Effective August 26, 2026. These Commercial Terms supplement the consumer Terms of Use. We preserve prior versions and provide the version governing an organization's account on request.
These Terms apply when Mpalo is used on behalf of an organization, including organization and team accounts, administrative roles, API keys and paid plans purchased by a business. The consumer Terms remain the base agreement. These Commercial Terms prevail for organizational use where they differ. A signed order, service schedule or Data Processing Addendum prevails over these Terms only for the subject it expressly covers.
For Customer Data an organization submits to Palo Bloom for its own purposes, the organization ordinarily determines the purposes and means of processing. The organization is the controller or equivalent responsible business, and Mpalo is its processor or service provider. Mpalo processes Customer Data only on documented instructions and to provide, secure, maintain and support the service, unless a separate agreement or applicable law requires otherwise.
For a member's personal use outside an organization's workspace, Mpalo may act as controller under the consumer Privacy Policy. We identify roles by purpose instead of assigning one role to every feature.
Mpalo keeps Customer Data confidential and requires personnel with access to be bound by confidentiality obligations. We use appropriate technical and organizational measures, maintain processor instructions and subprocessor controls, assist with rights requests and incident obligations where required, and return or delete Customer Data at termination subject to documented retention requirements.
Customer Data processed under these Terms does not become Mpalo shared-model training data merely because it passes through the API. Any independent Mpalo purpose requires a separate legal role, notice and authorization where required. A customer training preference cannot authorize Mpalo to use another person's data beyond the customer's lawful instructions.
We provide the administrative and API controls documented for the account to export, correct and delete Customer Data. Deletion includes the source data and linked reconstructive representations that Mpalo creates and retains, including summaries, Portable Representations retained by Mpalo, internal semantic and episodic states, graph relationships, retrieval indexes and caches. Where a derived object depends on multiple records, we delete the attributable contribution or recompute it without the deleted data.
At termination, the organization may export available Customer Data and Portable Representations during the agreed transition window. Mpalo then removes it from active systems and allows encrypted backups to expire on their normal schedule. Restoration procedures are designed not to reintroduce data deleted before restoration. We may retain isolated records when law requires it.
Mpalo may use subprocessors for infrastructure, authentication, payments, communications, security and other functions. We require them to process Customer Data only for the services and instructions established in our agreements. We communicate material subprocessor changes through the applicable service documentation or contract. International transfers use a mechanism required by applicable law.
Organizational plans bill through Stripe against the payment method on file, with invoices retained for account administration. Purchase orders and custom arrangements are available through contact sales and take effect when confirmed in writing by both parties. Taxes and withholding are handled as stated in the order or required by law.
We publish observed service health and known limitations. Custom availability, support, recovery or security commitments belong in a signed order or service schedule. A commitment is not created by a marketing page or an unverified metric.
Each party protects the other's non-public information and uses it only for the relationship. Mpalo's current security measures are described on the Safety & Security page and in applicable contract schedules. We do not imply a certification we do not hold.
Where applicable law or a signed agreement requires an audit, Mpalo may satisfy it through current security documentation, an independent assurance report, a questionnaire and reasonable additional evidence. Audits must protect other customers' information and Mpalo's security.
The Open Decay Protocol applies to organizational and consumer memory data. If Mpalo is ever acquired or changes ownership, all user memory data is automatically deleted. It is not transferred to any acquiring entity. You cannot acquire Mpalo and receive its users' memories. Customer Data that Mpalo is legally prohibited from deleting remains isolated and may not be used by a successor for product, advertising, training or other commercial purposes while the restriction continues.
Either party may end an organizational subscription as stated in the order or at the close of a billing period. Mpalo may suspend access for non-payment, security risk, unlawful instructions or material breach. We will provide notice and an opportunity to cure where the risk permits.
Nothing in these Terms excludes responsibility that cannot lawfully be excluded. Liability allocation, warranties, support levels, service credits, governing law and dispute procedures are governed by the signed order where one exists. Otherwise, the consumer Terms apply to matters not addressed here, with mandatory commercial rights preserved.
Mpalo Inc.
Commercial inquiries: support@mpalo.com