MEDAIRE API TERMS
Last updated:
1. Introduction and Applicability
1.1 These API Terms ("API Terms") govern the Subscriber's access to and use of MedAire's Application Programming Interface, single sign-on service, and related integration services. These API Terms are supplemental to and form part of the agreement between MedAire and the Subscriber/Customer (the "Agreement"), including any applicable Certificate of Subscription.
1.2 Capitalized terms used but not defined in these API Terms shall have the meanings given to them in the Agreement.
1.3 In the event of any conflict between these API Terms and the terms of the Agreement (including any Certificate of Subscription) with respect to the subject matter of these API Terms, these API Terms shall prevail, provided that the exclusions and limitations of liability set out in the Agreement shall continue to apply in full to all claims arising under or in connection with these API Terms. In all other respects, the terms of the Agreement shall prevail.
1.4 MedAire may update these API Terms from time to time in accordance with clause 9.2.
2. Definitions
For the purposes of these API Terms:
(a) "API" means MedAire's content provisioning Application Programming Interface through which Information is made available, as further described in the API Documentation.
(b) "API Access Key" means the unique authentication credentials issued by MedAire to the Subscriber enabling access to the API.
(c) "API Documentation" means the technical documentation, specifications and integration guidelines provided by MedAire to the Subscriber in connection with the API, as updated by MedAire from time to time.
(d) "Authorized Application" means the Subscriber's internal application, or any third-party application or platform approved by MedAire in writing, in each case as identified on the Certificate of Subscription, through which Information may be accessed, displayed or integrated.
(e) "Customer Data" means any Customer data and content transmitted to MedAire through the API or a Third-Party API by or on behalf of the Subscriber.
(f) "Information" means, collectively, Provider Data and Customer Data.
(g) "Provider Data" means all data, content, information, and materials originated, sourced, compiled, aggregated or derived by MedAire and made available by MedAire through the API as part of MedAire's own product offering, which may include Travel Health data, Travel Security Risk Ratings, Alerts, Aviation Security Intelligence Alerts, and related content. For the avoidance of doubt, Provider Data does not include Third-Party Data.
(h) "SSO" means the single sign-on authentication service provided by MedAire enabling the Subscriber's authorized users to access MedAire's portal or application using the Subscriber's existing identity provider credentials, as further described in the API Documentation.
(i) "Third-Party API" means any application programming interface or data source provided or operated by a Third-Party API Provider.
(j) "Third-Party API Provider" means any third party that provides or operates an application programming interface or data source with which MedAire integrates in order to provide the API, the Information to the Customer or at the request or on behalf of the Customer.
(k) "Third-Party Data" means all data, content, information and materials originating from or provided by a Third-Party API Provider.
(l) "Third-Party Integration" means the service provided by MedAire of establishing and maintaining a technical integration with a Third-Party API on behalf of the Subscriber, as specified on the Certificate of Subscription.
(m) "Third-Party Platform Provider" means any third party that provides or hosts an application or platform into which the Subscriber integrates the API or through which Provider Data is accessed or displayed, in each case as approved by MedAire in writing under clause 6.4.
3. Scope of Access
3.1 Subject to the terms of the Agreement, Certificate of Subscription and these API Terms, MedAire grants the Subscriber: (a) access to the API for the purposes of integrating Provider Data with the Authorized Application; (b) where specified on the Certificate of Subscription, the Third-Party Integration, including access to Third-Party Data and, where applicable, the transmission of Customer Data through the applicable Third-Party API; and (c) where specified on the Certificate of Subscription, access to the SSO service, in each case as further specified on the Certificate of Subscription.
3.2 The Subscriber shall be entitled to a limited number of requests for Information through the API not to exceed 100,000 calls per month.
3.3 Provider Data will be provided in English. MedAire makes no representation regarding the language of any Third-Party Data.
3.4 MedAire reserves the right to modify, update or discontinue any feature of the API or the Information upon not less than thirty (30) days' prior written notice to the Subscriber, provided that where access to a feature of the API or the Information depends on a Third-Party API that is modified, suspended or discontinued by the applicable Third-Party API Provider, MedAire may modify, suspend or discontinue the affected feature with such shorter notice as is reasonably practicable in the circumstances.
3.5 Where MedAire integrates with a Third-Party API at the request or on behalf of the Subscriber, the Subscriber acknowledges and agrees that:
(a) the Subscriber is the client of, and maintains its own independent contractual relationship with, the applicable Third-Party API Provider, and is solely responsible for the fees, obligations and terms arising under that relationship;
(b) MedAire's role is limited to establishing a technical integration with the Third-Party API on the Subscriber's behalf;
(c) the Subscriber's use of data or services through a Third-Party API constitutes acceptance of the applicable Third-Party API Provider's terms of use, end-user license agreement or other standard terms as in effect from time to time; and
(d) any change to, or discontinuation of, a Third-Party API or the applicable Third-Party API Provider's terms shall not relieve the Subscriber of any obligation under the Agreement, including payment obligations.
(e) to the extent that MedAire enters into, accepts or is otherwise bound by any terms, conditions, policies, acceptable use requirements or other obligations imposed by a Third-Party API Provider in connection with the provision of the Third-Party Integration (collectively, "Third-Party API Terms"), such Third-Party API Terms are accepted by MedAire for and on behalf of the Subscriber, and the Subscriber shall be directly bound by and shall comply with all such Third-Party API Terms as if the Subscriber had entered into them directly with the applicable Third-Party API Provider;
(f) the Subscriber assumes all risk, liability and responsibility arising from or in connection with any Third-Party API Terms, including any breach thereof, and shall indemnify MedAire in accordance with clause 6.6(d) against any claim, loss, liability, damage, cost or expense arising from the Subscriber's failure to comply with any Third-Party API Terms; and
(g) MedAire shall have no liability to the Subscriber for any obligation, restriction, limitation or consequence arising under or imposed by any Third-Party API Terms, and the Subscriber shall have no claim against MedAire in respect of the content, scope, enforceability or effect of any such Third-Party API Terms.
4. Permitted Use and Restrictions
4.1 The Subscriber shall use the API and the Information solely for the purposes set out in clause 3.1 of these API Terms. Any other use, integration, modification, redistribution or commercialization of the Information or the API shall require the prior written approval of MedAire.
4.2 The Subscriber shall not, and shall not permit any third party to: (a) use the API or the Information for any purpose other than integration with the Authorized Application; (b) sublicense, sell, resell, transfer, assign, distribute or otherwise make the API or the Information available to any third party, except as expressly permitted under clause 6.4; (c) access the API in order to build a competitive product or service, or to copy any features, functions or content of the API or the Information; (d) use any bot, script, automated tool or scraping technology to access, query or extract data from the API other than through the methods described in the API Documentation; (e) attempt to exceed the access limits set out in clause 3.2 or otherwise circumvent technical limitations of the API; (f) reverse engineer, decompile, disassemble, modify, adapt or create derivative works of the API or the underlying software, code or systems; (g) remove, obscure or alter any proprietary notices, labels or markings on the Information or the API Documentation; or (h) use the API or the Information in a manner that violates any applicable law, regulation or the terms of the Agreement.
4.3 The Subscriber shall ensure that all persons accessing the Information through the Authorized Application are bound by obligations of confidentiality and use restrictions no less protective of MedAire's interests than those set out in the Agreement and these API Terms.
4.4 The Subscriber shall not cache, store or retain any Information obtained through the API for longer than twenty-four (24) hours, unless a different retention period is specified in the API Documentation or agreed in writing by MedAire. Upon expiry of the applicable retention period, the Subscriber shall promptly delete all cached or stored copies of such Information. This restriction does not apply to Information that is rendered to end users within the Authorized Application at the time of retrieval from the API, provided that such Information is not independently cached, stored or persisted by the Authorized Application beyond the retrieval session.
4.5 MedAire shall have the right, upon not less than ten (10) business days' prior written notice, to audit the Subscriber's use of the API and compliance with the terms of these API Terms, including by requesting access to relevant systems, logs and records. Such audits shall be conducted during normal business hours and shall not unreasonably interfere with the Subscriber's operations. The Subscriber shall cooperate with any such audit and provide all information and access reasonably requested by MedAire. If an audit reveals any material non-compliance, the Subscriber shall promptly remedy such non-compliance at its own cost and shall reimburse MedAire's reasonable costs of the audit.
5. Technical Specifications and Integration
5.1 MedAire shall provide the Subscriber with the API Documentation and an API Access Key upon execution of the applicable Certificate of Subscription and payment of the applicable fees.
5.2 The Subscriber shall be solely responsible for: (a) the development, integration, security, testing, maintenance and discontinuation of the integration of the API into the Authorized Application; (b) ensuring that the Authorized Application and the Subscriber's systems meet the minimum technical requirements specified in the API Documentation; (c) providing the necessary equipment, network connections and infrastructure for access to and use of the API; and (d) promptly implementing any technical updates or changes to the integration as notified by MedAire.
5.3 For avoidance of doubt, the Subscriber is not responsible for the development or maintenance of MedAire's API itself.
5.4 MedAire shall not be responsible for any loss, damage, delay or failure arising from: (a) the Subscriber's failure to implement the integration in accordance with the API Documentation; (b) the Subscriber's failure to provide the necessary equipment, network connections or infrastructure; or (c) any defect, malfunction or incompatibility in the Authorized Application or the Subscriber's systems.
5.5 MedAire may release new versions of the API from time to time. Upon release of a new version, MedAire shall continue to support the immediately preceding version for a period of time (the "Deprecation Period"), unless continued support would pose a security risk or violate applicable law. MedAire shall provide the Subscriber with reasonable prior written notice of any version deprecation, including the applicable Deprecation Period and any migration requirements. The Subscriber shall complete its migration to the current supported version before the expiry of the applicable Deprecation Period. MedAire shall have no obligation to support or maintain any version of the API after the expiry of the applicable Deprecation Period.
5.6 The Subscriber shall: (a) keep all API Access Keys strictly confidential and not disclose them to any unauthorized person or entity; (b) implement and maintain reasonable technical and organizational security measures for all systems that access the API, consistent with industry best practices; and (c) notify MedAire in writing without undue delay, and in any event within twenty-four (24) hours, of any suspected or actual unauthorized access to, or compromise of, any API Access Key or the Information obtained through the API. Upon receipt of such notification, MedAire may immediately revoke the compromised API Access Key and issue replacement credentials at its discretion.
6. Intellectual Property and Confidentiality
6.1 The API, the Provider Data, the API Documentation and all intellectual property rights therein are and shall remain the sole and exclusive property of MedAire. Nothing in these API Terms grants the Subscriber any right, title or interest in or to the API, the Provider Data or the API Documentation, except the limited right of access expressly granted in clause 3. As between the parties, all intellectual property rights in and to the Customer Data are and shall remain the property of the Subscriber. For the avoidance of doubt, MedAire does not claim any right, title or interest in or to Third-Party Data, and all intellectual property rights therein remain with the applicable Third-Party API Provider or other rights holder.
6.2 The Subscriber hereby grants MedAire a non-exclusive, royalty-free, worldwide license to use, process, store and display the Customer Data solely as necessary to provide the API and perform its obligations under the Agreement. The Subscriber represents and warrants that: (a) it has all necessary rights, licenses and consents to transmit the Customer Data through the API; (b) the Customer Data does not infringe the intellectual property rights of any third party; and (c) the transmission and processing of Customer Data through the API complies with all applicable laws and regulations.
6.3 The API, the Provider Data and the API Documentation shall be considered MedAire's confidential and proprietary information, and the Customer Data shall be considered the Subscriber's confidential and proprietary information. Third-Party Data shall not be considered the confidential or proprietary information of MedAire and shall be subject to the terms and conditions imposed by the applicable Third-Party API Provider. Each party shall protect the other party's confidential information in accordance with the confidentiality obligations set out in the Agreement, and shall not use, exploit, sell or disclose such confidential information for its own benefit or the benefit of another without the prior written consent of the disclosing party or unless agreed otherwise in the Agreement.
6.4 Where the Subscriber integrates the API into an application provided or hosted by a third-party platform, the Subscriber shall: (a) obtain MedAire's prior written approval for such integration; (b) ensure that the Third-Party Platform Provider is bound by written obligations of confidentiality and data protection no less protective than those set out in the Agreement and these API Terms; (c) remain fully responsible and liable for any acts or omissions of the Third-Party Platform Provider in connection with the Provider Data and the API, as if such acts or omissions were those of the Subscriber; and (d) ensure that the Third-Party Platform Provider does not use the Provider Data for any purpose other than displaying it within the Authorized Application.
For the avoidance of doubt, the Third-Party Platform Provider shall have no independent right of access to the API or the Provider Data, and all fees and obligations in respect of such access shall remain with the Subscriber. MedAire may revoke its approval of any third-party platform at any time upon written notice to the Subscriber if MedAire reasonably determines that the Third-Party Platform Provider has breached or is likely to breach any of the foregoing requirements, and upon such revocation the Subscriber shall promptly cease the integration with the affected third-party platform. Upon revocation of approval or termination of the Agreement, the Subscriber shall procure that the Third-Party Platform Provider promptly deletes all Provider Data in its possession or control and provides written certification of such deletion to MedAire within ten (10) business days.
6.5 The Subscriber shall not use any Information obtained through the API, or any derivative work, analysis, pattern or learning derived therefrom, for any AI-related activity, including training generative AI systems or developing machine learning models, without prior written consent from MedAire. Any restrictions on artificial intelligence set out in the Agreement apply in full to all Information obtained through the API.
6.6 The Subscriber shall indemnify, defend and hold harmless MedAire and its affiliates, officers, directors and employees from and against any and all claims, losses, liabilities, damages, costs and expenses (including reasonable legal fees) arising out of or in connection with:
(a) any act or omission of the Third-Party Platform Provider in connection with the Provider Data, the API or the API Documentation;
(b) any breach by the Third-Party Platform Provider of any applicable law or any obligation imposed under clause 6.4;
(c) any claim by a third party arising from the Third-Party Platform Provider's use, display, disclosure or handling of the Provider Data;
(d) any claim by a Third-Party API Provider, or any customer or affiliate of a Third-Party API Provider, arising from the Subscriber's use of Third-Party Data or the Subscriber's breach of any obligation that MedAire is required to pass through under its agreement with such Third-Party API Provider; or
(e) any claim arising from data, instructions or requests transmitted through the API by means of any artificial intelligence model, tool or agent used, configured or instructed by or on behalf of the Subscriber.
This indemnification obligation shall survive termination or expiration of the Agreement.
6.7 Where MedAire integrates with a Third-Party API that processes personal data on behalf of or at the instruction of the Subscriber, the Subscriber shall:
(a) ensure that it has obtained all necessary consents, authorizations and legal grounds required for the transmission of such personal data to or through the applicable Third-Party API Provider;
(b) cooperate with MedAire in entering into any data processing agreements or supplementary terms required by applicable data protection law in connection with such Third-Party API; and
(c) indemnify MedAire from and against any claims, losses, liabilities, damages, costs and expenses arising from the Subscriber's failure to comply with applicable data protection laws in connection with personal data transmitted through a Third-Party API.
7. Liability Specific to API Use
7.1 The Information provided through the API is subject to the same limitations, disclaimers and exclusions set out in the Agreement, including any "as is" and "as available" disclaimers and exclusions of warranties.
7.2 Without limitation to the foregoing, MedAire shall not be liable for: (a) any inaccuracy, delay or omission in the Provider Data delivered through the API; (b) any decisions made by the Subscriber or any third party in reliance on the Provider Data obtained through the API; (c) any loss, damage or liability arising from unauthorized access to or use of the API resulting from the Subscriber's failure to safeguard the API Access Key; or (d) any interruption, suspension or discontinuation of the API, whether planned or unplanned, except to the extent caused by MedAire's gross negligence or willful misconduct.
7.3 Except with respect to willful misconduct or gross negligence by MedAire, MedAire's entire liability (whether caused by negligence, indemnity, or otherwise) in connection with the API and the Information shall not exceed the annual Fees paid by the Subscriber to MedAire under the Agreement during the twelve (12) months preceding the date the Subscriber makes a claim against MedAire. For the avoidance of doubt, any liability arising under these API Terms shall be included within, and not in addition to, the general liability cap set out in the Agreement.
7.4 Without limiting clause 3.5, where MedAire integrates with a Third-Party API on behalf of the Subscriber, the Subscriber acknowledges and agrees that:
(a) the availability, accuracy, completeness and timeliness of Third-Party Data are subject to the terms, limitations and disclaimers imposed by the applicable Third-Party API Provider, which are beyond MedAire's control;
(b) MedAire makes no representation or warranty regarding Third-Party Data;
(c) MedAire shall not be liable for any modification, suspension, discontinuation or revocation of access to a Third-Party API by the applicable Third-Party API Provider;
(d) MedAire shall not be responsible or liable for any other act, omission, default, interruption or failure of any Third-Party API Provider or any Third-Party API, including any inaccuracy, delay, suspension or discontinuation of the data or services provided through such Third-Party API;
(e) the Subscriber assumes all risk associated with the use of any Third-Party API and shall have no claim against MedAire arising from or in connection with the performance, non-performance or conduct of any Third-Party API Provider; and
(f) MedAire shall have no obligation to vet, audit or monitor the Third-Party API Provider's compliance with its own terms, security practices or applicable law.
7.5 Neither Party nor any of its Affiliates and their respective directors, officers, employees or agents shall be liable for any damages for lost profits, indirect, special, incidental, consequential, or exemplary damages arising out of or in connection with the API, the Information, the SSO, any Third-Party Integration or these API Terms, including without limitation, punitive, loss of goodwill, loss of data, loss of or interruption to business, loss of use, or any other commercial damages or losses, fees, costs, charges or expenses howsoever arising even if the other Party had been advised of the possibility thereof and regardless of the legal or equitable theory upon which the claim is based. This clause 7.5 applies in addition to, and does not limit, any exclusion or limitation of liability set out in the Agreement.
8. Suspension and Termination of API Access
8.1 Without prejudice to MedAire's other rights under the Agreement, MedAire may immediately suspend or restrict the Subscriber's access to the API, in whole or in part, if: (a) the Subscriber breaches any of the use restrictions set out in clause 4 of these API Terms; (b) the Subscriber exceeds the access limits set out in clause 3.2 and fails to cure such excess within five (5) business days of written notice from MedAire; (c) MedAire reasonably determines that the Subscriber's use of the API poses a security risk to MedAire's systems, data or other subscribers; (d) MedAire is required to do so by applicable law, regulation or order of a competent authority; or (e) any fees payable by the Subscriber remain outstanding for more than thirty (30) days following the due date.
8.2 MedAire shall use reasonable efforts to notify the Subscriber prior to or promptly following any suspension, except where immediate suspension is required under clause 8.1(c) or 8.1(d).
8.3 Any breach by the Subscriber of clauses 3.5, 4, 5.6, 6.3, 6.4, 6.5 or 6.7 of these API Terms shall constitute a material breach of the Agreement.
8.4 Upon termination or expiration of the Agreement or the applicable Certificate of Subscription (for any reason), MedAire shall deactivate the Subscriber's API Access Key and the Subscriber's access to the API shall cease immediately. The Subscriber shall promptly delete all copies of the API Documentation and any cached or stored Information obtained through the API, and shall certify such deletion in writing to MedAire within ten (10) business days of termination.
9. General
9.1 These API Terms are supplemental to and form part of the Agreement.
9.2 MedAire may update these API Terms from time to time by publishing a revised version at the URL referenced in the Certificate of Subscription. MedAire shall provide the Subscriber with not less than thirty (30) days' prior written notice of any material changes to these API Terms. Continued use of the API or SSO service after the expiry of the notice period shall constitute acceptance of the updated API Terms. If the Subscriber does not agree to any material change, the Subscriber may discontinue use of the API and SSO service before the change takes effect.
9.3 These API Terms do not create any rights or obligations independent of the Agreement. The Subscriber's access to the API and SSO service is conditional upon the Agreement being in full force and effect and the Subscriber having an active Certificate of Subscription.
9.4 The governing law and dispute resolution provisions of the Agreement apply to these API Terms.
10. Third-Party Platform Provider
10.1 The Subscriber shall ensure that each Third-Party Platform Provider: (a) has no independent right of access to the API, the Provider Data or the API Documentation; (b) its access to the Provider Data is derived solely from the Subscriber's rights under the Agreement and these API Terms, and is conditional upon MedAire's continuing written approval; and (c) MedAire may revoke such approval at any time in accordance with clause 6.4.
10.2 The Subscriber shall procure that each Third-Party Platform Provider shall: (a) use the Provider Data solely for the purpose of displaying it within the Authorized Application and for no other purpose; (b) not sublicense, redistribute, sell, publish or otherwise make the Provider Data available to any other person or entity; (c) not cache, store or retain any Provider Data for longer than twenty-four (24) hours, unless a different period is specified in the API Documentation; (d) not modify, adapt, reverse engineer, decompile or create derivative works of the Provider Data, the API or the API Documentation; (e) not use any Provider Data, or any derivative work, analysis, pattern or learning derived therefrom, for any AI-related activity, including training generative AI systems or developing machine learning models; and (f) not remove, obscure or alter any proprietary notices, branding or attribution associated with the Provider Data.
10.3 The Subscriber shall procure that each Third-Party Platform Provider shall: (a) treat all Provider Data and API Documentation as confidential information of MedAire and protect it with at least the same degree of care it uses for its own confidential information, and in any event no less than a reasonable standard of care; (b) implement and maintain reasonable technical and organizational security measures for all systems that access or store Provider Data, consistent with industry best practices; and (c) notify the Subscriber and MedAire in writing without undue delay, and in any event within twenty-four (24) hours, of any suspected or actual unauthorized access to, breach of, or compromise of the Provider Data.
10.4 The Subscriber shall procure that each Third-Party Platform Provider complies with all applicable laws and regulations in connection with its access to and use of the Provider Data, including all applicable data protection and privacy laws. Where the Provider Data includes personal data, the Subscriber shall procure that the Third-Party Platform Provider processes such data only in accordance with the Subscriber's instructions and applicable law, and does not transfer such data outside the jurisdiction(s) approved by MedAire without MedAire's prior written consent.
10.5 MedAire makes no representations or warranties to the Third-Party Platform Provider regarding the Provider Data, and the disclaimers and exclusions set out in clause 7 apply in full to the Third-Party Platform Provider's use of the Provider Data.
10.6 The Subscriber shall procure that each Third-Party Platform Provider complies with all applicable export control laws, trade sanctions and restrictive measures in connection with its access to and use of the Provider Data. The Subscriber shall procure that the Third-Party Platform Provider does not, directly or indirectly, export, re-export, transfer or make available any Provider Data to any country, entity or person subject to applicable trade sanctions or export restrictions. The Subscriber shall monitor the sanctions status of each Third-Party Platform Provider and shall immediately suspend and revoke such third party's access to the Provider Data if the Third-Party Platform Provider, or any of its principals, becomes the subject of any applicable trade sanction, export restriction or designated persons list. The Subscriber shall promptly notify MedAire in writing of any such suspension or revocation.
