Terms of Service
Effective date: August 11, 2026
These Terms of Service ("Terms") are a binding agreement between Noah Consulting Services, operating as "Briefo" ("Briefo," "we," "us"), and the individual or entity that accepts them ("Customer," "you"). By creating an account, clicking "I agree," signing an order form that references these Terms, or authorizing Briefo to connect a data source, you agree to these Terms, including the Data Processing Agreement (Schedule 1) and the Sub-processors list (Schedule 2), which form part of these Terms. If you accept on behalf of an organization, you represent that you have authority to bind it.
If you do not agree, do not use the Service.
1. Definitions
- "Service" — the Briefo AI knowledge-base platform, websites, applications, connectors, and related services.
- "Connected Data" — content and metadata Briefo accesses from data sources you connect (e.g., email, calendar, files), as described in the Privacy Policy.
- "Customer Data" — Connected Data plus any other data you provide.
- "Output" — answers, summaries, citations, and other results the Service generates.
- "Documentation" — Briefo's user guides and materials.
2. The Service
Briefo ingests Customer-authorized data sources and provides an AI-generated, citation-backed question-answering interface over that data. Access is read-only; Briefo does not create, modify, send, or delete content in your connected sources. Connectors are currently configured by Briefo personnel on your behalf ("admin-run onboarding"); this does not change your responsibilities under Section 4. We may update, add, or discontinue features at any time.
3. Accounts and access
You are responsible for your account, your users, and all activity under them, and for maintaining the confidentiality of credentials. You must promptly notify us of unauthorized use. You must provide accurate information and keep it current.
4. Customer authorizations, warranties, and responsibilities
This Section is a material condition of the Service. You represent, warrant, and covenant, on a continuing basis, that:
- Authority. You have all rights, authority, licenses, and lawful bases necessary to connect each data source, to authorize Briefo's access to it, and to have the Connected Data processed as described in these Terms, the Privacy Policy, and the DPA.
- Consents. You have obtained and will maintain all notices, consents, and permissions required from your employees, personnel, contacts, and any other individuals whose personal data may be contained in the Connected Data, including any consents required to allow processing of email, calendar, and file content.
- Ownership / permission. You own or are authorized to use and submit the Connected Data, and Briefo's processing of it will not infringe or violate any third party's rights or any law.
- Lawfulness of content. The Connected Data does not violate any law or third-party right, and you are solely responsible for its content, accuracy, and legality.
- Sensitive data. You are responsible for deciding whether to connect sources containing sensitive, regulated, privileged, or special-category data (e.g., health, financial, legal, or biometric data), and for any heightened obligations that apply to such data.
You are solely responsible for which sources you connect and for reviewing what they contain. Briefo has no obligation to monitor, and does not control, the content of your Connected Data.
5. Acceptable use
You will not, and will not permit anyone to: (a) use the Service unlawfully or in violation of any third-party right; (b) connect data you are not authorized to connect; (c) attempt to access another tenant's data; (d) reverse engineer, scrape, or circumvent security or access controls; (e) overload or disrupt the Service; (f) resell or provide the Service to third parties except as permitted; (g) use the Service to build a competing product or to train competing models; or (h) use Output in a manner prohibited by Section 8. We may suspend access for violations (Section 14).
6. Third-party services
The Service interoperates with third-party providers (e.g., Google, Microsoft, Amazon Web Services). Your use of those providers is governed by their terms, and your authorizations are subject to their consent flows and policies. Briefo is not responsible for third-party services, their availability, changes, suspension, or acts, or for any consequences of a provider changing or revoking access. Provider warnings shown during authorization (including "unverified app" notices) are controlled by the provider, not Briefo.
7. Intellectual property
As between the parties, you retain all rights in Customer Data. You grant Briefo a limited, non-exclusive license to host, copy, process, transmit, and display Customer Data solely to provide and support the Service and as permitted by the DPA. Briefo retains all rights in the Service, software, models, integrations, and Documentation. You may not use Briefo's marks without permission. You may provide feedback, which Briefo may use without restriction or obligation.
8. AI Output — no reliance; not professional advice
You understand and agree that:
- Output is generated by automated AI systems and may be inaccurate, incomplete, outdated, or misleading, and may not reflect the current or complete state of your Connected Data.
- Output is provided for informational purposes only and is not professional advice of any kind (including legal, financial, tax, medical, or other advice), and does not create any professional or fiduciary relationship.
- You are solely responsible for evaluating and verifying Output before relying on or acting on it, and for any decisions you make based on it.
- Citations and retrieved sources are provided to assist verification and may be incomplete or imperfect.
Briefo disclaims all responsibility and liability for any reliance on Output.
9. Fees
The Service is provided on a paid subscription basis: a one-time setup fee and a recurring monthly subscription fee, as stated in the order form or plan you accept. Unless the order form says otherwise:
- Fees are billed in advance, are stated in USD, and are exclusive of taxes; you are responsible for applicable taxes other than taxes on Briefo's net income.
- Fees are non-refundable except where required by law, and no credit is given for partial periods or unused capacity.
- Payment is due on the invoice or renewal date. Late or failed payments may result in suspension after notice (Section 15) and may accrue interest at the lower of 1.5% per month or the maximum permitted by law.
- We may change pricing effective at your next renewal on prior notice.
- The subscription renews for successive monthly terms unless cancelled before the renewal date, as described in the order form.
Payments are processed by a third-party payment processor; your use of that processor is subject to its terms.
10. Confidentiality
Each party will protect the other's Confidential Information with reasonable care and use it only to perform under these Terms, excluding information that is public, independently developed, or rightfully received from a third party, or that must be disclosed by law. Customer Data is your Confidential Information; Briefo's non-public technology and pricing are ours.
11. Data protection
Briefo's processing of personal data within Customer Data is governed by the Data Processing Agreement in Schedule 1, which forms part of these Terms. The Privacy Policy at briefo.io/privacy describes our data practices. In case of conflict regarding personal-data processing, Schedule 1 controls.
12. Disclaimer of warranties
THE SERVICE, INCLUDING ALL OUTPUT, IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. TO THE MAXIMUM EXTENT PERMITTED BY LAW, BRIEFO DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, ACCURACY, AND NON-INFRINGEMENT. BRIEFO DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, THAT OUTPUT WILL BE ACCURATE OR COMPLETE, OR THAT DATA WILL NOT BE LOST OR ALTERED. SOME JURISDICTIONS DO NOT ALLOW CERTAIN WARRANTY EXCLUSIONS, SO SOME OF THE ABOVE MAY NOT APPLY TO YOU.
13. Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
- No indirect damages. NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS INTERRUPTION, EVEN IF ADVISED OF THE POSSIBILITY.
- Cap. BRIEFO'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICE OR THESE TERMS WILL NOT EXCEED THE GREATER OF (a) THE FEES YOU PAID TO BRIEFO IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO THE LIABILITY, OR (b) USD $100.
- AI Output. BRIEFO HAS NO LIABILITY FOR ANY DECISION, ACTION, OR OMISSION BASED ON OUTPUT.
- Basis of the bargain. These limitations apply regardless of the theory of liability and are a fundamental basis of the agreement.
Exceptions. Nothing in these Terms limits liability that cannot be limited by law (which may include gross negligence, willful misconduct, fraud, death or personal injury, or certain statutory obligations). Some jurisdictions do not allow certain limitations, so parts of this Section may not apply to you.
14. Indemnification
You will defend, indemnify, and hold harmless Briefo and its officers, employees, and agents from and against any claims, damages, liabilities, losses, and costs (including reasonable legal fees) arising out of or related to: (a) your Connected Data or Customer Data; (b) your breach of Section 4 (authorizations and warranties) or Section 5 (acceptable use); (c) your violation of law or any third-party right, including privacy, data-protection, and intellectual-property rights; (d) your failure to obtain required consents; or (e) your use of the Service or Output.
15. Term, suspension, and termination
These Terms apply while you use the Service. Either party may terminate for convenience on 30 days' written notice, effective at the end of the then-current paid month, unless an order form states otherwise. We may suspend or terminate immediately for breach, non-payment, security risk, legal requirement, or provider revocation. On termination, your right to use the Service ends and Customer Data is handled per the Privacy Policy and the retention terms in Schedule 1. Sections that by their nature should survive (including 4, 7, 8, 9, 10–14, 16) survive termination.
16. Governing law and dispute resolution
These Terms are governed by the laws of the Province of Quebec and the federal laws of Canada applicable therein, without regard to conflict-of-laws rules, and excluding the U.N. Convention on Contracts for the International Sale of Goods.
Jurisdiction. The courts of the Province of Quebec, judicial district of Montreal, have exclusive jurisdiction over any dispute, claim, or controversy arising out of or relating to these Terms or the Service, and each party consents to venue there. For Customers established in the United States, this choice of Quebec law and forum is a negotiated term of a business-to-business agreement.
Individual claims. To the fullest extent permitted by applicable law, each party agrees to bring claims against the other only in an individual capacity, and not as a plaintiff or class member in any purported class, collective, or representative proceeding. Enforceability of this provision varies by jurisdiction and may be limited for certain consumers; where it is unenforceable, it is severed and the remainder of this Section continues to apply.
Exceptions. Either party may bring an individual claim in small-claims court and may seek injunctive relief in court to protect its intellectual property or confidential information.
You agree to first attempt to resolve disputes informally by contacting admin@briefo.io, and to allow 30 days to resolve the matter before commencing proceedings.
17. Force majeure
Briefo is not liable for any delay or failure due to causes beyond its reasonable control, including provider outages, internet or infrastructure failures, acts of God, and governmental actions.
18. Changes to these Terms
We may modify these Terms. Material changes will be notified via the Service or by email. Continued use after the effective date constitutes acceptance. If you do not agree, stop using the Service.
19. Miscellaneous
Entire agreement (these Terms, including Schedules 1 and 2, together with the Privacy Policy and any order form); severability (invalid terms are limited, not voided); no waiver by delay; assignment (you may not assign without consent; Briefo may assign in a corporate transaction); independent contractors; notices to admin@briefo.io and to your account email; headings are for convenience only. These Terms are drawn up in English; les parties ont exigé que la présente convention soit rédigée en anglais.
Schedule 1 — Data Processing Agreement
This Data Processing Agreement ("DPA") forms Schedule 1 to, and part of, the Terms of Service (the "Agreement") between Noah Consulting Services, operating as "Briefo" ("Briefo," "Processor"), and the Customer ("Customer," "Controller"), and governs Briefo's processing of Personal Data on the Customer's behalf. If the Agreement and this DPA conflict as to personal-data processing, this DPA controls.
S1.1 Definitions
Capitalized terms not defined here have the meanings in the Agreement. "Data Protection Laws" means all applicable laws governing the processing of Personal Data, including the EU GDPR, the UK GDPR, the Swiss FADP, the California CCPA/CPRA, and Canada's PIPEDA and Quebec Law 25, as applicable. "Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings in the GDPR (or the equivalent under other Data Protection Laws). "Customer Personal Data" means Personal Data contained in Customer Data or Connected Data that Briefo Processes on the Customer's behalf.
S1.2 Roles and scope
(a) As between the parties, the Customer is the Controller (or a processor acting for another controller) and Briefo is the Processor of Customer Personal Data.
(b) Briefo will Process Customer Personal Data only (i) to provide the Service, (ii) in accordance with the Customer's documented instructions (the Agreement, this DPA, and configuration/use of the Service constitute such instructions), and (iii) as required by law (in which case Briefo will, where permitted, inform the Customer first).
(c) Briefo will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
(d) CCPA. With respect to California Personal Information, Briefo acts as a "service provider" and will not sell or share it, retain, use, or disclose it except to provide the Service (the "business purpose"), or combine it with data from other sources except as permitted. Briefo certifies it understands and will comply with these restrictions.
S1.3 Customer obligations
The Customer warrants that (a) it has a lawful basis and all necessary consents, authority, and notices to provide the Customer Personal Data and to authorize its Processing; (b) its instructions comply with Data Protection Laws; and (c) it is responsible for the accuracy, quality, and legality of the Customer Personal Data and the means by which it was obtained.
S1.4 Confidentiality
Briefo ensures that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis.
S1.5 Security
Briefo implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex C, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and risk of the Processing. The Customer is responsible for its own security (credential hygiene, user management, and decisions about what to connect).
S1.6 Sub-processors
(a) The Customer provides general authorization for Briefo to engage the sub-processors listed in Schedule 2 and to appoint new ones to provide the Service.
(b) Briefo will impose data-protection obligations on each sub-processor that are no less protective than this DPA and remains responsible for its sub-processors' performance.
(c) Briefo will give the Customer prior notice (via Schedule 2 or email) of a new sub-processor at least 30 days before it begins Processing, and the Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service as its sole remedy.
S1.7 Data Subject rights and assistance
Taking into account the nature of the Processing, Briefo will (a) promptly notify the Customer if it receives a Data Subject request relating to Customer Personal Data and not respond directly except to confirm the request relates to the Customer; and (b) provide reasonable assistance (through appropriate technical and organizational measures, insofar as possible) to help the Customer respond to Data Subject requests and to comply with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation.
S1.8 Personal Data Breach
Briefo will notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations. Briefo's notice is not an acknowledgment of fault or liability.
S1.9 Deletion and return
On termination or expiry of the Service, or on the Customer's request, Briefo will delete or return Customer Personal Data and delete existing copies within 30 days, except to the extent retention is required by law or for backups that are cycled out within 35 days and remain protected until deleted.
S1.10 Audits
Briefo will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or its auditor no more than once per 12 months, on reasonable prior notice, subject to confidentiality, during business hours, and not unreasonably disrupting Briefo's operations. Briefo may satisfy audit requests by providing then-current third-party reports or questionnaires where available.
S1.11 International transfers
Where Customer Personal Data protected by EEA/UK/Swiss law is transferred to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses (and the UK International Data Transfer Addendum, where relevant) are incorporated by reference and completed by the details in the Annexes, with Briefo as "data importer." For EU SCCs, Module Two (Controller-to-Processor) applies where the Customer is a controller, and Module Three (Processor-to-Processor) applies where the Customer is itself a processor; the governing-law and supervisory-authority elections follow the Customer's EEA establishment (or, failing that, Ireland).
S1.12 Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws or to Data Subjects where such limitation is not permitted.
S1.13 General
This DPA is governed by the law and dispute-resolution terms of the Agreement, except where Data Protection Laws or the Standard Contractual Clauses require otherwise. If any part is invalid, the rest remains in effect.
Annex A — Details of Processing
- Subject matter: Provision of the Briefo AI knowledge-base Service.
- Duration: For the term of the Agreement, plus the deletion period in Section S1.9.
- Nature and purpose: Ingesting Customer-authorized data sources; extracting text; building search indexes; storing and indexing; retrieving relevant content; and generating cited answers to Customer queries.
- Types of Personal Data: As contained in the connected sources, which may include names, email addresses, message content and metadata, calendar event details and attendees, file content and metadata, and other personal data the Customer chooses to connect. The Customer controls what is connected.
- Categories of Data Subjects: The Customer's employees, personnel, contacts, correspondents, and other individuals referenced in the Connected Data.
- Special-category data: Not intended; the Customer is responsible if it connects sources containing such data.
Annex B — Sub-processors
The current list of authorized sub-processors is set out in Schedule 2 to the Agreement.
Annex C — Technical and Organizational Measures
- Tenant isolation: Each Customer's data is logically isolated by tenant identifier; all data access passes through a single enforced, tenant-scoped access layer, with database-level access controls, so one Customer's data cannot be returned to another.
- Encryption: In transit (TLS) and at rest.
- Access control & secrets: Least-privilege access; credentials and tokens stored in a managed secrets service; read-only access to connected sources.
- Logging & monitoring: Access and operational logging.
- Data minimization: Configurable look-back windows and source/folder scoping so only authorized, relevant data is ingested.
- Deletion: Deletion on disconnection/termination per Section S1.9.
Schedule 2 — Sub-processors
Last updated: August 11, 2026
Briefo (operated by Noah Consulting Services) engages the third-party sub-processors below to help provide the Service. Each is bound by data-protection obligations no less protective than those in Schedule 1 (the Data Processing Agreement), and access is limited to what is necessary to provide the Service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, and AI processing (Amazon Bedrock) | United States |
| Google LLC | Authorized access to connected Google Drive / Gmail / Calendar data | United States |
| Microsoft Corporation | Authorized access to connected Outlook mail/calendar via Microsoft Graph | United States |
| Stripe, Inc. | Payment processing (subscription and setup fees) | United States |
We will give notice of any new sub-processor at least 30 days before it begins processing customer personal data, as described in Section S1.6. To receive notifications or ask a question, contact admin@briefo.io.
Noah Consulting Services (operating as Briefo), Province of Quebec, Canada — admin@briefo.io