TovenAI

Terms of Service

Toven AI · Version 1.0 · Last updated 25 September 2026

These Terms of Service ("Terms") govern your organisation's use of the Toven AI service. They form an agreement between Meridien Inc., a company incorporated in the State of Delaware whose principal office is at 2 N 6th St, Brooklyn, NY 11249 ("Toven", "we", "us" or "our"), and the organisation that signs an Order Form referring to these Terms or otherwise accepts them ("Customer", "you" or "your").

The Service is provided only to businesses and other organisations. It is not offered to consumers. If you accept these Terms for an organisation, you confirm that you are authorised to bind it.

If you have signed an Order Form or another written agreement with us, it takes precedence over these Terms where the two conflict.

1. Definitions

2. The Service

2.1 What we provide. Toven provides AI-assisted compliance software for financial services firms. The modules in your Order Form determine what the Service does. It can review electronic communications, support trade surveillance and trade reconstruction, assist with eDiscovery and case analysis, scan regulatory publications, and review research and marketing publications. Each module produces Output for your staff to review.

2.2 Use rights. During the subscription term in your Order Form, you may access and use the Service for your internal business purposes. This is subject to these Terms and to any limits in the Order Form.

2.3 Changes to the Service. We may update the Service. We will notify your named contacts before a material change takes effect if it affects the Service's capabilities, its analytical pipeline (including the AI models it uses) or the data it handles.

2.4 What you provide. You supply Customer Data through the connectors agreed at onboarding. You also supply the qualified reviewers who make the final decision on every item the Service escalates. Any third-party systems you connect, such as communications archives or trading platforms, are provided under your own agreements with those providers. We are not responsible for them.

2.5 Support. Support is provided as set out in your Order Form. If the Order Form does not cover support, we provide it by email at sam@toven.ai during business hours.

3. Accounts and access

3.1 You decide who your Users are and which roles they hold. Users sign in through Microsoft Entra ID.

3.2 You are responsible for:

  1. making sure that only authorised Users access the Service and that they comply with these Terms;
  2. keeping sign-in credentials confidential;
  3. removing access promptly when a User leaves or no longer needs it; and
  4. all activity under your account.

3.3 Tell us at sam@toven.ai as soon as you become aware of any unauthorised use of your account or any other suspected security issue.

3.4 We may suspend a User's access, or the Service, where this is reasonably necessary to deal with a security threat to the Service or to Customer Data, or where the law requires it. Any suspension will be limited to what is necessary. We will tell you promptly and restore access once the issue is resolved.

4. Customer Data

4.1 Ownership. As between you and us, you own Customer Data, including Output. We acquire no rights in Customer Data except the limited licence in section 4.2.

4.2 Our limited licence. You grant us a non-exclusive licence to host, copy, process, transmit and display Customer Data. We may do this only as needed to provide the Service to you, including support, security and troubleshooting, in line with these Terms and your Order Form, or where the law requires it.

4.3 No training, no sale, no sharing. We do not use Customer Data to train or fine-tune AI models. We do not sell Customer Data or share it with other customers. Our AI model providers are engaged on terms that do not allow them to use your data to train their models.

4.4 Your responsibilities. You are responsible for the accuracy and lawfulness of Customer Data. You must have all the rights, notices, consents and legal bases needed to give it to us and to have it processed as these Terms describe. This includes any notices to, or consents from, your personnel, clients and counterparties whose communications or records are included, where employment, privacy, communications or other laws require them.

4.5 Usage Data. We may collect and use Usage Data to operate, secure, support and improve the Service. Where Usage Data identifies individuals, our Privacy Policy (toven.ai/privacy) applies.

5. Data protection

5.1 Roles. For personal data within Customer Data, you are the controller and we are your processor. For personal data we collect to run our business, we are the controller and our Privacy Policy applies. That data includes User account details, business contact details and Usage Data.

5.2 Instructions. We process Customer Data only on your documented instructions. Your instructions are these Terms, your Order Form and the way you configure and use the Service. If the law requires us to process Customer Data in any other way, we will tell you before we do so, unless the law prohibits that. We will also tell you if we believe an instruction infringes Data Protection Law.

5.3 Details of processing.

5.4 Personnel. Everyone we authorise to process Customer Data is bound by confidentiality obligations.

5.5 Security. We implement the measures in section 9.

5.6 Subprocessors. You give us general authorisation to engage Subprocessors on the terms in section 9.8.

5.7 Assistance. We will give you reasonable help with the following, taking into account the nature of the processing and the information available to us:

  1. responding to requests from individuals exercising their rights under Data Protection Law;
  2. your data protection impact assessments and any prior consultation with a supervisory authority; and
  3. your obligations on security and breach notification.

If an individual contacts us directly about Customer Data, we will refer them to you. We will not respond to the request ourselves unless the law requires it.

5.8 Information and audits. We will make available the information reasonably needed to show that we comply with this section 5. This includes our security documentation and answers to reasonable security questionnaires. We will allow for and contribute to audits, including inspections, by you or by an independent auditor you appoint, as required by Article 28(3)(h) of the GDPR. You must give reasonable notice of an audit. Audits take place during business hours, must not disrupt the Service, are kept confidential and are at your cost.

5.9 International transfers. Customer Data is hosted in the EU, as described in section 9.9. Customer Data may be transferred outside the European Economic Area or the UK, for example when our personnel or Subprocessors access it from another country. In that case we will make sure a safeguard recognised by Data Protection Law is in place, such as an adequacy decision or the European Commission's Standard Contractual Clauses.

5.10 Return and deletion. Section 13 applies.

6. AI Output and human review

6.1 Decision support. The Service is a decision-support tool, not an autonomous decision-maker. It presents recommendations with its reasoning and citations to the source records. A qualified reviewer at your organisation decides each item, and the recorded decision is that reviewer's, not the Service's. The Service is not designed or supported for use as an unsupervised control.

6.2 Review before relying on Output. Output is produced with AI models and may be incomplete or wrong. You are responsible for reviewing Output before relying on it, and for your decisions and actions.

6.3 Limits of the Service.

  1. Output covers only the data connected to the Service. The Service will not see conduct on a channel, in a system or during a period that is not connected.
  2. No surveillance system detects all misconduct. We do not warrant that the Service will identify every problematic item, or that every item it raises is a genuine concern.
  3. Output is not legal or regulatory advice. Your compliance and legal functions remain responsible for deciding whether conduct breached a rule and how regulatory changes apply to you.
  4. Results depend on your data, your risk configuration and your review standards. Any published figures for throughput or accuracy reflect particular deployments and particular data.
  5. The Service is not a system of record. It does not fulfil your recordkeeping, reporting or supervisory obligations, and it does not replace your archiving system.

6.4 Models. The Service uses foundation models supplied by third parties through Microsoft Azure AI Foundry. Model versions change over time. We notify material changes under section 2.3.

7. Acceptable use

You will not, and will not allow anyone else to:

  1. use the Service in breach of any law or regulation, or to process data you have no right to process;
  2. access, or try to access, data or parts of the Service you are not authorised to use;
  3. scan, probe or penetration-test the Service, or try to get around its security or access controls, without our prior written consent;
  4. upload malware or anything designed to damage or disrupt a system, or to gain unauthorised access to one;
  5. interfere with the Service, put an unreasonable load on it, or exceed the limits in your Order Form;
  6. copy, modify, reverse engineer, decompile or disassemble the Service, except where the law allows this despite this restriction;
  7. resell or sublicense the Service, or otherwise make it available to third parties, except as your Order Form allows; or
  8. use the Service to build a competing product or service.

If a breach of this section threatens the Service, other customers or Customer Data, we may suspend the affected access where reasonably necessary. We will give notice first where practicable.

8. Confidentiality

8.1 "Confidential Information" means non-public information that one party discloses to the other and that is marked confidential or that a reasonable person would understand to be confidential. Customer Data is your Confidential Information. Non-public information about the Service is ours. That includes our pricing, our security documentation, and the prompts, configurations and methods the Service uses.

8.2 The party receiving Confidential Information will:

  1. use it only to perform its obligations or exercise its rights under these Terms;
  2. protect it with at least reasonable care; and
  3. disclose it only to employees, contractors, Subprocessors and professional advisers who need to know it and who are bound by confidentiality obligations at least as protective as this section.

8.3 These obligations do not apply to information that:

These exceptions do not reduce our obligations for Customer Data under sections 4, 5, 9 and 13.

8.4 A party may disclose Confidential Information where the law requires it. Where the law allows, it will first give the other party prompt notice and reasonable help to seek protective treatment.

8.5 These obligations continue during the term and for five years after it ends. For Customer Data, they continue for as long as we hold it.

9. Security Commitments

We maintain the following measures to protect Customer Data throughout your subscription term. This section covers the production environment of the Service that Toven operates. Environments you operate are not covered, including any work our personnel do inside your own cloud tenancy. Your Order Form governs that work.

9.1 Security programme. We maintain written information security policies. They cover access management, audit logging, incident response, vulnerability management, data management and retention, vendor management, change management and business continuity, among other topics. Everyone at Toven with access to Customer Data acknowledges these policies.

9.2 Encryption and network protection. Customer Data is encrypted in transit using TLS. It is encrypted at rest using the cloud platform's managed encryption. Our databases, storage and AI inference endpoint accept connections only from our private network and cannot be reached from the public internet. Application secrets are held in a managed key vault.

9.3 Access control. Access follows the principle of least privilege. Only named Toven personnel with a business need can access production systems and Customer Data. They sign in through Microsoft Entra ID with multi-factor authentication. We review access at least once a year and whenever someone's role changes. When someone leaves, we remove all of their access within 24 hours.

9.4 Logging and monitoring. Production systems log security-relevant events to a dedicated audit log store. These include sign-in attempts, administrative actions and changes to privileges. Database, key vault and storage activity is logged to a managed log workspace. Production systems are monitored continuously with automated health checks and alerts, and we review alerts to identify security incidents. We also use cloud tools for security posture management and threat protection.

9.5 Vulnerability management. Production systems are scanned for vulnerabilities at least monthly and after each major change. Our source code and dependencies are scanned automatically. Each finding is triaged by severity and has a remediation deadline for its severity level. Critical vulnerabilities are remediated within seven days.

9.6 Incident response. We maintain a documented incident response process. It covers triage, validation, containment, eradication, recovery and a post-incident review.

9.7 Security Incident notification. If we become aware of a Security Incident, we will notify your designated contacts without undue delay. We will give you the information reasonably available to us about the nature of the incident, the categories of Customer Data affected and the measures we are taking. We will send further information as it becomes available, to help you meet your own obligations. A notification is not an admission of fault.

9.8 Subprocessors. We currently use these Subprocessors:

SubprocessorWhat it doesWhere
Microsoft (Microsoft Azure, including Azure AI Foundry and Azure Databricks)Hosting, storage, databases, identity and sign-in, AI model inference and data processingCustomer Data is hosted in the EU (Azure Sweden Central region)
CloudflareDNS, TLS termination and proxying of traffic to the ServiceCloudflare's global network (data in transit)

Before a new vendor connects to our production environment, we complete a vendor risk review and get leadership approval. We host production systems only with providers that hold SOC 2 or equivalent security certifications. Each Subprocessor is bound by written data protection terms that meet the requirements of Data Protection Law, and we remain responsible for its performance.

We will notify you at least 30 days before we add or replace a Subprocessor. We may give shorter notice if an urgent security or continuity need requires it. You may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the affected Order Form by written notice before the change takes effect.

9.9 Data location. Unless your Order Form says otherwise, Customer Data is hosted in Microsoft Azure's Sweden Central region in the European Union. Traffic to and from the Service passes through Cloudflare's network. Section 5.9 applies to any transfer outside the European Economic Area or the UK.

9.10 Personnel. Everyone at Toven with access to Customer Data:

9.11 Assurance. We are working towards a SOC 2 Type 2 report and ISO 27001 certification. We do not currently hold either. We will answer reasonable security questionnaires on request.

9.12 Reporting a vulnerability. Report a suspected vulnerability or security incident to sam@toven.ai.

9.13 Changes. We notify changes to this section 9 under section 16.

10. Availability and support

10.1 We use commercially reasonable efforts to keep the Service available. Target availability, support hours, response times and service credits apply only if your Order Form sets them. Otherwise, we do not commit to a specific level of availability.

10.2 Each deployment of the Service runs in a single cloud region.

10.3 We schedule planned maintenance outside your trading hours where possible and notify you in advance. We tell your named contacts about unplanned interruptions. For anything material, we follow up with an account of the cause and of how we fixed it.

11. Fees

11.1 Fees, invoicing and payment terms are set out in your Order Form.

11.2 Fees do not include taxes. You are responsible for any applicable taxes, other than taxes on our income.

11.3 If undisputed fees are still unpaid 30 days after their due date, we may suspend the Service after giving you at least 10 days' written notice.

12. Term and termination

12.1 These Terms start when you accept them or when your first Order Form starts, whichever is earlier. They continue until every Order Form has ended. Each Order Form sets out its own term and any renewal.

12.2 Either party may terminate an Order Form by written notice if the other party:

  1. materially breaches these Terms and does not remedy the breach within 30 days of receiving written notice of it; or
  2. becomes insolvent, enters administration, liquidation or a similar process, or stops trading.

12.3 When an Order Form ends:

12.4 Sections 4.1, 5 (for as long as we hold Customer Data), 8, 13, 14.4, 15, 17 and 18 continue to apply after these Terms end.

13. Return and deletion of Customer Data

13.1 During the term. You may ask us to delete Customer Data at any time by emailing sam@toven.ai. We will delete it within 30 days of your request, unless the law requires us to keep it.

13.2 After termination. We keep Customer Data for 30 days after your subscription ends. During that period you can reinstate your account or ask us to return the data. At your choice, we will either return Customer Data to you in a commonly used electronic format or delete it. When the period ends, we will delete any remaining Customer Data within a further 30 days.

13.3 Exceptions. We keep Customer Data beyond these periods only where the law requires it, and any data we keep stays protected under these Terms. Copies in backups are deleted when those backups expire in the normal backup cycle.

14. Warranties and disclaimers

14.1 Each party warrants that it has the authority to enter into these Terms.

14.2 We warrant that we will provide the Service with reasonable skill and care and materially as described in the Service Description. We also warrant that we will maintain the Security Commitments in section 9 throughout your subscription term.

14.3 You warrant that you have the rights, notices, consents and legal bases described in section 4.4.

14.4 Except as these Terms expressly state, the Service and Output are provided "as is". To the extent the law allows, we disclaim all other warranties and conditions, express or implied, including merchantability, satisfactory quality, fitness for a particular purpose and non-infringement. We do not warrant that the Service will be uninterrupted or error-free. We do not warrant that Output will be complete or accurate, or that it will identify all misconduct.

15. Limitation of liability

15.1 Neither party is liable for any indirect, incidental, special, consequential or punitive loss. Neither party is liable for any loss of profits, revenue, business, goodwill or anticipated savings. These exclusions apply however the loss arises, even if the party was told it was possible.

15.2 Each party's total liability arising out of or in connection with these Terms and all Order Forms is limited to the fees paid and payable by you to us in the 12 months before the event that gave rise to the claim.

15.3 Nothing in these Terms limits or excludes:

16. Changes to these Terms

16.1 We may update these Terms. We publish the current version at toven.ai/terms with its version number and date.

16.2 We will notify each customer of a material change by email to its account contacts at least 30 days before the change takes effect. This includes any change to section 9. A change that is required by law, or that strengthens security, may take effect sooner. In that case we will notify you as promptly as we can.

16.3 If a material change adversely affects you, you may terminate the affected Order Form by written notice before the change takes effect.

16.4 An update does not change an Order Form or any other written agreement you have signed with us unless both parties agree in writing.

17. Governing law and jurisdiction

Governing law and venue: the laws of the State of Delaware, and the state and federal courts located in the State of Delaware. That law governs these Terms and any dispute or claim arising out of or in connection with them. Each party submits to the exclusive jurisdiction of those courts.

18. General

18.1 Entire agreement. These Terms, your Order Forms and the documents they refer to are the entire agreement between us about the Service. They replace any earlier understanding about it.

18.2 Order of precedence. If these documents conflict, they apply in this order: a signed Order Form or other written agreement, then these Terms, then the Service Description.

18.3 Assignment. Neither party may assign these Terms without the other's written consent. The exception is an assignment, with written notice, to a successor in a merger, an acquisition or a sale of all or substantially all of the relevant business or assets.

18.4 Subcontracting. We may use subcontractors and Subprocessors to provide the Service. We remain responsible for them.

18.5 Force majeure. Neither party is liable for a delay or failure caused by events beyond its reasonable control. This does not excuse payment obligations.

18.6 Publicity. We will not use your name or logo in our marketing without your prior written consent.

18.7 Feedback. If you give us suggestions about the Service, we may use them without any obligation to you.

18.8 Notices. We send notices to the contact email addresses in your Order Form or account. You send notices to sam@toven.ai. An emailed notice takes effect when it is sent, unless the sender receives a delivery failure message.

18.9 Other terms. The parties are independent contractors. No third party has rights under these Terms. Not enforcing a provision does not waive it. If a provision is unenforceable, the rest of these Terms remains in effect.

19. Contact

Toven AI is a trading name of Meridien Inc., 2 N 6th St, Brooklyn, NY 11249.

Questions about the Service, security, privacy or legal matters: sam@toven.ai

We use optional analytics cookies to understand how this site is used. Read our Privacy Policy.