# AiDi Embedded Analytics

AiDi Embedded Analytics is a pre-built fully customizable Analytics Portal that enables you to embed Power BI reports, dashboards, and Q\&A. AiDi process rich monitoring capabilities and is built as a Progressive Web App. It also integrates with Azure OpenAI and WhatsApp and allows you to instantly deliver Analytical Insights in a more efficient and simplified manner.

* No coding or development required
* Enabling faster time-to-value
* Azure OpenAI & WhatsApp integration

{% embed url="<https://www.youtube.com/watch?t=8s&v=HLj0DtZqEfI>" %}

### Jump right in

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Features</strong></td><td>App Features</td><td><a href="/files/UHF7zjwcq36zmrwja3ub">/files/UHF7zjwcq36zmrwja3ub</a></td><td></td><td><a href="/pages/7aUFmnCMx9m4smGncsXL">/pages/7aUFmnCMx9m4smGncsXL</a></td></tr><tr><td><strong>Getting Started</strong></td><td>How to get started</td><td><a href="/files/vxs1ER5I8VkIA0IaOqfo">/files/vxs1ER5I8VkIA0IaOqfo</a></td><td></td><td><a href="/pages/OUsIvvKIgY1m7ntJpRUO">/pages/OUsIvvKIgY1m7ntJpRUO</a></td></tr><tr><td><strong>User Access</strong></td><td>Give your users access to the reports</td><td><a href="/files/WqTZslyWgLz3XWQj63oY">/files/WqTZslyWgLz3XWQj63oY</a></td><td></td><td><a href="/pages/k0BPG7lmGkZIotoX59EA">/pages/k0BPG7lmGkZIotoX59EA</a></td></tr></tbody></table>


# Secure and scalable platform

Aidi is hosted on Microsoft Azure App Service - a highly scalable and self-patching web hosting service. AiDi uses Microsoft Entra ID to protect any identity and secure access to the reports and dashboards

<figure><img src="/files/6ZS4PcF9Ki5xtM9tiTDz" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
The user access to different resources are managed using Microsoft Entra Security Groups
{% endhint %}


# Embedded interactive reports

Provide users access to Power BI Embedded data-driven insights without leaving an application's interface.

<figure><img src="/files/URZVWhenJXFMpu0ECiCB" alt=""><figcaption><p>Revenue AiDi</p></figcaption></figure>

<figure><img src="/files/4vX39LuqisRUrf6KtCRx" alt=""><figcaption><p>Finance AiDi</p></figcaption></figure>


# Customizable user interface

## Branding

Match the branding and user experience of your own apps with fully customizable reports and dashboards. You can customise the banner image, your logo and the favcon and meta title for the PWA app.&#x20;

<figure><img src="/files/lutaF2wLXIRRoBGP1wVn" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
You can also customize the colour theme with a primary & secondary colour of your choice.
{% endhint %}

## Custom Domain

AiDi reports can be loaded on any custom domain of your choice. You can map an existing custom Domain Name System (DNS) name to App Service with no downtime.


# Sample Report Walkthrough

{% embed url="<https://www.youtube.com/watch?v=h_r10wFM5KQ>" %}
In this video, we showcase a sample report generated by AiDi, our AI-powered analytics solution designed to deliver actionable insights at your fingertips.
{% endembed %}


# Prerequisites

Everything you need to deploy & configure the AiDi App

### Azure Services Required

* [x] Azure Subscription
* [x] Power BI Tenant
* [x] Fabric Capacity or Power BI Embedded Capacity


# Installation Steps

1. **Subscribe The Application**

   The first step is to subscribe to the AiDi App. You can do it either from the Azure Portal or from Azure Marketplace

   1. [Azure Portal Link](https://portal.azure.com/?microsoft_azure_marketplace_ItemHideKey=d001376d-407a-4d2d-b5a2-0ab00168e91f#create/vizlake.vizlake_aidi_az1-preview/preview)
   2. [Azure marketplace link](https://azuremarketplace.microsoft.com/en-us/marketplace/apps/vizlake.vizlake_aidi_az1-preview?tab=Overview\&flightCodes=d001376d-407a-4d2d-b5a2-0ab00168e91f)

You need to select your azure subscription and a resource group to manage deployed resources and costs. Select the Plan, fill-in the details, review & click on subscribe

<div><figure><img src="/files/vkhKDYDzbrsqqmnj2EHu" alt=""><figcaption></figcaption></figure> <figure><img src="/files/sZS9huO83UikVWlMWvue" alt=""><figcaption></figcaption></figure></div>

2. **Provisioning** : Once Subscribed, the application will be provisioned and you will be configure the account

<div><figure><img src="/files/RxjBGPwh1gXipLEghBJ5" alt=""><figcaption></figcaption></figure> <figure><img src="/files/IMwa3JXTShQfEPjtGquR" alt=""><figcaption></figcaption></figure></div>

3. **Check & Confirm** : Once in the publisher portal, review the details and click on **Subscribe.**

<figure><img src="/files/gcLfr0NVO9ACnZpnz3cc" alt=""><figcaption></figcaption></figure>

4. **Status :** You will be taken to the Subscriptions page where the subscription details and the activation status is displayed

<figure><img src="/files/dgzhckSs3MXpmFXMy573" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/E7qmdgApC4sTf57j3d84" alt=""><figcaption><p>Pending for activation</p></figcaption></figure>

<figure><img src="/files/vW84kwnG41TtYjw75BkW" alt=""><figcaption><p>Activation Complete</p></figcaption></figure>

5. **Mail Confirmation** : You will also receive a mail confirmation from Microsoft regarding the activation

<figure><img src="/files/k9fT0jIfoSSOlraxL9LU" alt=""><figcaption></figcaption></figure>

6. **Management** : You can manage the subscription and billing from the Azure Portal effortlessly&#x20;

<figure><img src="/files/P9QbpmY2SPqnY4ADEN5g" alt=""><figcaption></figcaption></figure>

{% hint style="success" %}
Congratulations :tada: You have successfully subscribed and installed the AiDi Application
{% endhint %}

In the next session, we will see how to configure the app


# Configuring AiDi App

{% stepper %}
{% step %}

### [Admin Portal](/get-started/configuring-aidi-app/admin-portal)

{% endstep %}

{% step %}

### [Master Data Update](/get-started/configuring-aidi-app/master-data-update)

{% endstep %}

{% step %}

### [PowerBI Configuration](/get-started/configuring-aidi-app/powerbi-configuration)

{% endstep %}

{% step %}

### [Refresh PowerBI Metadata](/get-started/configuring-aidi-app/refresh-powerbi-metadata)

{% endstep %}

{% step %}

### [Workspace Permissions](/get-started/configuring-aidi-app/workspace-permissions)

{% endstep %}
{% endstepper %}


# Admin Portal

## Accessing the Portal

You can access the admin portal from [app.aidi.ai](https://app.aidi.ai/)

<figure><img src="/files/HTNEs1PNiCXUDwcisvAG" alt=""><figcaption></figcaption></figure>

## User Consent

You can login using your Microsoft Entra (Azure AD) credentials. During the initial login, you will be asked to grant consent to the AiDi app. If you are an admin, you can consent on behalf of your organization.&#x20;

<div><figure><img src="/files/4p7L4VLV5DCUFMED65dV" alt=""><figcaption></figcaption></figure> <figure><img src="/files/ADAH0u1I1gjpvTyIO3et" alt=""><figcaption></figcaption></figure></div>

## Admin Dashboard

Once inside the portal, you will be able to access the admin dashboard

<figure><img src="/files/pqfxh2e5xnvh6nc9akpd" alt=""><figcaption></figcaption></figure>


# Master Data Update

## Edit Menu

Click on the edit icon under the heading '**Actions**' to update your Organizations Master Data.

<figure><img src="/files/4x8xaG8ekDlxDwr6fyXI" alt=""><figcaption></figcaption></figure>

You can update your address, communication details, tax details, **custom domain** as well as your unique **branding** color theme with a primary and a secondary color.

## Hamburger Menu

Click on the hamburger menu to get a list of options which you can configure

<figure><img src="/files/2biuSj9rRVq62uHtQPuV" alt=""><figcaption></figcaption></figure>

You can set all the **Embedding** and **RLS** configurations from the above menu


# PowerBI Configuration

Settings to enable PowerBI Embedded

{% stepper %}
{% step %}

### [Azure App Registration](/get-started/configuring-aidi-app/powerbi-configuration/azure-app-registration)

{% endstep %}

{% step %}

### [PowerBI Admin Portal Configurations](/get-started/configuring-aidi-app/powerbi-configuration/powerbi-admin-portal-configurations)

{% endstep %}

{% step %}

### [AiDi App Configurations](/get-started/configuring-aidi-app/powerbi-configuration/aidi-app-configurations)

{% endstep %}
{% endstepper %}


# Azure App Registration

We need to create an App registration inside Microsoft Entra in your Azure Portal. We will be using this application to embed the PowerBi reports and dashboards.&#x20;

### 1. App Registration

You need to **register an application** and create a **client secret** for the same. Also note down the **expiry date** of the client secret.&#x20;

<figure><img src="/files/N8Uj8spSnCbESxfCaOLh" alt=""><figcaption></figcaption></figure>

Once the App has been registered, note down the **Application ID**

***

### 2. Create a client secret

{% stepper %}
{% step %}
From the **Manage** tab inside the application click on '**New client secret**'
{% endstep %}

{% step %}
Give a Description and set an expiry date. Then click '**Add**'
{% endstep %}

{% step %}
{% hint style="warning" %}
Copy the **Client secret value** immediately. You won't be able to get it afterwards
{% endhint %}
{% endstep %}
{% endstepper %}

<figure><img src="/files/RUvKNjQy7Zm2Lk6Y8ZJv" alt=""><figcaption></figcaption></figure>

***

### 3. Create a Security Group

Create a Security Group in Microsoft Entra and **add** the above application as a **member** into the security group


# PowerBI Admin Portal Configurations

Here we are granting necessary permissions to the azure application we created in the previous step, so that the application can access the PowerBi & Fabric APIs.

Add the Security Group in which the application is a member into the enabled list of the following settings:

<figure><img src="/files/dkGXbVQIH9o5sVrODDIN" alt=""><figcaption></figcaption></figure>


# AiDi App Configurations

The final step is to update the application details in AiDi App's Admin Portal.

1. Click on '**Pbi Config**' from the hamburger menu&#x20;

<figure><img src="/files/mRTSpjmxbInWXm6scV6t" alt=""><figcaption></figcaption></figure>

***

2. Update your Tenant ID, App ID, App Secret & the expiry date in the portal and click 'Submit'

<figure><img src="/files/9Nw8phaYkJGpFAy1SMRi" alt=""><figcaption></figcaption></figure>


# Refresh PowerBI Metadata

Once the [PowerBI configurations](/get-started/configuring-aidi-app/powerbi-configuration/aidi-app-configurations) are updated, you can proceed to  refresh the Powerbi Metadata.

1. Click on '**Pbi Refresh**' from the hamburger menu&#x20;

<figure><img src="/files/OKzvJYo7KdbmV8VjGITY" alt=""><figcaption></figcaption></figure>

2. You will see a notification once the refresh is successful

<figure><img src="/files/Kl5vnkbtgj6sxYwCH3BU" alt=""><figcaption></figcaption></figure>

3. Once the refresh is completed, you will be able to see the list of PowerBI resources grouped under the respective workspaces in your Dashboard

<figure><img src="/files/cmU1qgiJESyeoiKY5T3L" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Note that **only the metadata** has been synced by the application. In order to embed the reports or dashboards, you need to grant the [application](/get-started/configuring-aidi-app/powerbi-configuration/azure-app-registration) we created necessary [workspace permissions in the PowerBI Service](/get-started/configuring-aidi-app/workspace-permissions).

Also, you need to ensure that the workspace is assigned to a PowerBI Embedded or Fabric Capacity.
{% endhint %}


# Workspace Permissions

In order to embed the reports or dashboards, we need to grant the [Azure AD Application](/get-started/configuring-aidi-app/powerbi-configuration/azure-app-registration) we created necessary workspace permissions.

{% stepper %}
{% step %}
Go to the workspace in PowerBI service and select 'Manage Access'
{% endstep %}

{% step %}
Add the [Azure AD Application](/get-started/configuring-aidi-app/powerbi-configuration/azure-app-registration) as a member in the workspace&#x20;
{% endstep %}
{% endstepper %}

<figure><img src="/files/5laXw5eOaFYDR0IixMEx" alt=""><figcaption><p>1</p></figcaption></figure>

<figure><img src="/files/TzAksUm3EnbM7qspeDok" alt=""><figcaption><p>2</p></figcaption></figure>


# View Reports

Once [necessary permissions are granted](/get-started/configuring-aidi-app), you can view the reports and dashboards using the view button against the PowerBI resource from the Dashboard.

<figure><img src="/files/bWbvVAGTb5TysccECRvL" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/ZzUU5OBj97ZBP7H1hLEw" alt=""><figcaption></figcaption></figure>


# Accessing AiDi

{% embed url="<https://www.youtube.com/watch?v=-rifBW_KfzM>" %}


# User Access

## Security Groups

User Access to the AiDi application is managed through Microsoft Entra Security Groups

{% embed url="<https://learn.microsoft.com/en-us/microsoft-365/community/all-about-groups#microsoft-entra-security-groups>" fullWidth="false" %}

AiDi Application allows you to map a Security Group against a PowerBI Workspace. Once a mapping is done, the member users of that security group are given access to the PowerBI resources in the mapped workspaces. Follow the below steps to achieve this:

{% stepper %}
{% step %}

### Create a Security Group in Microsoft Entra

{% endstep %}

{% step %}

### Add your users as members of the Security Group

{% endstep %}

{% step %}

### Update the Security Groups in AiDi Admin Portal

Roles can be specified to enable **RLS**&#x20;
{% endstep %}

{% step %}

### Create a Security Group <--> Workspace Mapping in AiDi Admin Portal

{% endstep %}
{% endstepper %}


# Create a Security Group in Microsoft Entra

(to be done in Azure Portal)

1. Login to Azure Portal and navigate to Microsoft Entra ID

<figure><img src="/files/4rhrcNZrTk43MA4tMplX" alt=""><figcaption></figcaption></figure>

2. Navigae to **Groups** under 'Manage' section

<figure><img src="/files/MKjhIrtukctkZEeEC6X8" alt=""><figcaption></figcaption></figure>

3. Click on '**New group**'

<figure><img src="/files/na3xlyWxQdMHTkb7aR8t" alt=""><figcaption></figcaption></figure>

4. Select the group type as 'Security' and give a name and description to the group. Add the users as members of the security group (you can add/modify members later as well as per requirement). Click on 'Create' once done.

<figure><img src="/files/D8C3XrwAFr2EOaDxwngF" alt=""><figcaption></figcaption></figure>

5. Once the security group is created, note the Object ID of the group&#x20;

<figure><img src="/files/hvvn3CvKNB4EZxOX6Iyo" alt=""><figcaption></figcaption></figure>


# Add Security Group in AiDi App

(to be done in AiDi Admin Portal)

1. Click on '**Security groups**' from the hamburger menu in AiDi Admin Portal

<figure><img src="/files/gJ7Cl9opKn3i3AxKgOMY" alt=""><figcaption></figcaption></figure>

2. In the Client Group 'Add' menu, give the particulars of the [Security Group](/user-access/user-access/create-a-security-group-in-microsoft-entra) we created

<figure><img src="/files/fuTRpIsOWR3mBnVpwfRn" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note that if you have an **RLS** role defined in your PowerBI dataset and wants it to be applied for the users in this security group, you need to mention the role here. You can pass multiple roles by way of a comma separated list
{% endhint %}

3. Once you click Submit, you will receive a successful creation notification; and you can proceed for [workspace group mapping](/user-access/user-access/security-group-less-than-greater-than-workspace-mapping)

<figure><img src="/files/wgpwXw9kApjPwqoeXpIe" alt=""><figcaption></figcaption></figure>


# Security Group <--> Workspace Mapping

AiDi Application allows you to map a Security Group against a PowerBI Workspace. Once a mapping is done, the member users of that security group are given access to the PowerBI resources in the mapped workspaces.

1. Click on '**Workspace group map**' from the hamburger menu in AiDi Admin Portal

<figure><img src="/files/VYBqOIEwpKNKKXPMFkIl" alt=""><figcaption></figcaption></figure>

2. Select the security group and workspace from the dropdown list and assign relevant permissions

<figure><img src="/files/CPyERNLP6DlGNTXeXA04" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/QrfYf6iVjxrGzAhS3FA2" alt=""><figcaption></figcaption></figure>


# User Login

Once the steps mentioned in [User Access](/user-access/user-access) are completed, the user will be able to log in to the portal and access the reports.

Access the admin portal from [app.aidi.ai](https://app.aidi.ai/) or from your Custom Domain and login using the Microsoft Entra ID

<figure><img src="/files/HTNEs1PNiCXUDwcisvAG" alt=""><figcaption></figcaption></figure>

User will be taken to his Dashboard where the resources from the Workspaces mapped to his Security Groups will be displayed

<figure><img src="/files/KAm8ibvaMvD2Tmi58Hac" alt=""><figcaption></figcaption></figure>

You can view the reports and dashboards using the view button against the PowerBI resource from the Dashboard.

<figure><img src="/files/hGpzlDZA4P945UhL1TmB" alt=""><figcaption></figcaption></figure>


# AiDi Revenue Dashboard

Plug-and-play detailed PowerBI reports for revenue/sales analysis

Kickstart your analytics <mark style="color:green;">**without any coding or ETL expertise**</mark>. AiDi Revenue Dashboards allows you to experience the cool features of PowerBI reports with an option to <mark style="color:green;">**connect and visualize your own data**</mark> in an <mark style="color:green;">**excel format**</mark>. You can connect and instantiate the APP securely with your own Microsoft accounts. <mark style="color:green;">**No data moves out of your environment**</mark>.

<figure><img src="/files/dtQlghwGXRC5gN8g7qGz" alt=""><figcaption></figcaption></figure>

This detailed report makes use of all the latest and awesome Power BI features such as Field Parameters, Mobile views, Dynamic Reports, Drill-Through etc.

The free version of this report lets you experiance all the features with a row limit of 1000 rows. If you wish to refresh more of your historical data without any row limits, then head over to our website and check out our purchase options.

We offer a subscription option to let you refresh all your historical data using this AppSource version, this version can be full refreshed, however the data model, Power Query applied steps, and DAX cannot be edited.

{% embed url="<https://account.aidi.ai/subscribe/dafc87b6dc14c7eb18155b3bfe10c08c6a2bba0f6b053217afe8ded60e8a6aa6/aidi-rev-std>" %}


# Connect Your Data

Securely Connect Your Own Data

## 1. Download Templates

You need to have your Sales data along with the relevant masters such as Customer Master & Product Master. Download the following sample date and make sure you follow the same template.

{% file src="/files/nhAOfjRAGnAG59jI1X2n" %}
Sales Register
{% endfile %}

{% file src="/files/sIbp6U3niBxnfbtub0f8" %}
Item Master
{% endfile %}

{% file src="/files/1tH4mkamwZM70AjzSyB1" %}
Customer/Store/BP Master
{% endfile %}

## 2. Update the files with your own data

Replace the file contents with your own data.&#x20;

## 3. Upload the files into your Onedrive/Sharepoint

Simply upload the files to your Onedrive folder or Sharepoint site and make a note of the path.

The SharePoint path will look like this : [https://\<yourdomain>.sharepoint.com/sites/\<sitename>/Shared Documents/\<folder structure>/customer\_master.csv](https://vizlake.sharepoint.com/sites/VizlakeTeam/Shared%20Documents/Internal%20Activities/Demo/customer_master.csv)

### How to get path of the file in Onedrive

1. Go to your OneDrive or SharePoint online folder
2. Click on the file -> the details will be opened on the right pane
3. Scroll down and you will see the path -> simply copy it

<figure><img src="/files/AUXzHQpozQ1ctF9SVZP0" alt=""><figcaption></figcaption></figure>


# Privacy Policy

## Vizlake Privacy Statement

Your privacy is important to us. This privacy statement explains the personal data Vizlake processes, how Vizlake processes it, and for what purposes. This Privacy Policy statement relates to information collected by Vizlake Analytics Private Limited (referred to in this Privacy Policy as “Vizlake” “we” or “us” or “our”) through your use of our website and our Services, features, and information available on our website (which are collectively referred to in this Privacy Policy as the “AiDi Embedded Analytics” or “AiDi” or “Our Products and Services”).

## Data we collect

The data we collect depends on the context of your interactions with Vizlake. While subscribing to AiDi, you will be required to provide us with information (including personally identifiable information and non-personally identifiable information). In addition, we may obtain your personally identifiable information from you if you identify yourself to us by sending us an e-mail with questions or comments. Depending on your use of our products or services, we collect two types of information: Personally identifiable information and non-personally identifiable information.

## How we use your data

We do not sell any data, including your personal data. We will only process your personal data in accordance with applicable data protection and privacy laws. Vizlake uses the data we collect to provide you better experiences. In particular, we use data to:

* Provide our products and services, which includes updating, securing, and troubleshooting, as well as providing support. It also includes sharing data, when it is required to provide the service or carry out the transactions you request.
* Improve and develop our products.
* Personalize our products and make recommendations.
* Advertise and market to you, which includes sending promotional communications, targeting advertising, and presenting you with relevant offers.

We also use the data to operate our business, which includes analyzing our performance, meeting our legal obligations, developing our workforce, and doing research.

We are committed to protecting the privacy of children. Our Products and Services are not designed for or directed to children under the age of 13. We do not collect personally identifiable information from any person we actually know is under the age of 13.

In general, we use the information collected to provide you with a great overall experience using Our Products and Services, to help us understand who uses our Our Products and Services, for internal operations such as operating and improving Our Products and Services, to contact you for customer service and billing purposes, and to facilitate the delivery of our advertising in some cases. We use your information to send you a welcome e-mail after you create an account, when you are invited to AiDi Embedded Analytics Portal, or when you sign up for a demo or webinar. We also use your information to send other e-mail communication related to Our Products and Services.

## Storing and Transferring of Data

Your data, including personal data that we collect from you, may be transferred to, stored at and processed by us and other third parties outside the country in which you reside, including, but not limited to India, where data protection and privacy regulations may not offer the same level of protection as in other parts of the world. By using our platform, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this policy. Your team’s project and report data will never be transferred to third parties. The only data we share with third parties is for analytics, error tracking, and marketing.

We will only retain your personal data as long as reasonably required for you to use the Site/Application(s) and/or to provide you with the Services unless a longer retention period is required or permitted by law (for example, for regulatory purposes).

## How Secure is your data

Vizlake Analytics brings simplicity, speed, and scale to our customer’s Data Analytics by using cutting edge analytics technologies and tools and smart minds to put data to work. We intend to optimize business operations for creating measurable new Net Profit. Our uniqueness identify our client’s business needs and not just limit to what the client asks for. &#x20;

Our organization is committed to preserving the Confidentiality, Integrity, Availability and Legality of all our client data as well as our own information assets. Service availability and security of client data are our top priorities. Our objective is to manage the information security risks to acceptable levels to ensure compliance with national and international data protection and privacy regulation/ legislations as well as meet the contractual obligations of our customers.&#x20;

Business Partners and Employees of Vizlake are required to comply with the Information Security Policies, the ISMS (Information Security Management Systems) based on ISO 27001:2022 that implements this policy as well as the requirements Data Protection Regulations in the regions our customers are located in.&#x20;

Information security requirements will continue to be aligned with Vizlake business objectives and obligations, aligned to the clients and their relevant requirements to meet the business objectives. The Information Security Management Systems (ISMS) is intended to be an enabling mechanism for information sharing, for data analytics activities, for data modelling and for reducing risks to information security to acceptable levels.&#x20;

The Information Risk Management framework at Vizlake provides the context for identifying, assessing, evaluating, and controlling information-related risks through the establishment and maintenance of an Information Security Management System. &#x20;

The Classification of Information, Risk Assessment, Business Impact Assessment, Statement of Applicability and Risk Treatment Plan identifies how information related risks are controlled and managed. The IT Director is responsible for the management and maintenance of the Information Security Management System.&#x20;

Business continuity and contingency plans, Information Security Continuity Plans, avoidance of malware and internal and external hackers, access control to systems are fundamental to this policy. Any incident or activity that causes or may cause a break down in the confidentiality, integrity or availability of the physical or electronic information assets of the Organization and its clients shall be treated as a security incident and needs to be reported, investigated, root cause identified, and corrective and preventive actions initiated.&#x20;

The ISMS is the Information Security Management System, of which this policy, the ‘Information Security Manual’ and other supporting and related documentation is a part, and which has been designed in accordance with the specification contained in ISO 27001: 2022. The ISMS is subject to continuous, systematic review and improvement. &#x20;

## Outside Contractors

We may employ independent contractors, vendors, and suppliers (collectively, “Outside Contractors”) to provide specific services and products related to Our Products and Services, such as hosting, credit card processing and fraud screening, and mailing list hosting for Our Products and Services. In the course of providing products or services to us, these Outside Contractors may have access to information collected through Our Products and Services, including your personally identifiable information. We require that these contractors agree to (1) protect the privacy of your personally identifiable information consistent with this Privacy Policy (2) not use or disclose your personally identifiable information for any purpose other than providing us with the products or services for which we contracted or as required by law.

## Sale of Business

We reserve the right to transfer information to a third party in the event of a sale, merger or other transfer of all or substantially all of the assets of Vizlake Analytics or any of its Corporate Affiliates (as defined herein), or that portion of Vizlake or any of its Corporate Affiliates to which the Service relates, or in the event that we discontinue our business or file a petition or have filed against us a petition in bankruptcy, reorganization or similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.

## Affiliates

We may disclose information (including personally identifiable information) about you to our Corporate Affiliates. For purposes of this Privacy Policy, “Corporate Affiliate” means any person or entity which directly or indirectly controls, is controlled by or is under common control with Vizlake Analytics, whether by ownership or otherwise. Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Privacy Policy.

## Laws and Legal Rights

We may disclose your information (including personally identifiable information) if we believe in good faith that we are required to do so to comply with an applicable statute, regulation, rule or law, a subpoena, a search warrant, a court or regulatory order, or other valid legal process. We may disclose personally identifiable information in special circumstances when we have reason to believe that disclosing this information is necessary to identify, contact, or bring legal action against someone who may be violating our Terms of Service, to detect fraud, or to protect the safety and/or security of our users, Our Products or Services, or the general public. We are subject to the investigatory and enforcement powers of the Laws in India. We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

## Contact Details

If you have any questions or comments about this Privacy Policy or feel that we are not abiding by the terms of this Privacy Policy, please contact our Privacy Agent in any of the following ways:

Email : <info@vizlake.com>

Postal mail or courier: Attn : Privacy Officer, Vizlake Analytics Private Limited No.6/858-M, 2nd Floor, Suite# 287 Valamkottil Towers, Judgemukku, Thrikkakara P.O Kakkanad, Ernakulam, Kerala, India - 682021


# Terms and Conditions

This Standard Contract ("Agreement") is between you ("you" or "Customer") and Vizlake Analytics Private Limited ("Vizlake" or "Publisher" or "Service Provider") from which you are procuring Offerings (defined below) and governs your use of Offerings purchased through either our Website or through our affiliates or through Microsoft AppSource or Azure Marketplace (collectively, "Marketplace").

This Agreement is the parties' entire agreement on this subject and merges and supersedes all related prior and contemporaneous agreements. By agreeing to these terms, you represent and warrant that you have the authority to accept this Agreement, and you also agree to be bound by its terms. This Agreement applies to all Orders entered into under this Agreement.

### 1. LICENSE TO OFFERINGS <a href="#id-1-license-to-offerings" id="id-1-license-to-offerings"></a>

1.1  **License grant**. Offerings are licensed and not sold. Upon acceptance of an Order, and subject to Customer's compliance with this Agreement, Vizlake grants Customer a nonexclusive and limited license to use the ordered Offerings. These licenses are solely for Customer's own use and business purposes and are nontransferable except as expressly permitted under this Agreement or applicable law.

Offerings may contain or be provided with components that are subject to open-source software licenses. Any use of those components may be subject to additional terms and conditions and Customer agrees that any applicable licenses governing the use of the components will be incorporated by reference in this Agreement.

1.2  **Duration of licenses**. Licenses granted on a subscription basis expire at the end of the applicable subscription period set forth in the Order, unless renewed. Licenses granted for metered Offerings billed periodically based on usage continue as long as Customer continues to pay for its usage of the Offerings. All other licenses become perpetual upon payment in full.

1.3  **End Users**. Customer will control access to and use of the Offerings by End Users and is responsible for any use of the Offerings that does not comply with this Agreement.

1.4  **Affiliates**. Customer may order Offerings for use by its Affiliates. If it does, the licenses granted to Customer under this Agreement will apply to such Affiliates, but Customer will have the sole right to enforce this Agreement against Publisher. Customer will remain responsible for all obligations under this Agreement and for its Affiliates' compliance with this Agreement and any applicable Order(s).

1.5  **Reservation of Rights**. Vizlake reserves all rights not expressly granted in this Agreement. Offerings are protected by copyright and other intellectual property laws and international treaties. No rights will be granted or implied by waiver or estoppel. Rights to access or use Offerings on a device do not give Customer any right to implement Publisher's patents or other intellectual property in the device itself or in any other software or devices.

1.6  **Restrictions**. Except as expressly permitted in this Agreement, Documentation or an Order, Customer must not (and is not licensed to):

> **a.**  copy, modify, reverse engineer, decompile, or disassemble any Offering, or attempt to do so;
>
> **b.**  install or use any third-party software or technology in any way that would subject Vizlake's intellectual property or technology to any other license terms;
>
> **c.**  work around any technical limitations in an Offering or restrictions in Documentation;
>
> **d.**  separate and run parts of an Offering on more than one device;
>
> **e.**  upgrade or downgrade parts of an Offering at different times;
>
> **f.**  use an Offering for any unlawful purpose;
>
> **g.**  transfer parts of an Offering separately; or
>
> **h.**  distribute, sublicense, rent, lease, or lend any Offerings, in whole or in part, or use them to offer hosting services to a third party.

1.7  **License transfers**. Customer may only transfer fully-paid, perpetual licenses to (1) an Affiliate or (2) a third party solely in connection with the transfer of hardware to which, or employees to whom, the licenses have been assigned as part of (A) a divestiture of all or part of an Affiliate or (B) a merger involving Customer or an Affiliate. Upon such transfer, Customer must uninstall and discontinue using the licensed Offering and render any copies unusable. Customer must notify Publisher of a License transfer and provide the transferee a copy of this Agreement and any other documents necessary to show the scope, purpose, and limitations of the licenses transferred. Attempted license transfers that do not comply with this section are void.

1.8  **Feedback**. Any Feedback is given voluntarily, and the provider grants to the recipient, without charge, a non-exclusive license under provider's owned or controlled non-patent intellectual property rights to make, use, modify, distribute, and commercialize the Feedback as part of any of recipient's products and services, in whole or in part and without regard to whether such Feedback is marked or otherwise designated by the provider as confidential. The provider retains all other rights in any Feedback and limits the rights granted under this section to licenses under its owned or controlled non-patent intellectual property rights in the Feedback (which do not extend to any technologies that may be necessary to make or use any product or service that incorporates, but are not expressly part of, the Feedback, such as enabling technologies).

### 2. PRIVACY <a href="#id-2-privacy" id="id-2-privacy"></a>

2.1  **EU Standard Contractual Clauses**. To the extent applicable, the parties will abide by the requirements of European Economic Area and Swiss data protection law regarding the collection, use, transfer, retention, and other processing of Personal Data from the European Economic Area and Switzerland. All transfers of Customer Data out of the European Union, European Economic Area, and Switzerland will be governed by the Standard Contractual Clauses, as designated by the European Commission, made available by the Publisher at the applicable URL for such terms or as otherwise communicated to Customer.

2.2  **Personal Data**. Customer consents to the processing of Personal Data by Publisher and its Affiliates, and their respective agents and Subcontractors, as provided in this Agreement. Before providing Personal Data to Publisher, Customer will obtain all required consents from third parties (including Customer's contacts, partners, distributors, administrators, and employees) under applicable privacy and Data Protection Laws.

2.3  **Processing of Personal Data; GDPR**. To the extent Publisher is a processor or subprocessor of Personal Data subject to the GDPR, the Standard Contractual Clauses govern that processing and the parties also agree to the following terms in this subsection ("Processing of Personal Data; GDPR"):

> **a.**  **Processor and Controller Roles and Responsibilities**. Customer and Publisher agree that Customer is the controller of Personal Data and Publisher is the processor of such data, except when (a) Customer acts as a processor of Personal Data, in which case Publisher is a subprocessor or (b) stated otherwise in any Offering-specific terms. Publisher will process Personal Data only on documented instructions from Customer. In any instance where the GDPR applies and Customer is a processor, Customer warrants to Publisher that Customer's instructions, including appointment of Processor as a processor or subprocessor, have been authorized by the relevant controller.
>
> **b.**  **Processing Details**. The parties acknowledge and agree that:
>
> > **i.**  the subject-matter of the processing is limited to Personal Data within the scope of the GDPR;
> >
> > **ii.**  the duration of the processing will be for the duration of the Customer's right to use the Offering and until all Personal Data is deleted or returned in accordance with Customer instructions or the terms of this Agreement;
> >
> > **iii.**  the nature and purpose of the processing will be to provide the Offering pursuant to this Agreement;
> >
> > **iv.**  the types of Personal Data processed by the Offering include those expressly identified in Article 4 of the GDPR; and
> >
> > **v.**  the categories of data subjects are Customer's representatives and end users, such as employees, contractors, collaborators, and customers, and other data subjects whose Personal Data is contained within any data made available to Publisher by Customer.
>
> **c.**  **Data Subject Rights; Assistance with Requests**. Publisher will make information available to Customer in a manner consistent with the functionality of the Offering and Publisher's role as a processor of Personal Data of data subjects and the ability to fulfill data subject requests to exercise their rights under the GDPR. Publisher will comply with reasonable requests by Customer to assist with Customer's response to such a data subject request. If Publisher receives a request from Customer's data subject to exercise one or more of its rights under the GDPR in connection with an Offering for which Publisher is a data processor or subprocessor, Publisher will redirect the data subject to make its request directly to Customer. Customer will be responsible for responding to any such request including, where necessary, by using the functionality of the Offering. Publisher will comply with reasonable requests by Customer to assist with Customer's response to such a data subject request.
>
> **d.**  **Use of Subprocessors**. Customer consents to Publisher using the subprocessors listed at the applicable Publisher URL or as otherwise communicated to Customer. Publisher remains responsible for its subprocessors' compliance with the obligations herein. Publisher may update its list of subprocessors from time to time, by providing Customer at least 14 days notice before providing any new subprocessor with access to Personal Data. If Customer does not approve of any such changes, Customer may terminate any subscription for the affected Offering without penalty by providing, prior to expiration of the notice period, written notice of termination that includes an explanation of the grounds for non-approval.
>
> **e.**  **Records of Processing Activities**. Publisher will maintain all records required by Article 30(2) of the GDPR and, to the extent applicable to the processing of Personal Data on behalf of Customer, make them available to Customer upon request.

2.4  **Security**. Publisher will take appropriate security measures that are required by Data Protection Laws and in accordance with good industry practice relating to data security.

2.5  **Support Data**. Publisher may collect and use Support Data internally to provide technical support for the Offering. Publisher will not use Support Data for any other purpose unless otherwise agreed in writing by the parties.

### 3. CONFIDENTIALITY <a href="#id-3-confidentiality" id="id-3-confidentiality"></a>

3.1  **Non-Disclosure Agreement**. The parties will treat all confidential information exchanged between the parties under this Agreement in accordance with the separate nondisclosure agreement ("NDA") executed by the parties. If no separate NDA is in effect, the following provisions apply to the parties' exchange of confidential information.

3.2  **Confidential Information**. "Confidential Information" is non-public information that is designated "confidential" or that a reasonable person should understand is confidential, including, but not limited to, Customer Data, Support Data, the terms of this Agreement, and Customer's account authentication credentials. Confidential Information does not include information that: (1) becomes publicly available without a breach of a confidentiality obligation; (2) the receiving party received lawfully from another source without a confidentiality obligation; (3) is independently developed; or (4) is a comment or suggestion volunteered about the other party's business, products, or services.

3.3  **Protection of Confidential Information**. Each party will take reasonable steps to protect the other's Confidential Information and will use the other party's Confidential Information only for purposes of the parties' business relationship. Neither party will disclose Confidential Information to third parties, except to its Representatives, and then only on a need-to-know basis under nondisclosure obligations at least as protective as this Agreement. Each party remains responsible for the use of Confidential Information by its Representatives and, in the event of discovery of any unauthorized use or disclosure, must promptly notify the other party.

3.4  **Disclosure required by law**. A party may disclose the other's Confidential Information if required by law, but only after it notifies the other party (if legally permissible) to enable the other party to seek a protective order.

3.5  **Duration of Confidentiality obligation**. These obligations apply: (1) for Customer Data, until it is deleted by Publisher; and (2) for all other Confidential Information, for a period of five years after a party receives the Confidential Information.

### 4. SERVICE LEVEL AGREEMENTS (SLA) <a href="#id-4-service-level-agreements-sla" id="id-4-service-level-agreements-sla"></a>

Publisher may offer further availability and support obligations for an Offering. Such service level agreement ("SLA") will be made available by the Publisher at the applicable URL for such SLA or as otherwise communicated to Customer.

### 5. VERIFYING COMPLIANCE <a href="#id-5-verifying-compliance" id="id-5-verifying-compliance"></a>

5.1  Customer must keep records relating to Offerings it and its Affiliates use or distribution. At Publisher's expense, Publisher may verify Customer's and its Affiliates' compliance with this Agreement by directing an independent auditor (under nondisclosure obligations) to conduct an audit or ask Customer to complete a self-audit process. Customer must promptly provide any information and documents that Publisher or the auditor reasonably requests related to the verification and access to systems running the Offerings. If verification or self-audit reveals any unlicensed use, Customer must order sufficient licenses to cover the period of its unlicensed use. The audits may be conducted more frequently, if required by the party's auditors and/or regulators, of books and records related to this Agreement. The expenses for all such audit will be borne by the party conducting the audit. All information and reports related to the verification process will be Confidential Information and used solely to verify compliance.

5.2  Upon request, Publisher will make available to Customer all information necessary to conduct an audit and demonstrate compliance under GDPR provisions for the processing of Personal Data. Customer may request information through a security questionnaire or self-attestation.

### 6. REPRESENTATION AND WARRANTIES <a href="#id-6-representation-and-warranties" id="id-6-representation-and-warranties"></a>

6.1  Publisher continuously represents and warrants that:

> **a.**  it has full rights and authority to enter into, perform under, and grant the rights in, this Agreement;
>
> **b.**  its performance will not violate any agreement or obligation between it and any third party;
>
> **c.**  the Offering will substantially conform to the Documentation;
>
> **d.**  the Offering will not:
>
> > **i.**  to the best of Publisher's knowledge, infringe or violate any third party patent, copyright, trademark, trade secret, or other proprietary right; or
> >
> > **ii.**  contain viruses or other malicious code that will degrade or infect any products, services, software, or Customer's network or systems, and
>
> **e.**  while performing under this Agreement, Publisher will comply with law, including Data Protection Laws and Anti-Corruption Laws, and will provide training to its employees regarding Anti-Corruption Laws.

6.2  **Disclaimer**. Except as expressly stated in this Agreement, the Offering is provided as is. To the maximum extent permitted by law, Publisher disclaims any and all other warranties (express, implied or statutory, or otherwise) including of merchantability or fitness for a particular purpose, whether arising by a course of dealing, usage or trade practice, or course of performance.

### 7. DEFENSE OF THIRD-PARTY CLAIMS <a href="#id-7-defense-of-third-party-claims" id="id-7-defense-of-third-party-claims"></a>

7.1  **By Customer**. Customer will defend Publisher and its Affiliates from and against any and all third party claims, actions, suits, proceedings arising from or related to: Customer's or any authorized user's violation of this Agreement or user terms (a "Claims Against Publisher"), and will indemnify Publisher and its Affiliates for all reasonable attorney's fees incurred and damages and other costs finally awarded against Publisher or its Affiliates in connection with or as a result of, and for amounts paid by Publisher or its Affiliates under a settlement Customer approves of in connection with a Claim Against Publisher. Publisher must provide Customer with prompt written notice of any Claims Against Publishers and allow Customer the right to assume the exclusive defense and control of the claim and cooperate with any reasonable requests assisting Customer's defense and settlement of such matter.

7.2  **By Publisher**. Publisher will defend Customer from and against any and all third party claims, actions, suits, proceedings, and demands alleging that: (i) the use of the Offering as permitted under the Contract infringes or misappropriates a third party's intellectual property rights and (ii) any violation of applicable law including Data Protection Laws (a "Claim Against Customer"), and will indemnify Customer for all reasonable attorney's fees incurred and damages and other costs finally awarded against Customer in connection with or as a result of, and for amounts paid by Customer under a settlement Publisher approve of in connection with a Claim Against Customer; provided, however, that the Publisher has no liability if a Claim Against Customer arises from: (1) Customer Data or non-Publisher products, including third-party software; and (2) any modification, combination or development of the Offering that is not performed or authorized in writing by Publisher, including in the use of any application programming interface (API). Customer must provide Publisher with prompt written notice of any Claim Against Customer and allow Publisher the right to assume the exclusive defense and control and cooperate with any reasonable requests assisting Publisher's defense and settlement of such matter. This section states Publisher sole liability with respect to, and Customer's exclusive remedy against Publisher for, any Claim Against Customer.

7.3  Notwithstanding anything contained in the above subsections (a) and (b), (1) an indemnified party will always be free to choose its own counsel if it pays for the cost of such counsel; and (2) no settlement may be entered into by an indemnifying party, without the express written consent of the indemnified parties (such consent not to be unreasonably withheld), if: (A) the third party asserting the claim is a government agency; (B) the settlement arguably involves the making of admissions by the indemnified parties; (C) the settlement does not include a full release of liability for the indemnified parties; or (D) the settlement includes terms other than a full release of liability for the indemnified parties and the payment of money.

### 8. LIMITATION OF LIABILITY <a href="#id-8-limitation-of-liability" id="id-8-limitation-of-liability"></a>

For each Offering, each party's maximum, aggregate liability to the other under this Agreement is limited to direct damages finally awarded in an amount not to exceed the amounts Customer was required to pay for the Offerings during the term of the applicable licenses, subject to the following:

> **a.**  **Subscriptions**. For Offerings ordered on a subscription basis, Publisher's maximum liability to Customer for any incident giving rise to a claim will not exceed the amount Customer paid for the Offering during the 12 months before the incident or $500,000, whichever is greater.
>
> For Offerings ordered on a subscription basis, Publisher's maximum liability to Customer for any unauthorized access, use, or disclosure of Customer Data due to a breach of Publisher's obligations under Section II(6) (Security), Publisher's maximum liability to Customer will not exceed two times (2x) the amount Customer paid for the Offering during the 12 month before the incident or $2,000,000, whichever is greater.
>
> **b.**  **Free Offerings and distributable code**. For Offerings provided free of charge and code that Customer is authorized to redistribute to third parties without separate payment to Publisher, Publisher's liability is limited to direct damages finally awarded up to US$5,000.
>
> **c.**  **No Indirect Damages**. In no event will either party be liable for indirect, incidental, special, punitive, or consequential damages, or loss of use, loss of profits, or interruption of business, however caused or on any theory of liability.
>
> **d.**  **Exceptions**. No limitation or exclusions will apply to liability arising out of either party's: (1) confidentiality obligations under Section 3 (except for liability related to Customer Data, which will remain subject to the limitations and exclusions above); (2) defense obligation under Section 7; (3) violation of the other party's intellectual property rights; or (4) gross negligence, willful misconduct, or fraud.

### 9. PRICING AND PAYMENT <a href="#id-9-pricing-and-payment" id="id-9-pricing-and-payment"></a>

Vizlake will invoice and charge Customer under the terms of the applicable Order.

### 10. TERM AND TERMINATION <a href="#id-10-term-and-termination" id="id-10-term-and-termination"></a>

10.1  **Term**. This Agreement is effective until terminated by a party, as described below. The term for each Order will be set forth therein.

10.2  **Termination without cause**. Unless otherwise set forth in an Order, either party may terminate this Agreement or any Order without cause on 60 days' notice. Termination without cause will not affect Customer's perpetual licenses, and licenses granted on a subscription basis will continue for the duration of the subscription period(s), subject to the terms of this Agreement. Publisher will not provide refunds or credits for any partial subscription period(s) if the Agreement or an Order is terminated without cause.

10.3  **Termination for cause**. Without limiting other remedies it may have, either party may terminate this Agreement or any Order immediately on notice if (i) the other party materially breaches the Agreement or an Order, and fails to cure the breach within 30 days after receipt of notice of the breach; or (ii) the other party becomes Insolvent. Upon such termination, the following will apply:

> **a.**  All licenses granted under this Agreement will terminate immediately except for fully-paid, perpetual licenses.
>
> **b.**  All amounts due under any unpaid invoices will become due and payable immediately. For metered Offerings billed periodically based on usage, Customer must immediately pay for unpaid usage as of the termination date.
>
> **c.**  If Publisher is in breach, Customer will receive a credit for any subscription fees, including amounts paid in advance for unused consumption for any usage period after the termination date.

10.4  **Suspension**. Publisher may suspend use of the Offering without terminating this Agreement during any period of material breach. Publisher will give Customer reasonable notice before suspending the Offering. Suspension will only be to the extent reasonably necessary.

10.5  **Refund**. For Offerings ordered on a subscription basis that are $100,000 or more, if Publisher breaches any of the foregoing warranties and those breaches remain uncured for 30 days, Customer may terminate this Agreement and Publisher will provide Customer a full refund of all fees paid to Publisher.

10.6  **Survival**. The terms of this Agreement, including the applicable Order, that are likely to require performance, or have application to events that may occur, after the termination or expiration of this Agreement or any Order, will survive termination or expiration, including all indemnity obligations and procedures.

### 11. MISCELLANEOUS <a href="#id-11-miscellaneous" id="id-11-miscellaneous"></a>

11.1  **Entire Agreement**. This Agreement supersedes all prior and contemporaneous communications, whether written or oral, regarding the subject matter covered in this Agreement. If there is a conflict between any parts of this Agreement, the following order of precedence will apply:

> **a.**  Order;
>
> **b.**  this Agreement;
>
> **c.**  Service Level Agreement (SLA); and
>
> **d.**  Documentation.

11.2  **Independent contractors**. The parties are independent contractors. Customer and Publisher each may develop products independently without using the other's Confidential Information.

11.3  **Agreement not exclusive**. Customer is free to enter into agreements to license, use, and promote the services of others.

11.4  **Amendments**. Unless otherwise agreed in a writing signed by both parties, Publisher will not change the terms of this Agreement, including privacy terms, during the term of this Agreement.

11.5  **Assignment**. Either party may assign this Agreement to an Affiliate, but it must notify the other party in writing of the assignment. Customer consents to the assignment to an Affiliate or third party, without prior notice, of any rights Publisher may have under this Agreement to receive payment and enforce Customer's payment obligations, and all assignees may further assign such rights without further consent. Furthermore, either party may assign this Agreement without the consent of the other party in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all of such party's assets. Any other proposed assignment of this Agreement must be approved by the non-assigning party in writing. Assignment will not relieve the assigning party of its obligations under the assigned Agreement. Any attempted assignment without required approval will be void.

11.6  **Severability**. If any part of this Agreement is held to be unenforceable, the rest of the Agreement will remain in full force and effect.

11.7  **Waiver**. Failure to enforce any provision of this Agreement will not constitute a waiver. Any waiver must be in writing and signed by the waiving party.

11.8  **No third-party beneficiaries**. This Agreement does not create any third-party beneficiary rights except as expressly provided by its terms.

11.9  **Notices**. Notices must be in writing and will be treated as delivered on the date received at the address, date shown on the return receipt, email transmission date, or date on the courier or fax confirmation of delivery. Notices to Publisher must be sent to the address stated in the Order. Notices to Customer will be sent to the individual at the address Customer identifies on its account as its contact for notices. Publisher may send notices and other information to Customer by email or other electronic form.

11.10  **Applicable law**.

> **a.**  **United States and Canada**. If you acquired the Offering in the United States or Canada, the laws of the state or province where you live (or, if a business, where your principal place of business is located) govern the interpretation of these terms, claims for breach of them, and all other claims (including consumer protection, unfair competition, and tort claims), regardless of conflict of law principles.
>
> **b.**  **Outside the United States and Canada**. If you acquired the Offering in any other country, the laws of that country apply.

11.11  **Order of precedence**. The body of this Agreement will take precedence over any conflicting terms in other documents that are part of this Agreement that are not expressly resolved in those documents. Terms in an amendment control over the amended document and any prior amendments concerning the same subject matter.

11.12  **Government procurement rules**. By accepting this Agreement, Customer represents and warrants that: (1) it has complied and will comply with all applicable government procurement laws and regulations; (2) it is authorized to enter into this Agreement; and (3) this Agreement satisfies all applicable procurement requirements.

11.13  **Compliance with laws**. Publisher will comply with all laws and regulations applicable to its provision of the Offerings. Publisher will obtain and maintain any approvals, licenses, filings, or registrations necessary to its performance, and will comply with all law (including law related to export, corruption, money laundering, or any combination of these). Customer must also comply with laws applicable to their use of the Offerings.

11.14  **Construction**. Neither party has entered this Agreement in reliance on anything not contained or incorporated in it. This Agreement is in English only. Any translation of this Agreement into another language is for reference only and without legal effect. If a court of competent jurisdiction finds any term of the Agreement unenforceable, the Agreement will be deemed modified as necessary to make it enforceable, and the rest of the Agreement will be fully enforced to affect the parties' intent. Lists of examples following "including", "e.g.", "for example", or the like are interpreted to include "without limitation," unless qualified by words such as "only" or "solely." This Agreement will be interpreted according to its plain meaning without presuming that it should favor either party. Unless stated or context requires otherwise:

> **a.**  all internal references are to this Agreement and its parties;
>
> **b.**  all monetary amounts are expressed and, if applicable, payable, in U.S. dollars;
>
> **c.**  URLs are understood to also refer to successors, localizations, and information or resources linked from within websites at those URLs;
>
> **d.**  a party's choices under this Agreement are in its sole discretion, subject to any implied duty of good faith;
>
> **e.**  "written" or "in writing" means a paper document only, except where email is expressly authorized;
>
> **f.**  "days" means calendar days;
>
> **g.**  "may" means that the applicable party has a right, but not a concomitant duty,
>
> **h.**  "partner," if used in this Agreement or related documents, is used in its common, marketing sense and does not imply a partnership;
>
> **i.**  "current" or "currently" means "as of the Effective Date" but "then-current" means the present time when the applicable right is exercised or performance rendered or measured;
>
> **j.**  "notify" means to give notice under subsection (i) above; and
>
> **k.**  a writing is "signed" when it has been hand-signed (i.e., with a pen) or signed via an electronic signature service by a duly authorized representative of the signing party.

### 12. DEFINITIONS <a href="#id-12-definitions" id="id-12-definitions"></a>

"Affiliate" means any legal entity that controls, is controlled by, or is under common control with a party.

"Anti-Corruption Laws" means all laws against fraud, bribery, corruption, inaccurate books and records, inadequate internal controls, money-laundering, and illegal software, including the U.S. Foreign Corrupt Practices Act.

"Control" means ownership of more than a 50% interest of voting securities in an entity or the power to direct the management and policies of an entity.

"Confidential Information" is defined in the "Confidentiality" section.

"Customer Data" means all data, including all text, sound, software, image or video files that are provided to Publisher or its Affiliates by, or on behalf of, Customer and its Affiliates through use of the Offering. Customer Data does not include Support Data.

"Data Protection Law" means any law applicable to Publisher or Customer, relating to data security, data protection and/or privacy, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and the free movement of that data ("GDPR"), and any implementing, derivative or related legislation, rule, regulation, and regulatory guidance, as amended, extended, repealed and replaced, or re-enacted.

"Documentation" means all user manuals, handbooks, training material, requirements, and other written or electronic materials Publisher makes available for, or that result from use of, the Offering.

"End User" means any person Customer permits to use an Offering or access Customer Data.

"Feedback" means ideas, suggestions, comments, input, or know-how, in any form, that one party provides to the other in relation to recipient's Confidential Information, products, or services. Feedback does not include sales forecasts, future release schedules, marketing plans, financial results, and high-level plans (e.g., feature lists) for future products.

"Insolvent" means admitting in writing the inability to pay debts as they mature; making a general assignment for the benefit of creditors; suffering or permitting the appointment of a trustee or receiver for all or any of its (i.e., the non-terminating party's) assets, unless such appointment is vacated or dismissed within 60 days from the date of appointment; filing (or having filed) any petition as a debtor under any provision of law relating to insolvency, unless such petition and all related proceedings are dismissed within 60 days of such filing; being adjudicated insolvent or bankrupt; having wound up or liquidated; or ceasing to carry on business.

"Offering" means all services, websites (including hosting), solutions, platforms, and products identified in an Order and that Publisher makes available under or in relation to this Agreement, including the software, equipment, technology, and services necessary for Publisher to provide the foregoing. Offering availability may vary by region.

"Order" means an ordering document used to transact the Offering via the Marketplace.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Representatives" means a party's employees, Affiliates, contractors, advisors and consultants.

"Standard Contractual Clauses" means the standard data protection clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, as described in Article 46 of the GDPR.

"Subcontractor" means any third party: (1) to whom Publisher delegates its obligations under this Agreement, including a Publisher Affiliate not contracting directly with Customer through an Order; or (2) who, in performing under a contract between it and Publisher or a Publisher Affiliate, stores, collects, transfers or otherwise processes Personal Data (obtained or accessed in connection with performing under this Agreement) or other Customer Confidential Information.

"Support Data" means all data, including all text, sound, video, image files, or software, that are provided to Publisher by or on behalf of Customer (or that Customer authorizes Publisher to obtain from an Offering) through an engagement with Publisher to obtain technical support for the Offering covered under this Agreement.

"Use" means to copy, download, install, run, access, display, use or otherwise interact with.


# Welcome to Mosaic

The AI-native workspace for BI Centers of Excellence.

Mosaic is where your BI Center of Excellence asks, builds, and ships answers - together, in one AI-native workspace. Embed any Power BI report inside the page, write inline DAX, ask questions in plain English, and collaborate with your teammates in real time.

It's built on the Microsoft stack your IT already trusts. Microsoft Entra ID is the only sign-in. Power BI is a first-class citizen. Everything runs on Azure.

## Jump right in

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><strong>Get Started</strong></td><td>Prerequisites, installation, and Power BI configuration.</td><td><a href="/pages/tyK0xHERJuf1Q2KgvfG5">/pages/tyK0xHERJuf1Q2KgvfG5</a></td></tr><tr><td><strong>User Access</strong></td><td>Sign in, share workspaces, manage roles.</td><td><a href="/pages/TJmKp4lMxDuT0fqs7Jva">/pages/TJmKp4lMxDuT0fqs7Jva</a></td></tr><tr><td><strong>Policies</strong></td><td>Privacy policy and terms.</td><td><a href="/pages/STXfBz4Dkq24tvV8q9Ra">/pages/STXfBz4Dkq24tvV8q9Ra</a></td></tr></tbody></table>

## What you bring

Mosaic is **bring-your-own-licence** for both Power BI and AI inference. The Mosaic subscription covers the platform; capacity and inference are on you, in your own tenant.

* **Power BI capacity** — Microsoft Fabric, Power BI Premium / PPU, or Power BI Embedded in your Microsoft 365 tenant. Embedded reports must be backed by your capacity.
* **LLM capacity** — Azure AI Foundry *(recommended)* or an Anthropic / OpenAI API key. Inference is billed by your provider, against your account.

Mosaic does not include or resell Microsoft licensing or AI tokens. See [Prerequisites](/mosaic/get-started/prerequisites) for the full list.

## Plans

| Capability                                    | Mosaic Standard | Mosaic Premium |
| --------------------------------------------- | :-------------: | :------------: |
| Unlimited users and workspaces                |        ✓        |        ✓       |
| All seven Power BI embed types + custom DAX   |        ✓        |        ✓       |
| Built-in AI assistants (Auto, Pro, DAX Agent) |        ✓        |        ✓       |
| Real-time multi-user editing                  |        ✓        |        ✓       |
| Voice input and read-aloud                    |        ✓        |        ✓       |
| Microsoft Entra single sign-on                |        ✓        |        ✓       |
| **Custom AI agents**                          |        —        |        ✓       |
| **Audit log export**                          |        —        |        ✓       |
| **Priority support**                          |        —        |        ✓       |
| **Quarterly success review**                  |        —        |        ✓       |

Subscribe via the Mosaic listing on Microsoft AppSource.

## Looking for AiDi?

[**AiDi Embedded Analytics**](https://docs.aidi.ai) is the sister product from Vizlake Analytics. AiDi is a pre-built embedded analytics portal; Mosaic adds AI-native chat, custom agents, and document workflows on top of your Power BI investment.

Both products share the same Vizlake activation experience after AppSource purchase.

## Support

* **General queries and onboarding**: `info@vizlake.com`
* Vizlake Analytics is **ISO 27001 certified**

***

*Mosaic — by Vizlake Analytics. Built on Microsoft Entra · Power BI · Azure.*


# Prerequisites

Before installing Mosaic, confirm your organisation has the following.

Mosaic is **bring-your-own-licence (BYOL)** for both Power BI and AI inference. The Mosaic subscription covers the platform — workspaces, collaboration, agents, audit, integration. Power BI capacity and LLM inference are on you, in your own tenant. This keeps your data in your environment and your spend visible to your finance team.

## Microsoft 365 tenant

Mosaic uses **Microsoft Entra ID** as its sole identity provider. You need:

* An active Microsoft 365 tenant
* A Microsoft Entra administrator who can grant **tenant-wide admin consent** when Mosaic is installed for the first time

## Power BI capacity in your tenant

Mosaic plugs into the Power BI you already have. Embedded reports must be backed by your own capacity. One of the following is required:

* **Microsoft Fabric capacity** (F-SKU)
* **Power BI Premium**
* **Power BI Premium Per User** (PPU) for every user who will sign in to Mosaic
* **Power BI Embedded** capacity (A-SKU)

Mosaic does not include or resell Microsoft licensing. The capacity sits in your Microsoft 365 tenant, not Vizlake's.

## Power BI workspace and content

* At least one Power BI workspace assigned to a capacity above
* The reports, dashboards, and datasets you intend to embed must already live in that workspace
* You must have admin or member access on those Power BI workspaces

## LLM capacity in your tenant

Mosaic does not bundle AI inference. You bring your own LLM capacity, and Mosaic routes every chat, agent run, and DAX-generation call through it. One of the following is required:

* **Azure AI Foundry** project *(recommended)* — a deployed model in your own Azure subscription. Cleanest data-residency and billing story for Microsoft-native customers.
* **Anthropic API key** — direct integration with the Claude family
* **OpenAI API key** — direct integration with GPT-4 / GPT-4o

You'll connect this in [LLM Configuration](/mosaic/get-started/llm-configuration) after activation. Inference cost is billed by your provider, against your account — Mosaic does not handle inference billing.

## Mosaic plan

A Mosaic Standard or Mosaic Premium subscription via Microsoft AppSource.

* **Custom AI agents** require Mosaic Premium
* **Audit log export**, **priority support**, and **quarterly reviews** require Mosaic Premium

## Mosaic plan

A Mosaic Standard or Mosaic Premium subscription via Microsoft AppSource.

* **Custom AI agents** require Mosaic Premium
* **Audit log export**, **priority support**, and **quarterly reviews** require Mosaic Premium

## Recommended

* Familiarity with Power BI Admin Portal tenant settings - you'll touch these during configuration
* A test user account in your tenant for verifying the access flow before rolling out broadly
* A Microsoft Entra security group already created (or permission to create one) for grouping Mosaic users

## What's next

When the prerequisites are in place, follow [Installation Steps](/mosaic/get-started/installation-steps).


# Installation Steps

Subscribe via Microsoft AppSource, activate your tenant, configure Power BI, invite your team.

Follow these steps after you've completed the [Prerequisites](/mosaic/get-started/prerequisites). The flow is: subscribe on AppSource, activate your tenant on the Vizlake landing page, configure Power BI, and invite your team.

{% stepper %}
{% step %}
**Subscribe via Microsoft AppSource**

1. Open the **Mosaic** listing on [Microsoft AppSource](https://appsource.microsoft.com/)
2. Click **Get it now** and choose **Mosaic Standard** or **Mosaic Premium**
3. Complete the purchase under your Microsoft 365 tenant's billing profile

After purchase, AppSource redirects you to the Vizlake activation page.
{% endstep %}

{% step %}
**Activate your tenant**

You arrive at the **shared Vizlake activation page** — the same landing experience used by [AiDi](https://docs.aidi.ai). It recognises which Vizlake product you've purchased (Mosaic or AiDi) and provisions the right tenant for you.

1. Sign in with the Microsoft Entra account that has **tenant administrator** rights
2. Review the requested permissions:
   * Sign in and read your profile
   * Read Power BI content on behalf of the user (delegated, OBO flow)
3. Tick **Consent on behalf of your organisation** *(strongly recommended — saves every user from a separate consent prompt later)* and click **Accept**
4. The activation page provisions your Mosaic tenant and redirects you to the product

{% hint style="info" %}
Tenant-wide admin consent at this step avoids per-user consent prompts later. If your organisation requires admin consent for any third-party app, see [Azure App Registration → Tenant-wide admin consent](/mosaic/get-started/powerbi-configuration/azure-app-registration).
{% endhint %}
{% endstep %}

{% step %}
**Configure Power BI**

Mosaic must be allowed to call your Power BI tenant on behalf of your users. Complete the [Power BI Configuration](/mosaic/get-started/powerbi-configuration) section before inviting users.
{% endstep %}

{% step %}
**Configure your LLM**

Mosaic doesn't include AI inference - you bring your own LLM capacity. Connect [Azure AI Foundry](/mosaic/get-started/llm-configuration/azure-ai-foundry) *(recommended)* or paste an [API key from Anthropic / OpenAI](/mosaic/get-started/llm-configuration/byo-api-key). Until this step is done, the chat panel will show "AI not configured" and agent runs are blocked.
{% endstep %}

{% step %}
**Onboard your team**

Activate creates a **personal workspace** for the admin who signed in, with a "Getting Started" page. To work with others, create a shared workspace and invite teammates by email - see [Accessing Mosaic](/mosaic/user-access/accessing-mosaic).
{% endstep %}

{% step %}
**Smoke-test before broad rollout**

Before rolling Mosaic out to your whole BI team:

* Sign in with a test user from your tenant
* Confirm the test user can see the workspace they were invited to
* Embed one Power BI report and confirm it renders under the test user's identity (Row-Level Security should hold - the user should only see what they could in Power BI directly)
* Run a sample DAX query to confirm Power BI access is working end-to-end
  {% endstep %}
  {% endstepper %}

## What if something goes wrong?

If activation fails, contact `info@vizlake.com` with:

* Your Microsoft Entra tenant ID
* The exact error message visible on the page
* Approximate time of the issue (so we can correlate with our logs)


# Power BI Configuration

Mosaic must be authorised on your Power BI tenant to embed reports and execute DAX queries on behalf of your users.

There are three steps, in order:

1. [**Azure App Registration**](/mosaic/get-started/powerbi-configuration/azure-app-registration) — created automatically when you activate Mosaic; this page covers what was registered and how to verify
2. [**Power BI Admin Portal Configurations**](/mosaic/get-started/powerbi-configuration/powerbi-admin-portal) — enable the necessary tenant-level switches in the Power BI Admin Portal
3. [**Mosaic App Configurations**](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations) — point Mosaic at your Power BI workspaces and curate the resource catalog

## Who runs these steps

You'll need:

* A user with the **Power BI Administrator** role (to change tenant settings)
* A user with **Microsoft Entra Application Administrator** rights (to verify the Mosaic enterprise application registration)
* A user with **Mosaic Tenant Admin** access (to curate the catalog inside Mosaic)

These are often three different people. Coordinate before you start.

## How long it takes

Plan to spend **\~30 minutes** the first time. Most of it is one-time setup that doesn't need to be repeated unless your Power BI capacity, tenant settings, or workspaces materially change.


# Azure App Registration

When you activate Mosaic, Microsoft Entra automatically registers Mosaic as an enterprise application in your tenant. This page describes what was created and how to verify it.

## What gets registered

Mosaic is published as a **multi-tenant Microsoft Entra application**. When your admin activates the subscription, Entra creates a service principal entry for Mosaic in your tenant.

The application is configured with **delegated permissions only** - Mosaic acts on behalf of the signed-in user via the **OAuth 2.0 On-Behalf-Of (OBO) flow**. Mosaic cannot access Power BI data the user themselves cannot see. Power BI Row-Level Security is preserved end-to-end.

The permissions requested cover:

* **Microsoft Entra ID** — sign-in and basic profile (`User.Read`, `openid`, `profile`, `email`)
* **Power BI Service** — read access to workspaces, datasets, reports, and dashboards the calling user has been granted on Power BI directly. No write permissions, no admin permissions.

## Verify the registration

1. Sign in to the [Azure Portal](https://portal.azure.com) as a Microsoft Entra administrator
2. Navigate to **Microsoft Entra ID → Enterprise applications**
3. Filter the list by **Mosaic**
4. Open the entry to inspect:
   * **Properties** - confirm the app is enabled for users to sign in
   * **Permissions** - confirm the requested permissions match what's listed above
   * **Sign-in logs** - useful when troubleshooting failed sign-ins later
   * **Users and groups** - control which users in your tenant can see Mosaic at all (separate from Mosaic's internal workspace access - see [User Access](/mosaic/user-access/accessing-mosaic))

## Tenant-wide admin consent

If your organisation requires admin consent for any third-party application, Microsoft Entra prompts for tenant-wide consent on first activation.

When the consent dialog opens, tick **"Consent on behalf of your organisation"** before clicking **Accept**. This grants the application's permissions for every user in your tenant in one step — individual users will no longer see consent prompts when they first sign in to Mosaic.

<figure><img src="/files/hYxhkduF3pac1EQpsBpT" alt=""><figcaption><p>Microsoft Entra admin consent dialog. Tick the highlighted checkbox to grant on behalf of the whole organisation.</p></figcaption></figure>

<figure><img src="/files/5JR1uqe5DjueXbWcBhpx" alt=""><figcaption><p>The same dialog with the consent checkbox ticked, ready to Accept.</p></figcaption></figure>

To re-grant or verify consent later:

1. Microsoft Entra ID → Enterprise applications → **Mosaic** → **Permissions**
2. Click **Grant admin consent for \[your organisation]**
3. Sign in as a tenant administrator and accept

## Restricting who can sign in

By default, every user in your tenant can attempt to sign in to Mosaic. Once they're in, [workspace roles](/mosaic/user-access/workspace-roles) determine what they can actually do. If you'd prefer to restrict who can even reach Mosaic - for example, only allowing a specific BI team - Microsoft Entra has a built-in feature for that:

1. Microsoft Entra ID → Enterprise applications → **Mosaic** → **Properties**
2. Set **Assignment required?** to **Yes**
3. Under **Users and groups**, assign the individual users or Microsoft Entra security groups that should be able to sign in

This is purely a Microsoft Entra feature - Mosaic itself doesn't read these groups. It just respects the access decision Entra hands it at sign-in time.

{% hint style="info" %}
**Microsoft Entra security group integration on the Mosaic side is on the roadmap.** Today, Mosaic's own workspace access is managed individually by email (see [Adding Members to a Workspace](/mosaic/user-access/adding-members)). We plan to add native Entra group → workspace role mapping in a future release. Let us know at `info@vizlake.com` if this is critical for your deployment.
{% endhint %}

## What's next

[Power BI Admin Portal Configurations →](/mosaic/get-started/powerbi-configuration/powerbi-admin-portal)


# Power BI Admin Portal Configurations

A Power BI Administrator must enable a small number of tenant settings before Mosaic can embed your content. All changes are made in the Power BI Admin Portal.

## Open the Admin Portal

1. Go to the [Power BI service](https://app.powerbi.com)
2. Click the **Settings** gear in the top-right
3. Choose **Admin portal**
4. Open **Tenant settings** in the left navigation

You will only see this option if you hold the **Power BI Administrator** role on the tenant.

<figure><img src="/files/NkDSg7tgDR80nL9V0EpQ" alt=""><figcaption><p>The Power BI / Fabric Admin Portal — Tenant settings view. Use this page to enable each of the settings listed below. (The highlighted boxes in this screenshot are not the ones Mosaic requires — see the per-setting instructions below.)</p></figcaption></figure>

## Tenant settings to enable

The settings below are minimum requirements for Mosaic embedding to work for your users.

### Embed content in apps

* **Setting**: *Embed content in apps*
* **Where**: Tenant settings → Developer settings
* **Value**: Enabled
* **Apply to**: the Microsoft Entra security group whose members will use Mosaic (recommended) — or *The entire organisation* if you prefer a tenant-wide allow

This is the master switch that lets Mosaic load Power BI content via the embed API on behalf of users. Without it, embedded reports return an error.

### Allow XMLA endpoints and analyze in Excel

* **Setting**: *Allow XMLA endpoints and Analyze in Excel with on-premises datasets*
* **Where**: Tenant settings → Integration settings
* **Value**: Enabled (for Mosaic-using groups)

Required for Mosaic's DAX query block to execute queries against your datasets. Mosaic uses the Power BI REST API's `executeQueries` endpoint, which requires XMLA access on the dataset's hosting capacity.

> XMLA endpoints are also a Premium / Fabric / PPU / Embedded-capacity feature. Datasets in standard (non-capacity) workspaces cannot accept Mosaic's DAX queries.

### Service principals can use Power BI APIs *(for AOD model and data queries)*

* **Setting**: *Service principals can use Power BI APIs*
* **Where**: Tenant settings → Developer settings
* **Value**: Currently optional

Mosaic today uses the **User Owns Data** model - every Power BI call is on behalf of a signed-in user. Service principal permissions are not required.

If needed Mosaic can support **App Owns Data** (Embed Token mode) for higher-scale deployments. When that ships, you will optionally enable this setting and grant the Mosaic service principal access to your workspaces. We will publish a separate guide at that time.

## Workspace-level requirements

For each Power BI workspace you intend to expose in Mosaic:

1. Confirm it is **assigned to a capacity** (Fabric F-SKU, Power BI Premium, PPU, or Power BI Embedded). Workspaces in shared capacity can be browsed but cannot embed for users without their own Pro license.
2. Confirm the users who will sign in to Mosaic have **Viewer** or higher access to the workspace in Power BI itself. Mosaic does not bypass Power BI's own access model.

## Verify

The fastest way to verify the Admin Portal settings are correct is to complete the [Mosaic App Configurations](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations) and embed one report end-to-end with a test user.

## What's next

[Mosaic App Configurations →](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations)


# Mosaic App Configurations

How Mosaic itself is configured — the Admin console you have today, and how the Power BI catalog and workspaces are populated.

Once the [Azure App Registration](/mosaic/get-started/powerbi-configuration/azure-app-registration) and [Power BI Admin Portal](/mosaic/get-started/powerbi-configuration/powerbi-admin-portal) settings are in place, the last step is making sure Mosaic itself knows about your Power BI assets and your team.

This page describes what the Mosaic admin surface does today, and what's coming.

## Sign in as a Mosaic admin

1. Open `https://mosaic.aidi.ai` (or your Mosaic instance URL)
2. Sign in with a Microsoft Entra account that has the **`tenant_admin`** system role in Mosaic
3. Open the **Admin** console from the user menu

If you don't see the **Admin** entry, your account does not yet have tenant-admin rights inside Mosaic. The first user who activated the subscription was set as a tenant admin during installation. Subsequent admins are set by Vizlake on request — contact `info@vizlake.com`.

<figure><img src="/files/QlVDQrqvELdJUPGDAddr" alt=""><figcaption><p>Admin Console — Overview tab. Tenant-wide AI metrics and recent sessions.</p></figcaption></figure>

## What the Admin console does today

The Admin console is **AI-observability-focused**. It gives tenant admins visibility into how AI is being used across the whole tenant.

<table><thead><tr><th width="180">Tab</th><th>What you see</th></tr></thead><tbody><tr><td><strong>Overview</strong></td><td>Total AI sessions, active users, total tokens, error rate, average latency, sessions-per-day chart, and a list of recent sessions.</td></tr><tr><td><strong>Sessions</strong></td><td>Filterable list of every AI session in your tenant — by user, date, outcome (success / error). Click a session to drill in.</td></tr><tr><td><strong>Session Detail</strong></td><td>Per-session timeline of every tool call (dataset schema lookup, DAX execution), with timings, outcomes, model used, token usage, and a JSON export. Viewing a user's chat content requires explicit acknowledgement; the access itself is logged for compliance.</td></tr><tr><td><strong>Token Usage</strong></td><td>Token consumption trends over time, by user, model, and tool category.</td></tr></tbody></table>

<figure><img src="/files/lvDlOHfV8nX0FOEIomxj" alt=""><figcaption><p>Session detail — every tool call logged with timing, outcome, and JSON export.</p></figcaption></figure>

## Power BI resource catalog - how it's populated today

The **catalog** is the searchable index of Power BI reports, dashboards, datasets, and Q\&A entries that Mosaic's AI can reference and that users can embed via the slash menu.

Today, the catalog is populated **two ways**:

{% stepper %}
{% step %}
**End-user "Save to Catalog"**

When a user finds a useful Power BI report inside Mosaic - typed via the slash menu, suggested by the chat agent, or browsed via the resource picker - they can **Save it to the catalog** so the rest of their workspace can find it later.

This is the everyday path. Most catalog entries get added this way as your team works.
{% endstep %}

{% step %}
**CLI-driven seeding (Vizlake-assisted)**

For initial onboarding or large-batch imports, Vizlake runs initial synchronisation scripts directly against your tenant's Power BI environment. This is useful when you want to populate the catalog with dozens or hundreds of curated assets at once, with descriptions and tags pre-written.

If you have a list of Power BI assets you want pre-loaded (with descriptions and tags optimised for AI retrieval), email it to `info@vizlake.com` and we'll seed the catalog for you.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**Why descriptions and tags matter.** The AI retrieves catalog entries semantically when users ask in natural language. A report titled *"Revenue MIS"* with a description like *"Monthly revenue by region, brand, and product category, with comparisons to plan and prior year"* and tags `revenue`, `region`, `brand`, `monthly` - gets surfaced for many more questions than one with just the title. Five minutes invested per resource pays off across thousands of queries.
{% endhint %}

## Workspaces - how they're created today

In Mosaic today, workspaces are **owned and managed by their creators**, not by tenant admins:

* Any user can create a shared workspace from the workspace switcher
* The creator becomes the workspace **Owner** automatically
* The Owner invites teammates by email and assigns roles - see [Adding Members to a Workspace](/mosaic/user-access/adding-members) and [Workspace Roles](/mosaic/user-access/workspace-roles)

Tenant admins do **not** create or modify workspaces from the Admin console today. Workspace administration is owner-driven.

## Custom agents (Mosaic Premium plan)

If your subscription is **Mosaic Premium**, your users can build their own custom AI agents - named, scoped, instruction-driven helpers their team uses regularly.

<figure><img src="/files/UdOiiBDf26PrVKJIjsST" alt=""><figcaption><p>The agent picker — built-in agents (Auto, Pro, DAX Agent) plus your team's custom agents.</p></figcaption></figure>

Built-in agents are available on **both plans**:

<table><thead><tr><th width="160">Built-in agent</th><th>Best for</th></tr></thead><tbody><tr><td><strong>Auto</strong></td><td>Fast responses; the agent decides when to use tools.</td></tr><tr><td><strong>Pro</strong></td><td>Always uses tools and advanced reasoning. Slower, more thorough.</td></tr><tr><td><strong>DAX Agent</strong></td><td>Specialised for DAX formulas, with dataset access.</td></tr></tbody></table>

Custom agents add team-specific personas with their own briefs, tool selections, and dataset scope. Each agent runs under the calling user's Microsoft Entra identity — Row-Level Security holds end-to-end. Nothing an agent fetches is data the user couldn't see themselves.

<figure><img src="/files/NscYsSaKex0vITh2GNAm" alt=""><figcaption><p>Create Agent — name, description, instructions (up to 8 000 chars), tool selection.</p></figcaption></figure>

A full *AI Agents* guide is **coming soon** to this documentation, including agent design patterns, instruction examples, and tool-selection guidance.

## What's next

If you haven't yet connected an LLM, do that now: [LLM Configuration](/mosaic/get-started/llm-configuration). Otherwise move on to [User Access](/mosaic/user-access/accessing-mosaic) to onboard your team.


# LLM Configuration

Mosaic uses your AI capacity, not ours. Connect Azure AI Foundry (recommended) or any other LLM provider via API key.

Mosaic does not include AI inference in your subscription price. You bring your own LLM capacity, the same way you bring your own [Power BI capacity](/mosaic/get-started/powerbi-configuration). This is a deliberate design choice with three benefits:

* **You control cost.** Token spend is on your invoice, with your provider, with your usage caps. No surprises hidden in Mosaic's pricing.
* **You control data.** Chat content, page context, and DAX results are sent to the LLM endpoint **you** configure — staying in your Microsoft 365 / Azure environment if you choose Azure AI Foundry.
* **You control models.** Pick the model that matches your compliance, latency, and quality requirements. Switch providers without changing Mosaic.

## Two supported paths

{% stepper %}
{% step %}
**Azure AI Foundry&#x20;*****(recommended)***

The cleanest path for Microsoft-native customers. Mosaic calls a Foundry-hosted model in **your** Azure subscription. Data never leaves your tenant. Aligns with your existing Azure governance, billing, and compliance posture.

[Configure Azure AI Foundry →](/mosaic/get-started/llm-configuration/azure-ai-foundry)
{% endstep %}

{% step %}
**Bring your own API key**

If you already use Anthropic, OpenAI, or another supported provider directly, paste an API key into Mosaic and you're done. Useful for teams that don't yet have an Azure AI Foundry deployment.

[Bring your own API key →](/mosaic/get-started/llm-configuration/byo-api-key)
{% endstep %}
{% endstepper %}

## Who runs these steps

A user with **Mosaic Tenant Admin** access. The same person who configures Power BI typically does this in the same session — both are tenant-level setup.

## How long it takes

* **Azure AI Foundry**: \~20 minutes the first time, including deploying a model in Foundry and pasting the endpoint into Mosaic
* **BYO API key**: \~2 minutes if you already have an active Anthropic / OpenAI account

## What gets stored where

<table><thead><tr><th width="220">Item</th><th>Where it lives</th></tr></thead><tbody><tr><td>API key / Foundry endpoint</td><td>Encrypted in your Mosaic tenant configuration. Visible only to Tenant Admins.</td></tr><tr><td>Chat content sent to the LLM</td><td>Routed through Mosaic's backend to your configured endpoint. Mosaic retains the request/response in your audit log; the inference itself happens at your provider.</td></tr><tr><td>AI session history</td><td>Mosaic's PostgreSQL database (in your Mosaic tenant scope), as today.</td></tr></tbody></table>

## What's next

Pick one path:

* [Azure AI Foundry](/mosaic/get-started/llm-configuration/azure-ai-foundry) — recommended
* [Bring your own API key](/mosaic/get-started/llm-configuration/byo-api-key)

Once your LLM is connected, return to [Mosaic App Configurations](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations) to curate the Power BI resource catalog and finish onboarding.


# Azure AI Foundry

Recommended path. Deploy a model in your Azure AI Foundry project and connect it to Mosaic.

Mosaic connects to a model you've deployed in your own Azure AI Foundry project. Inference happens in your Azure subscription, your billing, your governance.

## Prerequisites

* An Azure subscription with permission to create AI Foundry resources
* Familiarity with the [Azure AI Foundry portal](https://ai.azure.com/)
* A Tenant Admin account in Mosaic

## Steps

{% stepper %}
{% step %}
**Create or open an Azure AI Foundry project**

In the [Azure AI Foundry portal](https://ai.azure.com/), create a project (or open an existing one). The project is the unit Mosaic will connect to.

If you don't already have a project: **+ Create project** → choose a hub → name it (e.g., `mosaic-inference`) → create.
{% endstep %}

{% step %}
**Deploy a model**

Inside the project: **Models + endpoints** → **Deploy model** → pick a model. Mosaic works well with:

* **Claude (Sonnet or Opus)** — best for the agent flows used by Variance Commentary, Sales Pulse, etc.
* **GPT-4 / GPT-4o** — strong general-purpose default
* **Mistral / Llama** — open-weight options if your governance prefers them

Give the deployment a name you'll recognise (e.g., `claude-sonnet-prod`).
{% endstep %}

{% step %}
**Copy the endpoint URL and key**

Once the deployment is running:

* **Endpoint URL** — visible on the deployment detail page (e.g., `https://<project>.openai.azure.com/`)
* **API Key** — under **Keys and endpoint** for the project

Copy both. The API key is sensitive — do not share or commit to source control.
{% endstep %}

{% step %}
**Connect Mosaic to your Foundry endpoint**

In Mosaic:

1. **Admin → AI Configuration**
2. **Add provider → Azure AI Foundry**
3. Paste:
   * **Endpoint URL**
   * **API Key**
   * **Deployment name** (the one from step 2)
4. Click **Test connection** — Mosaic sends a tiny test prompt and verifies the response
5. Click **Save**

Mosaic now uses your Foundry endpoint for all AI inference across the tenant.
{% endstep %}

{% step %}
**Verify**

Open a Mosaic chat and ask any question. The agent reasoning should stream as expected. Check **Admin → AI Sessions** — the model name shown for the new session should match your Foundry deployment name.
{% endstep %}
{% endstepper %}

## Recommended Foundry settings

* **Content filter**: Microsoft's default (Strict / Default / Off). Strict reduces false positives from analyst questions about sensitive topics; Default is the safer baseline for most tenants.
* **TPM (tokens per minute) quota**: start at 100 K TPM and scale based on usage. Foundry shows usage trends in its monitoring dashboards.
* **Region**: pick the region closest to your users. Mosaic's app servers are in India; latency is acceptable from any global Foundry region but lower from nearby ones.

## Switching models

You can change the deployed model in your Foundry project at any time. Mosaic re-uses whatever the deployment-name resolves to. There's no Mosaic-side switch; just update Foundry.

## What's next

[Mosaic App Configurations →](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations)


# Bring Your Own API Key

Connect Mosaic to Anthropic, OpenAI, or another supported provider using your own API key.

If you already use Anthropic or OpenAI directly — or you don't have Azure AI Foundry capacity yet — Mosaic accepts an API key from supported providers. Inference is billed by the provider, against your account.

## Supported providers

<table><thead><tr><th width="180">Provider</th><th>Models</th><th>Where to get the key</th></tr></thead><tbody><tr><td><strong>Anthropic</strong></td><td>Claude family (Sonnet, Opus, Haiku)</td><td><a href="https://console.anthropic.com/">console.anthropic.com</a> → API Keys</td></tr><tr><td><strong>OpenAI</strong></td><td>GPT-4, GPT-4o, o1</td><td><a href="https://platform.openai.com/">platform.openai.com</a> → API keys</td></tr></tbody></table>

If you'd rather keep everything in Azure, see [Azure AI Foundry](/mosaic/get-started/llm-configuration/azure-ai-foundry) — that's the recommended path for Microsoft-native customers.

## Prerequisites

* An active account with the provider above and an API key with permission to invoke models
* A Tenant Admin account in Mosaic
* A billing setup at the provider — Mosaic does not handle inference billing

## Steps

{% stepper %}
{% step %}
**Create the API key at your provider**

Sign in at the provider and create an API key scoped narrowly:

* Limit it to inference calls only (no admin / billing scopes)
* Set a usage cap — both as a hard limit and a soft alerting threshold
* Tag or name the key `mosaic-prod` so you can identify it later

Copy the key immediately — most providers don't let you view it again after creation.
{% endstep %}

{% step %}
**Connect Mosaic to your provider**

In Mosaic:

1. **Admin → AI Configuration**
2. **Add provider** → choose **Anthropic** or **OpenAI**
3. Paste the **API Key**
4. Pick the **default model** (e.g., `claude-3-5-sonnet-20241022`, `gpt-4o`). Specific recommendations:
   * **Anthropic**: Claude Sonnet for the orchestrator agent; Claude Haiku is fine for cheaper, lower-latency flows
   * **OpenAI**: GPT-4o for the orchestrator; GPT-4o-mini for cheaper flows
5. Click **Test connection** — Mosaic sends a tiny test prompt and verifies the response
6. Click **Save**
   {% endstep %}

{% step %}
**Verify**

Open a Mosaic chat and ask any question. Check **Admin → AI Sessions** — the model name shown should match the one you selected.
{% endstep %}
{% endstepper %}

## Operational tips

### Set a usage cap

Both Anthropic and OpenAI let you set monthly spend caps. Set a hard cap that's higher than your expected usage but well below the worst case. If a runaway agent loop ever happens, the cap stops the bleed.

### Rotate keys periodically

Treat the LLM API key like any other production credential. Rotate quarterly:

1. Create a new key at the provider
2. Update Mosaic with the new key
3. Test
4. Revoke the old key at the provider

Mosaic stores the key encrypted; rotating doesn't invalidate any session history.

### Switching providers

You can change provider at any time in **Admin → AI Configuration**. New chat sessions use the new provider; in-flight sessions complete on the previous one. No data migration is needed; chat history lives in Mosaic regardless of which inference backend ran it.

## When to switch to Azure AI Foundry

If any of these become true, plan a move to Foundry:

* Compliance requires data residency in your Azure tenant
* Your AI usage exceeds direct-API rate limits and you need provisioned throughput
* You want to consolidate AI billing under your existing Azure spend commit

The migration is straightforward — see [Azure AI Foundry](/mosaic/get-started/llm-configuration/azure-ai-foundry). No Mosaic-side data needs to move.

## What's next

[Mosaic App Configurations →](/mosaic/get-started/powerbi-configuration/mosaic-app-configurations)


# Accessing Mosaic

How users reach Mosaic, what gets created on first sign-in, and how access actually works.

Mosaic's access model is layered but uncomplicated. Microsoft Entra ID controls who can sign in. Workspaces control what they can see once they're in. Power BI controls what data they can read inside embedded content.

## Access model

<table><thead><tr><th width="170">Layer</th><th width="220">What it controls</th><th>How</th></tr></thead><tbody><tr><td><strong>Tenant</strong></td><td>Who can reach the app at all</td><td>Microsoft Entra ID. Only members of your Microsoft 365 tenant can sign in.</td></tr><tr><td><strong>System role</strong></td><td>Whether a user sees the Admin console</td><td><code>member</code> (default), <code>tenant_admin</code> (sees Admin), or <code>global_admin</code> </td></tr><tr><td><strong>Workspace</strong></td><td>Which shared workspaces a user can open and what they can do inside</td><td>Workspace owner adds members by email and assigns a role: <strong>Owner</strong>, <strong>Editor</strong>, or <strong>Viewer</strong>.</td></tr><tr><td><strong>Power BI</strong></td><td>Which Power BI rows / pages / reports a user actually sees inside an embed</td><td>The user's own Microsoft Entra identity is forwarded to Power BI via the On-Behalf-Of flow. Row-Level Security holds end-to-end. Mosaic never bypasses or caches Power BI access decisions.</td></tr></tbody></table>

## What happens on first sign-in

When a user opens Mosaic for the first time, a few things happen automatically:

{% stepper %}
{% step %}

#### Microsoft Entra signs them in

Mosaic redirects to Microsoft Entra ID. The user signs in with their Microsoft 365 work account - the same one they use for Power BI, Teams, and the rest of Microsoft 365.
{% endstep %}

{% step %}

#### Mosaic provisions their account

The first sign-in creates the user record in your Mosaic tenant.
{% endstep %}

{% step %}

#### A personal workspace is auto-created

Mosaic creates a **personal workspace** for the user, with a starter "Getting Started" page inside. Personal workspaces are private to the user — only they can edit content there.
{% endstep %}

{% step %}

#### They land on the home page

The user sees their personal workspace in the sidebar, the chat panel ready to take questions, and quick action pills for the common starting moves.

<figure><img src="/files/prsOZ3YNqvHrW3kTBmkB" alt=""><figcaption><p>Mosaic home — quick actions and recently-accessed resources.</p></figcaption></figure>
{% endstep %}
{% endstepper %}

That's it for first-time sign-in. They can immediately ask the chat questions, embed Power BI reports they have access to, and write pages.

## Sharing - moving from personal to team workspaces

A personal workspace covers solo work. To collaborate, someone needs to create a **shared workspace** and invite teammates by email.

{% stepper %}
{% step %}

#### Create a shared workspace

Any user can create a shared workspace (e.g., *FP\&A*, *Risk Reporting*, *Merchandising Analytics*). The creator becomes the workspace **Owner**.
{% endstep %}

{% step %}

#### Invite teammates by email

The Owner opens **Workspace settings → Members** and adds people by their work email, one at a time, with a role:

* **Editor** - can create and edit pages, run agents, embed Power BI, write DAX
* **Viewer** - read-only

Invitees must be members of your Microsoft 365 tenant — Mosaic does not support external guest collaboration today.

For more on what each role can do, see [Workspace Roles](/mosaic/user-access/workspace-roles).
{% endstep %}

{% step %}

#### Members sign in

Once added, the invitee sees the shared workspace in their sidebar the next time they sign in. Power BI access remains gated by Power BI's own access model — Mosaic shows them what they're allowed to see.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
**No security group integration today.** Mosaic does not currently read Microsoft Entra security groups. Each member is added to a workspace individually by email. If you'd like group-based provisioning, that's on the Mosaic roadmap — let us know at `info@vizlake.com` so we can prioritise it.
{% endhint %}

## Tenant administrators

Tenant admins (`system_role = tenant_admin`) see the **Admin** entry in their user menu. They can review:

* Total AI sessions, active users, token usage, error rate, latency
* Recent AI sessions across the whole tenant
* Per-session timelines (every tool call, dataset accessed, model used)
* Token usage trends

<figure><img src="/files/QlVDQrqvELdJUPGDAddr" alt=""><figcaption><p>Admin Overview — tenant-wide AI metrics and recent sessions.</p></figcaption></figure>

Tenant admins do **not** manage workspaces from the Admin console — workspaces are owner-driven. Setting a user's system role is currently done by Vizlake on request, or by an existing global admin via the `scripts/admin.ts` CLI. UI-driven role management is on the roadmap.

## Access URL

Your Mosaic instance is at `https://mosaic.aidi.ai`. Customers with custom domain configurations may have a different URL - check with your Mosaic administrator if unsure.

## What's next

* [Adding Members to a Workspace](/mosaic/user-access/adding-members) - the email-invite flow
* [Workspace Roles](/mosaic/user-access/workspace-roles) - what each role can do
* [User Login](/mosaic/user-access/user-login) - first-sign-in walkthrough and troubleshooting


# Adding Members to a Workspace

How a workspace owner invites teammates and assigns roles.

In Mosaic, workspaces are owned and managed by their creators. The owner of a shared workspace adds members one at a time by email, and assigns each one a role.

## Who can add members

Only the workspace **Owner** can invite new members or change roles. Editors and Viewers cannot.

A workspace can have more than one owner. Owners can promote an existing Editor to Owner if you want a co-pilot.

## Steps

{% stepper %}
{% step %}

#### Open the workspace

From the sidebar, switch to the workspace you want to add a member to. You must be the **Owner**.
{% endstep %}

{% step %}

#### Open Workspace settings → Members

The settings entry sits next to the workspace name in the sidebar.
{% endstep %}

{% step %}

#### Add a member by email

Click **Add member**. Enter the teammate's work email address. Pick the role:

* **Editor** - full create / edit / run / embed / DAX
* **Viewer** - read-only

Click **Add**.
{% endstep %}

{% step %}

#### They see the workspace on next sign-in

The member opens Mosaic and sees the shared workspace in their sidebar. If they haven't signed in to Mosaic before, their account is provisioned automatically by Microsoft Entra.
{% endstep %}
{% endstepper %}

{% hint style="warning" %}
**Members must belong to your Microsoft 365 tenant.** Mosaic does not currently support external (guest / B2B) collaboration. Invitees who don't have a Microsoft Entra account in your tenant cannot sign in.
{% endhint %}

## Changing a member's role

Open **Workspace settings → Members**, find the member, click the role dropdown next to their name, and pick a different role. Changes take effect immediately.

## Removing a member

In **Workspace settings → Members**, click the kebab (⋮) next to the member and choose **Remove**. They lose access to the workspace immediately. Their personal workspace and other workspaces they belong to are not affected.

{% hint style="info" %}
Removing a member is a Mosaic-side action only. It does not change anything in Microsoft Entra ID or in Power BI. If you also want to revoke their Power BI access, that's a separate step in Power BI itself.
{% endhint %}

## What's next

* [Workspace Roles](/mosaic/user-access/workspace-roles) — what each role can do, in detail


# Workspace Roles

What each workspace role — Owner, Editor, Viewer — can do.

Every member of a workspace has exactly one role: **Owner**, **Editor**, or **Viewer**. The role applies to that workspace only - a user can be an Owner of one workspace and a Viewer of another.

## What each role can do

<table><thead><tr><th width="120">Role</th><th>What they can do</th></tr></thead><tbody><tr><td><strong>Owner</strong></td><td>Everything an Editor can, plus: invite members, change member roles, remove members, archive the workspace, promote another member to Owner.</td></tr><tr><td><strong>Editor</strong></td><td>Create, edit, and delete pages, blocks, and DAX queries. Embed Power BI content from the catalog. Use built-in AI agents and any custom agents shared in the workspace. Pin AI artifacts to pages.</td></tr><tr><td><strong>Viewer</strong></td><td>Read-only. Open pages, scroll, read AI conversations. Embedded Power BI reports stay interactive (filters, slicers, drill-throughs) because that interactivity is a Power BI client feature, not a Mosaic edit. Viewers cannot create pages, run agents in the workspace, or pin AI output.</td></tr></tbody></table>

## How roles are assigned

The workspace **Owner** assigns each new member's role when they invite them - see [Adding Members to a Workspace](/mosaic/user-access/adding-members). Roles can be changed any time after that:

1. Open the workspace
2. **Workspace settings → Members**
3. Click the role dropdown next to a member
4. Pick a different role
5. The change is immediate

## Multiple owners

A workspace can have more than one Owner. To promote an Editor to Owner, an existing Owner changes their role in the same way as above. Removing all Owners from a workspace is not allowed - you must always have at least one.

## Power BI access vs. Mosaic role

Workspace roles control what someone can do **inside Mosaic**. They do **not** override Power BI's own access model.

A Viewer in Mosaic who has Edit access to a Power BI workspace in Power BI itself can still interact with embedded reports normally. Mosaic does not grant or revoke Power BI permissions - every Power BI call goes through the user's own Microsoft Entra identity (the On-Behalf-Of flow).

This means:

* If a user has no Power BI access, they see "no access" on embedded blocks regardless of their Mosaic role.
* If a user has Power BI Pro / PPU access plus Editor role in Mosaic, they can interact with reports and write DAX queries the same way.
* Row-Level Security defined in Power BI is preserved end-to-end.

## Personal workspaces

Every user has one **personal workspace** that's auto-provisioned on first sign-in. They are the implicit Owner. Personal workspaces cannot be shared - they're for solo work. To collaborate, create a shared workspace and invite teammates.

## What's next

* [Adding Members to a Workspace](/mosaic/user-access/adding-members) - invite flow
* [User Login](/mosaic/user-access/user-login)  first sign-in walkthrough


# User Login

First-time sign-in walkthrough plus the most common things to check when something goes wrong.

What a Mosaic user experiences on their first sign-in, and what to check when sign-in or embedded content doesn't work.

## First-time sign-in

{% stepper %}
{% step %}

#### Open Mosaic

The user opens `https://mosaic.aidi.ai` (or your tenant's custom Mosaic URL).
{% endstep %}

{% step %}

#### Sign in with Microsoft Entra

Mosaic redirects to Microsoft Entra ID. The user signs in with their work account - the same one they use for Power BI, Teams, and Microsoft 365. There is no separate Mosaic password.
{% endstep %}

{% step %}

#### Consent (first sign-in only)

If the tenant administrator already granted tenant-wide admin consent during [Installation](/mosaic/get-started/installation-steps), the user is signed in immediately.

If not, the user sees a permission consent dialog. They can usually consent for themselves; some organisations require an admin to grant consent - see [Azure App Registration → Tenant-wide admin consent](/mosaic/get-started/powerbi-configuration/azure-app-registration).
{% endstep %}

{% step %}

#### Mosaic provisions their account

On the very first sign-in, Mosaic creates a personal workspace for the user, with a starter "Getting Started" page inside.
{% endstep %}

{% step %}

#### They land on the home page

<figure><img src="/files/prsOZ3YNqvHrW3kTBmkB" alt=""><figcaption><p>The home page on first sign-in — personal workspace in the sidebar, chat ready, quick action pills, recently-accessed resources.</p></figcaption></figure>

The user sees:

* The personal workspace in the left sidebar (and any shared workspaces they've already been invited to)
* The chat panel ready to take questions
* Quick action pills - *Find reports*, *Write a DAX query*, *Build a page*, *Analyse trends*
* Recently-accessed Power BI resources, once they've used a few
  {% endstep %}
  {% endstepper %}

## Troubleshooting

### Sign-in fails with "AADSTS50105" or similar

**Cause**: Microsoft Entra is enforcing *Assignment required* on the Mosaic enterprise application, and the user (or their group) hasn't been assigned.

**Fix**: A Microsoft Entra administrator needs to either:

* Disable Assignment Required on the Mosaic enterprise app, or
* Add the user or their group under **Microsoft Entra ID → Enterprise applications → Mosaic → Users and groups**

See [Azure App Registration → Restricting who can sign in](/mosaic/get-started/powerbi-configuration/azure-app-registration).

### "You don't have access" or empty workspaces list

**Cause**: The user's account exists but they're not a member of any shared workspace.

**Fix**: Sign-in itself succeeded - there's just nothing shared with them yet.

* Their personal workspace should appear in the sidebar regardless. If they don't see *any* workspace, contact `info@vizlake.com` so we can investigate.
* For shared content, the workspace's Owner needs to invite them by email — see [Adding Members to a Workspace](/mosaic/user-access/adding-members).

### Embedded Power BI report shows "You don't have access to this report"

**Cause**: The user's Microsoft Entra account does not have access to the underlying Power BI workspace.

**Fix**: Grant the user access to the workspace in Power BI itself. Mosaic cannot bypass Power BI's own access model - every embed runs under the calling user's identity (OBO flow), and the user needs at least **Viewer** in the Power BI workspace. After Power BI access is granted, the embed loads on the next refresh.

### Embedded report renders but visuals are blank or show "capacity exceeded"

**Cause**: The Power BI capacity hosting the workspace is overloaded, paused, or not provisioned.

**Fix**: Open the **Power BI Admin Portal → Capacities** and check the capacity status. Resume or scale up as needed. See your Microsoft Fabric / Power BI Premium / Embedded administrator. Mosaic does not include capacity - it sits on top of yours.

### Voice input doesn't work

**Cause**: Browser microphone permission was denied, or the browser doesn't support the Web Speech API.

**Fix**:

* Check the browser's site permissions and re-grant microphone access for `mosaic.aidi.ai`
* Use a recent Chromium-based browser (Edge, Chrome) - Safari has partial support; Firefox does not currently expose `SpeechRecognition`

## Where to go next

* [Adding Members to a Workspace](/mosaic/user-access/adding-members) - bring teammates in
* [Workspace Roles](/mosaic/user-access/workspace-roles) - what each role can do
* *Working with Mosaic* - coming soon (block editor, slash commands, embedding flow, voice, pinning AI artifacts)
* *AI Agents* - coming soon (built-in agents reference + custom agents on Mosaic Premium)

In the meantime, end users can explore by typing `/` inside any page or chat input to see available commands and resources.


# Privacy Policy

## Vizlake Privacy Statement

Your privacy is important to us. This privacy statement explains the personal data Vizlake processes, how Vizlake processes it, and for what purposes. This Privacy Policy statement relates to information collected by Vizlake Analytics Private Limited (referred to in this Privacy Policy as “Vizlake” “we” or “us” or “our”) through your use of our website and our Services, features, and information available on our website (which are collectively referred to in this Privacy Policy as “Mosaic” or “Our Products and Services”).

## Data we collect

The data we collect depends on the context of your interactions with Vizlake. While subscribing to Mosaic, you will be required to provide us with information (including personally identifiable information and non-personally identifiable information). In addition, we may obtain your personally identifiable information from you if you identify yourself to us by sending us an e-mail with questions or comments. Depending on your use of our products or services, we collect two types of information: Personally identifiable information and non-personally identifiable information.

## How we use your data

We do not sell any data, including your personal data. We will only process your personal data in accordance with applicable data protection and privacy laws. Vizlake uses the data we collect to provide you better experiences. In particular, we use data to:

* Provide our products and services, which includes updating, securing, and troubleshooting, as well as providing support. It also includes sharing data, when it is required to provide the service or carry out the transactions you request.
* Improve and develop our products.
* Personalize our products and make recommendations.
* Advertise and market to you, which includes sending promotional communications, targeting advertising, and presenting you with relevant offers.

We also use the data to operate our business, which includes analyzing our performance, meeting our legal obligations, developing our workforce, and doing research.

We are committed to protecting the privacy of children. Our Products and Services are not designed for or directed to children under the age of 13. We do not collect personally identifiable information from any person we actually know is under the age of 13.

In general, we use the information collected to provide you with a great overall experience using Our Products and Services, to help us understand who uses our Our Products and Services, for internal operations such as operating and improving Our Products and Services, to contact you for customer service and billing purposes, and to facilitate the delivery of our advertising in some cases. We use your information to send you a welcome e-mail after you create an account, when you are invited to Mosaic Portal, or when you sign up for a demo or webinar. We also use your information to send other e-mail communication related to Our Products and Services.

## Storing and Transferring of Data

Your data, including personal data that we collect from you, may be transferred to, stored at and processed by us and other third parties outside the country in which you reside, including, but not limited to India, where data protection and privacy regulations may not offer the same level of protection as in other parts of the world. By using our platform, you agree to this transfer, storing or processing. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this policy. Your team’s project and report data will never be transferred to third parties. The only data we share with third parties is for analytics, error tracking, and marketing.

We will only retain your personal data as long as reasonably required for you to use the Site/Application(s) and/or to provide you with the Services unless a longer retention period is required or permitted by law (for example, for regulatory purposes).

## How Secure is your data

Vizlake Analytics brings simplicity, speed, and scale to our customer’s Data Analytics by using cutting edge analytics technologies and tools and smart minds to put data to work. We intend to optimize business operations for creating measurable new Net Profit. Our uniqueness identify our client’s business needs and not just limit to what the client asks for.

Our organization is committed to preserving the Confidentiality, Integrity, Availability and Legality of all our client data as well as our own information assets. Service availability and security of client data are our top priorities. Our objective is to manage the information security risks to acceptable levels to ensure compliance with national and international data protection and privacy regulation/ legislations as well as meet the contractual obligations of our customers.

Business Partners and Employees of Vizlake are required to comply with the Information Security Policies, the ISMS (Information Security Management Systems) based on ISO 27001:2022 that implements this policy as well as the requirements Data Protection Regulations in the regions our customers are located in.

Information security requirements will continue to be aligned with Vizlake business objectives and obligations, aligned to the clients and their relevant requirements to meet the business objectives. The Information Security Management Systems (ISMS) is intended to be an enabling mechanism for information sharing, for data analytics activities, for data modelling and for reducing risks to information security to acceptable levels.

The Information Risk Management framework at Vizlake provides the context for identifying, assessing, evaluating, and controlling information-related risks through the establishment and maintenance of an Information Security Management System.

The Classification of Information, Risk Assessment, Business Impact Assessment, Statement of Applicability and Risk Treatment Plan identifies how information related risks are controlled and managed. The IT Director is responsible for the management and maintenance of the Information Security Management System.

Business continuity and contingency plans, Information Security Continuity Plans, avoidance of malware and internal and external hackers, access control to systems are fundamental to this policy. Any incident or activity that causes or may cause a break down in the confidentiality, integrity or availability of the physical or electronic information assets of the Organization and its clients shall be treated as a security incident and needs to be reported, investigated, root cause identified, and corrective and preventive actions initiated.

The ISMS is the Information Security Management System, of which this policy, the ‘Information Security Manual’ and other supporting and related documentation is a part, and which has been designed in accordance with the specification contained in ISO 27001: 2022. The ISMS is subject to continuous, systematic review and improvement.

## Outside Contractors

We may employ independent contractors, vendors, and suppliers (collectively, “Outside Contractors”) to provide specific services and products related to Our Products and Services, such as hosting, credit card processing and fraud screening, and mailing list hosting for Our Products and Services. In the course of providing products or services to us, these Outside Contractors may have access to information collected through Our Products and Services, including your personally identifiable information. We require that these contractors agree to (1) protect the privacy of your personally identifiable information consistent with this Privacy Policy (2) not use or disclose your personally identifiable information for any purpose other than providing us with the products or services for which we contracted or as required by law.

## Sale of Business

We reserve the right to transfer information to a third party in the event of a sale, merger or other transfer of all or substantially all of the assets of Vizlake Analytics or any of its Corporate Affiliates (as defined herein), or that portion of Vizlake or any of its Corporate Affiliates to which the Service relates, or in the event that we discontinue our business or file a petition or have filed against us a petition in bankruptcy, reorganization or similar proceeding, provided that the third party agrees to adhere to the terms of this Privacy Policy.

## Affiliates

We may disclose information (including personally identifiable information) about you to our Corporate Affiliates. For purposes of this Privacy Policy, “Corporate Affiliate” means any person or entity which directly or indirectly controls, is controlled by or is under common control with Vizlake Analytics, whether by ownership or otherwise. Any information relating to you that we provide to our Corporate Affiliates will be treated by those Corporate Affiliates in accordance with the terms of this Privacy Policy.

## Laws and Legal Rights

We may disclose your information (including personally identifiable information) if we believe in good faith that we are required to do so to comply with an applicable statute, regulation, rule or law, a subpoena, a search warrant, a court or regulatory order, or other valid legal process. We may disclose personally identifiable information in special circumstances when we have reason to believe that disclosing this information is necessary to identify, contact, or bring legal action against someone who may be violating our Terms of Service, to detect fraud, or to protect the safety and/or security of our users, Our Products or Services, or the general public. We are subject to the investigatory and enforcement powers of the Laws in India. We also may be required to disclose an individual’s personal information in response to a lawful request by public authorities, including to meet national security or law enforcement requirements.

## Contact Details

If you have any questions or comments about this Privacy Policy or feel that we are not abiding by the terms of this Privacy Policy, please contact our Privacy Agent in any of the following ways:

Email : <info@vizlake.com>

Postal mail or courier: Attn : Privacy Officer, Vizlake Analytics Private Limited No.6/858-M, 2nd Floor, Suite# 287 Valamkottil Towers, Judgemukku, Thrikkakara P.O Kakkanad, Ernakulam, Kerala, India - 682021


# Terms and Conditions

This Standard Contract ("Agreement") is between you ("you" or "Customer") and Vizlake Analytics Private Limited ("Vizlake" or "Publisher" or "Service Provider") from which you are procuring Offerings (defined below) and governs your use of Offerings purchased through either our Website or through our affiliates or through Microsoft AppSource or Azure Marketplace (collectively, "Marketplace").

This Agreement is the parties' entire agreement on this subject and merges and supersedes all related prior and contemporaneous agreements. By agreeing to these terms, you represent and warrant that you have the authority to accept this Agreement, and you also agree to be bound by its terms. This Agreement applies to all Orders entered into under this Agreement.

### 1. LICENSE TO OFFERINGS <a href="#id-1-license-to-offerings" id="id-1-license-to-offerings"></a>

1.1 **License grant**. Offerings are licensed and not sold. Upon acceptance of an Order, and subject to Customer's compliance with this Agreement, Vizlake grants Customer a nonexclusive and limited license to use the ordered Offerings. These licenses are solely for Customer's own use and business purposes and are nontransferable except as expressly permitted under this Agreement or applicable law.

Offerings may contain or be provided with components that are subject to open-source software licenses. Any use of those components may be subject to additional terms and conditions and Customer agrees that any applicable licenses governing the use of the components will be incorporated by reference in this Agreement.

1.2 **Duration of licenses**. Licenses granted on a subscription basis expire at the end of the applicable subscription period set forth in the Order, unless renewed. Licenses granted for metered Offerings billed periodically based on usage continue as long as Customer continues to pay for its usage of the Offerings. All other licenses become perpetual upon payment in full.

1.3 **End Users**. Customer will control access to and use of the Offerings by End Users and is responsible for any use of the Offerings that does not comply with this Agreement.

1.4 **Affiliates**. Customer may order Offerings for use by its Affiliates. If it does, the licenses granted to Customer under this Agreement will apply to such Affiliates, but Customer will have the sole right to enforce this Agreement against Publisher. Customer will remain responsible for all obligations under this Agreement and for its Affiliates' compliance with this Agreement and any applicable Order(s).

1.5 **Reservation of Rights**. Vizlake reserves all rights not expressly granted in this Agreement. Offerings are protected by copyright and other intellectual property laws and international treaties. No rights will be granted or implied by waiver or estoppel. Rights to access or use Offerings on a device do not give Customer any right to implement Publisher's patents or other intellectual property in the device itself or in any other software or devices.

1.6 **Restrictions**. Except as expressly permitted in this Agreement, Documentation or an Order, Customer must not (and is not licensed to):

> **a.** copy, modify, reverse engineer, decompile, or disassemble any Offering, or attempt to do so;
>
> **b.** install or use any third-party software or technology in any way that would subject Vizlake's intellectual property or technology to any other license terms;
>
> **c.** work around any technical limitations in an Offering or restrictions in Documentation;
>
> **d.** separate and run parts of an Offering on more than one device;
>
> **e.** upgrade or downgrade parts of an Offering at different times;
>
> **f.** use an Offering for any unlawful purpose;
>
> **g.** transfer parts of an Offering separately; or
>
> **h.** distribute, sublicense, rent, lease, or lend any Offerings, in whole or in part, or use them to offer hosting services to a third party.

1.7 **License transfers**. Customer may only transfer fully-paid, perpetual licenses to (1) an Affiliate or (2) a third party solely in connection with the transfer of hardware to which, or employees to whom, the licenses have been assigned as part of (A) a divestiture of all or part of an Affiliate or (B) a merger involving Customer or an Affiliate. Upon such transfer, Customer must uninstall and discontinue using the licensed Offering and render any copies unusable. Customer must notify Publisher of a License transfer and provide the transferee a copy of this Agreement and any other documents necessary to show the scope, purpose, and limitations of the licenses transferred. Attempted license transfers that do not comply with this section are void.

1.8 **Feedback**. Any Feedback is given voluntarily, and the provider grants to the recipient, without charge, a non-exclusive license under provider's owned or controlled non-patent intellectual property rights to make, use, modify, distribute, and commercialize the Feedback as part of any of recipient's products and services, in whole or in part and without regard to whether such Feedback is marked or otherwise designated by the provider as confidential. The provider retains all other rights in any Feedback and limits the rights granted under this section to licenses under its owned or controlled non-patent intellectual property rights in the Feedback (which do not extend to any technologies that may be necessary to make or use any product or service that incorporates, but are not expressly part of, the Feedback, such as enabling technologies).

### 2. PRIVACY <a href="#id-2-privacy" id="id-2-privacy"></a>

2.1 **EU Standard Contractual Clauses**. To the extent applicable, the parties will abide by the requirements of European Economic Area and Swiss data protection law regarding the collection, use, transfer, retention, and other processing of Personal Data from the European Economic Area and Switzerland. All transfers of Customer Data out of the European Union, European Economic Area, and Switzerland will be governed by the Standard Contractual Clauses, as designated by the European Commission, made available by the Publisher at the applicable URL for such terms or as otherwise communicated to Customer.

2.2 **Personal Data**. Customer consents to the processing of Personal Data by Publisher and its Affiliates, and their respective agents and Subcontractors, as provided in this Agreement. Before providing Personal Data to Publisher, Customer will obtain all required consents from third parties (including Customer's contacts, partners, distributors, administrators, and employees) under applicable privacy and Data Protection Laws.

2.3 **Processing of Personal Data; GDPR**. To the extent Publisher is a processor or subprocessor of Personal Data subject to the GDPR, the Standard Contractual Clauses govern that processing and the parties also agree to the following terms in this subsection ("Processing of Personal Data; GDPR"):

> **a.** **Processor and Controller Roles and Responsibilities**. Customer and Publisher agree that Customer is the controller of Personal Data and Publisher is the processor of such data, except when (a) Customer acts as a processor of Personal Data, in which case Publisher is a subprocessor or (b) stated otherwise in any Offering-specific terms. Publisher will process Personal Data only on documented instructions from Customer. In any instance where the GDPR applies and Customer is a processor, Customer warrants to Publisher that Customer's instructions, including appointment of Processor as a processor or subprocessor, have been authorized by the relevant controller.
>
> **b.** **Processing Details**. The parties acknowledge and agree that:
>
> > **i.** the subject-matter of the processing is limited to Personal Data within the scope of the GDPR;
> >
> > **ii.** the duration of the processing will be for the duration of the Customer's right to use the Offering and until all Personal Data is deleted or returned in accordance with Customer instructions or the terms of this Agreement;
> >
> > **iii.** the nature and purpose of the processing will be to provide the Offering pursuant to this Agreement;
> >
> > **iv.** the types of Personal Data processed by the Offering include those expressly identified in Article 4 of the GDPR; and
> >
> > **v.** the categories of data subjects are Customer's representatives and end users, such as employees, contractors, collaborators, and customers, and other data subjects whose Personal Data is contained within any data made available to Publisher by Customer.
>
> **c.** **Data Subject Rights; Assistance with Requests**. Publisher will make information available to Customer in a manner consistent with the functionality of the Offering and Publisher's role as a processor of Personal Data of data subjects and the ability to fulfill data subject requests to exercise their rights under the GDPR. Publisher will comply with reasonable requests by Customer to assist with Customer's response to such a data subject request. If Publisher receives a request from Customer's data subject to exercise one or more of its rights under the GDPR in connection with an Offering for which Publisher is a data processor or subprocessor, Publisher will redirect the data subject to make its request directly to Customer. Customer will be responsible for responding to any such request including, where necessary, by using the functionality of the Offering. Publisher will comply with reasonable requests by Customer to assist with Customer's response to such a data subject request.
>
> **d.** **Use of Subprocessors**. Customer consents to Publisher using the subprocessors listed at the applicable Publisher URL or as otherwise communicated to Customer. Publisher remains responsible for its subprocessors' compliance with the obligations herein. Publisher may update its list of subprocessors from time to time, by providing Customer at least 14 days notice before providing any new subprocessor with access to Personal Data. If Customer does not approve of any such changes, Customer may terminate any subscription for the affected Offering without penalty by providing, prior to expiration of the notice period, written notice of termination that includes an explanation of the grounds for non-approval.
>
> **e.** **Records of Processing Activities**. Publisher will maintain all records required by Article 30(2) of the GDPR and, to the extent applicable to the processing of Personal Data on behalf of Customer, make them available to Customer upon request.

2.4 **Security**. Publisher will take appropriate security measures that are required by Data Protection Laws and in accordance with good industry practice relating to data security.

2.5 **Support Data**. Publisher may collect and use Support Data internally to provide technical support for the Offering. Publisher will not use Support Data for any other purpose unless otherwise agreed in writing by the parties.

### 3. CONFIDENTIALITY <a href="#id-3-confidentiality" id="id-3-confidentiality"></a>

3.1 **Non-Disclosure Agreement**. The parties will treat all confidential information exchanged between the parties under this Agreement in accordance with the separate nondisclosure agreement ("NDA") executed by the parties. If no separate NDA is in effect, the following provisions apply to the parties' exchange of confidential information.

3.2 **Confidential Information**. "Confidential Information" is non-public information that is designated "confidential" or that a reasonable person should understand is confidential, including, but not limited to, Customer Data, Support Data, the terms of this Agreement, and Customer's account authentication credentials. Confidential Information does not include information that: (1) becomes publicly available without a breach of a confidentiality obligation; (2) the receiving party received lawfully from another source without a confidentiality obligation; (3) is independently developed; or (4) is a comment or suggestion volunteered about the other party's business, products, or services.

3.3 **Protection of Confidential Information**. Each party will take reasonable steps to protect the other's Confidential Information and will use the other party's Confidential Information only for purposes of the parties' business relationship. Neither party will disclose Confidential Information to third parties, except to its Representatives, and then only on a need-to-know basis under nondisclosure obligations at least as protective as this Agreement. Each party remains responsible for the use of Confidential Information by its Representatives and, in the event of discovery of any unauthorized use or disclosure, must promptly notify the other party.

3.4 **Disclosure required by law**. A party may disclose the other's Confidential Information if required by law, but only after it notifies the other party (if legally permissible) to enable the other party to seek a protective order.

3.5 **Duration of Confidentiality obligation**. These obligations apply: (1) for Customer Data, until it is deleted by Publisher; and (2) for all other Confidential Information, for a period of five years after a party receives the Confidential Information.

### 4. SERVICE LEVEL AGREEMENTS (SLA) <a href="#id-4-service-level-agreements-sla" id="id-4-service-level-agreements-sla"></a>

Publisher may offer further availability and support obligations for an Offering. Such service level agreement ("SLA") will be made available by the Publisher at the applicable URL for such SLA or as otherwise communicated to Customer.

### 5. VERIFYING COMPLIANCE <a href="#id-5-verifying-compliance" id="id-5-verifying-compliance"></a>

5.1 Customer must keep records relating to Offerings it and its Affiliates use or distribution. At Publisher's expense, Publisher may verify Customer's and its Affiliates' compliance with this Agreement by directing an independent auditor (under nondisclosure obligations) to conduct an audit or ask Customer to complete a self-audit process. Customer must promptly provide any information and documents that Publisher or the auditor reasonably requests related to the verification and access to systems running the Offerings. If verification or self-audit reveals any unlicensed use, Customer must order sufficient licenses to cover the period of its unlicensed use. The audits may be conducted more frequently, if required by the party's auditors and/or regulators, of books and records related to this Agreement. The expenses for all such audit will be borne by the party conducting the audit. All information and reports related to the verification process will be Confidential Information and used solely to verify compliance.

5.2 Upon request, Publisher will make available to Customer all information necessary to conduct an audit and demonstrate compliance under GDPR provisions for the processing of Personal Data. Customer may request information through a security questionnaire or self-attestation.

### 6. REPRESENTATION AND WARRANTIES <a href="#id-6-representation-and-warranties" id="id-6-representation-and-warranties"></a>

6.1 Publisher continuously represents and warrants that:

> **a.** it has full rights and authority to enter into, perform under, and grant the rights in, this Agreement;
>
> **b.** its performance will not violate any agreement or obligation between it and any third party;
>
> **c.** the Offering will substantially conform to the Documentation;
>
> **d.** the Offering will not:
>
> > **i.** to the best of Publisher's knowledge, infringe or violate any third party patent, copyright, trademark, trade secret, or other proprietary right; or
> >
> > **ii.** contain viruses or other malicious code that will degrade or infect any products, services, software, or Customer's network or systems, and
>
> **e.** while performing under this Agreement, Publisher will comply with law, including Data Protection Laws and Anti-Corruption Laws, and will provide training to its employees regarding Anti-Corruption Laws.

6.2 **Disclaimer**. Except as expressly stated in this Agreement, the Offering is provided as is. To the maximum extent permitted by law, Publisher disclaims any and all other warranties (express, implied or statutory, or otherwise) including of merchantability or fitness for a particular purpose, whether arising by a course of dealing, usage or trade practice, or course of performance.

### 7. DEFENSE OF THIRD-PARTY CLAIMS <a href="#id-7-defense-of-third-party-claims" id="id-7-defense-of-third-party-claims"></a>

7.1 **By Customer**. Customer will defend Publisher and its Affiliates from and against any and all third party claims, actions, suits, proceedings arising from or related to: Customer's or any authorized user's violation of this Agreement or user terms (a "Claims Against Publisher"), and will indemnify Publisher and its Affiliates for all reasonable attorney's fees incurred and damages and other costs finally awarded against Publisher or its Affiliates in connection with or as a result of, and for amounts paid by Publisher or its Affiliates under a settlement Customer approves of in connection with a Claim Against Publisher. Publisher must provide Customer with prompt written notice of any Claims Against Publishers and allow Customer the right to assume the exclusive defense and control of the claim and cooperate with any reasonable requests assisting Customer's defense and settlement of such matter.

7.2 **By Publisher**. Publisher will defend Customer from and against any and all third party claims, actions, suits, proceedings, and demands alleging that: (i) the use of the Offering as permitted under the Contract infringes or misappropriates a third party's intellectual property rights and (ii) any violation of applicable law including Data Protection Laws (a "Claim Against Customer"), and will indemnify Customer for all reasonable attorney's fees incurred and damages and other costs finally awarded against Customer in connection with or as a result of, and for amounts paid by Customer under a settlement Publisher approve of in connection with a Claim Against Customer; provided, however, that the Publisher has no liability if a Claim Against Customer arises from: (1) Customer Data or non-Publisher products, including third-party software; and (2) any modification, combination or development of the Offering that is not performed or authorized in writing by Publisher, including in the use of any application programming interface (API). Customer must provide Publisher with prompt written notice of any Claim Against Customer and allow Publisher the right to assume the exclusive defense and control and cooperate with any reasonable requests assisting Publisher's defense and settlement of such matter. This section states Publisher sole liability with respect to, and Customer's exclusive remedy against Publisher for, any Claim Against Customer.

7.3 Notwithstanding anything contained in the above subsections (a) and (b), (1) an indemnified party will always be free to choose its own counsel if it pays for the cost of such counsel; and (2) no settlement may be entered into by an indemnifying party, without the express written consent of the indemnified parties (such consent not to be unreasonably withheld), if: (A) the third party asserting the claim is a government agency; (B) the settlement arguably involves the making of admissions by the indemnified parties; (C) the settlement does not include a full release of liability for the indemnified parties; or (D) the settlement includes terms other than a full release of liability for the indemnified parties and the payment of money.

### 8. LIMITATION OF LIABILITY <a href="#id-8-limitation-of-liability" id="id-8-limitation-of-liability"></a>

For each Offering, each party's maximum, aggregate liability to the other under this Agreement is limited to direct damages finally awarded in an amount not to exceed the amounts Customer was required to pay for the Offerings during the term of the applicable licenses, subject to the following:

> **a.** **Subscriptions**. For Offerings ordered on a subscription basis, Publisher's maximum liability to Customer for any incident giving rise to a claim will not exceed the amount Customer paid for the Offering during the 12 months before the incident or $500,000, whichever is greater.
>
> For Offerings ordered on a subscription basis, Publisher's maximum liability to Customer for any unauthorized access, use, or disclosure of Customer Data due to a breach of Publisher's obligations under Section II(6) (Security), Publisher's maximum liability to Customer will not exceed two times (2x) the amount Customer paid for the Offering during the 12 month before the incident or $2,000,000, whichever is greater.
>
> **b.** **Free Offerings and distributable code**. For Offerings provided free of charge and code that Customer is authorized to redistribute to third parties without separate payment to Publisher, Publisher's liability is limited to direct damages finally awarded up to US$5,000.
>
> **c.** **No Indirect Damages**. In no event will either party be liable for indirect, incidental, special, punitive, or consequential damages, or loss of use, loss of profits, or interruption of business, however caused or on any theory of liability.
>
> **d.** **Exceptions**. No limitation or exclusions will apply to liability arising out of either party's: (1) confidentiality obligations under Section 3 (except for liability related to Customer Data, which will remain subject to the limitations and exclusions above); (2) defense obligation under Section 7; (3) violation of the other party's intellectual property rights; or (4) gross negligence, willful misconduct, or fraud.

### 9. PRICING AND PAYMENT <a href="#id-9-pricing-and-payment" id="id-9-pricing-and-payment"></a>

Vizlake will invoice and charge Customer under the terms of the applicable Order.

### 10. TERM AND TERMINATION <a href="#id-10-term-and-termination" id="id-10-term-and-termination"></a>

10.1 **Term**. This Agreement is effective until terminated by a party, as described below. The term for each Order will be set forth therein.

10.2 **Termination without cause**. Unless otherwise set forth in an Order, either party may terminate this Agreement or any Order without cause on 60 days' notice. Termination without cause will not affect Customer's perpetual licenses, and licenses granted on a subscription basis will continue for the duration of the subscription period(s), subject to the terms of this Agreement. Publisher will not provide refunds or credits for any partial subscription period(s) if the Agreement or an Order is terminated without cause.

10.3 **Termination for cause**. Without limiting other remedies it may have, either party may terminate this Agreement or any Order immediately on notice if (i) the other party materially breaches the Agreement or an Order, and fails to cure the breach within 30 days after receipt of notice of the breach; or (ii) the other party becomes Insolvent. Upon such termination, the following will apply:

> **a.** All licenses granted under this Agreement will terminate immediately except for fully-paid, perpetual licenses.
>
> **b.** All amounts due under any unpaid invoices will become due and payable immediately. For metered Offerings billed periodically based on usage, Customer must immediately pay for unpaid usage as of the termination date.
>
> **c.** If Publisher is in breach, Customer will receive a credit for any subscription fees, including amounts paid in advance for unused consumption for any usage period after the termination date.

10.4 **Suspension**. Publisher may suspend use of the Offering without terminating this Agreement during any period of material breach. Publisher will give Customer reasonable notice before suspending the Offering. Suspension will only be to the extent reasonably necessary.

10.5 **Refund**. For Offerings ordered on a subscription basis that are $100,000 or more, if Publisher breaches any of the foregoing warranties and those breaches remain uncured for 30 days, Customer may terminate this Agreement and Publisher will provide Customer a full refund of all fees paid to Publisher.

10.6 **Survival**. The terms of this Agreement, including the applicable Order, that are likely to require performance, or have application to events that may occur, after the termination or expiration of this Agreement or any Order, will survive termination or expiration, including all indemnity obligations and procedures.

### 11. MISCELLANEOUS <a href="#id-11-miscellaneous" id="id-11-miscellaneous"></a>

11.1 **Entire Agreement**. This Agreement supersedes all prior and contemporaneous communications, whether written or oral, regarding the subject matter covered in this Agreement. If there is a conflict between any parts of this Agreement, the following order of precedence will apply:

> **a.** Order;
>
> **b.** this Agreement;
>
> **c.** Service Level Agreement (SLA); and
>
> **d.** Documentation.

11.2 **Independent contractors**. The parties are independent contractors. Customer and Publisher each may develop products independently without using the other's Confidential Information.

11.3 **Agreement not exclusive**. Customer is free to enter into agreements to license, use, and promote the services of others.

11.4 **Amendments**. Unless otherwise agreed in a writing signed by both parties, Publisher will not change the terms of this Agreement, including privacy terms, during the term of this Agreement.

11.5 **Assignment**. Either party may assign this Agreement to an Affiliate, but it must notify the other party in writing of the assignment. Customer consents to the assignment to an Affiliate or third party, without prior notice, of any rights Publisher may have under this Agreement to receive payment and enforce Customer's payment obligations, and all assignees may further assign such rights without further consent. Furthermore, either party may assign this Agreement without the consent of the other party in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all of such party's assets. Any other proposed assignment of this Agreement must be approved by the non-assigning party in writing. Assignment will not relieve the assigning party of its obligations under the assigned Agreement. Any attempted assignment without required approval will be void.

11.6 **Severability**. If any part of this Agreement is held to be unenforceable, the rest of the Agreement will remain in full force and effect.

11.7 **Waiver**. Failure to enforce any provision of this Agreement will not constitute a waiver. Any waiver must be in writing and signed by the waiving party.

11.8 **No third-party beneficiaries**. This Agreement does not create any third-party beneficiary rights except as expressly provided by its terms.

11.9 **Notices**. Notices must be in writing and will be treated as delivered on the date received at the address, date shown on the return receipt, email transmission date, or date on the courier or fax confirmation of delivery. Notices to Publisher must be sent to the address stated in the Order. Notices to Customer will be sent to the individual at the address Customer identifies on its account as its contact for notices. Publisher may send notices and other information to Customer by email or other electronic form.

11.10 **Applicable law**.

> **a.** **United States and Canada**. If you acquired the Offering in the United States or Canada, the laws of the state or province where you live (or, if a business, where your principal place of business is located) govern the interpretation of these terms, claims for breach of them, and all other claims (including consumer protection, unfair competition, and tort claims), regardless of conflict of law principles.
>
> **b.** **Outside the United States and Canada**. If you acquired the Offering in any other country, the laws of that country apply.

11.11 **Order of precedence**. The body of this Agreement will take precedence over any conflicting terms in other documents that are part of this Agreement that are not expressly resolved in those documents. Terms in an amendment control over the amended document and any prior amendments concerning the same subject matter.

11.12 **Government procurement rules**. By accepting this Agreement, Customer represents and warrants that: (1) it has complied and will comply with all applicable government procurement laws and regulations; (2) it is authorized to enter into this Agreement; and (3) this Agreement satisfies all applicable procurement requirements.

11.13 **Compliance with laws**. Publisher will comply with all laws and regulations applicable to its provision of the Offerings. Publisher will obtain and maintain any approvals, licenses, filings, or registrations necessary to its performance, and will comply with all law (including law related to export, corruption, money laundering, or any combination of these). Customer must also comply with laws applicable to their use of the Offerings.

11.14 **Construction**. Neither party has entered this Agreement in reliance on anything not contained or incorporated in it. This Agreement is in English only. Any translation of this Agreement into another language is for reference only and without legal effect. If a court of competent jurisdiction finds any term of the Agreement unenforceable, the Agreement will be deemed modified as necessary to make it enforceable, and the rest of the Agreement will be fully enforced to affect the parties' intent. Lists of examples following "including", "e.g.", "for example", or the like are interpreted to include "without limitation," unless qualified by words such as "only" or "solely." This Agreement will be interpreted according to its plain meaning without presuming that it should favor either party. Unless stated or context requires otherwise:

> **a.** all internal references are to this Agreement and its parties;
>
> **b.** all monetary amounts are expressed and, if applicable, payable, in U.S. dollars;
>
> **c.** URLs are understood to also refer to successors, localizations, and information or resources linked from within websites at those URLs;
>
> **d.** a party's choices under this Agreement are in its sole discretion, subject to any implied duty of good faith;
>
> **e.** "written" or "in writing" means a paper document only, except where email is expressly authorized;
>
> **f.** "days" means calendar days;
>
> **g.** "may" means that the applicable party has a right, but not a concomitant duty,
>
> **h.** "partner," if used in this Agreement or related documents, is used in its common, marketing sense and does not imply a partnership;
>
> **i.** "current" or "currently" means "as of the Effective Date" but "then-current" means the present time when the applicable right is exercised or performance rendered or measured;
>
> **j.** "notify" means to give notice under subsection (i) above; and
>
> **k.** a writing is "signed" when it has been hand-signed (i.e., with a pen) or signed via an electronic signature service by a duly authorized representative of the signing party.

### 12. DEFINITIONS <a href="#id-12-definitions" id="id-12-definitions"></a>

"Affiliate" means any legal entity that controls, is controlled by, or is under common control with a party.

"Anti-Corruption Laws" means all laws against fraud, bribery, corruption, inaccurate books and records, inadequate internal controls, money-laundering, and illegal software, including the U.S. Foreign Corrupt Practices Act.

"Control" means ownership of more than a 50% interest of voting securities in an entity or the power to direct the management and policies of an entity.

"Confidential Information" is defined in the "Confidentiality" section.

"Customer Data" means all data, including all text, sound, software, image or video files that are provided to Publisher or its Affiliates by, or on behalf of, Customer and its Affiliates through use of the Offering. Customer Data does not include Support Data.

"Data Protection Law" means any law applicable to Publisher or Customer, relating to data security, data protection and/or privacy, including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to processing of personal data and the free movement of that data ("GDPR"), and any implementing, derivative or related legislation, rule, regulation, and regulatory guidance, as amended, extended, repealed and replaced, or re-enacted.

"Documentation" means all user manuals, handbooks, training material, requirements, and other written or electronic materials Publisher makes available for, or that result from use of, the Offering.

"End User" means any person Customer permits to use an Offering or access Customer Data.

"Feedback" means ideas, suggestions, comments, input, or know-how, in any form, that one party provides to the other in relation to recipient's Confidential Information, products, or services. Feedback does not include sales forecasts, future release schedules, marketing plans, financial results, and high-level plans (e.g., feature lists) for future products.

"Insolvent" means admitting in writing the inability to pay debts as they mature; making a general assignment for the benefit of creditors; suffering or permitting the appointment of a trustee or receiver for all or any of its (i.e., the non-terminating party's) assets, unless such appointment is vacated or dismissed within 60 days from the date of appointment; filing (or having filed) any petition as a debtor under any provision of law relating to insolvency, unless such petition and all related proceedings are dismissed within 60 days of such filing; being adjudicated insolvent or bankrupt; having wound up or liquidated; or ceasing to carry on business.

"Offering" means all services, websites (including hosting), solutions, platforms, and products identified in an Order and that Publisher makes available under or in relation to this Agreement, including the software, equipment, technology, and services necessary for Publisher to provide the foregoing. Offering availability may vary by region.

"Order" means an ordering document used to transact the Offering via the Marketplace.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Representatives" means a party's employees, Affiliates, contractors, advisors and consultants.

"Standard Contractual Clauses" means the standard data protection clauses for the transfer of personal data to processors established in third countries which do not ensure an adequate level of data protection, as described in Article 46 of the GDPR.

"Subcontractor" means any third party: (1) to whom Publisher delegates its obligations under this Agreement, including a Publisher Affiliate not contracting directly with Customer through an Order; or (2) who, in performing under a contract between it and Publisher or a Publisher Affiliate, stores, collects, transfers or otherwise processes Personal Data (obtained or accessed in connection with performing under this Agreement) or other Customer Confidential Information.

"Support Data" means all data, including all text, sound, video, image files, or software, that are provided to Publisher by or on behalf of Customer (or that Customer authorizes Publisher to obtain from an Offering) through an engagement with Publisher to obtain technical support for the Offering covered under this Agreement.

"Use" means to copy, download, install, run, access, display, use or otherwise interact with.


