Legal

Terms of service

40° South AI Pty Ltd (ABN pending)

Effective date: March 2026

1. Agreement

These terms of service ("Terms") form a binding agreement between you ("Customer," "you") and 40° South AI Pty Ltd, a company registered in New South Wales, Australia ("40 South," "we," "us," "our"). By accessing or using the 40 South Guard platform ("Guard," "the Service"), you agree to these Terms. If you are agreeing on behalf of an organisation, you represent that you have authority to bind that organisation.

2. The service

40 South Guard is AI compliance middleware. Guard sits between your business and your AI providers, monitoring AI interactions against Australian regulatory frameworks, detecting personal information and prompt injection, generating cryptographically signed attestations, and maintaining a tamper-evident audit trail.

Guard does not replace your AI providers. It does not provide AI models, generate AI responses, or make decisions on your behalf. Guard monitors, logs, and attests.

3. Account and access

Account creation. To use Guard, your organisation must create an account. The person who creates the account is the initial administrator. Administrators can invite additional users and assign roles (such as CISO, auditor, or engineer).

Access credentials. You are responsible for keeping your login credentials and Guard API keys secure. Do not share API keys outside your organisation. Notify us at security@40south.au immediately if you believe your credentials have been compromised.

Authorised use. You may only use Guard for lawful business purposes consistent with these Terms. You may not use Guard to process data on behalf of third parties without our written agreement.

4. Subscription and payment

Pricing. Guard is available at $5,500 per month (AUD), billed monthly. This includes all compliance features, PII detection, prompt injection detection, attestation signing, audit trail storage (7 years), and standard support.

Pilot. We offer a 60-day pilot at a flat fee of $4,500 (AUD). The pilot includes full Guard functionality on one team or use case, integration support, policy setup, and a compliance gap report. No obligation to continue.

Payment terms. Invoices are issued monthly in advance. Payment is due within 14 days of the invoice date. All amounts are in Australian dollars and are exclusive of GST unless stated otherwise.

No lock-in. Either party may terminate the subscription at the end of any billing period with 30 days' written notice. There are no early termination fees.

Price changes. We will give you at least 60 days' written notice of any price increase. The new price takes effect at the start of the next billing period after the notice period.

5. Data handling

Your data is yours. All data processed through Guard belongs to you. We do not own, license, or claim any rights over your data.

Data location. All data is processed and stored in Australia (Google Cloud Sydney, australia-southeast1, with failover to australia-southeast2). Data never leaves Australian borders.

Data processing. We process your data solely to provide the Guard service. We do not use your data to train AI models. We do not sell your data.

Audit trail. Guard maintains a tamper-evident audit trail of all AI interactions. Evidence records are retained for 7 years, cryptographically signed and immutable once written.

PII handling. When Guard detects personal information, it records the detection (type, location, confidence) in the attestation. Raw PII is scrubbed from evidence records before storage.

6. Data export and portability

During your subscription. You can export your compliance data, attestations, and audit trail at any time through the Guard dashboard or API. Export formats include JSON and PDF.

On termination. After your subscription ends, you have 90 days to export your data. After 90 days, we will delete your account data and configuration. Audit trail records within the 7-year retention period remain accessible on request.

7. Service levels

Uptime. We target 99.9% uptime for the Guard proxy and API services, measured monthly. Scheduled maintenance windows are excluded.

Support. Standard support is included. We respond to enquiries within one business day. Critical issues (service outage, data breach) are escalated immediately.

Incident notification. If we become aware of a security incident that affects your data, we will notify you within 72 hours and provide ongoing updates until the incident is resolved.

8. What Guard does and does not do

Guard monitors AI interactions, detects Australian PII, detects prompt injection, generates cryptographically signed attestations, maintains a 7-year audit trail, and provides compliance reporting with APRA-ready evidence export.

Guard does not provide legal advice, guarantee regulatory compliance (it provides evidence and controls; compliance is your organisation's responsibility), replace your compliance team or auditors, make automated decisions on your behalf, or provide AI models or generate AI responses.

Guard is a tool that supports your compliance efforts. It does not substitute for professional legal or compliance advice.

9. Your obligations

You agree to provide accurate account information, keep your credentials and API keys secure, comply with all applicable Australian laws, not attempt to circumvent Guard's security features, not reverse engineer or decompile Guard, not process data you do not have lawful authority to process, and notify us promptly of any suspected security incident.

10. Intellectual property

Our IP. Guard, including its software, documentation, algorithms, and brand, is owned by 40° South AI Pty Ltd. These Terms do not transfer any intellectual property rights to you.

Your data. You retain all rights in your data. We do not acquire any intellectual property rights in your data by processing it through Guard.

11. Liability

To the maximum extent permitted by Australian Consumer Law, we are not liable for any indirect, incidental, consequential, or special damages arising from your use of Guard, including lost profits, lost data, or business interruption.

Our total aggregate liability for any claims arising from these Terms or the Service is limited to the fees you paid in the 12 months preceding the claim.

Nothing in these Terms excludes or limits any rights you have under the Australian Consumer Law that cannot be excluded or limited by contract.

12. Termination

By you. Cancel at any time with 30 days' written notice. Access continues until the end of the current billing period.

By us. We may suspend or terminate access if you breach these Terms and fail to remedy within 14 days of notice. We may also terminate immediately if required by law or if your use poses a security risk to other customers.

Effect. On termination, access is revoked. You have 90 days to export data. Audit trail records within the 7-year retention window remain accessible on request.

13. Changes to these terms

We may update these Terms from time to time. We will give you at least 30 days' written notice of material changes. If you do not agree, you may terminate your subscription before the changes take effect.

14. Governing law

These Terms are governed by the laws of New South Wales, Australia. The parties submit to the non-exclusive jurisdiction of the courts of New South Wales.

15. Contact

Legal enquiries: legal@40south.au

General enquiries: hello@40south.au

40° South AI Pty Ltd, New South Wales, Australia

40° South acknowledges the Traditional Custodians of the lands on which we work and live. We pay our respects to Elders past, present, and emerging, and recognise their continuing connection to land, waters, and culture.