1. The Service
Coapro evaluates prompts and file attachments submitted to third-party AI assistants against a policy you configure, applies the resulting decision, records the outcome, and generates coaching feedback for your personnel. It comprises a browser extension, desktop agents, an administrative console, and a hosted backend.
The Service does not block every route by which data can reach an AI assistant, and we do not represent that it does. Its coverage is described in the documentation and changes as those assistants change.
2. Your monitoring obligations
The Service records the content of communications your personnel send to AI assistants. You are the controller of that data and you are solely responsible for the lawfulness of the monitoring. You represent and warrant that, before deploying the Service to any individual, you will:
- give that individual clear written notice of the monitoring, its purpose, and the categories of data recorded;
- obtain any consent, and complete any consultation, works council agreement, impact assessment or filing, required by the law applying to that individual;
- maintain a lawful basis for the processing for as long as it continues; and
- not deploy the Service to capture communications that are legally privileged, or that you know to concern an individual’s health, union membership, or other protected characteristics.
The Service will not record captured content until an administrator confirms in the product that this notice has been given. That confirmation is stored with their name, the date, and the wording they agreed to. We provide notice templates as a convenience; they are not legal advice and do not transfer this responsibility to us.
3. Accounts and administrators
You are responsible for your administrators’ actions, for keeping credentials secure, and for promptly removing access when a person’s role ends. Roles that can read verbatim prompt content should be granted narrowly; the Service logs their use.
4. Customer Data and ownership
“Customer Data” means the prompts, attachment metadata, events, coaching records and configuration processed by the Service on your behalf. As between the parties, you own Customer Data. You grant us a licence to process it solely to provide, secure and support the Service.
We may use aggregated and de-identified data that cannot reasonably be associated with you or any individual to improve the Service. We do not use Customer Data to train machine-learning models, and we do not permit our sub-processors to do so.
5. Acceptable use
You will not, and will not permit anyone to:
- use the Service to monitor anyone who has not received the notice described in section 2;
- use the Service for covert surveillance, or to target an individual on the basis of a protected characteristic;
- use recorded content for a purpose you did not disclose in your notice;
- attempt to circumvent role restrictions on verbatim content; or
- resell, sublicense or reverse-engineer the Service.
6. Fees
Fees, billing period and seat count are set out in your order. Fees are payable in advance and are non-refundable except as these Terms expressly state. We may change fees on renewal with at least thirty days’ written notice.
7. Confidentiality
Each party will protect the other’s confidential information with at least reasonable care and use it only to perform under these Terms. Customer Data is your confidential information.
8. Security
We maintain administrative, technical and organizational measures designed to protect Customer Data, described in our security documentation. We will notify you without undue delay after becoming aware of a breach affecting your Customer Data.
9. Warranties and disclaimer
We warrant that the Service will perform materially as documented. We do not warrant that the Service will detect or prevent every disclosure of sensitive information. Detection is based on pattern matching and on the policy you configure; it will produce both false positives and false negatives. The Service is one control among several and is not a substitute for your own data protection program. Except as stated, the Service is provided “as is”.
10. Indemnity
You will defend and indemnify us against claims brought by your personnel or a regulator arising from your deployment of the Service without the notice, consent or assessments required by section 2. We will defend and indemnify you against third-party claims that the Service infringes intellectual property rights.
11. Limitation of liability
Neither party is liable for indirect or consequential loss. Each party’s aggregate liability is limited to the fees paid or payable in the twelve months before the claim. These limits do not apply to your indemnity under section 10, to either party’s breach of confidentiality, or to liability that cannot lawfully be limited.
12. Term, termination and deletion
Either party may terminate for material breach not cured within thirty days. On termination you may export Customer Data for thirty days, after which we will delete it within a further thirty days except where retention is legally required.
13. Changes
We may update these Terms on at least thirty days’ notice. If a change materially reduces your rights you may terminate before it takes effect and receive a pro-rata refund of prepaid fees.
14. General
Governing law and venue are set out in your order. If any provision is unenforceable the remainder continues in effect. These Terms, your order and the Data Processing Addendum are the entire agreement.