Product Terms
Service description, AI functionality, autonomous actions, connected platforms and security.
These Product Terms form an integral part of, and are incorporated by reference into, the Balt General Terms of Service. Capitalized terms not defined here have the meanings given in the Definitions.
In the event of a conflict between the documents making up the Agreement, the order of precedence set out in the General Terms applies.
1. Service Description and Delivery
1.1 Service Overview
Balt is an artificial intelligence agent for recruitment professionals. It connects to Customer's communication and productivity tools, which constitute Connected Platforms, and executes tasks, generates content, and supports workflows through AI-driven decision-making. The Service includes candidate search and sourcing, meeting transcription and analysis, document generation such as skills profiles, preparation of multi-channel outreach sequences, and generation of priority tasks.
The Service is provided on a software-as-a-service basis. Provider hosts and operates the underlying infrastructure and grants Customer remote access via the Internet. The Service is accessible within the Cobalt platform and is subject to a separate subscription and pricing.
1.2 Access to the Service
Provider delivers the Service by enabling Customer's account upon acceptance of the General Terms and, where applicable, execution of the Order Form. Access requires Customer to connect its integration credentials and designate its Authorized Users. The Service is deemed delivered, and Customer's payment obligations commence, upon enablement of the account or on the date specified in the Order Form.
Customer's acceptance of the General Terms, together with confirmation of the subscribed plan, functionalities, and applicable fees through the online flow, constitutes an Order Form for all purposes of the Agreement, including the commencement of the Subscription Term and of Customer's payment obligations.
1.3 Account Setup
After acceptance of the General Terms or execution of an Order Form, Customer is responsible for setting up its account, connecting its integration credentials, designating Authorized Users, and configuring permission scopes, using the self-service tools made available within the Service and the procedures described in the Documentation.
Provider is not responsible for delays or failures resulting from Customer's setup activities, from Customer's systems, networks, infrastructure, or third-party software, or from any misconfiguration not attributable to Provider.
1.4 Out-of-Scope Services
Unless expressly stated in the Order Form, the Service does not include data migration, custom development, user training, dedicated customer success management, onboarding services beyond the self-service tools described in the Documentation, configuration assistance, integration with systems not listed in the Documentation, or any managed services. Such services may be procured separately at Provider's then-current rates.
2. Artificial Intelligence Functionality
2.1 Nature of Outputs
The Service uses artificial intelligence models to generate Outputs. Outputs are probabilistic and may be inaccurate, incomplete, biased, or otherwise unsuitable for Customer's intended use. Customer acknowledges that Outputs are not a substitute for human judgment or professional advice, including legal, medical, financial, or other regulated advice. Customer is solely responsible for reviewing them before any use, distribution, or decision based on them.
2.2 AI Subprocessors
The Service is powered in part by third-party AI model providers, the AI Subprocessors, the current list of which is set out in the Privacy Policy and in the DPA. Provider has contractual arrangements with each of them which, as of the date of these Product Terms, prohibit the use of Customer Data to train general-purpose AI models or for advertising purposes.
Provider's commitments regarding AI Subprocessor behavior reflect the arrangements in force between Provider and each of them. AI Subprocessors may modify their terms unilaterally. If Provider becomes aware that such a modification would materially reduce the level of protection applicable to Customer Data, it will inform Customer within a reasonable time through the subprocessor change notification process set out in the DPA. Customer may then, as its sole remedy, terminate the affected portion of the Service without penalty and obtain a pro-rata refund of prepaid fees for the unused portion, excluding Credits already consumed and non-refundable Credit purchases.
2.3 Outputs and Third-Party Content
Customer acknowledges that AI-generated Outputs may, in rare cases, contain content that resembles, reproduces, or derives from third-party content, including copyrighted material, even where Provider and its AI Subprocessors take commercially reasonable measures to prevent this.
Customer is solely responsible for reviewing Outputs for potential intellectual property, defamation, privacy, or other third-party rights issues before any use or distribution. Provider's warranty under Section 7.1 of the General Terms does not extend to claims arising from Outputs that incidentally reproduce third-party material.
3. Autonomous Actions
3.1 Principle
The Service may execute actions on Connected Platforms with varying levels of autonomy. Customer acknowledges and accepts that:
- (a) Customer is solely responsible for configuring permission scopes, approval policies, and pre-authorization rules in its account settings, and for reviewing those configurations periodically;
- (b) Provider executes Pre-Authorized Actions in reliance on that configuration; Customer accepts all consequences of actions executed within the permissions it has configured, except where caused by Provider's gross negligence or wilful misconduct;
- (c) Provider does not guarantee that any specific action will be executed correctly, on time, or with the intended business outcome.
3.2 Customer Remains Operator
Customer acknowledges that AI-driven autonomous operations involve inherent uncertainty. Customer remains the operator of its own business processes and bears final responsibility for all business decisions and all actions executed through the Service.
3.3 High-Risk Actions
A limited set of action categories, the High-Risk Actions, always require explicit prior approval by an Authorized User before execution and can never be configured as Pre-Authorized Actions. As of the date of these Product Terms, those categories are:
- (a) changing the Service's own permission scopes, or connecting or disconnecting a Connected Platform;
- (b) having Balt join an online or in-person meeting and triggering its recording or transcription, given the information and consent obligations borne by Customer under Section 2 of the Acceptable Use Policy;
- (c) transmitting Customer Data, conversation excerpts, or reports to Provider for support or Service improvement purposes.
Provider may update the list of High-Risk Actions. Any change is published in the Documentation and notified under Section 16 of the General Terms.
3.4 Action-Type Controls
The Service provides controls allowing Customer to enable, disable, restrict, or require approval for specific categories of actions executed through Connected Platforms. Customer may, for example, prevent Balt from sending a message to a candidate, transmitting a skills profile to an end client, creating or updating a record in a connected system, or triggering a sequence.
The Service assigns default approval levels when an integration is connected: actions assessed as read-only may execute automatically, while actions that modify data or send a communication to an external recipient require approval by default. Customer is responsible for reviewing these defaults and adjusting them to its risk tolerance and internal authorization policies.
Where an action type is enabled, pre-authorized, or not subject to an approval requirement under Customer's configuration, Balt may execute it without separate human review. Changes to action-type controls apply prospectively and affect neither actions already executed nor actions already in progress.
3.5 No Solely Automated Decision
The Service is neither intended nor designed to take, on its own, a decision producing legal effects concerning a person or similarly significantly affecting them within the meaning of Article 22 GDPR, including a decision to reject an application. Outputs are decision support.
Customer undertakes to maintain effective human intervention in any decision relating to an application or an employment relationship, not to configure the Service so as to fully automate such a decision, and to inform data subjects of the use of algorithmic processing in accordance with its obligations as controller. A breach of this Section 3.5 constitutes a material breach of the Agreement.
4. EU Artificial Intelligence Act
The Parties acknowledge that Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence classifies as high-risk, in its Annex III, systems intended to be used for the recruitment or selection of natural persons, in particular to analyse and filter applications and evaluate candidates.
As between the Parties, Provider acts as provider of the artificial intelligence system and Customer acts as deployer. Customer accordingly undertakes to use the Service in accordance with the Documentation and the instructions for use communicated to it, to assign human oversight to persons with the necessary competence, training, and authority, to monitor the operation of the Service and promptly report to Provider any serious incident or malfunction of which it becomes aware, and to inform data subjects where the regulation so requires.
The Parties shall provide each other with the information and assistance reasonably necessary to enable each to meet its respective obligations under that regulation as they become applicable. This Section constitutes neither a declaration nor a warranty of conformity of the Service with that regulation.
5. Connected Platforms
5.1 Customer Warranties
When Customer connects a Connected Platform, Customer represents and warrants that:
- (a) Customer is duly authorized to grant Provider the access permissions necessary to deliver the Service, including any consent required from the third-party account owner;
- (b) Customer has obtained all consents required from individuals whose data will be accessed or processed through the integration;
- (c) the connection and Customer's use of the integrated data comply with the Connected Platform's own terms of service and policies.
5.2 Workspace-Shared Model
Integrations operate on a workspace-shared basis: once an integration is connected, Authorized Users with appropriate rights within the Service may invoke it, and actions executed through the integration use the permissions of the account that authorized the connection.
Customer is solely responsible for:
- (a) selecting the account used to authorize each integration, taking into account the permissions that account holds on the Connected Platform;
- (b) configuring workspace membership, role assignments, and approval policies within the Service to reflect the access controls it intends to apply;
- (c) periodically reviewing those configurations.
High-Risk Actions executed through a Connected Platform remain subject to the per-action approval requirement in Section 3.3.
5.3 OAuth Consent and Scope of Access
The Service integrates with Customer's tools using OAuth 2.0 authentication. During installation, the third-party platform presents a consent screen detailing the permissions Provider requests. By granting consent, Customer authorizes Provider to use those permissions to deliver the Service. The requested scopes are presented on that screen and described in the Documentation.
With respect to the Google Workspace APIs, Provider's use of information received complies with the Google API Services User Data Policy, including its Limited Use requirements. Data obtained via the Google APIs is not transmitted to artificial intelligence models, is not used to train, improve, or feed any machine learning or artificial intelligence model, whether generalized or personalized, and is not shared with subprocessors other than those strictly necessary to provide the Service.
5.4 Disconnection
Customer may disconnect a Connected Platform at any time from the Service settings or from the platform concerned. Disconnection immediately stops the collection of new data from that platform, deletes the associated connection credentials including OAuth tokens, and pauses scheduled tasks that depend on it.
Disconnection does not by itself delete previously collected Customer Data. Deletion of such data is governed by Section 11.8 of the General Terms and by the DPA.
5.5 Third-Party Platform Terms
Use of Connected Platforms is governed by Customer's own agreement with each platform provider. Provider is not responsible for their availability, changes to their programming interfaces, changes to their terms of service, or actions taken by their providers that limit or impair the Service.
6. Security
6.1 Security Program
Provider maintains an information security program proportionate to the nature of the Service and the risks involved, the measures of which are described below and supplemented by the DPA.
6.2 Technical and Organizational Measures
- Encryption: Customer Data encrypted in transit (TLS 1.3) and at rest;
- Access control: strong authentication and application of the least-privilege principle;
- Infrastructure: hosting on ISO/IEC 27001 certified infrastructure;
- Monitoring: production system logging, continuous monitoring, and anomaly detection;
- Continuity: regular backups with restoration testing;
- Personnel: data protection awareness and training for staff.
6.3 Data Location
The Service's primary data is hosted in France and in the European Union. Some subprocessors are established outside the European Union; those transfers are framed by the mechanisms described in the Privacy Policy and in the DPA, in particular the European Commission Standard Contractual Clauses and the EU-US Data Privacy Framework.
6.4 Breach Notification
Provider shall notify Customer, without undue delay, of any confirmed data breach affecting Customer Data, in accordance with the timelines and procedures set out in the DPA. The notification will include the information reasonably necessary to enable Customer to meet its own legal obligations.
7. Accessibility
Provider strives to make the Service accessible to users with disabilities and uses commercially reasonable efforts to work towards the Web Content Accessibility Guidelines (WCAG) 2.1, Level AA. Conformance is not warranted and may vary across features and platforms.
8. Service Levels
This Section constitutes the service level agreement applicable to the Service and forms an integral part of the Agreement.
Unless expressly specified in the Order Form, Provider does not provide a guaranteed availability percentage, uptime commitment, or minimum service availability level. Provider will use commercially reasonable efforts to make the production version of the Service available during the Subscription Term, subject to the exclusions below.
Any availability target specified in the Order Form shall be measured on a calendar-month basis and shall apply only to the production version of the Core Service. Unless expressly stated otherwise, availability calculations exclude unavailability, degradation, latency, or failure caused by scheduled or emergency maintenance, Customer's systems, networks, or devices, Connected Platform configuration, AI Subprocessors, hosting infrastructure providers, payment processors, telecommunications providers, force majeure events, suspension of the Service in accordance with the Agreement, Beta Features, trial, demo, or non-production environments, and any circumstances outside Provider's reasonable control.
Provider may perform scheduled maintenance. Provider will use commercially reasonable efforts to give advance notice of maintenance expected to materially affect availability of the production version. Unless otherwise specified in the Order Form, scheduled maintenance does not count as unavailability.
Provider may perform emergency maintenance without prior notice where necessary to address security, legal, operational, infrastructure, or data integrity risks. Provider will use commercially reasonable efforts to minimize the resulting disruption.
The other documents of the agreement
- Definitions : The defined terms used across the Balt contractual documents.
- General Terms : The core contractual terms governing access to and use of the Balt service.
- Acceptable Use Policy : The rules for acceptable and prohibited use of the Balt service, and prohibited data.
- Usage Terms : How Credits, allocations, top-ups and accounts work.
- License Terms : The license granted to use the Balt service, and its restrictions.
For any questions regarding how the Service works, contact us at: legal@cobalt-ia.com
