Termos de Uso
O texto deste documento está disponível apenas em inglês.
1. Who provides the service
The apiRiver service is provided by ФОП Александр Рич, a sole proprietor (ФОП). Country of registration: Ukraine. The registered address, the registration number and the registration status of the operator are stated in the Imprint. Contact for legal notices: [email protected].
2. What the service is
apiRiver is an HTTP API for working with electronic invoices under the EU e-invoicing standard: generating a document from structured data (JSON in) and validating an existing document against the EN 16931 business rules and national profiles.
Generation currently produces XRechnung 3.0 invoices in CII syntax. Validation accepts CII or UBL XML and PDF with an embedded CII invoice (Factur-X/ZUGFeRD), and checks EN 16931, XRechnung 1.2–3.0, and Factur-X/ZUGFeRD MINIMUM, BASIC WL and BASIC. UBL documents declaring Peppol BIS Billing 3.0 are checked against the EN 16931 core rules only. Other profiles, including EXTENDED, are reported as not assessed.
The service does not transmit documents to government channels and is not a delivery operator: it is not a Peppol Access Point, the Italian SdI, a French PDP or any other accredited channel. Delivering a resulting document to a counterparty or to a government channel is entirely the customer's responsibility.
3. Account
- Access to the service requires an account. An account is identified by an email address.
- Sign-in is by a one-time link sent to that address (a "magic link"). The service does not use or store passwords.
- The customer is responsible for controlling access to that mailbox: anyone who can read the email containing the link can sign in to the account.
- The service is intended for business use only: for entrepreneurs and legal entities acting in the course of their business or profession. It is not designed for consumers and is not intended for persons under 18. By creating an account you confirm that you are at least 18 years old and that you will use the service for business purposes only. This is a self-declaration: apiRiver does not verify it. [LAWYER REQUIRED: whether a self-declaration without verification is enough for the business-only restriction, and whether consumer-protection law still applies when an individual registers with only an email address; the business-to-business nature of the product does not automatically remove it]
4. API key
- API calls are authenticated with an API key. An account has one active key.
- The key's secret is shown exactly once, when the key is issued. It cannot be recovered: only an irreversible hash is stored. A lost key is replaced by issuing a new one, not by recovering the old one.
- The customer is responsible for keeping the key secret and for every call made with it. A key can be revoked from the cabinet at any time.
5. Acceptable use
The customer agrees not to:
- circumvent quotas and rate limits, including by creating several accounts to obtain the free quota repeatedly;
- use the service to process data the customer has no right to process;
- disrupt the service with a load that does not correspond to a normal integration.
The service enforces technical limits, including maximum request size, maximum processing time and a service-wide limit on concurrent processing; requests beyond them are rejected. The limits may change.
6. Resale and embedding
The customer may resell access to the service and embed the service in the customer's own products and services, without restriction, on the following four conditions:
- The customer is responsible for all calls made with the customer's key, including calls made on behalf of the customer's own clients or users.
- The customer must not create several accounts in order to obtain the free allowance repeatedly (section 5).
- Resale or embedding gives the customer no exclusive rights and no protection of its sales channel. apiRiver may itself sell the service to businesses, including to the customer's own clients.
- If the customer processes the data of its own clients through the service, then for that data apiRiver acts as the customer's sub-processor; section 8 and the DPA outline apply accordingly.
7. Nature of the result: what the service does not guarantee
The service generates and validates documents against the rules of the EN 16931 standard and of the supported national profiles. The service does not provide legal, tax or accounting advice and does not guarantee that a generated or validated document will be accepted by a particular counterparty, a particular government channel or a tax authority, or that it is correct with respect to the customer's tax obligations. The correctness of the source data (amounts, rates, counterparty identifiers, grounds for tax exemption) is the customer's responsibility; the service works with what it receives and does not check the data against the actual circumstances of the transaction. A successful validation means conformity with the machine-checked rules of the standard, and nothing more.
[LAWYER REQUIRED: this wording is an AI agent's proposal and carries the risk allocation between the parties — it needs legal review first]
8. Customer data
- The content of documents submitted for generation or validation is not stored after the request is processed. A document is received, processed, the result is returned, and the content is forgotten. How temporary copies of a document are handled while it is being processed is described in the Privacy Notice, section 6.
- With respect to the content of documents, apiRiver acts as a processor on the customer's instructions, not as the owner of the data. The terms of that processing are governed by a separate data processing agreement (see the DPA outline).
- With respect to account data (email, sign-in metadata, technical logs), apiRiver acts as a controller (see the Privacy Notice, section 2).
- Customer data is not used for the company's own purposes. No industry or market conclusions are drawn from customer data.
9. Aggregated statistics
apiRiver may produce and use anonymised aggregated statistics about how the service is used (for example: how many documents a typical account processes per month, which output formats are chosen most often (the formats offered are described in section 2), which rules of the standard fail validation most often) in order to develop and operate the service. Such statistics do not contain the content of the customer's documents and do not allow the customer or the customer's counterparties to be identified. Published aggregates are subject to authenticity rules: a cell is not published if it was computed from fewer than 10 customers; it is checked that no single participant contributes the main share of a value; and subtraction of neighbouring exports is monitored.
10. Payment
Each account receives 10 free generations once; they are not renewed and do not expire. While a subscription is active, generations count only against the subscription's monthly allowance, even after it is used up; unused free generations become available again when no subscription is active. Validation is unlimited.
The balance is held in euros and topped up by PayPal transfer with the account code in the note. The full transferred amount is credited, without deducting PayPal fees. Transfers in other currencies or above €2,000 are handled manually. A subscription is bought from the balance for 1–24 months at the price shown at purchase and includes a monthly allowance of generations; unused allowance does not carry over.
[AUTHOR DECISION REQUIRED: whether the prices shown include VAT and the tax status of the seller, refunds, and whether an unused balance expires or can be refunded — nothing is stated here.]
11. Availability
The service is provided "as is", on every plan, free or paid, with no commitment to availability, response time or time to fix faults.
12. Limitation of liability
[LAWYER REQUIRED IN FULL — no wording is proposed. The draft leaves this section empty on purpose: a liability cap is normally expressed as an amount or a multiple of payments, and a free plan has no payments; and how a limitation in a public offer relates to the liability regime of an individual entrepreneur in Ukraine is a legal question.]
13. Termination
- The customer may stop using the service at any time by revoking the key and no longer calling the API. Self-service account deletion is not available at this time: an account is kept for as long as it exists and is deleted on request sent to [email protected]; apiRiver does not delete inactive accounts on its own. How a deletion request is handled, and which records are kept, is described in the Privacy Notice, section 8.
- apiRiver may suspend or terminate access for a breach of section 5 or where required by law. Where use endangers the operation of the service, access may be suspended immediately, with notice given without undue delay. In other cases notice is sent to the account's address [AUTHOR DECISION REQUIRED: notice period, in days] before access ends.
- After termination: the key is revoked and API access ends. The key's record is not deleted from the database — it is needed for history and for the integrity of the future usage log; retention periods are in the Privacy Notice. [AUTHOR DECISION REQUIRED / LAWYER REQUIRED: what happens to the remaining balance and the unused part of a subscription when access is terminated]
14. Changes to these terms
apiRiver may change these terms. Changes that materially affect customers' rights are notified by email to the account's address no later than [AUTHOR DECISION REQUIRED / LAWYER REQUIRED: notice period] before they take effect. The date on which the current version takes effect is shown on this page. Continued use of the service after the changes take effect constitutes agreement to them. [LAWYER REQUIRED: whether this "deemed acceptance" construction is permissible for customers in the EU and under the governing law]
Effective date of this version: [AUTHOR TO PROVIDE: date this version takes effect, set apiriver.cabinet.legal.effective-date at publication]
15. Governing law and dispute resolution
[AUTHOR AND LAWYER REQUIRED IN FULL: the seller is in Ukraine while customers are mainly in the EU (the first market is Germany). "Ukrainian law, courts at the seller's place of registration" is natural for a seller, but its applicability to EU customers and compatibility with the mandatory rules of the customer's country need legal assessment. No option is recorded in the project documents.]