Terms of Service.
The rules for using Repizen embeds, the console, and the API — including what you are responsible for when you collect data from your own visitors.
Effective date: [Effective date] · Last updated: [Last updated]
This document has not been reviewed by a lawyer.
It is an internal working draft prepared to structure real terms of service. It is not legal advice, it does not yet bind anyone, and it must be reviewed and approved by qualified counsel in the relevant jurisdictions before it is published or relied upon.
Every [bracketed value] below is a placeholder that a human must fill in or delete — including the entity, the jurisdiction, the liability cap, and the refund position.
1. These terms, and who they are with
These Terms of Service (“Terms”) are an agreement between [Legal entity name], registered at [Registered address] (“repizen”, “we”), and the person or organisation that creates an account or uses the service (“Customer”, “you”). By creating an account, installing an embed, or calling the API, you accept these Terms. If you are accepting on behalf of an organisation, you confirm you have authority to bind it.
If you have a signed order form or master agreement with us, that document controls where it conflicts with these Terms.
2. Definitions
- Service — the repizen widgets, the API served from
widget.repizen.com, the admin console atadmin.repizen.com, and any related tooling we make available. - Embed — a contact form or scheduling widget you configure and install on a website you control.
- Tenant — your isolated account and its configuration.
- End User — a visitor to your website who interacts with one of your embeds.
- Customer Data — configuration you enter, plus form submissions, bookings and related content collected through your embeds.
3. Accounts and access
You must provide accurate registration details, keep your credentials secure, and be responsible for everything done under your account. Console access is authenticated through our identity provider; keep the list of people with access current.
Keys. Publishable keys (pk_) are designed to be visible in page source.
Administrative keys (sk_) are secrets: keep them server-side, never commit them, and never put
them in a page, a support ticket, or a chat transcript. You are responsible for activity performed with
your keys until you rotate them.
4. Acceptable use
You must not, and must not permit anyone else to:
- Use an embed to send unsolicited bulk or commercial email, or to relay mail to addresses that did not come from a genuine submission on your own site.
- Install an embed on a site you do not control, or configure recipients who have not agreed to receive the mail.
- Circumvent or attempt to circumvent rate limits, request-size caps, origin allowlists, bot traps, or plan entitlements — including by sharding traffic across accounts.
- Probe, scan, or load-test the Service without our prior written agreement, or attempt to access another tenant's data or configuration.
- Upload or transmit malware, or content that is unlawful, harassing, infringing, or that you have no right to transmit.
- Reverse engineer, resell, or white-label the Service except as expressly permitted by your plan.
- Use the Service in a way that damages the deliverability reputation of a shared sending domain, or that risks blocklisting of our infrastructure.
We may suspend an embed, a tenant, or specific traffic immediately where we reasonably believe it is causing abuse, a security risk, or deliverability harm. Where practical we will tell you first.
5. What you collect is your responsibility
This is the important clause for a form product. Because you decide which fields your embeds collect and what happens to the results:
- You are the controller of End User submissions; we act as your processor and only on your instructions. See the Privacy Policy.
- You are responsible for having a lawful basis for every field you collect, and for any consent, notice, cookie banner, or age gating your jurisdiction requires — including consent obtained before the embed loads, where that is required.
- You must publish your own privacy notice to your End Users, and must not use a repizen form to collect data you are not permitted to collect.
- You must not configure fields that solicit payment card numbers, passwords, government identifiers, or health or other special-category data unless you have the lawful basis and safeguards to do so. The Service is not designed or offered as a payment form or a clinical records system. [Confirm prohibited-data list with counsel]
- You are responsible for the accuracy of the sending domain, DNS records and recipient routing you configure, and for responding to End Users who exercise their rights over their submissions.
Where a data processing addendum is required, that is [Data Processing Addendum URL] and it is incorporated into these Terms once executed.
6. Plans, entitlements and limits
Plans, prices and included limits are described on the pricing section of our site and in the console. Entitlements — for example how many embeds a tenant may have, whether custom domains are available, and whether repizen branding can be removed — are enforced by the Service according to your current plan. Reaching a limit is not a fault: you will be shown or returned an upgrade path rather than a hard failure wherever we can do so.
We may change plan contents and prices with [Notice period] notice. [Grandfathering policy]
7. Fees, billing and cancellation
- Payment processing. Paid plans are billed through Stripe. Card details are entered on Stripe's hosted checkout, in a browser — never inside a chat, an assistant, or a support conversation. We do not receive or store full card numbers.
- Billing cycle. Subscriptions are charged in advance for each [Billing period] and renew automatically until cancelled.
- Taxes. Prices exclude VAT, GST and sales tax unless stated. You are responsible for taxes other than those on our net income.
- Upgrades and downgrades. Upgrades take effect immediately and are prorated. Downgrades take effect [at the end of the current period / immediately]; if a downgrade puts you over the limits of the lower plan, embeds beyond the limit may be disabled until you are within it.
- Cancellation. You may cancel at any time from the console. Cancellation stops future renewals; the plan remains active until the end of the period you have paid for. Cancelling does not by itself delete your data — request deletion if you want it removed.
- Refunds. [Refund policy — counsel to confirm; do not publish a refund commitment that finance has not agreed]
- Non-payment. If a charge fails we may suspend paid features after [Grace period] notice.
- Free plan. The free plan is provided as-is, may change or end with [Notice period] notice, and carries no support commitment beyond what we choose to give.
8. Availability and support
We aim to keep the Service available and to respond to support requests promptly, but unless you have a signed service level agreement — [SLA reference or “none”] — the Service is provided without an uptime commitment, and any response times published on our support page are targets rather than guarantees. Maintenance windows and incident communications go out via [Status page URL].
9. Intellectual property
We own the Service, the widget code, and everything we create around it. You own your Customer Data. You grant us the limited licence needed to host, process, transmit and back up Customer Data in order to provide the Service, and to use it in aggregated, de-identified form for capacity planning and abuse prevention. We do not use Customer Data to train models. [Confirm before publishing]
Feedback you send us may be used freely and without obligation.
10. Third-party services
The Service depends on third parties, including Stripe for payments and Keycloak at auth.pnebula.com for console identity, plus the infrastructure and email providers listed in the Privacy Policy. Their own terms apply to your use of them, and we are not responsible for their acts or omissions beyond our obligations as their customer.
11. Disclaimer
Except as expressly stated in these Terms, and to the maximum extent permitted by law, the Service is provided “as is” without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that email or calendar invites will be delivered to, or accepted by, any particular inbox or provider — deliverability depends on your domain, your DNS records and the receiving system.
Nothing in these Terms excludes liability that cannot lawfully be excluded, and consumer rights that apply to you are unaffected.
12. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill, or lost or corrupted data arising from these Terms.
Our total aggregate liability arising out of or related to these Terms is limited to [Liability cap — e.g. fees paid in the 12 months before the claim]. For customers on the free plan, [Free-plan liability cap]. [Counsel to confirm — caps and carve-outs vary by jurisdiction]
13. Indemnity
You will defend and indemnify us against third-party claims arising from your Customer Data, from what you collect through your embeds, from your breach of Section 4 or 5, or from your infringement of a third party's rights. [Mutual indemnity — counsel to confirm scope]
14. Term, suspension and termination
These Terms run for as long as you have an account. Either party may terminate for material breach that is not cured within [Cure period]. We may suspend access immediately for the abuse and security reasons in Section 4.
On termination, access ends and we will delete or return Customer Data in accordance with the retention terms in the Privacy Policy. Export your data before you terminate.
15. Changes to these Terms
We may update these Terms. Material changes will be posted here with a new effective date and notified via [Notification method] at least [Notice period] in advance. Continuing to use the Service after that date means you accept the change.
16. General
These Terms are the entire agreement on their subject matter and supersede prior discussions. If a provision is unenforceable, the rest survives. Neither party may assign without consent, except in a merger or sale of substantially all assets. No waiver is implied from delay. Notices go to [Notice address / email].
17. Governing law and disputes
These Terms are governed by the laws of [Governing law jurisdiction], and the courts of [Venue] have exclusive jurisdiction, without regard to conflict-of-laws rules. [Arbitration / class-action position — counsel to decide]
18. Contact
[Legal entity name]
[Registered address]
Support: repizen.com/support
Legal notices: [Legal contact email]