ONCEAI Agent Huddle

Service information

Version 2026-10-09 · adopted 9 October 2026

Availability and subscription controls are shown in the console. These services have no uptime SLA. The documented provider and fencing limits apply.

Download the complete version for your records

Service terms — version 2026-10-09

Adopted by Global Talent Leaders LTD on 9 October 2026. Paid service starts after checkout is enabled and the purchased subscription is confirmed.

Operator and service

Global Talent Leaders LTD, company number 14557865, trading as AI Agent Huddle. Registered office: Summit House, Horsecroft Road, Harlow, Essex, England, CM19 5BN. Support and privacy requests: accounts@aiagenthuddle.com. The company is not VAT registered.

ONCE and CLAIM are separate developer services. Their documentation defines supported interfaces and operations. ONCE records provider outcomes and recovery evidence for supported actions; it does not guarantee universal exactly-once execution. Its Stripe action adapter uses test credentials and creates unconfirmed PaymentIntents. Its GitHub adapter creates real issues in an authorised repository. CLAIM supplies expiring leases and fencing tokens; customers must enforce fencing in the downstream system. Neither service provides an uptime SLA.

Accounts and acceptable use

Users must be authorised to operate their account and any provider credentials they supply. Keep product keys and credentials confidential and server-side. Use opaque operation/resource identifiers and minimise submitted personal information. Do not submit card details, passwords, authentication links, special-category data or unlawful content in workload parameters, metadata or support correspondence. Do not evade quotas, interfere with other projects, test third-party systems without permission or resell access in a way that bypasses the documented limits.

Customers retain ownership of their submitted content. They authorise the processing needed to deliver their requests, maintain the ledger or leases, operate security and provide support. Customer provider calls remain subject to their provider agreement and charges. Provider outages or revoked credentials can prevent work or reconciliation.

Plans and payments

Launch offer: free 1,000 ordinary units per product/project per UTC calendar month; ONCE Starter £9/month with 10,000 units; CLAIM Starter £5/month with 20,000 units. Each subscription is purchased separately and renews monthly until cancelled. These prices currently have no added VAT. A CLAIM wait consumes five units; other ordinary requests consume one, including replays and denials. There are no automatic overage charges. Unused units do not carry forward.

Existing ONCE inspection/reconciliation, CLAIM status/release and required MCP discovery use a separate 60-request-per-project-per-minute allowance. This is rate-limited recovery access, not unlimited traffic. Exhaustion, provider errors and service failures must be handled explicitly by the integration. Admission, storage and compute scenarios are recorded in the release evidence; actual customer-period margin remains to be measured after launch.

ONCE reconciliation also has a reserved 100 requests per project per UTC calendar month, independent of ordinary units and identical across free/paid access. Each admitted reconciliation consumes one unit, including repeated/definitive results. Exhaustion stops provider lookup/history writes with HTTP429; inspection/discovery keep their separate minute budget. Unused reserved units do not carry forward, and a plan change does not reset the count. A quota error does not establish a safe retry or a noncommit outcome.

Cancellation schedules the subscription to end at the current billing-period boundary. Access then follows the free limits; historical usage is not erased by changing plan. Contact support from the registered email for billing problems, refunds or account closure. Refund requests are reviewed rather than automatically promised. Applicable statutory rights are unaffected. Future material price or allowance changes must be communicated before taking effect; existing paid periods retain the offer under which they were purchased.

Reliability, support and closure

Maintain your own record of operation keys, IDs and fencing tokens. Do not redispatch an UNKNOWN or AMBIGUOUS ONCE outcome blindly or treat an expired CLAIM lease as authority. Service evidence does not replace your application’s safety checks. Support has no guaranteed response time; include redacted diagnostic identifiers and UTC timestamps.

The operator may restrict abusive or unsafe traffic, investigate security incidents or discontinue a probe. Where practical, notify affected users before a planned discontinuation, stop new subscriptions, explain recovery/export options and address unused paid service. This is not an indefinite support commitment. Do not erase uncertain-outcome evidence during incident response.

On closure, revoke access, resolve subscriptions, offer a verified export of customer workload records and arrange deletion with the customer. No automatic ledger purge exists. Restrict records retained for legal obligations or unresolved security/billing matters. Backup copies expire through supplier retention and must not be restored into active processing after deletion without reapplying the deletion record.

Cancellation and consumer rights

To cancel renewal, use the account cancellation control or email accounts@aiagenthuddle.com from your registered address. Normal cancellation ends paid access at the current billing-period boundary. A consumer exercising a statutory withdrawal right has separate rights: notify us within 14 days of entering the subscription, by a clear email or letter. You may use: “I give notice that I cancel my subscription to [ONCE/CLAIM], ordered on [date], account email [email], name [name], address [address], date [date].” Send it to the support email or registered office above. A signature is needed only for a paper notice. This form is optional.

Checkout asks you expressly to request immediate service during that 14-day period. This does not waive the withdrawal right. If you withdraw after requesting immediate service, a proportionate charge for service actually supplied applies only where permitted by law; we refund the balance within the legally required time. We do not automatically refuse refunds merely because a subscription has started. Other mandatory consumer remedies remain available. Before paid service starts we provide a durable confirmation of the purchased plan, price, renewal/cancellation information and this version of the terms.

If we discontinue a paid probe, we stop new purchases, notify affected users where practical, offer verified export and recovery guidance, and refund unused prepaid service for the period we cannot supply. Customers may close their account through support after resolving subscription and export instructions.

Care, liability and governing law

We provide the service with reasonable care and skill. The documented limitations and lack of an uptime SLA do not remove mandatory obligations.

For customers acting in the course of business, aggregate liability under or in connection with a product subscription is limited to the greater of £1,000 and the fees paid for that product in the 12 months before the event giving rise to the claim, to the extent lawful and reasonable. The limit does not apply to fraud or fraudulent misrepresentation, death or personal injury caused by negligence, or liability that cannot lawfully be limited. It does not limit an individual's statutory data-protection rights. This business-customer cap does not apply to consumers.

The law of England and Wales governs these terms. Its courts have jurisdiction for business customers. Consumers retain mandatory rights to rely on the law and courts available in their place of residence. We give advance notice of material changes and do not retrospectively change a paid period's purchased offer. If a material prospective change is unacceptable, cancel before renewal or contact support to resolve access and export.

Privacy notice — version 2026-10-09

Adopted by Global Talent Leaders LTD on 9 October 2026.

Who is responsible

Global Talent Leaders LTD, trading as AI Agent Huddle, operates ONCE and CLAIM. Company number 14557865. Registered office: Summit House, Horsecroft Road, Harlow, Essex, England, CM19 5BN. Contact accounts@aiagenthuddle.com for privacy questions or requests.

We act as controller for our account administration, service security, support and billing records. Where a customer submits personal data in a workload on its organisation's instructions, our processing role and commitments belong in the customer processing schedule. The customer remains responsible for deciding what its workload should contain and for providing any necessary information to affected individuals.

Information we handle

Account information includes email, authentication identity, project details, discovery-source information, key prefixes/hashes and timestamps. ONCE stores operation keys, parameters, metadata, provider references, attempts and reconciliation evidence. CLAIM stores resource/agent identifiers, lease state, fencing tokens and coordination events. We also handle usage/security records, support correspondence, and billing customer/subscription/invoice identifiers, amounts and lifecycle state.

Use opaque identifiers and minimise personal information. Do not put credentials, authentication links, card details or sensitive personal information in parameters, metadata, resource identifiers or support messages. Provider credentials supplied through ONCE's dedicated headers are forwarded to the supported provider and are not stored in the operation ledger. Workload content itself is stored. Stripe hosts checkout; our application does not request card numbers.

Why we use it

We use account information to authenticate users, operate projects, answer support requests and administer subscriptions. Contract performance is the basis where the individual is our contracting customer; legitimate interests in administering the business relationship cover necessary corporate-contact administration.

We use security and usage information to isolate projects, control abuse, investigate failures and evaluate whether these services are useful. The legitimate interests are maintaining a reliable, secure service and assessing its operation, with access limited and internal/sandbox activity excluded from commercial success measurements. Required financial recordkeeping uses applicable legal obligations. The accompanying assessment limits these purposes to necessary account/security records and minimal evaluation evidence.

Customer workload processing follows the agreed instructions and processing schedule. No advertising mailing list or advertising tracking integration has been implemented. Technical quotas and billing states affect service access; no credit, employment or similar personal profiling service is offered.

Recipients and international processing

Supabase provides database/authentication; Vercel provides hosting/functions; Resend provides authentication and subscription-confirmation email; Stripe provides billing. GitHub or Stripe also receive the provider requests a customer instructs ONCE to make, using that customer's credential. These providers have their own terms and privacy information where they process data independently.

Our database/authentication supplier is Supabase Pte. Ltd.; hosting supplier is Vercel Inc.; transactional-email supplier is Plus Five Five, Inc., trading as Resend. The primary database and application functions are deployed in London. Resend sends this domain's email from Ireland and publishes that message/log/account data is stored in the United States. Supplier administration, support and subprocessors can involve processing outside the UK. London deployment does not mean UK-only processing.

The infrastructure accounts are operated on behalf of Global Talent Leaders LTD under standard online terms, without negotiated replacement agreements. Published supplier DPAs contain standard contractual clauses and UK-addendum provisions. Relevant references are the Supabase DPA, Vercel DPA, Resend DPA and their current subprocessor lists. Contact accounts@aiagenthuddle.com to request information about the relevant safeguards. Our release assessment records these destinations, readable-data exposure and safeguards. Supabase also uses Singapore administration and necessary US technical support. Contact us for information about the relevant safeguards.

Retention and closure

There is no automatic customer-ledger purge. Workload retention is assessed against ongoing service, deduplication and recovery needs, the customer's closure instructions and any specifically justified legal/security exception. Account, support and billing records require separate purpose-based retention decisions. Do not infer that deleting a ledger reverses an external provider action.

Our operating schedule calls for review at account closure and the Day-30 probe decision, minimisation of evaluation evidence, and a recorded purpose and next review for any retention exception. Supplier email copies have separate retention: Resend publishes 30-day email/log retention on Pro, with distinct backup and account-termination periods. This is not an automatic purge period for ONCE or CLAIM workload history.

On a verified request we assess export, closure and deletion under the applicable rights and processing instructions. Workload exports exclude privileged authentication/key material. Deletion from active processing and supplier backup expiry are separate; a restoration must reapply deletion records before reopening service. The operator procedure is docs/customer-data-requests.md. No immediate backup-erasure or fixed automatic 30/90-day guarantee is offered.

Your rights and choices

Depending on the processing and applicable law, individuals can request access, correction, erasure, restriction and portability. You can object to processing based on legitimate interests, including our service-security/evaluation purposes, by contacting accounts@aiagenthuddle.com. We assess requests and explain any applicable exception or necessary verification. Never send passwords, provider credentials or sign-in links to prove identity.

You may complain to the Information Commissioner's Office. Email and authentication are required to provide an account; without them we cannot sign you in. Discovery-source details are not a requirement for a paid subscription. Avoid submitting unnecessary personal data in workloads.

Customer workload processing schedule — version 2026-10-09

This schedule forms part of the adopted service terms where AI Agent Huddle processes personal data in customer workloads. The customer is the controller, or an authorised processor instructing us on its controller's behalf. Global Talent Leaders LTD trading as AI Agent Huddle is the processor. Account, billing and security-controller purposes are separately described in the privacy notice.

Instructions and processing particulars

We process workload data only on documented lawful instructions, including the customer's requests through the documented interfaces and transfer instructions in this schedule. If law requires other processing, we inform the customer beforehand unless prohibited. We notify the customer if we consider an instruction infringes applicable data-protection law and seek clarification before acting on it.

Purpose: authorised ONCE provider actions and recovery, or CLAIM coordination, isolation, usage accounting and associated incident response/support. Nature: receive, validate, store, retrieve, reconcile, transmit supported provider requests, export and delete records. Duration: service provision followed by verified export/closure/deletion. Subjects: customer personnel and people incidentally referenced in permitted minimal workload data. Categories: operation parameters, metadata, issue text, provider references, opaque resource/agent identifiers and timestamps. Do not submit special-category data, payment-card data or secrets in workload payloads. The customer determines lawful necessary payloads and informs affected people.

Confidentiality and security

We restrict personnel access to authorised duties and bind people with access to confidentiality. Measures include separate product database roles and credentials, project ownership checks, verified database TLS, hashed product keys, fixed provider hosts, rejection of redirects, bounded request sizes and usage, and exclusion of forwarded provider credentials from the ledger. Privileged operator access remains restricted. Supplier processing requires readable data where necessary; we do not promise end-to-end encryption against suppliers or an uptime certification.

Subprocessors and transfers

The customer generally authorises Supabase Pte. Ltd. (database/authentication, London primary database, Singapore administration and necessary US support); Vercel Inc. (hosting/functions, London functions with US builds/control-plane processing); and Plus Five Five, Inc., trading as Resend (authentication and subscription-confirmation email, Ireland sending with US message/log/account storage). Their published DPAs incorporate SCCs and UK-addendum mechanisms. Relevant lists: https://supabase.com/legal/subprocessor-list/June-1-2026.pdf ; https://security.vercel.com/ ; https://resend.com/legal/subprocessors . Optional supplier AI features are not part of these probes. Stripe performs billing under its applicable role; customer-instructed GitHub/Stripe actions use the customer's provider agreement and credential.

We impose equivalent data-protection obligations on subprocessors and remain responsible for their performance of those obligations. We inform customers in advance of intended direct additions or replacements, giving a reasonable opportunity to object on data-protection grounds through support. We assess objections, seek a practical alternative and, if unresolved, offer closure/export and refund unused paid service. We check upstream notices and current lists at the weekly Hunt review and before processing changes; we do not promise an upstream notice period beyond our supplier agreement. We provide information about applicable safeguards on request.

Assistance, incidents and accountability

Taking account of the processing and available information, we assist the customer with individual rights, security obligations, breach notifications and data-protection/consultation assessments. We forward workload rights requests for the customer's instructions rather than independently deciding the customer's purposes. We notify the customer without undue delay after becoming aware of a personal-data breach and provide available information about its nature, consequences and mitigation, with updates as facts become available.

We make information necessary to demonstrate compliance available and allow and contribute to proportionate audits, including inspections by the customer or its mandated auditor. Coordinate scope and secure access through support, avoiding disclosure of another customer's records or credentials. No provision removes an applicable regulator's powers or mandatory audit rights.

Return and deletion

At the customer's choice, on service end we return a verified tenant-scoped workload export or delete the workload data and copies, unless law requires retention. We agree and record the disposal plan through accounts@aiagenthuddle.com after ownership verification, resolving active subscriptions and safety implications. Restrict any legally retained exception and record its purpose and review date. There is no automatic ledger purge. Supplier backup expiry is separate from active deletion; deletion records must be reapplied before reopening restored data. The tested operator procedure excludes credentials and privileged authentication material from exports. It does not reverse an external provider action.

Support — version 2026-10-09

ONCE and CLAIM are operated by Global Talent Leaders LTD trading as AI Agent Huddle, company 14557865. Registered office: Summit House, Horsecroft Road, Harlow, Essex, England, CM19 5BN.

Contact accounts@aiagenthuddle.com for integration help, billing questions, cancellation problems, account closure or privacy requests. Include the product, approximate UTC time, operation or lease ID, HTTP status and a redacted error message. Never send API keys, provider credentials, session links, passwords or payment-card details. There is no advertised response-time or uptime SLA.

An uncertain ONCE result should be inspected and reconciled using its original key and operation ID. Do not generate a replacement key to bypass uncertainty. CLAIM applications must reject stale fencing tokens at downstream writes; lease expiration does not stop a process.

Subscriptions are separate for each product. Cancellation schedules the subscription to end at the current period boundary; inspect the account result to confirm it. Contact support if the result is uncertain. Refund requests are reviewed by the operator rather than promised automatically; statutory rights are unaffected. No automatic overage charges are offered.

Support actions are recorded without credentials. Internal test accounts are excluded from traction measurements.