Skip to content

Legal

Terms of Service

Last updated: July 12, 2026. These Terms of Service (“Terms”) are an agreement between Kuudo, an Openbridge Inc. company (“Kuudo,” “we,” “us”) and the person or organization accepting them (“Customer,” “you”). They govern your access to and use of the Kuudo application, managed deployment and orchestration services, authorization services, APIs, documentation, support, and related services (collectively, the “Service”).

The operating boundary

Kuudo deploys and orchestrates software in cloud accounts you control. Substantive Amazon business-data requests, responses, and outputs travel directly between resources in your cloud and the client tools you choose; Kuudo does not host or access that content. Kuudo does process limited control-plane information needed to manage your deployment and, when enabled, Amazon OAuth credentials and connection metadata needed to provide authorization and token services. The Data Processing Addendum defines this boundary in detail.

1. Agreement and authority

You accept these Terms by creating an account, clicking to accept them, signing an order form that incorporates them, or accessing or using the Service. If you use the Service for an organization, you represent that you have authority to bind that organization, and “Customer” means that organization. You must be at least 18 years old and legally capable of entering into this agreement. If you do not agree to these Terms, do not use the Service.

An executed order form, statement of work, or other written agreement referencing these Terms (each, an “Order”) may specify plan, scope, fees, support, usage limits, or additional terms. If documents conflict, the following order controls: the DPA for processing of personal data; the applicable Order; these Terms; and then incorporated policies.

2. The Service

Kuudo provides software and managed services for deploying, configuring, and operating MCP servers, integrations, Skills, data resources, and related workloads. The Service may connect Customer-controlled infrastructure and Customer-selected tools to Amazon Ads, Amazon Marketing Cloud, SP-API, Vendor Central, cloud platforms, storage systems, model providers, workflow tools, and other services Customer authorizes.

Service functionality depends on Customer's plan, Order, cloud provider, Amazon permissions, marketplace, region, connected tools, and third-party availability. Documentation and descriptions identify intended behavior but do not expand an Order or guarantee that every connector, API operation, beta feature, or third-party capability will always be available.

Community and separately licensed software

Source code, packages, examples, or other materials Kuudo makes available under a separate open-source or source-available license are governed by the license included with those materials, not by these Terms to the extent of a conflict. These Terms still govern Kuudo-hosted accounts, authorization services, managed orchestration, support, and other Service components you use.

3. Accounts and organizations

You must provide accurate account information and keep it current. You are responsible for safeguarding your sign-in methods, sessions, API keys, client secrets, OAuth applications, machine-to-machine credentials, and other account credentials and for activity performed through them. Notify Kuudo promptly if you suspect unauthorized access or credential compromise.

The Service organizes resources, authorizations, subscriptions, and permissions around Customer organizations. Organization owners and administrators may invite or remove members, manage subscriptions, authorize integrations, create machine clients, issue or revoke credentials, and otherwise control organization resources. Customer is responsible for its administrators, members, contractors, agents, and connected clients and for maintaining appropriate roles and access.

Certain credentials are displayed only once when created or rotated. Customer is responsible for saving them securely. Kuudo may enforce verification, authentication, scope, rate-limit, organization-membership, or administrator requirements before allowing sensitive operations.

4. Customer-cloud deployment and orchestration

Managed deployments run in an AWS, Google Cloud, Microsoft Azure, Cloudflare, or other cloud account owned or controlled by Customer. Customer authorizes Kuudo to use the cloud account identifiers, configuration, scoped keys, tokens, service identities, role-assumption details, and related information reasonably needed to deploy, configure, update, monitor, secure, support, and decommission Customer resources (“Cloud Orchestration Data”).

Customer is responsible for:

  • maintaining its cloud account, payment method, quotas, regions, networking, backups, retention settings, and provider agreement;
  • granting only the cloud-management permissions reasonably necessary for the Service and reviewing them periodically;
  • protecting access to Customer's cloud account and promptly revoking or rotating credentials when appropriate;
  • cloud-provider, network, storage, model, and other third-party fees incurred by Customer resources; and
  • configuration or changes Customer or its users make outside the Service that affect availability, security, or operation.

Customer authorizes Kuudo to create, modify, restart, scale, update, and delete Customer resources when reasonably necessary to perform the Service or when Customer directs those actions. Kuudo will use Cloud Orchestration Data only as described in the Agreement and DPA.

5. Amazon authorization and token services

Customer may authorize Amazon Ads or SP-API connections through a Kuudo-managed Amazon application or, where available, Customer's own Amazon application. Customer represents that it owns or is authorized to connect every Amazon account, advertising profile, seller account, marketplace, and application credential it provides or approves.

To provide authorization and token services, Customer authorizes Kuudo to:

  • receive and validate OAuth authorization codes and state;
  • exchange authorization codes for Amazon refresh and access tokens;
  • encrypt and store refresh tokens and, for bring-your-own-app connections, Customer-supplied client secrets;
  • perform limited identity, profile, marketplace, region, and connection-verification calls and retain resulting connection metadata;
  • exchange stored credentials for short-lived Amazon access tokens; and
  • issue those short-lived access tokens to authenticated service runtimes Customer has authorized.

Kuudo does not provide refresh tokens to browsers or Customer-selected client tools. A short-lived access token is a live bearer credential; Customer is responsible for the service runtimes, API keys, OAuth clients, machine principals, and scopes it authorizes to request one. Revoking a connection or credential may not invalidate a token already issued until that token expires. Customer may also revoke Kuudo's access through the applicable Amazon account.

Kuudo's authorization service is a credential and metadata control plane. Substantive Amazon API requests and responses are made directly between Customer Cloud Resources and Amazon and do not route through Kuudo. The DPA describes the distinction between Amazon Authorization Data and private Customer Amazon Data.

6. Customer data and the private data plane

As between the parties, Customer retains all rights in data, content, instructions, configurations, and materials Customer provides or controls and in outputs generated for Customer through its deployment (“Customer Materials”), subject to rights belonging to Amazon, Customer's connected providers, and other third parties.

Substantive Amazon business data and derived outputs are exchanged directly between Customer Cloud Resources and the client tools Customer chooses. Kuudo does not host or access that content in the standard deployment. Kuudo does process limited Cloud Orchestration Data and Amazon Authorization Data needed to provide the control plane. Customer instructs Kuudo to process that information as described in the DPA.

Customer is responsible for the legality, accuracy, quality, and permitted use of Customer Materials; for configuring access, retention, deletion, backups, and output destinations in Customer-controlled systems; and for obtaining all notices, consents, rights, and permissions required to process Customer Materials through the Service.

7. AI clients, outputs, and automated actions

Customer may connect AI clients, models, agents, workflow tools, and other software it selects. Those tools may generate probabilistic, incomplete, inaccurate, offensive, or outdated outputs. They may misunderstand instructions or recommend or initiate actions with financial, operational, legal, advertising, inventory, listing, account-health, or other consequences.

Customer is responsible for selecting and configuring those tools, reviewing outputs, setting scopes and approval gates, supervising automated workflows, and deciding whether to rely on or execute any output or action. Customer must maintain human review appropriate to the risk and must not treat AI output as legal, tax, financial, medical, or other professional advice. Kuudo does not guarantee any campaign result, revenue, ranking, listing status, account status, inventory outcome, or other result.

If Customer authorizes a client or agent to perform write operations, Customer authorizes the Service to carry out those instructions within the granted credentials and scopes. Customer remains responsible for actions initiated through its users, clients, agents, API keys, OAuth applications, machine credentials, and workflows, except to the extent directly caused by Kuudo's breach of the Agreement.

8. Customer responsibilities

Customer will:

  • use the Service only for accounts, data, systems, and operations it is authorized to access;
  • comply with applicable law, Amazon agreements and policies, cloud-provider terms, client and model-provider terms, and other connected-service rules;
  • maintain appropriate security, least-privilege access, user offboarding, credential rotation, backups, and business-continuity controls for systems it controls;
  • promptly investigate suspected misuse, unauthorized access, incorrect automated actions, or compromised credentials;
  • avoid sending substantive Amazon business data or outputs to Kuudo support and redact such material from support requests; and
  • cooperate reasonably with Kuudo's efforts to secure the Service and comply with law and applicable Amazon requirements.

9. Acceptable use

Customer and its users must not:

  • use the Service unlawfully, fraudulently, deceptively, or to violate another person's rights;
  • access or attempt to access another customer's account, organization, authorization, credentials, cloud resources, or data;
  • circumvent authentication, scopes, approval gates, tenant boundaries, usage limits, rate limits, or security controls;
  • probe, scan, disrupt, overload, damage, or introduce malicious code into the Service or connected systems, except under a written security-testing authorization;
  • use credentials or Amazon access for an account Customer does not own or have authority to manage;
  • use the Service to fabricate reviews, manipulate marketplaces, conduct prohibited advertising, misuse personal data, or violate Amazon's policies;
  • reverse engineer, copy, resell, sublicense, or provide the managed Service to third parties except as an Order or applicable license expressly permits;
  • use the Service or Kuudo materials to develop a competing hosted service where prohibited by applicable law and the license governing those materials; or
  • remove proprietary notices or misrepresent affiliation with Kuudo or Amazon.

Kuudo may investigate suspected violations and may restrict or suspend access where reasonably necessary to protect the Service, Customer, other users, Amazon, connected providers, or the public, or to comply with law or provider requirements.

10. Third-party services

Amazon, cloud providers, Stripe, identity providers, model providers, AI clients, container registries, MCP servers, storage providers, and other integrations are third-party services. Customer's use of them is governed by Customer's direct agreements with those providers. Kuudo is not responsible for their terms, content, models, data practices, security, availability, API changes, rate limits, suspensions, errors, pricing, or acts and omissions.

Third-party integrations may change, become unavailable, or require additional permissions or fees. Kuudo may modify or stop supporting an integration when its provider changes or withdraws access, when continued support would create security or legal risk, or when commercially reasonable. Amazon is not a party to these Terms, and Kuudo does not control Amazon accounts or policies.

11. Plans, fees, billing, and taxes

Plans, included features, resource limits, fees, billing periods, and support commitments are stated in the applicable Order, checkout, or pricing page. Organization owners or administrators may be permitted to purchase, change, restore, or cancel subscriptions. Paid subscriptions may renew automatically for successive periods unless canceled in the billing portal or as stated in the applicable Order.

Customer authorizes Kuudo and its payment processor to charge the applicable payment method for recurring fees, usage charges, and taxes. Fees exclude taxes unless stated otherwise. Customer is responsible for applicable sales, use, value-added, withholding, and similar taxes, excluding taxes based on Kuudo's net income.

Except where law or an Order requires otherwise, fees are non-refundable, cancellation takes effect at the end of the current paid period, and failure to pay may result in suspension or downgrade after notice. Cloud-provider, Amazon, model-provider, and other third-party charges are billed separately by those providers and are Customer's responsibility.

12. Ownership and licenses

Kuudo and its licensors retain all rights in the Service, managed platform, software, documentation, designs, workflows, templates, and technology, including improvements and derivative works, except for Customer Materials and components governed by separate licenses. Subject to these Terms and payment of applicable fees, Kuudo grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable term to access and use the Service for Customer's internal business purposes and for authorized services Customer provides to its clients under an applicable Order.

Customer grants Kuudo the limited rights necessary to use Control Plane Data, instructions, configuration, names, and materials Customer provides solely to deliver, secure, support, and improve the operation of the Service for Customer. This license does not permit Kuudo to use private Amazon business data or outputs for model training, cross-customer analytics, advertising, or product benchmarking.

If Customer voluntarily provides feedback, Customer grants Kuudo a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without restriction or attribution, provided Kuudo does not identify Customer or disclose Customer Confidential Information without permission.

13. Confidentiality

“Confidential Information” means non-public information disclosed by one party that reasonably should be understood as confidential, including security information, credentials, product plans, pricing in an Order, business information, and Customer Materials. It excludes information the recipient can document was already lawfully known, becomes public without breach, is received lawfully without confidentiality duty, or is independently developed without use of Confidential Information.

The recipient will use Confidential Information only to exercise rights and perform obligations under the Agreement; protect it using at least reasonable care; and disclose it only to personnel, contractors, and subprocessors who need to know it and are bound by confidentiality obligations. A recipient may disclose information when legally required after giving advance notice where permitted and reasonable assistance at the discloser's expense.

14. Privacy, security, and data processing

The Privacy Policy describes Kuudo's controller processing. The Data Processing Addendum applies when Kuudo processes personal data on Customer's behalf, including eligible Cloud Orchestration Data and Amazon Authorization Data. The Subprocessors page identifies providers Kuudo uses to support its operations and control plane. Those documents are incorporated into the Agreement as applicable.

Kuudo will maintain reasonable administrative, technical, and organizational safeguards for systems and Control Plane Data it controls. No service is perfectly secure. Customer is responsible for systems it controls and must promptly notify Kuudo of a suspected incident affecting the Service, Kuudo-issued credentials, or Amazon or cloud authorizations managed through Kuudo.

15. Availability, support, changes, and beta features

Kuudo will provide support and service levels, if any, stated in an Order. Unless an Order states otherwise, the Service is provided without a guaranteed uptime or response time. Maintenance, security work, provider outages, API changes, rate limits, Customer configuration, and events outside Kuudo's reasonable control may affect availability.

Kuudo may improve, update, replace, or discontinue Service features. Kuudo will provide reasonable notice before a material reduction in paid core functionality where commercially practicable, unless immediate action is needed for security, legal, Amazon-policy, or third-party-provider reasons.

Preview, beta, evaluation, experimental, or free features may be changed or withdrawn at any time, may be incomplete or unsupported, and are provided without service levels or warranties to the maximum extent permitted by law. Customer should not use them for production or high-risk workloads unless an Order expressly permits it.

16. Term, suspension, and termination

These Terms begin when Customer first accepts them and continue while Customer uses the Service. Each Order continues for its stated term. Either party may terminate an Order or these Terms for material breach if the breach is not cured within 30 days after written notice, or immediately if the breach cannot be cured. Either party may terminate immediately if the other becomes insolvent or enters a similar proceeding, subject to applicable law.

Kuudo may suspend affected access immediately when reasonably necessary to prevent a security incident, unauthorized access, material harm, unlawful activity, non-payment, or violation of Amazon or connected-provider requirements. Where practicable, Kuudo will limit the suspension, notify Customer, and restore access when the cause is resolved.

On termination, Customer's right to use the affected managed Service ends. Customer must revoke Kuudo's cloud and Amazon permissions and remains responsible for Customer Cloud Resources, data, exports, backups, third-party fees, and decommissioning unless an Order says Kuudo will perform it. Kuudo will handle Control Plane Data as stated in the DPA. Accrued payment obligations and provisions that by their nature should survive—including ownership, confidentiality, disclaimers, indemnity, liability, dispute, and general terms—will survive.

17. Warranties and disclaimers

Each party represents that it has authority to enter into the Agreement. Kuudo warrants that it will provide paid professional services in a professional and workmanlike manner. Customer's exclusive remedy for breach of that warranty is re-performance of the affected services or, if Kuudo cannot re-perform them, termination of the affected Order and refund of prepaid fees for the undelivered portion, subject to counsel confirmation.

TO THE MAXIMUM EXTENT PERMITTED BY LAW, EXCEPT FOR EXPRESS WARRANTIES IN AN ORDER OR THESE TERMS, THE SERVICE, SOFTWARE, DOCUMENTATION, INTEGRATIONS, AI OUTPUTS, AND BETA FEATURES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” KUUDO DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. KUUDO DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, SECURE, OR COMPATIBLE WITH EVERY THIRD-PARTY SERVICE, OR THAT OUTPUTS OR AUTOMATED ACTIONS WILL BE ACCURATE OR ACHIEVE A RESULT.

18. Indemnification

Customer will defend and indemnify Kuudo and its affiliates, officers, directors, employees, and agents against third-party claims, damages, fines, penalties, and reasonable legal fees arising from: Customer Materials; Customer's breach of Sections 3–10; Customer's violation of law, Amazon requirements, or third-party rights; or actions Customer or its users, clients, or agents authorize through connected accounts, except to the extent caused by Kuudo's breach, gross negligence, or willful misconduct.

Any Kuudo intellectual-property indemnity, exclusions, remedies, defense control, and cooperation requirements must be stated in an applicable Order or a counsel-approved revision of these Terms before publication.

19. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, BUSINESS, OR DATA, ARISING OUT OF THE AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY.

EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE AFFECTED SERVICE DURING THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. These limitations apply to the extent permitted by law and do not limit liability that cannot legally be limited.

20. General terms

Governing law and disputes

The Agreement is governed by the laws of the Commonwealth of Massachusetts, without regard to conflict-of-law rules. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Boston, Massachusetts, unless an approved arbitration or statutory consumer provision applies.

Notices

Kuudo may send operational and legal notices to the email associated with Customer's account, through the Service, or by posting an updated policy where permitted. Notices to Kuudo must be sent to contact@kuudo.com and Kuudo, an Openbridge Inc. company, 145 Tremont Street, Suite 201 -1185, Boston, MA 02111, United States. A notice is effective when received.

Changes to these Terms

Kuudo may update these Terms to reflect Service, legal, security, or provider changes. Kuudo will provide reasonable advance notice of material changes where required. Changes will not retroactively reduce protections or materially expand Customer's obligations during a current committed Order term unless required by law or agreed by Customer. Continued use after the stated effective date constitutes acceptance where permitted by law.

Assignment; relationship; force majeure

Customer may not assign the Agreement without Kuudo's prior written consent, except in connection with a merger or sale of substantially all relevant assets where the assignee is not a competitor and assumes the Agreement. Kuudo may assign the Agreement to an affiliate or in connection with a merger, reorganization, financing, or sale of substantially all relevant assets. The parties are independent contractors; the Agreement creates no partnership, agency, fiduciary, franchise, or employment relationship. Neither party is liable for delay caused by events beyond its reasonable control, except payment duties.

Entire agreement; severability; waiver

The Agreement is the entire agreement about the Service and supersedes prior discussions and representations about its subject. Purchase-order terms do not modify it. If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remainder will continue. Failure to enforce a provision is not a waiver. Headings are for convenience. “Including” means “including without limitation.” Electronic signatures and counterparts are valid.


Questions about these Terms may be sent to contact@kuudo.com. See also our Privacy Policy, Data Processing Addendum, and Subprocessors.