Master service agreementLast reviewed August 2026

Master Service Agreement

This page summarises the agreement under which Avrosh is supplied: who contracts with you, what you get, what each side owes the other, and what happens when things go wrong. It is a plain English summary and it is not itself the contract. Where a signed agreement exists between you and us, that document governs and this page loses. Where no signed agreement exists, your account is governed by the public Terms of Service alone, and the public defaults stated below are the ones that apply. Nothing here is legal advice.

Who you are contracting with

The contracting party is PT Laras Teknologi International, a company incorporated in Indonesia. It operates the Avrosh platform, issues the invoices, and is the entity that signs. Our registered address is not published here; it appears in the signature block of the signed agreement, and we will give it to you on request before you sign.

The company is established in Indonesia and is subject to Indonesian law, including Law 27 of 2022 on Personal Data Protection. Most of our customers are in the United States and the European Union, so the EU General Data Protection Regulation also applies to us directly under Article 3(2). Indonesia does not have an EU adequacy decision, so transfers of EU personal data to us run on Standard Contractual Clauses plus a transfer impact assessment. Those clauses form part of the data processing agreement that sits alongside this one.

GDPR Article 27 requires a non-EU company offering services into the EU to appoint a representative in the Union. We have not yet appointed one. That appointment is in progress and the name and address will be published on this page and in the data processing agreement when it is made. We would rather say that plainly than let silence imply it is done.

Written questions about the entity, the agreement or the signature block go to hello@avrosh.com.

What we agree to provide

Avrosh answers your customers by phone and by a QR or link chat, using your own business data. It takes bookings and orders, logs jobs for your staff, and hands off to a human when it cannot answer. Operators run the whole thing from a web dashboard.

We agree to provide the platform as it exists, to keep it running, and to keep it truthful: the system is built to answer from your data rather than to invent facts, and it escalates instead of guessing. What is verified and what is not is set out on the security page, and we would rather you read the limits there than take a marketing sentence from us.

Where your data is stored and which providers serve the answer are published facts, not a private arrangement. We run database regions in Northern Virginia, Singapore and Frankfurt. The AI models that actually serve answers today are hosted in Singapore and the United States, so an EU-region customer gets an EU database with no EU model in the answer path. The model serving each role is set with us rather than picked in the dashboard, and the origin of each is published. If a specific serving region matters to your compliance position, tell us before you sign, because we will not fix it in a contract clause that the running system does not honour.

Ordering, activation and the shape of an account

Access is arranged with us rather than bought from a page. You tell us about the business, we quote a price for it, and we activate the account. There is no public price list, no tier and no self-serve checkout that turns a stranger into a live account.

Activation is at the account level, not per property. Once your account is active, every additional business you add under it is born active as well. There is no separate subscribe step for the second location and no per-property cancel: cancelling is an account-level conversation with us, and it is wrong to think of one location as switchable off while the others keep running.

A partner or white-label license, where you resell Avrosh under your own brand, is a separate agreement arranged by application. Nothing in the subscription agreement grants resale rights.

Term, renewal and fees

Subscriptions run annually. The fee is quoted privately for your business and shown to you before you commit, because integrations, service levels and special features are shaped into the figure rather than sold as add-ons. This page states the mechanism only and carries no number, no band and no percentage.

Voice is the only metered part of the service. It is billed against prepaid credit on the account. Everything else, including chat, is included in the subscription.

Subscriptions are collected through our payments provider acting as merchant of record. That provider issues the checkout, handles the card, and owns the renewal and refund mechanics shown to you at checkout. Card details never reach our systems. Invoices and the payment method live in the provider's customer portal, reachable from your dashboard.

Price changes at renewal are agreed with you. We do not silently reprice an account mid-term.

What you are responsible for

You own the accuracy of what you publish into the system: prices, hours, policies, menus, services and availability. The AI answers from that content, so wrong content produces wrong answers, and that is not a platform defect.

You are responsible for your staff's use of the account, for the roles and access you grant them, and for keeping credentials safe. If you issue a machine credential to your own servers or to a vendor, you are responsible for what that credential does and for revoking it when the relationship ends.

You are responsible for handling your customers' personal data lawfully: your legal basis, your notices, your consent records, and your responses to your customers' rights requests. We process that data on your instructions under the data processing agreement.

Where you connect Avrosh to a third-party destination, for example your own CRM, calendar or automation tool, or where you configure your own mail server, that destination is engaged by you and is not our sub-processor. We deliver the data you told us to deliver, to the place you told us to deliver it.

Acceptable use

Do not use the service for unlawful content, to deceive or abuse your customers, to scrape or reverse engineer the platform, or to resell it outside a partner license. Do not use it to impersonate another business.

Outbound calling carries its own rules and they are enforced in the product, not just written here. The calling list must come from you. We do not scrape or buy lists and we will not accept one that was. Before a list can dial you must attest that you hold the consent required for those numbers, the system refuses to dial a list without that attestation, it checks a do-not-call suppression list on every target, and it honours calling windows and attempt caps. Breaching telephone consent law is expensive and the penalties land on you, so treat the attestation as the serious statement it is.

Some verticals we support, including dental and clinical businesses, mean a transcript can contain health information. We are not a HIPAA business associate, we hold no health data certification, and you must not route data into Avrosh that requires one. If your regulator demands assurances we cannot give, say so before you sign rather than after.

We may suspend an account that is breaching this section, and we will tell you why.

Your data, your content, our platform

You own your content and your customer relationships. Your business data, knowledge base, menus, catalogues, bookings, customer records, conversations and transcripts are yours. Signing up does not transfer any of it to us and does not give us a licence to use it for anything beyond running the service for you.

We do not sell your data and we do not use your customers' conversations to train models for other customers.

We own the platform, the software, the brand and everything we build to run it. Feedback and suggestions you give us we may use freely, without that creating any claim over your content.

The QR and link chat is deliberately zero personal data: no account, no phone number, no login for the person using it. That is a design choice, and it is the reason a large part of the guest surface carries no identifiers at all.

Confidentiality, and requests from authorities

Each side keeps the other's non-public information confidential, uses it only to perform the agreement, and protects it with at least the care it gives its own confidential material. Your business data is your confidential information. Our pricing, roadmap and non-public technical material is ours. The obligation survives the end of the agreement.

If a government body or law enforcement agency asks us for customer data, we require valid legal process rather than making a voluntary disclosure. We tell you about the request so you can respond, unless we are legally prohibited from telling you. We push back on requests that are overbroad or defective.

We do not currently publish a transparency count of such requests. Whether to start publishing one is an open decision, and it is listed below rather than quietly left out.

Warranties, and what we do not warrant

We warrant that we have the right to provide the service, that we will provide it with reasonable skill and care, and that we will not knowingly introduce malicious code.

Beyond that, the service is provided as is. We do not warrant uninterrupted availability. There is no uptime commitment unless one is written into a signed agreement with you; a public account has no service level, and we would rather say that than print a number we have not measured.

We hold no third-party certifications. There is no SOC 2 report, no ISO 27001 certificate, no HIPAA attestation and no PCI certification, and we will not imply otherwise on a questionnaire. Card data is out of scope for us entirely because the payments provider is merchant of record and cards never touch our systems.

We do not currently hold cyber liability insurance. There is no policy, no insurer and no limit. Buyers who require a certificate of insurance should raise it before signing, because today we cannot produce one.

Indemnities

We defend you against a third-party claim that the Avrosh platform itself infringes that party's intellectual property rights, and we pay the damages finally awarded or the settlement we agree, provided you tell us promptly, let us control the defence, and cooperate. This does not cover claims arising from your content, your configuration, or a combination we did not supply.

You defend us against third-party claims arising from your content, from how you use the service, from the calling lists and consent attestations you supply, and from your handling of your customers' personal data, on the same terms.

Each indemnity is subject to the liability limits below, except that the outbound calling and personal data indemnities you give us are not capped by them, because that exposure comes from your list and your legal basis rather than from our software.

Limitation of liability

Neither side is liable to the other for indirect, incidental, special or consequential loss, or for lost profits, lost revenue, lost data or lost goodwill, even if the possibility was known.

The public default, which applies where there is no signed agreement, is that our total liability for all claims in aggregate is limited to the fees you paid us in the twelve months before the event giving rise to the claim. If a signed agreement sets a different figure, that figure governs and this default does not apply. Do not read a number off this page and assume it is yours; check what you signed.

Nothing here limits liability that cannot be limited by law, including fraud, wilful misconduct, and death or personal injury caused by negligence.

Suspension, termination and getting your data out

You can end the subscription with us. We can suspend or terminate for a serious or unremedied breach of the acceptable use section, and for non-payment.

Non-payment today does not automatically cut service off. When our payments provider tells us a subscription has been cancelled, gone past due or been revoked, the account is marked overdue and the dashboard shows a red banner, but an overdue account keeps serving. There is no timed grace period in the system and no automatic cutoff, so any actual suspension is a decision we take and tell you about. A refund is the one event that returns an account to the unpaid state. We are stating the mechanism as it is rather than inventing a grace period that no code enforces, and the cutoff policy is an open decision listed below.

Your customers can already export and erase their own records themselves: the contact record, bookings, waitlist entries and consent history, with erasure stripping identifiers in place. An operator-side export of the whole business is not self-serve yet, so ask us for it before you delete anything.

When a business is deleted it is soft deleted first and hard purged after seven days, which is your window to change your mind. Retention is set out in full in the privacy documentation, and one part of it belongs here too: conversations, chat sessions, call records and their written transcripts have no automatic prune today and live for the life of the account. No call audio is recorded or stored; a written transcript and a call record are.

Governing law and how disputes are settled

The agreement is governed by Indonesian law.

Disputes that cannot be resolved between us go to binding arbitration administered by the Singapore International Arbitration Centre, seated in Singapore, conducted in English. Governing law and seat are two different things and both are stated here on purpose.

The reason matters to you as a buyer, so here it is plainly. A judgment from an Indonesian court is not readily enforceable in the United States or the European Union, and a US or EU judgment is not readily enforceable against an Indonesian company. An arbitral award is enforceable in more than 170 countries under the New York Convention, to which Indonesia, the United States and every EU member state are party. Arbitration is what makes a remedy against us actually collectible where you live. It is a protection for you as much as a convenience for us.

Either side may still seek urgent injunctive relief from a court to protect confidential information or intellectual property.

Changes

We may change the platform. We will not remove a capability you rely on without telling you, and material changes to these terms are published on this page with an updated review date. Continuing to use the service after a material change means you accept it. If a change is unacceptable to you, tell us and we will talk about it rather than hide behind the notice.

A signed agreement can only be changed in writing by both sides. A page edit here does not amend a contract you signed.

Anything on this page that is unclear, or that your legal team needs stated differently, is a conversation we are willing to have. Write to hello@avrosh.com.

This page summarises how Avrosh is supplied today and is not the contract itself. For the signed agreement, the registered address in the signature block, the data processing agreement and its Standard Contractual Clauses, or a security questionnaire, write to hello@avrosh.com.