MONODAT — Terms of Service
§1. Preliminary Provisions
-
These Terms of Service ("Terms") govern the provision of electronic services by the Operator of the MONODAT platform, in accordance with: (a) the Polish Act on Electronic Services of 18 July 2002, (b) the Polish Telecommunications Law of 16 July 2004, (c) Regulation (EU) 2016/679 (GDPR), (d) Regulation (EU) 2022/2065 (Digital Services Act – DSA), (e) Regulation (EU) 2024/1689 (Artificial Intelligence Act – AI Act), (f) the Polish Civil Code, and (g) the Polish Consumer Rights Act.
-
The Operator of MONODAT (https://monodat.com) is:
Moises Lopez Otero Studio Programistyczne ul. Osiedle Willowe 5, 31-901 Kraków, Poland NIP (Tax ID): 6793218612 | REGON: 389287603 Legal form: Sole trader (Indywidualna działalność gospodarcza) Email (operational contact, complaints, GDPR, notices): help@monodat.com Email (general matters): info@monodat.com
hereinafter referred to as the "Operator".
-
MONODAT provides services exclusively to professional B2B entities. These Terms do not apply to consumers under Polish law, subject to §23 (special provisions for sole traders).
-
By using the Platform, the User accepts these Terms and the Privacy Policy. Acceptance is confirmed by ticking the relevant box during registration.
-
The current version of the Terms is available at https://monodat.com/en/terms.
§2. Definitions
- Platform / Service: the MONODAT platform at https://monodat.com.
- Operator: Moises Lopez Otero Studio Programistyczne.
- User: an entity that has entered into an Agreement with the Operator.
- Account: the User's individual panel.
- Services: services described in §4.
- Subscription Plan: Pro Plan (PLN 299 net/month) or Avance Plan (PLN 399 net/month), plus applicable VAT. Current prices are published at https://monodat.com/en/pricing.
- Registry Data: data from Polish public registries (KRS, CRBR, VAT Whitelist, SUDOP, BZP, KRZ, MF e-Reports).
- Company Contact Data: email, phone and website addresses of business entities from public registries.
- Analytical Models: statistical predictive models (Prusak, Hołda, Mączyńska, Beneish M-Score, Health Score) provided through the Platform.
- Person Risk Indicators: derived indicators computed by the Operator about identified natural persons (e.g. director-of-many-companies patterns, sanctions/PEP list matches), as described in §16.
- Agreement: the contract for electronic service provision.
- AUP: Acceptable Use Policy (§11).
§3. Contact Points (DSA)
Pursuant to the DSA (Regulation EU 2022/2065), the Operator designates:
-
Contact point for Member State authorities, the Commission and the Digital Services Board: help@monodat.com (Polish or English).
-
Contact point for users and third parties: help@monodat.com (illegal content notifications, complaints).
-
Illegal content notice procedure is described in §25.
§4. Scope of Services
-
The Platform provides services including: a) access to aggregated and analysed Registry Data, b) monitoring of changes and corporate event notifications, c) financial scoring and analysis based on public data, d) Analytical Models, e) reports and market overviews, f) compliance and due diligence tools, g) access to Company Contact Data, h) access to KRZ, SUDOP, BZP, VAT Whitelist data.
-
The Platform does not provide legal, financial, tax, audit or investment advisory services.
-
Data is for informational purposes only and does not replace official documents. For legal purposes, Users must rely on official public registries.
-
The Operator informs Users that the Platform uses artificial intelligence systems (Analytical Models) in accordance with the transparency requirements of Art. 50 AI Act. These models do not constitute "high-risk AI systems" under Art. 6 AI Act.
§4a. Free Plan and Trial Periods
-
The Operator may offer a free access plan ("Free Plan") and trial periods. The Free Plan is provided "as is", without any warranty of availability, functional scope or continuity.
-
The Operator may at any time change the scope, limits or conditions of the Free Plan, and may suspend or withdraw the Free Plan entirely — without prior notice and without any claims on the User's part.
-
Features available in the Free Plan may at any time become available only under paid plans.
-
No service level commitments (SLA) apply to the Free Plan.
§4b. Service Levels — Paid Plans
-
Unless the Operator and the User have signed a separate, written service level agreement, no paid Subscription Plan carries an uptime, response-time or availability guarantee. The Operator undertakes to make commercially reasonable efforts to keep the Platform available, but §4a(4), §17, §17a and §18 apply equally to paid plans.
-
Planned maintenance is carried out, where feasible, outside Central European business hours and, where feasible, announced in advance via the Platform or by email. No advance notice is required for emergency maintenance necessary to preserve security or data integrity.
§5. Technical Requirements
-
Required: Internet-connected device, modern browser supporting JavaScript and cookies, active email address.
-
The Operator is not responsible for technical issues on the User's side or Internet connectivity issues.
§6. Registration and Account
-
Full Platform access requires registration.
-
During registration, the User: (a) provides accurate and current information, (b) accepts the Terms and Privacy Policy, (c) confirms being at least 18 years old and acting on behalf of an authorised entity.
-
The User is responsible for the security of login credentials and must immediately notify the Operator of unauthorised access.
-
Sharing the Account with third parties is prohibited. Each person in an organisation must have a separate Account.
-
The Operator may suspend or delete an Account for breach of Terms, false information, or actions violating third-party rights.
§7. Identity Verification and Refusal of Service
-
The Operator reserves the right to verify the User's identity at any time, including requesting documents confirming legal status.
-
The Operator reserves the right to refuse Service or terminate the Agreement immediately if: a) the User is a direct competitor of the Operator, b) the User or its beneficial owner is on a sanctions list (§13), c) the User previously had an Account terminated for Terms violation, d) there is reasonable suspicion of unlawful use, e) the User refuses identity verification or provides false documents, f) the Operator identifies a significant risk of abuse.
-
Refusal does not require justification beyond reference to the grounds in paragraph 2 and does not give rise to damages claims.
§8. Subscription and Payments
-
Subscription Plans:
- Pro Plan: PLN 299 net/month + VAT
- Avance Plan: PLN 399 net/month + VAT Current plan features and prices: https://monodat.com/en/pricing. In the event of a discrepancy between this paragraph and the price list published on the Platform, the binding price is the one accepted by the User during the payment process.
-
Payments are processed by a certified third-party provider. The Operator does not store payment card data.
-
Subscriptions renew automatically each month until cancelled.
-
Cancellation is effective at the end of the current billing period. Fees paid are non-refundable (subject to §23 and §24).
-
Failed payments may result in immediate suspension of Services without liability.
-
Price changes require 30 days' notice by email and do not affect the current paid period.
-
VAT invoices are issued automatically for Users providing a NIP. EU VAT reverse-charge may apply for non-Polish EU VAT taxpayers.
-
An unjustified chargeback initiated by the User despite properly performed Services entitles the Operator to immediately suspend the Account and to recover the charged amount together with operational costs and fees charged by payment providers.
-
Objections to an issued invoice must be raised within 14 days of receipt. Absence of objections within this period is deemed acceptance of the invoice, without prejudice to mandatory statutory rights.
-
The User bears all taxes, bank charges, currency conversion fees and other payment-related costs not charged by the Operator.
§9. API — Tokens, Technical Limits and Fair Use
-
Access to the Platform's public API is paid on a prepaid basis: the User buys token packs, and each call to a paid endpoint reduces the balance by the number of tokens stated for that endpoint in the API documentation. API access is not part of the Subscription Plan limits unless the Plan description says otherwise.
-
Token pack prices are stated in PLN as net prices, to which VAT is added at the applicable rate, and are shown before purchase. Payments are processed by Stripe; VAT invoices are issued in accordance with §8.
-
Tokens do not expire and cannot be exchanged for cash. Unused tokens are non-refundable, without prejudice to mandatory law, including §23 (Art. 38a of the Polish Consumer Rights Act).
-
No tokens are charged for calls ending in an error (4xx and 5xx responses). A response confirming that no data is available for an entity (
data_available: false) costs 1 token. In batch jobs, tokens for rows that could not be processed are refunded to the balance. Tokens charged and the remaining balance are returned in response headers (X-Tokens-Charged,X-Tokens-Balance). -
Regardless of the balance, the Operator applies technical rate limits per API key, published in the documentation (on the effective date of these Terms: 120 calls per minute with a burst of 20 calls per second, and 6 messages per minute for the AI analyst). Exceeding a limit returns HTTP 429 and no tokens are charged.
-
Welcome tokens granted after e-mail verification are promotional, non-refundable and non-transferable, and may be withdrawn in case of abuse (e.g. creating multiple Accounts).
-
The Operator applies a fair-use principle. A significant deviation from the typical usage pattern, in particular bulk extraction of data to reproduce the Platform's database, may be deemed a breach of §11 (AUP) and result in: (a) throttling, (b) suspension of the API key, or (c) for repeated or serious breaches, termination of the Agreement, applying §11a.
-
The Operator may change per-endpoint token prices and technical limits with at least 30 days' notice, published in the API documentation and changelog. Changes do not affect tokens already purchased.
§10. User Obligations
-
The User uses the Platform in compliance with law, the Terms and good practice.
-
The User: (a) maintains accurate Account information, (b) keeps credentials confidential, (c) uses the Platform for own professional/business purposes only, (d) promptly reports irregularities, (e) complies with GDPR when processing data obtained from the Platform, (f) ensures persons acting on its behalf know and accept the Terms.
§11. Acceptable Use Policy (AUP)
The following are strictly prohibited:
a) Automated extraction: scraping, crawling, harvesting of Platform data without the Operator's written consent.
b) Resale/distribution: reselling, sublicensing, distributing Platform data to third parties.
c) Building competitors: using Platform data, methodologies or structure to build competing products or services.
d) Credential sharing: sharing login credentials with third parties.
e) Bypassing safeguards: circumventing API limits, access controls, security mechanisms.
f) Reverse engineering: decompiling, disassembling, reconstructing source code, scoring algorithms, methodologies.
g) Unlawful use: violating Polish or EU law.
h) Harassment: using data to harass, stalk, discriminate against or harm individuals or entities.
i) False accounts: creating fictitious Accounts, impersonating others.
j) API abuse: usage that destabilises infrastructure.
k) AI training: using the Platform to train own AI or machine learning models.
l) Multiple accounts: creating or using multiple Accounts to circumvent Free Plan limits, API limits or other restrictions.
m) Mass database reconstruction: systematic retrieval of data to reconstruct a substantial part of the Platform's database.
n) Decisions about natural persons: using Platform data — including Person Risk Indicators such as director-count flags, sanctions/PEP matches or any other risk label the Platform attaches to an identified individual — as a basis for decisions concerning creditworthiness, employment, insurance, housing, or any other decision producing legal or similarly significant effects with respect to that individual (see §12a and §16).
o) Publication of Person Risk Indicators: publishing, broadcasting or otherwise making available to persons outside the User's own organisation any Person Risk Indicator, or any accusation of wrongdoing derived from one, without independent verification of the underlying facts. Person Risk Indicators are statistical patterns, not findings of fact (§16).
p) Marketing to CEIDG entrepreneurs and re-identification: using data of natural persons carrying out business activity (CEIDG) for direct marketing, or combining it with other sources to establish a home address, PESEL number, date of birth or contact details (see §15d).
Violation results in immediate termination and may give rise to damages claims and to the contractual penalties set out in §11a.
§11a. Contractual Penalties for AUP Breaches
-
The User's obligations under §11 and §12 are non-pecuniary in nature (obligations to refrain from acting). Pursuant to Art. 483 §1 of the Polish Civil Code, the Parties stipulate contractual penalties for their breach.
-
The User shall pay the Operator a contractual penalty of:
Breach Contractual penalty Automated data retrieval — scraping, crawling, harvesting (§11(a)) PLN 20,000 per established instance Systematic retrieval to reconstruct a substantial part of the database (§11(m)) PLN 50,000 per established instance Resale, sublicensing or disclosure of data to third parties (§11(b)) PLN 50,000 per established instance Use of data or methodology to build a competing product (§11(c)) PLN 50,000 per established instance Reverse engineering of the Analytical Models or algorithms (§11(f)) PLN 50,000 per established instance Use of the Platform to train AI or machine learning models (§11(k)) PLN 50,000 per established instance Use of Company Contact Data for spam or cold e-mail (§12(2)) PLN 20,000 per established instance Decision about a natural person based on Person Risk Indicators, or external publication of a Person Risk Indicator (§11(n)-(o)) PLN 50,000 per established instance Sharing sign-in credentials or the Account (§11(d)) PLN 5,000 per established instance Creating multiple Accounts to circumvent limits (§11(l)) PLN 5,000 per additional Account Circumventing security measures or API limits (§11(e)) PLN 10,000 per established instance -
For a continuing breach that persists despite the Operator's demand to cease, an additional penalty of PLN 1,000 per day accrues for each day the breach continues, counted from the day following delivery of the demand.
-
Pursuant to Art. 484 §1, second sentence, of the Polish Civil Code, the Parties expressly stipulate that the Operator may claim damages exceeding the amount of the stipulated contractual penalty under general principles.
-
Payment of a contractual penalty does not release the User from the obligation to cease the breach, remedy its effects, or destroy unlawfully obtained data.
-
Contractual penalties are due irrespective of the Operator's right to terminate the Agreement with immediate effect (§26(2)) and irrespective of claims arising from database protection (§20(7)) and trade secret protection (§20(2)).
-
The amounts have been set taking into account the value of the Platform's database, the effort required to build and maintain it, and the difficulty of proving actual damage resulting from breaches of this kind.
-
This paragraph does not apply to Users referred to in §23 (natural persons conducting business activity for whom the Agreement is not of a professional character), to the extent that it would be impermissible under mandatory consumer protection law.
§11b. Usage Monitoring and Investigation
-
The Operator monitors use of the Platform and API solely to ensure security, detect abuse and enforce the AUP, on the basis of Art. 6(1)(f) GDPR (legitimate interest). The scope and retention period of monitoring data are set out in the Privacy Policy.
-
Where a breach of §11 or §12 is reasonably suspected, the Operator may: a) demand that the User provide explanations within 7 days, b) temporarily throttle or suspend API access for the duration of the investigation, c) demand disclosure of the purpose and manner of use of the retrieved data, d) demand deletion of unlawfully obtained data and a statement confirming its destruction.
-
Failure to provide explanations within the deadline, or providing false explanations, constitutes an independent ground for immediate termination of the Agreement.
-
Suspension of access for the duration of an investigation does not entitle the User to a refund or damages, unless the investigation does not confirm the breach — in which case the suspension period will be added to the subscription term.
§12. Anti-Spam and Restrictions on Company Contact Data
-
Company Contact Data is provided exclusively for professional counterparty verification, due diligence and compliance.
-
The following are strictly prohibited when using Company Contact Data: a) mass sending of unsolicited commercial emails (spam) — Art. 10 of the Polish Act on Electronic Services, b) cold email/cold calling campaigns without prior consent — Art. 172 of Polish Telecommunications Law, c) automated mass sending of SMS, voice or push messages, d) building marketing databases without valid GDPR basis, e) any action violating data protection law.
-
The User bears sole and full legal and financial responsibility for the use of Company Contact Data outside the Platform.
-
In the event of claims, administrative proceedings, sanctions or fines against the Operator resulting from User's violation, the User fully indemnifies the Operator, including legal fees, administrative penalties and awarded damages.
-
The Operator may immediately block the Account upon reasonable suspicion of violation.
-
The Platform does not provide contact details of entrepreneurs registered in CEIDG (natural persons). The restrictions of this section apply accordingly to any contact details of such persons obtained by the User from other sources and combined with Platform data (§15d).
§12a. Nature of the Service — No Credit Bureau Status, Decision Restrictions and Evidentiary Value
-
MONODAT is not a credit information bureau (BIG) within the meaning of the Polish Act of 9 April 2010 on Access to Business Information and Exchange of Business Data, does not operate a debtors' register and does not provide "business information" within the meaning of that Act.
-
The Operator is not a credit rating agency within the meaning of Regulation (EC) No 1060/2009, and Analytical Model results do not constitute credit ratings.
-
It is prohibited to use Platform data or results as the sole or decisive basis for decisions concerning natural persons regarding: granting or refusing credit, employment, insurance, housing rental, or other determinations producing legal or similarly significant effects on such persons.
-
The Platform is not a public register. Data, reports and printouts from the Platform do not constitute official documents within the meaning of Art. 76 of the Polish Code of Administrative Procedure or Art. 244 of the Polish Code of Civil Procedure and carry no official evidentiary value. For official and judicial purposes, extracts and certificates must be obtained directly from the source registries.
-
Data presentation in the Platform respects the rules on re-use of public sector information (Polish Act of 11 August 2021 on Open Data and Re-use of Public Sector Information).
-
The restriction in paragraph 3 applies with particular force to Person Risk Indicators (§16): a person flagged as holding directorships in an unusually high number of companies, or as matching a sanctions or PEP list, is not thereby shown to have done anything unlawful. Such flags are statistical patterns computed by the Operator to support the User's own compliance process, not adjudications of fact, and must always be independently verified by the User before being relied upon or communicated to any third party, including the individual concerned.
§13. Sanctions and Anti-Corruption Compliance
-
The User represents and warrants that neither the User, nor its beneficial owners, nor controlling entities: (a) are listed on EU, US (OFAC), UK (HMT) or UN sanctions lists, (b) originate from embargoed jurisdictions (including Belarus, Russia, Iran, North Korea, Syria, Cuba), (c) act on behalf of entities described in (a)-(b).
-
Violation constitutes a material breach and results in immediate termination without refund.
-
The Operator may verify sanctions status at any time.
-
The User represents that it complies with applicable anti-bribery and anti-corruption law and has not offered, promised or given, and will not offer, promise or give, any undue advantage to any person in connection with the Agreement.
§14. Disclaimer — Analytical Models
-
Analytical Models (Prusak, Hołda, Mączyńska, Beneish M-Score, Health Score, HHI) are statistical instruments only, based on historical and public data. They do not constitute expert opinions, forecasts or recommendations.
-
Model results: (a) are not expert opinions, audits, legal advice or investment recommendations, (b) do not confirm or exclude solvency or financial condition, (c) cannot be the sole or primary basis for decisions, (d) depend on data quality submitted by the entity itself, (e) may be incomplete for entities without reporting obligations.
-
A negative result is not evidence of imminent insolvency, fraud or unlawful conduct. A positive result does not guarantee solvency.
-
Decisions based on Models are at the User's sole risk.
-
Pursuant to Art. 50(2) AI Act, Users are hereby informed that Models constitute an AI system generating statistical outputs.
§14a. AI Features, Chat and Automatically Generated Content
-
The Platform may provide features based on generative artificial intelligence (in particular an analytical chat and automatic summaries). Pursuant to Art. 50(1) AI Act, the Operator informs Users that when using these features they interact with an artificial intelligence system, not a human.
-
AI-generated content may contain errors, inaccuracies, omissions or outdated information (so-called hallucinations). It is auxiliary and informational only.
-
AI content does not constitute legal, financial, tax or investment advice. The User must verify AI content against source data before use.
-
The Operator is not liable for decisions made on the basis of AI-generated content.
-
Using AI features to circumvent plan limits, to generate unlawful content, or for purposes listed in §11 is prohibited.
§15. Disclaimer — Registry Data Quality
-
Platform data originates from Polish public registries. The Operator is not the creator or administrator of these registries.
-
The Operator is not liable for: (a) inaccuracies, incompleteness or errors in source data, (b) update delays from public authorities, (c) discrepancies between registry status and actual legal/operational status, (d) CRBR errors from incorrect declarations, (e) VAT Whitelist status (real-time data – Platform shows last synchronisation), (f) inaccuracies in MF e-Reports, (g) delayed visibility of KRZ data, (h) missing data for entities without registration obligations, (i) changes in data availability from source registry API changes, (j) temporary registry outages, (k) currency of company contact data, (l) the veracity of beneficial owner identities declared in the CRBR — the Operator does not verify declarations, (m) completeness and correctness of anonymisation of court judgments (SAOS), which depend on the source, (n) the existence of debts or liabilities not disclosed in public registries — absence of a registered debt does not mean no debt exists.
-
Absence of information does not mean an event did not occur.
-
An entity shown as "active" may not be operationally active — registration status ≠ operational status.
-
Platform data does not replace official documents. Users must rely on official registries for legal purposes.
§15a. Market and Stock Exchange Data (GPW, KNF, ESMA, EBA)
-
Market, stock exchange and regulatory data (including GPW quotations, KNF registers and warnings, ESMA and EBA data) may be delayed relative to real time and is informational only.
-
No Platform content constitutes an investment recommendation or information recommending or suggesting an investment strategy within the meaning of Regulation (EU) No 596/2014 (MAR), nor investment advice within the meaning of the Polish Act on Trading in Financial Instruments.
-
The Operator is not liable for investment or trading decisions made on the basis of Platform data.
§15b. Screening, Sanctions and Compliance Tools
-
Screening tools (sanctions, warnings, compliance monitoring) merely support the User's processes and do not replace the User's own legal obligations.
-
Use of the Platform does not constitute fulfilment of obligations under the Polish Act of 1 March 2018 on Counteracting Money Laundering and Terrorist Financing (AML) or analogous regulations. The Operator does not act as an obligated institution within the User's processes.
-
Screening results may include false positives and false negatives. No match in the Platform does not mean an entity is not on a sanctions list — the User must verify against official, current sources.
-
Absence of information in the Platform about debt, proceedings or any other event does not confirm that such event does not exist.
§15c. Monitoring, Alerts and Notifications
-
The Operator does not guarantee delivery or timeliness of notifications (email, in-Platform), which depend among others on third-party providers, spam filters and availability of source registries.
-
Notifications are auxiliary. The User should not base critical processes solely on Platform alerts.
-
Non-delivery, delay or omission of a notification does not constitute non-performance of the Agreement and creates no liability of the Operator.
§15d. Data on Sole Traders from CEIDG
-
The Platform presents data of natural persons carrying out business activity who are registered in CEIDG to an extent narrower than the official register, as described in section 3.3 of the Privacy Policy. The Platform does not disclose contact details, home address, date of birth, PESEL number or the other data excluded in that section, and does not allow searching by PESEL number.
-
The data referred to in paragraph 1 is personal data. A User who retrieves it outside the Platform (export, API, copies) processes it as an independent controller and is solely responsible for having its own legal basis, fulfilling the information obligation (Art. 14 GDPR) and handling data subjects' rights with respect to its own processing.
-
Without prejudice to §11 and §12, the following are strictly prohibited: a) using CEIDG entrepreneurs' data obtained from the Platform for direct marketing in any form (e-mail, telephone, SMS, messengers, postal mail), including building or feeding marketing databases; b) combining Platform data with other sources in order to establish an entrepreneur's home address, PESEL number, date of birth or contact details (re-identification), or to reconstruct data the Platform deliberately does not disclose; c) using signals, links or entry history as a basis for the decisions referred to in §11(n) with respect to an entrepreneur who is a natural person; d) publishing or passing to persons outside the User's own organisation compilations of signals concerning an identified CEIDG entrepreneur without independent verification of the facts in the source registers.
-
Risk signals, links (including those marked "probable") and change history concerning CEIDG entrepreneurs mirror entries in public registers matched by NIP or REGON and are for information only; they are neither findings of fact nor an assessment by the Operator. The Operator does not compute a Monodat Score or a Person Risk Indicator for CEIDG entrepreneurs. §12a, §15 and §16 apply accordingly.
-
A CEIDG entrepreneur's entry may at any time become unavailable on the Platform, in the API, in exports and in notifications as a result of deregistration from CEIDG, disappearance from the official report or a successful objection by the data subject. This does not constitute non-performance or improper performance of the Agreement.
-
A breach of paragraph 3 is an AUP breach within the meaning of §11 and entitles the Operator to immediately block the Account, terminate the Agreement and claim the contractual penalties set out in §11a; §12(3) and (4) apply accordingly.
§16. Profiling and Automated Decision-Making (Art. 22 GDPR)
-
The Platform performs two distinct kinds of profiling within the meaning of Art. 4(4) GDPR: (a) Analytical Models, which score business entities using their public financial data, and (b) Person Risk Indicators, which are derived indicators about identified natural persons — currently limited to a director-count pattern ("serial director" flag) and matches against sanctions/PEP lists — computed from Registry Data to support the User's own due-diligence and AML processes. Both are described in the Privacy Policy §4.
-
The Operator does not make decisions based solely on automated processing (including profiling) producing legal effects or similarly significantly affecting natural persons (Art. 22(1) GDPR), whether through Analytical Models or Person Risk Indicators.
-
Profiling results — of either kind — are provided to Users solely as a decision-support tool. All decisions are made by the User with human involvement, and never by the Operator. Users may never use Person Risk Indicators as the sole or decisive basis for a decision about the individual concerned (§11(n), §12a(6)).
-
Individuals subject to profiling have the right to: (a) information about the logic of profiling (Art. 15(1)(h) GDPR), (b) object to profiling (Art. 21 GDPR), (c) human review and expression of their position, (d) rectification where a Person Risk Indicator is based on inaccurate data (Art. 16 GDPR). Requests: help@monodat.com.
§17. Limitation of Liability
-
The Operator's total liability — regardless of the legal basis of the claim, whether contractual, tortious (including negligence) or otherwise — is limited to subscription fees paid by the User in the 3 months immediately preceding the event giving rise to the claim.
-
The Operator is not liable for: (a) indirect, consequential damages, lost profits, contracts, data or reputation, (b) User decisions based on Platform data, (c) technical interruptions, failures, force majeure (§18), (d) registry-side data availability changes, (e) User's violations of the Terms, (f) cyberattacks on third-party infrastructure.
-
These limitations do not apply to intentional damages or where limitation is not permitted under mandatory law.
-
Paragraphs 1-3 govern the Operator's liability to the User only. They do not limit, and are not to be read against, the User's indemnification obligations to the Operator under §12(4), §12b, or any other provision of these Terms — those obligations are uncapped, save to the extent mandatory law requires otherwise.
§17a. Backups and Data Loss
-
The Operator performs regular infrastructure backups but does not guarantee full recovery of all data in all circumstances.
-
The User exports and archives reports, watchlists and other data relevant to them at their own responsibility.
-
The Operator's liability for data loss is limited to reasonable efforts to restore data from the last available backup, subject to the limitations in §17.
§18. Force Majeure
-
The Operator is not liable for non-performance due to force majeure, including: (a) natural disasters, fires, floods, earthquakes, (b) war, terrorism, riots, general strikes, (c) cyberattacks on third-party infrastructure, (d) actions by public authorities preventing Service provision, (e) closure or restricted access to public registries serving as data sources, (f) widespread Internet, power or telecommunications infrastructure failures, (g) pandemics and epidemiological events.
-
The Operator informs Users during force majeure events and takes reasonable steps to restore Services.
-
If force majeure continues for more than 30 days, either party may terminate the Agreement without liability.
§19. Beta and Experimental Features
-
Features marked "beta", "experimental" or "early access": (a) are provided "as is" without warranty, (b) may contain bugs or instabilities, (c) may be discontinued without notice, (d) are not subject to SLAs or availability commitments.
-
Use of beta features is voluntary and at the User's sole risk.
§19a. Changes to Platform Functionality
-
The Operator may at any time develop, modify, add and withdraw Platform features and data sources.
-
A material reduction of functionality covered by a paid Subscription Plan requires 30 days' notice; a User who does not accept the change may terminate the Agreement effective at the end of the paid period.
-
Withdrawal or limitation of a data source caused by changes on the side of public registries, legal changes or changes in access conditions to source data does not constitute a Service defect or non-performance of the Agreement.
§20. Intellectual Property and Trade Secrets
-
All rights to the Platform (software, architecture, interface, Analytical Models, algorithms, methodologies, content) belong to the Operator or licensors.
-
Analytical Models, scoring algorithms, predictive methodologies, model weights and tuning parameters constitute trade secrets of the Operator under the Polish Act on Combating Unfair Competition of 16 April 1993. Attempts at reverse engineering, extraction or replication are prohibited and may result in criminal liability.
-
Registry Data is public, but its aggregation, analysis, enrichment, presentation and visualisation by the Platform constitute a copyrighted work.
-
The User obtains a limited, non-exclusive, non-transferable, revocable licence to use the Platform solely for own professional purposes during the Agreement.
-
Generated reports may be used internally. Public distribution requires written consent.
-
"MONODAT" name, logo and trademarks are the Operator's property.
-
The Platform's database is protected sui generis under the Polish Act of 27 July 2001 on the Protection of Databases and Directive 96/9/EC. Extraction or re-utilisation of a substantial part of the database without the Operator's consent is prohibited.
-
By providing feedback, suggestions or improvement proposals, the User consents to their free use by the Operator without time or territorial limitations.
§20a. Data Marking and Traceability
-
The Operator reserves the right for data, reports, exports (PDF, CSV) and API responses provided on the Platform to contain unique, non-removable identifying markers (including watermarks, Account identifiers embedded in the content, deliberately inserted canary records and other marking techniques) enabling the source to be established in the event of unauthorised disclosure, resale or publication.
-
Removing, modifying or circumventing the markers referred to in paragraph 1 constitutes a breach of §11(e) and is subject to a contractual penalty under §11a.
-
The presence, in the User's dataset, of canary records originating from the Platform constitutes a factual presumption that the dataset was obtained from the Platform.
-
This paragraph constitutes performance of the Operator's duty to inform — the User is hereby notified of the use of the techniques described and accepts them by entering into the Agreement.
§20b. Confidentiality
-
Each party undertakes to keep confidential any non-public information it obtains about the other party in connection with the Agreement ("Confidential Information"), and to use it solely to perform the Agreement.
-
For the Operator, Confidential Information includes in particular the source code, Analytical Models, scoring methodologies and infrastructure architecture (see §20(2)). For the User, Confidential Information includes non-public information about the User's own business that the Operator becomes aware of through the provision of Services.
-
Confidential Information does not include information that: (a) is or becomes public through no breach of this clause, (b) was already known to the receiving party without a confidentiality obligation, (c) is independently developed without use of the other party's Confidential Information, or (d) must be disclosed under a legally binding order of a court or authority — in which case the disclosing party, to the extent legally permitted, notifies the other party beforehand.
-
This clause does not limit the Operator's rights under §11b (investigation of suspected AUP breaches) or its ability to disclose information to advisers, auditors, insurers, successors under §30, or as necessary to enforce these Terms.
§21. Personal Data Protection
Personal data processing rules are set out in the Privacy Policy and Cookie Policy, forming an integral part of the Terms.
§22. Exclusion of Statutory Warranty
-
The parties exclude the application of statutory warranty provisions (Art. 558 § 1 of the Polish Civil Code) to the fullest extent permitted by law.
-
Services are provided "as is". The Operator makes no implied warranties of fitness for a particular purpose, data accuracy or uninterrupted availability.
-
This provision does not exclude liability for intentional damages.
§22a. No Reliance
The User confirms that, in entering into the Agreement, it has not relied on any representation, warranty, projection or statement not expressly set out in these Terms, the Privacy Policy, the Cookie Policy or (if concluded) the DPA, including any statement made during a sales conversation, demonstration or marketing communication. Nothing in this clause excludes liability for fraud or intentional misrepresentation.
§23. Special Provisions for Sole Traders (Art. 38a Polish Consumer Rights Act)
-
If the User is a natural person operating a sole proprietorship for whom the Agreement does not have a professional character (under their CEIDG-registered scope of activity), selected consumer protection provisions apply under Art. 38a of the Polish Consumer Rights Act.
-
Such Users have the right to withdraw from the Agreement within 14 days of its conclusion, without reason.
-
The right of withdrawal does not apply to digital services where performance has commenced before the 14-day period expires with the User's express consent, after being informed of the loss of the right of withdrawal.
-
During registration, the User gives express consent to commencement of Service provision before the withdrawal period expires and acknowledges loss of withdrawal right upon full performance of the Service for the relevant period.
§24. Complaints Procedure
-
Complaints: help@monodat.com, subject: "MONODAT Complaint – [Company Name]".
-
A complaint must contain: User data, Account email, problem description, date of occurrence.
-
The Operator responds within 14 calendar days of receipt.
-
If the complaint is rejected, the User retains the right to pursue claims in court.
§25. Illegal Content Notice and Action (DSA)
-
Pursuant to Art. 16 DSA, any person may notify the Operator of allegedly illegal content on the Platform.
-
Notices: help@monodat.com, subject: "DSA – Illegal Content Notice".
-
The notice should contain: (a) justification of illegality, (b) precise location (URL), (c) submitter's contact details (except for content related to offences under Articles 3-7 of Directive 2011/93/EU), (d) good faith statement.
-
The Operator confirms receipt and takes a decision without undue delay, with due diligence and objectivity.
-
The Operator informs the submitter and, where possible, the affected party, of the decision with reasoning and information about remedies.
§26. Termination
-
The User may terminate at any time by cancelling the subscription, effective at the end of the current billing period.
-
The Operator may terminate with immediate effect for material breach (especially §11, §12, §13).
-
The Operator may terminate with 30 days' notice for valid reasons (cessation of business, legal changes, data availability changes).
-
Upon termination, the Account is deactivated. Data is retained per the Privacy Policy and legal obligations.
§26a. Data Export After Termination
-
For 30 days following termination or cancellation of the Agreement (excluding termination under §26(2) for material breach involving unlawful use of data, where the Operator may restrict export), the User may request an export of its own Account data (reports, watchlists, saved searches, API call history) in a structured, commonly used format.
-
After this period, the data is deleted or anonymised in accordance with the retention periods set out in the Privacy Policy. The Operator is not liable for data no longer available after the export window has elapsed.
§27. Inactive Accounts
-
Accounts inactive (no login) for more than 12 months may be suspended after 30 days' email notice.
-
Subscription remains active until cancelled, regardless of Account activity.
-
After suspension, data is retained per Privacy Policy periods.
§28. Amendments
-
The Operator may amend the Terms for valid legal, technological or business reasons.
-
Changes are notified at least 14 days in advance by email and in-Platform notice, including a summary of changes.
-
Continued use after the effective date constitutes acceptance. Non-acceptance entitles termination without charges.
-
The Operator maintains version history with effective dates.
§29. Communications
-
Primary communication channel: the email address linked to the Account. Users must keep their email current and check correspondence regularly.
-
Notices are deemed effective within 24 hours of sending, regardless of actual receipt.
-
Correspondence to the Operator: help@monodat.com or the registered address specified in §1(2).
§29a. No Third-Party Beneficiaries
Except as expressly stated, the Agreement does not confer any right or benefit on any person who is not a party to it, including individuals whose data is displayed on the Platform. This clause does not affect statutory rights that such individuals hold directly against the Operator under GDPR or other mandatory law, which exist independently of the Agreement.
§30. Assignment
-
The User may not assign rights/obligations without the Operator's written consent.
-
The Operator may assign rights/obligations to a successor entity (sale, merger, division) with 30 days' notice. Users objecting may terminate.
§31. Survival
The following provisions survive termination, to the extent and for the time necessary:
- §11–§11a (AUP and contractual penalties — with respect to breaches committed during the term and to the continuing prohibition on using data obtained during that term),
- §12–§12a (User indemnification, nature of the Service),
- §14–§17b (disclaimers and limitations),
- §20–§20b (IP, trade secrets, data marking, confidentiality),
- §21 (data protection),
- §22a (no reliance),
- §26a (data export window),
- §29a (no third-party beneficiaries),
- §31 (survival),
- §33 (final provisions).
§32. Entire Agreement
These Terms, together with the Privacy Policy, Cookie Policy and (if signed) the DPA constitute the entire agreement between the Parties and supersede all prior arrangements, whether oral or written.
§33. Final Provisions
-
Governing law: Polish law.
-
Disputes are resolved by the court with jurisdiction over the Operator's seat (Kraków, Poland).
-
The Parties will attempt amicable resolution before judicial proceedings.
-
Invalidity of any provision does not affect the validity of others.
-
This version of the Terms (1.4.1) enters into force on the effective date shown in the document header.
-
Matters not regulated are governed by the Polish Civil Code, Act on Electronic Services, Telecommunications Law, GDPR, DSA, AI Act and applicable Polish and EU law.
-
The binding version of the Terms is the Polish version at https://monodat.com/terms. Other language versions are informational.
-
The Operator's failure to exercise, or delay in exercising, any right under these Terms does not constitute a waiver of that right.
-
Section headings are for convenience only and do not affect interpretation.
-
The User is solely responsible for verifying that its access to and use of the Platform complies with the law of every jurisdiction from which it accesses the Platform. The Operator makes no representation that the Platform is appropriate or lawfully available in any jurisdiction other than Poland.
-
Without prejudice to §8(9), any claim by the User against the Operator arising out of or in connection with the Agreement must be brought within one year of the date the User became aware, or ought reasonably to have become aware, of the facts giving rise to the claim, after which it is time-barred — except to the extent a shorter period would be contrary to mandatory law, in which case the statutory period applies.