Terms of Service

Effective Date: 13 January 2026

Last Updated: 23 February 2026

Provider: AI Agency Lab Pty Ltd, Suite 271 / 10-20 Gwynne Street, Cremorne, 3121 / ABN: 12 690 321 094

By engaging our services, the Client agrees to the following terms:

These Terms apply to all clients. If you’re an individual consumer, Australian law gives you certain rights that we cannot exclude. Nothing here affects those rights.

1. Services

We provide workflow design, AI-assisted outputs, and technical automation to improve lead generation and operational processes. Services are limited to design, build, and delivery.

Services are provided with reasonable care and skill in accordance with professional standards. While we strive for reliable performance, we do not guarantee specific outcomes, results, or uninterrupted operation.

We do not provide legal, compliance, privacy, or security advice, and the Client remains responsible for these areas.

2. Client Responsibilities

  • Provide accurate access, credentials, and data needed for workflow implementation.
  • Ensure workflows comply with all applicable laws, platform terms, data governance requirements, and relevant regulatory compliance (including privacy laws and the Spam Act 2003). The Provider is not responsible for any errors, losses, or legal consequences arising from non-compliance or misuse.
  • Review, validate, and authorise AI outputs before use.
  • Accept that misuse of workflows may result in loss, account restrictions, or legal liability, and the Client is responsible for these outcomes.
  • The Client is responsible for documenting permitted uses of collected data and enforcing prohibited uses, including via email, social media platforms, or SMS campaigns. The Client remains fully responsible for any downstream legal or regulatory obligations arising from the collection, storage, or use of such data.
  • The Client is responsible for implementing operational controls, access restrictions, policies, training, and audits to prevent misuse of data collected via workflows. The Provider does not enforce these controls and is not liable for any failures to do so.
  • The Client defines the criteria for data collection, schedules collection in line with planned outreach, and ensures that any out-of-scope, inaccurate, or irrelevant records are promptly removed. The Provider does not manage cohort selection or deletion of records.
  • Where workflows include human-in-the-loop processes, the Client manually reviews responses, updates or removes individuals from active or suppression lists, and maintains records to prevent re-contact. The Provider is not responsible for reviewing messages, enforcing opt-outs, or maintaining suppression or response records.
  • The Client is responsible for ensuring that any notices or templates inserted into workflows for regulatory compliance (e.g., APP 5 notices) are accurate, accessible, and fully compliant. The Provider may implement these templates but does not guarantee compliance or assume regulatory responsibility.
  • The Provider does not access, store, retain, or transmit Client data beyond the execution of workflows. Any data processed by the workflows, including through APIs or external connectors, remains the responsibility of the Client. The Provider is not liable for any loss, corruption, or misuse of such data.

3. Access & Roles

  • Only named individuals approved by the Client may access accounts.
  • Testing may occur in a staging environment under the Provider’s account; live systems are used only with explicit Client approval.
  • The Provider may build and implement automations that handle, process, or move data, but is not responsible for how data is stored, managed, or handled by the Client or any third-party platform. The Client remains fully responsible for ensuring compliance with all applicable data privacy, security, and regulatory obligations. The Provider does not assume liability for any breaches, data loss, or regulatory consequences arising from the Client’s systems, configurations, or third-party platforms.
  • Clients are responsible for managing and maintaining account security, including MFA, access controls, and operational security frameworks such as the ASD Essential Eight. The Provider does not manage or monitor account security and is not responsible for security breaches or account compromises arising from the Client’s systems, credentials, configurations, or third-party platforms.

4. Ownership

  • The Client owns all workflows, tools, and deliverables created in their accounts.
  • The Provider retains ownership of methods, templates, reusable components, and know-how.The Client may not claim exclusive rights or ownership of the Provider’s methods or reusable components, nor prevent the Provider from using these in other client work.
  • Modifications by the Client post-delivery are at the Client’s risk, and the Provider is not liable for outcomes.
  • Delivered workflows include documentation and guidance for operation. The Provider may provide explanations or handover support, but ongoing management and operational responsibility remain with the Client unless otherwise agreed in a separate agreement.

5. Third-Party Platforms

  • Workflows may use third-party tools (e.g., LinkedIn, Phantombuster) on Client-approved accounts.
  • Platform access changes, restrictions, or downtime may affect workflows; the Provider is not liable for such changes.
  • Automation may violate third-party terms; the Client accepts all risk, including account restrictions or bans.
  • The Client is solely responsible for complying with all third-party terms of service, platform rules, and policies. The Provider does not monitor, enforce, or manage compliance with any third-party TOS.

6. AI Outputs

  • AI-generated outputs are for operational guidance only and may be inaccurate, incomplete, or misleading.
  • The Client must review and validate outputs before use.
  • The Provider is not liable for any decisions, actions, or outcomes based on AI-generated outputs.
  • Some workflows may include AI-generated outputs or automated decision-making (ADM). These outputs are for operational guidance only and may be inaccurate, incomplete, or misleading.
  • Where workflows include human-in-the-loop (HITL) review, the Provider may perform checks and guidance, but the Client remains responsible for all decisions, actions, and outcomes arising from the use of workflows.
  • The Client must review, validate, and authorise any outputs before use.
  • The Provider is not liable for any decisions, actions, or consequences based on AI-generated outputs, ADM, or HITL guidance.

7. Limitation of Liability

Services are performed professionally and in good faith, but the Provider does not guarantee workflow performance, accuracy, or uninterrupted operation.

The Provider is not liable for indirect, consequential, or business interruption losses, including lost revenue, profits, or reputation.

  • The Client’s agreement to indemnify the Provider and the limits on liability do not apply to grossly negligent or intentionally harmful actions in the design or execution of workflows, and the Provider is not responsible for regulatory compliance, legal obligations, or outcomes resulting from how the Client uses the workflows or data.
  • The Client agrees to indemnify and hold the Provider harmless against any claims, losses, damages, fines, penalties, or legal costs arising from the Client’s actions, omissions, or failure to comply with applicable laws, regulations, platform terms, data privacy obligations, or operational responsibilities. This includes, but is not limited to:

    • Misuse of workflows or AI outputs
    • Breach of applicable laws or third-party platform terms
    • Third-party service failures or restrictions
    • Collection, use, or management of data, including human-in-the-loop decisions, suppression lists, and opt-outs
    • Regulatory compliance obligations, including APP, Spam Act 2003, and other relevant privacy/security laws

    These limits on liability apply as much as the law allows and do not take away any rights you have under Australian Consumer Law.

    8. Fees & Payment

    • Fees are set out in proposals or invoices and are payable according to agreed terms.
    • Non-payment may result in suspension of services until payment is made.
    • Fees exclude taxes unless otherwise stated.
    • Payment of an invoice constitutes acceptance of these Terms of Service, which are available on our website and referenced on the invoice.

    9. Termination

    • Either party may terminate with written notice if obligations are not met.
    • Termination does not remove payment obligations for completed work.
    • Clients retain ownership of delivered workflows upon payment.

    10. Governing Law

    These Terms are governed by Australian law, and any disputes are subject to the jurisdiction of local Australian courts.

    1.2 Managed Service (MSP)

    1.2.1 Services

    1.1 Nature of Service: The Provider provides the Client with a Managed Digital Employee — a suite of hosted automations designed to perform lead generation and outreach tasks. The Provider acts as the "Manager" of this digital worker, ensuring its technical health and operation.

    The Provider is an independent contractor. Nothing in this 'Digital Employee' metaphor shall be construed as creating a partnership, joint venture, or legal agency between the parties.

    The Provider hosts, monitors, and operates workflow automation within Provider-controlled environments to deliver specific outputs (“Outputs”) to the Client.

    Services are provided with reasonable care and skill. While the Provider strives for reliable performance, it does not guarantee specific outcomes, reply rates, conversions, or uninterrupted operation.

    The Provider does not provide legal, compliance, privacy, or security advice. The Client remains solely responsible for these areas.

    1.2.2 Scope of Service

    The technology stack (including Make.com scenarios, scripts, and connectors) resides exclusively within accounts owned and managed by the Provider.

    The Client has access only to Outputs (including ICP-matched leads, buying signals, messaging sequences, automated outreach execution, reports, and synced records). The Client has no direct access to the underlying logic, code, or configuration.

    The Outputs consist of ICP-matched leads, buying signals, messaging sequences, and automated outreach execution.

    The Client has five (5) days from delivery to raise any concerns regarding the Outputs. After this period, Outputs are deemed accepted.

    The Provider executes automated outreach to approved leads but does not guarantee reply rates, conversion metrics, data accuracy, or platform behaviour.

    The Provider uses best efforts to verify lead data; however, as this relies on third-party sources (e.g. LinkedIn), 100% accuracy cannot be guaranteed. Client has 5 days to flag any mismatched records for replacement.

    A final report of performance and results will be delivered within five (5) business days of the end of each billing cycle.

    The Client acknowledges inherent platform risks, including but not limited to account restrictions, warnings, or bans.

    1.2.3 Operational Control

    1.2.3.1: Upon receipt of the monthly fee, the Client is granted the right to use all specific prospect data and reports generated during that billing cycle. The Client acts as the Data Controller for all delivered data.

    1.2.3.2: The Provider maintains exclusive control over the automation environment. This is a managed service, and access is provided to the Outputs (leads and reports) rather than the back-end configuration, technical logic, or scenario files.

    1.2.3.3: While a prospect is in an “active” outreach sequence for the Client, the Provider will not surface that specific lead record or its attributed data to any direct competitor of the Client. Upon termination of this Agreement, or after ninety (90) days of inactivity on a specific record, the lead record returns to the Provider’s master intelligence feed and may be used commercially.

    1.2.4 Ownership

    The Provider retains ownership of all underlying technical logic, workflows, scripts, templates, systems, and know-how.

    1.2.4.2: The Client is granted a permanent, non-exclusive licence to use all delivered prospect data for its internal business purposes. The Provider’s role in running the automation ends upon termination of the Agreement.

    .

    The Provider’s role in running the automation ends upon termination of the Agreement.

    Transfer of hosted workflows to Client-controlled accounts is conditional upon full settlement of any outstanding Build or Configuration Fees.

    Any modification or use of underlying workflows by the Client is at the Client’s sole risk. The Provider is not liable for outcomes resulting from such use or modification.

    Non-Solicitation: Neither party shall, during the term of this Agreement and for twelve (12) months thereafter, solicit for employment or contract any employee or contractor of the other party who has been involved in the provision of the Services.

    1.2.5 Third-Party Platforms

    Automation may violate or conflict with third-party platform terms (including but not limited to LinkedIn, Phantombuster, or similar tools). The Client accepts all associated risks, including account restrictions, suspensions, or bans.

    Platform changes, downtime, enforcement actions, or restrictions may affect Outputs. The Provider is not liable for such interruptions.

    The Provider does not monitor, enforce, or manage compliance with third-party terms of service.

    5.3 Directed Outreach: The Digital Employee operates strictly at the direction and instruction of the Client. Similar to a human staff member, the Digital Employee executes outreach only to contacts approved by the Client. The Client, as the Employer of the service, remains the Authoriser of all communications for the purposes of the Spam Act 2003 (Cth).

    5.5: The Provider acts solely as a technical delivery agent at the documented instruction of the Client and is not responsible for the Client’s Spam Act obligations. The Client is the authoriser of all messages.

    5.6: The Provider acts strictly as a Data Processor and is not responsible for auditing, verifying, or validating lead consent or the legal basis for processing. Once the lead list or output is delivered to the Client, all responsibility for regulatory compliance, data storage, and adherence to privacy laws (including the Spam Act 2003 and the Privacy Act 1988) rests solely with the Client as the Data Controller.

    1.2.6 AI & Human-in-the-Loop

    AI-generated Outputs and Automated Decision-Making (ADM) are provided for guidance only and may be inaccurate or incomplete.

    The Client must review, validate, and authorise all Outputs before use.

    Where workflows include human-in-the-loop (HITL) review, the Provider performs managerial quality checks; however, the Client holds Final Approval authority. Once approved, Client accepts responsibility for the messaging outcomes.

    The Provider is not liable for any decisions, actions, or consequences arising from AI, ADM, or HITL guidance.

    1.2.7 Liability & Indemnity

    The Provider is not liable for indirect, consequential, incidental, or business interruption losses, including but not limited to lost revenue, lost profits, loss of goodwill, or reputational damage.

    Total liability for any claim arising under this Agreement is limited to the total fees paid by the Client in the twelve (12) months preceding the claim.

    7.3 Operational Liability:

    7.3: The Provider acts as a strategic advisor and technical manager. While the Provider assists in identifying target segments and drafting messaging, the Client holds Final Approval authority over all prospect lists and content. Because the Digital Employee acts as a proxy for the Client’s business, the Client accepts responsibility for the recipients and content of all messages sent once they have been approved.

    Provider will maintain industry-standard security measures, including Multi-Factor Authentication (MFA) and encryption of data in transit, to protect the hosted environment. Provider is not liable for security breaches arising from third-party platform vulnerabilities or Client-managed credentials.

    The Client agrees to indemnify and hold the Provider harmless against any claims, losses, damages, fines, penalties, investigations, enforcement actions, or legal costs arising from the Client’s actions, omissions, or failure to comply with applicable laws, including the Spam Act 2003 (Cth), Privacy Act 1988 (Cth), and Australian Privacy Principles (APP).

    The Provider acts strictly as a Data Processor and is not responsible for auditing, verifying, or validating lead consent or legal basis for processing. Upon delivery of Outputs, all responsibility for regulatory compliance rests solely with the Client as Data Controller.

    Examples of indemnifiable risks include:

      Misuse of workflows or AI outputs

      Breach of applicable laws or third-party platform terms

      Third-party service failures or restrictions

      Collection, use, or management of data, including HITL decisions, suppression lists, and opt-outs

      Regulatory compliance obligations, including APP, Spam Act 2003, and other privacy/security laws

    1.2.8 Fees & Payment

    MSP fees are payable in advance unless otherwise agreed in writing.

    The Monthly Fee covers the specific volume of leads or operations defined in the Client’s Service Order. If the actual volume exceeds this tier by more than 10%, the Provider will notify the Client to discuss a tier adjustment or overage fee to cover increased third-party platform and operational costs. No additional billing for overages will occur without prior notice to the Client.

    The Provider may suspend services if invoices remain unpaid more than seven (7) days past the due date.

    Payment of any invoice constitutes acceptance of these Terms.

    1.2.9 Termination

    This is a month-to-month service. Either party may terminate with thirty (30) days’ written notice prior to the next billing cycle.

    Termination does not remove obligations to pay for services already rendered.

    Upon termination, the Provider will cease workflow execution and provide a final export of Client-owned Outputs.

    1.2.10 Governing Law

    These Terms are governed by the laws of Victoria, Australia. Any disputes are subject to the jurisdiction of the courts of Victoria.

    1.2.11 Confidentiality

    Both parties agree to keep all non-public information (including lead lists, sales strategies, business processes, and technical logic) strictly confidential and will not disclose such information to third parties without prior written consent.