Agreement and order of precedence
These Terms of Service (the “Terms”) are a legally binding agreement between Gorillo, LLC, doing business as Handout (“Handout,” “we,” “us,” or “our”) and the person or organization accepting them (“Customer,” “you,” or “your”). They govern access to and use of Handout’s websites, application, customer-created sites, browser extension, APIs, MCP tools, tracking, session replay, integrations, previews, and related services, documentation, and support (collectively, the “Services”).
You accept these Terms by creating an account, clicking to accept, executing an Order, or accessing or using the Services. If you do not agree, do not use the Services. If you use the Services for an organization, “Customer” means that organization and you represent that you have authority to bind it.
These Terms bind Customers and Authorized Users. A person does not become a Customer merely by viewing a customer-created public site. The site owner’s terms, notices, and legal obligations govern its relationship with that visitor, while the Privacy Policy explains Handout’s data processing.
An “Order” means an online checkout, order form, statement of work, or other document accepted by Handout that identifies Services, fees, or a subscription term. If documents conflict, the order is: (1) an expressly negotiated Order; (2) the Data Processing Addendum in Sections D1–D10 for personal data processing; (3) these Terms; and (4) product documentation. A purchase order or Customer form is for administrative convenience only and does not modify this agreement unless Handout expressly signs it.
Business service; arbitration agreement
Eligibility and authority
You must be at least 18, legally able to contract, and using the Services for business purposes. You may not use the Services if you are barred under applicable law, subject to sanctions that prohibit the relationship, or acting for a competitor to evaluate, benchmark, or copy the Services without our written permission.
If an organization invited you, its administrator may control your account and workspace, access or export Customer Content, manage members and permissions, change or cancel the subscription, and request account transfer or deletion. Your relationship with that organization is between you and it.
Accounts, administrators, and security
You must provide accurate, current information; keep it updated; protect passwords, one-time codes, sessions, extension tokens, API credentials, MCP grants, and webhook secrets; and use reasonable device and endpoint security. Accounts and seats are for the assigned individual and may not be shared. You are responsible for activity under your accounts and for users, agents, applications, and endpoints you authorize.
Customer administrators are responsible for assigning least-privilege roles, promptly removing former personnel, reviewing connected clients and destinations, and keeping workspace and billing contacts current. Notify us immediately at hello@handout.link of suspected compromise, unauthorized access, or credential disclosure. We may require credential rotation, revoke sessions or tokens, or take protective action.
The Services, changes, and availability
Subject to these Terms and payment of applicable fees, Handout grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the subscription term to access and use the Services for Customer’s internal business operations and authorized client-facing sites. Documentation and plan descriptions may identify usage limits, entitlements, retention choices, seats, storage, automations, recordings, or support levels.
We may improve, modify, replace, or discontinue features to address law, security, abuse, provider changes, technical constraints, or product development. We will use commercially reasonable efforts to give advance notice before discontinuing a material paid feature where practicable. If we discontinue the core paid Service during a prepaid term without a substantially similar replacement, Customer’s exclusive remedy is a pro-rata refund of unused prepaid fees for that discontinued Service.
We do not promise uninterrupted or error-free operation. Maintenance, incidents, internet conditions, provider outages, browser changes, Gmail or marketplace changes, Customer configurations, or force majeure may affect availability. No service-level agreement, support response time, backup commitment, or data-residency commitment applies unless an Order expressly says so.
Free, preview, beta, and experimental features
Free, trial, beta, preview, early-access, and experimental features may be changed or withdrawn at any time, may be incomplete, and may have different limits or support. They are provided “AS IS” without any commitment to continued availability and should not be used for mission-critical or regulated workloads.
Subscriptions, fees, renewal, and taxes
Subscriptions and automatic renewal
Paid Services are sold for the billing period shown at checkout or in an Order, usually monthly or annually. Unless an Order states otherwise, each paid subscription automatically renews for successive periods of the same length until canceled. By purchasing, Customer authorizes Handout and Stripe to charge the payment method on file for recurring fees, additional seats, usage, taxes, and approved adjustments.
Fees and plan changes
Fees are stated in U.S. dollars unless the checkout says otherwise and are due in advance or as invoiced. Seat or plan changes may take effect immediately and be prorated through Stripe; a downgrade may take effect at the end of the current period or reduce functionality, limits, and retention. Customer is responsible for charges incurred by its administrators and authorized users. We may correct pricing or billing errors.
We may change fees for a future renewal by giving at least 30 days’ notice. Continuing the subscription after the change takes effect accepts the new fee. If Customer does not agree, its remedy is to cancel before renewal.
Taxes and payment disputes
Fees exclude sales, use, value-added, withholding, and similar taxes and duties. Customer will pay them except taxes based on Handout’s net income. If law requires withholding, Customer will gross up the payment so Handout receives the invoiced amount, unless prohibited. Customer must raise a good-faith billing dispute within 30 days of the charge and pay undisputed amounts on time. Overdue amounts may accrue the lesser of 1.5% per month or the lawful maximum, plus reasonable collection costs.
Cancellation and refunds
An administrator may cancel through the billing settings or by contacting us. Cancellation takes effect at the end of the then-current paid period, and Customer retains paid access until then unless the account is suspended or terminated for cause. Except where an Order or law requires otherwise, fees are non-cancelable and non-refundable, and we do not give credits for partial periods, unused seats, unused features, or Customer configuration. Removing the app, extension, content, or payment method does not itself cancel a subscription.
Customer Content and licenses
“Customer Content” means information, documents, editor content, sites, assets, recipient records, variables, links, embeds, instructions, configuration, and other materials submitted to or generated through the Services for Customer, excluding Handout technology, aggregated or de-identified information, and third-party materials.
As between the parties, Customer retains its rights in Customer Content. Customer grants Handout and its subprocessors a worldwide, non-exclusive, royalty-free license during the applicable term and wind-down period to host, copy, cache, transmit, render, modify for technical formatting, create previews of, display, and otherwise process Customer Content only to provide, secure, support, and improve the operation of the Services, comply with Customer instructions, and meet legal obligations.
Customer represents and warrants that it has all rights, permissions, notices, and lawful bases necessary for Customer Content and Handout’s processing under these Terms; Customer Content and its use will not violate law, contract, confidentiality, privacy, publicity, intellectual property, or other rights; and Customer’s instructions will not cause Handout to violate applicable law.
Handout does not acquire ownership of Customer Content and will not use a customer’s name, logo, site, or content in public marketing without permission. Suggestions and feedback are governed by Section 18.
Published sites, recipient links, and previews
Handout sites and recipient-specific versions are link-accessible public webpages, not authenticated virtual data rooms. Anyone with a link may open, copy, forward, screenshot, download, scrape, or share it. A link may identify a recipient or include name, company, domain, or variable values in its path or query. Links and preview images may appear in browser history, message previews, logs, caches, search results if indexing is enabled, and third-party systems.
Customer must use recipient links only for appropriate business information, avoid confidential or sensitive data, review the rendered result before sending, and unpublish or rotate links when access should end. Customer is responsible for whether content is indexed and for recipients to whom it distributes links. Handout does not guarantee that unpublishing or deletion removes copies, caches, previews, or records already made by a recipient or third party.
Preview images may be generated through automated browser rendering and stored at versioned public URLs to support email and social previews. A preview may persist in third-party caches after the underlying site is changed. Customer authorizes that generation and is responsible for the content displayed.
Customer legal and operational responsibilities
Customer is solely responsible for:
- Customer Content, recipients, public links, site settings, users, credentials, connected clients, embeds, automations, and webhook destinations;
- providing privacy, cookie, recording, and other notices; obtaining and recording valid consent; honoring opt-outs and rights; and selecting lawful retention settings;
- complying with privacy, ePrivacy, wiretap, communications, telemarketing, advertising, anti-spam, consumer-protection, accessibility, employment, export, sanctions, and industry-specific laws that apply to its use;
- ensuring any email, text, call, outreach, or sales activity involving a Handout link complies with CAN-SPAM, TCPA, Canada’s Anti-Spam Legislation (CASL), GDPR, PECR, and other applicable marketing and communications rules;
- evaluating recipients and visitors, establishing a legal basis for their information, responding to their requests, and ensuring Customer’s downstream use is compatible with the notice and consent given;
- testing sites, links, variables, embeds, replay blocking, and webhooks before use and maintaining appropriate records of consent and instructions; and
- maintaining its own backup or export of information it cannot afford to lose and a lawful notice and incident-response process.
Handout’s templates, consent interface, privacy link, replay masking, blocking, or documentation help implement Customer choices but are not legal advice and do not make Customer compliant. Customer must consult its own counsel and adapt its practices to its audience, jurisdiction, content, and purpose.
Activity tracking and Session Replay Addendum
This Section is the “Session Replay Addendum” referenced in the application. Enabling activity tracking or session replay constitutes Customer’s acceptance of this Section for the workspace.
Permitted purpose
Customer may use tracking and replay only to understand legitimate engagement with Customer’s own business content, improve that content, follow up lawfully, prevent abuse, and support recipients. Customer may not use replay for covert surveillance, employee monitoring, eligibility or credit decisions, insurance, housing, employment, education admissions, healthcare decisions, law-enforcement profiling, biometric analysis, or another high-impact or legally significant decision.
Notice and affirmative consent
Before enabling consent-gated measurement, Customer must determine that it has a lawful basis and, wherever consent is required, obtain freely given, specific, informed, unambiguous, and affirmative consent before collection begins. Customer must identify itself, explain the categories of behavior captured and purposes, link to an accurate notice, provide a genuine decline option, and make withdrawal as easy as consent. Customer must not bypass, obscure, manipulate, preselect, or interfere with Handout’s choice interface or trigger collection before a valid choice.
Customer acknowledges that consent requirements may arise under GDPR, UK GDPR, PECR, ePrivacy laws, state wiretap and interception laws, consumer-protection law, or contract even if a cookie is not used. Customer will maintain evidence of notice and consent and provide it to Handout upon reasonable request related to a complaint or investigation.
Handout requires its consent prompt before activity tracking or session replay begins. Customer must not remove, bypass, obscure, preselect, or interfere with the prompt, and must not use another integration or copy of Handout data to evade that requirement. Handout may also require geofencing or feature disablement where risk warrants.
Data minimization and prohibited capture
Customer must configure pages and blocked regions so replay-visible text does not contain sensitive, regulated, confidential, authentication, financial, health, government-identifier, biometric, children’s, or payment-card data. Customer may not modify the Services to defeat masking, collect field values, reconstruct blocked content, fingerprint a visitor, or combine tracking with data for an undisclosed incompatible purpose.
Customer access and downstream use
Customer will limit tracking and replay access to trained personnel with a business need, review access when roles change, select the shortest appropriate retention, and secure exports and webhook destinations. Customer is responsible for actions based on analytics and for any data it exports, copies, combines, or sends downstream.
Handout controls and enforcement
Handout may impose entitlement, storage, duration, event, start-rate, and daily-volume limits; pause or stop collection; delete recordings; update masking or consent controls; or require Customer to disable a feature when needed for law, security, capacity, or risk. Current replay is designed to mask form values, omit scripts and frames, strip URL credentials and query data, and cap individual recordings, but no control eliminates all risk.
Allocation of responsibility
Prohibited and regulated data
Unless an Order expressly authorizes it and the parties sign every required addendum, Customer must not submit, expose, or cause Handout to process:
- protected health information under HIPAA, medical records, or patient treatment data;
- full payment-card or bank credentials, card verification values, or PCI cardholder data outside Stripe’s hosted payment flow;
- government identifiers, passwords, authentication secrets, private keys, financial-account credentials, or precise geolocation;
- biometric templates, genetic information, intimate-life information, highly sensitive demographic profiles, or nonpublic consumer financial information governed by GLBA;
- education records governed by FERPA, criminal-justice information, or classified, export-controlled, or national-security information;
- information about children prohibited by Section 16 of the Privacy Policy; or
- material requiring access controls or regulatory assurances that Handout has not expressly agreed to provide.
Standard Services are not HIPAA-compliant services, and Handout does not enter a Business Associate Agreement by online acceptance. Customer bears all risk and cost arising from prohibited data and must notify Handout immediately if it is submitted.
Acceptable use
Customer and its users must not:
- violate law or the rights of others; facilitate fraud, phishing, impersonation, deceptive marketing, harassment, stalking, threats, exploitation, trafficking, or illegal goods or services;
- publish malware, malicious code, credential traps, unlawful sexual content, child sexual abuse material, non-consensual intimate imagery, or content that promotes terrorism or credible violence;
- infringe intellectual property, privacy, publicity, confidentiality, database, or contractual rights;
- send unsolicited bulk messages, evade opt-outs, misrepresent sender or destination, or use Handout to build or enrich an unlawful marketing database;
- probe, scan, interfere with, disrupt, overload, attack, or bypass security, rate limits, entitlement, consent, access, or usage controls;
- access another tenant, scrape nonpublic data, introduce viruses, use automated means that impose unreasonable load, or use the Services to develop or benchmark a competing product;
- reverse engineer, decompile, disassemble, copy, translate, or create derivative works of the Services except to the limited extent law prohibits that restriction;
- sell, rent, sublicense, time-share, or provide the Services as a service bureau, or transfer an account, except as expressly allowed in an Order; or
- encourage, enable, or attempt any prohibited act.
We may investigate suspected violations, preserve evidence, limit distribution, disable links or features, remove content, suspend access, and cooperate with authorities or affected parties as permitted by law.
Third-party services and content
The Services may interoperate with Stripe, Gmail and Chrome, GIPHY, Logo.dev, YouTube, Vimeo, Loom, calendar services, remote images, customer webhooks, AI or MCP clients, and other third-party products (“Third-Party Services”). Customer chooses whether to use them and authorizes Handout to exchange information necessary for the requested interoperability.
Third-Party Services are governed by their own terms and privacy practices and may change, block, rate-limit, suspend, or discontinue integration. Handout does not control and is not responsible for their content, security, data use, acts, omissions, availability, or compatibility. Handout does not warrant or endorse customer-selected embeds or destinations. Customer is responsible for obtaining licenses, complying with third-party terms, configuring privacy controls, and assessing transfers.
Extension, integrations, APIs, MCP, and agents
Browser extension
The Gmail extension is provided only to help an authorized user insert a selected Handout link or card into a compose window. Customer must comply with Google, Gmail, Chrome Web Store, communications, and privacy rules. Customer must not modify or use the extension to access message bodies, threads, attachments, contacts, or tokens beyond its intended functionality. Gmail and browser changes may interrupt the extension.
APIs, MCP, and software agents
A tool, script, AI agent, or third-party client acting with Customer credentials or authorization is an Authorized User. Customer authorizes Handout to treat its requests as Customer instructions and is responsible for every action it takes, including creating, changing, publishing, or deleting content or recipients and reading tracking data.
Customer must review an agent’s scope and provider terms, grant the least privilege, protect tokens, validate output, supervise publication, and promptly revoke access that is no longer needed. AI or automated output may be inaccurate, incomplete, infringing, or unsuitable. Handout is not responsible for a third-party model’s training, retention, security, output, or use of information Customer sends to it.
A model provider, MCP client, local application, computer, employee, or other recipient that Customer selects or authorizes is within Customer’s control and is not a Handout subprocessor merely because it receives information through a Customer-directed request. Customer is responsible for the recipient’s authority and need to know, disclosures, legal basis, contracts, international transfers, security, retention, onward deletion, and assistance with individual rights. If Handout independently selects and uses a provider to deliver the Services, that provider is handled under the DPA’s subprocessor terms instead.
Webhooks
Customer is responsible for its destination, lawful basis, recipient, availability, security, secret rotation, signature validation, payload handling, and downstream retention. Handout may retry deliveries, impose queues and usage limits, disable unsafe or failing destinations, and redact or delete delivery data under operational retention schedules.
Handout intellectual property
Handout and its licensors own the Services, software, source and object code, designs, interfaces, workflows, documentation, templates, models, compilations, improvements, trademarks, and all related intellectual property, excluding Customer Content. No rights are granted except the limited access right expressly stated in these Terms.
“Handout,” its logo, and related marks are Handout marks. Customer may not use them in a way that implies endorsement, partnership, or ownership. Customer may accurately identify that a site is powered by Handout and use materials expressly provided for that purpose, subject to brand guidelines and revocation.
Confidentiality
“Confidential Information” means nonpublic information disclosed by one party that is marked confidential or should reasonably be understood as confidential given its nature and context. Customer Confidential Information includes nonpublic Customer Content; Handout Confidential Information includes nonpublic product, security, pricing, roadmap, and technical information.
The recipient will use Confidential Information only to perform or exercise rights under the agreement, protect it using at least reasonable care, and disclose it only to personnel, advisers, and providers who need to know and are bound by protective obligations. These duties do not cover information that the recipient can document was lawfully known without restriction, independently developed, rightfully received from another source, or made public without breach.
A recipient may disclose information when legally required if, where lawful, it gives prompt notice and reasonable assistance at the discloser’s expense. Published sites, recipient links, public previews, and content Customer directs us to disclose are not confidential as to their intended recipients. This Section does not make Handout a secure data room or expand agreed security obligations.
Privacy and data processing
Our Privacy Policy explains processing for which Handout determines the purposes and means. Sections D1–D10 form the Data Processing Addendum (“DPA”) governing Customer Personal Data processed by Handout on Customer’s behalf and are incorporated into these Terms.
Customer will not instruct Handout to process personal data in violation of law, will provide all notices and obtain all rights and consents, and will respond to individuals and regulators. If Customer is a processor for another controller, Customer represents it is authorized to appoint Handout as a subprocessor and to give the instructions in this agreement.
Content reports, moderation, and copyright
Illegal or harmful content reports
A person may report content or conduct to hello@handout.link. A useful report identifies the exact URL or content location, explains the alleged illegality or violation, identifies the applicable right or law, includes supporting evidence, provides the reporter’s name and contact details, and states a good-faith belief that the report is accurate. We may request more information, forward the report to the customer, preserve evidence, and take proportionate action.
We process sufficiently precise reports in a timely, diligent, objective, and non-arbitrary manner. Where applicable law requires, we will confirm receipt, notify the reporter of our decision and available redress, and provide the affected customer a statement of reasons for a restriction. A customer may appeal a moderation decision within six months by replying to the notice with relevant facts. We may decline to disclose information where doing so would compromise safety, security, an investigation, legal obligations, or another person’s rights.
Nonconsensual intimate-image removal
How to request removal
For a valid request covered by applicable law, Handout will remove the reported image as soon as possible and no later than 48 hours after receipt and will make reasonable efforts to identify and remove known identical copies. We will provide a confirmation or reference and notify the requester of the result or information still needed. This process also covers qualifying digital forgeries. If someone is in immediate danger, contact emergency services or law enforcement first.
Copyright notices
A copyright owner or authorized agent may send a notice identifying: (1) the copyrighted work; (2) the exact location of allegedly infringing material; (3) contact information; (4) a good-faith statement that the use is unauthorized; (5) a statement under penalty of perjury that the notice is accurate and the sender is authorized; and (6) a physical or electronic signature.
Gorillo, LLC, doing business as HandoutAttn: Copyright
Email: hello@handout.link
A user whose material was removed may submit a counter-notice identifying the material and former location, consenting to jurisdiction in the U.S. federal judicial district where the user’s address is located (or, if outside the United States, any district where Handout may be found), agreeing to accept service from the complainant, and stating under penalty of perjury a good-faith belief that removal resulted from mistake or misidentification, with contact information and a signature. We may forward a counter-notice to the complainant and restore material after the statutory waiting period if the complainant does not notify us of a filed court action. False claims may create liability. We may terminate repeat infringers in appropriate circumstances.
Feedback and aggregated data
If Customer voluntarily provides an idea, suggestion, or feedback, Customer grants Handout a perpetual, irrevocable, worldwide, royalty-free, sublicensable, transferable license to use and incorporate it without restriction or compensation. Do not submit feedback subject to a duty that would restrict this license.
Handout may create and use aggregated or de-identified information for analytics, security, capacity planning, benchmarking, and product improvement, provided it does not identify Customer or an individual. We will not attempt to re-identify data that law requires to remain de-identified.
Suspension and protective action
Handout may immediately limit, suspend, or disable an account, site, public link, integration, tracking, replay, webhook, or other feature if reasonably necessary to: prevent harm or unauthorized access; address a security incident or credible legal claim; comply with law, court order, provider requirement, or sanctions; stop prohibited conduct or excessive use; protect another tenant or the Services; or address overdue fees.
We will use reasonable efforts to give notice and limit the scope and duration where circumstances permit. Customer remains responsible for fees during a suspension caused by Customer. We may require remediation, identity or authority verification, content removal, credential rotation, or written assurances before restoring access.
Term, termination, and data after termination
These Terms begin when accepted and continue while Customer has an account or Order. Either party may terminate an Order for a material breach not cured within 30 days after written notice, or immediately if the breach cannot be cured, involves unlawful or dangerous conduct, threatens the Services, or the other party becomes insolvent, ceases business, or enters bankruptcy proceedings not dismissed within 60 days.
On expiration or termination, Customer’s access ends, public sites may be unpublished, and Customer must stop using the Services and pay all accrued fees. If Handout terminates for uncured Customer breach, prepaid fees are not refunded and committed unpaid fees become due. If Customer terminates for Handout’s uncured material breach, Customer’s exclusive fee remedy is a pro-rata refund of unused prepaid fees for the terminated period.
During the subscription, Customer should export data it needs using available features. After termination, Handout may delete Customer Content after a reasonable wind-down period, subject to the DPA, backups, legal holds, security records, and information Handout is independently entitled or required to retain. We do not guarantee post-termination retrieval unless an Order states otherwise. Sections that by their nature should survive do survive, including accrued payment, ownership, confidentiality, disclaimers, indemnity, liability, dispute, and general terms.
Disclaimers
TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICES, DOCUMENTATION, OUTPUTS, TEMPLATES, CONSENT TOOLS, TRACKING, REPLAY, PREVIEWS, AND THIRD-PARTY CONTENT ARE PROVIDED “AS IS” AND “AS AVAILABLE.” HANDOUT AND ITS AFFILIATES, LICENSORS, AND PROVIDERS DISCLAIM ALL EXPRESS, IMPLIED, STATUTORY, AND OTHER WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, QUIET ENJOYMENT, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
HANDOUT DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, SECURE, ERROR-FREE, COMPLIANT FOR CUSTOMER, OR FREE OF HARMFUL COMPONENTS; THAT DATA WILL NEVER BE LOST OR EXPOSED; THAT MASKING OR BLOCKING WILL CAPTURE EVERY SENSITIVE ELEMENT; THAT A LINK WILL REMAIN PRIVATE; THAT AN INTEGRATION OR THIRD-PARTY SERVICE WILL CONTINUE; OR THAT CUSTOMER WILL ACHIEVE ANY SALES, ENGAGEMENT, REVENUE, DELIVERY, OR OTHER RESULT.
Handout does not provide legal, tax, accounting, compliance, marketing, employment, or security advice. Customer is responsible for independent review, professional advice, backups, results, and decisions. Some jurisdictions do not allow certain disclaimers, so they apply only to the extent lawful.
Customer indemnification
Customer will defend, indemnify, and hold harmless Handout, its affiliates, and their officers, directors, employees, contractors, licensors, and providers from claims, demands, investigations, proceedings, losses, judgments, settlements, penalties, damages, costs, and reasonable attorneys’ fees arising from or relating to:
- Customer Content, public sites, recipient data, links, previews, communications, products, services, or business practices;
- Customer’s tracking, replay, consent, personalization, embeds, webhooks, integrations, agents, exports, or downstream use;
- Customer’s or an Authorized User’s violation of these Terms, law, third-party terms, or another person’s rights;
- prohibited data, inaccurate instructions, or failure to provide notice, obtain consent, honor rights, or secure credentials and destinations; or
- any dispute between Customer and its users, recipients, or visitors.
Handout will give prompt notice, except delay relieves Customer only to the extent materially prejudiced. Customer controls the defense with qualified counsel, but may not settle in a way that admits fault by, imposes obligations on, or fails to unconditionally release an indemnified party without Handout’s written consent. Handout may participate with counsel at its own expense and may assume control if a conflict exists or Customer fails to defend.
Limitation of liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, HANDOUT AND ITS AFFILIATES, LICENSORS, AND PROVIDERS WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES; LOSS OF PROFITS, REVENUE, SAVINGS, GOODWILL, BUSINESS OPPORTUNITY, OR DATA; BUSINESS INTERRUPTION; PROCUREMENT OF SUBSTITUTE SERVICES; OR LIABILITY ARISING FROM THIRD-PARTY SERVICES, CUSTOMER CONTENT, PUBLIC LINKS, RECIPIENT ACTIONS, OR CUSTOMER DECISIONS, UNDER ANY THEORY AND EVEN IF ADVISED OF THE POSSIBILITY.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, HANDOUT’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THE SERVICES, AN ORDER, THE DPA, OR THESE TERMS WILL NOT EXCEED THE GREATER OF: (A) THE FEES PAID OR PAYABLE BY CUSTOMER TO HANDOUT FOR THE AFFECTED SERVICES DURING THE THREE MONTHS IMMEDIATELY BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY; OR (B) ONE HUNDRED U.S. DOLLARS (US $100).
The exclusions and cap apply in the aggregate to all claims, are an essential allocation of risk, and apply even if a remedy fails of its essential purpose. They do not limit liability that cannot lawfully be excluded or limited. Handout’s providers and licensors are intended beneficiaries of this Section. Customer’s payment and indemnity obligations are not limited by this Section.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, A CLAIM ARISING OUT OF OR RELATING TO THE SERVICES OR AGREEMENT MUST BE FILED WITHIN ONE YEAR AFTER THE CLAIM ACCRUES, OR IT IS PERMANENTLY BARRED. A STATUTORY PERIOD THAT CANNOT LAWFULLY BE SHORTENED CONTROLS. THE TOLLING EXPRESSLY PROVIDED IN SECTION 24 STILL APPLIES.
Disputes, arbitration, and governing law
Informal resolution
Before filing a claim, a party must send a written notice describing the claimant, facts, legal basis, requested relief, and calculation of any amount. The parties will confer individually and in good faith for 60 days. Limitation periods are tolled during that period. Notices to Handout must be sent by email to the contact in Section 28 with the subject line “Dispute Notice.”
Binding individual arbitration
EXCEPT FOR THE EXCEPTIONS BELOW, ANY DISPUTE ARISING OUT OF OR RELATING TO THE SERVICES, AN ORDER, THE DPA, THESE TERMS, OR THE PARTIES’ RELATIONSHIP WILL BE RESOLVED BY FINAL AND BINDING INDIVIDUAL ARBITRATION, NOT IN COURT, UNDER THE FEDERAL ARBITRATION ACT.
The American Arbitration Association (“AAA”) will administer the arbitration under its Commercial Arbitration Rules then in effect, as modified here. The arbitrator, and not a court, will decide disputes about the interpretation, applicability, enforceability, or formation of the agreement to arbitrate, except a court will decide the enforceability of the class and representative waivers. One arbitrator will conduct the matter in English. The hearing will occur remotely or in New York County, New York, unless the parties agree otherwise. The arbitrator may award relief available to an individual party under applicable law, must enforce this agreement, and will issue a reasoned written decision. A court may enter judgment on the award.
Class, representative, and jury waiver
EACH PARTY WAIVES TRIAL BY JURY. CLAIMS MAY BE BROUGHT ONLY IN AN INDIVIDUAL CAPACITY, NOT AS A PLAINTIFF, CLASS MEMBER, PRIVATE ATTORNEY GENERAL, OR REPRESENTATIVE IN A CLASS, COLLECTIVE, CONSOLIDATED, OR REPRESENTATIVE PROCEEDING. THE ARBITRATOR MAY NOT COMBINE CLAIMS OR AWARD RELIEF FOR ANYONE OTHER THAN THE INDIVIDUAL PARTIES.
Coordinated filings
If 25 or more substantially similar demands are submitted by or with the assistance of the same counsel or coordinated group, AAA’s Mass Arbitration Supplementary Rules then in effect apply. The parties will meet and select ten demands for initial bellwether proceedings, five per side. Other demands are stayed and administrative fees for a stayed case are due only as required by AAA’s applicable rules and fee schedule. After the bellwethers, the parties will mediate in good faith before remaining cases proceed in batches of no more than 25. A process arbitrator may resolve administrative disputes about this procedure. This process does not authorize class arbitration; limitation periods are tolled for stayed demands. If AAA declines to administer a dispute and the parties cannot agree on a substitute, a court may appoint an arbitrator under the Federal Arbitration Act.
Exceptions and opt-out
Either party may bring an eligible individual claim in small-claims court, seek temporary or injunctive relief for unauthorized access, misuse, or intellectual-property infringement, or ask a court to enforce the arbitration provision. A Customer may opt out of arbitration by emailing a signed notice with the subject “Arbitration Opt-Out” within 30 days after first accepting these Terms, identifying the Customer and account and clearly stating the decision to opt out. Opting out does not affect other Terms.
Law and courts
These Terms and non-arbitrable disputes are governed by the laws of New York, excluding conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods. Subject to arbitration, the parties consent to exclusive jurisdiction and venue in the state and federal courts located in New York County, New York. If part of the class waiver is finally unenforceable as to a particular claim, that claim will proceed in court after arbitrable claims, and the remainder survives.
Export controls, sanctions, and government use
Customer will comply with U.S. and other applicable export controls, sanctions, and anti-boycott laws. Customer represents that it and its users are not located in a comprehensively sanctioned jurisdiction, on a prohibited-party list, or owned or controlled by a prohibited party, and will not use the Services for prohibited end uses.
The Services are commercial computer software and documentation. U.S. government use is subject to the rights and restrictions customarily provided to the public under these Terms and applicable procurement rules.
Electronic communications and notices
Customer consents to electronic records, signatures, notices, and communications. We may send operational notices to the account email, display them in the Services, or post them on our site. Customer must keep contact information current. A notice is effective when sent or posted, except a formal breach, indemnity, arbitration, or termination notice is effective upon confirmed delivery and must also be sent to any notice address in the Order.
We may send service, security, billing, verification, and legal messages without offering a marketing opt-out because they are necessary to the relationship. A recipient may unsubscribe from optional marketing through the provided mechanism.
General terms
Assignment. Customer may not assign or transfer the agreement without Handout’s written consent. Handout may assign it to an affiliate or in connection with a merger, financing, reorganization, sale of assets, or change of control. An unauthorized assignment is void.
Independent parties. The parties are independent contractors. The agreement does not create employment, agency, partnership, fiduciary duty, franchise, or joint venture, and neither party may bind the other.
Force majeure. Neither party is liable for delay or failure caused by events beyond reasonable control, including internet or utility failure, provider outage, attack, epidemic, disaster, labor dispute, government action, war, or civil unrest. This does not excuse payment for Services already provided.
Waiver; severability. A waiver must be written and is limited to that instance. If a provision is unenforceable, it will be modified to the minimum extent needed to reflect its intent, and the rest remains effective, subject to Section 24’s special severability.
No third-party beneficiaries. Except for indemnified parties and providers protected by Sections 21–23, no person other than the parties has rights under the agreement.
Interpretation. “Including” means “including without limitation.” Headings are for convenience. A reference to law includes amendments and replacements. The English version controls to the extent permitted by law.
Entire agreement. These Terms, an Order, the DPA, and documents expressly incorporated by reference are the entire agreement about the Services and supersede prior or contemporaneous proposals and communications. Each party relies only on express terms.
Changes. We may update these Terms for changes in law, risk, technology, providers, or the Services. We will post the revised version and give reasonable advance notice of a material change. Except where law requires express acceptance, continued use after the effective date accepts the update. A material change will not retroactively reduce an express right or expand liability for events already completed. If Customer objects, its remedy is to stop using and cancel before the update takes effect.
Contact and legal notices
Attn: Legal
Email: hello@handout.link
Questions about these Terms and formal breach, indemnity, termination, or dispute notices to Handout may be sent by email. Use the subject line “Legal Notice” unless a different subject line is specified in these Terms, and include the sender’s name, account email, and enough detail to identify the matter. An arbitration opt-out may be sent by email as provided in Section 24.
The same email is Handout’s electronic point of contact for recipients, government authorities, and other notices concerning hosted content. English may be used. Use “Illegal Content Notice” for a content report and include the elements in Section 17. If European Union law requires a legal representative or additional official-language contact, Handout will publish that representative’s required details separately; this paragraph does not appoint one.
DPA scope, definitions, and roles
Sections D1–D10 are the Data Processing Addendum between Customer and Handout. They apply when Handout processes Customer Personal Data to provide the Services. “Customer Personal Data” means personal data, personal information, or equivalent regulated information contained in Customer Content or generated from a customer-directed site, recipient, tracking, replay, webhook, integration, or support workflow. It excludes information for which Handout determines the purposes and means as described in the Privacy Policy.
“Data Protection Law” means privacy, security, breach-notification, and data-protection law applicable to the processing, including GDPR, UK GDPR, the UK Data Protection Act 2018, Swiss FADP, and applicable U.S. state comprehensive privacy laws. “GDPR” means Regulation (EU) 2016/679. Controller, processor, business, consumer, sell, share, service provider, and personal data have the meanings in applicable Data Protection Law.
Customer is the controller or business and Handout is the processor or service provider for Customer Personal Data. If Customer is a processor, Handout is its subprocessor. Each party will comply with its obligations under Data Protection Law. Customer is responsible for the lawfulness, fairness, accuracy, notices, legal bases, consents, instructions, and rights handling for Customer Personal Data.
DPA processing details
| Element | Description |
|---|---|
| Subject matter and purpose | Providing, securing, supporting, and maintaining the customer-configured Handout Services, including sites, personalization, collaboration, tracking, replay, previews, integrations, webhooks, and support. |
| Duration | The applicable subscription or account term plus the deletion, return, backup, legal-hold, and wind-down periods described in the agreement. |
| Nature and frequency | Collection, receipt, hosting, organization, structuring, storage, retrieval, consultation, rendering, transmission, use, combination at Customer’s direction, restriction, deletion, and other processing necessary for the Services, on a continuous or Customer-directed basis. |
| Data subjects | Customer users and invitees; recipients and prospects; visitors to customer-created sites; Customer personnel, clients, contractors, contacts, and other people whose information Customer submits. |
| Personal-data categories | Identity and business contact data; account and team data; Customer Content; company, domain, recipient, and variable data; public-link context; device, browser, network, coarse location, visit, event, session, replay, and consent data; support and communications; integration, webhook, and audit data. |
| Sensitive data | Not intended or authorized. Credentials and access tokens are processed only to secure and provide the Services. Customer must not submit the sensitive and regulated categories prohibited by Section 10. |
| Customer rights and obligations | As controller, Customer may configure, access, export, correct, restrict, unpublish, and delete data through available features and may instruct Handout as provided in the agreement. |
Documented instructions and compliance
Handout will process Customer Personal Data only on documented instructions, including the agreement, Customer configuration, Authorized User actions, support requests, and other written instructions consistent with the Services, unless law requires otherwise. If law requires other processing, Handout will inform Customer before processing unless law prohibits notice.
Handout will promptly inform Customer if, in its opinion, an instruction violates Data Protection Law. Handout may suspend the affected instruction while the parties work in good faith on a lawful alternative and may terminate the affected Service if none is reasonably available. Handout does not independently determine whether Customer’s business, notices, consent, or instructions comply with law.
Handout will ensure personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access appropriate to their role.
Security measures
Taking into account the state of the art, implementation cost, and the nature, scope, context, and purposes of processing and risk to individuals, Handout will maintain appropriate technical and organizational measures, including as applicable:
- encryption in transit; encryption or provider-managed protection at rest for managed databases and object storage; and separate encryption for sensitive automation endpoints and signing secrets;
- authenticated, tenant-aware access controls; role and authorization checks; session and token revocation; and least-privilege operational access;
- private object storage and time-limited authorized access for replay data; input masking, blocked-region controls, and capture limits;
- secure development practices, dependency and code review, testing, vulnerability remediation, rate-limiting, origin protection, and SSRF defenses for customer-provided destinations and remote fetches;
- logging designed to redact secrets and sensitive fields, monitoring, incident response, backups, restoration measures, and provider resilience controls;
- subprocessor diligence and written data-protection obligations; and
- periodic review and adaptation of safeguards in light of risk and changes to the Services.
Customer is responsible for security within its control, including endpoints, credentials, users, roles, content, public links, embeds, exports, agents, webhook destinations, and configuration.
Subprocessors
Customer gives Handout general written authorization to use the subprocessors listed in the Privacy Policy and their own approved subprocessors as needed to provide the Services. Handout will impose data-protection obligations that provide materially equivalent protection for Customer Personal Data and remains responsible for a subprocessor’s performance to the extent required by Data Protection Law and this DPA.
Handout will provide at least 30 days’ notice before authorizing a new material subprocessor that processes Customer Personal Data, including by updating the list and notifying the account contact or making a subscription mechanism available. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Handout may elect not to provide the affected feature and Customer may terminate only that affected feature or Order, with a pro-rata refund of unused prepaid fees for it. This is Customer’s exclusive remedy for a subprocessor objection.
Rights, incidents, and regulatory assistance
Taking into account the nature of processing and information available, Handout will provide reasonable assistance for Customer to:
- respond to verified requests to exercise data-subject or consumer rights;
- conduct a legally required data-protection impact assessment or prior consultation relating to Customer’s use of the Services;
- meet security, breach-notification, and regulator-cooperation obligations; and
- demonstrate compliance with processor obligations.
If Handout receives a request concerning Customer Personal Data, it will not respond on Customer’s behalf unless authorized or legally required and may direct the requester to Customer. Customer will use available self-service tools first. Handout may charge reasonable fees for assistance that is unusually burdensome, repetitive, or outside standard functionality, unless the need results from Handout’s breach.
Personal Data Breach
Handout will notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Handout (a “Personal Data Breach”). Notification is not an admission of fault.
As information becomes available, Handout will provide the nature of the incident, affected categories and approximate volume where known, likely consequences, measures taken or proposed, and a contact for follow-up. Customer is responsible for notifying regulators and individuals unless law assigns that duty to Handout. Unsuccessful attacks, port scans, blocked attempts, and incidents confined to Customer-controlled systems are not Personal Data Breaches of Handout systems.
Return, deletion, and audits
During the term, Customer may use available features to access, export, correct, unpublish, and delete Customer Personal Data. On termination or written instruction, Handout will delete or return Customer Personal Data within a reasonable period, at Customer’s choice where technically available, unless law requires retention. Backup copies may remain until they age out under ordinary cycles; while retained, they remain protected and are not restored except for disaster recovery or legal necessity.
On reasonable written request, Handout will provide information needed to demonstrate compliance, such as relevant policies, summaries, or third-party assessments when available. No more than once in any 12-month period, Customer may have an independent auditor review that information, subject to confidentiality, scope, security, and non-disruption requirements.
An on-site or technical audit is permitted only where Data Protection Law requires it and the supplied information is insufficient, or after a confirmed material Personal Data Breach involving Customer Personal Data. It must occur during business hours with at least 30 days’ notice unless a regulator requires sooner, avoid access to other customers’ data, and comply with Handout security rules. Customer bears audit costs and Handout’s reasonable assistance costs unless the audit finds a material breach by Handout.
Restricted transfers and Standard Contractual Clauses
If Customer Personal Data protected by European transfer restrictions is transferred to Handout in a country without an adequacy decision and no other lawful mechanism applies, the parties will complete and execute the European Commission Standard Contractual Clauses adopted by Decision 2021/914/EU (“EU SCCs”) before the restricted transfer.
- Module Two applies where Customer is a controller and Handout a processor. Module Three applies where Customer is a processor and Handout a subprocessor.
- Clause 7 docking is not used. In Clause 9, Option 2 applies with the notice period in D5. The optional language in Clause 11 is not used.
- In Clause 17, Option 1 applies and the law is Ireland. In Clause 18, disputes are resolved by the courts of Ireland.
- Customer is the data exporter and Handout is the data importer. The parties will complete Annex I with each party’s legal name, address, contact-person details, role, activities, signature and date, the transfer details in D2 as supplemented by the transfer schedule, and the competent supervisory authority determined under the EU SCCs. Annex II is D4 as supplemented with any transfer-specific measures. Clause 9 uses general authorization, so the current subprocessor list is maintained under D5 rather than treated as the specific-authorization annex.
For UK restricted transfers, the parties will complete the then-current UK International Data Transfer Addendum issued by the Information Commissioner before the restricted transfer. The transfer schedule will complete Table 1 with required party and contact details, Table 2 with the SCC selections above, Table 3 with D2, D4, and transfer-specific details, and Table 4 with the selected ending party. For Swiss transfers, references to GDPR include the Swiss FADP where applicable, the competent authority is the FDPIC, and Swiss law and courts apply to the extent required.
Website acceptance of this DPA does not fill omitted information required by a transfer instrument. Customer must contact Handout and provide the information needed for the transfer schedule. Unless another lawful mechanism applies, Customer will not make, and Handout may suspend, a restricted transfer until the applicable instrument is complete.
The parties will reasonably cooperate on transfer assessments and supplementary measures. If a transfer mechanism is invalidated or a competent authority requires changes, the parties will use an available lawful alternative. The EU SCCs or mandatory addendum controls over conflicting agreement terms.
United States service-provider terms
For Customer Personal Data subject to a U.S. comprehensive state privacy law, Handout acts as a service provider or processor and will:
- process data only for the limited and specified business purposes in D2 and Customer’s documented instructions;
- not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship, or combine it with personal information received from another person or Handout’s own interactions, except as law permits for a service provider or processor;
- provide the same level of privacy protection required by applicable law, notify Customer if Handout determines it can no longer meet an obligation, and allow Customer to take reasonable steps to stop and remediate unauthorized use; and
- require subcontractors to observe applicable restrictions and assist with consumer requests as stated in D6.
Handout certifies it understands and will comply with these restrictions. Customer may monitor compliance through the audit process in D7. Each party will comply with legally required opt-out preference signals for processing under its control.
DPA priority, liability, and termination
The DPA ends when Handout no longer processes Customer Personal Data, except provisions that must survive. If Data Protection Law changes, the parties will negotiate in good faith a necessary amendment; Handout may implement mandatory changes on notice where needed to keep providing the Services lawfully.
Except to the extent the EU SCCs or mandatory law prohibits it, the disclaimers, exclusions, aggregate liability cap, dispute terms, and indemnities in these Terms apply to this DPA and all privacy and security claims in the aggregate, not in addition to other caps. Nothing in the DPA limits a party’s liability under the EU SCCs in a manner the EU SCCs prohibit or reduces a data subject’s mandatory rights under those clauses.