DRAFT — for legal review, not legal advice. This document is a drafting template prepared from Itemra's current source code and architecture. It must be reviewed and finalised by [LEGAL_ENTITY_NAME]'s qualified lawyer before use.
[PLACEHOLDER]tokens mark company-specific facts that must be filled in.
Itemra — Terms of Service
Version: 2026-07-16 · Effective date: [EFFECTIVE_DATE]
These Terms of Service ("Terms") govern access to and use of the Itemra warehouse and inventory management platform ("Itemra" or the "Service"), provided by [LEGAL_ENTITY_NAME], organisation number [ORG_NUMBER], registered at [REGISTERED_ADDRESS] ("we", "us", "Itemra" as the provider). By creating an account, clicking to accept these Terms, or using the Service, you and the organisation you represent ("Customer", "you") agree to these Terms.
If you do not agree, do not use the Service.
1. Definitions
- "Service" — the Itemra software-as-a-service platform for warehouse and inventory management, including its web application, APIs, and related documentation.
- "Account" — the Customer's tenant/organisation in Itemra, mapped 1:1 to an identity organisation in our authentication provider (see Section 9).
- "Authorised User" — an individual the Customer invites or permits to access the Service under the Customer's Account.
- "Customer Data" — all data the Customer or its Authorised Users submit to or generate in the Service, including inventory records (items, locations, containers, stock, counts, transfers), uploaded attachments, notes, supplier and purchasing records, and custom fields.
- "Account Data" — data we process to operate the commercial relationship, including organisation and user identity, role and status, billing identifiers, support requests, and service logs.
- "DPA" — the Data Processing Agreement at [DPA_URL], governing our processing of personal data contained in Customer Data on the Customer's behalf.
- "Privacy Policy" — our privacy policy at [PRIVACY_POLICY_URL], describing our processing of Account Data as a controller.
- "Subprocessor List" — the list of third parties we engage, at [SUBPROCESSOR_LIST_URL].
- "Subscription" — the Customer's paid or free plan to the Service.
- "Fees" — the charges for the Subscription.
2. The Service
2.1 Itemra provides a multi-tenant, cloud-hosted platform that lets businesses manage inventory, locations, stock movements, purchasing, attachments, and related operational data. Functionality available to the Customer depends on the Subscription plan (see Section 4).
2.2 We may improve, modify, or discontinue features over time. We will not make a material reduction to the core functionality of a paid plan during a paid term without reasonable notice.
2.3 The Service is delivered online. We host the application and primary SQL Server database on Itemra-operated infrastructure in Norway / the EEA ([VERIFY_SELF_HOSTED_APP_AND_SQL_LOCATION]). Uploaded files are stored in Microsoft Azure Blob Storage in region [VERIFY_AZURE_BLOB_REGION]. (Grounded in src/backend/infrastructure/Itemra.Persistence/DependencyInjection.cs (SQL Server) and src/backend/infrastructure/Itemra.Integrations.Storage/AzureBlobAttachmentStorage.cs (Azure Blob).)
3. Accounts, eligibility, and self-serve formation
3.1 Business use only. The Service is offered to businesses and other organisations for use in their trade, business, craft, or profession. It is not intended for consumers acting outside their business. By accepting these Terms, you confirm you are using the Service for business purposes. (See Section 12 on consumer rights.)
3.2 Authority. The individual who creates the Account or accepts these Terms represents and warrants that they are authorised to bind the Customer organisation to these Terms.
3.3 Self-serve registration. Accounts are created self-serve through our online sign-up. A new Account is provisioned automatically when your organisation is created in our authentication provider; you do not need to sign a paper contract to begin. (Grounded in the self-serve provisioning flow: a new authentication-provider organisation fires organization.created, which our webhook uses to provision the Itemra customer — see src/backend/infrastructure/Itemra.Integrations.WorkOS/WorkOsOrganizationGateway.cs.)
3.4 Authorised Users and invitations. The Customer's administrators may invite Authorised Users by email. The Customer is responsible for: (a) managing its Authorised Users, their roles, and their access; (b) all activity that occurs under its Account; and (c) ensuring its Authorised Users comply with these Terms. (Invitation flow: src/backend/infrastructure/Itemra.Integrations.WorkOS/WorkOsUserDirectoryGateway.cs; user lifecycle: src/backend/core/Itemra.Domain/Users/User.cs.)
3.5 Account security. You are responsible for safeguarding access to the Account. Authentication is handled through our identity provider; you must keep credentials secure and notify us promptly of any suspected unauthorised access.
4. Subscriptions, plans, trials, and fees
4.1 Plans and published prices. The Service is offered in the following plan tiers. Annual figures in this table are the monthly equivalent when the annual term is billed in advance; the displayed table figures are authoritative if a general savings slogan or rounded calculation differs. Taxes required by law are separate from the Fees shown.
| Plan | Included users | USD monthly / annual monthly equivalent | NOK monthly / annual monthly equivalent | Extra user / month | Package |
|---|---|---|---|---|---|
| Free | 1 | $0 / $0 | 0 kr / 0 kr | Not available | Core inventory, locations and containers, stock operations, scanning, labels, CSV import/export, one API key, and community support. |
| Solo | 2 | $19 / $15 | 199 kr / 159 kr | $9 / 99 kr | Free plus attachments, uncapped custom fields, purchasing/receiving/suppliers, BOMs/projects, reservations, alerts and scheduled reports, webhooks, and the full API. Planned, not yet available: Zapier/Make connector. |
| Team | 5 | $59 / $49 | 599 kr / 499 kr | $12 / 119 kr | Solo plus RBAC/custom roles, approvals, counting campaigns, guided picking, transfers/multi-site, tools/vehicles, serial numbers, and insight dashboards. Planned, not yet available: accounting integrations and the priority-support operation. |
| Business | 10 | $149 / $119 | 1,490 kr / 1,190 kr | $12 / 119 kr | Team plus lot/batch/expiry traceability and audit exports. Planned, not yet available: retention controls, SSO/SCIM, field-level permissions, a sandbox, the written SLA, and the onboarding-assistance operation. |
Items, orders, API access, and history depth are not metered pricing dimensions on any plan. Itemra does not impose separate feature add-on charges beyond the published plan and extra-user prices. This promise does not remove VAT/MVA or other taxes required by law. Extra-user amounts are published package prices; extra-user billing is not available until the seat-billing flow is activated, and no extra-user Fee will be charged before then. Some integrations named in a package may require the Customer's own third-party account and may carry charges imposed directly by that third party.
Support, onboarding, and SLA entries describe package entitlement. A contractual response target, service credit, dedicated support channel, or onboarding scope applies only after we publish and activate the corresponding service description or written SLA under Section 10. The present draft does not itself create an uptime or response-time commitment.
4.2 No-card Team trial. A newly created Account receives a 14-day Team trial without a payment card. The trial does not create a paid Stripe Subscription and cannot auto-convert or auto-charge. At the end of day 14, an Account that has not separately purchased a paid Subscription automatically returns to Free. Itemra preserves the Customer Data; the downgrade may prevent new activity that exceeds Free entitlements but does not delete existing data. Starting paid checkout does not start a second trial.
4.3 Payment processor. Paid Subscriptions are billed through Stripe, our third-party payment processor. You will be directed to Stripe's hosted checkout to start a paid Subscription and to Stripe's billing portal to manage payment details. Payment-card data is collected and processed directly by Stripe; Itemra does not receive or store your full card details. (Grounded in src/backend/infrastructure/Itemra.Integrations.Stripe/StripeBillingGateway.cs — Stripe Checkout and Billing Portal sessions; only the organisation id, customer email, and plan/price are sent to Stripe.)
4.4 Billing cycle and auto-renewal. Subscriptions are billed in advance on a recurring basis for the billing period shown at checkout (e.g. monthly or annual). Subscriptions renew automatically for successive periods at the then-current Fees unless cancelled before the renewal date (see Section 7).
4.5 Taxes (VAT/MVA). Fees are stated exclusive of value-added tax (VAT/MVA) and similar taxes unless stated otherwise. Applicable taxes will be added where required. For business-to-business sales within the EU/EEA, the reverse-charge mechanism may apply where you provide a valid VAT registration number; you are responsible for providing accurate tax information.
4.6 Grandfathered prices. The plan, interval, and currency price accepted at checkout remains grandfathered while that paid Subscription continues without interruption. Cancelling, allowing payment to lapse beyond the applicable recovery period, or changing plan, interval, or currency may end the grandfathered price; a later purchase uses the then-current published price. We may still change taxes required by law and separately agreed third-party pass-through charges. We will give at least [PRICE_CHANGE_NOTICE_DAYS] days' notice if counsel approves any exception to this continuous-subscription promise.
4.7 30-day money-back guarantee. The Customer may request a full refund of the first payment for its first paid Subscription within 30 days after that payment. The guarantee applies once per Customer and does not apply to later renewals, separately agreed services, or third-party charges. Requests go to [BILLING_CONTACT_EMAIL]. Refunds required by mandatory law remain available independently of this guarantee; otherwise, Fees are non-refundable after the guarantee period.
4.8 Billing contact. Billing questions should be directed to [BILLING_CONTACT_EMAIL].
5. Acceptable use and Customer obligations
5.1 You and your Authorised Users must not:
- (a) use the Service in violation of any applicable law or regulation;
- (b) upload or transmit malware, or attempt to gain unauthorised access to, disrupt, or impair the Service or its infrastructure;
- (c) probe, scan, or test the vulnerability of the Service except under a written authorisation from us;
- (d) reverse engineer, decompile, or attempt to extract source code from the Service, except to the extent this restriction is prohibited by mandatory law;
- (e) resell, sublicense, or provide the Service to third parties as a service bureau, except as expressly permitted by your plan;
- (f) use the Service to store or transmit content that is unlawful, infringing, or that you have no right to process; or
- (g) circumvent or exceed usage limits, rate limits, or plan entitlements, including via the API.
5.2 No special-category data in free-text or uploads. The Service is designed for warehouse and inventory data and does not collect special categories of personal data (GDPR Article 9) by design. You must not enter special-category personal data into free-text fields (such as notes) or uploaded attachments, and you are responsible for any personal data you choose to include there. (Grounded in the free-text and attachment surfaces: src/backend/core/Itemra.Domain/Files/Note.cs, src/backend/core/Itemra.Domain/Files/Attachment.cs.)
5.3 Customer is controller of Customer Data. As between the parties, the Customer is the controller of any personal data contained in Customer Data, and Itemra is the processor (see Section 8). The Customer warrants that it has a valid legal basis and has provided all required notices and obtained any required consents for the personal data it submits to the Service.
5.4 Customer-configured integrations. Some features rely on configuration you supply — for example, email delivery via an SMTP server you configure for your organisation. Where you direct the Service to send data to a destination you choose (such as your own SMTP provider), you are responsible for that destination and for the lawfulness of those transfers. (Grounded in per-org SMTP configuration: src/backend/infrastructure/Itemra.Infrastructure/Notifications/Email/SmtpEmailSender.cs, src/backend/core/Itemra.Domain/Settings/EmailSettings.cs.)
5.5 Support and bug reports. If you submit an in-app bug or feedback report, the report (including the reporter's name, email, the page URL, your description, and any screenshots or files you attach) is sent to our issue-tracking system to help us resolve the issue. Do not include sensitive information in bug reports that you do not wish to share for support purposes. (Grounded in src/backend/host/Itemra.Api/Services/GitHubBugReportService.cs, which creates an issue in our repository at GitHub and links to uploaded files; see the Subprocessor List and Privacy Policy for details.)
5.6 Outbound webhooks. Outbound webhooks are customer-configured integrations. The Customer chooses the destination and event filters and is responsible for the destination's security, availability, recipients, and lawful handling of transmitted Customer Data.
6. Customer Data, ownership, and intellectual property
6.1 Customer owns Customer Data. As between the parties, the Customer retains all rights, title, and interest in and to Customer Data. We claim no ownership of Customer Data.
6.2 Licence to operate the Service. You grant us a limited, non-exclusive licence to host, store, process, transmit, and display Customer Data solely as necessary to provide, maintain, secure, and support the Service, and as instructed under the DPA.
6.3 Itemra owns the platform. We retain all rights, title, and interest in and to the Service, including all software, designs, and documentation, and all intellectual property rights therein. Subject to these Terms, we grant you a limited, non-exclusive, non-transferable, revocable right to access and use the Service during the term for your internal business purposes.
6.4 Feedback. If you give us feedback or suggestions about the Service, you grant us a perpetual, irrevocable, royalty-free licence to use them without restriction or obligation to you.
6.5 Aggregated / de-identified data. We may generate and use aggregated and de-identified data derived from use of the Service for operating, securing, and improving the Service, provided such data does not identify you, your Authorised Users, or any individual.
7. Suspension, cancellation, and non-payment
7.1 Cancellation by you. You may cancel your Subscription at any time through the in-app billing settings (which use Stripe's billing portal). Cancellation takes effect at the end of the then-current paid period unless stated otherwise; you retain access until then. The Account then returns to the applicable Free entitlements. Cancellation or downgrade does not delete Customer Data, although creating new data or using paid functionality may be unavailable until the Account again satisfies the active plan's entitlements.
7.2 Suspension for non-payment. If a payment fails or Fees are overdue, we may, after a grace period of 7 days and reasonable notice, suspend the Account. While suspended, sign-in and access may be blocked but Customer Data is preserved. (Grounded in CustomerStatus.Suspended — "Temporarily disabled. Sign-in blocked; data preserved." in src/backend/core/Itemra.Domain/Customers/Customer.cs; subscription status is synced from Stripe webhooks, e.g. past_due/unpaid/canceled, via src/backend/infrastructure/Itemra.Integrations.Stripe/StripeWebhookProcessor.cs.)
7.3 Suspension for cause. We may suspend the Account or specific Authorised Users immediately if we reasonably believe there is: (a) a material breach of these Terms (including Section 5); (b) a security risk to the Service or other customers; or (c) a legal requirement to do so. We will limit the scope and duration of any such suspension to what is reasonably necessary.
7.4 Reinstatement. A suspended Account may be reactivated once the cause (e.g. overdue Fees) is resolved. (Grounded in Customer.Activate allowing reactivation from Suspended.)
8. Data protection and the DPA
8.1 Roles. For personal data contained in Customer Data, the Customer is the controller and Itemra is the processor. For Account Data (account, billing, support, and telemetry data), Itemra is the controller.
8.2 DPA incorporated by reference. Our processing of personal data within Customer Data is governed by the DPA at [DPA_URL], which is incorporated into and forms part of these Terms. By accepting these Terms you accept the DPA on behalf of the Customer.
8.3 Privacy Policy. Our processing of Account Data as a controller is described in the Privacy Policy at [PRIVACY_POLICY_URL].
8.4 Subprocessors. We engage third-party subprocessors to provide the Service, listed at [SUBPROCESSOR_LIST_URL]. The current subprocessors handling personal data include our authentication provider (identity/sign-in), Microsoft Azure Blob Storage (uploaded files), Stripe (billing), and our issue-tracking system (support/bug reports). The application and primary database are hosted on Itemra-operated infrastructure and are not a third-party subprocessor. (Grounded in the integrations under src/backend/infrastructure/ and src/backend/host/Itemra.Api/Services/GitHubBugReportService.cs.) Currency exchange rates are fetched from a third-party FX API, to which no personal data is sent (only currency codes). (Grounded in src/backend/infrastructure/Itemra.Infrastructure/Purchasing/FrankfurterFxRateProvider.cs.)
8.5 Order of precedence. In the event of a conflict between these Terms and the DPA regarding the processing of personal data, the DPA prevails.
9. Authentication and third-party dependencies
9.1 Sign-in and identity management are provided through our third-party authentication provider. Account creation and Authorised-User invitations route through that provider, and your organisation and user identity records are mirrored locally to operate the Service. (Grounded in src/backend/infrastructure/Itemra.Integrations.WorkOS/.)
9.2 The Service depends on third-party services (including those in Section 8.4). We are not responsible for the acts or omissions of those providers beyond our obligations under the DPA, but we remain responsible for our selection and oversight of subprocessors as set out in the DPA.
10. Availability, support, and maintenance
10.1 Service levels. Free, Solo, and Team are provided on a best-efforts basis without a service-level commitment. Business includes eligibility for an SLA package, but no uptime target, service credit, measurement method, or exclusion is contractual until a written SLA at [PLACEHOLDER — link to SLA, if any] is published, activated for the Customer, and incorporated into its Subscription.
Drafting note: SUP-05 remains incomplete and the repository contains no approved SLA artifact. Do not activate or advertise a contractual uptime target or credits until the owner and counsel approve the written SLA.
10.2 Support. Community support, priority support, and onboarding assistance are plan package labels. They do not promise a response time or dedicated channel until the relevant support channel and operating policy are activated and published. Current support is provided through [SUPPORT_CONTACT_EMAIL] and/or in-app bug reporting on a best-efforts basis.
Drafting note: SUP-01 remains an activation prerequisite for the support channel and service hours. Remove this note only when the published support operation matches the plan labels.
10.3 Maintenance. We may perform scheduled maintenance, which we will aim to carry out during [MAINTENANCE_WINDOW] and to announce in advance where practicable. We may perform emergency maintenance without prior notice where necessary to protect the security or integrity of the Service.
11. Warranties, disclaimers, and limitation of liability
11.1 Limited warranty. We warrant that we will provide the Service with reasonable skill and care and substantially in accordance with its documentation.
11.2 Disclaimer. Except as expressly stated in these Terms and to the maximum extent permitted by mandatory law, the Service is provided "as is" and "as available", and we disclaim all other warranties, whether express, implied, or statutory, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement. We do not warrant that the Service will be uninterrupted or error-free.
11.3 Customer responsibility for data. You are responsible for the accuracy, quality, and legality of Customer Data and for maintaining your own backups or exports of Customer Data where appropriate. Inventory ledgers and audit records in the Service are append-only by design and are not a substitute for your own records of account. (Grounded in append-only ledgers such as src/backend/core/Itemra.Domain/Audit/AuditEvent.cs and src/backend/core/Itemra.Domain/Inventory/MovementEvent.cs.)
11.4 Exclusion of indirect loss. To the maximum extent permitted by mandatory law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, revenue, goodwill, or anticipated savings, arising out of or in connection with these Terms.
11.5 Liability cap. To the maximum extent permitted by mandatory law, each party's total aggregate liability arising out of or in connection with these Terms is limited to [LIABILITY_CAP] (for example, the Fees paid or payable by the Customer in the 12 months preceding the event giving rise to the claim).
11.6 Carve-outs. The exclusions and cap in Sections 11.4 and 11.5 do not apply to: (a) liability that cannot be excluded or limited under mandatory law; (b) either party's liability for death or personal injury caused by negligence; (c) fraud or fraudulent misrepresentation; (d) the Customer's payment obligations; and (e) [as advised by counsel] either party's liability for breach of its data-protection obligations / indemnities, which may be addressed separately in the DPA.
11.7 Indemnities. [Reserved for counsel — e.g. Customer indemnity for unlawful Customer Data or breach of Section 5; Itemra indemnity for third-party IP claims arising from the Service. Coordinate with the DPA's allocation of data-protection liability.]
12. Consumer and mandatory-law savings
12.1 B2B contract. The Service is supplied for business use. Because this is a business-to-business contract, the consumer right of withdrawal (Norwegian angrerett / EU 14-day withdrawal right) does not apply.
12.2 If a consumer contracts. If, despite Section 3.1, you are a consumer (or a sole trader treated as a consumer), and a statutory right of withdrawal applies, you may have a 14-day right to withdraw. Where you request that we begin supplying the Service immediately during the withdrawal period, you acknowledge that, upon full performance of a digital service supplied with your prior express consent, the right of withdrawal is lost; for partially supplied services you may owe a proportionate amount.
Drafting note: confirm with counsel whether any consumers or sole traders are in scope. If yes, a compliant consumer flow (pre-contract information, withdrawal form, and waiver mechanism) is required and this clause must be expanded.
12.3 Mandatory rights preserved. Nothing in these Terms limits or excludes any rights you have that cannot be limited or excluded under mandatory Norwegian or EU/EEA law, including non-waivable consumer-protection and data-protection rights.
13. Term, termination, and post-termination data
13.1 Term. These Terms apply for as long as you have an Account or use the Service. A Subscription runs for the period selected and renews per Section 4.4 until cancelled or terminated.
13.2 Termination by you. You may terminate by cancelling your Subscription and ceasing use; cancellation takes effect per Section 7.1.
13.3 Termination by us. We may terminate these Terms or your Account: (a) for a material breach that is not cured within a reasonable period after notice; (b) immediately for the causes in Section 7.3; or (c) on reasonable notice if we cease to offer the Service generally.
13.4 Effect of termination. On termination, your right to access the Service ends. We may then archive the Account for read-only historical retention or, as applicable, suspend access pending data export/deletion. (Grounded in CustomerStatus.Archived — "End-of-life. Read-only historical retention." in src/backend/core/Itemra.Domain/Customers/Customer.cs.)
13.5 Data export and deletion. For a period of [EXPORT_WINDOW_DAYS] days after termination, you may request an export of Customer Data in a structured, commonly used, machine-readable format. After that window, we will delete or return Customer Data in accordance with the DPA's deletion-or-return obligation, except where retention is required by law (for example, billing and accounting records retained to meet bookkeeping-law obligations). (This must align with the DPA's Article 28(3)(g) deletion/return obligation. Note: the codebase currently uses status-based and soft-delete lifecycles rather than hard deletion in most stores — see src/backend/infrastructure/Itemra.Persistence/Interceptors/SoftDeleteInterceptor.cs; counsel and engineering must confirm the actual deletion procedure and timeline.)
13.6 Survival. Sections concerning ownership (6), payment obligations accrued before termination (4), data protection (8), warranties and liability (11), this Section 13, and governing law (15) survive termination.
14. Changes to these Terms
14.1 We may update these Terms from time to time. For material changes, we will give at least [TERMS_CHANGE_NOTICE_DAYS] days' notice by email and/or in-app notice before the change takes effect.
14.2 Continued use of the Service after the effective date of an update constitutes acceptance of the updated Terms. If you do not accept a material change, you may cancel your Subscription before it takes effect.
14.3 We maintain a version number and effective date at the top of these Terms.
15. Governing law, venue, and disputes
15.1 Governing law. These Terms are governed by the laws of [GOVERNING_LAW] (intended: Norway), without regard to conflict-of-laws rules.
15.2 Venue. The parties submit to the exclusive jurisdiction of the courts of [VENUE], subject to any mandatory venue rules that apply to consumers.
15.3 Dispute resolution. The parties will attempt in good faith to resolve any dispute informally before commencing proceedings. [Optional, per counsel: escalation, mediation, or arbitration clause.]
16. General
16.1 Entire agreement. These Terms, together with the DPA, Privacy Policy, Subprocessor List, and any plan/order details, form the entire agreement between the parties regarding the Service and supersede prior agreements on the subject.
16.2 Order of precedence. In case of conflict: (1) the DPA prevails on data-protection matters; (2) otherwise, an executed order or plan-specific terms prevail over these Terms; (3) then these Terms.
16.3 Assignment. You may not assign these Terms without our prior written consent, except to a successor in connection with a merger or sale of substantially all assets. We may assign these Terms to an affiliate or successor.
16.4 Subprocessors and subcontracting. We may use subprocessors and subcontractors to provide the Service, subject to the DPA.
16.5 Force majeure. Neither party is liable for failure or delay caused by events beyond its reasonable control.
16.6 Severability. If any provision is held invalid or unenforceable, the remaining provisions remain in effect, and the invalid provision is modified to the minimum extent necessary to make it enforceable.
16.7 No waiver. Failure to enforce a provision is not a waiver of the right to enforce it later.
16.8 Notices. Notices to us should be sent to [CONTACT_EMAIL]. Notices to you may be given by email to your Account's registered contacts or by in-app notice.
16.9 Contact. [LEGAL_ENTITY_NAME], organisation number [ORG_NUMBER], [REGISTERED_ADDRESS]. General: [CONTACT_EMAIL] · Billing: [BILLING_CONTACT_EMAIL] · Support: [SUPPORT_CONTACT_EMAIL] · Web: [WEBSITE_URL].
End of Terms of Service (DRAFT — for legal review).