Terms of Service

Codeora Vision (SMC-Private) Limited

Effective date: 29 August 2026 · Last updated: 29 August 2026


 

1. About these terms

These terms govern your use of codeoravision.com and, where you engage us, the services we provide. "We" and "us" means Codeora Vision (SMC-Private) Limited, Incorporation Number 0287521, registered at Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan. "You" means the person or organisation using the website or engaging us.

By using the website you accept these terms. If you do not accept them, do not use the website.


 

2. Business use only

We provide services to businesses. By engaging us you confirm you are acting for a business, that you are at least 18 years old, and that you have authority to bind the organisation you represent. Consumer protection rules that apply to individuals buying for personal use do not apply to this relationship.


 

3. What the website is

The website describes what we do. It is marketing material, not an offer capable of acceptance. Nothing on it forms a contract.

Pricing shown on the website is indicative and describes where builds typically start. Your actual price comes from a written scope following an architecture review. Timeframes shown are typical ranges, not commitments.

Performance figures and case outcomes shown on the website describe single anonymised engagements or published third-party benchmarks. They are not predictions of your result and are not guarantees. Where a figure is a modelled scenario based on industry data rather than a client outcome, we label it as such.


 

4. How an engagement works

4.1 Scoping

Engagements begin with an architecture review, usually 30 minutes, under mutual confidentiality. We then issue a written scope setting out deliverables, integrations, assumptions, timeline, price, and payment schedule.

4.2 The contract

A binding contract is formed when you accept a written scope, or when you pay the first invoice against it, whichever is earlier. Where an engagement is contracted through Upwork Direct Contracts, the contract terms you accept on that platform apply alongside these terms.

4.3 Order of precedence

If there is a conflict between documents, the following order applies, highest first:

  1. Any signed master services agreement between us
  2. Any Business Associate Agreement, where one applies
  3. The Data Processing Terms in Schedule 1
  4. The accepted written scope
  5. These terms

4.4 Changes to scope

Work outside an accepted scope is a change. We will tell you the cost and timeline impact in writing before starting it. Neither party is obliged to accept a change.


 

5. What we will do

We will perform the services with reasonable skill and care, using suitably qualified people, in line with the accepted scope. We will keep you informed of material issues, delays, or risks as they arise rather than at the end.

Every production build includes automated evaluation before launch, a defined human escalation path for cases the system cannot handle confidently, and a 90-day calibration window after go-live during which we tune the system against real traffic.


 

6. What you need to do

Delivery depends on you as much as on us. You agree to:

  • Give us timely access to the systems, accounts, documents, and people the scope requires
  • Provide accurate information about your workflows, protocols, and escalation rules
  • Nominate someone with authority to make decisions and sign off deliverables
  • Maintain your own accounts and licences for third-party platforms we integrate with
  • Review and approve system behaviour, scripts, and prompts before go-live

Where a delay is caused by your side, timelines shift accordingly and we are not liable for the consequences of that delay.


7. Compliance is shared, and some of it is yours

We design systems to be compliant with the regulatory framework identified in the scope. But you control how the system is used, who it contacts, and what data goes into it. Some obligations sit with you and cannot be transferred to us.

7.1 Calls, messages, and consent

Where a system places or receives calls or sends messages, you are responsible for having a lawful basis and any consent required for that contact, including under:

  • United States — the Telephone Consumer Protection Act, the National Do Not Call Registry, state do-not-call and call-recording consent laws (including two-party consent states), and CAN-SPAM
  • Canada — CASL and the National Do Not Call List
  • Australia — the Spam Act 2003, the Do Not Call Register Act 2006, and state call-recording laws
  • United Arab Emirates — applicable TDRA rules on unsolicited commercial communications

You are responsible for maintaining suppression and do-not-call lists and for supplying them to us.

7.2 Health information

Where an engagement involves protected health information, a Business Associate Agreement is put in place during scoping and executed before any such information is handled. You remain the covered entity and retain responsibility for your own HIPAA obligations, including your notice of privacy practices and your patients' rights.

7.3 Legal and regulated professions

Where an engagement supports a law firm, you remain responsible for compliance with your bar's rules, including on the unauthorised practice of law, conflicts of interest, client confidentiality, and advertising. No system we build gives legal advice, and no system we build establishes an attorney-client relationship.

7.4 Data you give us

You confirm you have the right to give us any data you provide or make accessible, and that doing so does not breach any law or any obligation you owe to a third party.


 

8. Fees and payment

  • Fees are as set out in the accepted scope.
  • Unless the scope says otherwise, 50% of the build fee is payable before work starts and the balance on delivery.
  • Monthly support fees are billed monthly in advance.
  • We will give you at least 30 days' written notice before changing recurring support fees. You may cancel support within that notice period if you do not accept the change.
  • All fees are in US dollars unless stated otherwise, and are exclusive of taxes, duties, and withholding. Where you are required to withhold tax, the amount payable to us is grossed up so we receive the invoiced sum.
  • Payment is made through Payoneer or through Upwork Direct Contracts, as agreed in the scope. Bank charges and currency conversion costs are yours. Where payment runs through Upwork, that platform's fees and terms apply to the transaction.
  • Invoices are due within 14 days. Overdue amounts may attract interest at 1.5% per month, and we may suspend work and system access on 7 days' written notice while an invoice remains unpaid.
  • Third-party platform costs — model API usage, telephony minutes, hosting, licences — are yours, billed by those providers directly to your accounts unless the scope says we pass them through.

9. Third-party services

Systems we build run on third-party platforms including model providers, voice and telephony infrastructure, cloud hosting, and the CRM, EHR, or practice management software you already use. Your use of those platforms is governed by their terms, not ours.

We are not responsible for those providers' availability, pricing changes, API changes, deprecations, or acts and omissions. Where a provider changes or withdraws a capability the scope depends on, we will tell you promptly and propose an alternative. Reworking a build to accommodate a third-party change is a change under clause 4.4.


10. How AI systems behave, and what we do not promise

This clause matters more than most. Read it.

10.1 Outputs are probabilistic

Systems built on large language models produce outputs by prediction, not by rule. They can be wrong. They can be confidently wrong. Independent benchmark research on multi-step agent tasks has found leading models completing well under half of them reliably. We design against that reality — narrow tool access, uncertainty routing, evaluation harnesses, human escalation — but we do not eliminate it, and no honest provider claims to.

10.2 No performance guarantee

We do not warrant that a system will achieve any particular accuracy rate, resolution rate, conversion rate, booking rate, cost saving, or return on investment, unless a specific measurable target is written into the accepted scope as a warranted outcome. Benchmarks and case figures we have published are context, not commitments.

10.3 Not professional advice

No system we build provides medical, legal, financial, or other professional advice, and none should be deployed as though it does. Systems in regulated settings are designed to gather information, route, schedule, and escalate — not to advise, diagnose, or decide.

10.4 Human oversight is a condition of use

Every production system includes a human escalation path. You agree to keep it operational, staffed appropriately for your business, and not to disable or bypass it. If you remove human oversight from a system we built, our responsibility for that system's outputs ends.

10.5 Continuity

Model providers deprecate models, change behaviour, and adjust pricing. A system that behaves one way today may need retuning after a provider update. This is what the calibration window and ongoing support exist for. It is a characteristic of the technology, not a defect in the build.


11. Intellectual property

11.1 Yours

You own your data, your documents, your content, your brand, and your systems. Nothing in these terms transfers any of it to us.

11.2 What you get

On full payment of all sums due, you own the deliverables built specifically for you under the scope — the configuration, the prompts, the workflow logic, and the custom code written for your engagement. You can run it, modify it, and take it elsewhere.

11.3 Ours

We keep everything we bring to the work: our methods, our internal frameworks and tooling, our reusable components, our templates, and anything we developed before or outside your engagement. Your ownership under clause 11.2 does not extend to these. We grant you a perpetual, non-exclusive, non-transferable licence to use them to the extent they are embedded in your deliverables and necessary to operate them.

11.4 What we learn

We may use general knowledge, skills, and experience gained during an engagement on other work. We will not use your confidential information, your data, or anything identifying you in doing so.

11.5 Naming you

We will not name you, use your logo, or describe your engagement in identifiable terms without your written permission. Anonymised descriptions by industry and size are used only where the engagement agreement permits.

11.6 Website content

The content of codeoravision.com belongs to us or our licensors. You may read it, quote it with attribution, and share links to it. You may not republish it wholesale, scrape it systematically, or use it to train a machine learning model without our written permission.


12. Confidentiality

Each of us will keep the other's confidential information confidential, use it only for the engagement, and protect it with at least the care we apply to our own. This survives the engagement by five years, and indefinitely for anything that is a trade secret or protected health information.

It does not apply to information that is public through no fault of the receiving party, was already known without obligation, is independently developed, or must be disclosed by law — in which case the disclosing party is told first where it is lawful to do so.

Discovery conversations run under mutual confidentiality from the first call, whether or not a separate NDA has been signed.


13. Warranties and disclaimers

We warrant that we will provide the services with reasonable skill and care, that we have the right to enter into the engagement, and that deliverables built for you will not knowingly infringe a third party's intellectual property rights.

Beyond that, and to the fullest extent the law allows, the website and the services are provided without warranty of any kind, express or implied, including implied warranties of merchantability, fitness for a particular purpose, uninterrupted operation, or error-free performance. We do not warrant that the website will be available without interruption or free of errors.


14. Limitation of liability

Nothing in these terms limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.

Subject to that:

  • Neither party is liable for indirect or consequential loss, loss of profit, loss of revenue, loss of anticipated savings, loss of business or goodwill, or loss or corruption of data, however arising.
  • Our total liability arising out of or in connection with an engagement, whether in contract, tort, or otherwise, is limited to the total fees you paid us under that engagement in the 12 months before the event giving rise to the claim.
  • We are not liable for loss arising from third-party platform failures, from your failure to maintain human oversight under clause 10.4, from data or instructions you gave us that were inaccurate, or from your use of a system outside the scope it was built for.

15. Indemnity

You will indemnify us against claims, losses, and reasonable costs arising from your breach of clause 7 (compliance), from data or content you gave us that you had no right to give us, or from your use of a deliverable in a way the scope did not contemplate.


16. Term, suspension, and termination

  • Either party may terminate an engagement on 30 days' written notice, unless the scope sets a different period.
  • Either party may terminate immediately if the other commits a material breach and fails to remedy it within 14 days of written notice, or becomes insolvent.
  • Monthly support may be cancelled by either party on 30 days' written notice, effective at the end of the current billing month.
  • On termination you pay for work performed and costs committed up to that date. We will hand over deliverables paid for in full, together with your data in a commonly used format, and delete or return the rest as you direct.
  • Clauses on intellectual property, confidentiality, liability, indemnity, governing law, and Schedule 1 survive termination.

17. Force majeure

Neither party is liable for delay or failure caused by events beyond reasonable control, including natural disaster, war, civil unrest, government action, sustained internet or power failure, and third-party platform outage. The affected party will notify the other promptly and both will work to minimise the impact. If the event continues beyond 60 days, either party may terminate without liability beyond sums already due.


18. General

  • These terms, the Data Processing Terms in Schedule 1, and the accepted scope are the entire agreement between us on their subject matter and replace any prior discussion.
  • Neither party may assign the agreement without the other's written consent, except in connection with a sale of substantially all of its business.
  • Nothing creates a partnership, joint venture, or employment relationship.
  • If a clause is found unenforceable, the rest continues in force.
  • A failure to enforce a right is not a waiver of it.
  • Notices must be in writing and are effective on delivery to the registered office above, to [email protected], or to the email addresses in the scope.
  • We may update these terms. The version in force at the date your scope was accepted governs that engagement.

19. Governing law and disputes

These terms and any dispute arising out of them are governed by the laws of the Islamic Republic of Pakistan. The courts of Karachi have exclusive jurisdiction, unless a signed master services agreement provides otherwise.

Before starting proceedings, both parties agree to attempt resolution in good faith through direct discussion for at least 30 days.

Where an engagement is contracted through Upwork Direct Contracts, that platform's dispute resolution process applies to disputes about payment for that engagement.


20. Contact

Codeora Vision (SMC-Private) Limited · Incorporation Number 0287521 Plot No. 558, 2nd Floor, Rajput Colony, Gulshan-e-Iqbal Block No. 3, Karachi, Pakistan [email protected]



Schedule 1 — Data Processing Terms

These Data Processing Terms apply automatically whenever we process personal data on your behalf in the course of an engagement. They form part of the contract between us and do not need to be signed separately. Where a signed data processing agreement or Business Associate Agreement exists between us, that document takes precedence over this Schedule.

S1.1 Definitions

Personal data, processing, data subject, controller, processor, and personal data breach carry the meanings given in the data protection law applicable to you. Client data means personal data we process on your behalf under an engagement. Sub-processor means a third party engaged by us to process client data.

S1.2 Roles

You are the controller (or, where you act on behalf of another organisation, the processor) of client data. We are your processor (or sub-processor). Each of us complies with the data protection law applicable to it.

You are responsible for the lawfulness of the data you give us, for having any notice or consent required to collect it, and for the accuracy of your processing instructions.

S1.3 Scope of processing

  
Subject matterBuilding, operating, and supporting the AI system described in the accepted scope
DurationFor the term of the engagement, plus any retention period in clause S1.10
Nature and purposeReceiving, routing, classifying, retrieving, storing, transmitting, and writing back data as the system requires in order to function
Types of personal dataAs determined by you. Typically names, contact details, appointment and scheduling information, call and message content and transcripts, account and case identifiers, and — where the scope provides for it and a BAA is in place — protected health information
Categories of data subjectAs determined by you. Typically your customers, patients, clients, tenants, prospects, and staff

S1.4 Our obligations

We will:

  • Process client data only on your documented instructions, including the accepted scope, unless required otherwise by law — in which case we will tell you first unless the law forbids it
  • Tell you promptly if, in our opinion, an instruction breaches applicable data protection law
  • Ensure everyone we authorise to process client data is bound by a written confidentiality obligation
  • Implement and maintain the security measures described in clause S1.6
  • Not use client data for any purpose other than delivering the engagement, and specifically not to train any AI model for our own or a third party's benefit

S1.5 Your instructions

The accepted scope, together with the configuration you approve before go-live — scripts, prompts, escalation rules, integration mappings, and retention settings — constitutes your complete documented instructions. Changes to those instructions are made through the change process in clause 4.4.

S1.6 Security

We implement and maintain technical and organisational measures appropriate to the risk, including:

  • Encryption in transit using TLS 1.3, and at rest using AES-256, on systems we control
  • Role-based access control on a least-privilege basis, with multi-factor authentication
  • Audit logging of access to client systems and client data
  • Segregation of client environments
  • Written confidentiality obligations on all personnel and delivery partners
  • Data minimisation — we request and retain only what the scope requires
  • Evaluation and monitoring of system behaviour before and after go-live

S1.7 Sub-processors

You give us general authorisation to engage sub-processors. The current list is:

Sub-processorPurpose
Amazon Web Services / Google Cloud PlatformHosting and infrastructure
Anthropic, OpenAI, and other model providersModel inference, on terms excluding training on submitted data
Twilio, Vapi, Retell AI, ElevenLabs, DeepgramVoice and telephony delivery, where the scope includes voice
LangSmithObservability and evaluation
CloudflareNetwork security and delivery
Contracted engineering partnersDelivery, under written confidentiality obligations

We impose data protection obligations on each sub-processor no less protective than these terms, and we remain liable to you for their performance.

We will give you at least 30 days' written notice before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the engagement without penalty, with fees payable for work performed up to that date.

S1.8 Assisting you

Taking into account the nature of the processing, we will provide reasonable assistance with:

  • Responding to requests from data subjects to access, correct, delete, restrict, port, or object to processing of their data. Where we receive such a request directly, we will not respond to it ourselves but will forward it to you promptly.
  • Your obligations to keep processing secure, to notify breaches, and to carry out data protection impact assessments and prior consultations.

Assistance beyond what is reasonably necessary may be chargeable at our then-current rates, and we will tell you before incurring a charge.

S1.9 Personal data breach

We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting client data. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Where we cannot provide all of it at once, we will provide it in stages without further undue delay.

We will not notify any regulator or data subject on your behalf unless you instruct us to, or unless we are independently required to.

S1.10 Return and deletion

On termination or expiry of an engagement, at your election, we will return client data in a commonly used, machine-readable format, or delete it, and delete existing copies — unless applicable law requires us to keep it, in which case we will tell you what we are keeping and why.

Unless you tell us otherwise, we will delete client data from systems we control within 90 days of the end of the engagement. Backups are deleted on the normal backup expiry cycle.

S1.11 Audit

We will make available the information reasonably necessary to demonstrate compliance with these terms, and will contribute to audits conducted by you or an auditor you appoint. Audits are limited to once per year unless a personal data breach or a regulator requires otherwise, require 30 days' written notice, take place during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality. You bear the cost of your own audit.

S1.12 International transfers

We process client data from Pakistan and our sub-processors operate globally. You authorise these transfers. We remain accountable for client data wherever it is processed and apply the safeguards described in clause S1.6.

Where client data originates in the United Kingdom or the European Economic Area, the European Commission's Standard Contractual Clauses (module three, processor to processor, or module two, controller to processor, as applicable) and the UK International Data Transfer Addendum are incorporated into these terms by reference and take precedence over any conflicting provision in this Schedule.

S1.13 Protected health information

Where an engagement involves protected health information as defined under HIPAA, a separate Business Associate Agreement is executed before any such information is handled. That agreement takes precedence over this Schedule to the extent of any conflict.

S1.14 Liability

Liability under this Schedule is subject to the limitations in clause 14 of these terms.


Questions about these Data Processing Terms: [email protected]