Skip to content
flatbrowser

DSA Art. 14 · Data Act Art. 25

Terms of Service

What we sell and to whom, what you agree to, exactly how our abuse detection works (Art. 14 DSA), and how you leave with your data (EU Data Act).

draft 2026-10-04 · unreviewed

1. Parties, scope and business customers only

These terms govern the use of the flatbrowser service (the “Service”) provided by [PLACEHOLDER: registered legal name incl. legal form (GmbH / UG (haftungsbeschränkt))] (“we”, “us”) to the account holder (“you”). They apply together with the Acceptable Use Policy, the billing, refund and dispute terms, the switching and export information and, for personal data you process through the Service, the Data Processing Agreement.

The Service is offered exclusively to businesses within the meaning of §14 BGB — companies, freelancers and other persons acting in their trade, business or profession. We do not contract with consumers (§13 BGB). When you sign up you confirm that you act as a business; we may ask for evidence, such as a VAT ID or a register entry, and may refuse or end a contract where that confirmation was untrue.

You accept these terms, the Acceptable Use Policy and the Data Processing Agreement when you create your account. We record the time of your acceptance and the version of the documents you accepted, and we ask you again when a new version takes effect (section 14).

2. What the Service is

The Service is browser-automation infrastructure: dedicated Chromium worker containers reachable over the Chrome DevTools Protocol and a small REST API. We provide a general-purpose browser. We do not decide what you visit or collect, we ship no target-specific automation, we operate no accounts on third-party services, we hold no third-party credentials for you, and we do not store or resell anything your sessions retrieve. Browser state (cookies, storage, downloads) is deleted when each session ends.

3. Plans, concurrency and the guardrails on “unmetered”

A plan grants a fixed number of dedicated workers at a flat monthly price with unmetered usage. Each worker supports 2 concurrent sessions, so the plan’s concurrency limit is workers × 2 (for example Solo: 1 worker, 2 concurrent sessions). An attempt to exceed it is refused with HTTP 429 and a Retry-After header, or — if you ask for it per request — waits up to 60 seconds for a free slot. Refused attempts are never billed.

Unmetered usage is subject to operational guardrails:

  • a session with no connected client is closed after an idle timeout (default 5 minutes, configurable per session);
  • every session has a hard maximum duration of 12 hours;
  • fair use on traffic volume: sustained outbound traffic far outside normal automation patterns may be rate-limited, but only after we have contacted you about it (how we notice it is described in section 6). Exporting your data or switching to another provider never incurs a charge and is never throttled under this fair-use rule.
  • reselling raw browser capacity as a competing service is not covered by any plan.

Availability: [PLACEHOLDER: availability target, if any is promised]. Planned maintenance is announced in advance via [PLACEHOLDER: channel used for incident and maintenance notices — status page URL and/or email to account owners]; see also the status page.

4. Fees, taxes and annual repricing

Plans are billed monthly in advance through Stripe. All prices are net; VAT is added at checkout, or the EU reverse charge applies when you give a valid VAT ID from another EU member state. Checkout collects your billing address and VAT ID for that purpose. You may cancel at any time with effect from the end of the current billing period. Refunds, failed payments and payment disputes are governed by the billing, refund and dispute terms; in short, partial periods are not refunded, and a failed renewal keeps the Service running for 7 days while the payment is retried.

Annual repricing. We may adjust plan prices once per calendar year. We will notify you by email at least [PLACEHOLDER: notice period for a price change, e.g. 30 days] before the new price applies to your subscription, and you may terminate with effect from the day before it takes effect. This clause exists because our own infrastructure costs can move; a flat unmetered plan that cannot be repriced is a plan that gets withdrawn instead.

5. Acceptable use

The Acceptable Use Policy is part of these terms. You are responsible for everything done with your API keys, including by your own users and by automation you deploy.

6. Abuse detection and enforcement

This section describes, as Art. 14(1) DSA requires, every tool we use to detect and act on misuse of the Service — and nothing we do not use.

6.1 What we record

Our gateway pipes the DevTools Protocol traffic between your client and your browser without reading it. It writes an append-only connection log with:

  • for every browser session: start and end time, your organisation, the ID of the API key used, the session ID, the worker and host it ran on, the IP address of the connecting client, the public IP address of that host — also when you bring your own proxy, because a browser can send traffic around a proxy; then the proxy’s host and port are recorded too (never its credentials) — the close reason, and the number of bytes piped;
  • for every client that attaches to or leaves an existing session: the time and its IP address;
  • for every REST call (screenshot, PDF, content, scrape): the target hostname — not the path, query string or page content — and the outcome, including refusals under 6.2 by the blocklist or because a hostname resolves to a private address (a private address written directly into the request is rejected as invalid and not logged);
  • per worker, every 15 minutes: the bytes it sent and received over its network interface (internet traffic and the DevTools traffic to our gateway alike);
  • billing and account events of your organisation: a completed checkout (billing country, acceptance and version of these terms, the types — not the numbers — of tax IDs entered), payment reminders, payment disputes, fraud warnings and refunds, a VAT ID removed or not verifiable, suspensions with their reason, and close requests and their withdrawal.

We do not record the URLs your browsers open over the DevTools Protocol, page content, response bodies, screenshots, form input or credentials. The connection log is kept for 3 years (1095 days) and then deleted automatically; the session list in your dashboard covers the last 90 days. We use the log to run the Service and to answer an abuse complaint or a lawful request about one of our IP addresses at a given time. Details are in the privacy policy.

6.2 Automated measures

  • Hostname blocklist. We keep a list of hostnames that may not be accessed through the Service, compiled by our staff from abuse notices, authority orders and our own investigations. A REST call to a listed hostname (or one of its subdomains) is refused with HTTP 403 before any browser starts, and the refusal is logged. Inside browser sessions the browser is set up so that the same hostnames cannot be resolved, also around a proxy you set for the whole session. This part is best effort: a proxy you configure per browser context over the DevTools Protocol resolves names itself, beyond our reach, and a very long list is applied to sessions up to a size limit (REST calls are always checked against the full list).
  • Private-network guard. Requests to private, loopback and cloud-metadata addresses are refused.
  • Traffic-volume alert. When an organisation’s browsers send more than 100 GB to the internet in one UTC day, our staff receive an alert. The alert restricts nothing by itself; a person looks at it.

Apart from refusing listed hostnames and private addresses request by request, no automated system restricts your account on its own for content or conduct reasons. A person reviews every case before we suspend or terminate an account, except where immediate suspension is necessary to stop ongoing harm, to comply with a legal order, or in the case of section 12(3)(e). (Automatic billing holds after a payment dispute are described in section 12.)

6.3 Decisions

When we restrict your account we give you a statement of reasons (section 7) and tell you how to contest it (section 8). We apply these measures diligently, objectively and proportionately, with due regard to your rights and legitimate interests.

7. Statement of reasons (DSA Art. 17)

Whenever we suspend, restrict or terminate an account for a reason other than a plain cancellation, we email the owners of the organisation a statement of reasons containing:

  1. the nature and scope of the measure, and how long it applies;
  2. the facts and circumstances we relied on;
  3. whether automated means were used in the detection or the decision;
  4. the contractual or legal ground for the measure;
  5. the remedies available to you, including this complaint route and recourse to the courts.

8. Complaints

Contest any measure by writing to [PLACEHOLDER: legal / DPA contact email] with the reference from the statement of reasons. A person who was not involved in the original decision reviews it. Target turnaround: [PLACEHOLDER: internal deadline for deciding a complaint, e.g. 10 working days]. We reverse a measure as soon as the ground for it falls away. Nothing here limits your right to go to court, and we are not an online platform under the DSA, so the Art. 20–21 internal complaint and out-of-court dispute mechanisms do not apply to us.

9. Notices of illegal content (DSA Art. 16)

Anyone can report allegedly illegal content or activity involving our infrastructure through the abuse report form. We confirm receipt, decide in a timely, diligent, non-arbitrary and objective manner, and tell the notifier the outcome and the remedies available. Where we become aware of a suspected criminal offence involving a threat to life or safety, we inform law enforcement immediately (Art. 18 DSA).

10. Your obligations and warranties

  • You act as a business (§14 BGB), and the account, billing and VAT details you give us are accurate.
  • You are the data controller for any personal data you collect through the Service, you have a legal basis for it, and you comply with the terms of the sites you visit.
  • You keep API keys secret and revoke them promptly when they leak.
  • You do not use the Service in ways the Acceptable Use Policy prohibits.
  • You do not resell raw browser capacity as a competing service.
  • You are not a sanctioned party and do not act on behalf of one.

10a. Indemnity

You indemnify us against claims by third parties — including our infrastructure and network providers — that arise because the Service was used through your account in breach of the Acceptable Use Policy, these terms or the law, to the extent you are responsible for that use. The indemnity covers the reasonable costs of our legal defence and charges a provider imposes on us because of that use. We tell you about such a claim without undue delay, do not acknowledge or settle it without consulting you, and let you take part in the defence.

11. Automation you supply, including AI agents

Scripts, selectors and AI-driven agents you run are yours. If you drive a browser with a language model, note that a hostile page can try to redirect that agent — keep credentials and secrets out of model context and out of authenticated sessions you cannot supervise. We accept no responsibility for actions your automation takes on third party systems.

12. Suspension and termination

  1. Your side. You may cancel at the end of any billing period from the billing portal, or close your organisation from the dashboard, which also stops the renewal. Switching to another provider is governed by section 12a.
  2. Our side. We may terminate with notice at the end of a billing period, and either party may terminate without notice for good cause.
  3. Suspension. We may suspend the Service for your organisation (a) for a material breach of these terms or the Acceptable Use Policy; (b) when a renewal payment is still unpaid 7 days after it failed and Stripe’s reminders went unanswered; (c) automatically, as a billing hold, when a payment is disputed or reported as fraudulent, or fully refunded, until the matter is resolved; (d) where sanctions or export-control law, or an order of a court or authority, requires it; and (e) immediately and without prior notice where our infrastructure provider demands it, or where it is necessary to stop our provider from blocking or terminating infrastructure that also serves other customers — limited to what is necessary and for as long as necessary. In the cases (a) and (c) to (e) you receive a statement of reasons under section 7 by email; for (b) the payment reminders we send when the payment fails state when the Service stops, and service resumes as soon as the invoice is paid.
  4. Effect of a suspension. Your running sessions are closed, your workers are removed and your API keys are refused. Except for billing holds, we pause billing while we do not serve you. Your data stays exportable during a suspension.
  5. Effect of termination. Workers are destroyed when the Service ends. Your account data stays retrievable for at least 30 days after that and is then erased, as section 12a describes — also when we terminate, unless a court or authority forbids it.

12a. Switching, data export and exit (EU Data Act, Arts. 23–31)

These clauses implement Art. 25 of Regulation (EU) 2023/2854. Where anything else in these terms conflicts with them, they prevail. The practical procedure, the export format and the information required by Arts. 26 and 28 are published on the switching and export page, which forms part of these terms.

  1. Request and notice period. You may ask at any time to switch to another provider, to move your data to your own infrastructure, or to have it erased — by closing your organisation in the dashboard or by email to [PLACEHOLDER: support email — DSA Art. 12 point of contact]. The notice period ends with the current billing period and never exceeds two months.
  2. Your choice. With the request, or before the notice period ends, you tell us whether you (a) switch to another provider, (b) port your data to on-premises infrastructure, or (c) want your exportable data erased.
  3. Transitional period. On request, the Service continues unchanged for up to 30 days after the notice period, at the standard monthly fee pro rata. During it we assist you and any third party you authorise, keep the Service running with due care, tell you about known risks to continuity, and keep security at the usual level. If 30 days are technically unfeasible, we tell you within 14 working days of your request, with reasons and an alternative period of at most 7 months. You may extend the transitional period once, for a period you consider more appropriate.
  4. Exit support. We give you all information relevant to your exit, starting with the switching page. The Service uses open interfaces: the Chrome DevTools Protocol and a documented REST API, so your scripts move to any CDP-compatible provider by changing the endpoint.
  5. Exportable data. Exhaustively: your organisation record, members and invitations (including terms acceptance records), API-key metadata, workers, your subscription, invoices, decisions we took about your account, your session history, usage and traffic records, and the connection log entries about your organisation. The format is described on the switching page; the export is a single JSON document you download from the dashboard at any time.
  6. Exempted data. Exhaustively, because they concern the internal functioning of the Service or its security: API-key secrets and their hashes (we never hold a key in readable form), worker access tokens, host and network configuration, our hostname blocklist, capacity and placement data, our internal audit log, and the identity of people who sent notices about your account. None of this delays a switch.
  7. Termination and notice. The contract ends when the switch has been completed, or — if you chose erasure — at the end of the notice period. We confirm the termination to you by email.
  8. Retrieval period. After the Service ends (and after any transitional period), you can still sign in and download your export for at least 30 days.
  9. Erasure. When the retrieval period expires we erase all exportable data generated by you or relating to you directly. We keep only what the law requires or allows us to keep for our own legal obligations: invoice and booking records (at Stripe and in our accounting archive, for the statutory periods), records of decisions under the DSA, and the connection log described in section 6.1 (billing and account events included) until its own retention ends. While an abuse case about your organisation is open, or your account is suspended under the Acceptable Use Policy or for sanctions reasons, the erasure waits until that case is decided. Backups expire within 15 days. On request we confirm the erasure in writing.
  10. Charges. There are no switching, data-export, egress or early-termination charges. During a transitional period only the standard monthly fee applies, pro rata.

13. Liability

[PLACEHOLDER: liability limitation — to be drafted with counsel (§§307, 309 BGB limits apply)]. Liability for injury to life, body or health, for intent or gross negligence and under the Product Liability Act remains unlimited in any case, as German law requires. Insurance cover: [PLACEHOLDER: insurance cover, once IT-Vermögensschadenhaftpflicht and Cyber are bound].

Upstream providers. The Service runs on servers and networks we rent from third parties (see the subprocessor list). We are not responsible for interruptions those providers cause without our fault — outages, network disruptions or measures they take against their infrastructure — and fees are not reduced for such interruptions unless an availability target above says otherwise. This does not limit our liability under the preceding paragraph.

14. Changes to these terms

We notify you by email at least [PLACEHOLDER: notice period for a change to these terms, e.g. 30 days] before a substantial change to these terms takes effect, and we tell you what changed. The dashboard then asks you to accept the new version. If you do not accept it, you may terminate with effect from the day before it applies (Art. 14(2) DSA), and section 12a applies to your data.

15. Governing law, jurisdiction, contact

[PLACEHOLDER: governing law and place of jurisdiction — to be set with counsel].

Contact: [PLACEHOLDER: general contact email] · users’ point of contact (Art. 12 DSA): [PLACEHOLDER: support email — DSA Art. 12 point of contact] · authorities (Art. 11 DSA): [PLACEHOLDER: email for authorities — DSA Art. 11 point of contact] · billing: [PLACEHOLDER: billing contact email (monitored, e.g. billing@)].