Introduction
These Terms of Service (the "Terms") form a legally binding agreement between you (the "Customer", "you") and Objective Labs LTD, a company registered in England and Wales under company number 17303955, whose registered office is at 124 City Road, London EC1V 2NX ("SCIM.Ninja", "we", "us", "our").
These Terms govern your access to and use of the SCIM.Ninja service described in section 03 (the "Service"). By creating an account, clicking to accept these Terms, or using the Service, you confirm that you accept these Terms and that the individual accepting them has authority to bind the organisation on whose behalf they are acting.
The Service is intended for businesses and organisations only. It is not intended for consumers, and you confirm that you are entering into these Terms in the course of a business.
Definitions
Capitalised terms used in these Terms have the meanings set out below.
- "Account" — the account you register to access the Service.
- "Active User" — a user that is shown as active (or the equivalent status) in the Connected Application's API response. Where the API does not return such a status attribute, every user returned by the API is treated as an Active User.
- "Connected Application" — a third-party software application that you connect to the Service so that it can be provisioned via SCIM.
- "Customer Data" — all data you, your Users, or your Identity Provider submit to or make accessible through the Service, including the personal data of the individuals you provision.
- "Credentials" — the API keys, tokens, usernames, passwords, or other authentication details you provide so that the Service can connect to a Connected Application.
- "Identity Provider" or "IdP" — your identity system (for example Okta, Microsoft Entra ID / Azure AD, or Google Workspace) used to drive provisioning.
- "Integration" — the SCIM integration that we build or attempt to build for a Connected Application.
- "Privacy Policy" — our privacy policy available at scim.ninja/privacy (or such other URL as we notify).
- "DPA" — our Data Processing Agreement at scim.ninja/dpa, which forms part of these Terms where we process personal data on your behalf.
- "Users" — the individuals you authorise to access your Account (for example Owner, Admin, and User roles).
The service
SCIM.Ninja provides SCIM-based user provisioning for enterprise applications that do not natively support SCIM. The Service sits between your Identity Provider and one or more Connected Applications and exposes a standardised SCIM endpoint for each Connected Application, allowing user lifecycle events (create, update, deactivate, delete) to be synchronised.
To deliver an Integration, our team reviews the API of the Connected Application you nominate and builds the connection on your behalf. The scope, features, and limitations of each Integration depend on the capabilities of the underlying application's API.
We may improve, change, add to, or remove features of the Service from time to time. We will not make changes that materially reduce the core functionality you are paying for without reasonable notice, except where the change is required for legal, security, or technical reasons.
Eligibility & accounts
To use the Service you must register an Account and provide accurate, current, and complete information. You are responsible for:
- keeping your Account credentials confidential and for all activity under your Account;
- ensuring that each of your Users complies with these Terms;
- assigning and managing the roles and permissions of your Users (Owner, Admin, User); and
- notifying us promptly if you suspect any unauthorised access to your Account.
You must be authorised to enter into these Terms on behalf of your organisation. The Owner of the Account is responsible for the Account and for the conduct of all Users.
Building your integration
Estimated timing. We aim to build and validate each Integration within approximately 24–48 hours of receiving the information we need. This is a target, not a guarantee or a contractual commitment. Delivery times vary, and an Integration may take materially longer — or may not be possible at all — depending on factors including the complexity of the Connected Application's API, the completeness of the information and Credentials you provide, our resourcing and queue at the time, and limitations or changes in the third-party application.
No guarantee of feasibility. Some applications cannot be integrated, for example where the application has no suitable user-management API, where its API does not support the operations SCIM requires, or where the application's own terms prohibit the integration. We will use reasonable efforts to assess feasibility, but we do not warrant that any given Integration can be built. Where we determine that an Integration cannot be built, we will tell you, and you will not be charged for that Connected Application (see section 08).
Your cooperation. Building an Integration depends on you providing accurate information, valid Credentials, and timely responses. Delays caused by incomplete or inaccurate information are not our responsibility.
Withdrawing from onboarding. Either party may withdraw from onboarding at any time before billing begins for the relevant Connected Application, on written notice and without charge or liability, including where we are unable to obtain the information or cooperation we need to complete the Integration. Withdrawal for one Connected Application does not affect any other Connected Application or the rest of your Account.
Credentials & acceptable use
Your authorisation and licence to us
To provide the Service, we need to use the Credentials you supply to connect to, test, operate, and monitor each Connected Application. By providing Credentials and using the Service, you:
- grant us a non-exclusive, royalty-free licence to access and use the Credentials and the Connected Application's API solely to build, test, operate, maintain, and support your Integration and the Service, and to measure usage for billing (including counting the number of provisioned users);
- represent and warrant that you have full right and authority to provide those Credentials and to authorise us to use them for these purposes, and that doing so does not breach any agreement between you and the operator of the Connected Application, your Identity Provider, or any third party; and
- acknowledge that you remain responsible for the security of your own systems, your IdP, and your Connected Applications, and for complying with the terms of service of any third party whose application you connect.
You are solely responsible for the consequences of provisioning, modifying, deactivating, or deleting any user account through the Service.
Acceptable use
You must not, and must not permit any User or third party to:
- use the Service to provision, manage, or access any system unlawfully, without authorisation, or in breach of any third party's rights or terms;
- resell, sublicense, rent, lease, or otherwise make the Service available to any third party except as expressly permitted in these Terms;
- use the Service to transmit malicious code, attempt to gain unauthorised access to any system, or interfere with or disrupt the Service;
- reverse engineer, decompile, or attempt to derive the source code of the Service, except to the extent this restriction is prohibited by law;
- use the Service in breach of any applicable law or regulation, including data-protection and export-control laws; or
- misrepresent your authority to provide Credentials or to provision the individuals you submit.
We may suspend or terminate access for breach of this section in accordance with section 11.
Accuracy of data and provisioning instructions
The Service acts on the data and the provisioning instructions (such as create, update, deactivate, and delete events) that you and your systems — including your Identity Provider — supply to it. You are solely responsible for the accuracy, completeness, and currency of that data and for the correctness of those instructions.
We perform provisioning based on the data and instructions received. We do not independently verify, correct, or validate them. To the fullest extent permitted by law, we are not liable for any user-management outcome — including a user being created, modified, granted or denied access, deactivated, or deleted incorrectly, or not at all — that results from data or instructions that are inaccurate, incomplete, out of date, duplicated, mis-mapped, or otherwise erroneous, or from a misconfiguration of your Identity Provider or Connected Application. You are responsible for reviewing the results of provisioning and for maintaining independent means of managing user access.
Your indemnity to us
You shall indemnify and hold harmless us, our officers, employees, and agents from and against any claim brought by a third party, and all resulting losses, damages, liabilities, fines, costs, and expenses (including reasonable legal fees), to the extent arising out of or in connection with:
- the Credentials you provide, including any claim that our use of those Credentials in accordance with these Terms was unauthorised or breached an agreement between you and the operator of a Connected Application, your Identity Provider, or any other third party;
- Customer Data, including any claim that you lacked a lawful basis or the necessary rights to provide it to us or to instruct the processing carried out through the Service; or
- the provisioning instructions issued through the Service by you, your Users, or your systems (including your Identity Provider),
except to the extent the claim results from our breach of these Terms or the DPA. We will notify you promptly of any such claim, allow you to conduct the defence and settlement of it (provided no settlement imposes any obligation or admission on us without our consent), and give you reasonable cooperation at your expense.
Free trial
Where offered, you receive a 7-day free trial, beginning when your Integration goes live. No payment card is required to start, and you are not charged during the trial. What happens at the end of the trial — including when your first payment is taken — is governed by section 08 (see "When billing starts"), and you can cancel before the trial ends to avoid any charge. We may change or withdraw trial offers at any time for new sign-ups.
Fees, billing & payment
Pricing
Fees are charged on a subscription basis and are tiered according to the number of Active Users in the Connected Application (currently the bands 1–50, 51–200, 201–1000, and 1000+). Current pricing is shown during onboarding and at scim.ninja/pricing. We measure the number of Active Users through the Connected Application's API for billing purposes.
Changes in the number of users (tier)
The number of users in a Connected Application may change during your subscription. We monitor the number of Active Users through the Connected Application's API.
If we detect that the number of Active Users in a Connected Application has risen above the tier you are subscribed to, we will notify you. You will then have 14 days from that notice to either (a) reduce the number of Active Users to within your current tier or (b) move to the tier that matches your actual usage. If you do neither within those 14 days, we may suspend and cancel your subscription for the affected Connected Application in accordance with section 11. Cancellation of one Connected Application does not affect your other Connected Applications.
If your user count falls into a lower tier, you may request a downgrade; downgrades take effect from your next Renewal Date. We do not provide refunds or credits for a reduction in users within a billing period, except as set out in section 09 or as required by law.
When billing starts
You are not charged to begin onboarding, and no payment card is required upfront. Billing begins when the Integration is confirmed as working (defined below). Where a free trial applies under section 07, billing instead begins at the end of the 7-day trial period — but in no case before the Integration is confirmed as working, so if you have reported a material failure that is not yet resolved, billing does not begin until it is. If we determine that an Integration cannot be built, you will not be charged for that Connected Application.
An Integration is confirmed as working on the earliest of the following:
- you confirm to us (by email or within the Service) that the Integration works; or
- 7 days have passed since we notified you that the Integration is live, without you reporting to us a material failure of the Integration.
If you report a material failure of the Integration within that 7-day period, the Integration is not treated as confirmed until we have resolved the failure, at which point a fresh 7-day period begins from our notice that it is resolved. Reporting an issue that does not materially prevent the Integration from performing its core provisioning function does not delay confirmation.
Billing cycle and renewal
Subscriptions are billed in advance on a monthly or, where you select one, an annual basis, and renew automatically at the end of each billing period (the "Renewal Date") until cancelled in accordance with section 10.
Changes to pricing
We may change the fees for your subscription from time to time. We will give you at least 30 days' notice of any such change (for example by email or within the Service), and the change will take effect from your next Renewal Date falling after that notice period. If you do not accept the new fees, you may cancel under section 10 before the change takes effect; continuing to use the Service after it takes effect constitutes acceptance of the new fees. This does not apply to a change in the fees payable because your usage has moved to a different tier, which is dealt with above.
Payment processing and merchant of record
Payments are processed through a third-party payment provider. Depending on the arrangement applicable to your Account, the seller and merchant of record will be either Paddle or Stripe:
- Where your order is processed by Paddle: Our order process is conducted by our online reseller Paddle.com. For those orders, Paddle.com is the Merchant of Record, provides all customer service inquiries, and handles returns. Your payment is made to Paddle, and Paddle's buyer terms also apply to the transaction. We remain responsible for providing the Service under these Terms.
- Where your order is processed by Stripe: Objective Labs LTD is the merchant of record and contracts directly with you for payment, and we (not Paddle) handle billing inquiries and returns for that transaction.
We will indicate the applicable provider at the point of purchase. You authorise the applicable provider to charge your selected payment method for all fees due, and you are responsible for keeping your payment details valid and up to date.
Taxes
Unless stated otherwise, fees are exclusive of VAT and any other applicable taxes, which you are responsible for paying in addition, except where the merchant of record (for example Paddle) is responsible for collecting and remitting such taxes.
Late or failed payment
If a payment fails or is overdue, we may suspend the Service in accordance with section 11 until payment is made.
Refunds
You may request a refund of a payment within 14 days of that payment. Where your order was processed by Paddle, refunds are handled by Paddle as Merchant of Record under its returns process; where your order was processed by Stripe, contact us at legal@scim.ninja. Refunds apply to the payment in question and do not by themselves cancel your subscription; to stop future charges you must also cancel under section 10. Because a refund returns the fees for the period that payment covered, we are under no obligation to continue providing the Service for that period: where you receive a refund, we may suspend or terminate your access to the Service (or to the affected Connected Application) in accordance with section 11, treating the refunded period as unpaid. Any such suspension or termination does not affect your rights in your Customer Data, which we will continue to handle in accordance with the DPA. This 14-day refund right applies regardless of the reason for cancellation, including where we suspend or cancel the Service for your breach or failure to act under section 11. This refund right is in addition to, and does not limit, any non-excludable rights you have under applicable law.
Cancellation
You may cancel your subscription at any time. To avoid being charged for the next billing period, you must give us notice of cancellation before the next Renewal Date (whether your plan is monthly or annual). Cancellation takes effect at the end of the then-current billing period, and you retain access until that date. We do not provide pro-rata refunds for partial periods on cancellation, except as required by section 09 or by law.
Suspension & termination
We may suspend or terminate your access to all or part of the Service if:
- you materially breach these Terms (including the acceptable-use and authorisation obligations in section 06) and, where the breach is capable of remedy, fail to remedy it within a reasonable period after notice;
- you fail to bring your usage within tier or adjust your tier following an overage notice under section 08;
- a payment is overdue, or you have been refunded a payment for the period in question (see section 09);
- we reasonably believe your use poses a security risk, may harm us or others, or may expose us to legal liability; or
- we are required to do so by law.
Where practicable and lawful, we will give notice before suspending. You may terminate by cancelling under section 10.
No refund where we suspend or cancel for your breach or failure to act. Where we suspend or cancel the Service, or any Connected Application, because of your breach of these Terms or your failure to act (including a failure to bring your usage within tier or adjust your tier following an overage notice under section 08), no refund or credit is due for any unused or remaining part of the then-current billing period, except that the 14-day refund right in section 09 continues to apply. This does not affect any right you have that cannot be excluded by law.
On termination: your right to use the Service ends; we will cease processing Customer Data except as needed to wind down the Service and as set out in the DPA; and any provision that by its nature should survive termination (including the indemnity in section 06 and sections 11 to 22) will survive.
Data protection
In providing the Service, we process the personal data of the individuals you provision on your behalf and on your instructions. For that personal data, you are the controller and we are the processor (or sub-processor, where applicable). This processing is governed by our Data Processing Agreement (the "DPA"), available at scim.ninja/dpa, which is incorporated into and forms part of these Terms. These Terms are the "Principal Agreement" referred to in the DPA. In the event of any conflict between the DPA and the rest of these Terms on matters relating to the processing of personal data, the DPA prevails.
Our handling of personal data is described in our Privacy Policy. Customer Data, including the personal data we process to deliver the Service, is hosted primarily in the United States. International transfers of personal data are addressed in the DPA (and summarised in our Privacy Policy) and are intended to rely on the UK Extension to the EU–US Data Privacy Framework (the "UK–US data bridge") and/or other appropriate safeguards as set out in the DPA.
You are responsible for ensuring you have a lawful basis to provide the Customer Data to us and to instruct the provisioning carried out through the Service.
Confidentiality
Each party may receive confidential information from the other. Each party will keep the other's confidential information confidential, use it only to perform these Terms, and protect it with reasonable care. This does not apply to information that is or becomes public through no fault of the receiving party, was already lawfully known, is independently developed, or is required to be disclosed by law (with notice where permitted). Credentials and Customer Data are your confidential information.
Intellectual property
We (and our licensors) own all intellectual property rights in the Service, including the SCIM.Ninja software, endpoints, design, and documentation, and in any Integrations and tooling we build. Nothing in these Terms transfers ownership of the Service to you. We grant you a limited, non-exclusive, non-transferable right to use the Service during your subscription, subject to these Terms.
You retain all rights in your Customer Data. You grant us the rights to process Customer Data as needed to provide the Service and as set out in section 06 and the DPA. We may use anonymised and aggregated data that does not identify you or any individual to operate and improve the Service.
Third-party services
The Service interoperates with third parties, including your Identity Provider, the Connected Applications you nominate, our hosting and backend providers, and our payment providers (Stripe and/or Paddle). We are not responsible for those third parties, their availability, or their terms, and your use of them is governed by their own agreements. Changes a third party makes to its API or terms may affect or disable an Integration, and we are not liable for the consequences of such third-party changes.
If a live Integration stops working due to a change outside our control — for example, the Connected Application withdraws, restricts, deprecates, or changes its API, alters its authentication, or changes its terms in a way that prevents the Integration from functioning — the following applies:
- we will use reasonable efforts to notify you and to assess whether the Integration can be repaired or rebuilt;
- where repair is feasible, we will use reasonable efforts to do so, but we do not guarantee that it will be possible or within any particular timeframe, and substantial rework may be treated as a new Integration; and
- where we determine that the Integration cannot be restored within a reasonable period, either party may terminate the subscription for the affected Connected Application on notice. From the next billing period after such termination you will not be charged for that Connected Application. Termination of one Connected Application does not affect your other Connected Applications.
We are not liable for any loss arising from an Integration ceasing to function because of a third-party change of this kind, and no refund is due for periods during which an Integration was affected, except as set out in section 09 or as required by law.
Disclaimers
The Service is provided "as is" and "as available". To the fullest extent permitted by law, we exclude all implied warranties, conditions, and terms, including as to merchantability, satisfactory quality, fitness for a particular purpose, and non-infringement.
We do not provide any uptime or service-level guarantee. We do not warrant that the Service will be uninterrupted or error-free, or that any Integration will be built within any particular time or at all. We implement appropriate technical and organisational measures designed to protect Customer Data and Credentials, as described in our Privacy Policy and the DPA; however, no service can be guaranteed to be completely secure, and we do not warrant that the Service will be free from all vulnerabilities or unauthorised access. You are responsible for maintaining your own backups and independent means of managing user access.
Nothing in these Terms excludes any warranty or right that cannot be excluded under applicable law.
Limitation of liability
Nothing in these Terms limits or excludes either party's liability for: death or personal injury caused by negligence; fraud or fraudulent misrepresentation; your indemnity obligations under section 06; or any other liability that cannot be limited or excluded by law.
Subject to the paragraph above:
- Neither party is liable for any indirect or consequential loss, or for loss of profits, revenue, business, goodwill, anticipated savings, or data, in each case whether arising in contract, tort (including negligence), or otherwise.
- Our total aggregate liability arising out of or in connection with these Terms and the Service, whether in contract, tort (including negligence), or otherwise, is limited to the greater of (a) the total fees paid by you for the Service in the twelve (12) months immediately before the event giving rise to the claim, or (b) £215 (two hundred and fifteen GBP).
Changes & custom agreements
We may update these Terms from time to time. If we make a material change, we will give you reasonable notice (for example by email or in the Service) before it takes effect. Your continued use of the Service after the change takes effect constitutes acceptance. If you do not accept a material change, your remedy is to cancel under section 10 before the change takes effect.
Where you and we have entered into a separate, signed agreement for the Service (for example an enterprise contract, order form, or master services agreement), the terms of that agreement prevail over these Terms to the extent of any conflict, for that Customer.
Force majeure
We are not liable for any failure or delay in performing our obligations caused by events beyond our reasonable control, including failures of third-party services, internet or hosting outages, acts of government, or other force-majeure events.
General
- Assignment. You may not assign or transfer these Terms without our consent. We may assign these Terms to an affiliate or in connection with a merger, acquisition, or sale of assets.
- Notices. We may give notices by email to your Account address or within the Service. You should send legal notices to legal@scim.ninja / Objective Labs Ltd., 124 City Road, London EC1V 2NX.
- Entire agreement. These Terms, together with the Privacy Policy, the DPA, and any applicable signed agreement, are the entire agreement between us regarding the Service and supersede prior discussions.
- Severability. If any provision is found unenforceable, the rest remains in effect.
- Waiver. A failure to enforce a provision is not a waiver of it.
- Publicity. We may identify you as a customer and use your name and logo in our marketing materials and customer lists. You may opt out at any time by emailing support@scim.ninja. We will only use any quote, testimonial, or case study featuring you with your prior written approval. This applies notwithstanding section 13 (Confidentiality).
- Third parties. A person who is not a party to these Terms has no rights under the Contracts (Rights of Third Parties) Act 1999 to enforce them.
Governing law
These Terms and any dispute or claim arising out of or in connection with them (including non-contractual disputes) are governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Contact us
If you have any questions about these Terms, please get in touch:
Objective Labs LTD
124 City Road, London EC1V 2NX
Company number: 17303955
Email: legal@scim.ninja