Terms of Service

GovernanceApp Services & Subscription Agreement

Intellectus Universe Pte. Ltd.

Effective Date: —

These Terms of Service ("Terms" or "Agreement") are entered into between Intellectus Universe Pte. Ltd. (UEN: 202556427R), a company incorporated in Singapore with its registered address at 12 Woodlands Square, #13-79, Woods Square, Singapore 737715 ("Service Provider", "IU", "we", "our" or "us"), and * ("Client", "you" or "your").

* Fields marked with an asterisk are mandatory.

By creating an account, clicking "I agree", signing below, or otherwise accessing or using GovernanceApp, you accept these Terms on behalf of yourself and, where applicable, your firm or organisation. If you do not agree, please do not use the Service.

1.About GovernanceApp

1.1GovernanceApp is an enterprise governance intelligence platform developed by IU that supports the end-to-end secretarial and governance workflow — including AI-assisted preparation of documents for board meeting, regulatory research, corporate drafting, engagement management, and a firm-wide Templates repository (hereinafter the "Service").

1.2The Service is hosted on reputable cloud infrastructure. Additional features and modules may be introduced, modified or withdrawn from time to time; we will give reasonable notice of any change that materially reduces the Service.

2.Free Trials & Discounts

2.1IU may, at its sole discretion, offer a free trial period, a promotional credit allowance, or a special discount to new sign-ups, existing clients, or any other group of users. Any such offer is discretionary, may vary between clients, and may be amended, extended or withdrawn by IU at any time without creating an entitlement for other clients.

2.2No subscription fees are payable during a free trial. There is no obligation to subscribe following completion of a trial.

3.Subscription, Credits & Payment

3.1Paid use of the Service is billed under the plan you select or that is assigned to your account (each a "Plan"), and is metered through a shared credit pool as described in your Plan and in-app billing dashboard.

3.2Fees are payable in advance for the applicable billing cycle and are processed through our payment provider. Except as required by law or as we expressly agree, fees are non-refundable.

3.3We may change Plan pricing or credit allowances for future billing cycles on reasonable prior notice. Changes will not apply retroactively to a period you have already paid for.

4.Licence to Use the Service

4.1Subject to your compliance with these Terms and payment of applicable fees, IU grants you a non-exclusive, non-transferable, revocable licence to access and use GovernanceApp — including the Templates — solely for your own or your firm's internal governance and business purposes.

4.2This licence does not permit you to resell, sublicense, redistribute, or otherwise make the Templates, or any other part of the Service available to any third party as a standalone product or service, whether for a fee or free of charge.

4.3You must not, and must not permit any third party to: (a) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying models, or architecture of the Service; (b) use the Service to build, train, or improve a competing product or service; or (c) systematically scrape, bulk-extract, or copy the Templates, or any contents of Knowledge, and Intelligence for use outside the Service.

5.AI Assistance — Human-in-the-Loop

5.1GovernanceApp uses artificial intelligence to assist — not replace — the professional judgment of qualified governance practitioners. The Service is a productivity tool, not a substitute for the human review, verification, and independent legal judgment that must remain part of every governance task you perform.

5.2AI-generated outputs may contain errors, omissions, or references to outdated laws, regulations, or sources. You must independently review, verify, and where appropriate have a qualified professional check any output before relying on it, filing it, sending it to a client or counterparty, or otherwise acting on it.

5.3You remain solely and fully responsible for all governance work, advice, filings, and other tasks you perform using the Service, and for exercising professional judgment consistent with your applicable professional and regulatory obligations. Nothing in the Service constitutes legal advice, and no attorney-client or equivalent professional relationship is created between you and IU.

6.Your Data, Confidentiality & Data Processing

6.1All documents, templates, precedents, work product, and other information you upload or generate through the Service remain your property. IU does not sell or commercially exploit your confidential information or that of your clients.

6.2IU processes personal data and other information you submit to the Service solely to provide, maintain, and improve the Service, in accordance with our Privacy Policy, Security Policy, and Annex A, which forms part of these Terms. Any processing of personal data in Client Materials uploaded by or on behalf of the Client shall also be governed by Annex A, and in the event of any inconsistency between these Terms and Annex A in relation to the processing of personal data, Annex A shall prevail solely to the extent necessary to give effect to the parties' data-processing obligations, and otherwise these Terms shall remain in full force. This includes appropriate technical and organisational measures to protect your data, use of vetted sub-processors where necessary to operate the Service, and deletion or return of your data on request following termination, subject to any retention we are required by law to maintain.

6.3Each party shall keep confidential any non-public information disclosed by the other in connection with the Service, and shall not disclose it except to personnel or contractors who need it to perform their obligations and who are bound by equivalent confidentiality obligations. This Clause 6 survives termination of this Agreement.

6.4You acknowledge that de-identified or aggregated usage insights, technical diagnostics, and product performance information may be used by IU for Service improvement, quality assurance, and research purposes, without including client-identifiable confidential information.

7.Intellectual Property

7.1IU and its licensors retain all right, title, and interest in and to the Service, including its software, models, design, Templates, Knowledge and Intelligence content supplied by IU, except for any Client-supplied content within them.

7.2You retain all right, title, and interest in your own documents, data, and work product uploaded to or generated through the Service.

8.Term, Suspension & Termination

8.1This Agreement commences on the Effective Date and continues for the term of your Plan, renewing automatically unless cancelled in accordance with your Plan's terms.

8.2Either party may terminate for convenience on written notice, or immediately if the other party materially breaches this Agreement and fails to remedy the breach within a reasonable period after notice. IU may also suspend or limit access to protect the Service, other users, or to comply with law.

8.3Any failure by you to pay any amounts due under this Agreement or your Plan when due shall constitute a material breach of this Agreement, and IU may suspend the Service or terminate this Agreement immediately.

8.4On termination, your right to access the Service ends. We will provide a reasonable opportunity to retrieve your data before deletion, except where you request earlier deletion or law requires otherwise.

9.Incorporation of Standard Terms

9.1The following ai2bundle.co policies are incorporated by reference and form an integral part of this Agreement:

9.2Where any provision of those general policies conflicts with a GovernanceApp-specific provision of this Agreement, this Agreement governs to the extent of the inconsistency, solely in relation to GovernanceApp.

10.Disclaimers & Exclusion and Limitation of Liability

10.1The Service is provided "as is" and "as available." IU does not warrant that AI-generated outputs will be accurate, complete, current, or fit for any particular purpose, or that the Service will be uninterrupted or error-free.

10.2To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, punitive, or exemplary damages, including but not limited to: loss of profits, revenue, or business opportunities, loss of data or information, loss of goodwill or reputation, business interruption, cost of substitute services, or any other intangible losses. This exclusion applies regardless of the theory of liability (contract, tort, negligence, strict liability, or otherwise) and even if we have been advised of the possibility of such damages.

10.3For the avoidance of doubt, the Parties agree that all liability of the Service Provider arising out of or in connection with this Agreement shall be governed by, and subject to, the limitation and exclusion provisions set out in the Service Provider's Terms and Conditions, as applicable.

10.4Nothing in this Agreement excludes liability that cannot lawfully be excluded.

11.Good Faith & General

11.1The parties intend to cooperate constructively; should any issue arise, both parties will work together in good faith towards a practical resolution before pursuing formal dispute resolution.

11.2This Agreement, together with the policies incorporated under Clause 9 and your Plan, constitutes the entire agreement between the parties on this subject and supersedes prior discussions on the same subject. IU may update these Terms from time to time by posting the updated version and, where changes are material, giving reasonable notice; continued use after the effective date of an update constitutes acceptance. You may not assign this Agreement without IU's consent; IU may assign it in connection with a merger, acquisition, or sale of assets. If any provision is held unenforceable, the remainder continues in effect.

12.Governing Law & Dispute Resolution

12.1This Agreement is governed by the laws of Singapore.

12.2Any dispute arising out of or in connection with this Agreement, including any question regarding its existence, validity, or termination, shall be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the Arbitration Rules of the Singapore International Arbitration Centre ("SIAC Rules") for the time being in force, which rules are deemed incorporated by reference into this clause. The seat of arbitration shall be Singapore, the Tribunal shall consist of one (1) arbitrator, and the language of the arbitration shall be English.

13.Acceptance

13.1For self-service sign-ups, you accept this Agreement electronically by creating an account and/or checking the "I agree to the Terms of Service" box during registration, which is as valid and binding as a physical signature.

13.2For enterprise clients onboarded directly by IU, this Agreement may instead be countersigned below or executed as an e-signed copy provided at onboarding.

ANNEX A — Data Processing Agreement (EU GDPR)

1.Purpose and Scope

1.1This Data Processing Agreement ("DPA") forms part of the Principal Agreement between Intellectus Universe Pte. Ltd. ("Processor", "we", "our" or "us") and the customer ("Controller", "you" or "your") identified in the applicable Order, Services & Subscription Agreement for the provision of the Services (hereafter the "Principal Agreement").

1.2This DPA applies where the Processor Processes Personal Data on behalf of the Controller in connection with the Services and Applicable Data Protection Laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), require a data processing agreement.

1.3This DPA supplements the Principal Agreement. Except as expressly provided in this DPA, the Principal Agreement, including the Terms and Conditions, Terms of Use, Privacy Policy and Security Policy, remains in full force and effect.

1.4In the event of any inconsistency between this DPA and the Principal Agreement, this DPA shall prevail only to the extent necessary to comply with Applicable Data Protection Laws.

2.Definitions

Unless otherwise defined in the Principal Agreement, capitalised terms used in this DPA have the meanings given under Applicable Data Protection Laws. For the purposes of this DPA:

2.1"Applicable Data Protection Laws" means all laws applicable to the Processing of Personal Data under this DPA, including the GDPR, as amended or replaced from time to time.

2.2"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given under the GDPR.

2.3"Principal Agreement" means the applicable subscription, order, Terms and Conditions, Services & Subscription Agreement and any documents incorporated by reference governing the Services.

2.4"Services" means the software, applications and related services provided by the Processor.

3.Roles of the Parties

3.1The parties acknowledge that:

  • (a) the Controller determines the purposes and means of the Processing of Personal Data submitted through the Services;
  • (b) the Processor Processes Personal Data solely on behalf of the Controller for the purposes of providing, maintaining, securing and supporting the Services, and for other purposes permitted under the Principal Agreement or Applicable Data Protection Laws; and
  • (c) each party shall comply with the Applicable Data Protection Laws applicable to its respective role.

3.2The Controller remains responsible for the accuracy, quality and lawfulness of the Personal Data and for ensuring that it has all necessary rights, consents or other lawful bases required for the Processing of such Personal Data.

4.Subject Matter, Nature and Duration of Processing

4.1The Processor Processes Personal Data on behalf of the Controller solely as necessary to provide, maintain, protect and improve the Services, fulfil its obligations under the Principal Agreement, comply with Applicable Data Protection Laws, or as otherwise permitted by the Principal Agreement.

4.2The categories of Personal Data, categories of Data Subjects and the nature and purpose of the Processing are described in Appendix A and may vary depending on the Services selected and how the Controller uses them.

4.3This DPA remains in effect for so long as the Processor Processes Personal Data on behalf of the Controller under the Principal Agreement.

5.Processor Obligations

The Processor will:

5.1Process Personal Data on the documented instructions of the Controller, as set out in the Principal Agreement, this DPA, or otherwise communicated by the Controller through its authorised use of the Services, unless otherwise required by Applicable Data Protection Laws.

5.2Implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Details of the Processor's current security measures are described in the Security Policy, which forms part of this DPA by reference and may be updated from time to time, provided that the overall level of protection is not materially diminished.

5.3Ensure that persons authorised to Process Personal Data are subject to appropriate confidentiality obligations.

5.4Notify the Controller of a confirmed Personal Data Breach affecting Personal Data Processed under this DPA without undue delay, taking into account the information reasonably available to the Processor.

5.5Provide reasonable assistance to the Controller, upon reasonable written request and to the extent required by Applicable Data Protection Laws, taking into account the nature of the Processing and the information available to the Processor.

5.6Make available information reasonably necessary to demonstrate compliance with this DPA, subject always to the confidentiality obligations, security requirements, intellectual property rights and legitimate commercial interests of the Processor and third parties.

Nothing in this clause requires the Processor to disclose source code, proprietary software, algorithms, AI models, system prompts, vulnerability assessments, penetration test reports, internal security procedures, trade secrets, information relating to other customers, or other confidential information.

6.Controller Obligations

The Controller is responsible for:

6.1determining the purposes and lawful basis for Processing Personal Data;

6.2ensuring that it has obtained all necessary rights, permissions and consents, where required;

6.3complying with Applicable Data Protection Laws in its use of the Services;

6.4ensuring that its instructions to the Processor comply with Applicable Data Protection Laws and do not require the Processor to violate any applicable law or the rights of any third party; and

6.5using the Services in accordance with the Principal Agreement.

The Controller acknowledges that the Services are provided as a configurable software platform. Except as expressly agreed in writing, the Controller is responsible for determining whether the Services are suitable for its own legal, regulatory, compliance and record-keeping requirements.

7.Sub-processors

7.1The Controller authorises the Processor to engage sub-processors as reasonably necessary to provide, maintain, secure and support the Services.

7.2The Processor shall maintain a current list of its principal sub-processors in Appendix B or by other reasonable means made available to the Controller.

7.3The Processor may appoint, replace or remove sub-processors from time to time. Where required by Applicable Data Protection Laws, the Processor will provide reasonable notice of material changes. The Controller may raise reasonable objections based on documented data protection concerns. The parties will work in good faith to address such concerns. If no reasonable solution is available, either party may terminate the affected Services upon written notice without further liability for such termination.

7.4The Processor will require its sub-processors to provide an appropriate level of protection for Personal Data consistent with the nature of the services they perform.

8.International Data Transfers

8.1The Controller acknowledges that the Services may involve the Processing of Personal Data in jurisdictions outside the European Economic Area, the United Kingdom or Switzerland.

8.2Where required by Applicable Data Protection Laws, the Processor will implement an appropriate transfer mechanism recognised under such laws, including the European Commission's Standard Contractual Clauses or any recognised successor mechanism, where applicable.

8.3Nothing in this DPA restricts the Processor from using globally distributed infrastructure or service providers, provided that appropriate safeguards are maintained where required by Applicable Data Protection Laws.

9.Data Subject Requests

9.1Taking into account the nature of the Processing, the Processor will provide reasonable assistance to enable the Controller to respond to requests from Data Subjects where required by Applicable Data Protection Laws.

9.2Where legally permitted, if the Processor receives a request directly from a Data Subject relating to Personal Data Processed on behalf of the Controller, the Processor may refer the request to the Controller for response.

9.3The Controller remains primarily responsible for responding to Data Subject requests and complying with its obligations under Applicable Data Protection Laws.

10.Audit and Compliance

10.1The Processor may satisfy its obligation to demonstrate compliance by providing documentation, policies, certifications, audit reports, questionnaires or other information reasonably sufficient to demonstrate compliance with this DPA.

10.2Where Applicable Data Protection Laws require an audit beyond the information provided, any such audit shall:

  • (a) be conducted upon reasonable prior written notice;
  • (b) occur no more than once in any twelve (12) month period unless otherwise required by Applicable Data Protection Laws or following a confirmed Personal Data Breach materially affecting the Controller;
  • (c) be conducted during normal business hours in a manner that does not unreasonably interfere with the Processor's business operations;
  • (d) be subject to appropriate confidentiality obligations; and
  • (e) be at the Controller's expense, including the Processor's reasonable costs incurred in facilitating the audit, to the extent permitted by Applicable Data Protection Laws.

10.3Nothing in this clause requires the Processor to disclose information that would:

  • (a) compromise the security or integrity of the Services;
  • (b) breach confidentiality obligations owed to other customers or third parties;
  • (c) disclose trade secrets, proprietary information, source code, AI models, system prompts, security architecture, penetration test reports or other confidential information; or
  • (d) otherwise violate Applicable Law.

11.Return or Deletion of Personal Data

11.1Upon termination or expiry of the Principal Agreement, the Processor will, within a reasonable period and subject to the functionality of the Services, either delete or return Personal Data Processed on behalf of the Controller, unless continued retention is:

  • (a) required or permitted by Applicable Law;
  • (b) reasonably necessary to establish, exercise or defend legal claims;
  • (c) required for security, fraud prevention, backup, disaster recovery or business continuity purposes; or
  • (d) otherwise permitted under the Principal Agreement or the Processor's Privacy Policy.

11.2The Controller acknowledges that deletion from backup systems and disaster recovery media may not occur immediately and will be performed in accordance with the Processor's standard retention and deletion practices.

12.Liability

12.1This DPA forms part of the Principal Agreement.

12.2To the fullest extent permitted by Applicable Law, the exclusions, limitations of liability, disclaimers and allocation of risk set out in the Principal Agreement apply equally to this DPA and form an integral part of it.

12.3Nothing in this DPA limits or excludes liability where such limitation or exclusion is prohibited by Applicable Law.

13.Miscellaneous

13.1This DPA shall be governed by the governing law and dispute resolution provisions set out in the Principal Agreement unless otherwise required by Applicable Data Protection Laws.

13.2The Processor may update this DPA, Annexes, Security Policy, Privacy Policy or list of sub-processors from time to time where reasonably necessary to:

  • (a) reflect changes in the Services;
  • (b) improve security;
  • (c) comply with Applicable Law;
  • (d) reflect changes to infrastructure or service providers; or
  • (e) improve operational efficiency,

provided that such changes do not materially reduce the level of protection required under Applicable Data Protection Laws.

13.3If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

13.4This DPA may be executed electronically and forms part of the Principal Agreement without further signature where the Principal Agreement is accepted electronically.

APPENDIX A — Description of Processing

A1. Subject Matter — Provision of the GovernanceApp platform and related services.

A2. Duration — For the duration of the Principal Agreement and any period during which the Processor Processes Personal Data on behalf of the Controller.

A3. Nature of Processing — Collection, storage, organisation, retrieval, transmission, analysis, hosting, AI-assisted processing, support, security monitoring and deletion of Personal Data as necessary for the operation of the Services.

A4. Purpose of Processing — To provide, maintain, secure, support and improve the Services, authenticate users, process customer instructions, provide AI-assisted functionality and comply with Applicable Law.

A5. Categories of Data Subjects — May include:

  • users of the Services;
  • employees;
  • contractors;
  • clients;
  • counterparties;
  • authorised representatives; and
  • other individuals whose Personal Data is submitted by the Controller.

A6. Categories of Personal Data — May include:

  • identity and contact information;
  • account information;
  • authentication information;
  • documents uploaded by the Controller;
  • prompts, queries and AI interaction data;
  • contractual, legal and governance documents;
  • communications;
  • technical, usage and device information; and
  • any other Personal Data submitted through the Services.

APPENDIX B — Principal Sub-processors

Sub-processorPurposeLocation
Anthropic, PBCAI providerUnited States
AssemblyAI, Inc.AI providerUnited States
Cloudflare, Inc.Cloud infrastructure and hostingAsia-Pacific (Singapore)
Google LLCCloud services and integrationsRegion of the client’s own account
ILOVEPDF, S.L.Document processingEuropean Economic Area
Microsoft CorporationCloud services and integrationsRegion of the client’s own account
OpenAI, LLCAI providerUnited States
OpenRouter, Inc.AI providerUnited States
OpenSanctions Datenbanken GmbHCompliance screening servicesGermany
Perplexity AI, Inc.AI providerUnited States
Resend, Inc.Email deliveryUnited States
Squarespace, Inc.Website and domain servicesUnited States
Stripe, Inc.Payment processingUnited States
Zoom Communications, Inc.Meeting services and integrationsUnited States
For and on behalf of:
INTELLECTUS UNIVERSE PTE. LTD.
Name: James Lee
Title: Founder & CEO
Date: —
For and on behalf of:
CLIENT
Sign below ↓
Name: *
Title: (optional)
Email: *
Date: —
✍ Draw
⌨ Type
⤴ Upload
Your typed name is rendered as a signature.
Upload a signature image (PNG / JPG, transparent background works best)
✓ Signature applied. You can re-sign anytime before finalising.
Data stored with Cloudflare — Award-winning Cloud Security Company. We never use your data to train AI models.
← Back to Sign In