Legal
Legal templates
Last updated: 14 May 2026
Outlines of our standard legal templates. The full executable versions ship via email — email legal@aliansoftware.net with your jurisdiction and we'll send the right variant.
DPA (Data Processing Agreement)
Required under GDPR, India's DPDP Act, and most enterprise procurement processes. We have a template ready or we redline yours.
# Data Processing Agreement · template structure ## 1 · Parties Client (Controller) · Alian Software Pvt Ltd · Alian AI division (Processor) ## 2 · Subject matter Processing of personal data necessary for the AI engagement defined in the underlying SOW. Scope, duration, and nature of processing detailed in Appendix A. ## 3 · Roles + responsibilities Client = Data Controller (determines purposes + means). Vendor = Data Processor (acts on documented instructions). ## 4 · Categories of data - [Categories per engagement: name, email, company, problem statement, etc.] - Sensitive categories require Appendix B sign-off (PHI, financial, biometric). ## 5 · Data subject rights Vendor will assist Client in responding to access, rectification, erasure, restriction, and portability requests within 5 business days of request. ## 6 · Security measures - Encryption in transit (TLS 1.2+) and at rest (AES-256) - Access controls per the principle of least privilege - SOC 2 in progress; current control list available on request - Annual penetration testing - Incident response plan with 24-hour notification SLA ## 7 · Sub-processors Anthropic · OpenAI · Vercel · Supabase / Neon · Resend (Current list maintained at /legal/subprocessors) Each sub-processor bound by its own DPA. New sub-processors require 30 days prior written notice to Client. ## 8 · International data transfers SCCs (Standard Contractual Clauses) attached as Appendix C for any EU → non-EU transfer. India DPDP-compliant transfer mechanisms also documented. ## 9 · Audit rights Client may audit Vendor's compliance with this DPA once per calendar year on 30 days notice, at Client's expense. Vendor will also provide its own audit reports (SOC 2 Type II when available). ## 10 · Breach notification Notification within 24 hours of confirmed material breach. Details required per GDPR Article 33 / DPDP equivalents. ## 11 · Data deletion Personal data deleted or returned within 30 days of engagement close, unless retention required by law. ## 12 · Liability Per the underlying MSA. Standard carve-outs for fraud and gross negligence. --- For the full executable version (40+ pages, redlined for various jurisdictions), email legal@aliansoftware.net.
MSA (Master Service Agreement)
Governs the overall engagement. Individual SOWs (see /sample-sows) incorporate this MSA by reference.
# Master Service Agreement · template structure ## 1 · Parties + effective date Client · Alian Software Pvt Ltd · effective [DATE] ## 2 · Definition of services Vendor provides AI consulting, design, development, deployment, and support services. Specific engagements scoped via individual SOWs that incorporate this MSA by reference. ## 3 · Engagement structure SOWs may use one of three pricing models: - Fixed-fee Sprint - Monthly Retainer - Hourly / Time-and-Materials Each SOW specifies model, scope, deliverables, acceptance criteria, timeline, and fees. ## 4 · IP ownership **Vendor work product (code, prompts, configurations, agent definitions, eval suite, documentation):** assigned to Client upon final payment of the relevant SOW. **Vendor's pre-existing IP** (frameworks, templates, methodology): Vendor retains ownership; Client receives a non-exclusive, royalty-free, perpetual license to use as needed for the engagement output. **Client's pre-existing IP** (data, brand assets, existing code): Client retains ownership; Vendor receives a limited license to use solely for performance of the engagement. ## 5 · Confidentiality Mutual confidentiality. Each party protects the other's confidential info with the same care it uses for its own (not less than reasonable care). Survives termination by 5 years. ## 6 · Warranties Vendor warrants services will be performed in a professional and workmanlike manner consistent with industry standards. Code deliverables materially conform to Specifications for 30 days post acceptance. DISCLAIMER OF IMPLIED WARRANTIES per standard commercial-software practice. ## 7 · Limitation of liability Each party's aggregate liability under this MSA + all SOWs combined is capped at the total fees paid in the 12 months preceding the claim. Standard carve-outs for indemnity obligations, breach of confidentiality, fraud, and gross negligence. ## 8 · Indemnification Vendor indemnifies Client against third-party IP infringement claims arising from the work product. Standard exclusions for Client-modified code or use outside the SOW. ## 9 · Term + termination Term: while any SOW is active. Either party may terminate for material breach with 30 days written notice + cure period. Vendor entitled to payment for work performed up to termination date. ## 10 · Governing law + jurisdiction Maharashtra, India. Disputes resolved by the courts of Pune. International clients may negotiate a US-state or English-law variant on request. ## 11 · Sub-processors Vendor may engage sub-processors (Anthropic, infrastructure providers) under DPA. Current list maintained at /legal/subprocessors. ## 12 · General Notices, assignment, force majeure, severability, entire agreement, counterparts, electronic signatures — standard commercial terms. --- Full executable version (typically 25 pages) ships via email. Email legal@aliansoftware.net with your jurisdiction and we'll send the right variant.
Mutual NDA
Standard mutual NDA for pre-engagement conversations. We sign yours or you sign ours. Either way, fast.
# Mutual NDA · template structure ## Parties Disclosing + Receiving parties (mutual — both directions covered). ## Definition of confidential information - Business strategy, technical roadmap, customer lists - Proprietary code, algorithms, model prompts, eval suites - Personal data shared during engagement scoping - Anything marked confidential or that a reasonable person would treat as such ## Excluded - Publicly available information - Independently developed - Received from a third party without restriction - Already known to the receiving party before disclosure ## Obligations Each party will protect the other's confidential info with the same care used for its own. No disclosure to third parties without written consent. Use limited to evaluation of potential / actual business relationship. ## Term 3 years from effective date, or 5 years for trade secrets. ## Standard provisions Return of materials on request, no warranty, no transfer of IP rights, remedies (injunctive relief recognized), governing law (Maharashtra, India), jurisdiction (Pune). --- Mutual NDA template runs 4 pages. Email legal@aliansoftware.net and we'll send the current version. We can also countersign yours if your legal team prefers — typical turnaround 1–2 business days.
SCCs (Standard Contractual Clauses)
Included in our DPA as Appendix C. Required for EU↔non-EU personal data transfers under GDPR. We use the 2021 EU SCCs in the Controller-to-Processor configuration.
For UK transfers, the UK Addendum is also included. India DPDP- compliant transfer mechanisms documented separately.
Sub-processors
Our current sub-processor list — bound by their own DPAs and referenced in ours:
- Anthropic (model inference, US + EU regions)
- OpenAI (model inference, fallback)
- Vercel (frontend hosting)
- Supabase / Neon (managed Postgres)
- Resend (transactional email)
- Langfuse (observability — self-hostable in client engagements)
New sub-processors require 30 days prior written notice to clients under signed DPA.
Getting paperwork done
For most engagements, signed paperwork is complete within 5–10 business days end-to-end. Faster if you accept our templates unchanged; slower if your legal team needs heavy redlines (which we welcome — it's their job).
Email legal@aliansoftware.net with your jurisdiction, engagement type, and any specific clauses you need addressed. We'll come back within a business day with the full executable templates.