Alpha and pilot terms.
Draft — requires legal review before publication. These terms are a working draft. Counsel has not reviewed them, bracketed sections are incomplete, and nothing here is an offer to contract.
The terms for using the Blokk research alpha and taking part in a design-partner pilot.
1. About these terms
These terms apply to access to the Blokk research alpha, including design-partner pilots, and are provided by Work Anywhere VOF, 97 Niewstraat, Essen 2920 Belgium. A signed order form or pilot agreement takes precedence where it differs. Blokk is offered to businesses, not consumers.
2. A research alpha
- Blokk is an early research product. Features, rules and interfaces change without notice.
- There is no service level agreement, uptime commitment or guaranteed support response time. Access may be interrupted, suspended or withdrawn.
- Assessments are uncalibrated heuristics from a limited rule baseline. Blokk does not detect all automation, and it does not identify or verify specific AI agents. “No automation indicators observed” never means a verified human.
- Blokk is not a web application firewall, DDoS protection or identity-verification service, and it does not guarantee that abuse will be prevented.
3. Shadow mode and your policy
Integrations run in shadow mode by default: your action continues and Blokk records an assessment. Any decision to block, challenge or otherwise treat a request differently is your policy and your responsibility. Evaluate assessments against the outcomes you confirm before enforcing anything. Keyboard-only use, missing JavaScript and assistive technology are not suspicious by themselves. Do not use an assessment as the sole basis for a decision with legal or similarly significant effects on a person.
Shopify pilot boundaries
Shopify is the first commercial adapter. The public app is not yet approved or publicly available. Store access requires an authorised installation route, merchant authentication and the relevant scopes. Theme and pixel observations are monitor-only; static checkout validation is unactivated and has not been demonstrated on a live store. No card-testing prevention or universal checkout protection is promised.
Any supported enforcement requires explicit activation, a documented failure policy and recovery checks. Requesting a pilot creates no subscription or charge. Public distribution, live coverage, pricing configuration and reviewed agreements are release gates. Shopify also provides platform authentication and signed events; these do not prove that a visitor is human or an order legitimate.
4. Your responsibilities
- Have a lawful basis for the processing and give your visitors appropriate notice. As controller, you decide whether consent is needed before loading the browser script, including under Article 5(3) of the EU ePrivacy Directive and national equivalents.
- Send only the data the integration is designed for. Never send message bodies or other form contents, passwords or other credentials, names, email addresses, payment details, raw IP addresses, raw account identifiers, cookies or full request headers.
- If you send account references, derive them on your servers, with your own secret, from the account you have authenticated—never from anything a visitor submits—and keep that secret away from Blokk. They are pseudonymous, not anonymous.
- Choose the integration mode and any telemetry experiment in your own server code. Interaction telemetry is off by default; tell your visitors before you run an experiment.
- Keep your own server-side checks: authentication, CSRF protection, input validation, authorisation and idempotency of your business operations. Blokk does not replace them.
- Keep API keys on your servers, revoke any key you believe is exposed, and control who can use your console accounts.
- Integrate and test only websites and applications you own or are authorised to test.
- Report outcomes accurately: the outcome you actually established, how you established it and the action you took, each from its fixed list. An action such as suspending an account is not a confirmed outcome; report it as unresolved until you have decided. Keep review notes free of personal data.
5. Acceptable use
You must not:
- use Blokk to probe, attack, load-test or collect data from services you are not authorised to test;
- try to access other customers’ data, bypass rate limits or quotas, or interfere with the service’s security;
- run load or stress tests against Blokk without our written agreement;
- use Blokk or its outputs to build or publish ways of evading bot detection on third-party services; or
- use Blokk for unlawful surveillance or discrimination, or for any processing the law prohibits.
6. Data protection
When Blokk processes information about your visitors, it acts as your processor under a data processing agreement based on Article 28 GDPR, which forms part of your pilot agreement. The privacy notice describes the information processed. By default, assessments are kept for 30 days (configurable from 7 to 180; pilots typically use 90), detailed features for 7 days, and assessments with any reported outcome (including an unresolved one) or a manual review label for up to 365 days after the newest one. When the alpha or a pilot ends, customer data is deleted or returned as the data processing agreement specifies.
In this release, your event data—attempts, observations, assessments, outcomes and review labels from your sites—is used only to provide the service to you. It is not used across customers to improve Blokk: it does not train, tune or evaluate rules for anyone else. What carries over between customers is Blokk’s code, detection rules and synthetic tests. [Any future reuse, and the processing roles it would require: to be decided by counsel before it happens.]
7. Fees
Fees, if any, are set out in a written order signed by both parties. Design-partner pilots may be paid. There are no public prices, and nothing on this website creates an obligation to pay.
8. Confidentiality and feedback
Each party keeps the other’s non-public information confidential and uses it only for the alpha or pilot. We may use feedback you choose to give to improve Blokk; feedback does not include your event data. [Detailed confidentiality terms: to be completed by counsel.]
9. Ownership
You keep your data and your applications. We keep Blokk, its software, rules and documentation. We process customer data only to provide the service to you and as the data processing agreement allows.
10. Suspension and ending
Either party may end the alpha or a pilot [notice period: to be completed by counsel]. We may suspend access immediately to protect the service or other customers, or if these terms are breached. When access ends, stop using your API keys; customer data is then deleted or returned as the data processing agreement specifies.
11. Warranties and liability
The alpha is provided for evaluation, without warranties except those the law does not allow to be excluded. [Warranty disclaimer, limitation and exclusion of liability, and indemnities: to be completed by counsel.]
12. Governing law and disputes
[Governing law, jurisdiction and dispute resolution: to be completed by counsel.]
13. Changes and contact
We may update these terms; a signed pilot agreement changes only by written amendment. Questions: g@blokk.bot
Back to Blokk