TERMS AND CONDITIONS AGREEMENT
“For customers using Code Engines Software LLC services“
Version 3.0 — Effective 15 September 2026. This version supersedes all prior versions of this Agreement. For existing Subscribers, this version applies from the date on which they accept it, or thirty (30) days after notice of it is given to their Administrator, whichever is earlier. The current version is published at https://casengine.app/terms-conditions/ and each published version is retained there.
This Agreement governs the Subscriber’s use of the software and services provided by Code Engines Software LLC, a limited liability company incorporated under the laws of the United Arab Emirates and licensed by the Dubai Department of Economy and Tourism under trade licence number 800700, whose registered office is at Office 216, Dubai Chambers New Extension, Dubai, United Arab Emirates, trading as Code Engines and CASENGINE (“Code Engines”). This Agreement incorporates the Privacy Policy. By registering to use the Service, or by accepting this Agreement at sign-up, the Subscriber agrees to be bound by it.
1. Definitions
1.1 Account Data: means data which pertains to the Subscriber, Users, and Registered Clients necessary to identify them and administer their use of the Service. For the avoidance of doubt, Account Data does not include data uploaded by the Subscriber or Users relating to contacts, matters, tasks or similar data.
1.2 Administrator: means the person designated by Subscriber (i) as its primary administrative contact for the purposes of support, issues related to outages and other problems and technical items and (ii) who has authority from the Subscriber to bind the Subscriber and administer the subscription to the Service and designate additional Users and/or Administrators. The first User is deemed to be designated as an Administrator.
1.3 Agreement: means these terms and conditions, the Privacy Policy and any written order form, quotation or enterprise agreement signed by both Parties that expressly incorporates them. In the event of conflict, a signed written agreement prevails, then these terms and conditions, then the Privacy Policy.
1.4 Confidential Information: has the meaning given to that term within Section No 4.
1.5 Content: means any information or materials a User uploads or posts to the Service, including, without limitation, information about its Users or Registered Clients.
1.6 Good Industry Practice: means the deployment of that degree of care and skill, technical resources and innovations which is to be expected of professional and adequately resourced providers of services similar to the Service within the GCC & MENA or other regions.
1.7 Including: means ‘including, without limitation’ and ‘include’ and ‘included’ will be interpreted in like manner.
1.8 Intellectual Property Rights: means all rights and interests in all
- (a) patents, utility models, patent applications, and continuing (continuation, divisional, or continuation-in-part) applications, re-issues, extensions, renewals, and re-examinations thereof and patents issued thereon;
- (b) registered and unregistered trademarks, service marks, trade names, domain names, and all of the associated goodwill;
- (c) registered and unregistered copyrights and all other literary and author’s rights or moral rights;
- (d) trade secrets, know-how, show-how, concepts, ideas, methods, processes, designs, discoveries, improvements, and inventions, whether or not patentable;
- (e) all other intellectual, industrial, and proprietary rights now or hereafter coming into existence throughout the world;
- (f) applications for and registrations, renewals, and extensions of any of the foregoing; and
- (g) exclusive and non-exclusive license rights to any of the foregoing.
1.9 Registered Client: means an individual who has been invited to use the client-facing features of the Service in a limited capacity as a client (or representative of a client) of a Subscriber.
1.10 Regulator: means
- any court, authority or professional body with supervisory, regulatory or disciplinary authority over the Subscriber or over its provision of legal or other services, including for Subscribers practising law in the Emirate of Dubai the Dubai Legal Affairs Department, for Subscribers practising law elsewhere in the United Arab Emirates the Ministry of Justice or the relevant free zone authority, and for Subscribers practising elsewhere the equivalent body;
- for Subscribers practicing law in UAE under the body which is responsible for regulating the provision of legal services: and
- for Subscribers practicing law elsewhere in the GCC or MENA or any other part of the world under the body which is responsible for regulating the provision of legal services.
1.11 Service: means the services provided from time to time by Code Engines under the brand name ‘CASENGINE’ through the website located at https://casengine.app
1.12 Subscriber: means the entity (typically a law firm or legal department) or a solo practitioner who utilizes the Service.
1.13 Security Emergency: shall mean a breach by Subscriber of this Agreement that
- could disrupt
- a) Code Engines provision of the Service;
- b) the business of other Subscribers; or
- c) the network or servers used to provide the Service; or
- provides unauthorized third-party access to the Service.
1.14 User: means an individual person, other than a Registered Client, provided with access to the Service by an Administrator.
1.15 Party: means Code Engines or the Subscriber, and Parties means both of them.
2. Limited License & Use of the Service
2.1 Subscriber is granted a non-exclusive, non-transferable, limited license to access and use the Service.
2.2 ‘Code Engines’ does not review or pre-screen Content and Code Engines’ claims no Intellectual Property Rights in the Content that the subscriber will upload
2.3 Subscriber shall ensure that Users and Registered Clients comply with this Agreement. Subscriber shall be responsible for the acts and omissions of the Users and the Registered Clients. Without limiting the generality of the foregoing, Subscriber is responsible for any disclosure of Content arising out of features enabled by Users.
2.4 Subscriber shall not copy or resell the Service. Subscriber must not exploit access to the Service or any portion of the Service, including the UI designs, source code(s), database files, published project, cascading style sheet or any visual design elements otherwise than for Subscriber’s own internal business and for the design purpose of the Service. Subscriber shall ensure that no Users or Registered Clients increase or attempt to increase the number of Users or extend the license expiry dates without having a valid license key issued from Codengines.
2.5 Subscriber shall not modify, reverse engineer, adapt or otherwise tamper with the Service, except as mandated by law, or modify another website so as to falsely imply that it is associated with the Service, Code Engines, or any other service provided by Code Engines.
2.6 Subscriber shall not use the Service in any manner which may infringe Intellectual Property Rights or in any manner which is unlawful, offensive, threatening, libellous, defamatory, pornographic, obscene or in violation of the terms of this Agreement.
2.7 Subscriber shall not use the Service to upload, post, host, or transmit unsolicited bulk e-mail “Spam”, short message service “SMS” messages, viruses, self-replicating computer programs “Worms” or any code of a destructive or malicious nature.
2.8 Except for the non-exclusive license granted pursuant to this Agreement, Subscriber acknowledges and agrees that all ownership, licenses, Intellectual Property Rights and other rights and interests in and to the Service shall remain solely with Code Engines. Subscriber is not entitled or permitted to use the Service otherwise than (a) through the internet-hosted version deployed by Code Engines.
2.8A Clause 2.8 does not prevent, and shall not be read as prohibiting, (b) an On-Premise Deployment licensed by Code Engines under Section 16 (On-Premise Deployment) where expressly agreed in writing.
2.9 Code Engines reserves the right, at any time, in its sole discretion, to take any action deemed necessary with respect to Content that breaches the terms of this Agreement, including removal of such Content.
2.10 Code Engines reserves the right at any time, and from time to time, to modify or discontinue, temporarily or permanently, any feature associated with the Service, with or without notice, except that Code Engines shall provide Subscriber with thirty (30) days’ notice of any modification that materially reduces the functionality of the Service and in such circumstances Subscriber shall have the right to terminate this Agreement by sending an email to support@codengines.com.
2.11 Code Engines reserves the right to temporarily suspend access to the Service for operational purposes, including maintenance, repairs or installation of upgrades. Code Engines will provide no less than two (2) business days’ notice prior to any such suspension. Such notice may include posting a message using the Service. Code Engines shall have the right to temporarily suspend access to the Service without notice in circumstances where urgent action is required to protect the Service if the delay caused by giving notice could cause material harm. Code Engines shall use all reasonable endeavours to minimize operational suspensions in order to minimize disruption to the Service.
2.12 The accounting features which form part of the Service are intended to be an aid for legal cashiers. They do not constitute a full accounting service and are not intended to meet the Regulator’s requirements for accounting packages for legal services providers.
2.12A The reminder, deadline, hearing and appeal-tracking features of the Service are an aid to the Subscriber’s own case management. The Subscriber remains solely responsible for identifying, calculating, monitoring and meeting all limitation periods, filing deadlines and hearing dates. Code Engines does not warrant that any reminder or notification will be generated, delivered or received.
2.12B The conflict check features of the Service are an aid to the Subscriber’s own conflicts procedure. They do not constitute a determination that no conflict of interest exists, and do not discharge the Subscriber’s professional obligations in relation to conflicts.
2.13 Code Engines uses one code-base for all jurisdictions. Subscriber is required, using settings available within the Service, to configure the Service for its own jurisdiction and to verify that the settings meet the Subscriber’s requirements. Code Engines will highlight known features that may require Subscriber review.
2.14 Subscriber grants to Code Engines the right during Subscriber’s use of the Service, to store and process the Confidential Information for the sole purpose of performing Code Engines obligations under the Agreement in accordance with its terms. Such rights shall include permission for Code Engines to generate and publish aggregate, anonymized reports on system usage and Content trends and type, provided they do not conflict with Section 4.1.
3. Access to the Service
3.1 Only Users and Registered Clients are permitted to use the Service. In order to access the Service, Users are required to provide their full legal name, a valid email address, and any other information reasonably requested by Code Engines.
3.2 Each User will be provided with a unique identifier to access and use the Service (“Username”). The Subscriber shall use all reasonable endeavours to ensure that each Username is only used by the User to whom it is assigned, and is not shared with, or used by, any other person, including other Users.
3.3 The Administrator shall have the authority to administer the subscription to the Service on behalf of the Subscriber and to designate additional Users and/or Administrators. Each Subscriber may have multiple Administrators. The Administrator shall have the authority to deactivate an active Username if the Administrator wishes to terminate access to the Service for that User.
3.4 Where a Subscriber has just one Administrator, it will provide Code Engines with the name and contact information of a designated User for use as an alternative point of contact if Code Engines is unable to reach the Administrator for a period of thirty days (30) following the initial attempt to contact the Administrator.
3.5 As between Code Engines and the Subscriber, any Content that the subscriber uploads remains the property of the Subscriber.
3.6 Upon cancellation or termination of the Service, Code Engines shall only liaise with the Administrator or the designated User described in Clause 3.4 above (if the Administrator is unable to be reached) regarding the retrieval of Content.
3.7 All access to and use of the Service via automated means (that is to say, use other than direct interaction with a human User) is strictly prohibited except insofar as the Service includes features which are designed for such use.
4. Confidentiality
4.1 Each Party during the term of this Agreement and thereafter shall comply with this Confidential Information clause which includes all information of a confidential nature furnished by one Party to the other Party including but not limited to the following: Account Data, Content and any information, or know-how considered proprietary or confidential by either party to this Agreement including either party’s research, services, inventions, processes, specifications, designs, drawings, diagrams, concepts, marketing, techniques, documentation, all analysis, software source, library and object codes, copyright material and manuals, trademarks and other intellectual property rights, specifications, training material and know-how relating to the Service, documentation and information relating to third parties or potential or existing customers, data, lists, plans, formulae, customer lists, business, operations, administration, price-sensitive information and policies, strategies, technical and financial information, information and data uploaded by Subscriber’s customers on the Service, documentation and the existence and terms of this Agreement. Confidential Information does not include information which:
- is or becomes publicly available through no breach of this Agreement or any other confidentiality obligation;
- is required to be disclosed by law;
- is required to be disclosed by a regulator with authority over the Receiving Party;
- is or becomes available to a Party from a third party which is lawfully in possession of that information and who has the lawful power to disclose such information to that Party on a non-confidential basis; or
- is lawfully known by a Party prior to the date of its disclosure to that Party.
4.2 A Party receiving Confidential Information (“Receiving Party”) from the disclosing Party (“Disclosing Party”) shall hold Disclosing Party’s Confidential Information as absolutely secret and in the strictest confidence and shall not at any time use the Confidential Information for its own benefit, or the benefits of any other party or for commercial gain except for the purpose of achieving or furthering the transactions contemplated under this Agreement or as permitted under this Agreement. Each Party shall not disclose, or permit to be disclosed, any Confidential Information to any third party.
4.3 Each Party may disclose the Confidential Information to its respective affiliates, employees, Users, contractors, advisers or officers (“Employees”) on a need-to-know basis and only to the extent necessary for each of them to perform its/his/her duties for the purpose of achieving or furthering the transactions contemplated under this Agreement or as permitted under this Agreement.
4.4 Each Party shall procure that its respective Employees, who may have access to the Confidential Information, comply with the terms and obligations of this Agreement as if each were a Party hereto. Each Party agrees to bear full responsibility in the event of a breach of the terms and obligations of this Agreement by any of their respective Employees and shall inform the other Party of such breach immediately.
4.5 All documents, records and other materials of every kind pertaining to a Party’s Confidential Information shall be and remain the exclusive property of Disclosing Party at all times. Disclosing Party may, at any time, request the prompt return of all such documents, records and materials and their copies which are in Receiving Party’s possession or under its control.
4.6 All rights, title and interest in Disclosing Party’s Confidential Information and intellectual property shall remain with the Disclosing Party. No license other than granted under Clause 2 of this Agreement, whether express or implied, in the Confidential Information is granted to Receiving Party other than to use Disclosing Party’s Confidential Information as permitted under this Agreement.
4.7 Subject to Clauses 4.1 to 4.6, neither Party shall make, or permit any person to make, any public announcement regarding this Agreement without the prior written consent of the other Party, except (a) where required by a court, a Regulator or applicable law; (b) in respect of information already in the public domain without fault on the part of the announcing Party; and (c) as permitted by Clause 15.10 (customer name and logo).
5. Security and Access
5.1 Code Engines shall provide a secure method of authentication and access to the Service, including:
- User password management and the protection of passwords by utilizing code consistent with Good Industry Practice relating to password management; and
- Transmission of passwords in an encrypted format.
5.2 Except as set out in Clause 5.1, Subscriber shall be responsible for protecting the security of Usernames and passwords, or any other codes associated to the Service, and for the accuracy and adequacy of Content.
5.3 Subscriber will implement policies and procedures to prevent unauthorized use of Usernames and passwords, and will promptly notify Code Engines upon suspicion that a Username or password has been lost, stolen, compromised, or misused.
5.4 At all times, Code Engines, shall:
- use Good Industry Practice in relation to information security and processing Content;
- employ Good Industry Practice with respect to network security techniques, including firewalls, intrusion detection, and authentication protocols, vulnerability and patch management;
- ensure its hosting facilities use Good Industry Practices for security and privacy.
5.5 Code Engines shall report to Subscriber, with all relevant details (except those which could prejudice the security of data uploaded by other subscribers), any event that Code Engines reasonably believes has led to or is likely to lead to unauthorized access to, disclosure of, use of, or damage to Content (a “Security Breach”). Code Engines shall make such report within seventy-two (72) hours after learning of the Security Breach.
5.6 In the event of a Security Breach, Code Engines shall
- cooperate with Subscriber to identify the cause of the breach and to identify any affected Content;
- assist and cooperate with Subscriber in investigating and preventing the recurrence of the Security Breach;
- assist and cooperate with Subscriber in any litigation or investigation against third parties that Subscriber undertakes to protect the security and integrity of Content; and
- use all reasonable endeavours to mitigate any harmful effect of the Security Breach.
6. Regulatory Requirements
6.1 Subscriber authorizes and Code Engines agrees to co-operate with all reasonable and lawful requests from a Regulator (and any lawful representatives of the Regulator) for access to Content pertaining to the clients and business of Subscriber. Except where the law or the Regulator prohibits it, Code Engines shall notify the Subscriber before providing Content to a Regulator and shall provide only the Content requested.
6.2 Notwithstanding any other provisions of the Agreement, Code Engines agrees to return, upon demand, in a complete, readable and understandable form, all Content. This obligation will prevail even if the Subscriber is in breach of its obligations to Code Engines, if the Subscriber is in dispute with Code Engines, or if any fees remain outstanding. Code Engines shall not withhold, suspend access to, or delete Content comprising client files, case records or documents by reason of unpaid fees; Code Engines shall pursue any unpaid amounts as a debt instead.
7. Legal Compliance
7.1 If Code Engines is required by law to make any disclosure of Confidential Information as mentioned in the second and third exclusions listed in Clause 4.1, Code Engines will provide Subscriber with prompt written notice (to the extent permitted by law) prior to such disclosure so that the Subscriber may seek a protective order or other appropriate relief. Subject to the foregoing sentence, Code Engines may furnish that portion (and only that portion) of the Confidential Information that it is legally compelled to disclose.
8. Managed Backup and Archiving
8.1 Code Engines maintains a managed backup service on servers located in the United Arab Emirates to facilitate restoration of Content to the server or device from which the Content originated in the event the primary data is lost or corrupted. Code Engines shall use such service to recover lost or corrupted Content at no cost to the Subscriber.
8.2 Following termination of the Service for any reason, the Subscriber shall have thirty (30) calendar days (the “Retrieval Period”) to retrieve any and all Content. The Retrieval Period is not conditional on payment of outstanding fees. Clause 10.4 governs the export format and the deletion that follows.
9. Payment, Refunds, and Subscription Changes
9.1 In exchange for the Service, Subscriber shall pay the subscription fees advertised by Code Engines and in the manner and at the times agreed
9.2 Subscribers must provide Code Engines with a valid credit card for payment for the applicable subscription fees. All subscription fees are exclusive of VAT or other sales or use taxes which Subscribers agree to pay as required by law, subject to Code Engines raising a valid VAT invoice.
9.2A Where agreed in writing, and in particular for government, ministry and enterprise Subscribers, Code Engines may accept payment by bank transfer against a valid tax invoice instead of by credit card.
9.3 In addition to any fees advertised for the Service, the Subscriber may incur additional expense incidentals to using the Service including charges for Internet access, data roaming, and other data transmission charges.
9.4 Monthly Subscribers will be charged their inaugural monthly fee at the conclusion of their free trial period. Thereafter, they will be charged in advance each thirty (30) days. Annual Subscribers will pay their annual fee in advance and will thereafter be charged annually on the anniversary date of the initial subscription charge. All charges and payments are non-refundable.
9.4A Where Code Engines offers a free trial, the length and scope of the trial will be as stated at sign-up. Code Engines may vary or withdraw free trials at any time. Content uploaded during a trial that does not convert to a paid subscription will be deleted thirty (30) calendar days after the trial ends, unless the Subscriber requests earlier deletion.
9.5 No refunds or credits (whether for monthly or annual subscriptions) will be issued for downtime, or for periods unused with an active subscription.
9.5A All subscription fees are payable in advance for the billing period to which they relate. Except where this Agreement expressly provides otherwise, fees already paid are not refundable, including where the Subscriber terminates before the end of a billing period or ceases to use the Service.
9.5B Where the Subscriber terminates, termination takes effect at the end of the billing period in which notice is given, and the Subscriber retains access for the remainder of that period. Clause 10.3A governs termination for convenience by either Party, and Clauses 6.2, 10.4 and 10.5 continue to apply on termination however it arises.
9.6 There are no charges for cancelling a subscription, and subscriptions cancelled prior to the end of their current billing cycle will be available until the end of the current billing cycle and will not be charged again in the following cycle.
9.7 The amount charged to the Subscriber on successive billing cycles will be automatically updated to reflect any changes to the Subscriber’s subscription, including upgrades or downgrades. Adding User subscriptions or subscription upgrades will trigger prorated charges in the current billing cycle. Subscriber authorizes Code Engines to apply updated charge amounts. Subscription changes, including downgrades, may result in loss of features, or an increase or reduction in the amount of available capacity for Content provided by the Service.
9.8 All payments under this Agreement shall be made without deduction or withholding for any taxes. If Subscriber is required to deduct or withhold any taxes from such payments, then the sum payable shall be increased as necessary so that, after making all required deductions or withholdings, Code Engines receives an amount equal to the sum it would have received had no such deduction or withholding been made.
9.9 The subscription payment is to license the Subscriber to use the Service as it is and does not include any other services like Data Migrations from old system, specific customizations requests or dedicated onboarding support. Such services are charged separately on case to case basis.
10. Term and Termination
10.1 This Agreement shall commence upon the aforementioned date and shall be perpetually valid (“TERM”) until it is terminated in accordance with the provisions of this Agreement.
10.2 Code Engines may, by providing an advance written notice of ten (10) calendar days, terminate this Agreement, without compensation to the Subscriber and without prejudice to any rights or claims the Subscriber may have against the Code Engines, pursuant to this Agreement or otherwise if:
- The Subscriber commits a breach deemed by the Code Engines to be a material breach of or is responsible for any material non-performance of any of the stipulations contained in this Agreement, or in the case of a breach capable of remedy, if such breach has not been remedied by the Subscriber within ten (10) working days of receipt of written notice from the Code Engines specifying the breach and requiring its remedy;
- makes any voluntary arrangement with its creditors; passes a resolution for winding up (other than for the purposes of a solvent amalgamation, reconstruction or restructuring) or a court makes an order to that effect;
- becomes or is declared insolvent or convenes a meeting of or makes or proposes to make any arrangement or composition with its creditors;
- has a liquidator, receiver, administrator, administrative receiver, manager, trustee or similar officer appointed over any of its assets; or a creditor takes possession, or a receiver is appointed over any of the property or assets of the Subscriber;
- the Subscriber or any of its directors, employees, agents or sub-contractors commits any act of fraud, negligence or willful misconduct in the performance of the services, which has been proved by a court of law;
10.3 Where fees have been outstanding for more than twenty (20) calendar days, Code Engines may suspend access to the Service, having first given the Subscriber not less than ten (10) calendar days’ written notice and an opportunity to pay. Suspension does not entitle Code Engines to withhold, delete or refuse to return Content, which remains subject to Clause 6.2.
10.3A Either Party may terminate this Agreement for convenience at any time, without stating a reason, on written notice to the other Party of not less than ninety (90) calendar days where Code Engines terminates, or not less than thirty (30) calendar days where the Subscriber terminates. Termination is without prejudice to any rights of either Party (including costs and fees incurred by Code Engines) accrued up to the effective date of termination. Code Engines shall, on the Subscriber’s reasonable request, provide copies of receipts and invoices in support of amounts paid.
10.4 Upon termination of this Agreement for any reason, Code Engines shall export all Subscriber data, including database contents and documents, and provide them to the Subscriber in a downloadable format. Structured data will be exported in Excel format and documents provided in a compressed archive. Code Engines is not obliged to provide a database backup file or to provide the data in any other format. All Subscriber data is stored in Microsoft Azure in the UAE North region. Code Engines will share a download link with the Subscriber’s Administrator. Neither the export nor the download link is conditional on payment of outstanding fees. Subscriber data will be deleted thirty (30) calendar days after the download link is issued, or earlier on the Administrator’s signed written instruction. Code Engines will confirm the deletion in writing on request.
10.5 As required by Clause 8 above (“Managed Backup and Archiving”), upon termination of a subscription Content is made available to the Administrator or to the designated User described in Clause 3.4. The Retrieval Period is thirty (30) calendar days from termination. At the end of the Retrieval Period, or earlier on the Administrator’s signed written instruction under Clause 10.4, all Content associated with the terminated subscription will be irrevocably deleted from the Service.
11. Limitation of Liability
11.1 Nothing in this Agreement shall exclude or limit any party’s liability for:
- death or personal injury resulting from that party’s negligence;
- that party’s fraud or statements made fraudulently by that party; or
- any other acts or omissions for which applicable law prohibits the exclusion or limitation of liability.
11.2 Code Engines will not be liable under any circumstances for any:
- loss of profit, loss of business, loss of goodwill, loss of savings, claims by third parties, loss of anticipated savings, business interruption whether direct or indirect in each case; or
- pure economic loss, indirect loss or consequential loss whatsoever and howsoever caused; or
- punitive or exemplary damages; even if caused by Code Engines’ negligence and/or breach of this Agreement and even if Code Engines was advised that such loss would probably result
11.3 Code Engines will not be liable for any loss or claims arising in connection with this Agreement to the extent that such loss or claims could have been avoided or reduced by the use of:
- back-up facilities available as part of the Service; or
- advice from help desk support or reasonable practices and tools promulgated by Code Engines to avoid such loss or claims.
11.4 Subject to Clauses 11.1 and 11.4A, Code Engines’ aggregate liability to the Subscriber for all claims, losses, damages or expenses whatsoever and howsoever caused arising in connection with this Agreement, including liability for breach of contract, misrepresentation (whether tortious or statutory), tort (including negligence) and breach of statutory duty, shall not exceed the total amount of subscription fees actually paid by the Subscriber in the six (6) months preceding the event giving rise to the cause of action.
11.4A Notwithstanding Clause 11.4, and by way of a raised cap rather than an exclusion, Code Engines’ aggregate liability for (a) breach of Clause 4 (Confidentiality), or (b) a Security Breach arising from Code Engines’ failure to meet its obligations under Clause 5 (Security and Access) or Section 19 (Data Protection), shall not exceed the total amount of subscription fees actually paid by the Subscriber in the twelve (12) months preceding the event giving rise to the cause of action.
11.5 Code Engines shall not be liable for failure to perform any obligation under this Agreement if such failure is caused by the occurrence of any contingency beyond the reasonable control of Code Engines (a “Force Majeure Event”).
12. Code Engines Further Commitments
12.1 Where a defect or fault in the Service adversely affects its operation, Code Engines shall remedy the defect or fault so as to ensure the continued operation of the Service.
13. Warranties and Representation
13.1 Code Engines represents that it is not aware of any restriction, legal or otherwise, or agreement with any third party, which would prevent it from entering into this Agreement;
- it holds all necessary licenses and permits entitling it to duly conduct the services;
- all of its staff, employees, consultants or agents engaged or to be engaged in the services are duly qualified and experienced to provide the services; and
- the provision of the services hereunder shall not cause a conflict with any of its duties or obligations to any third party.
13.2 All other conditions or other terms which might have effect between the parties or be implied or incorporated into this Agreement, whether by statute or other applicable law, are hereby excluded, including the implied conditions, warranties or other terms as to satisfactory quality and fitness for purpose. For the avoidance of doubt, this Clause does not exclude Code Engines’ obligations under Clause 5 (Security and Access), Clause 12 (Code Engines Further Commitments), Section 17 (Service Levels) or Section 19 (Data Protection), nor its obligation to perform the Service with reasonable skill and care.
13.3 The Subscriber must provide all the information that may be necessary to assist Code Engines in resolving the defect or fault, including a documented example of any defect or fault, or sufficient information to enable Code Engines to re-create the defect or fault.
13.4 Code Engines does not state, represent or assert that the use of the software shall be uninterrupted or error-free. Any defect or fault within the software in consequence of which it fails to conform in all material respects to the specification, will be remedied by Code Engines.
13.5 Subscriber warrants and represents that it has the legal right to store, process and distribute Content using the Service.
13.6 Nothing in this Clause 13 shall modify Code Engines’ obligations under Clause 4 above (“Confidentiality”) or Clause 5 above (“Security and Access”).
13.7 Each party acknowledges and agrees that it has not entered into this Agreement on the basis of any representations or promises not expressly contained herein.
13.8 Except as specifically provided elsewhere in this agreement, Code Engines hereby disclaims all warranties of any kind, implied or statutory, including the implied warranties of merchantability, fitness for a particular purpose, title and non-infringement of third- party rights with respect to any services provided by Code Engines.
14. Indemnification
14.1 Subscriber hereby agrees to indemnify and hold harmless Code Engines from and against any claim, action, proceeding, loss, liability, judgment, obligation, penalty, damage, cost or expense, including professional fees, which arise from or relate to the following:
- Users’ breach of any obligation stated in this Agreement, and
- Users’ negligent acts or omissions.
14.2 Code Engines will provide prompt notice to Subscriber of any indemnifiable event or loss. Subscriber will undertake, at Subscriber’s own cost, the defence of any claim, suit or proceeding with legal advisers reasonably acceptable to Code Engines. Code Engines reserves the right to participate in the defence of the claim, suit, or proceeding, at Subscriber expense, with counsel of Code Engines’ choosing.
14.3 Without regard to the exclusions set out in Clauses 11.2 and 11.3, but subject to Clause 14.3A, Code Engines shall indemnify, defend and hold Subscriber harmless from and against any and all direct party claims, losses, damages, suits, fees, judgments, costs and expenses which arise out of or relate to a claim brought by third parties alleging that the Service infringes any Intellectual Property Rights of any third party.
14.3A Code Engines’ aggregate liability under Clause 14.3 shall not exceed the total amount of subscription fees actually paid by the Subscriber in the twelve (12) months preceding the date on which the claim was first notified to Code Engines. Clause 11.1 is unaffected by this Clause.
14.4 Any indemnity given by Code Engines to Subscriber under this Agreement is subject to the pre-condition that (i) Subscriber must mitigate its loss; (ii) Code Engines is given prompt and complete control of the claim giving rise to the indemnity (at Code Engines’ cost); (iii) Subscriber does not prejudice Code Engines’ defence of such claim; (iv) Subscriber gives Code Engines all reasonable assistance with such claim (at Code Engines ’ cost); and (v) the claim does not arise as a result of any breach of Subscriber’s contractual obligations to Code Engines or other acts or omissions of Subscriber.
15. Miscellaneous
15.1 Code Engines shall be entitled to subcontract part, but not the whole, of the Service. To the extent that Code Engines does subcontract any part of the Service, Code Engines shall:
- be responsible for the acts and omissions of its subcontractors;
- procure from sub-contractors’ obligations and restrictions consistent with Code Engines’ obligations and restrictions in this Agreement or, where the subcontractor offers only standard non-negotiable terms, on terms affording a comparable standard of protection (including those relating to confidentiality, data protection and use of Content); and
- exercise reasonable care and skill in the appointment of subcontractors
15.2 Technical support and training videos are available to Users with active subscriptions, and is available by email or electronic support ticket. No physical training or support visits are included in the subscription package and can be availed as an added service which solely depend on the availability of the training resource and Code Engines is not obliged to deliver such service.
15.3 Code Engines may provide the ability to integrate the Service with third party products and services at Subscriber’s option and risk. Access to and use of any third-party products and services are subject to the separate terms and conditions required by the providers of the third- party products and services. Subscriber agrees that Code Engines has no liability arising from Subscriber’s use of any integrations or arising from the third- party products and services. Code Engines can modify or cancel the integrations at any time without notice. For purposes of calculating downtime, such calculation does not include the unavailability of any integration or any third- party products or services.
15.4 The failure of either party to enforce any provision hereof shall not constitute or be construed as a waiver of such provision or of the right to enforce it at a later time.
15.5 This Agreement constitutes the entire agreement between Subscriber and Code Engines and governs Subscriber’s use of the Service, superseding any prior agreements between Subscriber and Code Engines (including any prior versions of this Agreement), save for any signed written agreement that expressly incorporates this Agreement, which is governed by the order of precedence in Clause 1.3.
15.6 The Subscriber shall not assign any of its rights under this Agreement or sub-contract the whole or any part of the performance of the services or any of its obligations under the Agreement without the prior written consent of the Code Engines and upon the Subscriber agreeing in writing the identity of the person to whom the performance of all or part of the services is proposed to be assigned or sub-contracted. Any attempted assignment of this agreement in violation of this section shall be deemed void. A breach of this clause by the subscriber shall entitle the Code Engines to terminate this Agreement and seek damages from the Subscriber.
15.7 This Agreement shall be governed by and construed in accordance with the federal laws of the United Arab Emirates as applied in the Emirate of Dubai, without reference to any rule of choice or conflict of laws.
15.8 In the event that a dispute shall rise in relation to this Agreement, including any question regarding its existence, validity or termination, the Parties shall first seek settlement of that dispute through negotiation. If the dispute is not settled by negotiation within fifteen (15) working days following the due service of a notice of dispute by one party to another, or such further period as the Parties shall agree in writing, the dispute shall be referred to and finally resolved by Arbitration under the Arbitration rules of the Dubai International Arbitration Centre, (“DIAC rules”), which rules are deemed to be incorporated by reference to this clause. The selected language in the arbitration shall be English and the number of Arbitrators shall be one (1). The seat, or legal place, of Arbitration shall be Dubai, United Arab Emirates.
15.9 In the event that a provision or term of this Agreement is determined to be unenforceable for any reason, then a court or arbitrator may strike or modify the term or provision in order to best effect the business purpose of the parties in entering into the Agreement and the balance of the agreement shall remain valid and enforceable.
15.10 Code Engines may identify the Subscriber as a customer and display the Subscriber’s name and logo on its website and in its marketing materials. The Subscriber may withdraw that permission at any time by written notice, and Code Engines shall cease such use within thirty (30) days of receipt.
15.11 Notices under this Agreement shall be in writing and sent by email: to the Administrator, in the case of the Subscriber; and to legal@codengines.com, in the case of Code Engines, or to such other address as a Party notifies in writing. A notice is deemed given on the next business day after it is sent.
15.12 Clause 4 (Confidentiality), Clause 6.2 (Return of Content), Clauses 10.4 and 10.5 (Export and Deletion), Clause 11 (Limitation of Liability), Clause 14 (Indemnification), Section 19 (Data Protection) and this Clause 15 survive termination or expiry of this Agreement.
15.13 Code Engines may assign or novate this Agreement to an affiliate, or in connection with a merger, acquisition or sale of all or substantially all of its assets, on written notice to the Subscriber.
16. On-Premise Deployment
16.1 Where expressly agreed in writing, Code Engines may licence the Service for deployment on infrastructure owned or controlled by the Subscriber (an “On-Premise Deployment”).
16.2 An On-Premise Deployment operates only while a valid licence key issued by Code Engines is installed and unexpired. The Service, or parts of it, will cease to operate upon expiry of the licence key. The Subscriber is responsible for obtaining a renewed licence key before expiry.
16.3 For an On-Premise Deployment the Subscriber is solely responsible for the hosting environment, including infrastructure and network security, operating system and database patching, physical access control, backup, disaster recovery and business continuity. Clause 8 (Managed Backup and Archiving) does not apply to an On-Premise Deployment.
16.4 Content held in an On-Premise Deployment resides in the Subscriber’s environment and is not accessible to Code Engines, except where the Subscriber grants access for support purposes in accordance with Clause 19.7.
16.5 AI Features (Section 18) require outbound connectivity from the On-Premise Deployment to the Microsoft Azure services described in Clause 18.6. Where the Subscriber does not permit that connectivity, AI Features will be unavailable.
16.6 Section 17 (Service Levels) does not apply to an On-Premise Deployment, and Code Engines is not responsible for its availability or performance.
17. Service Levels
17.1 Code Engines will use commercially reasonable efforts to make the hosted Service available for at least the Availability Target set out in the Service Level Schedule published at [INSERT URL] (the “Service Level Schedule”), which at the effective date is 99.5% of each calendar month.
17.2 “Downtime” means any period during which the hosted Service is wholly unavailable to the Subscriber’s Users, measured in whole minutes and determined by Code Engines’ monitoring. Availability in a month is calculated as the total number of minutes in that month less Downtime, divided by the total number of minutes in that month.
17.3 Downtime excludes: (a) scheduled maintenance notified under Clause 2.11; (b) emergency maintenance where urgent action is required to protect the Service; (c) unavailability of any Third Party Service, including those referred to in Section 23; (d) failure of the Subscriber’s own network, devices or internet access; (e) any suspension permitted under this Agreement, including suspension for non-payment under Clause 10.3; (f) a Force Majeure Event; and (g) any On-Premise Deployment.
17.4 The Availability Target is a service commitment and not a warranty. Consistent with Clause 9.5, no service credits or refunds are payable for a failure to meet the Availability Target.
17.4A A Subscriber may agree an Enterprise Service Level Schedule with Code Engines in writing. Where it does, that schedule prevails over the Service Level Schedule for that Subscriber, including as to any service credits.
17.5 Technical support is provided in accordance with Clause 15.2 and the support hours, severity levels and response targets set out in the Service Level Schedule. Those targets are service objectives that Code Engines uses commercially reasonable efforts to meet. They are not warranties, no service credits or other compensation are payable for a failure to meet them, and a failure to meet a target does not of itself constitute a breach of this Agreement.
18. Artificial Intelligence Features
18.1 Definitions. “AI Features” means those parts of the Service that use machine learning or large language models, including the CASY assistant, document reading and extraction, optical character recognition, semantic search, chronology generation, entity resolution, grounded question answering, summarisation, drafting assistance, timesheet narrative drafting and compliance checking. “Input” means Content and other data submitted to an AI Feature. “Output” means material generated by an AI Feature.
18.2 Availability and control. AI Features are disabled by default. They may be enabled only by an Administrator, who must first accept the AI disclosure presented in the Service on behalf of the Subscriber. An Administrator may disable AI Features for the Subscriber’s account at any time. AI Features consume prepaid AI credits and will not operate once the credit balance is exhausted.
18.3 Output is not legal advice. Output is generated by automated means, is provided as an aid to qualified legal professionals, and does not constitute legal advice. Output may be inaccurate, incomplete, out of date or misleading, and may omit material information. The Subscriber must ensure that Output is reviewed and verified by a suitably qualified person before it is relied upon, communicated to a client, or filed with any court, tribunal or authority. This Clause applies with particular force to chronologies, summaries, extracted dates, deadline calculations and compliance results.
18.4 No warranty. Code Engines does not review Output for accuracy or completeness. AI Features and Output are provided on an “as is” and “as available” basis and Code Engines gives no warranty as to their accuracy, completeness, reliability or fitness for any purpose. Clauses 13.2 and 13.8 apply to AI Features.
18.5 Professional responsibility. The Subscriber remains solely responsible for compliance with its own professional, regulatory and ethical obligations when using AI Features, including duties of competence, supervision, confidentiality and disclosure to clients. The Subscriber is responsible for determining whether its Regulator permits the use of AI Features in a given matter and for obtaining any client consent required. The Subscriber retains control over how AI Features are configured, presented and used within its practice, and remains responsible for all interactions with, and outcomes affecting, its own clients and any third party who receives Output.
18.6 Processing by Microsoft Azure. Input and Output are processed using Microsoft Azure services, namely Azure OpenAI Service, Azure AI Search and Azure AI Document Intelligence. Code Engines does not transmit Input or Output to any artificial intelligence provider other than Microsoft Azure.
18.7 No model training. Neither Code Engines nor Microsoft uses Input or Output to train, retrain, fine-tune or otherwise improve any foundation or general-purpose model. Input and Output are not shared with OpenAI. Nothing in Clause 2.14 permits Code Engines to use Confidential Information to train any generalised model.
18.8 Human review. Code Engines personnel do not read Input or Output except (a) where the Subscriber or a User submits feedback, a support request or a defect report that refers to it, or (b) where required by law.
18.8A Abuse monitoring by Microsoft. Separately from Clause 18.8, Microsoft operates abuse monitoring on the Azure OpenAI Service. Under Microsoft’s standard terms, prompts and generated content may be retained by Microsoft for up to thirty (30) days for the purpose of detecting and preventing abusive or harmful use, and content flagged by that process may be reviewed by authorised Microsoft personnel. That retention and review is performed by Microsoft and not by Code Engines, and the content is not used to train any model. Code Engines is seeking Microsoft’s approval for modified abuse monitoring with zero data retention; if and when that approval is granted, the retention and review described in this Clause will cease to apply and Code Engines will update this Clause and its Privacy Policy accordingly.
18.8B Subscriber remedy. A Subscriber that is unable to accept the retention and review described in Clause 18.8A may disable AI Features for its account under Clause 18.2, in which case no Input is submitted to the Azure OpenAI Service at all. The remainder of the Service is unaffected.
18.9 Location of processing. Azure OpenAI processing is performed in the UAE North region where regional capacity permits. Where regional capacity is unavailable, requests may be served by Microsoft’s global or multi-region model deployments, which may process Input outside the United Arab Emirates. Clause 19.5 governs such transfers. Tenant databases remain in the UAE North region at all times.
18.9A Regional processing election. Code Engines will make available an option for AI Features to be served only from Microsoft Azure deployments located in the United Arab Emirates once Microsoft provides regional capacity for that purpose (the “UAE-only option”). Where the UAE-only option is available, a Subscriber may elect it through account settings or by written notice to Code Engines. Where that election is in force, a request that cannot be served from a United Arab Emirates region will fail rather than be routed elsewhere, and Code Engines is not responsible for any resulting unavailability of AI Features. AI credits are not consumed by a request that is not sent to the model because of the election; a request that is sent and returns no useful result consumes credits in the ordinary way. Until the UAE-only option is available, a Subscriber that requires all AI processing to remain in the United Arab Emirates should not enable AI Features, and Clause 18.8B applies.
18.10 Ownership. As between the Parties, Input remains the property of the Subscriber in accordance with Clause 3.5, and Output generated from the Subscriber’s Input belongs to the Subscriber. Code Engines claims no Intellectual Property Rights in Output. The Subscriber acknowledges that Output is not unique and that similar or identical Output may be generated for other subscribers.
18.11 Restrictions. The Subscriber shall not, and shall ensure that Users do not: (a) attempt to extract, reconstruct or discover any underlying model, model weights, system prompt or training data; (b) use AI Features or Output to develop, train or improve any artificial intelligence or machine learning model, or any competing product or service; (c) circumvent any usage, rate or credit limit; or (d) submit Input that the Subscriber does not have the legal right to submit.
18.12 Charges. AI credits are charged at the rates advertised from time to time and are non-refundable. Code Engines may vary AI credit pricing on thirty (30) days’ notice. Clause 2.10 applies to any material change to AI Features.
18.13 Preview features. Features identified as preview, beta, pilot or “coming soon” are made available on an “as is” basis, without warranty, service level or support obligation, and may be changed, suspended or withdrawn at any time without notice. They should not be relied upon in live matters. To the fullest extent permitted by law, Code Engines is not liable for any loss arising from their use.
18.14 Subscriber indemnity for AI use. The Subscriber shall indemnify Code Engines against any claim, loss or expense arising from (a) the Subscriber’s use or deployment of AI Features with its own clients or any third party, (b) the Subscriber’s failure to make any disclosure or obtain any consent required by applicable law or by its Regulator, (c) any representation the Subscriber makes to a third party about the AI Features, and (d) any decision taken or outcome arising from reliance on Output. Clause 14.1 applies to the conduct of any such claim.
19. Data Protection
This Section is drafted to be self-contained so that it may be issued as a standalone Data Processing Agreement on a Subscriber’s request without amending the remainder of this Agreement.
19.1 Roles. In respect of Content, the Subscriber is the controller and Code Engines is the processor. In respect of Account Data, Code Engines is the controller. Each Party shall comply with the data protection laws applicable to it.
19.1A Subscriber responsibilities. The Subscriber warrants that it has a lawful basis for the Content it uploads and for the instructions it gives, that it has given the notices and obtained the consents that applicable law requires, and that its instructions will not cause Code Engines to breach applicable data protection law. Code Engines shall inform the Subscriber without delay if, in its opinion, an instruction infringes applicable data protection law, and may suspend the relevant processing until the Subscriber confirms or withdraws the instruction.
19.2 Applicable laws. This Section is framed by reference to UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, once issued, its Executive Regulations and, where applicable to the Subscriber, DIFC Data Protection Law No. 5 of 2020, the ADGM Data Protection Regulations 2021, the Saudi Personal Data Protection Law, India’s Digital Personal Data Protection Act 2023 and Singapore’s Personal Data Protection Act 2012.
19.2A Government Subscribers. Where the Subscriber is a government entity to which the UAE Federal Decree-Law No. 45 of 2021 does not apply by virtue of Article 2(2) of that law, this Section applies as a matter of contract, and Code Engines shall in addition comply with any written government data policy that the Subscriber notifies to it and that the Parties agree in writing.
19.3 Processing instructions. Code Engines shall process Content only (a) to provide, secure, maintain and support the Service in accordance with this Agreement, (b) as instructed in writing by the Subscriber, and (c) as required by law. Code Engines shall not sell Content, use it for advertising, or use it for its own commercial purposes. Clause 2.14 (aggregate reporting) applies only to data from which all personal data and all identifiers of the Subscriber and its clients have been irreversibly removed.
19.4 Sub-processors. The Subscriber authorises Code Engines to engage the following sub-processors to process Content. (a) Core sub-processors, engaged for every Subscriber: Microsoft Azure (hosting, database and storage); Azure OpenAI Service, Azure AI Search and Azure AI Document Intelligence (AI Features); and Microsoft (Microsoft Graph / Exchange Online) for email delivery; and Sentry (Functional Software, Inc.), for application error monitoring, which receives technical diagnostics including user identifiers, IP addresses and the page in use, and is hosted outside the United Arab Emirates. (b) Optional sub-processors, engaged only where the Subscriber enables the corresponding integration, each of which is disabled by default: Microsoft SharePoint, Outlook, Teams and Entra ID / Active Directory, Dropbox, DocuSign, Intuit QuickBooks, and Twilio Inc. together with Meta Platforms (WhatsApp), where WhatsApp messages are transmitted through the Subscriber’s own Twilio account and delivered onward by Meta. The current list of both categories is published at https://casengine.app/sub-processors/. Where the Subscriber connects its own mailbox to the Service, email is sent and read through the Subscriber’s own email provider under the Subscriber’s own agreement with that provider, and that provider is not a sub-processor of Code Engines.
19.4A Terms applying to sub-processors. Each sub-processor is engaged under a written agreement that includes that provider’s data protection terms. Where a sub-processor is a large-scale provider offering standard, non-negotiable terms, Code Engines contracts on those terms and does not purport to impose bespoke obligations upon it. Code Engines has verified that those terms impose data protection obligations on the sub-processor equivalent in substance to those in this Section, and will provide the Subscriber with a copy of, or link to, the relevant terms on request. Clause 15.1 continues to govern Code Engines’ responsibility for its subcontractors.
19.4B Changes to Core sub-processors. Code Engines shall give the Subscriber not less than thirty (30) days’ notice before engaging a new Core sub-processor, or replacing an existing one. Notice is given by email to the Administrator or by updating the published list referred to in Clause 19.4, and the thirty (30) day period runs from the earlier of those events. Code Engines may in addition describe the change in its release notes, but release notes alone do not satisfy this Clause. If the Subscriber objects on reasonable data protection grounds within that period, the Parties shall discuss a remedy in good faith; and if no remedy is agreed, the Subscriber may terminate the affected part of the Service on written notice without penalty.
19.4C Optional integrations require no advance notice. Making a new integration available in the Service is not the engagement of a sub-processor and requires no notice under Clause 19.4B, because no Content is transferred to that provider unless and until the Subscriber enables the integration. Before the Subscriber enables an integration, the Service identifies the provider concerned and the categories of Content that will be transferred to it. The Subscriber’s act of enabling an integration constitutes its authorisation for that provider to act as a sub-processor, and the Subscriber may disable the integration at any time. Code Engines will describe newly available integrations in its release notes.
19.4D What is not a change of sub-processor. The following do not constitute the engagement of a new sub-processor and require no notice under Clause 19.4B: (a) a change of model, model version, or deployment configuration within a sub-processor already listed, including a change to the artificial intelligence model used within the Microsoft Azure OpenAI Service; (b) a change to a sub-processor’s own infrastructure, internal architecture or onward sub-contractors; and (c) a change of region within an existing sub-processor’s estate, provided that Clauses 18.9 and 19.5 continue to be satisfied. Clauses 18.6 (Azure only) and 18.7 (no model training) continue to apply to any model used. A change of artificial intelligence provider is not within this Clause and does require notice under Clause 19.4B.
19.5 International transfers. Content is hosted in the UAE North region. Transfers of Content outside the United Arab Emirates occur only (a) where AI Feature capacity requires processing by Microsoft’s global or multi-region deployments as described in Clause 18.9, or (b) where the Subscriber enables an integration that transmits data to the relevant provider; or (c) where application error monitoring diagnostics, as described in Clause 19.4, are transmitted to Sentry. Such transfers are made under the data protection terms and standard contractual clauses of Microsoft or the relevant provider, and are limited to what is necessary to provide the Service.
19.5A Transfer instruments. Where the Subscriber is established in the DIFC or the ADGM, or is subject to the Saudi Personal Data Protection Law, Code Engines shall on request enter into the standard contractual clauses or other transfer instrument that the Subscriber’s applicable law requires, both for the Subscriber’s transfer of Content to Code Engines and for any onward transfer under Clause 19.5, and shall give effect to any election made under Clause 18.9A.
19.6 Security and separation. Code Engines shall implement the measures described in Clause 5, including encryption of Content in transit and at rest, authentication controls, logging and monitoring. Each Subscriber’s Content is held in a separate database. No User of one Subscriber can access the Content of another Subscriber, and Code Engines treats that separation as an absolute boundary.
19.6A Permissions within the Subscriber’s own organisation. Visibility of Content among the Subscriber’s own Users is determined by the roles and permissions that the Subscriber configures. The Subscriber is responsible for assigning those roles appropriately, including any decision to grant a User administrative rights, which will give that User visibility of Content across the Subscriber’s account. Code Engines does not warrant that any particular User will be prevented from seeing particular Content within the Subscriber’s own account, and Clause 2.3 applies.
19.7 Support access to the application. Code Engines personnel do not access Content in the ordinary course of business. Where access is necessary to resolve a support request or a defect, it is granted only through the Service’s support-access mechanism, which requires approval, is authenticated by a one-time passcode, is limited in duration, and is recorded in an audit log available to the Subscriber’s Administrator. Code Engines shall not access Content for any other purpose except as required by law or under Clause 6.1.
19.7A Administrative access to infrastructure. A small number of named Code Engines personnel hold administrative access to the hosting infrastructure, including databases and file storage, because that access is necessary to operate, secure, back up and restore the Service. That access is limited to a named list of individuals maintained within Code Engines’ information security management system; every account on that list is protected by multi-factor authentication; and the list is reviewed periodically, with each review recorded. Administrative access is not used to read Content except where necessary for a specific operational or support purpose, and Clause 4 (Confidentiality) binds those individuals at all times. Code Engines operates an information security management system aligned to ISO/IEC 27001.
19.8 Requests from individuals. Where Code Engines receives a request from an individual concerning Content, it shall not respond on the merits and shall refer the individual to the Subscriber. Code Engines shall provide the Subscriber with reasonable assistance, within a period that allows the Subscriber to meet its own statutory deadline.
19.9 Personal data breach. Clause 5.5 applies. Code Engines shall notify the Subscriber without undue delay and in any event within seventy-two (72) hours of becoming aware of a Security Breach affecting Content. Code Engines becomes aware for this purpose when it has a reasonable degree of certainty that a Security Breach has occurred, rather than on first suspicion.
19.9A Notification in stages. Where Code Engines does not hold all relevant information within that period, it shall notify within the period with the information then available, identify what remains under investigation, and provide the remainder in stages as it is established, without further undue delay. An initial notification that is incomplete does not breach Clause 19.9. Code Engines shall in each case provide the information reasonably necessary for the Subscriber to meet its own notification obligations to regulators and to affected individuals.
19.10 Audit. On reasonable written notice, and not more than once in any twelve (12) month period, Code Engines shall provide the Subscriber with its then-current security documentation and shall respond to a reasonable security questionnaire. Where the Subscriber is established in the DIFC or the ADGM, or where its Regulator or applicable law requires it, Code Engines shall in addition permit and contribute to an audit or inspection by the Subscriber or an independent auditor mandated by it, on not less than thirty (30) days’ written notice, not more than once in any twelve (12) month period save following a Security Breach, during business hours, subject to reasonable confidentiality and security conditions, and at the Subscriber’s cost. Where the Subscriber’s Regulator requires more, Clause 6.1 applies.
19.11 Retention and deletion during the term. Content is retained for the term of this Agreement. Records and documents that a User deletes within the Service are marked as deleted, cease to be accessible to Users, and are excluded from search and from AI Features, but are retained in the Subscriber’s database until termination so that they can be restored on request and so that related records remain intact. On written request from the Subscriber’s account owner identifying particular records or documents, Code Engines will permanently delete or irreversibly anonymise them, together with any data derived from them by AI Features, within thirty (30) days. Backups are retained for ninety (90) days and are then overwritten. The application audit trail is retained for the term of this Agreement and is deleted with the Subscriber’s database under Clause 19.11A.
19.11A Deletion on termination. On termination, and following the Retrieval Period described in Clauses 10.4 and 10.5, Code Engines deletes the Subscriber’s entire tenant database, its stored files and its search index in full. Code Engines will confirm that deletion in writing on request under Clause 19.13.
19.12 Sensitive personal data. The Subscriber acknowledges that the KYC, client onboarding and document management features may be used to store identity documents (including passports, national identity documents and trade licences) and, in some matters, sensitive personal data such as health, criminal-record or family information. The Subscriber is responsible for ensuring that it has a lawful basis to collect and store such data, and for applying the principle of data minimisation.
19.13 Deletion confirmation. On the Subscriber’s written request following termination, Code Engines shall confirm in writing that Content has been deleted in accordance with Clauses 10.4 and 10.5.
20. Users, Registered Clients and Portal Users
20.1 Acceptance. Each User must accept this Agreement, and each Registered Client must accept the portal terms of use published by Code Engines (the “Portal Terms”), before first using the Service. Code Engines records that acceptance together with the date, the IP address and the browser used.
20.2 Subscriber-supplied terms. The Subscriber may configure the Service to present its own terms of use to Registered Clients, either alongside the Portal Terms or in place of their visible display. Where it does so, the Portal Terms remain incorporated by reference and continue to bind each Registered Client, and the Subscriber shall ensure that its own terms refer to the Portal Terms and do not conflict with them or with this Agreement. Any terms the Subscriber presents to its Users are additional to and do not replace this Agreement.
20.3 Portal access. Registered Clients, external legal representatives and judicial assistants are granted access at the Subscriber’s discretion and only to the extent the Subscriber configures. Clause 2.3 applies to their acts and omissions.
20.4 Role in respect of portal users. Code Engines processes the personal data of Registered Clients and other portal users as processor on the Subscriber’s behalf, save for the limited Account Data in respect of which Code Engines is controller under Clause 19.1.
21. Changes to this Agreement
21.1 Code Engines may amend this Agreement. Code Engines will give the Subscriber not less than thirty (30) days’ notice of any amendment that materially and adversely affects the Subscriber, by email to the Administrator or by notice within the Service.
21.2 Continued use of the Service after an amendment takes effect constitutes acceptance of it. Where the Subscriber does not accept an amendment falling within Clause 21.1, the Subscriber may terminate this Agreement by written notice given before the amendment takes effect, and Clauses 10.4 and 10.5 will apply.
21.3 Each version of this Agreement carries a version number and an effective date, and the current version is published at the URL stated at the head of this Agreement.
22. Compliance, Sanctions and Financial Crime
22.1 Each Party warrants that neither it nor any of its officers is subject to sanctions administered by the United Nations, the United Arab Emirates, the United States, the United Kingdom or the European Union, and that it shall not use or provide the Service in breach of applicable sanctions or export control laws.
22.2 Each Party shall comply with all applicable anti-bribery, anti-corruption, anti-money-laundering and counter-terrorist-financing laws.
22.3 The KYC features of the Service are an aid to the Subscriber’s own customer due diligence. They do not constitute sanctions screening, politically exposed person screening, or an anti-money-laundering compliance programme, and they do not discharge the Subscriber’s obligations under applicable law.
23. Third Party Services
23.1 The Service may allow the Subscriber to access, use or integrate with products and services provided by third parties, including those listed in Clause 19.4 (“Third Party Services”). Third Party Services are not part of the Service and are not subject to the warranties, indemnities, service commitments or other obligations in this Agreement.
23.2 Access to and use of any Third Party Service is subject to the separate terms of its provider, and the Subscriber is responsible for accepting those terms and for any fees charged by that provider. The availability of a Third Party Service through the Service does not imply endorsement of, or affiliation with, its provider.
23.3 Code Engines does not control Third Party Services and is not responsible for their availability, security, accuracy or continued interoperability. A provider may change or withdraw its service or its interface at any time, and Code Engines may consequently suspend or discontinue the corresponding integration. Where the Subscriber enables an integration, it authorises the transfer of the relevant data to that provider.
24. API Access and Account Disputes
24.1 Clause 3.7 does not prohibit the use of interfaces that Code Engines expressly makes available for programmatic access, including the Service’s application programming interface and the AI Features.
24.2 API credentials are Confidential Information. The Subscriber is responsible for keeping them secure and for all activity carried out using them. Code Engines may apply rate and fair-use limits, and may suspend API access where use threatens the stability or security of the Service, in which case Clause 1.13 (Security Emergency) may apply.
24.3 Disputes may arise between partners, firm members or others as to ownership of, or access to, an account and its Content, including on the dissolution or division of a firm. Code Engines does not adjudicate such disputes. Code Engines may, but is not obliged to: (a) request documentation it reasonably considers necessary to establish ownership; (b) require joint written instructions from all parties claiming ownership before making any change to the account; (c) suspend access to the account until the parties provide written evidence, in a form reasonably satisfactory to Code Engines, that the dispute is resolved; or (d) act on an order of a court or competent authority.
24.4 Any step taken under Clause 24.3 is for the purpose of account access only, is based solely on the information provided to Code Engines, and does not determine any Party’s underlying rights. Clause 6.2 (return of Content) continues to apply throughout. To the fullest extent permitted by law, Code Engines is not liable for any decision taken or not taken in good faith in connection with an ownership dispute.