Legal · Terms & DPA

Terms of Use &
Data Processing
Agreement.

VersionV1.1 EffectiveAugust 2026 StatusPilot Phase JurisdictionState of Florida, USA VenuePalm Beach County, FL Contactlegal@kazu.global
Part I
Terms of Use
§ 1 — § 12
§1 · Definitions

Key terms.

"Agreement"
These Terms of Use and the Data Processing Agreement (Part II), together with any Order Form, collectively forming the binding agreement between Kazu and the Client.
"Kazu"
Kazu Technologies, a company incorporated under the laws of the State of Florida, USA, operating the Kazu ERP platform.
"Client"
The business entity or individual that subscribes to the Services and has agreed to this Agreement on behalf of their organization.
"Authorized User"
Any individual granted access to the Services by the Client (e.g., employees, contractors, agents).
"Services"
The Kazu cloud-based ERP platform, including all modules (inventory, production, CRM, purchasing, finance integrations, workflows), APIs, and related support services.
"Client Data"
All data submitted by or on behalf of the Client through the Services, including data about the Client's customers, employees, suppliers, inventory, and financial records.
"Order Form"
A written or electronic order specifying the subscription tier, number of users, term, and fees applicable to the Client's use of the Services.
"Subscription Term"
The period during which the Client is authorized to access the Services, as specified in the applicable Order Form.
"Pilot Phase"
The current early-access period during which Kazu operates the Services, including the QuickBooks Online Integration, at a limited scale as described in §4.6 below.
Pilot Phase

Kazu is currently in a pilot phase. The Services, including the QuickBooks Online Integration, are being made available to a limited set of early Clients while Kazu validates the platform and prepares the integration for review by Intuit. Pricing, specific terms, and integration scope applicable during the Pilot Phase may be communicated separately and, where indicated, supersede the corresponding provisions of this Agreement for the duration of that period. See §4.6.

§2 · Acceptance

Acceptance & Access.

By accessing or using the Services, the Client agrees to be bound by this Agreement. If the Client is entering this Agreement on behalf of a business entity, they represent that they have authority to bind that entity. If the Client does not agree, they must not use the Services.

Access to the Services is granted only upon execution of an Order Form and payment of applicable fees. Kazu reserves the right to modify these Terms at any time, with 30 days' written notice to active Clients prior to material changes taking effect.

§3 · License

License & Permitted Use.

Subject to the terms of this Agreement and payment of applicable fees, Kazu grants the Client a limited, non-exclusive, non-transferable, revocable license to access and use the Services during the Subscription Term solely for the Client's internal business operations.

Restrictions. The Client must not, and must not permit any third party to:

  • Copy, modify, adapt, translate, or create derivative works of the Services or any component thereof
  • Reverse engineer, disassemble, decompile, or attempt to derive source code from the Services
  • Sell, resell, sublicense, rent, lease, or otherwise transfer rights to the Services to any third party
  • Use the Services to build a competing product or service, or to benchmark against competing products for publication
  • Access the Services using automated means (bots, scrapers) except as expressly permitted by Kazu's API documentation
  • Use the Services to process, store, or transmit unlawful, harmful, or abusive content
  • Circumvent any authentication, access controls, or security measures of the Services
  • Use the Services in any way that violates applicable law or regulation
§4 · Fees

Subscriptions, Fees & Payment.

4.1 Fees. Client agrees to pay the fees specified in the applicable Order Form. All fees are in US Dollars and are non-refundable except as expressly stated in this Agreement or required by applicable law.

4.2 Billing. Subscriptions are billed in advance on a monthly or annual basis, as selected in the Order Form. Kazu reserves the right to modify pricing with 60 days' written notice prior to the start of the next renewal term.

4.3 Late Payment. Amounts past due accrue interest at 1.5% per month (or the maximum rate permitted by law, whichever is lower). Kazu may suspend access after 15 days of non-payment following written notice.

4.4 Taxes. Fees are exclusive of applicable taxes. Client is responsible for all sales, use, value-added, or similar taxes, excluding taxes based on Kazu's net income.

4.5 Renewals. Subscriptions automatically renew for successive terms equal to the initial Subscription Term unless either party provides written notice of non-renewal at least 30 days before the end of the current term.

4.6 Pilot, Trial, and Beta Periods. During any pilot, trial, or beta period — including Kazu's current Pilot Phase — specific pricing, fees, and terms applicable to the Client will be communicated separately (e.g., via Order Form or written correspondence) and, to the extent inconsistent, supersede this Section for the duration of that period.

§5 · Responsibilities

Client Responsibilities.

5.1 Account Security. Client is responsible for maintaining the confidentiality of all account credentials and for all activities that occur under its account. Client must notify Kazu immediately at support@kazu.global upon becoming aware of any unauthorized access.

5.2 Authorized Users. Client is responsible for ensuring that all Authorized Users comply with this Agreement. Client must promptly revoke access for any Authorized User who is no longer authorized or who violates this Agreement.

5.3 Client Data Responsibility. Client is solely responsible for the accuracy, legality, and appropriateness of all Client Data submitted to the Services. Client represents and warrants that it has all necessary rights, consents, and permissions to submit Client Data to the Services and to authorize Kazu to process it as described in this Agreement.

5.4 Compliance. Client is responsible for ensuring its use of the Services complies with all applicable laws, regulations, and industry standards in the jurisdictions where it operates, including those related to data privacy, employment, and financial reporting.

5.5 Integrations. Client is responsible for its use of third-party integrations connected to the Services, including the QuickBooks Online Integration. Client's use of QuickBooks Online remains subject to Intuit's own terms of service and privacy policy, which are independent of this Agreement. Kazu is not liable for the acts or omissions of third-party integration providers. Details on what data is exchanged with QuickBooks and how it is used are set out in the Kazu Privacy Policy, which is incorporated into this Agreement by reference.

§6 · IP

Intellectual Property.

6.1 Kazu Ownership. Kazu retains all right, title, and interest — including all intellectual property rights — in and to the Services, the Kazu platform, underlying technology, documentation, and any improvements, modifications, or derivative works thereof. No rights are granted to the Client other than the limited license in §3.

6.2 Client Data Ownership. Client retains all right, title, and interest in and to Client Data. Kazu acquires no ownership rights in Client Data by virtue of this Agreement. Client grants Kazu a limited, worldwide license to use, process, and store Client Data solely to provide and improve the Services as described in this Agreement and the DPA.

6.3 Feedback. If Client provides suggestions, ideas, or feedback about the Services ("Feedback"), Kazu may use such Feedback without restriction or compensation to Client.

6.4 Usage Data. Kazu may collect and use aggregated, de-identified data derived from Client's use of the Services to improve the platform and generate industry benchmarks. Such data will not identify the Client or its users.

§7 · Confidentiality

Confidentiality.

Each party ("Receiving Party") may receive confidential information from the other party ("Disclosing Party"). "Confidential Information" means any non-public information disclosed that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure.

The Receiving Party agrees to: (a) hold Confidential Information in strict confidence using at least the same degree of care it uses to protect its own confidential information (but no less than reasonable care); (b) use Confidential Information only to fulfill obligations under this Agreement; and (c) disclose Confidential Information only to employees or contractors who need to know it and are bound by confidentiality obligations at least as protective as those herein.

Confidentiality obligations do not apply to information that: (i) is or becomes publicly known through no breach of this Agreement; (ii) was rightfully known before disclosure; (iii) is rightfully received from a third party without restriction; or (iv) is required to be disclosed by law or court order, provided prompt written notice is given to the Disclosing Party where legally permissible.

§8 · Warranties

Warranties & Disclaimers.

8.1 Kazu Warranty. Kazu warrants that the Services will perform materially in accordance with its documentation during the Subscription Term, and that it will employ commercially reasonable security measures to protect Client Data. Kazu's sole obligation for breach of this warranty is to use commercially reasonable efforts to correct the non-conformance, or if correction is not feasible, to provide a pro-rated refund for the affected period.

8.2 Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN §8.1, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." KAZU DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. KAZU DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR THAT ALL DEFECTS WILL BE CORRECTED.

§9 · Liability

Limitation of Liability.

9.1 Exclusion of Consequential Damages. IN NO EVENT SHALL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF PROFITS, REVENUE, DATA, OR BUSINESS OPPORTUNITIES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

9.2 Cap on Liability. EACH PARTY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CLIENT IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

9.3 Exceptions. The limitations in §9.1 and §9.2 do not apply to: (a) Client's breach of §3 (License Restrictions); (b) either party's indemnification obligations; (c) a party's gross negligence or willful misconduct; or (d) a party's breach of confidentiality obligations under §7.

§10 · Indemnification

Indemnification.

10.1 By Kazu. Kazu will defend Client against any third-party claim alleging that the Services, as provided by Kazu and used in accordance with this Agreement, infringe a third party's intellectual property rights, and will indemnify Client against damages and costs finally awarded by a court.

10.2 By Client. Client will defend, indemnify, and hold harmless Kazu and its officers, directors, employees, and agents from and against any claims, damages, costs, and expenses (including reasonable attorneys' fees) arising from: (a) Client Data; (b) Client's or any Authorized User's use of the Services in violation of this Agreement; (c) Client's violation of applicable law; or (d) Client's breach of its representations and warranties.

§11 · Termination

Term & Termination.

11.1 Term. This Agreement begins on the date the Client first accesses the Services and continues for the Subscription Term, renewing as described in §4.5.

11.2 Termination for Cause. Either party may terminate this Agreement immediately on written notice if the other party: (a) materially breaches this Agreement and fails to cure within 30 days of written notice; (b) becomes insolvent, makes an assignment for the benefit of creditors, or becomes subject to bankruptcy proceedings; or (c) ceases to operate as a going concern.

11.3 Termination for Convenience. Client may terminate this Agreement at the end of any Subscription Term by providing 30 days' written notice. No refunds are provided for early cancellation mid-term except as required by applicable law.

11.4 Effect of Termination. Upon termination: (a) all licenses granted to Client immediately terminate; (b) Client must cease all use of the Services; (c) Kazu will make Client Data available for export for 30 days, after which it will be deleted in accordance with the DPA (§18); and (d) all outstanding fees become immediately due and payable.

11.5 Survival. Sections §6, §7, §8.2, §9, §10, §11.4, and §12 survive termination of this Agreement.

§12 · General

General Provisions.

Governing Law & Venue. This Agreement is governed by the laws of the State of Florida, without regard to conflict of law principles. Any dispute shall be resolved exclusively in the state or federal courts located in Palm Beach County, Florida. Both parties consent to personal jurisdiction in those courts.

Entire Agreement. This Agreement, including any Order Forms and Appendices, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior agreements. In the event of a conflict, Order Forms take precedence over these Terms, which take precedence over Appendices.

Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable; all other provisions remain in full force. Waiver. Failure to enforce any provision does not constitute a waiver of future enforcement rights.

Assignment. Client may not assign this Agreement without Kazu's written consent. Kazu may assign this Agreement in connection with a merger, acquisition, or sale of substantially all its assets.

Force Majeure. Neither party is liable for delays or failures caused by circumstances beyond its reasonable control, including natural disasters, acts of government, internet outages, or pandemics, provided the affected party gives prompt notice and uses reasonable efforts to resume performance.

Notices. Legal notices must be sent to Kazu at legal@kazu.global. Notices to Client will be sent to the email address on the applicable Order Form.

Part II
Data Processing Agreement
§ 13 — § 19

This Data Processing Agreement ("DPA") forms part of the Agreement between Kazu and Client and governs Kazu's processing of personal data contained within Client Data.

§13 · DPA Scope

DPA Scope & Roles.

13.1 Applicability. This DPA applies where Kazu processes personal data on behalf of Client in connection with the Services. "Personal data" means any information relating to an identified or identifiable natural person, as defined under applicable law.

13.2 Roles. For the purposes of this DPA:

  • Client is the data controller — the party that determines the purposes and means of processing personal data
  • Kazu is the data processor — the party that processes personal data on behalf of, and under the instructions of, the Client

13.3 Details of Processing. The categories of data subjects, types of personal data processed, and processing purposes are set out in Appendix A to this Agreement.

§14 · Processing Instructions

Processing Instructions & Obligations.

14.1 Instructions. Kazu will process personal data only on documented instructions from Client, including those set out in this Agreement and any Order Form, unless required to process otherwise by applicable law.

14.2 Purpose Limitation. Kazu will not process Client Data for any purpose other than: (a) providing and maintaining the Services; (b) complying with applicable law; (c) as otherwise expressly authorized by Client in writing. Kazu will not use Client Data to develop, train, or improve artificial intelligence or machine learning models without Client's explicit written consent.

14.3 Personnel. Kazu ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and have received relevant data protection training.

14.4 Cooperation. Kazu will provide reasonable assistance to Client in fulfilling Client's obligations under applicable data protection law, including with respect to data protection impact assessments and responses to regulatory inquiries.

§15 · Sub-processors

Sub-processors.

15.1 Authorization. Client grants Kazu general authorization to engage sub-processors to assist in the provision of the Services. Kazu maintains a current list of sub-processors and makes it available to Client upon request.

15.2 Obligations. Kazu will: (a) enter into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this DPA; (b) remain liable to Client for the acts and omissions of sub-processors to the same extent Kazu would be liable if performing the processing directly.

15.3 Changes to Sub-processors. Kazu will provide Client at least 14 days' prior written notice before adding or replacing a sub-processor where such change involves access to Client Data. If Client reasonably objects on data protection grounds, the parties will work in good faith to resolve the objection. If unresolved within 30 days, Client may terminate the applicable Services with a pro-rated refund.

§16 · Security

Security & Breach Notification.

16.1 Security Measures. Kazu will implement and maintain appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are described in Appendix B.

16.2 Breach Notification. In the event of a personal data breach affecting Client Data, Kazu will:

  • Notify Client without undue delay and in any event within 48 hours of becoming aware of the breach
  • Provide Client with sufficient information to meet any breach notification obligations under applicable law (including Florida FIPA's 30-day notification requirement)
  • Cooperate with Client and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the breach
Florida FIPA Obligation

Under Florida FIPA (Fla. Stat. § 501.171), Client — as the data controller — is responsible for notifying affected Florida residents within 30 days of determining a breach. Kazu's 48-hour notification to Client is designed to give Client sufficient time to meet this obligation.

§17 · Data Subject Rights

Data Subject Rights.

17.1 Assistance. Taking into account the nature of processing and the information available to Kazu, Kazu will provide reasonable assistance to Client in responding to requests from data subjects exercising their rights under applicable data protection law.

17.2 Redirection. If Kazu receives a data subject request directly relating to Client Data, Kazu will promptly notify Client and, where legally permissible, refrain from responding until directed by Client.

17.3 Timing. Kazu will respond to Client requests for assistance under this section within 10 business days of receipt.

§18 · Deletion

Data Deletion & Return.

18.1 During the Term. Client may export or delete Client Data at any time through the platform's self-service tools.

18.2 Upon Termination. Following expiration or termination of the Agreement:

  • Client Data remains accessible for export for 30 days following the termination date ("Export Window")
  • After the Export Window, Kazu will securely delete or render irrecoverable all Client Data from its systems and those of its sub-processors, within 60 days
  • Kazu will provide written certification of deletion upon Client's written request

18.3 Backup Retention. Encrypted backup copies of Client Data may persist for up to 90 days beyond the deletion date due to backup rotation schedules, after which they are permanently deleted.

§19 · Audit

Audit Rights.

19.1 Documentation. Kazu will maintain records of its processing activities relating to Client Data and make them available to Client upon written request.

19.2 Audit. Kazu will allow for and contribute to audits, including inspections, conducted by Client or a mandated auditor, no more than once per calendar year, with at least 30 days' prior written notice. Audits must be conducted during business hours, must not unreasonably disrupt Kazu's operations, and are subject to reasonable confidentiality obligations. Client bears all costs of such audits.

19.3 Certification Alternative. In lieu of an on-site audit, Kazu may satisfy Client's audit requirements by providing a current SOC 2 Type II report, ISO 27001 certificate, or equivalent third-party security assessment, where available.

Appendices
Processing Details & Security Measures
A & B
Appendix A · Processing Details

Data processing details.

A.1 Subject Matter & Duration

Kazu processes personal data for the purpose of providing the Services described in this Agreement. Processing continues for the duration of the Subscription Term and, where applicable, the post-termination Export Window and backup retention period described in §18.

A.2 Categories of Data Subjects

  • Client's employees and contractors (Authorized Users of the platform)
  • Client's customers and prospects (data entered into the CRM module)
  • Client's suppliers and vendors (data entered into the purchasing module)
  • Any other natural persons whose data Client chooses to enter into the Services

A.3 Types of Personal Data

ModuleTypical personal data processed
User accountsName, business email, job title, login credentials, MFA data
CRMCustomer name, contact info, communication history, purchase history
PurchasingVendor contacts, names, email addresses, phone numbers
HR / Payroll (if enabled)Employee names, roles, hours worked (no sensitive categories by default)
Platform logsUser activity logs, IP addresses, session data, timestamps

A.4 Purposes of Processing

  • Providing, hosting, and maintaining the Kazu ERP platform and its modules
  • Authenticating and authorizing Authorized Users
  • Enabling Client workflows, reporting, and integrations
  • Providing technical support and troubleshooting
  • Security monitoring, fraud prevention, and audit logging
  • Complying with applicable legal obligations

A.5 Sub-processors (Representative List)

CategoryPurposeLocation
Cloud infrastructureHosting, compute, storage, databaseUSA
Payment processorSubscription billingUSA
Email deliveryTransactional & notification emailUSA
Customer supportHelp desk & ticketingUSA
AnalyticsProduct usage analytics (aggregated)USA
Security monitoringThreat detection, loggingUSA
Appendix B · Security Measures

Technical & organizational security measures.

The following measures describe the technical and organizational security controls Kazu maintains to protect Client Data, as referenced in §16.1 of this DPA.

B.1 Access Control

  • Multi-factor authentication (MFA) required for all internal systems
  • Role-based access control (RBAC) with least privilege
  • Access revoked within 24 hours of personnel departure
  • Quarterly access reviews for all privileged roles

B.2 Encryption

  • Data in transit: TLS 1.2+ (TLS 1.3 preferred)
  • Data at rest: AES-256 encryption
  • Encrypted backups stored separately from primary data
  • Key management via dedicated KMS; annual rotation

B.3 Network Security

  • Web Application Firewall (WAF) on all public endpoints
  • Production / staging / dev environments fully isolated
  • DDoS protection via cloud provider
  • Network traffic monitored for anomalies

B.4 Availability & Backup

  • Daily automated encrypted backups
  • Geographically separate backup storage
  • Backup restoration tested quarterly

B.5 Secure Development

  • OWASP Top 10 practices in all development
  • Automated SAST/DAST scanning in CI/CD pipeline
  • Peer code review for all changes
  • Annual vulnerability assessments and penetration testing

B.6 Organizational Measures

  • Annual security awareness training for all personnel
  • Documented incident response plan with tested procedures
  • Written DPA with all sub-processors
  • Annual policy review and update cycle