← Back to Home

MASTER SERVICES AGREEMENT (MSA) & ENTERPRISE AI RISK SHIELD

VERSION: 3.4 (UNILATERAL MODIFICATION, SOLE PROPRIETORSHIP & CLOUD EXCLUSION EDITION)
EFFECTIVE DATE: Upon electronic acceptance, clickwrap confirmation, or initiation of payment
PARTIES:

  1. PROVIDER / AGENCY: Adam Matar, an individual and sole proprietor doing business as (d/b/a) Vibehard (and/or Vibehard) ("Provider", "Agency", "We", "Us", "Adam Matar"). Provider reserves the unilateral right to incorporate or assign this Agreement to a successor corporate entity per Section 1.2.
  2. CLIENT: The purchasing company, entity, or individual executing this Agreement ("Client", "You", "Customer")

1. NATURE OF ENGAGEMENT, MANAGED CONTAINERS & UNILATERAL MODIFICATIONS

  1. Managed Architecture & Deployment: Provider designs, engineers, stages, and deploys custom autonomous AI workflows, private orchestration containers (e.g., self-hosted n8n instances on dedicated VPS environments), and ongoing Site Reliability Engineering (SRE) maintenance as specified in applicable Statements of Work (SOW).
  2. Sole Proprietorship & Entity Reorganization: Client expressly acknowledges that Provider is currently operated as a sole proprietorship by Adam Matar. Provider reserves the unilateral right, at his sole discretion and without requiring Client consent or advance notice, to incorporate, form an LLC or corporation, reorganize, or assign this Agreement and its assets to a successor corporate entity. Upon such formation or assignment, the successor entity assumes all rights and obligations hereunder, and all liability limitations and indemnifications continue to fully protect Adam Matar individually.
  3. Unilateral Right to Amend & Modify Terms:

    [!IMPORTANT] PROVIDER RESERVES THE UNILATERAL RIGHT, AT ITS SOLE DISCRETION, TO AMEND, MODIFY, UPDATE, OR REPLACE ANY PORTION OF THIS MASTER SERVICES AGREEMENT, INDIVIDUAL POLICIES, OR SRE RETAINER PRICING AT ANY TIME.

    Any such modification shall become effective immediately upon posting the updated version to Provider's public legal portal (https://tdhailabs.com/legal/msa.html) or upon transmission via email or WhatsApp notice. Client’s continued use of the software, access to automated workflows, or payment of ongoing retainer fees following any modification constitutes conclusive, binding, and affirmative acceptance of the amended terms. If Client does not agree to any updated term, Client’s sole and exclusive remedy is to terminate the monthly retainer upon thirty (30) days advance written notice pursuant to Section 2.3.


2. 50/50 MILESTONE BILLING & 7-DAY DEEMED ACCEPTANCE

  1. 50% Kick-Off Deposit: Due upon contract execution to allocate dedicated engineering compute and provision cloud infrastructure. Non-refundable once server provisioning commences.
  2. 7-Day Deemed Acceptance Rule: Upon notification by Provider that an automated workflow or container has been deployed to staging or production, Client shall have seven (7) business days ("Review Period") to submit written notice of reproducible material defects. If Client fails to submit written notice within seven (7) business days, OR if Client puts the workflow into active production use, the milestone shall be conclusively and irrevocably DEEMED ACCEPTED, and the remaining 50% Final Milestone Balance shall immediately become due and payable.
  3. Acceptance by Conduct: Client acknowledges that continued, beneficial use of the Services — including automated processing of Client's invoices, logins to the Client portal, or substantive replies to Service-related communications — constitutes acceptance of the then-current Terms by conduct, independent of and in addition to any deemed-acceptance-by-notice provision elsewhere in this Agreement. TDH maintains a contemporaneous, tamper-evident activity log of such use, available to Client upon request, which the parties agree is admissible evidence of the scope and timing of Client's use of the Services.
  4. Monthly SRE Retainer ($1,000/mo): Commences thirty (30) days post-deployment. Covers automated container health monitoring, self-healing recovery, error logging, and routine maintenance. Retainer may be canceled by either party with thirty (30) days advance written notice.
  5. No Chargebacks & Liquidated Damages: Client expressly covenants NOT to file any credit card chargeback, merchant dispute, or payment reversal. In the event of an unauthorized payment clawback, Client agrees to pay Provider liquidated damages equal to the disputed amount, plus 1.5% monthly interest and all reasonable legal collection fees.

3. EXHAUSTIVE AI & AGENTIC RISK WARNINGS (FRONTIER DEFENSE)

[!CAUTION] CRITICAL LEGAL NOTICE: AUTONOMOUS ARTIFICIAL INTELLIGENCE AGENTS AND LARGE LANGUAGE MODELS ARE INHERENTLY PROBABILISTIC, NON-DETERMINISTIC, AND EXPERIMENTAL COMPUTATIONAL SYSTEMS.

Client expressly acknowledges, understands, and assumes all risks associated with:

3.1. Non-Deterministic & Stochastic Behavior

Generative AI and LLM agents do not produce mathematically deterministic or repeatable results. Identical inputs, webhook payloads, or PDF documents may produce divergent summaries, general ledger classifications, data extractions, or downstream logic executions over time.

3.2. Direct & Indirect Prompt Injections (Adversarial Content Attacks)

Unstructured third-party data ingested by workflows (including customer emails, supplier PDF invoices, public web forms, chat messages, WhatsApp texts, and webhooks) may contain adversarial commands ("Direct/Indirect Prompt Injections", "Jailbreaks", or "Data Poisoning") designed to override system prompts, bypass security gates, or manipulate agent outputs. Provider makes ZERO WARRANTY that workflows will detect, sanitize, or block all prompt injections or adversarial payloads.

3.3. Hallucinations & Computational Workarounds

AI agents may fabricate plausible-sounding but completely false data ("hallucinations"), misinterpret complex business rules, generate invalid syntactical code, or execute unintended computational pathways outside specified operational guardrails.

3.4. Emerging Security Vulnerabilities & Zero-Days

The artificial intelligence and LLM software ecosystem is subject to emerging zero-day vulnerabilities, model inversion techniques, and algorithmic manipulation. Provider disclaims any warranty of absolute security or impenetrable defense against novel attack vectors.

3.5. Pre-Designed Architecture & Autonomous Agentic Customization Scope

Client expressly acknowledges and agrees that Provider deploys standardized, pre-designed architectural workflows (the "Golden Path"). Any client-specific customizations, schema alignments, and business rule configurations are engineered by a trained, autonomous agentic software development team. Baseline setups and the $1,000/month SRE retainer cover autonomous computational hosting, automated health canaries, and programmatic infrastructure maintenance with ZERO guaranteed human labor hours. If Client requests dedicated human supervision, manual human data auditing, forward-deployed engineering, or bespoke human operator-in-the-loop escalation, such professional services shall be billed separately at Provider's standard rate of $350.00 per hour, plus all actual, reasonable travel, lodging, and out-of-pocket expenses, and fulfilled via specialized contractor or engineering dispatch under a separate work order.


4. THIRD-PARTY INFRASTRUCTURE, HOSTING & CLOUD DEPENDENCIES

  1. Reliance on Unrelated Third-Party Providers: Client acknowledges that Provider utilizes separate, independent, and unrelated third-party services to deliver, host, and execute client workflows—including cloud hosting providers (e.g., Hostinger KVM VPS, AWS, Hetzner), container virtualization platforms (e.g., Docker, Linux OS distributions), public tunnel relays (e.g., Cloudflare), and third-party foundation model APIs (e.g., OpenAI, Anthropic, Google, DeepSeek, Meta, OpenRouter).
  2. Zero Control & Disclaimer of Upstream Failures: Provider does not own, operate, or control these third-party services. Provider passes through underlying infrastructure strictly "AS-IS" and "AS-AVAILABLE", and expressly disclaims any and all liability for:
  3. Standard Golden Path vs. Non-Standard / No-API Customizations: Standard turnkey deployments presume integrations with platforms supporting standard REST/OAuth APIs (specifically Google Workspace, QuickBooks Online, Stripe, and Twilio). If Client requests automation of third-party platforms, web portals, or legacy systems lacking an official public API or Model Context Protocol (MCP) server, or that employ anti-bot protections or restrictive terms of service:
  4. API & OAuth Provisioning Boundary: Client remains strictly responsible for administrative account ownership and authorization. Client agrees to provision a dedicated corporate email identity (e.g., anton@clientdomain.com) and invite said identity as an authorized user within Client's relevant third-party platforms (e.g., QuickBooks Online). Provider shall automate local token exchange, encryption, and scheduled credential rotation within Client's private container, but Client acknowledges Provider will not and cannot bypass Client's corporate 2FA/MFA requirements or administrative permission gates.

5. STRICT GEOGRAPHIC RESTRICTIONS & REGULATORY EXCLUSIONS (NO GDPR / NO CCPA)

[!IMPORTANT] TERRITORIAL LIMITATION: PROVIDER OFFERS SERVICES STRICTLY AND EXCLUSIVELY TO COMMERCIAL BUSINESSES OPERATING WITHIN THE UNITED STATES UNDER STANDARD US COMMERCIAL LAW.

  1. Express Prohibition on European (GDPR/UK GDPR) Data: Client represents, warrants, and covenants that it is NOT subject to the General Data Protection Regulation (GDPR) or UK GDPR, does not process personal data of residents or citizens of the European Economic Area (EEA) or United Kingdom, and will NOT route, ingest, or process any European data subject personal information through Provider's workflows.
  2. Express California (CCPA/CPRA) Exclusion: Client represents and warrants that it will NOT submit, ingest, or process consumer personal data subject to the California Consumer Privacy Act (CCPA) or California Privacy Rights Act (CPRA) through Provider's systems without prior written agreement.
  3. Prohibited High-Risk Regulated Data (HIPAA / ITAR / PCI): Client covenants that it will NOT submit any Protected Health Information (PHI) subject to HIPAA, payment card numbers subject to PCI-DSS, or ITAR/classified defense data through the automated workflows.
  4. Client Indemnification for Regulatory Violations: Client assumes 100% sole statutory, legal, and financial liability for any regulatory inquiry, fine, or private right of action arising under GDPR, CCPA, CPRA, HIPAA, or other extraterritorial privacy laws, and agrees to defend and indemnify Adam Matar against any such claims.

6. MANDATORY HUMAN SUPERVISORY OBLIGATION ("HUMAN-IN-THE-LOOP")

  1. Strict Duty of Verification: Client agrees and covenants that all AI-generated outputs, financial transactions, customer communications, contract summaries, and database mutations are subject to Client's independent human review and verification.
  2. Autonomous Action Waiver: Client assumes 100% operational and financial liability for all business actions initiated autonomously by workflows (including auto-dispatching customer emails, updating CRM records, issuing webhooks, or modifying databases).
  3. Accounting & Tax Disclaimer: Workflows are assistive computational software, NOT certified public accountants, licensed auditors, or legal counsel. Client retains 100% sole responsibility for auditing all journal entries, invoice postings, bill payments, and tax filings.

7. INTELLECTUAL PROPERTY & DATA SOVEREIGNTY

  1. Client Ownership: Client owns 100% of its dedicated server instance, private databases, customer data, and custom client-specific workflow code.
  2. Provider Background IP: Provider retains all rights, title, and interest in its pre-existing templates, proprietary node configurations, self-healing orchestration engines, and meta-deployer frameworks.
  3. Dual-Plane Data Privacy Disclosure:

8. TOTAL LIMITATION OF LIABILITY (HARD MONETARY CAP)

[!IMPORTANT] UNDER NO CIRCUMSTANCES SHALL ADAM MATAR, TDH AI LABS, OR ANY AFFILIATES, CONTRACTORS, OR AGENTS BE LIABLE TO CLIENT OR ANY THIRD PARTY FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES (INCLUDING LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF DATA, BUSINESS INTERRUPTION, LOSS OF REPUTATION, PROMPT INJECTION EXPLOITATION, CYBERATTACKS, THIRD-PARTY HOSTING OUTAGES, OR COST OF SUBSTITUTE SERVICES), REGARDLESS OF THE THEORY OF LIABILITY (WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR NEGLIGENCE), EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

AGGREGATE LIABILITY CAP: EXCEPT IN CASES OF PROVIDER'S JUDICIALLY DETERMINED GROSS NEGLIGENCE, WILLFUL MISCONDUCT, OR INTENTIONAL FRAUD, IN NO EVENT SHALL PROVIDER'S AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, FROM ALL CAUSES OF ACTION AND ALL THEORIES OF LIABILITY, EXCEED THE TOTAL FEES ACTUALLY PAID BY CLIENT TO PROVIDER UNDER THE APPLICABLE SOW IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO LIABILITY, OR TEN THOUSAND DOLLARS ($10,000.00 USD), WHICHEVER IS LESS.


9. ABSOLUTE PERSONAL INDEMNIFICATION OF ADAM MATAR (HOLD HARMLESS)

Except to the extent caused by Provider’s judicially determined gross negligence or intentional fraud, Client agrees to defend, indemnify, and hold harmless Adam Matar individually, his personal estate, heirs, affiliates, and Vibehard from and against any and all claims, liabilities, losses, damages, judgments, penalties, fines, costs, and expenses (including reasonable attorneys' fees and court costs) arising out of or related to:

  1. Client’s use, misuse, or reliance on the automated systems, AI agents, or generated outputs.
  2. Any prompt injection, adversarial jailbreak, data poison attack, or security exploit occurring on the private cloud infrastructure.
  3. Any data compromise, exfiltration, or breach involving Client data, credentials, or third-party hosting dependencies.
  4. Any financial, tax, accounting, or regulatory non-compliance resulting from automated workflows.
  5. Any claims brought by Client's employees, suppliers, customers, regulatory bodies, or third parties related to automated processing.

10. GOVERNING LAW, BINDING ARBITRATION & PREVAILING PARTY FEES

  1. Governing Law & Exclusive Venue: This Agreement shall be governed by and construed in accordance with the laws of the State of Oregon (or Provider's primary state of residence/registration), United States, without regard to conflict of law principles. Client expressly waives the application of foreign or extraterritorial laws.
  2. Mandatory Virtual Arbitration: Any dispute arising under this Agreement shall be resolved through confidential, binding individual arbitration administered virtually by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. Both parties expressly waive any right to a trial by jury or participation in a class-action lawsuit.
  3. Prevailing Party Fees: In any dispute, arbitration, or litigation arising out of this Agreement, the prevailing party shall be entitled to recover all reasonable attorneys' fees, expert witness costs, and arbitration fees from the non-prevailing party.

11. ENTIRE AGREEMENT, CLICKWRAP ENFORCEABILITY & MODIFICATIONS

This Agreement constitutes the complete and exclusive understanding between the parties. Electronic acceptance (via Stripe Checkout checkbox, digital signature, or funding of a milestone deposit) constitutes a valid, legally binding execution under the United States Electronic Signatures in Global and National Commerce Act (E-SIGN) and the Uniform Electronic Transactions Act (UETA). This Agreement and its pricing terms are subject to unilateral amendment by Provider as set forth in Section 1.3.