Effective Date: August 12, 2026 Version: source-access-2026-08-12
These Customer-Directed Source Access Terms (“Source Terms”) supplement the FINA1 Terms of Service and govern any use of ZENITH by FINA1 to access, retrieve, normalize, transmit, analyze, or otherwise process information from an independent third-party provider, website, API, application, account, document, database, or information source (each, a “Source”).
By initiating a covered Source operation, Customer agrees to these Source Terms. If these Source Terms conflict with the FINA1 Terms of Service on a Source-access issue, these Source Terms control for that issue.
1. Customer direction and technical agency
Customer selects the Source and operation and directs Zenith to perform the permitted request. For that limited purpose, Zenith acts as Customer’s technical agent solely to execute Customer’s instruction.
This limited technical agency does not:
- make FINA1 or Zenith a party to Customer’s agreement with a Source;
- authorize FINA1 to bind Customer to a Source;
- make a Source FINA1’s agent, partner, affiliate, or licensor;
- create a fiduciary relationship; or
- transfer to FINA1 any right in Source content beyond the limited processing rights necessary to provide the Service.
2. Customer representations and warranties
For each Source operation, Customer represents and warrants that:
- Authorized access. Customer is authorized to access the selected Source and the requested information.
- Authorized credentials. Customer is authorized to use and provide any account, subscription, API key, token, cookie, credential, license, or other access mechanism used for the request.
- Lawful instructions. The requested access, retrieval, processing, normalization, analysis, display, storage, caching, disclosure, redistribution, publication, and downstream use comply with applicable law and third-party rights.
- Provider obligations. Customer is responsible for complying with applicable Source terms, licenses, contractual restrictions, attribution duties, privacy terms, confidentiality duties, geographic restrictions, and usage limits.
- No circumvention. Customer will not use Zenith to bypass CAPTCHA, access controls, anti-bot systems, paywalls, credential restrictions, technical protection measures, or geographic restrictions.
- No prohibited action. Customer will not direct a destructive, harmful, fraudulent, unlawful, write-capable, or consequential operation prohibited by the Agreement or operation policy.
- Accurate authority information. Information Customer provides concerning credentials, licenses, authorization, and requested-use scope is materially accurate and current.
These representations are repeated each time Customer initiates a Source operation.
3. Independent Sources and third-party rights
Sources are independent third parties. Third-party materials remain subject to the rights of their respective owners.
FINA1 does not, merely by supporting a Source or operation:
- claim ownership of Source content;
- grant Customer a license to Source content;
- represent that Customer’s access or use is authorized by the Source;
- warrant that Source terms permit Customer’s intended downstream use;
- claim public-display, raw-redistribution, warehousing, or resale rights;
- claim sponsorship, endorsement, affiliation, certification, or partnership; or
- assume responsibility for Source accuracy, completeness, availability, legality, or continuity.
Customer must obtain any license, permission, consent, or other right required for its intended use.
4. Customer credentials
When Customer provides or binds a credential, Customer authorizes FINA1 and Zenith to use it only within the configured scope and only to perform Customer-authorized operations.
Customer remains responsible for:
- authority to use the credential;
- account and license restrictions;
- scope and permission settings;
- security of the underlying Source account;
- rotation and revocation; and
- activity Customer directs using the credential.
FINA1 may reject, quarantine, suspend, or revoke a credential binding where reasonably necessary to address suspected compromise, unauthorized use, Source complaints, legal risk, scope ambiguity, or security incidents.
Retrievable customer credentials are isolated, tenant-scoped, revocable, and protected through designated secret-management controls. Credentials are not shared across customers.
5. Operation-level authorization
Every Source operation remains subject to FINA1 and Zenith runtime controls, which may include:
- request validation;
- authenticated Customer and organization state;
- acceptance of current legal terms and Source Access Attestation;
- API-key or MCP authorization and revocation status;
- subscription entitlement;
- rate limits and call balance;
- Source and operation authorization;
- read-only and non-consequential classification;
- technical liveness and substantive validation;
- required credential or license state;
- prohibited-use evaluation; and
- Source health and availability.
A request denied before physical Source execution must not be represented as having reached the Source. FINA1 may apply zero-charge behavior to pre-execution denials in accordance with the applicable plan and metering policy.
6. Requested-use scope
Customer may be required to identify an intended use, such as:
- private research;
- private application use;
- internal commercial use;
- customer-facing display;
- redistribution;
- derived analytics;
- AI processing;
- persistent storage; or
- caching.
An operation’s technical availability does not grant rights for every requested use. Customer remains responsible for determining whether each downstream use is permitted.
FINA1 may deny an operation where a required license or permission is absent, the use is prohibited by known restrictions, or the requested use exceeds the configured operation policy.
7. Storage, caching, and request history
Unless an applicable operation policy or Order Form expressly authorizes otherwise:
- provider response payloads are not persistently stored by FINA1;
- persistent provider caching is disabled;
- provider cache TTL is zero;
- Customer credentials, Source sessions, tokens, cookies, and provider payload bodies are excluded from ordinary request history; and
- request history may retain metadata such as request ID, Customer/client identity, Source, operation, status, call charge, latency, record count, provenance, storage/cache decision, legal-policy versions, and timestamps.
Customer is independently responsible for the legality of any storage, caching, display, or redistribution it performs after receiving an authorized result.
8. Provenance and attribution
Zenith may attach Source identity, acquisition path, request and Source timestamps, freshness information, normalization version, record counts, storage/cache decision, policy version, and request identifier to outputs.
Customer may not materially falsify or remove provenance or attribution where doing so would violate law, Source terms, license obligations, the Agreement, or reasonably mislead a downstream user.
Attribution to a Source does not imply endorsement or partnership.
9. Exact-provider integrity
If Customer requests an exact Source, Zenith will not silently substitute a different Source and represent the substitute as the requested Source.
If the requested Source or operation is unavailable, degraded, unauthorized, or technically unsupported, FINA1 may deny the request or clearly identify an alternative only where Customer affirmatively chooses or the applicable product expressly provides for that behavior.
10. Prohibited Source use
Customer may not use Source-access functionality for:
- unlawful or unauthorized access;
- credential misuse;
- CAPTCHA or technical-protection circumvention;
- anti-bot bypass;
- destructive or write-capable activity outside an expressly approved operation;
- fraudulent, harmful, or deceptive conduct;
- unauthorized personal-data processing;
- intellectual-property, confidentiality, privacy, or contractual violations;
- false Source affiliation or impersonation;
- removal of legally or contractually required attribution;
- unauthorized bulk harvesting or persistent collection; or
- FINA1-branded raw-data resale where FINA1 has not expressly authorized the relevant rights model.
The FINA1 Acceptable Use Policy applies in addition to this Section.
11. Source changes, complaints, and suspension
A Source may change its technology, terms, authentication, rate limits, content, availability, or access practices without notice to FINA1.
FINA1 may suspend, restrict, reclassify, or remove a Source or operation where reasonably necessary because of:
- technical degradation;
- security concerns;
- a Source complaint or rights claim;
- legal or regulatory developments;
- suspected credential misuse;
- uncertainty about authorization;
- material changes to the Source; or
- risk to FINA1, Customer, a Source, or another person.
A prior successful request or prior classification does not guarantee future availability.
12. No legal determination
Source availability, catalog inclusion, technical callability, authorization by FINA1’s runtime, successful retrieval, normalization, provenance, or billing does not constitute a legal opinion that Customer’s access or downstream use is lawful or permitted by a Source.
Customer is responsible for obtaining professional advice when its intended use raises legal, licensing, privacy, intellectual-property, regulatory, or contractual questions.
13. Accuracy and reliance
Third-party materials and normalized outputs may be delayed, incomplete, stale, inaccurate, inconsistent, or affected by Source errors. Customer must independently validate outputs before relying on them for consequential purposes.
FINA1 does not warrant that any Source will remain available or that third-party materials are accurate, complete, current, non-infringing, or suitable for Customer’s intended purpose.
14. Customer indemnification for Source activity
In addition to Customer’s indemnification obligations under the FINA1 Terms of Service, Customer will defend, indemnify, and hold harmless FINA1, its affiliates, and their officers, directors, employees, contractors, agents, licensors, and service providers from third-party claims, investigations, demands, damages, judgments, settlements, penalties, losses, liabilities, costs, and reasonable attorneys’ fees arising from or relating to:
- Customer’s instructions or requested Source access;
- Customer credentials, accounts, subscriptions, or licenses;
- third-party materials accessed, retrieved, transmitted, processed, displayed, stored, cached, redistributed, published, or used at Customer’s direction;
- Customer’s violation or alleged violation of Source terms, contract, law, privacy rights, confidentiality obligations, intellectual-property rights, or license restrictions; or
- Customer’s downstream decisions, products, services, publications, redistribution, commercialization, or other use of Source materials.
The defense, settlement, and cooperation procedures in the FINA1 Terms of Service apply to this indemnity.
15. Privacy and personal data
If a Source operation includes personal data, Customer is responsible for establishing a lawful basis and satisfying notice, consent, minimization, purpose-limitation, retention, and rights obligations applicable to Customer’s use.
Where FINA1 processes that personal data on Customer’s behalf, the FINA1 Data Processing Addendum applies.
Customer must not intentionally request prohibited or specially regulated personal data unless an applicable Order Form or operation specification expressly permits it and required safeguards are in place.
16. Versioning and evidence
FINA1 may maintain immutable or append-only records identifying the Source Terms version, Source Access Attestation version, commercial policy version, safety-policy version, and call-weight version applicable to a completed request.
A later policy update does not retroactively alter the legal-policy version recorded for a historical request.
17. Survival
Sections concerning third-party rights, Customer responsibility, indemnification, privacy, legal compliance, evidence, disclaimers, and accrued obligations survive termination to the extent necessary to give them effect.