Privacy and Security
API AND MCP TOOLS TERMS AND CONDITIONS
These terms govern Customer's use of the RainFocus application programming interfaces ("APIs") and Model Context Protocol tools ("MCP Tools") (collectively, "Developer Tools") under the applicable statement of work ("SOW"). These terms supplement the parties' existing agreement for the RainFocus platform (the "Agreement"). In the event of conflict, these terms control with respect to the Developer Tools.
1.LICENSE AND MONITORING
Subject to Customer's compliance with these terms and the Agreement, RainFocus grants Customer a non-exclusive, non-transferable, revocable, limited license to access and use the Developer Tools solely to integrate with the RainFocus platform for Customer's internal business purposes, subject to any limitations RainFocus may impose.
RainFocus may monitor Developer Tools usage to maintain platform performance, resolve technical issues, and ensure platform security. Such monitoring is limited to system-level metrics, error logs, and usage patterns, and any Customer data encountered will be handled in accordance with the Agreement.
2. CUSTOMER RESPONSIBILITIES
Customer is responsible for:
- maintaining the confidentiality of all API keys, MCP credentials, tokens, and endpoints;
- all activity conducted through its credentials, MCP connections, AI tools, agents, applications, and connected systems;
- protecting personal data collected through the Developer Tools from unauthorized access or use using reasonable administrative, technical, and organizational safeguards;
- promptly notifying RainFocus of any actual or suspected unauthorized access, credential compromise, or security issue involving the Developer Tools;
- ensuring that its employees, contractors, vendors, AI tools, agents, and connected systems use the Developer Tools only as authorized;
- using the Developer Tools only with data that Customer is authorized to access, process, transmit, and use; and
- complying with all applicable laws, regulations, third-party terms, privacy notices, and consents.
3. RESTRICTIONS
Customer will not, and will not permit any person or system to:
- use the Developer Tools for any purpose other than as authorized in Section 1;
- reverse engineer, decompile, or create derivative works of the Developer Tools, or use them to develop a competing product or service;
- bypass or circumvent usage limits, rate limits, authentication, or security controls; conduct penetration testing or vulnerability scanning without RainFocus's prior written approval; or use the Developer Tools in a way that disrupts or degrades the RainFocus platform or any other customer's use;
- scrape, harvest, or extract data other than Customer Data (as defined in the Agreement); introduce malware or prompt injection payloads; or use RainFocus confidential information or non-public technical information to train or improve any AI model without RainFocus's prior written approval;
- share, distribute, or expose API keys, MCP credentials, tokens, or endpoints to any unauthorized person or system; publish or disclose performance benchmarks, latency data, or uptime metrics without RainFocus's prior written approval; or sublicense, resell, or make the Developer Tools available to any third party other than Customer's authorized users; or
- use the Developer Tools for unlawful, harmful, deceptive, or unauthorized purposes, or knowingly enable end users to violate applicable law, regulation, or these terms.
4. DATA AND AI TOOLS
Customer is solely responsible for its AI tools, agents, prompts, outputs, workflows, and connected systems, including independently validating all outputs and results before relying on them. RainFocus is not responsible for any outputs, actions, or decisions generated by Customer's AI tools or automated workflows. Customer will not process personal data through any AI tool or third-party integration unless Customer has all required rights, consents, and contractual protections.
5. INTELLECTUAL PROPERTY
All right, title, and interest in the Developer Tools and related intellectual property remain the exclusive property of RainFocus. No rights are granted except as expressly stated in these terms or the Agreement. RainFocus does not acquire ownership in Customer's applications. Certain components of the Developer Tools may be subject to open-source licenses, which will govern solely with respect to those components to the extent they expressly supersede these terms.
6. MODIFICATIONS AND SUSPENSION
RainFocus may modify, update, or discontinue the Developer Tools at any time. RainFocus may suspend or terminate Customer's access immediately if Customer's use creates a security, legal, or platform risk. RainFocus will provide reasonable notice of material changes when practicable.
7. WARRANTIES
EXCEPT AS EXPRESSLY SET FORTH IN THE AGREEMENT, THE DEVELOPER TOOLS ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.
8. LIABILITY; INDEMNIFICATION
Customer's use of the Developer Tools is at Customer's sole discretion. Customer is solely responsible for all inputs submitted to and outputs received through the Developer Tools, and for any decisions or actions taken in reliance on them.
Without limiting any indemnification obligations under the Agreement, Customer will indemnify, defend, and hold RainFocus harmless from any claims arising out of Customer's misuse of the Developer Tools or breach of these terms.
9. TERM AND SURVIVAL
These terms are effective upon execution of the SOW to which they are incorporated and will remain in effect for the duration of the applicable SOW; provided, however, that Sections 5, 7, and 8 will survive expiration or termination of these terms and the applicable SOW.
Upon expiration or termination, Customer will immediately cease use of the Developer Tools, disconnect any AI tools, AI agents, applications, and connected systems from the Developer Tools, and destroy all copies of API keys, MCP credentials, tokens, and cached API responses in its possession or control.