Publisher

Terms of use for AI agent orchestration

Duale AI's Terms of Use set the rules for using its AI agent orchestration Platform, covering data processing, model routing, and prohibited uses.

Terms of Use for Duale AI's AI Agent orchestration Platform, covering definitions, responsibilities, prohibited uses, data handling, and liability.

  • Defines Platform, Customer, User, Task, Tool, Model pool, and related terms.
  • Splits provider and deployer obligations under Regulation (EU) 2024/1689.
  • Lists prohibited uses from the Regulation and from the contract itself.
  • Covers GDPR roles, data portability under the Data Act, and security incident timelines.
  • Sets a twelve-month liability cap with exclusions for gross negligence and GDPR breach.

Summaries were generated by AI. Generative AI is experimental.

Publisher

DUALE AI SAS, a French Simplified Joint Stock Company (SAS) with capital of €10,000

  • Paris Trade Register: 994 521 128
  • Registered office: 60 rue François 1er, 75008 Paris, France
  • Publication Director: Clémence Lesné
  • Email: contact+info@mail.duale.ai

Hosting:

  • Website: Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, United States
  • Application data: Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Germany

Definitions

  • Platform: the AI Agent orchestration services Duale AI provides through its SDK and API, together with the web interface for administration and usage analytics
  • Customer: legal entity or individual acting in a professional capacity, holding a contract with Duale AI
  • User: individual authorized by a Customer to access the Platform
  • Services: the Platform’s functionalities, including submitting, orchestrating, and managing agentic tasks
  • AI Agents: artificial intelligence systems configured via the Platform
  • Task: one AI Agent run, guided by an objective, lasting from a few minutes to several days
  • Tool: a function the Customer develops and exposes to the AI Agent. Duale AI calls the Tool, the Customer executes it
  • Built-in tool: a function Duale AI develops and offers to the AI Agent alongside the Customer’s Tools. Duale AI calls it, Duale AI executes it
  • Model pool: the list of language models the Customer authorizes
  • Provider key: the access the Customer supplies to its own model providers
  • Wallet: the balance in euros the Customer loads in advance
  • Audit log: the record of configuration, access, routing dispatch, and task lifecycle events listed on the Intended purpose, excluded uses, and behavioral constraints page. It records Tool dispatch decisions by name, but not whether a Tool ran, succeeded, or what it returned
  • Usage analytics: the execution statistics the Platform presents in its web interface
  • Content: data, text, files submitted by the User
  • Outputs: results generated by AI Agents

Purpose

These Terms of Use set the rules for using the Platform. See the Terms of sale for the prepaid credit platform for commercial terms.

Acceptance

You accept these Terms by ticking a box when you create the account. Duale AI does not pre-tick that box. Mere browsing does not constitute acceptance.

Duale AI retains proof of your acceptance: timestamp, version of Terms accepted, IP address, and user action.

Platform Access

Access to the Platform is limited to Users whom a Customer with an active contract has authorized. Users must be at least 18 years old.

Your credentials are personal and confidential. You are responsible for all activity on your account.

Artificial Intelligence Services

Service Description

Through the Platform, Users submit, orchestrate, and manage AI Agent tasks that run on language models.

Data Processing and Enrichment

The Platform can:

  • Store and index your documents to make them accessible to AI Agents
  • Perform internet searches (public data only) and retrieve the pages they return, to enrich responses
  • Run a program an AI Agent writes in a fresh sandbox, separate from your systems, and return what it printed. The AI Agent decides whether that program reaches the internet for each Tool call. The Platform has no Customer-level network setting

Internal models: Duale AI uses open-source models hosted on its European infrastructure for document indexing and search result ranking. This processing stays on Duale AI’s infrastructure.

Web-search features are intended for public data. Do not include personal data in web-search queries unless the Customer has a lawful basis and the applicable order covers the processing.

Limitations

AI Agents can:

  • Make mistakes or “hallucinate” (invent information)
  • Reproduce biases
  • Vary in quality depending on complexity

How the Platform selects a model

The Customer declares the Model pool and supplies its own Provider keys. For each message, the Platform selects from that pool the model that handles the request. Duale AI never calls a model outside the Model pool.

Routing is not deterministic. Two identical tasks can run on different models, and a single Task can call several providers. Duale AI records the selected model in the Usage analytics.

The Customer sets these routing criteria: target accuracy, cost sensitivity, speed preference, priority, and required and preferred skills. The criteria are weightings. They steer the choice; they never forbid one.

Model skill labels describe capabilities measured on public benchmarks. They do not describe uses Duale AI recommends. If no model in the Model pool carries the requested skill, the Platform falls back to a general-purpose model.

What the Platform does not do

Tool calls arrive at least once. The same call can reach you twice or more. You deduplicate on your side. If a duplicated call moves money, sends a message, or writes to a third-party system, the correction is yours.

Duale AI does not stop a Task for you. The AI Agent that submitted a Task can stop it and every Task started under it. No other party can. Revoking a Provider key prevents new Tasks from starting; it does not stop those already running. A stop does not undo a call already sent to a Provider or a Tool: that call runs to its end.

Tool execution is asynchronous. You set a timeout. If it expires without a result, the AI Agent continues on a best-effort basis and the execution is not confirmed.

Deadlines are absolute dates, never relative durations.

An interrupted Task does not resume. Continuing a conversation needs a Task that finished successfully, so after an interruption you submit a new Task. It starts without the interrupted Task’s history and carries a new deadline that you set.

Who is responsible for what

Under the Platform’s documented intended purpose, Duale AI is the provider under Regulation (EU) 2024/1689 and the Customer is the deployer. This split can shift: Article 25(1)(c) makes the Customer the provider if it changes the system’s intended purpose and turns it into a high-risk system.

Duale AI does not accept that change. The Intended purpose, excluded uses, and behavioral constraints page lists the excluded uses and sets out the only open path: write to Duale AI at contact+highrisk@mail.duale.ai before you start, and obtain a separate signed agreement. Duale AI answers within 15 working days. Without a signed agreement, the use stays excluded.

Duale AICustomerUser
Infrastructure securityAI Agent configurationUse in accordance with the Terms
Routing algorithmModel pool declarationReport anomalies
Internal modelsHuman oversight over its Tools
Correction of defectsCompliance with prohibited uses
  • Duale AI
    Infrastructure security
    Customer
    AI Agent configuration
    User
    Use in accordance with the Terms
  • Duale AI
    Routing algorithm
    Customer
    Model pool declaration
    User
    Report anomalies
  • Duale AI
    Internal models
    Customer
    Human oversight over its Tools
    User
  • Duale AI
    Correction of defects
    Customer
    Compliance with prohibited uses
    User

No clause of this contract shifts an obligation the Regulation places on Duale AI. Each party answers for its own obligations before the market surveillance authority.

Output oversight

You decide where to place human oversight. The Platform imposes no review step and builds none for you. You develop the Tools the AI Agent calls, and you put your own review policy inside them. The Platform gives you one control: the AI Agent that submitted a Task can stop it and everything under it.

Duale AI recommends human oversight for external communications, code shipped to production, and any use with contractual or financial effect.

Uses prohibited by the Regulation

Article 5 of Regulation (EU) 2024/1689 has prohibited eight practices since February 2, 2025, and adds two more from December 2, 2026: manipulative techniques, exploiting vulnerabilities, social scoring, predicting the risk of an offence, scraping faces, inferring emotions at work and in education, sensitive biometric categorization, real-time remote biometric identification, then non-consensual intimate material and child sexual abuse material.

These prohibitions bind you directly, without passing through this contract. Their exact wording, exceptions, and dates are in the Regulation: https://eur-lex.europa.eu/eli/reg/2024/1689/oj (opens in a new tab)

The fines in Article 99 target operators, providers as well as deployers. Duale AI answers for its provider obligations, the Customer for its deployer obligations.

Uses prohibited by Duale AI

These prohibitions come from the contract, not from Article 5 of the Regulation:

  • Making an automated decision about a person without having arranged human oversight
  • Producing illegal content: hate speech, disinformation, child sexual abuse material
  • Hacking a system, bypassing it, or running an offensive operation against a computer system
  • Impersonating someone
  • Using the Platform as a safety component of a system critical to people’s safety

Transparency: Who informs whom

Article 50 of Regulation (EU) 2024/1689 applies from August 2, 2026. It places the marking of synthetic outputs on the provider, and informing exposed persons on the deployer. The Regulation sets the detail. This contract adds only three rules.

Duale AI answers for its provider obligations, including machine-readable marking and a means of detecting it. No clause of this contract shifts them onto the Customer.

The Customer does not alter markings. It does not remove, hide, or deliberately alter any marking attached to Outputs, and offers no tool that does so.

Duale AI does not alter incoming markings, those present in the Content you submit.

The Platform exposes no conversational interface to natural persons: the Customer’s code calls it through the SDK and the API. If the Customer re-exposes Outputs to natural persons, under its own name, it becomes the provider of that system, and Article 50 then requires it to inform those persons. Duale AI exposes a unique identifier and a description per AI Agent for that purpose.

Health data

The standard Duale AI offering does not include the HDS certification required by Article L1111-8 of the French Public Health Code. Health data processing requires a separate written review and agreement before use: contact+hds@mail.duale.ai

Your Obligations

  • Use the Platform in accordance with these Terms and with Intended purpose, excluded uses, and behavioral constraints, which states its intended purpose and limits
  • Deduplicate Tool calls on your side, and build a compensating action for every Tool whose effect is irreversible
  • Keep your credentials secret and do not share them
  • Do not hack, bypass, or test security without authorization
  • Respect intellectual property rights of Duale AI and third parties
  • Report any unauthorized access within 24 hours
  • Do not resell access to the Platform as such

However, you have the right to embed the Platform in your own product and expose it to your users, under your own name and responsibility. You then remain Duale AI’s sole contractual counterparty.

Content and Outputs

Your content remains yours. You grant Duale AI a non-exclusive, worldwide license for the duration of the contract, solely for the purpose of providing the Services.

AI outputs belong to you, subject to two reservations: third-party rights in training data or source content, and the originality requirements of copyright law.

EU law protects a work only if it is the author’s own intellectual creation. Purely AI-generated content, without significant human creative input, does not necessarily qualify for copyright protection.

Prohibited content: illegal, hateful, discriminatory, spam, disinformation, infringement of third-party rights.

Moderation: Duale AI has the right to remove illegal content or suspend an account. Duale AI gives reasons for each moderation decision and notifies the person concerned.

Intellectual Property

The Platform belongs to Duale AI. You have the right to use it while the contract is active, not to copy or resell it.

Personal Data

Controller for account, billing, and security data: DUALE AI SAS; DPO: contact+dpo@mail.duale.ai

For the Content you submit, Duale AI acts as processor. See the “Data processing agreement (Article 28 GDPR)” section of the Terms of sale for the prepaid credit platform.

Data collected: name, email, connection logs, platform usage.

Legal bases (GDPR Art. 6):

  • Contract performance (Art. 6.1.b): account management, Service provision
  • Legal obligation (Art. 6.1.c): invoices, security logs
  • Legitimate interest (Art. 6.1.f): Service improvement, fraud prevention

Retention periods: the full table is in the Privacy policy for personal data and AI services, section Retention periods.

Your rights (GDPR Art. 15-22): access, rectification, erasure, restriction, portability, objection → contact+privacy@mail.duale.ai (response within 1 month)

International transfers: see Subprocessors and data transfer safeguards. Transfers outside the European Economic Area rely on the Data Privacy Framework where it applies, or on the 2021 standard contractual clauses with supplementary measures where required.

Subprocessors: the subprocessor list sits on the Subprocessors and data transfer safeguards page. The data processing agreement required by Article 28 GDPR forms the “Data processing agreement (Article 28 GDPR)” section of the Terms of sale for the prepaid credit platform. Questions: contact+dpa@mail.duale.ai

The model providers you call with your own Provider keys are not Duale AI’s subprocessors. They are your recipients, and putting that transfer on a lawful footing is your responsibility.

Full details: Privacy policy for personal data and AI services

Data Portability and Export

Regulation (EU) 2023/2854 (Data Act) applies from September 12, 2025.

What you can retrieve, and how:

  • Audit log: a tenant administrator exports it from the web interface, in a standard format
  • Usage analytics: you view it in the web interface. You cannot export it through the API
  • Prompts, outputs, and configurations: on request to contact+support@mail.duale.ai

Timelines and fees:

  • Change notice: 2 months maximum
  • Transition period: 30 days maximum
  • After the transition period ends, you keep at least 30 days to retrieve your data
  • Export fees: none (switching charges eliminated from January 12, 2027)

Security

Duale AI encrypts data in transit. It applies application-level encryption at rest to Library documents and derived search data, database backups, and reporting copies. The public-page Web cache follows the separate rule stated in the Privacy policy for personal data and AI services. Duale AI also requires multi-factor authentication for sensitive account changes, separates data per Customer, controls access by role, and records configuration, access, and task lifecycle events. The binding list is in the Terms of sale for the prepaid credit platform, section Data processing agreement (Article 28 GDPR).

When an incident requires notification under applicable law, Duale AI:

  • warns you within 24 hours of becoming aware of the incident;
  • notifies you of the incident within 72 hours: initial assessment, severity, indicators of compromise;
  • hands you a final report within one month: detailed description, root cause analysis, corrective measures.

Personal data breach notification follows a separate rule, depending on whether Duale AI acts as controller or as processor. See the Privacy policy for personal data and AI services, section Security.

Report a vulnerability: contact+security@mail.duale.ai (responsible disclosure program)

Availability

Duale AI guarantees no figure for uptime. Duale AI aims for a service available 24/7 without guaranteeing it, warns 48 hours ahead of scheduled maintenance, and takes the service down without notice for a security emergency.

If the service is unavailable for more than 72 consecutive hours, the Customer can terminate immediately and Duale AI refunds the balance in full. The detail is in the Terms of sale for the prepaid credit platform, section Availability.

Liability

AI outputs are provided as is. They can contain errors or biases.

Cap: over a rolling twelve months, across all claims combined, Duale AI owes no more than the amounts the Customer paid during the twelve months preceding the event giving rise to the claim.

Exclusions: indirect damages, including lost revenue, reputational harm, and data loss.

The cap does not apply in cases of:

  • Gross negligence (faute lourde) or willful misconduct (dol) by Duale AI
  • Serious and established breach of GDPR obligations that caused damage
  • Personal injury
  • Damage falling under product liability for defective products, towards the injured natural person

Suspension and Termination

Service stops at a zero balance: when the Wallet reaches zero, the service stops. A Task submitted with an insufficient balance is rejected at submission.

Suspension by Duale AI: in case of serious Terms violation, fraud, security risk, or authority request. Duale AI notifies the User by email, with reasons.

Termination by the Customer: at any time, no notice, no fee. The contract has no fixed term and carries no commitment period.

Termination by Duale AI without fault: 3 months’ notice. During that notice the service continues and the Customer can spend its balance.

Termination for cause: immediate effect, no notice.

Consequences of termination:

Modifications

Duale AI notifies any modification by email 30 days before it takes effect. In case of disagreement, the Customer has the right to terminate without penalty.

Disputes

Governing Law: These Terms are governed by French law.

Jurisdiction: Courts of Paris, France.

Statute of limitations: 5 years from the date the claimant knew or was reasonably expected to know of the facts giving rise to the claim (Article 2224 French Civil Code).

Claims: contact+support@mail.duale.ai

Miscellaneous

The documents that form your contract, and the order in which they apply, are set out in the Terms of sale for the prepaid credit platform, section Which documents form your contract.

Invalidity of one clause does not affect the others. Not exercising a right is not a waiver of it.

Language. These Terms exist in French and English. If the two diverge, the French version prevails.

Force Majeure

Neither party is liable for a failure caused by force majeure within the meaning of Article 1218 of the French Civil Code. The three conditions, the suspensive effect, and the right to terminate beyond 30 days are set out in the Terms of sale for the prepaid credit platform, section Force majeure.

Assignment

The Customer must not assign the contract without prior written consent from Duale AI, except to a company it controls or that controls it within the meaning of Article L233-3 of the French Commercial Code, subject to prior written notice.

Duale AI has the right to assign the contract to any successor or acquirer of all or part of its business, subject to 30 days’ notice to the Customer.

Accessibility

Duale AI works to make the Platform more accessible. When a formal accessibility compliance statement is available, Duale AI publishes it separately.

Contact