NeoCore Platform Terms and Conditions
Enterprise terms governing access to and use of the NeoCore platform, the NeoCore APIs and the Neo 1 wearable device. Consumer use of Neo 1 is governed by the separate Neo 1 Terms and Conditions.
Data residency
Production conversation and transcript data is stored on India-resident servers.
ISO/IEC 27001 certified
Information security management system certified, awarded 19 September 2025.
No training on your data
Customer Data is never used to train, fine-tune or improve NeoSapien’s or third-party models.
Hard delete on request
Deletion is irreversible from production; backups purge within a maximum of 30 days.
15-day cure, 30-day notice
Either party may terminate for uncured material breach or for convenience on notice.
4-hour first response
Support first response within 4 business hours; resolution targets by severity.
The complete terms
1.Introduction and Scope
1.1These Terms and Conditions ("Terms") govern access to and use of NeoCore, the ambient conversational intelligence platform operated by ZenithZephyr Wellness Private Limited, trading as NeoSapien ("NeoSapien"), together with the NeoCore APIs, the administrative console, the Neo mobile application, and the Neo 1 wearable device where supplied (collectively, the "Service").
1.2These Terms apply to enterprise customers ("Customer"). The individual accepting these Terms represents that they have authority to bind the entity they represent.
1.3These Terms are supplemented by the documents listed in clause 1.4. Where a conflict arises, the following order of precedence applies, from highest to lowest:
- The executed Master Purchase Agreement or Master Services Agreement between the parties
- The executed Data Processing Agreement
- The Order Form, Individual Contract or Purchase Order
- The Service Level Agreement schedule
- These Terms
- The Documentation
1.4Use of the Neo 1 device by individual consumers outside an enterprise deployment is governed by the separate Neo 1 Terms and Conditions and not by these Terms.
1.5Continued use of the Service constitutes acceptance of these Terms. A Customer that does not accept these Terms must discontinue use of the Service.
2.Definitions
2.1The following definitions apply throughout these Terms.
| Term | Meaning |
|---|---|
| Customer Data | All audio captured through the Service, transcripts, memories, synthesised outputs, metadata and any other data submitted to or generated by the Service on the Customer’s behalf. |
| Personal Data | Has the meaning given under the Digital Personal Data Protection Act, 2023. |
| Data Fiduciary / Data Processor | Have the meanings given under the Digital Personal Data Protection Act, 2023. |
| Memory | A structured object generated by NeoCore from a captured conversation, comprising the full raw transcript and the synthesised outputs derived from it. |
| Tenant | The logically segregated environment within which the Customer’s data, users and configuration are held. |
| Wearer | An individual assigned a Neo 1 device and a corresponding user account under the Customer’s deployment. |
| Sub-processor | A third party engaged by NeoSapien to process Customer Data in the course of providing the Service. |
| Order Form | The order, purchase order or individual contract issued under the master agreement, setting out quantities, pricing, term, service levels and deployment-specific commitments. |
| Documentation | The NeoCore API documentation, the Postman collection, the Enterprise FAQ and any technical materials issued by NeoSapien to the Customer. |
2.2Words in the singular include the plural and vice versa. Headings are for convenience only and do not affect interpretation.
3.Accounts, Authentication and Access Control
3.1Access to the Service requires a NeoSapien account. Each Neo 1 device pairs one-to-one with a single user account, identified by email address or mobile number. The device cannot operate as a shared or unassigned asset.
3.2The Service supports single sign-on, OpenID Connect and multi-factor authentication. Role-based access control governs which administrators and analysts can view which users’ memories, scoped to an individual user, a group of users or the whole organisation.
3.3API access uses JWT-based token authentication. The Customer may issue scoped credentials per integration, per environment and per service principal, and may rotate or revoke those credentials at any time.
3.4Session timeout is set at a standard platform value and is not configurable per tenant as at the effective date of these Terms.
3.5The Customer is responsible for the security of its credentials, for the accuracy of its user-to-device assignments, and for de-provisioning users who leave its organisation. Credentials must not be shared.
3.6A lost or stolen device may be deactivated on the Customer’s report, revoking its access and unbinding it from the user account. The Customer must report lost or stolen devices promptly.
4.Licence and Restrictions
4.1NeoSapien grants the Customer a non-exclusive, non-transferable, non-sublicensable and revocable licence to access and use the Service for its internal business purposes for the term set out in the Order Form.
4.2The Customer shall not, and shall not permit any third party to:
- Reverse engineer, decompile or disassemble any part of the Service, or attempt to derive the models, weights or source code underlying it
- Resell, sublicense or make the Service available to any third party other than as permitted in the Order Form
- Circumvent rate limits, quotas, authentication controls or tenant boundaries
- Conduct penetration testing, vulnerability scanning or load testing against the Service without NeoSapien’s prior written agreement on scope and timing
- Attempt bulk or automated extraction of data beyond the volumes contemplated by the Order Form
- Use the Service for any unlawful purpose, or in any deployment where capture is prohibited by law or by the policy of the site of deployment
- Use the Service to infringe the intellectual property rights or privacy rights of any person
4.3NeoSapien applies rate limiting, anomaly detection and data-loss prevention controls to identify mass extraction attempts. Activity that breaches clause 4.2 may result in suspension under clause 22.
5.Recording, Notice and Consent
5.1The Service captures ambient conversation in the environment of the Wearer. The Customer determines the purpose and means of that capture and is the Data Fiduciary in respect of all Personal Data processed through the Service.
5.2The Customer is responsible for:
- Providing notice to, and obtaining any consent required from, Wearers and any third party whose speech may be captured
- Ensuring that consent is obtained prior to each interaction where the deployment design or applicable law requires it, with capture paused until consent is taken
- Instructing Wearers on the device status indicator and on the double-tap control that disables capture
- Restricting deployment in locations or contexts where capture is prohibited
- Determining the lawful basis for capture in each jurisdiction in which it deploys the Service
5.3Capture can be disabled at device level by the Wearer. Selective disabling based on meeting classification is not available as at the effective date of these Terms, and disabling of transcript download as a discrete control is not available.
5.4NeoSapien does not verify the adequacy of the Customer’s notice or consent arrangements and accepts no liability for capture undertaken without a lawful basis.
6.Description of the Service
6.1Audio is captured on the Neo 1 device and streamed over mobile data, through a paired smartphone, to the NeoCore cloud. Transcription, speaker diarization and synthesis are performed cloud-side. Raw audio is processed transiently and is not retained by default.
6.2Each Memory includes the full raw transcript, providing traceability from a synthesised output back to its source content.
6.3Memories are associated with the user account of the Wearer, not with a device serial number. The memory payload returns the user ID. The Customer maintains its own mapping from user to device to physical asset.
6.4The Service is delivered on a multi-tenant cloud architecture with documented logical segregation. Dedicated tenancy may be agreed under the master agreement.
6.5The functional boundaries and documented limitations of the Service are set out in Annexure D. The Customer acknowledges that it has reviewed Annexure D and has sized its deployment accordingly.
7.Customer Data and Ownership
7.1The Customer retains all right, title and interest in Customer Data. No intellectual property or ownership right in Customer Data transfers to NeoSapien under these Terms.
7.2The Customer grants NeoSapien a limited licence to process Customer Data solely for the purpose of providing the Service, and for no other purpose.
7.3Captured audio, transcripts and processed outputs are used solely to provide the Service to the Customer, in accordance with applicable data protection, confidentiality and contractual obligations.
7.4The Customer is responsible for the content of the conversations captured through its deployment, including any sensitive business information, proprietary information or trade secrets that the ambient environment may contain.
8.Data Protection and Roles under the DPDP Act
8.1For deployments processing Personal Data, the Customer acts as Data Fiduciary and NeoSapien acts as Data Processor. This allocation of roles is not varied by any other document unless expressly agreed in writing.
8.2A Data Processing Agreement is executed alongside the master agreement before production data flows through the platform. The Data Processing Agreement governs processing instructions, breach notification timelines, sub-processing, deletion on termination and assistance with data principal rights.
8.3NeoSapien supports the Customer’s obligations as Data Fiduciary through:
- Detection and redaction of personally identifiable information and personal, non-work conversations within the processing pipeline
- Granular memory deletion and correction endpoints, and bulk user-level and tenant-level deletion through the administrative API
- User-bound retrieval endpoints supporting access requests
- Configurable tenant lifecycle policies supporting defined retention windows
8.4Keyword-based masking of specific identifiers nominated by the Customer is configured during onboarding where agreed in the Order Form.
8.5NeoSapien has not completed a Data Protection Impact Assessment as at the effective date of these Terms. Formal DPDP Act compliance work is in progress. NeoSapien is certified to ISO/IEC 27001 for information security management, certificate awarded 19 September 2025.
9.Data Residency and Cross-Border Transfer
9.1Production conversation and transcript data is stored on India-resident servers. All recovery, failover and backup arrangements operate within that residency boundary.
9.2NeoSapien shall not transfer or permit access to Customer Data outside India unless all of the following conditions are met:
- The transfer is strictly necessary for providing the Service
- Prior written approval is obtained from the Customer
- Adequate transfer mechanisms and safeguards are implemented, including standard contractual clauses, onboarding to jurisdictions with adequate protection status, or equivalent legal safeguards
9.3Certain AI features are delivered using frontier large language models operated by third-party providers. Where inference for those features is performed on infrastructure outside India, the arrangement is disclosed to the Customer and is subject to clause 9.2. The Customer should not treat India-only processing as absolute across every feature of the Service without confirming the feature set in the Order Form.
9.4NeoSapien maintains records of all approved cross-border transfers and provides them to the Customer on request.
9.5Specific cloud regions and the identity of the hosting sub-processor are available to the Customer under non-disclosure agreement.
10.Retention, Deletion and Return
10.1Retention periods applicable to each category of data are set out in Annexure B.
10.2The Customer may request deletion or return of any raw or processed data at any time. NeoSapien complies within the timelines prescribed under applicable law and the executed agreement.
10.3Deletion is a hard delete. Data is irreversibly purged from production databases and from the vector store. Copies held in backup and disaster recovery systems are purged within a maximum of 30 days.
10.4On expiry or termination of the agreement, Customer Data is deleted or returned in line with the timelines specified in the Data Processing Agreement. A certificate of deletion is provided on request.
10.5Custom retention windows, for example 90 days, one year or seven years, are implemented through tenant lifecycle policies where agreed in the Order Form. Absent a configured window, transcripts and memories are retained until a deletion request is raised.
11.Security
11.1NeoSapien maintains an information security management system certified to ISO/IEC 27001, certificate awarded 19 September 2025. All information security policies and standards have been reviewed within the last 12 months. Security awareness training is mandatory for all employees.
11.2All API traffic is carried over TLS. Data at rest is encrypted using AES-256. Databases and backups are encrypted at rest and in transit.
11.3Encryption keys are managed by NeoSapien under a shared master key structure. Customer-managed keys and bring-your-own-key configurations are not supported.
11.4Identity and access management, role-based access control and multi-factor authentication are enforced at the application layer. There is no separately exposed backup environment; backups reside within restricted cloud infrastructure accessible only to authorised personnel.
11.5Security events are logged and centrally aggregated. Logs are tamper-proof and retained for 30 days by default, extendable where agreed in the Order Form.
11.6Independent vulnerability assessment and penetration testing is commissioned from an external agency on a fixed bi-annual cadence. Scope covers the platform, the API and the mobile application. Executive summaries are made available to the Customer under non-disclosure agreement.
11.7Issues identified through code review, vulnerability scanning and penetration testing are remediated before release into production. Known un-remediated vulnerabilities are communicated to the security monitoring function for awareness and monitoring.
11.8Continuous 24x7 security monitoring and a dedicated security operations centre are not in place as at the effective date of these Terms. First response is within 4 hours during business hours. Network segmentation is not implemented as at the effective date.
11.9A summary of the security control position is set out in Annexure A.
12.AI Processing and Use of Customer Data for Training
12.1NeoCore uses a fine-tuned proprietary Small Language Model for synthesis and knowledge-graph creation, transcription and diarization models, and embedding models feeding a vector database for semantic retrieval. Certain features are delivered using frontier large language models operated by third-party providers.
12.2Customer Data, including captured audio, transcripts, prompts, generated outputs and device telemetry, is not used to train, fine-tune or improve NeoSapien’s models or any third-party model. This commitment is binding and is restated in the Data Processing Agreement.
12.3Prompt history, contextual data and vector embeddings are scoped to the originating tenant and are not shared across tenants. Each request is processed within the authenticated user’s tenant context. No cross-user context is shared.
12.4Model updates undergo internal validation before promotion to production. Model output quality and drift are monitored internally.
12.5NeoSapien is not certified to ISO/IEC 42001 and does not operate a formal AI risk management framework certified to an external standard as at the effective date of these Terms.
13.AI Output Limitations and Human Review
13.1Transcripts, summaries and synthesised outputs are provided on an "as is" basis. They are not medical-grade and are not suitable for clinical, diagnostic or therapeutic decisions, or for other regulated workflows, without human review.
13.2The Customer is responsible for reviewing and validating outputs before use in any decision carrying legal, regulatory, employment or safety implications.
13.3Documented accuracy boundaries, including diarization accuracy, latency distribution and language validation, are set out in Annexure D. The Customer acknowledges that AI-generated outputs may contain errors and that performance should be validated during a pilot in the Customer’s own operating environment.
13.4Outputs must not be used as the sole basis for disciplinary action against any Wearer without independent human verification of the underlying transcript.
14.Sub-processors
14.1NeoSapien engages third-party services in the platform stack, including cloud hosting and third-party model providers. Each such sub-processor meets SOC 2 standards. The specific list of sub-processors is available to the Customer under non-disclosure agreement.
14.2NeoSapien as an entity does not hold a SOC 2 attestation. SOC 2 compliance stated in relation to the Service refers to platform sub-processors, not to NeoSapien. NeoSapien’s own certification is ISO/IEC 27001.
14.3Where the executed agreement so requires, NeoSapien shall not engage any sub-processor to process Customer Data without the Customer’s prior written consent.
14.4Every sub-processor is bound by written obligations no less stringent than those set out in the master agreement. NeoSapien remains fully liable for the acts, omissions and defaults of any approved sub-processor.
15.Audit and Assurance
15.1The Customer, or an auditor designated by the Customer, may conduct audits or inspections on reasonable prior notice and during normal business hours to verify NeoSapien’s compliance with its obligations.
15.2NeoSapien provides access to the relevant systems, facilities, personnel, processing records and security documentation necessary for such audit, and shall promptly address any non-compliance or gap identified, at its own cost.
15.3The assurance artefacts available to the Customer are listed in Annexure E.
15.4NeoSapien is not subject to sector-specific regulatory audit in respect of its current operations. The principal external assessments are the ISO/IEC 27001 certification and the bi-annual independent VA&PT.
16.Incident Management and Breach Notification
16.1NeoSapien notifies the Customer of any actual or suspected data breach, security incident, unauthorised access or compromise involving Customer Data as soon as it is made aware of the incident. The specific notification timeframe is set out in the Data Processing Agreement.
16.2NeoSapien maintains incident response and escalation procedures based on severity. A post-incident report including root cause analysis is provided for material incidents affecting the Customer’s tenant, within the timeframe set out in the Data Processing Agreement.
16.3As Data Fiduciary, the Customer remains responsible for onward notification to regulators and data principals under applicable law. NeoSapien provides the information and assistance required to support that process.
16.4The named contact for cybersecurity incidents is Husain Bohra, Product Manager, husain@neosapien.xyz, +91 9700753000.
16.5As at the effective date of these Terms, NeoSapien has not encountered or been investigated for any data breach incident involving personal data in the preceding three-year period.
16.6Vulnerability remediation service levels for critical and high severity findings, and the emergency patch process, are set out in the SLA schedule.
17.Availability, Support and Maintenance
17.1Observed platform uptime is greater than 99%. The target uptime commitment applicable to the Customer, the measurement methodology and any service credit structure are set out in the SLA schedule to the Order Form. No uptime commitment applies except as stated in that schedule.
17.2Enterprise support is provided over the channels named in the Order Form, with a named technical point of contact assigned at onboarding and a designated ticketing tool where agreed.
17.3First response is within 4 hours during business hours. Resolution targets vary by severity and are set out in Annexure C and in the SLA schedule.
17.4Scheduled maintenance windows and active incidents are communicated through the Customer’s named support channel. A public status page is not published as at the effective date of these Terms.
17.5Memory synthesis is not dependent on the availability of the Customer’s integration. Where the Customer’s integration cannot reach the API for a period, memories synthesised during that window remain retrievable through the sync endpoint once the integration recovers.
18.Business Continuity and Disaster Recovery
18.1NeoSapien maintains a documented business continuity and disaster recovery plan covering the NeoCore platform and the Neo 1 hardware supply chain. The plan is available to the Customer under non-disclosure agreement.
18.2Recovery objectives, including recovery time objective and recovery point objective, are defined by event class in that plan. First response is within 4 hours; recovery time depends on the severity of the event.
18.3Backups are encrypted in transit and at rest and are retained for a maximum of 30 days.
18.4Formal disaster recovery simulations and tabletop exercises have not been conducted as at the effective date of these Terms. A disaster recovery testing programme is being established.
19.API and Integration Terms
19.1The NeoCore API is authenticated using JWT tokens with a configurable lifetime. On expiry the API returns an error and the integration should request a new token and retry, following the standard refresh pattern.
19.2Default rate limits are sized to support routine polling and high-concurrency multi-site deployments. Specific limits and burst allowances are documented per tenant. The Customer shall share its expected call patterns during onboarding.
19.3Webhooks are supported as event notifications on memory creation. The memory payload is not pushed in the webhook; the Customer’s server fetches the memory through the API.
19.4A formal API versioning and deprecation policy is not published as at the effective date of these Terms. In practice, advance notice of changes is provided between two weeks and one month ahead, with backward compatibility maintained for a defined window. Enterprise customers receive direct communication of any change affecting their integration.
19.5The API specification is provided as a Postman collection. A formal OpenAPI export is not published. No separate sandbox environment with synthetic data is available; integration development is performed against the production API using a device linked to the Customer’s organisation, with test memories deleted before go-live.
19.6No dedicated device management API is exposed. User-to-device assignment is performed through the administrative console.
20.Neo 1 Device Terms
20.1This clause applies where Neo 1 devices are supplied under the Order Form.
20.2Each device carries a limited hardware warranty of twelve months from the date of delivery against material defects, subject to the terms of the master agreement. The warranty covers repair or replacement at NeoSapien’s cost.
20.3The warranty does not cover misuse, unauthorised modification, damage from accident or natural event, or operation outside intended conditions. The device carries no ingress protection rating and is not warranted against water or dust exposure.
20.4Replacement volumes, defective rate thresholds, dead-on-arrival handling and replacement turnaround are as stated in the Order Form. Where the Order Form states a replacement cap, that cap applies and no unlimited replacement entitlement arises.
20.5Firmware is updated over the air during cloud connectivity. Updates are integrity-checked using a SHA-256 hash before being applied, with automatic rollback on failure. Firmware binaries are not cryptographically signed as at the effective date of these Terms. Customers are notified of material firmware changes in advance through the support channel.
20.6The device requires continuous mobile data connectivity to capture conversations. There is no local memory buffer. Conversations occurring while the device is offline are not captured.
20.7The device does not implement a trusted execution environment, secure element or hardware-based secure boot, and does not provide physical or logical tamper detection. No persistent conversational data is stored on the device.
20.8Battery life is rated at up to 17 hours of continuous use on a single charge. Heavy continuous capture in noisy or high-activity environments reduces this. Deployment-specific battery commitments, where given, are stated in the Order Form.
21.Fees, Invoicing and Taxes
21.1Fees, payment milestones and payment terms are as set out in the Order Form.
21.2All fees are exclusive of goods and services tax and other applicable taxes, which are payable by the Customer at the prevailing rate. NeoSapien shall comply with the GST legislation, including accurate HSN and SAC coding on every invoice.
21.3Undisputed invoices are payable within the period stated in the Order Form. Disputed invoices are settled by mutual reconciliation, with the settled amount payable within the period stated in the Order Form from the date of resolution.
21.4NeoSapien may revise prices for subsequent Order Forms on prior written notice. Prices agreed in an executed Order Form remain binding for the term of that Order Form.
22.Term, Suspension and Termination
22.1The term of the Service is as stated in the Order Form.
22.2NeoSapien may suspend access, in whole or in part, on notice, where the Customer is in material breach of clause 4 or clause 5, where continued access presents a demonstrable security risk, or where undisputed fees remain unpaid beyond the period stated in the Order Form. NeoSapien shall restore access promptly on remedy.
22.3Either party may terminate for material breach if the breach is not cured within fifteen days of written notice. Either party may terminate for convenience on the notice period stated in the Order Form.
22.4Either party may terminate immediately if the other party becomes insolvent, is wound up, or is unable to continue performing its obligations.
22.5On expiry or termination the Customer’s right to access the Service ceases, Customer Data is deleted or returned under clause 10, and all outstanding fees for services delivered up to the termination date become payable.
22.6Clauses 7, 8, 10, 14, 16, 23, 24, 26, 27, 28 and 31 survive expiry or termination.
23.Confidentiality
23.1Each party shall protect the other’s confidential information with no less than reasonable care, shall use it only for the purpose of performing under these Terms, and shall disclose it only to personnel with a need to know who are bound by equivalent obligations.
23.2Confidential information does not include information that is public at the time of disclosure, becomes public without breach, was already lawfully in the recipient’s possession, was independently developed without access, or was lawfully received from a third party.
23.3Where disclosure is required by law, regulation or court order, the recipient may disclose only the part specifically required and shall notify the disclosing party in advance where legally permitted.
23.4Confidentiality obligations continue for three years after expiry or termination.
23.5On termination or on written request, the recipient shall return or destroy confidential information and copies, in accordance with the disclosing party’s instructions.
24.Intellectual Property
24.1NeoCore, the Neo 1 device, and all associated software, models, designs, trademarks, documentation and content are the intellectual property of NeoSapien. All improvements, derivative works and enhancements to the Service remain owned by NeoSapien.
24.2Nothing in these Terms transfers any ownership or intellectual property right in Customer Data to NeoSapien.
24.3Where the Customer provides feedback or suggestions relating to the Service, and that feedback does not incorporate Customer Data or Customer confidential information, NeoSapien may use it without restriction or obligation.
24.4Neither party may use the other’s trademarks, trade names or logos without prior written consent. Use of the Customer’s name or logo in NeoSapien marketing materials requires prior written approval.
24.5NeoSapien warrants that the Service does not infringe the intellectual property rights of any third party, and shall defend and indemnify the Customer against claims to the contrary in accordance with clause 28.
25.Warranties
25.1NeoSapien warrants that it has the authority and the necessary rights and licences to perform its obligations, that the Service will be performed with reasonable skill and care, and that it will not knowingly introduce malicious code into the Customer’s environment.
25.2Device-specific warranties are set out in clause 20. Performance commitments specific to a deployment, including transcription accuracy for a defined language set, apply only where expressly stated in the Order Form.
25.3The Customer warrants that it has the authority to enter into these Terms, that it has a lawful basis for the capture and processing it directs, and that its use of the Service complies with all applicable laws and regulations.
26.Disclaimer
26.1Except for the express warranties in clauses 20 and 25, the Service is provided "as is" without warranties of any kind, express or implied, including warranties of merchantability, fitness for a particular purpose and non-infringement.
26.2NeoSapien does not warrant that the Service will be uninterrupted or error-free, that transcription, diarization or synthesised outputs will be complete or accurate, or that the Service will meet requirements not stated in the Order Form.
26.3Any performance figure stated in the Documentation, including latency, accuracy and uptime observations, is an operational observation and not a contractual commitment unless restated in the Order Form or the SLA schedule.
27.Limitation of Liability
27.1Neither party is liable for indirect, incidental, special, punitive or consequential damages, or for loss of profit, revenue, goodwill or anticipated savings, arising out of or in connection with these Terms.
27.2The total aggregate liability of each party under these Terms shall not exceed the fees paid or payable by the Customer under the relevant Order Form in the preceding six months.
27.3The limitations in clauses 27.1 and 27.2 do not apply to breach of confidentiality obligations, breach of data protection obligations, the intellectual property indemnity under clause 28, wilful misconduct, or fraud.
28.Indemnification
28.1NeoSapien shall defend, indemnify and hold the Customer harmless against claims that the Service infringes the intellectual property rights of a third party, and shall at its own cost procure the right to continue use, modify the Service to make it non-infringing, or replace it.
28.2The Customer shall defend, indemnify and hold NeoSapien harmless against claims arising from capture undertaken without a lawful basis or without required notice or consent, from the content of conversations captured through its deployment, from its use of AI outputs in breach of clause 13, and from its breach of clause 4 or clause 5.
28.3Each indemnity is a continuing obligation, is independent of the other obligations under these Terms, and survives termination.
29.Force Majeure
29.1Neither party is liable for delay or failure in performance caused by an event beyond its reasonable control, including natural disaster, war, terrorism, riot, act of government, epidemic, power failure, or failure of public telecommunications networks.
29.2The affected party shall notify the other in writing within five working days of the event, including the anticipated duration. Where performance is wholly suspended for two consecutive months, the unaffected party may terminate on written notice.
30.General
30.1The Customer may not assign these Terms without NeoSapien’s prior written consent. NeoSapien may not assign without the Customer’s prior written consent, except to an affiliate or in connection with a merger, acquisition or sale of substantially all of its assets.
30.2Notices must be in writing and delivered to the address or named contact stated in the Order Form.
30.3The parties are independent contractors. Nothing in these Terms creates a partnership, joint venture, employment or agency relationship.
30.4No failure or delay in exercising a right operates as a waiver of that right.
30.5If any provision is held invalid or unenforceable, the remaining provisions continue in force and the parties shall replace the invalid provision with one of equivalent intent.
30.6NeoSapien may update these Terms. Material changes are communicated by email or in-app notification not less than thirty days before they take effect. Continued use after the effective date of a change constitutes acceptance. Where a change materially reduces the Customer’s rights, the Customer may terminate the affected Order Form on written notice within thirty days.
30.7These Terms, together with the documents listed in clause 1.3, constitute the entire agreement between the parties on this subject matter and supersede all prior negotiations and understandings.
30.8These Terms are executed in English, which governs in all respects.
31.Governing Law and Dispute Resolution
31.1These Terms are governed by the laws of India.
31.2Any dispute shall first be addressed through good-faith discussion between the parties. Where the dispute is not resolved within sixty days of written notice, it shall be referred to and finally settled by arbitration under the Arbitration and Conciliation Act, 1996, before a sole arbitrator appointed by mutual agreement, seated in Bangalore, India, conducted in English.
31.3The award is final and binding. The courts at Bangalore have exclusive jurisdiction in respect of any application for injunctive or interim relief.
31.4The parties shall continue to perform their obligations during the pendency of any dispute.
Annexure A: Security Control Position
Position as at the effective date of these Terms. Supporting evidence is available under non-disclosure agreement.
| Control area | Position | Detail |
|---|---|---|
| Certification | In place | ISO/IEC 27001, certificate awarded 19 September 2025. NeoSapien entity does not hold SOC 2. Platform sub-processors meet SOC 2. |
| Encryption in transit | In place | TLS across all API traffic and mobile-to-cloud paths. |
| Encryption at rest | In place | AES-256 across databases, vector store and backups. |
| Key management | Vendor-managed | Shared master key structure. CMK and BYOK not supported. Per-tenant dedicated keys not used. |
| Tenant segregation | In place | Multi-tenant with documented logical segregation. RBAC enforced at API layer. |
| Identity and access | In place | SSO, OIDC, MFA, RBAC, scoped JWT credentials with customer-controlled rotation. |
| Session timeout | Standard | Platform-wide value. Not tenant-configurable. |
| Logging and monitoring | In place | Centralised aggregation and monitoring. Tamper-proof logs, 30-day default retention, extendable. |
| 24x7 monitoring | Not in place | No dedicated security operations centre. First response within 4 hours during business hours. |
| Network segmentation | Not in place | Not implemented as at the effective date. |
| Penetration testing | In place | Bi-annual independent VA&PT by external agency, covering platform, API and mobile application. |
| Secure development | In place | Threat modelling, secure coding, code review and pre-production security review. Findings remediated before release. |
| Backup security | In place | Encrypted in transit and at rest. No separately exposed backup environment. |
| DR testing | Not in place | Formal DR simulations and tabletop exercises not yet conducted. Testing programme being established. |
| Device security | Limited | No TEE, secure element or hardware secure boot. OTA integrity-checked by SHA-256 with rollback, not cryptographically signed. No tamper detection. |
Annexure B: Data Categories, Retention and Deletion
| Data category | Default retention | Configurable | Deletion mechanism |
|---|---|---|---|
| Raw audio | Not retained. Processed transiently and discarded after transcription. | Short-term retention only by separate written arrangement | Not applicable |
| Transcripts | Indefinite until deletion request | Yes, via tenant lifecycle policy (e.g. 90 days, 1 year, 7 years) | Hard delete from production database and vector store |
| Memories and synthesised outputs | Indefinite until deletion request | Yes, via tenant lifecycle policy | Granular deletion endpoint; bulk deletion via administrative API |
| Processing metadata | Indefinite until deletion request | Yes, via tenant lifecycle policy | Deleted with the parent memory |
| Backup and DR copies | Maximum 30 days | No | Automatic purge on expiry of the 30-day window |
| Security and access logs | 30 days | Yes, extendable where agreed in the Order Form | Automatic purge on expiry of the retention window |
Annexure C: Support Severity and Response
Baseline position. Deployment-specific response and resolution targets, escalation paths and any service credit structure are set out in the SLA schedule to the Order Form and, where agreed, override this Annexure.
| Severity | Definition | First response | Resolution target |
|---|---|---|---|
| P1 | Platform unavailable, or capture and synthesis failing across the Customer’s tenant | Within 4 business hours | Per SLA schedule |
| P2 | Major function degraded, or failure affecting a defined site, cohort or integration | Within 4 business hours | Per SLA schedule |
| P3 | Single-user or single-device issue with a workaround available | Within 4 business hours | Per SLA schedule |
| P4 | Query, configuration request or documentation request | Within 4 business hours | Per SLA schedule |
First response is measured within business hours. Continuous 24x7 coverage is not provided as at the effective date of these Terms.
Annexure D: Documented Service Limitations
The Customer acknowledges the following limitations and has sized its deployment accordingly.
| Area | Limitation |
|---|---|
| Connectivity | Continuous mobile data connectivity is required to capture conversations. There is no local memory buffer on the device. Conversations occurring while the device is offline are not captured. Offline field deployments in connectivity-poor areas are not supported. |
| Latency | End-to-end latency to a retrievable memory is approximately 2 minutes at P50 and approximately 10 minutes at P99. Latency-sensitive workflows should be sized to P99. Sub-minute latency should not be assumed. |
| Diarization | Speaker diarization accuracy is 87% or better for multi-speaker conversations with a clear audio stream, reducing by approximately 4 percentage points in environments with significant ambient noise. |
| Language | Transcription is contractually validated for Hindi, English and Hinglish, including code-switching, where the Order Form so states. Broader language coverage reflects underlying model capability and is not a device-level validated commitment. Any additional language must be validated during a pilot before it is relied upon. |
| Domain vocabulary | The platform is not benchmarked on domain-specific lexicons. Customer-supplied catalogues can be boosted in the model; uplift varies by domain and requires pilot validation. |
| Minimum duration | A minimum-duration filter suppresses very short utterances. Single-word commands and brief acknowledgements may not be captured as memories. |
| Device identity | Memories are bound to the user account, not to a device identifier. The memory payload does not carry a device ID. Filtering is available by user ID only. |
| Recording controls | Capture can be disabled at device level. Classification-based recording restriction and a discrete control to disable transcript downloads are not available. |
| Data loss prevention | Customisable PII redaction, tenant isolation and RBAC are available. Dedicated policy-based DLP content inspection at egress is not available. |
| Encryption keys | Customer-managed keys and bring-your-own-key are not supported. A shared master key structure is used across tenants. |
| Records management | Search across memories and transcripts is available through the API. Enterprise legal hold and eDiscovery workflows are configured by the Customer in its own environment. |
| Mobile device management | Integration with EMM and MDM platforms, and device posture checks such as rooted or jailbroken detection, are not available. |
| Environment | No sandbox environment with synthetic data. Integration is developed against the production API. |
| API specification | Provided as a Postman collection. No published OpenAPI export and no published formal versioning policy. |
| Physical device | No ingress protection rating. No trusted execution environment, secure element, hardware secure boot or tamper detection. Firmware not cryptographically signed. |
Annexure E: Assurance Artefacts
| Artefact | Availability | Note |
|---|---|---|
| ISO/IEC 27001 certificate and Statement of Applicability | On request | Certificate awarded 19 September 2025 |
| VA&PT executive summary | Under NDA | Bi-annual cycle. Current cycle summary shared on completion |
| Data flow diagram and platform architecture overview | Under NDA | Detailed security architecture available on request |
| Business continuity and disaster recovery plan | Under NDA | Shared post NDA execution |
| Data classification and handling policy | On request | Client-ready version available |
| MFA and remote access policy | On request | Client-ready version available |
| Sub-processor list | Under NDA | Includes cloud hosting and third-party model providers |
| NeoCore API documentation and Postman collection | On request | Issued at onboarding |
| Data Processing Agreement | At contracting | Executed before production data flows |
Acceptance
By accessing or using NeoCore, the Customer acknowledges that it has read, understood and agreed to these Terms and Conditions.
| Field | Detail |
|---|---|
| Entity | ZenithZephyr Wellness Private Limited, trading as NeoSapien |
| Registered office | No 14, 3rd Cross, Scaler Innovation Lab, Parappana Agrahar, Electronic City Phase 1, Bengaluru, Karnataka 560100 |
| Contact | enterprise@neosapien.xyz |