1. Scope of services
CarefulAI Ltd and its AI agents design, configure and implement AI agents to work on a Client’s AI Provider platforms. Services include agent logic design, conversation flow mapping, voice selection, integration setup and testing. CarefulAI Ltd does not provide legal compliance review, ongoing monitoring or liability coverage for agent interactions. Where a Client engages CarefulAI under a public-sector framework (including the NHS SBS Healthcare AI Solutions framework), the data protection, security and assurance terms of that framework and its call-off contract take precedence over these Terms to the extent of any conflict.
2. Client responsibilities and acknowledgments
The Client must provide clear business requirements and a signed Statement of Work; all necessary content, scripts and response guidelines; access to the Client’s AI Platform Provider account with appropriate permissions; and timely feedback during development.
The Client acknowledges that AI agents are not human and may produce responses that are incorrect, incomplete or inappropriate; that the Client is responsible for disclosing to end-users that they are interacting with AI; and that the Client assumes legal responsibility for how the AI agent interacts with its customers.
3. Data and privacy
3.1 Roles of the parties. For the purposes of UK Data Protection Legislation, in standard design engagements the Client is the Controller and the Client’s AI Provider is a Processor. Where CarefulAI itself processes personal data on behalf of the Client — including any processing of NHS or healthcare data — CarefulAI acts as a Processor (or, where applicable, Sub-Processor) and these Terms incorporate the Article 28 processor obligations set out in Schedule 1 (Data Processing) and in the applicable framework Data Protection Protocol.
3.2 Processing location. All personal data processed by CarefulAI for healthcare purposes is processed and stored exclusively on data centres located in the United Kingdom, and is not transferred outside the United Kingdom. Healthcare data is not routed to AI model providers hosted outside the United Kingdom unless an appropriate transfer safeguard and the Controller’s documented instruction are in place.
3.3 Processing obligations. CarefulAI and any AI Provider it engages shall: process personal data only on the documented written instructions of the Client; ensure persons processing data are bound by confidentiality; assist the Client in responding to data subject requests and in meeting UK GDPR obligations; and delete or return all personal data at the Client’s choice on termination. CarefulAI shall also implement appropriate technical and organisational security measures, notify the Client of any personal data breach without undue delay and within 24 hours of becoming aware, maintain records of processing under Article 30, and make available the information necessary to demonstrate compliance, including by permitting and contributing to audits by the Client or its mandated auditor.
3.4 Sub-processors. Data may flow through AI providers. The Client provides general written authorisation for CarefulAI to engage these sub-processors on an as needed basis. CarefulAI maintains a register of sub-processors and their hosting locations, engages each under a written contract imposing Article 28 obligations, will inform the Client of intended changes to sub-processors and give the Client an opportunity to object, and remains liable to the Client for the acts and omissions of its sub-processors. Healthcare personal data is restricted to UK-hosted sub-processors as set out in clause 3.2.
3.5 Prohibited data. The Client shall not use agents to collect Special Category Data, children’s data without consent, or financial credentials unless explicitly agreed in writing following a Data Protection Impact Assessment.
3.6 Governance. Where CarefulAI processes NHS patient data or accesses NHS systems, CarefulAI completes and publishes an annual Data Security and Protection Toolkit assessment to ‘Standards Met’ level, operates an information security framework aligned to ISO/IEC 27001, and nominates an Information Governance Lead who reports to the CarefulAI board or equivalent governance body.
4. Compliance and use restrictions
CarefulAI Ltd will not design agents that impersonate individuals without disclosure or use voice cloning without consent, collect data deceptively or breach an AI Provider’s Acceptable Use Policies, or facilitate illegal activities.
5. Testing and quality assurance
CarefulAI Ltd conducts reasonable testing before delivery; final acceptance testing is the Client’s responsibility. AI behaviour can be unpredictable and CarefulAI Ltd cannot guarantee specific outcomes in all scenarios. CarefulAI operates a documented quality management system and, for security controls relevant to processing, conducts periodic penetration testing, vulnerability scanning and review of the effectiveness of its technical and organisational measures.
6. Intellectual property and usage rights
CarefulAI Ltd retains its methodologies, templates and design approaches. The Client receives full ownership of the specific agent configuration and custom scripts created for the Client on full payment. The Client grants CarefulAI Ltd access to accounts during the project and the right to use anonymous data to improve services.
7. Warranties and limitations
Services are performed with reasonable professional skill and care in accordance with the Consumer Rights Act 2015 where applicable. Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot be limited by law. Subject to that, CarefulAI Ltd’s total liability is capped at the fees paid for a specific project, and CarefulAI Ltd is not liable for indirect or consequential loss. The liability cap and the exclusion for third-party AI Platform Provider breaches do not apply to, and do not limit, CarefulAI’s liability for breaches of its data protection obligations to the extent such limitation would be inconsistent with the applicable public-sector framework or call-off contract.
8. Voice cloning and synthetic media
The Client warrants it has obtained explicit, written, informed consent from any individual whose voice is cloned, possesses all IP rights for commercial use of the voice, and will clearly notify end-users that audio is AI-generated.
9. Ongoing support, payment, termination, indemnity and law
Initial projects include two rounds of revisions; post-launch support requires a separate agreement. Fees are as set out in the signed Statement of Work, with a 10% non-refundable deposit to commence work and third-party AI provider costs payable by the Client. Either party may terminate for material breach or where work would violate legal or ethical standards, with payment due for work completed to date. The Client indemnifies CarefulAI Ltd against claims arising from Client-provided content or voices, defamation from AI output, and regulatory breaches, save that this indemnity does not extend to losses arising from CarefulAI’s own breach of its data protection or security obligations under these Terms or the applicable framework. This agreement is governed by the laws of England and Wales, with the courts of England and Wales having exclusive jurisdiction.
CarefulAI Ltd and its AI agents design, configure and implement AI agents to work on a Client’s AI Provider platforms. Services include agent logic design, conversation flow mapping, voice selection, integration setup and testing. CarefulAI Ltd does not provide legal compliance review, ongoing monitoring or liability coverage for agent interactions. Where a Client engages CarefulAI under a public-sector framework (including the NHS SBS Healthcare AI Solutions framework), the data protection, security and assurance terms of that framework and its call-off contract take precedence over these Terms to the extent of any conflict.
2. Client responsibilities and acknowledgments
The Client must provide clear business requirements and a signed Statement of Work; all necessary content, scripts and response guidelines; access to the Client’s AI Platform Provider account with appropriate permissions; and timely feedback during development.
The Client acknowledges that AI agents are not human and may produce responses that are incorrect, incomplete or inappropriate; that the Client is responsible for disclosing to end-users that they are interacting with AI; and that the Client assumes legal responsibility for how the AI agent interacts with its customers.
3. Data and privacy
3.1 Roles of the parties. For the purposes of UK Data Protection Legislation, in standard design engagements the Client is the Controller and the Client’s AI Provider is a Processor. Where CarefulAI itself processes personal data on behalf of the Client — including any processing of NHS or healthcare data — CarefulAI acts as a Processor (or, where applicable, Sub-Processor) and these Terms incorporate the Article 28 processor obligations set out in Schedule 1 (Data Processing) and in the applicable framework Data Protection Protocol.
3.2 Processing location. All personal data processed by CarefulAI for healthcare purposes is processed and stored exclusively on data centres located in the United Kingdom, and is not transferred outside the United Kingdom. Healthcare data is not routed to AI model providers hosted outside the United Kingdom unless an appropriate transfer safeguard and the Controller’s documented instruction are in place.
3.3 Processing obligations. CarefulAI and any AI Provider it engages shall: process personal data only on the documented written instructions of the Client; ensure persons processing data are bound by confidentiality; assist the Client in responding to data subject requests and in meeting UK GDPR obligations; and delete or return all personal data at the Client’s choice on termination. CarefulAI shall also implement appropriate technical and organisational security measures, notify the Client of any personal data breach without undue delay and within 24 hours of becoming aware, maintain records of processing under Article 30, and make available the information necessary to demonstrate compliance, including by permitting and contributing to audits by the Client or its mandated auditor.
3.4 Sub-processors. Data may flow through AI providers. The Client provides general written authorisation for CarefulAI to engage these sub-processors on an as needed basis. CarefulAI maintains a register of sub-processors and their hosting locations, engages each under a written contract imposing Article 28 obligations, will inform the Client of intended changes to sub-processors and give the Client an opportunity to object, and remains liable to the Client for the acts and omissions of its sub-processors. Healthcare personal data is restricted to UK-hosted sub-processors as set out in clause 3.2.
3.5 Prohibited data. The Client shall not use agents to collect Special Category Data, children’s data without consent, or financial credentials unless explicitly agreed in writing following a Data Protection Impact Assessment.
3.6 Governance. Where CarefulAI processes NHS patient data or accesses NHS systems, CarefulAI completes and publishes an annual Data Security and Protection Toolkit assessment to ‘Standards Met’ level, operates an information security framework aligned to ISO/IEC 27001, and nominates an Information Governance Lead who reports to the CarefulAI board or equivalent governance body.
4. Compliance and use restrictions
CarefulAI Ltd will not design agents that impersonate individuals without disclosure or use voice cloning without consent, collect data deceptively or breach an AI Provider’s Acceptable Use Policies, or facilitate illegal activities.
5. Testing and quality assurance
CarefulAI Ltd conducts reasonable testing before delivery; final acceptance testing is the Client’s responsibility. AI behaviour can be unpredictable and CarefulAI Ltd cannot guarantee specific outcomes in all scenarios. CarefulAI operates a documented quality management system and, for security controls relevant to processing, conducts periodic penetration testing, vulnerability scanning and review of the effectiveness of its technical and organisational measures.
6. Intellectual property and usage rights
CarefulAI Ltd retains its methodologies, templates and design approaches. The Client receives full ownership of the specific agent configuration and custom scripts created for the Client on full payment. The Client grants CarefulAI Ltd access to accounts during the project and the right to use anonymous data to improve services.
7. Warranties and limitations
Services are performed with reasonable professional skill and care in accordance with the Consumer Rights Act 2015 where applicable. Nothing in these Terms limits liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot be limited by law. Subject to that, CarefulAI Ltd’s total liability is capped at the fees paid for a specific project, and CarefulAI Ltd is not liable for indirect or consequential loss. The liability cap and the exclusion for third-party AI Platform Provider breaches do not apply to, and do not limit, CarefulAI’s liability for breaches of its data protection obligations to the extent such limitation would be inconsistent with the applicable public-sector framework or call-off contract.
8. Voice cloning and synthetic media
The Client warrants it has obtained explicit, written, informed consent from any individual whose voice is cloned, possesses all IP rights for commercial use of the voice, and will clearly notify end-users that audio is AI-generated.
9. Ongoing support, payment, termination, indemnity and law
Initial projects include two rounds of revisions; post-launch support requires a separate agreement. Fees are as set out in the signed Statement of Work, with a 10% non-refundable deposit to commence work and third-party AI provider costs payable by the Client. Either party may terminate for material breach or where work would violate legal or ethical standards, with payment due for work completed to date. The Client indemnifies CarefulAI Ltd against claims arising from Client-provided content or voices, defamation from AI output, and regulatory breaches, save that this indemnity does not extend to losses arising from CarefulAI’s own breach of its data protection or security obligations under these Terms or the applicable framework. This agreement is governed by the laws of England and Wales, with the courts of England and Wales having exclusive jurisdiction.