API Terms of Use
Last updated on September 15, 2026
1. These Terms
- We are Soigné B.V., a company registered in the Netherlands under number 92772390. We build software that helps hospitality businesses hire, manage and pay their teams. Where these terms mention our services, we mean that software and everything we make available with it.
- These terms cover the use of our APIs by anyone: our customers, developers building integrations, and anyone acting on behalf of a customer. By requesting API credentials or calling our APIs you accept them, and if you do that for a company you confirm you are allowed to bind it.
- These terms cover two situations. If you build software and want to connect it to our services, these terms are the whole agreement between us: they govern your access to our APIs, and nothing more. They do not give you a subscription and they do not make you a party to any agreement we have with our customers. If you are one of our customers and you use our APIs yourself, our Terms of Service govern your subscription and these terms govern your use of the APIs. If the two conflict, our Terms of Service come first, except on the technical use of the APIs, where these terms come first.
2. Access and Use
- We give you a limited, non-exclusive, non-transferable and revocable right to call our APIs to build and run an integration with our services, and nothing beyond that. Our APIs, documentation and software stay ours. Do not reverse engineer them, work around technical restrictions, or use them to build a competing product.
- Keep your credentials secret. Store them server-side only, and never put them in client-side code, mobile apps, repositories, logs or URLs. Everything done with your credentials counts as done by you. Tell us straight away if they are lost or exposed and rotate them.
- Only request the scopes you actually need. Follow our documentation, stay within rate limits, and do not scrape or bulk extract beyond what the documented endpoints are for.
- Before we issue production credentials we may ask you about your security practices and what you are building. We decide at our discretion whether to issue them, and we can review that decision if what you do materially changes.
- Use our test environment for development and testing only. Do not put real personal data into it.
3. Working with Customer Data
- This clause applies where you use our APIs to access data belonging to one of our customers. If you are that customer and it is your own data, this clause does not apply.
- The customer is the controller of its data. We hold it as their processor, and you act as a separate processor engaged directly by them. You are not our sub-processor. When you access their data through our APIs, we release it on their instruction, evidenced by their installation of your integration for their account.
- Before you touch a customer's data, you need a written processing agreement with them that meets article 28 GDPR, and you must comply with it and with data protection law. Access only what your integration needs. Do not process customer data for your own purposes, sell or monetize it, or use it to develop or train AI or machine learning models.
- If your integration sends data into our services, you confirm the customer authorized you to send it and that it contains nothing malicious or unlawful.
4. Security
- If you find or suspect a vulnerability in our APIs or services, report it to security@soigne.app. Do not exploit it beyond what is needed to show it exists, do not access, modify or extract data that is not yours, do not disrupt or degrade our services, and do not go public before it is fixed and we have agreed to disclosure. Automated scanning, load testing and penetration testing against our production environment need our prior written consent.
- We will acknowledge good faith reports within a reasonable time and keep you posted on what we are doing about confirmed issues. We will not pursue claims against you for research carried out in line with clause 4.1.
- If you build an integration that others use, give us a security contact and keep it current. We use it for vulnerability reports, incident coordination and urgent operational matters, so it needs to be monitored by someone who can act on it. Respond to our security and operational requests within a reasonable time.
- Build and run your integration securely, in line with good industry practice. That includes keeping your dependencies patched, protecting the systems that hold your credentials and any data you obtained through our APIs, and limiting access to the people who need it.
- Tell us straight away if you become aware of a security incident affecting your systems or your integration that could affect our services, our customers or their data. This applies even if the incident is not a personal data breach. Work with us to contain it and share what we reasonably need to assess the impact on our side.
5. Changes
- We do not make breaking changes to a published v1 endpoint. Where a change would break existing integrations, we publish it at a new versioned path and keep the existing endpoint running through its sunset window.
- Before we remove or sunset a published v1 endpoint, we give at least six months of notice through deprecation and sunset response headers, by email to the contact details you have registered with us, and in our documentation.
- Non-breaking changes, such as new endpoints, optional fields or new enum values, can happen without notice. Build a tolerant client that ignores what it does not recognize and keep your integration working with the current version.
- We can make changes at shorter notice, or without notice, where security, legal or regulatory reasons require it.
- We may update these terms and our documentation from time to time. Where a change materially and adversely affects you, we give at least 30 days of notice. Continuing to use our APIs after a change takes effect means you accept it.
6. Warranty
- We provide our APIs on an “as-is” and “as-available” basis, on a best-efforts basis and without warranties of any kind, except where these terms say otherwise. There is no committed availability or support unless we agree otherwise in writing.
- Building on our APIs is at your own risk. Keep your integration working with the current version.
- We currently provide API access free of charge. We may start charging for it, and if we do we will tell you at least one month before the change takes effect.
7. Liability
- If you are our customer, the liability provisions in our Terms of Service apply to you, and they cover your use of our APIs as well. Any liability under these terms falls within, and does not add to, the cap in our Terms of Service.
- Otherwise, our total liability to you is capped at one hundred euros per calendar year. We are not liable for indirect damages, including lost profits, business disruption, loss of data, missed savings, fines or third-party claims. This applies whatever the legal basis of the claim, except in case of intent or deliberate recklessness by our management.
- You indemnify us against claims from third parties, including our customers and regulators, arising from your integration, your use of our APIs, or your processing of customer data.
8. Brand
- You can say your integration works with Soigné. Do not otherwise use our name or logo, and do not suggest we endorse, support or certify what you built, without our written consent.
- If you send us feedback or ideas, we are free to use them without owing you anything.
9. Termination
- You may cease using our APIs at any time.
- We may suspend or terminate your access at any time, in particular where there is a security risk, where you are in breach of these terms, where suspension is required by law or by a regulator, where a customer withdraws its authorization, or where we reasonably suspect misuse. We will notify you where reasonably possible. Where we have suspended your access, we will restore it once the ground for suspension has been remedied.
- Upon termination, you shall cease all use of our APIs and delete your credentials. Where you hold data belonging to one of our customers, you shall handle that data in accordance with your agreement with that customer.
10. Other Legal Bits
- Dutch law governs these terms, and any disputes go exclusively to the courts in Amsterdam.
- If part of these terms turns out to be invalid, the rest stays in force and we will replace the invalid part with something as close to the original intent as possible. We may transfer these terms to another company, for example if our business is acquired. You cannot transfer them without our consent.