PLEASE READ THESE API TERMS OF USE CAREFULLY BEFORE USING THE API. BY USING THE API, YOU AGREE TO BE BOUND BY THESE API TERMS OF USE. IF YOU DO NOT AGREE TO THESE API TERMS OF USE YOU MUST NOT USE OUR API FOR ANY PURPOSE WHATSOEVER.

In these API Terms of Use, We, Our, Ourselves, Us or API Licensor means Open G I Limited (a company incorporated in England and Wales under number 01519547 whose registered office is at Open International Limited, Buckholt Drive, Warndon, Worcester WR4 9SR) and You, Your or AP Licensee means you (and if you are using the API on behalf of a legal person, business or other organisation (Organisation) includes you and such Organisation).

By using the APIs on behalf of any Organisation, You represent and warrant (promise) that You have all necessary capacity and authority to enter into these API Terms of Use on behalf of such Organisation as a legally binding contract between such Organisation and Us in all applicable jurisdictions and that the Organisation enters into such contract.

We may update these API Terms of Use, Our API Security Standard asset out in the Appendix to these API Terms of Use (Security Standard) and any of the policies or other documents referred to in them from time to time by notifying You by any reasonable means. If You do not agree to any such update, You should stop using the APIs and API Data before the update takes effect.

1. Our APIs

1.1. Our application programming interfaces (APIs) can be accessed via the link provided to You by Us and includes any documents (electronic or otherwise) that come with the APIs. Our APIs are intended to be used as an interface between: (a) Our website, platforms, cloud services or software, comprising Our relevant products or services (Platform); and (b) the applications or services provided by You through Your website or platform or your other applications, software or cloud services (Application).

1.2. As part of Your use of the APIs, You may access or otherwise use on Our Platform certain content, images, photographs, illustrations, icons, texts, video, audio, written materials, software or other content, materials or data made available via the APIs (API Data).

2. These API Terms of Use

2.1. These API Terms of Use set out Our and Your respective rights and obligations relating to the use of Our APIs to interface between Our Platform and Your Application and use of the API Data.

2.2. Your use of any of Our other products or services on Our Platform will be on different terms and conditions. If, and only so far as, these API Terms of Use and the terms and conditions applicable to Our other products or services are inconsistent as to the terms applicable to the use of Our API, the terms and conditions applicable to Our other products or services shall apply (and these API Terms of Use shall not).

2.3. If these API Terms of Use do not specifically say that You can do something in connection with the APIs, the API Data or the Platform, then You cannot.

3. Access to the APIs

3.1. You agree:

3.1.1. to access the APIs only using the credentials that We give You;

3.1.2. to keep Your API credentials secure and that You are responsible for any use of the APIs using Your credentials; and

3.1.3. that end users shall not be prompted to provide any passwords, usernames or other login details that they use to access the Platform directly to You. However, such details may be stored within the APIs in accordance with the Security Standard.

4. How You may use the APIs

4.1. You must:

4.1.1. obtain all appropriate consents;

4.1.2. implement industry standard security, including HTTPS/TLS, secure storage of credentials, error handling, logging and timely patching; and

4.1.3. ensure that Your use of the APIs complies with:

4.1.3.1. these API Terms of Use and the Security Standard

4.1.3.2. all documentation relating to the APIs and/or Platform provided or made available by Us to You (Documentation) (as updated from time to time);

4.1.3.3. any terms applicable to Your Application;

4.1.3.4. any terms applicable to the Platform;

4.1.3.5. any other terms agreed between Us and You; and

4.1.3.6. all relevant legislation, regulations, codes of practice, guidance and other requirements of any relevant jurisdiction, government or regulatory agency or other regulatory body.

4.2. You agree that We may monitor usage to:

4.2.1. ensure compliance;

4.2.2. protect availability and security;

4.2.3. impose metering or throttling to limit excessive usage where usage goes beyond reasonable limits; and

4.2.4. improve the APIs.

5. What the APIs must not be used for

5.1. You must not use the APIs to send spam or to interfere with ordegrade Our services in any way.

5.2. You must also not use the API for any unlawful purpose or activity whatsoever, including fraud or terrorism, or to promote any unlawful act, or in any way which:

5.2.1. makes any private information on the Platform publicly available on the Application;

5.2.2. causes or is intended to cause annoyance, inconvenience or needless anxiety;

5.2.3. is abusive, harmful, threatening or defamatory or may otherwise cause offence (including uploading any material that contains a virus or other malicious code);

5.2.4. does or could potentially breach a legal duty to anyone else (including a duty of confidentiality) or infringe a person’s right to privacy;

5.2.5. promotes discrimination or is likely to incite hatred; or

5.2.6. may infringe the intellectual property rights (e.g. copyright, trade marks, service marks, patents, database rights, know-how, design rights, domain names, know-how and rights in software (registered or not)) or any other rights of anyone (including Ours).

5.3. You must also not:

5.3.1. distribute, license, sell, rent, lease or otherwise deal in or encumber (like a guarantee, mortgage or security interest, for example) the APIs;

5.3.2. modify, add to, or otherwise enhance the APIs;

5.3.3. except as strictly necessary for You to integrate Our APIs with Your Application in a manner (and for such purposes) that comply at all times with these API Terms of Use, copy, reverse engineer or decompile the APIs; or

5.3.4. infringe or copy Our code or content or the design of Our Platform, the APIs and any of Our other intellectual property rights.

6. Licences to use the APIs and API Data

6.1. We grant You a non-exclusive, revocable and non-transferable licence, without a right to sublicense to end users, to use and to permit Your end users to use, the APIs within Your Application and subject to the restrictions on use in these API Terms of Use.

6.2. The API licensed under these API Terms of Use shall include any fixes, updates and new versions subsequently received (if any) of the API (Releases). You will implement and use such Releases as soon as possible and in any event in the time period specified by Us. During this time period, We shall provide reasonable support of prior iterations of the API whilst You implement the Releases.

6.3. We grant You a non-exclusive, revocable, and non-transferable licence, without a right to sublicense to end users, to download, copy, display, view and use the API Data for the purpose for which the API was created, provided that You shall not:

6.3.1. create permanent copies of the API Data, save where such API Data is necessary for your Application;

6.3.2. remove, alter, or cover up any trade mark, service mark, copyright and other proprietary notices contained in the API Data;

6.3.3. without Our prior written consent, make derivative works of, or commercially distribute or otherwise exploit the API Data, or use the Platform or any API Data in a way that inaccurately suggests an association between You and Us or Our licensors;

6.3.4. connect with any third party using the APIs or extract any API Data without our prior written consent; or

6.3.5. otherwise use or exploit the API Data in any way for any purpose except as specifically permitted by these API Terms of Use or the Security Standard.

6.4. This means that:

6.4.1. We can grant licences to anyone else (and retain rights to do things with the APIs and API Data Ourselves);

6.4.2. We can decide to take the licences back from You; and

6.4.3. You are not permitted to transfer Your rights to anyone else or to allow anyone else to use the APIs, the API Data or the Platform.

6.5. You accept that the API Data may contain third party intellectual property rights, and You shall ensure that Your use of such API Data does not infringe those rights.

6.6. Except for Your right to use the APIs, Platform and API Data as specifically granted in these API Terms of Use, all intellectual property rights in and to the APIs, Platform and API Data are Ours and remain Ours (or Our licensors’).

6.7. If You acquire any intellectual property rights (e.g. copyright, trade marks, service marks, patents, database rights, know-how, design rights, domain names, know-how and rights in software (registered or not)) in the APIs, Platform or any API Data, You shall transfer these rights (both existing and future) with full title guarantee to Us or anyone else We nominate (or You will make this happen immediately). You shall sign all documentation and do such things as We think necessary to transfer those rights.

6.8. You accept and understand that the APIs and API Data contain confidential and proprietary information and You shall not conceal, modify, remove, destroy or alter in any way any of Our proprietary markings on or in the APIs, API Data or any related materials and documentation.

7. Data

7.1. If data is exchanged through the APIs, a separate contract will be entered into between You and Us.

7.2. API Licensor’s rights

7.3. We have the right at any time to access Your API account and to monitor Your use of Your API account to ensure You are complying with these API Terms of Use.

7.4. Our Marks

7.5. All trade marks, logos and service marks (the Marks) which appear on the Platform or APIs are Our registered and unregistered Marks or are licensed for use by Us by the owners of those Marks.

7.6. Other Marks are proprietary marks and are registered to their respective owners.

7.7. Nothing contained on the Platform or APIs should be construed as granting any licence or right to use any Marks displayed on the Platform or APIs without Our written permission. Any such use (if agreed) must be strictly in compliance with any guidelines communicated by Us to You from time to time.

7.8. Misuse of any Mark displayed on the Platform or the APIs, or any other content on the Platform, except as provided herein, is strictly prohibited.

8. Confidentiality

8.1. You shall keep Our confidential information confidential. This includes all information (of any kind and in any format and coming into Your knowledge, possession or control in any way) relating to Our business, finance or technology, know-how, intellectual property rights, assets, strategy, products and other customers, where the information is identified as confidential at the time of disclosure or ought reasonably to be considered confidential given its nature or how it was disclosed (Confidential Information).

8.2. You shall only use Our Confidential Information to use, and undertake development work with, the APIs, and will give Us notice of any unauthorised misuse, disclosure, theft or loss of Our Confidential Information immediately upon becoming aware of this.

8.3. You shall not without Our prior written consent use, disclose, copy or modify Our Confidential Information (or permit others to do so) other than as is strictly necessary for You to be able to do what You are permitted and/or required to do under these API Terms of Use.

8.4. You may disclose Our Confidential Information to Your officers, employees, agents, professional advisers and contractors (and permit them to use, copy or modify Our Confidential Information) as is strictly necessary for You to be able to do what You are permitted and/or required to do under these API Terms of Use. Where disclosure to Your officers, employees, agents, professional advisers and contractors is necessary, You shall ensure such persons are made aware of and agree in writing to observe these same confidentiality obligations and at all times comply with them.

8.5. You may disclose Our Confidential Information as required by law. In the event that You become legally compelled to disclose any of the Confidential Information, then (to the extent permitted by law) You shall give Us prompt written notice of the fact so that We may take such steps to prevent such disclosure as We deem appropriate and You shall co-operate with Us in such manner as We may reasonably require.

9. Promises and disclaimers

9.1. You promise that:

9.1.1. You hold all rights and have obtained all licences required to use the API integration You develop and the API Data; and

9.1.2. Your use of the APIs will not infringe Our rights or anyone else’s, nor will it breach any applicable laws or regulations.

9.2. To the maximum extent permitted by applicable law, You accept that the APIs are provided on an ‘as is’ bas is and that:

9.2.1. the APIs may not be free of bugs or errors and that the existence of bugs or errors shall not constitute a breach of these API Terms of Use;

9.2.2. You remain responsible for Your own hardware, content and any other data uploaded through the APIs;

9.3. We accept no responsibility for any liability that arises in connection with anyone else unlawfully obtaining access to Your API account in order to abuse the nature and intent of the APIs; and

9.4. We accept no responsibility for any liability that arises in connection with the theft of Your username or password by unauthorised third parties.

9.5. We do not promise that the APIs shall be:

9.5.1. uninterrupted or error free; or

9.5.2. compatible with third party software or equipment.

9.6. Any promises that We make (and We are not saying that We are, unless We have to by applicable law) depend on You using the APIs in compliance with these API Terms of Use and the latest versions of all Documentation.

9.7. We shall not be liable, nor be required to fix, any problem arising from:

9.7.1. any modification made to any part of the APIs by anyone other than Us without Our express prior written consent; or

9.7.2. any defect or error wholly caused by any equipment or third party software used in connection with the APIs.

9.8. Subject to what it specifically says in these API Terms of Use and to the maximum extent permitted by applicable law, We and Our suppliers:

9.8.1. make no other promises and do not agree to any other terms and conditions (express, implied or statutory) in relation to the APIs, the API Data and the Platform or about results to be obtained from using the APIs, the API Data or the Platform; and

9.8.2. shall not be liable for any loss or damage arising out of any virus or other malicious code.

10. Liability

10.1. Subject to clause 10.2, We are not liable to You in any circumstances for any losses, damages, liabilities or claims arising under or in connection with these API Terms of Use.

10.2. We do not exclude or limit any liability to the extent the same cannot be excluded or limited by law (such as fraud, fraudulent misrepresentation, or personal injury resulting from Our or Our employees’ negligence).

11. Indemnification

11.1. You agree to indemnify Us against all losses or damage We may suffer related to:

11.1.1. the Application infringing the intellectual property rights of anyone (including Us);

11.1.2. any misuse of the APIs or API Data, including any claim Your use of the API Data infringes the intellectual property rights or privacy rights of anyone else; and

11.1.3. any breach by You of any promise or non-performance of any of Your obligations under these API Terms of Use.

11.2. This means that, in these particular circumstances, You will fully reimburse Us for any losses on an indemnity bas is, without Us having to take steps to avoid or minimise Our loss or to prove this is direct or foreseeable.

12. Updates to the API

12.1. We may make changes to the APIs at any time and for any reason. We will provide you with reasonable notice of any changes to the APIs that materially affect your use of the APIs.If any change We make is not acceptable to You, stop using the APIs. Your continued use of the APIs means that You accept the change to the APIs.

13. Termination

13.1. If You breach these API Terms of Use, Your rights to use the APIs and the API Data will automatically terminate, and We can shut down or restrict Your access to the APIs, the API Data and/or Your API integration.

13.2. Otherwise, the licences granted by Us under these API Terms of Use will continue until We terminate Your use (which we may do at any time for any reason and without notice)or You stop using the APIs, the API Data and the Platform.

13.3. In the event that any of the licences granted by Us under these API Terms of Use terminate for any reason, You shall promptly permanently delete and destroy all copies of API Data in Your possession or control.

13.4. Your obligations relating to the APIs, API Data, data protection, security and confidentiality and the indemnities and licences granted by You and the limitations and exclusions of liability set out in these API Terms of Use will continue even after any licences (and/or these API Terms of Use) have otherwise ended for any reason.

14. No Partnership

14.1. Nothing in these API Terms of Use shall (except as expressly provided) be deemed to constitute a partnership or create a relationship of principal and agent between You and Us for any purpose.

15. Governing law and jurisdiction

15.1. These API Terms of Use and any dispute or claim arising out of, or in connection with, these API Terms of Use, their subject matter or formation (including non-contractual disputes or claims) shall be:

15.1.1. governed by, and construed in accordance with, the laws of England and Wales; and

15.1.2. subject to the exclusive jurisdiction of the courts of England and Wales.

Appendix

API Security Standard

1. Purpose

This Security Standard forms part of the agreement between You and Us and applies to all access to, and use of, any APIs provided by Us.

2. Scope

This Security Standard applies to all persons who access or consume the APIs, whether directly or indirectly.

You shall ensure that all systems, applications, and users acting on its behalf comply with this Standard.

3. Authentication and Access Control

3.1. Access to the APIs shall only be made using the authentication mechanisms approved by Us (including, where applicable, OAuth2, mutual TLS, or API keys).

3.2. You shall:

  • Treat all credentials as confidential information
  • Store credentials securely using industry-standard protections
  • Ensure that each consuming system uses unique credentials
  • Not embed credentials in client-side code, mobile applications, or public repositories.

3.3. You shall not share credentials between environments, teams, or third parties.

4. Transport Security

4.1. All API traffic must be transmitted using TLS version 1.2 or higher.

4.2. You shall not attempt to access the APIs over unencrypted channels.

5. Rate Limiting and Abuse

5.1. You shall comply with all rate limits and usage policies notified to You from time to time.

5.2. Automated retry behaviour must implement appropriate back-off mechanisms.

5.3. You shall not generate traffic, whether intentionally or negligently, that may degrade the performance, availability, or security of the APIs or of other customers’ services.

6. Data Protection and Handling

6.1. You shall only request and process data obtained via the APIs for legitimate business purposes in accordance with the API Terms of Use, this Security Standard and any other agreement between You and Us.

6.2. You shall handle all data returned by the APIs in compliance with applicable data protection legislation, including the UK GDPR and Data Protection Act 2018.

6.3. API responses containing personal data or sensitive information must not be stored, cached, or logged in an insecure manner.

7. Secure Integration

You shall:

  • implement secure development practices aligned with recognised industry standards (including the OWASP Top 10)
  • validate and sanitise all input prior to transmission to the APIs
  • protect downstream systems from malformed, unexpected, or malicious responses
  • ensure that test and development environments do not use production credentials or live data.

8. Monitoring and Incident Notification

8.1. You shall monitor its API usage for abnormal or suspicious activity.

8.2. You shall notify Us without undue delay and in any event within 24 hours upon becoming aware of:

  • Any actual or suspected compromise of API credentials
  • Any unauthorised access to or misuse of the APIs.

8.3. We reserve the right to suspend or restrict API access immediately where it reasonably believes that such access presents a security risk, has been compromised, or is being abused.

9. Change and Lifecycle Management

9.1. You are responsible for maintaining compatibility with supported API versions.

9.2. Deprecated endpoints may be withdrawn in accordance with Our published lifecycle policy.

10. Assurance and Enforcement

10.1. Where Your API usage presents elevated risk, We may request reasonable evidence of compliance with this Security Standard.

10.2. Material or persistent non-compliance with this Security Standard shall constitute a breach of the Agreement and may result in suspension or termination of API access.