Legal

Terms of Use

These Terms are a contract between you and GR Digital, the company that operates Dcision. Please read them carefully: by creating an account or calling the API, you agree to them.

1.Who we are and this agreement

Dcision (“Dcision”, “we”, “us”) is a Decision as a Service platform operated by GR Digital, a company based in Brazil. These Terms of Use (“Terms”) govern your access to and use of the website at https://dcision.io, the app at https://app.dcision.io, the API at https://api.dcision.io, the documentation at https://docs.dcision.io and related services (together, the “Service”).

Operator details: legal name GR Negócios Digitais; CNPJ 29.691.265/0001-65; registered office Av. Luiz Boiteux Piazza, 1302, Sala 13, Florianópolis/SC, 88056-682.

By creating an account, signing in or using the Service, you agree to these Terms and to our Privacy Policy. If you use the Service on behalf of a company or another organization, you confirm that you are authorized to accept these Terms for it, and “you” refers to that organization.

You must be at least 18 years old and able to enter into a binding contract to use the Service.

2.The Service

Dcision lets you define decisions as versioned schemas (a JSON state, questions and policies), deploy them and execute them through the API, which returns typed results such as choices, scores, probabilities and a policy action.

Decisions are executed by a decision engine. By default we use the Jev engine (TypeSafe System One), called directly on TypeSafe's API with our platform credentials. You can connect your own provider keys instead (see “Your own engine keys (BYOK)”).

You can also attach destinations to a decision: per-outcome actions that Dcision runs on your instructions, such as webhooks, API calls, workflows, LLM or agent replies, fixed replies, or functions in your code (see “Destinations”).

The Service evolves over time. We may add, change or remove features. Features labeled beta, preview or Genesis are provided for evaluation and may change or end at any time.

3.Accounts and workspaces

You sign up with Google or with a 6-digit code sent to your e-mail, and you can also set a password. Your first sign-in creates your account and a free Genesis workspace, unless you join a workspace you were invited to.

A workspace can have several members, each with a role: Owner, Admin, Member or Viewer. Owners and admins can invite people by e-mail; invitations expire after 7 days. You can belong to several workspaces. The owner manages billing, can transfer ownership and can delete the workspace.

Keep your account information accurate and your sign-in methods secure. You are responsible for all activity in your account and in the workspaces you own or administer, including the actions of members you invite.

Tell us immediately at security@dcision.io if you suspect unauthorized access to your account or workspace.

4.API keys

API keys (starting with dcs_live_ or dcs_test_) authenticate API calls on behalf of a workspace. The full key is shown only once, when it is created; we store only a hash of it.

Keep your keys secret. Do not embed them in client-side code, mobile apps or public repositories, and revoke a key in the app as soon as you suspect it was exposed. You are responsible for all usage made with your keys, including usage billed under your plan.

Each plan has rate limits and quotas. We may throttle, suspend or revoke keys used in breach of these Terms or in a way that threatens the stability or security of the Service.

5.Acceptable use

You agree not to use the Service, directly or indirectly, to:

  • break the law or infringe the rights of others, including privacy, data protection, intellectual property and consumer rights;
  • process personal data without a valid legal basis, or send special categories of personal data that your purpose does not require;
  • commit or facilitate fraud, deception, spam, harassment, unlawful discrimination or unlawful surveillance;
  • distribute malware, or attack, probe, scan or overload the Service or any other system;
  • configure destinations that send unsolicited messages or call systems you are not authorized to use;
  • circumvent rate limits, quotas, billing, security or access controls, or share accounts to avoid plan limits;
  • reverse engineer, decompile or copy the Service, except where the law expressly allows it;
  • resell the Service or offer it to third parties as a standalone product without our written agreement;
  • carry out practices prohibited by applicable artificial intelligence regulation, or violate applicable sanctions and export control laws.

We may investigate suspected violations and suspend or limit the Service where necessary to protect users, third parties or the Service.

6.Automated and consequential decisions

Decision outputs are generated automatically and can be wrong. They are not professional advice and do not replace human judgment.

If you use the Service to support decisions with legal or similarly significant effects on people — for example about credit, employment, housing, insurance, healthcare, education, legal matters or access to essential services — you are solely responsible for having an appropriate legal basis, informing the people affected, providing meaningful human review and a way to contest the decision, testing for errors and bias, and complying with applicable law, including the LGPD (Brazil), the GDPR (European Union) and AI-specific regulation.

7.Your data

“Customer Data” means the states you send to the API, your decision schemas, the outputs the Service returns to you and the data your destinations send and receive. As between you and us, you own your Customer Data.

You grant us a limited license to host, copy, process and transmit Customer Data only as needed to provide, secure and support the Service, as described in the Privacy Policy. We do not sell Customer Data and we do not use it to train machine learning models.

Execution logs record metadata about each call, such as status, latency and engine. By default they also store the inputs (state) and outputs of each call; you can turn this off per decision (storeInput and storeOutput). Logs are deleted at the end of your plan's retention period, or of a shorter period you set.

You are responsible for the lawfulness of the Customer Data you send, including the rights, notices and consents needed to send it to us and to the engine provider. For personal data inside Customer Data, you act as controller and we act as processor (operator, under the LGPD). Enterprise customers can request a data processing agreement at legal@dcision.io.

8.Your own engine keys (BYOK)

You can connect your own keys for supported providers (currently TypeSafe, OpenRouter and Vercel AI Gateway). We encrypt them with AES-256-GCM, never show them again in full and use them only to execute your workspace's decisions.

When you use your own keys, the decision state is sent to the provider you chose under your own agreement with that provider. You are responsible for that agreement, including its fees, limits, data handling and availability. We are not responsible for charges, outages or changes on the provider's side.

Decisions executed with your own keys still count toward your plan's usage.

9.Destinations

Destinations are per-outcome actions you attach to a decision: webhooks, API calls, workflows, LLM or agent replies, fixed replies, or functions in your code. When an execution matches a destination, Dcision runs it on your instructions and sends the data you configured: webhooks and workflows receive the decision's outcome and the parameters you map (the state is not included unless you map it); API calls send the request you write; LLM and agent replies send your instructions and an input that, by default, is the decision's state. Fixed replies are rendered by Dcision, and function destinations are returned for your own code to run.

You are responsible for the destinations you configure: being authorized to call each endpoint, the data you send to it, the secrets you store for it, and the terms of any third-party service it uses — such as your LLM provider (OpenRouter or Vercel AI Gateway, used with your own key), your agent or a workflow tool. Those services act under your agreements with them, and we are not responsible for their availability, charges, outputs or data handling.

Webhooks, API calls, workflows and asynchronous agent hand-offs are delivered at least once, with retries for about 7 hours, but delivery is not guaranteed: an endpoint can be unreachable or reject a request. LLM and synchronous agent replies are requested while the decision runs and can fail without failing the decision. Calls to private or internal network addresses are blocked, and webhooks and agent requests are signed so that you can verify they come from Dcision.

10.Plans, billing and credits

Plans, prices and limits are listed on our pricing page and in the app. Prices are in US dollars unless the checkout shows another currency — customers in Brazil are charged in Brazilian reais — and taxes are added where applicable.

  • Genesis is free and includes 1,000,000 decisions per month. Decisions above that volume are paid with prepaid credits, as described below; without credits, they are rejected (HTTP 402) until the next calendar month (UTC), until you add credits or until you upgrade.
  • Paid plans (Developer and Growth) are billed in advance for each monthly or annual period through our payment processor, Stripe. The annual base price is 20% lower; prices per million decisions paid with credits stay the same.
  • Credits: decisions above the volume included in your plan are paid from your workspace's prepaid credit balance, at that plan's price per million decisions. Credits are bought by card through Stripe, in your workspace's billing currency. Promotional credits, such as the bonus for adding a card or credits from a voucher, expire on the date shown in the app (the card bonus, 90 days after it is granted) and are used before paid credits; paid credits do not expire. Usage is charged to the balance shortly after it happens, so calls already running when the credits run out are still charged and can leave a small negative balance, which your next purchase covers. Without credits, calls above the included volume are rejected (HTTP 402).
  • Automatic recharge and spend cap: the workspace owner may turn on automatic recharge, explicitly authorizing us to charge the saved card the chosen amount whenever the available credit falls below the chosen threshold. The owner can turn it off at any time on the Billing page, and a declined card pauses it. The owner may also set a spend cap per billing period: once the credit spending of the period reaches it, calls above the included volume are rejected (HTTP 402) until the next period or until the cap is raised.
  • A billable decision is a successful API call. Playground runs and calls that end in an error are not billed.
  • Upgrades take effect immediately, with a prorated charge. Downgrades take effect at the end of the current period.
  • Enterprise plans are governed by a separate written agreement.

We may change prices or plan limits. For paid plans, changes apply from your next billing period, and we will notify you at least 30 days in advance.

If a payment fails, your subscription may become past due. If payment is not completed after the retries of our payment processor, the subscription is canceled and the workspace returns to the Genesis limits.

11.Cancellation and refunds

You can cancel a paid plan at any time in the app. Cancellation takes effect at the end of the current billing period: you keep the paid plan until then, and the workspace returns to the Genesis limits afterwards.

Fees already paid are non-refundable, including for partial periods and unused included decisions, except where applicable consumer law gives you a right to a refund.

12.Genesis program and Decision Points

Genesis is a free early-access program. We may change its benefits and limits, close it to new members or end it.

Decision Points are off-chain community points planned for the Genesis campaign, to recognize usage and contributions. They are not tokens or currency, have no monetary value, cannot be transferred, sold or exchanged, do not give any right to receive tokens and give you no claim against us. The criteria may change; participation does not guarantee receipt of any reward; legal, geographic and verification requirements may apply; and the token may never be launched.

We may adjust or cancel Decision Points obtained through fraud, abuse, farming, automated or duplicate accounts, or any breach of these Terms. Abuse or farming invalidates eligibility.

13.Token information

Information about the DEC token on our website is preliminary and for information only. It is not an offer to sell, or a solicitation of an offer to buy, any token or security. DEC is a preliminary proposal and may never be issued. Any participation in a token sale requires eligibility checks, identity verification and separate written agreements, and is not available to residents of excluded jurisdictions.

You never need a token to use the Service, and these Terms give you no right to any token.

14.Intellectual property

We and our licensors own the Service, including its software, documentation, design and the Dcision name and logos. Apart from the limited right to use the Service under these Terms, no rights are granted to you.

If you send us feedback or suggestions, we may use them freely, with no obligation to you.

Open-source components included in the Service are subject to their own licenses.

15.Third-party services

The Service relies on third-party services, such as Google (sign-in), Stripe (payments) and engine providers, and your destinations can call services you choose. Their own terms and policies apply to your use of them, and we are not responsible for them.

16.Availability and support

We work to keep the Service available and secure, but we do not guarantee that it will be uninterrupted or error-free. We may carry out maintenance and changes that affect availability. Service levels are committed only in Enterprise agreements.

Support is provided through the channels described for your plan.

17.Disclaimer of warranties

To the maximum extent permitted by law, the Service and all outputs are provided “as is” and “as available”, without warranties of any kind, express or implied, including warranties of accuracy, merchantability, fitness for a particular purpose and non-infringement. You are responsible for evaluating whether the outputs are suitable for your use.

18.Limitation of liability

To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential or punitive damages, or for lost profits, revenue, goodwill or data, even if advised of their possibility.

To the maximum extent permitted by law, our total liability for all claims relating to the Service is limited to the greater of (a) the amounts you paid us for the Service in the 12 months before the event that gave rise to the claim and (b) $100.

These limits do not apply where liability cannot be limited by law, including in cases of fraud or willful misconduct, nor to the rights you have as a consumer under mandatory law.

19.Indemnification

You will defend and indemnify GR Digital against third-party claims, damages and reasonable costs arising from your Customer Data, from the destinations you configure, from decisions you make or support with the Service, or from your breach of these Terms or of the law.

20.Suspension and termination

You may stop using the Service at any time and ask us to delete your account at privacy@dcision.io.

We may suspend or terminate your access, with notice where reasonable, if you breach these Terms, do not pay amounts due, create a security or legal risk, or if the law requires it. We may also discontinue the Service with reasonable prior notice; in that case we will refund prepaid fees for the unused period.

When your account ends, your right to use the Service ends and your data is deleted as described in the Privacy Policy. Provisions that by their nature should survive, such as payment obligations, limitations of liability and governing law, survive termination.

21.Governing law and disputes

These Terms are governed by the laws of the Federative Republic of Brazil. Disputes will be settled by the courts of the place of the registered office of GR Digital in Brazil, except where applicable consumer law gives you the right to bring a claim in the courts of your own domicile.

Before going to court, please contact us at legal@dcision.io so that we can try to resolve the issue amicably.

22.Changes to these Terms

We may update these Terms. If a change materially affects your rights, we will notify you by e-mail or in the app at least 30 days before it takes effect. The date at the top of this page shows the current version. If you keep using the Service after a change takes effect, the updated Terms apply; if you do not agree, you may cancel before that date.

23.General terms

These Terms, together with the Privacy Policy and any order or agreement for your plan, are the entire agreement between you and us about the Service. If a provision is found unenforceable, the rest remains in effect. Not enforcing a provision is not a waiver. You may not assign these Terms without our consent; we may assign them in a merger, acquisition or sale of assets. Neither party is liable for delays caused by events beyond its reasonable control.

These Terms are available in several languages. If versions conflict, the English version prevails, except where the law requires otherwise.

24.Contact

Dcision is operated by GR Digital (GR Negócios Digitais, CNPJ 29.691.265/0001-65), Av. Luiz Boiteux Piazza, 1302, Sala 13, Florianópolis/SC, 88056-682, Brazil.