Draft — to be reviewed by counsel before publication

Terms of service

These terms are a draft between MB Tobuli ("we") and the customer ("you"). Counsel must review them before publication. Company code [Company code]. Address [Registered address]. VAT [VAT number]. Contact [Contact email].

The service

We provide a transactional email API. You send with an API key. A key with prefix st_test_ does not send a real email. A key with prefix st_live_ can. Live mail requires a verified sending domain. The API base URL on the production host is to confirm. The example host in the OpenAPI file is not that host.

The service is one Region, eu-central-1. We do not offer a second Region, a dedicated IP, or an uptime percentage.

Accounts and keys

You keep keys secret. You are responsible for mail sent with your keys. We authenticate the key and reject a revoked key. A full-scope key can create or revoke a key. How you receive the first key is to confirm.

Acceptable use

You follow the Acceptable use policy. We may revoke keys and cancel queued and scheduled mail when your sending threatens the shared account. That pause is an operator action. A paused label in our records does not, by itself, stop the API.

Message data

You are the controller of the personal data in the messages you send. We process that data as a processor under the Data processing agreement. That role split is to confirm by counsel. You must have a lawful reason to send to each recipient. You must not retry an address we suppressed for a hard bounce or a complaint, except where the policy allows a correction.

Fees

A free plan can be used without a card. The API enforces the plan send caps before it accepts a send. Free allows 100 live recipients per UTC day and 3 000 per UTC month. Pro allows 100 000 live recipients per UTC month and has no daily cap. Scale allows 1 000 000 live recipients per UTC month and has no daily cap. A tenant override replaces that plan's default. Zero disables sends for that period. Test keys share a separate cap of 1 000 recipients per UTC day and do not consume the live caps. A send past a cap is refused and stores no email. Paid use, when enabled, is billed by Stripe. Stripe's role and the transfer tool are in the Data processing agreement and Subprocessors. Prices are to confirm.

Suspension

We may suspend live sending for the whole service when the email provider reviews or pauses the account. Test keys do not call that provider. We will tell you when live sending stops and when it resumes. We will not promise a resume time we do not have.

Liability and law

A liability cap, exclusions, and the governing law are to confirm by counsel. Do not invent a cap or a court. Nothing in this draft limits liability that the law says we cannot limit.

End of contract

You may stop using the API at any time. We may end access if you break the acceptable use policy or if we discontinue the service. A dashboard owner of the organization can export its retained data with GET /organizations/{tenant_id}/export and schedule deletion with DELETE /organizations/{tenant_id}. Deletion returns purge_at 720 hours (30 days of 24 hours) after the first request. The owner can restore the organization before that time. Export and deletion are described in the Data processing agreement. See ADR-0024 (docs/adr/0024-account-export-and-deletion.md).

Changes

We will post the counsel-approved text before it applies. Continued use after the posted date is to confirm by counsel as a consent mechanism. Do not rely on that sentence until counsel accepts it.