1. Agreement and scope
These Terms govern access to Zubu’s hosted legal hold, preservation, collection and related services (the “Services”). “Customer” means the organization subscribing to the Services; “Authorized Users” means individuals it permits to use them. “Zubu” means the service provider identified in the applicable signed order form or services agreement. A person accepting these Terms for an organization must have authority to bind it.
A signed agreement or order form takes precedence over these Terms where they conflict. An applicable data processing agreement governs conflicting provisions about personal data processing. Purchased functionality, usage limits, subscription periods and service commitments are those expressly agreed in writing.
2. Services and permitted use
The Services support custodian administration, hold notices and acknowledgments, preservation workflows, collection orchestration and related reporting. Available integrations may include Microsoft 365, Google Workspace, Slack and Confluence, depending on the subscribed services and supported configuration. Collection destinations may include customer-controlled cloud storage.
Zubu grants Customer a limited, non-exclusive right to access the subscribed Services during the agreed term for its internal business purposes, subject to the agreement and purchased limits. Trials and preview features may have separate conditions and should not be relied on for production preservation without an agreed scope.
3. Accounts and authorized access
Customer is responsible for designating administrators, approving user access, maintaining accurate contact details and promptly removing access when no longer required. Users must safeguard credentials, use available authentication controls as required by Customer’s policies, and avoid sharing individual accounts.
Customer must promptly report suspected credential compromise, unauthorized access or misuse to security@zubu.ai. Customer remains responsible for its users’ instructions and for the security of its identity providers, endpoints and connected systems.
4. Customer data and processing instructions
Customer retains its rights in information it submits, connects, preserves or collects using the Services (“Customer Data”). Customer authorizes Zubu to process Customer Data to provide the agreed Services, follow authorized instructions, support the service and meet applicable legal obligations, subject to the governing agreement.
Customer must have the necessary rights and lawful authority to access and process source data, including required notices, permissions and organizational approvals. Personal data processing, subprocessors, transfers and assistance obligations are governed by the applicable data processing agreement and privacy disclosures. These Terms do not independently authorize unrelated reuse or model training on Customer Data.
5. Legal holds and preservation responsibilities
Customer and its legal advisers determine whether a preservation duty exists, which custodians and data sources are in scope, what notices to issue, and when a hold may be released. Customer must review workflow results, investigate failures and verify that required preservation remains effective in the source environment.
Deleting data, disabling an integration, revoking permissions or terminating a subscription can affect ongoing workflows. Before taking those actions, Customer must evaluate applicable holds and retention obligations. The Services support legal processes but do not provide legal advice or guarantee admissibility, completeness of discovery, or any litigation outcome.
6. Integrations and customer-controlled storage
Customer authorizes connections to third-party services and is responsible for required accounts, licenses, permissions, storage configuration and destination access. Source-system limits, API changes, retention settings and outages can affect preservation or collection.
Where data is delivered to customer-controlled storage, Customer is responsible for its access policies, encryption settings, lifecycle rules, backup arrangements and associated charges. Responsibility for each service component is allocated by the agreement; using customer-controlled storage does not remove either party’s expressly agreed obligations.
7. Security, confidentiality and incidents
Zubu’s security obligations are those in the applicable agreement and any incorporated security schedule, including agreed safeguards for access control, confidentiality and operation of the Services. Customer must implement the complementary controls applicable to its users, integrations and environment.
Each party must protect the other’s confidential information, use it for the agreed purpose and restrict disclosure to authorized recipients with appropriate obligations, except where legally required. Incident notification, cooperation and remediation obligations follow the applicable agreement and law. Suspected security incidents should be reported to security@zubu.ai; avoid sending sensitive evidence until a suitable transfer channel is agreed.
No particular uptime, incident-notification deadline, certification or audit outcome is created by this page. Any SOC 2 assurance statement must be supported by an issued report and its defined scope.
8. Acceptable use
Customer and Authorized Users must not use the Services unlawfully, access data without authorization, distribute malicious code, interfere with service availability, evade access controls, or disclose another party’s confidential information without authority. Security testing requires prior written authorization defining its scope.
Customer must not resell the Services, misrepresent ownership, or reverse engineer protected components except to the extent applicable law permits. Zubu may restrict activity that creates a material security or legal risk in accordance with the agreement, with notice and an opportunity to resolve the issue where practicable.
9. Automated outputs and audit records
Customer must evaluate automated recommendations, classifications and generated outputs before relying on them for legal or operational decisions. Results may be incomplete or inaccurate because of source permissions, missing data, configuration or other limitations.
Customer should review relevant acknowledgments, collection results and audit records and retain appropriate evidence under its policies. Record availability, export capabilities and retention periods are governed by the purchased functionality and agreement; this page does not promise indefinite retention.
10. Fees, subscription and support
Fees, invoicing, taxes, renewal, cancellation and any usage-based charges are defined in the applicable order form or signed agreement. This page does not introduce an automatic renewal, cancellation penalty or refund policy beyond those agreed terms.
Support channels, response targets, maintenance arrangements, availability commitments and service credits apply only where expressly agreed. Customer should maintain a current administrative contact for service and account notices.
11. Suspension, termination and data handling
Suspension and termination rights, notice periods and any cure periods are governed by the agreement and applicable law. Customer must coordinate preservation continuity and export of required records before access ends, including any independent retention requirements affecting customer-controlled systems.
Return, export, deletion and residual backup handling of Customer Data follow the agreement, data processing agreement and applicable law. Data subject to a binding preservation obligation must be handled consistently with that obligation. No fixed export window or deletion deadline is implied by these Terms.
12. Intellectual property, warranties and liability
Zubu and its licensors retain rights in the Services, software and documentation, excluding Customer Data and rights expressly granted to Customer. Customer receives no ownership rights in the underlying platform.
Warranties, remedies, indemnities, exclusions and liability limits are those in the governing agreement, subject to applicable law. These Terms do not replace negotiated liability provisions or exclude rights that cannot lawfully be excluded.
13. Changes, disputes and contact
Material changes to these Terms will be communicated through the contact or notice mechanism specified in the agreement, with the effective date identified. Changes do not retroactively override a signed agreement without the agreement’s required amendment process.
Governing law, dispute resolution and formal notice requirements are those specified in the applicable signed agreement. Questions about these Terms or privacy can be sent to contact@zubu.ai. Security concerns and incident reports should be sent to security@zubu.ai. Customers should use the designated contractual address for notices where the agreement requires one.

