1. Parties and business-only eligibility
Contracting provider and data controllerGökhan VodinaliGäbelbachstrasse 39, 3027 BernSwitzerland (CH)Legal form / registration: Individual operator; no commercial-register number providedsupport@hemelion.com“Provider,” “MandateShield,” “we” and “us” mean the operator identified above. “Customer” and “you” mean the organization named in the clickwrap record. The service is offered only for trade, business, craft or professional purposes. It is not offered for personal, family or household use. The person accepting must be at least 18 and authorized to bind Customer. Do not create an account or subscribe if either representation is untrue.
These Terms, the order shown at checkout, the Acceptable Use Policy, the Data Processing Addendum and the Privacy Policy form the agreement. Customer accepts through an unchecked, affirmative clickwrap. MandateShield retains the account, organization, versions, cryptographic agreement digest, time and pseudonymized request evidence.
2. Exact service boundary
MandateShield evaluates data supplied by Customer against deterministic controls and can return ALLOW, REVIEW or BLOCK, reserve a bounded execution authorization, issue provider-bound permits whose server-side state grants only one fresh claim, record lifecycle transitions and produce signed evidence. An ALLOW means only that the submitted fields passed the documented configured checks. It does not establish that omitted or false facts are true.
MandateShield is not a bank, payment institution, money transmitter, merchant of record, escrow service, card vault, identity provider, law firm, insurer, sanctions-screening service or general fraud guarantee. It does not hold funds or payment credentials and does not itself initiate a bank or card payment. Customer and its regulated providers remain responsible for the final execution decision and transaction.
The optional Deploy & Prove flow may complete privately after an authenticated account accepts the current legal documents, proves control of the selected HTTPS domain or public GitHub repository, and completes the bounded lifecycle. Creating or completing that private pilot does not direct publication and creates no public activation record. After private completion, Customer may separately request a time-limited public record by sending a fresh finalization request with publication_consent=true. That affirmative request directs MandateShield to publish the selected subject, the exact default-branch commit where applicable, bounded lifecycle identifiers, timestamps, cryptographic digests and the record's explicit assurance limits. Customer represents that it controls the selected subject and is authorized to direct that publication. Omitting or declining publication consent leaves the completion private. A published record is publicly retrievable for up to 180 days unless the operational account is deleted earlier. It never establishes customer status, revenue, payment submission, provider enforcement, certification, audit results or deployment security.
3. Customer responsibilities
Customer must configure correct mandates, limits, trusted keys, merchant and payee bindings, provider accounts, audiences, idempotency controls and retention settings; validate every integration before production; keep credentials outside models, browsers and untrusted agents; investigate REVIEW and BLOCK results; and maintain independent stop, reconciliation and recovery controls.
Customer is solely responsible for lawful authority and consent, accuracy of submitted data, sanctions/export and anti-money- laundering controls applicable to it, consumer and employment law, tax, invoices, refunds, fulfillment, payment-provider rules and all notices to its users. Customer must not represent MandateShield as regulatory approval, insurance, certification or provider adoption.
Customer must keep the provider-bound processor-side integration separate from models, browsers and untrusted agents and require a fresh, exact permit claim before each provider submission. That claim is not proof of exactly-once provider delivery or execution. Customer must preserve provider idempotency, must not bypass provider binding, permit claiming or cumulative-budget limits, and must reconcile every unknown or conflicting execution outcome before retrying.
4. Data restrictions and security
Customer must not submit cardholder data, bank credentials, private keys, passwords, authentication secrets, children's data, special-category or highly sensitive personal data, or personal data unnecessary for the documented decision. Customer must promptly revoke exposed credentials, notify MandateShield through the published responsible-disclosure route and cooperate with containment. The security documentation describes controls, not a promise that incidents are impossible.
5. Fees, renewal, taxes and cancellation
Published paid plans renew monthly until cancelled. Checkout shows the selected base price, included decisions, metered overage rate, renewal interval and applicable taxes before purchase. Customer expressly accepts recurring subscription terms before a Checkout Session is created. Usage is measured from authenticated persisted decisions under the pricing methodology in effect when incurred.
Customer may cancel without contacting support through the Stripe billing portal in the dashboard. Cancellation normally takes effect at the end of the current paid period. Except where mandatory law requires otherwise, accrued charges and completed billing periods are non-refundable. Failed or disputed payments may pause new live verification while reconciliation and evidence-preserving actions remain available.
6. Availability, changes and beta standards
Public plans do not include an uptime SLA or service credits. Emergency changes may be made to contain abuse, security or regulatory risk. Material incompatible changes to a stable API will be versioned where reasonably practicable. Emerging protocol adapters may implement only the explicitly documented projection; references to AP2, TAP, UCP, x402, MPP, ACP, Stripe or other third parties do not imply sponsorship, partnership or certification.
7. Intellectual property and feedback
Each party retains its pre-existing rights. Subject to payment and these Terms, Customer receives a non-exclusive, non-transferable right to use the hosted service for its internal business and integrated customer workflows. Published open-source code is licensed only under the license accompanying that code. Third-party names remain their owners' marks. Customer grants MandateShield a perpetual, worldwide, royalty-free right to use feedback without identifying Customer or disclosing confidential information.
8. Confidentiality and data processing
Each party will protect the other's non-public business, technical and security information with reasonable care and use it only to perform the agreement. Duties do not apply to information already lawfully known, independently developed, public without breach or lawfully received from another source. Compelled disclosure is permitted after notice where legally allowed.
The DPA governs personal data processed by MandateShield on Customer's behalf. MandateShield may use aggregated or de-identified operational statistics that cannot reasonably identify Customer, an individual, a merchant or a transaction.
9. Suspension and termination
MandateShield may proportionately suspend affected credentials, endpoints or accounts to address a credible security incident, unlawful use, sanctions requirement, non-payment, material breach or risk to other customers. Where practicable, notice and an opportunity to cure will be provided. Either party may terminate for an uncured material breach. Sections intended by their nature to survive—including payment, confidentiality, liability, indemnity, evidence and dispute provisions—survive termination.
10. Warranties and disclaimers
Each party warrants that it has authority to enter the agreement. MandateShield warrants that it will provide the paid service substantially in accordance with its current documentation. As the exclusive remedy for a verified material breach of that warranty, MandateShield will use reasonable efforts to correct the service or terminate the affected subscription and refund prepaid fees for the unused affected period.
To the maximum extent permitted by law, all other warranties, conditions and representations are excluded, including implied merchantability, fitness for a particular purpose, non-infringement and uninterrupted or error-free operation. No output is legal, financial, compliance or investment advice, and no control makes a transaction, agent or counterparty inherently legitimate.
11. Allocation of liability
To the maximum extent permitted by applicable law, neither party is liable for indirect, incidental, special, exemplary, punitive or consequential damages, or lost profits, revenue, goodwill or data, arising from the agreement, even if advised of the possibility. MandateShield's aggregate liability arising from the service will not exceed the greater of $100 or fees paid by Customer for the affected service during the twelve months before the first event giving rise to liability.
These exclusions and cap do not apply where and to the extent prohibited by mandatory law, including liability that cannot be excluded for intent, gross negligence, death or personal injury, or a party's fraudulent conduct. Nothing limits Customer's payment obligations, misuse of credentials, infringement or violation of the data and acceptable-use restrictions.
12. Customer indemnity
To the extent permitted by law, Customer will defend and indemnify MandateShield and the operator against third-party claims caused by Customer's unlawful transaction, submitted content, violation of the Acceptable Use Policy, lack of mandate or consent, misuse of credentials, or representation that MandateShield provides a regulated or guaranteed service it does not provide. MandateShield must promptly notify Customer, allow Customer to control the defense, provide reasonable cooperation at Customer's cost and may reject a settlement that admits fault or imposes an obligation on MandateShield.
13. Governing law and disputes
The agreement is governed by the substantive laws of Switzerland, excluding conflict-of-law rules. The parties submit to the exclusive business-to-business venue of the ordinary courts at Bern, Switzerland, except that either party may seek urgent injunctive relief in any competent court and mandatory jurisdiction rules remain unaffected.
14. General
Neither party is liable for delay caused by events beyond its reasonable control, excluding payment obligations. Customer may not assign the agreement without consent, except with a bona fide merger or sale of substantially all relevant assets; MandateShield may assign it with the service or to an affiliate, subject to applicable data law. The agreement is the entire agreement and supersedes prior statements on its subject. Purchase-order boilerplate does not amend it. Invalid provisions are narrowed to the minimum necessary, and failure to enforce is not waiver.
Material adverse changes require notice and renewed acceptance or apply only at the next renewal where law requires. Security, regulatory or clarifying changes may take effect when posted. Electronic notices and records satisfy writing requirements to the extent permitted by law.
Terms 2026-07-28.2 · Privacy 2026-07-28.3 · DPA 2026-07-26 · AUP 2026-07-26