Marketplace Vendor Agreement
Effective date 01 Oct 2026
This Agreement governs participation in the Starhive Marketplace. It is between Starhive AB, Swedish company registration number 559362-7648 (Starhive, we or us), and the organisation or individual acting in the course of business identified in the vendor account (Vendor or you).
You accept this Agreement through the Marketplace acceptance process. The person accepting for an organisation confirms their authority to bind it. For a new Vendor, it takes effect on acceptance. For an existing Vendor, this version takes effect through the notice and acceptance process applicable to its existing agreement. Separate agreements for Starhive products or services remain unchanged.
1. Purpose and responsibilities
The Marketplace enables you to publish applications, integrations, connectors and extensions compatible with Starhive (Apps). An App includes its updates, manifest, Remote Functions and supporting components under your control. End Users are the business customers and their authorised users who activate or use an App. Participation is non-exclusive.
You are responsible for your Apps and the services you provide to End Users. Starhive is responsible for the Marketplace and infrastructure it provides. Each party must use reasonable care and skill in performing its obligations and remains responsible for its personnel and service providers. End Users use your Apps under your End User terms. Those terms must identify you as the App provider and must not purport to change Starhive's separate obligations to its customers.
2. Publishing and maintaining Apps
Keep your vendor information and support, legal and security contacts accurate. Listings must identify you and accurately describe functionality, compatibility, dependencies, material limitations and support. Provide accessible End User terms and the data security and privacy statement required by Section 6.
To publish an App, upload its App bundle to Starhive's infrastructure and provide a manifest accurately declaring the Starhive resources it creates and uses and the external systems it reaches. Keep the manifest and supporting information up to date. Declare Remote Functions and their purposes, external services or endpoints, and data flows in the manifest or accompanying review information; where the external address is supplied by the End User, declare the categories of system and the host patterns you permit.
Remote Functions are App functionality that communicates with systems or services outside Starhive's infrastructure, including to retrieve external data or send End User Data outside Starhive, whether the communication is made by Starhive on the App's behalf or by the App in the End User's browser.
Starhive will review new App submissions; publication requires its approval. Introducing Remote Functions, whether initially or later, requires Starhive's prior approval. Material changes to approved functionality, permissions, external recipients or data flows also require prior approval before release or activation. This applies to changes in remote services even where the uploaded App bundle or the manifest does not change. All updates must follow the publishing process communicated by Starhive. You may release an update without Starhive's prior approval where it is urgently needed to contain a security incident or vulnerability, provided it only disables or restricts functionality and introduces none. Notify Starhive under Section 7.
Starhive may request information reasonably needed for review and will explain a refusal or request for changes. Approval relates to the submitted version and disclosed behaviour; it is not a certification or guarantee of security or legal compliance and does not relieve either party of its own responsibilities.
Provide an accessible support channel, use reasonable efforts to maintain your Apps and address material defects, and give reasonable notice of material compatibility or support changes. No particular support response time or certification is required unless separately agreed. This does not affect Sections 5 and 7. Transferring an App to another provider requires Starhive's consent under Section 12, and the transferee must accept this Agreement before the transfer takes effect.
3. Intellectual property and permissions
Each party retains its intellectual property. You must hold the rights needed for your Apps and listing materials and comply with applicable third-party and open-source licences. App licensing must not require Starhive to disclose or license its own proprietary software.
You give Starhive a non-exclusive, worldwide licence to display, reproduce and format your supplied listing materials, names and logos solely to operate and promote the Marketplace and your Apps. Active promotion ends on removal; existing promotional materials and protected archives need not be recalled.
Starhive permits you to use its published App-development interfaces and documentation to develop, test, publish and support Apps, subject to applicable technical requirements. You may accurately describe compatibility with Starhive. Other use of its logos or badges requires written approval. Neither party may imply an unauthorised endorsement. Either party may use voluntary feedback without disclosing the other's Confidential Information.
4. Vendor Code and hosting
Vendor Code means the App bundle, scripts, manifest, configuration and related materials you provide for an App. You grant Starhive a non-exclusive, worldwide licence to store, copy, execute, host, scan, test, back up and make strictly necessary technical adaptations to Vendor Code solely to review, operate, secure and make the App available to End Users. This licence lasts while the App is provided under this Agreement and during any separately agreed transition period.
Starhive must protect non-public Vendor Code as Confidential Information and may use authorised service providers for these purposes. This does not permit using Vendor Code to develop competing products, train general-purpose AI models or for unrelated purposes. Independent development without using your Vendor Code or Confidential Information is not restricted.
You remain responsible for your code, its dependencies, configuration and services you select or operate, and must keep your own copies. Starhive remains responsible for the hosting infrastructure it supplies. Neither party guarantees uninterrupted or error-free operation or compatibility with every third-party system.
Starhive will delete Vendor Code from active systems within 30 days after the App ceases to be provided, except protected copies reasonably needed for legal or security records. Routine backups may remain until overwritten under normal retention cycles and may not be used to continue operating the App.
5. Legal compliance and security
Each party must comply with laws applicable to its activities, including data protection, intellectual property, anti-bribery, sanctions and export-control requirements.
Maintain safeguards proportionate to the systems and data you control: secure development, access and credential protection, encryption appropriate to the risk, dependency and vulnerability management, and incident response. Starhive must maintain appropriate safeguards for the Marketplace and its hosting infrastructure. Each party may rely on relevant safeguards supplied by the other while remaining responsible for its own components and configuration.
Apps must not contain malicious or undisclosed harmful functionality, access or modify data without authorisation, bypass permissions or resource limits, or disrupt systems. Testing requires the relevant system owner's authorisation. Promptly investigate vulnerabilities and address them according to severity; critical or actively exploited vulnerabilities require immediate containment. Starhive may request proportionate evidence of compliance, protecting confidential material under Section 8.
6. Privacy, Remote Functions and End User approval
End User Data means information an App accesses or processes in connection with an End User, including personal data, operational records and credentials. This Agreement does not transfer ownership of that data.
For each App, you must provide and maintain a publicly accessible link to an accurate data security and privacy statement (Statement). It must explain:
- what data and permissions the App uses, and for what purposes;
- whether Remote Functions access, transmit or store End User Data outside Starhive, the external recipients or service providers, and relevant processing locations;
- the safeguards applied, retention periods and arrangements for returning or deleting data, including after deactivation; and
- privacy and security contact details and how applicable data-subject rights can be exercised.
Date or version the Statement and retain earlier versions. Starhive will display its link on the App listing and require an authorised End User representative to approve it before activation. Each party must retain appropriate records of approvals it obtains.
Use End User Data only for the disclosed, authorised App purposes and access only what is necessary. External transmission or processing requires Starhive's approval under Section 2 and the relevant End User's informed authorisation. Do not imply that data remains exclusively within Starhive where the App sends it elsewhere.
Before materially changing data access, purposes, external recipients or processing locations, update the Statement, notify Starhive and affected End Users, obtain any required Starhive approval, and obtain renewed End User approval for the changed processing. Do not enable that processing for an End User who has not approved it. A changed webpage alone is not renewed approval.
End User approval authorises the disclosed App functionality; it does not replace a lawful basis for processing, required data-subject notices or consent, a required data-processing agreement, or international-transfer safeguards. Each party is responsible for obligations arising from its actual role, including under the GDPR where applicable. Before processing personal data on another party's behalf, the relevant parties must put any required processor or subprocessor agreement and authorisations in place. This Agreement does not itself replace those arrangements or automatically designate Vendor as Starhive's subprocessor.
On deactivation or withdrawal of authorisation, stop further App access to End User Data and return or delete copies you control according to applicable instructions, the Statement and law. Any lawfully retained copies must remain protected and used only for the permitted retention purpose. Each party remains responsible for its own processing; App approval does not remove Starhive's obligations under its customer agreements or applicable law.
7. Security incidents
Each party must notify the other without undue delay, and within 24 hours of awareness, of an actual or reasonably suspected security compromise involving its systems, Apps or service providers that affects, or is reasonably likely to affect, the App, End User Data or the other party's systems. Notify Starhive at legal@starhive.com; Starhive will notify your registered security contact.
Provide available facts, likely impact, containment steps and a response contact without waiting for a complete investigation. Each party must promptly investigate matters within its responsibility, mitigate harm, share material updates and reasonably cooperate with the other and affected End Users. Each remains responsible for its own legally required notifications; this reporting period does not extend statutory deadlines.
8. Confidentiality
Protect the other party's non-public business, technical and operational information (Confidential Information) with reasonable care. Use it only for this Agreement and disclose it only to people who need access and are bound to protect it.
Information is not confidential if lawfully known without restriction, independently developed, lawfully received without restriction, or made public without breach. Legally required disclosure is permitted, with advance notice where lawful and practical.
On request or termination, return or delete Confidential Information, except protected copies needed for legal, security or routine backup purposes. Confidentiality continues for five years after termination and, for trade secrets, while they remain protected. Data protection duties continue while relevant data is retained.
9. Marketplace operation, removal and termination
Starhive will operate the Marketplace with reasonable care but does not promise a particular listing position, adoption level or indefinite availability. It will give reasonable advance notice of material platform changes affecting Apps, allowing time to adapt where practicable, except where urgent security or legal requirements prevent this.
Either party may terminate this Agreement on 30 days' written notice. You may withdraw an individual App, and Starhive may remove one, on the same notice. Starhive will explain its reason for removal. Either party may terminate for a material breach not remedied within 14 days after written notice, or immediately for deliberate malicious conduct or a material breach that cannot be remedied.
Starhive may immediately restrict or suspend an App only to the extent reasonably necessary to address a material security threat, unlawful activity, serious harm, or a legal requirement. For other remediable breaches, it will normally allow an opportunity to correct them before restricting access. Measures must be proportionate. Starhive will explain its decision promptly unless legally prohibited or disclosure would compromise security, and restore access once the grounds no longer apply. You may request review at legal@starhive.com; Starhive will consider your response fairly.
During an ordinary notice period, the parties will reasonably cooperate to notify affected End Users and allow transition and retrieval of App-related data using available means. The parties will use reasonable efforts to keep existing installations available during that period, subject to necessary security or legal restrictions and obligations in separate agreements. Neither party must provide additional transition services after the effective end date unless separately agreed or legally required.
Withdrawal or termination ends new installations and active promotion. Existing End User licences are not automatically revoked, but hosting and operation may end on the effective end date unless otherwise agreed or legally required. Continued End User rights and support follow your End User terms. Confidentiality, data handling, liability, dispute resolution and other provisions intended to survive remain effective.
10. Limitation of liability
Excluded losses. Neither party is liable to the other for indirect or consequential losses, or for lost profit, revenue, business opportunity or goodwill. Reasonable direct costs of restoring data or investigating and containing a security incident are not excluded merely because they concern data loss or security; they remain subject to the cap below.
Mutual cap. Each party's total aggregate liability to the other arising out of or in connection with this Agreement is limited to EUR 25,000 for each consecutive 12-month period, measured from when the parties first entered into a Marketplace Vendor Agreement. Claims are allocated to the period in which the event giving rise to liability first occurred. Claims arising from the same or related events share the period of the first such event. The cap applies across all Apps, incidents and End Users, not separately to each. Updating this Agreement does not restart these periods.
Scope and exceptions. These limits apply regardless of the legal basis of a claim, including negligence, and cover confidentiality, security, data protection and intellectual property obligations. Neither the exclusions nor the cap applies to fraud, wilful misconduct, gross negligence, or liability that cannot lawfully be excluded or limited. This Agreement creates no separate obligation to defend or indemnify the other party against third-party claims.
Separate rights. This Section governs claims between Starhive and Vendor only. It does not restrict third parties' statutory rights, regulatory powers or obligations under separate agreements. Each party must take reasonable steps to reduce loss. Either party may seek appropriate non-monetary protective relief.
11. Changes to this Agreement
Starhive will provide at least 30 days' notice of changes, or longer where reasonably needed for technical adaptation. Shorter notice is permitted only to meet a legal requirement or address an urgent security risk, and only for changes necessary for that purpose. Changes do not apply retroactively.
Material contractual changes require your renewed acceptance. If you do not accept, either party may end participation under Section 9. Until then, the previously accepted terms continue, subject to mandatory law and necessary security measures. Publishing instructions and technical requirements may explain operational processes but cannot override this Agreement, expand permitted use of Vendor Code or End User Data, or change the liability allocation.
12. General terms and contact
The parties act independently; neither may bind the other. This is the complete agreement for Marketplace participation. Separately agreed data-processing arrangements govern their subject matter. Changes to Section 10 require both parties' express agreement. Mandatory law prevails. Unenforceable terms do not affect the remainder; failure to enforce a right is not a waiver.
Either party may assign to an affiliate or successor to its relevant business, with notice and assumption of its obligations. Otherwise, consent is required and must not be unreasonably withheld.
Neither party is liable for failure beyond its reasonable control if it gives prompt notice and reasonably mitigates the effects.
Swedish substantive law applies, excluding conflict-of-law rules. The parties will try in good faith to resolve disputes for 30 days after written notice. Unresolved disputes are subject to the exclusive jurisdiction of the Swedish courts, with Stockholm District Court (Stockholms tingsrätt) as the first instance. Either party may seek urgent relief from any competent court or preserve legal time limits without waiting. The parties may jointly agree to arbitrate a dispute.
Send contractual notices, security reports and questions to legal@starhive.com or Starhive AB, Box 3012, SE-103 61 Stockholm, Sweden. Notices to Vendor may be sent to its registered contact email. Contractual notices must be written in English. These arrangements do not replace applicable rules for formal service of proceedings.