Legal
Terms of Service
The contract between your organisation and FortressFlag.
- Version
- draft-2026-09-09
- Bundle
- draft-2026-09-09
- Permanent
- /legal/terms/draft-2026-09-09
- Status
- Draft - not in force
1. What this document is
These Terms of Service (the “Terms”) form a contract between FortressFlag LLC (“FortressFlag”, “we”, “us”) and the organisation that accepts them (the “Customer”, “you”). They govern your access to and use of the FortressFlag feature-flagging platform, including the control-plane dashboard, the management API, the data-plane delivery of flag values, and our software development kits (together, the “Service”).
You accept these Terms by ticking the acceptance box when you create an organisation, when you accept an invitation to join one, or when you are asked to accept an updated version inside the product. Acceptance is recorded against your organisation with the version of each document as it was served to you.
The following documents are incorporated into these Terms by reference and form part of them:
- the Acceptable Use Policy;
- the Data Processing Agreement;
- the Sub-processor list.
The Privacy Policy is a notice, not a contractual term. It describes what we do with personal data for which we are the controller. Nothing in it is something you “agree” to.
2. Who is agreeing, and in what capacity
By accepting these Terms you represent and warrant that:
2.1 Authority to bind. You are authorised to enter into these Terms on behalf of the Customer, and the Customer is bound by them.
2.2 Business capacity. The Customer is entering into these Terms wholly or mainly for purposes relating to its trade, business, craft or profession, and not as a consumer. The Service is offered only for business use. If you are a sole trader, an individual developer or any other natural person, you are still contracting in a business capacity, and consumer-protection regimes that apply only outside a trade or profession — including the right of withdrawal for distance contracts under EU and UK law — do not apply to this agreement.
2.3 Flow-down to your users. You will ensure that every person to whom you give access to the Service — including members you invite, members provisioned automatically from your identity provider, and any contractor or affiliate acting on your behalf (each an “Authorised User”) — complies with these Terms and with the Acceptable Use Policy. You are responsible for your Authorised Users’ acts and omissions in connection with the Service as if they were your own, and you will bind them to terms at least as protective as these before granting access.
This clause is what makes it sound for an administrator to accept the Acceptable Use Policy on behalf of users the identity provider will create later: the undertaking is yours, given by you, about people you control.
3. The Service
3.1 Access. Subject to these Terms, we grant you a non-exclusive, non-transferable, non-sublicensable right, during the term, to access and use the Service for your internal business purposes.
3.2 Changes to the Service. We may modify the Service. We will not make a change that materially reduces the core functionality you are then paying for without giving reasonable prior notice through the Service or to the email address of an account owner.
3.3 Beta and free tiers. Any part of the Service offered free of charge, on a trial basis, or labelled beta, preview or evaluation, is provided as is and as available, with no service level commitment, no availability commitment, no support commitment, and no warranty of any kind. We may change, suspend or withdraw it at any time. The free trial tier described on our pricing page is such an offering. This clause survives the rest of section 7 and section 8: where the Service is free, our liability for it is limited to the maximum extent the applicable law permits.
3.4 Support. Support for paid use is provided through the support section of the dashboard. We respond on a reasonable-efforts basis and commit to no response times. No support commitment attaches to the free tier (section 3.3).
4. Your responsibilities
4.1 Acceptable use. You and your Authorised Users will use the Service in accordance with the Acceptable Use Policy.
4.2 Credentials. You are responsible for keeping management credentials — passwords, management API tokens, and server SDK keys — confidential, and for all activity under your organisation’s account. Client SDK keys are read-only, scoped, and public by design — they ship inside your applications. Server SDK keys are secrets: they are shown once at creation and must not be embedded in client-side code or otherwise published. You are responsible for revoking or rotating any credential you believe has been misused.
4.3 Your content. You are responsible for the flag keys, names, descriptions, targeting rules, segment definitions and other configuration you enter (“Customer Content”), and for having the rights to enter it. We do not require personal data in any of these fields, and you should not put any there.
4.4 Your own compliance. You decide what your applications do when a flag is on. We do not review, approve or take responsibility for the features you gate.
5. Fees
5.1 Charges. Fees are as stated on our pricing page or in an order you place through the Service. Billing is per monthly-active device, as described there.
5.2 Payment. Paid plans are billed through our payment processor. Fees are exclusive of taxes, which you are responsible for except taxes on our income.
5.3 Non-payment. If an invoice is more than [[GRACE_DAYS]] days overdue we may suspend the
paid features of the Service after notice to an account owner.
6. Confidentiality
Each party may receive information of the other that is marked confidential or that a reasonable person would understand to be confidential (“Confidential Information”). The receiving party will use it only to perform under these Terms, will protect it with at least reasonable care, and will not disclose it except to its personnel and advisers who need it and are bound by confidentiality obligations. This does not apply to information that is or becomes public without breach, was already known without a duty of confidence, or is independently developed. A party may disclose Confidential Information where legally compelled, giving notice where lawful.
7. Warranties and disclaimers
7.1 Mutual. Each party warrants that it has the authority to enter into these Terms.
7.2 Our warranty. We warrant that the paid Service will perform materially in accordance with its then-current documentation. Your exclusive remedy for a breach of this warranty is that we will use reasonable efforts to correct the non-conformity, and if we cannot do so within a reasonable period you may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees.
7.3 Disclaimer. Except as expressly stated in section 7.2, and to the maximum extent permitted by applicable law, the Service is provided as is, and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free.
7.4 Nothing excluded that cannot be. Nothing in these Terms excludes or limits liability that cannot lawfully be excluded or limited, including liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or any other liability the applicable law does not permit to be limited.
8. Limitation of liability
DRAFTING NOTE — FOR COUNSEL, NOT FOR THE READER. This section is the one most likely to be unenforceable as drafted in some of the markets we intend to sell into, and it is flagged here rather than quietly shipped. Under German law, §§305–310 BGB police standard business terms in business-to-business contracts far more strictly than US or English law does. Blanket exclusions of consequential loss and single aggregate caps are frequently struck down there — and when a clause falls, §306(2) BGB replaces it with the statutory default (full liability) rather than severing it and leaving the rest of the contract intact. A cap that is invalid in Germany is therefore worse than a narrower cap that holds. Counsel should decide whether to carve out a Germany-specific liability regime, to narrow this section generally, or to accept the risk. The same review should confirm the position in every other civil-law market on the sales list.
8.1 Exclusion. To the maximum extent permitted by applicable law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenues, goodwill or anticipated savings, however caused.
8.2 Cap. To the maximum extent permitted by applicable law, each party’s total aggregate liability arising out of or related to these Terms is limited to [[LIABILITY_CAP]].
8.3 Free use. Where you are using the Service without charge, our total aggregate liability is limited to [[FREE_TIER_CAP]].
8.4 Exceptions. Sections 8.1 to 8.3 do not apply to your payment obligations, to either party’s indemnification obligations under section 9, or to liability that cannot lawfully be limited (section 7.4).
9. Indemnification
9.1 By us. We will defend you against a third-party claim that the Service, used in accordance with these Terms, infringes that third party’s intellectual property rights, and will pay damages finally awarded or agreed in settlement. If the Service becomes, or we believe it may become, the subject of such a claim, we may procure the right to continue using it, modify it, or terminate the affected subscription and refund prepaid, unused fees.
9.2 By you. You will defend us against a third-party claim arising from Customer Content or from your or your Authorised Users’ use of the Service in breach of these Terms or the Acceptable Use Policy, and will pay damages finally awarded or agreed in settlement.
9.3 Process. The indemnified party will give prompt notice, allow the indemnifying party to control the defence, and provide reasonable cooperation. A settlement that imposes a non-monetary obligation on the indemnified party requires its consent.
10. Term, termination and suspension
10.1 Term. These Terms begin when you first accept them and continue until all subscriptions have ended and your organisation is closed.
10.2 Termination for convenience. You may stop using the Service and close your organisation at any time. Fees already incurred remain payable, and prepaid fees are not refundable except where these Terms say otherwise.
10.3 Termination for cause. Either party may terminate if the other materially breaches these Terms and does not cure the breach within thirty (30) days of written notice.
10.4 Suspension. We may suspend access where required by law, where continued access presents a security risk to us or to another customer, or for a material breach of the Acceptable Use Policy. We will limit the suspension to what the circumstances require and restore access when they end.
10.5 Effect. On termination your right to access the Service ends. Sections 6, 7.3, 7.4, 8, 9, 11 and 12 survive, together with any provision that by its nature should.
11. Data, portability and switching
11.1 Personal data. Where we process personal data on your behalf, the Data Processing Agreement applies and forms part of these Terms.
11.2 Your data is yours. As between the parties, you own Customer Content. We use it only to provide and support the Service, and as the Data Processing Agreement permits.
11.3 Switching and exit — EU Data Act. These commitments apply to every customer, not only to those established in the European Union, and they are made to satisfy Chapter VI of Regulation (EU) 2023/2854 (the Data Act), applicable since 12 September 2025:
- You may switch away at any time. You may terminate for the purpose of switching to another provider or to your own on-premises infrastructure by giving notice, and the maximum notice period we require to initiate switching is two (2) months.
- Transitional period. After you initiate switching we will maintain your access to the Service, and to the assistance described here, for a transitional period of at least thirty (30) days, extendable by agreement where the migration reasonably requires it.
- Exportable data and digital assets. During the transitional period, and for a further thirty (30) days after it ends, you may export your exportable data and digital assets — your flag definitions, states, targeting rules, segments, variants, environments, projects, membership list and audit history — through the management API and the audit export, in a structured, commonly used, machine-readable format.
- No obstacles. We will not impose contractual, commercial, technical or organisational obstacles that inhibit you from switching, and we will provide reasonable assistance and information about the structure of your exportable data on request.
- Charges. We do not charge switching fees.
11.4 Deletion after exit. After the periods in section 11.3 we delete or anonymise Customer Content in accordance with the Data Processing Agreement. Audit history is deleted as a deliberate, separately authorised operation, not as a side effect of closing an account.
12. General
12.1 Changes to these Terms. We may publish a new version of any document in this bundle. Each version is published at a permanent, dated URL and never edited in place. When a new bundle version is published, an administrator of your organisation is asked to accept it inside the product, and changes that make the Service materially worse for you take effect only on that acceptance. Notice of a change is given in the product, not by email.
12.2 Sub-processor changes. We give notice of a new or replacement sub-processor in the product, as described in the Data Processing Agreement.
12.3 Assignment. Neither party may assign these Terms without the other’s consent, except to a successor in connection with a merger or a sale of substantially all assets, on notice.
12.4 Notices. Legal notices to us go to [[NOTICE_ADDRESS]]. Notices to you go to an account owner’s email address, or are given in the product.
12.5 Governing law and venue. These Terms are governed by [[GOVERNING_LAW]], and the parties submit to [[VENUE]]. This section does not deprive a party of the protection of mandatory provisions of the law of its own place of establishment where those provisions cannot be derogated from by agreement.
12.6 Force majeure. Neither party is liable for a failure to perform caused by circumstances beyond its reasonable control, other than payment obligations.
12.7 Entire agreement. These Terms, together with the documents they incorporate, are the entire agreement between the parties on this subject and supersede prior discussions. In case of conflict, these Terms prevail over the incorporated documents, except that the Data Processing Agreement prevails on the subject of personal data.
12.8 Severability and waiver. If a provision is held unenforceable, it is modified to the minimum extent necessary or severed, and the rest continues in effect — subject always to section 8’s drafting note, since not every legal system severs. A failure to enforce is not a waiver.
12.9 Language. These Terms and the documents they incorporate are drafted in English. Where the product interface or any translation presents them in another language, the English text controls.
12.10 Independent contractors. The parties are independent contractors. Nothing here creates a partnership, agency or employment relationship.
13. Definitions
“Authorised User” has the meaning in section 2.3.
“Customer Content” has the meaning in section 4.3.
“Personal data”, “processing”, “controller” and “processor” have the meanings given in the Data Processing Agreement.
“Service” has the meaning in section 1.
Adapted from the Common Paper Cloud Service Agreement Standard Terms v2.1, used under CC BY 4.0. Common Paper does not endorse this adaptation, and the changes made here — including sections 2.2, 2.3, 3.3, 8’s drafting note and 11.3 — are ours.
All five documents, and their versions, are listed at /legal.