Please read these terms carefully before using BITSTRIC services.
Last updated: Sep 20, 2026
Version 2.0 · Supersedes prior version on 9 May 2026
This summary helps you navigate. It is not a substitute for the Terms below, which govern if there is any difference.
| Topic | Short answer | Where |
|---|---|---|
| Who you contract with | BITSTRIC Pte. Ltd., a Singapore company | §1 |
| Which document wins | A signed agreement and Data Processing Agreement first, then your Order, then the Service-Specific Terms, then these General Terms | §3 |
| Do you train AI models on our data? | No — not without your written agreement | §7, §15.5 |
| Who touches regulated environments? | Only Singapore-based BITSTRIC personnel, unless you agree otherwise in writing | §7, §12.3 |
| Is anything "free discovery"? | Introductory calls are free and non-binding. Discovery, readiness, and pilot engagements are paid, fixed-scope work | §8 |
| Are preview features production-ready? | No. Preview, pilot, and early-access features are provided as-is, without service levels | §14 |
| Do you certify us as compliant? | No. We provide evidence, mapping, and engineering support — not certification, audit opinions, or legal advice | §15.8, §19.5 |
| How much can each side claim? | Generally capped at 12 months of fees for the relevant Order, with a higher cap for data-protection breaches and no cap for fraud, death, or personal injury | §20 |
| Can we get our data back? | Yes — a 30-day export window after termination, then deletion | §23 |
| Will you change the Terms on us mid-contract? | Material adverse changes do not bind an active paid Order until renewal, unless required by law | §31 |
| Disputes | Senior-level escalation first, then SIAC arbitration in Singapore. Consumers may use the Small Claims Tribunals | §34 |
1.1 Who we are. "BITSTRIC", "we", "us", and "our" mean BITSTRIC Pte. Ltd. (UEN [●]), and, where the context requires, its Affiliates acting on its behalf.
1.2 Agreement to these Terms. These Terms of Service ("Terms") govern your access to and use of the Website, the Platform, and the Services. You accept these Terms when you (a) browse or use the Website, (b) create an account or access a portal, (c) submit an enquiry, assessment, or checkout form, (d) click or otherwise indicate acceptance electronically, (e) sign or accept an Order, or (f) use any Service. Electronic acceptance has the same effect as a signature, consistent with the Electronic Transactions Act 2010. If you do not agree, do not use the Website or Services.
1.3 Acting for an organisation. If you act on behalf of an organisation, you represent that you are authorised to bind it, and "you" and "Client" include that organisation.
1.4 Predecessor business. Before the incorporation of BITSTRIC Pte. Ltd., services were offered under the name "BITSTRIC" by Bitstric Solution (the "Predecessor"). Engagements entered into with the Predecessor continue on their existing terms until transferred to BITSTRIC Pte. Ltd. by novation or other written agreement with the relevant client. We will contact affected clients directly. From the Effective Date, all new engagements, Orders, accounts, and Website use are with BITSTRIC Pte. Ltd.
1.5 Business use and consumers. The Website and Services are intended primarily for business, professional, and public-sector use. Certain SIRE household features may be offered to individuals acting in a personal capacity ("Consumers"). If you are a Consumer, nothing in these Terms excludes or limits any right or remedy you have under the Consumer Protection (Fair Trading) Act 2003 or any other law that cannot be excluded by contract, and §34.5 applies to you.
1.6 Age. You must be at least 18 years old to create an account or enter into an Order.
In these Terms:
3.1 What makes up the Agreement. For any engagement, the Agreement consists of: (a) any master, professional services, or subscription agreement signed by both parties ("Master Agreement"); (b) any DPA; (c) the applicable Order; (d) the Service-Specific Terms; (e) these General Terms; and (f) the Documentation and policies expressly incorporated by reference, including the Privacy Policy and Acceptable Use Policy.
3.2 Conflicts. If documents conflict, they apply in this order: (i) the Master Agreement; (ii) the DPA, but only for matters concerning Personal Data; (iii) the Order, but only for that engagement and only where the Order expressly states that it overrides a specified provision; (iv) the Service-Specific Terms; (v) these General Terms; (vi) the Documentation.
3.3 Client paper excluded. Terms in a Client's purchase order, vendor registration portal, supplier code, invoice-processing system, or similar document do not form part of the Agreement and have no effect, even if acknowledged, clicked through, or signed by BITSTRIC personnel for administrative purposes, unless a director of BITSTRIC signs a document that expressly identifies those terms and states that they override these Terms.
3.4 Proposals. Proposals and quotations are valid for 30 days unless stated otherwise. They are not binding offers and create no obligation until an Order is accepted by both parties.
4.1 Credentials. Where the Services require an account, you must keep credentials, API keys, and access tokens confidential; use multi-factor authentication where offered; and promptly notify us at [[email protected]] of any actual or suspected unauthorised access.
4.2 Responsibility for use. The Client is responsible for all activity under its accounts and credentials and for its Authorised Users' compliance with these Terms, except to the extent the activity results from BITSTRIC's failure to implement reasonable access controls within systems BITSTRIC operates.
4.3 Accurate information. You must provide accurate, current, and complete information and keep it up to date.
5.1 Prohibited conduct. You must not, and must not permit anyone to:
5.2 Enforcement. We may investigate suspected breaches, preserve relevant records, cooperate with law-enforcement and regulatory authorities, and take proportionate action under §22.3.
5.3 Responsible disclosure. We welcome good-faith security research. Report suspected vulnerabilities to [[email protected]]. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access or modify data beyond what is needed to demonstrate the issue, and give us reasonable time to fix the issue before disclosure.
6.1 Information only. Website content, articles, frameworks, templates, whitepapers, diagrams, leaderboards, and other public materials ("Public Materials") are for general information only. They are not legal, tax, financial, cybersecurity, certification, or regulatory advice, and do not create an advisory or professional relationship.
6.2 No guarantee of currency. We may update or withdraw Public Materials at any time. Public Materials may not reflect the latest legal, regulatory, technical, or market developments.
6.3 Roadmap statements. Any feature, product, integration, or capability described as "planned", "preview", "pilot", "early access", "future milestone", "coming soon", or similar is a statement of current intent only. It is not a commitment to deliver, and you should not rely on it when deciding whether to purchase any Service.
6.4 Third-party links. Links to third-party websites or resources are provided for convenience. We do not control or endorse them, and you use them at your own risk.
6.5 Marketing communications. If you subscribe to updates, we will send them in accordance with the Spam Control Act 2007 and the PDPA, including the Do Not Call provisions where applicable. You may unsubscribe at any time using the link in each message.
These commitments are binding obligations under the Agreement, subject to Part F.
7.1 No training on your data. We do not use Client Data to train, fine-tune, or improve general-purpose AI models, or any model made available to other clients, and we do not permit our providers to do so, unless you agree in writing in an Order that specifies the purpose and scope.
7.2 Prime accountability. Where we use subcontractors or delivery partners, we remain responsible to you for their performance as if it were our own (§12.2).
7.3 Regulated environments. Only BITSTRIC personnel based in Singapore access Regulated Client Environments, unless you agree otherwise in writing (§12.3).
7.4 Data location. Where we host or store Client Data, we do so in the location stated in your Order. For Regulated Clients, the default location is Singapore.
7.5 Incident notification. We will notify you of a Security Incident affecting your Client Data without undue delay, as set out in §16.5.
7.6 Exit and portability. You can export your Client Data at the end of an engagement (§23.3).
7.7 Accurate capability statements. We do not describe a Service as generally available unless its Documentation states that it is. Preview Features are labelled as such.
7.8 Named accountability. Each Order identifies a BITSTRIC principal who is accountable for delivery of that engagement.
8.1 Stages. BITSTRIC engagements typically follow these stages: Discover (use cases, data exposure, platform stack, risk); Design (architecture, controls, metrics, scope); Pilot (a narrow, fixed-scope workflow or deployment); Deploy (production implementation); and Govern (ongoing managed governance). Each stage is a separate Order unless an Order combines them.
8.2 Introductory calls versus paid engagements. Introductory and scoping calls are free of charge. They are informational only, create no advisory relationship, and carry no duty of care. Discovery, risk review, readiness assessment, and proof-of-concept engagements are paid, fixed-scope engagements, unless an Order expressly states otherwise.
8.3 Pilots and proofs of concept. Each pilot or proof of concept ("Pilot") has a fixed scope, duration, and success criteria stated in its Order. Completing a Pilot does not oblige either party to enter into further Orders, unless the Pilot Order contains conversion terms (for example, a subscription commitment triggered by meeting agreed success criteria), in which case those terms apply. No Pilot converts to a paid subscription without the Client's express acceptance of the conversion terms in the Order.
8.4 Design-partner arrangements. Where an Order grants design-partner pricing, the Client provides the reference, case-study, and feedback rights stated in that Order in return.
9.1 Fees. Fees are stated in the Order and, unless stated otherwise, are in Singapore dollars.
9.2 Deposits. Where an Order requires a deposit or upfront payment, work begins only after we receive cleared funds. Deposits are non-refundable, except that we will refund the unperformed portion if (a) we cancel the engagement before work begins for reasons other than your breach, or (b) you terminate under §22.4 for our uncured material breach.
9.3 Milestone billing. For project engagements, Fees are invoiced on the milestones stated in the Order, typically tied to acceptance or handover events.
9.4 Subscriptions and retainers. Subscription, managed-service, and retainer Fees are invoiced quarterly in advance unless the Order or online checkout states otherwise.
9.5 Payment terms. Invoices are payable within [14] days of the invoice date unless the Order states otherwise.
9.6 Late payment. On overdue amounts, we may charge interest at [1]% per month (or the maximum rate permitted by law, if lower) from the due date until payment, together with reasonable costs of recovery. If an undisputed amount remains unpaid [14] days after we give written notice of non-payment, we may suspend work and access under §22.3(d) until payment is received. Agreed timelines extend by the period of any suspension, and re-mobilisation may be charged.
9.7 Invoice disputes. If you dispute an invoice in good faith, notify us in writing within [10] Business Days of receipt, giving reasons, and pay the undisputed portion by the due date. Invoices not disputed within that period are treated as accepted, without prejudice to your statutory rights.
9.8 Taxes. Fees exclude goods and services tax ("GST") and other taxes, duties, and levies. Where BITSTRIC is registered for GST, GST is charged at the prevailing rate. If you are required by law to withhold tax, you must increase the payment so that we receive the amount we would have received without the withholding, and provide evidence of the withholding.
9.9 Pass-through costs. Third-party cloud, compute, model-API, software-licence, hardware, travel, and similar costs are procured under your own accounts or billed to you as stated in the Order. We do not absorb these costs.
9.10 Renewal pricing. We may change subscription Fees effective from a renewal date by giving at least [60] days' written notice. If you do not accept the change, you may elect not to renew under §22.2.
9.11 No set-off. You must pay all amounts without set-off, counterclaim, or deduction, except as required by law.
10.1 Cooperation. The Client must provide, on time, the access, information, documentation, decisions, personnel, approvals, interviews, and technical support reasonably required, and must identify all relevant systems, vendors, risks, policies, and stakeholders.
10.2 Client systems. The Client remains responsible for its Client Environments, including infrastructure, access control, backups, change management, vendor relationships, internal policies, and production decisions.
10.3 Reliance on Client information. Our work relies on the evidence, access, assumptions, and representations the Client provides. We are not responsible for errors resulting from inaccurate, incomplete, or late information.
10.4 Change control. Changes to scope, systems, data, Deliverables, timelines, integrations, or assumptions require a written change request agreed by both parties, which may adjust Fees and timelines. We are not obliged to perform out-of-scope work until a change request is agreed.
10.5 Client-caused delay. If Client dependencies are not met, we may extend timelines, pause work, and charge for idle time and re-mobilisation as stated in the Order. If a pause caused by the Client lasts longer than [30] days, we may invoice work performed to date and treat the affected milestone as complete for billing purposes.
11.1 Criteria. Deliverables are tested against the acceptance criteria in the Order.
11.2 Acceptance period. Within [10] Business Days of delivery, the Client must either accept the Deliverable or reject it by written notice that identifies how it fails the acceptance criteria.
11.3 Deemed acceptance. A Deliverable is accepted on the earlier of (a) written acceptance; (b) expiry of the acceptance period without a compliant rejection notice; or (c) use of the Deliverable in production or for its intended business purpose.
11.4 Remediation. If a Deliverable is properly rejected, we will correct and resubmit it. If it fails the acceptance criteria after two resubmissions, the parties' senior representatives will meet under §34.2. If the issue is not resolved within [15] Business Days after that meeting, either party may terminate the affected milestone, and we will refund the Fees paid for that milestone only.
12.1 Delivery method. We determine the personnel, methods, and tools used to deliver the Services. We may use employees, Affiliates, independent contractors, and local delivery partners.
12.2 Responsibility. We remain responsible for the acts and omissions of our subcontractors and delivery partners as if they were our own.
12.3 Regulated Client Environments. Only BITSTRIC personnel based in Singapore, or Singapore-based delivery partners working under BITSTRIC's documented procedures, may access Regulated Client Environments, unless the Client agrees otherwise in writing. Personnel and contractors based outside Singapore do not access Regulated Client Environments.
12.4 Sub-processors. Our current list of sub-processors for Client Personal Data is available on request and in the DPA. We will give notice of new sub-processors as set out in the DPA, and the Client may object on reasonable data-protection grounds.
12.5 Personnel changes. We may replace personnel, including named principals, with suitably qualified personnel on reasonable notice.
12.6 Site policies. Personnel working on Client premises will comply with the Client's reasonable site, security, and conduct policies that have been notified to us in writing in advance.
13.1 Third-party services. Some Services use or connect to third-party cloud providers, AI model providers, SaaS applications, Model Context Protocol (MCP) and other connected services, and telecommunications operators. The provider's terms govern those services. The Client is responsible for accepting and complying with those terms where the services are procured under its accounts. We are not responsible for third-party services' availability, performance, data practices, pricing, or changes.
13.2 Open-source software. Open-source components are licensed under their own licences, and nothing in these Terms restricts rights granted to you under those licences. Notices are available on request or in the Documentation.
13.3 Hardware. Unless an Order expressly states that BITSTRIC sells hardware, hardware used in the Services is supplied by an authorised manufacturer or channel partner under that supplier's terms. Title, risk, warranty, and returns for that hardware are between the Client and the supplier.
13.4 Third-party trade marks. Third-party names and trade marks are used only to identify the relevant products and remain the property of their owners. Their use does not imply any affiliation, sponsorship, endorsement, or partnership, unless we expressly state otherwise.
13.5 Provider changes. If a third party changes or discontinues a component that a Service depends on, we may substitute a component with materially similar functionality after giving notice. If the change materially and adversely affects a paid Service and we cannot provide a reasonable substitute, the Client may terminate the affected Service on written notice and receive a pro-rata refund of prepaid Fees for the unused period.
14.1 What they are. Features or products identified as "preview", "beta", "pilot", "early access", "evaluation", or similar, and anything we provide at no charge ("Preview Features"), are made available so that you can evaluate them and give feedback.
14.2 Terms. Preview Features are provided "as is" and "as available", without service levels, support commitments, or warranties. They may contain defects, may be changed, suspended, or discontinued at any time without liability, and are not intended for production use or for processing Regulated Client Environment data unless an Order expressly permits it.
14.3 Liability. To the extent permitted by law, our total liability for Preview Features is limited to S$[500].
14.4 Confidentiality. Preview Features, and your feedback on them, are BITSTRIC Confidential Information.
15.1 Nature of Outputs. AI systems are probabilistic. Outputs may be inaccurate, incomplete, biased, outdated, non-deterministic, or unsuitable for a particular purpose, and may vary between runs. Outputs are decision-support information, not decisions.
15.2 Human review and accountability. The Client must apply appropriate human review before relying on Outputs for business, legal, financial, credit, employment, clinical, safety, regulatory, or other high-impact purposes. The Client remains accountable for decisions it makes and actions it takes.
15.3 Agentic systems. For AI agents and agentic workflows:
15.4 Model and performance drift. Model providers change models, and model behaviour and performance can drift over time. Governance and monitoring Services are designed to help detect drift and risk. They do not prevent drift, and they do not guarantee that every issue will be detected.
15.5 No training. Our commitment in §7.1 applies. Any fine-tuning, evaluation, benchmarking, or synthetic-data generation using Client Data is performed only as scoped in an Order, and the resulting Client-specific artefacts are used only for that Client.
15.6 Outputs. As between the parties, and subject to third-party provider terms, the Client owns Outputs generated from Client Data in the course of the Client's use of the Services. We do not warrant that Outputs are original or that they do not infringe third-party rights, and similar Outputs may be generated for others.
15.7 Prohibited AI uses. The Client must not use the Services to (a) make solely automated decisions producing legal or similarly significant effects on individuals without meaningful human review; (b) carry out unlawful biometric identification or surveillance; (c) generate deceptive content impersonating real persons or organisations; or (d) develop weapons or facilitate serious harm.
15.8 Regulatory frameworks. References to frameworks and standards — including the MAS Technology Risk Management Guidelines, MAS notices and guidelines, the PDPA, the Model AI Governance Framework, the Government Instruction Manual on ICT and Smart Systems Management (IM8), the Cybersecurity Code of Practice, ISO/IEC 42001, ISO/IEC 27001, SOC 2, NIST publications, and HIPAA — describe mapping, evidence-collection, and engineering support. They are not a certification, attestation, audit opinion, legal opinion, or regulatory determination. Conclusions about compliance rest with the Client, its auditors, and the relevant authorities.
16.1 Website data. For Personal Data we collect through the Website, enquiries, and our own business relationships, BITSTRIC is the responsible organisation under the PDPA, and our Privacy Policy [link] applies.
16.2 Client Data. Where we process Personal Data in Client Data on the Client's behalf, the Client is the responsible organisation and BITSTRIC acts as its data intermediary. The DPA sets out the processing details, and we process such Personal Data only on the Client's documented instructions and for the purposes of the Agreement.
16.3 Client obligations. The Client must (a) have a lawful basis, notifications, and consents required under the PDPA and other applicable law for the Personal Data it provides; (b) minimise the Personal Data it submits; and (c) not submit NRIC numbers or other national identification numbers unless they are necessary and permitted by law and the PDPC's advisory guidelines.
16.4 Security. We maintain reasonable security arrangements, proportionate to the nature of the data and the Services, to protect Client Data in our possession or control against unauthorised access, collection, use, disclosure, copying, modification, disposal, and loss, as described in the Documentation and DPA.
16.5 Security Incidents. If we become aware of a breach of security leading to the accidental or unlawful loss of, or unauthorised access to, or disclosure of, Client Data in our possession or control (a "Security Incident"), we will (a) notify the Client without undue delay, and in any event within [48] hours after confirming the Security Incident; (b) provide the information reasonably available to help the Client assess whether the incident is notifiable and meet its own notification obligations to the PDPC, regulators, and affected individuals; and (c) take reasonable steps to contain and remediate the incident.
16.6 Cross-border transfers. We transfer Personal Data outside Singapore only in accordance with the PDPA and the Personal Data Protection Regulations 2021, the DPA, and any data-location commitment in the Order.
16.7 Retention and return. We retain Client Data only for as long as needed for the Services, legal obligations, and the periods in §23.
16.8 Service Data. We may collect and use technical telemetry, usage metrics, and security logs about the operation of the Services ("Service Data") to provide, secure, support, and improve the Services, and may create aggregated and de-identified statistics from it. Service Data does not include the content of Client Data. We do not use Service Data to identify the Client or any individual publicly, and we do not sell it.
17.1 Definition. "Confidential Information" means non-public information disclosed by or on behalf of one party ("Discloser") to the other ("Recipient") that is marked as confidential or that a reasonable person would understand to be confidential. Client Data is the Client's Confidential Information. BITSTRIC Materials, pricing, non-public product information, Preview Features, and evaluation methodologies are BITSTRIC's Confidential Information.
17.2 Obligations. The Recipient must (a) use Confidential Information only to perform or receive the Services; (b) protect it with at least reasonable care; and (c) disclose it only to its and its Affiliates' personnel, contractors, professional advisers, auditors, and insurers who need to know it and are bound by confidentiality obligations at least as protective.
17.3 Exclusions. Confidentiality obligations do not apply to information that (a) is or becomes public through no fault of the Recipient; (b) the Recipient already lawfully knew; (c) is lawfully received from a third party without restriction; or (d) is independently developed without use of the Discloser's information.
17.4 Compelled disclosure. The Recipient may disclose Confidential Information if required by law, court order, or a regulatory or supervisory authority. Where lawful, it must give prompt notice and disclose only what is required. A Regulated Client may disclose BITSTRIC's Confidential Information to its regulators and statutory auditors to the extent they request it.
17.5 Duration. These obligations continue for [5] years after the Agreement ends, and indefinitely for trade secrets and Client Data.
18.1 BITSTRIC Materials. BITSTRIC and its licensors retain all rights in the Website, the Platform (including the Aether™ platform components and Kage™ middleware), Documentation, methodologies, evaluation frameworks, scoring and weighting logic, benchmarks, harnesses, prompts, scripts, templates, checklists, tools, libraries, know-how, and all improvements to them, whether created before or during an engagement ("BITSTRIC Materials"). No rights are granted except those expressly stated.
18.2 Client Materials. The Client retains all rights in Client Data and in its pre-existing documents, systems, and materials. The Client grants BITSTRIC a non-exclusive licence to use them solely to provide the Services, and warrants that it has the rights needed to grant that licence.
18.3 Deliverables. Subject to full payment of the applicable Fees:
18.4 Residual know-how. Each party may use general skills, knowledge, and experience retained in unaided memory, provided it does not disclose the other party's Confidential Information or infringe its intellectual property.
18.5 Feedback. If you provide suggestions or feedback, we may use them without restriction or compensation. Feedback is not your Confidential Information unless it contains Client Data.
18.6 Trade marks. BITSTRIC, Aether™, Kage™, SIRE, Laminar, IEI, and associated names and logos are trade marks of BITSTRIC Pte. Ltd., whether registered or unregistered. You may not use them without our prior written consent, except to identify our Services accurately.
18.7 Restrictions. Except to the extent a restriction is prohibited by the Copyright Act 2021 or other applicable law, you must not copy, modify, create derivative works of, reverse engineer, decompile, or disassemble any part of the Platform or BITSTRIC Materials.
19.1 Our warranties. We warrant that we will perform the Services (a) with reasonable skill and care, consistent with good industry practice for comparable services; (b) using suitably qualified personnel; and (c) in compliance with laws applicable to us as a provider of the Services.
19.2 Remedy. If we breach §19.1 and you notify us within [30] days of the relevant performance, we will re-perform the non-conforming Services. If re-performance does not remedy the breach, we will refund the Fees paid for the non-conforming part. This is your exclusive remedy for breach of §19.1, without prejudice to §7, §16, §17, and §21.1.
19.3 Mutual warranty. Each party warrants that it has authority to enter into the Agreement.
19.4 Disclaimer. Except as expressly stated in the Agreement, and to the fullest extent permitted by law, the Services, Platform, Outputs, and Public Materials are provided without any other warranty, representation, or condition, whether express, implied, or statutory, including as to satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement. We do not guarantee (a) uninterrupted or error-free operation; (b) prevention of security breaches, scams, fraud, or losses; (c) any particular model performance, business outcome, revenue, or cost saving; or (d) that any audit, certification, procurement process, or regulatory review will be passed.
19.5 Not a regulated professional service. BITSTRIC is not a law firm, public accounting firm, statutory auditor, certification body, regulator, licensed financial adviser, or insurer. Unless we hold the applicable licence and the Order expressly states otherwise, BITSTRIC does not provide penetration-testing services or managed security operations centre (SOC) monitoring services within the meaning of the Cybersecurity Act 2018. Our advisory work supports your decision-making. It does not replace your management accountability or independent professional advice.
20.1 Liability that is not limited. Nothing in the Agreement limits or excludes liability for (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) wilful misconduct; (d) the Client's obligation to pay Fees; (e) the Client's breach of §5 or infringement of BITSTRIC's intellectual property; or (f) any other liability that cannot be limited or excluded by law.
20.2 Excluded losses. Subject to §20.1, neither party is liable to the other, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, for any (a) loss of profit, revenue, business, contracts, or anticipated savings; (b) loss of goodwill or reputation; (c) loss of business opportunity; (d) loss or corruption of data, except the reasonable cost of restoring data from the Client's most recent backup where BITSTRIC caused the loss; or (e) indirect or consequential loss, in each case whether or not foreseeable.
20.3 General cap. Subject to §20.1, §20.4, and §20.5, each party's total aggregate liability arising out of or in connection with an Order is limited to the Fees paid and payable under that Order in the 12 months before the event giving rise to the claim. For a fixed-fee engagement shorter than 12 months, the limit is the total Fees under that Order.
20.4 Data-protection cap. For claims arising from BITSTRIC's breach of §16 or §17, BITSTRIC's total aggregate liability is limited to [two (2)] times the amount in §20.3. This is a separate cap, and the two caps do not add together for the same claim.
20.5 Free and Preview Services. For Services provided free of charge and for Preview Features, §14.3 applies.
20.6 Consumers. For Consumers, §20.2 to §20.5 apply only to the extent permitted by the Consumer Protection (Fair Trading) Act 2003, the Unfair Contract Terms Act 1977, and other applicable law.
20.7 Basis of the bargain. The parties agree that these limits are reasonable, having regard to the Fees, the availability of insurance, each party's ability to control the relevant risks, and each party's opportunity to seek advice and negotiate.
20.8 Time limit for claims. To the extent permitted by law, any claim arising under the Agreement must be notified in writing within [12] months after the claimant became aware, or ought reasonably to have become aware, of the facts giving rise to it, and proceedings must be commenced within [12] months after that notice. This clause does not apply to claims under §20.1 or to claims for unpaid Fees.
20.9 Mitigation. Each party must take reasonable steps to mitigate any loss it suffers.
21.1 By BITSTRIC. BITSTRIC will defend the Client against any third-party claim alleging that BITSTRIC Materials or Deliverables, as provided by BITSTRIC and used in accordance with the Agreement, infringe that third party's intellectual property rights enforceable in Singapore, and will pay damages and costs finally awarded or agreed in settlement. BITSTRIC has no obligation to the extent a claim arises from (a) Client Data or Client materials; (b) modification by anyone other than BITSTRIC; (c) combination with items not supplied by BITSTRIC; (d) Third-Party Components or open-source software; (e) use outside the Documentation or Agreement; or (f) continued use after BITSTRIC has provided a non-infringing alternative. If a claim is made or likely, BITSTRIC may modify or replace the item, procure a licence, or terminate the affected Service and refund prepaid Fees for the unused period. BITSTRIC's liability under this §21.1 is subject to the cap in §20.4.
21.2 By the Client. The Client will defend BITSTRIC against, and indemnify BITSTRIC for losses arising from, any third-party claim (including by a regulator) to the extent it arises from (a) Client Data or Client materials, including claims that they infringe rights or were collected or provided unlawfully; (b) the Client's or its Authorised Users' breach of §5 or §16.3; (c) AI system actions taken within a configuration the Client approved, as described in §15.3(d); or (d) the Client's use of Outputs or Deliverables in its dealings with its own customers, end users, or counterparties.
21.3 Procedure. The indemnified party must (a) notify the indemnifying party promptly; (b) allow it sole control of the defence and settlement, provided that no settlement admitting fault or imposing obligations on the indemnified party may be made without its consent (not to be unreasonably withheld); and (c) give reasonable assistance at the indemnifying party's cost.
22.1 Term. Each Order runs for the term stated in it.
22.2 Renewal. Subscription and managed-service Orders renew automatically for successive periods equal to the initial term (up to 12 months each), unless either party gives at least [60] days' written notice of non-renewal before the end of the current term. We will send a renewal reminder at least [90] days before the renewal date. Pilots do not renew automatically.
22.3 Suspension. We may suspend all or part of the Services, limited to what is reasonably necessary, if:
We will give notice before suspending where practicable (and otherwise promptly afterwards), and restore the Services promptly once the cause is resolved. Fees continue to accrue during a suspension under (c) or (d).
22.4 Termination for cause. Either party may terminate an Order by written notice if the other party (a) commits a material breach that is not remedied within [30] days after written notice describing it; or (b) to the extent permitted by the Insolvency, Restructuring and Dissolution Act 2018 and other applicable law, becomes insolvent, enters liquidation, or ceases to carry on business.
22.5 Termination for legal or risk reasons. We may terminate an affected Order on written notice if continuing to provide it would breach applicable law, sanctions, or export controls, or would expose us or others to a material legal, regulatory, security, or safety risk that cannot reasonably be mitigated. In that case we will refund prepaid Fees for the unperformed Services.
22.6 Termination for convenience.
23.1 Accrued amounts. On termination or expiry, all Fees accrued up to that date become due. Work in progress is invoiced at the rates in the Order.
23.2 Access. Access to the affected Services ends, except as needed for the export in §23.3.
23.3 Data export. For [30] days after termination or expiry, the Client may export its Client Data, and audit evidence records held on the Platform, in a standard machine-readable format, using available tools or with our reasonable assistance.
23.4 Deletion. After the export window, we will delete or irreversibly anonymise Client Data within [30] days, except for data we must retain by law, and backup copies, which are deleted in the ordinary backup cycle and remain protected under §16 and §17 until then. We will confirm deletion in writing on request.
23.5 Transition assistance. On request, we will provide reasonable transition assistance for up to [90] days at our then-current rates, subject to payment in advance.
23.6 Survival. Provisions that by their nature should survive termination survive, including §5, §9, §16, §17, §18, §20, §21, §23, §29, §33, and §34.
24.1 Improvements. We may update and improve the Services. During a paid subscription term, we will not make changes that materially reduce the core functionality of the subscribed Service, unless required by law, for security reasons, or because of a third-party change under §13.5.
24.2 Discontinuation. If we discontinue a paid subscription Service, we will give at least [90] days' notice, refund prepaid Fees for the unused period, and provide reasonable migration assistance under §23.5.
24.3 Preview Features. §24.1 and §24.2 do not apply to Preview Features.
25.1 Relief. Neither party is liable for failure or delay in performance (other than payment obligations) caused by events beyond its reasonable control, including natural disasters, epidemics, war, terrorism, civil unrest, governmental action, changes in law, sanctions, export controls, hardware supply or allocation shortages, failures of utilities, telecommunications, or third-party cloud or model providers, and cyber-attacks, except cyber-attacks that succeed because the affected party failed to maintain the security arrangements required by the Agreement.
25.2 Mitigation. The affected party must notify the other promptly and use reasonable efforts to mitigate the effects of the event.
25.3 Prolonged events. If a force majeure event prevents performance for more than [60] consecutive days, either party may terminate the affected Order on written notice, and we will refund prepaid Fees for Services not performed.
26.1 By the Client. The Client may not assign, novate, or transfer the Agreement without our prior written consent, which we will not unreasonably withhold.
26.2 By BITSTRIC. The Client consents in advance to BITSTRIC assigning or novating the Agreement, on written notice, to an Affiliate or to a successor in connection with a merger, acquisition, corporate reorganisation, or sale of all or substantially all of the relevant business or assets, provided the transferee agrees in writing to be bound by the Agreement, including §7, §16, and §17. The Client may terminate the affected Order within [30] days after the notice, with a pro-rata refund of prepaid Fees, if the transferee (a) is a direct competitor of the Client; (b) is subject to sanctions; or (c) for a Regulated Client, would cause the Client to breach its regulatory obligations.
26.3 Subcontracting. We may subcontract in accordance with §12.
26.4 Continuity arrangements. Business continuity, key-person, and service-continuity arrangements for a specific Service are set out in the applicable Order or Regulated Entity Addendum.
26.5 Protection of Client Data. Our obligations regarding the return, deletion, and protection of Client Data continue to bind us, and any successor or permitted assignee, in all circumstances, including insolvency.
27.1 Regulated Entity Addendum. On request, we will negotiate in good faith a Regulated Entity Addendum addressing, to the extent required by the Client's applicable regulatory requirements (including MAS outsourcing and technology-risk requirements), (a) audit, inspection, and access rights for the Client, its auditors, and its regulators; (b) notification obligations; (c) subcontracting controls; (d) business continuity and exit; and (e) data location.
27.2 Regulatory characterisation. The Client is responsible for determining whether its use of the Services is an outsourcing arrangement or a material outsourcing arrangement, or is otherwise subject to regulatory notification or approval. We will provide information reasonably requested for that assessment.
27.3 Audit costs. We will support one audit per year at no additional charge. Further audits are chargeable at our then-current rates, except audits required by a regulator or conducted after a Security Incident.
27.4 Vendor risk questionnaires. Where an Order includes vendor risk management or security questionnaire responses, those are a scoped, chargeable deliverable. Our questionnaire responses describe our practices when given. They are not warranties unless expressly incorporated into the Agreement.
27.5 Public sector. Where Services are procured through Government procurement channels (including GeBIZ), the applicable Government contract conditions apply to the extent agreed in the contract award.
28.1 Export controls and sanctions. Each party must comply with applicable export-control and sanctions laws, including the Strategic Goods (Control) Act 2002, MAS targeted financial sanctions requirements, and, where relevant to hardware, software, or models used in the Services, the export-control laws of other jurisdictions. The Client must provide end-user and end-use information reasonably required by us or our suppliers, and must not export, re-export, or transfer any item or technology in breach of those laws.
28.2 Anti-corruption. Each party must comply with the Prevention of Corruption Act 1960 and other applicable anti-bribery laws.
28.3 General. Each party must comply with the laws applicable to its own performance under the Agreement.
During an Order and for [12] months after it ends, neither party will directly solicit for employment or engagement any employee or contractor of the other party who was materially involved in the Services, without the other party's written consent. General recruitment advertising, and hiring anyone who responds to it without direct solicitation, are not prohibited. If a party breaches this clause, it must pay the other party a placement fee equal to [25]% of the individual's first-year remuneration, which the parties agree is a genuine pre-estimate of the recruitment and replacement costs the other party will incur.
Neither party will use the other's name, logo, or trade marks in publicity without prior written consent, except as provided in a design-partner arrangement under §8.4.
31.1 Website and free use. We may update these Terms by posting a revised version with a new Effective Date. For Website use and free Services, the revised Terms apply from that Effective Date.
31.2 Paid Orders. For an active paid Order, we will give at least [30] days' notice of material adverse changes. Those changes apply only from the next renewal of that Order, unless (a) they are required by law, regulation, or a court; (b) they address a security risk; or (c) the Client agrees in writing. Changes that are not adverse to the Client apply from the Effective Date.
31.3 Version history. Prior versions of these Terms are available on request.
32.1 Operational notices. Operational notices may be given by email to the contact addresses in the Order or account, or through the Platform.
32.2 Legal notices. Notices of breach, termination, indemnity claims, or disputes must be in writing and sent by email to the designated legal contact, with a copy by courier or registered post to the recipient's registered office. For BITSTRIC, send legal notices to [[email protected]] and to our registered office.
32.3 Deemed receipt. Email is deemed received at the time of sending, if sent before 5 pm on a Business Day (Singapore time), and otherwise at 9 am on the next Business Day, unless the sender receives a delivery-failure notification. Courier or registered post is deemed received on delivery.
33.1 Entire agreement. The Agreement is the entire agreement between the parties on its subject matter and supersedes prior proposals and discussions. Nothing in this clause limits liability for fraud or fraudulent misrepresentation.
33.2 Severability. If any provision is held invalid or unenforceable, it applies with the minimum modification needed to make it valid, and the remaining provisions continue in full force.
33.3 No waiver. A failure or delay in exercising a right is not a waiver of it.
33.4 Third-party rights. A person who is not a party to the Agreement has no right under the Contracts (Rights of Third Parties) Act 2001 to enforce any of its terms.
33.5 Relationship. The parties are independent contractors. Nothing creates a partnership, joint venture, agency, fiduciary, or employment relationship.
33.6 Electronic execution. Orders and other documents may be signed electronically and in counterparts.
33.7 Language and interpretation. The Agreement is in English. Headings are for convenience only. "Including" means "including without limitation". A reference to a statute includes any amendment or re-enactment of it and any subsidiary legislation made under it.
33.8 Equitable relief. Each party may seek injunctive or other equitable relief for actual or threatened breaches of §5, §17, or §18, in addition to other remedies.
34.1 Governing law. The Agreement and any non-contractual obligations arising from it are governed by the laws of Singapore.
34.2 Escalation. The parties will first try to resolve any dispute through good-faith discussions between senior representatives within [20] Business Days after written notice of the dispute. The parties may also agree to refer the dispute to mediation at the Singapore International Mediation Centre.
34.3 Arbitration. Any dispute that is not resolved under §34.2, arising out of or in connection with the Agreement (including any question about its existence, validity, or termination), will be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the Arbitration Rules of the SIAC in force when the arbitration commences. The seat of arbitration is Singapore. The tribunal will consist of one arbitrator. The language of the arbitration is English. The parties agree to use the SIAC's expedited or streamlined procedures where the dispute is eligible for them. The arbitration and any award are confidential, except as required by law or to enforce an award.
34.4 Court carve-outs. Despite §34.3, either party may (a) seek urgent interim or injunctive relief from the courts of Singapore; and (b) bring proceedings in the courts of Singapore to recover undisputed invoiced amounts.
34.5 Consumers. If you are a Consumer, you are not required to arbitrate. You may instead bring a claim in the Small Claims Tribunals (where your claim is within its jurisdiction) or the courts of Singapore.
34.6 Individual claims. To the extent permitted by law, claims must be brought on an individual basis, not as a claimant or member in any representative or class proceeding.
BITSTRIC Pte. Ltd. · UEN [●] · [Registered office address] · [[email protected]] · [[email protected]] · [[email protected]]
These terms apply in addition to the General Terms when the Client uses the relevant Service. Service names are descriptive, and the Order governs scope.
Covers: AI Risk Discovery, AI Readiness Audit, Cloud AI Readiness Review, Cloud AI Cost & Control Review, Hybrid Sovereign Transition Plan, Executive AI Risk Advisory (including board briefings, vendor risk assessment, governance operating models, and ISO/IEC 42001-readiness support), and vendor risk questionnaire responses.
S1.1 Point-in-time. Findings reflect the evidence, access, and scope available at the time of the engagement, and may not identify every risk.
S1.2 Not an audit opinion. Readiness and discovery Deliverables are not assurance engagements, audit opinions, certifications, or legal opinions.
S1.3 Reliance. Deliverables are prepared solely for the Client. No third party may rely on them, and BITSTRIC owes no duty of care to any third party, unless BITSTRIC signs a reliance letter. The Client may share Deliverables under §18.3(c).
S1.4 Scope boundaries. Each engagement's Order states what the engagement is not (for example, whether it looks back at AI systems already running or forward at a candidate workflow). Those exclusions define scope.
Governance layer: AI and agentic system discovery, risk assessment, and audit-trail oversight.
S2.1 Authorisation to scan. The Client authorises BITSTRIC to discover, inventory, and assess AI systems within the Client Environments and scope specified in the Order, and warrants that it has authority to grant that authorisation, including for systems operated by its vendors.
S2.2 Risk indicators. Risk scores, ratings, and classifications are methodology-based indicators that support the Client's own risk assessment. The Client decides what action to take on them.
Infrastructure layer: secure model-inference deployment and hosting in private-cloud, air-gapped, or hybrid configurations.
S3.1 Deployment model. The Order states whether Aether™ Core is deployed in a Client Environment or in an environment BITSTRIC manages. For Client-hosted deployments, the Client is responsible for the underlying infrastructure, capacity, physical security, and network.
S3.2 Service levels. Availability and support service levels apply only if stated in the Order or an attached service-level schedule.
S3.3 Customer-managed keys. Where encryption keys are managed by the Client, the Client is solely responsible for key custody, rotation, and backup. Data encrypted with lost keys may be unrecoverable, and BITSTRIC is not liable for that loss.
Continuous IT GRC and sovereignty automation: stack discovery and health scanning, continuous control monitoring, control cross-mapping, remediation support, and audit evidence records.
S4.1 Connectors and credentials. The Client provisions the connectors and credentials for cloud accounts, repositories, and systems, using the least-privilege and, where possible, read-only scopes described in the Documentation. The Client may revoke access at any time, which may impair the Service.
S4.2 Remediation requires your approval. Remediation proposals, scripts, and configuration changes generated by the Service are delivered as recommendations, pull requests, or changes to non-production or staging environments. The Client must review and approve every remediation before it is applied to production. BITSTRIC does not apply changes to production systems unless the Order expressly authorises it and the change passes through the Client's change-management process.
S4.3 Control mappings. Mappings between controls and frameworks are interpretive aids. Auditors and regulators may take different views.
S4.4 Evidence records. Audit evidence ledgers and logs include integrity features designed to detect alteration. The weight and admissibility of any evidence are determined by auditors, regulators, and courts, and are not guaranteed.
S4.5 Tiers. Self-serve tiers are billed as shown at checkout and are subject to these Terms. Enterprise and sovereign deployment tiers are available only under a separate Order, subject to availability.
S4.6 Trust-center content. The Client is responsible for anything it publishes through trust-center or dashboard features, and must ensure its public statements are accurate.
S5.1 Status. The Aether™ Trace SDK is not generally available. If we make it available to you, we do so as a Preview Feature under §14, which may include a capped, no-charge pilot alongside another Service.
S5.2 No reliance. The SDK is provided without service levels, may change or be withdrawn without notice, and must not be used in production or relied on as a reason to purchase any other Service.
Scam and fraud signal detection, clustering, and referral for businesses, public-sector entities, and households.
S6.1 Signals, not determinations. SIRE produces probabilistic signals, scores, and clusters ("Scam Indicators"). They may include false positives and false negatives. They are not determinations that any person has committed fraud or any offence.
S6.2 Your decisions. The Client is responsible for any action it takes based on Scam Indicators, including blocking, flagging, reporting, or declining transactions or communications, and must maintain its own review and recourse processes for affected persons.
S6.3 Referrals. With the Client's authorisation, or as otherwise permitted by the PDPA and applicable law, SIRE may share Scam Indicators (for example, phone numbers, URLs, message patterns, and account identifiers associated with suspected scams) with anti-scam bodies, telecommunications operators, financial institutions, industry signal-sharing networks, and law-enforcement agencies, to help detect, prevent, and investigate scams. The Order or, for households, the in-product notice describes the categories of recipients and data shared.
S6.4 Not an emergency service. SIRE is not an emergency, law-enforcement, or victim-recovery service. If you are in danger, call the Police at 999. For scam-related advice, call the ScamShield Helpline at 1799.
S6.5 No guarantee. SIRE does not guarantee that scams or losses will be prevented. To the extent permitted by law, BITSTRIC is not liable for losses caused by scams or fraud perpetrated by third parties.
S6.6 False reports. Users must not submit reports they know to be false, or use SIRE to harass or target any person.
S7.1 Status. Laminar is available on a pilot or early-access basis under §14, unless an Order expressly states otherwise.
S7.2 Controls. Laminar workflows operate within the autonomy levels, tools, and approval gates the Client configures and approves under §15.3.
S7.3 Vertical templates. Industry and vertical workflow templates (including for finance, public sector, energy and utilities, and healthcare) are starting points. The Client must validate them for its own regulatory and operational context.
S7.4 Healthcare. Laminar is not a medical device and is not intended for diagnosis, treatment, or clinical decision-making.
Model and system evaluation using BITSTRIC's IEI evaluation methodology.
S8.1 Methodology confidential. The IEI methodology, including pillar definitions, test suites, scoring mechanics, and weighting, is BITSTRIC's Confidential Information and trade secret. We disclose it only to the extent stated in the Order.
S8.2 Results. Results apply only to the specific model, version, configuration, prompts, tasks, and runs evaluated, at the time of evaluation. Results are reported as distributions across repeated runs, not as guarantees of future behaviour.
S8.3 Not certification. IEI evaluations are not certifications. No person may describe any model, system, or product as "IEI-Certified", "IEI Certified", or similar, unless BITSTRIC has issued a written certification under a published certification scheme.
S8.4 Publication. The Client may use results internally and share them under §18.3(c). Any public reference to results, or to BITSTRIC, requires our prior written approval of the wording. BITSTRIC will not publish Client-identifiable results without the Client's consent.
S8.5 Third-party models. References to third-party models and providers in evaluations and leaderboards are nominative, and do not imply endorsement by or of those providers.
S9.1 Hardware. Hardware is supplied by an authorised channel partner under §13.3. BITSTRIC provides deployment, configuration, governance, and managed services.
S9.2 Site. The Client provides and is responsible for a secure location, power, cooling, network connectivity, and physical access control for the hardware.
S9.3 Remote access. BITSTRIC accesses the deployment remotely only through channels the Client approves, and the Client may revoke that access at any time.
S9.4 Sizing. Each deployment is sized for the workloads specified in the Order. Performance beyond that specification, and scaling to larger infrastructure, are outside scope unless agreed in a new Order.
S9.5 Software stack. The deployment may include Third-Party Components and open-source components (including integration harnesses), which are subject to §13.
S9.6 Export controls. §28.1 applies, including the Client's obligation to provide end-user and end-use information.
S9.7 Managed governance. On acceptance, the deployment may transition to a managed governance retainer as stated in the Order.
S10.1 Your accounts. Cloud AI services are provisioned under the Client's own provider accounts unless the Order states otherwise. Provider consumption charges are billed to the Client.
S10.2 Cost controls. Budget guardrails and routing controls reduce the risk of overspending. They are not guaranteed spending caps unless the provider enforces them.
S10.3 Provider data practices. Provider data handling is governed by the provider's terms. We help assess those terms, but do not control them.
S11.1 Scope. Deployments may include a private retrieval-augmented generation (RAG) stack, a secure ingestion pipeline, role-based access, prompt and tool controls, an evaluation baseline, audit logs, and deployment documentation, as specified in the Order.
S11.2 Production responsibility. The Client is responsible for internal approval, production use, governance, and operational risk acceptance.
S12.1 Scope. Managed services may include monthly control reviews, drift and retrieval-quality checks, risk and usage reports, incident logs, access reviews, provider-change reviews, and executive summaries, as specified in the Order.
S12.2 Service levels and exclusions. Service levels, support windows, exclusions, and dependencies are set out in the Order. Managed services do not guarantee uninterrupted operation, breach prevention, or regulatory compliance.
S13.1 Keys and limits. API keys are Client credentials under §4. We may apply rate limits and quotas, and may throttle traffic that threatens Platform stability.
S13.2 Deprecation. For generally available APIs, we will give at least [90] days' notice before deprecating a version, except where required for security or by law. Preview APIs may change at any time.
S13.3 Messaging compliance. For notification and messaging features, the Client is responsible for message content and recipients, and for compliance with the Spam Control Act 2007 and the Do Not Call provisions of the PDPA.
End of Terms. Version 2.0.
The following clauses are preserved from the prior SaaS-oriented user terms as historical fallback language only. They apply only if a separate service order, subscription agreement, or platform-specific written agreement expressly incorporates them.
The legacy terms were drafted for an IT consultation service, Software as a Service platform, and AI Integral as a Service environment. They focused on platform access, account use, subscription management, and AI coding assistant usage.
Users and Authorized Users were granted a limited, non-exclusive, non-transferable license to access and use the service solely for internal business purposes, subject to the applicable service order and fair use limits.
The legacy platform rules required accurate registration information, secure handling of credentials, lawful and ethical use, and prompt notice of unauthorized access.
The prohibited conduct set included:
The legacy service language referenced industry-standard security measures, service levels, support windows, and advance notice for material service changes.
The legacy platform terms contemplated service orders, recurring subscriptions, auto-renewal, taxes, deposits, and suspension or termination for non-payment or excess usage.
The legacy terms referenced APAC and EU privacy compliance, a data processing addendum, cross-border transfer controls, breach notification, subprocessors, anonymization, and aggregation of usage data.
The legacy IP language retained BITSTRIC ownership of the service, internal materials, and reusable know-how, while granting users a limited right to use user content and AI-generated output in connection with their projects.
The appendix also preserved guidance on open source compliance, including attribution, permissive versus copyleft licensing, and the need to review AI-generated code for license compatibility.
The legacy terms included confidentiality obligations, suspension and termination rights, limitation of liability, indemnification, Singapore governing law, and SIAC arbitration.
The legacy platform terms also addressed changes to terms, severability, assignment, entire agreement, no waiver, and notice mechanics.
Our legal team is available to discuss enterprise-specific MSAs and compliance requirements.