Apex
Back to home

Commercial Terms

Apex API — Commercial Terms of Service

Effective from 1 October 2026

These Commercial Terms of Service (the "Terms") govern access to and use of the Apex large language model service, comprising the API served at api.callstack.ai, the developer console at platform.callstack.ai, the website at apex.callstack.com, and the associated SDKs and related services (together, the "Services"). All of them are operated by a single provider: Callstack.io spółka z ograniczoną odpowiedzialnością, with its registered office at ul. Prosta 36, 53-508 Wrocław, Poland, entered in the Register of Entrepreneurs of the National Court Register kept by the District Court for Wrocław-Fabryczna in Wrocław, VI Commercial Division, under KRS number 0000606530, NIP 8992785616, REGON 363921820 ("Callstack", "we", "us").

These Terms also constitute the terms of service (regulamin świadczenia usług drogą elektroniczną) required by Article 8 of the Polish Act of 18 July 2002 on the provision of services by electronic means. They are available free of charge at https://apex.callstack.com/legal/terms in a form that allows you to download, store and reproduce them.

These Terms apply where you access the Services on behalf of a company, partnership or other organisation, or as a sole trader for purposes directly connected with your professional activity. If you are an individual, the Terms for Individual Users at https://apex.callstack.com/legal/individual-terms apply to you instead.

By clicking "I agree", by executing an Order Form referring to these Terms, or by accessing or using the Services, you ("Customer", "you") accept these Terms and represent that you have authority to bind the entity you represent.


1. Documents forming the agreement

1.1. The agreement between you and Callstack (the "Agreement") comprises these Terms, including:

  • Annex 1 — Acceptable Use Policy
  • Annex 2 — Data Processing Agreement, with its Appendices
  • Annex 3 — Data Retention and Zero Data Retention
  • Annex 4 — Service Operations

together with the Documentation and any Order Form executed by both parties.

1.2. Where these documents conflict, the following order of precedence applies: (1) Order Form; (2) Annex 2; (3) the body of these Terms; (4) Annexes 1, 3 and 4; (5) the Documentation.

1.3. Terms contained in any purchase order, vendor portal or similar document issued by you do not apply and are expressly excluded, even if we do not object to them.

1.4. Sole traders acting outside their professional specialisation. Where you are a natural person conducting business activity and this Agreement is not of a professional character for you, the mandatory provisions of the Consumer Rights Act and the Civil Code that apply to such persons (in particular Articles 7aa and 38a of the Consumer Rights Act and Articles 385⁵, 556⁴ and 556⁵ of the Civil Code) prevail over any conflicting provision of these Terms. This applies in particular to Sections 17.3, 19, 21 and 24.11.

1.5. We may amend the Annexes in accordance with Section 21.


2. Definitions

  • "Apex" means the large language model or family of models developed by Callstack by post-training a base model released by Qwen (Alibaba Group), in each version we make available at apex.callstack.com/models.
  • "Customer Application" means your product, service or internal system that integrates with the Services.
  • "Customer Data" means Inputs and Outputs.
  • "Documentation" means the technical documentation we make available in the developer console at platform.callstack.ai, as updated from time to time.
  • "End User" means any person who accesses the Services through your account or through a Customer Application.
  • "Input" means data you or your End Users submit to the Services, including prompts, files, fine-tuning datasets, system instructions and tool definitions.
  • "Output" means content generated by the Services in response to Input. Output does not include model weights, parameters, or any other component of the Services.
  • "Prepaid Balance" means credits purchased in advance and drawn down by usage.
  • "Usage Limits" means rate limits, token limits, concurrency limits, throughput limits or spend limits applicable to your account, as stated in the console or in an Order Form.

3. Accounts and API keys

3.1. You must provide accurate registration and billing information and keep it current.

3.2. API keys are confidential credentials issued to you. You must store them securely, must not embed them in client-side code, public repositories or distributed applications, and must not sell, lease, share or transfer them to any third party. You are responsible for all activity conducted with your API keys, whether or not authorised by you.

3.3. You must notify us at security@callstack.com without undue delay, and in any event within 24 hours, of any known or suspected compromise of an API key or account.

3.4. We may require identity verification, including verification of beneficial ownership, as a condition of access or of increased Usage Limits.


4. Licence

4.1. Subject to the Agreement and to payment of Fees, we grant you a non-exclusive, non-transferable, non-sublicensable (except to End Users as set out in Section 6), revocable right during the term to access and use the Services, and to integrate them into Customer Applications.

4.2. All rights not expressly granted are reserved. Callstack and its licensors own all right, title and interest in and to the Services, Apex, model weights and parameters, our trade marks, and all intellectual property therein. You acquire no ownership interest in any of them. Apex incorporates a Qwen base model, which Callstack uses under licence from Qwen; rights in the base model remain with Qwen. Apex model weights are not distributed and are available only as part of the hosted Services.

4.3. Authorised distribution. We make the Services available both directly and through third-party platforms, gateways, marketplaces and resellers, which are identified in Annex 4. Nothing in these Terms restricts an authorised distribution partner from making the Services available to its own customers. Where you access the Services through such a partner, the partner's terms govern your relationship with the partner, these Terms govern your use of Apex itself, and Annex 1 applies in full.


5. Restrictions

5.1. You will not, and will not permit any End User or third party to:

(a) use the Services in breach of applicable law, of Annex 1, or of third-party rights;

(b) reverse engineer the Services, or attempt to discover, extract or reconstruct model weights, parameters, architecture, training data or source code, including by model extraction, model inversion, membership inference or similar attacks;

(c) use Outputs to train, fine-tune, distil or otherwise develop any machine learning model, other than: (i) models intended solely to classify, categorise, embed or organise your own data, which are not distributed or made commercially available to third parties; and (ii) fine-tuning of Apex itself through features we expressly provide for that purpose;

(d) systematically extract Outputs at scale for the purpose of building a dataset, other than as expressly permitted by us in writing;

(e) circumvent, disable or interfere with Usage Limits, safety mitigations, content filters, rate limiting, watermarking, provenance metadata, or authentication mechanisms;

(f) resell, sublicense or provide the Services as a standalone model-inference service, model gateway, or router to third parties, unless you have a separate written reseller or distribution agreement with us or are an authorised distribution partner under Section 4.3. Embedding the Services within a Customer Application that provides substantial additional functionality is permitted;

(g) conduct penetration testing, vulnerability scanning, red-teaming or load testing against the Services without our prior written consent, which you may request at security@callstack.com;

(h) submit Input containing special categories of personal data within the meaning of Article 9 GDPR, data relating to criminal convictions, payment card data, or personal data of children below the applicable age of digital consent, unless expressly agreed in an Order Form;

(i) misrepresent Outputs as human-generated where disclosure is required by law, or remove or alter any AI-disclosure, watermark or provenance signal we apply.

5.2. Benchmarking and public evaluation. You may publish performance evaluations, benchmarks and comparisons of the Services provided that you (a) identify the exact model version and the date of testing, (b) describe your methodology in sufficient detail to allow reproduction, and (c) give us seven days' advance notice at press@callstack.com. We may respond publicly, but will not require the withdrawal of accurate results.


6. End Users and Customer Applications

6.1. You are responsible for all acts and omissions of your End Users and for all activity under your account, as if they were your own.

6.2. You must impose on your End Users, by contract, restrictions at least as protective as Sections 5, 7 and 22 and Annex 1, and you must enforce them.

6.3. Where a Customer Application is directed to consumers, you must: (a) disclose that the user is interacting with an AI system; (b) not represent Outputs as human-generated; and (c) implement human review before Outputs are used to make or materially inform decisions with legal or similarly significant effects on individuals, including in employment, education, credit, insurance, housing, healthcare or legal contexts.

6.4. You must maintain and publish a mechanism through which End Users can report misuse or harmful Outputs, and must act on reports without undue delay. We may require you to suspend an End User who breaches Annex 1; if you do not do so promptly, we may suspend that End User's access ourselves.


7. Inputs and Outputs

7.1. As between the parties, and to the maximum extent permitted by law, you retain all rights in Inputs and own all Outputs. We assign to you all right, title and interest we may have in Outputs generated for you.

7.2. You represent and warrant that you hold all rights, licences and permissions necessary to submit Inputs to the Services and to permit the processing described in the Agreement.

7.3. Outputs may be inaccurate. Apex is a probabilistic system. Outputs may be incorrect, incomplete, biased, offensive or otherwise unsuitable, and may state falsehoods with apparent confidence. Outputs are not professional advice. You are solely responsible for evaluating Outputs for accuracy, bias, legality and fitness for your use case before relying on them or making them available to any third party, and for determining where human review is appropriate.

7.4. Outputs are not unique. Other customers may receive identical or similar Outputs from identical or similar Inputs. Outputs generated for other customers are not your Outputs. We make no representation that Outputs are original or that their use will not infringe third-party rights, except as set out in Section 18.

7.5. Open-source material in Outputs. Apex was post-trained on open-source software, described in the Training Data Summary at https://apex.callstack.com/legal/training-data-summary. Outputs may occasionally reproduce or closely resemble code from that software. You are responsible for reviewing Outputs and for complying with any licence obligations, including attribution and notice requirements, that apply to material you incorporate into your products.

7.6. If you disable or reduce any safety filter, content classifier or moderation feature that we make available, you assume full responsibility for the resulting Outputs.


8. Our use of Customer Data

8.1. No training. We do not use Inputs or Outputs to train, fine-tune or otherwise improve Apex or any other machine learning model. The only content that may be used for model improvement is Feedback you choose to send us under Section 8.4.

8.2. Permitted uses. You grant us a worldwide, non-exclusive, royalty-free licence (sublicensable to our sub-processors) to host, copy, transmit and process Customer Data solely to: (a) provide, maintain, secure and troubleshoot the Services; (b) enforce Annex 1 and detect abuse; and (c) comply with legal obligations.

8.3. Zero data retention. All Inputs and Outputs are processed under zero data retention, as set out in Annex 3. We do not store them, and cannot retrieve them after a request completes.

8.4. Feedback. If you send us suggestions, bug reports, evaluations or flagged conversations ("Feedback"), you grant us an unrestricted, perpetual, irrevocable, royalty-free licence to use it for any purpose, including model improvement. Feedback is not your Confidential Information. Do not include in Feedback anything you are not willing to have used in this way.

8.5. Aggregate data. We may generate and use aggregated, de-identified statistical data about use of the Services, such as token volumes, latency distributions and error rates, that does not identify you, your End Users, or the content of Inputs or Outputs.


9. Model versions, changes and deprecation

9.1. We publish stable model version identifiers at apex.callstack.com/models. Requests to a pinned version will be served by that version for as long as it is available.

9.2. Deprecation. We will give at least six months' notice by email and in the Documentation before retiring a generally available model version, and at least 30 days' notice before making a change that materially reduces the functionality of a generally available model version. The current deprecation schedule is in Annex 4. If such a change materially and adversely affects you, you may terminate the affected Services on 30 days' written notice given within 30 days of the notice, and receive a pro-rata refund of prepaid Fees for the unused period.

9.3. Preview and experimental features. Models and features labelled preview or experimental are provided as is, may change or be withdrawn without notice, are excluded from any service level commitment and from Section 17.1, and are used at your own risk. We have no liability arising from them.

9.4. We may adjust safety mitigations, content classifiers and refusal behaviour at any time where necessary for legal compliance, user safety, or system integrity, without prior notice.


10. Usage Limits and availability

10.1. Your use is subject to Usage Limits. We may impose, adjust or enforce Usage Limits to protect capacity, prevent abuse, or manage risk. Where an adjustment materially reduces limits applicable to a paid plan, we will give 30 days' notice unless the change is required urgently for security or stability.

10.2. We may throttle, queue or degrade service during capacity constraints. Where an Order Form includes an availability commitment, the service credits stated in it are your sole and exclusive remedy for a failure to meet it.


11. Fees, billing and payment

11.1. Pricing. Fees are as stated at apex.callstack.com/pricing or in an Order Form. Usage is metered by us; our metering records are the authoritative basis for invoicing, absent manifest error. Usage data is available to you in the console.

11.2. Payment processing. Payments are processed by Stripe Payments Europe, Limited and its affiliates. Callstack is the merchant of record and the seller of the Services; Stripe is not a party to the Agreement. By providing a payment method you authorise us and Stripe to store it and to charge it for amounts due under the Agreement, including recurring and usage-based charges initiated by us without further action by you. Your use of Stripe's services is additionally subject to Stripe's own terms and privacy policy.

11.3. Prepaid Balance. You may purchase a Prepaid Balance, drawn down as you consume the Services. Prepaid Balance: (a) may be used only to pay for the Services; (b) is not transferable and is not redeemable for cash, and confers no interest in or claim on any funds; (c) expires twelve months after purchase; and (d) is non-refundable except as required by law or as expressly stated in the Agreement. Usage is charged against a Prepaid Balance at the rates in force at the time that balance was purchased. Promotional credits expire as stated when granted, are applied before purchased credits, and are not refundable.

11.4. Post-paid billing. Where we grant post-paid terms, we invoice monthly in arrears for usage in the preceding period. Invoices are payable within 14 days of issue. We may charge your stored payment method automatically on the invoice date. Invoices to Polish taxable persons are issued as structured invoices through the National e-Invoicing System (KSeF).

11.5. Automatic top-up. If you enable automatic top-up, you authorise us to charge your payment method the configured amount whenever your Prepaid Balance falls below the configured threshold. You are responsible for configuring spend limits. We are not liable for charges resulting from your configuration, from End User activity, or from a compromised API key, except to the extent caused by our breach.

11.6. Failed payment. If a charge fails, we may retry it, and we may suspend the Services on seven days' notice. Overdue amounts bear statutory interest for late payment in commercial transactions under the Polish Act of 8 March 2013 on counteracting excessive delays in commercial transactions, and we may recover the recovery costs provided for by that Act.

11.7. Disputed invoices. You must notify us at billing@callstack.com within 15 days of the invoice date, stating your reasons, and must pay all undisputed amounts on time. Amounts not disputed within that period are deemed accepted.

11.8. Chargebacks. You must raise billing disputes with us under Section 11.7 before initiating a chargeback or payment reversal. If you initiate a chargeback for amounts properly due, we may suspend your account immediately, and you must reimburse us for the disputed amount together with any chargeback fees, network fees and reasonable administrative costs we incur.

11.9. Taxes. Fees are exclusive of VAT and any other taxes, duties or levies. You are responsible for all such amounts other than taxes on our net income. You must provide a valid VAT identification number where applicable. Where the reverse charge mechanism applies to a supply to a taxable person in another EU Member State, you are responsible for accounting for VAT in your jurisdiction. If you are required by law to withhold any tax, you must increase the payment so that we receive the full invoiced amount.

11.10. Price changes. We may change prices on 30 days' notice. Changes do not affect Prepaid Balance already purchased, or prices fixed in an Order Form for its stated term. We may correct manifest pricing errors, including after invoicing.

11.11. Refunds. Except where required by law or expressly stated in the Agreement, Fees are non-refundable and payment obligations are non-cancellable. Where we terminate for convenience under Section 20.3, or where you terminate under Section 9.2, 16.2 or 21.3, we refund prepaid Fees for the unused period on a pro-rata basis.


12. Free tier and trials

12.1. We may offer free access, trials or evaluation credits. Free-tier use is subject to lower Usage Limits, carries no availability commitment, and may be modified or withdrawn at any time.

12.2. Inputs and Outputs processed through the free tier are not used to train our models.

12.3. Creating multiple accounts to circumvent free-tier limits, Usage Limits or suspensions is prohibited and is grounds for immediate termination.


13. Confidentiality

13.1. "Confidential Information" means non-public information disclosed by one party to the other that is marked confidential or that a reasonable recipient would understand to be confidential. Our Confidential Information includes Apex's weights, parameters and architecture, benchmarks not published by us, non-public Documentation, and security information. Your Confidential Information includes Customer Data, subject to Sections 8.4 and 8.5.

13.2. The recipient will use Confidential Information only to perform the Agreement, will protect it with at least reasonable care, and will disclose it only to personnel, affiliates, advisers and sub-processors who need to know and who are bound by equivalent obligations. The recipient remains responsible for their compliance.

13.3. These obligations do not apply to information that is or becomes public without fault of the recipient, was lawfully known before disclosure, is lawfully received from a third party without restriction, or is independently developed without use of the Confidential Information.

13.4. Disclosure compelled by law or by a competent authority is permitted, provided the recipient gives prior notice where lawful and limits disclosure to what is required.

13.5. These obligations survive for five years after termination, and indefinitely in respect of trade secrets.


14. Data protection

14.1. Each party will comply with Regulation (EU) 2016/679 (GDPR) and other applicable data protection law.

14.2. Where we process personal data contained in Customer Data on your behalf, you act as controller and we act as processor, and Annex 2 applies. Annex 2 is the contract required by Article 28(3) GDPR and incorporates the European Commission's Standard Contractual Clauses for any transfer outside the European Economic Area.

14.3. We act as controller in respect of account, billing, security and support data. Our processing in that capacity is described in the Privacy Policy at https://apex.callstack.com/legal/privacy.

14.4. Our current sub-processors are listed in Appendix 2 to Annex 2. We will give at least 30 days' notice of additions, with a right to object as set out in Annex 2.


15. AI regulatory compliance and allocation of roles

15.1. Our role. Apex is a modification of a general-purpose AI model provided by Qwen within the meaning of Regulation (EU) 2024/1689 (the "AI Act"). On the basis of the compute used for our modification, measured against the indicative criterion in the Commission's Guidelines on the scope of obligations for providers of general-purpose AI models, Callstack is not the provider of a general-purpose AI model in respect of Apex. Callstack is the provider of the Services as an AI system, and complies with the obligations that apply to it in that capacity. We nonetheless publish, voluntarily, a summary of the content we used for post-training at https://apex.callstack.com/legal/training-data-summary, and we maintain a policy for compliance with Union copyright law, a copy of which is available to you on request.

15.2. Documentation. We make available to you, on request, information about our modification of the base model sufficient to enable you to understand Apex's capabilities and limitations and to comply with your own obligations. Information about the base model is published by Qwen. We will notify you of material changes.

15.3. Your role. You are solely responsible for determining the regulatory classification of your Customer Application and for compliance with the obligations that attach to it, including as a provider or deployer of an AI system. In particular you are responsible for:

(a) transparency obligations under Article 50 of the AI Act, including informing natural persons that they are interacting with an AI system and marking synthetic content, where those obligations attach to your Customer Application;

(b) any conformity assessment, risk management, human oversight, logging and registration obligations that apply if your Customer Application is a high-risk AI system;

(c) ensuring AI literacy among your personnel under Article 4 of the AI Act;

(d) not placing your own name or trade mark on Apex, and not substantially modifying it, in a way that would make you its provider under the AI Act, unless you accept the resulting obligations in full.

15.4. Prohibited practices. You must not use the Services for any practice prohibited under Article 5 of the AI Act. These are set out in Part A of Annex 1.

15.5. We will provide reasonable cooperation and information to support your own regulatory obligations and your responses to competent authorities, at your cost where the effort required is more than incidental.


16. Security

16.1. We maintain the technical and organisational measures set out in Part A of Annex 4, and will not materially diminish them during the term.

16.2. If we materially reduce our security measures, you may terminate the affected Services on written notice given within 30 days of being notified, with a pro-rata refund of prepaid Fees.

16.3. We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, in accordance with Annex 2.

16.4. You are responsible for the security of your own systems, credentials and Customer Applications, and for configuring the Services securely.


17. Warranties and disclaimer

17.1. We warrant that, during the term, the Services will perform materially in accordance with the Documentation, and that we will provide them with reasonable care and skill using appropriately qualified personnel.

17.2. Each party warrants that it has the authority to enter into the Agreement.

17.3. Except as expressly stated in Sections 17.1 and 17.2, and to the maximum extent permitted by law, the Services are provided as is and we disclaim all other warranties, express, implied or statutory, including any warranty of merchantability, satisfactory quality, fitness for a particular purpose, accuracy, or non-infringement. We do not warrant that the Services will be uninterrupted or error-free, that Outputs will be accurate, complete, current, unbiased or suitable for any purpose, or that defects will be corrected. Statutory warranty rights under the Polish Civil Code (rękojmia) are excluded to the extent permitted between entrepreneurs. This Section does not apply to a Customer described in Section 1.4.


18. Indemnities

18.1. By Callstack. We will defend you against any third-party claim alleging that the Services, as provided by us and used in accordance with the Agreement, infringe that third party's intellectual property rights, and will indemnify you against damages and costs finally awarded against you or agreed in settlement.

18.2. Exclusions. Section 18.1 does not apply to claims arising from: (a) combination of the Services with anything not supplied by us, where the claim would not have arisen otherwise; (b) modification of the Services or Outputs other than by us; (c) Inputs; (d) Customer Applications; (e) use in breach of the Agreement or of applicable law; (f) continued use after we have notified you to stop; (g) your disabling of safety filters or provenance signals; or (h) Outputs generated from Inputs designed to elicit content resembling protected works.

18.3. Mitigation. If the Services become, or we reasonably believe they may become, the subject of an infringement claim, we may at our option procure the right for you to continue using them, modify or replace them, or, if neither is commercially reasonable, terminate the affected Services with a pro-rata refund of prepaid Fees.

18.4. By Customer. You will defend and indemnify us and our affiliates against third-party claims arising from: (a) Inputs; (b) Customer Applications; (c) use of the Services or Outputs in breach of the Agreement, of Annex 1, or of applicable law; or (d) your breach of Section 6 or Section 15.3.

18.5. Procedure. The indemnified party must notify the indemnifying party promptly, give it sole control of the defence and settlement (subject to no admission of liability or non-monetary obligation without consent, not to be unreasonably withheld), and provide reasonable cooperation at the indemnifying party's expense. This Section states each party's sole remedy for third-party intellectual property claims.


19. Limitation of liability

19.1. Nothing in the Agreement limits or excludes liability for damage caused intentionally (Article 473 § 2 of the Polish Civil Code), for death or personal injury caused by negligence, or for any other liability that cannot lawfully be limited.

19.2. Subject to Section 19.1, neither party is liable for loss of profit, loss of revenue, loss of anticipated savings, loss of business or goodwill, loss or corruption of data, or any indirect or consequential loss, however arising.

19.3. Subject to Sections 19.1 and 19.4, each party's total aggregate liability arising out of or in connection with the Agreement is limited to the total Fees paid or payable by you to us in the twelve months preceding the first event giving rise to the liability, or EUR 5,000 where that period is shorter than three months and no Fees have been paid.

19.4. The cap in Section 19.3 does not apply to: (a) your payment obligations; (b) either party's indemnity obligations under Section 18; (c) your breach of Section 5 or Section 22; or (d) either party's breach of Section 13.

19.5. The parties agree that the allocation of risk in this Section reflects the Fees payable and is a fundamental basis of the bargain.

19.6. This Section does not apply to a Customer described in Section 1.4.


20. Term, suspension and termination

20.1. Term. The Agreement starts when you first accept it or first use the Services, and continues until terminated, or for the term stated in an Order Form.

20.2. Termination by you. Where no Order Form is in effect, you may terminate at any time by closing your account and paying all amounts due. Prepaid Balance is not refunded, except as required by law.

20.3. Termination for convenience by us. We may terminate on 60 days' written notice, refunding unused Prepaid Balance on a pro-rata basis.

20.4. Termination for cause. Either party may terminate immediately on written notice if the other materially breaches the Agreement and fails to cure within 30 days of notice, or where the breach is incapable of cure, or if the other becomes insolvent, enters liquidation, or has a receiver appointed.

20.5. Suspension. We may suspend or limit access to all or part of the Services, with notice where practicable and without notice where not, if: (a) required by law or by a competent authority; (b) you or an End User breach Section 5, Section 22 or Annex 1; (c) there is a credible security threat, fraud risk, or risk of serious harm to us, the Services, or any person; (d) Fees are overdue under Section 11.6; or (e) your usage threatens the stability of the Services. We will tailor any suspension as narrowly as reasonably practicable and restore access promptly once the cause is resolved. You may appeal a suspension under Section 23.

20.6. Effect of termination. All rights granted to you cease immediately. Amounts accrued remain payable. You must delete all Callstack Confidential Information in your control. Because Inputs and Outputs are not retained (Annex 3), no Customer Data remains to be deleted or returned on termination. We will delete Feedback identifying you, and retain request metadata only as set out in Annex 3.

20.7. Survival. Sections 2, 5, 7.3 to 7.6, 8.4, 8.5, 11 in respect of accrued amounts, 13, 17.3, 18, 19, 20.6, 20.7, 22, 23 and 24 survive termination.


21. Changes

21.1. We may amend these Terms and their Annexes where there is a valid reason to do so, including a change in law or regulation, a change in the Services, security requirements, or a change in the commercial terms on which we operate.

21.2. We will give at least 30 days' notice by email and in the console of any change that materially and adversely affects you, except where a shorter period is required for legal compliance or urgent security reasons, in which case we will give as much notice as is reasonably possible. Other changes take effect on posting.

21.3. If a change materially and adversely affects you, you may terminate the Agreement without penalty by notice given before the change takes effect, and receive a pro-rata refund of prepaid Fees for the unused period. Continued use after the effective date constitutes acceptance.

21.4. Changes do not apply retroactively to disputes arising before the change, or to prices fixed in an executed Order Form for its stated term.


22. Trade controls and sanctions

22.1. You must comply with all applicable export control and sanctions laws, including those of the European Union, Poland, the United States and the United Kingdom.

22.2. You represent and warrant that neither you, your affiliates, your controlling persons, nor your End Users: (a) are located in, organised under the laws of, or ordinarily resident in a territory subject to comprehensive European Union or United States sanctions; (b) are designated on any applicable sanctions or restricted-party list, including the EU consolidated sanctions lists, the Polish sanctions list, the OFAC Specially Designated Nationals List, and the BIS Entity List and Denied Persons List; or (c) are owned or controlled by any such person.

22.3. You must not export, re-export or otherwise make the Services or Outputs available in breach of those laws, and must not submit as Input any technical data whose transfer requires a licence you do not hold.

22.4. We may restrict availability of the Services by country. Availability is described in Part B of Annex 4.


23. Complaints and appeals

23.1. You may submit a complaint concerning the Services, including an appeal against suspension or termination, by email to apex@callstack.com or in writing to our registered address. The complaint should state your account identifier, a description of the issue, the date it arose, and the outcome you seek.

23.2. We will respond to a complaint within 14 days of receiving it, on paper or another durable medium.

23.3. Where you are a Customer described in Section 1.4, out-of-court dispute resolution is available through the permanent consumer arbitration courts and mediation conducted by the Trade Inspection (Inspekcja Handlowa), and through the bodies listed in the register maintained by the President of the Office of Competition and Consumer Protection (UOKiK). Callstack does not undertake in advance to participate in out-of-court dispute resolution, and will consider each request on its merits.

23.4. This procedure does not restrict either party's right to pursue any claim before the courts.


24. General

24.1. Notices. Notices to you may be sent to the email address on your account or posted in the console, and are deemed received on sending. Notices to us must be sent to legal@callstack.com with a copy to our registered address marked "Legal".

24.2. Assignment. You may not assign or transfer the Agreement without our prior written consent, not to be unreasonably withheld. We may assign the Agreement to an affiliate, or to a successor to all or substantially all of our business or assets, on notice. We may use sub-processors and subcontractors and remain responsible for their performance.

24.3. Force majeure. Neither party is liable for failure or delay caused by circumstances beyond its reasonable control, excluding payment obligations.

24.4. Publicity. Neither party may use the other's name, logo or marks, or make public statements about the relationship, without prior written consent.

24.5. No partnership. The parties are independent contractors. Nothing in the Agreement creates a partnership, agency, joint venture or employment relationship.

24.6. No third-party rights. The Agreement does not confer rights on any third party.

24.7. Entire agreement. The Agreement is the entire agreement between the parties on its subject matter and supersedes all prior discussions and representations, save in respect of fraud or fraudulent misrepresentation.

24.8. Waiver and severability. Failure to enforce a provision is not a waiver of it. If a provision is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remainder continues in full effect.

24.9. Language. These Terms are made in English. Any translation is provided for information only, and in the event of inconsistency the English version prevails, except where mandatory law provides otherwise.

24.10. Governing law. The Agreement is governed by Polish law, excluding conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.

24.11. Jurisdiction. The courts having jurisdiction over the seat of Callstack in Wrocław, Poland have exclusive jurisdiction over any dispute arising out of or in connection with the Agreement. This Section does not apply to a Customer described in Section 1.4.



ANNEX 1 — Acceptable Use Policy

This Annex applies to you, to your End Users, and to anyone accessing Apex through an authorised distribution partner. Report violations to apex@callstack.com.

Part A — Prohibited in all circumstances

No exception, waiver or contractual variation is available for anything in this Part.

Child safety. Child sexual abuse material; sexualisation of minors; grooming; generating or refining material that facilitates the sexual exploitation of children.

Weapons and mass harm. Developing, acquiring or deploying chemical, biological, radiological or nuclear weapons; developing conventional weapons or means capable of causing mass casualties; providing operational uplift toward any of these.

Cyber harm. Creating malware, ransomware, exploits, credential-stealing tooling or denial-of-service capability; gaining unauthorised access to systems; attacking critical infrastructure.

Sexual and intimate-image harms. Non-consensual intimate imagery; sexual content depicting real identifiable people without their consent; sexual extortion.

Fraud and deception. Fraud, phishing, identity theft, impersonation of real people or organisations, spam at scale, coordinated inauthentic behaviour, academic or financial fraud.

Democratic process. Election interference, voter suppression, fabricated statements attributed to real candidates or officials.

Targeted harm to people. Harassment, stalking, doxxing, threats of violence, incitement to violence or self-harm, promotion of terrorism or violent extremism.

Practices prohibited by Article 5 of the AI Act. Manipulative or exploitative techniques causing significant harm; exploiting vulnerabilities of age, disability or social or economic situation; social scoring; predicting criminal offences from profiling or personality traits alone; untargeted scraping of facial images to build recognition databases; inferring emotions in workplaces or educational institutions; biometric categorisation to infer protected characteristics; real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes.

Integrity of the Services. Circumventing safety measures, filters, rate limits, watermarks or provenance signals; extracting model weights or training data; using Outputs to train a competing model.

Part B — Permitted only with safeguards

These uses are allowed if you implement meaningful human review before an Output is acted on, and disclose AI involvement to affected individuals where the Customer Application is consumer-facing:

  • legal, medical, mental-health, financial, tax or insurance advice
  • decisions affecting employment, education, credit, insurance, housing, benefits or immigration status
  • content moderation at scale
  • law-enforcement and border-management applications
  • safety-critical engineering, industrial or transport contexts

Part C — Requires our prior written approval

Request approval at apex@callstack.com before deploying:

  • applications directed at, or reasonably accessible to, people under 18
  • processing of biometric data
  • fully autonomous agents able to transact, execute code in production, or communicate externally without human review
  • government surveillance applications
  • political advertising or campaign messaging

Part D — Enforcement

We normally escalate: warning, then rate limiting or feature restriction, then suspension, then termination. We may move directly to suspension or termination where the conduct falls under Part A, where there is a risk of serious or irreversible harm, or where the law requires it.

You may appeal any enforcement action under Section 23. We restrict access no more than necessary and restore it once the cause is resolved.



ANNEX 2 — Data Processing Agreement

This Annex is the contract required by Article 28(3) GDPR. It applies where we process personal data contained in Customer Data on your behalf. In this Annex, "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in the GDPR.

1. Roles. You are the controller and we are the processor in respect of personal data contained in Inputs and Outputs. You are responsible for the lawfulness of the processing you instruct, including having a lawful basis and providing required information to data subjects.

2. Subject matter and details. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Appendix 1.

3. Instructions. We process personal data only on your documented instructions, which comprise the Agreement, your configuration of the Services, and the API calls you make, unless required otherwise by Union or Member State law, in which case we will inform you before processing unless that law prohibits it. We will inform you if, in our opinion, an instruction infringes data protection law.

4. Confidentiality. We ensure that persons authorised to process personal data are bound by an appropriate obligation of confidentiality and are trained in their responsibilities.

5. Security. We implement the technical and organisational measures set out in Part A of Annex 4, which are appropriate to the risk within the meaning of Article 32 GDPR. We may update them provided the level of protection is not materially reduced.

6. Sub-processors. You give general written authorisation for us to engage sub-processors. Our current sub-processors are listed in Appendix 2. We will notify you at least 30 days before adding or replacing one. You may object on reasonable data-protection grounds within that period; if we cannot accommodate the objection, you may terminate the affected Services without penalty and receive a pro-rata refund of prepaid Fees. We impose on each sub-processor data protection obligations equivalent to those in this Annex, and remain fully liable for their performance.

7. Data subject rights. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. If a data subject contacts us directly, we will refer them to you and will not respond substantively except to confirm the referral, unless legally required to do otherwise.

8. Assistance. We assist you in ensuring compliance with Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to us. Assistance that requires more than incidental effort is at your cost.

9. Personal data breach. We notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data processed on your behalf, and provide the information reasonably available to us to enable you to meet your own notification obligations.

10. Deletion and return. Personal data contained in Inputs and Outputs is not retained beyond the processing of each request (Annex 3), so there is none to return on termination. Any other personal data processed on your behalf is deleted on termination, except where Union or Member State law requires continued storage.

11. Audit. We make available to you the information necessary to demonstrate compliance with Article 28 GDPR, including any current third-party audit reports and security documentation we hold. Where that is insufficient, you may conduct an audit, or mandate an independent auditor who is not our competitor, on 30 days' written notice, no more than once in any twelve-month period except following a personal data breach, during business hours, subject to confidentiality, without unreasonable disruption, and at your cost.

12. International transfers. We process personal data within the European Economic Area. Where a transfer to a third country occurs, it takes place under Commission Implementing Decision (EU) 2021/914 (the Standard Contractual Clauses), which are incorporated into this Annex by reference, with Module Two (controller to processor) applying between you and us, or Module Three (processor to processor) where you are yourself a processor. For the purposes of those Clauses: the optional docking clause applies; the option for general written authorisation of sub-processors applies with a 30-day notice period; the governing law is Polish law; the forum is the courts of Poland; and Appendices 1 and 2 to this Annex populate their Annexes I and II. Where the UK GDPR applies, the UK International Data Transfer Addendum applies in addition.

13. Precedence. In the event of conflict between this Annex and the rest of the Agreement, this Annex prevails in respect of the processing of personal data.

Appendix 1 — Details of processing

Subject matter Provision of the Apex API and related services
Duration The term of the Agreement. Personal data in Inputs and Outputs is held in memory only for the duration of each request
Nature and purpose Receiving, transmitting and processing Inputs in memory to generate Outputs, and automated safety checks carried out during that processing, under zero data retention
Types of personal data Any personal data the Customer chooses to include in Inputs, and any personal data appearing in the resulting Outputs. Special categories of personal data, data relating to criminal convictions, and payment card data must not be submitted (Section 5.1(h))
Categories of data subjects Determined by the Customer. Typically the Customer's End Users, personnel, customers and contacts
Frequency Continuous, for the duration of the Agreement

Appendix 2 — Sub-processors

Sub-processor Function Processing location Data accessible
Modal Labs, Inc. GPU inference hosting EU Prompts and outputs, transiently in memory
Google Cloud Poland Sp. z o.o. Cloud infrastructure: API gateway, load balancing EU Prompts and outputs in transit; request metadata

We notify additions or replacements at least 30 days in advance, in accordance with paragraph 6.



ANNEX 3 — Data Retention and Zero Data Retention

1. Zero data retention for all traffic. Every request to the Services is processed under zero data retention, for every customer, every plan and every route of access, including traffic reaching us through an authorised distribution partner identified in Annex 4. Zero data retention cannot be switched off.

2. What it means. Inputs and Outputs are held in memory only for as long as necessary to process the request and return the response, and are then discarded. They are not written to persistent storage, logs, analytics systems, error-reporting tools or backups, by us or by any sub-processor. They are not used to train any model.

3. Safety checks. Automated checks for breaches of Annex 1 run on Inputs and Outputs in memory while the request is being processed. They do not store content. Where a check identifies a likely breach, we may record the fact and category of the finding against the account, without the content itself.

4. Metadata. We retain only the non-content metadata needed for billing, rate limiting, security and troubleshooting: timestamps, token counts, model identifiers, API key identifiers, source IP addresses, response status codes, latency, and safety-check findings recorded under paragraph 3. Metadata relevant to billing is kept for the period required by Polish tax and accounting law; other metadata for up to twelve months.

5. Account and billing data. Account, billing and support records are retained for the period required by Polish accounting and tax law, and thereafter for as long as necessary for the establishment, exercise or defence of legal claims.

6. Feedback. Content you choose to send us as Feedback under Section 8.4 is not API traffic and is not covered by zero data retention. We keep it for up to 24 months.

7. Features. Features that require content to be stored between requests — such as batch processing, fine-tuning and server-side conversation state — are not offered. Transient caching of computation within the processing of a request, held only in memory and never persisted, is not storage for the purposes of this Annex.

8. Consequences. Because we hold no content, we cannot reproduce past requests for you, cannot recover content you did not keep, and cannot provide content in response to requests from any third party, including public authorities. Our ability to investigate abuse is limited to metadata and to safety-check findings. Responsibility for content-level monitoring and record-keeping for Customer Applications rests with you.



ANNEX 4 — Service Operations

Part A — Technical and organisational security measures

Encryption. Data in transit is encrypted with TLS 1.2 or later. Data at rest is encrypted using AES-256 or an equivalent standard.

Access control. Access to production systems follows least privilege, requires multi-factor authentication, is granted on a named-individual basis, is reviewed at least quarterly, and is revoked on role change or departure. Administrative actions on production systems are logged.

Network and infrastructure. Production environments are segregated from development and test environments. Systems are patched on a risk-prioritised schedule. Vulnerability scanning is performed on a continuous basis.

Tenant separation. Customer accounts are logically separated. API keys are scoped to a single account and are stored only as salted hashes.

Personnel. Personnel with access to Customer Data are subject to written confidentiality obligations and receive security and data protection training on joining and periodically thereafter.

Resilience. Systems are designed for redundancy across availability zones. Backups are encrypted and restoration is tested periodically.

Incident response. We maintain a documented incident response procedure covering detection, containment, eradication, recovery and notification, and review it after any significant incident.

Secure development. Changes to production are peer-reviewed, version-controlled and deployed through an automated pipeline. Dependencies are monitored for known vulnerabilities.

Vendor management. Sub-processors are assessed before engagement and are bound by written data protection and security obligations.

Reporting a vulnerability. Report suspected vulnerabilities to security@callstack.com. We will acknowledge within five business days. Do not conduct testing against production without our prior written consent under Section 5.1(g).

Part B — Availability and processing locations

Apex is served from infrastructure located in the European Economic Area. Inference takes place within the European Economic Area. Inputs and Outputs are not stored anywhere.

The Services are not available in any territory subject to comprehensive European Union or United States sanctions. We may restrict availability in other jurisdictions where legal or regulatory requirements make provision impracticable, and will state any such restriction in the console at signup.

Part C — Model deprecation schedule

Model version Status Deprecation notice given Retirement date

No generally available model version is currently scheduled for retirement. We give at least six months' notice under Section 9.2, and update this Part when notice is given.

Part D — Authorised distribution partners

The following third-party platforms are authorised to make Apex available to their own customers under Section 4.3:

Partner Service
Vercel Inc. Vercel AI Gateway

Access obtained through a partner is subject to that partner's own terms as between the customer and the partner. Annex 1 applies in full to all such use.