Railbase

Compliance Plugin Special Terms and Risk Acknowledgment

Version: 1.1 Effective date: 8 August 2026

1. Agreement, parties, and precedence

1.1. These Compliance Plugin Special Terms and Risk Acknowledgment (the "Special Terms") are a binding agreement between Silkway Tech LLC, a Wyoming limited liability company with a mailing address at 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA (the "Vendor"), and the company or other legal entity acquiring, trialing, installing, or using the Railbase Compliance plugin (the "Customer"). The individual accepting these Special Terms represents that they have authority to bind the Customer.

1.2. These Special Terms supplement the Terms of Service, Railbase Core EULA, Plugin Subscription & Marketplace Agreement, and, where applicable, the Data Processing Addendum (together, the "General Terms"). They apply specifically to the Railbase Compliance plugin (the "Plugin").

1.3. If these Special Terms conflict with the General Terms on a matter specific to the Plugin's compliance analysis, risk signals, Customer decisions, or the operational safeguards required for the Plugin, these Special Terms control. Capitalized terms not defined here have the meanings in the General Terms.

2. Definitions

2.1. "Affected Person" means a natural person about whom Source Data is processed or whose rights, opportunities, employment, access, reputation, finances, or other interests may be affected by Plugin Output or a Customer decision informed by Plugin Output.

2.2. "Customer Systems" means the Customer's Railbase deployment, Vault, infrastructure, information systems, configured connectors, accounts, networks, devices, and third-party services from which the Plugin receives or with which it exchanges data.

2.3. "Source Data" means records, fields, files, events, identifiers, configurations, and other information supplied by or on behalf of the Customer or obtained from Customer Systems under the Customer's authority.

2.4. "Plugin Output" means any alert, score, possible match, relationship, classification, risk indicator, case, summary, visualization, normalized record, recommendation, or other derived result produced or displayed by the Plugin.

2.5. "Material or Adverse Decision" means an action or omission that produces or may reasonably produce a legal, employment, financial, contractual, disciplinary, regulatory, reputational, or similarly significant effect on an Affected Person or another person or entity.

2.6. "Human Review" means a documented, substantive, and independent evaluation by a natural person who has appropriate competence, access to relevant evidence, sufficient time and support, and actual authority to disagree with, disregard, correct, escalate, or override Plugin Output.

2.7. "Supported Configuration" means a source-system edition, connector, mapping, field set, workflow, deployment pattern, and Plugin version identified as supported in then-current Documentation, subject to the limitations and assumptions stated there.

2.8. "Serious Incident" means an event, defect, pattern, unauthorized access, security compromise, unlawful use, or materially misleading output that has caused or is reasonably likely to cause significant legal, financial, employment, privacy, security, discriminatory, physical, psychological, or reputational harm.

2.9. "Documentation" means the then-current technical, connector, configuration, use, release, security, and limitation documentation supplied by the Vendor for the Plugin.

3. Nature, intended purpose, and status of Plugin Output

3.1. The Plugin is a self-hosted data organization, analysis, continuous-controls-monitoring, and visualization tool. It receives data made available by the Customer through Railbase and configured information-system connectors; normalizes and links that data; applies configured rules, mappings, checks, and analytical methods; and produces Plugin Output.

3.2. The intended purpose of the Plugin is to assist qualified Customer personnel with internal compliance monitoring, risk triage, investigation planning, evidence organization, and review. The Plugin is an aid to, and not a substitute for, professional judgment, lawful process, or Human Review.

3.3. The Plugin does not independently establish new source facts about a person, company, transaction, or event. Plugin Output consists of derived analytical indications based on Source Data, configuration, rules, and the Plugin version in use.

3.4. Plugin Output is not proof, a legal conclusion, an audit opinion, a certification of compliance, an accusation, a finding of misconduct, or professional legal, accounting, employment, sanctions, financial, medical, credit, insurance, regulatory, or investigative advice.

3.5. The Customer must not represent Plugin Output as a determination, certification, or statement made by the Vendor, by a source-system provider, or by a regulator.

4. Permitted and prohibited uses

4.1. The Customer may use the Plugin only for lawful business purposes within the intended purpose described in Section 3 and in accordance with the Documentation, the General Terms, these Special Terms, and applicable law.

4.2. The Customer must not use Plugin Output as the sole or determinative basis for a Material or Adverse Decision.

4.3. The Customer must not use the Plugin for solely automated decision-making that produces legal or similarly significant effects on an Affected Person unless that use is expressly permitted by applicable law and all required safeguards, notices, assessments, rights, and Human Review procedures have been implemented.

4.4. The Customer must not use the Plugin to infer or assign race, ethnicity, religion, health status, disability, sexual orientation, political opinion, trade-union membership, biometric identity or categorization, or another legally protected or highly sensitive characteristic, except where the specific processing is lawful, necessary, proportionate, documented, and expressly approved under the Customer's applicable compliance process.

4.5. The Customer must not use the Plugin for unlawful covert surveillance, indiscriminate monitoring, social scoring, retaliation, harassment, discriminatory profiling, or the targeting of persons based on protected characteristics.

4.6. The Customer must not use Plugin Output to make or materially influence employment, worker discipline, credit, lending, insurance, housing, education, healthcare, public-benefit, essential-service, or law-enforcement decisions unless the Customer has first determined that the use is lawful, completed all required assessments and audits, provided all required notices, and implemented effective Human Review, correction, contest, accommodation, and appeal mechanisms.

4.7. The Customer must not communicate an allegation or suspicion as an established fact, file a report that presents Plugin Output as verified evidence, or take punitive or irreversible action without an appropriately scoped investigation and Human Review.

4.8. The Customer must not use the Plugin to avoid, restrict, or interfere with an Affected Person's applicable rights to notice, access, correction, explanation, objection, human intervention, accommodation, contest, appeal, or due process.

4.9. The technical ability of the Plugin to ingest, link, analyze, display, or export data is not a representation that the Customer's intended use is lawful or permitted.

4.10. The Vendor may restrict, suspend, disable, or withdraw a Plugin feature when the Vendor reasonably believes that continued use creates a material security, legal, safety, or rights risk, subject to applicable law and the General Terms.

5. Customer decision-making and Human Review

5.1. The Customer is solely responsible for its use of the Plugin and for every investigation, conclusion, action, omission, communication, filing, disciplinary measure, employment decision, payment hold, vendor decision, report, or other decision made in reliance on Plugin Output. Using the Plugin does not transfer the Customer's duties, judgment, accountability, or legal responsibility to the Vendor.

5.2. Before relying on Plugin Output for a Material or Adverse Decision, the Customer must conduct and document Human Review by personnel appropriate to the subject matter and the potential impact of the decision.

5.3. The Customer must ensure that each reviewer has appropriate training, competence, access to relevant Source Data and Documentation, awareness of known limitations and error modes, sufficient time and organizational support, independence from improper incentives, and authority to override or escalate Plugin Output.

5.4. Human Review must, as applicable, inspect the underlying source records; confirm identity and data provenance; check completeness, currency, configuration, mappings, thresholds, and legal context; seek explanations from Affected Persons; consider exculpatory and contradictory evidence; distinguish correlation from causation; and follow the Customer's investigation, escalation, due-process, and approval procedures.

5.5. Merely viewing Plugin Output, accepting a default recommendation, clicking an approval control, or checking that required fields are populated does not constitute Human Review.

5.6. The reviewer must document the evidence considered, unresolved limitations, any disagreement with Plugin Output, any override or escalation, the reviewer's conclusion, and the independent reasons for the Customer's final decision.

5.7. A decision made without the Human Review required by these Special Terms is the Customer's own choice and risk. To the maximum extent permitted by law, the Customer may not attribute that decision or its consequences to the Vendor merely because Plugin Output was considered.

6. Source-system assumptions, lawful access, and data quality

6.1. Default mappings and analytical behavior are developed and tested using common enterprise data patterns and representative configurations, including typical 1C and QuickBooks implementations. This reference scope is not a certification by, endorsement from, or guarantee of compatibility with those vendors, every edition or localization, or any particular Customer deployment.

6.2. Custom fields, extensions, localizations, non-standard workflows, renamed entities, incomplete history, inconsistent identifiers, different accounting or HR practices, unsupported data types, access restrictions, delayed synchronization, and Customer-specific integrations can materially change Plugin Output. Differences caused by Customer Systems, Source Data, configuration, source-data quality, or departure from documented assumptions do not by themselves constitute a defect or breach by the Vendor.

6.3. The Customer represents and warrants that it owns or has all rights, permissions, authority, and lawful bases required to access, connect, copy, combine, normalize, analyze, retain, and otherwise process Source Data for the Customer's intended purpose.

6.4. The Customer is responsible for configuring connector credentials, source-system roles, field access, extraction scope, synchronization frequency, and tenant boundaries according to least-privilege and data-minimization principles.

6.5. The Customer must not knowingly provide materially false, misleading, unlawfully obtained, or improperly scoped Source Data or configure the Plugin in a manner intended to produce a predetermined allegation or discriminatory result.

6.6. The Customer must validate mappings, source coverage, field meaning, identity resolution, access scope, synchronization frequency, thresholds, and detector behavior before operational reliance and after material changes.

6.7. To the extent the Customer controls input data, the Customer must take reasonable measures to ensure that Source Data is relevant, sufficiently complete, current, accurate, and representative for the intended purpose, while avoiding collection of unnecessary personal data.

7. Pre-deployment assessment and commissioning

7.1. Before operational use, the Customer must document the intended purpose, business process, decision context, categories of Source Data, categories of Affected Persons, expected benefit, reasonably foreseeable misuse, potential harm, responsible owner, reviewers, escalation path, and applicable legal requirements.

7.2. The Customer must complete any data-protection impact assessment, fundamental-rights impact assessment, algorithmic or automated-decision impact assessment, bias audit, security assessment, employment consultation, records assessment, or other review required by applicable law or reasonably appropriate to the intended use.

7.3. Where applicable, the Customer must consult its data protection officer, legal counsel, information-security personnel, compliance function, internal audit, employee representatives, works council, labor organization, or other required stakeholder before deployment.

7.4. The Customer must perform controlled acceptance testing using representative and appropriately protected data. Testing must evaluate mappings, source coverage, expected true-positive and true-negative scenarios, false positives, false negatives, duplicates, stale data, identity mismatches, access controls, tenant isolation, reviewer workflow, and the ability to correct and override Plugin Output.

7.5. The Customer must record its test scope, results, known limitations, remediation, residual risks, accepted use cases, prohibited use cases, and an authorized go/no-go decision before operational reliance.

7.6. The Customer must repeat or update the assessment and acceptance testing after a material change to the Plugin, Customer Systems, Source Data, mappings, configuration, intended purpose, affected population, legal environment, or decision process.

8. Expected error modes and continuing change

8.1. The Customer understands that the Plugin may produce correct results, incorrect results, false positives, false negatives, duplicate or incomplete results, stale results, missed relationships, identity mismatches, misclassified records, misleading correlations, or results that require additional context.

8.2. A lack of an alert does not establish compliance or the absence of misconduct, and an alert does not establish non-compliance or misconduct.

8.3. Rules, algorithms, mappings, thresholds, detectors, risk weights, and user interfaces may be corrected, tuned, expanded, replaced, or retired over time. Those changes may alter Plugin Output for the same Source Data.

8.4. The Vendor does not warrant a particular detection rate, false-positive rate, false-negative rate, outcome, equivalence between Plugin versions, or consistency across different Customer configurations.

9. Data protection and safeguards for Affected Persons

9.1. The Customer is the controller, business, employer, records owner, or other responsible party for personal data and business data processed in its self-hosted deployment, except to the limited extent a mandatory law or an applicable Data Processing Addendum expressly assigns a different role.

9.2. The Customer must determine and document a lawful basis and permitted purpose; provide required privacy and workplace notices; obtain consent where required; respect data-subject, employee, and worker rights; limit access by role and need; apply data-minimization, purpose-limitation, accuracy, retention, deletion, and cross-border-transfer requirements; and comply with employment, workplace-monitoring, whistleblowing, investigation, anti-discrimination, privacy, banking, sanctions, and other applicable laws.

9.3. The Customer is responsible for deciding whether identifiers, bank details, contact data, addresses, employment records, relationships, transactions, allegations, and other sensitive data may lawfully be connected and analyzed for the Customer's intended purpose.

9.4. Where required by applicable law, the Customer must inform Affected Persons that automated analysis or Plugin Output is being used or considered, explain the relevant purpose and decision process in understandable terms, and identify an accessible contact or procedure for exercising applicable rights.

9.5. The Customer must provide an effective procedure for an Affected Person to report inaccurate Source Data, submit relevant additional information, and request correction of data used in the Customer's decision process where required by law.

9.6. Where required by law or appropriate to the risk, the Customer must provide a meaningful opportunity to contest a Material or Adverse Decision and obtain review by a qualified natural person who was not improperly bound by the original Plugin Output.

9.7. The Customer must provide reasonable accommodation and an alternative evaluation process where disability, accessibility, language, data availability, or another relevant circumstance may make the Plugin-assisted process inaccurate or unfair and applicable law requires accommodation.

9.8. The Customer must not retaliate against an Affected Person for correcting data, requesting Human Review, seeking an accommodation, contesting a decision, raising a compliance concern, or exercising another protected right.

9.9. Before using a regulated system at the workplace, the Customer must notify and consult affected workers and their representatives to the extent required by applicable law, collective agreement, or established labor practice.

9.10. The Customer remains responsible for responding to access, correction, deletion, objection, restriction, explanation, appeal, and other rights requests concerning Source Data, Plugin Output, and Customer decisions.

10. Ongoing monitoring, bias testing, and governance

10.1. The Customer must appoint an accountable business owner for each operational use of the Plugin and clearly assign responsibility for configuration, access, data quality, Human Review, complaints, monitoring, incident response, and approval of continued use.

10.2. The Customer must periodically review the Plugin's operation at a frequency proportionate to the intended use, volume, sensitivity of Source Data, affected population, known limitations, and potential severity of harm.

10.3. Monitoring must, as appropriate, evaluate false positives, false negatives, identity mismatches, stale or missing data, unsupported configurations, detector drift, overrides, reversed decisions, complaints, access anomalies, and differences between expected and observed outcomes.

10.4. Where lawful and appropriate, the Customer must assess whether the use produces materially different error rates or adverse outcomes for legally protected or vulnerable groups. This obligation does not require the Customer to collect or infer protected characteristics where doing so would be unlawful or disproportionate.

10.5. The Customer must document monitoring results, material limitations, remediation, accepted residual risk, and the responsible person's decision to continue, restrict, modify, or stop the use.

10.6. The Customer must promptly correct configuration or data problems within its control and suspend affected use where monitoring indicates a material risk of unlawful, discriminatory, insecure, or seriously misleading operation.

10.7. The Vendor will describe confirmed material limitations and known reasonably foreseeable risks requiring Customer action through the Documentation, release notes, security notice, in-product notice, or another commercially reasonable channel. This obligation does not constitute a representation that every possible error, misuse, or risk can be identified in advance.

11. Decision records, logs, and retention

11.1. For each Material or Adverse Decision informed by Plugin Output, the Customer must retain a record sufficient to reconstruct the relevant process, subject to applicable data-protection and records laws.

11.2. The record should include, where applicable, the Plugin and detector version; relevant rule, mapping, and threshold version; time of analysis; references to material Source Data; Plugin Output considered; known limitations; identity of the reviewer; evidence reviewed; corrections; explanation received from an Affected Person; override or escalation; final decision; and independent reasons for that decision.

11.3. The Customer should preserve source references or appropriately protected snapshots only to the extent necessary for accountability, investigation, legal obligations, and defense of the decision. The Customer must not retain unnecessary copies of sensitive Source Data merely because the Plugin can display or export them.

11.4. The Customer must set and enforce documented retention and deletion periods appropriate to the intended purpose and applicable law. No uniform retention period stated by the Plugin replaces the Customer's legal and records-management analysis.

11.5. The Customer must protect decision records and logs against unauthorized access, alteration, loss, and premature deletion; maintain appropriate audit trails; and restrict access according to role and need.

11.6. Where applicable law requires preservation of automatically generated logs for a minimum period, the Customer is responsible for configuring and maintaining that retention in Customer Systems to the extent those logs are under the Customer's control.

12. Serious Incidents, complaints, and suspension

12.1. When the Customer discovers or reasonably suspects a Serious Incident, it must promptly stop or restrict the affected use where continued operation could increase harm, preserve relevant evidence, prevent unauthorized access, and begin an appropriately independent investigation.

12.2. The Customer must notify the Vendor without undue delay when Vendor assistance, correction, or investigation is reasonably required, while minimizing personal data and protecting legally privileged, confidential, and regulated information.

12.3. The Customer is responsible for determining and completing any notice, report, consultation, remediation, or cooperation required with Affected Persons, employees, representatives, regulators, law enforcement, customers, insurers, or other parties.

12.4. When the Vendor confirms a material defect, vulnerability, or risk that requires Customer action, the Vendor will use commercially reasonable efforts to notify known affected Customers without undue delay, subject to lawful security-disclosure practices and any instruction or restriction imposed by a competent authority.

12.5. The Vendor may investigate reported defects; issue instructions, warnings, mitigations, patches, or corrected mappings; and restrict, disable, withdraw, or replace affected functionality when reasonably necessary to reduce a material risk.

12.6. The Customer must reasonably cooperate with corrective action, apply critical updates or mitigations, retest affected use, and avoid re-enabling suspended functionality until the Customer has documented that continued use is appropriate.

12.7. Each party remains responsible for its own non-waivable regulatory reporting and incident-response obligations. Nothing in these Special Terms makes the Vendor responsible for deciding whether the Customer must notify an Affected Person or authority.

13. Self-hosting, confidentiality, and security

13.1. The Plugin runs inside the Customer's self-hosted Railbase deployment and stores Plugin business data in the Customer's Vault. The Plugin does not automatically transmit Source Data, normalized business data, identifiers, bank details, alerts, cases, or other Plugin business data to the Vendor.

13.2. Railbase separately exchanges limited account, licensing, activation, version, tenant-registration, purchase, and security-related operational metadata with railbase.app as described in the General Terms and Privacy Policy. That operational metadata does not include the Customer's Plugin business data.

13.3. The Customer chooses the infrastructure on which Railbase and the Plugin run and is responsible for its trustworthiness and security, including physical and network security, operating-system and Railbase updates, credentials and secrets, TLS, firewalls, endpoint protection, access controls, administrator activity, backups, restore testing, monitoring, incident response, business continuity, source-system permissions, connector credentials, and secure disposal.

13.4. The Customer must promptly remove access for personnel who no longer require it, periodically review privileged access, protect connector credentials, and investigate suspected unauthorized access.

13.5. The Customer remains responsible for the availability, integrity, accuracy, confidentiality, backup, retention, restoration, and lawful deletion of its data. No Plugin feature replaces the Customer's backup, security, records-management, or disaster-recovery program.

14. Customer-initiated support and exceptional data access

14.1. The Vendor has no routine or persistent access to Source Data or Plugin Output in the Customer's self-hosted deployment.

14.2. If the Customer requests support, the Customer may choose to disclose diagnostic information, screenshots, logs, samples, or temporary access. The Customer must ensure that it has authority to make that disclosure and must minimize, redact, pseudonymize, or use synthetic data wherever reasonably possible.

14.3. Before the Vendor receives Plugin business data or remote access, the parties must establish an authorized support scope and apply the General Terms and any required Data Processing Addendum. Access must be limited to the approved purpose, systems, personnel, privileges, and time period.

14.4. When the Vendor accepts such access or data, the Vendor will apply reasonable confidentiality and security measures, use the information only to provide the requested support or satisfy mandatory law, log or otherwise document access where reasonably practicable, and not use the information to train a general-purpose or third-party AI model.

14.5. The Vendor will return, delete, or render inaccessible Customer-provided support materials when they are no longer reasonably required for the authorized support purpose, contractual records, security investigation, or mandatory legal retention.

14.6. Completion of a support engagement does not create continuing Vendor access to Customer Systems. The Customer is responsible for revoking temporary credentials, tokens, network access, and support accounts after the authorized work ends.

15. AI-assisted development and regulatory classification

15.1. The Vendor may use artificial-intelligence-assisted tools in designing, coding, testing, reviewing, documenting, or maintaining the Plugin. The Customer acknowledges the general limitations of AI-assisted development, including the possibility of defects, omissions, unexpected behavior, or incomplete reasoning.

15.2. Unless a specific Plugin feature and its Documentation expressly state otherwise, the Plugin does not send the Customer's Plugin business data to a third-party AI provider and does not delegate the Customer's final decisions to an external AI service.

15.3. The Vendor does not represent that every Plugin feature or Customer deployment is, or is not, an artificial-intelligence system, high-risk AI system, automated decision-making technology, automated employment decision tool, profiling system, or other legally regulated system. Classification depends on applicable law, the feature, intended purpose, configuration, Source Data, decision process, affected persons, jurisdiction, and the Customer's actual use.

15.4. Each party is responsible for determining and performing the mandatory legal obligations assigned to that party by applicable law. Contractual allocation of operational responsibility does not eliminate a non-waivable statutory duty of the Vendor or Customer.

15.5. If a Plugin feature or use is regulated, the Customer is responsible for its obligations as deployer, user, employer, controller, decision-maker, or other applicable role, including required impact assessments, governance, Human Review, training, input-data controls, monitoring, logging, notices, explanations, correction, contest, appeal, worker consultation, registration, and regulatory cooperation.

15.6. The Vendor will provide the Documentation and technical information that it is contractually or legally required to provide and may, on reasonable request, provide additional information then reasonably available to help the Customer perform an applicable assessment. Such assistance is technical information, not legal advice, certification, or a transfer of the Customer's obligations.

15.7. The Vendor's use of AI-assisted development tools does not reduce the Customer's Human Review, validation, monitoring, or decision-making obligations under these Special Terms.

16. Third-party systems, connectors, and dependencies

16.1. References to 1C, QuickBooks, or another third-party product describe representative integration patterns only and do not imply certification, sponsorship, endorsement, partnership, or a guarantee by the third-party provider.

16.2. The Customer is responsible for obtaining and maintaining all third-party accounts, subscriptions, licenses, API rights, consents, credentials, network access, and source-system support required for the Customer's use.

16.3. The Vendor does not control and is not responsible for a third party's availability, security, data quality, schema, API, localization, authentication, rate limits, pricing, licensing terms, deprecation, or product changes.

16.4. A third-party change may interrupt synchronization, alter field meaning, reduce available data, require remapping, or change Plugin Output. The Customer must monitor connector health and validate affected mappings before relying on data following such a change.

16.5. The Vendor may update, restrict, or discontinue a connector or Supported Configuration when a third-party change, legal restriction, security risk, or unreasonable maintenance burden makes continued support impracticable, subject to the General Terms.

17. Material changes, revalidation, and re-acceptance

17.1. A "Material Change" includes a new or materially changed detector, algorithm, risk score, threshold, mapping, category of Source Data, intended purpose, external data transfer, regulated use, decision workflow, security characteristic, or limitation that can reasonably affect Plugin Output, Customer obligations, or risk to an Affected Person.

17.2. The Vendor will identify material Plugin changes through release notes, Documentation, in-product notice, marketplace notice, or another commercially reasonable channel, except where immediate action is reasonably necessary for security, law, safety, or incident response.

17.3. Before relying on an affected feature after a Material Change, the Customer must review the change, update its assessments and Documentation, repeat proportionate acceptance testing, retrain relevant personnel, and obtain a new internal go/no-go approval.

17.4. A material revision to these Special Terms, the stated intended purpose, data-transfer behavior, or allocation of risk may require separate re-acceptance for a later purchase, trial, renewal, activation, or continued use as specified in the applicable notice.

17.5. The Vendor may deploy an urgent correction or disable functionality without advance notice when reasonably necessary to address a vulnerability, Serious Incident, unlawful behavior, third-party outage, or material risk. The Vendor will provide notice when reasonably practicable.

17.6. A change may cause the same Source Data to produce different Plugin Output. Unless expressly stated, updates do not automatically recalculate, correct, or invalidate historical Plugin Output or Customer decisions.

18. No warranty of compliance or fitness for a decision

18.1. THE PLUGIN AND ALL PLUGIN OUTPUT ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE VENDOR DISCLAIMS ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING ACCURACY, COMPLETENESS, NON-INFRINGEMENT, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ERROR-FREE OPERATION, RESULTS, LEGAL COMPLIANCE, AUDIT ACCEPTANCE, DETECTION OF ANY PARTICULAR EVENT, AND FITNESS FOR EMPLOYMENT, INVESTIGATIVE, REGULATORY, FINANCIAL, OR OTHER DECISIONS.

18.2. The Customer has had the opportunity to evaluate the Plugin, its Documentation, trial availability, mappings, and limitations before purchase. Purchase does not create a warranty that the Plugin fits Customer Systems, the Customer's controls framework, risk appetite, jurisdiction, investigation process, or regulatory obligations.

18.3. No statement about a Supported Configuration guarantees uninterrupted compatibility, complete field coverage, a particular result, or continued support after changes by the Customer or a third party.

19. Allocation of responsibility and claims

19.1. To the maximum extent permitted by law, the Customer assumes the risks arising from Source Data, Customer Systems, configuration, infrastructure, legal basis, access decisions, investigations, Human Review, and reliance on or communication of Plugin Output.

19.2. No claim may be based solely on the existence of an error mode, source-system difference, AI-assisted development practice, third-party change, or analytical limitation disclosed in these Special Terms or the Documentation.

19.3. The indemnity and limitation-of-liability provisions in the General Terms apply to the Plugin and these Special Terms. In particular, the Customer will defend, indemnify, and hold the Vendor harmless, to the extent permitted by law, from third-party claims arising from the Customer's unlawful data processing, failure to provide required notices or rights, insecure self-hosted environment, unsupported or incorrect configuration, prohibited use, decisions made without required Human Review, or violation of law or third-party rights.

19.4. Nothing in these Special Terms excludes or limits liability to the extent it cannot lawfully be excluded or limited. No provision purports to excuse fraud or intentional or reckless misconduct.

19.5. Subject to mandatory law, the Vendor's aggregate liability remains limited as stated in the General Terms, and responsibility for the Customer's decisions and their consequences remains with the Customer.

20. Acceptance, authority, and evidence

20.1. The Customer may not start a trial or purchase the Plugin unless an authorized representative separately and affirmatively accepts these Special Terms. Acceptance is not bundled with acceptance of the General Terms.

20.2. The Vendor records the accepting account, Customer tenant, context, time, network address, Special-Terms version, and cryptographic hash of the exact text accepted. The version accepted for a purchase or trial governs that acquisition unless a later version is validly accepted or mandatory law requires otherwise.

20.3. By selecting the separate acceptance checkbox and continuing, the representative confirms that they had the opportunity to open, read, retain, and print these Special Terms before proceeding; understand the limitations, prohibited uses, and Human Review requirement; have authority to bind the Customer; and intend the electronic act to constitute the Customer's signature and agreement.

20.4. The electronic acceptance record establishes the representative's affirmative act, representations, and opportunity to review the recorded version. It does not constitute a Vendor guarantee that the representative actually read or subjectively understood every provision.

21. Term, cessation, and survival

21.1. These Special Terms apply during evaluation, trial, purchase, installation, activation, renewal, and use of the Plugin and continue for as long as the Customer retains or relies on Plugin Output or decision records generated through the Plugin.

21.2. On expiration, revocation, or termination of the applicable license, the Customer must stop using the Plugin as required by the General Terms. The Customer remains responsible for lawful retention, export, restriction, and deletion of its data and records.

21.3. Sections concerning definitions, status of Plugin Output, Customer decisions, Human Review, data protection, affected-person rights, records, incidents, confidentiality, warranties, responsibility, evidence, and governing law survive to the extent necessary to give them effect.

22. Governing law and severability

22.1. These Special Terms are governed by the laws of the State of Wyoming, USA, without regard to conflict-of-laws rules, and the venue provisions in the General Terms apply.

22.2. If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remaining provisions will remain effective. A mandatory legal right or duty prevails only to the extent it cannot lawfully be varied by agreement.

23. Contact

23.1. Silkway Tech LLC — 5830 E 2nd St, Ste 7000 #30294, Casper, WY 82609, USA. Questions: via the support page.