Terms of Service
Last updated: September 18, 2026
These Terms of Service ("Terms") govern your access to and use of the DefensibleHR.ai platform and services ("Services") provided by DefensibleHR LLC ("Company," "we," "us," or "our"). By clicking "I agree," creating an account, submitting a Free Compliance Scan after being presented with these Terms, or otherwise using the Services where these Terms are conspicuously presented, you agree to be bound by these Terms. Company may maintain records of the date, time, account or email identifier, IP address, document version, and acceptance method associated with your assent.
If you access or use the Services on behalf of a corporation, limited liability company, partnership, governmental entity, or other organization ("Customer"), you represent and warrant that you have full authority to bind Customer to these Terms. In that event, "you" and "your" refer to Customer and its authorized users. Customer is responsible for its authorized users' compliance with these Terms.
The Services are offered solely for business and professional use. By accessing or using the Services, including a Free Compliance Scan, you represent and warrant that you are using the Services on behalf of a Customer and not for personal, family, or household purposes.
DefensibleHR LLC is not a law firm and does not provide legal representation or legal advice. Use of the Services or any Output does not create an attorney-client relationship, fiduciary relationship, joint-defense relationship, attorney work-product protection, or other legal privilege between Company and any user. Outputs are automated informational materials for decision-support purposes only. Scan results are generated by artificial intelligence, which can and does make mistakes — including false positives (flagging issues that do not exist) and false negatives (missing issues that do exist). Results may be incomplete, inaccurate, or inapplicable to your specific jurisdiction or circumstances. DefensibleHR LLC is not responsible for any decisions, actions, or outcomes based on scan results. Always seek the advice of a qualified employment attorney before making employment decisions or relying on any scan findings.
THESE TERMS CONTAIN A BINDING INDIVIDUAL ARBITRATION PROVISION AND A CLASS ACTION WAIVER (SECTION 15). EXCEPT FOR THE MATTERS DESCRIBED IN SECTION 15, YOU AND DEFENSIBLEHR LLC AGREE TO RESOLVE ALL DISPUTES THROUGH BINDING INDIVIDUAL ARBITRATION, WHICH MEANS YOU WAIVE ANY RIGHT TO HAVE A DISPUTE DECIDED BY A JUDGE OR JURY, AND YOU WAIVE YOUR RIGHT TO PARTICIPATE IN CLASS ACTIONS, CLASS ARBITRATIONS, OR REPRESENTATIVE PROCEEDINGS.
1. Services Description
DefensibleHR.ai provides an AI-powered compliance scanning assistant that reviews workplace documents — including investigation reports, termination letters, performance improvement plans, employment contracts, non-compete agreements, and HR memos — for potential legal risks such as biased language, missing policy references, due process gaps, and other compliance concerns.
The Services include:
- Document upload and text extraction
- AI-powered compliance scanning across 30 risk categories and 100+ checks
- Automatic PII redaction (9 categories: SSNs, phone numbers, email addresses, dates of birth, driver's license numbers, bank account numbers, credit card numbers, EINs, and passport numbers) before AI processing. Company uses automated measures designed to identify and redact certain structured identifiers before Extracted Text is transmitted to the AI provider. Automated redaction is not infallible and may fail to identify, redact, or accurately redact personal information or other sensitive information.
- Findings labeled by category (required, recommended, or optional) for the applicable jurisdiction, an overall risk level for the document, and remediation suggestions
- Jurisdiction detection with links to state Department of Labor resources
- Scan history, document management, and an account activity record (supervision record) of upload, review, export, and settings events
- A one-time free compliance scan available without account registration
The Services are an AI-powered assistant tool designed to flag potential issues for human review. They are not a substitute for professional legal counsel. AI can and does make mistakes. DefensibleHR LLC assumes no liability for the accuracy or completeness of scan results.
1.1 Definitions
- "Customer Data" means documents, files, text, information, and metadata that Customer or an authorized user uploads, submits, or otherwise makes available to the Services.
- "Extracted Text" means machine-readable text derived from Customer Data during file ingestion or processing.
- "Full Outputs" or "Outputs" means the scan results, narrative findings, risk rationales, remediation suggestions, example replacement language, reports, and remediation memoranda generated by the Services.
- "Scan Metadata" means non-content operational and integrity information, including document hash, timestamps, rule and model version identifiers, issue counts, category labels, and internal severity values, but excluding Extracted Text, quoted document content, and narrative findings or remediation language.
- "Customer Personal Data" has the meaning given in the Data Processing Addendum.
- "Applicable Privacy Laws" means privacy, data-protection, breach-notification, direct-marketing, and similar laws applicable to the processing of personal information under these Terms.
- "DPA" means the DefensibleHR Data Processing Addendum, version dated September 18, 2026, available at defensiblehr.ai/dpa.
- "Security Breach" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, as further defined in the DPA.
- "De-Identified Data" means information that has been de-identified or anonymized, as applicable, in accordance with Applicable Privacy Laws and is not reasonably capable of being linked to, or used to infer information about, Customer or an identified or identifiable individual.
1A. Free Compliance Scan
1A.1 Availability
We offer a one-time free compliance scan that does not require account registration. The free scan provides the same AI-powered analysis as our paid plans. Free scans are limited to one per email address. We also limit free scans to three per IP address within a 24-hour period to prevent abuse, and we may decline free scans submitted through VPN, proxy, or hosting-provider connections as an additional abuse-prevention measure.
1A.2 Information Required
To run the free scan, you must upload a document and affirmatively accept these Terms as described in Section 1A.3; providing your name and company name is optional. The scan runs before any email address is collected, and a summary of the results (overall risk level, issue counts, and the title of the most severe finding) is displayed on screen. To receive the full findings and report, you must provide and verify a valid email address. By submitting a free scan, you consent to our collection and use of the information described in our Privacy Policy, including your IP address, browser information, and document fingerprints collected at the time of the scan.
1A.3 Consent and Agreement
Before submitting a free scan, you must affirmatively agree to these Terms of Service and our Privacy Policy by checking the consent box. Submitting a free scan without checking the consent box is not permitted.
By submitting a Free Compliance Scan, you represent and warrant that: (a) you own the submitted document or have all authority necessary to submit it to Company for automated processing; (b) your submission and Company's processing of the document as contemplated by these Terms do not violate any confidentiality obligation, court order, privacy law, employment law, or third-party right; and (c) you have provided all notices and obtained all permissions, consents, or other lawful authorizations required under Applicable Privacy Laws. Marketing and follow-up communications relating to Free Compliance Scans are described in the Privacy Policy.
1A.4 Results and Data
A results summary is displayed on screen after the scan; the full findings are shown, and the complete report emailed, only after you verify an email address. Results are not saved to an account. If you never provide an email address, we retain no contact information about you: the extracted document text is automatically deleted within 24 hours, and we keep only a consent and scan record (timestamp, IP address, browser information, optional name, document fingerprints, risk level, and issue count) and the anonymous cached results described in our Privacy Policy. If you verify an email, we retain your contact information and scan summary metadata (risk level and issue count) — not the document text. To save scan results and access them later, you must create a free account.
For clarity, no provision of the Privacy Policy stating that Company stores scan results applies to Full Outputs from a Free Compliance Scan, except as expressly stated in Privacy Policy Section 2.2.
1A.5 Applicable Terms
All provisions of these Terms apply to free scan usage, including the "Not Legal Advice" disclaimer, AI-Generated Results (Section 6), Prohibited Uses (Section 7), Disclaimer of Warranties (Section 9), and Limitation of Liability (Section 10).
2. Account Registration
To use the full Services beyond the one-time free scan, you must create an account by providing accurate and complete information. You are responsible for:
- Maintaining the confidentiality of your account credentials
- All activity that occurs under your account
- Notifying us immediately of any unauthorized use
Account sharing is prohibited. Each user must have their own account. Sharing credentials constitutes a material breach of these Terms.
Customer is responsible for all acts and omissions of its authorized users and any person who accesses the Services through Customer's Access Credentials, except to the extent caused by Company's breach of these Terms or failure to maintain the security measures it has expressly committed to provide.
2.1 Eligibility
You must be at least eighteen (18) years old to create an account, submit a Free Compliance Scan, or otherwise use the Services. If you use the Services for a Customer, you represent and warrant that you are authorized to bind that Customer to these Terms.
3. Plans and Pricing
3.1 Plans
We offer the following subscription tiers:
- Free: Limited document scans per month for evaluation purposes
- Starter ($99/month): Up to 10 documents scanned per month (each scanned document includes up to 5 free rescans), remediation memo export with example replacement language
- Professional ($249/month): Up to 50 documents scanned per month (each scanned document includes up to 5 free rescans), remediation memo export with example replacement language, team workspace (3 seats included, additional seats $29/month each)
- Enterprise (custom pricing): High-volume scan allowances as agreed in the applicable order form, SSO, activity record, API access, dedicated support
3.2 Billing
Paid subscriptions are billed monthly in advance through Stripe. You must maintain a valid payment method on file. Fees do not include applicable taxes, which are your responsibility.
3.3 Price Changes
We may adjust pricing with at least 30 days' advance notice. Price changes take effect at the start of your next billing cycle. If you do not agree with a price change, you may cancel before the next billing cycle.
4. Term and Cancellation
4.1 Subscription Term
Paid subscriptions renew automatically on a monthly basis until cancelled. You may cancel at any time. Cancellation takes effect at the end of your current billing period — you retain access until then.
4.2 Fees; Service Credits
Except as required by applicable law or expressly stated in an Order Form, fees are non-cancelable and non-refundable. Company may offer Enterprise customers a service-level agreement ("SLA") in an applicable Order Form. If Company fails to meet a stated SLA, Customer's sole and exclusive remedy, and Company's entire liability for that failure, will be the service credits specified in that SLA. Service credits are applied only to future invoices, are not refundable or payable in cash, and do not excuse Customer's payment obligations. No service interruption will constitute a material breach of these Terms unless expressly stated in the applicable Order Form.
4.3 Termination by Us
We may suspend or terminate your account if you:
- Violate these Terms or engage in Prohibited Uses (Section 7)
- Fail to pay fees for more than 30 days past due
- Use the Services in a manner that poses a security risk
We may provide reasonable notice and an opportunity to cure before termination, except in cases of Prohibited Uses or security threats.
4.4 Effect of Termination
Upon termination, access to the paid Services ceases. Customer may export its scan history from the dashboard for as long as the account remains open. Original uploaded files are deleted at ingestion and are not available for export. Full Outputs and Extracted Text are automatically deleted no later than ninety (90) days after their creation, and earlier upon Customer-initiated deletion or account deletion. Company may retain Scan Metadata for up to three (3) years after termination solely for audit, security, legal-compliance, and dispute-resolution purposes. If a dispute, claim, or legal proceeding involving Customer is pending or reasonably anticipated, deletion and retention timelines are suspended for affected records until the matter is resolved, as permitted or required by law.
Sections of these Terms that by their nature should survive (including Sections 8, 9, 10, 11, 12, and 15) will continue in effect.
5. Your Documents and Data
5.1 Ownership
You retain all rights in the documents you upload and the information contained in them. We claim no ownership of your content.
5.2 License to Company; De-Identified Data
(a) Service License. Customer grants Company a non-exclusive, worldwide, royalty-free license during the Term to host, reproduce, transmit, process, analyze, and otherwise use Customer Data solely as necessary to provide, secure, support, and improve the Services for Customer and to comply with law.
(b) De-Identified Data. Subject to Applicable Privacy Laws, Company may create and use de-identified, aggregated, and non-identifiable information derived from Customer Data ("De-Identified Data") to operate, analyze, secure, test, validate, and improve the Services, including Company's rule library, prompts, and evaluation of system performance. Company will not use Customer Data, Extracted Text, or Outputs to train, fine-tune, or otherwise improve any machine-learning or artificial-intelligence model, and relies on its AI provider's published commercial terms, under which inputs and outputs submitted through the provider's API are not used to train the provider's models.
(c) No Identification or Reidentification. Company will not attempt to identify Customer or any individual from De-Identified Data, and will not disclose De-Identified Data in a manner that identifies Customer or any individual.
(d) Enterprise Opt-Out. An Enterprise Customer may opt out of the use of De-Identified Data described in subsection (b) by stating that election in its Order Form or by delivering written notice to [email protected]. The opt-out applies prospectively after Company has had a reasonable opportunity to implement it and does not require Company to delete De-Identified Data created before the effective date of the opt-out where retention is permitted by Applicable Privacy Laws.
5.3 Document Processing and Deletion
When you upload a document:
- The original uploaded file is deleted immediately after text extraction — we do not retain original files.
- Personally identifiable information is automatically redacted before any text is sent to the AI for analysis. Redaction applies to the nine structured identifier categories listed in the Privacy Policy. Employee names, job titles, narrative descriptions, and other unstructured content are not redacted and are included in the text sent to our AI provider for analysis.
- During an active account, Company retains Extracted Text and Full Outputs for no longer than ninety (90) days after the applicable scan is generated, unless Customer deletes the document earlier. Narrative scan findings (issue titles, document excerpts, and suggested replacement language) are purged on that schedule even while your account remains active; Scan Metadata is retained as described in Section 4.4. Remediation memo export is unavailable for a scan once its Full Outputs have been deleted. Purge and deletion timelines are suspended while a legal hold is in effect (see Section 4.4).
- You may manually delete a document and its associated Extracted Text and Full Outputs at any time from your dashboard. Company will complete deletion without undue delay, subject to legal hold.
- Scan Metadata may be retained for up to three (3) years as described in Section 4.4 — never the document content or Extracted Text.
- Company uses authorized AI/API providers to process Extracted Text. Company configures and contracts with those providers to process Customer Personal Data only as necessary to provide the Services, subject to the provider's applicable service terms and Company's DPA obligations. Our current AI provider (Anthropic) does not use API-submitted data to train its models and retains API inputs in accordance with Anthropic's then-current data retention policy.
Redaction Limitations. Although Company uses automated measures designed to identify and redact certain categories of personally identifiable information before AI processing, automated redaction is not infallible and may fail to identify, redact, or accurately redact all personal information or other sensitive information. Customer is solely responsible for reviewing Customer Data before upload and for determining whether it is appropriate to submit any personal information, sensitive personal information, or other regulated data to the Services. Customer should avoid submitting personal information, sensitive personal information, or other regulated data unless submission is necessary for Customer's intended use of the Services, Customer is authorized to disclose that information, and Customer accepts the risk that automated redaction may be incomplete.
5.4 Your Responsibilities
You represent and warrant that:
- You have the legal authority to upload each document (e.g., as an authorized HR representative, legal counsel, or management employee of the organization)
- Uploading the document does not violate any confidentiality agreement, court order, or applicable law
- You will handle scan results — which may contain sensitive information — with appropriate care and in compliance with your organization's data handling policies
- You have a valid legal basis under Applicable Privacy Laws for collecting, using, disclosing, and transferring Customer Personal Data to Company
- You have provided all required privacy notices, and have obtained any consent, authorization, consultation, or other approval required by law
Customer's instructions to Company must comply with all applicable privacy, employment, labor, anti-discrimination, and cross-border transfer laws.
5.5 Sensitive Information
Workplace documents may contain sensitive employee information, including references to protected characteristics, medical conditions, allegations of misconduct, and legal claims. You acknowledge that processing such documents through an AI system involves inherent risks, and you accept responsibility for determining whether AI-assisted review is appropriate for each document.
Customer must not submit Protected Health Information, as defined by HIPAA, unless Company and Customer have executed a separate Business Associate Agreement and Company has expressly agreed in writing to process that information. Customer must not submit classified government information, export-controlled information, payment-card data, or other data subject to heightened legal restrictions unless expressly authorized by Company in writing.
6. AI-Generated Results
6.1 Nature of Results
Scan results are generated by artificial intelligence and are provided as a decision-support assistant tool, not as definitive legal analysis. AI can and does make mistakes. Results may:
- Contain false positives (flagging language that is not actually problematic)
- Miss issues that a human reviewer or attorney would identify (false negatives)
- Reflect general compliance principles that may not apply to your specific jurisdiction or circumstances
- Be incomplete, outdated, or based on legal standards that have changed since the AI model was trained
- Misinterpret context, tone, or intent in ways that produce incorrect findings
Descriptions of the Services' features, categories, checks, and Outputs are general descriptions of functionality and do not constitute a representation that the Services will identify every applicable issue, law, or risk in any document.
6.2 Human Review Required
All scan results must be reviewed by a qualified professional before any action is taken. Do not rely solely on AI-generated results to make employment decisions, finalize legal documents, or determine legal strategy. DefensibleHR LLC is not responsible for any consequences — including legal liability, regulatory penalties, adverse employment outcomes, or litigation — arising from actions taken or not taken based on scan results. Seek the advice of a qualified employment attorney when needed.
6.3 No Guarantee of Accuracy
DefensibleHR LLC makes no representation or warranty that scan results are accurate, complete, current, or applicable to your situation. The absence of a flagged issue does not mean a document is legally compliant. A flagged issue does not necessarily mean a document is non-compliant. Results are starting points for human review, not conclusions.
6.4 Jurisdiction Detection
The Services may detect state or local jurisdictions referenced in your documents and display general compliance notices with links to state Department of Labor resources. These notices are informational only and do not constitute advice about specific state or local law requirements. Consult local counsel for jurisdiction-specific guidance.
6.5 Artificial Intelligence Disclosure
Company seeks to provide transparent information regarding the use and limitations of AI in the Services. Nothing in this Section represents that the Services are certified, approved, or endorsed by the Federal Trade Commission or any governmental authority.
- Individual scan results — findings, category labels, risk levels, remediation suggestions, and example replacement language — are generated by artificial intelligence (large language models operated by Anthropic) applying Company's rule library to your document, and not by human reviewers, attorneys, or compliance professionals. The rule library is written and periodically reviewed by people against primary sources; that review is of the rule library, not of your document or your results, and does not make any Output legal advice or create an attorney-client relationship.
- No employee, contractor, or attorney of DefensibleHR LLC reviews, verifies, or approves individual scan results before they are delivered to you.
- AI language models are probabilistic systems. Identical text scanned with the same settings and the same version of Company's rule library will return the same findings; any change to the document, to the selected jurisdictions or other settings, or to the rule library or model may change the results. Any output may contain errors, omissions, or fabricated content ("hallucinations").
- Example replacement language in scan results and remediation memos is AI-drafted template text, not attorney-drafted contract language. It must be reviewed and adapted by a qualified employment attorney before use in any document.
- The AI models underlying the Services may be updated or replaced over time, which may change the nature, format, or substance of results.
- We do not use AI to make automated decisions that produce legal or similarly significant effects about any individual. The Services analyze documents; they do not evaluate, score, or make decisions about employees or job applicants.
6.6 No Automated Employment Decisions; Output Limitations
The Services analyze documents; they do not evaluate, rank, score, profile, recommend, or make decisions about applicants, employees, contractors, or other individuals. Customer must not use the Services or any Output as the sole or determinative basis for a hiring, termination, promotion, compensation, discipline, performance, benefits, or other employment decision.
6.7 Citations and System Evaluation
Where available, Outputs may include citations or links to public legal sources for convenience. References are provided for convenience only and may be incomplete, outdated, or inapplicable. Verify all legal authorities independently before relying on them. Company uses reasonable measures designed to evaluate and improve system performance, including periodic review of prompts, rulesets, and model configurations. Company does not warrant that Outputs are complete, current, unbiased, or error-free.
7. Prohibited Uses
You may not use the Services to:
- Upload documents you are not authorized to access or share
- Process documents for the purpose of concealing evidence, obstructing investigations, or facilitating discrimination
- Reverse engineer, decompile, or attempt to extract the source code, AI prompts, compliance rulesets, or underlying architecture of the Services
- Use the Services, or any scan result, finding, suggested language, remediation memo, or metadata derived from the Services, to train, fine-tune, evaluate, or benchmark any artificial intelligence or machine learning model, or to create datasets for such purposes
- Systematically collect or aggregate outputs or metadata from the Services to build a competing product or derivative compliance methodology
- Resell, sublicense, or provide the Services to third parties without our written consent
- Introduce malicious code, viruses, or scripts that interfere with the Services
- Use automated tools (bots, scrapers) to access the Services
- Circumvent rate limits, authentication, or security measures
- Use the Services in violation of applicable law
- Provide access to competitors for the purpose of competitive analysis
- Upload, transmit, or process any data prohibited by Section 5.5
Violation of this section constitutes a material breach and may result in immediate account termination.
8. Intellectual Property & License Enforcement
8.1 Our Property
The Services — including the platform, software architecture, scanning algorithms, AI prompts, compliance rulesets and methodology, risk categories and scoring systems, output formats and schemas, redaction pipeline, user interface, and documentation — are and remain the exclusive property of DefensibleHR LLC and are protected by intellectual property laws. These Terms do not grant you any rights to our intellectual property except the limited right to use the Services as described here. All rights not expressly granted are reserved.
8.1A Scan Results License
Subject to these Terms, we grant you a perpetual, non-exclusive license to use scan results, findings, example replacement language, and remediation memos generated from your documents for your organization's internal business and compliance purposes, including incorporating such language into your own documents. This license does not include the right to resell outputs, provide them to third parties as a service, or use them for the machine learning purposes prohibited by Section 7. The structure, format, categories, and methodology reflected in outputs remain our property under Section 8.1.
8.2 Feedback
If you provide suggestions, ideas, or feedback about the Services, you grant us a perpetual, royalty-free, worldwide license to use and incorporate that feedback without obligation to you.
8.3 Copyright Complaints (DMCA)
You represent and warrant that you own or have the necessary rights to upload any document you submit to the Services. Documents uploaded to the Services are private to your organization, are not published or made publicly available by us, and original files are deleted immediately after text extraction as described in Section 5.
If you believe that material processed through the Services infringes your copyright, you may submit a notification under the Digital Millennium Copyright Act (17 U.S.C. § 512) to our designated agent: Copyright Agent, DefensibleHR LLC, [email protected]. Your notice must include: (a) identification of the copyrighted work claimed to be infringed; (b) identification of the material claimed to be infringing and information reasonably sufficient to locate it; (c) your contact information; (d) a statement that you have a good-faith belief that the use is not authorized by the copyright owner, its agent, or the law; (e) a statement, under penalty of perjury, that the information in the notice is accurate and that you are authorized to act on behalf of the copyright owner; and (f) your physical or electronic signature.
We will respond to valid notices by removing or disabling access to the identified material and, where appropriate, terminating the accounts of repeat infringers.
8.4 Credentials, Keys, and Seat Integrity
Account credentials, session tokens, verification codes, and any API keys or access tokens we issue (collectively, "Access Credentials") are issued to a specific named user or to your organization, are our property, and are licensed — not sold — for use solely as permitted by these Terms and your plan.
- No sharing or pooling. Each set of user credentials may be used only by the individual to whom it is issued. You may not share, pool, rotate, or transfer credentials among multiple individuals to defeat seat limits under Section 3, and you may not permit any person who is not an authorized user on your plan to access the Services through your credentials.
- API keys. Where a plan includes API access, keys are confidential to your organization, may not be published, embedded in publicly accessible code, sold, or shared with any third party, and may be used only to access the Services on your organization's own behalf.
- Your responsibility. You are responsible for all activity under your Access Credentials, whether or not authorized by you, until you notify us of a compromise. You will notify us promptly at [email protected] upon becoming aware of any loss, theft, or unauthorized use of Access Credentials.
- Our controls. We may suspend, rotate, or revoke any Access Credential at any time where we reasonably believe it has been compromised, shared in violation of this Section, or used in connection with a breach of these Terms.
8.5 Anti-Circumvention
The Services include technological measures that control access, enforce plan limits, and protect our intellectual property and our users' data — including authentication, email verification, scan quotas and seat limits, rate limits, bot-detection, the PII redaction pipeline, and content gating. You may not, and may not assist, encourage, or permit any third party to:
- Bypass, remove, disable, probe, or interfere with any such measure, or access any non-public interface, endpoint, or administrative function of the Services;
- Evade usage limits or eligibility rules — including by creating multiple accounts or organizations, supplying false or third-party email addresses or identities, manipulating verification flows, or resetting or rotating identifiers — to obtain scans, seats, features, or free-tier access beyond what your plan provides;
- Interfere with our measurement of usage, or misrepresent usage, for the purpose of reducing amounts owed;
- Remove, obscure, or alter any proprietary notice, disclaimer, or attribution appearing in the Services or in outputs (including remediation memos); or
- Frame, mirror, or republish any part of the Services without our prior written consent.
8.6 Enforcement and Remedies
Any breach of Sections 7, 8.4, or 8.5 is a material breach of these Terms. In addition to any other rights we have:
- Suspension and termination. We may suspend or terminate access immediately under Section 4.3, without refund, upon any such breach;
- Recovery of evaded amounts. Where usage limits were exceeded or evaded, we may invoice, and you agree to pay, fees for the actual usage obtained at our then-current published rates;
- Injunctive relief. You acknowledge that breach of this Section 8 or of the confidentiality and machine-learning restrictions in Sections 7 and 12 would cause us irreparable harm for which monetary damages are an inadequate remedy, and that we are entitled to seek injunctive or other equitable relief — notwithstanding the arbitration provisions of Section 15, either party may seek such relief in a court of competent jurisdiction to protect intellectual property or confidential information;
- No waiver; survival. Our failure to enforce any provision is not a waiver. This Section 8 survives termination of these Terms, along with the licenses and restrictions it protects.
9. Disclaimer of Warranties
THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY. We specifically disclaim:
- Any warranty that scan results will be accurate, complete, or current
- Any warranty of merchantability, fitness for a particular purpose, or non-infringement
- Any warranty that the Services will be uninterrupted, error-free, or secure
- Any warranty that the Services will identify all legal risks in a document
The Services are an AI-powered assistant tool to aid qualified professionals — not a replacement for legal counsel. AI can and does make mistakes. You are solely responsible for the legal sufficiency of your workplace documents and for verifying any scan findings with a qualified attorney. DefensibleHR LLC is not responsible for any errors, omissions, or inaccuracies in scan results.
No oral or written information, advice, scan result, suggested language, or marketing statement obtained from DefensibleHR LLC or through the Services creates any warranty not expressly stated in these Terms. Some jurisdictions do not allow the exclusion of implied warranties, so some of the above exclusions may not apply to you; in that case, any implied warranties are limited to the minimum scope and duration permitted by law.
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW:
- DefensibleHR LLC is not liable for any indirect, incidental, special, consequential, or punitive damages, including lost profits, lost data, business interruption, or damages arising from employment decisions made in reliance on scan results or from the use, adoption, or publication of AI-generated suggestions, replacement language, or remediation memos
- Company's total aggregate liability arising out of or relating to these Terms or the Services will not exceed the greater of: (a) the fees actually paid by Customer to Company during the twelve (12) months immediately preceding the event giving rise to the claim; or (b) one thousand dollars ($1,000). The foregoing cap applies in the aggregate, not per claim.
- DefensibleHR LLC is not liable for any legal consequences, regulatory penalties, adverse employment outcomes, or litigation outcomes resulting from actions taken or not taken based on scan results
- DefensibleHR LLC is not responsible for errors, omissions, false positives, false negatives, or any other inaccuracies in AI-generated scan results
These limitations apply regardless of the theory of liability (contract, tort, strict liability, or otherwise) and even if we have been advised of the possibility of such damages. You acknowledge that the Services are an AI-powered assistant that can make mistakes, and you assume all risk associated with using scan results without independent legal review.
11. Indemnification
11.1 Your Indemnification
You agree to indemnify and hold harmless DefensibleHR LLC and its officers, directors, employees, and agents from any claims, damages, losses, or expenses (including reasonable attorneys' fees) arising from:
- Your use of the Services or violation of these Terms
- Documents you upload, including claims by employees or third parties whose information appears in those documents
- Your reliance on scan results without appropriate professional review
- Your violation of any applicable law or regulation
11.2 Company Indemnification
Company will defend Customer against a third-party claim alleging that Customer's authorized use of the unmodified Services infringes that third party's United States copyright or trademark, and will pay final damages awarded or settlements approved by Company. Customer must promptly notify Company in writing after receiving a written third-party claim for which Customer seeks indemnification under this Section; provided that Customer's failure to provide prompt notice will relieve Company of its obligations only to the extent Company is materially prejudiced by that failure. In addition, Customer must: (a) give Company sole control of the defense and settlement; and (b) reasonably cooperate at Company's expense. Company may not settle a claim in a manner that admits Customer liability or imposes non-monetary obligations on Customer without Customer's consent.
11.3 Remedies; Exclusions
If the Services become subject to a claim, Company may: (a) procure the right for Customer to continue using the Services; (b) modify or replace the affected Services; or (c) terminate the affected Services and refund prepaid, unused fees for the terminated portion. Company has no obligation for claims arising from Customer Data; Outputs (including scan results, findings, risk ratings, suggestions, example replacement language, and remediation memos, and any claim arising from Customer's use, adoption, publication, or incorporation of Outputs into its documents); Customer's modification of the Services; use with products, data, or content not supplied by Company; or use contrary to these Terms. Company's liability under Section 11.2 will not exceed the greater of $20,000 or five (5) times the fees paid by Customer during the twelve (12) months preceding the claim. This Section 11 states Company's entire obligation and Customer's exclusive remedy for any third-party claim relating to the Services.
12. Confidentiality
Each party agrees to protect the other's confidential information with the same care it uses for its own (and no less than reasonable care). Confidential information includes:
- Your uploaded documents and scan results
- Our proprietary technology, AI prompts, and compliance rulesets
- Business terms, pricing, and account information
Confidentiality obligations do not apply to information that is publicly available, independently developed, or required to be disclosed by law.
Notwithstanding the foregoing, Company may disclose Customer Confidential Information to its authorized subcontractors, cloud providers, and API providers solely to the extent necessary to provide, secure, support, or improve the Services, provided that each recipient is bound by written confidentiality, privacy, and security obligations no less protective than those applicable to Company under these Terms and the DPA.
13. Privacy and Data Processing
Company's collection and use of personal information is governed by the Privacy Policy, which is incorporated into these Terms by reference. To the extent Company processes Customer Personal Data on Customer's behalf, the DefensibleHR Data Processing Addendum ("DPA"), version dated September 18, 2026, available at defensiblehr.ai/dpa and incorporated into these Terms by reference, automatically applies to that processing.
By creating an account, executing an Order Form, or submitting Customer Personal Data to the Services, Customer agrees to the DPA. If these Terms conflict with the DPA concerning the processing of Customer Personal Data, the DPA controls to the extent of the conflict. Customer is responsible for responding to rights requests concerning Customer Personal Data, subject to Company's assistance obligations under the DPA and Applicable Privacy Laws.
Cookie, advertising, and preference practices are governed by the Privacy Policy; Customer Data and Full Outputs are not used for advertising technologies.
14. Communications
14.1 Permission-Based Email
We send transactional, service, and marketing email only as permitted by Applicable Privacy Laws and in accordance with the Privacy Policy. Marketing messages are subject to the opt-out rights in Section 14.3. We do not send email to purchased or third-party lists.
14.2 Types of Email
We send the following categories of email:
- Account and security: Welcome emails, password resets, and account security alerts
- Transactional: Payment receipts, invoice notifications, plan change confirmations, and billing-related notices
- Support: Ticket confirmations, status updates, and responses to your support requests
- Service: Material changes to these Terms, the Privacy Policy, or the Services
- Marketing: Product updates, feature announcements, and information about DefensibleHR.ai services, sent where permitted by Applicable Privacy Laws. Every marketing email includes an unsubscribe link.
14.3 Opting Out
Marketing emails include a one-click unsubscribe mechanism, and we honor opt-outs within 10 business days. Transactional and account-related emails (receipts, security alerts, material Terms changes) do not have a separate unsubscribe because we are required to send them while you maintain an active account; to stop these, close your account by contacting [email protected].
14.4 Email Suppression
We automatically suppress email delivery to addresses that have generated a hard bounce (permanent delivery failure) or a spam complaint. If your email address has been suppressed and you believe this is in error, contact [email protected] to request removal from the suppression list.
14.5 SMS Communications
SMS messages are sent only with your separate express opt-in consent and are governed by the Privacy Policy. SMS consent is not a condition of purchase. You may revoke consent through the method disclosed at enrollment, through available account settings, or by replying STOP. Message frequency may vary; message and data rates may apply.
15. Governing Law and Disputes
15.1 Governing Law
These Terms are governed by the laws of the State of Wyoming, without regard to its conflict-of-law principles. Any dispute that is not subject to arbitration under this Section 15 shall be brought exclusively in the state courts located in Sheridan County, Wyoming, or the United States District Court for the District of Wyoming, and you and DefensibleHR LLC each consent to personal jurisdiction and venue in those courts.
15.2 Informal Resolution First
Before initiating arbitration, the party asserting a dispute must send the other party a written notice describing the dispute and the relief sought (for notices to us: [email protected], subject line "Dispute Notice"). The parties will attempt in good faith to resolve the dispute within 30 days of the notice. Arbitration may not be commenced until this period has expired.
15.3 Binding Arbitration
YOU AND DEFENSIBLEHR LLC AGREE THAT ANY DISPUTE, CLAIM, OR CONTROVERSY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICES — INCLUDING THEIR FORMATION, INTERPRETATION, BREACH, OR TERMINATION, AND INCLUDING STATUTORY, CONSUMER-PROTECTION, AND TORT CLAIMS — SHALL BE RESOLVED EXCLUSIVELY THROUGH FINAL AND BINDING ARBITRATION ON AN INDIVIDUAL BASIS, AND NOT IN COURT. ARBITRATION WILL BE ADMINISTERED BY JAMS UNDER ITS STREAMLINED ARBITRATION RULES IN EFFECT WHEN THE ARBITRATION IS COMMENCED. Unless the parties agree otherwise, the arbitration will be conducted remotely by videoconference. If an in-person hearing is required by applicable law, the JAMS rules, or the arbitrator, the hearing will take place in Cheyenne, Wyoming. THE FEDERAL ARBITRATION ACT GOVERNS THE INTERPRETATION AND ENFORCEMENT OF THIS SECTION. THE ARBITRATOR — NOT ANY COURT — HAS EXCLUSIVE AUTHORITY TO RESOLVE DISPUTES ABOUT THE INTERPRETATION, APPLICABILITY, OR ENFORCEABILITY OF THIS ARBITRATION AGREEMENT, EXCEPT THAT A COURT DECIDES WHETHER A CLAIM MAY PROCEED ON A CLASS OR REPRESENTATIVE BASIS IF SECTION 15.4 IS FOUND UNENFORCEABLE. JUDGMENT ON THE AWARD MAY BE ENTERED IN ANY COURT OF COMPETENT JURISDICTION. EACH PARTY BEARS ITS OWN ATTORNEYS' FEES EXCEPT WHERE THE APPLICABLE LAW OR JAMS RULES PROVIDE OTHERWISE; WE WILL PAY JAMS FILING, ADMINISTRATIVE, AND ARBITRATOR FEES TO THE EXTENT REQUIRED BY THE JAMS CONSUMER ARBITRATION MINIMUM STANDARDS.
15.4 Class Action and Jury Trial Waiver
YOU AND DEFENSIBLEHR LLC EACH WAIVE THE RIGHT TO A TRIAL BY JURY AND THE RIGHT TO PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, CONSOLIDATED PROCEEDING, OR REPRESENTATIVE PROCEEDING OF ANY KIND. Disputes must be brought on an individual basis only. The arbitrator may not consolidate more than one party's claims or preside over any form of class or representative proceeding. If this waiver is found unenforceable as to a particular claim, that claim (and only that claim) shall proceed in court, and the remaining claims shall proceed in arbitration.
15.5 Exceptions
This Section 15 does not require arbitration of: (a) individual claims within the jurisdiction of small claims court; (b) claims for injunctive or equitable relief relating to intellectual property infringement, misappropriation, or breaches of confidentiality, which either party may bring in court; or (c) claims that cannot be arbitrated as a matter of law.
15.6 Severability of Arbitration Provisions
If any portion of this Section 15 (other than the class action waiver in Section 15.4) is found unenforceable, that portion shall be severed and the remainder of this Section shall be enforced. If the class action waiver in Section 15.4 is found wholly unenforceable, this entire Section 15 shall be null and void, and disputes shall be resolved in the courts identified in Section 15.1.
15.7 Time Limit on Claims
To the extent permitted by law, any claim arising out of or relating to these Terms or the Services must be filed within one (1) year after the claim accrued, or it is permanently barred.
16. General Provisions
16.1 Entire Agreement
These Terms, together with the Privacy Policy and the DPA, constitute the entire agreement between you and DefensibleHR LLC regarding the Services and supersede all prior agreements.
16.2 Amendments
We may modify these Terms at any time. We will notify you of material changes at least 10 days before they take effect via email or a prominent notice on the platform. Continued use after the effective date constitutes acceptance.
16.3 Severability
If any provision is found unenforceable, it will be modified to the minimum extent necessary. The remaining provisions continue in full effect.
16.4 Assignment
You may not assign these Terms without our written consent. We may assign these Terms in connection with a merger, acquisition, or sale of assets with notice to you.
16.5 No Waiver
Our failure to enforce any provision does not waive our right to enforce it later.
16.6 Independent Contractors
These Terms do not create a partnership, agency, or employment relationship between the parties.
16.7 Force Majeure
Neither party is liable for failure to perform obligations due to circumstances beyond reasonable control, including natural disasters, war, pandemics, government actions, or internet or infrastructure failures.
16.8 Export Compliance
You agree to comply with all applicable U.S. export control and sanctions laws. You may not use the Services from a sanctioned country or provide access to sanctioned individuals or entities.
16.9 Accessibility
Company endeavors to improve the accessibility of the Services over time, with the goal of moving toward substantial conformance with WCAG 2.1 Level AA. Upon written request, Company will provide its then-current accessibility information, if any. This Section does not create a warranty that the Services conform to any accessibility standard or will be error-free or accessible in every respect.
16.10 Geographic Scope
The Services are hosted in and offered exclusively within the United States and are intended solely for Customers located in the United States. Customer represents that it is located in the United States and agrees not to submit personal data that is subject to the data-protection laws of the European Economic Area, the United Kingdom, or Switzerland. Company does not offer Standard Contractual Clauses or other cross-border transfer mechanisms. If you access the Services from outside the United States, you do so on your own initiative and are responsible for compliance with applicable local law; any information you submit will be transferred to and processed in the United States.
17. Contact
For questions about these Terms:
- General: [email protected]
- Support: [email protected]