Terms of service
Version 1.2 · Last updated 2026-08-27
These are the terms an organisation agrees to when it uses this product. They are written to be read by the person who has to live with them rather than to be skimmed, and where the software enforces something they say which mechanism does it.
What this covers
These terms apply to the organisation that signs up, not to the individual who happens to click the button. The people who work in that organisation get access through it, and the organisation is responsible for what they do with that access.
An organisation's workspace is separate from every other organisation's. That separation is not a policy we promise to observe — it is enforced in the database itself, on every query, so a mistake in application code cannot expose one organisation's records to another.
- Who can hold an account
- Anyone acting for an organisation that can enter into an agreement. If you are signing up on behalf of a company, you are confirming you are allowed to.
- Who can be added to one
- The organisation decides. Adding someone gives them access to that organisation's data at the level their role allows, and removing them ends it.
- One account is not a shared login
- Credentials belong to a person. Sharing one removes the only record of who did what, which is the record both of us need if something goes wrong.
Sending, and what the product refuses to do
You are responsible for having a lawful basis to contact the people you contact. That is not boilerplate: it is the one obligation here that we cannot discharge for you, because only you know where a contact came from.
What we can do is refuse to help you get it wrong, and that is how the product is built. Consent, suppression and jurisdiction checks run before a send rather than being reported after one, and there is no configuration, plan or support request that turns them off.
- An unsubscribe is permanent and immediate
- Someone who opts out is suppressed at the point of sending. Re-importing them does not clear it, and neither does creating a new list — suppression is checked against the address, not against the list it arrived on.
- Permission is never inferred from a relationship
- Having someone's address, having met them, or having a record of them in a CRM is not recorded as agreement to be contacted.
- Purchased and scraped lists are not acceptable use
- Not a taste preference. A list nobody on it asked to be on generates the bounce and complaint rates that damage the sending reputation shared with every other customer.
- Where you are sending changes what is allowed
- Rules differ by jurisdiction, and the stricter rule is applied rather than the one most convenient for the sender.
- A test never sends anything real
- Test and development environments cannot reach a real recipient. Outbound sending in those environments goes to a substitute, not to a person.
The rest of acceptable use
Do not use the product to break the law, to impersonate someone, to attack or probe systems you are not authorised to test, or to work around another organisation's security. Do not resell access, and do not use it to build a competing product from the inside.
Do not upload content you have no right to, and do not use the product to process categories of personal data it was not designed for — health records, payment card numbers, government identity numbers and children's data are the ones worth naming, because a customer usually reaches for them without thinking of them as unusual.
Text the product drafts for you
The product drafts text — messages, summaries, suggested next steps. A draft is a starting point, not an approval, and anything sent under your organisation's name is your organisation's responsibility even when software wrote the first version of it.
Where a person on the receiving end would reasonably need to know that they are interacting with software rather than a colleague, the product says so. That obligation is not something a customer can switch off to make a message read better.
- Nothing outbound goes without a human approving it
- Approval is a step in the product, not a setting. The point of a draft is that someone reads it.
- A generated answer can be wrong
- Treat anything drafted as you would a first pass from a new colleague: useful, and checked before it leaves.
Your data stays yours
Everything you put into the product — your contacts, your messages, your records of what happened — remains yours. Using the product does not transfer ownership of any of it, and ending the agreement does not either.
We use it to run the service for you: to store it, to show it back to you, to send what you ask us to send, and to fix things when they break. We do not sell it, and we do not use one customer's data to build a product feature that is then sold to another.
- Your data is not training data
- Your content is not used to train models for anyone else's benefit.
- You can take it out
- Export is a normal function of the product rather than a request that has to be approved, and it is not withdrawn when an account is closing.
- The software itself is ours
- You get the right to use the product for as long as the agreement runs. That right does not include copying it, taking it apart, or rebuilding it.
Security, and who else is involved
One organisation's data is separated from another's in the database itself, on every read and every write. Credentials you connect — a mail-sending role, a calendar, a payment provider — are stored encrypted, and the parts that are secret are never returned to a browser and never written to a log.
Running this product involves other companies: somewhere to host it, somewhere to send mail from, providers whose models draft text. They are named, individually, on the sub-processors page rather than described as a category.
- You keep control of the credentials you connect
- A connection you authorise can be revoked by you, and revoking it stops the access rather than merely hiding the button.
- We tell you when something happens to your data
- If your data is affected by a security incident, you are told — with what is known, when it is known, rather than after it has been tidied up.
Availability and support
The product is provided as it is. It is actively run and actively fixed, and problems that affect sending or data are treated as the most urgent kind, because they are.
These terms do not state an uptime percentage or a guaranteed response time. That is deliberate. A number here would be a commitment, and publishing one we do not measure and could not evidence would be worse than saying plainly that no such number is promised yet. If your organisation needs one, it belongs in a written agreement with us rather than on this page.
Maintenance happens. Where it will interrupt something, notice comes first where that is possible; where a fix is urgent enough that waiting is the greater risk, it is applied and then explained.
Limits
Neither of us is responsible to the other for indirect losses — lost profit, lost opportunity, or the cost of something that did not happen because a message did not arrive.
Nothing in these terms limits anything that cannot lawfully be limited, and that carve-out is not decoration: it is the part that survives wherever local law says a limit does not apply.
You are responsible for the consequences of what you send and who you send it to. We are responsible for running the product as described here.
When these terms change
These terms carry a version number and a date, both at the top of this page. A substantive change bumps the version, and the date says when. That is deliberate: a document that can be edited silently is not a document anyone can rely on.
A change that materially reduces what you get, or materially increases what you owe, is notified before it takes effect rather than announced by having already happened. If you do not want to continue under the new version, you can stop and take your data with you — the export described below is not withdrawn as leverage.
Ending it
You can stop at any time. We can stop the account for non-payment, or for the sending conduct described below — sending to people who did not agree to hear from you puts the sending reputation of everyone else on the same infrastructure at risk, so it is the one thing that ends an account quickly.
Ending the agreement is not the same as deleting your data, and the two are deliberately kept apart. Your data remains exportable for a period after the account closes, because a customer who leaves in a hurry is exactly the customer most likely to need it back.
- Suspension is narrower than termination
- Where the problem is a specific behaviour, the narrower response is used: sending can be paused for one project without closing the account or touching anything else.
- Deletion is a request you make, not a thing that happens to you
- Closing an account does not immediately erase it. Ask for deletion and it is carried out; until you do, the data stays retrievable.
Which law applies
These terms are governed by the laws of the Republic of Korea. Disputes go to the Seoul Central District Court, unless the law of the place you are in gives you a court closer to home that you are entitled to use instead.
Choosing a law does not switch off anyone else's. Data protection rules follow where you and the people in your data are, not what this page says — so if the GDPR, the Korean Personal Information Protection Act, or your own state's privacy law applies to you, it still applies, and nothing here reduces it.
- Where we are
- The organisation behind this product is established in the Republic of Korea. That is why Korean law governs — it is where we actually are, rather than a jurisdiction chosen to be inconvenient to reach.
- Rights you cannot sign away
- Wherever local law says a protection cannot be waived by contract, it is not waived by this one. That carve-out is the part that survives everywhere.
Asking about any of this
If something here matters to your organisation and this page does not answer it, ask before you sign up rather than after. A term you had to guess at is a term neither of us can rely on.
What happens to personal data — what is collected, how long it is kept, and what a person can ask for — is set out in the privacy statement rather than repeated here, so that the two cannot drift apart.
Who you are contracting with
- Registered name
- SHMAPLEX
- 상호
- 슈마플렉스
- Business registration number
- 208-06-17257
- Representative
- Robert Kenan Sawyer
- Address
- 서울특별시 관악구 문성로30길 46