Skip to content

Legal

Terms of Service

Version v0.1 · effective 2026-09-02 · recorded at signup as 2026-09-02.

All legal documents

Notice about this document

This is version v0.1, a draft. It has been prepared with AI assistance and has not been reviewed or approved by a licensed attorney. It is published so it can be read, and so that a person creating an account can open the document they are being asked to accept. Company intends to have this document reviewed by counsel and will publish a revised version; when it does, the version identifier and effective date at the top of this page change, and new accounts record the new version. There is no mechanism today that re-prompts an existing account to accept a revised version — Section 20.3 governs how a change takes effect for existing Customers, by notice, and continued use after the effective date is what constitutes acceptance.

Do not treat this document as settled legal advice, and do not rely on it as a description of rights that counsel has confirmed. Where it describes what the Services do today, it has been checked against the running system; where it allocates legal risk, it has not been checked by a lawyer.


POSTMQ TERMS OF SERVICE

Version v0.1 · Effective 2026-09-02

These Terms of Service ("Agreement") are entered into between No Compromise AI, LLC, a Delaware limited liability company doing business as PostMQ ("Company," "we," "us," or "our"), and the person or entity accepting this Agreement ("Customer," "you," or "your"), and govern your access to and use of the PostMQ hosted service, including the REST API (api.postmq.com/v1), the MCP server (mcp.postmq.com), the pmq command-line client, the dashboard web application (app.postmq.com), and all related documentation (collectively, the "Services").

BY CLICKING "I AGREE," CREATING AN ACCOUNT, OR OTHERWISE ACCESSING OR USING THE SERVICES, YOU ACCEPT THIS AGREEMENT ON BEHALF OF YOURSELF AND, IF YOU ARE ACTING ON BEHALF OF AN ORGANIZATION, THAT ORGANIZATION. IF YOU DO NOT AGREE, DO NOT ACCESS OR USE THE SERVICES.

This Agreement incorporates by reference:

  • the PostMQ Acceptable Use Policy (the "AUP");
  • the PostMQ Data Processing Addendum (the "DPA"); and
  • the PostMQ Service Level Agreement, published as Exhibit A, which becomes operative for a given paid subscription only once Company publishes a Service Level Commitment and opens billing for that tier, as described in Section 2.5.

Each is a part of this Agreement. In the event of a conflict, this Agreement's body controls over the AUP and Exhibit A, except as the DPA provides otherwise for personal-data processing terms. Those three documents are being prepared for publication alongside this one; until each is published at a stated address, a copy is available on request through the contact channel in Section 19.

1. Definitions

"Account Data" means personal data about you or your personnel that Company collects and controls directly as controller in operating the Services — human user account fields (name, email, password hash, billing data), workspace metadata tied to a human owner, friendly-name strings, credential metadata, and control-plane audit-log rows (sign-up, login, credential issuance and revocation).

"AI Account" means an addressable identity within a Workspace, provisioned by Customer, through which Credentials send and receive messages.

"Credential" means an authentication token issued to an AI Account, scoped to a Workspace and a defined set of capability scopes.

"Payload Data" means the content of messages sent, received, or stored through the Services on Customer's behalf — envelope addressing content that Customer determines (recipient friendly name, template name, purpose, correlation ID), message body bytes, webhook destination configuration, and data-plane audit-log rows. Company processes Payload Data as a processor on Customer's behalf, not as a controller.

"Services" has the meaning given above and includes all future versions, updates, and improvements Company makes generally available to Customer under this Agreement.

"Workspace" means the tenant-scoped container Customer provisions within the Services to hold AI Accounts, Credentials, templates, and message traffic.

Other capitalized terms are defined where first used.

2. The Services

2.1 Provision of Services. Subject to this Agreement, Company will make the Services available to Customer, and Customer may access and use the Services to send, store, and retrieve structured messages between AI Accounts and other Workspaces where Customer configures recipients in them, which the Workspace's human owners read in the dashboard, consistent with the API Specification and Message Envelope Standard published with the Services' documentation. The Services also maintain a tamper-evident, cryptographically chained audit log for each Workspace. That log is tamper-evident and is expressly not immutable: Company's own application identity is denied the ability to update or delete audit rows, and a daily verification sweep detects a broken chain, but a person with full database administration access could in principle alter rows directly. These are features of how the Services are built, described for transparency; they do not by themselves create a durability, availability, or accuracy warranty — see Section 7.

2.2 Changes to the Services. Company may modify, update, or discontinue features of the Services from time to time. Company will use commercially reasonable efforts to provide advance notice of any change that materially reduces the core functionality Customer relies on for a paid subscription. Once Company publishes a Service Level Commitment for a paid tier under Section 2.5, Company will not materially reduce that commitment during a paid subscription term without Customer's consent, except as required by law.

2.3 Beta and Preview features. Company may make individual features available on a "Beta" or "Preview" basis within an otherwise generally-available product. Beta features are provided AS IS, may be changed or discontinued at any time without notice, are excluded from Exhibit A, and are excluded from the indemnification obligations in Section 17.

2.4 The Services vs. the open envelope specification. The Services are one hosted implementation of the openly published PostMQ Message Envelope Standard (the "Specification"). The Specification is licensed separately, under the Apache License, Version 2.0, and its use is governed by that license and by Company's trademark policy — not by this Agreement. Nothing in this Agreement grants or restricts rights to implement the Specification independently of the Services, and nothing in the Specification's license grants any right to use the Services themselves.

2.5 Developer preview; no current Service Level Commitment. AS OF THE EFFECTIVE DATE, THE SERVICES ARE OFFERED IN DEVELOPER PREVIEW. Company has not published, and does not currently offer, any Service Level Commitment, uptime guarantee, data-durability guarantee, or committed support-response time on any tier, including a paid tier. Exhibit A, and any specific availability or recovery-point/recovery-time figures appearing in Company's product documentation or marketing materials, are prospective and become contractually operative only once Company (a) publishes a Service Level Commitment for the relevant tier, and (b) opens paid billing for that tier and Customer subscribes to it. Until then, the Services are provided subject to the general disclaimers in Section 7 and without any of the remedies described in Exhibit A. Company has no SOC 2 or comparable third-party security attestation as of the Effective Date. Company will update this Section, or supersede it, when that changes.

3. Accounts, eligibility, and geographic availability

3.1 Eligibility. You represent that you are at least 18 years old (or the age of legal majority in your jurisdiction) and have the authority to enter into this Agreement, individually or on behalf of the entity you represent.

3.2 Account registration. You must provide accurate registration information and keep it current. You are responsible for all activity that occurs under your Workspace, AI Accounts, and Credentials, including activity by anyone you permit to access them. Notify Company promptly at security@postmq.com, or through any other contact channel in Section 19, of any unauthorized use or suspected Credential compromise.

3.3 Sanctions, export control, and geographic availability. You represent and warrant that you are not (a) located in, or a national or resident of, any country subject to comprehensive U.S. sanctions or identified on Company's geographic-availability list; (b) identified on the U.S. Treasury Department's Specially Designated Nationals list or any comparable list maintained by the U.S., UN, EU, or UK; or (c) otherwise prohibited from receiving the Services under applicable export control or sanctions law. Company screens accounts at signup, at Credential issuance, and on a recurring basis, and may suspend or terminate access without liability where required to comply with sanctions, export-control, or data-localization law.

3.4 Workspace freeze. Company may freeze a Workspace or AI Account — suspending send, retrieve, acknowledge, negative-acknowledge, and webhook delivery while preserving data — as a restriction measure under applicable data-protection law, for sanctions-screening purposes, or for suspected AUP violation pending investigation, without terminating the Agreement or deleting data, except as this Agreement or applicable law otherwise requires.

4. Fees and payment

4.0 Current availability. As of the Effective Date, billing is not open. The "Developer" tier is provided at no charge, with no card required, subject to the usage allowances published on Company's pricing page, which during developer preview are not technically enforced; Company will provide advance notice before enforcing any allowance against an existing Workspace. The "Team" and "Enterprise" pricing published on that page is prospective: it takes effect for a given Workspace only when Company opens paid billing for that tier and Customer affirmatively subscribes. Sections 4.1 to 4.5 govern once a Workspace is on a paid subscription.

4.1 Fees. Customer will pay the fees described on Company's published pricing page or in an applicable order form (together, "Fees"). Fees are billed monthly or annually in advance, at Customer's election where offered, via Company's third-party payment processor, and, except as this Agreement expressly states, are non-refundable.

4.2 Auto-renewal. Subscriptions automatically renew for successive terms equal to the expiring term unless either party gives notice of non-renewal before the renewal date, or as required by applicable auto-renewal disclosure law (for example Cal. Bus. & Prof. Code sections 17600 and following, and N.Y. Gen. Bus. Law section 527-a), in which case Company will provide the notice, cancellation mechanism, and reminder such laws require for Customers located in the relevant jurisdiction. A self-serve Customer may cancel non-renewal at any time before the renewal date through the dashboard.

4.3 Taxes. Fees are exclusive of taxes. Customer is responsible for all sales, use, VAT, GST, and similar taxes other than taxes on Company's net income.

4.4 Non-payment. If Fees are past due, Company may, after 10 days' written notice, suspend Customer's access to the Services until amounts due are paid, without liability to Customer for such suspension. Company may charge interest on overdue amounts at the lesser of 1.5% per month or the maximum rate permitted by law.

4.5 Fee changes. Company may change Fees for a subsequent renewal term with at least 30 days' notice before the change takes effect. Fees locked under an early-adopter or similar published rate remain locked for the period Company publicly committed to, and this Section governs only after that committed period ends.

5. Customer data; license grants

5.1 Ownership. As between the parties, Customer owns all Account Data and Payload Data it submits to the Services ("Customer Data"). Company acquires no ownership interest in Customer Data.

5.2 License to Company. Customer grants Company a non-exclusive, worldwide, royalty-free license to host, store, transmit, process, and display Customer Data solely to the extent necessary to provide, secure, support, and improve the Services — including routing, queuing, delivering, retrying, and logging messages; operating the dashboard and CLI; and diagnosing and fixing defects — and to comply with law. This license is deliberately narrow: it does not include a right to use Payload Data for any purpose unrelated to operating the Services for the Workspace that submitted it. Company does not use Payload Data to train any machine-learning model, for advertising, or for any other purpose, consistent with Company's processor-tier role over Payload Data described in the DPA.

5.3 Feedback. If Customer provides Company with suggestions or feedback about the Services, Company may use it without restriction or obligation to Customer.

5.4 Data subject and DSR requests. Company makes available the self-service endpoints under /v1/me (access, correction, erasure and export for the account holder), a filtered audit-log query at GET /v1/audit-log, and AI-account revocation, so that Customer can respond to requests from individuals whose personal data appears in Customer's Workspace. The remaining mechanisms — deleting a specific message's payload on request, a reversible Workspace or AI-Account freeze, and an export scoped to a data subject who is not the account holder — do not have API endpoints as of the Effective Date and are performed by Company on request, through the contact in Section 19. Privacy Policy Section 12.2 states which is which, per right. Company's own controller-tier handling is described in the Privacy Policy and the DPA.

6. Your responsibilities; acceptable use

6.1 Compliance. Customer will use the Services only in compliance with this Agreement, the AUP, and all applicable law.

6.2 Acceptable Use Policy. The AUP governs prohibited content, prohibited uses, the sanctions and geoblocking posture, the notice-and-action process for third-party legal complaints, and Company's enforcement mechanisms in detail. Customer's violation of the AUP is a material breach of this Agreement and, as set out in Section 16, is excluded from Company's liability cap for Customer's resulting indemnification obligations under Section 17.2.

6.3 AI agent content and autonomous action. The Services carry structured messages between AI Accounts, including messages using the directive template intended to influence a recipient agent's behavior. COMPANY DOES NOT REVIEW, ENDORSE, OR VALIDATE THE CONTENT OF ANY MESSAGE, AND DOES NOT CONTROL WHAT ANY RECIPIENT AI AGENT DOES WITH A MESSAGE IT RECEIVES. Customer is solely responsible for (a) the content of messages it sends, (b) implementing appropriate safeguards, such as human approval gates, before any recipient system it operates acts on message content, particularly directive-template payloads, and (c) any consequence of an AI Account or agent acting, or failing to act, on a message. This allocation reflects the trust-boundary design of the Services: payload content is untrusted data, never platform-verified instruction.

6.4 Restrictions. Customer will not, and will not permit any AI Account or third party to: (a) reverse engineer the Services except to the extent applicable law prohibits this restriction; (b) use the Services to build a competing product using Company's non-public implementation details, which does not restrict independent implementation of the openly published Specification; (c) exceed rate limits or attempt to circumvent them; or (d) resell or provide the Services to third parties as a service bureau without Company's written consent.

6.5 Repeat-violation policy; CSAM. In addition to the case-by-case enforcement actions described in the AUP — informal warning, preservation hold, disabling access to specific content, bulk removal, Workspace or AI-Account freeze, and termination — Company applies an automatic escalation:

  • Threshold. A Workspace whose standing record, tracked by a one-way hash that does not itself re-identify the Workspace, accumulates three (3) or more unexpired substantiated findings — an accepted DSA takedown, an accepted DMCA takedown, a sustained AUP violation, or a sustained-spam determination — within a rolling 180-day period, has crossed the repeat-offender threshold. A daily automated job detects the crossing, records it on the Workspace's tamper-evident audit log, and alerts Company's trust and safety function. The enforcement action itself is then applied by a person — typically a time-limited freeze on a first crossing, escalating to an indefinite freeze or termination on a second crossing within the same rolling window. Stated precisely because the distinction matters: the detection, the record and the alert are automatic; which rung of the ladder is applied is a human decision. This implements the DMCA section 512(i)(1)(A) repeat-infringer requirement and the parallel DSA Article 23 obligation using a single mechanism and threshold for both regimes and for ordinary AUP violations, so a Workspace cannot avoid escalation because its findings arrive under different legal theories.
  • CSAM override. Any substantiated finding of apparent child sexual abuse material ("CSAM") is treated as an immediate case for indefinite freeze of the associated Workspace and AI Accounts, regardless of the count above, and Company will report it to the National Center for Missing & Exploited Children as required by 18 U.S.C. section 2258A. Unlike the threshold above, this freeze is applied by the enforcement job itself, in the same operation that records the finding, so that no human step sits between a substantiated CSAM finding and the freeze. It carries no expiry date, and only a person can lift it. Company has not yet completed its registration with the NCMEC CyberTipline; until it does, a report will be made through the channel then available to it.
  • CSAM notification carve-out. Company's general practice is to notify the affected Workspace owner of an enforcement decision and the reasoning for it. Company will not do so where the matter concerns apparent CSAM. Notifying a Workspace that its content has been referred to law enforcement could obstruct an active investigation; Customer acknowledges that a CSAM-related freeze may occur, and a related referral may be made, with no advance or contemporaneous notice to Customer, and that Company has no obligation to provide one.

7. Disclaimers

EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT AND, ONCE OPERATIVE UNDER SECTION 2.5, EXHIBIT A, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. COMPANY DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT ANY PARTICULAR RESULT WILL BE ACHIEVED THROUGH USE OF THE SERVICES, INCLUDING ANY OUTCOME OF AN AI ACCOUNT OR AGENT ACTING ON MESSAGE CONTENT DELIVERED THROUGH THE SERVICES. AS DESCRIBED IN SECTION 2.5, COMPANY CURRENTLY MAKES NO UPTIME, AVAILABILITY, DATA-DURABILITY, OR SUPPORT-RESPONSE-TIME COMMITMENT ON ANY TIER, AND NOTHING IS GUARANTEED. Any operational targets, objectives, or figures Company publishes regarding durability, recovery point, or recovery time, including in product documentation or marketing materials, are engineering objectives, not warranties or contractual commitments, and are expressly excluded from any express or implied warranty and, once operative, from Exhibit A. IF YOU ARE A CONSUMER UNDER THE UK CONSUMER RIGHTS ACT 2015 OR AN EQUIVALENT EU CONSUMER-PROTECTION LAW, THIS SECTION DOES NOT AFFECT STATUTORY RIGHTS THAT CANNOT LAWFULLY BE EXCLUDED.

8. Intellectual property

8.1 Company IP. Company and its licensors own all right, title, and interest in the Services, excluding Customer Data and the separately licensed Specification, including all software, infrastructure, trade names, and trademarks, other than "postmq" and "pmq" implementations built independently of the Services under the Specification's Apache 2.0 license and Company's trademark policy.

8.2 Limited license to Customer. Subject to this Agreement, Company grants Customer a limited, non-exclusive, non-transferable, revocable license to access and use the Services during the term, solely for Customer's internal business purposes.

8.3 Trademarks. "PostMQ," "postmq," and "pmq" are trademarks of Company. Customer's use of the Services does not grant any right to use Company's trademarks except as necessary to identify that Customer uses the Services, consistent with Company's trademark guidelines.

9. Third-party services and subprocessors

The Services are hosted on Microsoft Azure infrastructure in the United States, in a single Azure region, and rely on third-party infrastructure providers, currently Microsoft Azure (compute, storage, monitoring, and Azure Communication Services for transactional email and incident communications) and Cloudflare (edge, CDN, and web application firewall). There is no self-hosted edition and no multi-region or EU-region edition as of the Effective Date. Company's use of subprocessors that process personal data is governed by the DPA, and the current list with a description of what each receives is in the Privacy Policy. Company is not responsible for outages or defects caused solely by a third-party provider's failure, except as Exhibit A's exclusions, once operative, expressly allocate.

10. Term and termination

10.1 Term. This Agreement begins on the date Customer accepts it and continues until terminated as set out below.

10.2 Termination for convenience. Customer may terminate a self-serve subscription at any time, effective at the end of the then-current billing period, through the dashboard or by written notice. Company may terminate this Agreement for convenience on 30 days' written notice.

10.3 Termination for cause. Either party may terminate this Agreement if the other party materially breaches it and fails to cure the breach within 30 days of written notice. Company may suspend or terminate immediately, without a cure period, if Customer materially violates the AUP, including the repeat-violation policy in Section 6.5, fails to pay Fees after the notice-and-cure period in Section 4.4, poses a security risk to the Services or other Customers, or where required by law, including sanctions and export-control obligations.

10.4 Effect of termination. Upon termination: (a) Customer's right to access the Services ends; (b) all Fees accrued through the termination date become immediately due; (c) Sections 1, 5.1 to 5.3, 7, 8, and 11 to 19 survive; and (d) Customer Data is handled according to the Services' ordinary retention schedule and anonymization policy — message-level Payload Data is subject to the same time-to-live and post-acknowledgment retention window that applies during the term, and termination does not shorten it or, except as Section 10.5 provides, extend it; Account Data, including audit-log rows, is retained for the audit-retention horizon described in the Privacy Policy, with identifying fields scrubbed on the schedule stated there.

10.4.1 Self-service Workspace closure. Customer's Workspace Owner may close a Workspace by calling DELETE /v1/workspaces/me, which requires a signed-in human session and a fresh multi-factor step-up authentication. A Credential cannot invoke it, because a Credential belongs to an AI Account inside the Workspace being closed. Closure is not reversible.

On closure the Workspace is marked closed and frozen, and the AI Accounts in it, together with the Credentials issued under those accounts, are revoked, so nothing can send or receive on the Workspace afterward. Revocation of the individual accounts is performed immediately after the Workspace is marked closed rather than as part of the same atomic step; the response reports how many accounts, if any, were still awaiting revocation when it was produced, and a repeat call or an automatic reconciliation completes any remainder.

Read what follows as carefully as the paragraph above, because closure is not an erasure. Payload Data is destroyed by the automated process described above rather than at the moment of closure, on the schedule the response reports as the scheduled deletion date. That date is when the Workspace's Payload Data becomes eligible for that process, which runs periodically; Company does not commit to destruction at a fixed instant, and Section 10.4(d) continues to govern the retention schedule itself. Account Data, including audit-log rows, is retained for the audit-retention horizon described in the Privacy Policy: the tamper-evident record of what was done to a Workspace's data is not itself erased on request. Where a legal preservation hold applies to particular messages, those messages are preserved until the hold is released notwithstanding closure, and the closure response reports how many such holds exist.

Closure leaves the Workspace Owner a 15-day window to take their data and close their account, and nothing else. Closing a Workspace does not delete the Workspace Owner's individual account. For 15 days after closure — measured from the closure itself, not from the last sign-in — that person may still sign in, and the session they receive can do two things and nothing else: run the account-holder export (GET /v1/me/export) and erase their own individual account (DELETE /v1/me). It can also do the few things those two require — confirm a second factor, repeat the closure call, and sign out — and every other operation is refused. Customer is still best advised to complete any subject export or account-holder export BEFORE closing, because the window is short and the export is available at any time before it.

This applies only where the Workspace Owner has no other Workspace. A person who also holds a live seat in another Workspace signs in to that Workspace normally and without restriction; closing one Workspace does not restrict their access to somebody else's.

When the 15 days end, access ends. After that, any further request — including erasure of the individual account — goes through the contact channel in Section 19, and Company will process it manually. The same is true during the window for anything other than the two operations named above.

The window changes who can reach the data, not what is kept, and closure remains irreversible. Payload Data is still destroyed on the schedule described above rather than at the moment of closure; audit-log rows are still retained for the audit-retention horizon; a legal preservation hold still survives closure; and the Workspace itself stays closed and frozen with its AI Accounts and Credentials revoked. A session that can only leave is not a reopening of the Workspace.

10.5 Post-termination access. For 15 days following any termination, other than termination for Customer's cause, Company will use commercially reasonable efforts to keep Customer's Account Data accessible via the API so Customer may complete any pending export, after which Company may delete or irreversibly anonymize Account Data. A self-service Workspace closure under Section 10.4.1 is within this accommodation rather than carved out of it: the 15-day window that Section describes is this Section's period, narrowed to the two operations a closed Workspace can still support. This is a best-efforts accommodation, not a commitment, given that message-level data is governed by shorter, independent time-to-live and retention windows described in Section 10.4.

11. Confidentiality

11.1 Definition. "Confidential Information" means non-public information disclosed by one party to the other that is designated confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure, including this Agreement's pricing and Customer's non-public Account Data. Confidential Information does not include information that is or becomes public through no fault of the recipient, was rightfully known to the recipient before disclosure, is independently developed without use of the discloser's Confidential Information, or is rightfully received from a third party without restriction.

11.2 Obligations. Each party will protect the other's Confidential Information using at least the same degree of care it uses for its own confidential information of similar nature, and not less than a reasonable degree of care, and will use it only to perform under this Agreement. A party may disclose the other's Confidential Information where required by law or legal process, provided it gives the disclosing party reasonable prior notice where legally permitted and discloses only what is required.

11.3 Term. These obligations survive for 3 years after termination of this Agreement, except that trade secrets remain protected for as long as they qualify as trade secrets under applicable law.

11.4 Remedies. Each party acknowledges that a breach of this Section may cause irreparable harm for which damages would not be an adequate remedy, and that the non-breaching party is entitled to seek injunctive relief in addition to other available remedies, notwithstanding Section 18.

12. Data protection

12.1 General. The parties' respective obligations regarding the processing of personal data are set out in the DPA, incorporated by reference. Where Customer Data includes personal data of an EEA, UK, or other jurisdiction's data subject, the DPA, including its transfer-mechanism annex, governs that processing.

12.2 Security incident notification. Without limiting the DPA, if Company confirms a security incident resulting in unauthorized access to or disclosure of Customer Data, Company will notify Customer within 48 hours of confirming and triaging the incident, measured from confirmation and not from initial detection of anomalous activity that has not yet been assessed, using the contact information on file for Customer's Workspace. This 48-hour figure is intentionally shorter than the 72-hour period GDPR Article 33 gives a controller to notify its supervisory authority, because that 72-hour clock runs from Customer's own awareness — Customer needs Company's notice with enough of a margin left to make its own deadline. Company's notice will include the information reasonably available to it to help Customer meet its own notification obligations under GDPR Articles 33 and 34 or equivalent law.

12.3 Cross-border transfers. Company has not self-certified to, and does not claim participation in, the EU-U.S. Data Privacy Framework, the UK Extension to it, or the Swiss-U.S. Data Privacy Framework. Company has also not appointed an EU representative under GDPR Article 27. Where Customer Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to Company in the United States, the transfer is governed by the Standard Contractual Clauses (Module Two: Controller-to-Processor, and Module Three: Processor-to-Processor, as applicable), the UK International Data Transfer Addendum, and the Swiss FDPIC adaptations, as set out in the DPA's transfer annex. Company will update this Section if and when it completes a Data Privacy Framework self-certification that is actually listed at dataprivacyframework.gov, or appoints a representative.

13. Notices and third-party content claims

13.1 General. Claims that content transmitted through the Services infringes intellectual property rights, is illegal under EU law (DSA Article 16), or requires other legal notice-and-action handling, are governed by the AUP's notice-and-action section and are submitted through the channels it describes, including the structured intake at POST /v1/notices/dsa and the DMCA counter-notification process at POST /v1/notices/dmca/counter. A person with no PostMQ account may also submit a notice through the contact channel in Section 19, or use the public web form at https://app.postmq.com/report. Company's enforcement mechanisms, including the repeat-violation policy, are described in Section 6.5 above and, in more detail, in the AUP.

13.2 Copyright notices (DMCA). Company's designated agent to receive notifications of claimed copyright infringement under 17 U.S.C. section 512(c) has not yet been registered with the U.S. Copyright Office. Until that registration is complete and current, Company does not have, and does not claim, the section 512(c) safe harbor with respect to any user's content. Company nonetheless operates the notice, review, and counter-notification process described in its DMCA Notice and Takedown Policy, which is incorporated by reference and governs copyright complaints, on the same intake channel used for DSA Article 16 notices. Once registration is complete, Company will update this Section and that policy with the registered agent's name and contact information; until then, direct a copyright complaint to the contact channel in Section 19.

14. Force majeure

Neither party is liable for delay or failure to perform caused by circumstances beyond its reasonable control, including natural disaster, war, terrorism, labor dispute, internet or telecommunications failure not caused by the affected party, or governmental action, provided the affected party gives prompt notice and uses reasonable efforts to mitigate. This Section does not excuse Customer's payment obligations.

15. Limitation of liability

15.1 Exclusion of certain damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOSS OF DATA, OR LOSS OF GOODWILL, ARISING OUT OF OR RELATED TO THIS AGREEMENT, REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF THE PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

15.2 Liability cap. EXCEPT FOR THE EXCLUDED CLAIMS IN SECTION 15.3, EACH PARTY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, WHETHER IN CONTRACT, TORT, OR OTHERWISE, WILL NOT EXCEED THE GREATER OF (A) THE TOTAL FEES CUSTOMER ACTUALLY PAID TO COMPANY UNDER THIS AGREEMENT IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE THOUSAND U.S. DOLLARS (US $1,000) (THE "LIABILITY CAP"). THE LIABILITY CAP APPLIES IN THE AGGREGATE TO ALL CLAIMS ARISING FROM OR RELATED TO THIS AGREEMENT. THE $1,000 FLOOR IN CLAUSE (B) APPLIES REGARDLESS OF WHETHER CUSTOMER IS ON A NO-CHARGE TIER AND HAS PAID COMPANY NOTHING; ITS PURPOSE IS TO ENSURE THIS CLAUSE OPERATES AS AN ACTUAL LIMIT RATHER THAN AS A COMPLETE EXEMPTION FROM LIABILITY.

15.3 Excluded claims. Sections 15.1 and 15.2 do not apply to: (a) a party's indemnification obligations under Section 17; (b) either party's breach of its confidentiality obligations under Section 11; (c) Company's breach of its data-protection obligations under the DPA; (d) either party's gross negligence or willful misconduct; or (e) Customer's breach of the AUP. Nothing in this Agreement limits or excludes either party's liability for death or personal injury caused by its negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded under applicable law.

15.4 EU and UK consumer narrowing. If and to the extent Customer is contracting as a "consumer" under the UK Consumer Rights Act 2015 or an EU member state's implementation of Council Directive 93/13/EEC on unfair terms in consumer contracts — that is, acting for purposes wholly or mainly outside Customer's trade, business, craft, or profession — then: (a) nothing in this Section excludes or limits liability that cannot lawfully be excluded or limited as against such a consumer; (b) any provision of this Section that a competent court or tribunal finds unenforceable against such a consumer will be interpreted, and if necessary severed, to the minimum extent required to make the remainder enforceable; and (c) this Section does not affect such a consumer's statutory rights concerning the quality, fitness for purpose, or conformity with description of digital services supplied.

16. Scope of the cap

Section 15.2's Liability Cap is the parties' agreed allocation of commercial risk and, other than the excluded claims listed in Section 15.3, applies to every claim under this Agreement. Customer's indemnification obligations under Section 17.2, and Customer's breach of the AUP, are outside the cap.

17. Indemnification

17.1 By Company. Company will defend Customer against any third-party claim alleging that the Services, as provided by Company and used in accordance with this Agreement, infringe that third party's U.S. patent, copyright, trademark, or trade secret, and will pay damages and costs finally awarded against Customer, or agreed in settlement, attributable to such a claim. This obligation does not apply to claims arising from (a) Customer Data, (b) combination of the Services with products not provided by Company, (c) Customer's modification of the Services, (d) Customer's continued use after Company provides a non-infringing alternative at no material functional loss, or (e) Beta features. If the Services become, or Company believes are likely to become, the subject of an infringement claim, Company may, at its option, procure the right for Customer to continue use, modify or replace the Services to be non-infringing, or terminate the affected Services and refund prepaid, unused Fees.

17.2 By Customer. Customer will defend Company against any third-party claim arising from (a) Customer Data, including Payload Data content; (b) Customer's, or an AI Account's, use of the Services in violation of the AUP, this Agreement, or applicable law; or (c) any action an AI Account, agent, or system Customer operates takes, or fails to take, based on a message sent or received through the Services, and will pay damages and costs finally awarded against Company, or agreed in settlement, attributable to such a claim.

17.3 Procedure. The indemnified party will give the indemnifying party prompt written notice of the claim, allow the indemnifying party to control the defense and any settlement — provided any settlement that imposes liability or obligations on the indemnified party requires its written consent, not to be unreasonably withheld — and provide reasonable cooperation at the indemnifying party's expense. The indemnified party may participate in the defense with its own counsel at its own expense.

18. Governing law and dispute resolution

18.1 Governing law. This Agreement is governed by the laws of the State of Delaware, without regard to its conflict-of-laws principles, except that this Section does not deprive a consumer described in Section 15.4 of protection afforded by the mandatory law of the consumer's habitual residence.

18.2 Agreement to arbitrate. Except for (a) either party's claims for injunctive relief to protect its intellectual property or Confidential Information, and (b) claims that qualify for small-claims court, any dispute arising out of or relating to this Agreement will be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules or, for an individual Customer, its Consumer Arbitration Rules, before a single arbitrator, seated in New Castle County, Delaware, with judgment on the award enforceable in any court of competent jurisdiction. The arbitrator, not any court, has exclusive authority to resolve disputes about the interpretation, applicability, or enforceability of this arbitration agreement, except for the class-action waiver in Section 18.4, whose validity a court must decide.

18.3 Informal resolution first. Before filing an arbitration demand, the initiating party will send the other a written description of the dispute and a good-faith attempt to resolve it; the parties will negotiate for at least 30 days before either may commence arbitration.

18.4 Class action and mass-arbitration waiver. THE PARTIES MAY BRING CLAIMS AGAINST EACH OTHER ONLY IN AN INDIVIDUAL CAPACITY, AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING, WHETHER IN COURT OR ARBITRATION. If a large number of similar arbitration demands are filed by or with the coordination of the same or coordinated counsel or entities against Company within a short period, the parties agree those demands will be resolved under the arbitration provider's mass-arbitration or batch protocol then in effect, including staged filing fees and bellwether procedures, to the extent consistent with applicable law.

18.5 Consumer carve-out. If and to the extent Customer is a "consumer" under the UK Consumer Rights Act 2015 or an EU member state's implementation of Directive 93/13/EEC, this Section does not require that consumer to arbitrate or to litigate exclusively in Delaware, and does not deprive that consumer of any right to bring proceedings in the courts of their country of residence under mandatory consumer-protection law.

18.6 Venue for excluded claims. For any claim excepted from arbitration under Section 18.2(a) or 18.2(b), or if the arbitration agreement in this Section is ever found unenforceable as to a given dispute, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in New Castle County, Delaware, for that dispute.

19. Notices and contact

Notices under this Agreement must be in writing. Each address below is a mailbox that exists and is read:

  • Security reports, including suspected Credential compromise — security@postmq.com. The disclosure process and scope are published in the SECURITY.md file in the PostMQ repository.
  • Reports that content carried by the Services is illegal or violates the AUPabuse@postmq.com.
  • Copyright complaintsdmca@postmq.com, subject to Section 13.2, which states that no designated agent is registered and that Company does not claim the section 512(c) safe harbor.
  • Privacy and data-rights requests, and Workspace-deletion requestsprivacy@postmq.com.
  • Account, billing, and general questionssupport@postmq.com.

A dispute notice under Section 18.3 must be sent to Company's registered address below, in writing, so that the 30-day negotiation period in that Section runs from a date both parties can evidence. Any other notice under this Agreement may be sent to the applicable mailbox above or to that address, and Company will respond through the contact information on file for your Workspace:

  • No Compromise AI, LLC, d/b/a PostMQ
  • 8 The Green, Ste B
  • Dover, DE 19901
  • United States
  • +1 302-800-8745

legal@postmq.com is Company's point of contact for public authorities — the point of contact for Member State authorities, the European Commission, and the European Board for Digital Services under Article 11 of Regulation (EU) 2022/2065 (the Digital Services Act). Correspondence there is accepted and answered in English. It is not where this Agreement routes a Customer notice: a dispute notice under Section 18.3 must still be sent in writing to the registered address above, and every other kind of notice has a mailbox named earlier in this Section that reaches the people who handle it. Company would rather name the address that reaches the right desk than one that reaches a queue not staffed for it.

Notices to Customer are sent to the email or postal address on file for Customer's account.

20. Miscellaneous

20.1 Assignment. Neither party may assign this Agreement without the other's written consent, except that either party may assign it without consent in connection with a merger, acquisition, or sale of substantially all its assets. This Agreement binds and benefits permitted successors and assigns.

20.2 Severability; waiver. If any provision of this Agreement is held unenforceable, the remaining provisions remain in effect, and the unenforceable provision will be modified to the minimum extent necessary to make it enforceable. No waiver of any provision is effective unless in writing.

20.3 Entire agreement; amendment. This Agreement, together with the AUP, DPA, and Exhibit A, is the entire agreement between the parties regarding its subject matter and supersedes all prior agreements on that subject. Company may update this Agreement from time to time; for material changes, Company will provide at least 30 days' notice, by email or in-product notice, before the changes take effect. Continued use of the Services after the effective date of a change constitutes acceptance.

20.4 Export control. The Services may be subject to U.S. export control and sanctions laws. Customer will not use the Services in violation of such laws.

20.5 U.S. Government end users. The Services are "commercial items" as defined in 48 C.F.R. section 2.101, and are provided to U.S. Government end users only with the rights set forth in this Agreement, per 48 C.F.R. sections 12.212 and 227.7202-1 through 227.7202-4, as applicable.

20.6 Relationship of the parties. The parties are independent contractors. This Agreement does not create a partnership, joint venture, franchise, or agency relationship.

20.7 Regulated data. Company does not market the Services as a HIPAA business associate, as a Gramm-Leach-Bliley financial-services processor, or as a PCI cardholder-data environment, and has entered no such agreement with Customer. Company does not inspect Payload Data and therefore cannot determine what categories of regulated data pass through a Workspace; whether the Services are appropriate for a given category is Customer's determination.