API Terms of Use
1. Scope and Application
These Terms of Use ("Terms") apply to any developer, partner, or entity ("Developer") accessing or integrating with the ProductFlow API ("API"). By using the API, the Developer agrees to comply with these Terms.
2. API Access and Credentials
Developers must request access via official ProductFlow channels and will receive unique API credentials. Credentials must not be shared or reused across individuals or organizations.
3. Permitted Use
The API may only be used to support services for clients of ProductFlow ("Clients") and only in accordance with applicable data protection laws. Use of the API for any illegal, harmful, or unauthorized purpose is strictly prohibited.
4. Data Security and Protection
The Developer must:
- Implement multi-factor authentication (MFA) for all user accounts accessing API data.
- Encrypt data in transit (TLS 1.2+) and at rest (AES-128 or higher).
- Apply access controls based on the principle of least privilege.
- Avoid storing Personally Identifiable Information ("PII") longer than necessary and delete it securely (e.g., NIST 800-88).
- Ensure systems are regularly updated and monitored.
- Retain logs for at least 90 days and review them bi-weekly.
5. Subprocessors and Third Parties
If the Developer involves any third party (e.g., subcontractor or integration partner), the Developer must:
- Impose equivalent data protection obligations by contract.
- Retain documentation of such agreements.
- Notify ProductFlow of material changes.
6. Incident Management
In the event of a data breach or security incident:
- Notify ProductFlow within 24 hours.
- Cooperate in the investigation.
- Maintain a documented incident response plan.
7. Data Use and Restrictions
The Developer may not:
- Use data obtained via the API for analytics, profiling, or cross-client aggregation.
- Sell, license, or share API data with third parties.
- Combine API data with data from other platforms unless explicitly permitted.
8. Confidentiality
All API-related documentation, technical details, and client data are confidential. The Developer must not disclose any such information to third parties without written consent from ProductFlow.
9. Oversight and Audit by ProductFlow
ProductFlow reserves the right to conduct audits or require evidence of compliance with these Terms upon reasonable notice. The Developer agrees to cooperate fully with any such audit request, including the provision of technical documentation, log access, and policies upon request.
10. Enforcement and Sanctions
In case of breach of these Terms, ProductFlow reserves the right to suspend or terminate API access with immediate effect. ProductFlow may also report serious violations to affected Clients or, where applicable, to legal or regulatory authorities.
11. Acceptance and Version Control
Access to the API is conditional on the Developer’s acceptance of these Terms. Acceptance shall be confirmed:
- At the time of requesting API access (e.g., via a technical interface such as an API key portal).
- Upon any update to these Terms. Continued use of the API after such updates shall constitute renewed acceptance.
- ProductFlow reserves the right to maintain version history of the Terms, and will notify Developers of material changes.
12. Governing Law and Jurisdiction
These Terms shall be governed by Dutch law. Any disputes shall be submitted to the competent court of Amsterdam, the Netherlands.
13. Contact
For questions or concerns, contact: legal@productflow.com