The terms, in plain words.

Your expert writes the answers, we find the step, you keep everything, and you can stop at any time.

1. Who

Provider: Sarsa Formation OÜ, a private limited company registered in the Estonian Commercial Register under registry code 17290516, registered office Lõõtsa tn 1a, 11415 Tallinn (Lasnamäe linnaosa, Harju maakond), Estonia, email sana@muoto.xyz (“we”). Buyer: the company that buys one wrong-answer diagnosis through the payment link on our website (“you”). You confirm that you are buying for business purposes and have authority to bind the Buyer. Accepting these terms at checkout, or paying, is agreeing to them as they read on that date; the version is at the foot. How we handle your own details as our customer is in our privacy notice.

2. What you buy, and the price

One wrong-answer diagnosis of one AI feature: a map of every path through it, up to 20 questions, up to 25 steps of the feature (each point where it branches counts as a step), about 50 pages of documents in total, and one report. Price: €900, fixed, paid up front. Sarsa Formation OÜ is currently not registered for Estonian VAT and adds no Estonian VAT. Where reverse charge or another mandatory tax treatment applies to you, each of us accounts for it as the law requires, and the invoice says so. Anything larger is quoted in writing before any work starts, and is a separate agreement.

3. How it works, and how either of us stops

  1. Your expert writes the answers first. We send a template; we never write your answers. Before any model sees your documents the answers are locked, and we both keep a fingerprint (a hash) of the answers and of the documents they were written against, so any change to either afterwards would show.
  2. Before we run anything, we send you the run plan, and nothing runs until you agree to it. It names the paths through your feature, the steps on them we will test, and the price of each step — equal shares of €900 across the steps named (ten steps, €90 each; five steps, €180 each); where we expect the feature to fail, and what result would prove us wrong; and the data details in §10 (what kinds of personal data are involved, which model providers each call goes to and with what settings, and where the data is processed).
  3. Until anything runs, you may withdraw for any reason or none and get a full refund, within ten business days. That includes the case where the answers cannot be written or you cannot share documents. Stopping here costs you nothing.
  4. You may stop at any time after we start, for any reason or none. A step already started is earned at the plan’s price; you receive everything produced so far; anything unearned is refunded within ten business days.
  5. We may stop if we cannot perform a step (and cannot check it from the outside), if the material is unlawful, is not yours to give us, or contains data §10.3 excludes that cannot be removed, if we hear nothing from you for 30 days, for a security reason we name, or if you materially breach these terms. What is earned depends on who stopped and why: if we stop because we cannot perform a step, or for a security reason you did not cause, the step under way is not earned; if we stop because of your breach, unlawful or excluded material, or missing cooperation, a step already started is earned. Either way you receive what was produced and the rest is refunded within ten business days.
  6. Steps we cannot run ourselves — your private code, your live data — are checked from the outside: what goes in and what comes out. The report says which steps we could not open.
  7. When a step starts: when we make its first model call, or, for a step checked from the outside, when we first send you input for it or you first run it for us, whichever comes first. The run log records that moment for each step, and which of these it was.
  8. When you get the report: within two business days after the later of two days, the day your answers are locked and the day you agree to the run plan. Time we wait on you for something the run plan names as yours to do, such as running a step for us or giving us access, does not count; the run log records each wait. If we are late, you may stop and we refund the full price, whatever steps have started, within ten business days; you still receive everything produced so far.

4. What you keep, and what you may do with it

Yours: your documents and your expert’s answers. They were always yours.

Ours: our method, and the tools, code and know-how we had before working with you (“our existing IP”). Nothing here transfers it.

What we deliver: the report, the run plan, the run settings, every reply from the model with its cost and why it stopped, the files specific to your diagnosis, and the scripts we used. We grant you a perpetual, worldwide, royalty-free, non-exclusive right to use, copy and change all of it, including any of our existing IP inside the scripts, for your internal purposes — which include use by contractors and professional advisers working for you, and by the supplier who built or runs the feature for you, each under confidentiality. You may not offer the scripts to others as a standalone service. Third-party components in the scripts, such as open-source libraries and the providers’ own client libraries, stay under their own licences, which the delivery lists; the grant above covers only what is ours to grant.

What works without us: the report can be reproduced from the files we deliver, without contacting us. The scripts depend on no service we host. Re-running them depends on the model providers and models you choose and pay for still being available and behaving the same; a provider can retire or change a model, and we do not promise otherwise. Nothing needs an account with us, and nothing stops working when we are done.

5. Your material: confidentiality, security, where it goes

  • Confidential. Your documents, your answers, the details of your AI feature and the report are confidential. We use them only for your diagnosis and to answer your questions about the report. We never use your name, the engagement, your material or the findings publicly without your written permission.
  • Security. Your material is encrypted in transit and at rest; only the people working on your diagnosis can reach it, with the least access they need; it is never put into a consumer AI product; it is deleted on the schedule in §10.9; and it reaches only the model providers the run plan names, set up the way the plan says. We tell you without undue delay after becoming aware of a security breach affecting your material.
  • Model providers. To run the diagnosis we send your material to model providers through their business APIs, under their data-processing terms, never through a consumer product. The providers we may use are Anthropic, OpenAI and OpenRouter; where OpenRouter is used, the run plan names the provider behind it that the call is fixed to, and each company in that chain is named as a sub-processor or further sub-processor. Documents you send us by email are held by our mail provider, Resend, which is a sub-processor too. Our own AI agent, which prepares the run plan and writes the report, reads your material only through Anthropic’s business API under the same terms and settings, and the run plan names it as a route like any other; it never reads your material through a consumer subscription. The run plan names the providers, models, locations and settings for your diagnosis, and the run log records, for every call, which provider and model answered.
  • Training. Neither we nor any model provider used for your diagnosis may use your material, or what the models return, to train or improve general-purpose models. Before we run anything we set up and contract each provider accordingly, and the run plan names the settings.
  • How long we keep it. We keep our copy of your material and the model replies until 30 days after we deliver the report or the engagement ends under §3, whichever comes first, so we can answer your questions — that is part of the service — unless you ask us to delete it sooner, in which case we delete our working copies at once. Copies kept along the way — by our mail provider, and by the model providers under the retention settings the run plan names — expire on the schedules the plan states, never more than 30 days after the mail or the call; we do not send personal data by any route that keeps it longer. Any backup expires within 90 days and is not otherwise used. Invoices and this agreement are business records we keep as the law requires, separately from your material.

6. What the report is not

Not a benchmark score, a certificate, or a promise that your AI feature is right. It tells you what your expert’s answers could catch, for the questions in it, and nothing more. What you do with it is your decision.

7. Liability

Our liability under this agreement is capped at the price you paid. Neither of us is liable to the other for indirect loss. This cap does not apply to intentional non-performance or gross negligence, and nothing here limits liability that cannot be limited under Estonian law.

8. Law

Estonian law. Disputes go to Harju County Court, Estonia, unless a mandatory rule where you are gives you another forum.

9. Changes and ending

These terms are the ones on our website on the date you paid; the version is at the foot. You can end the engagement in writing at any time under §3.3 or §3.4, and we can end it only for the reasons in §3.5. On ending, the money owed is what §3 says. §4 to §8 and §10 survive the end of the engagement: what you keep, confidentiality, security, deletion, the limits of the report, liability, law and the data-processing schedule.

10. Data-processing schedule — applies automatically if your material contains personal data

This schedule is part of these terms and applies, without anyone asking, whenever the material you give us contains personal data. For that material you are the controller and we are the processor. For our own billing, contracting, security and legal-administration data (your name, address, payment record, this agreement) we are the controller, and our privacy notice says how we handle it.

  1. Subject matter and duration: processing the personal data in your documents, your answers and the model replies, until 30 days after we deliver the report, unless you tell us to delete or return it sooner or the engagement ends under §3.
  2. Nature and purpose: mapping the paths through your AI feature; running it as it is, and again with one step at a time given the right answer; checking its fixed logic against every combination of inputs it reads; comparing the results with your expert’s answers; writing the report; and answering your questions about it during those 30 days. Nothing else.
  3. Types of data and data subjects: the run plan records, for your diagnosis, the kinds of personal data and the groups of people it concerns (usually the people named in the documents or requests your feature reads). We do not process special-category data (Article 9 GDPR) or data about criminal convictions and offences (Article 10 GDPR) in this engagement. Do not give us any. If we become aware that some has reached us, we tell you, do not use it, and delete it from our copies at once. If it sits in a document your answers were written against, you send a copy without it and we lock the answers and the documents again before anything runs.
  4. Instructions. We process only on your documented instructions, which are these terms and the run plan you agreed to, including for transfers outside the EEA. If we think an instruction breaks the law, we tell you. If Union or Member-State law requires us to process personal data other than on your instructions, we tell you before doing so unless that law prohibits us from telling you.
  5. People. Everyone who handles your data is bound to confidentiality.
  6. Security. The measures in §5, and any others the risk requires.
  7. Sub-processors. The run plan is your specific written authorisation of the sub-processors for your diagnosis. It names each company in the processing chain — as a sub-processor, or as a further sub-processor where a router such as OpenRouter passes the call on to another provider — with its processing locations, the retention and training settings for the calls, and, for each transfer outside the EEA, the transfer mechanism under Chapter V of the GDPR (an adequacy decision where one applies, or the appropriate module of the standard contractual clauses) and any additional safeguards required. Where you send material by email, it also names our mail provider. Our scripts send calls only by the route the plan names, with automatic fallback to other providers and provider data collection switched off, and refuse any call that would leave it; the run log records which provider and model answered each call. No sub-processor is added or replaced unless you agree to a revised run plan; if you do not, either of us may stop under §3. Each sub-processor is bound by data-processing terms that impose, in substance, the same data-protection obligations as these; a provider whose terms do not is not used for personal data. We remain responsible to you for each sub-processor’s performance of those obligations.
  8. Assistance. We help you answer requests from the people your data concerns, and help with security, breach notification, impact assessments and prior consultation, as far as the data we hold allows. We notify you without undue delay after becoming aware of a personal-data breach affecting personal data processed under this engagement.
  9. End. When processing ends (§10.1) we delete or return your personal data, as you choose — returning means handing over any personal data we still hold that you have not already received — and delete our copies as §5 says, unless the law requires us to keep them; copies kept along the way expire as §5 says; backups expire within 90 days and are not otherwise used.
  10. Audit. We give you the information needed to show these duties are met, and allow an audit by you or an auditor you appoint, on reasonable notice, at your cost.