Innovedus

Terms of Service

Version date: 2026/7/17

Applicable services: Member Center, shared sign-in services, and newsletter subscription management services

1. Applicability and Acceptance

Welcome to the Member Center (https://member.innovedus.com), shared sign-in, OAuth/OpenID Connect authorization, newsletter subscription management, member profile management, delegated file access authorization, and related websites or APIs (collectively, the "Service") provided by Innovedus Inc. (Chinese legal name: 智匯創育股份有限公司; "we," "us," or "our").

By registering for, signing in to, using, or accessing the Service, being redirected from a partner website to the Service, subscribing to newsletters, managing personal data, or using OAuth authorization, you acknowledge that you have read, understood, and agree to be bound by these Terms of Service and the Privacy Policy. If you do not agree to these Terms, please stop using the Service.

If you use the Service on behalf of a company, organization, tenant website, or other legal entity, you represent that you have authority to accept these Terms on behalf of that entity. In that case, "you" also refers to that entity.

2. Service Description

The Service currently provides the following main features:

  1. Shared member accounts and a sign-in center for multiple websites.
  2. OAuth 2.0/OpenID Connect authorization, including Authorization Code + PKCE, client credentials, token issuance, and token validation.
  3. Member registration, sign-in, sign-out, email verification, forgot password, password reset, and password change.
  4. Member profile, address book, and subscription data management.
  5. Newsletter subscription, double opt-in confirmation, subscription preference management, unsubscribe, and one-click unsubscribe.
  6. Administration features for tenants, OAuth clients, newsletter lists, subscriptions, blacklists, audit logs, and security settings.
  7. Necessary webhook, token, scope, audience, and tenant data synchronization with Send Engine, file access services, or other partner services.

We may add, adjust, suspend, or terminate certain features based on operational needs. If a material change affects your important rights or interests, we will provide reasonable notice.

The Service currently does not include paid memberships, payment processing, or guaranteed service levels (SLA). If we later provide paid plans, enterprise agreements, SLA commitments, or other commercial services, the relevant fees, service levels, support scope, and special conditions will be governed by the applicable plan description or written agreement between the parties.

3. Beta, Preview, and Experimental Features

We may periodically provide beta, preview, experimental, or other features that have not been generally released. These features may still be under development, testing, or validation and may be changed, interrupted, contain errors, cause data loss or reduced performance, or operate differently from generally available features.

Except as otherwise required by law, we do not guarantee the availability, stability, continued provision, or fitness for a particular purpose of these features, and we may modify, limit, or discontinue them at any time without prior notice.

4. Eligibility and Use by Minors

The Service is generally intended for natural persons with full legal capacity, businesses, organizations, or users with lawful authorization.

If you are a minor or a person under guardianship or assistance, you must use the Service with the consent of your legal representative, guardian, or assistant. By using the Service, you represent that you have obtained the necessary consent or authorization.

If we reasonably believe that you have not obtained the necessary consent or authorization, we may restrict, suspend, or terminate your account or certain Service features.

5. Account Registration and Security

You must provide accurate, complete, and up-to-date registration and account information, and update it promptly when it changes. You may not use another person's email address, impersonate another person, create false accounts, or register for or use the Service through automated, malicious, or otherwise prohibited means.

You are responsible for safeguarding your account, password, sign-in session, authorization tokens, API client secrets, and other credentials. Except where attributable to us, activities conducted through your account, credentials, or an authorized client are your responsibility.

If you discover unauthorized use, leakage, or a suspected security incident involving your account, password, tokens, or client secrets, you must notify us immediately and take necessary replacement, revocation, or disabling measures.

6. External Sign-In and Third-Party Websites

The Service may support Google or other third-party sign-in providers, and third-party websites, tenant websites, or partner services may redirect you to the Service for sign-in, authorization, subscription, or unsubscribe flows.

Third-party websites, sign-in providers, partner services, and tenant websites are operated by their respective operators. We do not control their content, data processing, service quality, security measures, or terms and policies. When you use third-party services, you should read and comply with their terms of service and privacy policies.

7. Newsletter Subscription and Unsubscribe

You may subscribe to newsletters through flows provided by tenant websites or the Service. Some subscriptions use double opt-in and require confirmation through an email. You may unsubscribe through unsubscribe links, one-click unsubscribe, the Member Center subscription management page, or other methods we provide.

You may not subscribe using another person's email address without authorization, conduct malicious mass subscriptions, interfere with unsubscribe mechanisms, forge subscription confirmations, or abuse newsletter features. Due to bounces, spam complaints, legal requirements, platform security, or email deliverability considerations, we or tenant websites may stop sending, unsubscribe an email address, or add it to a suppression list or blacklist.

8. API, OAuth Client, and Integration Rules

If you use APIs, OAuth clients, webhooks, or delegated file access authorization as a tenant, developer, administrator, or partner service, you must comply with the following rules:

  1. Use APIs and data only for lawful, authorized, and necessary purposes.
  2. Properly protect client secrets, private keys, webhook secrets, tokens, and other credentials, and do not disclose, transfer, or provide them to unauthorized persons.
  3. Request only scopes, audiences, and tenant data that correspond to the service purpose, and do not bypass or compromise tenant isolation.
  4. Do not attempt to forge tokens or bypass PKCE, redirect URI, scope, audience, tenant, or webhook signature validation.
  5. Do not use crawlers, stress testing, scanning, brute-force attacks, replay attacks, or other methods to interfere with the Service.
  6. Process data obtained from the Service in accordance with applicable personal data, security, electronic communications, anti-spam, and other laws.
  7. If a data breach, credential leak, or security incident occurs, notify us immediately and cooperate with investigation, revocation, rotation, and remediation.

For security, compliance, maintenance, or abuse-prevention reasons, we may limit, suspend, revoke, or adjust API access, tokens, clients, webhooks, or integration features.

9. Security Vulnerability Reporting

If you discover a vulnerability, misconfiguration, authorization bypass, credential exposure, or other security issue that may affect the Service, you should notify us within a reasonable period using the contact information in these Terms and avoid publicly disclosing technical details that may increase security risk.

Without our prior written consent, you may not publicly disclose or exploit a vulnerability, expand the scope of testing, or test or validate the issue in any other manner that may interrupt the Service or expose data.

10. User Conduct

When using the Service, you must not:

  1. Violate law, competent authority orders, third-party rights, or these Terms.
  2. Impersonate another person, provide false information, or mislead us, tenant websites, or other users.
  3. Intrude into, interfere with, damage, reverse engineer, scan, or test vulnerabilities of the Service unless you have obtained our prior written consent.
  4. Upload, transmit, or distribute malware, spam, phishing content, fraudulent content, or infringing content.
  5. Collect, query, export, copy, or use another person's personal data without authorization.
  6. Circumvent rate limits, access controls, permission validation, tenant isolation, or other security measures.
  7. Cause excessive load or service interruption to the Service or related infrastructure.
  8. Use the Service for unlawful marketing, unsolicited email, or other communications against recipients' wishes.

11. Responsibilities of Administrators and Tenants

If you are an administrator, tenant website, OAuth client owner, or partner service, you must ensure that you have the legal basis, consent, or authorization required to process user personal data, send newsletters, call APIs, receive webhooks, synchronize data, or entrust the Service to process data.

You must maintain the security of your own systems and integrations, including redirect URIs, return URLs, client secrets, webhook endpoints, email delivery flows, unsubscribe links, data exports, and personnel permissions. You are responsible for damages caused by inadequate protection, misconfiguration, or unlawful use by you or your systems.

12. Intellectual Property

The programs, interfaces, designs, documents, trademarks, logos, database structures, API specifications, technical content, and other materials included in the Service are owned by us or lawful rights holders, unless otherwise indicated or owned by third parties.

Except as authorized by these Terms or by our separate written authorization, you may not reproduce, modify, distribute, publicly transmit, lease, sell, reverse engineer, decompile, or otherwise exploit Service content. You retain rights to data you provide or upload, but you authorize us to use, process, store, transmit, and display that data within the scope necessary to provide, maintain, protect, and improve the Service.

13. Personal Data and Privacy

We process your personal data in accordance with the Privacy Policy, which forms part of these Terms. Please read the Privacy Policy to understand what data we collect, the purposes of use, sharing recipients, retention periods, security measures, and your rights.

14. Service Availability and Changes

We will use reasonable efforts to maintain the stability and security of the Service, but we do not guarantee that the Service will be uninterrupted, error-free, vulnerability-free, or always compatible with all browsers, devices, third-party services, or integration methods.

We may suspend, limit, or adjust the Service due to maintenance, updates, security, system failure, third-party service interruption, force majeure, legal requirements, or other reasonable causes. Where feasible, we will provide reasonable notice of material maintenance or changes.

15. Suspension, Restriction, and Termination

If you violate these Terms or the law, infringe others' rights, create security risks, abuse the Service, access data without authorization, or if we reasonably believe action is necessary to protect users, tenants, third parties, or the Service, we may:

  1. Request correction, supplementation of information, or cessation of specific conduct.
  2. Limit, suspend, or terminate accounts, administrator permissions, API clients, tokens, webhooks, or integration features.
  3. Delete, restrict access to, or isolate violating data.
  4. Notify affected users, tenants, partner services, competent authorities, or law enforcement agencies.
  5. Take other necessary measures permitted by law.

You may stop using the Service, delete your account, or request data handling through methods provided by the Service. However, we may continue to retain data within the necessary scope where required by law, contract, audit, security, dispute resolution, or abuse prevention.

16. Disclaimer

To the maximum extent permitted by law, the Service is provided on an "as is" and "as available" basis. We do not warrant that the Service will fully meet all of your needs, be uninterrupted, completely secure, error-free, virus-free, free from data loss, or compatible with all third-party services, tenant websites, email services, cloud platforms, browsers, or devices.

Except where we are responsible under law or contract, third-party websites, tenant websites, external sign-in providers, Send Engine, file storage services, email services, or other third-party services are responsible for problems, damages, or data processing arising from their own services.

17. Limitation of Liability

Except for willful misconduct, gross negligence, liabilities that may not be limited by law, or mandatory provisions such as consumer protection laws, we are not liable for indirect, incidental, special, consequential, punitive, goodwill, business, data loss, lost profit, or third-party claim damages arising from use of or inability to use the Service.

If we are legally required to bear liability, our liability is limited to the fees you actually paid to us for the service giving rise to the liability during the twelve months before the event. If the service is provided free of charge, our liability is limited to NTD 10,000. This limitation does not apply where prohibited by law.

18. Indemnification

If your violation of these Terms, unlawful use of the Service, infringement of third-party rights, failure to safeguard accounts or credentials, misconfiguration of integrations, or failure to obtain necessary consent or authorization causes us, our affiliates, employees, partners, tenants, or other users to suffer damages, expenses, fines, settlements, attorneys' fees, or third-party claims, you shall indemnify and hold them harmless to the extent permitted by law.

19. Updates to These Terms

We may update these Terms due to changes in service features, law, security, or business operations. Updated Terms will be posted on the Service or provided through another appropriate notice. If you continue using the Service after the updated Terms take effect, you agree to the updated Terms. If you do not agree, please stop using the Service.

If an update materially affects your rights or interests, we will take reasonable steps to notify you. Where law requires renewed consent, we will handle it in accordance with law.

20. Governing Law and Jurisdiction

These Terms are governed by the laws of the Republic of China (Taiwan). Any dispute arising from these Terms or the Service shall first be resolved through good-faith negotiation. If negotiation fails, the Taiwan Taipei District Court shall be the court of first instance, unless mandatory law provides otherwise.

21. Miscellaneous

If any part of these Terms is held invalid or unenforceable by a court or competent authority, the remaining parts remain effective. Our failure to immediately exercise a right under these Terms does not constitute a waiver of that right. You may not assign your rights or obligations under these Terms without our prior written consent. We may assign these Terms in connection with restructuring, merger, spin-off, asset transfer, or service transfer.

22. Contact

If you have questions about these Terms or the Service, please contact us:

Operator: Innovedus Inc. (智匯創育股份有限公司) Unified Business Number: 93698713 Email: cs@innovedus.com Address: 4F., No. 19-11, Sanchong Rd., Nangang Dist., Taipei City, Taiwan