This AI and LLM Processing Addendum (this "Addendum") is incorporated into and forms part of the Agreement between Harmonic AI, Inc. ("Company") and Customer. Capitalized terms not defined in this Addendum have the meanings given in the Harmonic Standard Terms or Terms of Service between the parties, if applicable.
1.1 “AI Feature(s)” means any feature or functionality of the Services that uses machine learning, large language models, generative AI, embedding models, ranking models, or similar automated systems to generate, summarize, transform, classify, extract, or otherwise process data.
1.2 “LLM” means a large language model or generative model (including any hosted model or API) used to generate or transform text, code, images, embeddings, or other content.
1.3 “AI Service Company” means a third party that provides an LLM or other AI model, model endpoint, or model-hosting infrastructure used by Company to deliver AI Features. The AI Service Companies and model families currently used by Company are listed in Appendix B.
1.4 “Customer Input” means Customer Content, Confidential Information, and any other data, documents, prompts, inputs, or materials submitted to the Services by or on behalf of Customer (including from Customer’s systems via integrations).
1.5 “Output” means any data, content, recommendation, summary, extraction, or other material generated by an AI Feature in response to Customer Input.
1.6 “Sensitive Data” means any (a) information regulated as “special category” or “sensitive” under applicable privacy law; (b) credentials, secrets, or authentication data; (c) payment card data; (d) health/medical information; (e) government IDs; (f) data subject to export controls/ITAR; and (g) any other data Customer designates in writing as sensitive.
1.7 “Excluded Data” means data types that the Services and/or AI Features are not designed to process and that Customer must not submit, as listed in Section 4 (unless the parties agree in writing to permit them with additional safeguards).
2.1 AI Use. Customer acknowledges that the Services include AI Features and that Company may process Customer Input using LLMs, including LLMs provided by AI Service Companies, solely to provide and support the Services and AI Features.
2.2 Customer Instruction. Customer instructs Company to process Customer Input using AI Features (including transmission to AI Service Companies) for the purposes described in this Agreement, and represents it has the rights and permissions necessary to provide such instruction.
2.3 Company will disable AI Features and/or, where technically available,restrict categories of Customer Input routed to AI Features upon Customer’s written request.
2.4 Rate Limits. Access to AI Features are subject to standard rate limits applicable to all Customers, which may govern the number of requests, tokens processed, or outputs generated within a given time period. Customers on upgraded subscription tiers may be entitled to higher rate limits as specified in their applicable Order Form or Service Description. Company reserves the right to throttle, queue, or temporarily suspend AI Feature access for any Customer that exceeds its applicable rate limit. Company will provide reasonable notice of any material changes to standard rate limits, except where immediate action is required to protect the security, stability, or performance of the Services.
3.1 Purpose Limitation. Company will use Customer Input only to (a) provide the Services and AI Features; (b) maintain security, prevent fraud/abuse, and debug or improve reliability; (c) comply with law; and (d) any other purpose expressly authorized in writing by Customer.
3.2 No Training on Customer Input. Company will not use Customer Input to train, fine-tune, or improve any general-purpose model, foundation model, or model offered to third parties.
3.3 Flow-Down to AI Service Companies. Company will contractually require that AI Service Companies (and any downstream subprocessors) process Customer Input only to provide the relevant AI Feature, and not use Customer Input to train or fine-tune their models absent Customer’s prior written instruction or permission.
4.1 Excluded Data. Unless the parties expressly agree in writing (including any required compliance addenda, e.g., BAA/PCI/ITAR addenda), Customer will not submit: (a) payment card data; (b) protected health information/clinical data; (c) classified information; (d) ITAR/export-controlled data; or (e) credentials/secrets (API keys, passwords, private keys).
4.2 Regulated Uses. Customer is responsible for assessing whether its use of the AI Features is subject to applicable AI-specific or sector-specific regulations and for complying with any obligations that apply to Customer as the user of the AI system.
5.1 Use of Subprocessors. Customer authorizes Company to use subprocessors, including AI Service Companies, to process Customer Input and personal data as necessary to provide the Services.
5.2 Subprocessor List. Company will maintain an up-to-date list of subprocessors (including AI Service Companies) and will make that list available to Customer on request or via a public URL.
6.1 Retention to Provide the Service. Company will retain Customer Input and Output only for as long as necessary to provide the Services, unless a longer retention is (a) required by law, (b) required for security/abuse monitoring, or (c) configured by Customer (e.g., to store conversation history within Customer’s account).
6.2 Abuse/Security Logs. Company may retain limited prompts/outputs in logs for security, abuse detection, and troubleshooting.
6.3 Deletion on Termination. Upon termination/expiration, Company will delete Customer Input in accordance with Company’s standard deletion timelines, subject to legally required retention and standard backup retention, and will maintain confidentiality for any retained copies.
7.1 Security Program. Company will maintain appropriate administrative, technical, and physical safeguards designed to protect Customer Input and personal data against unauthorized access, disclosure, alteration, and destruction.
8.1 Confidentiality. Customer Input is Customer’s Confidential Information. Company will protect Customer Input under the confidentiality obligations of the Agreement.
8.2 Permitted Disclosure to AI Service Companies. Disclosure of Customer Input to AI Service Companies and subprocessors solely to provide the Services is a permitted disclosure under the confidentiality clause, provided Company ensures such parties are bound by confidentiality and security obligations no less protective than this Agreement.
9.1 Output Characteristics. Customer acknowledges Output may be inaccurate, incomplete, non-unique, or may incorporate or resemble third-party information. Customer is responsible for reviewing Output before relying on or using it.
10.1 Customer Input. As between the parties, Customer retains all right, title, and interest in Customer Input.
10.2 Company Technology. Company retains all rights in the Services, models, prompts/templates, and Company materials (excluding Customer Input).
11.1 De-Identified Data. Company may create and use de-identified and aggregated data derived from Customer Input or usage of AI Features to improve the Services (e.g., reliability, performance, safety), provided that (a) Company uses industry-standard measures to prevent re-identification, reverse engineering, or derivation of competitively sensitive insights, and (b) such data cannot be used to identify Customer or any individual.