FDE Preview Terms
These AWS Forward Deployed Engineering (“FDE”) preview terms and conditions (“Terms”) are subject to the AWS Customer Agreement, or other agreement between you and AWS governing your use of the Services (the “Agreement”). The Terms take effect when you “Accept” an FDE Sprint Letter or, if earlier, when you provide AWS with access to your AWS environment for the purposes of commencing an FDE sprint (the “Effective Date”). You represent to us that you are lawfully able to enter an FDE sprint. If you are entering into an FDE sprint for an entity, such as the company you work for, you represent to us that you have legal authority to bind that entity. Unless otherwise expressly defined in these Terms, all capitalized terms will have the meanings set forth in the Agreement.
1.0. The Service. FDE combines AI agents with AWS experts to help achieve your business outcomes. FDE sprints are intended to be delivered in 45-day sprints where FDE resources will work with you to build, test, debug, implement, and deploy artificial intelligence or machine learning Services, features, functionality, and workflows (collectively “FDE Solutions”) in your AWS environment. FDE is a Service for purposes of the Agreement.
2.0. Agents and AI Services.
2.1. AWS may build and deploy specialized AI agents using AI Services in your environment as part of the sprint (“Customer Agents”). We will tailor Customer Agents using Your Content, and they will remain in your AWS environment after the sprint ends. You will have exclusive use of these agents. The output you generate using these agents is Your Content. Due to the nature of machine learning, output may not be unique across customers and agents developed during a sprint may generate the same or similar results across customers.
2.2. We may use AWS proprietary agents and tooling ("AWS Agents and Tools") in an FDE sprint. In an FDE sprint, AWS Agents and Tools will not access or use Your Content for developing and improving the AWS Agents unless otherwise provided in the Service Terms. For clarity, AWS Agents and Tools are AWS Background IP (as defined below).
3.0 Intellectual Property.
3.1. Each party retains ownership of its intellectual property rights existing prior to or created outside the scope of an FDE sprint ("Background IP"). Each party owns intellectual property rights in improvements it makes to its own Background IP during a sprint, including, for AWS, improvements to Delivery Agents, services, products, tools, and methodologies of AWS and its Affiliates. Neither party may use the other's Background IP unless the other party agrees in writing.
3.2. You own Developed Content we create for you under a sprint that is delivered to you. Developed Content consists of (a) documents and diagrams (“Documents”) (b) software (in source or object code form), sample code, or scripts (“Software”), or (c) machine learning and artificial intelligence assets, including trained or fine-tuned models, model weights, adapters, agents, prompts, orchestration logic, and datasets created specifically for you ("AI/ML Assets"). For clarity, Developed Content does not include Services or improvements to AWS Background IP or Third Party Content. To the extent any Developed Content contains any AWS Background IP, AWS retains ownership of such AWS Background IP and grants you a perpetual, irrevocable, worldwide, non-exclusive, royalty-free, sublicensable, transferable license to distribute, reproduce, make derivative works of, perform, display, use, make, sell, offer for sale, and import such Background IP as part of Developed Content.
3.3. You may, at your sole expense, seek patent protection for any new inventions in Developed Content. Upon your written request, AWS will use commercially reasonable efforts to assist you in perfecting your ownership of patent applications and resulting patents for inventions in Developed Content ("Patents"), including by providing relevant information and signing necessary documents. You hereby grant AWS a perpetual, irrevocable, worldwide, non-exclusive, royalty-free, sublicensable, transferable license under any such Patents to make, use, sell, offer for sale, and import services and products of AWS and its Affiliates.
4.0. Data Access.
4.1. If you direct AWS to access any Content that includes or is defined under applicable law as “personal data,” “personal information,” “controlled unclassified information,” or other sensitive or restricted data types which are defined or governed by applicable law (including data privacy law), regulation, regulatory framework, or industry standard (excluding Content defined under HIPAA law as PHI (defined below)) (collectively, “Customer Regulated Data”), AWS’s processing of such Customer Regulated Data is subject to the AWS Supplementary Data Processing Addendum (the “Supplementary DPA”). For purposes of your FDE sprints, terms in the Supplementary DPA have the following meanings: “AWS Professional Services” means AWS FDE, “Professional Services Order” means these FDE Preview Terms, and “AWS Professional Services Consultants” means AWS FDEs.
A. For clarity, your “Documented Instructions”, as used in the Supplementary DPA, includes your written guidance which may be formally or informally communicated to FDEs. You acknowledge that you are solely responsible for determining how Customer Regulated Data is collected, used, stored, and processed, and that AWS will only process such Customer Regulated Data in accordance with the Documented Instructions. You may provide verbal guidance to FDEs but when such guidance establishes a new processing instruction or changes an existing processing instruction, you agree to confirm such instruction in writing within a reasonable period (not to exceed 48 hours) by email, ticketing system entry, shared project record, meeting notes, or other similar written mechanism, as reasonably assisted by AWS. You acknowledge that it is your responsibility to ensure such written confirmation occurs, and that AWS's processing of Customer Regulated Data will be based on, and limited to, the Documented Instructions as so confirmed
4.2. If you direct AWS to access any Content that includes or is defined under the Health Insurance Portability and Accountability Act (“HIPAA”) as “protected health information” (“PHI”), AWS’s processing of such PHI is subject to the terms of the AWS FDE Business Associate Addendum (“FDE BAA”) between you and AWS attached as Exhibit 1.
4.3. Incidental personal data related to your personnel that AWS obtains as part of an FDE sprint is not Customer Regulated Data. This type of data is treated as “Account Information,” and AWS and its affiliates will handle it in accordance with the AWS Privacy Notice (available at https://aws.amazon.com/privacy/), which you will make available to your personnel.
5.0. Production Access.
5.1. An FDE sprint may require AWS to provide services in your Production Environment (environments where software, applications, code, or other products are placed into live operation for their intended use by internal or external end users). You may not allow AWS to access your Production Environment until you and AWS review and mutually approve security access, controls, and policies, which include technical controls (i.e., least privilege access controls, logging, monitoring, and alerting, encryption), and operational controls (i.e., written instructions, change management plans, onboarding, and offboarding procedures to access) (“Security Plan”). AWS will follow the security mechanisms agreed with you in the Security Plan. You authorize such access specified in the Security Plan and agree that AWS will only provide services in your Production Environment consistent with the Security Plan and only at your express direction received by AWS prior to providing FDEs production access.
5.2. For the duration of time you provide AWS with access to your Production Environment, you must ensure you provide AWS with the least privileged access necessary for AWS to complete our activities. Upon completion of the activities that require Production Access, you are responsible for ensuring that any AWS access to your Production Environment is promptly revoked.
6.0. Customer Rights and Responsibilities.
6.1. You will cooperate with AWS to help ensure the FDE sprint is delivered on time, which includes promptly providing AWS with access to data, tools, software licenses, source code, equipment, engineering resources who will work alongside FDEs, and any other reasonably necessary resources to support the FDE sprint.
6.2. To assist with delivery of the FDE sprint, you will install and onboard, or allow FDEs to install and onboard, the AWS Agents and Tools in your AWS environment.
6.3. While FDEs may advise and assist, you remain responsible for all activities within your Production Environment including: (a) determining deployment-readiness of deliverables and managing their subsequent deployment, operation, and maintenance; (b) overall management of AWS accounts, pipelines, deployment gates, and logs and records; (c) all access and permissions control, and (d) testing, deploying, maintaining, implementing, and supporting any Developed Content or deliverables provided or recommended by FDEs.
6.4. You are responsible for compliance with any applicable regulatory requirements prior to your use or the deployment of any FDE Developed Content, including obtaining the appropriate clearances or approvals.
6.5. You are responsible for ensuring your directions to FDEs comply with applicable laws, rules, regulations, and policies.
7.0. Out of Scope Activities. AWS does not provide, and an FDE sprint does not constitute, financial, legal or compliance advice. You are responsible for determining whether your use of any FDE Solution complies with applicable laws, rules, regulations, and policies.
8.0. Use Case Limitations
8.1. You are responsible for ensuring that FDE Solutions, including but not limited to their design, intended purpose, and their use, comply with all applicable laws, rules, regulations, and policies. This includes laws specific to artificial intelligence such as the EU AI Act and all AWS Policies, including but not limited to the AWS Responsible AI Policy and the AWS Acceptable Use Policy
8.2. FDE Solutions are not authorized for use in, or in association with, the operation of any hazardous environment or critical systems that may lead to serious bodily injury or death or cause environmental or property damage, and you are solely responsible for liability that may arise in connection with any such use.
8.3. FDE Solutions are not authorized for use in providing security or investment advice or facilitating trades for third parties.
8.4. FDE Solutions are not designed for finished medical devices, are not intended to be used in finished medical devices, are not intended to enable the clinical functionality of a finished medical device and are not authorized for use by themselves for any clinical decision-making or other clinical use.
8.5. FDE Solutions may not be sold, commercialized, or marketed under AWS’s name or branding.
9.0. Limitation of Liability.
9.1. AWS and its affiliates will not be liable to you for any damages arising from (a) AWS’s actions taken pursuant to any instructions or requests that you provide or approve, (b) you not following an instruction or recommendation from AWS, (c) your delay or withholding of approval for AWS to take a requested action, or (d) any change by you to your AWS Environment.
9.2. You are solely responsible for all modifications to your Production Environment, including those performed by AWS at your direction. AWS will not be liable for any damages arising from any access to your Production Environments.
10.0. Business Relationship. AWS's relationship with Customer is that of an independent contractor, and nothing in these Terms will be construed to create a partnership, agency, joint venture, employment or similar relationship. AWS's personnel will not be considered Customer's employee or agent under these Terms. Neither Party will have any right to act for, represent or otherwise bind the other Party in any manner, except as expressly authorized by such other Party.
11.0. Taxes. Each party will be responsible for any taxes imposed on that party with respect to the development, delivery, ownership, or use of work product created under a FDE sprint. For purposes of applicable tax law, including value added tax, goods and services tax, and similar indirect taxes, FDE is professional and consulting services and not electronically supplied services.
12. Termination. Either party may terminate immediately for breach of these Terms.
Exhibit 1 - AWS Forward Deployed Engineering Business Associate Addendum
THIS AWS FORWARD DEPLOYED ENGINEERING BUSINESS ASSOCIATE ADDENDUM (this “Addendum”) to the AWS Customer Agreement located at http://aws.amazon.com/agreement (and any successor locations designated by AWS) by and between the Customer on an FDE sprint (“you”) and Amazon Web Services, Inc. (“AWS”), or other agreement between you and AWS governing your use of the Services (the “Agreement”). Unless otherwise expressly defined in this Addendum, all capitalized terms in this Addendum will have the meanings set forth in the Agreement or in HIPAA.
The parties agree as follows:
- Applicability. This Addendum applies only to the Use and Disclosure of PHI by AWS Forward Deployed Engineering (FDE) Consultants to deliver FDE to you. You acknowledge and agree that this Addendum does not apply to the creation, receipt, maintenance, or transmission by the Services of any “protected health information” (as defined in 45 C.F.R. § 160.103) in an AWS account. Prior to or concurrently with accepting this Addendum, you must enter into a separate business associate addendum with AWS (an “AWS BAA”) applicable to such accounts. Both this Addendum and the AWS BAA will be addenda to the Agreement and will apply in accordance with their respective terms.
- Permitted Uses and Disclosures.
- AWS Forward Deployed Engineering. AWS may Use or Disclose PHI for or on behalf of you to deliver FDE as agreed upon between you and AWS.
- Administration and Management of AWS. AWS may Use and Disclose PHI as necessary for the proper management and administration of AWS. Any Disclosures under this section will be made only if AWS obtains reasonable assurances from the recipient of the PHI that (a) the recipient will hold the PHI confidentially and will Use or Disclose the PHI only as required by law or for the purpose for which it was Disclosed to the recipient, and (b) the recipient will notify AWS of any instances of which it is aware in which the confidentiality of the information has been breached.
- Obligations of AWS.
- Limit on Uses and Disclosures. AWS will Use or Disclose PHI only as permitted by this Addendum or as required by law, provided that any such Use or Disclosure would not violate HIPAA if done by a Covered Entity, unless permitted under HIPAA for a Business Associate.
- Safeguards. AWS will use reasonable and appropriate safeguards to prevent Use or Disclosure of the PHI other than as provided for by this Addendum, consistent with the requirements of Subpart C of 45 C.F.R. Part 164 (with respect to Electronic PHI) as determined by AWS.
- Reporting.
- Reporting of Impermissible Uses and Disclosures. AWS will report to you any Use or Disclosure of PHI by FDE Consultants not permitted or required by this Addendum of which AWS becomes aware.
- Reporting of Security Incidents. AWS will report to you any Security Incidents involving PHI of which AWS becomes aware in which there is a successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an Information System in a manner that risks the confidentiality, integrity, or availability of PHI that are caused by an FDE Consultant in the course of delivering FDE to you. Notice is hereby deemed provided, and no further notice will be provided, for unsuccessful attempts at unauthorized access, use, disclosure, modification, or destruction, such as pings and other broadcast attacks on a firewall, denial of service attacks, port scans, unsuccessful login attempts, or interception of encrypted information where the key is not compromised, or any combination of the above.
- Reporting of Breaches. AWS will report to you any Breach of your Unsecured PHI that AWS may discover to the extent required by 45 C.F.R. § 164.410. AWS will make such report without unreasonable delay and in no case later than 60 calendar days after discovery of such Breach.
- Subcontractors. If AWS engages any Subcontractors to deliver FDE for you, AWS will ensure that any such Subcontractors that create, receive, maintain, or transmit PHI on behalf of AWS agree to restrictions and conditions at least as stringent as those found in this Addendum, and agree to implement reasonable and appropriate safeguards to protect PHI.
- Access to PHI. AWS will make PHI in a Designated Record Set available to you so that you can comply with 45 C.F.R. § 164.524.
- Amendment to PHI. AWS will make PHI in a Designated Record Set available to you for amendment and incorporate any amendments to the PHI, as may reasonably be requested by you in accordance with 45 C.F.R. § 164.526.
- Accounting of Disclosures. AWS will make available to you the information required to provide an accounting of Disclosures in accordance with 45 C.F.R. § 164.528 of which AWS is aware, if requested by you.
- Internal Records. AWS will make its internal practices, books, and records relating to the Use and Disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services (“HHS”) for purposes of determining your compliance with HIPAA. Nothing in this section will waive any applicable privilege or protection, including with respect to trade secrets and confidential commercial information.
- Your Obligations.
- Necessary Consents. You warrant that you have obtained any necessary authorizations, consents, and other permissions that may be required under applicable law prior to providing FDE Consultants with access to PHI.
- Restrictions on Disclosures. You will not agree to any restriction requests or place any restrictions in any notice of privacy practices that would cause AWS to violate this Addendum or any applicable law.
- Impermissible Requests. You will not request or cause AWS to make a Use or Disclosure of PHI in a manner that does not comply with HIPAA or this Addendum or your privacy practices.
- Appropriate Safeguards. You will implement appropriate privacy and security safeguards in order to protect your PHI in compliance with HIPAA and this Addendum.
- Term and Termination.
- Term. The term of this Addendum will commence on the Addendum Effective Date and will remain in effect until the earlier of (a) the termination of the Agreement or (b) the termination of this Addendum by either party as set forth in Section 5.2 below.
- Termination. Either party has the right to terminate this Addendum for any reason upon 90 days’ prior written notice to the other party. A material breach of this Addendum will be treated as a material breach of the Agreement.
- Effect of Termination. At termination of the Addendum, AWS, if feasible, will return or destroy all PHI not in your AWS accounts that FDE Consultants still maintain in any form and retain no copies of such information or, if such return or destruction is not feasible, extend the protections of this Addendum to the information and limit further Uses and Disclosures to those purposes that make the return or destruction of the information infeasible.
- No Agency Relationship. As set forth in the Agreement, nothing in this Addendum is intended to make either party an agent of the other. Nothing in this Addendum is intended to confer upon you the right or authority to control AWS’s conduct in the course of AWS complying with the Agreement and Addendum.
- Entire Agreement; Conflict. Except as amended by this Addendum, the Agreement will remain in full force and effect. This Addendum, together with the Agreement as amended by this Addendum and any AWS BAA: (a) is intended by the parties as a final, complete and exclusive expression of the terms of their agreement; and (b) supersedes all prior agreements and understandings (whether oral or written) between the parties with respect to the subject matter hereof. If there is a conflict between the Agreement and this Addendum, this Addendum will prevail. If there is a conflict between any other addendum or amendment to the Agreement covering the subject matter hereof and this Addendum, the document later in time will prevail.
- Definitions.
- “FDE Consultant” means an AWS employee providing FDE services.
- “HIPAA” means the Administrative Simplification Subtitle of the Health Insurance Portability and Accountability Act of 1996, as amended by Subtitle D of the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations.
- “PHI” means “protected health information” as defined in 45 C.F.R. § 160.103 that is Used or Disclosed by an FDE Consultant.