Legal

Terms of Service

Effective August 20, 2026 · Panoverse Inc., a Delaware corporation

Security and compliance

SOC 2 Type IISecurity, availability, confidentiality
ISO/IEC 27001Information security management certified
GDPREU General Data Protection Regulation
CCPA / CPRACalifornia consumer privacy compliance
Panoverse holds a SOC 2 Type II attestation — controls operating continuously against the Trust Services Criteria for security, availability and confidentiality, verified by an independent auditor — and is certified to ISO/IEC 27001 for its information security management system. Data processing complies with the GDPR and the CCPA/CPRA (compliance regimes, neither of which has a certifying body). Reports and certificates are available under NDA through security@panoverse.com, along with our DPA and subprocessor list.

Read-only access, revocable at any time

Every platform connection uses OAuth with read-only scopes. We hold no ability to publish, modify or delete anything in your accounts. You can revoke from the platform side or through us at any time; ingestion stops immediately.

Aggregate by design, no consumer PII

The engine works on aggregate and content-level fields: spend, impressions, views, order counts, inventory, review text. We do not pull or store your end consumers' names, addresses, payment details or identity records.

Brand isolation, never pooled

Each brand's data is processed inside its own logical boundary. Your data is never used to serve another client, never pooled into a cross-client model, and never sold. Detection thresholds calibrate to your own historical distribution — that is both the product design and a consequence of the isolation.

Encrypted in transit and at rest

TLS 1.2 or above in transit, AES-256 at rest. Credentials live in a managed secret store separate from business data, granted on least privilege, with access logged.

Zero retention with model providers

Language models are used for explanation and orchestration only. Our agreements with model providers specify zero retention and no training on your data. Numbers come from deterministic statistical computation, never from a model.

Deletion on request

On termination or on request, we delete or return your data within 30 days and confirm in writing. Backup copies age out on their retention cycle, no longer than 90 days.

1. Acceptance

By accessing panoverse.com or using our services you accept these terms. If you accept on behalf of a company, you represent that you are authorised to bind it.

Where you have signed a separate services agreement or order form with us, that agreement prevails over these terms.

2. The service

Panoverse is a growth data engine for consumer brands: it unifies authorised data into one canonical schema, detects signals, builds evidence chains, delivers actions with an acceptance contract, and grades them when the measurement window closes.

Analytical output is decision support. It is not a guarantee of business results, revenue or return on investment. Whether to act, and how, remains the client's decision and commercial risk.

3. Accounts and authorisation

You warrant that you have the right to authorise our access to the sources you connect, that the information you give is accurate, and that you keep your credentials secure. You may revoke any platform authorisation at any time.

4. Acceptable use

You agree not to:

  • Break applicable law, or the agreements between you and third-party platforms
  • Circumvent technical limits, or reach data that is not yours
  • Reverse engineer the service, or use it to build a competing product
  • Upload personal data you have no right to process — in particular consumer identity or payment records

5. Ownership of data

Your data stays yours. We take no ownership, only a limited licence to process it in order to deliver the service to you. On termination it is deleted or returned as set out in section 6 of the privacy policy.

The service itself — software, detectors, methods and interface — remains ours. We grant you a non-exclusive, non-transferable right to use it during the engagement.

6. Confidentiality

Each party keeps the other's non-public information confidential for as long as it remains confidential. We will not publish your name, data or results without written permission — including not listing you as a public reference or case study.

7. Security

We protect your data with the controls described in the Security and compliance section below. If an incident affects your data we notify you within the timeframe applicable law requires.

8. Fees

Onboarding and the Day-0 audit are free. Usage is billed at the model token cost the engine actually consumed, passed through at par, plus a 20% service fee. Monthly settlement, no minimum spend, stop any time and billing stops with you. The bill itemises down to each investigation.

9. Termination

Either party may terminate on 30 days' written notice. Either may terminate immediately for a material breach left uncured 15 days after notice. On termination, access stops at once and data is handled per the privacy policy.

10. Disclaimers and limitation of liability

To the fullest extent permitted by law the service is provided "as is", without express or implied warranties of merchantability, fitness for a particular purpose or non-infringement.

To the fullest extent permitted by law neither party is liable for indirect, incidental, special or consequential damages, and our aggregate liability is capped at the fees you actually paid us in the twelve months before the claim. Nothing here limits liability for fraud, wilful misconduct, or anything the law does not allow to be limited.

11. Indemnity

You will indemnify us against third-party claims arising from your breach of these terms, your breach of applicable law, or your supplying data you had no right to process.

12. Disputes and governing law

These terms are governed by the laws of the State of Delaware, without regard to conflict-of-laws rules. The parties will negotiate in good faith for 30 days; failing that, disputes go to the courts of competent jurisdiction in Delaware.

13. Changes and contact

We update the effective date when these terms change, and give clients of record notice of material changes. Questions to legal@panoverse.com.

Contact

Legal and terms: legal@panoverse.com
Privacy and data rights: privacy@panoverse.com
Security review and documentation: security@panoverse.com