Version 0.1Effective September 17, 2026

Product-Specific Authorizations (Annex B)

Status: Draft — for legal review; not legal advice Version: 0.1 Released: 2026-09-17 Effective date: 2026-09-17 Note: this is the published version's effective date; a signed Order Form incorporates the version current at signing. Owner: Pranab Document key: authorizations (see docs/specs/contracting-flow.md) Execution: Annex B to every Order Form (signed with it). Also published at /authorizations and incorporated into the Terms of Service (§3.4): for self-serve clients, each grant is shown in the dashboard when the corresponding feature is configured and is made by completing that configuration.


This annex records the authority the Client gives [MISSING: entity.legal_name] ("TurboDemand") to act on the Client's systems, domains, and behalf. Each grant is limited to the Client Domains listed in Section 4 of the Order Form (or configured in the dashboard) and lasts for the Subscription Term plus the wind-down period in Section 6, unless revoked earlier in writing. Revoking a grant may make part of the Service impossible to deliver; the Fees are unaffected unless the Agreement says otherwise.

The Client confirms that the person signing the Order Form, and each client administrator who configures these features in the dashboard, has authority to make these grants.

1. Crawling and use of Client website content and brand assets

1.1 The Client authorises TurboDemand to crawl, fetch, and store the content of the websites listed as "Websites authorised for crawling" in the Order Form (and any other website the Client adds in the dashboard), including pages, images, logos, PDFs, sitemaps, structured data, and linked assets on those domains, and to extract from them the Client's brand knowledge: company identity, products and services, locations, people, credentials, testimonials, reviews, and style.

1.2 The Client authorises TurboDemand to use the Client's name, logos, trademarks, brand colours, typography, imagery, and other brand assets in Generated Content and on the Microsite, and to submit them, together with extracted brand knowledge, to the LLM and image providers listed in the Data Processing Agreement for the purpose of producing content.

1.2a TurboDemand's crawler honours robots.txt Allow and Disallow rules on the authorised websites and reads the site's /sitemap.xml. Pages the Client's own robots.txt disallows are not fetched; if the Client wants them used, the Client adjusts its robots.txt or uploads the content directly. The crawler is bounded in page count and request rate and identifies itself with the User-Agent Mozilla/5.0 (compatible; TurboDemand/1.0; +https://turbodemand.com/bot) (robots product token turbodemand).

1.3 The Client warrants that it owns or is licensed to use the content and assets on the authorised websites, that crawling them does not breach any agreement (for example a website builder's or agency's terms), and that people named or pictured on those pages have consented to that use where required.

1.4 The Client authorises TurboDemand to connect to review platforms (Google Business Profile, Trustpilot, or others the Client links) using credentials the Client provides, to import the Client's ratings and reviews for display on the Microsite.

2. Publishing on the Client's domain

2.1 The Client authorises TurboDemand to publish, update, and unpublish Generated Content and supporting assets on each Client Domain, at the feeds path or subdomain in the Order Form, in the Client's name, at the cadence the Plan and editorial calendar define.

2.2 The Client acknowledges that the Client is the publisher of the Microsite and that TurboDemand acts as its agent for publication only within this annex. TurboDemand may hold back or unpublish content it believes breaches the Acceptable Use Policy or creates legal risk, and will tell the Client when it does.

2.3 The Client authorises TurboDemand to emit sitemaps, robots directives, canonical tags, hreflang tags, structured data (JSON-LD), redirects within the feeds path, and Open Graph metadata for the Microsite, and to submit the Microsite to search engines through Google Search Console where the Client connects it.

3. Deployment to the Client's host and custody of deploy credentials (Client-host mode)

Applies where the Order Form's deploy target mode is "Client host (SSH)".

3.1 The Client authorises TurboDemand to connect over SSH to the host, port, username, and remote path the Client configures as a deploy target, and to synchronise built Microsite files to that path. Synchronisation mirrors the destination path exactly: files not part of the current build are removed from that path. The Client must therefore provide a path dedicated to the Microsite (at least three path segments deep; the platform refuses home or system directories) and must not place other files there. In releases mode, each deploy writes to a new timestamped directory under the path and switches a current symlink; the last 20 releases are retained for rollback.

3.2 Credentials. The Client either (a) generates an SSH key pair and gives TurboDemand the private key for a deploy-only user, or (b) within 24 hours installs TurboDemand's published public key in the deploy user's authorized_keys. Under (a) TurboDemand becomes custodian of the Client's key material and will: store it encrypted (AES-256-GCM) with the master key outside the database; never display it after save (only its fingerprint); decrypt it only in the deploy worker at deploy time; write it to a temporary file with owner-only permissions and delete it when the deploy ends; use it only for the deploy target it was given for; and pin the host's SSH fingerprint, refusing to connect if it changes until the Client confirms the new fingerprint.

3.3 The Client will: create a dedicated deploy user with write access limited to the Microsite path; not reuse the key for any other purpose; rotate the key on request and after any suspected compromise; and tell TurboDemand promptly of host, path, or key changes. TurboDemand will test the connection before activating a target and on request.

3.4 TurboDemand may add or change its published deploy public key on notice; the Client will install the new key within 30 days.

3.5 On termination, TurboDemand deletes the stored key material within the retention period in Section 6 and, on request, immediately. The Client should also remove the key from the host.

4. TurboDemand-hosted mode and lead-capture endpoints

Applies where the deploy target mode is "TurboDemand-hosted" (subdirectory proxy or subdomain).

4.1 The Client authorises TurboDemand to serve the Microsite from infrastructure operated by TurboDemand and its hosting sub-processors (currently a shared static origin at DreamHost behind Cloudflare, with per-client unguessable path tokens so that no client's pages are reachable under another client's prefix), and to serve the lead-capture and analytics API from TurboDemand's application servers, both under the Client Domain.

4.2 The Client authorises TurboDemand to set TLS certificates for the Client Domain or subdomain through Cloudflare where TurboDemand controls the DNS or the CNAME target.

5. DNS and reverse-proxy authorisation for subdirectory mode

Applies where the deploy target mode is "TurboDemand-hosted, subdirectory proxy". Two methods exist; the Order Form states which.

5.1 Managed nameservers (TurboDemand holds the zone)

5.1.1 The Client authorises TurboDemand to create a DNS zone for the Client's apex domain in TurboDemand's Cloudflare account; to discover and replicate the Client's existing DNS records (A, AAAA, CNAME, MX, TXT including SPF, DKIM, DMARC and verification records, SRV, and others) into that zone before any switch; to deploy a reverse-proxy Worker and a single route matching {{domain}}/{{feeds_path}}/* that forwards to TurboDemand's origin; and to hold the zone and serve DNS for the whole domain for as long as the Client's nameservers point at Cloudflare's assigned nameservers.

5.1.2 The Client understands and agrees that: (a) TurboDemand cannot guarantee it has discovered every existing record, and will not ask the Client to switch nameservers until its automated discovery reaches a confidence threshold and every discovered record resolves identically from the new zone; (b) a low-confidence or mismatching result blocks the switch until a human review is complete; (c) the Client will supply any record TurboDemand asks it to confirm; (d) the Client performs the nameserver change at its registrar and remains responsible for its registrar account; (e) after cutover the Client manages its own records through the dashboard DNS editor, where TurboDemand's routing records are read-only; (f) TurboDemand monitors the domain for 72 hours after cutover and will, with the Client, roll back by nameserver reversion if a regression is confirmed. Nameserver changes are never automated.

5.1.3 Offboarding. TurboDemand will never delete a delegated zone while the Client's nameservers still point at it. On termination or a change of topology, TurboDemand exports the zone's records to the Client, the Client repoints its nameservers, and only then does TurboDemand remove the Worker, route, and zone.

5.1.4 TurboDemand uses its own Cloudflare account and API token for this method and takes custody of no Client credential.

5.2 Manual method (Client applies the proxy in its own Cloudflare account)

5.2.1 TurboDemand provides the exact Worker script and route (as copy-paste instructions, a one-click deploy, or a Terraform snippet). The Client applies them in its own Cloudflare account. TurboDemand holds no credential and makes no change to the Client's DNS. The Client is responsible for keeping the route in place and for applying updated Worker versions TurboDemand publishes.

5.2.2 A scoped-API-token method — in which the Client pastes a Cloudflare API token so TurboDemand can deploy the Worker into the Client's account — is not offered. If it is offered later, this annex will be versioned with a clause covering the token's account-wide Workers scope, naming convention, logging, expiry, and revocation.

6. Content, credentials, and takedown on termination

6.1 The Client owns Generated Content per the Agreement and may keep hosting it after termination. In Client-host mode the published files remain on the Client's host and TurboDemand does not remove them. In TurboDemand-hosted mode the retention rule in 6.3 applies (served for 90 days after the end date, then no longer served unless the hosting-only plan is selected).

6.2 Lead forms on the Microsite stop accepting submissions at termination and return the response the Client configured (redirect or thank-you message). The analytics endpoint stops recording.

6.3 In Client-host mode the files remain on the Client's host. In TurboDemand-hosted mode TurboDemand continues serving the pages during the 90-day retention period and, if the Client selects hosting-only, thereafter under that plan; otherwise TurboDemand stops serving them at the end of the retention period. The Client can take a static export (HTML and assets, downloadable for 90 days) to host elsewhere.

6.4 The Client removes the Microsite from its domain, if it wishes, by removing the proxy route, subdomain CNAME, or files on its own host. TurboDemand provides written instructions and, for managed-nameserver zones, the offboarding steps in 5.1.3.

6.5 TurboDemand deletes deploy keys, connected-mailbox credentials, integration tokens, and other Client credentials by crypto-shredding at the end of the retention period or sooner on request, and confirms deletion in writing.

7. Lead forms, notifications, and email sent on the Client's behalf

7.1 The Client authorises TurboDemand to render lead-capture forms on the Microsite, to receive submissions at TurboDemand's servers, to apply spam filtering and lead scoring, to store leads in the Client's organisation, and to forward leads to the notification and CRM destinations the Client configures (email to Client users, Slack, Zapier, webhooks, HubSpot, Salesforce).

7.2 Emails to the Client's own users (lead alerts, reports, invitations, onboarding sequences, billing) are sent by TurboDemand from noreply@turbodemand.com or another TurboDemand address. TurboDemand does not email the Client's visitors or leads unless a feature the Client enables says so.

7.3 Outreach email (for example backlink outreach) is sent only from a mailbox the Client connects (SMTP, Gmail, or Microsoft 365 credentials stored encrypted), as the Client, after the Client approves each message or schedule. The Client is the sender of record and responsible for compliance with anti-spam law, opt-outs, and its mail provider's terms. TurboDemand will not send outreach from a TurboDemand identity on the Client's behalf. (Pre-issue engineering condition: confirm the legacy outreach@ send path in docs/specs/backlink-outreach-sending.md §1.2 is disabled or migrated before this clause is issued.)

8. AI-generated content disclosure and review responsibility

8.1 The Client acknowledges that Generated Content is produced with large language models and image models operated by the providers in the Data Processing Agreement, guided by TurboDemand's prompts and the Client's brand knowledge, and reviewed under the editorial process for the Client's Plan.

8.2 TurboDemand grounds product, service, credential, and location claims in the Client's own website content and structured brand knowledge, and applies automated grounding checks; content that fails those checks is held for review or omitted. These controls reduce but do not eliminate error.

8.3 The Client is responsible for the factual accuracy and regulatory compliance of content published under its brand and will review Generated Content, especially specifications, prices, certifications, statistics, comparisons, and testimonials, using the review and override tools, and correct or unpublish inaccurate content promptly. TurboDemand will correct or regenerate content the Client flags within 2 business days.

8.4 Where law or the Client's own policies require disclosure that content is AI-assisted, the Client is responsible for that disclosure on the Microsite; TurboDemand can add a configurable disclosure line on request.

8.5 The Client may provide, and TurboDemand may store, feedback rules that constrain future generation (for example claims never to make, terms to avoid). TurboDemand applies them on a best-effort basis to future content.

9. Integrations the Client connects

By connecting an integration in the dashboard (Google Search Console, HubSpot, Salesforce, Slack, Zapier, generic webhook, WordPress, Shopify, Google Business Profile, Trustpilot, Google Ads, or a mailbox), the Client authorises TurboDemand to store the credential encrypted, to call the integration on the Client's behalf for the purpose shown in the dashboard, and to send the data described there. The Client can disconnect at any time, which revokes the grant for that integration.

10. Bring-your-own LLM keys

Where the Client provides its own LLM API keys, the Client authorises TurboDemand to store them encrypted and to use them for the Client's content generation only; the Client selects whether a failing key falls back to TurboDemand's platform key or fails closed, and TurboDemand notifies the Client on every fallback or failure.

11. Versioning of this annex

This annex is versioned. An Order Form incorporates the version in force at signature. TurboDemand may issue a new version for new features; a new grant applies to a Client only when the Client signs an Order Form referencing it or a client administrator enables the feature in the dashboard and accepts the grant shown there.