These API Terms govern access to and use of the askHermis Public API (the “API”): programmatic, organisation-scoped access to bookings, guest conversations, alerts and room availability. They supplement the askHermis Terms of service; in case of conflict regarding API use, these API Terms prevail. By requesting or using an API key you agree to them. If you integrate on behalf of a hotel or other organisation, you confirm that you are authorised to bind that organisation.
1. API keys and security
API keys are issued per organisation by the askHermis team and are shown only once, when issued. You must:
- treat keys as confidential credentials: store them securely and never put them in client-side code, mobile apps or public repositories;
- never share keys with third parties or between organisations;
- accept responsibility for all activity performed with your keys, whether or not you authorised it;
- notify us immediately at team@askhermis.com if you suspect a key has been compromised; revocation takes effect within sixty (60) seconds;
- accept that we may rotate, suspend or revoke keys at any time for security or compliance reasons.
2. Sandbox and live environments
Sandbox keys (prefixed ah_sandbox_) perform real read operations against your organisation’s data, while all write operations are simulated and have no side effects. Live keys (prefixed ah_live_) perform real operations, including delivering messages to guests. You must test your integration in the sandbox before using a live key, and you are solely responsible for the content and timing of messages your integration sends to guests.
3. Acceptable use
You may use the API only to provide services to the organisation that owns the key. You must not:
- attempt to circumvent authentication, rate limits or organisation-level data isolation;
- access or attempt to access data of any organisation other than the one that owns your key;
- sell, sublicense or disclose data obtained through the API to third parties without the organisation’s authorisation and a lawful basis;
- use the API to build or train a competing product or service;
- poll endpoints excessively or in ways that degrade the service for others;
- use the API in breach of applicable law, including data protection and consumer communication laws, or of our AI Acceptable Use Policy.
4. Guest data and privacy
The API exposes personal data of hotel guests, including names, contact details, booking information and conversation content. The organisation remains the controller; you process this data solely on its behalf and instructions. You must:
- process guest data only as necessary to provide services to the organisation;
- apply appropriate technical and organisational security measures;
- not use guest data for your own marketing, profiling or any other purpose;
- comply with the GDPR and all other applicable data protection law;
- delete guest data obtained through the API when your key is revoked or your engagement with the organisation ends, except where the law requires you to keep it.
askHermis processes the organisation’s data under our Data Processing Addendum.
5. Rate limits, availability and API changes
API usage is subject to the rate limits stated in the API reference, which we may adjust with reasonable notice. The API is provided without an availability guarantee and may be temporarily unavailable for maintenance or operational reasons. The API is versioned (currently /api/v1); we aim to give reasonable advance notice of breaking changes or deprecations, but additive, non-breaking changes may happen at any time.
6. Suspension and termination
We may suspend or revoke API keys, with or without notice, in case of a breach of these terms, suspected abuse, a security risk or a legal requirement. You or the organisation may request key revocation at any time. The sections on guest data, confidentiality and liability survive termination.
7. Disclaimer and limitation of liability
The API and its documentation are provided “as is” and “as available”, without warranties of any kind. To the extent the law allows, askHermis is not liable for indirect, incidental, special or consequential damages, loss of profits or loss of data arising from use of the API, and our aggregate liability does not exceed the fees paid for API access (if any) in the twelve (12) months before the claim. These limits do not apply to liability that cannot be limited by law.
8. Changes and governing law
We may update these API Terms; material changes will be announced with reasonable notice through the dashboard or by email, and continued use of the API after the effective date means acceptance. These terms are governed by the laws of Greece, and the courts of Athens, Greece have exclusive jurisdiction over any dispute.