Skip to content

Legal

Terms of Service

Contract terms for nox.markets: accounts, plans, licenses, credits, customer content, acceptable use, liability, and how the relationship ends.

Last updated: 16 September 2026 Governing law and venue: State of Wyoming, USA; courts located in Wyoming (Section 14) Contracting entity: NOX AETERNA GROUP LLC, a Wyoming limited liability company, trading as nox.markets, 5830 E 2nd St, Ste 7000 #34506, Casper, WY 82609, USA Notices:

These Terms of Service (the Terms) govern access to and use of the nox.markets website, catalog, hosted application, APIs, documentation, and related services (together, the Service). nox.markets is a B2B marketplace of first-party tools, agents, workflows, and packs. English is the language of the Service. Fees are denominated in United States dollars (USD).

By creating an account, starting a trial, clicking to accept, or using the Service, the organization you represent (the Customer) agrees to these Terms. If you do not have authority to bind that organization, do not accept.

An executed master services agreement, order form, or data processing addendum (DPA) with NOX AETERNA GROUP LLC controls over these Terms where they conflict, except that the DPA controls over these Terms on data protection. Product pages, /security, /trust, /legal/subprocessors, /legal/sla, and /legal/acceptable-use-policy describe operational facts and commitments; they do not replace these Terms unless expressly incorporated.


1. The Service

1.1 What we sell. Customer may browse, trial, subscribe to, and license catalog products that run as hosted (on nox.markets), connected (on nox.markets, acting in Customer systems via scoped OAuth or similar grants Customer can revoke), or self-hosted (Customer runs the software; we license it). Catalog contents, setup_minutes, published evals, and named failure modes are product facts, not warranties of a particular business result.

1.2 First-party catalog. At launch, listings are built, evaluated, integrated, supported, and priced by nox.markets. “Marketplace” describes the buying experience (browse, compare, buy, deploy). These Terms do not create a multi-seller marketplace or any agency for third-party vendors.

1.3 What we are not. We are not Customer’s bookkeeper, lawyer, tax filer, payroll processor of record, or decision-maker of record. Model output and product output may be wrong. For finance-backoffice agents and workflows, human approval exists and is the default; Customer remains responsible for what is posted to Customer’s general ledger, CRM, mailbox, payroll, or bank after (or without) that approval.

1.4 Systems of record. Customer’s GL, CRM, HRIS, mailbox, and bank remain authoritative. nox.markets does not keep a second AR/AP subledger. Work already written to Customer’s systems of record is not unwound on pause, revoke, or termination.

1.5 Eligibility. The Service is for business customers, not consumers. Accounts require a work email. The Service is not directed at children under 16.


2. Accounts, workspaces, and users

2.1 Workspace owner. The individual who creates the workspace, or a successor they appoint, is the owner. The owner is responsible for billing, ownership transfer, and deletion of the workspace.

2.2 Users and roles. Plans include unlimited seats. Access is controlled by role, not seat count. On Growth, roles are owner, admin, and member as described on /security. Scale and Enterprise may add custom roles. Customer must keep credentials confidential, force SSO where Customer’s policy requires it, and promptly deprovision users who leave.

2.3 Authority. Actions taken by any user in the workspace bind Customer. Customer is responsible for configuring approval, retention, spend ceilings, integrations, and who may connect or revoke OAuth grants.

2.4 Age and capacity. Users must be legally able to transact for Customer. We may refuse or close accounts that are not bona fide business use.


3. Plans, trials, licenses, and credits

3.1 Tiers. Public tiers are starter, growth, scale, and enterprise, as published on /pricing. Feature entitlements (SSO, SCIM, audit retention, SLA) follow that grid and spec 15 as implemented. Pricing on /pricing is the commercial source of truth for list prices; these Terms describe how those products are licensed.

3.2 Trial. The public trial is fourteen (14) days of Growth, with 25,000 credits, and no payment card required. It converts to a paid Growth plan if Customer adds billing, or it ends. There is no permanent free agent tier and no downgrade to a free unattended-work plan.

3.3 Monthly and annual. Monthly subscriptions are month-to-month. Annual subscriptions are billed upfront and are presented as two months free relative to monthly list, with a twenty-four (24) month price lock on the subscription and the dollar-per-credit rate, as stated on /pricing. Quarterly prepay terms, if offered, follow /pricing.

3.4 Credits. Work consumes credits. Each product publishes a fixed credits_per_run (with USD equivalent at Customer’s tier) and a per-run hard ceiling. Above the ceiling the run stops and re-quotes; it does not keep charging. Included monthly grants, rollover (up to 2× grant on Starter, Growth, and Scale; full term on Enterprise), grace band (first 10% over grant each month is free), overage rates, and purchase credits follow /pricing.

3.5 Spend controls. A hard spend ceiling at grant plus 50% is on by default. Nothing runs past it unless an admin raises it. Any account exceeding 3× its monthly grant in a month may be rate-limited pending a human conversation (the circuit breaker). Alerts at 50% / 80% / 100% of grant are operational, not a substitute for the ceiling.

3.6 One-time licenses. A one-time purchase is a perpetual, single-workspace license to that product slug’s logic, UI, and connectors. Runs still spend credits. Customer owns the license, not the inference. Credit-back: 40% of the one-time price returns as non-expiring purchase credits, valued at Customer’s tier effective rate, as stated on /pricing. Members (active subscribers) buy out-of-tier one-time products at 25% off list. If a product is included in Customer’s tier, it is not sold again as a duplicate license.

3.7 What survives churn. Purchased one-time licenses and purchase credits survive cancellation and downgrade. Tier inclusions do not. One hundred percent of one-time spend in the trailing twelve (12) months credits against Customer’s first annual plan invoice, up to that invoice, as stated on /pricing.

3.8 Maintenance on one-time connected products. A one-time license includes twelve (12) months of updates and connector maintenance. After that, connected products require the published annual maintenance fee to keep OAuth connectors current; if Customer declines, the license continues on last-shipped connectors.

3.9 Self-hosted. self-hosted products are licensed per product per year (list: USD 18,000 per product per year unless an order form states otherwise), consume zero credits, and run in Customer’s environment. Customer data for those deployments does not enter nox.markets production except license telemetry (license check, version, heartbeat). Source-escrow, if any, is an Enterprise commercial term in the MSA or order form, not a self-serve click-wrap promise.

3.10 Enterprise extras. Dedicated VPC, custom DPA, zero-retention, model-version pinning, and related options are sold only as stated on an order form. HIPAA / a BAA is not offered until the dated roadmap on /trust (target 2027-06-30). Until then, ePHI is forbidden (see Acceptable Use).

3.11 Taxes and payment processing. Fees are exclusive of taxes. NOX AETERNA GROUP LLC is the seller and merchant of record; Stripe, Inc. processes self-serve card payments once checkout takes payment. We do not store payment card PAN or CVV; we store Stripe customer and subscription identifiers and last-four for display.

3.12 Refunds. Availability service credits are governed by /legal/sla and are the sole remedy for availability. Pro-rata refund of unused prepaid platform fees on a DPA-based subprocessor objection is governed by the DPA. Other refunds:


4. Customer content and licenses

4.1 Customer Content means account data, workspace configuration, connector secrets, run payloads, run metadata, audit events, support materials Customer submits, and any data Customer causes the Service to pull from connected systems.

4.2 Ownership. As between the parties, Customer retains all rights in Customer Content. We do not claim ownership of Customer’s invoices, bills, mailboxes, or books.

4.3 License to operate. Customer grants NOX AETERNA GROUP LLC a limited license to host, copy, process, transmit, display, and delete Customer Content solely to provide, secure, and support the Service, including routing prompts and retrieved context to named model subprocessors where a product requires a model call, as described on /security and /legal/subprocessors.

4.4 No training. Customer Content is not used to train nox.markets models or, by contract, provider foundation models we route to. We do not use Customer runs to improve other customers’ products. Aggregated, non-content metrics (run counts, latency, credit burn, eval scores on our fixtures) may be used to operate the Service. A clause that would permit training on Customer Content is rejected.

4.5 Confidentiality. We will treat Customer Content as Customer’s confidential information and will not disclose it except to personnel and subprocessors bound to confidentiality who need it to perform, to professional advisers under duty, or as required by law. Break-glass access to run_payload by our staff is ticketed, time-boxed (≤ 4 hours), MFA-gated, and logged, with no standing production access.

4.6 Customer warranties. Customer warrants that it has the right to submit Customer Content and to grant the integrations it connects; that Customer Content does not violate the Acceptable Use Policy; and that Customer will not submit ePHI, children’s data under 16, or other forbidden classes except as expressly permitted in a signed BAA (not offered until the /trust date).


5. Data processing, security, and subprocessors

5.1 Roles. For website visitors, marketing form submits, our employee data, and billing identity, we act as a controller (or equivalent under applicable US state law). For workspace content (run_payload, configs, tokens, audit events, and related personal data in the workspace), we act as a processor (or service provider / contractor under CCPA/CPRA) under the DPA.

5.2 DPA. The DPA at /legal/data-processing-addendum is incorporated for Growth and above when accepted (click-wrap or signed). Starter customers may request the DPA. Custom DPA paper is an Enterprise conversation. On data protection, the DPA prevails.

5.3 Security standard. We will maintain commercially reasonable technical and organizational measures as described on /security (encryption in transit and at rest, access control, logging, tenancy isolation). Those measures are not described as bank-grade. SOC 2 Type I, SOC 2 Type II, ISO/IEC 27001, and HIPAA/BAA are Planned as dated on /trust as of 15 September 2026; they are not held. A pricing cell or sales deck is not evidence of a report.

5.4 Subprocessors. Customer authorizes the subprocessors listed at /legal/subprocessors, including model providers. New subprocessors that process Customer personal data are notified 30 days in advance, with a 15-day written objection window for DPA customers, as in the DPA. Customer SaaS tools Customer connects (for example QuickBooks Online, HubSpot, Gmail) are Customer’s processors, not ours.

5.5 Model routing. Below Scale, nox.markets selects the model. The subprocessor list still names the legal entities that may process prompts. Scale and Enterprise may use BYOK under the conditions on /security. If a provider or version cannot hold the product’s published eval, we pause new runs for that slug rather than silently degrade.

5.6 Output disclaimer. Model and product output may contain errors. Published evals and named failure modes are the accuracy contract for the product, not a guarantee that a given run is correct. Customer is responsible for review, approval, and use of outputs, including postings to Customer’s systems of record.


6. Acceptable use and suspension

6.1 Customer and its users must comply with the Acceptable Use Policy at /legal/acceptable-use-policy.

6.2 We may suspend the Service, a product, or an integration immediately if: (a) AUP is breached; (b) fees are unpaid after notice; (c) use threatens the security, tenancy isolation, or availability of the Service or another customer; (d) a P1 compromise is ongoing; or (e) law requires it. We will restore access when the cause is cured, unless we terminate under Section 9.


7. Third-party systems and model providers

7.1 Connected systems are contracted between Customer and those vendors. Their uptime, at-rest encryption, and terms are theirs. OAuth grants are Customer’s to revoke in the IdP or in /dashboard/integrations. We delete connector_secrets within 24 hours of revoke or disconnect.

7.2 Model-subprocessor outages are passed through on /status. Availability credits apply only if our control plane or application was down, as defined in /legal/sla. We do not credit Customer for a provider outage we did not cause, except to the extent we were also down.

7.3 Self-hosted uptime is Customer’s.


8. Intellectual property

8.1 We and our licensors own the Service, catalog software, documentation, eval harnesses, and our trademarks, including nox.markets. Customer receives only the licenses expressly granted.

8.2 Feedback may be used without restriction or attribution, provided we do not identify Customer without consent.

8.3 Enterprise IP indemnity, if any, is only as stated on an order form.


9. Term, export, and deletion

9.1 These Terms continue until the workspace is closed or the paid term ends and is not renewed.

9.2 Customer may cancel a monthly plan at period end; there is no monthly lock. Annual cancellation and true-up:

9.3 Pause and revoke. Customer may pause a product in the dashboard. Revoking an OAuth grant stops connected products that needed it. Pause does not delete data except as Customer separately deletes runs.

9.4 Export. For 30 days after account closure (or as the DPA states on termination of processing), Customer may export configuration and run history in JSON/CSV, plus original files where we still have them.

9.5 Deletion. Primary deletion of workspace data occurs within 30 days of termination of the Service for that workspace. Encrypted backups age out on a 35-day rolling clock and are not scrubbed on demand; they expire by day 65 after closure (30 + 35), except legal hold, tax invoices (7 years), and other records we must keep by law. Run-level deletion from the UI is queued immediately and applied to primary storage within 24 hours; backups still follow the 35-day clock. Enterprise legal hold may pause deletion for named objects.

9.6 Connected write-back. Data already in Customer’s systems of record remains there. We revoke our grants; we do not attempt to delete Customer’s QuickBooks bills or HubSpot records.


10. Warranties and disclaimers

10.1 Each party represents it has authority to enter these Terms.

10.2 Disclaimer. EXCEPT FOR COMMITMENTS EXPRESSLY STATED IN THESE TERMS, AN ORDER FORM, THE DPA, OR /legal/sla, THE SERVICE IS PROVIDED “AS IS.” WE DISCLAIM IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, TO THE EXTENT PERMITTED BY WYOMING LAW. We do not warrant that output is error-free, that a product will save a stated number of hours in Customer’s environment, or that we hold any certification listed as Planned on /trust.

10.3 Catalog time_saved_per_month figures are volume-based formulas on the product card, not measured customer results.


11. Indemnity

11.1 Customer. Customer will defend and indemnify NOX AETERNA GROUP LLC against third-party claims arising from Customer Content, Customer’s use of outputs, Customer’s connected systems, or Customer’s breach of the AUP or Section 4.6, except to the extent caused by our willful misconduct.

11.2 Us. Our indemnity obligations, if any beyond Section 8.3, are


12. Limitation of liability

12.1 Excluded damages. To the extent permitted by Wyoming law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or lost profits, revenue, or data, even if advised of the possibility.

12.2 Cap. Except for (a) Customer’s payment obligations, (b) Customer’s indemnity, (c) breach of the AUP or confidentiality by Customer, and (d)

, each party’s aggregate liability under these Terms in any twelve (12) month period is limited to the amounts Customer paid for the Service in that period (excluding one-time licenses already delivered, except as counsel reallocates).

12.3 SLA. Service credits under /legal/sla are the sole remedy for availability. Starter and Growth have no availability SLA.

12.4 Nothing in these Terms excludes liability that cannot be excluded under Wyoming law (including fraud).


13. Changes

13.1 We may update these Terms. Material changes will be emailed to the workspace owner at least 30 days in advance where required. Continued use after the effective date constitutes acceptance, except where Wyoming law requires a different mechanism.

13.2 Product behavior changes that would silently degrade a published eval are handled as production incidents for that slug, with a changelog entry, not as a Terms change.


14. Miscellaneous

14.1 Governing law. These Terms are governed by the laws of the State of Wyoming, USA, excluding conflict-of-law rules. Exclusive venue: the state and federal courts located in Wyoming, except that we may seek injunctive relief in any court of competent jurisdiction.

14.2 Export and sanctions. Customer will not use the Service in violation of applicable export control or sanctions laws.

14.3 Assignment. Customer may not assign these Terms without our consent, except to a successor in connection with a merger or sale of substantially all assets, provided the successor is not a competitor and assumes these Terms. We may assign to an affiliate or in connection with a corporate transaction.

14.4 Force majeure. Neither party is liable for delay caused by events beyond reasonable control, excluding payment obligations.

14.5 Entire agreement. These Terms, the AUP, Privacy Policy, Cookie Policy, DPA (when in force), SLA (when applicable), order forms, and policies linked here are the entire agreement for the Service, superseding prior discussions. Order of precedence: (1) order form / MSA, (2) DPA on data protection, (3) SLA on availability credits, (4) these Terms, (5) other legal pages.

14.6 Severability; waiver; no third-party beneficiaries. If a provision is unenforceable, the rest remains. Waiver must be in writing. No third-party beneficiaries, except as the DPA provides for data subjects as required by law.

14.7 Government. If Customer is a government entity, additional terms:

14.8 Contact. Questions: /contact (Sales, Support, or Security). Security reports: security@nox.markets and /legal/security-disclosure.


15. Definitions (selected)

agent / workflow / tool / pack, hosted / connected / self-hosted, and starter / growth / scale / enterprise have the meanings in the nox.markets taxonomy and on product pages. P1 means production down or suspected customer-data exposure, as used on /security and /legal/sla.