Open MercatoSandbox
Back to home

Terms of Service

Last updated August 1, 2026

Section 1. Provider and Scope of these Terms

  1. 1.1.The provider of the Service is Open Mercato sp. z o.o. with its registered office in Wrocław (address: ul. Wyspa Słodowa 7, 50-266 Wrocław; registered by the District Court for Wrocław-Fabryczna in Wrocław, KRS number: 0001253104; TIN/EU VAT no.: 8982336029, active VAT payer; share capital: PLN 80,000.00; the “Provider”).
  1. 1.2.The Provider may be contacted at info@openmercato.com or through the contact form available via the Site.
  1. 1.3.These terms and conditions (these “Terms”) govern the provision of electronic services, the conclusion and performance of the Agreement, the use of the Account, Sandboxes, AI Tools, and additional services, as well as payments, complaints, suspension, and termination of use of the Service.
  1. 1.4.These Terms constitute terms and conditions for the provision of electronic services. They are made available to the User before the Agreement is concluded in a manner that enables the User to save, reproduce, and retain them.
  1. 1.5.The following documents form an integral part of the Agreement: the Order, these Terms, the Pricing, and the Specification in effect when the Order is placed and, to the extent that the Provider processes personal data on the User’s behalf, the data processing agreement (the “DPA”). In the event of a conflict, the Order will prevail, followed by the DPA in matters concerning data protection, these Terms, and then the Pricing and the Specification.
  1. 1.6.These Terms are effective as of August 1st, 2026.

Section 2. Definitions

  1. 2.1.“Pricing” means the information concerning Plans, prices, parameters, limits, and billing units made available on the Site or through the Dashboard before an Order is placed.
  1. 2.2.“User Data” means source code, files, databases, configurations, content, personal data, credentials, and other information entered, uploaded, stored, or generated by the User in connection with the Service, excluding the Provider’s billing and telemetry data.
  1. 2.3.“Business Day” means any day from Monday through Friday, excluding public holidays in Poland.
  1. 2.4.“AI Features” means features that enable the use of AI Tools and Models through the Provider’s infrastructure and integrations.
  1. 2.5.“Consumer” means an individual who enters into the Agreement with the Provider for purposes not directly related to that individual’s trade, business, craft, or profession.
  1. 2.6.“Account” means the User’s individual account on the Site, secured by authentication credentials.
  1. 2.7.“AI Credits” means the Provider’s internal, non-exchangeable, and non-transferable billing units used exclusively to cover charges for the use of AI Features.
  1. 2.8.“Models” means artificial intelligence models made available by third parties, including through OpenRouter.
  1. 2.9.“AI Tools” means preinstalled AI-enabled development tools, including Codex and Claude Code, or their successors.
  1. 2.10.“Billing Period” means the monthly billing period specified in the Order, which, as a rule, corresponds to a calendar month.
  1. 2.11.“Dashboard” means the online interface used to manage the Account, Sandboxes, payments, AI Credit balance, and support requests.
  1. 2.12.“Plan” means a Service option with the parameters and price specified in the Pricing.
  1. 2.13.“Consumer-Protected Entrepreneur” means an individual who enters into the Agreement directly in connection with that individual’s business activity, where the Agreement is not of a professional nature for that individual, as determined on the basis of the subject matter of the Agreement.
  1. 2.14.“Sandbox” means an individual, managed cloud development environment made available to the User under the selected Plan.
  1. 2.15.“Site” means the Provider’s website, the Dashboard, and any other interfaces through which the Service is offered or provided.
  1. 2.16.“Specification” means the then-current description of the features, technical requirements, parameters, and limitations of the Service made available on the Site or through the Dashboard.
  1. 2.17.“Service” means the managed Open Mercato Sandboxes cloud development environment service comprising the elements specified in Section 6.
  1. 2.18.“User” means an individual, legal entity, or organizational unit that has entered into the Agreement, as well as an individual who uses the Account on its behalf.
  1. 2.19.“Business User” means a User that is neither a Consumer nor a Consumer-Protected Entrepreneur.
  1. 2.20.“Order” means the User’s statement submitted through the electronic purchasing process specifying, in particular, the Plan, price, Billing Period, and User details.
  1. 2.21.“Agreement” means the agreement for the provision of the Service entered into between the Provider and the User on the basis of the Order and the documents specified in Section 1.5.
  1. 2.22.“Support” means the Provider’s handling of User requests concerning the technical operation of the Service through the channels and during the hours specified in Section 13.4. Support does not include administration of the User’s application, development services, consulting, or any other services not expressly specified in the Order or Pricing.

Section 3. Intended Users and Territory

  1. 3.1.The Service may be used only by adults with full legal capacity and by entities represented by duly authorized persons.
  1. 3.2.The Service is intended for persons with at least a basic knowledge of web application development and use of the Linux command line. It is not a training service or an application administration service for the User’s application.
  1. 3.3.The Service is offered to Users in countries for which the Provider enables the placement of Orders. The Provider may refuse to enter into the Agreement or restrict access in relation to countries, persons, or entities subject to sanctions, embargoes, export restrictions, payment provider restrictions, or other legal or technical impediments.
  1. 3.4.The User must provide accurate information concerning its status, country of residence or registered office, tax information and, in the case of a business, registration and VAT information. An individual conducting business activity may be asked to indicate whether the Agreement is of a professional nature for that individual. The Provider may not make the conclusion of the Agreement conditional on such a statement where otherwise provided by law.
  1. 3.5.The Service is not intended for production, critical, high-risk, or business-continuity-sensitive use cases, including the provision of financial or healthcare services, critical infrastructure, life or health safety, weapons systems, or the making of legally significant decisions concerning individuals.
  1. 3.6.The technical availability of the Site in a particular country does not mean that the Provider directs its offering to Users in every country or that the Service complies with sector-specific requirements applicable to the User’s activities.

Section 4. Conclusion of the Agreement and Activation

  1. 4.1.The Agreement is concluded once all of the following conditions have been met: (a) the Account has been created and the email address verified; (b) these Terms have been accepted; (c) the Order has been placed; and (d) the first payment has been successfully made, unless the Order provides for a free trial period.
  1. 4.2.The Service is activated automatically following payment confirmation and may require a brief period to create the Sandbox and allocate resources.
  1. 4.3.Before activation or during the term of the Agreement, the Provider may verify the User’s details, the authority of a person acting on the User’s behalf, the User’s tax status, sanctions compliance, or the risk of abuse. Failure to cooperate may result in refusal to activate the Service, suspension, or termination of the Agreement.
  1. 4.4.The Account is personal and is currently intended for a single user. Shared Accounts, the sharing of authentication credentials, and the use of one Account by multiple persons are not supported and are prohibited.
  1. 4.5.The User is responsible for maintaining the confidentiality of its login credentials, the security of its devices, all activity conducted through the Account, and promptly reporting any suspected unauthorized access.
  1. 4.6.Recovery of access to the Account may require confirmation of access to the verified email address and consistency with the information provided during registration. The Provider may refuse to restore access if it cannot reliably verify the requesting person’s authority.
  1. 4.7.The authentication methods available through the Dashboard may change. The Provider may require additional authentication where justified by the security of the Service.

Section 5. User Responsibilities and Technical Requirements

  1. 5.1.Use of the Service requires: (a) an up-to-date web browser in one of the two most recent stable versions supported by its vendor; (b) a stable internet connection with a bandwidth of at least 10 Mbps; (c) a device capable of running a browser, terminal, and development environment; (d) support enabled for necessary cookies, session tokens, and JavaScript; and (e) the technical knowledge specified in Section 3.2.
  1. 5.2.The User accesses the Sandbox through a browser-based SSH terminal and browser-based IDE. The Provider may not support access using an external SSH client, the addition of the User’s own SSH keys, or root access.
  1. 5.3.The User is responsible for configuring, updating, and testing its own code, dependencies, databases, applications, and integrations, as well as for securely storing confidential or sensitive information. Passwords, API keys, and other confidential or sensitive information must not be placed directly in source code.
  1. 5.4.The User should maintain its own additional copies of data where data loss could have material consequences. Backups performed by the Provider are an operational mechanism of the Service and are not a substitute for the User’s business continuity strategy.
  1. 5.5.The Provider is not liable for any inability to use the Service resulting from failure to meet the technical requirements, failure of the User’s device or internet connection, an unsupported configuration, or the operation of software installed by the User.

Section 6. Scope and Nature of the Service

  1. 6.1.The Service consists of providing a managed cloud development environment intended for creating, testing, and demonstrating applications, including applications based on Open Mercato.
  1. 6.2.Depending on the Plan, the Service may comprise: (a) the creation of an individual Sandbox with the CPU, RAM, storage, and data transfer parameters specified in the Pricing; (b) an operating system and managed updates to the base image; (c) access to a browser-based SSH terminal and a browser-based IDE based on code-server or another solution permitting commercial self-hosting; (d) preinstalled AI Tools; (e) support for the technologies specified in the Specification, including TypeScript, Node.js, PostgreSQL, and GitHub integration; (f) basic infrastructure monitoring; (g) backups as specified in Section 11; (h) the ability to publish an application under a subdomain owned by the Provider with an automated TLS certificate provided using Let’s Encrypt or an equivalent solution; or (i) access to AI Features billed separately using AI Credits.
  1. 6.3.The Plan parameters, limits, number of Sandboxes, and scope of additional services are specified before the Order is placed. The Provider may make resources available to the User on a shared basis with other users within a virtualized infrastructure, while maintaining logical separation between environments.
  1. 6.4.As a rule, the Sandbox is hosted in a Hetzner data center located in Germany. The Provider may change the infrastructure provider or region in accordance with Section 18, subject to compliance with its data protection obligations.
  1. 6.5.The Sandbox IP address may be dynamic or shared. The Provider does not warrant that the IP address will remain unchanged, that particular ports will be available, or that the User will be able to use its own domain, its own TLS certificate, or a dedicated IP address.
  1. 6.6.Inbound traffic is restricted by default in accordance with a deny-by-default approach. The Provider may restrict ports, protocols, outbound data transfer, and the number of connections to protect the Service and prevent abuse.
  1. 6.7.Scaling is not automatic. An increase in parameters requires a change of Plan or the purchase of an additional service, if available.
  1. 6.8.The Provider may update the operating system, images, libraries, IDE, and tools. The User is responsible for verifying the compatibility of its code with such updates.
  1. 6.9.The Service is not a production environment and does not provide parameters appropriate for production hosting of business applications, including a guaranteed SLA, high availability, automatic scaling, geographic redundancy, or a disaster recovery plan tailored to the User’s application.
  1. 6.10.The Models are not developed or hosted by the Provider. The Provider provides only the technical integration necessary to route requests to Model providers through OpenRouter or another aggregator.

Section 7. Additional Services

  1. 7.1.To the extent made available in the Pricing, the User may purchase additional storage, data transfer, Sandboxes, or AI Credits.
  1. 7.2.Backup restoration is performed by Support. Four restorations in each calendar month are included in the Plan fee. Further restorations may be subject to an additional charge based on an individual quotation provided before work begins.
  1. 7.3.The Provider does not currently offer a dedicated IP address, use of the User’s own domain or TLS certificate, private Models, guaranteed routing of AI requests exclusively within the EEA, or premium support with a guaranteed SLA, unless otherwise specified in the Pricing or an individual Order.
  1. 7.4.The Provider does not provide automatic migration of applications created by the User. The obligations relating to data export and provider switching are set out in Section 12.

Section 8. AI Features

  1. 8.1.The AI Features are supplemental and depend on the availability of OpenRouter, Model providers, AI Tools, and their respective interfaces, limits, and terms.
  1. 8.2.The User selects a Model from among the Models then available through the Service interface. The list of Models, their providers, parameters, prices, and availability may change over time, including without prior notice where the change results from the actions of a third party, security considerations, or a legal obligation.
  1. 8.3.The primary API key used by the Provider is not disclosed to the User. The Provider attributes use of AI Features to the Account and may apply virtual identifiers, usage limits, rate limiting, and spending controls.
  1. 8.4.AI Features are blocked once the AI Credit balance has been exhausted. A negative balance is not permitted. Usage information is made available through the Dashboard; the Provider does not warrant that separate spending alerts will be sent.
  1. 8.5.The Provider does not warrant that prompts, files, code, or other data submitted to Models will be processed exclusively within the EEA. Requests may be routed to providers operating in third countries, depending on the selected Model and the policies of OpenRouter or the relevant provider.
  1. 8.6.The User must not submit the following through the AI Features: (a) personal data, including special categories of personal data and personal data relating to criminal convictions and offenses, unless the Provider has expressly permitted such processing and appropriate legal grounds and safeguards are in place; (b) trade secrets, confidential information, production data, authentication credentials, keys, credentials, or other information whose disclosure could result in harm; or (c) data, code, or content that the User has no right or authority to submit for processing by Model providers.
  1. 8.7.The Provider does not warrant zero-data-retention processing, that prompts will not be stored, that data will not be used to improve or train Models, or any particular retention period applied by third parties, unless expressly stated otherwise for a particular Model. The User must review the information made available when selecting a Model.
  1. 8.8.Model output may be inaccurate, incomplete, susceptible to security vulnerabilities, unlawful, similar to third-party materials, or unsuitable for the intended purpose. Before using, publishing, or deploying any output, the User must subject it to human review and functional, security, and licensing tests.
  1. 8.9.The Provider does not warrant any particular result, the correctness of code, the absence of vulnerabilities, the originality of output, or the acquisition of intellectual property rights in the output. The scope of rights in the output is determined by applicable law and the terms of the relevant Model provider.
  1. 8.10.The User must not use the AI Features for any purpose prohibited by law, including laws governing artificial intelligence systems, or to create or operate any solution referred to in Section 3.5.
  1. 8.11.The Provider may suspend access to a particular Model, AI Tool, or AI Feature in the event of suspected abuse, prompt injection, data exfiltration, circumvention of safeguards, excessive resource use, breach of third-party terms, or a security threat.

Section 9. User Data and Intellectual Property

  1. 9.1.The User retains its rights in the User Data and code created by it in the Sandbox. The Provider does not acquire rights in code or output solely because it was created, stored, or processed using the Service.
  1. 9.2.The User grants the Provider a non-exclusive, royalty-free license and authorization, limited to the duration and purpose of providing the Service, to technically reproduce, store, transmit, back up, restore, display, and make User Data available to the public to the extent necessary to perform the Agreement, carry out the User’s instructions, maintain security, and comply with legal obligations.
  1. 9.3.The User represents that it holds all rights and has all legal grounds necessary to submit User Data to the Service and have it processed in accordance with the Agreement.
  1. 9.4.Elements of Open Mercato made available under the MIT License or another open-source license are subject to the applicable license terms. The provision of the hosted Service does not constitute a transfer of rights in the Provider’s infrastructure, interfaces, billing systems, configurations, trademarks, or components that have not been designated as open source.
  1. 9.5.The User may commercialize its own code and applications, subject to third-party rights, licenses applicable to open-source components, the terms of Model and AI Tool providers, and applicable law.
  1. 9.6.The names and marks OpenAI, Anthropic, Claude, Codex, OpenRouter, Visual Studio Code, GitHub, Hetzner, Let’s Encrypt, and other third-party designations belong to their respective owners. The availability of an integration does not imply that the Provider is affiliated with, sponsored by, or authorized by any such third party.
  1. 9.7.Voluntary feedback provided to the Provider may be used without charge to develop the Service, provided that it does not contain information designated as confidential or User Data.

Section 10. Acceptable Use and Public Hosting

  1. 10.1.The User must use the Service in compliance with applicable law, these Terms, the Specification, third-party rights, the principles of social coexistence, and the terms of service providers used in connection with the Service.
  1. 10.2.The following activities are prohibited in particular: (a) storing, publishing, transmitting, or distributing unlawful content or content that infringes intellectual property rights, personal rights, privacy, or legally protected secrets; (b) creating, hosting, or distributing malware, ransomware, viruses, exploits, phishing tools, botnets, data theft tools, or other harmful components; (c) sending spam, conducting unsolicited campaigns or bulk messaging, or engaging in activities that disrupt networks or systems; (d) scanning, penetration testing, or attempting to obtain unauthorized access to third-party resources, unless such activities relate exclusively to the User’s own resources or are conducted with the documented consent of the owner; (e) cryptocurrency mining or providing proxy, VPN, Tor, anonymization, or resource resale services, unless the Provider has given prior written consent; (f) circumventing limits, safeguards, metering, Model restrictions, tenant isolation, or cost-control mechanisms; (g) engaging in activities that cause excessive resource consumption, disrupt the Service, or create a risk for other users; and (h) using the Service to violate sanctions, export controls, data protection laws, consumer protection laws, or sector-specific regulations.
  1. 10.3.An application published under the Provider’s subdomain may be publicly accessible. The User is responsible for its content, security, legal documentation, data processing, information provided to end users, and compliance with the laws applicable to its intended audience.
  1. 10.4.The Provider does not generally monitor User Data. It may, however, apply proportionate technical measures and analyze metadata for security, billing, abuse detection, and compliance with legal obligations.
  1. 10.5.A notice concerning unlawful content should be submitted to info@openmercato.com and contain at least: (a) an explanation of why the notifying person considers the content unlawful; (b) the exact location of the content, including its URL and information enabling it to be identified; (c) the name or business name and email address of the notifying person, except where the law does not require such information; and (d) a statement that the notice has been submitted in good faith and that the information contained in it is complete and accurate.
  1. 10.6.The Provider may remove or block content, an application, a public URL, a Sandbox, or an Account where justified by the nature of the infringement, a threat, an order of a competent authority, or the need to mitigate harm. Where permitted by law, the Provider will provide the User with the reasons for its decision and enable the User to submit an appeal to info@openmercato.com.
  1. 10.7.The Provider may take immediate action without prior notice where delay could expose any person, system, or the Provider to harm, interfere with the implementation of an authority’s order, defeat the purpose of a protective measure, or breach a confidentiality obligation.

Section 11. Backups and Restoration

  1. 11.1.As a rule, the Provider creates one backup per day and retains up to seven daily restore points.
  1. 11.2.A backup covers the code located in the Sandbox working directory and a backup of the PostgreSQL database to the extent technically supported by the Service. A backup may exclude cache data, ephemeral data, data stored outside the specified scope, external services, repositories, third-party resources, or elements excluded in the Specification.
  1. 11.3.Backups are stored in Hetzner infrastructure located within the European Union and are protected in transit and at rest in accordance with the solutions used by the Provider and the infrastructure provider.
  1. 11.4.The Provider will use reasonable efforts to restore a backup within 24 hours after accepting a complete request. This target is not a guaranteed SLA unless otherwise specified in the Order.
  1. 11.5.Restoration may replace current data with data from the selected restore point. Before restoration, the User should secure any data it wishes to retain.
  1. 11.6.The Provider does not warrant that every backup will be error-free, complete, or suitable for every purpose. Subject to Section 17, the Provider is responsible for creating backups in accordance with the parameters specified in this Section.
  1. 11.7.The User may download data or a backup in the format made available through the Dashboard or by Support. The scope and format of an export depend on the functionality of the Service.

Section 12. Export, Provider Switching, and Data Deletion

  1. 12.1.During the term of the Agreement, the User may export User Data using the functions available through the Dashboard or by submitting a request to Support.
  1. 12.2.Following termination of the Agreement, the Provider will give the User at least 30 days to download exportable User Data and digital assets, unless the User requests their earlier deletion, retention is prohibited by law, or the Account has been terminated due to serious abuse requiring the immediate preservation or deletion of data.
  1. 12.3.To the extent technically feasible and required by law, data will be made available in a structured, commonly used, and machine-readable format. The Provider will provide the information necessary to download the data and discontinue use of the Service.
  1. 12.4.The Provider does not warrant automatic migration, operation of the application with another provider, compatibility with the target environment, or the transfer of elements belonging to the Provider or third parties. Additional migration work beyond the Provider’s obligations under mandatory laws governing switching between data processing service providers may be provided for an additional charge subject to a separate agreement.
  1. 12.5.After the download period expires, the Provider will delete active User Data, except for data that it is required to retain by law or for the establishment or defense of claims, security, or billing purposes. Residual data in backups will be deleted in the ordinary overwrite cycle, as a rule within the following seven days.
  1. 12.6.The User may request deletion of the Account and User Data through a form or by email. The Provider may require identity verification and will inform the User of the irreversible consequences. Deletion of a Sandbox by the User is irreversible and may result in immediate data loss.
  1. 12.7.Billing information, invoices, security logs, and support request records may be retained after termination of the Agreement for the period required by law or the Provider’s legitimate interests.
  1. 12.8.This Section does not limit any rights of the User or obligations of the Provider under Chapter VI of Regulation (EU) 2023/2854 of the European Parliament and of the Council (Data Act), including those relating to provider switching, the transitional period, the export of data and digital assets, technical assistance, and charges associated with switching.

Section 13. Availability, Maintenance, and Support

  1. 13.1.The Provider does not warrant any percentage level of Service availability and does not provide an SLA under the basic Plan.
  1. 13.2.The Provider may perform scheduled maintenance, in particular between 2:00 a.m. and 6:00 a.m. CET/CEST. Where practicable, the Provider will give reasonable advance notice of scheduled maintenance that may materially restrict the Service.
  1. 13.3.Emergency maintenance, security updates, and actions required by a third party or competent authority may be performed without prior notice.
  1. 13.4.Support is available through the form and by email on Business Days between 9:00 a.m. and 5:00 p.m. CET/CEST. The Provider will use reasonable efforts to provide an initial response within one Business Day. This is an indicative target only.
  1. 13.5.“Unavailability” means an inability to connect to the Sandbox for reasons attributable to the Provider, despite compliance with the technical requirements and the Account remaining in good standing. Unavailability does not include, in particular: (a) scheduled or emergency maintenance; (b) any act or omission of the User or any issue with its code, application, configuration, or integration; (c) failure to meet the technical requirements or failure of the User’s internet connection, device, browser, or network; (d) a suspension imposed in accordance with these Terms; (e) failure of a Model, OpenRouter, or an AI Tool where the Sandbox itself remains available; or (f) force majeure or events beyond the Provider’s reasonable control.
  1. 13.6.The User may request an extension of the Sandbox activation period within 30 days after the end of the Billing Period in which the Unavailability occurred. For each full 24 hours of aggregate Unavailability during a Billing Period, the Provider will extend the activation period by one day. The aggregate extension may not exceed the number of days in the applicable Billing Period or the equivalent of 100% of the fixed Plan fee.
  1. 13.7.An extension is not granted automatically. The request should include the Account and Sandbox identifiers, the date and times of the incident, a description, and any available evidence.
  1. 13.8.If a request to a Model was not completed, the User should not be charged for its completion. AI Credits deducted in error will be returned following successful verification of the request.
  1. 13.9.For a Business User, the extension specified in Section 13.6 is the exclusive remedy for Unavailability itself, except in the case of damage caused intentionally. This provision does not limit the rights of a Consumer or Consumer-Protected Entrepreneur.

Section 14. Prices, Payments, and Invoices

  1. 14.1.The prices of Plans, AI Features, and additional services are specified in the Pricing and presented before the Order is placed. The total amount shown to the User immediately before confirmation of the Order is binding.
  1. 14.2.The Provider’s billing currency is USD. The payment provider may enable payment in another currency and apply its own exchange rate, fees, or currency conversion rules, for which the Provider is not responsible.
  1. 14.3.Prices for Business Users may be displayed exclusive of tax, with clear information that applicable taxes will be added. Before placing an Order, a Consumer or Consumer-Protected Entrepreneur will be shown the total price inclusive of taxes applicable on the basis of the available location and tax-status information.
  1. 14.4.The Plan fee is charged in advance for each Billing Period. The first Billing Period ends on the last day of the calendar month unless the Order specifies a different cycle. The amount payable for the first Billing Period is always stated before the Order is placed.
  1. 14.5.The subscription renews automatically for successive Billing Periods until automatic renewal is disabled. The User may disable renewal through the Dashboard at any time before the next Billing Period begins. Access remains active until the end of the paid Billing Period unless there are grounds for suspension or termination with immediate effect.
  1. 14.6.Payments are processed by Stripe or another payment provider identified during the payment process. The User may be subject to the payment provider’s terms. The Provider does not store complete card details where payment is processed directly by the payment provider.
  1. 14.7.The User authorizes the Provider and the payment provider to automatically charge the selected payment method for amounts payable for renewals and ordered additional services, in accordance with the information presented before such services are ordered.
  1. 14.8.If a payment fails, the Provider may retry the charge, restrict the AI Features, and send the User a demand for payment. The Provider may suspend the Sandbox if payment is not made within seven days after delivery of the demand and may subsequently terminate the Agreement with immediate effect. The foregoing cure period does not apply in the event of a reasonable suspicion of fraud, a chargeback, use of an unauthorized payment method, or a security threat.
  1. 14.9.A chargeback, reversal of payment, or reasonable suspicion of fraud may result in temporary suspension until verification has been completed.
  1. 14.10.Invoices and billing documents are issued electronically using the information provided by the User. The User is responsible for ensuring that such information is accurate and up to date.
  1. 14.11.Discounts, coupons, free periods, and promotions are subject to the terms specified when they are granted and may not be exchanged for cash.

Section 15. AI Credits and Usage Measurement

  1. 15.1.AI Credits are the Provider’s internal service units. They are not electronic money, a payment instrument, a deposit, or a means of storing value.
  1. 15.2.AI Credits may not be transferred between Accounts or exchanged for cash during the term of the Agreement, except for refunds provided for in these Terms or required by law.
  1. 15.3.Unless otherwise specified in the Pricing, paid AI Credits are valid for 12 months from the date of purchase. AI Credits with the shortest remaining validity period are used first. Promotional AI Credits may have a shorter validity period.
  1. 15.4.The cost of using AI Features is determined on the basis of the then-current rate applicable to the Model and type of use, including input, output, cache, reasoning, tool calls, or other units applied by the Model provider. The rates are available in the Pricing or interface before use.
  1. 15.5.Billing is based on measurement data from the Provider’s systems, taking into account data received from OpenRouter or the Model provider. If an error is confirmed, the Provider will make an appropriate adjustment.
  1. 15.6.A Business User may dispute a measurement within 30 days after the usage statement is made available. After that period, the data will be deemed accepted, except in the case of an error that could not have been detected through the exercise of due care. This period does not limit the rights of Consumers or Consumer-Protected Entrepreneurs under applicable law.
  1. 15.7.Following termination of the Agreement, the User may request a refund of the value of unused AI Credits acquired for consideration. The refund will correspond to the portion of the price actually paid for the unused AI Credits, taking into account any discounts. Promotional AI Credits expire without a refund. The Provider may set off any amounts then due from the User.
  1. 15.8.Refunds to a Consumer or Consumer-Protected Entrepreneur are made subject to mandatory law, including the rules governing withdrawal from the Agreement and liability for conformity of the Service with the Agreement.

Section 16. Suspension and Termination of the Agreement

  1. 16.1.Except where these Terms or applicable law give the User a right to terminate the Agreement earlier, the User may terminate the Agreement by disabling automatic renewal. The Agreement will then terminate at the end of the paid Billing Period.
  1. 16.2.In relation to a Consumer or Consumer-Protected Entrepreneur, the Provider may terminate the Agreement for good cause, effective at the end of the Billing Period, on 14 days’ prior notice, including where the Provider discontinues the Service or a particular Plan, a material technological change prevents continued provision of the Service, the Provider loses a key supplier, the law changes, or a permanent risk to the security of the Service arises. The notice will state the reason and the termination date and will be provided on a durable medium. In relation to a Business User, the Provider may terminate the Agreement at any time without stating a reason, effective at the end of the Billing Period, on 14 days’ notice.
  1. 16.3.The Provider may suspend all or part of the Service with immediate effect if: (a) the User commits a material or repeated breach of these Terms, applicable law, third-party rights, or binding third-party terms and suspension is necessary to mitigate the consequences of the breach; (b) a payment is overdue or reversed or gives rise to a reasonable suspicion of fraud; (c) use of the Service threatens security, stability, other users, or infrastructure; (d) the Account or Sandbox is used for unlawful content or any activity specified in Section 10; (e) suspension is required by an authority’s order, sanctions, export controls, or a legal obligation; or (f) suspension is necessary to address an incident, data exfiltration, use of stolen authentication credentials, or other abuse.
  1. 16.4.If a breach is capable of remedy and immediate action is not required due to security considerations, unlawful use of the Service, a risk of material harm, fraud, or a legal obligation, the Provider will, before terminating the Agreement, require the User to remedy the breach within a period appropriate to its nature, which will not be shorter than seven days. Failure to remedy the breach within that period entitles the Provider to suspend the Service or terminate the Agreement with immediate effect.
  1. 16.5.The Agreement may be terminated with immediate effect in the event of a material breach, repeated breaches, unlawful use, a security threat, failure to make payment in accordance with Section 14.8, or the provision of false information, subject to Section 16.4.
  1. 16.6.Depending on the nature of the risk, a suspension may be limited to a particular feature, Model, public URL, Sandbox, or the entire Account. The Provider will apply a measure proportionate to the nature and scale of the risk unless applicable law, an authority’s decision, or security considerations require a broader measure.
  1. 16.7.Following termination of the Agreement, public URLs and features will cease to operate, and User Data will be handled in accordance with Section 12. Reactivation is possible only before active data has been deleted and after all outstanding amounts have been paid. The Provider will inform the User of the termination date, the deadline for downloading User Data and, where applicable, the deadline for requesting a refund of unused AI Credits.
  1. 16.8.Termination of the Agreement does not affect rights and obligations that arose before its termination. Provisions that, by their purpose or nature, are intended to survive termination will remain in effect, including those concerning settlements, intellectual property rights, confidentiality, liability, and disputes.

Section 17. Liability

  1. 17.1.The Provider is liable for failure to perform or improper performance of the Agreement in accordance with applicable law, subject to the modifications permitted in relation to Business Users and specified below.
  1. 17.2.The Provider is responsible for organizing and maintaining the elements of the Service under its control. The Provider does not warrant the uninterrupted operation of third parties, Models, OpenRouter, the payment provider, GitHub, Let’s Encrypt, the public network, or other services on which the Service relies.
  1. 17.3.The User is responsible for User Data, its own code, applications and configurations, the logical security of its applications, legal compliance, testing of AI output, production deployment, and the consequences of decisions made on the basis of output.
  1. 17.4.In relation to a Business User, the Provider is not liable for loss of profits, revenue, contracts, reputation, savings, data falling outside the scope of backups, indirect loss, or the consequences of using a Sandbox as a production or high-risk environment.
  1. 17.5.The Provider’s aggregate liability to a Business User arising out of all events connected with the Agreement will not exceed the total fixed Plan fees paid by the User during the three months immediately preceding the event giving rise to liability or, if the Agreement has been in effect for a shorter period, the total fees paid during its term. Fees paid for AI Credits will be included only to the extent that the claim directly concerns their incorrect billing.
  1. 17.6.The limitations in Sections 17.4 and 17.5 do not apply to damage caused intentionally or to liability that cannot be excluded or limited under mandatory law.
  1. 17.7.A Business User is liable to the Provider under generally applicable law for damage and reasonable costs associated with third-party claims arising from unlawful User Data, infringement of third-party rights, use inconsistent with Section 10, or the acts of persons to whom the Business User has provided access to the Account.
  1. 17.8.Nothing in these Terms will be interpreted as limiting any rights of a Consumer or Consumer-Protected Entrepreneur under mandatory law.

Section 18. Personal Data, Security, and Confidentiality

  1. 18.1.The Provider is the controller of personal data processed in connection with Account registration, the conclusion and performance of the Agreement, payments, invoices, Support, security, communications, and the establishment, exercise, or defense of claims. Further information is provided in the Privacy Policy available on the Site.
  1. 18.2.If the Provider processes personal data contained in User Data on the User’s behalf, the DPA made available on the Site applies. The User must not commence such processing unless it has an appropriate legal basis and complies with its obligations as a controller or processor.
  1. 18.3.Data in an active Sandbox is generally stored in Germany. Messaging services may be provided by Resend using a region located in Ireland. Payments are processed by Stripe. Data submitted through AI Features may be processed by OpenRouter and Model providers outside the EEA.
  1. 18.4.The then-current list of processors, the rules governing changes to that list, and the applicable transfer mechanisms are specified in the Privacy Policy or DPA. For transfers subject to the GDPR, the Provider applies the required legal grounds and safeguards to the extent that it is responsible for the relevant transfer.
  1. 18.5.The Provider applies technical and organizational measures appropriate to the nature of the Service, including logical separation of environments, personnel access controls, protection of integration keys, administrative logs, encryption in transit, abuse monitoring, and incident response procedures.
  1. 18.6.Unless expressly stated otherwise in the Specification, the Provider does not warrant encryption at rest of all active Sandbox data. The User should not store in a Sandbox any data that requires such a measure or a particular level of security.
  1. 18.7.The Provider’s personnel may access a Sandbox or User Data only to the extent necessary for Support, security, performance of the User’s instructions, billing, or compliance with a legal obligation, on a need-to-know basis and in accordance with the applicable authorization mechanisms.
  1. 18.8.The Provider will notify the User of a personal data breach affecting personal data processed on the User’s behalf without undue delay, in accordance with the DPA.
  1. 18.9.In the relationship with a Business User, each party must keep confidential the other party’s non-public information that is designated as confidential or is confidential by its nature. This obligation does not apply to information that is public, was known to the recipient without breach of an obligation, was lawfully obtained from a third party, or was independently developed. Disclosure required by law is permitted to the extent necessary. The obligation continues for five years following termination of the Agreement and, in relation to trade secrets, for as long as they remain legally protected.
  1. 18.10.Information submitted to Models should not be treated as confidential as against Model providers. The User must comply with the restrictions specified in Section 8.6.

Section 19. Changes to the Service, Pricing, and Terms

  1. 19.1.The Provider may change the features, Specification, a Model, an AI Tool, the infrastructure provider, a subprocessor, or these Terms for a justified reason, including: (a) a change in law, an authority’s decision, or a regulatory interpretation; (b) improvements to security, stability, performance, or protection against abuse; (c) development of functionality, a change in technology, or withdrawal of unsupported elements; (d) a change, withdrawal, or restriction of a third-party service; (e) a change in the cost of infrastructure, Models, taxes, exchange rates, or payment providers; or (f) the need to clarify provisions, correct errors, or improve transparency without adversely affecting the User. In relation to a Consumer or Consumer-Protected Entrepreneur, the reason for the change must fall within paragraphs (a) through (f), be directly related to the scope of the change, and the change may be made only to the extent necessary and proportionate to that reason. The change must not alter the essential nature of the Service.
  1. 19.2.A change to the fixed Plan fee may apply to the User from the first Billing Period beginning at least 14 days after the User is notified of the change. The User may disable automatic renewal before that Billing Period begins, in which case the new price will not apply to the User. Notice of a price change will be sent to the email address assigned to the Account and, in the case of a Consumer or Consumer-Protected Entrepreneur, on a durable medium.
  1. 19.3.Changes to Model rates or AI Credit consumption may result from the then-current rates charged by third parties and may take effect when published through the interface. They do not affect the nominal AI Credit balance but may affect the amount of usage that can be covered by that balance. New rates apply to AI Credits purchased after they are published. In relation to paid AI Credits remaining on the balance, a change may apply no earlier than 30 days after notice is given to the User, subject to the option of obtaining an earlier refund of their unused value.
  1. 19.4.A material change to these Terms or the Service will be communicated to the User at least 14 days before it takes effect, by email or through the Dashboard and, in relation to a Consumer or Consumer-Protected Entrepreneur, on a durable medium. A change may take effect without the ordinary notice period only to the extent objectively necessary to comply with a mandatory provision of law or a decision of a competent authority or to eliminate an immediate threat to the security of the Service, Users, or their data. The Provider will communicate such a change without undue delay.
  1. 19.5.In relation to a Consumer or Consumer-Protected Entrepreneur, a change to a digital service during a period of continuous supply may be made without additional charge only for a valid reason specified in the Agreement. If a change materially and adversely affects the Consumer’s or Consumer-Protected Entrepreneur’s access to or use of the Service, the Provider will give appropriate advance notice on a durable medium of the features and timing of the change and of the right to terminate the Agreement without notice within 30 days after the change is made or the information concerning the change is received, whichever is later. This right does not apply if the Provider enables the User to retain the Service in conformity with the Agreement, unchanged and without additional charge.
  1. 19.6.The version history of these Terms is made available on the Site. If the User does not accept a change affecting the Agreement then in effect, the User may terminate the Agreement before the change takes effect. A change will bind the User from its effective date if it was introduced and communicated in accordance with these Terms and applicable law.

Section 20. Complaints

  1. 20.1.Complaints concerning the Service, payments, measurement of AI Feature usage, backups, suspension, or other elements of the Agreement may be submitted to info@openmercato.com or through the form available on the Site.
  1. 20.2.A complaint should contain information enabling identification of the User, the Account and Sandbox identifiers, a description of the issue, the date and time of the event, the requested remedy, and any available evidence. Failure to provide this information does not deprive a Consumer of any rights but may delay investigation of the matter.
  1. 20.3.The Provider may request technical information necessary for diagnosis, subject to the data-minimization principle and the prohibition against submitting passwords or credentials.
  1. 20.4.A complaint submitted by a Consumer or Consumer-Protected Entrepreneur will be considered within 14 days after receipt unless a specific provision of law provides otherwise. As a rule, a complaint submitted by a Business User will be considered within 30 days.
  1. 20.5.A Business User must submit complaints concerning the measurement of AI Feature usage and requests for an extension due to Unavailability within the periods specified in Sections 15.6 and 13.6, respectively. These periods do not limit the statutory rights of a Consumer or Consumer-Protected Entrepreneur.
  1. 20.6.The response will be sent to the email address assigned to the Account or to another address specified in the complaint.
  1. 20.7.If a Consumer’s complaint is not upheld, the Consumer may seek assistance from a municipal or county consumer ombudsman, a consumer organization, the European Consumer Centre in a cross-border dispute, or a competent alternative dispute resolution entity. The Provider will state whether it is willing or refuses to participate in a particular ADR procedure, as required by law.

Section 21. Specific Rights of Consumers and Consumer-Protected Entrepreneurs

  1. 21.1.This Section applies to Consumers and, to the extent provided by law, Consumer-Protected Entrepreneurs.

Right of Withdrawal

  1. 21.2.A User who has entered into the Agreement at a distance may withdraw from it within 14 days after its conclusion without stating a reason, subject to the exceptions provided by law.
  1. 21.3.During the Order process, the User may choose: (a) for provision of the Service to begin after 14 days from conclusion of the Agreement; or (b) for provision of the Service to begin before that period expires, following the User’s express request.
  1. 21.4.If the User requests that provision begin before the withdrawal period expires and subsequently withdraws from the Agreement, the User must pay an amount proportionate to the services provided up to the time of withdrawal. The mere creation of or logging into a Sandbox does not automatically result in loss of the right of withdrawal. That right may expire only after full performance of a paid service, provided that the statutory requirements concerning express prior consent, appropriate information, and acknowledgment of the loss of the right have been satisfied.
  1. 21.5.A notice of withdrawal may be submitted to info@openmercato.com or sent by mail to the Provider’s address. The form attached as Appendix 1 may be used but is not mandatory.
  1. 21.6.The Provider will refund all amounts due without undue delay and no later than 14 days after receiving the notice of withdrawal, using the same payment method unless the User agrees to a different method that does not result in additional costs. The Provider may deduct the amount payable for services provided at the User’s express request before withdrawal.

Conformity of the Digital Service with the Agreement

  1. 21.7.The Provider will supply the Service without undue delay after conclusion of the Agreement or at the time agreed in the Order and is responsible for its conformity with the Agreement throughout the period of continuous supply.
  1. 21.8.The Service conforms with the Agreement if it corresponds to the description, type, quantity, quality, completeness, functionality, compatibility, interoperability, support, and updates resulting from the Order, these Terms, the Pricing, and the Specification and is suitable for any particular purpose accepted by the Provider.
  1. 21.9.In the event of a lack of conformity, the User may require the Service to be brought into conformity. The Provider will do so within a reasonable time and without undue inconvenience unless doing so is impossible or would require excessive costs.
  1. 21.10.The User may make a statement reducing the price or withdrawing from the Agreement in the circumstances specified in the Polish Consumer Rights Act, including where bringing the Service into conformity is impossible, has not occurred within a reasonable time, the lack of conformity continues, or the lack of conformity is sufficiently serious to justify the immediate exercise of such a remedy.
  1. 21.11.Service credits, liability caps, and other contractual remedies do not exclude or limit statutory rights arising from a lack of conformity of the Service with the Agreement.
  1. 21.12.The Provider will provide updates necessary to maintain the Service’s conformity with the Agreement during the period in which it is supplied. The User should cooperate in installing or applying updates relating to its own environment, provided that the User has been properly informed of them.

Section 22. Governing Law, Communications, and Miscellaneous

  1. 22.1.The Agreement is governed by Polish law. This choice of law does not deprive a Consumer of the protection granted by mandatory provisions of the country of the Consumer’s habitual residence where the applicable conflict-of-laws rules provide for such protection.
  1. 22.2.Disputes with a Business User are subject to the exclusive jurisdiction of the court of general jurisdiction having venue over the Provider’s registered office. Jurisdiction in disputes with a Consumer or Consumer-Protected Entrepreneur is determined by generally applicable law.
  1. 22.3.Communications concerning the Agreement will be conducted through the Dashboard and the email address assigned to the Account. The User must keep its email address up to date and regularly check its messages. Information required to be provided on a durable medium will be sent in a manner that enables it to be retained and reproduced.
  1. 22.4.Without further consent, the Provider may transfer its rights and obligations under the Agreement to a legal successor or an entity taking over the Service. A Business User may not transfer the Agreement without the Provider’s prior consent.
  1. 22.5.If any provision of these Terms is invalid or ineffective, the remaining provisions will remain in effect, and the invalid provision will be replaced by the applicable provision of law or a solution that most closely reflects its lawful purpose.
  1. 22.6.These Terms have been drawn up in English. Translations may be made available for informational purposes. In relation to a Business User, the English-language version will prevail unless otherwise specified in the Order.

Appendix 1: Model Withdrawal Form

(Complete and return this form only if you wish to withdraw from the Agreement.)

To: Open Mercato sp. z o.o. ul. Wyspa Słodowa 7, 50-266 Wrocław

Email: info@openmercato.com

I/We hereby give notice that I/we withdraw from the Agreement for the provision of the Open Mercato Sandboxes Service.

Date of conclusion of the Agreement:

....................................................................................................................

User’s name / business name:

....................................................................................................................

User’s address:

....................................................................................................................

Email address assigned to the Account:

....................................................................................................................

Date:

....................................................................................................................

User’s signature (only if this form is submitted on paper):

....................................................................................................................