1. Parties and acceptance
These Terms govern access to and use of the Social Cognitive platform (the Service), provided by Lait and its affiliates (the Provider), by the organisation that registers an account and by the individuals it authorises (together, the Customer).
By creating an account, the Customer accepts these Terms and authorises the processing of its personal data under the Privacy Notice referred to in section 13. The two are recorded as separate acts. Where an individual registers on behalf of an organisation, that individual represents that they are authorised to bind it.
2. Contracting entity
The Provider operates through more than one entity. Which one the Customer contracts with, and which law governs that contract, depends on where the Customer is established:
| Customer established in | Contracting entity | Governing law and forum |
|---|---|---|
| United States and Canada | The Provider's US entity | Laws of the State named in the order form |
| Anywhere else | The Provider's Colombian entity | Laws of the Republic of Colombia |
The order form identifies the entity, and section 26 governs disputes. The allocation of responsibility for data protection in sections 7 to 17 is the same for both entities.
3. Accounts and authorised users
The Customer is responsible for everything done through its account, including by the individuals it authorises. It shall keep credentials confidential, not share individual logins between people, and tell the Provider promptly if it believes an account has been compromised.
The Customer shall ensure that every authorised user is bound by obligations at least as protective as these Terms, and that authorised users who leave are removed from the account.
4. Plans, usage allowances and fees
Access is sold as a subscription plan. Each plan carries a usage allowance, metered in the Service. Collections and AI-assisted analysis consume that allowance; the Service shows current consumption and stops work that would exceed the allowance until it is renewed or increased.
Fees are those stated in the order form, exclusive of taxes, which the Customer bears. Unless the order form says otherwise, subscriptions renew for successive periods and either party may stop renewal by giving notice before the end of the current period.
An allowance consumed on work the Provider actually carried out is not refunded because the result was smaller than the Customer hoped: sources vary, and a legitimately empty result is still work performed. Allowance consumed on work that failed through the Provider's fault is credited back.
5. What the Service does
The Service allows the Customer to instruct the Provider to:
- collect information published on social networks, news sites and other public sources, including profiles, posts, comments and their authors;
- analyse it with automated and AI-assisted techniques: sentiment, topics, demographics, engagement and similar;
- generate aggregated outputs, reports and synthetic audience simulations derived from it.
The Service does not access private messages, does not circumvent authentication, and does not collect from sources that require credentials the Customer is not entitled to use.
6. Third-party sources
The information the Service collects comes from platforms the Provider does not control. Those platforms set their own terms, change their structure without notice, and may restrict or block automated access at any time.
The Customer acknowledges that:
- the Provider grants no rights over third-party content, and the Customer is responsible for its own compliance with the terms of any source it asks the Service to use;
- coverage, completeness and freshness depend on those sources and are not guaranteed: a source may return less than it did yesterday, or nothing at all;
- the Provider may add, change or withdraw support for a source when continuing would be unlawful, technically unworkable or contrary to that source's terms.
7. Roles of the parties
For the information the Customer instructs the Provider to collect and analyse, the Customer acts as the controller and the Provider acts as the processor. The Customer determines the purposes of each collection and declares them in the Service under section 10.
Where the Provider determines essential means on its own account — in particular the design of its AI models, the construction of synthetic personas, and product improvement — the parties may act as joint controllers for that specific processing. Those activities are governed by the Data Processing Agreement, and features that depend on them are enabled per Customer rather than by default.
8. Customer warranties on lawfulness
This section is the core of the allocation of responsibility between the parties.
The Customer represents and warrants, on a continuing basis, that:
- it has a valid legal ground for every collection and analysis it instructs, under every law applicable to the people the information concerns, not only the law of its own country;
- it has carried out any assessment its applicable law requires before relying on that ground, including balancing tests and impact assessments where these apply;
- the information it instructs the Provider to collect is pertinent and limited to what those purposes require;
- it will keep its own records of that legal ground, and will produce them to a supervisory authority if asked.
The Provider does not verify, and is not in a position to verify, whether the Customer's legal ground is correct. The Service records what the Customer declares, when it declared it, and which version of these Terms was in force at that moment; it does not validate the declaration.
9. Applicable data protection laws
The Service is offered internationally, and the laws that apply depend on where the people the information concerns are located, not only on where the Customer is established. More than one of the following may apply to the same Customer at the same time, and each applies to the extent it does:
| Jurisdiction | Instrument | Model |
|---|---|---|
| Colombia | Ley Estatutaria 1581 de 2012 and Decreto 1074 de 2015 | Prior, express and informed authorisation, with limited exceptions |
| European Union | Regulation (EU) 2016/679 (GDPR) | One of six lawful bases; special categories require an additional condition |
| United Kingdom | UK GDPR and Data Protection Act 2018 | As above |
| United States | State privacy laws in force in the relevant state | Notice and opt-out; publicly available information generally out of scope |
| Brazil | Lei 13.709/2018 (LGPD) | Legal bases comparable to the GDPR |
| Elsewhere | The data protection law of the relevant territory | As that law provides |
The Customer is not required to select one of these in the Service. The warranty in section 8 covers whichever apply.
10. Permitted purposes and responsibility for use
The Service is contracted solely for the following purposes:
- Market acceptance. Measuring how a brand, product, service or topic is received, and understanding preferences, reputation and the public conversation around them.
- Political and electoral strategy. Analysing public conversation about issues, candidacies or campaigns, subject to the reinforced restrictions in section 11.
Any other purpose falls outside the contracted scope. Section 12 additionally lists uses that are prohibited regardless of the purpose declared.
Who determines the purpose. Within that scope it is the Customer — not the Provider — who decides what it collects and analyses for, because the Customer is the controller (section 7). The Provider does not choose the purpose of any given collection, nor validate it. Limiting which purposes the Service admits defines the scope of what is contracted; it does not determine the Customer's processing.
What is for the Customer to do. Specify its purposes in a specified, explicit and legitimate manner; inform the people the information relates to where its law requires it; keep its own record of processing activities; and not put the Results to purposes incompatible with those it collected for.
What the Service records. When a Collection Session is opened, the purposes the Customer has declared on its account at that moment are recorded on it, together with the version of these Terms then in force. The Collections carried out within that Session are covered by that record.
The Customer keeps its declaration current from its account settings. A change applies to Sessions opened afterwards: it does not rewrite what is already recorded, because the record must keep reflecting what the Customer had declared when the work was done. If the declaration changes, the Customer should open a new Session.
11. Political and electoral use
Inferring political opinions is treated as sensitive processing in most of the jurisdictions listed in section 9, and is specifically regulated in Colombia by Circular Externa 002 de 2026 of the Superintendencia de Industria y Comercio.
Accordingly, the Customer shall not use the Service to:
- build profiles of identified individuals based on their political opinions, or segment communications on that basis, without a valid ground under its applicable law and, where that law requires it, the express authorisation of the person;
- infer political affiliation, religious belief, health, sexual orientation, trade union membership or ethnic origin about identified individuals, other than as anonymous aggregate figures;
- add people to messaging groups, distribution lists or mass mailings on the basis of information obtained through the Service.
Features that produce electorally oriented analysis are disabled by default and are enabled only for Customers whose agreement expressly permits them.
Mandatory declaration. The Customer declares in its account settings whether it carries out political or electoral processing, and keeps that declaration current. It is not informational: it is what switches on the reinforced safeguards in this section, and what allows the Provider to discharge its duty to warn when an instruction it receives would breach applicable law — it cannot warn about what it does not know. Operating under this regime without having declared it is a breach of these Terms.
12. Prohibited uses
The Customer shall not use the Service to:
- target, profile or monitor children, or collect information the Customer knows or ought to know relates to them;
- harass, intimidate, stalk or discriminate against any person, or facilitate any of those;
- make decisions producing legal or similarly significant effects on a person solely by automated means, unless its applicable law permits it and it has told the person;
- resell or redistribute raw collected information as a dataset;
- circumvent technical restrictions, rate limits or access controls of any source.
13. Privacy Notice
The Provider's handling of the Customer's own personal data — the account holder's name, email and usage — is described in the Privacy Notice, which the Customer authorises by a separate act when accepting these Terms and which is versioned independently of this document.
14. Rights of the people the information concerns
The Provider operates a mechanism through which a person whose information has been collected may request its deletion and object to further collection. Requests are honoured across the platform: the person is excluded from subsequent collections and removed from stored results and from any derived audience.
Where a request reaches the Provider but relates to processing the Customer controls, the Provider will act on it and inform the Customer. The Customer shall not instruct the Provider to re-collect information about a person who has objected.
15. Retention
Collected information is retained for the period configured for the Customer's plan and is deleted after it, unless the Customer deletes it earlier. Deleting an account starts a grace period, after which the Customer's data is irreversibly purged.
16. International transfers and sub-processors
The Service processes information in the Provider's cloud infrastructure and uses third-party providers — hosting, data collection and AI analysis — which may involve transfers outside the Customer's country. Transfers are made under the mechanism required by the applicable law, and the Data Processing Agreement identifies the recipients and the mechanism relied on.
The Provider maintains a current list of sub-processors and gives the Customer notice before adding one. The Customer may object on reasonable data protection grounds within the period stated in the Data Processing Agreement; if the objection cannot be resolved, the Customer may terminate the affected part of the Service.
17. Security and incidents
The Provider maintains technical and organisational measures appropriate to the risk, including encryption in transit, access control, tenant isolation and logging of access to collected information.
On becoming aware of a breach affecting information processed for the Customer, the Provider will notify the Customer without undue delay, with what is known about the nature and scope, the likely consequences and the measures taken, so that the Customer can meet its own notification duties.
18. Intellectual property and licence
The platform, its software, models and documentation belong to the Provider. Nothing in these Terms transfers ownership of them.
As between the parties, the Customer owns the outputs the Service generates for it — reports, analyses, charts and simulations — and the Provider grants no rights over the underlying third-party content they draw on.
The Customer grants the Provider the licence necessary to host, process and analyse the collected information in order to provide the Service. That licence is limited to providing the Service; it does not permit the Provider to use the Customer's collected information to train models offered to other customers, unless the Customer opts in separately and in writing.
19. AI-assisted outputs
Sentiment, topics, demographics, affinity and audience simulations are probabilistic inferences, not statements of fact. They may be wrong about any given person or post, and different runs may differ.
The Customer therefore undertakes to:
- apply human review before acting on an output in a way that affects an identified person;
- not present an inference as a verified attribute of a person to third parties;
- not use outputs as the sole basis for decisions producing legal or similarly significant effects, as section 12 already requires.
Synthetic personas and simulated audiences are generated constructs. They do not represent real identified individuals and must not be presented as if they did.
20. Availability and disclaimer
The Provider will use reasonable efforts to keep the Service available, but does not warrant uninterrupted or error-free operation. Where an availability commitment applies, it is stated in the order form.
Except as these Terms expressly state, and to the extent the applicable law permits, the Service is provided as is, and the Provider disclaims implied warranties of merchantability, fitness for a particular purpose, accuracy and completeness of information obtained from third-party sources.
21. Suspension
The Provider may suspend access where it has a reasonable belief that the Customer is using the Service in breach of sections 8, 11 or 12, or where a supervisory authority requires it. Where practicable the Provider will give notice and an opportunity to remedy first.
22. Term and termination
These Terms apply for as long as the Customer holds an account. Either party may terminate for material breach that is not remedied within thirty days of written notice, and the Customer may terminate at any time by closing its account.
On termination the Customer's access ends, and collected information is deleted after the grace period described in section 15. Sections 8, 12, 18, 24, 25 and 26 survive termination.
23. Changes to these Terms
The Provider may issue new versions. Each version carries an identifier and an effective date, and previous versions are retained for as long as information collected under them is still processed. Material changes require the Customer to accept the new version before continuing to collect.
24. Liability and indemnity
The Customer indemnifies the Provider against claims arising from the Customer's breach of sections 8, 11 or 12, including claims brought by the people the information concerns and proceedings opened by a supervisory authority.
Except for the indemnity above, each party's aggregate liability is limited to the fees paid or payable in the twelve months before the event, and neither party is liable for indirect or consequential loss or loss of profit.
Nothing in these Terms limits either party's liability where its applicable law does not permit that limitation, including liability for fraud, wilful misconduct or death or personal injury.
25. Confidentiality
Each party shall keep the other's non-public information confidential, use it only to perform these Terms, and protect it with at least reasonable care. The obligation does not apply to information that is public through no breach, was already known, is independently developed, or must be disclosed by law, in which case the disclosing party gives notice where it lawfully can.
26. Governing law and disputes
These Terms are governed by the law stated for the contracting entity in section 2, without prejudice to mandatory consumer or data protection rules that apply to the Customer. The parties submit to the exclusive jurisdiction of the courts of that place, and will attempt to resolve a dispute in good faith before starting proceedings.
27. General
- Export control and sanctions. The Customer warrants that it is not subject to sanctions that would prohibit the Provider from contracting with it, and will not make the Service available in breach of applicable export control rules.
- Assignment. Neither party may assign these Terms without the other's consent, except to an affiliate or in connection with a merger or sale of substantially all assets.
- Force majeure. Neither party is liable for failure caused by events beyond its reasonable control, including the withdrawal or blocking of a third-party source under section 6.
- Severability. If a provision is unenforceable, the rest remains in force.
- Notices. Notices are given to the contact addresses in the account and the order form.
- Entire agreement. These Terms, the order form, the Privacy Notice and the Data Processing Agreement are the whole agreement on their subject matter. Where they conflict, the Data Processing Agreement prevails on data protection and the order form prevails on commercial terms.
28. Definitions
Collection. A single instructed retrieval of information from a source.
Collection Session. The body of work the Customer opens in the Service, under which the Collections that follow are carried out. It is the unit recorded with the declared purposes and the version of these Terms then in force.
Controller. The party that determines the purposes and means of processing.
Processor. The party that processes on behalf of, and on the instructions of, the controller.
Data Processing Agreement. The separate agreement governing processing carried out by the Provider on the Customer's behalf, including transfers and sub-processors.
Personal data. Any information relating to an identified or identifiable person, as defined by the applicable law in section 9. Information that is public does not stop being personal data for that reason alone.
Purpose. The use the Customer pursues with a Collection, declared in the Service under section 10. A Collection may have more than one.
Output. Anything the Service generates from collected information: analyses, reports, charts, audiences and simulations.
Order form. The commercial document identifying the contracting entity, plan, allowance, fees and term.