Attribute
Log in

Terms of Service

Effective Date: August 3, 2026
Last Updated: August 30, 2026

These Terms of Service ("Terms") are a binding agreement between Ultimate, Inc., which offers the Services under the Attribute brand ("Attribute," "we," "us," or "our"), and the person or entity that accepts these Terms ("you"). By clicking to accept, executing an Order Form that incorporates these Terms, creating an Account, or accessing or using the Services, you agree to these Terms. If you do not agree, do not access or use the Services.

If you accept these Terms for a company, employer, customer, or other organization, you represent that you have authority to bind that organization. In that case, "you" and "Customer" refer to the organization, and each individual using the Services for it is an Authorized User.

IMPORTANT DISPUTE NOTICE Section 30 contains a governing-law provision, a jury-trial waiver for business disputes, and a binding arbitration agreement and class-action waiver for certain U.S. individual users. Review that section carefully. The arbitration provision includes a 30-day right to opt out.

1. Agreement and contract structure

1.1 Acceptance and scope

These Terms govern the websites, applications, personal intelligence and self-discovery services, enterprise resource planning and business services, AI-assisted features, document-processing tools, APIs, integrations, automation tools, support, and related offerings that Attribute makes available and identifies as subject to these Terms (collectively, the "Services").

Some Services may be offered directly to an individual, through a Customer, or under a separate signed agreement. The rights and responsibilities that apply depend on the Service, the Account or Workspace used, and the documents governing the relationship.

1.2 Contracting entity

The legal entity that contracts with you is Ultimate, Inc., unless an Order Form or product-specific term expressly identifies a different contracting entity. The contracting entity's address and legal notice details appear in Section 33.

1.3 Additional terms and order of precedence

The following documents may supplement these Terms: a mutually signed master agreement or Order Form; a Data Processing Addendum ("DPA"); a Service Level Agreement ("SLA"); product-specific terms; documentation; and policies expressly incorporated into the agreement. A document controls over these Terms only for its stated subject matter and only to the extent of a conflict.

1. Signed commercial agreement or Order Form. Controls the purchased Services, subscription, fees, quantities, term, and expressly negotiated provisions.

2. DPA. Controls processing of Personal Information on Customer's behalf, including processor or service-provider obligations, security, subprocessors, international transfers, and return or deletion.

3. SLA and product-specific terms. Control service levels and product-specific functionality or restrictions.

4. These Terms. Control all remaining use of the Services.

A purchase order, vendor onboarding form, procurement portal term, or similar Customer document does not modify the agreement unless Attribute expressly signs a written amendment that identifies the modified provision.

1.4 Privacy Policy and policies

Our Privacy Policy explains how Attribute processes Personal Information when acting as a controller or business and describes our role when processing Customer Data for a Customer. The Privacy Policy does not reduce rights or obligations in an applicable DPA. Attribute may publish operational policies, security guidance, and documentation that apply to particular features, provided they do not silently expand our rights to Customer Data or User Content.

2. Eligibility, age, and authority

2.1 Age and legal capacity

You must be at least 18 years old and legally capable of entering into a binding agreement, unless Attribute expressly authorizes a different age or supervised use in product-specific terms. The Services are not directed to children. A Customer may not authorize a minor to use the Services unless the applicable Service, agreement, notices, consents, safeguards, and law expressly permit that use.

2.2 Authority for organizations

If you use the Services for an organization, you represent and warrant that the organization is validly existing, that you are authorized to accept the agreement and provide all instructions you give, and that the organization is responsible for its Administrators, Authorized Users, Agents, integrations, configurations, and use of the Services.

2.3 Legal restrictions

You may not use the Services if applicable law prohibits you from receiving them; if you are located in a jurisdiction where Attribute is prohibited from providing them; or if you are a prohibited or restricted party under applicable sanctions, export-control, or trade laws. You must not provide the Services, directly or indirectly, to a prohibited person, territory, or use.

3. Definitions

"Account" means an account used to authenticate and access the Services.

"Administrator" means an Authorized User whom a Customer permits to manage a Workspace, users, permissions, settings, integrations, agents, billing, or other administrative functions.

"Agent" means an automated or AI-assisted software principal, process, or workflow configured to propose, initiate, or perform tasks. The term is technical and does not create legal agency or authority to bind Attribute.

"AI Feature" means a Service feature that uses machine learning, language models, document analysis, embeddings, classification, generation, prediction, model routing, or similar automated techniques, whether through an Attribute-selected provider, a Customer-selected provider, or a local or private model deployment.

"AI Provider" means an external model developer, model host, cloud AI platform, inference service, model router or broker, or similar provider used to support an AI Feature. Depending on the configuration, an AI Provider may be selected by Attribute or by a Customer or Direct User.

"Authorized User" means an individual whom a Customer authorizes to use Enterprise Services.

"Customer" means an organization that purchases, contracts for, or administers Enterprise Services or an organization Workspace.

"Customer Data" means data, records, documents, content, instructions, and other information submitted to, stored in, transmitted through, generated for, or made available to Enterprise Services by or for a Customer, including through integrations. Output generated for a Customer from Customer Data is Customer Data, subject to Attribute's pre-existing rights in the Services and materials.

"Direct User" means an individual who uses Services directly outside an organization Workspace.

"Documentation" means Attribute's then-current user, administrator, API, security, or technical documentation for the applicable Service.

"Enterprise Services" means Services purchased, configured, or administered for a Customer, including Attribute ERP and organization Workspaces.

"High-Impact Decision" means a decision that produces a legal or similarly significant effect on an individual, including decisions concerning employment, housing, education, credit, insurance, healthcare, legal services, essential services, or another regulated eligibility or access determination.

"Input" means prompts, instructions, files, records, data, or other content submitted to an AI Feature.

"Order Form" means an order, subscription confirmation, statement of work, or other ordering document accepted by Attribute and Customer that identifies Services or commercial terms.

"Output" means text, structured data, extracted fields, summaries, classifications, recommendations, proposed actions, code, images, or other material generated by an AI Feature in response to Input.

"Personal Information" means information defined as personal data, personal information, personally identifiable information, or a similar term under applicable privacy law.

"Service Data" means technical, usage, performance, diagnostic, security, and operational data concerning the provision and use of the Services. Service Data excludes raw Customer Data and User Content, except where information has been aggregated or deidentified so it cannot reasonably identify a Customer, user, or individual.

"Third-Party Service" means a product, platform, model provider, data source, website, API, payment service, identity provider, or other service not controlled by Attribute.

"User Content" means information, files, conversations, prompts, responses, memories, preferences, assessments, and other content a Direct User provides to or generates through the Services outside an Enterprise Service relationship.

"Workspace" means a personal, organizational, platform, project, or other bounded environment in the Services where data and access are administered.

4. Accounts, credentials, and electronic communications

4.1 Account registration

You must provide accurate, current, and complete Account information and keep it updated. Attribute may require identity, email, domain, payment, or organizational verification before enabling particular features or administrative authority.

4.2 Credentials and Account security

You are responsible for safeguarding passwords, passkeys, authentication factors, API keys, integration credentials, recovery methods, and devices used to access the Services. You may not share an individual credential or permit multiple people to use one Account unless the Service expressly supports shared or service credentials. Customer must promptly disable access for people who no longer require it.

You must promptly notify Attribute at security@ultimate.dev if you know or reasonably suspect that an Account, credential, Workspace, integration, or Agent has been compromised. Attribute may treat actions performed through valid credentials as authorized until we receive notice and have a reasonable opportunity to act, except to the extent an incident results from Attribute's breach of the agreement.

4.3 Authentication providers and single sign-on

A Customer may require single sign-on or another identity provider. The Customer is responsible for the configuration and security of its identity provider and for promptly updating memberships and access. Authentication confirms identity but does not by itself determine every permission, purpose, workflow, or action available in the Services.

4.4 Electronic communications and records

You consent to receive agreements, disclosures, notices, invoices, and other records electronically at the email address associated with your Account or through the Services. You are responsible for maintaining a current email address and hardware and software capable of accessing, downloading, and retaining electronic records. You may withdraw consent to ordinary electronic communications by closing your Account, but doing so may prevent continued use of the Services. This subsection does not limit any non-waivable right to receive a notice in another form.

5. Individual Services and personal spaces

5.1 Personal use

Individual Services may help a Direct User reflect, organize information, discover patterns, develop plans, and receive AI-assisted suggestions. They are tools for personal information management and reflection, not substitutes for human judgment or licensed professional services.

5.2 Personal space control

User Content stored in a personal space is controlled by the Direct User and is not automatically Customer Data merely because the user also works for or belongs to an organization. A Direct User must use the correct Workspace and must not place an organization's confidential information into a personal space without authorization. If a user copies, shares, or transfers content into an organization Workspace, the receiving Customer and its Administrators may gain access and control as described in these Terms.

5.3 No professional relationship or emergency service

Individual Services do not create a therapist-patient, physician-patient, attorney-client, financial-advisor, employment-assessment, fiduciary, or other licensed professional relationship. Attribute does not diagnose a medical or mental-health condition, determine legal rights, or provide emergency monitoring. If you may be in immediate danger or experiencing an emergency, contact local emergency services or an appropriate crisis service instead of relying on the Services.

5.4 Personal insights and assessments

Reflections, assessments, skills descriptions, personality-related observations, recommendations, or plans may be incomplete, subjective, or wrong. You must not use them as a clinical diagnosis, validated psychological test, employment screening result, or definitive statement about you or another person unless an expressly identified and legally suitable feature provides otherwise.

6. Enterprise Services and organization workspaces

6.1 Enterprise license

Subject to the agreement and payment of applicable fees, Attribute grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to allow its Authorized Users to access and use the purchased Enterprise Services for Customer's internal business purposes and any other use expressly stated in an Order Form.

6.2 Personal, organization, and shared data boundaries

The Services may separate personal spaces, organization Workspaces, and other administrative boundaries. The following summary describes the default relationship; product-specific terms or a Customer agreement may provide additional detail.

EnvironmentPrimary controllerDefault treatment
Personal spaceDirect UserUser Content. Organization Administrators do not automatically control it.
Organization WorkspaceCustomerCustomer Data. Customer and authorized Administrators control access, retention, configuration, and business use.
Shared or connected resourceThe resource keeps its originating owner or Workspace unless transferredAccess is created by an explicit share, connection, integration, or authorized copy. Separate copies may have separate retention and access.

6.3 Customer systems and records

Customer is responsible for deciding which system is authoritative for each business record. Unless an Order Form or integration specification states otherwise, Attribute does not replace a Customer's legal, accounting, tax, payment, human-resources, regulatory, or third-party system of record. Customer must reconcile business records, review synchronization status, and maintain records required by law.

6.4 Affiliates and third parties

Only the Customer entity and affiliates expressly covered by an Order Form may use Enterprise Services. Customer may not provide a service bureau, outsourcing, managed-service, timesharing, or resale offering using the Services unless Attribute agrees in writing.

7. Administrators, Authorized Users, and organization control

7.1 Administrator authority

Customer appoints its Administrators and is responsible for their selection and actions. Attribute may rely on instructions from an Administrator concerning the Workspace, Authorized Users, roles, permissions, integrations, Agents, retention, support, billing, and Customer Data. An Administrator's instruction binds Customer to the extent of the Administrator's apparent authority in the Services.

7.2 Administrator access

Subject to the Service and Customer configuration, Administrators may be able to access, disclose, export, modify, restrict, suspend, or delete Customer Data; review logs and activity; change permissions; connect systems; configure AI and Agent features; and terminate an Authorized User's access. Authorized Users should not expect organization Workspace activity to remain private from the Customer or its authorized Administrators.

7.3 Customer responsibilities for users

Customer is responsible for ensuring that Authorized Users are informed of applicable Customer policies and privacy notices, use the Services lawfully, and have only the access and authority they require. Customer must promptly remove or reduce access when responsibilities change, employment or another relationship ends, or authority is revoked.

7.4 Workspace and Administrator disputes

Attribute is not responsible for resolving internal disputes about Workspace ownership, employment, authority, or data control. If we receive conflicting instructions or reasonably question authority, we may require documentation, restrict administrative changes, preserve relevant data, or suspend affected access while the parties resolve the dispute.

8. Customer and user responsibilities

8.1 Lawful data and instructions

You are responsible for the legality, accuracy, quality, and appropriateness of your Input, Customer Data, User Content, instructions, configurations, and use of Output. You represent and warrant that you have all rights, notices, permissions, consents, and lawful bases necessary for Attribute and its authorized providers to process the information and perform the requested Services.

8.2 Configuration and oversight

Customer is responsible for configuring its Workspace, users, roles, permissions, workflows, approval thresholds, integrations, retention settings, data classifications, Agent authority, and review procedures. Attribute may provide defaults or recommendations, but Customer must determine whether they are appropriate for its operations, data, risks, and legal obligations.

8.3 Business decisions and compliance

Customer remains responsible for business decisions made using the Services, including customer onboarding, purchasing, inventory, manufacturing, accounting, approvals, employment, pricing, credit, supplier management, and external communications. Customer must obtain professional advice where appropriate and must not represent that Attribute has independently approved a decision, verified a record, or certified legal compliance unless Attribute expressly agrees in writing.

8.4 Backups and continuity

Customer is responsible for maintaining copies of information and records that it must preserve independently of the Services, particularly before bulk changes, integrations, migrations, expiration, or termination. Attribute backups are designed for service resilience and are not a substitute for Customer's legal recordkeeping or business-continuity plan.

8.5 Cooperation

You must reasonably cooperate with investigations of suspected security incidents, unlawful activity, infringement, misuse, payment disputes, or material violations of the agreement. You may not obstruct, conceal, or falsify information relevant to such an investigation.

9. Content, Input, Output, and ownership

9.1 Customer Data and User Content

As between the parties, Customer retains all right, title, and interest in Customer Data, and a Direct User retains all right, title, and interest in User Content. Providing content to the Services does not transfer ownership to Attribute.

9.2 Limited processing license

You grant Attribute and its authorized service providers a worldwide, non-exclusive, limited license to host, reproduce, transmit, display, modify, create technical or feature-specific derivatives of, and otherwise process Customer Data and User Content only as reasonably necessary to provide, operate, secure, support, and maintain the Services; follow your lawful instructions; prevent fraud or abuse; comply with law; and exercise rights expressly granted by the agreement. This license includes use of subprocessors and AI Providers for those purposes. It does not authorize generalized model training except as stated in Section 10.5.

9.3 Input and Output ownership

You retain your rights in Input. To the extent Attribute acquires any transferable right in Output generated specifically for you, Attribute assigns that right to you upon creation, subject to your payment obligations, applicable law, third-party rights, and Attribute's ownership of the Services, models, methods, Documentation, templates, pre-existing materials, and general know-how. Output generated for an organization Workspace is Customer Data.

9.4 Output may not be unique

AI systems can produce the same or similar Output for different users. Your ownership rights do not extend to another person's input or output, public-domain material, facts, ideas, methods, or content in which no enforceable rights arise. Attribute does not warrant that Output is unique, protectable, non-infringing, or suitable for registration as intellectual property.

9.5 Service Data and deidentified information

Attribute may collect and use Service Data to provide, secure, administer, analyze, and improve the Services. Attribute may use and disclose information that has been aggregated or deidentified so that it cannot reasonably identify a Customer, user, or individual, provided Attribute does not attempt to reidentify it except to test or improve deidentification and does not disclose it in a form that reasonably identifies the source.

9.6 Feedback

If you voluntarily provide ideas, suggestions, or feedback about the Services, you grant Attribute a perpetual, irrevocable, worldwide, royalty-free right to use and commercialize that feedback without restriction or compensation. Feedback does not include Customer Data, User Content, or confidential information clearly identified as such.

10. Privacy and data processing

10.1 Attribute-controlled processing

When Attribute determines the purposes and means of processing Personal Information, including for Account registration, billing, direct support, website operations, service security, legal compliance, and direct-to-user Services, our Privacy Policy governs that processing.

10.2 Customer-controlled processing

When Attribute processes Personal Information contained in Customer Data on Customer's behalf, Customer generally acts as the controller or business and Attribute acts as the processor, service provider, contractor, or equivalent. Customer is responsible for its notices, permissions, lawful bases, data-subject responses, instructions, and decisions. Our Data Processing Addendum, if incorporated, governs that processing.

10.3 Requests concerning Customer Data

An individual seeking access, correction, deletion, restriction, portability, appeal, or another privacy right concerning Customer Data should ordinarily contact the Customer that collected or submitted the information. Attribute will assist Customer as required by the applicable DPA and law.

10.4 Sensitive information and data minimization

You must limit Personal Information and sensitive information to what is lawful and reasonably necessary for the requested feature. Access to information does not automatically authorize every use, disclosure, export, AI processing purpose, or automated action. Customer must apply any additional notice, consent, classification, minimization, provider, workflow, or human-review controls required for its use case.

10.5 Generalized AI model training

Attribute does not use Customer Data or User Content to train generalized AI models for Attribute or third parties unless the applicable Customer or Direct User provides separate, affirmative authorization through a clear opt-in or written agreement. Ordinary use of an AI Feature, acceptance of these Terms, or an Administrator's activation of routine functionality is not by itself authorization for generalized model training. Any authorized program must describe the data scope and purpose and will apply prospectively unless the parties expressly agree otherwise.

10.6 Subprocessors and providers

Attribute may use affiliates and subprocessors, including infrastructure, security, support, analytics, document-processing, direct AI model, model-hosting, and model-routing providers, to deliver the Services. Where Attribute acts as a processor, Subprocessor use is governed by the DPA. An AI Provider selected and controlled by Customer through its own account, credential, endpoint, cloud project, or private deployment is generally a Customer-directed Third-Party Service rather than an Attribute Subprocessor. Attribute remains responsible for Attribute-selected providers to the extent required by the agreement and applicable law.

11. AI-assisted features and Outputs

11.1 AI disclosure

AI Features are automated software systems. You are interacting with software, not a human, and Output is not the statement, judgment, or endorsement of a human professional merely because it is expressed conversationally or confidently.

11.2 Model sources, assignment, and availability

Where offered, AI Features may connect directly or through a routing layer to models or services from providers such as Anthropic (Claude), Google Cloud (Gemini), OpenAI, SpaceXAI (Grok), OpenRouter, and other current or future providers. AI Features may also use local, private, self-hosted, customer-hosted, or open-weight models. These examples do not guarantee availability, endorsement, continued support, or use of a particular provider for any Service.

11.3 Customer-selected models and routing controls

Where the Services permit, a Customer Administrator may assign an approved model, provider, provider route, region, data policy, or Customer-supplied credential or endpoint to a Workspace, internal workflow, Agent, tool, task, or data classification. Customer is responsible for the Third-Party Service terms, permissions, fees, retention and training settings, availability, and lawfulness of a Customer-selected connection. Attribute may enforce stricter restrictions, block unsupported providers or models, and decline or fail a request when no eligible provider or route satisfies the configured security, privacy, residency, retention, training, or availability requirements. A routing fallback does not authorize use of a provider outside those constraints.

11.4 Output limitations

Output may be inaccurate, incomplete, inconsistent, outdated, biased, misleading, offensive, or fabricated. It may omit material facts, misunderstand context, miscalculate amounts, cite sources that do not support a statement, or incorrectly extract information from a document. Confidence scores and validations are indicators, not guarantees.

11.5 Review and verification

You must independently review and verify Output before relying on it, publishing it, communicating it to another person, entering it into an authoritative system, approving a transaction, filing it with an authority, signing a document, or using it for a decision. Appropriate review may require comparing the Output with source records, using qualified personnel, obtaining professional advice, testing generated code, and confirming legal or regulatory requirements.

11.6 No licensed professional advice

Unless an Order Form expressly states otherwise, Output is not medical, mental-health, legal, tax, accounting, investment, credit, insurance, engineering, compliance, or other licensed professional advice. Attribute does not represent that an AI Feature is equivalent to or endorsed by a licensed professional.

11.7 High-Impact Decisions

You may not use an AI Feature or Output as the sole or determinative basis for a High-Impact Decision. A Customer may use a Service to assist such a process only if the applicable Order Form expressly permits the use, the Customer has completed required legal and risk review, affected individuals receive required notices and rights, qualified humans exercise meaningful review, and the use complies with all applicable anti-discrimination, privacy, consumer-protection, employment, credit, healthcare, and other laws.

11.8 Generated code and executable material

Generated code, formulas, scripts, configurations, mappings, and automation instructions must be reviewed, tested, secured, and licensed before production use. You are responsible for dependency, vulnerability, data-loss, access-control, and intellectual-property risks arising from deployment.

11.9 Safety controls and refusals

Attribute may apply safety, security, data-use, capability, or policy controls; refuse or limit a request; require additional review; or prevent an AI Feature from processing particular information or performing an action. These controls reduce risk but do not guarantee that all harmful, inaccurate, unauthorized, or unsuitable content will be detected or prevented.

12. Agents, automation, approvals, and consequential actions

12.1 Technical Agents are not legal agents

An Agent is an automated software capability and is not a legal agent, employee, fiduciary, or representative of Attribute. No Agent has authority to bind Attribute, make a representation on Attribute's behalf, waive a right, or enter into an agreement for Attribute.

12.2 Configuration and delegated authority

Customer may configure an Agent to access information, propose actions, or execute actions within a defined Workspace, task, role, permission, delegation, tool, integration, limit, or approval workflow. Customer represents that it has authority to grant that access and is responsible for ensuring the Agent's authority does not exceed the authority of the person or organization on whose behalf it acts.

12.3 Approval and execution boundaries

A recommendation, draft, preview, or proposed action is not an executed transaction. An action becomes effective only when it passes the applicable server-side authorization, workflow, approval, tool, integration, and system-of-record controls and the relevant system accepts it. A prior approval or past authorization does not necessarily authorize a later action if permissions, data, risk, or circumstances have changed.

12.4 Customer oversight of consequential actions

Customer must establish human review and segregation-of-duties procedures appropriate to the risk. Unless expressly enabled and governed by an Order Form, Customer must not allow an Agent to autonomously:

  • release or transfer funds, change banking or payment instructions, or create a payment beneficiary;

  • execute a contract, legal filing, tax filing, certification, attestation, or regulatory submission;

  • hire, terminate, discipline, compensate, or materially evaluate a person;

  • make a consumer credit, insurance, housing, healthcare, education, or other High-Impact Decision;

  • approve its own work or bypass a required approval, dual-control, or segregation-of-duties rule;

  • make a material inventory adjustment, pricing commitment, purchase commitment, or external representation without the configured authority and review.

12.5 Responsibility for configured actions

Customer is responsible for actions performed through Agents and automation it configures or authorizes, including resulting records in connected systems, except to the extent an unauthorized action is directly caused by Attribute's breach of the agreement. Customer must monitor Agent activity, maintain appropriate approval paths, and promptly revoke authority that is no longer required.

12.6 Audit and attribution

The Services may record the initiating user or process, represented authority, task, delegation, tool, authorization result, approval, integration, and resulting transaction. Such records support security and accountability but may not capture every external event or replace Customer's required books, records, or audit procedures.

13. Documents, extraction, and validation

13.1 Rights to documents

You may submit a document, image, scan, form, certificate, application, invoice, identity or tax document, resale or licensing record, trade reference, contract, correspondence, or other file only if you have authority to possess, disclose, and process it through the Services. You must provide required notices and obtain required permissions from individuals whose information appears in a document.

13.2 Automated extraction and review

The Services may extract text and fields, classify documents, detect apparent omissions or inconsistencies, calculate confidence indicators, compare information, and propose structured records. These functions assist review and do not guarantee authenticity, validity, identity, legal sufficiency, fraud detection, creditworthiness, completeness, or accuracy.

13.3 Source documents control

Unless a verified correction or authoritative process establishes otherwise, the source document and authoritative business record control over an extracted field, summary, or AI-generated interpretation. Customer must review discrepancies before approval, onboarding, credit extension, payment, filing, or another material action.

13.4 Malicious or unsafe files

You may not upload malware, corrupted files, hidden executable content, or documents designed to manipulate, evade, or attack document-processing or AI systems. Attribute may scan, quarantine, reject, transform, or delete files that create security, legal, or operational risk.

14. Integrations, APIs, and Third-Party Services

14.1 Customer-directed connections

When you connect a Third-Party Service, including an ERP, identity provider, data source, direct AI model provider, model router, cloud model platform, Customer-hosted endpoint, or other integration, you authorize Attribute to access, receive, transmit, create, update, or delete information through that connection as configured and permitted by the relevant credentials and scopes. You represent that you have authority to connect the system and direct the resulting processing and actions.

14.2 Third-party terms and responsibility

Third-Party Services are governed by their own terms and privacy practices. Attribute does not control and is not responsible for a Third-Party Service's availability, security, data use, pricing, changes, errors, or acts. Attribute is not liable for a loss caused by a Third-Party Service except to the extent Attribute independently breached the agreement.

14.3 Credentials and minimum access

Customer must protect API keys, tokens, certificates, service credentials, and integration secrets and grant only the minimum scopes reasonably necessary. Credentials may not be embedded in public code, client-side applications, documents, prompts, or messages. Attribute may rotate, reject, or revoke a credential that is exposed, insecure, inactive, or misused.

14.4 Synchronization and source-of-truth risk

Integrations can be delayed, unavailable, duplicated, out of sequence, or affected by schema, field, unit, meaning, permission, or provider changes. Customer must monitor integration status and reconcile material records. Deleting or changing information in Attribute does not necessarily delete or change copies in a connected system, and vice versa.

14.5 API use

API access is subject to Documentation, authentication, rate limits, quotas, versioning, and security requirements. You may not exceed limits, avoid metering, share credentials outside authorized use, interfere with other users, scrape beyond permitted endpoints, or systematically query the Services to reconstruct underlying models, security controls, hidden prompts, or nonpublic data.

14.6 Customer applications

Customer is responsible for applications, scripts, connectors, and workflows it develops or operates, including their security, notices, permissions, error handling, data retention, user support, and legal compliance. Attribute may suspend API access that threatens the Services or violates the agreement.

15. Acceptable use

You may not use, assist another person to use, or permit use of the Services to:

  • violate law, court order, regulatory requirement, contractual duty, or another person's rights;

  • infringe intellectual property, privacy, publicity, confidentiality, data-protection, or employment rights;

  • commit or facilitate fraud, deception, identity theft, phishing, impersonation, false documentation, money laundering, or unauthorized access;

  • generate, publish, or submit fabricated reviews, references, records, evidence, certifications, invoices, credentials, or statements as if they were genuine;

  • harass, threaten, exploit, discriminate against, defame, or unlawfully profile a person;

  • create, possess, solicit, facilitate, or distribute child sexual abuse material or sexualized content involving a minor;

  • promote violent wrongdoing, terrorism, unlawful weapons activity, human trafficking, or imminent physical harm;

  • introduce malware, ransomware, destructive code, credential theft, denial-of-service activity, or content designed to manipulate or compromise systems;

  • probe, scan, test, reverse engineer, or circumvent authentication, authorization, usage limits, safety controls, data boundaries, logging, or security without Attribute's written permission;

  • access another person's or organization's Account, Workspace, data, or resource without authorization or attempt to infer whether protected data exists;

  • send unsolicited communications, bulk messages, or automated traffic in violation of law or provider rules;

  • conduct unlawful biometric identification, surveillance, location tracking, employee monitoring, or scraping of personal information;

  • misrepresent AI Output as human-created, professionally endorsed, verified, or factually established when that representation would be deceptive or unlawful;

  • use the Services in a life-safety, emergency dispatch, autonomous weapons, nuclear, aviation control, or other environment where failure could reasonably cause death or catastrophic physical damage unless Attribute expressly approves the use in writing.

Attribute may investigate suspected violations and may preserve or disclose information as permitted by the agreement, the Privacy Policy, and law. Enforcement decisions may consider severity, intent, risk, recurrence, cooperation, and whether a narrower restriction can adequately address the issue.

16. Regulated data and restricted decisions

16.1 Specially regulated data

Unless an Order Form expressly authorizes the data type and the parties have completed required legal, security, and contractual steps, you must not submit or process through the Services:

  • protected health information subject to HIPAA or similar health-data regimes;

  • consumer-report information or data used by a consumer reporting agency under the Fair Credit Reporting Act;

  • full payment-card data outside an Attribute-approved payment flow;

  • nonpublic financial information subject to specialized financial-institution obligations that the agreement does not address;

  • biometric identifiers or templates used to identify a person;

  • classified, controlled unclassified, export-controlled, ITAR, law-enforcement-sensitive, or government-secret information;

  • information about children or minors where the applicable Service and agreement do not expressly permit it;

  • other information subject to a legal regime requiring controls Attribute has not expressly agreed to provide.

16.2 Business onboarding and trade credit

A supported business onboarding workflow may process business contact information, business tax identifiers, resale certificates, licenses, trade references, and other commercial application materials. Customer remains responsible for the legality of collection, verification, retention, and decision-making. Unless expressly agreed, Attribute is not a consumer reporting agency and the Services may not be used to create a consumer report or make a consumer credit decision.

16.3 Employment and workforce use

Customer must not use personal Attribute assessments, conversational inferences, or general AI Output to screen, rank, hire, terminate, discipline, compensate, or otherwise make a material employment decision unless an expressly approved feature is legally suitable for that purpose and Customer provides all required notices, assessments, validation, accommodations, human review, and rights.

16.4 Customer assessment

Customer is responsible for determining whether its data and intended use are permitted, for conducting required risk or impact assessments, and for obtaining legal or compliance advice. Attribute may request information, impose restrictions, or decline a regulated use that is outside the contracted Service or presents unreasonable risk.

17. Security

17.1 Attribute safeguards

Attribute maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, acquisition, loss, alteration, disclosure, or destruction, taking into account the nature of the information and processing. No service or security control can eliminate all risk, and Attribute does not guarantee that the Services will be immune from every vulnerability or incident.

17.2 Customer security duties

Customer must maintain reasonable security for its devices, networks, identity provider, credentials, integrations, endpoints, users, and data. Customer must use available security features appropriate to its risk, including strong authentication, least privilege, access reviews, prompt offboarding, secure secrets management, and monitoring of administrative, Agent, and integration activity.

17.3 Security testing and vulnerabilities

You may not perform penetration testing, vulnerability scanning, load testing, or security research against the Services without prior written authorization and compliance with Attribute's vulnerability-disclosure rules. Report suspected vulnerabilities to security@ultimate.dev and do not publicly disclose them before Attribute has a reasonable opportunity to investigate and remediate.

17.4 Security incidents

Security-incident notification and cooperation for Customer Data are governed by the applicable DPA or enterprise agreement. You must not make a public statement purporting to speak for Attribute about an incident without our written approval, except where law requires otherwise.

18. Confidentiality

18.1 Confidential Information

"Confidential Information" means nonpublic information disclosed by or on behalf of a party that is identified as confidential or that a reasonable person would understand to be confidential given its nature and circumstances. Customer Data, User Content, nonpublic security information, product roadmaps, pricing, credentials, and nonpublic technical or business information are Confidential Information. Confidential Information does not include information that the receiving party can document: was lawfully known without restriction; becomes public without breach; is received lawfully from a third party without confidentiality duty; or is independently developed without use of the disclosing party's Confidential Information.

18.2 Protection and permitted use

The receiving party will use Confidential Information only to perform or exercise rights under the agreement and will protect it using at least reasonable care and no less care than it uses for similar information. The receiving party may disclose Confidential Information only to personnel, professional advisers, affiliates, and service providers who need it for the permitted purpose and are subject to confidentiality obligations at least as protective as this Section.

18.3 Required disclosure

A receiving party may disclose Confidential Information when legally required, provided it gives prior notice where lawful and reasonably cooperates, at the disclosing party's expense, with efforts to seek protective treatment. The receiving party will disclose only what is legally required.

18.4 Equitable relief

Unauthorized use or disclosure of Confidential Information may cause harm that monetary damages cannot adequately remedy. A party may seek appropriate injunctive or equitable relief without waiving other remedies, subject to applicable law and Section 30.

19. Attribute intellectual property and copyright

19.1 Attribute ownership

Attribute and its licensors retain all right, title, and interest in the Services, software, user interfaces, designs, models, methods, workflows, Documentation, templates, trademarks, service marks, and related technology, including improvements and derivative works that do not consist of Customer Data or User Content. Except for the limited rights expressly granted, no rights are transferred to you.

19.2 Restrictions

Except as permitted by law or written agreement, you may not copy, modify, translate, distribute, sell, lease, sublicense, publicly display, frame, mirror, create derivative works of, or reverse engineer the Services; remove proprietary notices; access source code or model weights; use the Services to develop a substantially similar competing service through systematic extraction; or permit a third party to do so. This restriction does not prohibit ordinary use of Output that you own under Section 9.

19.3 Open-source and third-party components

Open-source or third-party components may be governed by separate license terms or notices. To the extent such terms conflict with these Terms for that component, the applicable third-party terms control.

19.4 Marks and publicity

Neither party may use the other party's name, logo, or trademarks in advertising, publicity, customer lists, or case studies without prior written consent, except that Attribute may identify the contracting entity on invoices, security notices, and operational records. No right to use a mark is implied.

19.5 Copyright complaints

Attribute may remove or restrict access to material that it reasonably believes infringes copyright and may terminate repeat infringers where appropriate. Copyright notices should be sent to legal@ultimate.dev and include the information required by applicable law. If applicable law requires use of a separately designated copyright agent, Attribute will publish that agent’s current contact information.

20. Fees, subscriptions, billing, and taxes

20.1 Fees and payment authorization

You must pay the fees and charges shown at checkout or in an Order Form. You authorize Attribute and its payment providers to charge the payment method associated with your Account for fees, usage, overages, taxes, and other disclosed charges. Except as required by law or expressly stated in the agreement, fees are non-refundable and payment obligations are non-cancelable during a committed subscription term.

20.2 Recurring subscriptions and renewal

Before charging for a recurring subscription, Attribute will disclose the material subscription terms and obtain required consent. Unless an Order Form states otherwise, a subscription renews for successive periods equal to the expiring term at the then-current price unless either party gives notice of non-renewal at least 30 days before renewal. Consumer subscriptions may be canceled through a simple mechanism described at checkout or in Account settings, and mandatory cancellation rights control over this subsection.

20.3 Trials and promotions

A trial or promotional period may convert to a paid subscription only as clearly disclosed and authorized. Attribute may limit eligibility, duration, seats, usage, or features and may revoke a promotion obtained through abuse or misrepresentation.

20.4 Price changes and usage

Attribute may change prices for a renewal term by giving at least 30 days' notice, unless a longer period is required by law or an Order Form. Usage-based charges are calculated from Attribute's metering records unless Customer identifies a demonstrable error. Customer is responsible for use by its Accounts, Authorized Users, Agents, and integrations.

20.5 Taxes and withholding

Fees exclude taxes, duties, levies, and similar governmental charges. You are responsible for such charges other than taxes on Attribute's net income. For business Customers, if law requires withholding, Customer will gross up the payment so Attribute receives the amount that would have been due absent the withholding, unless prohibited by law or an Order Form states otherwise.

20.6 Late payment and billing disputes

Undisputed overdue amounts may accrue interest at the lesser of 1.5% per month or the maximum lawful rate, plus reasonable collection costs. Attribute may suspend paid Services for material nonpayment after notice and a reasonable opportunity to cure. You must notify Attribute of a good-faith billing dispute within 60 days after the charge or invoice, without limiting non-waivable consumer rights.

21. Free, trial, beta, preview, and evaluation Services

Attribute may offer free, trial, beta, preview, early-access, sandbox, proof-of-concept, or evaluation Services. Unless an Order Form states otherwise, such Services are provided for evaluation, may have limited functionality, may change or end at any time, may not be supported, may be subject to lower security or retention commitments, and are not covered by an SLA, service warranty, or Attribute IP indemnity. You must not use them for production-critical, regulated, irreversible, or consequential actions unless Attribute expressly authorizes the use in writing.

Nonpublic preview features and related materials may be Attribute Confidential Information. Attribute may request feedback and usage information concerning a preview, subject to the Privacy Policy and Section 9.5.

22. Availability, support, and Service changes

22.1 Availability

Attribute will use commercially reasonable efforts to operate paid Services in accordance with the applicable agreement. The Services may be unavailable for maintenance, security response, provider outages, network failures, force majeure events, or other reasons. Any uptime, response, recovery, or support commitment applies only if stated in an SLA or Order Form.

22.2 Support

Support scope, hours, channels, response targets, and Customer obligations are stated in the applicable plan, Documentation, or Order Form. Attribute may require an authorized Administrator, diagnostic information, reproduction steps, temporary support access, or reasonable configuration changes to investigate an issue.

22.3 Service evolution

Attribute may improve, modify, replace, or discontinue features. During a current paid Enterprise subscription, Attribute will not materially reduce the core functionality of the purchased Service except where reasonably necessary for security, legal compliance, third-party dependency changes, or replacement with substantially equivalent functionality. Attribute will provide reasonable advance notice of a material deprecation when practicable.

22.4 No reliance on future features

Purchases are not contingent on delivery of a future feature, roadmap, release date, statement, or expectation unless an Order Form expressly makes it a binding deliverable. Product descriptions and demonstrations are illustrative and remain subject to the agreement and Documentation.

23. Suspension

23.1 Grounds for suspension

Attribute may suspend or restrict an Account, Workspace, feature, integration, credential, Agent, API, or Service if reasonably necessary to: prevent or address a security incident or material risk; stop unlawful, fraudulent, abusive, or harmful activity; protect another customer or the Services; respond to a legal requirement; address material nonpayment; investigate a material breach; or prevent processing that is not permitted by the agreement.

23.2 Scope and notice

Where practicable, Attribute will provide notice and an opportunity to cure before suspension and will limit the suspension to the affected scope. Attribute may act immediately when delay would create material risk. Attribute will restore access when the underlying issue is resolved to our reasonable satisfaction, subject to law and any termination right.

23.3 Customer suspension of users

A Customer or authorized Administrator may suspend an Authorized User, Agent, credential, integration, or permission in accordance with the Service. Customer is responsible for ensuring that its suspension and monitoring decisions comply with law, contract, and required notice obligations.

24. Term and termination

24.1 Term

These Terms begin when you first accept them or use the Services and continue until all Accounts and subscriptions governed by them terminate. A paid subscription continues for the term stated at checkout or in the Order Form, including any renewal period.

24.2 Termination by a Direct User

A Direct User may stop using the Services and close an Account through available settings or by contacting support. Closing an Account does not entitle the user to a refund for a committed or already billed period except as required by law or expressly stated at purchase.

24.3 Termination for cause

Either party may terminate an affected paid agreement if the other party materially breaches it and does not cure the breach within 30 days after written notice. A party may terminate immediately if the other party becomes insolvent, ceases business without a successor, makes an assignment for creditors, or enters a bankruptcy or similar proceeding that is not dismissed within 60 days, to the extent permitted by law. Attribute may terminate immediately for unlawful use, intentional security abuse, repeated material violations, or conduct creating substantial risk that cannot reasonably be cured.

24.4 Effect of termination

Upon termination, your right to access the affected Services ends, outstanding payment obligations become due, and Customer must stop using Attribute software and confidential materials. Termination does not undo completed transactions in connected systems or require Attribute to reverse actions lawfully performed before termination. Sections that by their nature should survive do survive, including ownership, confidentiality, payment, disclaimers, indemnification, liability limits, disputes, and general terms.

25. Data export, retention, and deletion

25.1 Export during the term

You may export Customer Data or User Content through available features and formats. Customer is responsible for performing exports before expiration or termination and for validating that exported information is complete and usable for its purposes. Some Service Data, security logic, model internals, system metadata, derived operational information, or third-party licensed material may not be exportable.

25.2 Post-termination retrieval

Unless an Order Form states otherwise, a paid Enterprise Customer may request a standard export of reasonably available Customer Data for 30 days after subscription termination, provided the Account is not subject to a security restriction and undisputed fees are paid. Attribute may charge reasonable fees for nonstandard extraction, restoration from backup, or professional services. After the retrieval period, Attribute may delete Customer Data without further obligation.

25.3 Deletion and retention

Deletion is subject to the Privacy Policy, DPA, Customer configuration, legal holds, security and audit requirements, fraud prevention, dispute preservation, backup cycles, and technical limitations. Data may remain in encrypted or access-restricted backups until overwritten in the ordinary cycle. Attribute may retain billing, contract, security, authorization, audit, and deidentified information as permitted by law and the agreement.

25.4 Connected systems and copies

Deleting data from Attribute does not delete copies previously exported, disclosed, or written to a Third-Party Service. Customer and recipients are responsible for those copies. Separate shared or copied resources may have independent retention and must be managed separately.

26. Limited warranties

26.1 Mutual authority

Each party warrants that it has the legal power and authority to enter into the agreement. Customer further warrants that its use, data, and instructions will comply with the agreement and applicable law.

26.2 Paid Enterprise Service warranty

During a paid Enterprise subscription, Attribute warrants that the purchased Service will perform materially in accordance with the applicable Documentation under normal authorized use. Customer must notify Attribute with reasonable detail within 30 days after discovering a material nonconformity. Attribute's exclusive obligation and Customer's exclusive remedy for breach of this warranty are for Attribute to use commercially reasonable efforts to correct or replace the affected functionality; if Attribute cannot do so within a reasonable period, either party may terminate the affected Service and Attribute will refund prepaid fees allocable to the unused remainder of the terminated term.

26.3 Exclusions

The warranty does not apply to free or preview Services; AI Output; Third-Party Services; Customer Data; Customer-developed code or integrations; misuse; unauthorized modifications; use outside Documentation; unsupported environments; or issues caused by Customer systems, credentials, instructions, or failure to implement a provided correction.

27. Disclaimers

EXCEPT FOR THE EXPRESS WARRANTIES IN SECTION 26 AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, OUTPUT, DOCUMENTATION, SUPPORT, AND ALL RELATED MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE." ATTRIBUTE AND ITS LICENSORS DISCLAIM ALL IMPLIED OR STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, QUIET ENJOYMENT, ACCURACY, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

ATTRIBUTE DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, SECURE AGAINST EVERY THREAT, OR COMPATIBLE WITH EVERY SYSTEM; THAT DATA WILL NEVER BE LOST; THAT OUTPUT WILL BE ACCURATE, COMPLETE, UNIQUE, CURRENT, UNBIASED, OR NON-INFRINGING; THAT AN INTEGRATION WILL REMAIN AVAILABLE; OR THAT THE SERVICES WILL SATISFY A PARTICULAR LEGAL, REGULATORY, ACCOUNTING, TAX, CREDIT, EMPLOYMENT, OR PROFESSIONAL REQUIREMENT.

Nothing in these Terms excludes a warranty or right that cannot lawfully be excluded, including mandatory consumer rights. Some jurisdictions do not allow particular disclaimers, so parts of this Section may not apply to you.

28. Indemnification

28.1 Customer and user indemnity

To the extent permitted by law, Customer will defend Attribute, its affiliates, and their personnel against a third-party claim arising from: Customer Data, User Content, Input, or Customer instructions; Customer's or an Authorized User's violation of law, privacy rights, intellectual property rights, or these Terms; a Customer-configured Agent, integration, or Third-Party Service; Customer's High-Impact Decision or business decision; or Customer's representation to another person about the Services or Output. Customer will indemnify them for finally awarded damages, approved settlements, and reasonable external legal fees. This obligation does not apply to the extent the claim results from Attribute's breach of the agreement or willful misconduct.

28.2 Attribute intellectual-property indemnity for paid Enterprise Services

For a paid Enterprise Customer, Attribute will defend Customer against a third-party claim that the unmodified purchased Service, when used as authorized, directly infringes a United States patent, copyright, or trademark, and will indemnify Customer for finally awarded damages, approved settlements, and reasonable external legal fees. This obligation does not cover claims arising from Customer Data, Input, Output, Third-Party Services, open-source components, Customer specifications, modifications not made by Attribute, combinations not required by Documentation, use after notice to stop, or use outside the agreement.

If a Service becomes or is likely to become subject to such a claim, Attribute may obtain the right to continue use, modify or replace the affected Service with materially equivalent functionality, or terminate it and refund prepaid fees allocable to the unused remainder of the terminated term. This Section states Attribute's entire obligation and Customer's exclusive remedy for third-party intellectual-property infringement by the Services.

28.3 Procedure

The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation at the indemnifying party's expense, and allow the indemnifying party to control the defense and settlement. A delayed notice relieves the indemnifying party only to the extent materially prejudiced. The indemnifying party may not settle a claim in a way that admits fault by, imposes nonmonetary obligations on, or fails to fully release the indemnified party without written consent, not to be unreasonably withheld.

29. Limitation of liability

29.1 Excluded damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY NOR ITS AFFILIATES OR LICENSORS WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, CONSEQUENTIAL, OR PUNITIVE DAMAGES; LOST PROFITS, REVENUE, BUSINESS, GOODWILL, OR ANTICIPATED SAVINGS; LOSS OR CORRUPTION OF DATA; BUSINESS INTERRUPTION; COST OF SUBSTITUTE SERVICES; OR DAMAGES ARISING FROM ANOTHER PARTY'S SYSTEM OR CONDUCT, EVEN IF ADVISED THAT SUCH DAMAGES ARE POSSIBLE.

29.2 Aggregate cap

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ATTRIBUTE'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICES OR AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY CUSTOMER FOR THE AFFECTED SERVICES DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. FOR FREE SERVICES OR A DIRECT USER WHO PAID NO FEES, ATTRIBUTE'S TOTAL AGGREGATE LIABILITY WILL NOT EXCEED US $100. MULTIPLE CLAIMS DO NOT INCREASE THE CAP.

29.3 Exclusions from Customer limitations

Any limitation on Customer's liability does not apply to payment obligations; Customer's indemnification obligations; unauthorized use of Attribute intellectual property; intentional security abuse; or a violation of Sections 15 or 16. Nothing limits liability that cannot lawfully be limited, including liability for fraud or willful misconduct to the extent applicable law prohibits limitation.

29.4 Allocation of risk

The disclaimers, exclusive remedies, and liability limits are fundamental parts of the parties' allocation of risk and apply regardless of the legal theory and even if a remedy fails of its essential purpose. An Order Form or DPA may state a different cap for a specified subject matter.

30. Governing law, disputes, arbitration, and class-action waiver

READ THIS SECTION CAREFULLY The individual-user provisions below require arbitration of most disputes on an individual basis and waive class or representative proceedings, unless you timely opt out. Enterprise and other business disputes follow the court provisions below unless a signed agreement states otherwise.

30.1 Informal dispute process

Before filing a lawsuit or arbitration, the claimant must send a written Notice of Dispute to the other party describing the claimant, Account or contract, facts, legal basis, requested relief, and a good-faith settlement proposal. Notices to Attribute must be sent to legal@ultimate.dev and 16192 Coastal Highway, Lewes, DE 19958. The parties will attempt in good faith to resolve the dispute for 60 days. A limitations period is tolled during that 60-day period to the extent permitted by law.

30.2 Business and Enterprise disputes

For a Customer, Authorized User acting in a business capacity, or other dispute not subject to Section 30.3, the agreement is governed by the laws of Delaware, without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply. The state courts located in Sussex County, Delaware, and the United States District Court for the District of Delaware have exclusive jurisdiction, and each party consents to personal jurisdiction and venue in those courts. EACH PARTY WAIVES, TO THE EXTENT PERMITTED BY LAW, ANY RIGHT TO A JURY TRIAL.

30.3 Arbitration agreement for U.S. individual users

If you are a Direct User residing in the United States and use the Services primarily for personal, family, or household purposes, you and Attribute agree that any dispute, claim, or controversy arising out of or relating to the Services, these Terms, or the relationship between you and Attribute will be resolved by binding individual arbitration, except for the matters in Section 30.5. This arbitration agreement is governed by the Federal Arbitration Act.

30.4 Arbitration rules and procedure

The American Arbitration Association ("AAA") will administer the arbitration under its then-current Consumer Arbitration Rules and applicable fee schedule, as modified by this Section. One neutral arbitrator will decide the dispute. The arbitration may occur by video, telephone, documents, or in person in the county where you live, at your election where the rules permit. Attribute will pay arbitration fees it is required to pay under the AAA rules or applicable law. The arbitrator may award the same individual relief a court could award and must issue a reasoned written decision.

30.5 Exceptions

Either party may bring an individual claim in small-claims court if it qualifies. Either party may seek temporary or preliminary injunctive relief in court to prevent unauthorized access, security abuse, or infringement or misappropriation of intellectual property or Confidential Information, while the merits remain subject to arbitration where applicable. A request for public injunctive relief that cannot lawfully be arbitrated may proceed in court after arbitrable issues are resolved.

30.6 Class-action and representative-action waiver

YOU AND ATTRIBUTE AGREE THAT EACH MAY BRING CLAIMS ONLY IN AN INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, PRIVATE ATTORNEY GENERAL, OR REPRESENTATIVE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE ACTION. The arbitrator may not combine claims or preside over a representative proceeding without the written consent of all affected parties. If this waiver is finally found unenforceable for a particular claim, that claim must proceed in court and the remaining claims remain subject to arbitration.

30.7 Right to opt out

You may opt out of Sections 30.3 through 30.6 by sending a written opt-out notice within 30 days after first accepting these Terms. The notice must include your full name, Account email, mailing address, and a clear statement that you opt out of arbitration. Send it to legal@ultimate.dev or 16192 Coastal Highway, Lewes, DE 19958. Opting out will not affect your Account or access to the Services. An opt-out applies only to you and not to an organization or another user.

30.8 Consumer rights and severability

Nothing in this Section eliminates a non-waivable consumer right or prevents a regulator from acting within its authority. If a portion of this Section is unenforceable, it will be severed to the minimum extent necessary, except as stated for the class-action waiver. The governing-law clause does not deprive a consumer of mandatory protections of the consumer's home jurisdiction.

31. Changes to these Terms

Attribute may update these Terms to reflect changes in law, the Services, security, or business practices. We will post the updated Terms and update the "Last Updated" date. For a material change, we will provide reasonable advance notice through the Services, by email, or another appropriate method. Unless law or an urgent security need requires earlier application, a materially adverse change to a current paid Enterprise subscription will take effect at renewal rather than during the committed term.

We will not use an update to these Terms or the Privacy Policy alone to obtain new rights to train generalized AI models on Customer Data or User Content already provided. Such use requires the separate affirmative authorization described in Section 10.5. If you do not agree to an update, you must stop using the affected Service before it takes effect. Continued use after the effective date constitutes acceptance to the extent permitted by law.

32. General terms

32.1 Assignment

You may not assign or transfer the agreement without Attribute's prior written consent. Attribute may assign it to an affiliate or in connection with a merger, reorganization, financing, sale of substantially all relevant assets, or similar transaction, provided the assignee assumes the applicable obligations. Any prohibited assignment is void.

32.2 Independent parties; no agency

The parties are independent contractors. The agreement does not create a partnership, joint venture, fiduciary, franchise, employment, or legal agency relationship. No user, Administrator, Agent, integration, or AI Output has authority to bind Attribute.

32.3 Force majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, war, terrorism, civil disorder, epidemic, labor disruption, utility or network failure, cloud or provider outage, governmental action, or widespread cyberattack, except that this Section does not excuse payment obligations for Services already provided. The affected party will use reasonable efforts to mitigate and resume performance.

32.4 Notices

Operational notices may be delivered through the Services or to the Account email and are effective when sent or posted. Legal notices must be in writing and delivered by personal delivery, nationally recognized overnight courier, certified mail, or email where this Section expressly permits it. Notices to Customer go to the billing or Administrator contact in the Account or Order Form. Notices to Attribute go to the address in Section 33.

32.5 Severability and waiver

If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable or severed if modification is not possible, and the remaining provisions remain effective. A waiver must be in writing and applies only to the specific instance. A delay in enforcement is not a waiver.

32.6 Entire agreement and interpretation

The agreement is the complete agreement concerning its subject matter and supersedes prior or contemporaneous proposals, statements, or agreements on that subject. Headings are for convenience. "Including" means "including without limitation." The English version controls unless law requires otherwise. The agreement will not be construed against a party merely because it drafted a provision.

32.7 No third-party beneficiaries

Except for indemnified parties and Attribute licensors and service providers where expressly stated, the agreement does not create rights for a third party. An Authorized User is not a third-party beneficiary of Customer's agreement with Attribute.

32.8 Export and sanctions compliance

You must comply with applicable export-control, sanctions, and trade laws. You represent that you are not located in, organized under the laws of, or ordinarily resident in a prohibited territory and are not a prohibited or restricted party. You may not export, reexport, transfer, or provide access to the Services, software, technical data, or controlled information in violation of law.

32.9 Government use

The Services are commercial computer software and commercial computer software documentation. Government users receive only the rights granted under the agreement and applicable procurement law. No specialized government security or contracting requirement applies unless Attribute expressly agrees in writing.

33. Contact information

Questions about these Terms, legal notices, or the Services may be directed as follows:

Ultimate, Inc. 16192 Coastal Highway Lewes, DE 19958 United States
Legal
legal@ultimate.dev
Security
security@ultimate.dev
Privacy
privacy@ultimate.dev
ContactPrivacyTermsDPASubprocessorsSecurity

Know what matters. Shape what's next.