The agreement under which Deployed provides the composerID API, the reference sandbox and the developer portal. It covers eligibility, what you may and may not do, what the Service stores and sends, confidentiality, ownership, warranties and liability. A signed agreement with Deployed takes precedence over it.
These composerID API Terms (this “Agreement”) govern use of the Service (defined below) provided by Deployed, a company based in London, United Kingdom (“Deployed”), to the customer and its users (“Customer” or “you”).
By accepting this Agreement, whether by creating a developer account, by using an API key or client credentials, or by otherwise accessing the Service, Customer agrees to its terms. If Customer and Deployed have signed a written agreement governing Customer’s access to and use of composerID, that signed agreement governs and supersedes this Agreement.
If you do not accept this Agreement, do not access or use the Service. The Service is intended for Customer and its authorised users only and is not for use by anyone under 18 years of age. If an individual signs up using an email address from their employer or another organisation, or otherwise signs up for that organisation’s benefit, then (a) they are deemed to represent that organisation, (b) their acceptance binds it to this Agreement, and (c) “Customer” in this Agreement refers to it.
This Agreement is effective on the earlier of the date Customer accepts it and the date Customer first accesses or uses the Service (the “Start Date”). Deployed may modify this Agreement; a modification takes effect on the earlier of (i) 30 days after Deployed posts it and (ii) Customer’s continued use of the Service after posting. Material changes are noted in the changelog.
Certain capitalised terms are defined below; others are defined in the body of this Agreement.
You represent and warrant that you are at least 18 years of age, that you have not previously been suspended or removed from the Service, and that you have authority to bind Customer. To access the Service you register for an account and provide accurate information about yourself, which you will keep accurate and up to date. Accounts and API keys are personal to the individual they are issued to. You are responsible for the confidentiality of your credentials and for all activity that occurs under them. If you believe a credential is no longer secure, notify Deployed immediately at jamie.gannaway@deployed.co and rotate it.
Deployed grants Customer a non-exclusive, non-transferable, revocable right during the Term to access and use the Service, solely in accordance with the Documentation and this Agreement, for the purpose of evaluating composerID and of building and operating integrations between Triage and Customer’s Destinations.
Customer will not, and will not permit any User or third party to:
Each of (a) to (i) is a “Prohibited Use”.
Deployed will provide the Service in conformance with, and subject to, this Agreement and the Documentation. The Sandbox is a reference implementation: it runs over mock Destination tenants, carries no service level and may be reset at any time, and Deployed makes no commitment as to its availability. Service levels for the production service, once live, are set in the written agreement under which Customer purchases Triage.
Deployed will use commercially reasonable efforts to respond to Customer’s support requests about errors, bugs or other issues with the Service. Support requests go to jamie.gannaway@deployed.co. Support is included; there is no separate fee.
Deployed may update the Service and the Documentation. Changes that remove or alter a documented behaviour of a versioned API path are announced in the changelog before they take effect, with a deprecation period of at least 90 days for the production service. The Sandbox tracks the current contract and may change without notice.
Customer will use the Service only in accordance with the Documentation and all applicable laws, including data protection, employment and export control laws. Customer will not export, re-export or use the Service in breach of the export control or sanctions laws of the United Kingdom or any other applicable jurisdiction. Deployed may suspend use of the Service that breaches this Section on written notice, which may be by email.
Customer is responsible for holding, and complying with, the licences, API terms and tenant permissions of each Destination it connects. Deployed does not grant, and cannot grant, any right to use a Destination. Where a Destination licenses API access separately, obtaining that licence is Customer’s responsibility; the Documentation flags where this is known to apply.
Customer represents that it has all rights, permissions and consents necessary to submit Customer Data to the Service and to have it published into the Destinations it selects, and that doing so does not breach any law or any agreement with a third party.
Customer grants Deployed a limited, non-exclusive licence during the Term to process Customer Data to provide and maintain the Service, to publish into the Destinations Customer instructs, to derive Usage Data, and as otherwise instructed by Customer in writing. Deployed will not use Customer Data for any other purpose and will not use it to train generalised artificial intelligence or machine-learning models.
The Service stores Intent Records, their append-only timelines and the publishing receipts returned by Destinations, so that a publish is idempotent and the audit trail is complete. A Destination receives only a valid request plus the Intent ID; diagnostic answers, scores and the Compliance File never leave composerID. Each platform page in the Documentation lists what crosses the boundary and what is never sent, and Deployed will keep those lists true.
To the extent Customer Data includes personal data processed on Customer’s behalf, the Data Processing Agreement applies and is incorporated into this Agreement. Personal data about Users themselves (names, work email addresses) is handled as described in the Privacy Policy.
Deployed maintains appropriate physical, technical and organisational safeguards to protect Customer Data, as described in Annex II of the Data Processing Agreement. Authentication uses per-person API keys or short-lived, scoped client-credentials tokens; inbound webhooks are signature-verified; Destination credentials are never supplied by callers.
The “Term” of this Agreement starts on the Start Date and continues while Customer holds an active account or credential, unless terminated earlier: (a) by Customer at any time, by closing its account or notifying jamie.gannaway@deployed.co; or (b) by Deployed on 30 days’ written notice for convenience, or immediately on written notice if Customer commits a material breach that is incapable of remedy or is not remedied within 14 days of notice.
Without limiting Section 6.1, if Customer breaches this Agreement, or if Deployed reasonably believes Customer’s use threatens the security or integrity of the Service or of a Destination, Deployed may immediately suspend access until the issue is remedied, following written notice to Customer, which may be by email.
On termination or expiry, Customer’s rights under Section 2.2 end and Customer will stop using the Service. Within 30 days of a written request made at or after termination, Deployed will delete Customer Data in its possession, except for copies held in routine backups, which are deleted in the ordinary backup cycle, and records Deployed must retain by law. Sandbox data is deleted on reset regardless.
Sections 1, 5.2, 6.3, 6.4, 8, 9, 10.2, 11, 12 and 13 survive any termination or expiry of this Agreement.
Developer access and the Sandbox are provided without charge. composerID is sold with Triage and is not available as a separate purchase; fees for the production service are set in the written agreement under which Customer buys Triage, and that agreement governs invoicing, payment and taxes. Deployed may introduce fees or usage limits for the hosted Sandbox on 30 days’ notice.
Information of a confidential or proprietary nature disclosed by one party (the “Disclosing Party”) to the other (the “Receiving Party”) is the Disclosing Party’s “Confidential Information”. Deployed’s Confidential Information includes non-public aspects of the Service and information conveyed in support. Customer’s Confidential Information includes Customer Data. Confidential Information excludes information that: (a) the Receiving Party already knew without an obligation of confidentiality; (b) is or becomes public through no fault of the Receiving Party; (c) the Receiving Party rightfully receives from a third party without a confidentiality obligation; (d) is Feedback; or (e) the Receiving Party independently develops without using the Disclosing Party’s Confidential Information.
Each party will use the other’s Confidential Information only to perform this Agreement, will not disclose it to any third party except as this Agreement permits, and will protect it with at least the care it uses for its own confidential information and no less than reasonable care. The Receiving Party may share Confidential Information with its employees, agents, advisers and Affiliates who need to know it and are bound by confidentiality obligations at least as protective as these.
The Receiving Party may disclose Confidential Information where required by law, regulation or court order, provided that (where lawful) it gives the Disclosing Party prompt written notice so that the Disclosing Party can contest or limit the disclosure, discloses only what is legally required, and uses reasonable efforts to obtain confidential treatment for it.
As between the parties, Deployed owns and retains all right, title and interest in and to the Service, the Software, the Documentation, Usage Data and Feedback. Except for the right granted in Section 2.2, this Agreement transfers no rights in them to Customer. Source code Deployed publishes carries its own licence, which governs its reuse.
As between the parties, Customer owns and retains all right, title and interest in and to Customer Data. Records the Service creates inside a Destination belong to whoever owns that Destination tenant under its own terms. Except for the licence in Section 5.1, this Agreement transfers no rights in Customer Data to Deployed.
Customer may give Deployed comments, suggestions or recommendations about the Service (“Feedback”). Deployed may use Feedback freely and without obligation to Customer, and Customer assigns to Deployed any rights it may have in Feedback. Feedback never includes Customer Data.
Each party represents and warrants that it has validly entered into this Agreement and has the legal power to do so. Customer further represents and warrants that it has and will maintain the rights, permissions and consents described in Section 4.3, and that it will use the Service in compliance with applicable law and the terms of each Destination it connects.
Except as expressly set out in this Agreement, the Service is provided “as is” to the fullest extent permitted by law. Deployed and its licensors exclude all other warranties, conditions and terms, express or implied, including any implied terms of satisfactory quality, fitness for a particular purpose and non-infringement. Deployed does not warrant that the Service will be error-free or uninterrupted, that it will maintain a connection to any particular Destination, that Destination documentation cited in the Documentation reflects that vendor’s current product, or that the Service will meet Customer’s requirements. The Sandbox in particular is provided for evaluation and testing only.
Customer will defend Deployed and its Affiliates, and their officers, directors, employees and agents (the “Deployed Indemnified Parties”), against any third-party claim, demand, suit or proceeding, and will indemnify the Deployed Indemnified Parties against any related losses, liabilities, damages, costs and expenses (including reasonable legal fees) finally awarded or agreed in settlement, to the extent arising from: (a) a Prohibited Use by Customer or a User; (b) Customer’s breach of Section 4 (Customer’s obligations); or (c) an allegation that Customer Data, or Deployed’s processing of it as instructed by Customer, infringes a third party’s rights or breaches applicable law. Deployed will notify Customer promptly of any such claim, give Customer control of its defence and settlement (provided no settlement admits fault or imposes obligations on Deployed without Deployed’s consent), and cooperate at Customer’s expense.
12.1 Nothing in this Agreement limits or excludes either party’s liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for any liability that cannot be limited or excluded under the law of England and Wales.
12.2 Subject to Section 12.1, neither party, nor its Affiliates, nor the officers, directors, employees, shareholders or representatives of any of them, will be liable to the other for any indirect, special, incidental or consequential loss or damage, or for any loss of profit, revenue, business, goodwill, data or anticipated savings, arising out of or in connection with this Agreement, however caused and whether in contract, tort (including negligence), breach of statutory duty or otherwise, even if the other party was told of the possibility.
12.3 Subject to Sections 12.1, 12.4 and 12.5, each party’s total aggregate liability arising out of or in connection with this Agreement, however arising, will not exceed the greater of (a) the fees paid by Customer to Deployed for the Service in the 12 months immediately preceding the event giving rise to the claim and (b) one hundred pounds sterling (£100). Where the Service is provided without charge, (b) applies.
12.4 “Excluded Claims” means claims arising from Deployed’s breach of Section 5.4 (Security). Deployed’s total aggregate liability for Excluded Claims will not exceed two times the amount in Section 12.3.
12.5 “Uncapped Claims” means claims arising from (a) either party’s breach of Section 8 (Confidentiality), other than a security breach which remains subject to Section 12.4; (b) Customer’s indemnification obligations under Section 11; or (c) a party’s gross negligence or wilful misconduct. Sections 12.3 and 12.4 do not apply to Uncapped Claims.
12.6 The existence of more than one claim does not enlarge the limits in this Section 12.
This Agreement, with the documents it incorporates, is the entire agreement between Customer and Deployed about its subject matter and supersedes all prior agreements and understandings about it. The parties are independent contractors; this Agreement creates no partnership, joint venture or agency. Failure to exercise a right is not a waiver of it. A person who is not a party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term. Notices under this Agreement must be in writing and may be given by email: to Deployed at jamie.gannaway@deployed.co, and to Customer at the email address on its account. If any provision is found unenforceable it will be enforced to the maximum extent permissible and the rest of this Agreement will remain in force. Neither party may assign this Agreement without the other’s prior written consent, except to a successor in connection with a merger, acquisition or sale of all or substantially all of its assets, on written notice. Deployed may identify Customer as a composerID customer, by name and logo, only with Customer’s prior written consent.
This Agreement is governed by the laws of England and Wales, without regard to conflict-of-laws rules. If a dispute cannot be settled by the parties within 30 days of written notice of it from one party to the other, either party may refer it to mediation under the CEDR Model Mediation Procedure before commencing proceedings, save that either party may at any time seek injunctive or other equitable relief to protect its intellectual property or Confidential Information. Subject to that, the courts of England and Wales have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement.