Our standard Master Services Agreement and Data Processing Agreement, pre-filled with CARTIEAI LLC (a Texas limited liability company). Designed to short-circuit the 4–6 week back-and-forth that most enterprise procurement calls start with. Send this URL to your legal team — they can redline directly and email us back.
Not a substitute for legal review.
These templates reflect our standard terms and are offered as a starting point in good faith. You are encouraged to have your own counsel review them before signing. We're happy to negotiate reasonable redlines — email hello@cartieai.com.
Document 1 of 2
This Master Services Agreement (the "Agreement") is made and entered into as of the date of the last signature below (the "Effective Date") by and between CARTIEAI LLC, a Texas limited liability company with its principal place of business in Texas, United States ("CARTIE AI") and the customer entity signing below ("Customer").
CARTIE AI will provide Customer with access to its AI-native cloud financial intelligence platform and related services (the "Services"), as further described atcartieai.com and in any mutually agreed Order Form or Statement of Work. The Services are subject to our publicly posted Terms of Service, which are incorporated by reference. In case of conflict between this Agreement and the public Terms, this Agreement controls for the Customer.
Each party agrees to protect the other party's Confidential Information with at least the same degree of care it uses for its own confidential information of like importance, and never less than reasonable care. Confidential Information does not include information that is publicly available, independently developed, or rightfully received from a third party without restriction.
Customer retains ownership of all data it provides to or generates through the Services ("Customer Data"). Customer grants CARTIE AI a limited, non-exclusive, worldwide license to host, process, and display Customer Data solely to provide the Services. CARTIE AI will not use Customer Data to train AI models for the benefit of other customers. Aggregated, de-identified statistics may be used to improve the Services.
CARTIE AI will maintain administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Customer Data, as described in our Privacy Policy and the Data Processing Agreement below. Current safeguards include AES-256 encryption at rest, TLS 1.3 in transit, bcrypt password hashing, RBAC, audit logging, and 35-day encrypted backups. Formal SOC 2 Type II audit is targeted for Q2 2026.
CARTIE AI warrants that the Services will perform materially as described in our public documentation and the applicable Order Form. EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES ARE PROVIDED "AS IS" AND CARTIE AI DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
CARTIE AI will defend Customer against any third-party claim that the Services infringe a U.S. patent, copyright, or trade secret, and will indemnify Customer for damages finally awarded, provided Customer promptly notifies CARTIE AI in writing and allows CARTIE AI sole control of the defense. Customer will similarly defend CARTIE AI against claims arising from Customer Data or Customer's use of the Services in violation of this Agreement.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS OR REVENUES. Each party's aggregate liability under this Agreement will not exceed the fees paid or payable by Customer in the 12 months preceding the claim. The foregoing limitations do not apply to (a) breaches of confidentiality, (b) indemnification obligations, or (c) Customer's payment obligations.
This Agreement is governed by the laws of the State of Texas, United States, without regard to conflict-of-law rules. The state and federal courts located in Travis County, Texas have exclusive jurisdiction over any dispute, except that either party may seek injunctive relief in any court of competent jurisdiction. Parties agree to attempt good-faith resolution within 30 days before initiating litigation.
CARTIEAI LLC
By: Lakshmi Kiranmai Guduru
Founder & Manager
Signature & date
CUSTOMER
By:
Title:
Signature & date
Document 2 of 2
This Data Processing Agreement (the "DPA") supplements the Master Services Agreement above between CARTIEAI LLC (the "Processor") and the Customer (the "Controller"). It applies to all Personal Data (as defined by the EU General Data Protection Regulation 2016/679 and the California Consumer Privacy Act, collectively "Applicable Data Protection Laws") that Processor processes on Controller's behalf.
Processor will process Personal Data only for the duration of the underlying MSA and only as necessary to provide the Services. Categories of data subjects: Controller's employees, contractors, and end-users to the extent reflected in cloud cost and usage telemetry.
Processor will process Personal Data solely to (a) provide the Services, (b) detect and prevent fraud or abuse, (c) comply with legal obligations, and (d) generate aggregated, de-identified statistics.
Controller authorises Processor to engage subprocessors listed at cartieai.com/subprocessors (current vendors include AWS, Stripe, Resend, MongoDB Atlas, Anthropic, OpenAI). Processor will notify Controller at least 14 days before engaging any new subprocessor and will impose contractual data-protection obligations no less stringent than those in this DPA.
Processor's primary data hosting is in the United States (MongoDB Atlas, US-East region). For Personal Data originating in the EU/UK, the parties incorporate the EU Standard Contractual Clauses (Module 2: controller-to-processor) by reference. Processor will assist Controller with any transfer-impact assessment.
Processor will, on reasonable notice and no more than once per 12-month period, make available to Controller (or its independent auditor under NDA) the information necessary to demonstrate compliance with this DPA, including the most recent SOC 2 report once available. Audits will be conducted during business hours and will not unreasonably interfere with Processor's operations.
Processor will provide reasonable assistance, including by appropriate technical and organisational measures, to enable Controller to respond to requests from data subjects exercising rights under Applicable Data Protection Laws (access, rectification, erasure, portability, restriction, objection). Requests received directly by Processor will be forwarded to Controller within 5 business days.
Liability under this DPA is governed by Section 9 (Limitation of Liability) of the MSA. Each party indemnifies the other for fines or damages arising from its own breach of Applicable Data Protection Laws.
This DPA is governed by the laws of the State of Texas, United States. Where Applicable Data Protection Laws require, mandatory provisions of those laws prevail.
PROCESSOR — CARTIEAI LLC
By: Lakshmi Kiranmai Guduru
Founder & Manager · Data Protection Lead
Signature & date
CONTROLLER
By:
Title:
Signature & date
Send this URL to your legal team. They can paste redlines directly into an email reply and we'll turn around v2 within 2 business days. Or hop on a 30-min call with the founder to walk through any concerns — most enterprise deals close in under a week.
Fill this once. We'll send back a counter-signed PDF within 1 business day.
Every change to this MSA + DPA is logged here. Public, timestamped, append-only.
| Version | Date | Type |
|---|---|---|
| v1.0 | June 6, 2026 | Initial release |
We don't silently rewrite our standard terms. Every customer on a previous version keeps their original agreement until they explicitly renew under a newer version. Amendments = 0.