Terms of Service

Effective 2026-07-21Version 1.0Governing law: Poland (EU)
The short version. Obstruo is a control plane that sits between your applications and the AI providers and MCP servers they call. You bring your own provider keys. Obstruo redacts data on the way in, routes requests to the region you choose, applies guardrails, governs which MCP tools an agent may use, and writes an audit record of every call. It runs on EU infrastructure in France, with data encrypted in transit and at rest. Obstruo holds no security certification of its own, and the console's governance records are tooling rather than proof of compliance. Redaction and guardrails are statistical systems, so we do not promise they catch everything. The Service is sold to businesses only. You choose the providers and models, and you remain responsible for your use case. The binding text is below.
1.

Definitions

"Obstruo", "we", "us": OBSTRUO prosta spółka akcyjna (a simple joint-stock company under Polish law), registered office at ul. Święty Marcin 29 lok. 8, 61-806 Poznań, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court Poznań - Nowe Miasto i Wilda in Poznań, 8th Commercial Division of the National Court Register, under KRS number 0001254019, NIP 7831958330, REGON 545245656, share capital PLN 20,000.00. Obstruo is represented by its board of directors (rada dyrektorów); each director is authorised to make declarations on behalf of Obstruo acting alone.

"Customer", "you": the legal entity accepting these Terms. The Service is offered exclusively to businesses and other legal entities, not to consumers.

"User": an individual authorised by the Customer to use the Service on the Customer's behalf.

"Service": the Obstruo control plane, comprising the features made available under the Customer's plan, namely: (a) an API gateway that mediates calls to Upstream Providers; (b) redaction of personal and sensitive data before transmission to an Upstream Provider; (c) routing of requests to Customer-selected providers and jurisdictions; (d) guardrails, meaning detection of prompt injection on inbound requests and content filtering on outbound responses; (e) an MCP gateway that proxies Customer-registered MCP servers with per-tool allow and deny rules; (f) an audit log of gateway calls; (g) the Panel, including its governance, registry and records surfaces; and (h) further features described in the Documentation. Features identified as beta, preview or forthcoming are subject to Section 17.

"Panel": Obstruo's administrative web interface for configuration, user management, governance records and reporting.

"Documentation": the product documentation made available to the Customer inside the Panel after registration, together with Obstruo's published pricing page. Documentation does not include marketing materials, the public website, or performance figures stated on it.

"Customer Data": all data submitted to or processed through the Service by or on behalf of the Customer, including request and response payloads, MCP tool calls and their results.

"Upstream Provider": a third-party provider of large language model services to which the Service routes requests, as configured by the Customer. The Customer supplies its own credentials for each Upstream Provider. Obstruo stores those credentials in encrypted form and uses them solely to route the Customer's own requests. The relationship governing use of an Upstream Provider is between the Customer and that provider. Models operated on the Customer's own infrastructure, and MCP servers operated by the Customer, are part of the Customer's environment and are not subcontractors of Obstruo.

"DPA": the Data Processing Agreement between Obstruo and the Customer, which forms an integral part of these Terms once executed.

"Order": an order form, subscription selection or other document specifying the plan, fees and term agreed with the Customer.

2.

The Service

2.1 Provision. Obstruo will provide the Service materially as described in the Documentation and the applicable Order.

2.2 Service levels and performance. No service level is guaranteed. The Service is operated on commercially reasonable efforts, and availability commitments may be agreed separately in an Enterprise Order or an SLA annex. Latency, throughput and overhead figures published on Obstruo's website are indicative measurements, not commitments.

2.3 Upstream Providers and MCP servers. Obstruo does not control Upstream Providers or Customer-registered MCP servers, and is not responsible for their availability, performance, output content, the effects of tool calls executed against them, or changes to their terms or models. The Service transmits data only to Upstream Providers and MCP servers the Customer has configured; if one is not configured, no Customer Data is sent to it.

2.4 Nature of redaction and guardrails. Redaction and guardrails are statistical systems and carry no absolute guarantee. The Customer acknowledges that: (a) Obstruo does not warrant that every instance of personal or sensitive data will be detected and redacted; (b) guardrails and fail-closed behaviour may produce false positives and block legitimate requests, and Obstruo is not liable for the business consequences of such blocking; (c) where the Customer enables reversible tokenization, the ability to restore original values is a Customer-selected configuration and the Customer is responsible for assessing its risk; (d) the Customer remains responsible for judging whether the Service's level of effectiveness is adequate for its data and use case, and for configuring the Service accordingly. Obstruo's liability for failures of redaction is addressed in Section 11 and is not excluded by this Section.

2.5 No legal advice and no certification. Reports, audit trails, posture scores, framework readiness indicators, exposure maps, DPIA and ROPA registers, and other outputs of the Panel are technical tools that assist the Customer's own compliance work. They do not constitute legal advice, do not certify the Customer or Obstruo against any standard or framework, and do not discharge any obligation the law places on the Customer.

2.6 Changes and deprecation. Obstruo may improve or modify the Service. For changes that remove or incompatibly alter documented API functionality, Obstruo will give at least 6 months' notice, except where a shorter period is required for security or legal reasons, or where the functionality is a beta or preview feature under Section 17.

3.

Account and access

3.1 The Service is available only to legal entities acting in the course of business.

3.2 Free plan. Obstruo offers a free plan with the token, provider key and audit retention limits set out in its published pricing. The free plan is provided "as is", without service levels or support commitments, and Obstruo may modify or withdraw it with 30 days' notice. It runs for an indefinite term and either party may end it at any time with immediate effect. Audit records held under the free plan are deleted at the end of the plan's retention window and cannot be recovered afterwards.

3.3 The Customer is responsible for all activities of its Users and for maintaining the confidentiality of credentials, API keys, and any provider credentials it stores in the Service.

3.4 Obstruo may suspend the Customer's access upon material breach of these Terms with 5 business days' prior notice, or immediately and without prior notice where the breach creates a security risk to the Service, to other customers, or to Upstream Provider accounts.

4.

Acceptable use

4.1 The Acceptable Use Policy published alongside these Terms forms part of them and expands this Section. In addition, the Customer must not use the Service to:

  • deliberately circumvent or defeat the redaction, guardrail or MCP tool-permission functions;
  • process special categories of personal data (Art. 9 GDPR), including health data, without Obstruo's prior written consent and the additional measures set out in an executed DPA;
  • violate EU or national law, including practices prohibited by Article 5 of the AI Act;
  • reverse engineer, probe or disrupt the Service's infrastructure, except as permitted by mandatory law;
  • resell or white-label the Service without a separate written agreement;
  • operate high-risk applications, including medical diagnosis without human oversight, life-support systems, autonomous vehicles, critical infrastructure control, or weapons systems.

4.2 Upstream terms. The Customer must comply with the usage policies of the Upstream Providers it configures, under its own agreement with each of them. The Customer acknowledges that a violation may result in the Upstream Provider restricting or suspending the Customer's own provider account, and that Obstruo may suspend routing to a provider where that provider or applicable law requires it, or where necessary to protect the integrity of the Service. The Customer must not use the Service, including its routing features, to circumvent territorial or entity-based restrictions imposed by an Upstream Provider.

4.3 Adversarial testing. Penetration testing, red-teaming or other adversarial testing of the redaction, guardrail, MCP gateway or routing functions requires Obstruo's prior written approval, requested at office@obstruo.ai. Obstruo will not unreasonably refuse approval for testing conducted under a documented security assessment.

4.4 Model and tool selection. The Customer is solely responsible for selecting Upstream Providers, models, MCP servers, tool permissions and configurations appropriate for its use case, including any regulated, high-risk or customer-facing use, and for the consequences of tools it permits an agent to call.

4.5 Sanctions and export controls. Each party represents that it is not subject to, and will not make the Service available to any person subject to, applicable EU, UK or US sanctions or export control restrictions. Obstruo may suspend the Service immediately where continued provision would breach those restrictions.

5.

Customer data and intellectual property

5.1 The Customer retains all rights to Customer Data and to its configurations, policies and registry entries. Audit logs and reports generated by the Service from Customer Data are Customer Data.

5.2 Obstruo retains all rights to the Service, its software, models (including redaction and guardrail models), infrastructure and documentation. No rights are granted except the limited right to use the Service during the term.

5.3 Service improvement. Obstruo may use aggregated operational metadata to operate, secure and improve the Service, such as counts of redactions by entity type, latency, routing outcomes and error rates. Request and response bodies, audit log content and any other Customer Data are not used for this purpose, and Customer Data is not used to train models.

5.4 The Customer warrants that it has a lawful basis for the processing of personal data it submits through the Service and that its instructions to Obstruo comply with applicable law.

6.

Fees and payment

6.1 Fees, billing model and currency are specified in the Order. Plans are tiered monthly subscriptions priced in EUR, with limits on tokens, provider keys, seats and audit retention as set out in Obstruo's published pricing. A change to the pricing page does not constitute an amendment of these Terms; a fee increase binds the Customer from the first billing period starting at least 30 days after notice. Fees are exclusive of VAT and other applicable taxes, which are added at the applicable rate. Subscription fees are invoiced in advance for each billing period, monthly or annually as selected in the Order.

6.2 Invoices are payable within 14 days. If payment is overdue by more than 14 days, Obstruo may suspend the Service after written notice until payment is received.

6.3 Renewal. Subscriptions renew automatically for successive periods equal to the term selected in the Order, monthly or annual, unless cancelled from the Panel or by written notice before the end of the current period. Cancellation takes effect at the end of the period already paid for, and the Service remains available until then.

6.4 Fees are non-refundable for paid periods already elapsed, except as expressly provided for SLA credits where an SLA has been agreed, or on termination under Section 13.3.

6.5 Usage above plan limits. On the free plan, the Service stops accepting requests once a plan limit is reached. On paid plans, usage above the plan limit is metered and invoiced in arrears at the rate set out in Obstruo's published pricing, together with the next periodic invoice. The Panel provides configurable usage alerts. The Customer is responsible for configuring those alerts and for monitoring its own consumption, and Obstruo is not liable for charges arising from usage by the Customer, its Users, or automated systems and agents operating with the Customer's credentials.

7.

Confidentiality

7.1 Each party will protect the other party's confidential information with at least reasonable care and use it only to perform under these Terms.

7.2 Customer Data is the Customer's confidential information and is disclosed only to the subprocessors listed in the DPA.

7.3 Disclosure required by law or by a court or regulator is permitted; the disclosing party will notify the other party where legally permitted.

7.4 Confidentiality obligations survive for 5 years after termination.

8.

Data protection

8.1 Where a DPA has been executed, it governs the processing of personal data within Customer Data and prevails over these Terms on personal data matters. Until a DPA is executed, Obstruo processes personal data within Customer Data solely to provide the Service as configured by the Customer and on the Customer's documented instructions.

8.2 Where the Customer is itself a processor for its own clients, Obstruo acts as a subprocessor and the DPA applies accordingly.

8.3 No training on Customer Data. Obstruo does not use Customer Data to train models. Requests are routed to Upstream Providers under the Customer's own provider credentials, so whether a provider may use submitted data for model training, and any opt-out from that use, is governed by the Customer's agreement with that provider and is configured by the Customer on its own provider account. Obstruo cannot set or change those options on the Customer's behalf.

8.4 Processing location and hosting. Obstruo's infrastructure is hosted on OVHcloud Public Cloud instances operated by OVH SAS in France, within the European Economic Area. Obstruo processes Customer Data in the region selected by the Customer for the relevant endpoint. Where the Customer routes a request to an Upstream Provider whose endpoint is outside the EEA, that transfer is made on the Customer's instruction and is recorded in the audit log. OVH SAS is a subprocessor of Obstruo and is listed in the subprocessor annex. Upstream Providers accessed under the Customer's own credentials are not subprocessors of Obstruo: the transfer to them is made on the Customer's instruction and under the Customer's own arrangements with that provider. Obstruo also engages subprocessors for transactional e-mail delivery and for the business e-mail service through which it receives support correspondence, as listed in the subprocessor annex. Customers should not send Customer Data to Obstruo by e-mail where it is not necessary, since e-mail is processed outside the gateway and outside the redaction path.

8.5 Security measures. Obstruo maintains technical and organisational measures appropriate to the risk, including at minimum: encryption of Customer Data in transit over TLS 1.2 or higher, with mutual TLS between internal services; encryption at rest at both the storage volume layer and the application layer; logical separation of Customer environments; role-based access control over production systems; multi-factor authentication for Panel accounts, which the Customer may enforce across its whole organisation, and which an individual User may enable for their own account; application-layer encryption keys held in a dedicated secrets manager, so that direct access to the data stores yields ciphertext only; multi-factor authentication enforced for Obstruo personnel on all systems that support it; access to production data stores restricted to a strictly limited number of named administrator identities; weekly full backups with daily incremental backups, retained for 30 days and then overwritten; logging of actions taken in the Panel, retained for the same period as the Customer's audit log under its plan; audit logging of key retrieval from the secrets manager; and hosting in EU facilities operated by a provider that maintains an independently audited information security management system. Obstruo may update these measures provided the level of protection is not reduced.

8.6 Data minimisation in logs. Redaction is applied in memory while a request is in flight. Where redaction is enabled and matches, only post-redaction content is written to the audit log and to Obstruo's operational logs, and the mapping that allows a reversible token to be resolved is held in a cache operated without persistence, so that it is not written to durable storage and is lost on restart. Obstruo does not therefore expect to hold unredacted personal data at rest. This is a description of how the Service operates, not a warranty that no personal data is ever persisted, because content will reach durable storage where: (a) the Customer has not enabled redaction, or has not configured a recogniser covering the relevant data category; (b) the Customer has enabled raw-audit mode for a project, in which redaction may be skipped and requests and responses are stored as submitted; or (c) redaction does not match a particular value, which Section 2.4 confirms can occur. Raw-audit mode is off by default and can be enabled only by the Customer, through an explicit confirmation step in the Panel. Enabling it is the Customer's documented instruction, and the Customer remains responsible as controller for the resulting processing and for the lawfulness of storing unredacted content. Activation is recorded in the organisation's log, including the User who enabled it and the time.

9.

Warranties and disclaimers

9.1 Obstruo warrants that the Service will perform materially as described in the Documentation, meaning the product documentation available in the Panel and the published pricing page. Statements on Obstruo's website, in marketing materials or in sales discussions do not form part of that warranty.

9.2 Except as expressly stated in these Terms, the Service is provided "as is", and Obstruo disclaims all other warranties, express or implied, to the maximum extent permitted by law, including fitness for a particular purpose. Statutory warranty (rękojmia) is excluded to the fullest extent permitted between businesses.

9.3 Certification status. Obstruo does not hold, and does not claim to hold, certification or attestation against ISO 27001, ISO 42001, SOC 2, HIPAA or any comparable framework. Obstruo's internal controls are designed with reference to the control objectives of those frameworks, which is a design intention and not an audited result. OVHcloud holds ISO 27001 and ISO 27701 certification covering the Public Cloud infrastructure services on which the Service runs; that certification applies to the infrastructure layer within the scope of OVHcloud's own certificate and does not extend to the Service or to Obstruo's own controls.

9.4 Obstruo makes no representation that use of the Service establishes the Customer's compliance with the GDPR, the AI Act or any other regulation. Where a Customer requires an independent assurance report, the parties may agree the terms on which one is obtained.

10.

Indemnification

10.1 By the Customer. The Customer will defend and indemnify Obstruo against third-party claims arising from (a) Customer Data, including claims that its submission or processing as instructed by the Customer infringes the rights of third parties or violates law; and (b) the Customer's breach of Section 4.

10.2 By Obstruo. Obstruo does not provide an intellectual property indemnity under these Terms. Where one is required, it may be agreed in an Enterprise Order, subject to a cap and to carve-outs for Customer Data, output generated by an Upstream Provider, modifications not made by Obstruo, and combinations with materials Obstruo did not supply.

11.

Limitation of liability

11.1 Exclusions. To the maximum extent permitted by law, Obstruo is not liable for (a) acts or omissions of Upstream Providers or of MCP servers registered by the Customer; (b) damage caused by the Customer's configuration of the Service, including tool permissions and routing rules; (c) the content of outputs generated by Upstream Providers; (d) consequences of use in breach of Section 4; (e) indirect and consequential damages, including lost profits and loss of data held on the Customer's side.

11.2 Cap. Each party's aggregate liability under these Terms is limited to the greater of (a) the fees paid by the Customer in the 12 months preceding the event giving rise to the claim and (b) EUR 100. The floor matters on the free plan, where fees paid are zero and a bare fee-based cap would amount to a total exclusion. The cap does not apply to the Customer's payment obligations, to the indemnification obligations under Section 10, or to liability for breach of Section 4.

11.3 Redaction and guardrail failures. For the avoidance of doubt, liability for a failure of the redaction function, meaning personal data transmitted to an Upstream Provider despite configured redaction, is not excluded, but is subject to the cap in Section 11.2.

11.4 No cap. Nothing in these Terms limits liability for wilful misconduct, gross negligence, death or personal injury, or any liability that cannot be limited under applicable law. Liability for damage caused intentionally cannot be excluded or limited in advance under art. 473 § 2 of the Polish Civil Code.

11.5 Contractual liability between the parties is separate from each party's own regulatory responsibility under the GDPR and other regulation. These Terms do not shift responsibilities that the law assigns to the Customer as controller or to Obstruo as processor.

12.

Term and termination

12.1 The agreement runs for the monthly or annual term stated in the Order and renews under Section 6.3. Either party may terminate with 30 days' notice to the end of the current term.

12.2 Obstruo may terminate with immediate effect upon material breach of Section 4, non-payment persisting after notice under Section 6.2, or Customer actions that endanger the security of the Service.

12.3 Either party may terminate with immediate effect if the other party commits a material breach and fails to cure it within 30 days of receiving written notice.

12.4 The Customer may additionally terminate without further charge for the remaining term if Obstruo materially changes these Terms to the Customer's detriment (Section 13.3), or for chronic failure of an SLA where one has been agreed.

12.5 After termination, Customer Data remains available for export for 30 days, after which it is deleted. Export is available as CSV from the Panel and, on plans that include the audit log API, also through that API, in each case covering the audit history retained under the Customer's plan and shown in the Panel. Data already outside the plan's retention window is not recoverable. Following deletion, residual copies may persist in encrypted backups for up to 30 days until they are overwritten in the ordinary backup cycle, and remain subject to the confidentiality and security obligations in these Terms. At the Customer's request made before the end of the export window, the parties may agree paid extended storage.

13.

Changes to these Terms

13.1 Obstruo may amend these Terms with at least 30 days' notice by e-mail.

13.2 For self-serve subscriptions, continued use after the effective date constitutes acceptance. For Customers with a negotiated Order, amendments require written agreement of both parties.

13.3 If an amendment materially reduces the Customer's rights, the Customer may terminate before the effective date without charge for the remaining prepaid term, and Obstruo will refund the unused portion pro rata.

14.

Force majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, including internet backbone failures, acts of government and natural disasters. The affected party will notify the other and take reasonable steps to mitigate. If force majeure persists beyond 30 days, either party may terminate the affected Order.

15.

Publicity

Obstruo may identify the Customer by name and logo as a customer reference on its website and in its marketing materials. The Customer may opt out at any time by written notice to office@obstruo.ai, and Obstruo will remove the name and logo within 30 days of receiving that notice. Any use beyond name and logo, including case studies, quotations, or descriptions of the Customer's deployment, requires the Customer's prior written consent.

16.

Support

Support is provided by e-mail only, at office@obstruo.ai. Requests are handled during Obstruo's business hours on business days in Poland, excluding public holidays. Response times are committed only where they are expressly agreed in an Order; otherwise Obstruo responds as soon as reasonably practicable. No response time is committed on the free plan.

17.

Beta and preview features

Features identified in the Panel or the Documentation as beta, preview or forthcoming, including the kill switch, human oversight and deferred-control workflows, and the agent and skill registries, are provided without warranty, may change or be withdrawn at any time, and are excluded from Sections 2.2 and 9.1.

Section 11.3 continues to apply to the production redaction path even where a beta feature is enabled. It does not apply to redaction or guardrail behaviour of a feature that is itself expressly labelled beta or preview.

18.

Governing law and disputes

18.1 These Terms are governed by Polish law, excluding conflict-of-law rules.

18.2 The Polish common courts have exclusive jurisdiction over any dispute arising out of or in connection with these Terms, and specifically the court having jurisdiction over Obstruo's registered office in Poznań. This is an exclusive choice of court agreement for the purposes of Article 25 of Regulation (EU) 1215/2012. The parties may agree in an Order to submit disputes instead to the Court of Arbitration at the Polish Chamber of Commerce in Warsaw.

18.3 These Terms are made in English, which is the binding version. A Polish translation is available on request from office@obstruo.ai. Where a translation is provided, it is for convenience only and the English version prevails in the event of any discrepancy.

19.

Miscellaneous

19.1 These Terms, the Order, the DPA and the annexes are the entire agreement and supersede prior discussions. Order terms prevail over these Terms; the DPA prevails for personal data matters.

19.2 Neither party may assign the agreement without the other's consent, except to an affiliate or in connection with a merger or sale of substantially all assets, with notice.

19.3 If a provision is invalid, the remainder stays in force and the parties will replace the invalid provision with a valid one closest in effect.

19.4 Notices are given by e-mail to the addresses designated in the Panel or the Order, and to Obstruo at office@obstruo.ai.

19.5 Provisions which by their nature should survive termination, including Sections 5, 7, 10, 11, 18 and 19, survive termination of the agreement.

20.

Annexes

  • Annex 1: Data Processing Agreement, required by Art. 28 GDPR. In preparation.
  • Annex 2: SLA, where agreed in an Enterprise Order.
  • Annex 3: DORA addendum for financial-sector Customers, covering the service description and levels, processing locations, incident support, participation in threat-led penetration testing, termination rights and exit support.
  • Annex 4: Subprocessor list, maintained as a static annex. The subprocessors engaged for the processing of Customer Data are: OVH SAS (France), hosting infrastructure; Scaleway SAS (France), delivery of transactional e-mail sent by the Service; and Microsoft (Ireland), the business e-mail service through which Obstruo receives support correspondence, on a tenant located in the European Union. All three process Customer Data within the EEA. Obstruo will give 30 days' advance notice by e-mail before adding a subprocessor, and the Customer may object on reasonable data-protection grounds.