Firmloom Terms of Use

Version: 2026-08-05 Effective date: 2026-08-05

These Terms of Use ("Terms") are a legal agreement between Creator Alliance Group Pty Ltd (ABN/ACN ABN 41 689 817 070), trading as Firmloom ("Firmloom", "we", "us", "our"), and the person or organization that accepts them ("you"). They govern access to and use of the Firmloom service described in Section 3.

Please read these Terms carefully. By accepting them (see Section 1), you agree to be bound by them. If you do not agree, do not accept them and do not use the Service.

In plain English: This is the contract for using Firmloom. Firmloom connects to your organization's email (and, over time, other systems you authorize), builds a searchable, permission-aware memory of it, and lets approved people and AI assistants ask questions of it. These Terms explain what you can expect from us, what we expect from you, and how the legal pieces (fees, data, liability, termination) fit together. The short summary boxes like this one are plain-language aids only — the numbered legal text below each box is what actually binds both of us.


1. Parties, Acceptance and Effective Date

In plain English: These Terms take effect when you tick the acceptance box at signup. If you are an administrator connecting an organization's systems, you are agreeing on behalf of that whole organization and everyone you let use Firmloom. If you are an individual connecting only your own mailbox, you are agreeing for yourself. When we publish a new version, we will ask you to accept it again before you keep using the admin console.

1.1 Who these Terms are between

These Terms are between Firmloom and:

(a) an organization — where an administrator accepts these Terms in connection with an organization-wide connection ("Application Mode", Section 3.2), in which case "you", "Customer" and "your" mean that organization, and the individual accepting warrants that they are authorized to bind it; or

(b) an individual — where a person accepts these Terms in connection with a connection of only their own mailbox ("Delegated Mode" or the "solo/delegated tier", Section 3.2), in which case "you", "Customer" and "your" mean that individual.

1.2 Acceptance mechanics (clickwrap)

You accept these Terms by ticking a checkbox that is unticked by default and that reads, in substance, "I have read and agree to the Terms of Use and Privacy Policy", with each document available to open before you tick it. Acceptance occurs before the connection process begins:

(a) in Application Mode, the administrator must accept before the Microsoft Entra administrator-consent step is initiated, and by accepting binds the organization and all of its Authorized Users; and

(b) in Delegated Mode, the individual must accept before the OAuth authorization step is initiated, and by accepting binds only themself.

We record each acceptance, including the accepting person's email, the document and Version accepted, the connection mode, the time of acceptance and (where available) the originating IP address. Acceptance is enforced by our systems, not merely by the interface: a connection cannot be established unless a current-Version acceptance is on record for it.

1.3 Authorized Users

If you are an organization, you are responsible for your Authorized Users' compliance with these Terms as if their acts and omissions were your own. Authorized Users access the Service under your account and under these Terms; you must ensure they are aware of and abide by the obligations in these Terms that apply to their use.

1.4 Version, effective date and re-acceptance

Each version of these Terms carries a Version string in the format YYYY-MM-DD and an Effective date, both shown at the top of this document. When we publish a materially changed version (Section 17), the Version string changes, and the next time an affected administrator or solo user signs in to the admin console they will be asked to accept the new Version before continuing. Machine-to-machine access by connected AI assistants (Section 6.4) is not interrupted by a pending re-acceptance, but the admin console remains gated until the current Version is accepted.

1.5 No professional advice

These Terms are a binding contract. Nothing in the Service, its outputs, or its documentation is legal, financial, tax, or other professional advice.


2. Definitions

In plain English: These are the capitalized words we reuse throughout both this document and our Privacy Policy, defined once so they mean the same thing everywhere. The most important ones: the Service is Firmloom; you are the Customer; the people you let in are Authorized Users; a Connected Source is any system (currently your Microsoft 365 mail, calendar, and Teams meeting transcripts, your SharePoint and OneDrive documents, and — if you connect it — your Salesforce org, which we only ever read from) you let us read; the Corpus is the raw content we ingest; Derived Data is what our AI builds from it; AI Providers and Subprocessors are the outside companies that help run the Service; and the Order Form is the quote or agreement that sets your plan and price. Google Workspace is listed in Schedule A.1 as a source suite that is not yet available — Gmail and Google Drive only, connected by each person individually rather than by one administrator. Nothing in these Terms lets us read a Google source until you authorize it and we make it available.

The following defined terms are used consistently across these Terms and the Privacy Policy:

Additional terms used in these Terms:


3. The Service

In plain English: Firmloom reads and stores your organization's email, sends content to AI providers to extract and organize it, and lets approved people and AI assistants (like Claude or ChatGPT) search it — always filtered to what each person is allowed to see. The AI-extracted answers and summaries can be incomplete or wrong. Firmloom shows you the exact source quotes behind every answer: check those before you rely on anything. Firmloom is a tool for finding and organizing information — it is not professional advice.

3.1 What the Service does

The Service ingests content from your Connected Sources via the relevant provider's API, parses and indexes it, generates Derived Data using AI Providers, applies permission and sensitivity filtering, and makes the result queryable through: (a) the web administration console; (b) programmatic API endpoints; and (c) MCP-compatible AI assistants that you connect (Section 6.4). Search queries are answered from Firmloom's own index; the specific data flows and Subprocessors involved are described in the Privacy Policy.

3.2 Connection modes

The Service supports two connection modes, which differ in who consents and to what:

(a) Application Mode — an administrator grants organization-wide access to the Connected Source (for Microsoft 365, the Microsoft Graph permissions required to read mail, mailbox settings, and directory data), acting for the organization. Access may be narrowed to an in-scope group of mailboxes by an access-control policy the Customer configures in the Connected Source (for Microsoft 365, an Exchange Application Access Policy). That policy is enforced by the Connected Source, not by Firmloom; Firmloom provides a check the Customer can run to verify it has taken effect, and does not condition onboarding on it.

(b) Delegated Mode — an individual authorizes access to only their own mailbox, acting for themself only, without organization-wide consent or directory access.

The available modes differ by source suite. Both modes above are available on Microsoft 365. On Google Workspace, Delegated Mode is the only mode: each individual authorizes access to their own Gmail mailbox and Google Drive content and may withdraw that authorization themselves, and there is no Application Mode equivalent. Firmloom does not use, and does not hold, Google's organization-wide domain-wide-delegation credential, because that credential can impersonate any user in a domain and Google provides no way to restrict it to a defined group or to demonstrate to you that it has been restricted. An administrator may separately authorize read-only access to the Google Workspace directory (users, groups, and group membership); that authorization connects no mailbox and grants no access to any individual's mail or files. Where these Terms describe organization-wide consent, they describe Microsoft 365 only.

3.3 AI-output disclaimer

The Service uses artificial intelligence, and AI output can be incomplete, inaccurate, or wrong. Decisions, commitments, risks, entities, relationships, summaries, and sensitivity classifications that the Service extracts or generates are automated interpretations of source material. They may miss content, misattribute it, or misstate it. The Service surfaces the exact source quotes and message references underlying its outputs so that you can verify them. You must not rely on any AI-generated output as a complete or accurate statement of fact without checking it against the cited sources. You are responsible for any decision you make based on the Service's output.

3.4 No professional advice

The Service does not provide legal, financial, tax, compliance, medical, or other professional advice, and its outputs must not be treated as such.

3.5 Availability and changes

We provide the Service on a commercially reasonable-efforts basis. We may modify, add to, or discontinue features of the Service as described in Section 17. We may perform maintenance and may impose reasonable technical limits (including rate limits) to protect the Service and its users.


4. Customer Responsibilities

In plain English: Before you connect a mailbox, you must have the legal right to do so. If you turn on features that read up the management chain, you must first tell the affected employees — and Firmloom actually blocks that feature until an administrator confirms they were told. You must keep your access scope and exclusions accurate, keep your account secure, and make sure the people you let in follow these Terms.

4.1 Lawful basis to connect

You represent and warrant that you have all rights, consents, and lawful bases necessary to authorize Firmloom to access, ingest, and process the content of each Connected Source you connect, including the mail of the mailboxes within your chosen scope and any personal data of third-party correspondents contained in that mail, and — where you connect Salesforce — the personal data of the contacts, users, and activity records in that org. In Application Mode, you represent that you are authorized to grant organization-wide access on behalf of the organization. Where a source suite offers only per-user connection (Google Workspace, Section 3.2), each connecting individual makes the equivalent representation for their own mailbox, and the organization remains responsible under this Section for having asked them to connect it.

4.2 Employee notification and transparency duty

Where you enable access that follows a management or reporting hierarchy (so that a manager's scope can reach subordinates' content), you must first inform the affected employees, consistent with applicable law and your own policies. The Service enforces this: an administrator must confirm that affected employees have been informed before hierarchy-based access is enabled. You are responsible for the truth of that confirmation and for making any employee notifications and disclosures required by law in your jurisdiction.

4.3 Scope, exclusions, and access-control policy

You are responsible for configuring and maintaining: (a) the in-scope mailbox group and any provider-side access-control policy (for Microsoft 365, the Exchange Application Access Policy) that narrows the Service's access; (b) the sensitivity exclusions and excluded mailbox addresses (such as HR, legal, or payroll addresses) that keep sensitive content out of scope; and (c) the accuracy of these settings over time as your organization changes. Firmloom provides the controls; you decide and maintain the configuration.

4.4 Account security

You must keep account credentials, administrator access, and issued tokens secure, restrict them to authorized individuals, and promptly notify us of any suspected compromise or unauthorized use. You are responsible for activity that occurs under your account and your Authorized Users' credentials, except to the extent caused by our breach of these Terms.

4.5 Authorized Users' conduct

You must ensure your Authorized Users comply with these Terms, including the acceptable-use rules in Section 8, and you are responsible for their use of the Service.

4.6 Cooperation

You must provide accurate account and billing information, respond to reasonable requests needed to provision or support the Service, and comply with the technical and configuration requirements documented for the Service.


5. Connected Sources and Consents

In plain English: Firmloom reads your Microsoft 365 mail, calendar, Teams meeting transcripts, and SharePoint and OneDrive documents today, and — if an administrator connects it — reads (never writes) your Salesforce org. Google Workspace (Gmail and Drive only, no calendar and no meetings) is listed in Schedule A.1 as not yet available. It is built to grow to other systems and AI providers over time. Each new source you connect needs its own fresh authorization from you. The source provider's own terms (like Microsoft's) also apply, and if a provider requires us to change or stop an integration, we may have to. We keep the current list of sources and providers in Schedule A, and can update that list by notice without rewriting these Terms.

5.1 The Connected Sources model

The Service is designed to connect to multiple categories of third-party system over time. Your obligations and our commitments in these Terms are written against the categories — Connected Source, AI Provider, Subprocessor — while the specific instances current at any time are listed in Schedule A and, for Subprocessors, in the Privacy Policy. As at the Effective date, the Connected Sources are Microsoft 365 mail, calendar, Teams meeting transcripts, and SharePoint and OneDrive documents (the last read only from sites or drives you select), and Salesforce where an administrator authorizes it — read-only, limited to the objects and fields itemized in Schedule A.1, and never written to — together with any further Current source listed in Schedule A.1. Any further sources noted in Schedule A are informational and do not take effect until made available and authorized by you. Google Workspace (Gmail, Google Drive, and the Workspace directory) is listed in Schedule A.1 as not yet available, and this Section states its scope in advance: on that suite Firmloom reads mail and documents only — no calendar, no contacts, and no meeting recordings or transcripts — requests no write scope of any kind, and takes consent from each individual for their own mailbox rather than organization-wide from an administrator (Section 3.2).

5.2 Fresh authorization for each source

Each Connected Source requires your fresh, specific authorization before the Service will access it. Adding a new Connected Source, or expanding the access scope of an existing one, requires a new authorization (for Microsoft 365, this corresponds to granting new or additional Graph permissions; for Google Workspace, to each affected individual granting new or additional OAuth scopes, since consent on that suite is given per person). We will not access a source you have not authorized.

5.3 Provider terms also apply

Your use of each Connected Source through the Service is also subject to that provider's own terms of service and acceptable-use policies (for example, Microsoft's terms for Microsoft 365 and Microsoft Graph). You are responsible for maintaining your own subscriptions and rights with those providers. Where the Service connects an AI assistant that you separately license (Section 6.4), your use of that assistant is governed by your agreement with that assistant's provider, not by these Terms.

5.4 Changes to sources and providers; suspension

We may add, change, or remove Connected Sources, AI Providers, and Subprocessors by updating Schedule A and, for Subprocessors, the Privacy Policy, and giving you notice (Section 17.3). We may suspend, modify, or discontinue an integration with a Connected Source or provider if that provider changes or withdraws access, requires it, or if continued integration would breach the provider's terms or applicable law. We will use reasonable efforts to give you advance notice where practicable.


6. Accounts, Seats and Tokens

In plain English: Access is managed by seats and by tokens. Your plan sets how many seats and mailboxes you get. Access tokens for AI assistants are shown to you once — copy and store them safely, because we only keep a hashed version and can't show them again. We periodically reconcile who has access, and administrators can add or remove users. Roles matter: administrators can do things ordinary users cannot.

6.1 Seats and mailbox scope

Your Order Form sets your seat allowance and mailbox cap. Seats and mailbox scope determine who and what the Service covers. Exceeding your allowances is handled under Section 7.3.

6.2 Administrator and user roles

The Service distinguishes administrator roles from ordinary user roles. Administrator capabilities (including scope configuration, exclusions, hierarchy enablement, erasure, and offboarding) are restricted to Authorized Users you designate as administrators. You are responsible for who you grant administrator rights to.

6.3 Tokens and credential hygiene

Access tokens issued for programmatic or assistant access are displayed to you once, at creation. We store only a hashed form of each token and cannot re-display it; you are responsible for storing tokens securely and rotating them if compromised. Tokens must not be shared beyond the Authorized Users entitled to them. Session and token rules (including any single-active-session rule) documented for the Service apply to your use.

6.4 Connected AI assistants

You may connect MCP-compatible AI assistants (such as Claude or ChatGPT) that you separately license, so that Authorized Users can query the Service through them. Those assistants receive only results the Service returns under the querying user's permissions. Your use of a connected assistant is governed by your agreement with the assistant's provider. We are not responsible for the assistant provider's processing of results once returned to it under your connection.

6.5 Seat reconciliation and deprovisioning

We periodically reconcile seats and access against your directory and plan. When an Authorized User is removed from your directory or their seat is withdrawn, their access is deprovisioned. You are responsible for promptly deprovisioning users who should no longer have access.


7. Fees and Payment

In plain English: Your price is set in your Order Form or quote — there is no public price list, and we do not put prices in this document. There may be a one-time setup or backfill fee. If you go over your seat allowance you'll be warned and then invoiced for the overage; going over your mailbox cap is blocked rather than billed. Invoices are due when the Order Form says. If you don't pay, we can suspend the Service, and continued non-payment leads to offboarding, which purges your data.

7.1 Fees are set by Order Form

Fees for the Service are those set out in your Order Form or quote. There is no public price list, and no pricing figures are stated in these Terms. Your plan tier, seat allowance, mailbox cap, and any one-time setup or backfill fee are as specified in your Order Form.

7.2 Invoicing and payment terms

We invoice the fees in your Order Form. Unless the Order Form states otherwise, invoices are payable within the period stated on the invoice or Order Form. You must keep your billing contact and details current.

7.3 Overages and tier changes

If your usage exceeds your seat allowance, we may first warn you and then invoice the additional seats used ("seat overage"). If your usage would exceed your mailbox cap, the Service may block the excess rather than invoice it ("mailbox overage is hard-limited"). Tier changes take effect as agreed in a revised Order Form. Our periodic reconciliation of usage is the reference for what is billed.

7.4 Taxes

Fees are exclusive of taxes. You are responsible for all sales, use, VAT, GST, and similar taxes on the fees, except taxes on our income. Where we are required to collect such taxes, they will be added to your invoice.

7.5 Late payment

Overdue amounts may accrue interest at the rate stated in the Order Form or, if none, the maximum rate permitted by law, and you are responsible for reasonable costs of collection. We may withhold or condition further work on payment of undisputed overdue amounts.

7.6 Non-payment: suspension and offboarding

If you fail to pay undisputed fees when due, we may, after giving notice and a reasonable opportunity to cure, suspend your access to the Service. Continued non-payment is a material breach entitling us to terminate under Section 16, which triggers the offboarding purge described in Sections 5 of the Privacy Policy and 16.4 of these Terms. Suspension does not relieve you of the obligation to pay fees accrued before suspension.


8. Acceptable Use

In plain English: Don't use Firmloom to surveil people beyond the scope you've disclosed and are allowed to access. Don't try to get around the permission filters, reverse-engineer the system, overload it, or try to re-identify data that has been anonymized as part of an erasure. Use it lawfully.

You must not, and must not permit any Authorized User or third party to:

(a) use the Service to conduct surveillance of individuals beyond the scope you have lawfully configured and, where required, disclosed;

(b) attempt to access content beyond your permitted scope, or to bypass, disable, or defeat the Service's permission filtering, sensitivity exclusions, tenant isolation, or access controls;

(c) reverse engineer, decompile, disassemble, or attempt to derive the source code, models, or underlying structure of the Service, except to the extent this restriction is prohibited by applicable law;

(d) probe, scan, or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, except under a testing arrangement we have authorized in writing;

(e) impose an unreasonable or disproportionately large load on the Service, exceed documented rate limits, or interfere with its integrity or performance;

(f) attempt to re-identify, reconstruct, or recover data that has been anonymized or erased through the Service's erasure or offboarding functions;

(g) use the Service to store or transmit unlawful, infringing, or malicious material, or to violate the rights of any person; or

(h) use the Service in violation of applicable law or of a Connected Source or AI Provider's terms.

We may suspend access that we reasonably believe violates this Section, consistent with Section 16.


9. Customer Data and Ownership

In plain English: Your data stays yours — both the email content we ingest and the AI-built memory made from it. You give us only the permission we need to run the Service for you. We can use anonymized, aggregated operational statistics (things like error rates and usage counts — never your email content) to run and improve the Service.

9.1 Ownership

As between you and Firmloom, you own and retain all right, title, and interest in your Corpus and your Derived Data. These Terms grant us no ownership of them.

9.2 License to us

You grant us a non-exclusive, worldwide license to host, copy, process, transmit, index, generate Derived Data from, and display the Corpus and Derived Data, solely as necessary to provide, secure, support, and maintain the Service for you and as otherwise permitted by these Terms and the Privacy Policy. This license ends when the relevant data is deleted or your account is offboarded, subject to Section 16.4.

9.3 Derived Data

Derived Data generated from your Corpus forms part of your data and is owned by you as set out in Section 9.1. We generate and maintain it to provide the Service.

9.4 Aggregated operational telemetry

We may collect and use aggregated, de-identified operational and telemetry data about the performance, reliability, and use of the Service (such as error metadata, latency, coverage metrics, and volume counts) to operate, secure, support, and improve the Service. Such data does not include the content of your Corpus. We do not use your Corpus or Derived Data to train AI models, and, as described in the Privacy Policy, we use AI Providers under terms that do not permit them to train on our API traffic.


10. Privacy and Data Processing

In plain English: Our Privacy Policy explains how we handle personal data, and it is part of this agreement. For organizations, you are the controller of your email content and we are your processor. If we sign a separate data processing agreement (DPA) with you, that DPA wins on data-processing questions.

10.1 Privacy Policy incorporated

Our Privacy Policy, published at /legal/privacy, is incorporated into these Terms by reference and describes how we collect, use, disclose, and protect personal data in connection with the Service.

10.2 Roles

For organization Customers, you are the controller of the personal data in your Corpus and we act as your processor for that data; we are the controller of account, billing, audit, and telemetry data. For solo/delegated-tier Customers, we act as controller as described in the Privacy Policy. These roles are stated more fully in the Privacy Policy.

10.3 DPA precedence

If you and Firmloom execute a DPA, that DPA governs the processing of personal data on your behalf and, to the extent of any conflict with these Terms on data-processing matters, the DPA controls. The order of precedence in Section 18.6 applies.


11. Confidentiality

In plain English: Each side must keep the other's confidential information private and use it only to work together under this agreement. This does not cover information that is already public, independently developed, or that the law requires to be disclosed.

11.1 Obligations

Each party ("receiving party") that receives non-public information of the other ("disclosing party") that is marked or reasonably understood to be confidential ("Confidential Information") must: (a) use it only to exercise its rights and perform its obligations under these Terms; (b) protect it with at least reasonable care; and (c) not disclose it except to its personnel, advisers, and Subprocessors who need it and are bound by confidentiality obligations at least as protective.

11.2 Exclusions

Confidential Information does not include information that is or becomes public without breach of these Terms, was known to the receiving party without a duty of confidentiality, is independently developed without use of the disclosing party's Confidential Information, or is rightfully received from a third party without restriction.

11.3 Compelled disclosure

The receiving party may disclose Confidential Information to the extent required by law or legal process, giving reasonable prior notice where lawfully permitted so the disclosing party may seek protection.


12. Intellectual Property

In plain English: We own Firmloom — the software, models, and how it works. You own your data. If you send us feedback or suggestions, we can use them to improve the Service without owing you anything.

12.1 Our IP

As between the parties, we and our licensors own all right, title, and interest in and to the Service, including its software, models, know-how, and all intellectual property rights in them. Except for the limited rights expressly granted in these Terms, no rights are granted to you in the Service.

12.2 Feedback

If you give us feedback, suggestions, or ideas about the Service, you grant us a perpetual, irrevocable, worldwide, royalty-free license to use them to develop and improve our products and services, without obligation or attribution to you.


13. Warranties and Disclaimers

In plain English: We'll provide the Service with reasonable care. Beyond that, the Service is provided "as is": we don't promise it will be error-free, uninterrupted, or that the AI's output will be accurate or complete. It is not professional advice. Some consumer-protection laws give you rights that cannot be excluded — nothing here takes those away.

13.1 Limited warranty

We warrant that we will provide the Service with reasonable skill and care and substantially as described in the applicable documentation.

13.2 Disclaimer

Except as expressly stated in Section 13.1, and subject to Section 14.4, the Service is provided "as is" and "as available". To the maximum extent permitted by law, we disclaim all other warranties, conditions, and representations, whether express, implied, statutory, or otherwise, including any implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, and any warranty arising from course of dealing or usage of trade. We do not warrant that the Service will be uninterrupted, error-free, or secure against all threats, or that its AI-generated output will be accurate, complete, or reliable (see Section 3.3). The Service is not, and does not provide, legal, financial, or other professional advice (Section 3.4).

13.3 Customer responsibility for reliance

You acknowledge Section 3.3 and are responsible for verifying AI-generated output against cited sources before relying on it.

13.4 Non-excludable rights

Sections 13.2 and 14 do not exclude, restrict, or modify any guarantee, condition, warranty, right, or remedy that applicable law confers on you and that cannot lawfully be excluded, restricted, or modified. See Section 14.4.


14. Limitation of Liability

In plain English: If something goes wrong, neither side is liable for indirect or consequential losses, and each side's total liability is capped at the fees you paid in the 12 months before the claim. This cap does not apply to a few things (like your payment obligations, breaches of confidentiality, your indemnities, or either side's willful misconduct). And in New South Wales, Australia, any consumer-protection rights that can't legally be excluded still apply on top of everything here.

14.1 Exclusion of indirect damages

To the maximum extent permitted by law, neither party is liable for any indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, goodwill, anticipated savings, or data (except costs of restoring data from your own backups), however caused and under any theory of liability, even if advised of the possibility.

14.2 Liability cap

To the maximum extent permitted by law, each party's total aggregate liability arising out of or related to these Terms is limited to the total fees paid or payable by you for the Service in the twelve (12) months immediately preceding the event giving rise to the liability.

14.3 Exclusions from the cap

The limitations in Sections 14.1 and 14.2 do not apply to: (a) your obligation to pay fees; (b) either party's breach of Section 11 (Confidentiality); (c) your obligations under Section 15 (Indemnities); (d) either party's fraud or willful misconduct; or (e) liability that cannot be limited or excluded under applicable law.

14.4 Consumer-law carve-out (New South Wales, Australia)

Nothing in these Terms excludes, restricts, or modifies any consumer guarantee, right, or remedy conferred by the applicable law of New South Wales, Australia that cannot lawfully be excluded, restricted, or modified. Where the law of New South Wales, Australia implies into these Terms any guarantee, condition, or warranty that cannot be excluded, and permits us to limit our liability for breach of it, our liability for that breach is limited, at our option and to the extent permitted, to re-supplying the relevant Service or paying the cost of having it re-supplied. Where the Australian Consumer Law applies, the guarantees it confers apply to the extent they cannot be excluded, and this Section operates as an "ACL guarantee" limitation to the extent permitted.

14.5 Basis of the bargain

The parties agree that the limitations and exclusions in this Section reflect a reasonable allocation of risk and are a fundamental basis of the bargain, including the fees charged.


15. Indemnities

In plain English: If you connect a mailbox you had no right to connect, or you fail to tell employees when you were required to, and someone brings a claim about it, you cover us. In return, if someone claims the Service itself infringes their intellectual property, we cover you.

15.1 Customer indemnity

You will defend, indemnify, and hold harmless Firmloom and its personnel from and against third-party claims, and reasonable resulting losses, damages, and costs (including reasonable legal fees), arising out of or relating to: (a) your connection of a Connected Source or mailbox that you were not authorized or lawfully entitled to connect; (b) your failure to make an employee notification or disclosure required by law or by Section 4.2; (c) your or your Authorized Users' breach of Section 8 (Acceptable Use); or (d) your breach of Section 4.1 (lawful basis).

15.2 Our IP indemnity

We will defend you against a third-party claim that the Service, as provided by us and used in accordance with these Terms, infringes that third party's intellectual property rights, and we will pay damages finally awarded (or a settlement we approve). This indemnity does not apply to claims arising from your Corpus, your Derived Data, a Connected Source, your combination of the Service with other products not provided by us, or your use in breach of these Terms. If the Service becomes, or we believe it may become, the subject of such a claim, we may procure the right for you to continue using it, modify it, or terminate the affected Service and refund prepaid unused fees.

15.3 Indemnity procedure

The indemnified party must promptly notify the indemnifying party of the claim, give it sole control of the defense and settlement (provided no settlement imposes liability or admission on the indemnified party without consent), and provide reasonable cooperation.


16. Term, Suspension and Termination

In plain English: The agreement runs for the term in your Order Form and can be ended for convenience with notice, or sooner for a serious unfixed breach. We can suspend access for urgent security, legal, or non-payment reasons. When things end, we purge your data on offboarding (target 72 hours) and give you a signed certificate proving it — and you get a window beforehand to ask for an export.

16.1 Term

These Terms apply from your first acceptance and continue for as long as you have an active Order Form or connection, or until terminated as set out below.

16.2 Termination for convenience

Either party may terminate for convenience on the notice period stated in the Order Form or, if none, on thirty (30) days' written notice. Termination for convenience does not entitle you to a refund of fees already accrued, except as stated in the Order Form.

16.3 Termination for cause and suspension

Either party may terminate immediately on written notice if the other materially breaches these Terms and fails to cure the breach within thirty (30) days of notice (or immediately, if the breach is incapable of cure). We may suspend access, in whole or part, where reasonably necessary to address a security risk, a legal requirement, a Connected Source or provider requirement, non-payment (Section 7.6), or a violation of Section 8. We will restore access when the cause is resolved, where the agreement remains in effect.

16.4 Effect of termination; offboarding purge and export

On termination or offboarding:

(a) your right to access the Service ends, and any outstanding accrued fees become due;

(b) we perform a full offboarding purge of your stored data (rows and blobs), with a target completion of seventy-two (72) hours, and, on completion, make available a signed, downloadable purge certificate evidencing the deletion; and

(c) before the purge, we provide a reasonable data-export window during which you may request available exports of your data. Export formats and scope are as documented or as reasonably agreed; where a requested export is not a standard feature, we will cooperate in good faith on a reasonable basis.

Sections that by their nature should survive termination (including Sections 9, 11, 12, 13, 14, 15, and 18) survive.


17. Changes to the Service and to These Terms

In plain English: We may improve or change the Service over time. When we make a material change to these Terms, we bump the version and ask you to accept the new version before you keep using the admin console — connected AI assistants keep working in the meantime. Smaller updates, like adding a new subprocessor or source to Schedule A, are made by notice without a re-signing.

17.1 Changes to the Service

We may modify, enhance, or discontinue features of the Service. We will not materially reduce the core functionality you are paying for during a paid term without giving you reasonable notice and, where the reduction is material and adverse, a right to terminate the affected Service for that reason.

17.2 Changes to these Terms; re-acceptance

We may update these Terms. When we make a material change, we will change the Version string and give you notice. Continued use after the change is subject to acceptance of the new Version: the next time an affected administrator or solo user signs in to the admin console, they must accept the current Version before continuing (Section 1.4). Machine-to-machine access by connected AI assistants is not interrupted by a pending re-acceptance. Non-material or clarifying changes may be made without re-acceptance.

17.3 Schedule updates by notice

Updates to Schedule A (Connected Sources) and to the Subprocessor list — for example, adding a new Connected Source, AI Provider, or Subprocessor — are made by updating the relevant schedule or the Privacy Policy and giving you notice, without a full re-draft or re-acceptance of these Terms. This mechanism lets the Service add sources and providers (Section 5) without rewriting the agreement.


18. General

In plain English: This last section is the standard legal machinery: which law applies and where disputes are heard, that you can't hand off the agreement without our okay, that neither side is liable for things outside its control, that this document plus your Order Form and any DPA is the whole deal, and — importantly — which document wins if they ever disagree: Order Form first, then DPA, then these Terms, then the Privacy Policy.

18.1 Governing law and jurisdiction

These Terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of New South Wales, Australia, without regard to conflict-of-laws rules.

18.2 Assignment

You may not assign or transfer these Terms without our prior written consent, except to a successor of all or substantially all of your business or assets that is not our competitor, on notice to us. We may assign these Terms to an affiliate or in connection with a merger, acquisition, or sale of assets. Any prohibited assignment is void.

18.3 Force majeure

Neither party is liable for failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including acts of God, outages of Connected Sources, AI Providers, or Subprocessors, network or infrastructure failures, government action, and labor disputes.

18.4 Notices

We may give notices via the admin console, by email to your registered contact, or through the Service. You may give notices to us at admin@creatoralliancegroup.com. Notices are effective when sent, if by email or in-product, or when delivered, if by other means.

18.5 Entire agreement; severability; waiver

These Terms, together with any Order Form, any DPA, the Privacy Policy, and Schedule A, are the entire agreement between the parties on their subject matter and supersede prior discussions. If any provision is held unenforceable, it is modified to the minimum extent necessary or severed, and the rest remains in effect. A failure to enforce a provision is not a waiver.

18.6 Order of precedence

If there is a conflict between documents forming this agreement, the following order of precedence applies, from highest to lowest: (1) the Order Form; (2) any executed DPA (which controls for personal-data processing matters, per Section 10.3); (3) these Terms of Use; and (4) the Privacy Policy. A more specific provision prevails over a general one on the same subject within the same document.

18.7 Independent contractors

The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, agency, or employment relationship.

18.8 No third-party beneficiaries

Except for indemnified persons under Section 15, these Terms do not confer rights on any third party.

18.9 Contact

Questions about these Terms may be sent to admin@creatoralliancegroup.com, Creator Alliance Group Pty Ltd, Suite 302, 13/15 Wentworth Avenue, Sydney NSW 2000, Australia.


Schedule A — Connected Sources and Subprocessors

In plain English: This is the living list of what Firmloom connects to and who helps run it. We can update it by notice (Section 17.3) as we add sources and providers, without rewriting the agreement above.

A.1 Connected Sources (current)

Connected Source Access Status
Microsoft 365 mail (via Microsoft Graph) Mail, mailbox settings, and directory data within your authorized scope Current — as at the Effective date
Microsoft 365 calendar (via Microsoft Graph) Calendar events within your authorized scope, access scoped by event attendees Current — as at the Effective date
Microsoft Teams meeting transcripts (via Microsoft Graph) Meeting transcript content for meetings organized within your tenant, narrowed by a Teams access policy Current — as at the Effective date
SharePoint and OneDrive documents (via Microsoft Graph) Document content and metadata linked from ingested mail Current — as at the Effective date
Gmail (via the Gmail API) Read-only. Message content, metadata, participants and attachments from the mailbox of each individual who connects their own Google account, bounded by your ingestion window. Firmloom requests https://www.googleapis.com/auth/gmail.readonly and no Gmail write scope — it sends, replies to, modifies, labels, inserts and deletes nothing Not yet available — disclosed in advance; not offered until Firmloom's application completes Google's OAuth verification
Google Drive documents (via the Google Drive API) Read-only. Document content and metadata, and each file's own sharing list, read so that Firmloom never shows a document to someone Drive does not already grant access to. Firmloom requests https://www.googleapis.com/auth/drive.readonly and no Drive write scope — it creates, modifies and deletes nothing Not yet available — disclosed in advance
Google Workspace directory (via the Admin SDK Directory API) Read-only. Licensed users (directory id, primary email, display name) and the membership of groups an administrator chooses to import. Requested only on an administrator's connection. Connecting the directory connects no mailbox Not yet available — disclosed in advance
Salesforce (via the Salesforce REST, Bulk 2.0, and Pub/Sub APIs) Read-only. Firmloom requests the api and refresh_token OAuth scopes only, and requests no write scope. From the Salesforce org an administrator connects, Firmloom reads eight standard objects and only the following fields from each: Account (Id, Name, Website, ParentId, SystemModstamp); Contact (Id, FirstName, LastName, Name, Email, AccountId, ReportsToId, Title, SystemModstamp); User (Id, Name, Email, IsActive, SystemModstamp); Opportunity (Id, Name, AccountId, Amount, StageName, IsClosed, IsWon, CloseDate, SystemModstamp); OpportunityContactRole (Id, OpportunityId, ContactId, Role, IsPrimary, SystemModstamp); OpportunityHistory (Id, OpportunityId, StageName, Amount, CreatedDate, SystemModstamp); Task and Event (Id, WhoId, WhatId, Subject, ActivityDate, SystemModstamp). No other object and no other field is stored. Where Change Data Capture is enabled on the connected org, Salesforce's change events may deliver other changed fields of a record; Firmloom discards those fields without storing them. Records so read are stored in Firmloom, and facts derived from them are labelled as asserted by the CRM rather than observed in communications, and follow CRM norms rather than mailbox grain — they are not restricted to the mailbox that received a message. They are not tenant-wide either: a seat is shown a CRM fact about an account only where it already has a visible window onto that account (at least one message it may read that mentions it), and a seat with no window onto an account is shown no CRM data for it. Disconnecting purges the staged CRM records. Current — available for you to authorize

Planned (informational only; not active until made available and authorized): additional third-party platforms, APIs, and integrations.

On the three Google rows. They are marked not yet available because no Customer can connect Google Workspace to the Service today. They are stated here in advance so that the scope of that suite — mail and documents only, read-only, per-user consent — is on the record before it is offered rather than after. No Google Calendar, Google Contacts, or Google Meet source appears in this table, and none is planned in this phase. When the suite becomes available these rows move to Current under Section 17.3.

A.2 Subprocessors and AI Providers (current)

The current list of Subprocessors, including AI Providers, is maintained in the Privacy Policy and summarized here. As at the Effective date it includes:

Subprocessor Category Purpose
Microsoft (Graph API / Entra ID) Connected Source platform, identity Source platform and identity for Microsoft 365
Google (Gmail API / Google Drive API / Admin SDK Directory API) Connected Source platform, identity Source platform and identity for Google Workspace — not yet available (Schedule A.1); mail and documents only, read-only, per-user consent
Salesforce (REST / Bulk 2.0 / Pub/Sub APIs) Connected Source platform Source platform for the Customer's own Salesforce org, only where the Customer connects one; read-only
Anthropic AI Provider Extraction, classification, summarization, evaluation
Voyage AI AI Provider Embeddings and reranking
Replit (one Reserved VM deployment running both halves of the product) Hosting and compute Hosting of the running application
Neon (managed Postgres) Database The relational database — all relational data, encrypted at rest by the provider
Amazon Web Services (Amazon S3) Blob storage Storage of blob content — raw MIME messages, attachment bytes, and extracted document/transcript text
Sentry Monitoring Error and trace monitoring
Resend Transactional email Operational email delivery (re-authentication reminders and administrator alerts)

May include (disclosed as planned): Amazon Web Services beyond the blob storage listed above — hosting and Amazon Bedrock model hosting in the Asia Pacific (Sydney) region, as part of the migration to Australian data residency (see the Privacy Policy); and a payment processor when billing is automated.

Updates to this Schedule are governed by Section 17.3.


Change Log

Version Effective date Summary of changes
2026-08-05 2026-08-05 Material change under Section 17.2. Google Workspace is disclosed as a second source suite, in advance of being offered. Section 2 gains a Source suite definition and states that calendar and meeting-transcript content are Microsoft 365 categories only. Section 3.2 states that Delegated Mode is the only mode on Google Workspace — there is no Application Mode equivalent, Firmloom does not use and does not hold Google's organization-wide domain-wide-delegation credential, and an administrator's read-only directory authorization connects no mailbox. Section 4.1 extends the lawful-basis representation to a suite where each person connects their own mailbox. Sections 5.1 and 5.2 state the Google scope and the per-person authorization mechanic. Schedule A.1 adds Gmail, Google Drive and the Google Workspace directory, all marked not yet available and all read-only, and Schedule A.2 adds Google as a source platform and identity Subprocessor on the same footing as Microsoft. This is a disclosure of scope in advance of availability, not a widening of what the Service reads today: no Customer can connect Google Workspace, and nothing in this amendment permits Firmloom to access a source you have not authorized (Section 5.2). It is published as a material change rather than a Schedule-only update because Sections 2, 3.2, 4.1 and 5.1 — the body of the agreement — had to change with it, and because Section 3.2 states a security property of the connection model that a Customer is entitled to be told about deliberately rather than to find in a schedule.
2026-08-03 2026-08-03 Version aligned with the Privacy Policy, which was amended on this date to list one additional Microsoft Graph scope. No clause of these Terms changed.
2026-08-02 2026-08-02 Version increase for the Salesforce amendment, which was first drafted under 2026-08-01 and is republished here. Sections 2, 4.1 and 5.1 name Salesforce as a Connected Source, and Schedule A.1 states the read-only OAuth scopes (api, refresh_token), the eight standard objects, and the exact fields stored from each. Section 4.1's representation is expanded accordingly: where you connect Salesforce, it covers the personal data of the contacts, users and activity records in that org. That is an expansion of a Customer representation and not merely a disclosure, so it is published under its own version rather than amended into 2026-08-01 — re-acceptance is keyed on the version string, and an amendment made in place under a version already published cannot trigger it. Schedule A.1 also states plainly that where Change Data Capture is enabled on the connected org, Salesforce's change events may deliver other changed fields of a record and Firmloom discards them without storing them. Schedule A.2 is corrected: hosting is ONE Reserved VM deployment running both halves of the Service, and Neon is listed as the managed-Postgres Subprocessor in its own right.
2026-08-01 2026-08-01 Material change under section 17.2, in two parts, both published under the same version and effective date. (1) Section 5.1 now names SharePoint and OneDrive documents among the Connected Sources current at the Effective date, matching this document's own Schedule A.1; and the application-mode description no longer represents the access-control policy as mandatory or as a precondition of completing onboarding — that policy is configured by the Customer and enforced by the Connected Source, and Firmloom provides a verification check the Customer can run instead. (2) Salesforce is disclosed as a Connected Source (Schedule A.1), and sections 2, 4.1 and 5.1 are amended to name it. This is a disclosure of an integration already built into the Service, not a new or widened processing activity: the Service requests read-only OAuth scopes (api, refresh_token) and no write scope, reads eight standard objects and only the fields itemized in Schedule A.1, and reads nothing at all unless an administrator connects an org. It was previously absent from this agreement, which understated the scope of what the Service can be authorized to read — including personal data of third parties held in the Customer's CRM.
2026-07-28 2026-07-28 Version increase only. These Terms are unchanged; the version tracks the Privacy Policy amendment of the same date, which narrowed the mail ingestion scope (unsent drafts are never read). Firmloom publishes both documents under one acceptance version, so a material Privacy Policy change moves this version too.
2026-07-11 2026-07-26 Schedule-only update under Section 17.3: corrected Schedule A.2 — Amazon Web Services (Amazon S3) is a current Subprocessor for blob storage, not a planned one; the Replit row is narrowed to hosting, compute, and the Neon-backed database.
2026-07-11 2026-07-11 Added SharePoint and OneDrive documents as a Current Connected Source (Schedule A).
2026-07-10 2026-07-10 Initial publication of the Firmloom Terms of Use.

These Terms of Use are a binding agreement. Capitalized terms have the meanings given in Section 2 and are used consistently with the Firmloom Privacy Policy.