Legal

Self-Serve Terms of Service

Contents
1. Introduction and Acceptance 2. Self-Serve Scope and Excluded Services 3. Definitions 4. Accounts, Authority, and Users 5. The Service 6. Orders, Plans, Trials, Fees, and Payment 7. Customer Content and Customer Data 8. Buyer, Responder, and Invitation Workflows 9. AI-Assisted Features 10. Customer Responsibilities and Compliance 11. Acceptable Use 12. Security and Account Protection 13. Privacy, Data Protection, and Cloud Infrastructure 14. Third-Party Services and Integrations 15. Support, Maintenance, and Availability 16. Beta, Preview, and Early Access Features 17. Intellectual Property 18. Confidentiality 19. Publicity and References 20. Warranties and Disclaimers 21. Indemnification 22. Limitation of Liability 23. Suspension, Term, and Termination 24. Changes to the Service and Terms 25. Notices 26. Governing Law and Disputes 27. General Provisions 28. Contact Information Schedule 1 - Acceptable Use Policy Schedule 2 - AI-Assisted Features Terms Schedule 3 - Support and Availability Policy Schedule 4 - Security and Data Protection Overview Schedule 5 - Self-Serve Data Processing Terms Schedule 6 - Beta and Early Access Terms

Effective Date: 2026-07-27

Company Legal Name: Sama Ventures, Inc.
Website / Application: rfpbench.com
Legal Contact: Legal Office ([email protected])

1. Introduction and Acceptance

1.1 Agreement. These RFPBench Self-Serve Terms of Service, together with any Order, online plan description, Product Terms, Acceptable Use Policy, Privacy Policy, Data Processing Terms, and other documents expressly incorporated by reference (collectively, the “Terms”), govern access to and use of the Self-Serve Service.

1.2 Who is bound. “Customer” means the company, organization, or other legal entity on whose behalf the Service is used. If an individual creates an account using a business email address or otherwise uses the Service for an organization, that individual represents that they are authorized to bind that organization. “User” means an individual authorized by Customer to access the Service.

1.3 Electronic acceptance. Customer accepts these Terms by clicking “I agree,” creating an account, signing up for a plan, using the Service, inviting Users, uploading Customer Content, paying an invoice, or otherwise accessing the Service after being presented with or linked to these Terms. The individual accepting these Terms represents that they have authority to do so.

1.4 Business use only. The Service is intended for government, educational institutions, business, professional, procurement, sales, compliance, security, and vendor-management use. It is not intended for consumer or household use. If consumer protection law applies despite this business-use restriction, nothing in these Terms limits rights that cannot legally be waived.

1.5 Order of precedence. If there is a conflict between documents, the following order applies unless expressly stated otherwise: (a) a signed written agreement between RFPBench and Customer, if any; (b) an applicable Order; (c) Data Processing Terms for privacy and data-protection matters; (d) Product Terms or plan-specific terms; (e) these Terms; and (f) policies incorporated by reference. These Self-Serve Terms do not override a separately signed enterprise agreement.

2. Self-Serve Scope and Excluded Services

2.1 Self-Serve Service. These Terms apply only to the standard RFPBench self-serve software-as-a-service offering made available through RFPBench’s website, web application, or online subscription flow. The Self-Serve Service is expected to be a multi-tenant cloud-hosted service operated by RFPBench and its infrastructure providers.

2.2 Excluded services. These Terms do not apply to:

  • dedicated single-tenant cloud deployments;
  • private cloud deployments;
  • customer on-premises or customer-premises deployments;
  • managed enterprise deployments;
  • custom hosting environments;
  • custom implementation, migration, data conversion, professional services, training, or consulting;
  • negotiated enterprise support, custom SLAs, custom security terms, custom data residency terms, or custom audit rights; or
  • any services governed by a Master Subscription Agreement, Enterprise Agreement, Statement of Work, Data Processing Agreement, Business Associate Agreement, or other separately signed contract.

2.3 Separate enterprise terms required. Dedicated cloud, private cloud, and on-premises deployments require separate written terms signed by RFPBench. No provision in these Terms grants Customer the right to install, host, operate, copy, or modify RFPBench software outside the Self-Serve Service.

2.4 Cloud infrastructure flexibility. RFPBench may deploy, host, process, store, back up, and transmit data using third-party cloud infrastructure providers, including Amazon Web Services, Google Cloud Platform, or other reputable cloud providers. RFPBench may change cloud providers, cloud regions, or hosting architecture from time to time, provided that RFPBench maintains commercially reasonable safeguards appropriate for the Service and complies with any applicable Data Processing Terms.

2.5 No dedicated environment commitment. Unless an Order expressly states otherwise, Customer is not receiving a dedicated instance, dedicated database, dedicated network, dedicated cloud account, dedicated encryption key, physical segregation, on-premises software, or custom data residency commitment.

2.6 Documentation and service descriptions. Marketing materials, website descriptions, demos, roadmaps, blog posts, pitch decks, or public statements are not binding commitments unless expressly incorporated into an Order or these Terms.

3. Definitions

TermMeaning
“Account”The administrative account or workspace created to access the Service.
“AI-Assisted Features”Features that use machine learning, natural language processing, generative AI, retrieval, ranking, classification, summarization, comparison, scoring support, or similar technologies.
“AI Input”Prompts, questions, uploaded content, source documents, instructions, metadata, or other information submitted to AI-Assisted Features.
“AI Output”Text, suggestions, summaries, classifications, comparisons, confidence indicators, citations, drafts, scores, recommendations, or other output generated by AI-Assisted Features.
“Customer Content”RFPs, RFIs, RFQs, questionnaires, answers, proposals, policy documents, security materials, compliance documents, templates, scoring materials, comments, files, data, and other content submitted to or created in the Service by or for Customer.
“Customer Data”Customer Content and any Personal Data or usage data processed by RFPBench on behalf of Customer in connection with the Service.
“Documentation”User guides, knowledge-base articles, technical materials, product instructions, API documentation, and service descriptions made available by RFPBench.
“Order”An online checkout, plan selection, invoice, order form, purchase flow, or other ordering document accepted by RFPBench.
“Plan”The subscription tier, limits, features, usage allowances, and fees selected by Customer.
“RFPBench”Sama Ventures Inc., doing business as RFPBench, together with its affiliates where applicable.
“Self-Serve Service” or “Service”The standard multi-tenant RFPBench SaaS platform and related self-serve features made available online under these Terms.
“Subscription Term”The monthly, annual, trial, or other subscription period shown in the Order or online Plan.
“User”An individual invited, authorized, or enabled by Customer to use the Service.

4. Accounts, Authority, and Users

4.1 Account creation. To use the Service, Customer or its Users may need to create an Account, provide accurate registration information, and maintain current account and billing details.

4.2 Authority. The person creating an Account, choosing a Plan, inviting Users, submitting payment details, or accepting these Terms on Customer’s behalf represents that they have authority to bind Customer.

4.3 Administrators. Customer is responsible for designating administrators, managing workspace settings, assigning roles, configuring permissions, inviting and removing Users, and controlling which Users can upload, view, edit, approve, export, or submit Customer Content.

4.4 User responsibility. Customer is responsible for all acts and omissions of its Users and any person who accesses the Service using Customer’s credentials, invite links, domains, integrations, API keys, or single sign-on configuration.

4.5 Credentials. Customer and Users must protect passwords, authentication factors, API keys, tokens, and other credentials. Customer must promptly notify RFPBench of any suspected compromise or unauthorized use.

4.6 Account accuracy. Customer must provide complete and accurate account, billing, tax, and contact information and promptly update it when it changes.

4.7 Age and capacity. Users must be at least the age of majority in their jurisdiction and capable of entering into binding business obligations, or otherwise use the Service under lawful authorization of Customer.

4.8 Domain and workspace claims. RFPBench may allow an organization to claim or administer accounts associated with its verified business domain. If a domain is claimed, Users using that domain may become subject to the organization’s workspace controls, security settings, and administrator visibility.

5. The Service

5.1 Purpose. The Service helps Customers manage RFP, RFI, RFQ, vendor-questionnaire, security-questionnaire, due-diligence, procurement, proposal, and related workflows. The Service may support buyer-side workflows, responder-side workflows, or both.

5.2 Buyer-side workflows. Buyer-side features may include creating questionnaires, distributing requests, inviting responders, receiving submissions, organizing responses, comparing vendor answers, scoring or evaluation support, internal comments, approvals, exports, and reports.

5.3 Responder-side workflows. Responder-side features may include uploading past answers and policy documents, building knowledge bases, searching prior responses, drafting answers, linking sources, assigning reviewers, tracking approvals, exporting responses, and maintaining reusable answer libraries.

5.4 Feature availability. Features vary by Plan, account configuration, region, release stage, usage limits, and product availability. RFPBench may add, modify, suspend, or discontinue features subject to Section 24.

5.5 Documentation. Customer will use the Service in accordance with the Documentation. RFPBench may update Documentation from time to time.

5.6 No exclusive remedy. The Service is a workflow, drafting, collaboration, and review tool. It does not replace Customer’s procurement, legal, compliance, security, sales, finance, or executive approval processes.

5.7 Service administration. RFPBench may access, process, or inspect system logs, metadata, and Customer Data as reasonably necessary to provide, secure, maintain, troubleshoot, support, improve, or enforce the Service, subject to the Privacy Policy and Data Processing Terms.

6. Orders, Plans, Trials, Fees, and Payment

6.1 Orders and Plans

6.1.1 Plan selection. Customer may subscribe to a Plan through an online checkout flow, account page, invoice, or other Order accepted by RFPBench. The Plan may define features, usage limits, User limits, workspace limits, storage limits, upload limits, AI usage, support level, billing period, and fees.

6.1.2 Plan changes. Customer may upgrade, downgrade, add seats, remove seats, or change billing frequency if supported by the Service. Plan changes may take effect immediately, at the next renewal, or as stated in the account interface or Order.

6.1.3 Usage limits. RFPBench may enforce Plan limits, including limits on storage, documents, pages, projects, workspaces, API calls, AI requests, invitations, exports, and Users. RFPBench may charge overage fees or require an upgrade if Customer exceeds Plan limits.

6.2 Trials and free plans

6.2.1 Free trials. RFPBench may offer free trials or promotional access. Trial terms, duration, features, and limits are determined by RFPBench and may be changed or discontinued. Trial access may be limited, suspended, or terminated at any time.

6.2.2 Conversion to paid plan. If a trial requires payment information, the subscription may automatically convert to a paid subscription at the end of the trial unless Customer cancels before the trial ends, if that was clearly disclosed during signup.

6.2.3 Free plans. RFPBench may offer free or freemium Plans with limited features. Free Plans may be modified, suspended, or discontinued, and may include lower support, retention, storage, or availability commitments.

6.3 Fees, taxes, and billing

6.3.1 Fees. Customer will pay all fees shown in the Order, account page, invoice, or online Plan description. Fees are due in the currency shown at checkout or on the invoice.

6.3.2 Taxes. Fees are exclusive of taxes unless stated otherwise. Customer is responsible for applicable taxes, duties, levies, withholding, value-added tax, goods and services tax, harmonized sales tax, provincial sales tax, sales tax, use tax, and similar charges, except taxes based on RFPBench’s net income.

6.3.3 Payment method. Customer authorizes RFPBench and its payment processor to charge the payment method provided for fees, taxes, renewals, upgrades, overages, and other charges. Customer must keep payment information current.

6.3.4 Failed payment. If payment fails, RFPBench may retry payment, notify Customer, suspend access, reduce features, or terminate the subscription after reasonable notice, subject to applicable law.

6.3.5 Invoices. If RFPBench agrees to invoice Customer, invoices are due within the stated payment period or, if none is stated, within 30 days of invoice date. Late amounts may accrue interest at the lesser of 1.5% per month or the maximum allowed by law.

6.3.6 Third-party payment processors and billing platforms. RFPBench may use one or more third-party payment processors, subscription-management providers, tax providers, invoice providers, marketplace providers, or billing platforms to process payments and manage billing for the Self-Serve Service. These providers may include Stripe or another comparable provider selected by RFPBench from time to time.

6.3.7 Billing data processed by providers. Customer authorizes RFPBench and its payment, tax, and billing providers to collect, process, store, transmit, and disclose billing contact details, payment method information, cardholder name, billing address, partial card number, card expiration date, transaction details, invoices, receipts, subscription package details, Plan tier, seat count, usage limits, renewal dates, cancellation status, upgrade and downgrade history, payment status, tax information, and related commercial records as necessary for billing, payment processing, tax, accounting, fraud prevention, chargeback management, compliance, and customer support.

6.3.8 No RFPBench storage of full card data. RFPBench does not intend to store full payment-card numbers, card security codes, or bank account numbers in its own production databases for the Self-Serve Service. Customer must not submit full payment-card numbers, card security codes, bank account credentials, or other payment authentication data through support tickets, contact forms, RFP content, AI prompts, uploaded documents, chat messages, or other non-payment channels.

6.3.9 Payment processor compliance. RFPBench will use commercially reasonable efforts to select payment processors that maintain payment-card security controls appropriate to their role, which should include PCI DSS validation for payment-card processing and, for material billing providers where available, SOC 2 Type II or comparable independent assurance. RFPBench may rely on the payment processor’s hosted checkout, billing portal, tokenization, invoices, receipts, and payment-method vaulting to reduce RFPBench’s exposure to payment-card data.

6.3.10 Payment processor terms. Payment processing may be subject to the processor’s own terms, privacy policy, card-network rules, fraud-prevention rules, and payment-method requirements. RFPBench is not responsible for acts or omissions of payment processors except to the extent required by applicable law or these Terms.

6.4 Renewal, cancellation, and refunds

6.4.1 Automatic renewal. Unless cancelled before renewal, paid subscriptions renew automatically for successive terms equal to the expiring Subscription Term or as stated in the Order.

6.4.2 Cancellation. Customer may cancel through the account settings, billing portal, or by contacting RFPBench at the cancellation contact provided in the Service. Cancellation takes effect at the end of the then-current Subscription Term unless the account page or applicable law states otherwise.

6.4.3 No refunds. Fees are non-refundable and non-creditable except as required by law or expressly stated in the Order. If Customer cancels during a Subscription Term, Customer remains responsible for fees through the end of that term.

6.4.4 Price changes. RFPBench may change prices for future renewal terms by providing notice before the new price takes effect. If Customer does not agree to the price change, Customer may cancel before renewal.

6.4.5 Downgrades. Downgrading may result in loss of features, capacity, content, settings, or functionality. Customer is responsible for exporting or preserving Customer Content before downgrading.

7. Customer Content and Customer Data

7.1 Ownership. As between Customer and RFPBench, Customer retains all rights in Customer Content. These Terms do not transfer ownership of Customer Content to RFPBench.

7.2 License to operate the Service. Customer grants RFPBench a worldwide, non-exclusive, royalty-free license to host, copy, process, transmit, display, perform, index, parse, analyze, transform, back up, restore, and otherwise use Customer Content as necessary to provide, secure, maintain, support, troubleshoot, improve, and develop the Service, enforce these Terms, and comply with law.

7.3 Customer responsibility. Customer is solely responsible for Customer Content, including its accuracy, legality, confidentiality, quality, permissions, consents, intellectual-property rights, procurement sensitivity, export-control status, privacy compliance, and suitability for use in the Service.

7.4 No prohibited sensitive content unless authorized. Customer must not upload highly sensitive, regulated, or restricted information unless Customer has confirmed that the Service, Plan, and applicable contractual terms support such information and Customer has all required legal authority. Examples include protected health information, payment card data, classified information, government secrets, biometric identifiers, children’s data, precise location data, special categories of personal data, social insurance numbers, social security numbers, passport numbers, tax identifiers, criminal-record information, or export-controlled technical data.

7.5 RFP and proposal confidentiality. Customer acknowledges that RFPs, pricing, proposals, vendor submissions, security questionnaires, policy documents, compliance evidence, product roadmaps, and similar materials may be confidential or competitively sensitive. Customer is responsible for configuring permissions and sharing only with authorized parties.

7.6 Backups are not archives. RFPBench may maintain backups for resilience and disaster recovery, but the Service is not a legal records archive unless an Order expressly says so. Customer is responsible for retaining required procurement records, proposal records, source materials, and approval evidence outside the Service if required by law, policy, or contract.

7.7 Content review. RFPBench does not undertake to review Customer Content for legality, accuracy, confidentiality, privilege, privilege waiver, trade-secret status, intellectual-property infringement, export controls, public-records obligations, or procurement compliance.

7.8 Content removal. RFPBench may remove, quarantine, restrict, or disable access to Customer Content if RFPBench reasonably believes it violates these Terms, creates security risk, infringes rights, violates law, or could expose RFPBench, Customers, Users, or third parties to liability.

7.9 Aggregated and de-identified data. RFPBench may create and use aggregated, anonymized, or de-identified data derived from use of the Service for analytics, benchmarking, security, product improvement, research, and business purposes, provided such data does not identify Customer or any individual and is not reasonably capable of being re-identified by RFPBench.

8. Buyer, Responder, and Invitation Workflows

8.1 Buyer responsibilities

8.1.1 Buyer-controlled process. If Customer uses the Service to issue or evaluate RFPs, Customer remains responsible for the design, fairness, legality, documentation, scoring, award decisions, communications, conflicts management, confidentiality, and records retention of its procurement process.

8.1.2 No procurement decision by RFPBench. RFPBench does not select vendors, make award decisions, determine responsiveness, determine compliance, decide conflicts of interest, or validate bid integrity.

8.1.3 Evaluation support. Any comparison, scoring, summary, table, ranking, confidence indicator, or suggested evaluation generated by the Service is informational workflow support only and must be reviewed by qualified Customer personnel.

8.2 Responder responsibilities

8.2.1 Responder-controlled submissions. If Customer uses the Service to respond to RFPs, questionnaires, RFIs, or security reviews, Customer remains responsible for final answers, certifications, representations, attachments, pricing, promises, compliance statements, and submissions.

8.2.2 No guarantee of award. RFPBench does not guarantee that Customer will be shortlisted, selected, awarded, deemed compliant, deemed responsive, or evaluated favorably.

8.2.3 Source verification. Customer must verify that any reused answer, AI Output, source citation, policy reference, security claim, certification reference, legal statement, or compliance claim remains current, accurate, approved, and authorized for the relevant recipient.

8.3 Invitations and external parties

8.3.1 Invitations. Customer may invite external parties to participate in workflows if the Plan allows it. Customer is responsible for ensuring that invitations are sent to the correct recipients and that sharing Customer Content with such recipients is lawful and authorized.

8.3.2 External user obligations. External invitees may be required to create accounts and accept applicable terms. Customer is responsible for its relationship with external parties and for procurement, confidentiality, and submission rules applicable to those parties.

8.3.3 Misaddressed invitations. Customer is responsible for promptly revoking or correcting misdirected invitations or access permissions. RFPBench is not responsible for disclosures caused by Customer’s configuration, invitations, or sharing decisions.

9. AI-Assisted Features

9.1 AI assistance only. AI-Assisted Features are designed to assist with drafting, retrieval, summarization, comparison, organization, classification, confidence indicators, and review workflows. They are not a substitute for human review, legal advice, procurement judgment, compliance review, security review, or professional advice.

9.2 Human review required. Customer must review AI Output before using, submitting, publishing, relying on, or sharing it. Customer is solely responsible for final content, submissions, decisions, approvals, certifications, and external communications.

9.3 Accuracy limitations. AI Output may be inaccurate, incomplete, outdated, biased, duplicative, non-unique, non-compliant, or unsuitable. AI Output may incorrectly summarize documents, omit material facts, misstate sources, or generate unsupported text. Customer must verify all AI Output against authoritative source materials and applicable requirements.

9.4 Sources and confidence indicators. The Service may display sources, citations, linked passages, confidence scores, similarity matches, or other indicators. These are aids only and do not guarantee correctness, completeness, legal sufficiency, or contractual compliance.

9.5 Model providers. RFPBench may use internal models, hosted models, third-party AI providers, retrieval systems, embeddings, indexing systems, or document-processing providers to deliver AI-Assisted Features. Such providers may be listed as subprocessors where required by Data Processing Terms.

9.6 No public model training unless authorized. Unless an Order, product setting, or separate written agreement says otherwise, RFPBench will not use Customer Content to train public foundation models and will require third-party AI providers not to use Customer Content to train their general models.

9.7 Customer AI compliance. Customer is responsible for using AI-Assisted Features in compliance with applicable AI, procurement, employment, privacy, anti-discrimination, sectoral, records, and professional-responsibility laws. Customer must not use the Service as a high-risk or regulated AI system without confirming that the use is supported by appropriate terms and controls.

9.8 Similar output. Due to the nature of AI and common source materials, AI Output may be similar or identical for different customers or users. Customer obtains no exclusive rights in generic AI Output that does not incorporate Customer Content.

9.9 Prompt injection and malicious content. Customer must not intentionally submit prompts, files, or instructions designed to bypass security, reveal system prompts, extract confidential information, override safeguards, or cause unauthorized behavior.

9.10 Additional AI terms. Schedule 2 contains additional AI-Assisted Features Terms and forms part of these Terms.

10. Customer Responsibilities and Compliance

10.1 General compliance. Customer will comply with all laws, regulations, contracts, policies, procurement rules, privacy laws, AI laws, trade controls, anti-corruption laws, competition laws, sanctions, and third-party rights applicable to Customer’s use of the Service.

10.2 Procurement integrity. Customer must not use the Service to engage in bid rigging, collusive tendering, price fixing, unlawful information sharing, bribery, kickbacks, conflicts concealment, retaliation, discrimination, false certifications, procurement fraud, vendor manipulation, or other unlawful procurement conduct.

10.3 Anti-corruption. Customer must not use the Service to offer, promise, solicit, authorize, conceal, or facilitate bribes, kickbacks, improper benefits, gifts, entertainment, political contributions, or other improper inducements.

10.4 Competition and antitrust. Customer must not use the Service to exchange competitively sensitive information with competitors or coordinate bids, pricing, territories, customers, output, wages, market allocation, or other conduct prohibited by competition or antitrust laws.

10.5 Privacy and permissions. Customer is responsible for providing legally required notices, obtaining consents, establishing lawful bases, honoring rights, and ensuring that it may upload, process, disclose, and transfer personal information through the Service.

10.6 Records and public-sector obligations. If Customer is a public-sector entity or subject to public procurement, freedom-of-information, access-to-information, open-records, retention, accessibility, localization, or audit rules, Customer is responsible for determining whether the Self-Serve Service is appropriate and for complying with those rules.

10.7 No regulated environment without agreement. Customer must not use the Self-Serve Service in a manner that requires RFPBench to comply with special regulatory frameworks, such as HIPAA, PCI DSS cardholder data obligations, CJIS, classified-government requirements, ITAR-controlled hosting, or equivalent regimes, unless RFPBench has expressly agreed in writing.

10.8 Export controls. Customer must not upload export-controlled technical data or use the Service in violation of export-control or sanctions laws. Customer represents that it and its Users are not located in, organized under the laws of, or ordinarily resident in sanctioned jurisdictions and are not restricted parties under applicable sanctions laws.

10.9 Cooperation. Customer will reasonably cooperate with RFPBench in investigating security incidents, abuse, legal requests, payment disputes, and suspected violations of these Terms.

10.10 Payment data handling. Customer must use only the designated checkout, billing portal, invoice payment link, marketplace checkout, or other approved payment flow to submit payment information. Customer must not include payment-card data or payment authentication data in Customer Content, RFP responses, uploaded files, comments, messages, AI Inputs, support requests, contact forms, or other Service areas not designed for payment processing.

11. Acceptable Use

11.1 AUP incorporated. Customer and Users must comply with the Acceptable Use Policy (AUP) in Schedule 1. RFPBench may update the Acceptable Use Policy to address new security, legal, abuse, or product risks, provided updates do not materially reduce Customer’s rights during a paid Subscription Term without notice.

11.2 Prohibited conduct. Without limiting Schedule 1, Customer must not:

  • access or use the Service unlawfully or for fraudulent purposes;
  • interfere with or disrupt the Service;
  • attempt to gain unauthorized access to systems, accounts, data, or networks;
  • reverse engineer, decompile, copy, frame, scrape, or benchmark the Service except where allowed by law;
  • upload malware or harmful code;
  • violate third-party rights;
  • use the Service to send spam or unsolicited communications;
  • circumvent usage limits or security controls;
  • use the Service to develop a competing product using non-public features or data; or
  • misrepresent AI Output, source materials, or procurement results.

11.3 Enforcement. RFPBench may investigate suspected violations and may remove content, throttle usage, suspend accounts, block traffic, disable integrations, or terminate access as reasonably necessary to protect the Service, customers, users, RFPBench, or third parties.

12. Security and Account Protection

12.1 RFPBench safeguards. RFPBench will implement and maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, disclosure, alteration, and destruction, taking into account the nature of the Self-Serve Service, the sensitivity of Customer Data, and the risks of processing.

12.2 Customer safeguards. Customer is responsible for secure configuration of its Account, including strong passwords, multi-factor authentication where available, single sign-on settings, role-based access, invite management, access reviews, exports, and removal of Users who no longer need access.

12.3 Shared responsibility. Security of the Service depends on both RFPBench and Customer. RFPBench is responsible for the Service infrastructure it controls. Customer is responsible for Customer Content, User access, endpoint security, identity provider configuration, local downloads, exports, integrations, and downstream sharing.

12.4 Security incidents. Customer must promptly notify RFPBench of suspected unauthorized access, credential compromise, misuse, or security vulnerabilities. RFPBench will assess and respond to security incidents in accordance with its incident-response procedures and applicable legal or contractual obligations.

12.5 Vulnerability testing. Customer must not conduct penetration testing, vulnerability scanning, load testing, or security assessments of the Service without prior written authorization from RFPBench. RFPBench may provide a responsible disclosure process.

12.6 Security documentation. RFPBench may provide security summaries, questionnaires, reports, or documentation at its discretion or as available for the applicable Plan. Self-Serve Plans do not include custom security audits, onsite audits, or custom control mapping unless separately agreed.

13. Privacy, Data Protection, and Cloud Infrastructure

13.1 Privacy Policy. RFPBench’s Privacy Policy explains how RFPBench collects, uses, discloses, and protects personal information. The Privacy Policy is incorporated by reference but does not override negotiated Data Processing Terms for Customer Data.

13.2 Data Processing Terms. Schedule 5 applies where RFPBench processes Personal Data on behalf of Customer as a processor, service provider, or similar role under applicable privacy law. If Customer requires a separate signed Data Processing Agreement, Customer must contact RFPBench before using the Service for regulated Personal Data.

13.3 Customer instructions. Customer instructs RFPBench to process Customer Data as necessary to provide, secure, support, troubleshoot, maintain, improve, and develop the Service; comply with Customer’s use of features and settings; comply with law; and perform activities described in these Terms and the Data Processing Terms.

13.4 Cloud providers. Customer acknowledges that the Service may use AWS, Google Cloud Platform, or other cloud infrastructure providers for hosting, compute, storage, networking, backup, logging, monitoring, security, and related infrastructure. RFPBench may change such providers or regions subject to applicable contractual commitments.

13.5 Data location. Unless an Order expressly states a data residency commitment, RFPBench does not guarantee that Customer Data will be stored or processed only in a particular country, province, state, or region. Cross-border transfers may occur as described in the Privacy Policy and Data Processing Terms.

13.6 Subprocessors. RFPBench may use subprocessors to provide the Service, including cloud infrastructure, AI, document processing, logging, monitoring, customer support, email, authentication, analytics, and payment providers.

13.7 Customer privacy compliance. Customer is responsible for determining whether the Service is appropriate for Customer’s data, use case, industry, and jurisdiction, and for providing notices, obtaining consents, honoring rights, maintaining legal bases, and complying with applicable privacy laws.

13.8 Data deletion and return. Data deletion, return, export, and retention are addressed in Section 23 and Schedule 5. Customer should export Customer Content before termination, downgrade, or deletion.

13.9 Billing and payment data. Billing and payment information may be processed by RFPBench and by third-party payment, subscription-management, tax, and billing providers. Such providers may act as independent controllers, processors, service providers, subprocessors, or similar roles depending on the processing activity and applicable law. The Privacy Policy provides additional information about payment-related personal information.

14. Third-Party Services and Integrations

14.1 Third-party services. The Service may integrate with or rely on third-party services, such as cloud hosting, identity providers, document storage, email, calendar, collaboration tools, CRM systems, payment processors, analytics, monitoring, AI providers, and customer systems.

14.2 Customer-enabled integrations. If Customer enables an integration, Customer authorizes RFPBench to exchange data with the third-party service as necessary to provide the integration. Customer is responsible for the third-party account, permissions, data flows, and compliance.

14.3 Third-party terms. Third-party services are governed by their own terms and privacy policies. RFPBench is not responsible for third-party services that are not controlled by RFPBench, including outages, data practices, support, errors, or changes to third-party APIs.

14.4 Marketplace or app stores. If Customer obtains the Service through a marketplace or reseller, marketplace terms may apply to billing, cancellation, taxes, support, and procurement. These Terms continue to govern use of the Service unless a signed agreement states otherwise.

14.5 Payment processors. RFPBench may use payment processors, billing platforms, tax providers, and subscription-management providers to process fees, manage subscriptions, issue invoices and receipts, calculate or collect taxes, handle payment disputes and chargebacks, maintain payment-method tokens, and operate billing portals. Customer authorizes RFPBench to share information with those providers as necessary for these purposes.

14.6 Payment processor changes. RFPBench may replace or add payment, billing, subscription-management, or tax providers from time to time. RFPBench will use commercially reasonable efforts to select providers with security and compliance measures appropriate for their role. Changes to payment processors do not require amendment of these Terms, but may require Customer to re-enter payment information or accept updated payment-provider terms.

15. Support, Maintenance, and Availability

15.1 Support. RFPBench will provide self-serve support resources and standard support for paid Plans as described in the Plan or Schedule 3. Free Plans and trials may receive limited or no individualized support.

15.2 Maintenance. RFPBench may perform scheduled or emergency maintenance. RFPBench will use commercially reasonable efforts to minimize disruption, but maintenance may affect availability or functionality.

15.3 Availability. Availability commitments, service credits, and remedies apply only if expressly stated in an Order or Schedule 3. Unless otherwise stated, service credits are Customer’s sole remedy for failure to meet an applicable availability commitment.

15.4 No mission-critical guarantee. The Self-Serve Service is not designed for emergency, life-safety, mission-critical, or real-time decision-making uses. Customer should maintain independent copies and contingency processes for time-sensitive RFP, procurement, proposal, legal, compliance, or business deadlines.

15.5 Support limitations. RFPBench is not required to provide support for issues caused by Customer systems, third-party services, unsupported browsers, misuse, unauthorized modifications, internet connectivity, identity provider issues, local downloads, or Customer’s failure to follow Documentation.

16. Beta, Preview, and Early Access Features

16.1 Beta features. RFPBench may offer beta, preview, experimental, alpha, early access, pilot, or evaluation features. Such features may be incomplete, unstable, unsupported, changed, withdrawn, or subject to additional terms.

16.2 Use at Customer’s risk. Beta features are provided for evaluation and feedback and should not be used for production, time-sensitive, or legally sensitive workflows unless RFPBench expressly authorizes such use in writing.

16.3 Feedback. Customer may provide feedback regarding beta features. RFPBench may use feedback without restriction or obligation, provided RFPBench does not disclose Customer Confidential Information except as permitted by these Terms.

16.4 No obligation to release. RFPBench has no obligation to make beta features generally available or to preserve compatibility, data, settings, or functionality from beta features.

16.5 Additional terms. Schedule 6 contains additional Beta and Early Access Terms.

17. Intellectual Property

17.1 RFPBench ownership. RFPBench and its licensors retain all rights, title, and interest in and to the Service, software, technology, APIs, models, prompts, system prompts, workflows, user interfaces, algorithms, search and retrieval methods, scoring methods, documentation, templates provided by RFPBench, improvements, derivative works, and related intellectual property.

17.2 License to use the Service. During the Subscription Term, RFPBench grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right to access and use the Service for Customer’s internal business purposes in accordance with these Terms, the Order, and Documentation.

17.3 Restrictions. Customer must not copy, modify, distribute, sell, lease, sublicense, create derivative works from, reverse engineer, decompile, disassemble, or attempt to extract source code, models, system prompts, or non-public algorithms from the Service, except to the extent such restriction is prohibited by law.

17.4 Feedback. Customer grants RFPBench a perpetual, irrevocable, worldwide, royalty-free license to use feedback, suggestions, ideas, requests, bug reports, and recommendations for any purpose without obligation to Customer.

17.5 Customer materials. Customer retains ownership of Customer Content and Customer’s pre-existing materials. RFPBench receives only the rights necessary to provide and improve the Service as described in these Terms.

17.6 Open-source software. The Service may include or interact with open-source software. Open-source components are licensed under their applicable open-source licenses, not these Terms, to the extent required by those licenses.

17.7 Trademarks. Customer may not use RFPBench’s names, logos, trademarks, or branding without prior written permission, except to identify RFPBench as a service provider in internal records.

18. Confidentiality

18.1 Confidential Information. “Confidential Information” means non-public information disclosed by one party to the other that is marked confidential or should reasonably be understood to be confidential given its nature and circumstances, including Customer Content, security information, business plans, pricing, product roadmaps, technical information, and non-public Service information.

18.2 Exclusions. Confidential Information does not include information that the receiving party can show: (a) is or becomes public without breach; (b) was known without confidentiality obligation before disclosure; (c) is received from a third party without confidentiality obligation; or (d) is independently developed without use of Confidential Information.

18.3 Protection and use. The receiving party will use the same degree of care it uses to protect its own similar confidential information, but not less than reasonable care, and will use Confidential Information only to perform under these Terms or as permitted by law.

18.4 Disclosure. The receiving party may disclose Confidential Information to its employees, contractors, advisors, affiliates, and service providers who need to know and are bound by confidentiality obligations. The receiving party may also disclose Confidential Information if required by law, provided it gives notice where legally permitted.

18.5 Injunctive relief. Unauthorized disclosure of Confidential Information may cause irreparable harm for which monetary damages are inadequate. The disclosing party may seek injunctive or equitable relief without posting bond where permitted by law.

19. Publicity and References

19.1 No logo use without consent. RFPBench will not publicly use Customer’s name, logo, or trademarks in marketing materials without Customer’s prior consent, except that RFPBench may identify Customer as necessary in private investor, advisor, or due-diligence materials subject to confidentiality obligations.

19.2 Case studies. Any public case study, testimonial, press release, or reference quote requires Customer’s prior written approval.

19.3 Feedback attribution. RFPBench may use anonymized or aggregated feedback in marketing or product materials if it does not identify Customer or reveal Customer Confidential Information.

20. Warranties and Disclaimers

20.1 Mutual authority. Each party represents that it has authority to enter into these Terms and perform its obligations.

20.2 Service disclaimer. Except as expressly stated in these Terms or an Order, the Service, AI-Assisted Features, beta features, support, documentation, and all outputs are provided “as is” and “as available.” To the maximum extent permitted by law, RFPBench disclaims all warranties, conditions, and representations, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, non-infringement, accuracy, availability, uninterrupted operation, security, error-free operation, and results.

20.3 No professional advice. The Service does not provide legal, procurement, compliance, security, accounting, tax, financial, engineering, medical, public-sector, or professional advice. Customer should consult qualified professionals before relying on outputs or making decisions.

20.4 No guarantee of outcome. RFPBench does not guarantee successful RFP issuance, successful response submission, compliance, award, shortlist, evaluation outcome, security certification, legal sufficiency, procurement fairness, vendor performance, or commercial result.

20.5 Internet and third-party risks. RFPBench is not responsible for delays, failures, outages, data loss, or security incidents caused by Customer systems, third-party services, internet connectivity, force majeure events, or circumstances outside RFPBench’s reasonable control.

20.6 Non-excludable rights. Some jurisdictions do not allow exclusion of certain warranties or conditions. In those jurisdictions, exclusions apply only to the maximum extent permitted by law.

21. Indemnification

21.1 Customer indemnity

Customer will defend, indemnify, and hold harmless RFPBench, its affiliates, officers, directors, employees, contractors, and agents from and against claims, damages, liabilities, losses, costs, and expenses, including reasonable legal fees, arising out of or relating to:

  • Customer Content;
  • Customer’s or Users’ use of the Service in violation of these Terms;
  • Customer’s procurement, RFP, proposal, evaluation, submission, or vendor-management process;
  • Customer’s violation of law, regulation, third-party rights, privacy obligations, procurement obligations, competition laws, anti-corruption laws, or sanctions laws;
  • Customer’s configuration, sharing, invitations, exports, or integrations; or
  • Customer’s final submissions, certifications, representations, or reliance on AI Output.

21.2 RFPBench IP indemnity

For paid subscriptions, RFPBench will defend Customer against a third-party claim that the unmodified Service, as provided by RFPBench and used in accordance with these Terms, directly infringes that third party’s patent, copyright, or trademark, and will pay damages finally awarded or settlements approved by RFPBench.

21.2.1 Exclusions. RFPBench has no obligation for claims arising from Customer Content, Customer instructions, third-party services, combinations not provided by RFPBench, modifications not made by RFPBench, continued use after notice, beta features, free Plans, trials, or use outside these Terms.

21.2.2 Remedies. If the Service is or may be subject to an infringement claim, RFPBench may procure continued use, modify the Service, replace the Service, or terminate affected access and provide a prorated refund of prepaid unused fees for the affected Service. This Section states Customer’s exclusive remedy for infringement claims.

21.3 Indemnity procedures

The indemnified party must promptly notify the indemnifying party of the claim, provide reasonable cooperation, and allow the indemnifying party to control defense and settlement. The indemnifying party may not settle a claim in a way that admits fault by the indemnified party or imposes non-monetary obligations without consent, not to be unreasonably withheld.

22. Limitation of Liability

22.1 Exclusion of damages. To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, exemplary, punitive, enhanced, or lost profits damages; loss of revenue; loss of goodwill; loss of business opportunity; business interruption; loss or corruption of data; procurement delays; missed deadlines; failed bids; failed awards; substitute services; or reputational harm, even if advised of the possibility of such damages.

22.2 Liability cap. To the maximum extent permitted by law, each party’s aggregate liability arising out of or relating to these Terms or the Service will not exceed the amounts paid by Customer to RFPBench for the Service during the 12 months before the event giving rise to liability. For free Plans, trials, or beta features, RFPBench’s aggregate liability will not exceed the minimum amount required by law.

22.3 Cap exclusions. The liability cap does not apply to Customer’s payment obligations, Customer’s indemnification obligations, Customer’s misuse of the Service, Customer’s violation of RFPBench intellectual-property rights, or either party’s liability that cannot legally be limited. Liability for confidentiality breaches, data-security incidents, or privacy violations may be subject to a separate negotiated cap only if expressly stated in a signed agreement.

22.4 Basis of bargain. The limitations in this Section are fundamental to the pricing and availability of the Self-Serve Service and apply regardless of the legal theory, including contract, tort, negligence, strict liability, statute, or otherwise.

22.5 Jurisdictional limitations. Some jurisdictions do not allow certain limitations of liability. In those jurisdictions, the limitations apply to the maximum extent permitted by law.

23. Suspension, Term, and Termination

23.1 Term

These Terms begin when Customer first accepts them and continue until all subscriptions expire or are terminated and Customer stops using the Service.

23.2 Suspension

RFPBench may suspend or restrict access to the Service, in whole or in part, if RFPBench reasonably believes:

  • Customer or a User violated these Terms or the Acceptable Use Policy;
  • continued access creates a security, legal, operational, or reputational risk;
  • payment is overdue;
  • Customer is using the Service beyond Plan limits;
  • RFPBench is required to do so by law, court order, regulator, cloud provider, or third-party service provider;
  • Customer’s use may infringe third-party rights; or
  • Customer’s account, credentials, integrations, or content appear compromised.

RFPBench will use reasonable efforts to provide prior notice of suspension when practical, but may suspend immediately where necessary to protect the Service, customers, users, or third parties.

23.3 Termination by Customer

Customer may terminate by cancelling the subscription through the account settings, billing portal, or cancellation contact. Termination or cancellation does not relieve Customer of fees incurred before the effective termination date.

23.4 Termination by RFPBench

RFPBench may terminate Customer’s access if Customer materially breaches these Terms and fails to cure within 15 days after notice, if Customer repeatedly violates these Terms, if payment remains overdue, if RFPBench discontinues the Service, or if continued provision would create legal, security, or operational risk.

23.5 Effect of termination

Upon termination or expiration, Customer’s right to access the Service ends. Customer must stop using the Service and delete or return any RFPBench Confidential Information in its possession, except as required by law or retained in ordinary-course backups.

23.6 Export and deletion

Customer should export Customer Content before termination. Unless the account interface, Order, or Data Processing Terms state otherwise, RFPBench may keep Customer Content available on the platform for up to 90 days after termination for paid Plans, after which RFPBench may delete Customer Content. This allows Customer to re-subscribe to the service without losing their old work. Backup copies may remain for a limited period and will be overwritten or deleted according to RFPBench’s backup cycles.

Payment, invoice, receipt, tax, subscription, chargeback, and related commercial records may be retained by RFPBench and/or its payment, billing, subscription-management, and tax providers as required or permitted by law, accounting rules, tax obligations, fraud-prevention requirements, chargeback rules, audit requirements, and legitimate business needs, even after Customer Content is deleted.

23.7 Survival

Sections that by their nature should survive termination will survive, including payment obligations, Customer Content responsibility, confidentiality, intellectual property, disclaimers, indemnification, limitation of liability, governing law, and general provisions.

24. Changes to the Service and Terms

24.1 Service changes. RFPBench may modify, enhance, discontinue, or remove Service features from time to time. RFPBench will use reasonable efforts not to materially reduce core paid functionality during a Subscription Term without notice, but the Self-Serve Service remains a cloud service that evolves over time.

24.2 Terms changes. RFPBench may update these Terms from time to time. Material changes will be communicated by posting notice, updating the effective date, emailing account administrators, or presenting updated terms in the Service. Changes apply to new subscriptions immediately and to existing paid subscriptions at renewal or after the notice period stated by RFPBench, unless immediate changes are required by law, security, or abuse-prevention needs.

24.3 Continued use. Continued use of the Service after updated Terms take effect constitutes acceptance of the updated Terms. If Customer does not agree, Customer must stop using the Service and cancel before renewal.

24.4 Product-specific terms. RFPBench may add product-specific terms for new features, integrations, AI capabilities, data regions, beta programs, or regulated use cases. Customer must accept such terms before using the applicable feature if required.

25. Notices

25.1 Notices to Customer. RFPBench may provide notices by email to account contacts, in-product notices, postings on the website, account dashboard messages, or other reasonable means. Customer is responsible for keeping contact information current.

25.2 Notices to RFPBench. Customer may provide legal notices to RFPBench at [email protected], unless a different notice address is specified in an Order or on the RFPBench website.

25.3 Security notices. Security notices should be sent to [email protected]. Privacy notices should be sent to [email protected].

25.4 Effective date of notices. Email notices are deemed given when an automated email receipt is received by Customer. If no automated email receipt is received, contact us on the form on our website RFPbench.com and report the issue.

26. Governing Law and Disputes

26.1 Governing law. These Terms are governed by the laws of [British Columbia] and the federal laws of [Canada] applicable therein, without regard to conflict-of-laws rules. Confirm governing law and venue with counsel before publication.

26.2 Venue. Subject to any mandatory law, the parties submit to the exclusive jurisdiction of the courts located in [Vancouver, British Columbia, Canada] for disputes arising out of or relating to these Terms or the Service.

26.3 Informal resolution. Before commencing formal proceedings, the parties will use reasonable efforts to resolve disputes through good-faith discussions between business representatives, except for urgent injunctive relief, payment collection, confidentiality breaches, security incidents, or intellectual-property misuse.

26.4 Equitable relief. Either party may seek injunctive or equitable relief in any court of competent jurisdiction to prevent misuse of intellectual property, unauthorized access, confidentiality breaches, or security threats.

26.5 Class and representative actions. To the extent permitted by law, disputes must be brought on an individual basis and not as a class, collective, consolidated, or representative action. This clause should be reviewed by counsel for enforceability in all target jurisdictions before publication.

26.6 Public-sector customers. If Customer is a public-sector entity and mandatory law prohibits certain governing law, venue, indemnity, audit, or limitation clauses, the parties may need a separate written agreement. The Self-Serve Service may not be appropriate for public-sector procurements requiring non-standard terms.

27. General Provisions

27.1 Assignment. Customer may not assign these Terms without RFPBench’s prior written consent, except to a successor in connection with a merger, acquisition, reorganization, or sale of substantially all assets, provided the successor is not a competitor of RFPBench and assumes all obligations. RFPBench may assign these Terms to an affiliate or successor.

27.2 Subcontractors. RFPBench may use subcontractors and service providers to perform under these Terms. RFPBench remains responsible for their performance as required by these Terms.

27.3 Force majeure. Neither party is liable for delay or failure to perform caused by events beyond reasonable control, including acts of God, natural disasters, war, terrorism, civil unrest, labor disputes, internet or telecommunications failures, cloud provider outages, cyberattacks, government actions, epidemics, or power failures. Payment obligations are not excused.

27.4 Severability. If any provision is held invalid or unenforceable, the remaining provisions remain in effect and the invalid provision will be modified to the minimum extent necessary to make it enforceable.

27.5 Waiver. Failure to enforce a provision is not a waiver. Waivers must be in writing and signed by the waiving party.

27.6 No agency. The parties are independent contractors. These Terms do not create a partnership, joint venture, employment, fiduciary, franchise, or agency relationship.

27.7 No third-party beneficiaries. These Terms do not create rights for third parties except as expressly stated.

27.8 Entire agreement. These Terms constitute the entire agreement between Customer and RFPBench for the Self-Serve Service and supersede prior or contemporaneous understandings about the Self-Serve Service, unless a signed agreement states otherwise.

27.9 Language. The parties agree that these Terms and related documents may be drafted in English. If a translation is provided, the English version controls unless applicable law requires otherwise.

27.10 Headings. Headings are for convenience only and do not affect interpretation.

28. Contact Information

Legal entity: Sama Ventures Inc.

Business name: RFPBench

Legal notices: [email protected]]

Privacy notices: [email protected]

Security notices: [email protected]

Support: [email protected]

Cancellation/billing: [email protected]

Schedule 1 - Acceptable Use Policy

This Acceptable Use Policy applies to all Customers and Users of the Self-Serve Service. Capitalized terms have the meanings given in the Terms.

1. Lawful use

Customer must use the Service only for lawful business purposes and in compliance with all applicable laws, regulations, contractual obligations, procurement rules, and third-party rights.

2. Security abuse

Customer must not:

  • attempt unauthorized access to accounts, systems, networks, data, models, prompts, or infrastructure;
  • test, scan, probe, or benchmark the Service without written authorization;
  • interfere with, degrade, overload, or disrupt the Service;
  • bypass access controls, rate limits, usage limits, billing controls, authentication, authorization, or security controls;
  • upload malware, ransomware, spyware, worms, destructive code, or exploit payloads;
  • use the Service for phishing, credential harvesting, social engineering, impersonation, or account takeover;
  • attempt to extract system prompts, model weights, source code, non-public APIs, or confidential information;
  • use bots, scrapers, crawlers, or automated tools except as expressly allowed by Documentation; or
  • use the Service to mine cryptocurrency or perform compute-intensive activity unrelated to normal RFP workflows.

3. Content abuse

Customer must not upload or process content that:

  • is unlawful, fraudulent, defamatory, harassing, abusive, threatening, or deceptive;
  • infringes intellectual-property, privacy, publicity, confidentiality, trade-secret, or contractual rights;
  • contains regulated sensitive information not supported by the applicable Plan and written terms;
  • contains full payment-card numbers, card security codes, bank account credentials, payment authentication data, or other payment information submitted outside the designated payment flow;
  • contains malware or intentionally hidden malicious instructions;
  • facilitates violence, terrorism, trafficking, exploitation, illegal weapons, or child sexual abuse material;
  • facilitates illegal discrimination, hate, or harassment;
  • creates unauthorized surveillance or privacy violations;
  • misrepresents vendor capabilities, certifications, compliance posture, source materials, or approval status; or
  • violates procurement, anti-corruption, competition, or bid-integrity laws.

4. AI misuse

Customer must not use AI-Assisted Features to:

  • make legally or similarly significant decisions about individuals without appropriate human review and legal basis;
  • generate deceptive, fraudulent, or misleading procurement records;
  • fabricate citations, certifications, audit evidence, compliance proof, legal conclusions, or approval history;
  • evade content filters, rate limits, security controls, or model safeguards;
  • extract confidential information from other customers or the Service;
  • create deepfakes, impersonation content, or deceptive public-interest content without required disclosures;
  • perform high-risk or regulated AI use cases unless supported by appropriate written terms and controls; or
  • violate applicable AI laws, transparency obligations, or AI governance requirements.

5. Enforcement

RFPBench may investigate suspected violations and may suspend, restrict, remove content, disable integrations, throttle traffic, or terminate access as necessary to protect the Service or comply with law. RFPBench may report unlawful activity to authorities where appropriate or required.

Schedule 2 - AI-Assisted Features Terms

This Schedule supplements Section 9 and applies to all AI-Assisted Features.

1. AI Inputs and AI Outputs

AI Input and AI Output are Customer Content to the extent they are submitted by or generated for Customer. Customer is responsible for determining whether AI Input may be submitted to the Service and whether AI Output may be used, stored, submitted, or shared.

2. Human-in-the-loop workflow

Customer must maintain human review and approval for AI Output before external submission. AI Output should be treated as draft material unless and until approved by Customer’s authorized personnel.

3. Source-grounded drafting

The Service may attempt to ground AI Output in Customer’s uploaded source documents, previous answers, policies, templates, or knowledge base. Grounding, citations, source links, confidence indicators, and similar features are aids only. Customer must verify source accuracy and ensure that sources are current, approved, and appropriate for the recipient.

4. AI provider use

RFPBench may use third-party AI providers to provide AI-Assisted Features. RFPBench will use commercially reasonable measures to ensure that such providers process Customer Content only to provide the Service and do not use Customer Content to train their general public models unless Customer authorizes otherwise.

5. Model and feature changes

RFPBench may change models, providers, retrieval methods, prompts, safety systems, embeddings, indexing methods, or AI workflows from time to time. Changes may affect output style, latency, accuracy, cost, limits, or feature behavior.

6. No regulated AI commitment

Unless expressly agreed in writing, RFPBench does not represent that the Self-Serve Service complies with requirements for high-risk AI systems, regulated professional advice, employment decisions, credit decisions, public benefits decisions, medical decisions, legal decisions, law-enforcement decisions, biometric identification, or similar regulated use cases.

7. AI audit trail

Where available, Customer should use review history, approval status, source links, comments, and audit logs to preserve evidence of human review. Customer remains responsible for retention and audit obligations applicable to its RFP process.

8. Restrictions on synthetic data and benchmarking

Customer must not use the Service to generate datasets, benchmarks, model evaluations, or training corpora for competing services without RFPBench’s prior written consent.

Schedule 3 - Support and Availability Policy

This Schedule describes standard self-serve support and availability expectations. It does not create a custom SLA unless an Order expressly says so.

1. Support channels

RFPBench may provide support through documentation, help center articles, email, ticketing, chat, in-product support, community resources, or other channels. Available channels vary by Plan.

2. Severity levels

Support will be triaged based on the severity of the incident. RFPBench will decide the severity of incidents solely based on its judgment.

SeverityDescription
Severity 1Production Service unavailable for most paid users, with no reasonable workaround.
Severity 2Major feature unavailable or materially degraded for Customer, with limited workaround.
Severity 3Non-critical issue, question, configuration help, or minor defect.
Severity 4How-to questions, feature requests, feedback, or documentation issues.

3. Availability objective

RFPBench may publish an availability objective for paid self-serve Plans, such as 99.5% monthly uptime excluding scheduled maintenance, emergency maintenance, beta features, third-party outages, Customer-caused issues, internet failures, force majeure, and events outside RFPBench’s reasonable control. These are aspirational objectives and not a commitment by RFPBench to Customer.

4. Service credits

No service credits apply unless expressly included in an Order or published SLA. If service credits are offered, they are Customer’s sole and exclusive remedy for failure to meet the stated availability commitment.

5. Maintenance

RFPBench may perform scheduled and emergency maintenance. RFPBench will use reasonable efforts to provide advance notice of scheduled maintenance where practical.

6. Exclusions

Support and availability commitments do not apply to issues caused by Customer systems, unsupported browsers, third-party services, identity providers, integrations, misuse, prohibited testing, force majeure, beta features, free Plans, trials, or events outside RFPBench’s reasonable control.

Schedule 4 - Security and Data Protection Overview

This Schedule will summarize expected safeguards for the Self-Serve Service. It will be finalized after RFPBench confirms production architecture, cloud provider, regions, identity controls, logging, encryption, backup design, incident response, and vendor list.

Schedule 5 - Self-Serve Data Processing Terms

These Data Processing Terms apply where RFPBench processes Personal Data on behalf of Customer in connection with the Self-Serve Service. They are designed as baseline self-serve terms and may need replacement with a formal Data Processing Agreement for enterprise or regulated customers.

1. Roles

For Customer Content containing Personal Data that Customer submits to the Service, Customer is the controller, business, organization, or equivalent responsible party, and RFPBench is the processor, service provider, or equivalent service provider, unless applicable law or a specific processing activity requires a different classification.

2. Processing instructions

Customer instructs RFPBench to process Personal Data to provide, secure, maintain, support, troubleshoot, monitor, improve, and develop the Service; comply with Customer’s settings and Users’ actions; respond to requests; prevent abuse; comply with law; and perform obligations under the Terms.

3. Categories of data and subjects

Personal Data may include names, business emails, job titles, account identifiers, IP addresses, usage logs, comments, assignments, approvals, document metadata, and any Personal Data included in Customer Content. Data subjects may include Customer personnel, buyer personnel, responder personnel, vendors, prospects, contractors, and other individuals identified in Customer Content.

Personal Data may also include billing contact details, subscription package details, Plan tier, seat count, usage limits, invoice and receipt information, tax information, payment status, renewal and cancellation information, upgrade and downgrade history, and payment-related identifiers or tokens, to the extent processed in connection with the Self-Serve Service.

4. Confidentiality

RFPBench will require personnel authorized to process Personal Data to be subject to confidentiality obligations.

5. Security

RFPBench will maintain commercially reasonable security measures appropriate for the Self-Serve Service and the risk of processing, as summarized in Schedule 4.

6. Subprocessors

Customer authorizes RFPBench to use subprocessors to provide the Service. RFPBench will impose contractual obligations on subprocessors that are materially consistent with these Data Processing Terms. RFPBench may update subprocessors from time to time. Customer may stop using the Service if it objects to a new subprocessor and no commercially reasonable alternative is available.

Subprocessors may include payment processors, billing platforms, subscription-management providers, tax providers, fraud-prevention providers, cloud infrastructure providers, AI providers, document-processing providers, email providers, logging and monitoring providers, customer-support providers, and other providers reasonably necessary to provide and secure the Service.

7. International transfers

RFPBench may transfer Personal Data internationally as necessary to provide the Service. Where required by applicable law, RFPBench will use appropriate transfer mechanisms, such as adequacy decisions, standard contractual clauses, transfer risk assessments, or other lawful safeguards. Customer is responsible for determining whether such transfers are appropriate for Customer’s data and jurisdiction.

8. Data subject requests

To the extent required by law and taking into account the nature of processing, RFPBench will provide reasonable assistance for data subject requests relating to Customer Personal Data. RFPBench may direct individuals and agencies to Customer where Customer controls the relevant Personal Data.

9. Security incidents

RFPBench will notify Customer without undue delay after becoming aware of a confirmed security incident involving Customer Personal Data, as required by applicable law or contract. Notice may be provided to account administrators or designated security contacts. Customer is responsible for regulator and individual notifications where Customer is legally responsible, unless otherwise agreed.

10. Deletion and return

Upon termination, Customer should export Customer Content within the available export period. RFPBench will delete or anonymize Customer Personal Data according to account settings, retention schedules, backup cycles, legal obligations, and the Terms. Backup copies may persist until overwritten or deleted.

11. Audits

For Self-Serve Plans, RFPBench may satisfy audit obligations by providing documentation, security summaries, certifications, or questionnaire responses where available. Onsite audits, custom audits, and third-party audits are not included unless separately agreed in writing.

12. CCPA / CPRA service provider terms

Where applicable, RFPBench will process Personal Information as a service provider or contractor for Customer and will not sell or share such Personal Information, retain, use, or disclose it outside the business purpose of providing the Service, or combine it with other personal information except as permitted by applicable law and these Terms.For clarification, CCPA stands for the California Consumer Privacy Act, and CPRA stands for California Privacy Rights Act.

13. Payment and billing providers

Payment processors and billing providers may process certain Personal Data under their own legal roles and terms, including as independent controllers for payment-card processing, fraud prevention, compliance, tax, accounting, and card-network obligations. RFPBench will use commercially reasonable efforts to select providers that offer privacy and security commitments appropriate to their role.

Schedule 6 - Beta and Early Access Terms

These terms apply to beta, preview, alpha, pilot, evaluation, proof-of-concept, and early access features or programs.

1. Evaluation purpose

Beta features are provided for evaluation, testing, validation, and feedback. They may not be suitable for production or external submissions.

2. No reliance

Customer should not rely on beta features for time-sensitive procurement deadlines, final RFP submissions, legal compliance, security certifications, regulated workflows, or other critical business functions.

3. Data caution

Customer should avoid uploading highly confidential, sensitive, regulated, or production-critical Customer Content into beta features unless RFPBench expressly states that the feature is suitable for that content and Customer accepts the associated risk.

4. Changes and termination

RFPBench may modify, reset, suspend, discontinue, or terminate beta features at any time. Data, settings, outputs, and configurations associated with beta features may not migrate to generally available features.

5. Feedback license

Customer grants RFPBench the right to use beta feedback, bug reports, suggestions, and usage observations to improve the Service without compensation or obligation.

6. Disclaimer

Beta features are provided “as is,” without warranty, support, availability commitments, service credits, indemnity, or liability beyond the minimum required by law.