Legal Center

API Terms

Terms for Business/API access, credentials, webhooks, and automated use of GLWS.

Last updated · Version 2026-08-31.2

These API Terms apply if you access GLWS programmatically, including the versioned product API under /v1 and any webhooks. They supplement the Terms of Service. GLWS is a service operated by FinDech UAB.

If you process personal data of your end users through the API as a controller, the Data Processing Addendum may also apply.

1. Access and credentials

1.1 API and webhook access require a Business or Platform entitlement. Marketing references to a Business/API plan are not a licence until that entitlement is actually granted and credentials are issued.

1.2 You must keep credentials confidential, restrict them to authorised applications, and rotate them if they may have been exposed.

1.3 You are responsible for all use of your credentials, including use by employees, contractors, and integrated marketplaces.

2. Permitted use

You may use the API to create, read, and manage GLWS deals and related records for lawful transactions that comply with the Terms of Service and the Acceptable Use Policy.

You must not:

  • attempt to bypass authentication, rate limits, or use limits;
  • probe, scrape, or overload the Service beyond documented use;
  • reverse engineer the API except as permitted by law;
  • resell raw API access without our written consent;
  • use the API to build a competing deal-record service using our confidential APIs;
  • use outputs as the sole basis for a fully automated legally significant decision about a person where GDPR would require additional safeguards, unless those safeguards are in place;
  • submit or store payment-card PAN/CVC data in GLWS fields.

3. Rate limits, versioning, and availability

3.1 We may apply rate limits and may change them.

3.2 We may version, modify, or discontinue API endpoints. We will take reasonable steps to announce breaking changes, but the API is provided without an SLA unless a separately signed contract says otherwise.

3.3 Webhook delivery, if enabled, is best-effort. Retries may occur. You must treat webhook handlers as idempotent. Non-delivery or delayed delivery can happen.

3.4 A webhook or API status is a technical record. It may later change because of payment reversal, partner correction, reconciliation, fraud investigation, or another legitimate event. Do not treat a paid or similar status as final settlement.

4. Idempotency and mutations

Where a mutation could be duplicated by a retry, you must send an idempotency key as documented. You must not spoof seller, buyer, or organisation identity in JSON; identity comes from verified credentials.

5. Personal data and payment data

5.1 You must have a lawful basis to submit personal data about Buyers, Sellers, or other individuals.

5.2 Do not send payment-partner secrets, raw card data, or unnecessary special-category data.

5.3 Public deal responses are limited safe DTOs. Do not attempt to retrieve hidden fields such as handover codes through undocumented means.

6. High-risk and prohibited automated use

You must not use the API to facilitate fraud, sanctions evasion, credential stuffing, or prohibited transactions. We may suspend API access immediately where reasonably necessary.

7. Suspension and termination

We may suspend or terminate API access for breach, security risk, unpaid fees (if a paid API plan exists), partner requirements, or discontinuation of the Service. On termination, you must stop calling the API and delete credentials.

8. Contact

info@glws.com · legal@findech.com