MCP & API Subscription Service Terms
SERVICE-SPECIFIC TERMS
Version [2.2] — Publication date: 01/02/2026
These Service-Specific Terms (the “API and MCP Terms”) supplement and form an integral part of the Master Services Agreement (MSA) entered into between the SERVICE PROVIDER and the SERVICE RECIPIENT. They govern access to, use of and subscription to the Application Programming Interfaces (APIs) and to the components, servers or connectors based on the Model Context Protocol (MCP) contracted through the corresponding Service Order. Capitalized terms not defined here have the meaning given to them in the MSA.
1. SCOPE AND LICENSE
1.1. Subscription license. Subject to compliance with the Contract, the SERVICE PROVIDER grants the SERVICE RECIPIENT, for the term of the Service Order, a limited, non-exclusive and non-transferable license to access and consume the specified APIs and MCP connectors. The license may be suspended or revoked only in the cases provided for in the Contract.
1.2. MCP components. MCP-based services enable the interconnection and exchange of context between Artificial Intelligence models and the SERVICE RECIPIENT’s repositories, databases or tools. The SERVICE PROVIDER supplies the technical integration architecture (MCP servers or clients) but assumes no liability for the autonomous behavior of third-party models that consume such context, except as provided in clause 4.2.
1.3. Deployment modes. The Service Order will state whether the components are (a) hosted by the SERVICE PROVIDER; (b) self-hosted on the SERVICE RECIPIENT’s infrastructure; or (c) hybrid. For self-hosted components, the SERVICE RECIPIENT is responsible for their infrastructure, availability and security, and the availability levels in clause 6 apply only to components hosted by the SERVICE PROVIDER.
1.4. Authorized users. The Services may be used by the employees and contractors of the SERVICE RECIPIENT and of the Affiliates named in the Service Order. Integrating the Services into products or services that the SERVICE RECIPIENT offers to third parties requires express authorization in the Service Order.
1.5. Documentation. The technical documentation published at [URL] forms part of the Contract with respect to specifications, limits and integration requirements.
2. ACCEPTABLE USE AND CONSUMPTION LIMITS
2.1. Usage limits. Use of the APIs and MCP components is subject to the volume limits, call quotas, concurrency and bandwidth set out in the Service Order or in the technical documentation.
2.2. Overages. When the SERVICE RECIPIENT exceeds the limits, the SERVICE PROVIDER may, as stated in the Service Order, (a) temporarily throttle or reject requests that exceed the limits; or (b) invoice the excess in accordance with clause 5.11 of the MSA.
2.3. Restrictions. In addition to the restrictions in clause 7.3 of the MSA, the SERVICE RECIPIENT undertakes not to: (a) reverse engineer, decompile or attempt to extract the source code of the SERVICE PROVIDER’s APIs or MCP architectures; (b) use the Services in a way that degrades, overloads or interferes with the stability of the SERVICE PROVIDER’s servers; (c) circumvent the authentication mechanisms or the assigned tokens; (d) publish performance benchmarks without prior authorization; (e) transmit malicious code or unlawful content; (f) use the Services in breach of the usage policies of Artificial Intelligence model providers; or (g) use the Services to make automated decisions that produce legal or similarly significant effects on natural persons without human review.
2.4. Suspension. Breach of this clause entitles the SERVICE PROVIDER to suspend the Services in accordance with clause 6.2 of the MSA.
3. SECURITY, TOKENS AND CREDENTIALS
3.1. Custody. The SERVICE PROVIDER will supply API keys, tokens or credentials to authenticate the components. The SERVICE RECIPIENT is solely responsible for keeping them confidential within its systems, environment variables and development workflows.
3.2. Individual credentials. Credentials will be assigned per User or application, may not be shared and must be rotated in accordance with the technical documentation.
3.3. Preventive revocation. The SERVICE PROVIDER may immediately revoke or suspend any credential if it detects anomalous traffic patterns or suspects a leak, in order to protect its infrastructure and the SERVICE RECIPIENT’s data. It will inform the SERVICE RECIPIENT as soon as possible and issue new credentials once the risk has been addressed.
3.4. Compromised credentials. The SERVICE RECIPIENT will immediately report any suspected compromise of its credentials. Charges arising from the use of compromised credentials before such notice will be borne by the SERVICE RECIPIENT.
4. ARTIFICIAL INTELLIGENCE COMPONENTS
4.1. Third-party models. The Service Order will identify the Artificial Intelligence model providers to which the Services connect and who supplies the credentials. When the SERVICE RECIPIENT supplies its own credentials, it will contract directly with the model provider, bear its costs and terms, and the data sent to the model will flow under that direct relationship. When access to the model is provided by the SERVICE PROVIDER, its costs will be invoiced as Third-Party Charges and the SERVICE PROVIDER will disclose the provider used and its data processing policies.
4.2. Agent permissions and actions. MCP connectors will be configured with the minimum permissions necessary and, by default, in [read-only] mode. Write, delete or execute capabilities will be enabled only upon a written request from the SERVICE RECIPIENT specifying their scope. The SERVICE RECIPIENT is responsible for approving such capabilities and for requiring human confirmation of sensitive actions. The SERVICE PROVIDER will not be liable for actions carried out by models or agents within the permissions enabled by the SERVICE RECIPIENT, unless caused by a defect in the SERVICE PROVIDER’s components.
4.3. Malicious instructions. The SERVICE RECIPIENT acknowledges that models may be manipulated through instructions injected into the content of data sources. The SERVICE PROVIDER will apply reasonable mitigation measures in its components, without guaranteeing that such risk is entirely prevented. The SERVICE RECIPIENT will limit data sources and permissions to what is strictly necessary.
4.4. Outputs. Outputs generated by models may be inaccurate or incomplete and are not guaranteed. The SERVICE RECIPIENT will subject them to human review before using them in decisions, in production deployments or in communications with third parties, in accordance with clause 11.4 of the MSA.
4.5. Compliance. The SERVICE RECIPIENT is responsible for ensuring that its use of the Services and the sending of data to models comply with applicable regulation, including obtaining the authorizations of the Data Subjects of Personal Data.
5. INTELLECTUAL PROPERTY AND DATA
5.1. Components. The APIs, endpoints, technical documentation, MCP server architecture, connectors and base code used to provide the subscription are Provider Tools owned exclusively by the SERVICE PROVIDER. The perpetual license in clause 9.4 of the MSA does not apply to them.
5.2. Context and data. The data, schemas and fragments of information that pass through the MCP connectors or are sent to the APIs are Recipient Data owned exclusively by the SERVICE RECIPIENT. The SERVICE PROVIDER will not use them to train models or for purposes unrelated to the technical performance of the subscription, and will handle them in accordance with clause 10 of the MSA and, where applicable, the DPA.
5.3. Technical logs. The SERVICE PROVIDER will retain technical logs (request metadata, errors and consumption) for [thirty (30)] calendar days for operations, security, billing and support purposes, after which it will delete or anonymize them, except for billing records it must keep by law. The content of the context and of the requests will not be stored beyond what is necessary for their processing, unless the Service Order provides for temporary storage functions.
6. AVAILABILITY AND SERVICE LEVELS
6.1. Commitment. The SERVICE PROVIDER commits to a monthly availability of [ninety-nine point five percent (99.5%)] for the production endpoints it hosts.
6.2. Calculation. Availability is calculated as the percentage of minutes in the calendar month during which the endpoint was available, excluding the events in clause 6.3. An endpoint is considered unavailable when it returns server errors or fails to respond for more than [five (5)] consecutive minutes, according to the SERVICE PROVIDER’s monitoring.
6.3. Exclusions. The following do not count as unavailability: (a) scheduled maintenance notified at least [seventy-two (72)] hours in advance, up to [eight (8)] hours per month; (b) emergency maintenance required for security reasons; (c) failures of Third-Party Platforms, including Artificial Intelligence model providers; (d) failures of the SERVICE RECIPIENT’s networks or systems; (e) throttling due to overages or suspension under the Contract; (f) force majeure; and (g) beta features.
6.4. Service credits. If monthly availability falls below the commitment, the SERVICE RECIPIENT will be entitled to the following credits on the monthly fee of the affected Service:
| Monthly availability | Credit |
|---|---|
| Below [99.5%] and at or above [99.0%] | [5%] |
| Below [99.0%] and at or above [97.0%] | [10%] |
| Below [97.0%] | [25%] |
Credits must be requested within thirty (30) calendar days after the end of the month and will be applied to the next invoice; they are not payable in cash except upon termination of the Contract. Credits are the exclusive remedy in accordance with clause 12.6 of the MSA.
6.5. Repeated failure. If availability is below [97.0%] for [three (3)] consecutive months or [four (4)] months within any twelve (12) month period, the SERVICE RECIPIENT may terminate the affected Service without penalty, with a pro rata refund of amounts prepaid and unused.
7. SUPPORT
Support will be provided through [email / support portal] during business hours of [Monday to Friday, 8:00 to 18:00, Colombia time]. Incidents affecting the availability of production endpoints will be handled with a response time of [one (1) hour] on a [24x7] basis; other requests, within [one (1) business day].
8. VERSIONS, CHANGES AND DEPRECATION
8.1. Versioning. APIs are identified by versions. The SERVICE PROVIDER will maintain support for the current major version and for at least [one (1)] previous major version.
8.2. Compatible changes. The SERVICE PROVIDER may introduce backward-compatible changes, such as new endpoints or optional fields, without prior notice.
8.3. Breaking changes and deprecation. Breaking changes will be notified in accordance with clause 15.3 of the MSA and the deprecation of versions in accordance with its clause 15.4, except when they are required for security reasons or imposed by a third party, in which case they will be notified as far in advance as possible.
9. BETA FEATURES
Features identified as beta, preview or experimental are offered as is, without service levels, may be modified or discontinued at any time and must not be used in production environments unless the SERVICE RECIPIENT expressly assumes that risk.
10. THIRD-PARTY COMPONENTS
Third-party and open-source components included in the Services are governed by their respective licenses, in accordance with clause 9.7 of the MSA.
11. EFFECTS OF TERMINATION
Upon termination of the subscription: (a) the SERVICE PROVIDER will revoke the credentials and end access to the Services; (b) technical logs will be deleted in accordance with clause 5.3 and Recipient Data in accordance with the DPA and clause 10.7 of the MSA; and (c) in the self-hosted mode, the SERVICE RECIPIENT will uninstall the SERVICE PROVIDER’s components from its environments within [fifteen (15)] calendar days and, upon request, certify so in writing.