These Terms of Service ("Terms") govern access to and use of the services provided by Vivid Algorithms W.L.L., a company registered in the Kingdom of Bahrain under Commercial Registration No. 191837-1, with registered address at Building No. 1913, Road No. 2124, Block No. 321, Al Gudaibiya, Kingdom of Bahrain ("Vivid", "we", "us", or "our").
By executing a Service Agreement, accessing the Services, or clicking to accept these Terms, you ("Client", "you") agree to be bound by these Terms, the Schedules attached, and the documents incorporated by reference.
PLEASE READ THESE TERMS CAREFULLY. THEY CONTAIN LIMITATIONS OF LIABILITY, DISCLAIMERS OF WARRANTY, AND OBLIGATIONS RELATING TO DATA PROTECTION THAT AFFECT YOUR LEGAL RIGHTS.
1. STRUCTURE OF THE AGREEMENT AND ORDER OF PRECEDENCE
1.1 Documents Forming the Agreement
The agreement between the parties (the "Agreement") consists of:
(a) the Service Agreement, Order Form, or Statement of Work executed by the parties (the "Service Agreement");
(b) any Addendum, side letter, or amendment executed by both parties;
(c) these Terms;
(d) Schedule A — Acceptable Use Policy;
(e) Schedule B — Support and Availability;
(f) Schedule C — Data Processing Addendum, including its Annexes;
(g) the Privacy Policy, as published at vividsystems.co; and
(h) the technical documentation made available within the Services or supplied to Client, as updated from time to time.
1.2 Order of Precedence
In the event of conflict or inconsistency, the documents govern in the following descending order of precedence:
- Any Addendum, side letter, or amendment executed by both parties, in respect of the subject matter it addresses;
- The Service Agreement;
- Schedule C (Data Processing Addendum);
- These Terms;
- Schedule A (Acceptable Use Policy) and Schedule B (Support and Availability);
- The Privacy Policy;
- The technical documentation.
1.3 No Other Terms
No purchase order, vendor portal terms, or other document issued by Client shall vary the Agreement, notwithstanding any provision in such document to the contrary and notwithstanding Vivid's acceptance of or performance under such document.
2. DEFINITIONS
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership of more than 50% of voting securities.
"Aggregated Data" means data derived from Client Data that has been (i) stripped of all direct and indirect identifiers of Client, Client's End Users, and Client's business, (ii) combined with data from other sources, and (iii) rendered such that it cannot reasonably be re-identified or attributed to Client or any End User by any means reasonably likely to be used. Aggregated Data does not include de-identified but client-attributable data.
"Authorized User" means an individual employee, contractor, or agent of Client whom Client authorizes to access the Services using unique credentials issued to that individual.
"Client Data" means all data, content, and information submitted to or collected through the Services by or on behalf of Client, including End User records, CRM data, behavioural data, and Outputs.
"Client-Specific Model" means a machine learning model or model instance trained exclusively on Client Data, used exclusively to generate Outputs for Client, and logically segregated from models serving any other client.
"End User" means a natural person who is a customer, patient, client, or prospect of Client and whose Personal Data is Processed through the Services.
"Output" means any prediction, risk score, segment assignment, confidence value, recommendation, or analytic result generated by the Services from Client Data.
"PDPL" means Law No. 30 of 2018 of the Kingdom of Bahrain with respect to Personal Data Protection, together with all implementing resolutions, orders, and decisions issued under it, as amended.
"PDPA" or "Authority" means the Personal Data Protection Authority of the Kingdom of Bahrain, whose functions are discharged by the Ministry of Justice, Islamic Affairs and Waqf.
"Personal Data", "Sensitive Personal Data", "Data Controller", "Data Processor", "Data Subject", and "Processing" have the meanings given in the PDPL.
"Platform Model" means any machine learning model, model architecture, weight set, feature definition, or algorithmic component that is used, or is capable of being used, to serve more than one client.
"Services" means Vivid's predictive customer retention platform as described in Section 3 and specified in the Service Agreement.
"Subscription Period" means the term specified in the Service Agreement.
"Vivid IP" means the Services, the platform software, Platform Models, Client-Specific Model architectures and code (but not Client Data or Outputs), APIs, documentation, trade marks, and all improvements and derivative works of the foregoing.
3. THE SERVICES
3.1 Description
Vivid provides a predictive customer retention platform that:
(a) analyses End User behavioural patterns to generate churn risk Outputs;
(b) enables Client to configure and dispatch automated messaging interventions to End Users;
(c) provides analytics dashboards with segmentation and retention reporting;
(d) integrates with Client's CRM systems, messaging platforms, and booking software; and
(e) provides API access for custom integrations.
3.2 Nature of Outputs — Decision Support Only
Outputs are probabilistic estimates derived from historical patterns. They are decision-support tools only. Vivid does not warrant any level of predictive accuracy. Accuracy varies materially by data quality, data completeness, cohort size, industry, seasonality, and business context, and past performance is not indicative of future performance.
3.3 Human Oversight Requirement (PDPL Article 22)
Client acknowledges that Outputs assess End Users in respect of matters including conduct and reliability, and that PDPL Article 22 confers on Data Subjects the right, where a decision is based solely on automated Processing intended to assess them in respect of performance at work, financial standing, credit-worthiness, reliability, or conduct, to request that the decision be reconsidered by means that are not solely automated, free of charge.
Accordingly, Client shall not:
(a) use Outputs as the sole basis for any decision that produces a legal effect or similarly significant effect on an End User, including refusal of service, denial or withdrawal of treatment or care, differential pricing, credit decisions, blacklisting, or account termination;
(b) deploy the Services in a configuration that removes meaningful human review from any such decision; or
(c) represent to any End User, regulator, or third party that Vivid is the decision-maker in respect of any such decision.
Client shall maintain a documented human review process for any decision materially informed by Outputs and shall handle all Article 22 reconsideration requests itself as Data Controller. Vivid shall provide reasonable technical assistance in accordance with Schedule C.
3.4 Modification of the Services
Vivid may modify or enhance the Services at any time. Vivid shall not materially degrade the core functionality described in the Service Agreement during a Subscription Period without Client's consent. Vivid shall give at least ninety (90) days' notice before deprecating any API version or discontinuing a material feature, except where a shorter period is required to address a security vulnerability, legal requirement, or third-party dependency failure outside Vivid's control.
3.5 Beta and Preview Features
Features designated as beta, preview, pilot, or early access are provided "AS IS", without warranty or service level commitment, may be discontinued at any time, and are excluded from Schedule B. Client uses such features at its own risk and shall not submit Sensitive Personal Data to them.
4. ACCOUNT, ACCESS, AND SECURITY
4.1 Eligibility
The Services are offered solely to business entities. Client represents that it is a duly constituted legal entity, that the individual accepting these Terms has authority to bind it, and that its registration information is accurate and complete.
4.2 Authorized Users
Access credentials are issued per individual and shall not be shared. Client shall:
(a) maintain an accurate register of Authorized Users;
(b) revoke access within twenty-four (24) hours of an Authorized User ceasing to require it, including on termination of employment;
(c) enable and enforce multi-factor authentication for all Authorized Users where the Services make it available; and
(d) ensure Authorized Users comply with the Agreement. Client is responsible for their acts and omissions as if they were its own.
4.3 Credential Security
Client is solely responsible for safeguarding account credentials, API keys, access tokens, and webhook secrets. Client shall notify Vivid at support@vividsystems.co within twenty-four (24) hours of discovering any actual or suspected compromise. Vivid may rotate or suspend credentials immediately where it reasonably believes they are compromised.
4.4 Usage Limits
The Services are subject to usage limits (including API rate limits) published in the technical documentation and, where applicable, specified in the Service Agreement. Vivid may throttle, queue, or suspend requests exceeding those limits. Sustained excess usage may be invoiced at Vivid's then-current overage rates on thirty (30) days' notice.
5. CLIENT DATA — OWNERSHIP, LICENCE, AND PERMITTED USE
5.1 Ownership
As between the parties, Client retains all right, title, and interest in and to Client Data, including all Outputs generated from it. Vivid claims no ownership of Client Data.
5.2 Licence Grant to Vivid
Client grants Vivid a limited, non-exclusive, non-transferable, royalty-free licence to host, copy, transmit, display, and Process Client Data solely to the extent necessary to provide the Services to Client, to perform its obligations under the Agreement, and to comply with law.
5.3 Model Training — Two-Tier Regime
This Section is the operative provision governing what Vivid may and may not do with Client Data in connection with machine learning.
(a) Client-Specific Models — Permitted as Core Service Delivery.
Vivid trains, retrains, tunes, and evaluates Client-Specific Models using Client Data. Client acknowledges that this is an inherent and inseparable part of the Services, that such models are logically segregated per client, and that no Client Data, Output, model weight, or learned parameter derived from Client Data is used to serve any other client. Client's instruction to Vivid to provide the Services constitutes its documented instruction to perform this Processing.
(b) Platform Models and Cross-Client Learning — Prohibited Absent Written Opt-In.
Vivid shall not use Client Data, Outputs, or any derivative of either to train, retrain, fine-tune, benchmark, evaluate, or otherwise improve any Platform Model, any multi-tenant model, any publicly available AI model, or any model owned or operated by a third party, unless Client has given prior specific written authorisation in the Service Agreement or a separate signed instrument. Such authorisation is opt-in, is not implied by use of the Services, and may be withdrawn on thirty (30) days' written notice.
(c) Aggregated Data.
Vivid may generate and use Aggregated Data (as strictly defined in Section 2) for capacity planning, security analytics, and reporting. Vivid shall not publish or disclose Aggregated Data in any form that identifies Client, any End User, or that could reasonably be re-identified. Where an Addendum prohibits the creation of Aggregated Data, that prohibition prevails.
(d) Third-Party AI Services.
Vivid shall not transmit Client Data to any third-party generative AI, large language model, or machine learning service that reserves rights to train on submitted data. Any third-party AI processor used by Vivid shall be listed as a Sub-Processor in Annex 3 to Schedule C and shall be contractually bound to a zero-retention, no-training commitment.
5.4 Prohibited and Restricted Data
(a) Prohibited Data. Client shall not submit to the Services:
- payment card data subject to PCI DSS, bank account numbers, or financial credentials;
- national ID numbers, CPR numbers, passport numbers, or other government identifiers, except where expressly permitted in the Service Agreement;
- biometric identifiers or data used for identity verification;
- Personal Data of any individual under eighteen (18) years of age, except under Section 5.5;
- data revealing racial or ethnic origin, political opinions, philosophical beliefs, religious beliefs, trade union membership, or criminal records;
- login credentials, private keys, or secrets belonging to any third party.
(b) Restricted Data — Health and Medical Data. Client shall not submit health, medical, treatment, diagnosis, prescription, or clinical data ("Health Data"), unless all of the following are satisfied and recorded in the Service Agreement or an executed Addendum:
- the Service Agreement expressly designates Client as a Health Data client and identifies the specific categories of Health Data in scope;
- Client has obtained the explicit consent of each End User to the Processing, or has established another lawful basis available under PDPL Article 5 for Sensitive Personal Data;
- Client has obtained, and provides Vivid with evidence of, any prior written authorisation of the Authority required under PDPL Article 15 in respect of automatic Processing of Sensitive Personal Data; and
- the enhanced controls set out in Annex 2 to Schedule C are in force.
(c) Consequences. If Client submits Prohibited Data, or Restricted Data without satisfying Section 5.4(b), Vivid may (i) delete or quarantine the data without liability, (ii) suspend the affected integration or the Services under Section 12.2, and (iii) require Client to certify remediation. Client shall notify Vivid within twenty-four (24) hours of becoming aware of any such submission. Client indemnifies Vivid under Section 11.1 in respect of all such submissions.
(d) Screening. Vivid may deploy automated screening to detect field patterns indicative of Prohibited Data. Client acknowledges that such screening is a reasonable-efforts control, is not a guarantee of detection, and does not transfer responsibility from Client to Vivid.
5.5 Minors
The Services are not designed for the Processing of children's data. Where Client's business necessarily involves End Users under eighteen (18) — including paediatric, dental, and family medical practices — Client shall (i) declare this in the Service Agreement, (ii) confirm that guardian consent has been obtained in accordance with the PDPL, and (iii) ensure no automated messaging intervention is dispatched to a minor directly rather than to their guardian. Absent such declaration, Client warrants that no data of minors is submitted.
5.6 Return and Deletion
On termination or expiry, and at any time on Client's written request in respect of specified data:
(a) Client may export Client Data via the Services or request an export in a structured, commonly used, machine-readable format within thirty (30) days;
(b) Vivid shall delete Client Data from active production systems within ten (10) business days of the later of the termination date and the expiry of any agreed export window, and shall decommission all Client-Specific Models;
(c) Encrypted backup and disaster recovery media: Client Data residing in encrypted backups is not immediately erasable without compromising the integrity of the backup set. Such data is logically isolated from production, is not accessible for Processing, and is overwritten on a rolling cycle not exceeding ninety (90) days, after which it is permanently and irretrievably deleted. Vivid's confidentiality and security obligations continue to apply to it throughout;
(d) Vivid shall issue a written certificate of destruction within ten (10) business days of completing production deletion, stating the categories deleted, the date of deletion, and the residual backup expiry date; and
(e) Vivid may retain Client Data where and for as long as required by applicable law, subject to continuing confidentiality and security obligations, and shall notify Client of the legal basis and duration where lawful to do so.
6. CONFIDENTIALITY
6.1 Definition
"Confidential Information" means non-public information disclosed by one party ("Discloser") to the other ("Recipient") that is designated confidential or that a reasonable person would understand to be confidential from its nature or the circumstances of disclosure. Client Data is Client's Confidential Information. Vivid IP, security architecture, pricing, and roadmap are Vivid's Confidential Information. The terms of the Agreement are the Confidential Information of both parties.
6.2 Obligations
Recipient shall (a) use Confidential Information solely to perform the Agreement, (b) protect it with no less than reasonable care and in no event less than the care it applies to its own confidential information of like importance, and (c) disclose it only to those of its personnel, Affiliates, professional advisers, and Sub-Processors who have a need to know and who are bound by written obligations no less protective than this Section.
6.3 Exclusions
The obligations do not apply to information that Recipient can demonstrate: (a) was public at disclosure or became public without breach; (b) was lawfully known to Recipient without duty of confidence before disclosure; (c) was lawfully received from a third party without duty of confidence; or (d) was independently developed without use of or reference to Confidential Information.
6.4 Compelled Disclosure
Recipient may disclose Confidential Information to the extent required by law, court order, or a lawful demand of a regulator or the Authority, provided that it (a) gives prompt written notice to Discloser unless legally prohibited, (b) discloses only the minimum required, and (c) reasonably cooperates, at Discloser's expense, with any effort to obtain protective treatment.
6.5 Duration
Obligations survive for five (5) years after termination of the Agreement, and indefinitely in respect of Personal Data and trade secrets for as long as the information retains that character under applicable law.
6.6 Publicity
Neither party shall use the other's name, marks, or logo in publicity, case studies, or client lists without prior written consent, which may be given in the Service Agreement and may be withdrawn on thirty (30) days' notice. Vivid may identify Client by generic industry descriptor (e.g. "a Bahrain-based medical centre") without consent.
7. DATA PROTECTION
7.1 Roles
In respect of End User Personal Data: Client is the Data Controller and Vivid is the Data Processor. Vivid Processes such Personal Data only on Client's documented instructions, as set out in Schedule C.
In respect of (a) Personal Data of Client's own Authorized Users used for account administration, security, and billing, (b) website visitor data, and (c) Aggregated Data, Vivid acts as Data Controller and Processes such data in accordance with the Privacy Policy.
7.2 Data Processing Addendum
Schedule C (Data Processing Addendum) forms part of the Agreement and applies to all Processing of Personal Data. It addresses Processing instructions, confidentiality of personnel, security measures, Sub-Processors, Data Subject rights assistance, breach notification, cross-border transfers, audit, and deletion.
7.3 Client's Controller Obligations
Client warrants and undertakes that it shall, throughout the Subscription Period:
(a) establish and document a lawful basis under the PDPL for all Processing it instructs, and obtain explicit consent where the PDPL requires it;
(b) provide End Users with all information required under PDPL Articles 17 and 18, including the fact that automated Processing generating churn and behavioural Outputs is carried out and that a third-party processor is engaged;
(c) obtain and maintain specific consent from each End User for the transfer of their Personal Data outside the Kingdom of Bahrain, or confirm to Vivid that the transfer is covered by a whitelisted jurisdiction or an authorisation of the Authority under PDPL Article 12;
(d) submit any notification required under PDPL Article 14 and obtain any prior written authorisation required under PDPL Article 15, including in respect of Sensitive Personal Data;
(e) handle all Data Subject requests and Article 22 reconsideration requests as Data Controller;
(f) obtain valid, documented, opt-in consent from each End User to receive automated messaging interventions on each channel used, and honour opt-out requests immediately; and
(g) not instruct Vivid to Process Personal Data in any manner that would cause Vivid to breach the PDPL.
7.4 Vivid's Right to Refuse Unlawful Instructions
Vivid may refuse, suspend, or cease any Processing instruction that it reasonably believes infringes the PDPL or other applicable law, and shall notify Client without undue delay. Such refusal is not a breach of the Agreement or of Schedule B, and does not entitle Client to any credit, refund, or damages.
7.5 Regulatory Cooperation
Each party shall notify the other without undue delay of any communication from the Authority, or any complaint or claim from a Data Subject, that relates to Processing under the Agreement, and shall provide reasonable cooperation in responding. Vivid shall not respond substantively to a Data Subject request relating to Client Data other than to direct the Data Subject to Client.
8. ACCEPTABLE USE AND MESSAGING COMPLIANCE
8.1 Acceptable Use Policy
Client shall comply, and shall procure that Authorized Users comply, with Schedule A (Acceptable Use Policy). Vivid may update Schedule A on thirty (30) days' notice; where an update materially and adversely restricts Client's permitted use, Client may terminate the affected Services without penalty within that period.
8.2 Messaging — Client Warranties
Automated interventions are configured, approved, and dispatched under Client's control and in Client's name. Client warrants that:
(a) it has documented, auditable, opt-in consent from each recipient for the channel used, obtained in compliance with the PDPL and the regulations of the Telecommunications Regulatory Authority of Bahrain on unsolicited commercial communications;
(b) all message content complies with applicable law, including advertising, consumer protection, and — where Client is a licensed healthcare provider — the advertising and patient-communication rules of the National Health Regulatory Authority (NHRA) and any applicable professional code;
(c) it complies with the business and commerce policies of each messaging platform used (including WhatsApp Business Messaging Policy and SMS aggregator terms), and holds all necessary sender registrations;
(d) every message includes a functioning, cost-free opt-out mechanism, and opt-outs are honoured across all channels within twenty-four (24) hours;
(e) message content does not disclose health information, appointment details, diagnosis, or treatment to any person other than the Data Subject or their authorised guardian; and
(f) it reviews and approves all message templates before activation.
Client is solely responsible for message content and for all consequences of dispatch. Vivid is a conduit and exercises no editorial control.
8.3 Suspension for Abuse
Vivid may immediately suspend messaging or the Services under Section 12.2 where it reasonably believes Client is in breach of this Section, where a messaging platform notifies Vivid of a policy violation, or where complaint rates exceed platform thresholds.
9. FEES AND PAYMENT
9.1 Fees
Client shall pay the fees in the Service Agreement. Fees are exclusive of VAT and all other taxes, duties, and withholdings, which are Client's responsibility. Where Client is required to withhold tax, Client shall gross up so that Vivid receives the full invoiced amount.
9.2 Invoicing and Payment
Invoices are payable within thirty (30) days of invoice date unless otherwise stated, in the currency specified, without set-off, counterclaim, deduction, or withholding.
9.3 Late Payment
Overdue amounts may accrue interest only at the rate expressly stated in the Service Agreement, subject to the maximum permitted by Bahraini law. If no rate is stated, Vivid may recover only interest and collection costs available under applicable law. Vivid may suspend access under Section 12.2 if payment is more than fifteen (15) days overdue, and may terminate under Section 12.3 if more than thirty (30) days overdue.
9.4 Fee Changes and Renewal
Unless the Service Agreement states otherwise, the Subscription Period renews automatically for successive periods of equal length. Vivid may change fees effective from the start of a renewal period on at least sixty (60) days' written notice. Either party may elect not to renew by written notice at least thirty (30) days before the end of the then-current Subscription Period.
9.5 Refunds
Fees are non-refundable except as expressly provided in Schedule B, in the Service Agreement, or where required by law. Termination by Client for convenience does not entitle Client to a refund of prepaid fees. Termination by Client for Vivid's uncured material breach entitles Client to a pro-rata refund of prepaid fees for the unused portion of the Subscription Period.
10. INTELLECTUAL PROPERTY
10.1 Vivid IP
Vivid retains all right, title, and interest in Vivid IP. No rights are granted except the licence in Section 10.2. For the avoidance of doubt, Vivid IP does not include Client Data or Outputs.
10.2 Licence to Client
Subject to the Agreement and payment of fees, Vivid grants Client a limited, non-exclusive, non-transferable, non-sublicensable, revocable licence to access and use the Services for Client's internal business purposes during the Subscription Period.
10.3 Restrictions
Client shall not, and shall not permit any third party to: reverse engineer, decompile, or disassemble the Services; extract, replicate, or derive model weights, parameters, feature definitions, or training methodology; access the Services to build a competing product; benchmark or publish performance results without Vivid's prior written consent; remove proprietary notices; or resell, sublicense, or provide the Services on a service-bureau basis.
10.4 Feedback
If Client provides feedback or suggestions, Vivid may use them without obligation or compensation. Client assigns all rights in such feedback to Vivid, provided that feedback shall not include, and Vivid acquires no rights in, Client Data or Client's Confidential Information.
11. INDEMNITIES
11.1 Client Indemnity
Client shall indemnify, defend, and hold harmless Vivid, its Affiliates, and their respective officers, directors, employees, and agents against all claims, liabilities, damages, losses, fines, penalties, and reasonable costs (including legal fees) arising from:
(a) Client Data, including any allegation that its collection, submission, or Processing was unlawful or without required consent;
(b) breach of Sections 5.4 (Prohibited and Restricted Data), 7.3 (Controller Obligations), or 8.2 (Messaging Warranties);
(c) message content or the dispatch of automated interventions;
(d) Client's use of Outputs, including any decision made in reliance on them;
(e) claims by End Users relating to privacy, consent, or unsolicited communications; and
(f) breach of Schedule A or violation of applicable law by Client or any Authorized User.
11.2 Vivid IP Indemnity
Vivid shall indemnify, defend, and hold harmless Client against third-party claims alleging that the Services, as provided by Vivid and used in accordance with the Agreement, infringe that third party's intellectual property rights, and shall pay damages finally awarded or amounts in settlement approved by Vivid.
Exclusions. Vivid has no obligation to the extent a claim arises from: (a) Client Data; (b) modification of the Services by anyone other than Vivid; (c) combination of the Services with products, data, or systems not provided or approved by Vivid; (d) use in breach of the Agreement; or (e) Client's continued use after notice to stop.
Remedies. If the Services are or may become subject to such a claim, Vivid may at its option procure the right to continue use, modify or replace the Services so they are non-infringing, or terminate the affected Services and refund prepaid unused fees. This Section states Vivid's entire liability and Client's exclusive remedy for intellectual property infringement.
11.3 Procedure
The indemnified party shall (a) promptly notify the indemnifying party in writing, (b) give the indemnifying party sole control of defence and settlement (provided no settlement imposing non-indemnified liability or admission of fault on the indemnified party is made without its consent, not to be unreasonably withheld), and (c) provide reasonable cooperation at the indemnifying party's expense.
12. WARRANTIES, DISCLAIMERS, SUSPENSION, AND TERMINATION
12.1 Warranties
(a) Mutual. Each party warrants that it is duly organised, has authority to enter into the Agreement, and shall comply with applicable law, including anti-bribery, anti-money-laundering, and sanctions laws.
(b) Vivid. Vivid warrants that (i) the Services will perform materially in accordance with the documentation, (ii) it will use commercially reasonable, industry-standard practices in providing the Services, (iii) it maintains the security measures in Annex 2 to Schedule C, and (iv) it will not knowingly introduce malicious code into the Services. Client's exclusive remedy for breach of (i) is Vivid's re-performance of the affected Services or, if Vivid cannot remedy within thirty (30) days, termination of the affected Services and a pro-rata refund.
(c) Client. Client warrants the matters set out in Sections 5.4, 7.3, and 8.2.
(d) Disclaimer. EXCEPT AS EXPRESSLY STATED, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE". TO THE MAXIMUM EXTENT PERMITTED BY LAW, VIVID DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE, THAT OUTPUTS WILL ACHIEVE ANY BUSINESS OUTCOME OR LEVEL OF ACCURACY, OR THAT AUTOMATED INTERVENTIONS WILL PREVENT CHURN.
12.2 Suspension
Vivid may suspend all or part of the Services immediately, with such notice as is reasonably practicable, where: (a) Client breaches Section 5.4, 8.2, or Schedule A; (b) continued provision poses a material security risk to Vivid, Client, or other clients; (c) payment is more than fifteen (15) days overdue; (d) required by law or by the Authority; or (e) a messaging platform or Sub-Processor requires it. Vivid shall restore the Services promptly once the cause is resolved. Suspension under (a)–(c) does not relieve Client of payment obligations and is excluded from Schedule B.
12.3 Termination
(a) For convenience. Either party may elect not to renew under Section 9.4.
(b) For material breach. Either party may terminate on thirty (30) days' written notice specifying a material breach, if the breach is not cured within that period.
(c) Immediate termination by Vivid. Vivid may terminate immediately on written notice if Client (i) breaches Section 5.4 in respect of Sensitive Personal Data or Section 10.3, (ii) engages in Processing that is unlawful under the PDPL, (iii) is subject to a direction of the Authority requiring cessation, or (iv) commits a breach incapable of cure.
(d) Insolvency. Either party may terminate immediately if the other becomes insolvent, enters liquidation or administration, or ceases to carry on business.
12.4 Effect of Termination
On termination: (a) all licences cease and access is revoked; (b) Section 5.6 (Return and Deletion) applies; (c) all accrued fees become immediately due; and (d) Sections 1, 2, 5.1, 5.6, 6, 9 (accrued), 10, 11, 12.4, 13, 14, and 15 survive, together with any provision that by its nature should survive.
13. LIMITATION OF LIABILITY
13.1 Exclusion of Indirect Damages
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, GOODWILL, ANTICIPATED SAVINGS, BUSINESS OPPORTUNITY, OR CUSTOMER RETENTION, HOWEVER ARISING, EVEN IF ADVISED OF THE POSSIBILITY.
13.2 Tiered Liability Caps
Subject to Section 13.3:
(a) General cap. Each party's total aggregate liability arising out of or relating to the Agreement shall not exceed the total fees paid or payable by Client under the Service Agreement in the twelve (12) months immediately preceding the first event giving rise to liability (the "General Cap").
(b) Enhanced cap for data protection and confidentiality. Notwithstanding (a), each party's total aggregate liability for breach of Section 6 (Confidentiality) or Schedule C (Data Processing Addendum), including regulatory fines imposed on the other party as a direct result of that breach, shall not exceed two (2) times the General Cap.
13.3 Exceptions to the Caps
Nothing in the Agreement limits or excludes liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; (c) wilful misconduct; (d) Client's payment obligations; (e) Client's indemnity under Section 11.1; (f) breach of Section 10.3 (IP restrictions); or (g) any liability that cannot lawfully be limited or excluded.
13.4 Allocation of Risk
The parties acknowledge that the limitations in this Section are an essential basis of the bargain and are reflected in the fees, and that they apply even if any limited remedy fails of its essential purpose.
13.5 Insurance
Where the Service Agreement requires insurance, Vivid shall maintain the specified coverage with reputable insurers and provide evidence of that coverage on reasonable request.
14. GOVERNING LAW AND DISPUTES
14.1 Governing Law
The Agreement is governed by the laws of the Kingdom of Bahrain, without regard to conflict of law principles.
14.2 Escalation
Before commencing proceedings, the parties shall attempt good-faith resolution through escalation to senior executives for a period of thirty (30) days from written notice of dispute. This does not prevent either party seeking urgent injunctive relief.
14.3 Jurisdiction
The courts of the Kingdom of Bahrain have exclusive jurisdiction. The parties may agree to arbitration only in an executed Service Agreement or Addendum.
15. GENERAL
15.1 Entire Agreement. The Agreement is the entire agreement and supersedes all prior discussions. Neither party has relied on any statement not set out in it, save that nothing excludes liability for fraudulent misrepresentation.
15.2 Amendment. Vivid may amend these Terms and the Schedules on thirty (30) days' written notice to Client. If an amendment is materially adverse to Client, Client may terminate the affected Services without penalty by notice within that period, and shall receive a pro-rata refund of prepaid fees. Provisions of an executed Addendum or Service Agreement may be amended only by written instrument signed by both parties.
15.3 Assignment. Neither party may assign without the other's prior written consent, except that either party may assign the Agreement in its entirety, on notice, to an Affiliate or in connection with a merger, acquisition, or sale of substantially all assets — provided that Client may object within thirty (30) days where the assignee is a direct competitor of Client, and may terminate without penalty.
15.4 Sub-contracting. Vivid may sub-contract performance but remains liable for its sub-contractors' acts and omissions. Sub-Processors are governed by Schedule C.
15.5 Severability. If any provision is held unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remainder continues in force.
15.6 Waiver. No failure or delay in exercising a right operates as a waiver. No waiver is effective unless in writing.
15.7 Force Majeure. Neither party is liable for failure to perform due to causes beyond its reasonable control, including natural disaster, war, terrorism, epidemic, labour dispute, government action, regional internet or utility failure, or failure of a third-party service provider — provided that this does not excuse payment obligations, and that a force majeure event continuing beyond sixty (60) days entitles either party to terminate on notice.
15.8 Notices. Notices must be in writing and sent to the addresses in the Service Agreement, with a copy to support@vividsystems.co for Vivid. Notice is deemed given on delivery if by hand, on receipt of confirmation if by email, or three (3) business days after posting. Notices of breach, termination, and indemnity claims must additionally be sent by registered post or courier.
15.9 No Third-Party Rights. No person other than the parties and their permitted successors has any right to enforce the Agreement.
15.10 Relationship. The parties are independent contractors. Nothing creates a partnership, joint venture, agency, or employment relationship.
15.11 Counterparts and Electronic Signature. The Agreement may be executed in counterparts and by electronic signature, each of which is an original.
15.12 Language. These Terms are executed in English, which governs between the parties to the fullest extent permitted by law. Any Arabic translation is for convenience unless an executed Service Agreement states otherwise or mandatory Bahraini law requires a certified Arabic text for a particular proceeding.
SCHEDULE A — ACCEPTABLE USE POLICY
Client and Authorized Users shall not:
- Submit data without a lawful basis, required consent, or authority.
- Submit Prohibited Data or, absent the conditions in Section 5.4(b), Restricted Data.
- Use the Services for spam, harassment, unsolicited communications, or any messaging to recipients who have not opted in or who have opted out.
- Send messages that are deceptive, defamatory, obscene, discriminatory, or that disclose an End User's health information to a third party.
- Use Outputs as the sole basis for consequential decisions about End Users, contrary to Section 3.3.
- Reverse engineer, decompile, or attempt to extract model weights, parameters, or training methodology.
- Circumvent rate limits, authentication, quotas, or access controls, or conduct penetration testing, vulnerability scanning, or load testing without Vivid's prior written consent.
- Resell, sublicense, white-label, or provide the Services on a service-bureau basis without written permission.
- Introduce malicious code, or interfere with the integrity, availability, or performance of the Services.
- Scrape, crawl, or bulk-extract data other than through documented APIs and export functions.
- Use the Services to compile profiles for sale to third parties, or to build a competing product.
- Impersonate any person or misrepresent affiliation, including in message sender identity.
- Use the Services in violation of applicable law, including PDPL, TRA regulations, NHRA rules, sanctions, and anti-money-laundering law.
Reporting: support@vividsystems.co. Vivid may suspend under Section 12.2 for violations.
SCHEDULE B — SUPPORT AND AVAILABILITY
B.1 Availability
Vivid uses commercially reasonable efforts to keep the dashboard and API available. Unless a Service Agreement expressly states a monthly uptime commitment, the Services are not subject to a guaranteed uptime percentage or service-credit regime.
Scheduled maintenance, emergency maintenance, Client systems or connectivity, third-party platforms, force majeure events, beta features, and suspension permitted by the Agreement are excluded from any separately agreed availability calculation.
B.2 Support
Support requests may be submitted to support@vividsystems.co. Vivid prioritises incidents by severity and uses commercially reasonable efforts to respond promptly. Binding response or resolution times apply only where stated in a Service Agreement.
B.3 Continuity
Vivid maintains backup and recovery procedures appropriate to the Services. Any committed recovery-time objective, recovery-point objective, or disaster-recovery testing obligation must be stated in the Service Agreement.
SCHEDULE C — DATA PROCESSING ADDENDUM
This Schedule applies where Vivid Processes Personal Data on Client's behalf and forms part of the Agreement. In the event of conflict between this Schedule and the body of the Terms in respect of Processing of Personal Data, this Schedule prevails.
C.1 Subject Matter and Roles
Client is Data Controller; Vivid is Data Processor. The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are set out in Annex 1.
C.2 Processing Instructions
Vivid shall Process Personal Data only on Client's documented instructions, being the Agreement, the configuration Client establishes in the Services, and any further written instruction accepted by Vivid. Provision of the Services in accordance with the Agreement — including training and retraining of Client-Specific Models under Section 5.3(a) — constitutes a documented instruction. Vivid shall inform Client if it considers an instruction to infringe the PDPL and may refuse under Section 7.4.
C.3 Confidentiality of Personnel
Vivid shall ensure that personnel authorised to Process Personal Data are subject to confidentiality obligations and are granted access on a least-privilege, need-to-know basis.
C.4 Security Measures
Vivid shall implement and maintain the technical and organisational measures in Annex 2. Vivid may update those measures provided the overall level of protection is not reduced.
C.5 Sub-Processors
(a) General authorisation. Client authorises Vivid to engage the Sub-Processors listed in Annex 3, each of which is bound by written terms imposing data protection obligations no less protective than this Schedule. Vivid remains fully liable for its Sub-Processors' performance.
(b) Changes. Vivid shall give at least thirty (30) days' notice before adding or replacing a Sub-Processor, by email to Client's notified data-protection contact. Client may subscribe to notices through support@vividsystems.co.
(c) Objection. Client may object on reasonable data protection grounds within the notice period. The parties shall discuss in good faith. If Vivid cannot offer a commercially reasonable alternative, Client may terminate the affected Services on notice and receive a pro-rata refund of prepaid unused fees, as its sole remedy.
(d) Specific authorisation. Where an Addendum requires Client's prior express written consent to disclosure to third parties, Annex 3 as countersigned by Client constitutes that consent for the listed Sub-Processors, and Vivid shall obtain fresh written consent before engaging any additional Sub-Processor in respect of that Client's data.
C.6 Data Subject Rights
Vivid shall, taking into account the nature of the Processing, provide reasonable technical and organisational assistance to enable Client to respond to Data Subject requests under the PDPL, including access, rectification, blocking, erasure, objection, portability, and Article 22 reconsideration.
Vivid shall acknowledge a request for assistance within one (1) business day and provide substantive assistance within five (5) business days.
Where a Data Subject contacts Vivid directly, Vivid shall not respond substantively but shall forward the request to Client without undue delay and direct the Data Subject to Client.
C.7 Personal Data Breach
(a) Notification. Vivid shall notify Client in writing within twenty-four (24) hours of discovering any Personal Data Breach affecting Client Data, being any unauthorised access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Client Data.
(b) Content. The notification shall describe, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and the contact point for further information. Where full information is not available within twenty-four (24) hours, Vivid shall provide an initial notification within that window and supplement it without undue delay.
(c) Cooperation. Vivid shall cooperate fully with Client and take all reasonable steps to mitigate and remediate, and shall provide the information Client reasonably requires to meet its own seventy-two (72) hour notification obligation to the Authority.
(d) No unilateral notification. Vivid shall not notify the Authority or any Data Subject of a breach affecting Client Data without Client's prior written consent, unless required by law, in which case Vivid shall notify Client first where lawful to do so.
(e) No admission. Notification under this Section is not an acknowledgement of fault or liability.
C.8 Cross-Border Transfers
(a) Vivid shall not transfer Personal Data outside the Kingdom of Bahrain except in accordance with PDPL Article 12 and as disclosed in Annex 4.
(b) Client acknowledges that PDPL Article 12 prohibits transfer of Personal Data outside Bahrain without the specific consent of the Data Subject, unless the destination is on a whitelist specified by ministerial decision or a special authorisation has been issued by the Ministry of Justice, Islamic Affairs and Waqf. Client, as Data Controller, is responsible for establishing the applicable lawful transfer mechanism and shall confirm it to Vivid in the Service Agreement.
(c) Vivid shall protect transfers in transit, apply contractual safeguards where appropriate, and provide Client with information reasonably necessary for its Article 12 assessment or authorisation application.
(d) Any alternative data-residency arrangement must be expressly documented in a signed Service Agreement and is subject to technical availability, fees, and feature limitations.
C.9 Audit and Assurance
(a) Vivid shall make available information reasonably necessary to demonstrate compliance with this Schedule, including a completed security questionnaire, a security-controls summary, and any current penetration-test summary, third-party audit report, or certification it holds.
(b) Client may, no more than once in any twelve (12) month period, on at least thirty (30) days' written notice, conduct an audit of Vivid's compliance with this Schedule. Audits shall: be conducted during business hours; not unreasonably disrupt operations; be subject to confidentiality obligations; be conducted by Client or an independent auditor who is not a competitor of Vivid; and not extend to any data, system, or premises of any other client.
(c) Client bears its own costs and Vivid's reasonable costs of supporting the audit, save where the audit reveals a material breach by Vivid, in which case Vivid bears its own costs and shall remediate at its expense.
(d) Vivid's provision of a current third-party audit report or certification satisfies (b) unless Client has reasonable grounds, notified in writing, to require a specific audit.
(e) Additional audits may be conducted following a Personal Data Breach or at the direction of the Authority, without regard to the frequency limit.
C.10 Deletion and Return
On termination, Section 5.6 applies, including the production/backup split and the certificate of destruction.
C.11 Records and Cooperation
Vivid shall maintain records of Processing carried out on Client's behalf sufficient to support Client's obligations under PDPL Article 14, and shall provide reasonable cooperation with Client's data protection impact assessments, notifications to the Authority, and applications for prior authorisation under PDPL Article 15.
C.12 Data Protection Contact
Vivid's data protection contact is support@vividsystems.co.
ANNEX 1 — DESCRIPTION OF PROCESSING
| Item | Detail |
|---|---|
| Subject matter | Provision of predictive customer retention analytics and automated messaging interventions |
| Duration | The Subscription Period, plus the deletion periods in Section 5.6 |
| Nature of Processing | Collection, storage, structuring, analysis, model training (client-specific only), scoring, segmentation, message dispatch, erasure |
| Purpose | Generating churn risk Outputs and delivering Client-configured retention interventions |
| Categories of Data Subjects | Client's customers, patients, and prospects; Client's employees whose details appear in operational records |
| Categories of Personal Data | Name; mobile number; email; appointment and booking history; visit and cancellation patterns; transaction history and payment timing; lifecycle stage; engagement and messaging metadata; service usage; Outputs (risk scores, segments, confidence values) |
| Sensitive Personal Data | None by default. For a Client expressly designated under Section 5.4(b), only the exact health-related categories listed in its signed Service Agreement or Addendum, such as appointment type, department, or treatment category |
| Excluded | Message content, except where Client expressly authorises its Processing in writing; Prohibited Data under Section 5.4(a) |
ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES
Access control: unique named accounts; role-based, least-privilege permissions; access revocation when no longer required; and no intentional credential sharing.
Transport and secrets: TLS for data in transit; credentials and secrets excluded from source control; restricted production access; and credential rotation following suspected compromise.
Tenant isolation: logical segregation through tenant-scoped application and database access controls. Client-Specific Models and Outputs are scoped to the relevant Client.
Application security: authenticated APIs; rate limiting where appropriate; input validation; parameterised database access; dependency review; peer-reviewed changes; and separate development, staging, and production environments.
Logging and monitoring: authentication, administrative, security, and application-event logging, with retention based on operational and legal need and normally not exceeding twelve (12) months unless an investigation or law requires longer.
Backup and recovery: automated backups and documented recovery procedures, with backup expiry not exceeding ninety (90) days unless a Service Agreement or legal obligation requires otherwise.
Incident response: documented escalation and response procedures, including the Client notification obligation in Section C.7.
Additional controls: multi-factor authentication, dedicated infrastructure, field-level encryption, enhanced audit reporting, and health-data-specific controls apply only where enabled or expressly stated in a signed Service Agreement or Addendum.
ANNEX 3 — SUB-PROCESSORS
The following providers may process data only for the stated service and only where the relevant feature is used:
| Sub-Processor | Purpose | Primary Location | Data Categories | Transfer Basis |
|---|---|---|---|---|
| Hostinger International Limited | Production infrastructure, compute, database storage, and backups | France | Client Data hosted in the Services | Bahrain Order No. 42 of 2022 adequacy list |
| Meta Platforms, Inc. and affiliates | WhatsApp and Instagram connection, message dispatch, delivery status, and media handling | United States and Meta's global infrastructure | Contact identifiers, message content and media, delivery metadata | Order No. 42 adequacy list for the United States; other lawful mechanism where required |
| OpenAI, L.L.C. | Optional AI assistance and transcription when configured and authorised | United States | Prompts, audio, and limited Client Data necessary for the enabled feature | Order No. 42 adequacy list |
| Anthropic, PBC | Optional AI assistance when configured and authorised | United States | Prompts and limited Client Data necessary for the enabled feature | Order No. 42 adequacy list |
| Google LLC | Sign-in, calendar integration, and email delivery where configured | United States and Google's global infrastructure | Authorized User identity, calendar data, email recipients and content | Order No. 42 adequacy list for the United States; other lawful mechanism where required |
| Resend, Inc. | Transactional email delivery where configured | United States | Email recipient, content, and delivery metadata | Order No. 42 adequacy list |
| Notion Labs, Inc. | Internal sales and onboarding workflow where configured | United States | Prospective-client and business-contact data | Order No. 42 adequacy list |
Vivid gives the notice required by Section C.5 before adding or replacing a Sub-Processor. A Client whose signed Addendum requires specific written consent must approve the applicable list before that provider processes its Client Data.
ANNEX 4 — CROSS-BORDER TRANSFERS
| Destination | Data Categories | PDPL Mechanism |
|---|---|---|
| France | Client Data hosted in the production platform and database | Country listed under Bahrain Order No. 42 of 2022 |
| United States | Data processed by the optional and integration providers listed in Annex 3 | Country listed under Bahrain Order No. 42 of 2022 |
| Any other destination used by a listed provider | Only the categories required for the enabled service | Authority authorisation, a statutory exception, or another mechanism permitted by the PDPL and documented before transfer |
Primary data residency: France. Feature-specific processing may occur in the locations disclosed in Annex 3.
END OF TERMS OF SERVICE
