1. What this document is
This page sets out what changes for an Enterprise customer. Everything in our Terms of Service still applies — this document supplements it and, where the two conflict, this document wins for an Enterprise Order.
Capitalised terms — Service, Customer, Customer Content, Generated Output, Credits, Workspace, Project, Published App, Order, Beta Feature, Documentation, Sub-processor — have the meanings given in the Terms of Service.
2. Order of precedence
Where documents disagree, this is the order:
- The Order form signed by both parties, for the term of that Order.
- This Enterprise Terms page.
- Our data processing agreement at /dpa, for anything about Customer Personal Data.
- Our Service Level Agreement at /sla, for availability.
- The Terms of Service and the policies it incorporates.
- The Documentation at docs.vibely.sh.
3. Who this applies to
This page applies to a Customer that has an Order form executed by both parties. Buying a plan through checkout does not create an Enterprise engagement, and nothing on this page applies to a self-serve Workspace. To start an Order, email [email protected].
4. Seats and provisioning
An Enterprise Order names the seat count and the price per seat. Seats are counted as members of the Workspace named in the Order.
Single sign-on is available through SAML and Google Workspace. User provisioning and de-provisioning is available through SCIM over SAML or OIDC. We support these against your identity provider; we do not administer your identity provider for you.
Members hold one of four roles — Owner, Admin, Editor or Viewer — which govern what they can do in the Workspace. Groups are defined inside the Workspace and control who can open a Published App.
Adding seats mid-term is billed pro-rata on the next invoice. Reducing seats takes effect at the next renewal.
5. Publishing and access controls
Publishing a Project to your workspace only, to named groups, or privately to yourself is available on Business and Enterprise plans. Restricting a Project’s visibility to the Workspace is the same. On other plans a Published App is public to anyone with the link.
6. Security
Each Project runs in an isolated cloud sandbox with its own filesystem, operated by a third-party sandbox provider. Access to the Service is controlled by the roles above. Secrets and configuration are held in AWS Systems Manager Parameter Store rather than in code. Audit events for your Workspace are recorded and retained for 91 days. We do not hold a third-party attestation of any of this — see "Compliance programmes and audit" below.
We will tell you about a personal data breach affecting your Customer Personal Data without undue delay and, where we are your processor, within 72 hours of becoming aware of it, with what we know at the time.
You are responsible for what your own applications do — the code the agent generates for you is Customer Content, and you decide what to publish and what data to collect in it.
7. Compliance programmes and audit
We tell you where we actually are. We do not hold a SOC 2 report or an ISO 27001 certificate, no audit against either framework is under way, and we are not naming a date for one. If either matters to your procurement, know that before the Order rather than after.
We will not say we hold either, and we will not describe a programme we have not started. If we engage an auditor we will say so at /security on the day we do, and share the report under NDA when there is one.
Audit rights under an Enterprise Order are a written security questionnaire, once in any twelve months, answered within 30 days. We do not offer on-site audits or customer-run penetration tests of our production environment. Security researchers are welcome under our Responsible Disclosure policy.
8. Data protection
For Customer Personal Data you are the controller, or Data Fiduciary, and we are the processor. We process it on your documented instructions to provide the Service. For Service Data — your account, billing, usage metering, logs and support correspondence — we are the controller in our own right.
Our Article 28 Data Processing Agreement is published at /dpa and applies to every Enterprise Order without separate signature. It incorporates the EU Standard Contractual Clauses and the UK Addendum, and its Annexes 1 and 2 serve as the SCC annexes. If your procurement process needs a counter-signed copy, email [email protected] and we will execute one against that text.
We do not use your prompts, code, or project data to train models. Product-improvement data collection is off by default on every plan and collects usage metrics only — model, provider, token counts and cost — never prompts or code.
9. Sub-processors
Our current Sub-processors are published at /subprocessors, and that published list is the authoritative one. We post changes there and email Workspace owners at least 30 days before a new Sub-processor begins processing Customer Personal Data.
Prompts are sent to third-party AI model providers to run a turn. Providers receive only the input necessary to fulfil the turn and standard request metadata. Where a specific transfer mechanism or a specific set of providers matters to you, raise it with [email protected] before the Order is signed — some providers are usable under terms we can evidence and some are not.
10. Data residency — what we can and cannot offer
Infrastructure is not in one country. Application servers and Project sandboxes run in the United States (AWS us-east-1); the primary database, authentication and file storage run on Supabase in Singapore (ap-southeast-1); our CDN serves from edge locations worldwide. Mana Intelligence Private Limited operates the Service from India, so our personnel access all of it from India. If a residency commitment is going in the Order, it has to describe that split, not a single region.
We cannot today offer a region of your choosing, a single-tenant or on-premise deployment, deployment into your own cloud account, or customer-managed encryption keys. If residency is a requirement, tell us before the Order rather than after — we would rather lose the deal than write a commitment we cannot keep.
11. Retention and getting your data out
A deleted Project is recoverable for 30 days and is then purged, together with its stored files, by an automated nightly job. Audit log entries are retained for 91 days. Form submissions collected by the apps you publish are retained for 730 days. Client error reports are retained for 30 days. When you close your account we delete your personal data within 30 days, except where retention is required by law.
Your Project source is yours throughout. You can connect a GitHub repository and sync it at any time, and we recommend doing that rather than relying on an export at the end of a term.
12. Support
An Enterprise Order names a support contact at Vibely and up to five named contacts at your organisation who may raise tickets. Support is by email.
Support hours are 09:00 to 18:00 India Standard Time, Monday to Friday, excluding Indian public holidays. Our target first response is 4 support hours for an issue that makes the Service unusable for your Workspace, 1 business day for a significant impairment with no workaround, and 2 business days for everything else.
These are response targets, not resolution times, and they are not backed by service credits. The only commitment carrying a credit is the uptime commitment in our Service Level Agreement.
13. Availability
Our Service Level Agreement at /sla applies to every Enterprise Order, including the service credits and the claim window in it. Where an Order states a different uptime commitment, that Order wins for its term.
14. Invoicing and payment
An Enterprise Order is invoiced rather than charged to a card on file. Fees are invoiced annually in advance in US dollars unless the Order says otherwise. Payment is due 30 days from the invoice date.
If you need a purchase order number on the invoice, give it to us before the Order is signed. A missing purchase order number is not a reason to pay late.
We may suspend the Service on 14 days’ written notice for an invoice that is more than 30 days overdue. Fees paid are non-refundable except as set out in our Refund and Cancellation Policy.
15. Credits under an Order
An Order states the Credit volume included and the rate for additional Credits. Credits are consumed as measured model spend, subject to a small per-turn minimum, and are not transferable between Workspaces. On a paid plan, credits you have not spent when the cycle renews roll over once: they stay spendable through the following cycle and expire at the end of it.
16. Tax
All fees are billed in USD. Prices exclude any tax that applies where you are; you are responsible for it. Give us your billing country and, where you have one, your VAT or GST registration number before the first invoice.
17. Term, renewal and termination
The initial term is 12 months from the Order start date unless the Order says otherwise, and renews for successive 12-month terms.
Either party may stop the renewal by written notice at least 30 days before the end of the current term. That is termination for convenience: it takes effect at the end of the term you have paid for and does not refund it.
Either party may terminate mid-term for material breach that is not cured within 30 days of written notice. Where we are the party in material breach, we refund the prepaid fees for services not delivered as of the termination date, including the pro-rata portion of an annual fee.
On termination your access ends at the end of the term and unused Credits granted under the Order are forfeited. Export what you need before then.
18. Confidentiality
The mutual confidentiality obligations in our Terms of Service apply to Enterprise engagements and are the confidentiality terms for anything shared during evaluation, procurement and the term. Where you require your own mutual non-disclosure agreement, sign it before the Order and name it in the Order; it will then govern confidentiality in place of that section.
19. Liability
The limitation of liability in our Terms of Service applies to Enterprise Orders unchanged unless the Order says otherwise. It reads: "To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, consequential, or punitive damages, including lost profits, even if advised of the possibility."
"The aggregate liability of Mana Intelligence Private Limited — us, the company that operates Vibely — arising out of or relating to the service will not exceed the greater of (a) the amounts you paid us in the 6 months before the date the claim first arose, or (b) USD 100." "For claims related to our breach of confidentiality or data protection obligations, the liability cap is 2× the amount above."
If you need a different cap, it is negotiated on the Order form, not here.
20. Governing law
"These Terms are governed by the laws of India, without regard to conflict-of-law principles. The courts at Hyderabad, Rangareddy district, Telangana, India have exclusive jurisdiction over any dispute arising out of or relating to these Terms or the service, and both of us submit to that jurisdiction."
21. Contact
Orders, pricing and renewals: [email protected]. Contractual notices and data protection: [email protected]. Invoices and payment: [email protected]. Vibely is operated by Mana Intelligence Private Limited, incorporated in India.