Logo Logo
  • HOME
  • CONTACT US
  • EN
  • /
  • PL
  • /
  • UA
LOG IN

Terms of Service

Last Updated: August 21, 2026

INTRODUCTION

These Terms of Service (“Terms”) constitute a binding agreement between NANNOS sp. z o.o. (“the Company”, “we”, “us”, or “our”) and the individual or entity accessing or using the Intsurfing API Platform, API-based services, API endpoints, documentation, account tools, or related service pages that link to these Terms (“you” or “the User”). The Services are offered through the Intsurfing API Platform. NANNOS sp. z o.o. is the contractual provider and billing entity for the Services. The Company may engage technology, infrastructure, payment, and support providers to operate parts of the Services.

By creating an Account, activating a Service, generating or using an API Key, submitting requests to our endpoints, or otherwise using the Services, you acknowledge that you have read, understood, and agreed to be bound by these Terms.

The Services provide structured technical access to publicly available datasets sourced from official or authoritative sources, as well as non-data technical processing functionalities. We act solely as an infrastructure provider: we standardize, normalize, and deliver publicly accessible datasets through secure API interfaces designed for compliant, professional, and legitimate business use. We do not create, verify, or alter the underlying content of any public record.

These Terms describe the conditions under which you may access and use the Services, the responsibilities associated with their use, authentication and billing rules, and the legal framework applicable to the Services. If you accept these Terms on behalf of a business or organization, you represent that you have authority to bind that entity.

If you do not agree with these Terms, you must discontinue all use of the Services and refrain from accessing any API Keys. Continued use of the Dashboard or the submission of API calls constitutes acceptance of the current version of these Terms and any subsequent modifications.

DEFINITIONS

For the purposes of these Terms of Service, the following terms shall have the meanings set out below. Definitions apply to both the singular and plural and are intended to ensure clarity in technical, legal, and billing matters associated with the use of the Services.

  1. “Company”, “we”, “us”, or “our” means NANNOS sp. z o.o., a company registered in Poland, which provides and bills the Services offered through the Intsurfing API Platform.
  2. “Services” means the suite of API endpoints, technical infrastructure, data-access functionality, and technical processing services made available through the Intsurfing API Platform, including parsing, normalization, enrichment, validation, transformation, and access to publicly available datasets.
  3. “User”, “Client”, or “you” means any natural or legal person who creates an account, accepts these Terms of Service, obtains an API Key, and accesses or uses the Services in any capacity.
  4. “Dashboard” or “Intsurfing API Platform” means the secure web-based interface through which the User manages Account settings, payment methods, Services, API Keys, usage information, and invoices.
  5. “Account” means the User’s registered account on the Intsurfing API Platform through which the User accesses and administers the Services.
  6. “API Key” means the unique authentication credential issued to the User for accessing the Services. An API Key is considered confidential information and functions as the technical and legal identifier of the User within the system. Each request submitted using an API Key is deemed to be made by the User to whom that key is assigned.
  7. “Pay-As-You-Go Model” means a usage-based billing structure under which charges accrue only for executed API calls. The calculation of fees is tied to the number of successful requests and applies regardless of the number of records returned in the response.
  8. “Payment Processor” means a third-party payment service provider authorized by the Company to verify payment methods, process payments, perform authentication or fraud-prevention procedures, and settle payments relating to the Services. The Company may use one or more Payment Processors and may change them from time to time.
  9. “Data” means information accessed, processed, or delivered through the Services that originates from publicly available sources, including but not limited to governmental, administrative, regulatory, or other lawfully published public information, which may include justice, civil, administrative, or other public records, depending on the specific API.
  10. “Effective Date” means the date on which the current version of these Terms of Service becomes operative. Each version is assigned a unique timestamp for audit and compliance tracking.
  11. “Documentation” means technical materials describing the Services, including API schemas, endpoint descriptions, limits, examples, and integration guidance published for the Intsurfing API Services.
  12. “Confidential Information” means any non-public information disclosed by one party to the other in connection with the Services, including API Keys, billing information, usage patterns, or internal system behavior. Publicly available Data retrieved through the API does not constitute Confidential Information.
  13. “Applicable Law” means laws, regulations, and binding legal requirements applicable to the Company, the User, the Services, the Data, or the User’s use of the Services.

DESCRIPTION OF THE SERVICES

  1. Scope of the Services. The Company grants the User a limited, revocable, non-exclusive, and non-transferable right to access and use the Services via API interfaces for lawful business purposes.

    The Services may include both (a) access to publicly available datasets sourced from official or authoritative sources, and (b) non-data technical processing functionalities, such as parsing, normalization, enrichment, validation, transformation, and other data-processing or analytical services.

    The specific scope, functionality, data categories, and technical characteristics of each Service or API endpoint are described in the applicable Documentation and may vary depending on the Service used.

  2. Nature of Public Data. The Services provide technical access to information that is lawfully published and made publicly available by competent authorities or other lawful public sources. The specific type, jurisdiction, and scope of Data may vary depending on the API and applicable Documentation.

  3. No Transfer of Intellectual Property. All rights, title, and interest in the Services, including the APIs, Intsurfing API Platform, underlying software, Documentation, and related intellectual property, remain with the Company and/or its licensors and technology providers, as applicable. Access to Data does not grant the User ownership of the underlying Data or any intellectual-property rights in the Services.

  4. Permitted Use. The Services may be used solely for lawful, legitimate business purposes consistent with the nature of public records. All use of the Services is further governed by the Acceptable Use Policy outlined in Section 6, which forms an integral part of these Terms.

  5. Prohibited Use. The User must not rely on the Services for any purpose regulated under the Fair Credit Reporting Act (FCRA) or for decisions relating to employment, housing, insurance, credit, government benefits, or any other regulated sector. The Services must not be used to generate, contribute to, or support any regulated “consumer report.”

  6. Commercial Model. The Services are provided on a Pay-As-You-Go basis. There are no subscription fees unless expressly stated otherwise for a particular Service. Charges are based on actual API usage and the applicable pricing for each Service. A valid default payment method must be maintained where required for access to paid Services and settlement of accrued usage.

  7. Modification of the Services. The Company may modify, enhance, limit, or discontinue any component of the Services to maintain operational stability, comply with legal requirements, or improve functionality. Such changes do not constitute a breach of these Terms.

  8. No Relationship with Data Subjects. Individuals whose information appears in public records accessed through the Services are not users of the Services and have no contractual, legal, fiduciary, or other relationship with the Company. The Company owes no duty of care, obligation, or responsibility to such individuals arising from the availability, processing, or delivery of public record information.

  9. No Professional or Investigative Services. The Services do not constitute professional due diligence, investigative, verification, screening, or background-check services of any kind. The Company does not validate identities, confirm factual accuracy, or provide conclusions, recommendations, or assessments regarding any individual, record, or dataset.

ACCOUNT REGISTRATION AND MANAGEMENT

  1. Account Creation and Profile Information. To access the Services, the User must create an Account through the Intsurfing API Platform and provide accurate, complete, and current information. The email address provided during registration is the primary identifier of the Account and cannot be changed after registration. To use payment functionality and activate paid Services, the User must complete the required profile information, including full name, phone number, billing address, and country. The User represents that all information provided through the Account is accurate and lawful.

  2. Responsibility for Credentials and Account Security. The User is responsible for protecting login credentials, API Keys, and any authentication methods associated with the Account. The Platform may offer multi-factor authentication (“MFA”) as an additional security measure. If enabled, the User is responsible for maintaining access to the authentication method used for MFA. Any activity performed through the User’s Account or API Key may be treated as activity of the User unless the Company has been notified of unauthorized access.

  3. Updating Account Information and Password. The User may update profile information made editable through the Platform. The registered email address cannot be changed. To change a password, the User must request a verification code sent to the registered email address, enter the code, and create a new password. A new password must be different from the current password.

  4. Payment Profile Requirements. The User must complete the required profile information before adding a payment method. Missing or outdated required information may prevent the User from adding or verifying a payment method until the profile is updated.

  5. API Key Issuance and Lifecycle. Each API available through the Platform is managed as a separate Service. When the User activates a Service, the Platform generates an API Key for that Service. Each active Service may have one active API Key per Account unless otherwise stated in the Documentation.

    Deactivating a Service prevents future requests through the associated API Key but does not cancel charges for usage incurred before deactivation. A deactivated API Key and its usage information may remain visible in the Platform until the associated usage has been invoiced and successfully paid. After payment is completed, the deactivated key may be removed from the Platform.

  6. Restrictions on Sharing and Disclosure. An API Key is issued for the User’s exclusive use. The User must not: share, sublicense, resell, or transfer any API Key; embed an API Key in client-side or publicly accessible code; expose an API Key through repositories, logs, screenshot uploads, support tickets, or third-party systems.

    Any detection of API Key sharing, exposure, or unauthorized use may result in immediate suspension under Section 4.7, without liability to the User.

  7. Local Security Obligations. The User must implement reasonable and industry-standard security measures to protect their development, staging, and production environments, including but not limited to: secure storage of API Keys, restricted developer access, encrypted configuration vaults, version-control hygiene, and timely rotation of compromised credentials.

    The User must notify the Company immediately if they suspect unauthorized access, misuse of their credentials, or compromise of their API Key.

  8. Account Suspension and Reinstatement. The Company may suspend Account access, without prior notice, if: an API Key is compromised or suspected of compromise; the User engages in activity violating these Terms or Applicable Law; suspicious or abusive request patterns are detected; the User fails to maintain a valid payment method; required communications are unanswered or administrative issues remain unresolved.

    Reinstatement of the Account is at the sole discretion of the Company and may require additional verification, updated credentials, or satisfaction of outstanding billing obligations.

ACCESS TO API SERVICES

  1. Authentication Requirements. Access to the Services requires a valid, active API Key. Each API request must include the API Key in the designated authentication header. Requests submitted without proper authentication, with expired or revoked API Keys, or via deprecated methods will be rejected. The User is responsible for ensuring that API Keys are securely integrated and not exposed in client-side environments, public repositories, shared logs, or unsecured configurations.

  2. Technical Limits and Rate Controls. Technical limits, including request rates, record limits, response characteristics, and other operational parameters, may vary by Service and are described in the applicable Documentation.

    The Company may establish or modify technical limits where necessary to maintain platform stability, protect the Services, prevent abuse, or comply with operational or legal requirements.

  3. Availability and Operational Stability. The Services are provided on an “as-available” basis. While the Company implements robust infrastructure, redundancy, and monitoring, uninterrupted availability is not guaranteed. Temporary delays, interruptions, throttling, or maintenance windows may occur due to infrastructure updates, system load, public-record source changes, cloud service disruptions, or other external factors.

    The Company may temporarily throttle or delay request processing to preserve overall system stability.

  4. API Key Regeneration, Revocation, and Expiry. The User may regenerate their API Key at any time via the Dashboard. Regeneration immediately invalidates all previous keys. The Company may revoke or invalidate an API Key, in whole or in part, if: suspicious activity is detected; abuse or misuse is identified; security risks or anomalies arise; the User fails to comply with these Terms or Applicable Law; or access must be restricted for operational or legal reasons. Revocation may occur without prior notice.

  5. Geographic, Regulatory, and Legal Restrictions. The Company may restrict or deny access to the Services from jurisdictions where the retrieval, use, or dissemination of publicly available data or technical processing services is limited, prohibited, or inconsistent with Applicable Law.

    Where specific datasets or API endpoints are subject to additional legal or regulatory requirements (including, where applicable, rules governing the dissemination of certain categories of public-record information), the Company may impose additional access restrictions to ensure compliance with such requirements.

    The User is solely responsible for ensuring that their use of the Services is lawful in their applicable jurisdiction.

  6. Automated Monitoring and Abuse Detection. The Company utilizes automated and manual monitoring to detect abnormal request patterns, high-volume enumeration, scraping activity, data harvesting, unusual concurrency, rotating tokens, or any behavior inconsistent with legitimate use. Detection of such activity may trigger rate limiting, throttling, API Key revocation, or account suspension as described in Section 3.8.

  7. Temporary Suspension for Security or System Protection. The Company may temporarily suspend, restrict, or limit access to the Services if necessary to: protect system security or infrastructure; respond to suspected or actual misuse; comply with legal requests or obligations; prevent degradation of service for other Users; respond to inconsistencies or changes in upstream public-record sources.

    Such suspension may occur immediately, without prior notice, and without liability to the User.

BILLING AND PAYMENTS

  1. Billing Model. The Services operate on a Pay-As-You-Go billing model. There is no recurring subscription fee unless expressly stated otherwise for a particular Service. Charges apply to billable API requests successfully processed by the Services. A request is considered successfully processed when the Service accepts the request, processes it, and returns a response without a system error. Requests that fail due to a system error are not charged. Usage is tracked separately for each Service, while charges for multiple Services may be combined into one billing event and invoice.

  2. Free Request Allowance. Certain Services may include a number of free requests during each billing period, as described in the applicable pricing or Documentation. Free request allowances reset at the beginning of each billing period and do not constitute a trial or subscription. Requests exceeding the applicable free allowance are charged according to the pricing model for the relevant Service.

  3. Payment Processing. Payments for the Services are processed through third-party Payment Processors. The Company does not receive or store full payment-card details. Sensitive payment information is handled by the applicable Payment Processor according to its own terms, security standards, and regulatory requirements. Payment verification and processing may involve additional authentication or fraud-prevention procedures, including 3D Secure, issuer approval, verification transactions, and other checks required by the Payment Processor or the User’s bank. The Company is not responsible for payment restrictions, declines, verification requirements, or delays imposed by the User’s bank, card issuer, or Payment Processor.

  4. Payment Methods and Verification. The User must maintain a valid default payment method where required for paid Services. The payment methods available to a User are those displayed through the Platform and supported by the applicable Payment Processor. Available payment methods may vary by country, currency, account configuration, or Payment Processor requirements. Where the Platform permits multiple payment cards to be stored, the User must designate one as the default payment method used for billing. At least one valid payment method must remain associated with the Account while amounts for previously incurred API usage remain payable.

  5. Billing Cycle and Automatic Charges. API usage is calculated on a monthly basis. Charges for usage incurred during a billing period are normally processed during the first days of the following month. For example, usage incurred during a calendar month may be charged at the beginning of the next calendar month. Deactivating a Service during a billing period stops future usage through that Service but does not cancel charges for requests already made before deactivation. The User authorizes NANNOS sp. z o.o. to charge the User’s default payment method automatically for payable API usage without requiring separate approval for each monthly usage charge.

  6. Invoices and Records. The Dashboard maintains a complete and immutable archive of all invoices generated in connection with the Services. Invoices include usage metrics, applicable charges, total amounts due or paid, and timestamps of billing events.

    Invoices cannot be retroactively edited, modified, or deleted.

  7. Taxes and Bank Fees. The User is responsible for all applicable taxes, duties, levies, currency conversion fees, and bank charges associated with their payment method.

    The Company does not reimburse bank commissions, exchange-rate differences, or fees imposed by financial institutions.

  8. Billing Disputes. The User must report any billing-related issues within seven (7) calendar days of invoice issuance. Failure to dispute within this period constitutes irrevocable acceptance of the invoice.

    A billing dispute does not suspend the User’s obligation to pay undisputed amounts.

  9. Refunds. Refunds are issued only where the Company determines, in its sole discretion, that a charge resulted from a verified and reproducible service malfunction attributable to the Company. Refunds are not provided for: User errors; integration mistakes; invalid or malformed requests; downtime caused by third parties; periods of throttling or rate limiting; or changes in public-record availability or content.

    Refunds are issued only where the Company determines, in its sole discretion, that a charge resulted from a verified and reproducible service malfunction attributable to the Company. Refund decisions are final and non-negotiable.

  10. Non-Payment and Collection. If a payment attempt fails, the Company may: retry the payment method, request an updated card, suspend API access, or terminate the Account.

    If outstanding amounts remain unpaid, the Company reserves the right to engage collection procedures or legal action. The User shall be liable for all associated costs, fees, and expenses, including attorneys’ fees.

ACCEPTABLE USE POLICY

The User must use the Services responsibly, ethically, and strictly in accordance with Applicable Law. This Acceptable Use Policy (“AUP”) forms an integral part of these Terms and applies to all access to, and use of, the Services.

  1. General Principles. The Services provide access to publicly available data and technical processing functionalities for legitimate and lawful business purposes only.

    The User must not misuse the Services, interfere with or disrupt the Company’s systems, violate Applicable Law, applicable data dissemination rules, or use the Services in any manner contrary to these Terms.

    The User is solely responsible for the legality of their downstream use of the Services and any data or outputs obtained through the Services.

  2. Prohibited Uses. The User must not use the Services, Data, Dashboard, or any API Key for any of the following:

    1. Fair Credit Reporting Act (FCRA) Uses. The Services may not be used to create, contribute to, or support: employment eligibility decisions, tenant screening, creditworthiness assessments, insurance underwriting, government benefit determinations, or any regulated “consumer report.” Any FCRA-related use is strictly prohibited.

    2. Harassment, Discrimination, or Abuse. The User must not use the Data to: harass, intimidate, threaten, or target any individual; discriminate based on race, nationality, religion, gender, disability, or any protected class; shame, stalk, or expose individuals for personal, political, or ideological purposes.

    3. Commercial Republishing or Data Harvesting. The User must not: resell, redistribute, publish, or repackage the Data; build competing services or datasets using the Data; use the API for bulk extraction, scraping, or enumerating entire jurisdictions; create derivative datasets intended for resale or redistribution. Public records accessed through the Services cannot be republished in bulk or commercialized.

    4. Security Violations and Technical Misuse. The User must not: share, expose, or embed API Keys in public repositories; rotate accounts or tokens to bypass technical limits; simulate or spoof traffic, identities, or systems; interfere with rate limits or circumvent API restrictions; use bots, traffic generators, or distributed infrastructure to overload endpoints; attempt to access systems or data outside the permitted scope.

    5. Unlawful or Unauthorized Purposes. The User must not use the Services for: unauthorized surveillance, social-media doxxing, law-enforcement impersonation, hacking or cyber operations, extracting private or sealed data, any breach of Applicable Law.

  3. Permitted Uses. The Services may be used for: internal analytics and research; risk mapping, modeling, and data enrichment; compliance workflows not regulated under FCRA; due diligence workflows that rely solely on public records; software integrations for lawful business operations; generating internal insights based on publicly available information.

    Permitted uses do not override any prohibition listed in this Section.

  4. State-Level Dissemination Restrictions. The User acknowledges that U.S. states may impose differing legal rules governing how publicly available records may be accessed, displayed, redistributed, updated, or removed, including variations in update frequency, retention periods, redaction requirements, and expungement or sealing rules.

    Where applicable, such restrictions may also apply to specific categories of criminal-justice-related public information. The User must comply with all state-level dissemination rules relevant to their use of the Data.

    The Company may restrict, modify, or limit access to certain Services or data categories as necessary to comply with applicable state requirements.

  5. Security Responsibilities. The User must implement industry-standard technical safeguards to protect their systems, including: secure storage of API Keys; prevention of unauthorized access; encryption of sensitive environments; prompt rotation of compromised credentials; monitoring and logging of internal API usage.

    The User is solely responsible for the cybersecurity of any system that sends requests to the Company’s API.

  6. Enforcement and Consequences. The Company may take any of the following actions, at its sole discretion, upon detecting or suspecting a violation of this AUP: immediate suspension of API access, revocation of API Keys, temporary or permanent account termination, reporting unlawful activity to relevant authorities, preservation or disclosure of logs for investigation or legal compliance.

    Suspension or termination under this Section may occur immediately and without liability to the User.

  7. The Services are not available to individuals, residents, citizens, entities, or organizations located in, incorporated in, or operating under the laws of the Russian Federation or the Republic of Belarus. The Company may suspend or terminate access immediately upon detecting a violation of this restriction.

DATA ORIGINS AND LEGAL BASIS

  1. Public Record Sources Only. The Data accessible through the Services originates exclusively from publicly available sources that are lawfully published and accessible under applicable law. The Services may aggregate, process, or structure public information from different jurisdictions and subject matters, depending on the specific API and the applicable Documentation.

    Such sources may including, by way of example and without limitation, publicly available governmental or administrative publications, such as state or federal registries, court records, regulatory notices, and other public records made available by competent authorities for public access, including, where applicable, certain categories of criminal-justice-related public information.

    The Company does not obtain, purchase, license, collect, or scrape any non-public, sealed, restricted, proprietary, or commercially confidential databases.

  2. No Private, Sealed, or Restricted Data. The Company does not access private, paid, sealed, restricted, or non-public databases, including law-enforcement back-office systems, systems requiring warrants, subpoenas, or exceptional credentials, or commercial datasets that aggregate non-public information.

    The Services are strictly limited to information already released to the general public by competent authorities.

  3. Nature, Variability, and Accuracy of Public Records. Nature, Variability, and Accuracy of Public Records. Public records, including publicly available datasets released by governmental or administrative authorities, inherently vary by jurisdiction, source, and agency in completeness, scope, update frequency, accuracy, formatting, structure, and availability.

    The Company does not modify the substance of any record. Any formatting, normalization, or structuring performed by the Company is technical and does not alter the legal meaning of the underlying information. The Data is provided strictly “as-is” and “as available”.

  4. Company’s Role in Data Processing. The Company functions solely as a technical intermediary, standardizing and delivering publicly available data and technical processing outputs through API interfaces.

    The Company does not verify identities or data accuracy; evaluate individual profiles or histories; provide risk assessments, compliance determinations, or eligibility decisions for employment, housing, insurance, credit, or government programs; or interpret, classify, or provide legal conclusions regarding any data.

    All conclusions, decisions, or actions taken by the User based on the Services are solely at the User’s own discretion and responsibility.

  5. Legal Basis for Processing (GDPR, CCPA, International). Where Data constitutes “personal data” under applicable privacy laws, the Company relies on the following legal bases:

    1. GDPR - Legitimate Interest (Art. 6(1)(f)). The processing is necessary to provide technical access to information that is already publicly accessible and lawfully published by authorities.

    2. GDPR - Publicly Available Information Exception. The Data originates from sources expressly intended for public access under law.

    3. CCPA - “Business Purpose”. Processing is limited to operational business purposes relating to access to public records.

    4. Allocation of Roles (Critical Legal Clarification). For GDPR and similar frameworks: The User acts as the data controller of any personal data obtained through the Services. The Company acts solely as a technical processor/intermediary, facilitating access to publicly available information.

  6. Compliance with Dissemination Laws. The User is solely responsible for: determining the lawfulness of their downstream processing, understanding state-specific dissemination rules, complying with federal, state, and international privacy frameworks, respecting restrictions on republication, aggregation, redistribution, or removal of public records.

    The Company may restrict, suspend, modify, or revoke access if required to comply with changing disclosure rules or legal obligations.

  7. No Guarantee of Continuity, Completeness, or Availability. Because publicly available records may be revised, corrected, removed, sealed, restricted, or unpublished by competent authorities at any time, the Company does not guarantee that any Data will remain available in the future, that the Data is complete or up to date, or that all jurisdictions publish information with the same frequency, scope, or level of detail.

    This applies, where relevant, to all categories of publicly available data, including public-record or criminal-justice-related information, if and to the extent such data is made publicly accessible by the originating authorities.

    The Company’s role is limited to technically retrieving and transmitting information that is publicly available at the time of the User’s request.

  8. No Obligation to Update or Correct Data. The Company has no obligation to monitor, update, correct, refresh, or otherwise maintain the accuracy, completeness, or timeliness of any Data after it has been retrieved from public sources. Any updates, corrections, sealing, expungement, removal, or modification of public records are determined exclusively by the originating governmental authorities and are outside the Company’s control.

DATA STORAGE AND SECURITY

  1. Hosting and Cloud Infrastructure. Hosting and Cloud Infrastructure. All components of the Services are hosted on Amazon Web Services (AWS) using industry-standard cloud infrastructure.

    The Company selects AWS regions and resources appropriate for hosting publicly available data, service-related data, technical processing outputs, system metadata, and logs. The Company maintains full administrative control over its cloud environment and implements strict role-based access controls to minimize exposure and ensure operational integrity.

    The Company does not store or process sensitive payment information. Payment data is handled exclusively by third-party Payment Processors in accordance with their applicable security standards and compliance requirements.

  2. Encryption and Data Protection. The Company employs multiple layers of security controls, including:

    1. Encryption at Rest: All stored Data, logs, and system metadata are encrypted using AWS-managed or equivalent secure encryption mechanisms.

    2. Encryption in Transit: All communication between the User’s systems and the Services occurs through secure HTTPS/TLS channels.

    3. IAM and Access Controls: Access to operational systems is restricted using least-privilege principles, multi-factor authentication, and continuous audit logging.

      The Company regularly updates and reviews access rights to ensure adherence to internal and industry-standard security practices.

  3. API Logs, Monitoring, and Retention. The Company maintains API request logs for security monitoring, billing accuracy, diagnostics, and abuse detection. Such logs may include: request timestamps, endpoint identifiers, rate-limit interactions, API Key metadata, performance metrics and error details.

    API logs do not include the User’s internal data unrelated to API interactions, nor are logs used for user profiling, behavioral analytics, or any purpose beyond operational needs.

    Retention periods follow the Company’s internal data-retention schedule and may be extended only where required to meet legal obligations or investigate security incidents.

  4. User Account Data Stored in the Dashboard. The Dashboard stores only the minimum internal data necessary to operate the Services. Certain technical identifiers or payment-related tokens may be stored internally for operational purposes and are not exposed or displayed to the User.

    The Company does not store plaintext passwords or card numbers. Passwords are hashed using industry-standard algorithms.

  5. Internal Access, Personnel Controls, and Confidentiality. Access to production infrastructure, code repositories, logs, and operational tools is strictly limited to authorized personnel whose roles require it. All employees and contractors are bound by confidentiality obligations and are required to comply with internal security procedures.

    Administrative access requires multi-factor authentication. Permissions are reviewed periodically and revoked upon role changes or termination.

  6. Security Monitoring, Incident Detection, and Response. The Company maintains technical and procedural controls to identify and respond to potential security incidents, including: automated anomaly detection, alerting on suspicious API activity, investigation of irregular request patterns, triage and escalation procedures, containment and remediation measures.

    In the event of a confirmed security incident involving the Services, the Company will act promptly to mitigate impact and, where legally required, notify affected Users.

  7. No Guarantee of Error-Free or Uninterrupted Operation. While the Company employs reputable cloud infrastructure, monitoring, and best-practice security measures, no method of electronic transmission or storage is completely secure or error-free. The User acknowledges that temporary downtime, delays, or security vulnerabilities may occur due to infrastructure conditions, third-party dependencies, or events beyond the Company’s control.

  8. User Responsibilities for Local Security. The security of the User’s systems, devices, networks, and development environments is entirely the User’s responsibility. The User must: store API Keys securely, prevent unauthorized access to their systems, encrypt sensitive environments, use secure configuration management, rotate compromised credentials promptly.

    Any breach of the User’s local environment does not constitute a breach of the Company’s systems.

SUPPORT AND COMMUNICATION

  1. Support Channels. Support for the Intsurfing API Platform is available through the communication channels listed in the Platform and on the official Intsurfing API website. technical support is available at support@intsurfing.com. Billing support is available at billing@intsurfing.com. The Company may introduce additional support channels, including ticketing, secure messaging, or live chat.

  2. Scope of Support. Support is limited to matters directly related to Account access and credential management, API availability, errors, performance issues, billing inquiries and invoice clarification, and interpretation of the Documentation and endpoint behavior.

    Unless expressly agreed in writing under a separate agreement, the Services and Support do not include custom development, software integration, consulting, or other professional services.

    Any custom development, integration, or professional services, if provided, are subject to separate commercial terms and agreements.

    Support does not include troubleshooting of the User’s local environment, network, infrastructure, or code.

  3. Response Times. The Company aims to respond to support requests within commercially reasonable timeframes, taking into account request volume, severity, and operational conditions. No guaranteed response time or service-level agreement (SLA) applies unless expressly agreed in writing.

  4. Official Communications. All official notices regarding these Terms, important service updates, billing matters, or security alerts are sent to the email address associated with the User’s Account. The User is responsible for maintaining an active, monitored, and deliverable email inbox.

    The Company is not responsible for communications that are filtered, blocked, delayed, or redirected by the User’s email provider, security systems, spam filters, or technical configuration.

  5. Changes to Communication Methods. The Company may update or modify its communication or support procedures at any time to maintain the quality, availability, or security of the Services.

WARRANTIES AND LIABILITY

  1. No Warranty on Data Accuracy, Completeness, or Timeliness. The Services may provide structured technical access to publicly available datasets sourced from official or other authoritative public sources, as well as non-data technical processing functionality.

    Where the Services provide access to public-record Data, the Company acts solely as an infrastructure provider. We may standardize, normalize, process, and deliver publicly available information through API interfaces, but we do not create, independently verify, or alter the underlying content of public records.

    Because the Company does not control the sources from which such Data originates, the Company makes no representation, warranty, or guarantee, whether express or implied, regarding the accuracy, completeness, or correctness of any Data; the timeliness or frequency of source updates; the legal status of any public record; the availability or continued publication of any information; or errors, omissions, redactions, inconsistencies, or other limitations originating from the underlying source.

    All Data and technical outputs provided through the Services are made available on an “as-is”, “as-available”, and “with all faults” basis.

  2. No Legal, Regulatory, or Compliance Advice. The Company does not provide: legal advice, background screening services, compliance assessments, identity verification, risk scoring, recommendations regarding Data interpretation.

    The User acknowledges that the Services are not designed to satisfy any requirement under the Fair Credit Reporting Act (FCRA) or any equivalent screening regulation. The User must not use the Services for employment, housing, credit, insurance, or benefit determinations.

    All decisions made using Data are solely at the User’s own risk and responsibility.

  3. No Guarantee of Availability or Performance. The Company does not warrant that the Services will: be uninterrupted or error-free, meet the User’s performance expectations, integrate seamlessly with the User’s environment, function without delays, throttling, or rate limiting, remain compatible with future systems, tools, or platforms.

    Temporary unavailability may occur due to maintenance, system load, updates, upstream changes, or external factors beyond the Company’s control.

  4. Limitation of Liability. To the fullest extent permitted by Applicable Law:

    1. The Company shall not be liable for any: direct, indirect, incidental, punitive, or consequential damages; lost revenue, profits, business opportunities, savings, or goodwill; reputational harm; decisions or actions taken by the User based on Data; loss or corruption of data; integration errors or system failures; delays, outages, or third-party interruptions; unauthorized use of API Keys resulting from the User’s failure to secure their environment.

    2. In all cases, the Company’s maximum aggregate liability, whether arising in contract, tort, negligence, strict liability, or otherwise, shall not exceed the total amount paid by the User for the Services in the thirty (30) days immediately preceding the event giving rise to the claim. If no such payments were made, the Company’s liability is zero.

    3. This limitation applies regardless of: the number of claims, form of action, theory of liability, foreseeability of damages.

  5. Allocation of Risk. The User agrees that the limitations set forth in this Section reflect a fair and reasonable allocation of risk, taking into account: the nature of public data, the variability and imperfection of public records, the technical model of the Services, the pricing structure, the fact that the Company does not create or verify the underlying information.

    The User acknowledges that these limitations are essential terms of the Agreement.

  6. Indemnification by the User. The User shall defend, indemnify, and hold harmless the Company and its directors, officers, employees, contractors, and affiliates from and against any and all claims, liabilities, losses, damages, costs, or expenses (including attorneys’ fees) arising out of or relating to:

    1. the User’s misuse of the Services or Data; violation of these Terms or Applicable Law; unlawful, discriminatory, or harmful downstream use of Data; publication, redistribution, or commercialization of Data; failure to implement adequate security measures to protect API Keys; use of the Data in any FCRA-regulated or otherwise prohibited context; breach of intellectual-property, privacy, or confidentiality obligations.

    This obligation survives termination of the User’s Account.

  7. External Dependencies and Upstream Data Sources. The Company is not responsible for downtime, latency, inaccuracies, or disruption caused by third parties or circumstances beyond its reasonable control, including AWS or other infrastructure providers, Stripe or other Payment Processors, governmental or other public-data sources, internet or network failures, attacks on third-party infrastructure, third-party integrations, or force-majeure events.

    Changes made by upstream public-data sources may affect the availability, consistency, scope, or content of Data provided through the Services.

  8. No Duty to Investigate or Resolve Complaint. The Company has no duty to investigate, verify, resolve, adjudicate, or respond to complaints, disputes, or claims regarding the accuracy, legality, relevance, or impact of any public record Data. Any such complaints or disputes must be addressed directly with the governmental authority or court responsible for the publication or maintenance of the relevant record.

GOVERNING LAW AND DISPUTE RESOLUTION

  1. Governing Law. These Terms and disputes arising out of or relating to them or the Services shall be governed by the laws of Poland, excluding conflict-of-laws rules, unless mandatory Applicable Law requires otherwise.
  2. Jurisdiction. Subject to mandatory Applicable Law, disputes arising out of or relating to these Terms or the Services shall be submitted to the competent courts in Warsaw, Poland.
  3. Good-Faith Resolution. Before initiating legal proceedings, the parties will make reasonable efforts to resolve the dispute through written communication. A party may initiate this process by sending written notice describing the dispute. If the matter is not resolved within thirty (30) days, either party may pursue the remedies available under Applicable Law.
  4. Injunctive and Equitable Relief. Nothing in these Terms prevents either party from seeking urgent injunctive or equitable relief where necessary to prevent misuse of the Services, unauthorized disclosure, security harm, infringement of intellectual-property rights, or other immediate harm.
  5. Individual Claims. To the fullest extent permitted by Applicable Law, claims relating to the Services shall be brought on an individual basis and not as part of a class, collective, or representative proceeding.
  6. International Users. Users located outside Poland acknowledge that these Terms are entered into with a Polish legal entity. Nothing in these Terms excludes rights or obligations that cannot lawfully be waived under mandatory Applicable Law.
  7. Time Limit for Claims. To the extent permitted by Applicable Law, claims arising from or relating to the Services must be brought within one (1) year after the cause of action arose.

CHANGES TO THESE TERMS

  1. Right to Modify the Terms. The Company may update these Terms to reflect changes in the Services, pricing or billing arrangements, Applicable Law, security requirements, operational requirements, or business practices.
  2. Publication and Effective Date. Updated Terms will be published on the Intsurfing API website and will identify the applicable Effective Date.
  3. Notification of Material Changes. Where changes materially affect the User’s rights or obligations, the Company will provide reasonable notice through email, the Intsurfing API Platform, or both. Administrative, technical, clarifying, or other non-material changes may be published without individualized notice.
  4. Acceptance of Updated Terms. The Company may require the User to explicitly accept materially updated Terms before continuing to access affected Services. Where explicit acceptance is not required, continued use of the Services after the Effective Date of the updated Terms constitutes acceptance to the extent permitted by Applicable Law. If the User does not accept updated Terms, the User must stop using the affected Services. Usage and payment obligations incurred before discontinuation remain payable.
  5. Versioning. The Company may retain previous versions of these Terms for legal, audit, and operational purposes. Previous versions may be provided where reasonably required.

MISCELLANEOUS

  1. Severability. If any provision of these Terms is held to be invalid, unlawful, or unenforceable, such provision shall be enforced to the maximum extent permitted by law, and the remaining provisions shall remain in full force and effect without limitation.

  2. No Waiver. No failure or delay by the Company in exercising any right, power, or remedy under these Terms shall operate as a waiver of such right. A waiver is valid only if provided in a written instrument executed by the Company.

  3. Entire Agreement. These Terms constitute the entire agreement between the parties with respect to the Services and supersede all prior and contemporaneous agreements, proposals, negotiations, representations, and communications, whether written or oral.

    No statement, promise, or representation not expressly included in these Terms is binding.

  4. Assignment. The Company may assign or transfer its rights or obligations under these Terms, in whole or in part, without requiring the User’s consent, including in connection with a merger, acquisition, corporate restructuring, or transfer of assets.

    The User may not assign, transfer, or delegate any rights or obligations under these Terms without the Company’s prior written consent. Any attempted assignment in violation of this provision is void.

  5. Independent Contractors. The parties are independent contractors. These Terms do not create any partnership, joint venture, employment, fiduciary, agency, or franchise relationship.

    The User has no authority to bind the Company in any manner.

  6. Force Majeure. The Company shall not be liable for any failure or delay in performing its obligations resulting from events beyond reasonable control, including: natural disasters, war, civil unrest, acts of government or law enforcement, internet or telecom failures, cloud infrastructure outages, strikes or labor disputes, pandemics, or any other event qualifying as force majeure under Applicable Law.

    During such events, obligations remain suspended until performance becomes feasible.

  7. Interpretation. Headings, titles, and section labels are provided for convenience only and do not affect the interpretation of these Terms.

    References to “including” or “include” mean “including without limitation.”

  8. Survival. The following provisions survive termination or expiration of the Agreement: Confidentiality (Section 1.12), Acceptable Use Policy (Section 6), Data Origin & Responsibilities (Section 7), Security (Section 8), Liability & Indemnification (Section 10), Governing Law (Section 11). Any payment obligations accrued prior to termination. These obligations continue indefinitely to the extent permitted by law.

  9. Notices. Official notices to the User may be sent to the email address associated with the User’s Account or displayed through the Intsurfing API Platform.

    The User is responsible for maintaining an active and monitored email address.

    Official correspondence to the Company regarding these Terms may be sent to contact@intsurfing.com unless another contact method is specified in these Terms or the Platform.

  10. Third-Party Beneficiaries. Except as expressly stated, these Terms do not grant rights to any third party. Affiliates, directors, and employees of the Company may enforce rights relating to liability protections and indemnification.

  11. Export Compliance. The User must comply with all applicable export-control, sanctions, and trade-compliance laws. The Services may not be used in, or exported to, jurisdictions subject to comprehensive sanctions.

COMPANY DETAILS

Service provider and billing entity
NANNOS sp. z o.o.
Ostrobramska 101A/301
04-041 Warszawa
Poland KRS: 0001246729
NIP: 1133204311
REGON: 544967531 Company website: https://www.nannostech.com/
Product / Platform: https://platform.api.intsurfing.com/
Product website: https://www.api.intsurfing.com/
Official correspondence: contact@intsurfing.com

Logo
2026 Copyright Intsurfing LLC
API services are provided and billed by NANNOS sp. z o.o.
Privacy policy Terms of use
Name parsing API My account Status
Contact us:
contact@intsurfing.com
Follow us on LinkedIn
stripe