XPLORO AI ADDENDUM
This Xploro AI Addendum (“AI Addendum”) forms part of the Master Service Agreement (“MSA”) between XploroTech Solutions Private Limited (“XploroTech”, “Company”, “we”, “us”, or “our”) and the Customer.
This AI Addendum applies where Xploro AI or any artificial intelligence, machine learning, natural language processing, analytics, recommendation, report-generation, support, knowledge-base, code-analysis, bug-analysis, troubleshooting, automation, or related feature is enabled or used through VENTA Xploro POS, VENTA Admin, VENTA Insights, VENTA Captain, related APIs, dashboards, integrations, or future VENTA-branded services (collectively, the “AI Services”).
Capitalised terms not defined in this AI Addendum have the meanings given in the MSA.
For AI-specific use, governance, restrictions, and operational controls, this AI Addendum prevails over the MSA and VENTA User Terms. For the processing of Customer Personal Data, the Data Processing Addendum remains applicable.
1. Purpose and Scope
1.1 Xploro AI is designed to assist authorised users with permitted business activities, including:
a. business data analytics and reporting;
b. natural-language report queries;
c. sales, inventory, purchase, production, reservation, membership, loyalty, customer, and operational insights;
d. help articles, training guidance, and product-support information;
e. issue analysis, troubleshooting, bug analysis, log analysis, and diagnostic support;
f. code, database schema, configuration, SQL, workflow, and integration analysis;
g. suggestions for bug fixes, reports, dashboards, configurations, workflows, and operational improvements; and
h. other AI-enabled functions made available by XploroTech.
1.2 AI Services may be made available as part of a subscription plan, add-on, trial, pilot, beta programme, or separately enabled feature.
1.3 XploroTech may change, improve, limit, suspend, replace, or discontinue an AI feature, AI model, provider, capability, rate limit, usage limit, or workflow where reasonably necessary for security, reliability, legal compliance, data protection, cost control, product improvement, or operational reasons.
2. Definitions
For this AI Addendum:
“AI Input” means a prompt, question, instruction, request, query, report request, file, attachment, code fragment, schema detail, log, diagnostic record, dataset, or other information submitted to or made available to an AI Service.
“AI Output” means any answer, summary, report, chart, recommendation, forecast, insight, classification, SQL, code suggestion, workflow suggestion, troubleshooting guidance, help content, analysis, or other response generated by an AI Service.
“AI Provider” means XploroTech, an XploroTech-hosted model, or an approved third-party artificial-intelligence, machine-learning, cloud, inference, analytics, vector-search, safety, monitoring, or related service provider used to provide AI Services.
“Approved AI Provider” means an AI Provider listed in the AI Subprocessors & Data Use Notice or otherwise approved by XploroTech for the relevant AI Service.
“Customer Data” has the meaning given in the MSA and includes AI Inputs and AI Outputs to the extent they relate to the Customer.
3. Authorised Use of AI Services
3.1 The Customer may use AI Services only for legitimate, lawful, authorised business purposes and only within the permissions, plan limits, usage limits, and features made available by XploroTech.
3.2 The Customer is responsible for ensuring that each Authorised User is properly trained and permitted to use the relevant AI Service.
3.3 XploroTech may apply role-based access controls, tenant boundaries, data-access limitations, rate limits, context limits, usage limits, feature restrictions, and safety controls to AI Services.
3.4 AI Services are intended to access only the data that the requesting Authorised User is permitted to access through the relevant VENTA application, module, company, outlet, role, and assigned permissions.
3.5 The Customer must promptly report any suspected unauthorised AI access, unexpected AI disclosure, incorrect data scope, prompt injection attempt, security issue, or AI-related misuse to XploroTech.
4. Customer Responsibility for AI Inputs
4.1 The Customer is responsible for all AI Inputs submitted by its Authorised Users, systems, integrations, devices, and accounts.
4.2 The Customer represents and warrants that it has all necessary rights, permissions, notices, consents, lawful bases, and authority to submit AI Inputs and permit their processing through the AI Services.
4.3 The Customer must ensure that AI Inputs are relevant, accurate, lawful, and limited to what is reasonably necessary for the authorised purpose.
4.4 The Customer must not submit or permit submission of:
a. passwords, OTPs, PINs, access tokens, API keys, private keys, secrets, authentication credentials, or security codes;
b. full payment-card numbers, CVV, magnetic-stripe data, card verification information, or sensitive payment-authentication data;
c. malware, ransomware, spyware, phishing tools, malicious scripts, harmful files, exploit code, or unauthorised security-testing content;
d. Personal Data, confidential information, source code, customer information, business data, or third-party information that the Customer is not authorised to disclose;
e. unlawful, defamatory, discriminatory, abusive, deceptive, infringing, exploitative, or fraudulent content; or
f. information that is prohibited from being processed under applicable law, contract, regulatory requirement, or Customer policy.
4.5 Where reasonably possible, the Customer should remove, redact, anonymise, pseudonymise, aggregate, or minimise Personal Data and confidential information before submitting AI Inputs.
5. AI Outputs and Human Review
5.1 AI Outputs are generated using probabilistic systems and may be inaccurate, incomplete, inconsistent, outdated, biased, misleading, non-unique, or unsuitable for a particular purpose.
5.2 The Customer and its Authorised Users must independently review, validate, test, and approve AI Outputs before relying on, sharing, filing, publishing, implementing, deploying, or acting upon them.
5.3 AI Outputs must not be treated as tax, legal, accounting, financial, investment, employment, regulatory, medical, security, or other professional advice.
5.4 The Customer remains solely responsible for all business decisions, tax decisions, statutory filings, regulatory actions, reports, invoices, communications, code deployments, database changes, configurations, workflows, and actions taken in reliance on AI Outputs.
5.5 XploroTech does not guarantee that AI Outputs will be accurate, complete, lawful, non-infringing, current, unique, suitable, available, or fit for a particular purpose.
5.6 The Customer must not represent an AI Output as independently verified, professionally certified, legally compliant, or approved by XploroTech unless XploroTech has expressly confirmed this in writing.
6. AI Data Processing and Model Use
6.1 AI Services may process AI Inputs, relevant Customer Data, selected reports, transaction summaries, schemas, metadata, logs, diagnostic records, code fragments, support information, and AI Outputs through:
a. XploroTech-hosted models and infrastructure;
b. Approved AI Providers;
c. approved cloud, hosting, vector-search, monitoring, analytics, safety, support, and security providers; and
d. other approved Subprocessors identified in the AI Subprocessors & Data Use Notice.
6.2 XploroTech may use different Approved AI Providers, models, model versions, routing methods, retrieval systems, safety systems, and processing approaches for different AI features or requests.
6.3 XploroTech may process AI Inputs and AI Outputs for the following purposes:
a. providing the requested AI Service;
b. maintaining context during an authorised AI interaction;
c. quality assurance, safety monitoring, abuse prevention, fraud prevention, and security monitoring;
d. troubleshooting, support, debugging, and incident response;
e. improving the reliability, performance, accuracy, safety, and functionality of Xploro AI; and
f. complying with applicable law, lawful authority requests, court orders, contractual obligations, and regulatory requirements.
6.4 XploroTech may retain AI Inputs, AI Outputs, usage records, routing records, safety records, logs, diagnostic information, and audit information in accordance with the Privacy Notice, Data Processing Addendum, AI Subprocessors & Data Use Notice, and Data Retention & Customer Exit Policy.
6.5 XploroTech may use aggregated and de-identified information that does not reasonably identify the Customer or an individual for security, analytics, benchmarking, capacity planning, quality assurance, product improvement, and research.
6.6 AI Providers may have their own operational, security, abuse-monitoring, retention, and legal-compliance requirements. Relevant provider categories and processing information are described in the AI Subprocessors & Data Use Notice.
6.7 Except where the Customer expressly opts in through a written agreement or explicitly enabled product setting, XploroTech will not use Customer Data, AI Inputs, AI Outputs, source code, schemas, support logs, or other Customer-specific information to train a general-purpose AI model.
7. AI-Generated Code, SQL, Configuration and Bug Fixes
7.1 AI Services may analyse errors, logs, code, schemas, configurations, workflows, database structures, APIs, and related technical information to identify possible causes of issues and suggest potential fixes.
7.2 AI-generated code, SQL, database scripts, configuration changes, workflow changes, integration changes, or bug-fix suggestions are recommendations only unless a specific feature expressly states otherwise.
7.3 The Customer must ensure that all AI-generated technical suggestions are:
a. reviewed by a suitably qualified and authorised person;
b. tested in a safe environment where reasonably practical;
c. assessed for security, data integrity, access control, compatibility, performance, tax, statutory, and operational impact;
d. approved through the Customer’s required change-management process;
e. deployed only by an authorised person or approved automated workflow;
f. logged and auditable; and
g. capable of rollback or remediation where reasonably practical.
7.4 AI Services must not independently alter statutory invoices, GST records, payment records, financial ledgers, membership balances, loyalty balances, inventory balances, transaction history, or other controlled business records without explicit authorised user action through an approved and auditable workflow.
7.5 The Customer remains responsible for maintaining appropriate backups, testing, change-control, approval, rollback, and business-continuity processes before implementing AI-generated technical changes.
8. Restricted AI Uses
The Customer and its Authorised Users must not use AI Services to:
a. evade GST, suppress revenue, conceal statutory records, create fraudulent invoices, generate false reports, manipulate financial or transaction data, or misrepresent business activity;
b. access, infer, reveal, summarise, extract, or attempt to obtain data that the user is not authorised to access;
c. bypass role permissions, tenant boundaries, access controls, audit logs, security safeguards, subscription limits, or system restrictions;
d. conduct prompt injection, jailbreak attempts, model manipulation, instruction override, system-prompt extraction, data exfiltration, privilege escalation, or attempts to defeat AI safety controls;
e. generate, distribute, request, deploy, or facilitate malware, ransomware, phishing, credential theft, harmful code, exploit code, unauthorised security testing, or cyberattack activity;
f. generate false evidence, deceptive communications, impersonation content, fraudulent records, unlawful marketing, misleading customer communications, or misinformation;
g. discriminate unlawfully, harass, defame, threaten, abuse, exploit, or harm any person;
h. submit information that is unlawful, confidential, restricted, or outside the Customer’s authority to share;
i. use AI Outputs as the sole basis for high-impact financial, employment, legal, tax, regulatory, safety, or customer-rights decisions; or
j. use AI Services in any manner that violates the MSA, Data Processing Addendum, Acceptable Use Policy, VENTA User Terms, applicable law, or third-party provider terms.
9. Intellectual Property and AI Outputs
9.1 XploroTech and its licensors retain all rights, title, and interest in the AI Services, software, models, prompts, system instructions, interfaces, workflows, retrieval systems, safety mechanisms, Documentation, and related technology.
9.2 As between XploroTech and the Customer, the Customer retains rights in its Customer Data, subject to the rights granted under the MSA and this AI Addendum.
9.3 Subject to the MSA, this AI Addendum, and applicable third-party provider terms, the Customer may use AI Outputs generated from its authorised use of AI Services for its internal business purposes.
9.4 AI Outputs may be similar or identical to outputs generated for other users or customers. XploroTech does not represent that AI Outputs are exclusive, unique, protectable, non-infringing, or available for intellectual-property registration.
9.5 The Customer is responsible for determining whether an AI Output is appropriate, lawful, accurate, original, non-infringing, and suitable for its intended use.
10. Availability, Changes and Third-Party AI Providers
10.1 AI Services may depend on XploroTech infrastructure, internet connectivity, Customer Data availability, prompt quality, system capacity, Approved AI Providers, and third-party services.
10.2 AI Services are provided on an “as available” basis unless an applicable Order Form expressly states otherwise.
10.3 XploroTech may impose fair-use limits, request limits, rate limits, token limits, feature limits, data-size limits, storage limits, or other reasonable controls.
10.4 XploroTech may change or replace an Approved AI Provider, model, model version, routing method, data-processing method, or AI feature, provided that XploroTech will use reasonable efforts to maintain materially similar core AI functionality during an active paid Subscription Term.
10.5 XploroTech is not responsible for interruptions, reduced performance, model changes, output changes, outages, limitations, pricing changes, policy changes, or discontinuation by third-party AI Providers, except to the extent directly caused by XploroTech’s breach of the MSA.
11. Suspension and Enforcement
11.1 XploroTech may limit, suspend, disable, or terminate AI Services, AI access, features, usage, prompts, users, integrations, or accounts where reasonably necessary due to:
a. suspected fraud, misuse, unlawful activity, or policy breach;
b. security risk, data-protection risk, prompt injection, malware, or attempted unauthorised access;
c. excessive, abusive, disruptive, or unauthorised usage;
d. risk to XploroTech, the Customer, other customers, AI Providers, or third parties;
e. legal, regulatory, contractual, or lawful-authority requirements;
f. failure to pay applicable fees; or
g. operational, capacity, quality, safety, or service-stability reasons.
11.2 XploroTech may preserve relevant AI Inputs, AI Outputs, logs, audit records, technical records, and evidence where reasonably necessary for security, investigation, legal compliance, fraud prevention, dispute resolution, or enforcement.
11.3 Suspension or restriction of AI Services does not automatically suspend or terminate the Customer’s access to non-AI VENTA Services.
12. Liability and Disclaimer
12.1 The warranty disclaimers, liability limitations, indemnities, and exclusions in the MSA apply to AI Services and this AI Addendum.
12.2 Nothing in this AI Addendum expands XploroTech’s liability beyond the limits stated in the MSA.
12.3 XploroTech shall not be responsible for losses, damages, penalties, claims, decisions, actions, omissions, deployments, filings, communications, code changes, database changes, or business outcomes arising from:
a. Customer reliance on an AI Output without appropriate review;
b. inaccurate, incomplete, outdated, biased, misleading, or unsuitable AI Outputs;
c. Customer Data, AI Inputs, prompts, instructions, or information supplied by the Customer;
d. Customer implementation of AI-generated code, SQL, configuration, reports, workflows, or recommendations;
e. actions of third-party AI Providers or third-party services; or
f. unauthorised or prohibited use of AI Services.
13. Changes to This AI Addendum
13.1 XploroTech may update this AI Addendum from time to time to reflect changes in law, regulations, AI technology, models, providers, safety practices, security practices, Services, or business operations.
13.2 XploroTech will publish the updated version in the VENTA Legal Centre and update the version number and effective date.
13.3 For material changes, XploroTech may provide notice through the Services, dashboard, email, website, app notification, or another reasonable electronic method.
13.4 Continued use of AI Services after the effective date of an updated AI Addendum constitutes acceptance, except where express re-acceptance is required by applicable law or XploroTech.
14. Contact
For questions, concerns, misuse reports, security reports, privacy matters, or AI-related issues, contact:
AI Support: xploro@xplorotech.com
Security Incident Reporting: xploro@xplorotech.com
Privacy / Grievance Contact: xploro@xplorotech.com
Legal Notices: xploro@xplorotech.com
AI Subprocessors & Data Use Notice: https://venta-pos.com/ai-subprocessors-and-data-use/
VENTA Legal Centre: https://www.venta-pos.com/legal





