Consumer Privacy Act as amended, and comparable United States state privacy laws.
(b) “Personal Information” means information within Customer Content that identifies or is reasonably capable of being associated with an identified or identifiable natural person, as defined under Data Protection Laws.
(c) “Process” and “Processing” mean any operation performed on Personal Information.
(d) “Controller” (or “Business”) and “Processor” (or “Service Provider”) have the meanings given under the applicable Data Protection Laws.
(e) “Subprocessor” means a third party engaged by the Company to Process Personal Information in providing the Service.
2. Roles and instructions
The Customer is the Controller (or Business) of the Personal Information. The Company is a Processor (or Service Provider) acting on the Customer’s behalf. The Company will Process Personal Information only on the Customer’s documented instructions, which consist of the Agreement, the applicable Order, this DPA, and the configuration choices the Customer makes in the Service. The Company will inform the Customer if it believes an instruction violates Data Protection Laws. The Customer is responsible for the lawfulness of the Customer Content and for providing any notices and obtaining any consents required for the Company to Process it.
3. Service provider and business-purpose commitments
The Company will Process Personal Information only for the business purposes of providing, securing, supporting, metering, billing for, and improving the Service, and as otherwise permitted by Data Protection Laws. The Company:
(a) will not sell or share Personal Information, as those terms are defined under Data Protection Laws;
(b) will not retain, use, or disclose Personal Information for any purpose other than the business purposes specified above, or as otherwise permitted by Data Protection Laws, and will not retain, use or disclose it outside the direct business relationship between the parties;
(c) will not combine Personal Information received under the Agreement with personal information from another source, except as Data Protection Laws permit a service provider to do; and
(d) certifies that it understands the restrictions in this Section 3 and will comply with them.
No training on Customer Content. The Company will not use Personal Information, or any other Customer Content, to train, fine-tune, evaluate or otherwise develop any artificial-intelligence or machine-learning model, and will not sell, rent or license it to any third party. This commitment is permanent and survives termination, and mirrors Section 3.7 of the Agreement.
4. Confidentiality
The Company will ensure that personnel authorized to Process Personal Information are bound by appropriate confidentiality obligations.
5. Security
The Company will maintain the contractual security baseline in Section 8.3 of the Agreement. Changes to informational web pages do not reduce that baseline.
6. Subprocessors
The Customer authorizes subprocessors subject to Section 8.4 of the Agreement, including advance email notice, reasonable objections and the termination/refund remedy. The Company will impose written data protection obligations no less protective than this DPA and remains responsible for their performance. A customer-selected AI Client is independent; a provider engaged by the Company to process Customer Content is a subprocessor.
7. Assistance to the Customer
Taking into account the nature of the Processing, the Company will:
(a) assist the Customer, by appropriate technical and organizational measures and insofar as reasonably possible, to respond to requests from individuals to exercise their rights under Data Protection Laws. Because the Company does not hold Epicor records and Processes limited Personal Information, the Customer can fulfil most such requests by exporting its configured tool definitions through the administration console and by requesting deletion of other account and configuration data as described in Section 9;
(b) assist the Customer with security-incident notification as described in Section 8, and with data protection impact assessments and consultations with regulators, in each case at the Customer’s reasonable request and expense; and
(c) make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. On the Customer’s written request, not more than once per twelve (12) months and subject to reasonable confidentiality and security conditions, the Company will respond to a reasonable written security and privacy questionnaire; on-site audits are available only under a signed Enterprise Order.
8. Security incidents
A “Security Incident” means a confirmed unauthorized access to, or acquisition of, Personal Information in the Company’s possession, or of the Customer’s Epicor connection or service-account credentials. The Company will notify the Customer’s designated contact by email without undue delay, and in any event within seventy-two (72) hours, after the Company determines that a Security Incident has occurred. Where the Company is a third-party agent within the meaning of Fla. Stat. § 501.171, notice will be no later than ten (10) days after the Company determines that a Security Incident occurred or has reason to believe it occurred, as that statute requires. The Company will investigate, contain and mitigate the incident and provide the information the Customer reasonably needs to meet its own notification obligations. As the Controller, the Customer determines whether to notify individuals or regulators. Notification is not an admission of fault.
9. Retention, return and deletion
During the Subscription Term the Customer may export its configured tool definitions through the administration console. After termination or expiration of the Agreement, the Company will retain the Customer’s account and configuration data for thirty (30) days, after which the Company will delete it. The Company may retain Personal Information only (a) as usage data or aggregated or de-identified data, (b) in billing, tax and audit records for as long as the law requires, and (c) in routine backups until those backups expire in the ordinary course. The Customer may request deletion at any time by emailing support@cutova.ai; the Company will action the request within thirty (30) days, subject to the retention exceptions above. Deletion is irreversible.
10. Prohibited Data
The Customer will not transmit through the Service the categories of Prohibited Data described in Section 3.4 of the Agreement, subject to the inadvertent-transmission exception in Section 3.4, including protected health information subject to HIPAA, cardholder data subject to PCI DSS, government classified or controlled unclassified information, biometric identifiers, or personal information of children under 13, unless the parties agree otherwise in a signed writing.
11. International transfers
The Service is operated in the United States, and Personal Information is Processed in the United States. This DPA addresses United States state privacy laws. If the Customer requires the Company to Process personal data subject to the European Union or United Kingdom General Data Protection Regulation, the parties will agree an appropriate transfer mechanism, such as the applicable Standard Contractual Clauses, in a separate signed writing before that data is transmitted.
12. Liability and precedence
For conflicts about processing Personal Information, this DPA prevails as stated in Section 20.2 of the Agreement. The limits and exclusions in Sections 7.11 and 11 of the Agreement apply to this DPA. This DPA does not increase those caps or exclude liability that cannot lawfully be excluded.
13. Term
This DPA takes effect when Agreement Version 2.4 becomes applicable to the Customer and the Company processes Personal Information on its behalf and remains in effect for as long as the Company Processes Personal Information under the Agreement. Provisions that by their nature should survive, including Sections 3, 5, 8, 9 and 12, survive termination.
14. Questions and separately agreed terms
No separate signature is required for Schedule A. Contact legal@cutova.ai to request a separately signed form or discuss additional requirements. Changes to this standard DPA follow Section 17 of the Agreement; a later website version does not automatically replace this one.
Lens Software LLC, 12234 Meadowcrest Lane, Jacksonville, FL 32246.
Cutova is a product of Lens Software LLC, Jacksonville, Florida.