1. Purpose
This API Fair Use Policy (“Policy”) applies to all customers, partners, developers, and third parties that access or use APIs provided by Circumtec.
The purpose of this Policy is to ensure that API resources are used fairly, securely, and in a way that does not adversely affect the performance, availability, or integrity of our services.
2. Default API Usage Limit
Usage limits may also apply at the account, application, customer, endpoint, or IP-address level. Additional short-term rate limits may be applied where necessary to protect the platform from excessive, automated, or abnormal traffic.
Higher limits may be made available to approved partners or customers under a separate commercial or enterprise agreement.
3. Reasonable Use
API users are expected to:
- Use the API only for legitimate and authorised business purposes.
- Follow the published API documentation and integration requirements.
- Use valid authentication credentials and keep those credentials secure.
- Cache responses where appropriate to avoid unnecessary repeated requests.
- Use webhooks or event-based notifications where available instead of continuous polling.
- Implement appropriate retry logic, including exponential backoff.
- Avoid duplicate, unnecessary, or excessively frequent requests.
4. Prohibited Use
Users must not:
- Circumvent, disable, or attempt to avoid usage limits or rate controls.
- Create multiple accounts, applications, or API credentials to bypass restrictions.
- Use the API in a way that disrupts, overloads, degrades, or harms the platform.
- Conduct load testing, stress testing, vulnerability scanning, or penetration testing without prior written approval.
- Attempt to gain unauthorised access to systems, accounts, services, or data.
- Share API credentials with unauthorised persons or organisations.
- Use the API for unlawful, fraudulent, deceptive, malicious, or abusive purposes.
- Access, collect, store, or disclose data without appropriate authority or consent.
5. Limit Enforcement
When an applicable usage or rate limit is reached, API requests may be rejected,
delayed, or temporarily throttled. The API may return an
HTTP 429 Too Many Requests response.
Where supported, the response may include a Retry-After header or
other usage information indicating when further requests may be attempted.
6. Monitoring
We may monitor API usage for service reliability, security, fraud prevention, capacity planning, performance optimisation, support, billing, and compliance with this Policy.
Monitoring under this section does not transfer ownership of customer data to us.
7. Excessive or Abnormal Usage
Usage may be considered excessive or abnormal where it materially differs from ordinary integration activity, creates unnecessary processing load, affects other users, or presents a security or operational risk.
We may contact the API user to request reasonable technical changes, such as reducing polling frequency, introducing caching, using batch endpoints, or moving to webhook-based processing.
8. Suspension and Enforcement
If we reasonably believe that an API user has breached this Policy, we may:
- Issue a warning or request corrective action.
- Apply additional rate limits or temporary throttling.
- Temporarily suspend API credentials or application access.
- Require changes to the relevant integration.
- Terminate API access in cases of serious, repeated, or deliberate misuse.
Where reasonably practicable, we will provide notice before taking enforcement action. Immediate action may be taken where necessary to protect the security, stability, integrity, or availability of our systems.
9. Requesting a Higher Limit
Customers or partners that require more than 2,000 requests per day should contact us before deploying the integration into production. We may request information about expected request volumes, peak traffic, endpoints used, retry behaviour, and the intended business purpose.
Approval of a higher limit is at our discretion and may be subject to additional technical requirements, fees, or contractual terms.
10. Changes to this Policy
We may update this Policy from time to time. The revised version will be published on our website or otherwise made available to affected API users. Continued use of the API after the effective date of an updated Policy constitutes acceptance of the revised Policy.
11. Contact
Questions about this Policy or requests for higher API limits may be sent to:
Circumvend
Email:
support@circumtec.com