Terms of Service
Effective date: August 2026
1. Acceptance of Terms
By accessing or using the getpeppr API, SDK, dashboard, or website (collectively, the "Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organisation, you represent that you have authority to bind that organisation.
These Terms are between you and Zero Loop Labs Ltd, a company registered in England & Wales (Company No. 17035492), 17 Heronsforde, London W13 8JE, UK ("Zero Loop Labs", "we", "us").
Your use of the Service is also governed by our Privacy Policy, which describes how we collect and process personal data.
2. Description of Service
getpeppr provides a developer-first SDK and API gateway for sending and receiving Peppol e-invoices. The Service translates JSON invoice data into Peppol-compliant UBL XML and delivers documents to the Peppol network via our access point provider.
3. Account Registration
To use the Service, you must create an account. You are responsible for maintaining the confidentiality of your API keys and account credentials. You must notify us immediately at hello@getpeppr.dev if you suspect unauthorised access to your account.
You must not share your sk_live_ or sk_sandbox_ API keys in client-side code, public repositories, or any context where they may be exposed to third parties.
4. Acceptable Use
You agree not to use the Service to:
- Send fraudulent, fictitious, or misleading invoices
- Violate any applicable law or regulation, including EU/UK e-invoicing regulations
- Infringe the intellectual property rights of any third party
- Attempt to reverse-engineer, decompile, or disassemble the Service
- Overload or disrupt the Service infrastructure (including API abuse beyond rate limits)
- Transmit malicious code, viruses, or harmful data
We reserve the right to suspend or terminate accounts that violate these restrictions without prior notice.
5. Peppol Network Obligations
By sending invoices through the Service, you acknowledge that:
- You are responsible for the accuracy and legality of all invoice data you submit
- Invoices transmitted to the Peppol network may be subject to country-specific legal obligations
- Certain EU member states mandate e-invoicing for B2B transactions — compliance with local law is your responsibility
- We act as a technical intermediary; we are not a tax advisor or legal counsel
6. Identity Verification and Attestation
6.1 Attestation requirement
Before you can send invoices to the Peppol network via the Service in production, you must (a) declare the legal name of the entity on whose behalf you will invoice, and (b) confirm, via a checkbox at the time you register a Peppol identifier, that you are authorised to invoice on behalf of that entity using that identifier.
6.2 Verification process
We verify the declared name against public business registries. Which registry we query depends on the Peppol scheme of the identifier you register:
- UK VAT numbers (Peppol scheme
GB:VAT) → verified manually by our team before your identifier is published. We do not currently query an automated UK registry; once HM Revenue & Customs grants us production access to its “Check a UK VAT number” service, verification for these identifiers will become automatic. - Belgian enterprises (Peppol scheme
0208) → VIES, the European Commission's VAT Information Exchange System, and where VIES cannot confirm the name, the KBO/BCE (Crossroads Bank for Enterprises). - French SIRENE/SIRET identifiers (Peppol schemes
0002/0009) → VIES (SIREN root derived to VAT per the French key algorithm) and INSEE Sirene. For a SIRET the INSEE check runs even when VIES confirms the name, because a VIES match proves the SIREN root rather than the specific establishment. - French CTC identifiers (Peppol scheme
0225) → INSEE Sirene only; these values are not derivable to a VAT number. - German VAT numbers (Peppol scheme
9930) → VIES. Note that the German tax administration withholds the registered business name from VIES responses as a matter of member-state privacy policy; for German identifiers we verify only VAT validity, and your attestation under §6.1 is the authoritative confirmation that you represent the declared entity. - Swedish organisation numbers (Peppol scheme
0007) → Bolagsverket, the Swedish Companies Registration Office.
Where a fallback registry is queried, our Privacy Policy describes what is transmitted to it and what we retain.
Automated registry verification typically completes within one minute of registration; where we verify manually, it takes longer. You will be notified of the outcome by email. Our public documentation at /docs/onboarding/verification describes each verification state and how to resolve a failure.
6.3 Retention of verification records
We retain a minimized audit record of each verification — provider, verdict, similarity score, country, the last four characters of the identifier, and the verification timestamp — for six years from the verification date. We align that period with the six-year time limit for bringing a claim on a simple contract under the Limitation Act 1980, so that we can establish and defend claims about who we admitted to the network. Raw registry names and addresses are not stored in the default audit record. Once the six years have elapsed the record is purged by a monthly job, so it may persist for up to a further month.
6.4 Re-attestation
We may require re-attestation when these Terms are materially updated. Continued access to production invoice sending may require you to re-confirm the attestation in §6.1. The dashboard will display a non-dismissible banner when re-attestation is required.
6.5 Legal basis
We process verification data under UK GDPR Article 6(1)(b) (performance of this contract — §6.1 attestation and §6.2 verification are pre-conditions for production invoice sending) and Article 6(1)(f) (legitimate interest in preventing impersonation on the Peppol e-invoicing network and in preserving its integrity). Our duties under the OpenPeppol Integrator agreement are contractual rather than statutory, so we do not rely on Article 6(1)(c) for this processing. You may therefore object to it and ask us to erase the record; we will do so unless we have compelling legitimate grounds to continue, or need it to establish or defend a legal claim.
7. Fees and Payment
Fees are charged per document exchanged — both sent and received (see pricing at getpeppr.dev/pricing). Billing is managed via Stripe. You authorise us to charge your payment method on file. All fees are exclusive of VAT. Invoices are issued monthly in arrears.
We reserve the right to change pricing with 30 days' notice. Continued use of the Service after a price change constitutes acceptance of the new pricing.
8. Service Availability
We aim for high availability but do not guarantee uninterrupted service. The Service is provided "as is" without warranty of any kind, express or implied. We will endeavour to provide notice of planned maintenance where practicable. Current service status is available at status.getpeppr.dev.
9. Intellectual Property
The getpeppr SDK (@getpeppr/sdk) is published under an open-source licence (see the GitHub repository for the specific licence terms). The getpeppr API, dashboard, and all associated proprietary software remain the exclusive property of Zero Loop Labs Ltd.
You retain all rights to the invoice data you submit. You grant us a limited licence to process that data solely to provide the Service.
10. Confidentiality
Each party agrees to keep confidential any non-public information disclosed by the other party in connection with the Service, and to use such information only for purposes of these Terms.
11. Limitation of Liability
To the maximum extent permitted by applicable law, Zero Loop Labs Ltd shall not be liable for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, revenue, data, or business opportunities, arising out of or in connection with the Service, even if advised of the possibility of such damages.
Our total aggregate liability to you shall not exceed the greater of (a) the amounts paid by you to us in the 12 months preceding the claim, or (b) £100.
Nothing in these Terms excludes or limits liability for death or personal injury caused by negligence, fraud, or any other liability that cannot be excluded under English law.
12. Indemnification
You agree to indemnify and hold harmless Zero Loop Labs Ltd, its officers, directors, and employees from any claims, damages, or expenses arising from your use of the Service, your violation of these Terms, or your violation of any applicable law or third-party rights.
13. Termination
Either party may terminate these Terms at any time. You may close your account via the dashboard or by emailing hello@getpeppr.dev. We may suspend or terminate your access for breach of these Terms, non-payment, or if required by law.
Upon termination, your right to use the Service ceases immediately. Your data will be retained for 30 days after account deletion to allow recovery, after which it is permanently removed. Financial records are retained for 7 years as required by UK law. See our Privacy Policy for full details.
14. Governing Law and Disputes
These Terms are governed by the laws of England and Wales. Any dispute arising from these Terms shall be subject to the exclusive jurisdiction of the courts of England and Wales.
We encourage you to contact us first at hello@getpeppr.dev to resolve any dispute informally before commencing legal proceedings.
15. Changes to These Terms
We may update these Terms from time to time. We will provide at least 14 days' notice of material changes by email or by posting a notice on the dashboard. Continued use of the Service after changes take effect constitutes your acceptance of the revised Terms.
16. Contact
For questions about these Terms, contact us at hello@getpeppr.dev.