General Terms of Use and Service
Website • Free Plan • SaaS Platform • API • Institutional Services
Effective date: September 4, 2026 · Replaces the version of June 4, 2026
This is a courtesy translation. The Portuguese version is the legally binding document.
Important. Read these Terms before accessing or using any Espectrosint website, platform, API, content or output. By creating an account, using any Service, subscribing to a plan or clicking to accept, you agree to be bound by these Terms and by our Privacy Policy. If you do not agree, do not use the Services.
The Services are offered to professionals, organizations and individuals who use them for a lawful purpose. Where you are a consumer under the Brazilian Consumer Defense Code or a mandatory law of your country of residence, nothing in these Terms removes rights that cannot be waived.
- About us and these Terms
- Definitions
- Contract documents and precedence
- Eligibility, verification and authority
- Accounts, credentials and security
- Access rights and license
- Public website and content
- Free plan, previews and beta features
- Plans, credits, payment and renewal
- Lawful, ethical and acceptable use
- Technical and commercial restrictions
- Customer Data, searches, Investigations and Usage Data
- Outputs, Third-Party Sources and independent verification
- AI-generated analysis
- API and integrations
- Intellectual property, marks and feedback
- Confidentiality
- Privacy and data protection roles
- Security and service integrity
- Availability, support and changes to the Services
- Warranties, disclaimers and no sole reliance
- User indemnity
- Liability
- Suspension and termination
- Consequences of expiry or termination
- Changes to these Terms
- Notices and communications
- General provisions
- Trade controls, anti-corruption and regulatory compliance
- Ethics and compliance commitments
- Governing law and jurisdiction
- Contact
- Annex I — Data Processing Addendum
- Annex A — Processing details
- Service application matrix
1. About us and these Terms
1.1. The Services are provided by Espectrosint ("Espectrosint", "we", "us" or "our"), an open-source intelligence (OSINT) platform established in Brazil and operated at espectrosint.com. Contact: help@espectrosint.com.
1.2. These General Terms of Use and Service ("Terms") govern access to and use of every product and service we make available, including: (a) our public websites, blog, guides, newsletters and other freely available online resources ("Website"); (b) the free plan, previews, trials and promotional access ("Free Services"); (c) our hosted platform, dashboard, search modules, Investigations workspace, notifications, reports and related features ("Platform"); (d) any application programming interface, key, connector or developer tool we make available ("API"); (e) institutional, enterprise or onboarding services agreed in writing ("Institutional Services"); and (f) all documentation, content, results, exports and support supplied with any of the above. Together, the "Services".
1.3. If you access or use the Services for or on behalf of a company, public body, law-enforcement agency, non-profit or other organization ("Organization"), you represent and warrant that you have authority to bind that Organization, and "you" includes the Organization.
1.4. If you are an individual using the Services in a personal capacity, the provisions on organizational accounts, API integrations and Institutional Services apply only to the extent relevant. Nothing in these Terms excludes mandatory consumer rights.
2. Definitions
| Term | Meaning |
|---|---|
| Account | an account created to access any authenticated Service. |
| Authorized User | an individual whom you permit to access a Service for your Permitted Purpose and for whom you are responsible. |
| Credits | the units of use included in a plan or purchased separately, consumed per search as described on the Plans page. |
| Customer Data | identifiers, selectors, queries, files (including images), instructions, notes, configurations and other material submitted to or transmitted through a Service by or for you, excluding Usage Data. |
| Documentation | our help content, plan descriptions, usage instructions, policies and technical specifications for a Service, as updated from time to time. |
| Free Services | any Service supplied without charge, including the free plan, previews, trials, beta features and public Website content. |
| Investigation | the workspace in which you may save, organize, connect and annotate Outputs of searches you have executed. |
| Order | an online checkout, plan selection, quotation, proposal or other ordering document accepted by us that identifies Services, fees, term and limits. |
| Output | any search result, card, response, report, AI-generated analysis, visualization, export, link, indicator, inference, metadata or other information returned or generated through a Service. |
| Permitted Purpose | your lawful, authorized and proportionate purpose for using the Services, such as legitimate investigation, due diligence, compliance, fraud prevention, security research, journalism, academic research or verification of your own digital exposure. |
| Subscription Term | the period during which you are entitled to access a paid Service. |
| Third-Party Source | a website, platform, public record, API, data provider, open-source project or other external source consulted by, integrated with or linked from a Service. |
| Usage Data | technical, diagnostic, security, billing and service-usage data relating to the operation and use of the Services (such as search counts, feature interactions, latency, errors and account activity), excluding the substantive content of Customer Data and Outputs except where strictly necessary for security, abuse prevention or support. |
3. Contract documents and precedence
3.1. The agreement between you and us consists of these Terms, the Privacy Policy, Annex I (Data Processing Addendum), the Plans page, any applicable Order, and any document expressly incorporated by reference (together, the "Contract").
3.2. In case of conflict, the following order applies: (a) a signed Order or written institutional agreement; (b) Annex I, solely for personal-data processing matters; (c) these Terms; (d) the Privacy Policy; (e) the Documentation.
3.3. Purchase orders, procurement portals and other customer documents are administrative only; additional or inconsistent terms in them do not form part of the Contract unless we expressly accept them in writing.
4. Eligibility, verification and authority
4.1. You must be at least 18 years old and legally capable of entering into the Contract. Registration information must be complete, accurate and kept current.
4.2. We may require identity, organization, professional-status, use-case, payment, sanctions, security or other due-diligence information before or during access to any Service, and may condition, limit, suspend or withdraw access where we reasonably consider that the user, Organization, jurisdiction, use case or risk profile is unsuitable, unlawful, inconsistent with Section 30 or likely to expose any person or system to harm.
4.3. Our acceptance of a registration, activation of a feature or provision of a Service does not constitute an assessment or approval of your lawful basis, authority or purpose.
5. Accounts, credentials and security
5.1. The Account is personal. You are responsible for all activity under your Account, including activity by Authorized Users and by any person using your credentials, API keys or access tokens, except to the extent caused by our breach of the Contract.
5.2. Credentials must not be shared, transferred, published or embedded in publicly accessible code. Where the Service supports it, you must use strong passwords and multi-factor authentication, keep sessions under review and revoke devices you no longer use.
5.3. You must notify us immediately at help@espectrosint.com if you suspect unauthorized access, credential compromise, a security weakness or misuse. We may reset, rotate, revoke or disable credentials and sessions where reasonably necessary to protect the Services, users or third parties.
6. Access rights and license
6.1. Subject to the Contract, we grant you a limited, non-exclusive, non-transferable, non-sublicensable and revocable right to access and use the Services, during the applicable access period, solely for the Permitted Purpose.
6.2. No right is granted by implication. We and our licensors retain all rights, title and interest in the Services, Documentation, software, methods, interfaces, compilations, design, know-how, branding and related intellectual property.
6.3. Free Services are licensed, not sold, and may be withdrawn, restricted or changed at any time. Unless expressly stated, Free Services do not include support, service levels, data recovery or continuity commitments.
7. Public website and content
7.1. You may view and use the Website and its publicly available content for lawful personal, informational or internal business purposes, and print or download reasonable extracts, provided proprietary notices are retained and the content is not materially altered or presented misleadingly.
7.2. You must not use crawlers, scrapers, browser automation or similar means to access, copy, index, monitor or extract Website or Platform content, except through an API expressly provided for that purpose or with our prior written permission.
7.3. You may link to the Website in a fair and lawful manner that does not damage our reputation or suggest endorsement. You must not frame, mirror or embed the Website.
7.4. Website, blog and guide content is general information only and is not legal, regulatory, financial, investigative or other professional advice.
8. Free plan, previews and beta features
8.1. The free plan is made available at our discretion, subject to usage limits, periodic revalidation and the Permitted Purpose. Unused free allowances expire at the end of the applicable period and do not roll over.
8.2. Illustrative previews. Where the free plan displays a preview of a report, that preview is a demonstration of the structure and categories of a report and does not constitute a real result of the query. Real Outputs are delivered on the paid plans.
8.3. A free trial or promotional period is governed by the conditions displayed when it begins and converts to a paid subscription only where that consequence, the price and the cancellation method are clearly stated and accepted beforehand.
8.4. Beta, preview, early-access and experimental features may be incomplete, unstable, changed without notice or withdrawn at any time, and must not be used for evidential or legally significant purposes.
9. Plans, credits, payment and renewal
9.1. The available plans, prices, Credits, limits and features (including the AI-generated analysis and the Investigations workspace) are described on the Plans page and in your Account. An Order becomes binding when we accept it, including by activating the Service.
9.2. Payments are processed by our payment providers (card payments via Stripe; Pix via Mercado Pago, for Brazil). We do not store full card details. Access to a paid plan is released only after the payment is confirmed by the provider; a pending, expired, disputed or reversed payment does not release access.
9.3. Credits are consumed per search, as described in the Documentation, and do not accumulate between periods. Where a search fails because of a technical error on our side, the corresponding Credit is automatically returned. Credits have no cash value and are not refundable except as stated in Section 9.7 or required by law.
9.4. Subscriptions renew automatically for successive periods equal to the current one (monthly or annual) unless canceled before the renewal date. You may cancel at any time through your Account or the payment portal; cancellation takes effect at the end of the period already paid, and no further charges are made.
9.5. We may change prices or plan composition by giving reasonable advance notice; changes take effect at the next renewal. Fees are stated inclusive of applicable Brazilian taxes unless indicated otherwise; you are responsible for bank, foreign-exchange and payment-processing charges imposed by your own providers.
9.6. A chargeback, dispute or reversal of a payment suspends the associated access immediately and may lead to closure of the Account. We may recover amounts due together with the costs of recovery permitted by law.
9.7. Right of withdrawal (Art. 49 of the Brazilian Consumer Defense Code). For consumers resident in Brazil, for contracts concluded online a consumer may withdraw within 7 (seven) calendar days of contracting, with a refund proportional to the unused Credits. Credits already consumed are non-refundable, as the corresponding service has been effectively rendered. Requests are made by e-mail. Outside Brazil, this 7-day withdrawal period does not apply, except where a mandatory law of your country of residence grants an equivalent or broader right, in which case that right is honored.
9.8. Institutional or enterprise agreements may set specific commercial terms (invoicing, payment terms, seats, volumes); in that case the Order prevails on those points.
10. Lawful, ethical and acceptable use
10.1. You must use the Services only for a Permitted Purpose, in accordance with the Contract, the Documentation and all applicable laws, regulations, professional duties, court orders, licenses and codes of practice, including Law No. 13.709/2018 (LGPD), Law No. 12.965/2014 (Marco Civil da Internet), Law No. 12.737/2012 and, where applicable, the EU and UK General Data Protection Regulations (GDPR).
10.2. Before submitting any identifier, selector or other personal data of a third party, you must have a lawful basis, legitimate authority and a proportionate reason to do so. You are solely responsible for determining and documenting the legality, necessity, proportionality and fairness of each search, investigation, disclosure and downstream use.
10.3. Public availability is not, by itself, a lawful basis. The fact that information is accessible online does not establish an unrestricted right to collect, correlate, disclose or retain it. You must assess the purpose and context of each use.
10.4. You must contextualize and corroborate Outputs, preserve provenance where relevant, apply human judgment and keep appropriate records and approvals for sensitive or high-impact uses.
10.5. You must not use, or permit the use of, the Services:
- (a) for unlawful surveillance, stalking, harassment, intimidation, coercion, extortion, blackmail, vigilantism, doxxing, identity theft, impersonation or targeting of any person without lawful authority;
- (b) to investigate, locate, profile or monitor children or adolescents, or to obtain, infer or expose data of a minor;
- (c) to discriminate unlawfully, persecute protected or vulnerable groups, suppress lawful expression, undermine human rights or the rule of law, or facilitate violence or abuse;
- (d) to make a solely automated decision that produces legal or similarly significant effects on a person, or to determine eligibility for employment, housing, credit, insurance, education, healthcare, immigration or another high-impact service, without an independent lawful basis, verification, human review and any notices or rights required by law;
- (e) to obtain, infer, expose or exploit sensitive personal data (such as health, sexual orientation, religion, political opinion, biometric or genetic data) where the use is unlawful, unnecessary or disproportionate;
- (f) to investigate a person for a purely personal dispute, curiosity, revenge, romantic, domestic or other non-professional purpose that lacks a lawful basis;
- (g) to check, test or exploit credentials, passwords or accounts that are not yours or that you are not expressly authorized to verify;
- (h) for spam, bulk marketing, unsolicited contact, credential attacks, phishing, malware, fraud, money laundering, sanctions evasion, terrorism or any other criminal or harmful activity;
- (i) to access or attempt to access non-public systems, accounts or data without authorization, or to bypass access controls, rate limits, quotas, security measures or technical restrictions of the Services or of any Third-Party Source;
- (j) to test the vulnerability of any Service or Third-Party Source without express written authorization; or
- (k) in any manner likely to cause material harm to a person, interfere with third-party rights, compromise an investigation, contaminate evidence or create a misleading impression of certainty.
10.6. We may require additional approvals, training, use restrictions or technical controls for sensitive functionality or use cases. Failure to comply is a material breach. Violation of this Section may result in immediate suspension or termination without refund, and in reporting to the competent authorities where required by law.
11. Technical and commercial restrictions
11.1. Except to the extent expressly permitted by the Contract or by non-excludable law, you must not:
- (a) copy, modify, adapt, translate, create derivative works from, reverse engineer, decompile, disassemble or otherwise attempt to discover the source code, models, methods or underlying structure of any Service;
- (b) sell, rent, lease, sublicense, distribute, make available, white-label, share or otherwise commercialize the Services or raw Outputs as a standalone product;
- (c) use the Services or Outputs to create, train, improve, benchmark or validate a competing product, service, dataset or model;
- (d) bulk-download, harvest, aggregate or build a persistent repository of Outputs beyond what is reasonably necessary for the Permitted Purpose and lawful retention (the Investigations workspace is the supported means of retaining Outputs you need);
- (e) remove, obscure or alter proprietary notices, source attribution, provenance information, confidence indicators, warnings or usage restrictions;
- (f) misrepresent the source, completeness, accuracy, age or meaning of an Output, or state or imply that we or any Third-Party Source endorses you or your conclusions;
- (g) share Accounts, exceed purchased Credits, seats, concurrency, volume or other limits, or circumvent the free-plan limits by creating multiple Accounts;
- (h) interfere with, overload, disrupt or degrade the Services, networks, infrastructure, Third-Party Sources or another user's access.
11.2. Statutory rights to observe or decompile software may be exercised only to the minimum extent that cannot lawfully be excluded, after you have first requested the necessary information from us.
12. Customer Data, searches, Investigations and Usage Data
12.1. You retain ownership of Customer Data. You grant us and our subprocessors a limited, non-exclusive right to host, transmit, process and use Customer Data only as necessary to provide, secure, support and administer the Services, in accordance with the Contract and, where we act as processor, your documented instructions and Annex I; to comply with law; and to enforce the Contract.
12.2. You represent, warrant and undertake that you have all rights, permissions, notices, lawful bases and authority needed for us to process Customer Data under the Contract, and that Customer Data and its collection, submission, search, use, retention and disclosure do not infringe any law, duty, confidentiality obligation, privacy right or intellectual-property right.
12.3. Searches and Outputs. Searches are executed at the time of the query and Outputs are delivered to your browser. Outputs are not retained as part of your Account unless you save them to an Investigation, request an AI-generated analysis, or a late-arriving result is being delivered, in each case as described in the Privacy Policy. The Services are not an evidential archive or backup system; you are responsible for exporting and preserving any Outputs, case files or records you require.
12.4. Files you upload. Images or files you upload are processed only to execute the requested function and are not retained beyond what is necessary for that purpose. We do not offer facial recognition or biometric identification; reverse image search compares visual content through a Third-Party Source and does not create biometric templates.
12.5. Investigations. Content you save to an Investigation (snapshots of Outputs, connections, notes) is stored in your Account, isolated to you, until you delete it or your Account is closed, subject to the retention rules in Section 25 and the Privacy Policy. You are responsible for applying lawful retention periods, access controls, data minimization and secure deletion to anything you retain or export.
12.6. Usage Data. We may generate and use Usage Data to operate, secure, monitor, measure, bill, support and improve the Services, detect misuse and produce aggregated or de-identified statistics. We do not use your search queries, uploaded files or Outputs to identify your investigative subjects for marketing, and we do not use Customer Data or Outputs to train artificial-intelligence models.
13. Outputs, Third-Party Sources and independent verification
13.1. The Services retrieve, organize, correlate, display and analyze information from Third-Party Sources and from open, public or commercially available sources. We do not control those sources and are not responsible for their availability, legality, accuracy, completeness, security, terms or continued operation.
13.2. Outputs may be incomplete, unavailable, delayed, duplicated, incorrectly associated, changed or removed by a source, and may reflect homonyms, aliases, recycled identifiers, historic information or conflicting records. An Output is an investigative lead or data point, not a verified finding, factual determination or statement about a person's identity, character, conduct, guilt or legal status.
13.3. You must independently verify and corroborate material Outputs using appropriate sources, methods and human judgment before acting, publishing, disclosing, taking enforcement action or making any decision affecting a person. You are responsible for the conclusions, reports and actions you base on Outputs.
13.4. Espectrosint is not a credit bureau, a consumer-reporting agency or a background-check company, and Outputs must not be used as the basis for decisions regulated by consumer-credit, employment-screening or similar laws.
13.5. Links to or references to Third-Party Sources do not imply affiliation, endorsement or approval. Third-party terms, privacy notices and access restrictions may apply, and you are responsible for compliance where you directly access or use a Third-Party Source.
13.6. We may add, remove, suspend or change a Third-Party Source, module or feature at any time, including in response to source changes, legal requirements, ethical review, security concerns or commercial availability.
13.7. Leak Sonar alerts are best-effort. They cover only leaked data that reaches our database after you add an item; we do not see every leak, an alert can arrive late or not at all, and the absence of an alert does not mean your data is safe. You may only add emails and domains you control, and usernames that are yours.
13.8. The Leak Sonar icon is from Streamline (streamlinehq.com), used under the CC BY 4.0 license.
14. AI-generated analysis
14.1. Where you request an AI-generated analysis (narrative or dossier), the Outputs of the relevant search are processed by an artificial-intelligence model to produce a summary. The analysis is automatically generated content that may contain errors, omissions or unfounded inferences and is provided as an aid to your own analysis.
14.2. The analysis is not a decision, recommendation or professional opinion, and must not be used as the sole basis for any action affecting a person. Section 13 applies to AI-generated content in full. Information on the provider and on your rights regarding automated processing is in the Privacy Policy.
15. API and integrations
15.1. Where we make an API available, you may access it only through credentials issued by us and in accordance with the Documentation, rate limits, field restrictions, authentication requirements and versioning rules.
15.2. You must ensure that any application that connects to the API has appropriate security, authentication, logging and access controls; provides its end users with clear terms and privacy information; does not expose API credentials or permit uncontrolled onward access; does not alter, omit or obscure provenance, confidence indicators, warnings or restrictions returned with an Output; and is operated in compliance with the laws applicable to you and your end users.
15.3. You may store and use API Outputs only to the extent reasonably necessary for the Permitted Purpose, an authorized end-user workflow or lawful retention. You must not resell raw API Outputs, build a general-purpose identity repository or allow end users to query the API outside your controlled application unless expressly permitted in an Order.
15.4. We may change, deprecate or discontinue an API, endpoint, field or version. Where reasonably practicable we will give advance notice of a material breaking change to a paid API; we may make immediate changes where required for security, law, source changes or prevention of harm. We may monitor API metadata and usage patterns to verify compliance, protect infrastructure, calculate fees and detect abuse.
16. Intellectual property, marks and feedback
16.1. The "Espectrosint" mark, logo, brand elements, Platform, software, texts and other elements are owned by or licensed to us. No right to use them is granted without our prior written consent. You must not register or use any domain name, company name, product name, social handle or mark identical or confusingly similar to ours.
16.2. If you provide suggestions, ideas, requests, corrections or other feedback, you grant us a worldwide, perpetual, irrevocable, royalty-free right to use and incorporate it without restriction or obligation, provided we do not identify you publicly without consent.
16.3. The Services may include open-source or third-party components subject to separate license terms, which prevail for those components to the extent required by the applicable license.
17. Confidentiality
17.1. Each party must keep the other party's non-public business, technical, security, pricing, customer, investigative or operational information ("Confidential Information") confidential, use it only to perform or exercise rights under the Contract, and protect it with at least reasonable care. Confidential Information does not include information that is or becomes public other than through breach, was lawfully known without restriction before disclosure, is lawfully received from a third party without a confidentiality duty, or is independently developed.
17.2. A party may disclose Confidential Information to personnel, advisers and subcontractors who need to know it and are bound by equivalent obligations, and where required by law, court or regulator, giving prompt notice where lawful.
17.3. Your non-public Customer Data, Investigations, notes and case details are your Confidential Information. Our non-public Documentation, security information, technical methods, roadmaps and API credentials are our Confidential Information.
18. Privacy and data protection roles
18.1. Each party must comply with the data-protection and privacy laws applicable to it in connection with the Contract. Our processing of personal data relating to users, Accounts, website visitors, service administration and persons who may appear in Outputs is described in the Privacy Policy.
18.2. Your Account data. For personal data relating to you as a user (registration, billing, sessions, usage), Espectrosint is the controller.
18.3. Customer Data you submit to execute searches. For personal data contained in Customer Data that you submit and that we process solely to execute your query on your documented instructions (identifiers, selectors, uploaded files, search instructions), you act as controller and we act as processor. You determine and are solely responsible for the purpose, lawful basis, necessity, proportionality and scope of your searches and of any downstream use, and for providing notices, obtaining any required consents or authorizations, keeping records of lawful basis, carrying out any required impact assessment (RIPD / DPIA) and responding to data-subject requests relating to your purposes. Annex I applies automatically to this processing.
18.4. Our independent processing. We act as an independent controller for personal data where we determine the purposes and means of processing, including personal data processed for account administration, billing, security, fraud and abuse prevention, legal and regulatory compliance, Usage Data to the extent it contains personal data, and information that we independently obtain, organize or process for purposes determined by us, including the handling of requests from persons who may appear in Outputs. Nothing in the Contract is intended to reclassify the parties' roles where applicable law determines otherwise.
18.5. Where the parties are independent controllers for particular processing, each is separately responsible for its own compliance, transparency, lawful basis, security, retention and response to rights requests. Where we receive a request from a data subject that relates solely to your purposes, we may refer the requester to you, unless the law requires us to respond directly.
18.6. Where the EU or UK GDPR applies to your use of the Services, you are responsible for identifying and documenting an Article 6 lawful basis and, where applicable, an Article 9 or Article 10 condition, before each relevant search. Our acceptance of a search does not constitute a determination of your lawful basis.
19. Security and service integrity
19.1. We use reasonable technical and organizational measures designed to protect the Services and personal data against unauthorized access, loss, alteration or disclosure, taking account of the nature of the Services and the risks involved. No system is completely secure, and we do not guarantee that security incidents will never occur.
19.2. You are responsible for the security of your devices, networks, applications, exports, credentials and copies of Outputs, and for configuring the Services appropriately for your use case.
19.3. Neither party may publicly disclose a vulnerability affecting the other party's systems without first providing sufficient details, allowing a reasonable remediation period and coordinating disclosure, except where prohibited by law. Security testing of the Services requires prior written authorization.
19.4. You must cooperate with the reasonable investigation and remediation of suspected misuse or security incidents connected with your Account, application or users.
20. Availability, support and changes to the Services
20.1. We provide paid Services with reasonable skill and care. Service levels, response times, maintenance windows or credits apply only if stated in an Order or written institutional agreement. The current availability of the Services is published on our status page.
20.2. The Services may be unavailable due to maintenance, updates, emergency work, security events, network or cloud failures, Third-Party Sources, force majeure, your systems or other matters outside our reasonable control.
20.3. We may update, improve, reconfigure or change the Services and Documentation. For paid Services, we will use reasonable efforts not to materially reduce the core functionality purchased during the current Subscription Term, except where required by law, security, ethical review, source availability or prevention of harm.
20.4. Support is provided by e-mail and through the Platform to the extent included in your plan. You must provide reasonable diagnostic information and cooperate in reproducing and resolving issues.
21. Warranties, disclaimers and no sole reliance
21.1. Each party warrants that it has authority to enter into and perform the Contract.
21.2. For a paid Service, we warrant that during the Subscription Term it will perform materially in accordance with the Documentation when used as authorized. Where it does not, we will use reasonable efforts to correct or re-perform the affected Service; if we cannot do so within a reasonable period, you may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period.
21.3. Free Services, beta features, Third-Party Sources and Outputs are provided "as is" and "as available". To the maximum extent permitted by law, we do not warrant that any Service or Output will be uninterrupted, error-free, complete, accurate, current, secure, available in every jurisdiction or suitable for a particular investigation, legal standard, evidential purpose or outcome.
21.4. We do not warrant that an Output identifies a particular person, proves ownership or control of an account, establishes guilt or wrongdoing, or is sufficient for enforcement, publication or a decision affecting a person. Section 13 applies.
21.5. Except as expressly stated in the Contract and to the maximum extent permitted by law, all conditions, warranties and other terms implied by statute or otherwise are excluded. Nothing in this Section limits the legal guarantees owed to consumers under mandatory law.
22. User indemnity
22.1. You will indemnify and hold harmless Espectrosint, its partners, staff and contractors against third-party claims, regulatory actions, losses, liabilities, damages, penalties, reasonable legal fees and costs arising from or relating to: (a) Customer Data, your application, or an allegation that either infringes a third party's intellectual-property, privacy, confidentiality or other rights; (b) your or an Authorized User's unlawful, prohibited, negligent or unauthorized use of a Service or Output; (c) your publication, disclosure, retention, decision, enforcement action or other downstream use of an Output; (d) your breach of Sections 10, 11, 12, 15, 17, 18 or 19; or (e) a data-subject, third-party or regulator claim arising from your search instructions, purpose or failure to obtain required authority, notices, consents or lawful basis.
22.2. We will give you prompt notice of an indemnified claim, allow you to control the defense and settlement with competent counsel, and provide reasonable cooperation at your cost. You may not settle a claim in a way that admits fault by us or imposes an obligation on us without our prior written consent.
23. Liability
23.1. Nothing in the Contract excludes or limits liability for death or personal injury caused by negligence, for fraud or willful misconduct, or for any other liability that cannot lawfully be excluded or limited, including liability owed to consumers under mandatory law.
23.2. Subject to Section 23.1, neither party is liable for loss of profit, revenue, business, contracts, anticipated savings, goodwill, reputation, opportunity or data, wasted expenditure, business interruption, or any indirect or consequential loss arising out of or in connection with the Contract, even if foreseeable.
23.3. Subject to Sections 23.1 and 23.4, our total aggregate liability arising out of or in connection with the Contract, whether in contract, tort (including negligence), misrepresentation, breach of statutory duty or otherwise, will not exceed: (a) for a paid Service, the total fees paid by you for the affected Service during the 12 (twelve) months immediately before the event giving rise to the first claim; and (b) for a Free Service or Website use, R$ 500,00 (five hundred Brazilian reais).
23.4. Your payment obligations and your liability under Section 22 are not limited by Section 23.3.
23.5. The parties agree that these exclusions and limitations are reasonable in light of the nature of the Services, your obligation to verify Outputs, and the allocation of risk reflected in the fees.
24. Suspension and termination
24.1. We may suspend or restrict access immediately where reasonably necessary to address: (a) suspected unlawful or prohibited use; (b) a security risk or credential compromise; (c) harm to a person, source, investigation or system; (d) breach of usage limits; (e) an overdue, disputed or reversed payment; (f) a legal, regulatory, sanctions or source requirement; or (g) a material risk to us or another user. Where appropriate, we will notify you and allow a reasonable opportunity to remedy.
24.2. Either party may terminate the Contract by written notice if the other party materially breaches it and, where the breach is capable of remedy, fails to remedy it within 14 (fourteen) days after notice. We may terminate immediately for a breach of Sections 4, 10, 11, 15, 17, 18 or 19, or where continued provision would be unlawful or create a serious risk of harm.
24.3. You may stop using the Services and close your Account at any time through your Account settings. Closing the Account cancels any active subscription; fees already paid for the current period are not refunded except as stated in Section 9.7.
24.4. We may end a Free Service at any time, and may refuse renewal where you no longer satisfy Section 4, change your use case without approval, are subject to sanctions or export restrictions, or the relevant Service is discontinued.
25. Consequences of expiry or termination
25.1. On expiry or termination, your right to access the affected Services ends and you must stop using credentials, APIs, Documentation and other licensed materials. We may disable Accounts and API keys.
25.2. You must pay accrued amounts. If you terminate for our uncured material breach under Section 24.2, we will refund prepaid fees for the unused portion of the affected paid Service.
25.3. Your content. When you close your Account, your Account data and the content you saved (Investigations, notes, AI-generated analyses, notifications) are deleted as described in the Privacy Policy. When a paid plan ends without closure of the Account, Investigations become read-only and are deleted 180 (one hundred and eighty) days after the end of the plan, unless you resubscribe or delete them earlier. Export anything you need before that.
25.4. Termination does not require you to delete lawfully retained Outputs incorporated into your own case files, reports or records, but you must continue to comply with applicable law, confidentiality, provenance, security, retention and use restrictions.
25.5. Sections that by their nature should survive will survive, including Sections 11 to 13, 16 to 18 and 21 to 31, together with accrued rights and payment obligations.
26. Changes to these Terms
26.1. We may update these Terms to reflect changes in law, regulation, security, technology, the Services, Third-Party Sources or business practices. We will publish the updated version with its effective date and may give notice by e-mail, Account notification or another reasonable method.
26.2. For Website use and Free Services, changes take effect on the stated effective date, and continued use after that date constitutes acceptance.
26.3. For a paid Subscription Term, a materially adverse change ordinarily takes effect at the next renewal, unless an earlier change is reasonably required by law, regulation, security, ethics, a Third-Party Source or prevention of harm. If an earlier change materially reduces your contracted rights and you object within 30 (thirty) days of notice, you may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused period.
27. Notices and communications
27.1. You agree to receive communications relating to your Account and the Services by electronic means (e-mail and in-Platform notifications), which have the same validity as written communications. Operational notices may be sent by e-mail, through your Account or via the Website.
27.2. Formal notices to us must be sent in writing to help@espectrosint.com. Notices to you may be sent to the e-mail address associated with your Account. An e-mail notice is deemed received when sent without a delivery-failure message; a notice sent outside business hours is deemed received on the next business day in Brazil.
28. General provisions
28.1. Entire agreement. The Contract is the entire agreement concerning its subject matter and supersedes prior proposals, discussions and representations, without limiting liability for fraud.
28.2. Assignment. You may not assign, transfer or subcontract your rights or obligations without our prior written consent. We may assign the Contract to an affiliate or in connection with a merger, restructuring or sale of all or substantially all of the relevant business, provided this does not materially reduce your rights.
28.3. Subcontracting. We may use affiliates and subcontractors to provide the Services and remain responsible for their performance to the extent required by the Contract.
28.4. Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control (excluding payment obligations). The affected party must use reasonable efforts to mitigate the impact.
28.5. No partnership. The Contract does not create a partnership, joint venture, employment, fiduciary or agency relationship.
28.6. Waiver. A failure or delay to exercise a right is not a waiver. A waiver must be in writing and applies only to the specific circumstance stated.
28.7. Severance. If a provision is invalid or unenforceable, it will be modified to the minimum extent necessary to make it valid, or deleted if modification is not possible, without affecting the remaining provisions.
28.8. Third-party rights. A person who is not a party to the Contract has no right to enforce it, except that our affiliates and indemnified persons may enforce provisions expressly benefiting them.
28.9. Language. The Portuguese-language version of these Terms controls. Translations are provided for convenience only.
29. Trade controls, anti-corruption and regulatory compliance
29.1. Each party must comply with applicable sanctions, export-control, anti-bribery, anti-corruption (including Law No. 12.846/2013) and anti-money-laundering laws in connection with the Contract.
29.2. You must not access or use the Services in or for a jurisdiction, person or end use prohibited by applicable sanctions or export-control laws, and must provide information reasonably requested to verify compliance.
29.3. We may suspend, refuse or terminate access without liability where we reasonably believe provision or use would breach a trade restriction or expose us, our suppliers or a Third-Party Source to sanctions or regulatory risk.
30. Ethics and compliance commitments
30.1. Open-source intelligence is a discipline, not a shortcut. Our tools exist to support tradecraft, human judgment and lawful investigation, and the following commitments apply to how we build, operate and grant access to the Services.
We will:
- provide access to OSINT capabilities aligned with lawful, proportionate and legitimate investigative need;
- document and communicate source provenance, limitations and analytical uncertainty wherever possible;
- maintain channels for persons who may appear in Outputs to exercise their rights, and act on verified requests;
- continually review our practices in light of legal, ethical and societal expectations.
We will not:
- facilitate unlawful surveillance, targeting or intelligence collection;
- obscure data origins, limitations or analytical uncertainty;
- market OSINT as a silver bullet or a replacement for due process and verification;
- support activities that undermine human rights or the rule of law;
- prioritize commercial outcomes over ethical responsibility.
31. Governing law and jurisdiction
31.1. The Contract and any dispute or claim arising out of or in connection with it, its subject matter or formation, including non-contractual disputes, are governed by the laws of the Federative Republic of Brazil, including the Marco Civil da Internet, the LGPD and, where applicable, the Consumer Defense Code.
31.2. Before initiating legal action, the parties will seek to resolve any dispute amicably through the contact e-mail. Consumers in Brazil may also use the public platform consumidor.gov.br.
31.3. The courts of the judicial district of São Paulo, State of São Paulo, Brazil, are elected to resolve disputes, without prejudice to a consumer's right to bring proceedings in the courts of their own domicile. If you reside in the European Economic Area, the United Kingdom or another jurisdiction whose mandatory law grants you the right to bring proceedings in another court or protections that cannot be excluded, those rights are not affected, and nothing in these Terms limits your right to lodge a complaint with your local data-protection authority.
32. Contact
For questions about these Terms, to exercise data-protection rights or to send a formal notice, contact help@espectrosint.com.
Annex I — Data Processing Addendum
This Annex I applies automatically whenever Espectrosint processes personal data as processor on your behalf under the Contract (Section 18.3). It is intended to satisfy the requirements applicable to controller–processor arrangements under Art. 39 of the LGPD and, where applicable, Art. 28 of the EU and UK GDPR. Capitalized terms have the meanings given in the Terms.
1. Scope and roles
1.1. You are the controller and Espectrosint is the processor for the personal data described in Annex A, to the extent we process it on your behalf and documented instructions. You remain responsible for the lawfulness of those instructions and for the obligations that apply to you as controller.
1.2. Processing carried out for our own independently determined purposes (Section 18.4) is outside this Annex.
2. Documented instructions
2.1. We will process personal data only on your documented instructions, which consist of the applicable Order, your authorized use of the Services and any written instruction accepted by us, to the extent consistent with the Contract and applicable law, unless applicable law requires otherwise; where legally permitted, we will inform you before processing required by law.
2.2. We will promptly inform you if, in our reasonable opinion, an instruction infringes applicable data-protection law, and may suspend the affected processing until the matter is resolved.
3. Confidentiality and personnel
3.1. We ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations and receive access only to the extent necessary for their functions.
4. Security
4.1. We implement and maintain appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, taking account of the state of the art, implementation costs and the nature, scope, context and purposes of processing and the risks to individuals. Measures include, as appropriate, access controls and per-account isolation, authentication and session management, encryption in transit and at rest, logging with redaction, rate limiting, vulnerability management, resilience and recovery controls, and periodic review, as further described in the Privacy Policy.
5. Subprocessors
5.1. You give general written authorization for us to engage the subprocessors necessary to provide the Services. The current list of subprocessors, their function and location is maintained in the Privacy Policy.
5.2. We will give reasonable notice of an intended addition or replacement of a material subprocessor by updating the Privacy Policy and, where required by law, by direct notice. You may object on reasonable documented data-protection grounds; the parties will work in good faith to address the objection, and if no reasonable alternative is available either party may terminate the affected Service on reasonable notice.
5.3. We impose written data-protection obligations on each subprocessor providing a level of protection materially equivalent to this Annex, to the extent applicable to the subprocessor's processing, and remain responsible for their performance to the extent required by applicable law.
6. Data-subject rights
6.1. Taking account of the nature of the processing, we will provide reasonable assistance through appropriate technical and organizational measures to help you respond to data-subject requests under applicable law.
6.2. If we receive a request relating solely to personal data processed on your behalf under this Annex, we may refer the requester to you unless the law requires us to respond directly. Requests relating to our independent processing are handled under the Privacy Policy.
7. Security incidents
7.1. We will notify you without undue delay after becoming aware of a security incident affecting personal data processed under this Annex, and will provide the information reasonably available to us that you require to meet your notification obligations under Art. 48 of the LGPD or Art. 33 of the GDPR. Notification or assistance is not an admission of fault or liability.
8. Compliance assistance and impact assessments
8.1. Taking account of the nature of processing and information available to us, we will provide reasonable assistance with your obligations concerning security, incident notification, impact assessments (RIPD / DPIA) and prior consultation with a supervisory authority where required. You remain responsible for determining whether your use of the Services requires an impact assessment or consultation, and for its content and conclusions.
9. Return and deletion
9.1. Personal data submitted solely to execute a query is processed transiently for the duration of the query and is not retained as part of your Account, except where you save Outputs to an Investigation, request an AI-generated analysis, or a late-arriving result is being delivered, in each case for the periods stated in the Privacy Policy. On closure of your Account we delete the personal data processed under this Annex, unless applicable law requires retention. Data in routine backups may remain until overwritten in the ordinary course, provided it is protected and not restored except for legitimate disaster-recovery purposes.
10. Information and audits
10.1. We will make available the information reasonably necessary to demonstrate compliance with the processor obligations applicable to us. You may conduct an audit, or appoint an independent auditor bound by confidentiality, no more than once in any 12-month period, on reasonable advance notice, during business hours and in a manner that avoids unreasonable disruption, unless a regulator requires otherwise or there has been a material security incident. You bear your audit costs; assistance beyond the information ordinarily made available may be charged at reasonable rates unless the audit identifies our material breach.
11. International transfers
11.1. We will not make an international transfer of personal data processed under this Annex except in accordance with your documented instructions and a lawful transfer mechanism under applicable law, including Art. 33 of the LGPD (adequacy decision, standard contractual clauses approved by the ANPD, or another valid mechanism) and, where the GDPR applies, Chapter V of the GDPR (adequacy decision, standard contractual clauses, or another valid mechanism).
12. Conflict and survival
12.1. This Annex prevails over inconsistent provisions of the Terms solely in relation to processing for which we act as processor. Obligations that by their nature should continue after termination survive for so long as we retain the relevant personal data.
Annex A — Processing details
| Item | Details |
|---|---|
| Subject matter | Provision, operation, support and security of the Services used by you, including search modules, the Investigations workspace, AI-generated analysis and, where made available, the API. |
| Duration | For the duration of your use of the Services, plus only the limited period required for secure deletion, legal retention or completion of documented post-termination obligations. Query data used solely to execute a search is processed transiently. |
| Nature of processing | Receiving, transmitting, consulting Third-Party Sources, organizing, structuring, correlating, analyzing, returning Outputs, storing Outputs you choose to save, securing, troubleshooting, restricting and deleting personal data. |
| Purpose | To execute searches you initiate and other documented instructions, provide and secure the contracted Services, and perform support you request. |
| Types of personal data | Identifiers and selectors you submit (such as e-mail addresses, usernames, telephone numbers, names, domains, tax identifiers), uploaded images or files, search parameters, query metadata, and personal data contained in Outputs you save or send for AI-generated analysis. |
| Sensitive data | Customer Data or Outputs may contain sensitive, special-category or criminal-offence information depending on your search and use case. We do not process biometric data for identification purposes. |
| Categories of data subjects | Individuals whose identifiers you submit or who appear in Outputs; individuals appearing in files you upload; your Authorized Users. |
| Controller instructions | You determine the purpose and scope of each search, may issue lawful documented instructions within the Contract, and retain the rights and responsibilities of the controller under applicable law. |
| Retention | As stated in the Privacy Policy: query data transient; saved Investigations while the Account is active and up to 180 days after the end of a paid plan; late-arriving results up to 30 days; AI-generated analyses for 90 days, after which their content is removed. |
| Subprocessors | The providers listed in the Privacy Policy, engaged in accordance with Section 5 of Annex I. |
Annex I is incorporated into these Terms; no separate signature is required unless an Order expressly provides otherwise.
Service application matrix
This matrix is explanatory and does not limit the operative provisions above.
| Item | Website | Free plan | Paid plan | API / Institutional |
|---|---|---|---|---|
| Access right | View public content | Revocable, within quotas | For the Subscription Term | Within Order and Documentation |
| Verification | None for browsing | May be required | May be required | Generally required |
| Fees | None | None | As stated on Plans page | As stated in Order |
| Service levels | None | None | Status page; SLA only if agreed | Only if expressly agreed |
| Outputs | Informational only | Illustrative previews | Permitted Purpose | Controlled application and Permitted Purpose |
| Automation | No scraping | Built-in features only | Built-in features only | Authorized API only |
| Support | None | E-mail, best effort | Plan dependent | Order dependent |
| Liability cap | R$ 500 | R$ 500 | 12-month fees | 12-month fees |