# Terms of Service

> The rules for using the HyperJobs API, including what you may do with the data you retrieve and what you may not.

Source: https://hyperjobs.io/legal/terms

These terms are the contract between you and us for the HyperJobs API. They cover
what you may do with the data you retrieve, what we promise about it, and what
happens when either side wants to stop.

## 1. Scope and acceptance

You accept these terms when you create an account or call the API, whichever
happens first. If you are agreeing on behalf of a company, you confirm you can
bind that company, and "you" means that company.

This is a business product. It is sold to businesses and developers, and it is
not designed or marketed for personal or household use. If you are a consumer,
sections 15, 16 and 19 leave your statutory rights intact — see also the
[Refund Policy](/legal/refund).

These terms incorporate the [Privacy Policy](/legal/privacy), the
[Cookie Policy](/legal/cookies), and the [Refund Policy](/legal/refund).

## 2. The service

HyperJobs is a read-only HTTP API over a dataset of job postings collected from
employers' public applicant-tracking boards — Greenhouse, Lever, Ashby, Workday,
SmartRecruiters and others — enriched with fields such as skills, seniority,
salary and location, and joined to company firmographics.

The API is served from `https://api.hyperjobs.io/v1`. Every endpoint is a `GET`.
There are no write endpoints, no webhooks, and no job-application feature: we do
not accept CVs, host candidate profiles, or send applications anywhere.

We may change, add, or remove endpoints and fields. Breaking changes ship as a
new version path rather than by altering `/v1` underneath you. See the
[documentation](/docs) for the current surface.

## 3. Accounts

You need an account to get a key. You must give an accurate email address, keep
it current, and keep your credentials to yourself. Accounts are per organisation,
not per person you wish to share one login with.

We block disposable email domains at signup and limit how many accounts may be
created from one IP address in a given window. These are anti-abuse controls, not
a judgement about you; if a legitimate signup is caught by them, contact
<Email kind="support" subject="Signup blocked" />.

You must be 16 or older to hold an account.

## 4. API keys

Keys carry the prefix `hj_live_` and are sent as `Authorization: Bearer <key>`.
Each key grants the `jobs:read` scope. You may hold up to 10 active keys per
account.

We show a key's full value once, at creation, and never again. We store only a
SHA-256 hash of it plus a short prefix for display. We cannot recover a lost key
and we will never ask you for one.

Keys are your responsibility. Anything done with your key is treated as done by
you, and you are liable for it. Do not commit keys to repositories, embed them in
client-side code, or paste them into support tickets. If a key leaks, revoke it
in the dashboard and create a new one. See
[Authentication](/docs/authentication).

## 5. Licence and permitted use

For as long as your account is in good standing and your fees are paid, we grant
you a non-exclusive, non-transferable, non-sublicensable, worldwide licence to
access the API and to use, copy, store, modify and combine the data it returns
for your own internal business purposes and inside your own products and
services.

That licence is deliberately broad on the output side. You may:

- Store retrieved data in your own systems and keep it synced.
- Enrich it, transform it, and combine it with your own data.
- Show it to your users inside your product, including a product you charge for.
- Build analyses, models, dashboards, and reports on top of it.
- Show it to your clients as part of a service you deliver.

The line is not "you may not make money from this". It is that you may not turn
around and become a source of the dataset itself. Section 6 says what that means.

## 6. Restrictions

You may not:

- **Resell or redistribute the dataset as a dataset.** Do not sell, licence,
  publish, or otherwise supply the postings we return — in bulk, as a feed, as a
  file, as a database, or through an API of your own — as a substitute for
  someone else buying access from us. Data surfaced inside a product that does
  something with it is fine; a pipe from us to a third party is not.
- **Build a competing jobs dataset for resale.** You may not use the API, or
  data from it, to assemble a jobs-data product that you offer to others in place
  of ours.
- **Systematically reconstruct the corpus.** Do not enumerate, crawl, or page
  through the API for the purpose of extracting the full dataset or a substantial
  part of it, as opposed to retrieving the data your use case actually needs.
- **Circumvent quotas or rate limits.** Do not run multiple accounts to multiply
  a quota, share keys across organisations, rotate IPs to dodge limits, or
  otherwise engineer around the limits on your plan. If you need more, buy more —
  see [Pricing](/pricing) — or talk to us.
- **Remove or obscure attribution** where you are required to keep it, or
  misrepresent the data's origin.
- **Reverse-engineer** the API, its classifiers, or its ranking beyond what
  mandatory law permits.

If you are unsure which side of this line your use case falls on, ask before you
build. [Data licensing](/help/data-licensing) covers the common cases, and we
would much rather answer the question early than have this conversation later.

## 7. Acceptable use

We do not maintain a separate acceptable use policy; this section is it.

You may not use the API:

- To break the law, or to help anyone else break it.
- To discriminate unlawfully against people, including by using enrichment
  fields to screen or target individuals on protected characteristics.
- To send unsolicited bulk email or messages in breach of applicable marketing
  or privacy law. Company data in the dataset is not a licence to spam.
- To identify, profile, track, or build a dossier on any individual person.
- To attack, probe, overload, or interfere with the API, our infrastructure, or
  anyone else's — including denial-of-service attempts and vulnerability testing
  you have not agreed with us first.
- To introduce malware, or to use the service to distribute it.
- To infringe anyone's intellectual property, privacy, or confidentiality.

Security testing requires written permission in advance. To report a
vulnerability you have found, contact <Email kind="security" subject="Vulnerability report" />
and give us reasonable time to fix it before disclosing.

## 8. Plans, quotas, and rate limits

Each plan carries a monthly request quota and a per-minute rate limit:

| Plan | Price | Requests per calendar month | Rate limit |
| --- | --- | --- | --- |
| Free | $0 | 500 | 10 req/min |
| Starter | $49/mo | 50,000 | 60 req/min |
| Growth | $199/mo | 500,000 | 300 req/min |
| Scale | $499/mo | 5,000,000 | 1,000 req/min |

Where a plan is offered on yearly billing, the yearly price is ten times the
monthly price — two months free.

<Note>
  Quotas and rate limits apply to your **account**, not to each key. Ten keys do
  not get you ten quotas; they share one. Quotas reset on the first day of each
  calendar month.
</Note>

Exceeding the rate limit returns `429`. Exhausting your monthly quota stops
further requests until the quota resets or you upgrade. Neither is a breach of
these terms — they are the service working as designed — but persistently
hammering a limit rather than pacing your client is a breach of section 7. See
[Rate limits](/docs/rate-limits).

We may apply higher limits to your account by agreement. Those overrides are
discretionary and we can withdraw them on notice.

## 9. Fees, taxes, and renewal

Paid plans are billed in advance through Stripe for the billing period you pick
at checkout. Prices are in US dollars.

Subscriptions renew automatically for another period at the then-current price
until cancelled. You cancel through the Stripe customer portal, reachable from
your settings page. Cancellation takes effect at the end of the period you have
already paid for, and your access continues until then.

Prices exclude VAT and any other transaction taxes. You are responsible for such
taxes where they are due on your purchase; we are responsible for tax on our own
income. Where a reverse charge applies to a supply to a business in another EU
member state, it applies on the usual conditions. Our VAT number is in section 20.

If a payment fails, we may retry it and may suspend access until it clears. We
may change prices for future periods with at least 30 days' notice; the change
takes effect at your next renewal, and cancelling before then avoids it.

Refunds are covered by the [Refund Policy](/legal/refund).

## 10. Suspension and termination

You can stop whenever you like: cancel in the Stripe customer portal, or simply
stop calling the API.

We may suspend or terminate your access if you break these terms, if your
payment fails and stays unpaid, if your use threatens the stability or security
of the service, or if we are required to by law. Where the circumstances allow
it, we will warn you first and give you a chance to fix the problem. Where they
do not — an active attack, a legal order, a serious breach of section 7 — we may
act immediately.

On termination, your licence under section 5 ends and you must stop calling the
API. Data you already retrieved and stored may stay in your systems, and you may
keep using it under section 5 for the purposes you were already using it for,
except where we terminated you for a breach of section 6, in which case you must
delete it. Sections 11 to 20 survive termination.

Deleting your account is covered in [Deleting your account](/help/delete-account).

## 11. Data accuracy

Read this section carefully; it describes what the dataset actually is.

Postings are **mirrored from third-party boards**. We collect what an employer
published on its own careers board and reflect it. We do not verify that a
posting is genuine, current, lawful, or that the job exists. Postings go stale,
get taken down, and get reposted, and we track those boards on a delay.

Enrichment fields — including `skills`, `seniority`, `salary`, `taxonomies`, and
normalised location — are **derived by classifiers and parsers**. They are
inferences, not facts stated by the employer. They are wrong some of the time.
Salary parsing in particular reads free text written by humans who were not
trying to be machine-readable. Coverage varies by field and by source; see
[coverage](/docs/reference/coverage) for the current picture.

Firmographic data about companies comes from a mix of sources and carries the
same caveat.

So: we do not warrant that the data is accurate, complete, current, or fit for
any particular purpose. Do not use it as the sole basis for a decision that
affects a person's employment, creditworthiness, or legal position. If you find
data that is wrong, tell us — send the job id to <Email kind="support" /> — and
see [Data corrections](/help/data-corrections).

## 12. Third-party content

The postings originate with the employers who published them. Their content —
titles, descriptions, requirements, branding — is theirs, and any rights in it
stay with them. `apply_url` points at the employer's own application form, and
what happens after a user follows it is between that user and that employer.

We are not the employer, not an agent of the employer, and not a party to any
hiring process. We make no representation about any employer or any posting.

Where a posting's own terms restrict what may be done with it, those restrictions
are between you and the employer, and section 5 does not override them.

## 13. Intellectual property

The API, the dataset as a compilation, the enrichment models, the taxonomies, the
documentation, and the software are ours, including all intellectual property
rights in them and any database rights in the compilation. Section 5 grants you a
licence to use the output; it transfers nothing else, and rights not granted are
reserved.

You keep everything of yours: your data, your product, and anything you build.
Feedback you send us we may use freely, without obligation to you, and without it
making you an owner of anything we build with it.

You may say that your product uses HyperJobs. Do not otherwise use our name or
marks in a way that implies we endorse, sponsor, or partner with you.

## 14. Confidentiality

Each side may learn non-public information from the other. Neither side will
disclose the other's confidential information, or use it for anything other than
this agreement, and each will protect it with at least reasonable care.

This does not cover information that is public through no fault of the receiver,
that the receiver already had, that the receiver develops independently, or that
it gets from a third party without a duty of confidence. Disclosure compelled by
law is permitted, with notice to the other side where lawful.

Your API keys are your confidential information. The dataset and our
non-public documentation are ours.

## 15. Warranty disclaimer

The service is provided **as is** and **as available**.

To the fullest extent the law allows, we disclaim all warranties, express or
implied, including implied warranties of merchantability, fitness for a
particular purpose, non-infringement, and any warranty arising from course of
dealing or trade usage.

We do not warrant that the service will be uninterrupted, timely, secure, or
error-free, that defects will be corrected, or that the data will be accurate or
complete. We publish no uptime commitment on these terms; if you need one, talk
to us about a written agreement.

Nothing here excludes a warranty that cannot lawfully be excluded, and nothing
here limits the statutory rights of a consumer.

## 16. Limitation of liability

Neither side excludes liability for death or personal injury caused by
negligence, for fraud or fraudulent misrepresentation, or for anything else that
cannot lawfully be excluded or limited. Nothing in this section limits the
statutory rights of a consumer.

Subject to that:

- Neither side is liable for indirect or consequential loss, loss of profit,
  loss of revenue, loss of business, loss of anticipated savings, loss of
  goodwill, or loss or corruption of data, however caused.
- **Our total aggregate liability** arising out of or in connection with this
  agreement, whether in contract, tort (including negligence), or otherwise, is
  **capped at the total fees you paid us in the 12 months before the event that
  gave rise to the claim**.
- If you are on the Free plan and have paid us nothing, our aggregate liability
  is capped at €100.

We are not liable for decisions you make on the basis of the data, for the
conduct of any employer, or for the content of any posting. Section 11 explains
why.

## 17. Indemnity

You will indemnify us against claims, damages, losses, and reasonable costs
(including legal fees) brought by a third party and arising from your use of the
service or the data in breach of these terms, your breach of section 6 or 7, or
your infringement of a third party's rights.

We will tell you promptly about any such claim, let you control the defence of
it, and give you reasonable cooperation. You may not settle in a way that admits
fault on our part or imposes an obligation on us without our written agreement.

## 18. Changes

**To the service.** We may change the service as described in section 2. We will
not make a breaking change to `/v1` without shipping it as a new version path.

**To these terms.** We may update these terms. If a change materially reduces
your rights or increases your obligations, we will give you at least 30 days'
notice by email or in the portal before it takes effect, and it will not apply
retroactively. Continuing to use the service after a change takes effect means
you accept the new version. If you do not accept it, cancel before it takes
effect. Every version carries a version number and a date; this one is at the top
of this page.

We record which version of these terms you accepted, and when. The
[Privacy Policy](/legal/privacy) explains that record.

## 19. Governing law and venue

These terms, and any dispute arising out of or in connection with them —
contractual or not — are governed by **Italian law**, without regard to its
conflict-of-laws rules. The courts of **Salerno, Italy** have exclusive
jurisdiction.

If you are a **consumer** habitually resident in the EU, that choice of law does
not deprive you of the protection of the mandatory rules of the law of your own
country (Article 6 of the Rome I Regulation), and you may bring proceedings in
the courts of your own country, and be sued only there.

The United Nations Convention on Contracts for the International Sale of Goods
does not apply.

## 20. Contact

The service is operated by <LegalEntity />.

| Topic | Contact |
| --- | --- |
| These terms, technical questions, bad data | <Email kind="support" /> |
| Plans, billing, licensing questions | <Email kind="hello" /> |
| Security disclosure | <Email kind="security" /> |
| Data protection | <Email kind="dpo" /> |

## 21. General

These terms, with the documents they incorporate, are the entire agreement
between us on this subject, and replace anything said before it. Neither side
relies on any statement not written here, except where that statement was
fraudulent.

If any part of these terms is unenforceable, the rest stays in force and the
unenforceable part is read down to the minimum extent needed to make it work.

Failing to enforce a term is not a waiver of it.

You may not assign or transfer this agreement without our written consent, which
we will not unreasonably withhold. We may assign it to an affiliate or in
connection with a merger, acquisition, or sale of assets, on notice to you.

Nothing here creates a partnership, joint venture, agency, or employment
relationship. There are no third-party beneficiaries.

Neither side is liable for failure to perform caused by events beyond its
reasonable control, except for obligations to pay.
