Terms of Service
Last updated: [effective date]
These Terms of Service (the "Terms") govern access to and use of the daat.red service, comprising the REST API at api.daat.red, the operator console at app.daat.red, and the website at daat.red (together, the "Service").
The Service is provided by Red Code Company, s.r.o., IČO 22385151, with its registered seat at Děčínská 552/1, Střížkov, 180 00 Prague 8, Czech Republic ("Red Code Company", "we", "us", "our").
The Service is for businesses only. By requesting access, creating an account, or using the Service, you represent that you are acting in the course of a trade, business, craft or profession, and that the person accepting these Terms is authorised to bind the organisation identified in the account (the "Client", "you", "your"). If you do not agree to these Terms, do not use the Service.
1. Definitions
- "Account" — the Client's registered account for the Service.
- "API" — the daat.red application programming interface and its documented methods.
- "API Key" — a credential issued to the Account for authenticating API calls, optionally restricted by a source-IP allow-list.
- "AUP" — the Acceptable Use Policy at [AUP URL], as amended from time to time.
- "Client Data" — data, including personal data, that the Client or its users submit to the API.
- "Credits" — prepaid units of usage purchased or allocated to the Account.
- "DPA" — the Data Processing Agreement at [DPA URL].
- "Documentation" — the technical documentation for the API made available by us.
- "Results" — the responses, verdicts, indicators, codes and reference data returned by the API.
- "Sandbox" — any test or sandbox environment we may make available.
- "Order" — an order form, online sign-up, written confirmation or other document by which the parties agree Account-specific commercial terms (including pricing and Credit allocation).
2. The Service
2.1 The Service provides pre-authorization payment-data and identity-verification checks through the following methods: Card check, Card info, BIN lookup, IP info, Email info, Email check, and Balance. Each method is described in the Documentation.
2.2 Card check verifies whether a cardholder name supplied by the Client matches the card issuer's records. To perform the check, we forward the verification request to the relevant card network / payment system, under our own direct contractual relationships with those networks, and return the network's response together with a check code. Only the transaction chosen by the Client determines which network is involved.
2.3 We may modify, add, deprecate or remove methods, endpoints, response fields and features. We will use reasonable efforts to give advance notice of changes that are materially adverse to Clients, through the console or by email, and to maintain deprecated functionality for a reasonable transition period where practicable.
2.4 The Results are informational signals. They are not instructions, recommendations or decisions, and they do not constitute legal, compliance, payments or credit advice.
3. Access, accounts and eligibility
3.1 Access is granted per Account following a request to us and our approval, at our discretion. We may decline or revoke access.
3.2 The Client must provide accurate and complete registration information and keep it current.
3.3 The Client is responsible for all activity under its Account and API Keys, whether or not authorised by the Client.
4. API Keys and security
4.1 The Client must keep API Keys confidential, store them securely, restrict them to systems under its control, and use the available controls (including source-IP allow-lists and key rotation) appropriately.
4.2 The Client must not share API Keys with third parties or embed them in client-side, public or distributed code.
4.3 The Client must notify us without undue delay at [security contact — suggested security@daat.red] if it suspects that an API Key or Account credential has been compromised. We may rotate or revoke credentials, and suspend access, where we reasonably believe this is necessary to protect the Service or third parties.
5. Credits, metering and billing
5.1 Prepaid model. Use of the Service is funded by prepaid Credits allocated to the Account. Credits must be topped up in advance through the credit-request and approval flow. If the Credit balance is insufficient, API calls will be rejected (for example with an HTTP 402 response) until the balance is replenished.
5.2 Metering. Usage is metered per successful result. The Credit cost of each method is as set out in the console and/or the applicable Order. Failed, rejected, rate-limited, "not valid" or no-data calls are not charged, and any Credits provisionally reserved for such calls are returned to the balance. The Balance method is not charged.
5.3 Pricing. Per-method Credit pricing and the price of Credit top-ups are agreed per Account and are not published. Pricing is set out in the applicable Order or as otherwise agreed in writing. We may change pricing prospectively on [notice period for price changes — suggested 30 days] notice; changes do not affect Credits already purchased.
5.4 No refunds for consumed Credits. Credits are non-refundable once consumed. [refund position for unused, unconsumed Credits on termination — e.g. non-refundable, or refundable less fees, or pro-rata.]
5.5 Expiry of unused Credits. [whether unused Credits expire, and after what period — e.g. no expiry, or expiry 12/24 months after purchase.]
5.6 Taxes. All amounts are exclusive of VAT and other applicable taxes and duties, which the Client is responsible for paying. Where a reverse-charge or intra-EU supply mechanism applies, the Client must provide a valid VAT identification number. If we are required to withhold tax, the Client will pay such additional amounts as are necessary so that we receive the full amount due.
5.7 Invoicing and payment. Invoices for Credit purchases are payable within [payment term — suggested 14 days] of the invoice date, unless the Order states otherwise. Overdue amounts bear statutory default interest under Czech law. [payment methods and any payment processor.]
5.8 Records. The metering and usage records generated by the Service are the definitive basis for calculating Credit consumption, absent manifest error.
6. Acceptable use
6.1 The Client and its users must comply with the AUP at all times. The AUP is incorporated into these Terms by reference.
6.2 Without limiting the AUP, the Client must not: use the Service or the Results to facilitate fraud, identity theft, unauthorised transactions, money laundering, or circumvention of card-network, sanctions or anti-money-laundering rules; perform lookups without a lawful basis or required notice or consent; use name, email or IP enrichment for spam, harassment, doxxing, or surveillance of individuals; carry out bulk harvesting beyond legitimate transaction screening; resell or redistribute the Results or build a competing dataset from them; or probe, load-test or attempt to circumvent the security or rate limits of the Service without our prior written permission.
6.3 We may throttle, suspend or terminate access, and take other steps described in section 11 and the AUP, for breach of this section.
7. Rate limits and fair use
7.1 The API is subject to a default rate limit of 20 requests per second per API Key. Calls exceeding the limit receive an HTTP 429 response with a Retry-After indication and are not charged.
7.2 We may apply additional fair-use, concurrency, queue and volume controls to protect the stability of the Service. We may agree a different limit for an Account in an Order.
8. Client responsibilities, representations and warranties
The Client represents, warrants and undertakes, on a continuing basis, that:
8.1 it has a valid lawful basis under applicable data-protection law for every lookup it performs, and for the disclosure of personal data to us for that purpose;
8.2 it has provided all information and notices to data subjects, and obtained all consents, required for the processing carried out through the Service;
8.3 its use of the Service and of the Results complies with all applicable laws and rules, including data-protection law, the rules and requirements of the relevant card networks and payment systems, and applicable payments, consumer-protection, anti-money-laundering and sanctions law;
8.4 the data it submits is accurate and lawfully obtained, and it is entitled to submit that data to us;
8.5 it will use the Results only as one input among others in its own risk, compliance and transaction decisions, and will not treat a Result as a sole or automated determinant of an outcome affecting an individual in a manner that would breach Article 22 GDPR;
8.6 it will not use the Service on behalf of, or to provide a substantially similar service to, an undisclosed third party without our prior written consent;
8.7 it maintains its own records and controls sufficient to demonstrate its compliance with this section.
9. Data protection
9.1 For Client Data submitted to the API, the Client is the controller and Red Code Company is a processor. The DPA governs that processing and is incorporated into these Terms. In the event of a conflict, the DPA prevails on data-protection matters.
9.2 For Account, authentication, billing and support data, Red Code Company is a controller and processes that data in accordance with its Privacy Policy at [Privacy Policy URL].
10. Intellectual property and licences
10.1 Our rights. As between the parties, Red Code Company and its licensors own all rights, title and interest in and to the Service, the API, the Documentation, the underlying software, models, reference data and infrastructure, and all improvements to them. No rights are granted except as expressly stated.
10.2 Licence to the Client. Subject to these Terms and payment of applicable fees, we grant the Client a non-exclusive, non-transferable, non-sublicensable, revocable licence, during the term, to access and use the API and Documentation solely for the Client's internal business purpose of screening its own transactions and accounts.
10.3 Client Data. The Client retains all rights in Client Data. The Client grants us a non-exclusive, worldwide licence to host, process and transmit Client Data as necessary to provide the Service, to perform the checks the Client requests, and as permitted by the DPA.
10.4 Results. Subject to these Terms, the Client may use the Results for its internal risk and compliance decisions. The Client must not resell, redistribute, publish or commercially exploit the Results, or use them to build or improve a product that competes with the Service, or to create an independent or derived dataset for distribution.
10.5 Aggregated data. We may compile and use aggregated and de-identified data derived from operation of the Service (for example volumes, latency, success rates and provider health) for security, capacity planning, billing, product improvement and reporting, provided such data does not identify the Client or any data subject.
10.6 Feedback. If the Client provides suggestions or feedback, we may use them without restriction or obligation.
11. Suspension and termination
11.1 Term. These Terms apply from the earlier of Account creation or first use of the Service, and continue until terminated.
11.2 Termination for convenience. Either party may terminate for convenience on [notice period — suggested 30 days] written notice, unless an Order specifies a fixed term.
11.3 Suspension. We may suspend or restrict access, in whole or in part, with or without prior notice where the circumstances reasonably require, if: (a) the Credit balance is exhausted or an invoice is overdue; (b) we reasonably believe the Client is in breach of the AUP or section 6 or 8; (c) suspension is necessary to protect the security, integrity or availability of the Service or the rights or safety of any person; (d) required by law, by a competent authority, or by a card network or payment system; or (e) an API Key appears to be compromised or misused. We will lift the suspension once the cause is resolved.
11.4 Termination for cause. Either party may terminate immediately on written notice if the other party commits a material breach that is not cured within 30 days of notice (or that is incapable of cure), or becomes insolvent, enters liquidation, or is subject to analogous proceedings. We may terminate immediately for a serious breach of the AUP, for use of the Service to facilitate unlawful activity, or for non-payment persisting more than [cure period for non-payment — suggested 14 days] after a reminder.
11.5 Effect of termination. On termination: all licences end; the Client must stop using the API; outstanding undisputed invoices become immediately due; consumed Credits are non-refundable, and unused Credits are treated as set out in section 5.4. The DPA governs return and deletion of Client Data. Sections that by their nature should survive (including 5.6, 8, 10, 11.5, 12, 13, 14, 15 and 17) survive termination.
12. Disclaimers
12.1 The Service, the API, the Documentation and the Results are provided "as is" and "as available". To the fullest extent permitted by law, we disclaim all implied warranties and conditions, including merchantability, fitness for a particular purpose, accuracy, completeness, non-infringement and any warranties arising from course of dealing or usage of trade.
12.2 We do not warrant that the Results are accurate, complete, current or fit for any particular decision; that the Service will be uninterrupted, timely, secure or error-free; that responses from card networks, payment systems or third-party data sources are accurate; or that the Service will meet the Client's regulatory obligations.
12.3 The Results are signals, not decisions. The Client is solely responsible for any action it takes, or does not take, on the basis of a Result.
12.4 We are not responsible for the availability, accuracy or acts of card networks, payment systems, or third-party data or infrastructure providers, or for delays or failures caused by them.
12.5 Nothing in these Terms excludes or limits any liability that cannot be excluded or limited under applicable law.
13. Limitation of liability
13.1 Subject to section 13.3, neither party is liable for any indirect, incidental, special, consequential or punitive damages, or for loss of profits, revenue, business, goodwill, anticipated savings, or loss or corruption of data, in each case however arising, whether in contract, tort (including negligence) or otherwise, even if advised of the possibility.
13.2 Subject to section 13.3, each party's total aggregate liability arising out of or in connection with these Terms is limited to the total amounts paid by the Client to us for the Service in the [liability cap reference period — suggested 12] months immediately preceding the event giving rise to the liability.
13.3 The exclusions and cap in sections 13.1 and 13.2 do not apply to: (a) the Client's payment obligations; (b) the Client's obligations under sections 8 and 10.4 and its indemnity under section 14; (c) either party's liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for wilful misconduct or gross negligence; or (d) any other liability that cannot be limited or excluded under applicable law.
13.4 Each party has a duty to mitigate its losses.
14. Indemnity
The Client will defend, indemnify and hold harmless Red Code Company and its officers, employees and agents from and against all claims, proceedings, losses, damages, fines, penalties, liabilities, costs and expenses (including reasonable legal fees) arising out of or in connection with: (a) the Client's breach of sections 6, 8 or 10.4 or of the AUP; (b) the Client's use of the Service or the Results in violation of applicable law or of card-network or payment-system rules; (c) the absence of a lawful basis, notice or consent for any lookup performed by or for the Client; or (d) any claim by a data subject, third party or authority relating to the Client's processing as controller.
15. Confidentiality
15.1 "Confidential Information" means non-public information disclosed by one party to the other that is marked or should reasonably be understood as confidential, including the Documentation, non-public API details, pricing and Order terms, security information, and the existence and content of any dispute.
15.2 The receiving party will use Confidential Information only to exercise its rights and perform its obligations under these Terms, protect it with at least reasonable care, and disclose it only to personnel and advisers who need to know it and are bound by confidentiality.
15.3 These obligations do not apply to information that is or becomes public through no fault of the receiving party, was lawfully known without a duty of confidentiality, is independently developed, or is lawfully received from a third party. Disclosure required by law or a competent authority is permitted, with prior notice to the other party where lawful.
15.4 This section does not apply to personal data, which is governed by the DPA and the Privacy Policy.
16. Force majeure
Neither party is liable for any failure or delay in performance (other than a payment obligation) caused by an event beyond its reasonable control, including natural disasters, war, terrorism, civil unrest, epidemic, labour disputes, failure of utilities or telecommunications, acts of government, and large-scale internet or infrastructure failures or attacks. The affected party will notify the other and use reasonable efforts to resume performance. If the event continues for more than [force majeure termination threshold — suggested 60 days], either party may terminate the affected services.
17. General
17.1 Governing law. These Terms and any non-contractual obligations arising out of them are governed by the laws of the Czech Republic, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods.
17.2 Jurisdiction. The parties submit to the exclusive jurisdiction of the courts of the Czech Republic. [confirm whether the competent court should be fixed by reference to Red Code Company's seat (Prague).]
17.3 Service levels. [state whether a Service Level Agreement applies — as a separate document — or that no SLA is offered and the Service is provided on a commercially reasonable-efforts basis.]
17.4 Notices. Legal notices to us must be sent to info@redcode.company and, where relevant, to [legal/notices address or mailbox]. Notices to the Client may be sent to the email addresses associated with the Account or posted in the console. Operational notices may be given through the console.
17.5 Changes to these Terms. We may amend these Terms. We will notify Clients of material changes at least [notice period for Terms changes — suggested 30 days] in advance through the console or by email. Changes required by law or for security may take effect sooner. Continued use after the effective date constitutes acceptance; if the Client objects to a material change, its sole remedy is to terminate before the change takes effect.
17.6 Assignment. The Client may not assign or transfer these Terms without our prior written consent. We may assign these Terms to an affiliate or in connection with a merger, acquisition or sale of assets, on notice.
17.7 Subcontracting. We may use subcontractors and sub-processors to provide the Service; we remain responsible for their performance. Sub-processing of personal data is governed by the DPA.
17.8 Entire agreement. These Terms, together with the AUP, the DPA, the Privacy Policy, the Documentation and any Order, constitute the entire agreement between the parties on their subject matter and supersede all prior discussions. In the event of conflict, the following order of precedence applies: (1) the DPA (on data-protection matters); (2) an executed Order; (3) these Terms; (4) the AUP; (5) the Documentation.
17.9 No waiver. A failure to enforce a provision is not a waiver.
17.10 Severability. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary, or severed, and the remainder remains in effect.
17.11 Independent contractors. The parties are independent contractors. Nothing creates a partnership, joint venture, agency or employment relationship.
17.12 Language. These Terms are made in English. [state which language version prevails if a translation is provided.]