Access by Approval
Access is defined for an approved integration, including the interfaces, permissions, and usage limits that apply.
These terms govern approved access to EMPHOS Group APIs and developer resources, including permitted integrations, credential security, data handling, and usage limits.
Access is defined for an approved integration, including the interfaces, permissions, and usage limits that apply.
Protect secret credentials, limit access to authorized personnel, and report suspected compromise promptly.
Use only approved functionality and data, follow the assigned limits, and protect the information your application handles.
Access may be restricted or withdrawn for misuse, security risks, or other grounds in the applicable agreement.
Overview
These API Terms of Use (“API Terms”) govern the application programming interfaces, developer tools, software development kits (SDKs), documentation, sample code, and related resources that EMPHOS Group Corporation (“EMPHOS Group,” “we,” “us,” or “our”) expressly makes available to you for an approved integration (collectively, the “API”).
By accessing or using the API, you (“Developer” or “you”) agree to be bound by these API Terms, our Terms of Service, Privacy Policy, and all other applicable EMPHOS Group policies. If you are using the API on behalf of an organization, you represent and warrant that you have the authority to bind that organization to these API Terms.
If you do not agree to these API Terms, do not access or use the API. A signed API, licensing, or integration agreement takes precedence over these API Terms to the extent of a conflict for the integration it covers. Any applicable fees, service levels, production access, or additional data-processing obligations must be set out in that agreement or otherwise agreed with you in writing.
Section 1
To discuss API access, email info@emphosgroup.com with the product or interface you want to integrate, your intended use case, the application you plan to build, and your technical contact details. Access requires our approval and is limited to the interfaces, environments, permissions, and purposes we authorize in writing. We may approve or decline a request.
The approved integration documentation or agreement will identify the authentication method and any keys, tokens, client secrets, or other credentials provided for your use (“API Credentials”). Use credentials only for the authorized application and environment. Keep secret credentials confidential and control access by the personnel and service providers you authorize.
| Requirement | Developer Obligation |
|---|---|
| Confidentiality | Limit access to authorized personnel and service providers working on the approved integration. Do not sell, publish, or share credentials with unauthorized parties. |
| Secure Storage | Protect secret credentials in storage and transit. Keep them out of public repositories, browser or other public client code, and application logs. Follow the approved authentication flow. |
| Incident Reporting | Notify EMPHOS Group promptly of suspected compromise and take reasonable steps to contain it. Do not include live secrets in an email report. |
| Credential Control | EMPHOS Group may restrict, revoke, or rotate credentials to address suspected misuse or security risks, consistent with the applicable agreement. |
Section 2
Once access is approved, and subject to these API Terms and the applicable agreement, we grant you a limited, non-exclusive, non-transferable, revocable licence to use the API to build, test, and operate the approved application or integration (“Application”). Internal business use and customer-facing use are permitted within the approved scope. Any separately identified licence for an SDK, sample, or third-party component also applies.
Purchasing or using an EMPHOS product does not by itself authorize access to private APIs. Activation, licensing, checkout, account, and other private interfaces may be used only through authorized software or an expressly approved integration.
Section 3
You must not use the API to:
Section 4
Rate limits and usage quotas are defined in the documentation or agreement for your approved access. Requests exceeding those limits may be throttled or rejected. Repeated abuse or attempts to evade limits may lead to suspension under Section 8. Follow documented retry instructions and contact us before increasing usage beyond the approved limits. Changes to limits will be handled under the applicable agreement.
Section 5
Handle personal and confidential information in accordance with applicable law, the approved integration scope, the relevant privacy notices, and any data-processing agreement between you and EMPHOS Group. Obtain the permissions or other lawful authority required to provide data to the API and to process any data returned through it.
You must:
Section 6
You are responsible for developing, maintaining, and securing your Application, for the activity you authorize through it, and for compliance with applicable law and these API Terms.
Your Application must:
Section 7
We may modify, update, deprecate, or discontinue an API or feature in accordance with the applicable agreement. Where reasonably practicable, we will provide at least 30 days' advance notice of breaking changes or deprecation. Urgent security, legal, or service-integrity changes may require shorter notice. Any separately agreed notice period or service commitment takes precedence. You are responsible for adapting your Application to supported interfaces.
Revisions to these API Terms will be posted on this page with an updated date. Notice of material changes, when they take effect, and any required acceptance will follow the applicable agreement and law.
Section 8
We may restrict, suspend, or terminate API access for a breach of these API Terms or the applicable agreement, or to address security risks, abuse, or a legal requirement. We may act immediately when needed to protect systems or data. Otherwise, notice and any opportunity to remedy a breach will follow the applicable agreement and law.
You may terminate your API access at any time by ceasing use of the API and notifying us at info@emphosgroup.com, subject to any separate contractual obligations. Stop making API calls and stop using the affected credentials when access ends. Return or delete API-provided data as required by the applicable agreement and law. Termination does not transfer ownership of your source content or require deletion of material you are independently entitled or legally required to retain. Any refund, payment, retention, or transition obligations remain governed by the applicable agreement and law.
Section 9
EXCEPT AS EXPRESSLY PROVIDED IN A SIGNED AGREEMENT, AND TO THE EXTENT PERMITTED BY APPLICABLE LAW, THE API IS PROVIDED “AS IS” AND “AS AVAILABLE.” EMPHOS GROUP DISCLAIMS WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
TO THE EXTENT PERMITTED BY APPLICABLE LAW, AND SUBJECT TO ANY SIGNED AGREEMENT, EMPHOS GROUP IS NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATING TO YOUR USE OF THE API.
Nothing in these API Terms excludes or limits a warranty, right, remedy, or liability that cannot lawfully be excluded or limited.
Section 10
For API access requests, technical questions, or to report API misuse, please contact us:
EMPHOS Group Corporation
9398 Coote Street, Chilliwack, BC, V2P 6B5, Canada
info@emphosgroup.com
Please include “API INQUIRY” in the subject line of your message.
Tell us which product or interface you want to work with, what you plan to build, and how to reach your technical contact.