The OpenAI Services Agreement is the contract for OpenAI’s business offerings. It “only applies to use of OpenAI’s APIs, ChatGPT Enterprise, ChatGPT Business, ChatGPT for Clinicians, and other services for customers who are businesses and developers”, and not to consumer use.[1] The version effective 2026-01-01 is the one cited here. Its commercial terms, such as Order Forms, renewal, minimum commitments and price changes, are summarised in OpenAI licensing. This article covers who and what the agreement licenses, the restrictions that matter in a compliance review, and the data controls that OpenAI publishes for business customers: retention settings, Zero Data Retention, Modified Abuse Monitoring and data residency.[2][3] Seat and token pricing is in OpenAI ChatGPT and API licensing.
Editions
The documents that make up the agreement
Where documents conflict, they apply in this order: the Order Form, the Service-Specific Terms, the Agreement, then the OpenAI Policies.[1] The OpenAI Policies are the Service-Specific Terms, the Sharing and Publication Policy and the Usage Policies. The version that applies is the one in effect on the latest of the Agreement’s effective date, the customer’s most recent Order Form, or its last renewal. New services added later follow the policies in force when the customer starts using them.[1] A customer’s applicable policy set therefore moves at each renewal, not only when OpenAI publishes a change.
Governing law
The Governing Laws are those of Ireland for customers in the EEA, Switzerland or the UK, and of California for all other customers.[1]
Metrics
The agreement sets no metric itself: Fees are those charged under an Order Form or, without one, the Pricing Page.[1] For usage-based purchases, OpenAI charges “based on the usage calculated by OpenAI”, so OpenAI’s metering is the contractual count.[1]
Counting / floors
Workspaces and Affiliates
OpenAI provisions the Services “to specific entities using dedicated workspaces and organizational IDs”. Affiliates may use the Services under the customer’s Account, in the same workspace and organization ID, and the customer is liable for their acts. If an Affiliate’s purchase and use is meant to be separate, it must sign its own Order Form and receives its own workspace and organization ID.[1] An inventory of OpenAI entitlements in a group of companies should therefore map each workspace or organization ID to the Order Form that funds it.
End Users and accounts
An End User is anyone who accesses the Services under the customer’s Account or uses a Customer Application, including employees, consultants, customers, agents and students of the customer and its Affiliates.[1] The use right includes integrating the API into Customer Applications and making them available to End Users.[1] Three account rules bear on seat counting:[1]
- An End User Account may only be provisioned to, registered for and used by a single End User.
- The customer may not share Account credentials or individual logins between multiple users.
- The customer may not resell or lease access to its Account or any End User Account, and may not buy, sell or transfer API keys with a third party.
The customer must also obtain any End User consents needed for Administrators to carry out the activities the Agreement describes.[1]
Restrictions
Besides the account rules, the customer may not, and may not let End Users:[1]
- use Output to develop AI models that compete with OpenAI’s products and services, except for a Permitted Exception;
- reverse engineer the Services, or extract data other than as the Services permit;
- circumvent rate limits, Usage Limits or safety mitigations;
- allow minors to use the Services without parental or guardian consent.
The Permitted Exception covers using Output to build models “primarily intended to categorize, classify, or organize data (e.g., embeddings or classifiers)” that are not distributed or sold to third parties, and to fine-tune models through OpenAI’s own services.[1] If an End User breaches the Agreement, OpenAI may ask the customer to suspend that account, and may do so itself if the customer does not act promptly.[1]
Data controls
Content ownership and training
The customer retains ownership of Input and owns Output. OpenAI may use Customer Content only to provide the Services, comply with law, enforce its policies and prevent abuse, and “will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use”.[1] OpenAI’s enterprise privacy page states the same default for ChatGPT Business, Enterprise, Healthcare, Edu, Teachers and the API Platform after 2023-03-01, with training only where the customer has “explicitly opted in”, for example through feedback mechanisms.[2] Business data may be run through automated classifiers, which create metadata but do not contain the data itself.[2]
ChatGPT retention and access
| Plan | Who controls retention | Admin access to conversations |
|---|---|---|
| ChatGPT Enterprise, Edu, Healthcare | Workspace admins; deleted conversations removed within 30 days unless legally required | Audit log of conversations and GPTs through the Enterprise Compliance API |
| ChatGPT Business | Workspace admins; deleted or unsaved conversations removed within 30 days, with exceptions for law and harm prevention | Admins can view, access, export and delete End User conversations |
| ChatGPT for Teachers | Each workspace member | Not stated |
Source: OpenAI enterprise privacy FAQ.[2] For Enterprise, Edu and Healthcare, authorized OpenAI employees access conversations only to resolve incidents, to recover conversations with the customer’s explicit permission, or where required by law.[2] Workspace admins also control which apps are connected, and data accessed through apps is not used for training by default.[2]
API retention controls
By default, abuse monitoring logs, which may contain prompts and responses, are kept for up to 30 days for all API usage.[3] Two controls, available only after OpenAI’s prior approval and acceptance of additional requirements, change this:[3]
- Modified Abuse Monitoring excludes customer content from abuse monitoring logs across all endpoints, apart from image and file inputs in rare cases.
- Zero Data Retention (ZDR) does the same and also forces the
storeparameter of/v1/responsesand/v1/chat/completionsto false.
The controls are set per organization, with a project-level override, under Settings, Organization, Data controls.[3] ZDR does not stop every endpoint from keeping data. The documentation’s endpoint table shows endpoints such as /v1/assistants, /v1/threads, /v1/vector_stores, /v1/files, /v1/batches and /v1/fine_tuning/jobs as not ZDR-eligible, with application state retained “Until deleted”.[3] OpenAI may also, with advance written notice, make specific models ineligible for these controls for a customer, for example under Safety Retention where needed to investigate severe risk activity.[3] Customers using either control remain responsible for their users’ compliance with OpenAI’s policies.[3]
Data residency
Data residency is a per-project setting, subject to eligibility, that stores customer content at rest in a selected region where the endpoint needs persistence, and also runs inference there in regions that support regional processing.[3] It does not cover system data such as account data, usage statistics and billing information.[3] Regions other than the United States require approval for abuse monitoring controls and a Modified Retention amendment, and the United Arab Emirates region needs further approval.[3] Data residency endpoints carry “a 10% uplift” for eligible models released on or after 2026-03-05, which affects the price of the same token count.[3]
Cloud / BYOL
The customer “obtains only a limited right to use the Services”, and no ownership rights pass to it or its End Users.[1] Third-Party Services reachable through the Services are governed by their own Third-Party Service Terms as well as the Agreement.[1]
Programs
Security, audit reports and DPA
OpenAI has independent audits of its security controls and, on written request “no more than once per year”, provides the most recent Audit Reports, which are OpenAI Confidential Information.[1] ChatGPT Enterprise, Edu, Healthcare and Business and the API Platform have each completed a SOC 2 Type 2 audit.[2] If the customer processes Personal Data, the DPA applies and is incorporated into the Agreement; OpenAI executes DPAs for ChatGPT Business, ChatGPT Enterprise and the API through a request form, while ChatGPT Edu and for Teachers use a Student Data Privacy Agreement.[1][2] Protected Health Information may be processed only under a signed Healthcare Addendum and only with services designed for it.[1]
Changes and exit
If an update materially reduces functionality, the customer may terminate on thirty days’ notice given within five business days of OpenAI’s notice; beta features are excluded. A material reduction in the Security Measures gives a similar right.[1] On termination, OpenAI deletes all Customer Content within thirty days unless legally required to keep it or agreed otherwise in writing.[1] OpenAI may assign the Agreement to an Affiliate without notice or consent.[1]
Out of scope
- Consumer Terms of Use and individual Plus and Pro plans.
- The text of the DPA, Service-Specific Terms and Healthcare Addendum.
- Negotiated enterprise amendments, which can change retention and other terms.
- Data residency region list and per-region endpoint support.