Terms of Service

Terms of Service for Biosyn

Last Updated: September 2026

Welcome to Biosyn ("Biosyn," "we," "us," or "our"). These Terms of Service ("Terms") govern your access to and use of Biosyn (`biosyn.dev`), a multi-tenant cloud biometric gateway middleware SaaS platform that securely bridges physical attendance and access control hardware (such as ZKTeco devices) with customer destination CRM, ERP, HRMS, and payroll systems via real-time webhooks and REST APIs (the "Service").

By registering an account, generating an API key, connecting a physical hardware device, or utilizing the Service, you ("Customer," "User," or "you") agree to be bound by these Terms. If you are entering into these Terms on behalf of a business, corporation, or legal entity, you represent and warrant that you have full legal authority to bind such entity to these Terms.


1. Service Nature & Cloud Gateway Boundaries

Biosyn operates strictly as a cloud intermediary gateway middleware layer. You acknowledge and agree to the following operational boundaries:

  • Middleware Intermediary Role: Biosyn functions exclusively as a cloud transit pipeline for relaying hardware telemetry, biometric verification logs, RFID card scans, user enrollment synchronizations, and device heartbeat statuses to your designated destination endpoints.
  • No Hardware Ownership or Physical On-Site Support: Biosyn does not manufacture, sell, repair, or maintain physical biometric devices, turnstiles, or card readers. On-site hardware installation, firmware management, power supply, local network routing, and physical maintenance are your sole responsibility.
  • Third-Party System Independence: Biosyn is independent of third-party CRM, ERP, HRMS, and payroll software. We are not liable for downtime, API rate limiting, misconfigurations, or service interruptions occurring on your destination endpoints.

2. Merchant of Record & Payment Processing (Paddle)

Our payment processing and order fulfillment are conducted by our authorized online reseller and Merchant of Record:

  • Paddle as Merchant of Record: Paddle.com Market Limited (or Paddle Payments Limited, collectively "Paddle") is the Merchant of Record for all Biosyn orders, paid subscriptions, and billing transactions.
  • Billing & Customer Service: Paddle provides transaction processing, order invoicing, sales tax/VAT compliance, and billing support. When purchasing a subscription, you provide payment details directly to Paddle subject to Paddle's Terms of Service and Privacy Policy.

3. Subscription, Metered Billing & Active Usage Calculation

Access to Biosyn is provided under a flexible subscription model based on registered locations, connected physical devices, and enrolled user profiles:

  • Rolling 30-Day Billing: Subscriptions are billed on a rolling 30-day billing cycle processed automatically by Paddle. Fees are calculated from the total active users and physical hardware terminals configured across your registered locations.
  • Location-Based User & Device Calculation: Metered subscription usage is determined by counting user profiles and connected devices grouped under each registered location in your account. Adding locations, terminals, or users dynamically adjusts your billing tier.
  • Price Modifications: We reserve the right to modify subscription pricing upon 30 days' advance notice. Notice will be delivered via email or posted within your client dashboard.

4. Cancellation & Refund Policy

Our cancellation and refund terms are designed to be fair and transparent:

  • Self-Service Subscription Cancellation: You may cancel your subscription at any time via your client portal dashboard or by contacting Paddle support. Cancellation prevents future billing cycles and takes effect at the end of your current paid 30-day period.
  • 14-Day Money-Back Guarantee: New customers subscribing to Biosyn for the first time are eligible for a full refund within 14 calendar days of their initial order if the Service does not meet their technical integration requirements.
  • Refund Requests: To request a refund under our 14-day guarantee, submit a request to [email protected] or contact Paddle support directly. Detailed terms are available in our official Refund & Cancellation Policy.

5. Mandatory Biometric Privacy & Data Controller Warranties

Compliance with biometric privacy regulations (including Illinois BIPA, EU GDPR Article 9, CCPA/CPRA, and regional privacy statutes) is a strict condition of using Biosyn:

  • Data Controller Status: You are the sole Data Controller regarding all employee, contractor, visitor, or user data (including biometric templates, facial mathematical hashes, fingerprint templates, RFID codes, and attendance timestamps) processed through the Service. Biosyn acts strictly as a Data Processor carrying out your documented instructions.
  • Explicit Written Consent Warranty: You warrant and represent that you have provided all legally required privacy notices and obtained explicit, voluntary written consent from all data subjects prior to capturing, enrolling, or transmitting their biometric data or attendance logs through Biosyn.
  • Retention Schedules & Destruction Policies: You warrant that you publish and enforce legally compliant biometric data retention schedules and written destruction policies as mandated by applicable law.
  • Indemnification: You agree to fully defend, indemnify, and hold harmless Biosyn, its officers, directors, employees, and Paddle from any regulatory penalties, fines, lawsuits, or claims arising from your failure to obtain mandatory consent or comply with biometric privacy statutes.

6. Customer Responsibilities & Network Security

You are responsible for maintaining the operational integrity and security of your account:

  • API Key Confidentiality: You must maintain strict confidentiality of your account credentials and generated API keys. You are fully responsible for all API requests, webhook emissions, and activities executed under your API keys.
  • Network Connectivity & Firewalls: You are responsible for ensuring that your connected physical terminals maintain stable internet connectivity (Wi-Fi, 4G, broadband) and proper outbound firewall configurations to communicate with our cloud gateway servers.
  • Prohibited Activity & System Abuse: You agree not to reverse engineer gateway protocols, execute denial-of-service (DoS) attacks, flood webhook endpoints, attempt cross-tenant data access, or use the Service for illegal surveillance.

7. Service Availability, Webhooks & SLA Terms

  • Gateway Availability: We use commercially reasonable efforts to maintain a 99.9% cloud gateway API uptime target. Detailed commitments are set forth in our Support & SLA Policy.
  • Webhook Delivery Disclaimer: Biosyn incorporates automatic webhook delivery retry mechanisms for transient destination server drops. However, we are not responsible for lost or delayed logs caused by your receiving server downtime, network timeouts, invalid HTTP responses, or firewall blocks on your endpoint.
  • Maintenance Windows: Scheduled maintenance will be announced in advance when feasible. Critical security hotfixes may be applied immediately to protect infrastructure integrity.

8. Intellectual Property & Subscription License Grant

All rights, title, and interest in Biosyn, including cloud gateway software, REST APIs, webhook engines, dashboard interfaces, documentation, logos, and trademarks, remain the exclusive intellectual property of Biosyn. Subject to compliance with these Terms, we grant you a limited, non-exclusive, non-transferable, revocable subscription license to access and use the Service during your active paid billing term.

9. Limitation of Liability & Warranty Disclaimer

  • WARRANTY DISCLAIMER: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT.
  • CONSEQUENTIAL DAMAGES EXCLUSION: IN NO EVENT SHALL Biosyn, ITS AFFILIATES, OR PADDLE BE LIABLE FOR ANY INDIRECT, CONSEQUENTIAL, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, DATA, REVENUE, GOODWILL, OR BUSINESS INTERRUPTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR INABILITY TO USE THE SERVICE, PHYSICAL DEVICE DISCONNECTS, OR UNDELIVERED ATTENDANCE LOGS.
  • AGGREGATE LIABILITY CAP: OUR MAXIMUM AGGREGATE LIABILITY UNDER THESE TERMS SHALL NOT EXCEED THE TOTAL FEES ACTUALLY PAID BY YOU TO US IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

10. Term, Suspension & 30-Day Non-Payment Data Destruction

  • Account Suspension: We reserve the right to suspend API access, webhook routing, device connections, or account access immediately upon billing failure, non-payment default, or material breach of these Terms.
  • 30-Day Data Destruction Grace Period: If an account remains in billing default or unpaid status for thirty (30) consecutive calendar days, we reserve the right to permanently purge and destroy all associated tenant configurations, registered device routing tables, API keys, and event logs. Destroyed tenant data is permanently unrecoverable.

11. Governing Law & Dispute Resolution

These Terms and any dispute or claim arising out of or in connection with them shall be governed by and construed in accordance with the laws of India, without giving effect to conflict of law principles. Any legal suit, action, claim, or proceeding arising out of or relating to these Terms or the Service shall be instituted exclusively in the Barrackpore Sub-Divisional Court in North 24 Parganas, West Bengal, India, and you irrevocably submit to the exclusive jurisdiction of such court.

12. Modifications & Legal Contact

We reserve the right to modify these Terms at any time. Revised Terms will be published on `biosyn.dev` with an updated "Last Updated" date. Continued use of the Service after effective changes constitutes acceptance of the updated Terms.

For questions or legal inquiries regarding these Terms, please contact our legal and support team at [email protected] or consult technical documentation at docs.biosyn.dev.