data licensing terms
Data Licensing Terms.
These terms set out what you may do with the data you obtain from PeppolStatus. They form part of your agreement with us together with the Terms of Service. The guiding principle is simple: record‑level data is licensed, the value you build on it is yours. Use the records inside your own products freely, but do not republish the dataset itself.
Last updated 2026-08-17
1. What these terms cover
"Data" means the information you obtain from the Service. That comes through the app console, the REST API, the MCP server, webhooks, or agreed exports. It includes Peppol network measurements (uptime, incidents, certificates, change events), the participant directory, and registry‑enriched company facts sourced from official business registers.
Two categories matter throughout these terms:
- Record‑level data. These are individual records as delivered by the Service: a participant, a host, a company fact, an event.
- Aggregates and derived works. This is anything you compute from the data: statistics, scores, rankings, reports, analytics, models, and other results that do not reproduce the underlying records.
One grant for every tier. All plans, free and paid, carry the same data licence. Tiers differ only in which endpoints they unlock and their rate limits.
2. Your licence
During your subscription we grant you a non‑exclusive, non‑transferable, worldwide licence to:
- Use the data internally. Use it in your own systems, analyses, monitoring, and business processes.
- Display embedded records. Show individual records or small extracts inside your own product or service, as part of functionality you provide to your users.
The licence does not permit bulk redistribution: you may not publish, sell, or otherwise make available the dataset or substantial parts of it as such. That covers a file, a feed, an API, or a public database.
3. Derived works
You may create and commercialise derived works (reports, scores, market analyses, aggregates, dashboards, and analytics built on the data) without restriction and without further payment to us. Derived works are yours.
One limit applies: no substitute products. You may not offer a dataset, feed, or API whose main value is the PeppolStatus data itself. That is a product a customer could use instead of subscribing to PeppolStatus or instead of the underlying registries. The test is what your product adds: analysis, judgment, and integration are fine; re‑serving the records is not.
4. Caching and freshness
You may cache record‑level data for up to 30 days. After that, re‑fetch the record from the Service or delete your copy. This keeps stale registry facts (company names, addresses, statuses that change upstream) from living on in your systems.
Purge on notice. When we notify you that specific records must be removed or masked (for example because a company has objected to the use of its register data, a French registry record has become non‑diffusible, or a participant has been erased from the Peppol Directory), you must delete or mask those records from your caches and systems within 7 days.
Aggregates and derived works that no longer contain record‑level data are exempt from both the 30‑day window and purge notices.
5. Attribution
Registry‑enriched records carry source‑and‑date attribution as metadata. Examples include the Belgian Crossroads Bank for Enterprises (KBO/BCE, FPS Economy), the French Sirene register (INSEE, www.insee.fr), the Norwegian Enhetsregisteret (Brønnøysundregistrene), the Swedish Bolagsverket and SCB bulk files or the Finnish Business Information System (PRH/YTJ), each with the date of the underlying data. When you display or republish an enriched record, you must preserve that upstream attribution with it.
Crediting PeppolStatus as your source is encouraged but not required.
6. Upstream obligations that travel with the data
Parts of the data originate from official sources whose conditions bind us. Through these terms, they bind you too. Regardless of anything else in these terms, you must not:
- Use personal data for direct marketing. Where records identify natural persons (for example sole traders or company officers), you may not use that personal data for direct marketing or prospection. This ban comes from the KBO/BCE licence and from French law for opted‑out Sirene registrants, and it flows down to you and to anyone you pass the data to.
- Distort registry facts. Do not alter register data in a way that changes its meaning.
- Resell raw upstream files. The raw KBO/BCE, Sirene, Enhetsregisteret, Bolagsverket, SCB and PRH/YTJ source files are licensed to us and cannot be sublicensed; what you receive from the Service are enriched records, not the registries themselves.
- Ignore masking status. Records we mask or suppress (non‑diffusible French registrants, suppressed contact details from the Peppol Directory) must stay masked in your systems; do not attempt to restore or re‑identify them.
- Imply endorsement. Do not suggest that INSEE, the Belgian FPS Economy, Brønnøysundregistrene, Bolagsverket, SCB, PRH, OpenPeppol, or any other source endorses you or your product. PeppolStatus itself is not affiliated with or endorsed by any of them.
Norwegian company records carry a lighter obligation. The Enhetsregisteret data is published under the Norsk lisens for åpne data (NLOD 2.0), which allows reuse, including commercial reuse, and sets no purpose limit and no direct‑marketing carve‑out of its own. What it does require is attribution: keep the line Contains data from Brønnøysundregistrene (Enhetsregisteret), licensed under NLOD with any Norwegian record you display or republish. Data protection law still applies to records that identify a natural person, such as a sole proprietor.
Finnish company records carry a comparable obligation. The Business Information System bulk file is published by Patentti- ja rekisterihallitus (PRH) under CC BY 4.0, free to reuse, including commercial reuse, with no purpose limit. What it asks for is attribution: keep the line Contains data from the Finnish Business Information System (PRH/YTJ), licensed under CC BY 4.0 with any Finnish record you display or republish. A Finnish private trader (yksityinen elinkeinonharjoittaja) is a natural person, and PRH withholds those personal details from the open data, so no personal name reaches the Service for us to pass on.
Swedish company records carry a comparable obligation. The Bolagsverket and SCB bulk files are published as EU high-value datasets (värdefulla datamängder), free to reuse, including commercial reuse, with no purpose limit and no direct‑marketing carve‑out of their own. What they ask for is attribution: keep the line Contains data from Bolagsverket and SCB (värdefulla datamängder) with any Swedish record you display or republish. A Swedish sole trader (enskild näringsidkare) is a natural person, so data protection law applies to those records and we publish no personal name for them at all.
7. AI and machine use
Inference is fully allowed. You may use the data with AI systems at inference time (agents, MCP clients, retrieval‑augmented generation, copilots, and answer engines) under the same rules as any other use.
Training is limited to aggregates. You may train or fine‑tune models on aggregates and derived features computed from the data. Training that embeds record‑level data into model weights requires our prior written permission. Ask us at legal@e-invoice.be.
8. When your subscription ends
When your subscription ends, delete cached record‑level data within 30 days. Aggregates and derived works survive: everything you computed from the data remains yours, perpetually, under these terms.
9. Changes, law, and contact
These terms change the way the Terms of Service change (clause 11 there), and share their governing law and venue: Belgian law, Dutch‑language courts of Brussels. Questions about what a licence permits (or requests for a broader grant) go to legal@e-invoice.be.