These Product Specific Terms form part of the Customer Terms of Service and apply where you use the module described. Capitalised terms have the meanings given there. Where a section conflicts with the Customer Terms of Service on the module it governs, this document prevails.
1AI agents and credits
Agent and model-assisted features are governed by the AI Terms. In addition:
- Metering. Agent work consumes Credits at the rates published in the product when the work runs. A run reserves Credits before it starts and settles on completion; a reservation that is never settled is released.
- Visibility. Every run is recorded with what it did, which tools it called and what it consumed, so a charge can be traced to work.
- Insufficient balance. When a workspace has no Credits, metered AI work stops and the product says so. Non-AI functionality is unaffected.
- Autonomy settings. You choose which actions require human approval. Where you disable approval for a class of action, agents may take that action without further confirmation, and you accept the consequences within the permissions you granted.
- Limits. We may apply per-workspace rate limits to agent runs to protect platform stability, and will make them visible before enforcing them against you.
2Marketing email and outbound messaging
You are the sender of every message the platform sends on your behalf. You are responsible for consent, content, sender identity and compliance with the law of every recipient's country. The Acceptable Use Policy sets the rules; this section sets the mechanics.
- Unsubscribes and suppression. Marketing messages must offer an unsubscribe mechanism. The platform maintains a suppression list per workspace; you must not remove an address from it, or re-import it, in order to contact someone who has opted out.
- Deliverability. We may throttle, pause or block sending from a workspace where complaint rates, bounce rates or spam-trap hits threaten platform reputation, and will tell you why.
- Authentication. Where you send from your own domain, you are responsible for the DNS records that authenticate it. We are not responsible for delivery to any particular inbox.
- Volume. Sending limits apply per plan and during early access; where a limit applies, the product shows it.
- No relaying. You may send only your own messages, from addresses you are authorised to use.
3Connected mailboxes
You can connect a mailbox over IMAP and SMTP so correspondence appears against records.
- Authority. You confirm you are entitled to connect the mailbox and to have its contents processed in the platform — including where it belongs to an employee — and that you have given any notice their employment or local law requires.
- What we do. We synchronise messages and attachments from the folders you select, attribute them to records, and, where you enable enrichment, generate summaries. We do not read mailbox content for our own purposes.
- Credentials. Mailbox credentials are encrypted with a key held outside the database. You may disconnect a mailbox at any time; disconnection stops synchronisation but does not delete messages already filed against records.
- Third parties. Correspondents in a connected mailbox have not agreed to our terms. You remain the controller of their data and are responsible for their rights.
4Website analytics and tracking
Our website analytics is first-party and cookieless: a visitor is identified by a hash derived from a rotating daily salt, which cannot be linked across days and is not reversible to an IP address; approximate country comes from an edge header rather than from a stored address; paid-click identifiers are classified and discarded rather than stored.
- Your notice. You must publish a privacy notice covering the tracking, and obtain any consent your law requires before the snippet runs. Cookieless design reduces, but does not universally remove, consent obligations.
- Your sites only. Install the snippet only on sites you own or operate.
- Identification. Where a visitor identifies themselves — by submitting a form or following an identified link — subsequent activity is associated with that contact record. You must disclose that in your notice.
- Retention. Analytics events are retained for thirteen (13) months by default.
5Forms and embedded components
- Submissions are stored verbatim alongside whatever records they create, so you can see what a person actually sent.
- You are responsible for the fields you ask for, for the lawful basis to collect them, and for not requesting payment card data, credentials or special-category data.
- Embedded components render your workspace data on your site under permissions you configure. You are responsible for what you expose publicly; a component that publishes a record's data makes that data public.
- We apply rate limits to public form and embed endpoints to protect against abuse.
6Hosted pages, documents and shared links
- Pages you publish, and documents you share by link — quotes, invoices, proposals — are served by us on your behalf. You are responsible for their content and for who you send the link to.
- A shared link is an access mechanism: anyone holding it can view the document until you revoke it. Where a document contains personal or commercially sensitive data, treat the link accordingly.
- Views of a shared document are recorded and shown to you.
- We may remove published content that breaches the Acceptable Use Policy or that we are legally required to remove, and will tell you when we do.
7Quotes, invoices and commercial documents
The platform helps you produce quotes, invoices and related documents, and records their acceptance. It is a document and record-keeping tool, not an accounting, tax or e-invoicing compliance system, and it does not file anything with an authority on your behalf.
You are responsible for the legal and fiscal correctness of documents you issue, including tax rates, mandatory content, sequential numbering rules and archiving obligations in your jurisdiction. We do not provide tax or accounting advice.
Where a customer of yours accepts a document electronically, we record the acceptance; whether that constitutes a binding signature is a matter of your own law and arrangements.
8Automations and workflows
- Automations act with the authority you give them and can change data, send messages and call external systems. Test before enabling, and use the approval steps the product provides for consequential actions.
- We may pause an automation that loops, that exceeds fair-use limits, or that threatens platform stability, and will tell you why.
- You are responsible for the effects of an automation you enable, including messages it sends and records it changes.
9Public API, webhooks and connectors
- API keys carry the permissions you grant them. Treat them as credentials: never embed them in client-side code or a public repository, and rotate them when someone with access leaves.
- The API is rate limited per key. Sustained abuse, or use that degrades service for others, may be throttled or blocked.
- Webhooks are delivered on a best-effort basis with retries; you must verify the signature on every delivery and design your endpoint to tolerate duplicates and out-of-order delivery.
- We version the API and will give reasonable notice before a breaking change. Undocumented endpoints and internal interfaces may change at any time.
- Connectors and external tool interfaces — including any model-context connector we publish — grant a third-party client access to your workspace under a principal you choose. You are responsible for which clients you authorise and for the actions they take.
10Files, storage and retention
- Files are stored in private object storage and served through time-limited signed links.
- An uploaded file that is never attached to a record is deleted after thirty (30) days.
- Deleted records and files stay in the recycle bin for thirty (30) days and can be restored; after that, removal is permanent.
- Default retention periods for derived data — change history, analytics, transcripts, notifications, delivery logs — are published in the Privacy Policy. Where the product lets you shorten them, your setting prevails.
- Plan storage limits, where they apply, are shown in the product. We will notify you before enforcing a limit that would block uploads.
11Support and service levels
Support is provided by email at start@salexhub.ai during business hours in Dubai, in English, on commercially reasonable efforts. We aim to acknowledge within one business day.
During early access we do not offer an uptime commitment, service credits or a contractual response time, and we will not pretend otherwise. We publish material incidents and their causes to affected customers.
A service level agreement with defined availability targets and remedies is available to enterprise customers under a separate written agreement.
We perform maintenance that may briefly interrupt the Service. Where maintenance is planned and disruptive, we give advance notice.
12Self-managed deployments
Running the software on your own infrastructure requires a separate written licence from Salex Hub Commercial Brokers L.L.C, including a deployment licence key. These Product Specific Terms and the Customer Terms of Service govern our hosted service; they do not grant any right to install, copy or operate the software yourself.