Legal
Hillwinds Terms of Service
1. SaaS Services and Support
Subject to the terms hereof, Hillwinds LLC (“Company”) will provide Customer with reasonable support services in accordance with the Company’s standard service practice.
The Services include the Hillwinds web platform, the Hillwinds Intelligence API, and the Hillwinds outbound email sequencing features, in each case to the extent included in Customer’s Order Form or subscription plan.
2. Restrictions and Responsibilities
- Prohibited Actions: Customers will not reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure related to the Services or Software. Customers may not modify, translate, or create derivative works based on the Services. Customer shall not use the Services or any data obtained from the Services to train, fine-tune, or develop a standalone data product, commercial dataset, or artificial intelligence model that replaces, replicates, or commercially competes with the Services.
- Use Limitations: The Services may not be used for timesharing, service bureau purposes, or otherwise for the benefit of a third party. Customer shall not resell, sublicense, distribute, or otherwise make available to any third party any data obtained through the Services without prior written consent. Data must be used solely for internal business purposes, and using data to build, train, or enhance a competing product is strictly prohibited.
- Automated Access: Customer may use data obtained from the Services within its internal systems, including in automated workflows, analytics tools, and decision-support systems. Customer shall not use any automated means, including bots, AI agents, scraping tools, scripts, or crawlers, to access or extract data directly from the Services, except through the API as expressly permitted under Section 10 (API Access and Use).
- Compliance: Customer represents and warrants that they will use the Services only in compliance with the Company’s standard published policies and all applicable laws and regulations. Customer may not remove or export the Services in violation of United States export laws.
- Account Security: Customer is responsible for obtaining the equipment needed to access the Services and for maintaining the security of their account, passwords, API credentials, connected mailbox authorizations, and files.
- Indemnification for Misuse: Customer agrees to indemnify and hold harmless the Company against any damages, losses, or expenses arising from an alleged violation of these restrictions or Customer’s use of the Services.
3. Confidentiality and Proprietary Rights
- Protection of Information: “Proprietary Information” means any non-public business, technical, financial, product, security, or other information disclosed by or on behalf of one party to the other that is identified as confidential or that reasonably should be understood to be confidential given the nature of the information or circumstances of disclosure. Each party will use reasonable precautions to protect the other party’s Proprietary Information and will use such information only to perform or exercise its rights under this Agreement. A party may disclose Proprietary Information to its employees, contractors, professional advisers, and service providers who need to know such information and are subject to confidentiality obligations at least as protective as those contained in this Agreement. These obligations do not apply to information that the receiving party can demonstrate: (a) is or becomes publicly available without breach of this Agreement; (b) was lawfully known by the receiving party without restriction before disclosure; (c) is received lawfully from a third party without confidentiality obligations; or (d) is independently developed without use of the disclosing party’s Proprietary Information.
- Ownership: The Company owns and retains all right, title, and interest in the Services, Software, improvements, and all related intellectual property rights. This includes any proprietary datasets or structured outputs generated by the Company.
- Hillwinds Data: Hillwinds Data means all data, records, outputs, exports, downloads, reports, enrichments, signals, Contact Data, API outputs, and other information made available by or through the Services, including any copies, extracts, caches, or derivative datasets that contain or substantially reproduce such information. Hillwinds Data does not include Customer Data or Customer Communications Data.
- Customer License: Subject to Customer’s payment of all applicable fees and continued compliance with this Agreement, the Company grants Customer, during the applicable subscription term, a limited, non-exclusive, non-transferable, non-sublicensable right to use Hillwinds Data solely for Customer’s authorized internal business purposes and only as permitted by the applicable Order Form. No rights are granted except as expressly set forth in this Agreement or an applicable Order Form.
- Data Usage: The Company may collect and analyze data to improve the Services and may disclose such data solely in aggregate or other de-identified form. The Company will not use Customer-provided customer lists to enrich datasets made available to other customers.
- Connected Mailbox Content: Customer retains all right, title, and interest in the contents of its connected mailboxes, its message templates, and its sequence content (“Customer Communications Data”). The Company processes Customer Communications Data solely to provide the Services to Customer, to secure and support the Services, and as otherwise described in the Privacy Statement. The Company does not use Customer Communications Data to build, enrich, or supplement any dataset made available to other customers.
4. Payment of Fees
Customer will pay the Company the applicable fees described in their specific Order Form or selected subscription plan. Certain features, actions, lookups, and other usage events are metered in, and consumed as, Credits, as described in Section 4.1 (Credits). Fees may be paid through the Company’s third-party payment processor or by invoice, as specified in the applicable Order Form or subscription plan. Where Customer provides payment information to the Company’s payment processor, Customer authorizes the Company and its payment processor to charge the designated payment method for all applicable fees, including recurring subscription charges. Where fees are invoiced, Customer will pay each invoice in accordance with the payment terms stated in the applicable Order Form or invoice.
The Company reserves the right to change the Fees or applicable charges and to institute new charges and Fees at the end of the Initial Service Term or then-current renewal term, upon thirty (30) days prior notice to Customer. If Customer believes that the Company has billed Customer incorrectly, Customer must contact the Company no later than 60 days after the closing date on the first billing statement in which the error or problem appeared, in order to receive an adjustment or credit. Unpaid amounts are subject to a finance charge of 1.5% per month on any outstanding balance, or the maximum permitted by law, whichever is lower, plus all expenses of collection and may result in immediate termination of Service. Customer shall be responsible for all taxes associated with Services other than U.S. taxes based on the Company’s net income.
4.1 Credits
“Credits” are the unit of measure the Company uses to meter Customer’s consumption of designated features, actions, lookups, requests, and other usage events across the Services, including the web platform, the API, and the outbound sequencing features. Customer’s Order Form or subscription plan sets out the number of Credits allocated to Customer and the applicable price per Credit, and the Credit Schedule (defined below) sets out how many Credits each designated action consumes. Each designated action draws down Customer’s Credit balance when performed.
The “Credit Schedule” means the Company’s then-current schedule of Credit-consuming features, actions, and events and the number of Credits each consumes, which the Company makes available through the Services or its documentation and may update from time to time. The Company may, from time to time, update the Credit Schedule to (i) designate additional features, actions, or events as consuming Credits, and (ii) change the number of Credits required for any feature, action, or event. The Company will use commercially reasonable efforts to provide advance notice of material changes to the Credit Schedule where practicable, except where a change is necessary for security, legal compliance, or system integrity. Changes apply prospectively and do not reduce the number of Credits already allocated to Customer.
Except as expressly provided in an Order Form or written agreement between the parties executed before July 30, 2026, or where the Company has expressly designated a feature or action as not consuming Credits, all designated features, actions, and events consume Credits, and the Company may meter any feature, action, or event of the Services against Customer’s Credit balance. For an Order Form or written agreement executed before July 30, 2026, Credit consumption applies only to the extent, and for the features and actions, expressly set out in that agreement for the remainder of its then-current term; upon its next renewal, the Company’s then-current Credit Schedule and Credits terms apply.
Unless otherwise stated in the Order Form, Credits are non-refundable, non-transferable, may not be exchanged for cash or other services, and expire upon the earlier of (i) twelve (12) months after being granted or (ii) expiration or termination of the Agreement. Customer is responsible for monitoring its Credit consumption. Any use in excess of Customer’s available Credits, or of any applicable usage, rate, concurrency, or Service Capacity limit, may be subject to additional fees, suspension, throttling, or other remedies.
Credits are a single, unified balance. Any reference in these Terms, an Order Form, the Company’s documentation, or the user interface to “API credits” means Credits consumed for API usage; it does not create a separate or additional pool of credits and is governed by this Section 4.1.
5. Term and Termination
The Agreement begins on the Effective Date and continues for the Initial Service Term specified in the Order Form or selected subscription plan. The Agreement then renews automatically for successive renewal terms of the same duration as the Initial Service Term, at the Company’s then-current rates, unless either party gives written notice of non-renewal at least thirty (30) days prior to the end of the then-current term.
Where Customer purchases through a self-serve subscription plan, Customer may turn off renewal at any time from within the Services or by contacting the Company, effective at the end of the then-current term.
Either party may terminate this Agreement upon written notice if the other party materially breaches this Agreement and fails to cure such breach within thirty (30) days after receiving written notice. Customer will pay in full for the Services provided up to and including the last day on which the Services are provided.
Upon expiration or termination of this Agreement or an applicable Order Form, including termination for nonpayment, Customer shall immediately cease accessing and using all data, records, outputs, exports, downloads, reports, enrichments, signals, Contact Data, API outputs, and other information made available by or through the Services, including any copies, extracts, caches, or derivative datasets that contain or substantially reproduce such information (collectively, “Hillwinds Data”). Within thirty (30) days after expiration or termination, Customer shall permanently delete all Hillwinds Data from all systems, databases, customer relationship management systems, data warehouses, files, devices, and other storage within Customer’s possession or control. Customer shall also cause its employees, affiliates, contractors, service providers, and any other persons or entities to whom Customer provided Hillwinds Data to comply with these cessation-of-use and deletion requirements.
Upon the Company’s request, Customer shall provide written certification, signed by an authorized representative of Customer, confirming compliance with the foregoing requirements. Customer may retain Hillwinds Data only to the minimum extent required by applicable law, contained in routine backups not reasonably accessible in the ordinary course of business, or necessary to maintain suppression or opt-out records. Any retained Hillwinds Data shall remain subject to this Agreement, may not be accessed or used for any other purpose, and shall be deleted when the applicable basis for retention ends.
Accrued rights and obligations relating to payment, confidentiality and proprietary rights, restrictions on Customer’s use or retention of data, warranty disclaimers, limitations of liability, indemnification obligations, and the post-termination obligations in this Section 5 will survive expiration or termination of this Agreement.
6. Warranty and Disclaimer
The Company shall use commercially reasonable efforts to maintain the Services in a manner which minimizes errors and interruptions. However, the Company does not warrant that the Services will be uninterrupted or error-free. THE SERVICES ARE PROVIDED “AS IS” AND THE COMPANY DISCLAIMS ALL WARRANTIES, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. Data is provided “AS IS” without warranty of accuracy or completeness.
7. Limitation of Liability
Except for bodily injury, the Company shall not be liable for any indirect, exemplary, incidental, special, or consequential damages. THE COMPANY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT OR THE SERVICES WILL NOT EXCEED THE AMOUNTS PAID BY CUSTOMER TO THE COMPANY DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM.
8. Indemnification and Compliance
Except as expressly set forth in an applicable Order Form or other written agreement signed by the Company, the Company has no obligation to indemnify Customer. Customer is solely responsible for compliance with all applicable marketing, privacy, and communication laws (including TCPA, CASL, GDPR). Customer shall indemnify the Company for any claim arising from Customer’s marketing activities, including without limitation the CAN-SPAM Act, CASL, the TCPA, the GDPR, and applicable U.S. state privacy laws.
Customer shall indemnify, defend, and hold harmless the Company from and against any claim, liability, loss, damage, cost, or expense (including reasonable attorneys’ fees) arising out of or relating to:
(a) Customer’s marketing, outreach, or other communications activities, including any message sent through the Services;
(b) the content of any message Customer composes, schedules, or sends through the Services;
(c) Customer’s use of Contact Data or any data obtained through the Services or the API; and
(d) any claim by a recipient, a mailbox provider, a regulator, or a data protection authority arising from Customer’s outbound activity.
“Contact Data” means the personnel and contact information made available through the Services, including names, titles, business email addresses, and LinkedIn URLs, where available.
9. Outbound Email and Sequencing
This Section applies where Customer is provisioned access to the Hillwinds outbound email sequencing features (the “Sequencer”).
9.1 Connected Mailboxes
The Sequencer operates by connecting Customer’s own email accounts (each, a “Connected Mailbox”) to the Services through OAuth authorization or other credentials Customer supplies. Messages are transmitted through Customer’s own mail provider and Customer’s own sending domain. Customer authorizes the Company and its email infrastructure providers to access the Connected Mailbox to the extent necessary to compose, schedule, send, sync, and record messages and replies.
Customer represents that it has all rights and authorizations necessary to connect each Connected Mailbox, including any authorization required from the mailbox owner and from Customer’s IT or security administrators. Customer may disconnect a Connected Mailbox at any time from within the Services, which revokes the Company’s ongoing access on a prospective basis.
9.2 Sender of Record
Customer is the sender of record for every message sent through the Sequencer. The Company is a technology provider and does not originate, review, approve, or endorse Customer’s messages. As between the parties, Customer is solely responsible for the recipients it selects, the content it sends, the frequency of sending, and the legal basis for contacting each recipient. Customer’s responsibility applies regardless of whether the Services generate, suggest, personalize, modify, or otherwise assist with message content, recipient selection, timing, or sequencing.
9.3 Compliance Requirements
Customer shall ensure that every message sent through the Sequencer:
(a) uses accurate and non-deceptive header information, “From” names, reply-to addresses, and subject lines;
(b) includes a functional opt-out mechanism that remains operable for at least thirty (30) days after transmission, and honors any opt-out request within ten (10) business days;
(c) is sent to a recipient Customer has a lawful basis to contact under the laws applicable to Customer and to the recipient; and
(d) complies with all applicable anti-spam, marketing, privacy, and telecommunications laws.
9.4 Prohibited Sending Practices
Customer shall not use the Sequencer to:
(a) send messages from a fictional identity, pseudonym, assumed identity, or alias, or otherwise disguise the origin or subject matter of a message;
(b) falsify or manipulate the originating address, subject line, headers, or transmission path;
(c) send from group, distribution, or role-based addresses (for example, info@, sales@, hello@);
(d) send unlawful unsolicited or harassing messages, or messages to any recipient who has opted out of Customer’s communications;
(e) send messages that generate an unacceptable rate of bounces, spam complaints, or unsubscribe requests, or attempt to conceal such rates;
(f) transmit malware, phishing content, or links to malicious code;
(g) circumvent sending limits, throttling, warmup controls, suppression lists, or any other control implemented in the Services; or
(h) send messages on behalf of a third party, or resell, sublicense, or otherwise make available the Sequencer to a third party.
9.5 Sensitive Data
The Sequencer is a business-to-business sales and marketing tool. Customer shall not transmit, upload, or otherwise process through the Sequencer any protected health information as defined under HIPAA, any individually identifiable health or claims information, Social Security numbers, financial account numbers, government identifiers, or any other category of sensitive personal information. The Company is not a business associate of Customer and the Services are not designed, configured, or offered as a HIPAA-compliant environment.
9.6 Engagement Tracking
The Sequencer may include optional open tracking, link tracking, and reply detection. Where Customer enables these features, Customer is solely responsible for determining whether such tracking is permitted in the recipient’s jurisdiction and for providing any required notice or obtaining any required consent. Customer can disable tracking features within the Services.
9.7 Sending Limits, Monitoring, and Suspension
The Company may impose and adjust sending limits, rate limits, throttling, warmup periods, and per-mailbox volume caps. The Company may monitor sending volume, bounce rates, complaint rates, unsubscribe rates, and content signals for purposes of security, deliverability, abuse prevention, compliance, and enforcement.
The Company may suspend, throttle, or disable Customer’s Sequencer access or any Connected Mailbox, in whole or in part, without prior notice, if the Company reasonably believes Customer has violated this Section, created a security or deliverability risk, generated abuse complaints, or caused or may cause harm to the Services, the Company, other customers, or third parties. The Company will use commercially reasonable efforts to notify Customer where practicable.
9.8 Deliverability Disclaimer
The Company does not warrant that any message will be delivered, will reach a recipient’s inbox rather than a spam or promotions folder, or will achieve any particular delivery, open, click, or reply rate. Deliverability depends on Customer’s domain reputation, authentication configuration, content, list quality, and the independent filtering decisions of mailbox providers, none of which are within the Company’s control. Customer is responsible for configuring and maintaining SPF, DKIM, and DMARC records for its sending domains.
9.9 Third-Party Email Infrastructure
The Company uses third-party email infrastructure providers to establish and maintain mailbox connectivity. Customer’s use of the Sequencer is additionally subject to the terms and policies of Customer’s own mail provider, including Google Workspace and Microsoft 365 terms and any applicable sending limits those providers impose. A current list of subprocessors is available on request at privacy@hillwinds.ai. Where a written agreement between the parties includes data protection terms, notice of new subprocessors will be provided as set out in that agreement.
10. API Access and Use
This Section applies where Customer is provided access to any application programming interface, developer tool, API key, token, credential, endpoint, or related documentation made available by the Company in connection with the Services (collectively, the “API”). Customer’s use of the API is subject to these Terms, the applicable Order Form, and any technical documentation, usage limits, or instructions the Company provides from time to time.
10.1 Credentials
Customer is responsible for all access to and use of the API through Customer’s API keys, tokens, credentials, accounts, systems, personnel, contractors, agents, or representatives, whether or not such access was authorized by Customer. Customer shall maintain the confidentiality and security of all API keys, tokens, credentials, and authentication methods, and shall not disclose, transfer, sublicense, publish, embed in publicly accessible code, include in client-side applications, or otherwise make available any API key, token, or credential to any third party except as expressly authorized by the Company in writing. Customer shall promptly notify the Company of any actual or suspected unauthorized access to the API, compromise of API credentials, or security incident affecting Customer’s systems that may impact the Services.
10.2 Restrictions
Customer shall not, directly or indirectly:
(a) access or use the API in excess of any usage limits, rate limits, credit limits, concurrency limits, or other restrictions specified in the applicable Order Form, documentation, or notice from the Company;
(b) attempt to circumvent, disable, interfere with, or bypass any authentication, authorization, metering, billing, rate limiting, monitoring, logging, security, or usage control mechanism;
(c) use the API to scrape, harvest, bulk extract, mirror, reconstruct, or create a substitute for the Services or any Company database, dataset, index, model, signal, enrichment, or structured output;
(d) use the API or any data obtained through the API to build, train, fine-tune, enhance, benchmark, validate, or commercialize any product, service, dataset, artificial intelligence model, machine learning model, data broker product, sales intelligence product, or other offering that competes with or is reasonably substitutable for the Services;
(e) resell, sublicense, distribute, publish, disclose, or otherwise make available API outputs or data obtained through the API to any third party, except as expressly permitted in the applicable Order Form or otherwise approved by the Company in writing;
(f) use the API for unlawful, deceptive, abusive, fraudulent, or unauthorized purposes, or in any manner that violates applicable marketing, privacy, data protection, anti-spam, consumer protection, or other laws or regulations; or
(g) access or use the API in a manner that could damage, disable, overburden, impair, or interfere with the security, integrity, availability, or performance of the Services or the Company’s systems.
For clarity, Customer’s ordinary-course submission of API requests metered against and within Customer’s purchased Credits, and Customer’s storage and use of the corresponding API outputs within Customer’s internal systems for Customer’s authorized internal business purposes, shall not by itself constitute prohibited scraping, bulk extraction, a substitute for the Services, or an impermissible persistent copy or substantial extract under this Section, provided that Customer does not (i) systematically download, enumerate, or reconstruct the Services’ data beyond Customer’s bona fide internal use, or (ii) resell, redistribute, or use such outputs in violation of Section 2, Section 3, or this Section 10.
10.3 Permitted Use of API Outputs
Unless otherwise expressly stated in the applicable Order Form, Customer may use API outputs solely for Customer’s internal business purposes. Customer may store and cache API outputs only to the extent reasonably necessary to support Customer’s authorized internal use of the Services, system performance, auditability, and ordinary-course business records. Except for storage and caching expressly permitted above, Customer shall not create, maintain, or commercialize any standalone or substantially complete copy, mirror, database, directory, or substantial extract of the Services, the Company’s data, or API outputs, including any collection that substitutes for or materially replicates the Services.
Upon expiration or termination of this Agreement or the applicable Order Form, Customer shall immediately cease accessing and using the API. API outputs constitute Hillwinds Data and are subject to the cessation-of-use, deletion, certification, retention, and survival requirements set forth in Section 5.
10.4 Downstream Users
If Customer allows its employees, contractors, agents, service providers, developers, consultants, or affiliates to access or use the API or API outputs, Customer shall ensure that such persons and entities access and use the API and API outputs solely on Customer’s behalf, solely for Customer’s authorized internal business purposes, and subject to confidentiality, security, and use restrictions at least as protective of the Company as those set forth in these Terms. Customer is responsible and liable for all acts and omissions of such persons and entities.
10.5 Monitoring and Suspension
The Company may monitor Customer’s API usage for purposes of security, compliance, billing, capacity planning, product improvement, support, fraud prevention, and enforcement. The Company may suspend, throttle, limit, revoke, rotate, or disable Customer’s API access or credentials, in whole or in part, if the Company reasonably believes that Customer has violated these Terms, exceeded applicable limits, created a security risk, failed to pay amounts due, caused or may cause harm to the Services or the Company’s systems, or used the API in a manner inconsistent with the intended operation of the Services. The Company will use commercially reasonable efforts to provide notice where practicable, but may act without prior notice where immediate action is necessary.
10.6 Credit Consumption for API Usage
API usage is metered in Credits as described in Section 4.1 (Credits). References to “API credits” mean Credits consumed for API usage; they draw from the same single, unified Credit balance described in Section 4.1 and are subject to the same terms, including those governing non-refundability, non-transferability, and expiration. Expired or unused Credits confer no right to continued API access after the term.
The Company may count API requests, responses, lookups, enrichments, returned records, or other usage events against Customer’s Credit balance in accordance with the Credit Schedule. Customer is responsible for monitoring its API usage. Any use in excess of Customer’s available Credits, usage limits, or Service Capacity may be subject to additional fees, suspension, throttling, or other remedies.
10.7 Changes to the API
The Company may modify, update, deprecate, or discontinue API endpoints, fields, functionality, documentation, usage limits, credit methodologies (including the Credit Schedule and the Credits terms described in Section 4.1), authentication methods, or technical requirements from time to time. The Company will use commercially reasonable efforts to provide advance notice of material changes where practicable, except where changes are necessary for security, legal compliance, system integrity, or continued operation of the Services.
Notwithstanding Section 6 or anything to the contrary, the API is provided “AS IS,” and the Company does not warrant that the API will be uninterrupted, error-free, backward-compatible, or available at any particular volume, latency, throughput, or performance level except as expressly set forth in the applicable Order Form.
11. Miscellaneous
This Agreement is not assignable or transferable by the Customer without prior written consent. It shall be governed by the laws of the State of New York. In any action to enforce rights, the prevailing party is entitled to recover costs and attorneys’ fees.