Terms for a chatbot or customer service product
Customer terms for a chatbot, virtual agent or customer service platform used by businesses to talk to their own customers, drafted for a fixed fee of £995 in five working days.
Terms for a chatbot or customer service product
Terms for a chatbot, conversational AI or customer service platform sold to businesses, drafted for how the product talks to the customer's own customers, covering the customer as controller and the supplier as processor, transcripts and their retention, what the bot says and who is responsible for it, disclosure that the user is talking to a machine, human handover and complaints, training on conversations, and liability. £995, delivered in five working days.
Buy now, £995A chatbot product talks to people who are not the supplier's customers, on behalf of a business that is, and the terms have to manage that triangle: the business is the controller of the conversations and the supplier processes them, the business is responsible for what the bot tells its customers, the bot should say it is a bot, a human has to be reachable, and the transcripts have to be kept for as long as the business needs and no longer. Where the bot uses AI, the accuracy and training questions come with it. I draft those terms for a fixed fee of £995, delivered in five working days.
Who this is for
Businesses in England and Wales selling chatbots, virtual assistants, conversational AI, live chat and customer service platforms to business customers who deploy them on their own websites, apps and channels.
What matters in chatbot and customer service platform terms
The customer as controller and the supplier as processor
Conversations between the bot and the customer's users contain personal data, sometimes special category data when users describe health, financial or personal circumstances, and the customer is the controller while the supplier is its processor, so the terms must contain the provisions Article 28 of the UK GDPR requires, state security under Article 32, list subprocessors including any model provider with transfers addressed under Article 46, and require the customer to have the lawful basis and privacy notice its users need. The supplier should not become a controller of conversation content by using it for its own purposes without the terms saying so.
Transcripts, retention and access
The terms should say what is recorded (transcripts, metadata, attachments), how long the supplier retains it by default, that the customer can configure retention within limits and export or delete transcripts, who at the supplier can access conversations and why, and how requests from the customer's users under the UK GDPR are supported. Recording conversations for training the customer's staff or the bot needs the customer's users to be told, and the terms should require the customer to tell them.
What the bot says and who is responsible
The customer configures the bot's knowledge, answers and tone, and the terms should make the customer responsible for the content the bot provides to its users, for its accuracy, for compliance with the customer's own regulatory obligations (financial promotions, medical claims, consumer information), and for reviewing outputs where the bot generates rather than retrieves; the supplier provides the platform with reasonable care and skill under section 13 of the Supply of Goods and Services Act 1982. A statement made by the bot to a consumer is a statement by the customer under Part 4 of the Digital Markets, Competition and Consumers Act 2024, and the terms should say so.
Disclosure that the user is talking to a machine, and human handover
The terms should require the customer to configure the bot to identify itself as automated, to make a route to a human available for complaints and for users who ask, and to comply with accessibility obligations under the Equality Act 2010 in how the bot is deployed, because a service that traps a disabled user or a complainant in a bot loop is the customer's failure and the supplier's reputational problem. Where the customer serves EU users, the EU AI Act's transparency requirement for systems that interact with people applies to the deployment.
AI features, accuracy and training on conversations
Where the bot generates responses using AI, the terms should say that outputs may be inaccurate, that the customer must configure guardrails and review, and what the supplier's model does with conversation content: no training on the customer's conversations without consent, or training only on aggregated and de-identified data, stated in the terms and the privacy notice. Third-party model providers should be listed as subprocessors with their retention commitments described, and automated decisions about individuals with significant effects should be identified as within Article 22 of the UK GDPR and left to the customer's controls.
Fees, liability and the boilerplate
The terms should state pricing by seat, conversation or resolution with definitions the customer can check, renewal and notice, interest on late payment under the Late Payment of Commercial Debts (Interest) Act 1998, a liability cap at the fees paid in the preceding twelve months with consequential loss excluded and tested under section 11 of the Unfair Contract Terms Act 1977, the customer's indemnity for what the bot is configured to say, and English law with third-party rights excluded under the Contracts (Rights of Third Parties) Act 1999, so that the customer's users have no claim under the terms against the supplier.
What it costs
SaaS terms of service, £995. Your standard customer-facing terms. Five working days.
Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A bespoke contract drafted for how your product is sold, delivered and supported
- Service levels you can meet, with remedies that are proportionate rather than aspirational
- A liability position that is defensible and will survive enterprise procurement
- IP and data provisions that fit together rather than contradicting each other
- A commercial note on where you will get pushback and what is worth conceding
- One round of amendments
What is not included
- Negotiating individual enterprise deals, which I quote separately
- Advice on the law of jurisdictions outside England and Wales
- Technical security certification or audit
- Regulatory advice for regulated sectors such as financial services or health
Questions I am often asked
Our customer's bot gave one of their customers wrong information. Who is liable?
The customer, to its own user, as the terms make the customer responsible for the bot's content and configuration. The supplier is liable to the customer only for failing to provide the platform with reasonable care, within the cap.
Must the bot tell users it is a bot?
The terms require the customer to configure it that way, because fair dealing with consumers expects it and EU users are entitled to it. It is also the setting that reduces complaints.
Can we use conversations to improve our models?
Only on the basis the terms state and the customer has accepted: aggregated and de-identified data, or not at all. Conversations identifying the customer's users are the customer's data and stay that way.
Related guidance and services
- SaaS and technology contracts, £995, the service this page describes
- AI contracts and AI use policies, £995
- Data protection agreements and privacy terms, £795
- Terms for an AI-powered SaaS feature
- Getting an AI-drafted data processing agreement checked
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.