Legal

Terms of Service

Last updated 2 August 2026. These terms govern your use of InstantBlock. By creating an account or using the service you agree to them. If you are agreeing on behalf of an organisation, you confirm you are authorised to bind it.

Two documents govern data. These terms cover the commercial relationship. How we handle personal data is in the Privacy Policy, and where we process your visitors' data on your behalf, the Data Processing Agreement applies and prevails over these terms on that subject.

Parties and scope

"InstantBlock", "we" or "us" means InstantNode, operating the InstantBlock service. "You" or "Customer" means the account holder. "Visitor" means an end user of a website on which you deploy InstantBlock. "Service" means the detection engine, the browser client, the console at instantblock.eu, and the APIs and documentation we provide.

What the service does

InstantBlock evaluates requests to your website and returns a verdict — broadly allow, challenge or refuse — derived from a browser fingerprint, environment and network signals, a proof-of-work, and behavioural signals, scored across seven weighted dimensions. We issue a signed token carrying that verdict; your backend verifies the token offline using your site secret.

InstantBlock does not block anything by itself. We return a verdict. Your application decides what to do with it. In particular, requests we score as automated still receive a correctly-signed token — one carrying a refuse decision — and your backend must check the decision field, not merely the presence or signature validity of a token. If you do not implement that check, traffic we identified as automated will be admitted, and that outcome is your responsibility, not a defect in the service.

Accounts

You must provide accurate registration details and keep your credentials secure. Sign-up is limited to company email addresses. You are responsible for all activity under your account and under your site keys and API keys. Site secrets and API keys are displayed once at creation; we cannot recover them and can only issue replacements. Tell us promptly at security@instantblock.eu if you believe a credential has been compromised.

You must be at least 18 and capable of entering a binding contract. We may refuse or close an account where we reasonably believe these terms are being breached.

Plans, limits and fees

Current plans, their site counts, monthly verdict allowances and retention windows are on the pricing page and form part of these terms. All detection features are available on every plan; plans differ by volume, retention and support.

  • Paid plans are billed in advance, monthly, and renew automatically until cancelled. Fees are stated exclusive of VAT and other applicable taxes, which are added where required.
  • You may cancel at any time with effect from the end of the current billing period. We do not refund part-used periods except where required by law.
  • If you exceed your plan's verdict allowance we will contact you to move to an appropriate plan. We may throttle or suspend verification beyond the allowance, but we will not silently bill you for overage.
  • We may change prices with 30 days' notice by email, effective from your next billing period. If you do not accept the change you may cancel before it takes effect.
  • The Free plan is provided as-is and we may modify or discontinue it with 30 days' notice.

Your responsibilities

  • Deploy the client only on domains you own or are authorised to operate, and keep your registered domain configuration accurate.
  • Verify tokens server-side using your site secret, and check the decision field as described above.
  • Decide and implement your own behaviour when the service is unavailable or slow — whether you admit the request (fail open) or refuse it (fail closed). Our client does not make that choice for you, and an outage on our side must not be able to take your site down. Set a timeout.
  • Keep your integration reasonably current. We support the current and immediately preceding client version.
  • Do not attempt to bypass, reverse engineer or extract secrets from the client bundle beyond what applicable law permits you to do without our consent.

Privacy and visitor notice

This is the obligation customers most often miss. When you deploy InstantBlock you become the controller of your visitors' personal data and we become your processor. That means you — not us — are responsible for having a lawful basis, for disclosing this processing in your own privacy notice, and for answering your visitors' data subject requests.

Specifically, you agree that you will:

  • Disclose in your own privacy notice that you use a bot-detection service, that it reads technical characteristics of the visitor's browser and device, and that it derives a persistent device identifier. Our Privacy Policy describes what is collected in enough detail for you to reference or reproduce it.
  • Carry out your own assessment of the lawful basis for this processing, and any balancing test or data protection impact assessment your circumstances require.
  • Handle visitor access, erasure and objection requests as controller, and route to us anything you need our help to fulfil. We will assist you within the timeframes in the DPA.
  • Not deploy InstantBlock in a context where the processing would be unlawful for you, and not send us special-category data, children's data as a target population, or payment card data.

We will process visitor data only to provide the service and as described in the DPA, and will not use it to build advertising profiles or sell it.

Acceptable use

You may not use the service to:

  • Track, profile or identify individuals for any purpose other than distinguishing automated from human traffic on your own properties — in particular, not for advertising, price discrimination, or building a cross-site behavioural profile.
  • Discriminate against visitors on the basis of a protected characteristic, or systematically exclude users of assistive technology, privacy-preserving browsers or anonymity networks without a lawful and proportionate reason.
  • Attack, overload or probe the service or any other customer's tenancy, or use it as infrastructure in an attack on a third party.
  • Resell, sublicense or provide the service to third parties as your own product without a written reseller agreement.
  • Deploy it on unlawful content or services, or in breach of applicable law.

We may suspend access immediately where use presents a security risk, a legal risk, or degrades the service for others. Where practical we will notify you first and restore access once resolved.

Detection accuracy

No detection system is perfect and we do not claim ours is. InstantBlock produces a probabilistic verdict. It will sometimes classify a genuine person as automated (a false positive) and sometimes admit an automated client (a false negative). Privacy-hardened browsers, assistive technology, unusual hardware, corporate proxies and accessibility tooling raise the risk of false positives. We do not warrant any detection rate, false-positive rate or accuracy figure, and no benchmark, marketing claim or dashboard figure constitutes such a warranty.

Because of this, you must not rely on InstantBlock as the sole control protecting a critical function, and you should provide an alternative route for a genuine user who is refused. We tune detection continuously; behaviour may change between versions, and a change in verdict distribution is not by itself a defect.

Availability and changes

We aim to keep the service available and will give reasonable notice of planned maintenance. Any uptime commitment applicable to your plan is in the Service Level Agreement; where no SLA applies, the service is provided on a reasonable-efforts basis.

We may change the service, including detection logic, scoring, the client bundle and the API. We will give at least 30 days' notice of a change that removes functionality you rely on or is not backwards-compatible, except where a shorter timeline is needed for security. Detection rules, scoring weights and the obfuscated client bundle change frequently by design and are not subject to that notice.

Support

Support channels and response targets follow your plan. Security reports are welcome from anyone at security@instantblock.eu; we will not pursue legal action against good-faith security research that respects our customers' data, avoids privacy violations and service degradation, and gives us reasonable time to remediate before disclosure.

Intellectual property

We retain all rights in the service, including the engine, client, WASM module, documentation and brand. We grant you a non-exclusive, non-transferable, revocable licence to use the client and APIs to protect your own properties for the term of your subscription.

You retain all rights in your own content and data. You grant us only the licence needed to operate the service for you. If you send us feedback or suggestions, we may use them without obligation or compensation.

Confidentiality

Each party will protect the other's non-public information with at least reasonable care and use it only for the purposes of this agreement. Your site secrets, API keys and configuration are your confidential information; our non-public detection methods, the internals of the client bundle and our security documentation are ours. This does not apply to information that is public through no breach, independently developed, or required to be disclosed by law — in which case the disclosing party will give notice where legally permitted.

Warranties and disclaimers

We warrant that we will provide the service with reasonable skill and care and in accordance with these terms. Except as expressly stated, the service is provided "as is" and we disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty of uninterrupted or error-free operation or of any particular detection outcome.

Nothing in these terms excludes any warranty or right that cannot lawfully be excluded, including statutory rights of consumers where they apply.

Limitation of liability

Neither party is liable for indirect, incidental, special, consequential or punitive damages, or for loss of profit, revenue, goodwill, or data, however caused.

Each party's total aggregate liability arising out of or relating to this agreement is limited to the fees you paid or owed for the service in the twelve months preceding the event giving rise to the claim, or €100 where no fees were paid.

These limits do not apply to: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; your payment obligations; either party's breach of the confidentiality section; or any liability that cannot be limited by law. Nothing here limits either party's liability to a data subject or supervisory authority under applicable data protection law.

You are responsible for losses arising from your own integration decisions, including admitting traffic because you did not check the decision field, and outages caused by your choice of fail-open or fail-closed behaviour.

Term and termination

These terms apply from account creation until terminated. You may terminate at any time by closing your account. We may terminate for material breach that is not cured within 14 days of notice, immediately for a breach of the acceptable use section, or on 30 days' notice if we discontinue the service — in which case we will refund fees for any period paid but not served.

On termination your access ends and we delete your data in line with the retention periods in the Privacy Policy. You should export anything you need beforehand. Sections that by their nature survive — intellectual property, confidentiality, liability, and this section — continue to apply.

General

  • Governing law and venue. These terms are governed by the law of the jurisdiction stated in the Imprint, and the courts of that jurisdiction have exclusive jurisdiction, without prejudice to mandatory consumer protections in your country of residence.
  • Changes to these terms. We may update them on 30 days' notice by email or in-console notice. Continued use after they take effect is acceptance. If you do not accept, you may terminate before the effective date.
  • Assignment. You may not assign this agreement without our written consent. We may assign it to a successor in a merger or sale of substantially all assets, on notice to you.
  • Subcontractors. We may use subprocessors for hosting and infrastructure; those relevant to personal data are listed in the DPA.
  • Entire agreement and severability. These terms, the Privacy Policy, the DPA, the Acceptable Use Policy and any applicable SLA are the entire agreement between us. If a provision is unenforceable the rest remains in effect. A failure to enforce a right is not a waiver of it.
  • Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, excluding payment obligations.

Questions about these terms: legal@instantblock.eu.

Privacy Policy Data Processing Agreement