Welcome to CrafyCAPTCHA, operated by Maximiliano Nicolás Alemandi, doing business as Crafy Holding ("we", "our" or the "Company"). By registering, accessing, or using the CrafyCAPTCHA services and its associated SDKs (collectively, the "Service"), you ("Client", "User") agree to be bound by these Terms of Service ("Terms"). If you do not agree to these Terms, do not use the Service.
These Terms apply specifically to business customers (B2B) utilizing our Service to protect their applications. By using the Service, you represent and warrant that you are at least 18 years of age or the age of legal majority in your jurisdiction, and have the legal capacity to enter into a binding contract.
1. Description of Service
CrafyCAPTCHA is a Software as a Service (SaaS) designed to secure web applications against bots, massive traffic DDoS attacks, and spam using an adaptive friction system. The Service provides a frontend widget and backend SDKs for human traffic validation and fraud mitigation.
2. Merchant of Record and Billing
Our order process is conducted by our online reseller Armitage Labs OÜ (Creem), based in Estonia. Creem is the Merchant of Record for all our orders. They process all payments, manage subscription billing, and issue invoices. Customer service inquiries related to payments and billing should be directed to Creem, although we are happy to assist where possible.
3. Acceptable Use and Restrictions
You agree to use the Service exclusively for lawful purposes. We reserve the right to suspend or revoke access to the Service immediately, without prior notice or right to refund, if we determine the Service is being used for:
- Protecting unlawful or illegal operations under applicable international or local laws.
- Protecting or facilitating the distribution of malware, ransomware, phishing sites, or fraud schemes.
- Discriminatory Blocking: Using the Service to unjustly block or discriminate against end-users based on race, religion, sexual orientation, gender identity, or other protected classes.
- Unjustified Geo-blocking: Blocking entire countries or regions without a documented security justification.
- Deliberately attempting to bypass our Rate Limiting systems or reverse-engineer our API.
- Intentionally saturating our servers or performing load/DDoS testing against CrafyCAPTCHA's infrastructure without prior written authorization.
4. Security, Technical Environment, and Client Responsibilities
4.1. Credential Custody
The Client receives access keys (including a public_token and a secret_key). The Client is solely responsible for maintaining the absolute confidentiality of their secret_key.
The secret_key must never be exposed on the client-side (including, but not limited to, frontend code, JavaScript executed in the browser, or public mobile applications). Any breach, quota abuse, or security incident resulting from the exposure of the secret_key exempts CrafyCAPTCHA from all liability, placing it entirely on the Client.
4.2. Local Environment Requirements
Our backend SDKs rely on writing temporary files (such as .lock files for nonce management and .json for caching) to prevent Replay Attacks and optimize performance.
- The Client accepts that it is their exclusive responsibility to ensure their server environment has the appropriate read, write, and retention permissions for these directories.
- If the Client disables, prematurely purges, or misconfigures these directories, compromising the security of the validation flow, CrafyCAPTCHA is not responsible for resulting breaches.
5. Upstream Dependencies and Sub-processors
The CrafyCAPTCHA widget dynamically injects third-party scripts, specifically Cloudflare Turnstile (challenges.cloudflare.com) and utilizes Cloudflare infrastructure.
- Sub-processor Changes: We will provide a 30-day notice via email or dashboard notification before adding or changing critical sub-processors. The Client has the right to object to such changes. If the objection cannot be reasonably accommodated, the Client may terminate their contract.
6. Service Level Agreement (SLA)
We strive to maintain a 99.9% uptime for our API validation endpoints. However, this SLA excludes:
- Scheduled maintenance (notified in advance).
- Force majeure events.
- Outages caused by upstream providers (e.g., global Cloudflare routing issues).
In the event we fail to meet this SLA in a given calendar month, affected paying Clients are eligible to request service credits proportional to the downtime, up to a maximum of 50% of their monthly subscription fee.
7. Privacy and Data Processing Agreement (DPA)
In the context of data protection regulations (such as GDPR or CCPA), CrafyCAPTCHA acts as the "Data Processor", while the Client acts as the "Data Controller" regarding end-user data.
By accepting these Terms, the Client simultaneously accepts and agrees to be bound by our Data Processing Agreement (DPA), which is incorporated herein by reference and is available at Data Processing Agreement.
7.1. Client Obligations
The Client commits to:
- Transparently disclose in their own Privacy Policy that they use CrafyCAPTCHA (and its sub-processors) for bot mitigation.
- Obtain explicit end-user consent before loading the widget, if the jurisdiction applicable to the Client's traffic requires it.
8. Licenses and Intellectual Property
- SDKs and Open Source: The source code of the SDKs (client and server) provided by CrafyCAPTCHA via platforms like GitHub, NPM, PyPI, or Packagist is distributed under the MIT License.
- Proprietary API and System: The CrafyCAPTCHA backend infrastructure, risk evaluation algorithms, control panel, and main API are proprietary commercial services. Reverse engineering, copying, or reproducing these core systems is strictly prohibited.
9. Disclaimer of Warranties
9.1. False Positives and Evasion
No security system is infallible. The Service is provided "AS IS" and "AS AVAILABLE". CrafyCAPTCHA does not guarantee the interception or blocking of 100% of automated traffic, malicious bots, or advanced scripts.
Furthermore, the Client understands that the adaptive friction system may occasionally block or excessively challenge legitimate human users (false positives).
10. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL CRAFYCAPTCHA, ITS DIRECTORS, EMPLOYEES, OR AFFILIATES BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES.
This includes, without limitation:
- Loss of revenue, lost profits, or loss of business opportunities.
- Loss of conversions or sales resulting from the blocking of users (false positives).
- Damages resulting from DDoS attacks that successfully evade protections.
CrafyCAPTCHA's total liability to the Client for any claim under these Terms shall not exceed the total amount paid by the Client to CrafyCAPTCHA during the twelve (12) months prior to the event giving rise to the claim.
11. Indemnification
The Client agrees to defend, indemnify, and hold harmless CrafyCAPTCHA and its affiliates from any claim, demand, damages, obligation, loss, cost, or debt (including reasonable attorneys' fees) arising from the Client's improper use of the Service, violation of any term of this agreement (including exposing the secret_key), or third-party claims arising from traffic blocking or privacy issues if the Client failed to fulfill their Data Controller obligations.
12. General Provisions
- Severability: If any provision of these Terms is deemed invalid or unenforceable, the remaining provisions will remain in full force and effect.
- Governing Law and Jurisdiction: These Terms shall be governed by and construed in accordance with the laws of Santa Fe, Argentina. Any legal dispute shall be submitted to the exclusive jurisdiction of the courts located in Santa Fe, Argentina.
- Class Action Waiver: YOU AGREE THAT ANY DISPUTE RESOLUTION PROCEEDINGS WILL BE CONDUCTED ONLY ON AN INDIVIDUAL BASIS AND NOT IN A CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION. By accepting these Terms, you waive your right to participate in a class action lawsuit against the Company.
13. Modifications to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated to active Clients at least 30 days in advance via email or dashboard notification. Continued use of the Service after such notice constitutes acceptance of the revised Terms.
Contact
If you have any questions, technical inquiries, or legal requirements regarding these Terms, please contact us via:
- Customer Support: https://captcha.crafy.net/support/