# Terms of Service

> Version: 2026-08-15
> Issued: 15 August 2026
> Effective: 15 August 2026
> English is the authoritative version.

These Terms of Service (**Terms**) are a legal agreement between Magnolia Squared and the business
accepting them (**Customer**). Magnolia Squared is a Dutch sole proprietorship (`eenmanszaak`), KVK
90466659, VAT ID NL004818456B50, at Batavengaarde 4, 2408 TA Alphen aan den Rijn, the Netherlands.
The proprietor is Wessel Hendrik Pannebakker. Magnolia Squared is called
**Provider**, **we**, **us**, or **our** in these Terms. **Hendrik** means the Service described in
Section 1.1.

By accepting these Terms for a business, the individual accepting represents that they are at least
18, have authority to bind that business, and agree on its behalf. If they lack that authority, they
must not accept or use the Service.

## 1. The Service

1.1. **Service.** **Hendrik** is a warehouse-native software service for advertising and commerce
professionals. The Service includes the marketing website at `https://withhendrik.com`, the product
application at `https://app.withhendrik.com`, the trust-core API at
`https://api.withhendrik.com`, and public read-only endpoints at
`https://public-api.withhendrik.com`. It connects to customer-selected platforms, reports governed
metrics and provenance, generates analyses and recommendations, and may propose actions for a
customer to approve and execute in external accounts.

**Third-Party Provider** means a third party whose service Hendrik connects to or depends on,
including customer-selected platforms and Provider's own infrastructure, AI, analytics, email, and
billing vendors. It never means Provider.

1.2. **Human decision support.** The Service supports—not replaces—professional judgment. Analyses,
metrics, forecasts, recommendations, and AI output may be inaccurate, incomplete, delayed, or
unsuitable. Customer must independently review material decisions and live Third-Party Provider state.

Public read-only endpoints at `https://public-api.withhendrik.com` may be accessed without an
account under the license in Section 1.5.

1.3. **No SLA.** Unless an Order Form expressly states otherwise, Provider provides no uptime,
availability, response-time, recovery-time, or service-credit commitment. Provider will use
commercially reasonable efforts to operate and support the Service. Email support has a target,
not guaranteed, response time of seven days.

1.4. **Changes.** Provider may improve, replace, limit, or discontinue features. Provider will give
reasonable notice of a material discontinuation where practicable. Third-party platform changes may
require immediate changes or suspension.

1.5. **Public endpoints.** Provider grants any person accessing the public read-only endpoints a
revocable, non-exclusive, non-transferable license to retrieve and use the data they return,
conditional on not doing anything prohibited by Section 5.1. Provider may authenticate, document,
meter, rate-limit, condition, restrict, change, or withdraw access at any time. The endpoints are
provided as-is without warranty, and Sections 11–13 apply to Provider's liability to the maximum
extent permitted by law. Public endpoint access may not be used to circumvent product controls,
extract data in bulk, identify another customer, resell Hendrik data or functionality, or build or
benchmark a competing service, except to the extent a non-waivable law permits otherwise. Where the
person is also Customer or its authorized user, the Agreement additionally governs that access.

## 2. Contract formation and order of precedence

2.1. Customer accepts these Terms through versioned clickwrap at account creation, paid checkout, an
Order Form, or another acceptance method that clearly identifies these Terms. Merely visiting a
public website or accessing a public endpoint does not create a paid Service contract or constitute
a contract acceptance; Section 1.5's license and conditions apply to public-endpoint access instead.
Browser analytics and replay are governed by the Privacy Policy, not by acceptance of these Terms.
Before acceptance, Provider makes these Terms, the DPA, and incorporated policies available in a
form Customer can download, store, and reproduce. After acceptance, Provider sends a copy or a
permanent link to the accepted version to Customer's account-owner email.

2.2. If documents conflict, the following order applies to the conflict:

1. a signed master services agreement;
2. an Order Form, for its specific commercial terms;
3. the Data Processing Agreement, for processing of Customer Personal Data;
4. these Terms; and
5. incorporated policies and documentation.

A purchase order or Customer form does not amend the Agreement, even if Provider processes it.

2.3. The **Agreement** means these Terms, the applicable Order Form, the DPA, and incorporated
policies. It begins when Customer first accepts the Agreement and continues until terminated.

## 3. Accounts and customer responsibilities

3.1. Customer must provide accurate business and account information, keep it current, designate an
account owner, and keep authentication credentials secure. Customer is responsible for its users,
their permissions, and activity under its accounts except to the extent caused by Provider's breach.

3.2. Customer must promptly report suspected compromise to
`security@withhendrik.com`, remove users who no longer require access, and apply
reasonable organizational and technical controls.

3.3. Customer is responsible for:

- the legality, accuracy, quality, and rights in Customer Data and Customer instructions;
- providing required notices and obtaining required permissions or lawful bases;
- configuring roles, connected accounts, policies, budgets, protected resources, and approval rules;
- reviewing proposals, warnings, assumptions, provenance, staleness, and Third-Party Provider state;
- maintaining independent records and controls appropriate to its business; and
- complying with platform terms, advertising rules, laws, taxes, sanctions, and industry obligations.

## 4. External accounts, actions, and financial risk

4.1. **Customer controls external accounts.** Meta, Google, Shopify, Stripe, and other connected
accounts remain Customer's accounts. Customer is responsible for access, users, budgets, billing,
Third-Party Provider settings, Third-Party Provider policies, and activity outside the Service.

4.2. **Approved actions are instructions.** The Service separates proposal, authenticated approval,
and execution. An action approved by an authorized Customer user is Customer's instruction to
Provider. Customer must verify the proposal, immutable approval details, timing, scope, limits, and
current Third-Party Provider state before approval.

4.3. **Third-party behavior is outside Provider's control.** A third-party platform or service
(**Third-Party Provider**) may reject, delay, duplicate, reinterpret, attribute, preserve, reverse,
or independently change an action. Third-Party Providers may change
APIs, policies, account access, attribution, auction outcomes, billing, or enforcement without notice.
Provider does not guarantee acceptance, delivery, attribution, performance, preservation, or
reversibility of an external action.

4.4. **Overspend and opportunity risk.** Customer accepts that using advertising and commerce tools
involves the risk of overspend, underspend, missed revenue, lost opportunity, stale or conflicting
data, attribution differences, and unintended Third-Party Provider outcomes. Customer must maintain
Third-Party Provider-side
budgets and monitoring appropriate to its risk. To the maximum extent permitted by law, Provider is
not liable for Third-Party Provider outages, Third-Party Provider-originated changes, account
restrictions, enforcement, or
Customer's failure to review or maintain controls. Any remaining Provider liability for overspend,
underspend, or other account impact is subject to Sections 12 and 13.

4.5. **Rollback is best effort.** A rollback is a new Third-Party Provider action, not a guarantee that prior
state or commercial effect can be restored. Customer remains responsible for confirming live state.

## 5. Acceptable use and prohibited data

5.1. Customer must not use the Service to:

- violate law, sanctions, third-party rights, Third-Party Provider rules, or advertising policies;
- submit or process children's data, special-category or sensitive personal data, or shopper contact
  profiles such as names, emails, phone numbers, and postal addresses;
- make employment, credit, insurance, health, legal-rights, housing, or similarly significant
  decisions about individuals;
- send unlawful, deceptive, discriminatory, infringing, malicious, or prohibited advertising;
- distribute malware, spam, harmful code, or content that facilitates unlawful activity;
- share credentials, bypass access or usage controls, probe other tenants, or gain unauthorized access;
- reverse engineer except where a non-waivable law permits it, scrape the Service, resell it, or use
  it to build a competing service; or
- conduct security testing without prior written authorization.

5.2. These restrictions do not prohibit truthful reviews, lawful interoperability, or legitimate
comparative testing that does not access non-public systems, confidential information, or other
customers' data.

5.3. Provider may investigate suspected violations and remove or restrict unlawful or dangerous
content. Customer will reasonably cooperate with abuse, security, or legal investigations.

5.4. **EU AI Act allocation and covenants.**

- **Role allocation follows conduct.** For Regulation (EU) 2024/1689 (the **EU AI Act**), Provider
  intends to act as the provider of the AI system comprised in the Service and Customer ordinarily
  acts as its deployer. Legal roles nevertheless follow each party's actual conduct. Customer may
  become a provider or other regulated operator if it places the Service or a substantially modified
  system on the market or puts it into service under its own name or trademark, substantially
  modifies it, or changes its intended purpose in a way that triggers that result under applicable
  law. Customer must not do so without Provider's prior written consent.
- **High-risk covenant.** The Service is not designed, tested, or offered as a high-risk AI system.
  Customer must not put the Service into service or use its output for a purpose listed in Annex III,
  otherwise falling within Article 6, or prohibited by Article 5, including the decision types in
  Section 5.1. Section 14.1 applies to a claim arising from Customer's breach of this paragraph.
- **Transparency.** Provider identifies AI-generated analyses, recommendations, and conversational
  output within the Service. Customer is responsible for any further disclosure required when it
  passes that output to another person.
- **AI literacy and oversight.** Each party will take reasonable measures to ensure that personnel
  operating or relying on the Service have sufficient AI literacy for their role as contemplated by
  Article 4. Customer will assign competent personnel to review proposals and output before approval
  or reliance.

## 6. Customer Data, output, and intellectual property

6.1. **Customer Data.** As between the parties, Customer retains its rights in data, prompts,
configurations, and other material it submits or makes available (**Customer Data**). Customer grants
Provider and its subprocessors a non-exclusive, worldwide, limited license to host, copy, transmit,
transform, and otherwise process Customer Data only as needed to provide, secure, support, and
comply with law concerning the Service. This license runs for the Agreement and, thereafter, only
for so long and to the extent necessary to complete deletion, allow backups to expire, and satisfy
the retention obligations in the DPA and Privacy Policy. Provider will not use Customer prompts,
user inputs, underlying evidence, or raw tool payloads to improve the Service.

6.2. **Output.** As between the parties and subject to applicable law and third-party rights,
Customer may use output generated for it. Similar or identical output may be generated for others.
Provider does not represent that output is protectable, unique, accurate, or non-infringing.
Customer authorizes Provider to select and review generated Agent responses for quality assurance
and improvement of Hendrik, particularly where a response is incorrect, unexpected, or does not
follow the user's apparent intent. This authorization does not extend to the corresponding prompt,
user input, underlying evidence, or raw tool payload. Before such review, Provider will apply the
deterministic direct-identifier, payment-card, and secret redaction described in the Privacy Policy,
restrict access to authorized personnel, and apply the stated retention and erasure rules. Output
remains Customer Confidential Information and personal data to the extent it contains or reproduces
either. Provider will not publish the selected response, use it for advertising, or use it to train
a general-purpose model.

6.3. **Provider technology.** Provider and its licensors retain all rights in the Service, software,
interfaces, workflows, metric definitions, methods, models, documentation, designs, and improvements.
No rights are granted except the limited, non-exclusive, non-transferable, revocable right for
Customer and its authorized users to use the Service internally during the Agreement.

6.4. **No general-model training.** Provider will not use Customer confidential content to train a
general-purpose model. This does not change processing needed to deliver or secure a requested model
response under verified Third-Party Provider business terms.

6.5. **Feedback.** Customer grants Provider a perpetual, irrevocable, worldwide, royalty-free,
non-exclusive, sublicensable license to use feedback and suggestions without identifying Customer or
disclosing Customer Confidential Information.

## 7. Confidentiality

7.1. **Confidential Information** means non-public information disclosed by one party that is marked
confidential or reasonably should be understood as confidential. Customer Data and security details
are Customer Confidential Information; the Service, non-public product information, and pricing in
an Order Form are Provider Confidential Information.

7.2. The receiving party will use Confidential Information only to perform or exercise rights under
the Agreement, including Provider's narrowly limited use of selected Agent responses under Section
6.2; protect it with at least reasonable care; and disclose it only to personnel, advisers, and
providers who need it and are bound by confidentiality obligations. Section 6.2 does not authorize
product-improvement use of Customer prompts, user inputs, underlying evidence, or raw tool payloads.
These duties do not apply to information the receiving party can show was lawfully known without
restriction, independently developed, rightfully received without restriction, or public through no
breach.

7.3. A receiving party may disclose information required by law if, where legally permitted, it
gives prompt notice and reasonable assistance to seek protective treatment. Confidentiality survives
for five years after termination and for trade secrets as long as they remain trade secrets.

## 8. Privacy and security

8.1. Each party will comply with its applicable data-protection obligations. The Privacy Policy
governs Provider's controller processing. The DPA applies automatically where Provider processes
Customer Personal Data as processor or service provider.

8.2. Provider will maintain reasonable safeguards described in the DPA. Customer acknowledges that
no internet service is risk-free and is responsible for configuring and operating its own systems
and connected accounts securely.

## 9. Fees, billing, taxes, and Analysis Credits

9.1. **Fees and renewal.** Paid subscriptions renew for the monthly or annual interval selected in
the Order until canceled. Customer authorizes Provider and Stripe to charge the payment method for
recurring fees, eligible one-time purchases, and taxes. Prices exclude VAT, sales, use, withholding,
and similar taxes; Customer is responsible for them except taxes on Provider's net income. Valid
tax-exemption evidence must be provided before charging.

9.2. **Plan changes.** Upgrades take effect immediately and may be prorated. Downgrades take effect
at the next renewal. Cancellation stops renewal at the end of the current paid period.

9.3. **No refunds.** Fees are non-refundable and non-creditable except where law requires, for a
verified duplicate or incorrect charge, on termination under Section 8.3 of the DPA following a
valid subprocessor objection, on termination for Provider's uncured material breach, or at
Provider's discretion. Termination for Provider's uncured material breach entitles Customer to a
prorated refund of prepaid unused recurring fees for the terminated affected Service, as Customer's
exclusive fee remedy.

9.4. **Failed payment.** Customer has 14 days after notice of a failed payment to cure. Provider will
send at least two notices during that period to the billing and account-owner contacts. Provider may
then suspend chargeable AI and external-write capabilities, and later the Service, while
preserving read/export access where safe and technically feasible. Overdue amounts may accrue the
lower of 1% per month or the maximum lawful rate, plus reasonable collection costs.

9.5. **Analysis Credits.** An Analysis Credit is a contractual usage entitlement that represents
USD 1.00 of billable third-party AI inference cost admitted through Hendrik. It is not money,
electronic money, a token, or transferable stored value. It is inseparable from the applicable
Hendrik subscription and cannot be redeemed with another supplier or for money. Provider may
reserve a stated maximum before work begins and settle the exact billable amount in fractional
Analysis Credits after the work completes. Subscription-period Analysis Credits expire at the end
of their grant period, do not roll over, and are not refundable. Provider may release unused or
canceled reservations and correct an erroneous grant or ledger projection through compensating
entries. Available, reserved, settled, released, and expired amounts may be shown separately.
Provider charges VAT or another transaction tax only when and to the extent applicable law
requires. The tax classification or invoicing treatment of an Analysis Credit does not make it
transferable, redeemable for money, or usable independently of the Hendrik service. A change to the
value of newly issued Analysis Credits applies prospectively and does not reprice settled usage.

9.6. **Price changes.** Provider will give at least 30 days' notice before a material price increase
applies to a renewal. Customer may cancel before that renewal.

## 10. Suspension and termination

10.1. Provider may immediately limit or suspend access when reasonably necessary for a security risk,
abuse, unlawful use, material Third-Party Provider revocation, non-payment after the grace period, binding legal
demand, threat to the Service or others, or breach that cannot safely await cure. Where lawful and
practicable, Provider will state the reason and allow Customer to cure.

10.2. Either party may terminate for an uncured material breach 30 days after written notice. Either
party may terminate immediately for an incurable material breach, fraud, unlawful abuse, or a
security breach that makes continued performance unsafe. Customer may cancel a subscription at any
time effective at period end.

10.3. On termination, Customer's right to use the Service ends. Provider will preserve read/export
access where safe during the applicable deletion window, but may disable execution immediately.
Workspace deletion is reversible for 60 days by default; export is intended for the first 30 days.
Customer may instruct immediate non-reversible deletion under the DPA, in which case export and
restoration are unavailable. Active purge occurs after the applicable period, subject to legal
retention and the DPA. Customer should export data before access ends.

10.4. Accrued payment duties and provisions intended by nature to survive—including confidentiality,
IP, disclaimers, liability, indemnities, and disputes—survive termination.

## 11. Warranties and disclaimers

11.1. Each party represents it has authority to enter the Agreement. Provider warrants that it will
provide paid Services with commercially reasonable skill and care. Customer's exclusive remedy for
breach of this warranty is re-performance or, if Provider cannot materially cure, termination of the
affected Service and the prorated refund stated in Section 9.3.

11.2. Except for the express warranty above and to the maximum extent permitted by law, Provider
disclaims implied warranties of merchantability, satisfactory quality, fitness for a particular
purpose, non-infringement, title, uninterrupted availability, and error-free or accurate results.
Provider does not warrant forecasts, recommendations, attribution, savings, revenue, campaign
performance, Third-Party Provider acceptance, regulatory compliance, or any commercial outcome.

11.3. Free features, previews, and third-party services may be changed or withdrawn at any time and
are provided without a service commitment, subject to non-waivable law.

## 12. Excluded damages

To the maximum extent permitted by law, neither party is liable under or relating to the Agreement
for indirect, incidental, special, exemplary, punitive, or consequential loss; loss of profits,
revenue, savings, goodwill, opportunity, or business; or loss or corruption of Customer Data to the
extent it could have been avoided by Customer's use of export functionality Provider makes available
and by reasonable Customer controls over its own systems and connected accounts. This exclusion
applies regardless of theory and even if advised of the possibility.

For clarity, lost opportunity, expected advertising performance, attribution differences, overspend,
underspend, Third-Party Provider penalties, and Third-Party Provider account interruption are excluded to the maximum extent
they constitute the losses described above. Direct damages, if any, remain subject to Section 13.

## 13. Liability caps

13.1. Subject to Section 13.3, Provider's total aggregate liability arising from or related to the
Agreement will not exceed:

- for a paid Customer, the fees Customer paid Provider for the affected Service during the 12 months
  before the first event giving rise to liability; or
- for a Customer that paid no fees for the affected access during that period, EUR 100.

13.2. Subject to Section 13.3, Provider's total aggregate liability for breach of confidentiality,
data-protection, or security obligations and for a Security Incident under the DPA is subject instead
to a separate aggregate cap equal to the greater of:

- three times the amount calculated under Section 13.1; and
- EUR 1,000.

This privacy, confidentiality, and security cap applies in place of the Section 13.1 cap for the same
loss; the caps are not cumulative for the same claim. Provider's obligations under Section 14.2 and
every other claim against Provider arising from or relating to the Agreement remain within the single
aggregate cap in Section 13.1.

13.3. Nothing excludes or limits liability to the extent it cannot lawfully be excluded or limited,
including liability for fraud, wilful misconduct, deliberate recklessness, death or personal injury
caused by negligence where applicable, or another non-excludable statutory obligation. The Agreement
does not limit Customer's payment obligations or any data subject's right to full recovery under
applicable data-protection law. Customer's indemnity is governed only by the separate cap and
exceptions in Section 14.1.

13.4. The exclusions and Provider caps allocate risk and apply to Provider claims in aggregate,
including contract, tort, negligence, statutory duty, restitution, and indemnity, to the extent
permitted by law. Each party must take reasonable steps to mitigate loss. Customer's separate
indemnity pool under Section 14.1 is not reduced by a payment made by Provider.

## 14. Indemnities

14.1. **Customer indemnity.** Customer will defend Provider and its proprietor, personnel, and
affiliates against a third-party claim arising from Customer Data, Customer instructions, Customer
advertising or external-account activity, breach of Section 5, Third-Party Provider-policy violation, or alleged
infringement by Customer material, and will pay finally awarded damages and reasonable settlements.
Customer's obligations under this Section are not subject to Section 13. For each third-party claim,
Customer's liability under this Section is limited to the greater of EUR 1,000 and five times the
fees Customer paid or owes Provider for the affected Service during the 12 months before the first
event giving rise to that claim. No limit applies to the extent a claim results from Customer's
fraud, wilful misconduct, breach of Section 5.1, or infringement of a third party's intellectual
property, whether or not Customer knew of the breach. This is a separate Customer pool for each
claim. A payment by Provider under Section 13 or 14.2 does not reduce Customer's indemnity capacity.

14.2. **Provider IP defense for paid Customers.** Provider will defend a paid Customer against a
third-party claim that the unmodified paid Service, used as authorized, infringes that party's patent,
copyright, or trademark, and pay finally awarded damages and approved settlements. This does not
apply to Customer Data, output, third-party services, modifications, combinations, continued use
after notice, or use outside the Agreement. Provider may obtain continued rights, modify or replace
the affected Service, or terminate it and refund prepaid unused affected fees. This Section is the
exclusive remedy for such claims. Provider's liability under this Section is included within, and
does not increase, the aggregate cap in Section 13.1.

14.3. The indemnified party must give prompt notice, reasonable cooperation at the indemnifying
party's expense, and control of defense and settlement. A settlement may not admit fault, impose a
non-monetary obligation, or fail to fully release the indemnified party without its written consent.

## 15. Changes to these Terms

Provider may update these Terms. Provider will give at least 30 days' advance notice of a materially
adverse change. A change required for law, Third-Party Provider terms, or security may take effect sooner, with
prompt notice. If Customer objects to a materially adverse change, its remedy is to stop using and
cancel the affected Service before the change applies. Continued use after the effective date means
acceptance where legally valid; Provider may require renewed clickwrap.

## 16. Governing law and disputes

16.1. Dutch law governs the Agreement without regard to conflict-of-laws rules. The UN Convention on
Contracts for the International Sale of Goods does not apply.

16.2. Before proceedings, each party will give written notice describing the dispute and a requested
remedy, and authorized representatives will attempt in good faith to resolve it for 30 days. This
does not prevent urgent injunctive relief, limitation-period protection, or collection of undisputed
fees.

16.3. The competent courts of The Hague, the Netherlands, have exclusive jurisdiction, except where
applicable law gives a party a non-waivable right to another forum.

## 17. General

17.1. **Notices.** Legal notices must be sent to `legal@withhendrik.com`.
Provider may notify Customer through the Service or the account-owner email. Notices are effective
on confirmed receipt, or one business day after email without a delivery failure.

17.2. **Assignment and business transfer.** Customer may not assign the Agreement without Provider's
written consent. Provider may assign rights or transfer the Agreement in connection with
incorporation, reorganization, financing, merger, or sale of all or substantially all relevant
business or assets, with notice and subject to applicable law. For Article 6:159 of the Dutch Civil
Code, Customer gives its cooperation in advance to transfer of the Agreement, including all rights
and obligations, to a legal entity established by the proprietor to continue the business, provided
the written notice identifies the transferee and the transferee assumes all obligations under the
Agreement and DPA.
The transfer will be recorded in a written deed between Provider and the transferee. Provider will
make a copy or extract evidencing the transfer available to Customer on request, subject to
reasonable redactions.

17.3. **Force majeure.** Neither party is liable for delay or failure beyond its reasonable control,
including internet or Third-Party Provider failures, labor disputes, disasters, war, epidemic, government action,
or utility failure. This does not excuse payment due or reasonable security and recovery duties.

17.4. **Independent parties.** The parties are independent contractors. The Agreement creates no
agency, partnership, fiduciary duty, employment, or third-party beneficiary right.

17.5. **Entire agreement; waiver; severability.** The Agreement is the complete agreement on its
subject. A waiver must be written and is not continuing. If a provision is unenforceable, it will be
limited to the minimum extent necessary and the remainder continues.

17.6. **Electronic contracting.** Electronic acceptance, signatures, and records are valid. Headings
aid reading only. “Including” means “including without limitation.”

17.7. **Publicity.** Neither party may use the other's name, logo, or marks in publicity without
prior written consent. Provider may identify Customer by name and logo on its website or in sales
materials only after Customer has given written consent, which Customer may withdraw on 30 days'
notice. Either party may state that the Agreement exists where required by law or to professional
advisers.

## 18. Contact

- Support: `support@withhendrik.com`
- Billing: `billing@withhendrik.com`
- Security: `security@withhendrik.com`
- Legal notices: `legal@withhendrik.com`
- Postal address: Magnolia Squared, Batavengaarde 4, 2408 TA Alphen aan den Rijn, the Netherlands
