DataSapien Terms of Service for Software as a Service Tiers
Last Updated: 4 August 2026 Effective Upon: Customer account creation and acceptance of these Terms, subject to the staged effective dates set out below.
Summary of August 2026 changes
Tier names have been aligned to the DataSapien pricing page. The Instance model that governs deployment and billing has been added to Schedule B. Support commitments have been restated on a UK local time basis.
Tier renaming:
| Previous name | New name |
|---|---|
| Solo | Free |
| Pro | Launch |
| Grow | Scale |
| Enterprise | Sovereign |
Substantive changes:
- The Free tier replaces Solo and is genuinely free. The previous £0.50 per SDK per month charge on the Solo tier is withdrawn. The 50 monthly Active SDK cap is retained.
- Instances are now defined and priced. Scale includes 2 Instances with additional Instances at £500 per Instance per month. Launch is single-Instance only. This model was previously published on the pricing page but was absent from these Terms.
- Scale Active SDK inclusions are pooled across all Instances on the account. The previous per-Country licensing construct on the Grow tier is withdrawn. Separate data residency requirements continue to require separate Instances.
- Payment method for Launch and Scale is stated accurately for the first time. The platform fee and Instance fees are charged to the Customer’s card in advance at the start of each billing period. SDK overage is invoiced in arrears after the billing period closes, payable within 14 days. Invoiced payment terms of 30 days for all charges are a Sovereign inclusion.
- Scale support hours are stated as 08:00 to 18:00 UK time and the support channels for Scale are priority email and chat. Phone support is a Sovereign inclusion.
- Sovereign support is defined by the applicable Master Services Agreement. The previous blanket reference to 24/7 support at this tier is withdrawn. 24/7 cover is available as a priced add-on.
- Schedule A is no longer marked draft, now states an availability commitment for the Scale tier, and expresses all support hours in UK local time rather than GMT.
- Schedule E has been updated to describe accurately the categories of personal data DataSapien processes where a Customer configures Zero-Party Data submission or MeData streaming, and to distinguish DataSapien’s processor and controller roles.
- Definitions of Active SDK and Instance have been added and are consistent with DataSapien’s Master Services Agreement form.
Staged effective dates. Changes that expand or clarify Customer entitlements take effect on 4 August 2026. Changes that reduce a published entitlement or alter billing take effect on the dates below, in accordance with the notice periods in Schedule A (Change Management) and Schedule B (Price Changes).
| Change | Effective |
|---|---|
| Tier renaming, definitions, Instance model, pooled SDK inclusions, Free tier price reduction, Schedule A and Schedule E updates | 4 August 2026 |
| Scale support hours restated to 08:00 to 18:00 UK time; Scale support channels restated to priority email and chat | 3 September 2026 |
| Additional Instance fee applied to existing accounts | 3 October 2026 |
Existing customers on the previous Solo, Pro, Grow or Enterprise tiers transfer to the corresponding new tier automatically with no change to fees, other than the withdrawal of the Solo per-SDK charge.
Contents
- Master Agreement
- Schedule A – Service Level Agreement (SLA)
- Schedule B – Pricing and Licensing
- Schedule C – Branding Guidelines
- Schedule D – Acceptable Use Policy (AUP)
- Schedule E – Data Processing Addendum (DPA)
Master Agreement
1. Agreement Overview
These Terms of Service (“Agreement”) govern your use of the DataSapien Software Platform (“Software”), including the Orchestrator and SDK, provided by DataSapien Limited (“DataSapien”, “we”, “us”).
By creating an account or using the Software, you (“Customer”, “you”, “your”) agree to be bound by this Agreement.
2. Definitions
“Active SDK” means a unique SDK ID and Device ID pairing that has made at least one Platform call within a rolling 30-day period.
“Instance” means a separately configured Orchestrator instance with its own configuration, journey logic, rules, model and API scope, data residency, compliance posture, branding, and language.
“MeData” means data points collected, stored and processed on an end-user device by the SDK in accordance with the Customer’s configuration.
“Zero-Party Data” means data that an end user explicitly consents to share from their device, as configured by the Customer.
“UK time” means the local time in London, United Kingdom (Europe/London), being Greenwich Mean Time or British Summer Time as applicable on the relevant date.
3. Software and Services
3.1 Platform Components
- Orchestrator: A cloud-based interface for low-code and no-code orchestration of SDK functionality including APIs, data journeys, consent flows, and AI.
- Mobile Backend: A cloud-based API server that communicates with SDK instances.
- SDK: A downloadable software library to be embedded into applications for enabling Private Personalisation and Zero-Shared Data, deployed on end-user devices.
3.2 Subscription Services
- Access to the Orchestrator, Mobile Backend and SDKs
- Support tier based on selected plan (Free, Launch, Scale, or Sovereign)
- Optional professional services (training, onboarding, custom development), billed hourly
Support terms are defined in Schedule A – Service Level Agreement (SLA).
4. Account Tiers
| Tier | Includes |
|---|---|
| Free | Self-service access to the Orchestrator and Sandbox app for evaluation, prototyping and testing. One Instance. Capped at 50 monthly Active SDKs; an upgrade to Launch, Scale or Sovereign is required beyond this cap. No platform fee and no per-SDK charge. Self-serve documentation only. |
| Launch | Self-service platform access. One Instance only. Email support with 48 business-hour response. Inclusion: 5,000 monthly Active SDKs. Overage: £0.15 per Active SDK per month. £1,000 per month. |
| Scale | Supported use including Proofs of Concept and multi-Instance deployments. 2 Instances included, additional Instances at £500 per Instance per month. Priority email and chat support. Inclusion: 50,000 monthly Active SDKs pooled across all Instances on the account. Overage: £0.08 per Active SDK per month. £7,500 per month. |
| Sovereign | Named Technical Account Manager, custom SLA, flexible deployment including customer-hosted and on-premises, negotiated volume economics, and procurement-friendly commercial terms, all under a separate Master Services Agreement. |
Deployment for Free, Launch and Scale is DataSapien-hosted. Deployment options for Sovereign are set out in Schedule B, Section 6.
5. SDK Licensing and Usage
- SDK inclusion volumes vary by tier and are detailed in Schedule B.
- Each SDK is activated via a licence key provided by DataSapien.
- Monthly Active SDK volume in excess of the tier inclusion is billed at the tier overage rate set out in Schedule B.
- On the Scale tier, the Active SDK inclusion is pooled across all Instances on the account.
- SDK licences are non-transferable and managed via the DataSapien Orchestrator.
- Adjustments to SDK volume require 30 days’ notice.
6. Instances
- Each Instance is separately configured and separately provisioned.
- Free and Launch tiers are single-Instance only.
- Scale includes 2 Instances. Additional Instances are charged at £500 per Instance per month.
- Development, staging and production deployments each require their own Instance and are each chargeable where they exceed the tier inclusion.
- Sovereign Instance inclusions are set out in the applicable Master Services Agreement.
7. Pricing and Payment
7.1 Self-service tiers (Launch and Scale)
Launch and Scale are self-service tiers. Charges arise in two ways:
- Platform fee and Instance fees, by card in advance. By subscribing you authorise DataSapien to charge a valid payment card at the start of each monthly billing period, on a recurring basis, for the platform fee and any Instance fees for that period.
- SDK overage, invoiced in arrears. SDK overage for a billing period is invoiced once that period has closed and is payable within 14 days of invoice date. Hourly professional services are invoiced on the same terms.
You must maintain a valid payment card on the account for the duration of your subscription, and until any final overage invoice has been settled following cancellation. Where an overage invoice remains unpaid after its due date, DataSapien may charge the outstanding amount to the card held on the account.
All amounts are charged in pounds sterling and are exclusive of VAT and other applicable taxes.
Where a card payment is declined, DataSapien will retry and notify you. If payment remains outstanding 7 days after the first failed attempt, DataSapien may suspend access to the affected Instances. Late payment of an overage invoice may also result in suspension. Continued non-payment may result in termination under Section 12.2.
The Free tier requires no payment card.
7.2 Sovereign tier
Sovereign engagements are invoiced, with payment terms of 30 days from invoice date, or such other terms as are agreed in the applicable Master Services Agreement. Quarterly billing is available for qualifying accounts. Platform fees are invoiced in advance and overage in arrears.
Late payment of undisputed invoiced sums may result in suspension of service and attracts interest under the Late Payment of Commercial Debts (Interest) Act 1998.
8. Intellectual Property
8.1 All intellectual property rights in the DataSapien Software and related assets remain exclusively with DataSapien. No transfer or assignment of IP is implied or granted.
8.2 You may not modify, sublicense, resell, reverse-engineer, or redistribute the Software or SDKs, except as explicitly permitted by this Agreement or under a separate written agreement with DataSapien.
8.3 Authorised Resellers and White-Label Partners. Resale, white-labelling, embedding within a third-party platform for onward distribution, or sublicensing of the Software to third parties is permitted only under a separate written reseller or channel partner agreement with DataSapien, or under reseller terms scheduled to a Master Services Agreement. The standard Tier pricing set out in Schedule B does not apply to authorised reseller or white-label arrangements; commercial terms, branding rights, and end-customer obligations applicable to such partnerships are set out in the relevant agreement. Customers wishing to enter a reseller or white-label arrangement should contact partnerships@datasapien.com.
8.4 Any jointly developed assets, adaptations, or derivative works incorporating the DataSapien platform shall be jointly scoped and governed by a separate written agreement.
8.5 For clarity, any intellectual property developed independently by the Customer, including that which leverages or is built upon DataSapien technology, shall remain the sole and exclusive property of the Customer.
8.6 Nothing in this clause shall prevent the Customer from independently developing, owning, or commercialising products or services that make use of permitted outputs of the DataSapien platform, provided that such use does not reverse engineer, duplicate, or disclose the proprietary workings of the DataSapien Software.
9. Branding
Use of the optional “DataSapien Inside” trustmark is governed by Schedule C and available via licence.
10. Privacy, Security and Data Protection
10.1 Zero-Shared Data
- The Software processes personal data on-device by default. MeData is stored and processed locally on the end-user device.
- DataSapien has no access to MeData held on end-user devices.
- Data is only shared from the app where the end user explicitly consents, as Zero-Party Data, and only as configured by the Customer.
10.2 Zero-Party Data destination
Where the Customer configures a Zero-Party Data submission or a MeData stream, the destination depends on the configuration selected by the Customer:
- Customer endpoint: where the Customer configures submission to its own API endpoint, the data passes to the Customer’s systems and is not stored by DataSapien.
- DataSapien-hosted storage: where the Customer configures submission to Orchestrator storage, DataSapien stores the submitted data as a processor on the Customer’s behalf, in accordance with Schedule E.
Customers should select the configuration appropriate to their own regulatory position. Schedule E sets out the categories of personal data DataSapien processes in each case.
10.3 Account Data
- DataSapien stores Account Data (for example administrator details, billing information, and system logs) securely.
- Data is encrypted and access-controlled.
10.4 Data protection compliance
Customers subject to UK GDPR, EU GDPR, or similar data protection laws will have data processing governed by Schedule E – Data Processing Addendum (DPA), which includes:
- Role definitions
- Subprocessor transparency and objection rights
- Technical and organisational safeguards, and DataSapien’s current certification position
- Breach notification and audit rights
11. Confidentiality
Each party agrees to protect all confidential information shared under this Agreement. This obligation will remain in effect for five (5) years following termination.
Obligations with respect to trade secrets survive indefinitely.
12. Term and Termination
This Agreement remains in effect until terminated.
12.1 Termination by Customer
- Launch and Scale subscriptions may be cancelled at any time from the Orchestrator. Service continues to the end of the billing period already paid for. The platform fee for that final period is not refundable and no pro-rata refund applies.
- SDK overage accrued during the final billing period is invoiced on the normal cycle after that period closes. Your card authorisation must remain valid until that final invoice has been settled.
- Annual subscriptions, where offered, are cancellable at the end of the then-current term.
- Sovereign termination rights are set out in the applicable Master Services Agreement.
12.2 Termination by DataSapien
- 30 days’ written notice, or immediate termination for breach, fraud, or unlawful use.
12.3 Post-Termination
- SDKs must be deactivated.
- Outstanding amounts become due.
- Key terms (for example IP, confidentiality, liability, privacy, indemnity) survive.
13. Acceptable Use
You may not:
- Use the Software unlawfully or harmfully.
- Bypass access controls or licence mechanisms.
- Reverse-engineer SDK components.
See Schedule D – Acceptable Use Policy.
14. Business Continuity
DataSapien maintains operational and disaster recovery protocols to support service resilience. Recovery point and recovery time objectives are available on request and may be committed contractually at the Sovereign tier.
15. Indemnification by DataSapien
We will defend and indemnify you against third-party claims alleging that the Software infringes a copyright, patent, or trademark.
Our obligations under this section are conditional upon you providing us with:
(a) Prompt written notice of the claim (b) Sole control of the defence and settlement (c) Reasonable cooperation
If needed, we may modify or replace the Software or terminate your licence with a refund of unused fees.
This obligation excludes claims caused by:
- Your modifications or combinations.
- Use contrary to the Agreement.
16. Limitation of Liability
Total liability is limited to fees paid in the 12 months preceding the claim, except for:
- IP infringement indemnity (Section 15).
- Breach of confidentiality.
- Gross negligence or wilful misconduct.
- Liability that cannot legally be excluded.
Sovereign customers may agree alternative liability provisions in a Master Services Agreement.
17. Force Majeure
Neither party is liable for delays or failures caused by events beyond their reasonable control.
18. Feedback
You grant DataSapien a royalty-free licence to use suggestions or feedback to improve our products or services.
19. Audit and Compliance
- DataSapien is not currently certified to ISO/IEC 27001 and has not completed a SOC 2 Type II examination. Our information security controls are designed and operated in alignment with those frameworks.
- Security documentation, including our controls mapping to ISO/IEC 27001 and SOC 2 Type II, is available under NDA on written request.
- Additional audit rights are defined in the DPA.
20. Governing Law and Dispute Resolution
This Agreement is governed by the laws of England and Wales.
Disputes follow this order:
- Good-faith negotiation
- Optional non-binding mediation
- English courts (exclusive jurisdiction)
21. Schedules (Incorporated by Reference)
- Schedule A – Service Level Agreement (SLA)
- Schedule B – Pricing and Licensing
- Schedule C – Branding Guidelines
- Schedule D – Acceptable Use Policy
- Schedule E – Data Processing Addendum (DPA)
The SLA metrics defined in Schedule A apply to the Free, Launch and Scale tiers. Sovereign customers, and authorised resellers and channel partners, have service levels defined in the applicable Master Services Agreement or partner agreement, which override Schedule A in full for that customer or partner.
22. Sovereign Engagements
For customers requiring a custom enterprise agreement, dedicated security reviews, customer-hosted or on-premises deployment, specific data residency, or planning to license more than 500,000 Active SDKs, please contact our sales team. These engagements are governed by a separate Master Services Agreement (MSA).
Contact: sales@datasapien.com
23. Contact
DataSapien Limited, Monomark House, 27 Old Gloucester Street, London WC1N 3AX, UK Email: partnerships@datasapien.com
Schedule A – Service Level Agreement (SLA)
This Schedule A forms part of the DataSapien Terms of Service and defines the service levels for use of the Software provided by DataSapien Limited.
1. Scope
This SLA covers:
- The Orchestrator (cloud-based platform, including its user interface and REST API)
- The Mobile Backend (cloud-based API)
- SDK activation services and management APIs
This SLA does not apply to:
- Customer applications, infrastructure, devices, or internet access
- Third-party services not operated by DataSapien, including push notification services, Open Banking providers, and identity providers
- On-device SDK functionality. The SDK is designed to operate independently of network availability. On-device inference, cached journeys, and locally held MeData continue to function during a Mobile Backend interruption
- Professional services
- Features made available for early access, preview or beta evaluation
- Configuration authored by the Customer in the Orchestrator, including journey logic, rules, scripts and audience definitions
2. Availability commitment
| Tier | Monthly availability target |
|---|---|
| Free | None. No availability commitment applies |
| Launch | None. Commercially reasonable endeavours |
| Scale | 99.5% per calendar month, measured separately for the Orchestrator and the Mobile Backend |
| Sovereign | As set out in the applicable Master Services Agreement |
Availability is measured against production Instances only. Sandbox, development, staging and test Instances are excluded.
3. Scheduled Downtime
Scheduled Downtime means downtime for maintenance or system upgrades where notice is provided at least 72 hours in advance for Launch and Scale, performed during off-peak hours (typically 22:00 to 04:00 UK time), and not exceeding 4 hours per calendar month.
Scheduled Downtime is excluded from availability calculations.
Emergency maintenance required to address a security vulnerability or imminent service failure may be performed with such notice as is reasonably practicable and is excluded from availability calculations.
4. Tier: Free
Free is a self-service evaluation tier. No formal SLA applies.
| Service Metric | Commitment |
|---|---|
| Support Hours | None: self-serve documentation only |
| Initial Response Time | None |
| Support Channels | Public documentation and developer portal |
| Incident Updates | Posted to status.datasapien.com when applicable |
| Maintenance Notice | Posted to status.datasapien.com |
Free tier customers are not eligible for SLA credits.
5. Tier: Launch
| Service Metric | Commitment |
|---|---|
| Support Hours | Monday to Friday, 09:00 to 18:00 UK time, excluding UK public holidays |
| Initial Response Time | Within 48 business hours for all support tickets |
| Support Channels | Email only: support@datasapien.com |
| Incident Updates | Within 48 hours |
| Maintenance Notice | 72 hours minimum |
Launch tier customers are not eligible for SLA credits.
6. Tier: Scale
| Service Metric | Commitment |
|---|---|
| Support Hours | Monday to Friday, 08:00 to 18:00 UK time, excluding UK public holidays |
| Initial Response Time | Critical: within 4 business hours. All other: within 1 business day |
| Support Channels | Priority email and chat |
| Incident Updates | Critical: every 4 business hours. All other: within 1 business day |
| Maintenance Notice | 72 hours minimum |
| Availability | 99.5% per calendar month |
7. Tier: Sovereign
Service levels for Sovereign customers are defined in the applicable Master Services Agreement and override this Schedule A in full. Sovereign engagements include as standard:
- A named Technical Account Manager and a named escalation contact
- Email, telephone and a dedicated support chat group
- A custom SLA with an availability commitment, defined priority levels, and service credits
- Bespoke metrics where required, including recovery point objective, recovery time objective, and priority definitions
Extended cover, including cover outside UK business hours and 24/7 critical incident cover, is available as a priced add-on.
Contact: sales@datasapien.com
8. SLA Exclusions
In addition to the scope exclusions in Section 1, this SLA does not apply to:
- Issues caused by Customer hardware, network, or software
- Force majeure events
- Downtime of third-party services not operated by DataSapien
- SDKs used outside licensed scope or in unsupported environments
- Any period during which the account is suspended for non-payment or breach of the Acceptable Use Policy
9. SLA Credits
Available only for the Scale tier. Sovereign credits are as set out in the applicable Master Services Agreement.
| Item | Term |
|---|---|
| Eligibility | Measured monthly availability below the 99.5% target for the affected component |
| Credit | 10% of the monthly platform fee for the affected month |
| Claim Deadline | Must be submitted to support@datasapien.com within 30 days of the end of the affected month |
| Form of Credit | Applied against the next invoice. Credits are not payable in cash and are not refundable |
| Exclusive Remedy | Credits are the sole and exclusive financial remedy for failure to meet the availability commitment |
10. Change Management
We may update this SLA periodically. Changes that reduce a Customer entitlement will be communicated at least 30 days in advance.
Schedule B – Pricing and Licensing
This Schedule B forms part of the DataSapien Terms of Service and sets out the subscription pricing, Instance model, SDK licensing model, and billing structure applicable to the Customer’s use of the Software and Services.
1. Account Tiers
| Tier | Platform Fee (Monthly) | Instances | Active SDK Inclusion | Overage Rate | Support | Payment Terms |
|---|---|---|---|---|---|---|
| Free | £0 | 1 | 50 monthly Active SDKs (hard cap) | Not applicable. Upgrade required beyond 50 | Self-serve documentation | Not applicable |
| Launch | £1,000 | 1 only | 5,000 monthly Active SDKs | £0.15 per Active SDK per month | Fee by card in advance; overage invoiced, 14 days | |
| Scale | £7,500 | 2 included, additional at £500 per Instance per month | 50,000 monthly Active SDKs, pooled across all Instances | £0.08 per Active SDK per month | Priority email and chat | Fee by card in advance; overage invoiced, 14 days |
| Sovereign | Custom | Custom | Custom | Negotiated | Named Technical Account Manager and custom SLA | 30 days, invoiced |
Deployment for Free, Launch and Scale is DataSapien-hosted. Sovereign deployment options are set out in Section 6.
2. Instances
2.1 Instance model
An Instance is a separately configured Orchestrator instance with its own configuration, journey logic, rules, model and API scope, data residency, compliance posture, branding, and language.
- Free and Launch are single-Instance tiers. Additional Instances are not available at these tiers.
- Scale includes 2 Instances. Each additional Instance is charged at £500 per Instance per month.
- Development, staging and production deployments each require their own Instance. Customers should account for this when selecting a tier.
- Adding an Instance takes effect immediately on provisioning and is charged from the start of the following billing cycle.
2.2 Multi-territory deployment and data residency
Active SDK inclusions on the Scale tier are pooled across all Instances on the account, irrespective of the territories in which those SDKs are active. There is no per-territory platform fee at the Scale tier.
Instance charges continue to apply. Because an Instance carries its own data residency, compliance posture, branding and language, a deployment in a further territory will in practice require its own Instance and is charged accordingly under Section 2.1. The same applies where a Customer requires data to be held in a specific jurisdiction or requires separate compliance postures for different territories. Data residency options beyond the United Kingdom are available at the Sovereign tier.
2.3 Tier suitability and volume thresholds
Free tier is intended for evaluation, prototyping and testing only. Customers reaching the 50 monthly Active SDK cap must upgrade to Launch, Scale or Sovereign to continue activating SDKs.
Launch tier is intended for self-service development and single-product, single-Instance deployments with predictable, modest SDK volumes. Customers requiring more than one Instance must upgrade to Scale.
Customers with monthly Active SDK volume materially exceeding 50,000, or approaching 500,000, should contact sales regarding the Sovereign tier. DataSapien reserves the right to review tier suitability at any billing cycle and require an upgrade where usage materially exceeds the intended scope of the tier.
3. SDK Licensing and Pricing
3.1 Licensing model
- SDKs are licensed on a monthly active basis.
- An Active SDK is a unique SDK ID and Device ID pairing that has made at least one Platform call within a rolling 30-day period.
- Each SDK is tied to a unique activation key for a single user device.
- All SDK licences are non-transferable and managed via the DataSapien Orchestrator.
3.2 SDK overage pricing
Monthly Active SDKs in excess of the tier inclusion are billed monthly in arrears at the tier overage rate set out in Section 1. The tier inclusion is consumed first; the overage rate applies only to volume above inclusion.
On the Scale tier, the 50,000 Active SDK inclusion is pooled across all Instances on the account and is consumed in aggregate before overage applies.
Overage rates are flat per Active SDK and do not vary by volume. Customers seeking volume-based or graduated pricing should contact sales regarding the Sovereign tier.
4. Billing and Payment Terms
- Platform fees and Instance fees are billed monthly in advance.
- SDK overage usage fees are billed monthly in arrears.
- SDK fees are not prorated. An SDK is billed as active if telemetry is received in the period.
- Instance fees are not prorated for part months.
- Launch and Scale: the platform fee and Instance fees are charged by card in advance at the start of each billing period. SDK overage is invoiced in arrears once the period closes and is payable within 14 days of invoice date. A valid payment card must be maintained on the account. See Master Agreement Section 7.1.
- Sovereign is invoiced, with terms of 30 days from invoice date, or such other terms as are agreed in the applicable Master Services Agreement. Quarterly billing is available for qualifying accounts. See Master Agreement Section 7.2.
5. Upgrades, Downgrades and Term Changes
- Upgrades, for example from Launch to Scale, may be requested at any time and take effect at the next billing cycle.
- Downgrades require 30 days’ notice and are processed at the end of the current billing period.
- Adding an Instance to a Scale subscription is treated as an upgrade and is charged from the next billing cycle.
- Sovereign usage commitments and custom pricing are governed by a separate Master Services Agreement.
6. Sovereign Pricing, Deployment and Volume Licensing
Sovereign customers may negotiate:
- Annual or multi-year platform access
- Custom SDK pricing, including volume-based, graduated or committed-volume rates
- Custom Instance inclusions
- Multi-territory licensing and specified data residency
- Committed usage discounts and payment schedules
- Tailored invoicing and reporting requirements
- Reseller, channel partner or panel operator authority
Sovereign deployment options are:
- DataSapien-hosted (standard)
- Customer-hosted on the Customer’s own cloud tenancy, hybrid, or on-premises
- Data residency in the United Kingdom, European Union, United States, or elsewhere by agreement
These terms are documented in a Master Services Agreement.
Contact: sales@datasapien.com
7. Reseller, Channel Partner and White-Label Pricing
The Tier pricing in this Schedule B does not apply to authorised reseller, channel partner, white-label or embedded-distribution arrangements. Such arrangements are governed by a separate reseller or channel partner agreement, or by reseller terms scheduled to a Master Services Agreement, which set their own commercial terms including any partner discounts, revenue share, finder’s fees, margin, or per-deployment licensing structures. See Master Agreement Section 8.3.
Where a reseller or channel partner deploys the Platform for an end client, each end client is deployed on its own Instance. Instance fees and pooled SDK overage roll up to the partner account unless otherwise agreed.
Contact: partnerships@datasapien.com
8. Taxes
All fees are quoted exclusive of taxes. VAT, sales tax, or other required taxes will be added based on Customer location and applicable laws.
9. Price Changes
DataSapien may update pricing with 60 days’ written notice. Changes apply only to platform fees, Instance fees and SDK usage arising after the notice period. Sovereign pricing is fixed for the term agreed in the applicable Master Services Agreement.
10. Professional Services
Optional services such as advanced training, onboarding, integration support, and code review are available on request.
Unless otherwise agreed in a separate Statement of Work or Master Services Agreement:
- Professional services are billed at £200 per hour.
- Minimum billing increment: 1 hour.
- Travel, accommodation, and related expenses, if applicable, will be invoiced separately.
Sovereign engagements include a defined allocation of onboarding, training, code review and roadmap engagement as set out in the applicable Master Services Agreement. Effort beyond that allocation is chargeable at the rate above.
Schedule C – Branding Guidelines
(No changes from previous version.)
This Schedule C forms part of the DataSapien Terms of Service and governs the permitted use of the DataSapien brand, including its logos, SDK attribution, and the optional “DataSapien Inside” trustmark.
1. Licensing and Scope of Use
You are granted a limited, non-exclusive, revocable licence to use DataSapien brand assets under the following conditions:
Tier 1: Pre-Approved Use (No Approval Needed) – You may use brand assets for the standard uses listed in Section 2, provided you adhere to these guidelines.
Tier 2: Custom Use (Approval Required) – All other uses, including public press releases, joint marketing campaigns, advertisements, and case studies, require prior written approval from DataSapien.
2. Pre-Approved Uses
The following uses do not require prior approval if brand assets are used unaltered and within the styling rules defined in Section 4:
- In-app or on-device attribution, for example “Powered by DataSapien” or “DataSapien Inside”
- References in user-facing help documentation or privacy notices
- Internal stakeholder or B2B client presentations
- Trust-building UX elements, for example privacy settings screens and onboarding flows
These uses must not suggest partnership, endorsement, or certification unless explicitly approved.
3. Prohibited Uses
You may not:
- Alter, distort, animate, or modify any DataSapien logo or wordmark
- Use the brand in your company name, product name, or domain
- Imply endorsement, certification, or official partnership without written agreement
- Display brand assets alongside illegal, misleading, or offensive content
- Use DataSapien brand assets in any context that disparages DataSapien, its technology, or its services
4. Visual and Technical Guidelines
All brand assets must:
- Maintain minimum clear space equal to one times the height of the logo
- Use approved versions, with no cropping, colour inversion, or overlay effects
- Follow the colour and sizing rules defined at our Brand Resource Center
You can find logos, icons, and implementation guides at datasapien.com/brand-resources
5. Messaging and Attribution
5.1 Pre-Approved Messaging
You may use the following approved phrases in your UI, documentation, or marketing assets:
- “Powered by DataSapien”
- “Private Personalisation by DataSapien SDK”
- “User data protected with DataSapien Inside”
- “Privacy-enhanced by DataSapien”
- “On-device intelligence enabled by DataSapien”
You may not imply that DataSapien is responsible for your end-user data practices, unless your implementation has been reviewed and approved.
6. Co-Branded Campaigns and Approvals
If you wish to use brand assets in a joint go-to-market campaign, press release, customer case study, or advertising collateral, you must request approval via design@datasapien.com.
Requests should include a mockup or example of the proposed use and be submitted at least 10 business days before planned publication.
7. Termination and Revocation
All rights to use DataSapien branding terminate immediately upon:
- Expiry or termination of your Agreement
- Breach of these guidelines
- Written revocation of permission by DataSapien
Upon termination, you must remove or disable all brand references within 7 days.
Schedule D – Acceptable Use Policy (AUP)
(No changes from previous version.)
This Acceptable Use Policy (“AUP”) forms part of the DataSapien Terms of Service (“Agreement”) between DataSapien Limited (“DataSapien”) and the Customer.
By accessing or using the Software, SDKs, APIs, or services, you agree to comply with this AUP.
1. Prohibited Conduct
You may not use the Software or related services to:
1.1 Illegal or harmful activity
- Transmit or store material that is illegal, defamatory, deceptive, or otherwise unlawful
- Publish or disseminate content that constitutes hate speech, harassment, or misinformation, or incites or promotes violence
- Engage in or facilitate phishing, spamming, or the distribution of unsolicited bulk messages
- Promote or support malware, ransomware, or other malicious code
1.2 Security violations
- Attempt to gain unauthorised access to any DataSapien or third-party system, network, or data
- Probe, scan, or test for vulnerabilities without explicit written permission
- Bypass, disable, or interfere with authentication, access controls, or licensing mechanisms
1.3 Interference with service
- Disrupt, degrade, or overload platform performance
- Launch denial-of-service or similar disruptive attacks
- Use automated systems to mine, scrape, or stress-test platform APIs
2. SDK-Specific Restrictions
You may not:
- Reverse engineer, decompile, or disassemble the SDK
- Attempt to activate SDKs without valid activation keys issued by DataSapien
- Redistribute SDKs to third parties without prior written consent (see Master Agreement Section 8.3)
- Use SDKs outside their licensed device or agreed usage scope
3. Data Misuse
You are solely responsible for your relationship with your end users. This includes providing clear, transparent notice and obtaining all necessary rights and consents for the data you process using the Software.
You may not:
- Collect, process, or share personal data without a lawful basis or valid consent
- Mislead users about what data is being used or shared
- Circumvent or modify SDK defaults to extract personal insights without opt-in
- Attempt to bypass the Zero-Shared Data model or simulate platform impersonation
4. Brand and Platform Integrity
You may not:
- Misrepresent your use of the Software, including falsely implying affiliation, partnership, or certification by DataSapien
- Remove, alter, or obscure legal notices, attribution marks, or licensing information
- Use the Software to build or support a competing product
- Conduct any performance, vulnerability, or benchmark testing, or publish any analysis or comparison of the Software, without prior written consent from DataSapien
5. Enforcement and Consequences
DataSapien may suspend or terminate your account or specific components of it, without notice, if:
- This AUP is violated
- There is a credible security or legal risk
- Your use threatens the reliability or integrity of the platform
Where appropriate, DataSapien will provide notice and an opportunity to cure violations, unless immediate action is necessary to protect systems or comply with law.
6. Reporting Violations
To report misuse or suspected violations of this AUP, please contact DPO@datasapien.com
7. Updates
This AUP may be updated periodically. Material changes will be communicated through your registered account or displayed on our website.
Schedule E – Data Processing Addendum (DPA)
This Data Processing Addendum (“DPA”) forms part of the DataSapien Terms of Service (“Agreement”) between DataSapien Limited and the Customer (each a “Party” and collectively, the “Parties”).
This DPA applies where DataSapien processes personal data on behalf of the Customer under the Agreement, in accordance with the UK GDPR, EU GDPR, or similar data protection laws.
Sovereign customers may execute a separate data processing addendum under a Master Services Agreement, which overrides this Schedule E in full for that customer.
1. Definitions
Controller: the party determining the purposes and means of processing personal data.
Processor: a party acting on behalf of a Controller in processing personal data.
Personal Data, Data Subject, Processing, and other capitalised terms have the meanings given in the UK GDPR.
2. Roles and Scope
2.1 On-device processing
MeData is stored and processed on the end-user device by the SDK, in accordance with the configuration determined by the Customer. The Customer is the Controller of that processing. DataSapien has no access to MeData held on end-user devices and no technical means of obtaining access to it.
The SDK does not transmit MeData content to DataSapien except where the Customer configures a Zero-Party Data submission or a MeData stream to DataSapien-hosted storage under Section 2.2(c).
2.2 DataSapien as Processor
DataSapien acts as Processor on the Customer’s behalf in respect of:
(a) Account Data, including administrator names and email addresses, billing contact information, and system logs.
(b) Usage metadata and SDK telemetry, including SDK ID and Device ID pairings used to determine Active SDK counts for billing and operational purposes. The Parties acknowledge that SDK ID and Device ID pairings constitute pseudonymised personal data.
(c) Platform data, where and to the extent the Customer configures it, including:
- Zero-Party Data submissions stored in Orchestrator storage
- MeData streamed to the Orchestrator
- Consent records and the associated audit trail
- Audience and segment membership computed by the Mobile Backend for targeting purposes
- Push notification tokens
(d) Support and diagnostic data provided by or on behalf of the Customer in the course of a support request.
Where the Customer configures Zero-Party Data submission to its own API endpoint rather than to Orchestrator storage, DataSapien does not receive or store the submitted payload, and the data described in Section 2.2(c) is limited accordingly.
2.3 DataSapien as Controller
DataSapien acts as an independent Controller in respect of:
- Its own billing, account administration and financial records
- Aggregate service telemetry used to operate, secure, monitor and improve the platform
This does not extend to the content of MeData or Zero-Party Data.
3. Customer Responsibilities
The Customer:
- Acts as Controller in respect of the processing described in Sections 2.1 and 2.2
- Confirms it has a lawful basis to collect, process and share personal data
- Determines the configuration of the Software, including what data is collected, what is submitted, and where it is submitted
- Is solely responsible for end-user disclosures and for obtaining consent where required
- Is solely responsible for its own regulatory compliance. DataSapien is not authorised or regulated by the Financial Conduct Authority and provides no regulated service
4. Processor Obligations
DataSapien agrees to:
- Process personal data only on documented instructions from the Customer, including via this Agreement and via Customer configuration of the Software
- Ensure personnel are subject to confidentiality obligations
- Implement and maintain appropriate technical and organisational measures (see Section 7)
- Maintain logical separation between Instances
- Provide reasonable assistance to the Customer in responding to data subject rights requests, reporting personal data breaches, and carrying out data protection impact assessments where required
- Delete or return personal data on termination of the Agreement in accordance with Section 10
DataSapien will not use personal data processed under Section 2.2 to train or improve models made available to any other customer without the Customer’s prior written consent.
5. Subprocessors
5.1 Appointment
DataSapien uses subprocessors for hosting and service delivery. These are listed in the DataSapien Subprocessor Directory, available on written request to DPO@datasapien.com.
5.2 Notification and objection
- DataSapien will notify the Customer at least 30 days before adding or replacing a subprocessor
- The Customer may object on reasonable data protection grounds within that period
- If the objection cannot be resolved, the Customer may terminate the affected service without penalty
6. International Transfers
Customer Instance data for Free, Launch and Scale tiers is hosted in the United Kingdom.
Where personal data is transferred outside the UK or EEA:
- Transfers will be subject to the UK International Data Transfer Agreement, the UK Addendum to the Standard Contractual Clauses, or the Standard Contractual Clauses approved by the European Commission, as applicable
- DataSapien will implement supplementary safeguards including encryption and access controls
7. Security Measures
DataSapien maintains security measures appropriate to the risk, including:
- Encryption in transit and at rest
- Role-based access control and multi-factor authentication for administrative access
- Logical separation between Instances
- Regular third-party penetration testing
- Secure development practices
- Procedures designed and operated in alignment with ISO/IEC 27001 and SOC 2 Type II
DataSapien is not currently certified to ISO/IEC 27001 and has not completed a SOC 2 Type II examination. Details of our controls, including our mapping to those frameworks, are available under NDA on written request.
8. Personal Data Breaches
In the event of a confirmed personal data breach affecting Customer personal data:
- DataSapien will notify the Customer without undue delay, and in any event within 48 hours of confirmation
- The notice will describe the nature and likely impact of the breach, the measures taken or proposed, and a contact point for further enquiries
- DataSapien will provide such further information as the Customer reasonably requires to meet its own notification obligations to a supervisory authority or to affected data subjects
Sovereign customers may agree a shorter notification period in a Master Services Agreement.
9. Audit and Information Access
- DataSapien will provide documentation reasonably necessary to demonstrate compliance with this DPA
- On reasonable written request and subject to confidentiality, the Customer may receive security audit reports and controls documentation, and may conduct an audit no more than once per calendar year, at the Customer’s cost
- An additional audit may be conducted following a confirmed personal data breach affecting the Customer, or where required by a supervisory authority
10. Retention and Deletion
- DataSapien retains personal data processed under Section 2.2 for the duration of the Agreement
- On termination, DataSapien will delete Customer Instance data within 30 days of the effective date of termination, or return it to the Customer where the Customer so requests before that date
- Backup copies are purged within 90 days of the effective date of termination
- A certificate of deletion is available on written request
11. Duration
This DPA remains in effect for as long as DataSapien processes personal data on behalf of the Customer under the Agreement.
12. Precedence
In the event of a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict. Where a Sovereign customer has executed a data processing addendum under a Master Services Agreement, that addendum prevails over this Schedule E in full.
13. Contact
Questions or concerns related to this DPA may be directed to:
Data Protection Officer, DataSapien Limited Email: DPO@datasapien.com
Annex 1: Details of Processing
| Field | Detail |
|---|---|
| Subject matter | Provision of the Software, platform access, and support services to the Customer |
| Duration | The term of the Agreement, and thereafter as set out in Section 10 |
| Nature of processing | Hosting, storage, transmission, support, billing, diagnostics, and the computation of audience membership for targeting where configured by the Customer |
| Purpose | Delivery of the Software and Services, billing, platform security and operations, and the Customer’s own configured purposes |
Categories of personal data and data subjects:
| Category | Data subjects | Basis on which processed |
|---|---|---|
| Account Data: name, email, billing contact information, login credentials | Customer staff and administrators | Processor |
| Usage metadata and SDK telemetry: SDK ID and Device ID pairings, licence activations, API call logs | End users of the Customer’s application (pseudonymised) | Processor |
| Zero-Party Data submissions, where configured to Orchestrator storage | End users of the Customer’s application | Processor. Categories determined by the Customer’s journey configuration |
| MeData streams, where configured | End users of the Customer’s application | Processor. Categories determined by the Customer’s configuration |
| Consent records and audit trail | End users of the Customer’s application | Processor |
| Audience and segment membership, push notification tokens | End users of the Customer’s application | Processor |
| Support and diagnostic data | Customer staff, and end users where included by the Customer in a support request | Processor |
| Billing and financial records; aggregate service telemetry | Customer staff and administrators | Independent Controller |
MeData held on end-user devices is not processed by DataSapien and is outside the scope of this Annex.
