Client Terms of Service

Last updated: 9 September 2026 · Version 10 · In House It (Pty) Ltd t/a IndunAI

Important. These Terms are a binding agreement between In House It (Pty) Ltd, trading as IndunAI ("IndunAI", "we", "us" or "Provider"), and the person or business that starts a trial, orders, subscribes to or uses the Service ("Client", "you" or "your"). By accepting an order, clicking to subscribe, starting a trial, or continuing to use the Service after being given these Terms, you agree to them. Nothing in these Terms excludes a right or remedy that cannot lawfully be excluded.

Two clauses are set out in highlighted boxes below — clause 11 (AI limitations) and clause 22 (risk and limitation of liability) — because section 49 of the CPA requires a term of that kind to be drawn to your attention before the agreement is concluded. Please read them.

On this page

1. Provider information and ECTA disclosures

Trading nameIn House It
Legal name and statusIn House It (Pty) Ltd, a private company incorporated in the Republic of South Africa
Registration number2024/456850/07
Place of registrationRepublic of South Africa, registered with the Companies and Intellectual Property Commission (CIPC)
Office bearer / Information OfficerAngus Baumgardt
Registered office and physical address47 Moss Road, Ocean View, Durban, KwaZulu-Natal, 4052, South Africa
Address for service of legal documents47 Moss Road, Ocean View, Durban, KwaZulu-Natal, 4052, South Africa
Emailangus@indunai.co.za
Telephone / WhatsApp+27 76 786 4417
Websitehttps://indunai.co.za

The Service is described in clause 4 and in the applicable order, proposal, dashboard or pricing page. The price, billing frequency, any setup fee, applicable taxes and any usage allowance are shown before an order is accepted. These Terms can be accessed, stored and reproduced electronically from https://indunai.co.za/terms and may be requested by email.

Unless a different implementation date is agreed in writing, electronic service begins when the relevant Instance is activated after the Client has supplied the information and access reasonably required for setup. Where ECTA applies and no different time has been agreed, the Service will be rendered within the period required by law.

We retain subscription, invoice, payment and material transaction records for the periods required by law and, in general, for at least five years after the relevant transaction. A Client may request a copy of its available transaction record by emailing us.

We do not presently subscribe to a voluntary alternative-dispute-resolution code or industry accreditation scheme for the Service unless expressly stated in an order. Statutory remedies through courts, the Information Regulator and the National Consumer Commission remain available where they have jurisdiction.

2. Definitions

"AI Provider" — a third-party artificial-intelligence provider used to generate or analyse content, transcribe audio or perform related AI processing.
"Business Day" — a day other than a Saturday, Sunday or South African public holiday.
"Client Data" — information placed in, generated in or stored in the Client's Instance, including conversations, bookings, contact details, files, configuration and related records.
"Conversation" — a customer chat thread containing at least one inbound Customer message during the relevant calendar month, subject to any fair-use counting rule disclosed in the Client's plan.
"Customer" — a person who interacts with the Client through the Service, including a patient where the Client is a healthcare practice.
"Fees" — the fees, charges and usage amounts shown in the Client's order, proposal, dashboard or agreed pricing.
"Healthcare Instance" — an Instance used by a medical, dental, allied-health, healthcare or other practice subject to healthcare law, professional rules or patient-confidentiality duties.
"Instance" — the hosted environment configured for the Client, including its database, assistant configuration and connected services.
"Personal Information" — personal information as defined in POPIA, including special personal information where applicable.
"POPIA" — the Protection of Personal Information Act 4 of 2013.
"Service" — the IndunAI hosted AI-assistant platform and enabled functions described in clause 4.

3. Acceptance, authority and consumer law

The person accepting these Terms warrants that they are authorised to bind the Client. The Service is primarily supplied for business use. Where the Consumer Protection Act 68 of 2008 ("CPA") or any other consumer-protection law applies, these Terms must be read subject to that law.

If the Client is a juristic person to which the CPA does not apply because of an applicable statutory threshold, the CPA provisions referred to in these Terms do not create rights beyond those required by law. If the CPA does apply, no provision is intended to waive a non-waivable consumer right.

4. The Service

Depending on the Client's selected plan and configuration, the Service may include webchat, WhatsApp and email conversations, enquiry handling, appointment booking, rescheduling and cancellation, calendar integration, team dispatch, reminders, review requests, qualification workflows, quotes, invoicing, optional payment links, marketing-draft tools, CRM synchronisation, administrative dashboards, usage reporting and related automation.

We will provide the Service with reasonable skill and care. The Service depends on the information, permissions, third-party accounts and configuration supplied by the Client. The Client remains responsible for the accuracy of its business information and for decisions that require human or professional judgment. Marketing drafts are never published without your approval.

We may improve, replace or modify features. We will not intentionally remove a material core feature from a paid plan without reasonable notice, except where a change is required for security, law, third-party platform compliance or to prevent harm.

5. Trials and demonstrations

A free trial or demonstration may be provided for the period stated at signup, normally 14 days. A trial may have limits not present on paid plans. When a trial expires, the Instance may stop serving Customers. If the Client does not subscribe within 30 days after trial expiry, we may delete the trial Instance and its data, subject to applicable law.

We may suspend or end a trial used for resale, automated abuse, unlawful activity, security testing without written permission, or other use inconsistent with the trial's purpose.

6. Fees, billing, taxes and payment

(a) Fees are charged as shown in the accepted order, proposal, dashboard or checkout. South African Clients may be billed in South African rand by EFT or through an approved payment provider. International Clients may be billed through a merchant of record such as Paddle, in which case that merchant's checkout and payment terms also apply.
(b) A once-off setup fee may apply where quoted. Subscription fees are normally billed monthly in advance unless a different billing arrangement is agreed in writing.
(c) Where a plan includes a monthly Conversation allowance, the allowance and any fair-use counting rule will be disclosed with the plan. Unless stated otherwise, a thread with at least one inbound Customer message in a calendar month counts as one Conversation. Where more than 60 inbound Customer messages occur in one thread during a calendar month, each further block of up to 60 inbound messages may count as an additional Conversation. That threshold is far above any ordinary enquiry; it exists so that one extreme thread cannot consume an allowance meant for a month of real conversations.
(d) Top-ups, overages or additional usage are charged at the rate disclosed before purchase or use. A Client using its own AI-provider account is responsible for that provider's charges, and no Conversation allowance applies to it.
(e) Quoted Fees include VAT only where the quote or invoice states that VAT is included and we are required or entitled to charge it. We will issue tax invoices where required by law.
(f) These are two different events. If a payment fails, the Service continues for a grace period of 7 days and is then suspended until payment resumes. If you cancel, the Service continues to the end of the period you have already paid for (clause 7), and in any event for at least 7 days, and is suspended after that. Nothing is cut back in the meantime: your assistant runs at the full capacity of your plan until the day it is suspended. Client Data is retained during suspension.
(g) We may change recurring Fees on at least one calendar month's written notice. A Client that does not accept the change may cancel before it takes effect.

7. Term and cancellation

Unless an order expressly states otherwise, the subscription runs month to month. The Client may cancel at any time, effective at the end of the paid period. There are no lock-ins and no contractual early-cancellation penalty for a standard month-to-month subscription.

The Service continues to the end of the period you have already paid for: your assistant keeps working until the last day of the month you have paid for, and is suspended after it. Except where law or clause 8 requires otherwise, a partial paid month is not refunded pro rata because the Service remains available to you for that period.

8. ECTA cooling-off, refunds and statutory remedies

Where section 44 of the Electronic Communications and Transactions Act 25 of 2002 ("ECTA") applies, a consumer may cancel a transaction for services without reason and without penalty within seven days after conclusion of the agreement and is entitled to a full refund of amounts already paid, to be made within 30 days of cancellation. Section 44 does not apply to a service that began with the consumer's consent before the seven-day period ended, as contemplated in section 42(2)(d) of ECTA.

Where a Client asks us to activate the Service immediately, the Client expressly requests performance to begin as soon as setup is complete and acknowledges that, where section 42(2)(d) applies, the ECTA section 44 cooling-off right will not apply after performance has begun.

Where the CPA applies and the agreement resulted from direct marketing, any applicable CPA cooling-off right remains unaffected.

If we materially fail to provide the Service in a billing period, the Client should notify us promptly so that we can investigate and remedy the failure. Any contractual refund offered by us is additional to, and does not limit, a consumer's rights under section 54 of the CPA or any other non-waivable statutory remedy.

Top-ups or usage items already consumed are not refundable except where law requires otherwise. Refunds processed through a merchant of record are returned through that merchant to the original payment method where practicable.

9. Client obligations and acceptable use

The Client must:
(a) provide accurate, lawful and current information about its business, services, prices, availability, staff and policies;
(b) review information, workflows and connected calendars sufficiently to ensure the assistant is configured correctly, and take responsibility for reviewing and approving every marketing draft before publication — that approval is the Client's editorial decision, and published content is the Client's content;
(c) use the Service only for lawful purposes and not for deception, unlawful discrimination, harassment, defamation, fraud, prohibited content or other unlawful activity;
(d) keep credentials and connected-account secrets secure and notify us promptly of suspected compromise;
(e) comply with the terms and policies of connected third-party platforms, including Meta, Google, email providers, payment providers and CRMs;
(f) respond appropriately to escalations and human-handover requests;
(g) not attempt to penetrate, bypass, reverse engineer or security-test the Service without our prior written permission;
(h) not resell or white-label the Service unless a separate reseller or partner agreement permits it;
(i) ensure it has a lawful basis for all Personal Information supplied to or processed through the Service; and
(j) where it connects its own PayFast account so Customers can pay invoices online: the payment relationship is between the Client, its Customer and PayFast (Pty) Ltd under PayFast's terms — we never hold, receive or transmit the money. The Client is responsible for that account, its credentials (including keeping the passphrase entered in the dashboard in sync with its PayFast settings) and any fees PayFast charges it. The Service marks an invoice paid only after PayFast's payment notification passes our verification checks; the Client remains responsible for reconciling its own account.

10. Direct marketing and communications

The Client is responsible for determining whether a message is transactional, service-related or direct marketing and for ensuring that any direct marketing sent through the Service complies with POPIA, the CPA and other applicable law.

For electronic direct marketing, the Client must comply with section 69 of POPIA, including applicable consent or existing-customer requirements, identify the sender, provide a lawful opt-out mechanism and honour objections and withdrawals.

Where the CPA direct-marketing regime applies, the Client is responsible for registering as a direct marketer with the National Consumer Commission's Opt-Out Registry where required, renewing that registration, keeping registration details current, identifying itself as required, honouring relevant pre-emptive blocks and cleansing its direct-marketing database against the Registry at the legally required frequency. Unless an order specifically states that IndunAI performs a Registry function for the Client, use of the Service does not transfer those obligations to IndunAI.

The Client must not upload or use a marketing list that was unlawfully obtained, must not re-add a person who has validly opted out unless a new lawful basis exists, and must keep evidence of consent or other lawful authority where required.

11. IMPORTANT — AI limitations, human handover and emergency matters

The Service uses AI systems. AI output can be inaccurate, incomplete, delayed, misunderstood or inappropriate. It may misstate a price or detail, misunderstand an enquiry, handle a booking imperfectly or generate content the Client would not have written. We have engineered server-side safeguards — bookings can only be made from real availability, marketing is never published without your approval, and a human hand-off exists — but you accept the Service on this basis.

The Client must not represent the AI assistant as a human or as a qualified professional where that would be misleading. Where required by law, professional rules or the nature of the service, the assistant must identify itself as AI and disclose material limitations.

Human handover is available where configured and is mandatory for Healthcare Instances as set out in clause 12. The Client remains responsible for responding to escalations.

The Service is not an emergency service, crisis service or substitute for emergency responders. Where a conversation discloses a risk of self-harm in wording the Service recognises outright, it replies with fixed, pre-written text, with no AI involved at all, that identifies the assistant as automated and signposts public crisis helplines. Where the disclosure is phrased in a way only the AI itself picks up, the Service checks that those same crisis helplines are in the reply before it is sent. In both cases it alerts the Client urgently. Automated safety messaging or alerts are supplemental only, and conversations are not continuously monitored by a human in real time.

You will not rely on the assistant as your only record of commitments made to Customers; the dashboard gives you the full transcript of every conversation for exactly that reason. This clause is drawn to your attention in terms of section 49 of the CPA.

12. Healthcare and HPCSA addendum

This clause applies automatically to every Healthcare Instance and forms part of the agreement without requiring a separate signature.

12.1 Professional responsibility

The healthcare practice and its registered practitioners remain solely responsible for professional services, diagnosis, treatment, prescribing, clinical judgment, patient consent and compliance with the Health Professions Act, HPCSA ethical rules and any other professional or statutory obligations applicable to them.

12.2 AI disclosure and patient choice

The Healthcare Instance must identify the assistant as an AI assistant before or at the beginning of the interaction in a clear and reasonably prominent manner. A patient must have a reasonable means to request human assistance, and the Client must not deny or disadvantage a patient merely because the patient does not wish to interact with AI.

12.3 Permitted functions

The Healthcare Instance may perform administrative and non-clinical functions such as enquiries, appointments, reminders, practice information, approved general educational information, forms, payment or administrative information and human handover, subject to the Client's configuration and applicable law.

12.4 Prohibited autonomous clinical decisions

The Client must not configure or use IndunAI as the final decision-maker for diagnosis, treatment, prescribing, medication advice, interpretation of test results, clinical suitability, prognosis or other patient-care decisions requiring professional judgment. The Service may route, summarise or present information, but final clinical decisions must remain with an appropriately registered healthcare practitioner.

12.5 Approved clinical information

Any practice-specific clinical, treatment or patient-education information supplied to the assistant must be reviewed and approved by the Client or an appropriately qualified practitioner. The Client is responsible for ensuring that advertising, treatment claims, pricing communications, reviews and promotional material comply with applicable HPCSA rules and other healthcare advertising restrictions.

12.6 Health information and children

The Client acknowledges that patient conversations may contain health information, special personal information and, where relevant, information about children. The Client is the responsible party for that information and must ensure that processing is authorised under POPIA, including sections 26 to 35 where applicable. Where prior authorisation from the Information Regulator is legally required for a planned processing activity or cross-border transfer, the Client must obtain it before instructing that processing.

12.7 No cross-client patient learning

Identifiable patient conversations, patient summaries, patient-derived lessons and patient-specific information from a Healthcare Instance will not be made available to another Client or used to create cross-client learning material. Any general service improvement involving Healthcare Instance data must be performed in a manner consistent with POPIA, professional confidentiality and the Client's lawful instructions.

12.8 Patient records

The Client determines whether a communication or other record forms part of the patient's health record and remains responsible for applicable professional and statutory record-retention requirements. IndunAI's platform retention does not replace the Client's patient-record system unless expressly agreed in writing.

12.9 Emergency and sensitive matters

Where the assistant identifies a potentially urgent, emergency or sensitive matter, it may provide fixed or configured escalation information and alert the Client. This does not amount to diagnosis, triage by a healthcare professional or emergency monitoring. The Client must maintain appropriate emergency and human-escalation procedures for its practice.

13. Intellectual property

The Service, software, workflows, IndunAI branding, interfaces, platform design, code, proprietary prompts, documentation and original assets — including the IndunAI name, the Induna robot mark and our original artwork — remain the property of IndunAI or its licensors. The Client receives a limited, non-exclusive, non-transferable right to use the Service during the subscription; nothing in these Terms licenses the Client to use our branding or artwork outside the Service. During a free trial the Service displays a small "Powered by IndunAI" attribution on the chat widget, on assistant emails and on invoices; it is removed automatically when the Client subscribes to a paid plan.

Client Data remains the Client's data. The Client grants us the limited rights necessary to host, transmit, process, back up and otherwise handle Client Data to provide, secure and support the Service and to comply with lawful instructions.

To the extent we own rights in AI-generated drafts created specifically for the Client, we assign our interest in drafts the Client approves and publishes, subject to third-party rights and applicable law. The Client remains responsible for published content.

Feedback, suggestions and non-confidential ideas about the Service may be used to improve the Service without payment or restriction.

14. Confidentiality

Each party must keep the other party's non-public confidential information confidential and use it only for this agreement, except where disclosure is authorised, required by law or the information becomes public without breach.

The general confidentiality obligation survives termination for three years. The three-year period does not limit obligations relating to Personal Information, patient information, legally privileged information, trade secrets or information that law or professional rules require to remain confidential for longer.

15. Security

We maintain reasonable technical and organisational safeguards appropriate to the risks of the processing, including isolated Client environments with their own database and credentials, per-tenant credential separation so one Client's compromise cannot expose another's provider keys, encrypted transport, access control, restricted administrative access, logging, security maintenance, and nightly backups encrypted before they leave the server, retained for 30 days on the server itself, with encrypted copies also held off-site (currently with Microsoft, in OneDrive) that cannot be read without our key.

No electronic system is completely secure. The Client must also maintain reasonable security over its own users, devices, credentials and connected systems.

16. POPIA data-processing terms

For Personal Information processed through an Instance on behalf of the Client, the Client is ordinarily the responsible party and In House It (Pty) Ltd t/a IndunAI is the operator. This clause is intended to constitute the written operator arrangement required by section 21 of POPIA. We will:
(a) process Personal Information only with the Client's knowledge or authorisation, for the purposes of providing, securing, supporting and maintaining the Service, and as required by law. Where the Client's Instance is set up for the assistant to gather what it needs conversationally rather than by asking a fixed list of questions, a second automated reading of each conversation runs after the reply has been sent, to pick out the answers Customers gave and record them against that conversation; the sub-operator named in (d) below performs that reading, the record is held on the Client's Instance, and the Instance's customer-facing privacy page describes it;
(b) treat Personal Information as confidential (POPIA section 20) and require authorised personnel with access to be subject to confidentiality obligations;
(c) maintain the security safeguards described in clause 15 and review them as reasonably appropriate to the risks (POPIA section 21(1));
(d) engage only the sub-operators reasonably necessary to run the Service, currently: the AI Provider the Client selects or we supply (message content — including voice-note audio for transcription — to generate replies, and, where the second reading in (a) is in use on the Client's Instance, the conversation itself so that the answers in it can be picked out); Meta Platforms (WhatsApp Business Platform, if WhatsApp is connected); the Client's calendar provider (booking details, if connected); the Client's email provider (if a mailbox is connected); OpenStreetMap's Nominatim geocoding service (Customer street addresses only — no names or contact details — for team dispatch, if staff dispatch is used); PayFast (Pty) Ltd (payment confirmations, if online invoice payment is enabled); Microsoft Corporation (OneDrive: the encrypted off-site backup copies described in clause 15, which cannot be read without our key); ipwho.is (a web-chat visitor's network address alone, for coarse location); and our hosting provider (infrastructure). We remain responsible for our sub-operators' processing on our behalf;
(e) where we have reasonable grounds to believe that Personal Information processed for the Client has been accessed or acquired by an unauthorised person, notify the Client immediately, as section 21(2) of POPIA requires, and provide reasonable cooperation so that the Client can meet its section 22 obligations to the Information Regulator and to affected data subjects;
(f) provide reasonable assistance with data-subject access, correction, deletion, objection and regulatory requests relating to information in the Instance. We may charge reasonable costs for unusually extensive assistance that falls outside ordinary support, after notifying the Client. That assistance covers the Client Data in the Instance: where the Client has connected its own CRM account, a Customer's records already copied there, conversation content included, are outside it, and only the Client can find, correct or delete them there (clause 18(c));
(g) not sell Client Data, and not knowingly opt Client Data into general-purpose AI model training. Where the optional nightly self-review is enabled on the Client's Instance, the one-line practice lessons it produces are screened automatically against personal and client-identifying data: a lesson that passes that screen may be shared with other Clients' assistants, anything the screen suspects is held for our operator to read first, and our operator can review and withdraw any shared lesson at any time. Customer records, messages and contact details are never shared between Clients, the Client can switch this sharing off on its Instance, and clause 12.7 governs a Healthcare Instance absolutely.

The Client warrants that it has a lawful basis for the Personal Information it supplies, collects or instructs us to process and that its instructions will not knowingly require us to breach POPIA. The Client must not remove from any privacy notice it publishes itself the disclosures its Instance's customer-facing privacy page makes.

17. Sub-operators and international transfers

The Service depends on third-party providers. Depending on the Client's configuration, categories may include AI providers, Meta/WhatsApp, calendar and email providers, hosting providers, payment providers, geocoding/location services, backup providers and other integration providers. The current list is in clause 16(d), and the material provider categories are also described in our Privacy Policy.

We may appoint and replace sub-operators where reasonably necessary to provide the Service, provided we take reasonable steps to require appropriate confidentiality, security and data-protection obligations.

Some providers process Personal Information outside South Africa. All Client Data at rest is stored in Johannesburg, South Africa; encrypted backup copies are additionally held off-site with Microsoft Corporation (OneDrive, outside South Africa) and cannot be read without our key; and where the Client connects its own CRM account, the records we copy into it on the Client's instruction, including the conversation itself where that is switched on, rest there, on GoHighLevel's systems outside South Africa (clause 18(c)). International transfers must comply with section 72 of POPIA. Depending on the circumstances, a transfer may rely on adequate protection under foreign law or binding agreements/rules, consent, contractual necessity or another lawful mechanism permitted by section 72.

Where the Client is the responsible party, the Client remains responsible for ensuring that its instruction to transfer Personal Information internationally has an appropriate legal basis. We will provide reasonable information about known material processing locations and safeguards on request.

18. Connected accounts, CRM and third-party services

(a) Third-party services connected by the Client remain subject to their own terms and privacy practices. The Client is responsible for its accounts, licences, credentials and authorisations.

(b) Where the Client connects its own CRM, calendar, mailbox, WhatsApp account or other system, the Client instructs us to exchange the configured data with that system. Information copied into a third-party account controlled by the Client is then held under that account's retention and access settings and may be outside our ability to delete.

(c) The Client's own CRM connection. Separately, and only where the Client connects its own GoHighLevel CRM account to its Instance: GoHighLevel is not our sub-operator. The account, its credentials and the relationship with GoHighLevel are the Client's, and we copy records into it on the Client's instruction. What we send on that instruction is Customer names and contact details, the appointment, the service and its price, the assistant's short description of the enquiry, a Customer's street address where one was given for a call-out, and the answers to the Client's own qualifying questions. Conversation content is not among them unless the Client switches on Copy conversations into my CRM on the CRM card in its dashboard, which is off until it is switched on. Switched on, it is a further instruction from the Client, and each Customer message and each reply the assistant sends is copied into that account as the conversation happens. The Instance's customer-facing privacy page discloses that for as long as the switch is on; keeping any privacy notice the Client publishes itself accurate is the Client's responsibility, as clause 16 already requires. Those records then rest in the Client's CRM account, on GoHighLevel's systems outside South Africa, for as long as the Client keeps them there. We cannot read, edit or delete them. Pausing or disconnecting the sync stops further copies but removes nothing already sent, and where an agency administers that CRM account for the Client, its access to that copy is a matter between the Client and that agency.

19. Retention, export, deletion and backups

Client Data is retained only for as long as necessary for the Service, the Client's instructions, legitimate operational requirements and applicable law. The Client remains responsible for any retention period required by its industry, professional rules or legal obligations, and clause 12.8 governs a Healthcare Instance.

On termination, the Client may request an export of available contacts, bookings and conversation records before deletion, which we will provide in a common machine-readable format. Unless law requires longer retention, the active Instance and its Client Data will ordinarily be scheduled for deletion within 30 days after the Service ends, except what we must keep for legal or bookkeeping purposes.

Backups are used for disaster recovery and are not an ordinary archive. The encrypted backup archives described in clause 15 are whole-server snapshots and cannot be edited to remove one Instance: deleted data may persist in them until the relevant rotation expires — the copies on the server age out of the 30-day rotation by themselves, and the off-site copies stay in that archive, encrypted and unreadable without our key. When a backup is restored, applicable deletion instructions will be re-applied where reasonably practicable.

Where the Client has connected its own CRM account, records already copied into it, conversation content included, are outside the Instance and beyond our reach: deleting the Instance does not remove them, and only the Client can delete them there (clause 18(c)).

20. Our own processing

For the Client's own account, billing, support and relationship information, In House It (Pty) Ltd t/a IndunAI acts as responsible party. We process that information to administer the contract, provide support, secure the Service, bill the Client, comply with law and manage our business in accordance with our Privacy Policy, and retain it for as long as the Client is a client plus the period bookkeeping and tax law requires (generally five years). PayFast processes card payments; we never see or store full card numbers.

21. Service levels and support

We aim to make the Service continuously available but do not guarantee uninterrupted or error-free operation. Planned maintenance, security work, third-party outages, connectivity failures and events outside our reasonable control may affect availability.

Support is available through angus@indunai.co.za and +27 76 786 4417 during reasonable South African business hours on Business Days, unless a different support level is included in the Client's plan.

22. IMPORTANT — risk notice and limitation of liability

THIS CLAUSE LIMITS INDUNAI'S LIABILITY, REQUIRES THE CLIENT TO ACCEPT CERTAIN RISKS ASSOCIATED WITH AI AND THIRD-PARTY PLATFORMS, AND MUST BE DRAWN TO THE CLIENT'S ATTENTION BEFORE THE AGREEMENT IS CONCLUDED WHERE SECTION 49 OF THE CPA APPLIES.

AI output can be wrong. Third-party platforms can suspend accounts, change APIs or experience outages. Automated bookings, communications and integrations can fail or behave unexpectedly. The Client must maintain reasonable human oversight appropriate to the consequences of an error.

To the maximum extent permitted by law:
(a) we are not liable for indirect, special or consequential loss, loss of profit, loss of opportunity or reputational loss;
(b) we are not liable for loss caused by Client-supplied inaccurate information, Client-approved marketing content, Client misuse, unlawful Client instructions, or a third-party platform outside our reasonable control;
(c) our aggregate contractual liability arising from the Service is limited to the Fees paid by the Client to us for the three months immediately preceding the event giving rise to the claim; and
(d) nothing excludes or limits liability for fraud, wilful misconduct, gross negligence as contemplated in section 51(1)(c) of the CPA, death or personal injury caused by negligence where liability cannot lawfully be excluded, or any other liability that cannot lawfully be excluded.

Where the CPA applies, this limitation must be interpreted in accordance with sections 48, 49, 51 and other applicable provisions of the CPA.

23. Indemnity

To the extent permitted by law, the Client indemnifies us against third-party claims, regulatory costs and reasonable expenses arising from the Client's unlawful content, unlawful direct marketing, breach of a connected platform's terms, Client Data the Client had no lawful basis to process, or the Client's breach of these Terms, except to the extent the claim was caused by our own breach, negligence or unlawful conduct.

Where the CPA applies, this clause is subject to the CPA and must be brought to the consumer's attention in the manner required by section 49.

24. Suspension, termination and force majeure

(a) We may suspend the Service for non-payment after any applicable grace period, a serious security risk, unlawful use, or a serious or persistent breach of these Terms. Where a remediable breach does not require immediate suspension, we will give reasonable notice and an opportunity to remedy it.
(b) The Client may cancel under clause 7. We may terminate a month-to-month Service for convenience on at least one calendar month's notice and will refund prepaid Fees relating to any period after the termination date.
(c) Neither party is liable for delay or failure caused by an event beyond its reasonable control, including major connectivity, hosting, cloud-platform, power (including load-shedding), natural-disaster or government disruptions, provided the affected party takes reasonable steps to mitigate the impact.
(d) Clauses intended by their nature to survive termination, including confidentiality, data protection, intellectual property, liability, dispute and payment provisions, continue after termination.

25. Notices and domicilium

IndunAI chooses 47 Moss Road, Ocean View, Durban, KwaZulu-Natal, 4052, South Africa as its domicilium citandi et executandi and angus@indunai.co.za as its electronic address for notices.

The Client chooses the physical and electronic addresses supplied in its account or order. Either party may change its chosen address by written notice, provided a physical domicilium remains in South Africa where required.

A data message satisfies a legal requirement for writing where ECTA permits it. An electronic signature or other electronic act is effective to the extent recognised by ECTA and applicable law. Nothing in these Terms deems every data message to be an advanced electronic signature where the law specifically requires one.

26. Disputes and governing law

These Terms are governed by the laws of the Republic of South Africa. The parties will first attempt in good faith to resolve a dispute by written notice and direct negotiation for up to 20 Business Days.

If unresolved, either party may approach a court with jurisdiction. Nothing prevents urgent interim relief or a complaint to the Information Regulator, National Consumer Commission or another competent regulator where applicable.

If the CPA applies, nothing in this clause limits a consumer's statutory right to pursue a remedy through an appropriate consumer-protection body or court.

27. General

Entire agreement. These Terms, the accepted order/proposal, the applicable pricing and any expressly incorporated addendum form the agreement and replace prior representations not recorded in them.
Order of precedence. If an accepted order expressly conflicts with these Terms, the order prevails only for the specific commercial term it changes. The POPIA and Healthcare clauses prevail for their subject matter unless a lawful written amendment expressly states otherwise.
Variation. A negotiated variation must be recorded in writing (including by data message) and accepted by authorised representatives. General updates to these Terms are governed by clause 28.
Severability. If a provision is unlawful or unenforceable, it is severed or limited to the minimum extent necessary and the remainder continues.
No waiver. A delay or indulgence does not waive a right.
Assignment. The Client may not transfer this agreement without our written consent, not to be unreasonably withheld. We may transfer it as part of a genuine sale, restructuring or transfer of the business providing the Service, subject to applicable data-protection law.
Interpretation. Headings are for convenience. The word "including" does not limit the general words that precede it. These Terms must be interpreted consistently with mandatory South African law.

28. Changes to these Terms

We may update these Terms for changes to the Service, law, security, providers or business operations. Material changes will be notified by email, dashboard notice or another reasonable channel at least 14 days before they take effect, unless a shorter period is reasonably required by law or an urgent security issue.

If the Client does not accept a material change to a month-to-month subscription, the Client may cancel before the change takes effect. Continued use after the effective date constitutes acceptance where legally permitted. The version date at the top always reflects the current text, and prior versions are available from us on request.

29. Electronic checkout acknowledgement

Before a consumer finally places an electronic order, the checkout allows the consumer to review the transaction, correct mistakes and withdraw before submission. The checkout also displays or links the price, recurring billing terms, these Terms, the Privacy Policy and the important risk notice in clause 22.

Where immediate activation is requested, the checkout separately records the Client's request for the Service to begin as soon as setup is complete.