Operator agreement

Terms of service

Early access terms v0.1 · last updated 10 August 2026

1. Who we are

Maimava is a smart-fridge operations platform supplied by WooSee Limited, a company registered in England and Wales (no. 14364528), registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, VAT registration GB 486 515 656 ("we", "us", "Maimava").

"You" or "the Operator" means the business that has been given access to a Maimava workspace.

2. What Maimava is, and what it is not

Maimava produces documents and figures about your business: self-billed invoices to your hosts, output-VAT split statements, input-VAT summaries, profit-and-loss figures, stock valuations and margin analysis.

These are produced by software, from data you supply, for you to check. They are decision-support. They are not tax advice, accountancy, audit, or any other regulated professional service, and no part of this agreement creates a client-adviser relationship between us.

In particular:

  • You remain responsible for your own tax filings. Every figure Maimava produces is yours to verify before you rely on it, file it, or pay against it. We do not file anything on your behalf and we are not your agent for any tax purpose.
  • VAT classifications are recorded evidence, not opinions. Where Maimava records a product as standard-rated or zero-rated, it does so from a printed marking on a supplier document you uploaded — a Booker VAT code, a Tropicana VAT percentage — and it stores the quoted line as the source. It does not apply VAT law, and it will refuse to guess: an unclassified product blocks the VAT statement rather than being assumed.
  • Machine-read documents can be wrong. Supplier invoices are read automatically. Extraction failures are reported to you rather than hidden, but a figure that was read incorrectly and not corrected is still a figure you filed.
  • Indicative figures are labelled as such. Margin, P&L and projection screens carry a caveat on their face. Treat anything so labelled as an operational estimate, never as an accounting record.

2.1 Contested classifications

If you believe a VAT classification Maimava has recorded is wrong, you may tell us and we will review the underlying evidence with a human and either correct it or explain the marking we relied on. You may override any classification yourself at any time — your override always wins over a machine-set value, and we will not silently re-apply ours.

3. Your data, and who controls it

You are the data controller for the personal data in your workspace — your hosts' contact details, your staff's logins, and any prospect or outreach data you gather. We are your processor for that data and act on your instructions. The processing we carry out for you is set out in Annex A, which forms part of this agreement.

We are the controller for platform-level data: the accounts, credentials and audit records that let us run the service securely.

You are responsible for the lawfulness of your own use — in particular for any business-to-business marketing you conduct through the platform, which is subject to UK GDPR and the Privacy and Electronic Communications Regulations. We provide suppression and record-keeping tools; we do not decide who you may contact.

3.1 Retention and deletion

Live deletion on request is immediate. Residual copies persist in backups for up to 35 days and then age out; they will not be used for any purpose in the meantime. We will not tell you deletion is instantaneous everywhere, because it is not.

4. Money documents

Where Maimava issues a self-billed invoice on your behalf to one of your hosts, it does so only where you have recorded that a signed self-billing agreement covers that supply and is in date. You are responsible for having that agreement and for its contents.

Issued invoices are immutable: the PDF is rendered once and stored, and every later view is byte-identical. Corrections are made by later adjustment, never by rewriting a document that has been sent.

5. Licence to derive classification data

This clause is the one that materially benefits both sides, so it is written narrowly on purpose.

What you grant

You grant us a non-exclusive, perpetual, royalty-free licence to derive from the supplier documents you upload, and to use across the platform, the following and nothing else:

  • a product's identity — its barcode (GTIN), its supplier's product code, its description as printed, and its case size; and
  • its tax band — that a product is standard-rated or zero-rated, together with the printed marking relied on.

What we will never do with it

We will not use, expose, or derive from your documents:

  • any price you paid — unit costs, line totals, discounts, rebates or settlement terms;
  • any commercial term between you and a supplier;
  • your volumes, order patterns or supplier relationships;

and we will never make any of the above visible to another operator, in any form, aggregated or otherwise.

Why this is safe to grant

A barcode's tax band in a given country is a fact about that country's tax law, not about your business: a supplier's product code identifies the same item for every customer in Britain, and its UK VAT treatment is the same for all of them. What is commercially sensitive is what you paid for it, and that never leaves your workspace.

What you get back

Every operator's classifications improve the shared reference layer, so a product another operator has already classified arrives correctly rated in your catalogue, and the VAT statement that would otherwise be blocked is not.

The shared reference layer is not built yet. This clause describes what the licence is for; until the facility exists there is nothing for your classifications to flow into, and nothing flowing back. We would rather grant the licence in the open now than quietly widen a narrower one later.

"Perpetual" means this licence survives the end of the agreement, and that is the sentence in clause 5 worth reading twice. Classifications you have contributed stay in the shared layer after you leave — a shared reference anyone can withdraw from is not one anybody can rely on. It is a real ask, so we are saying it here rather than leaving it in the adjective. It does not touch clause 6.7: your workspace data is still yours to take and still deleted. What stays is a barcode, a supplier's code, a pack size and a tax band — facts about a product and a country, never about you.

6. Availability, liability and termination

6.1 Availability

We will supply the platform with reasonable skill and care. We do not commit to a level of availability. We will take reasonable steps to give notice of planned maintenance, and reasonable steps to restore service after an interruption.

Parts of the platform depend on services we do not run — your smart-fridge manufacturer's API, payment and card-statement providers, and the cloud services listed in Annex A. When one of those is unavailable, the parts of the platform that depend on it are unavailable too. We are not liable for their failures, but we will tell you what has failed rather than presenting stale figures as current.

6.2 Liability we do not limit

Nothing in this agreement limits or excludes our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited or excluded.

6.3 Liability we exclude

We are not liable for loss of profit, revenue, anticipated savings, goodwill or business opportunity, or for any indirect or consequential loss, in each case however arising.

We are not liable to the extent that a loss was caused by your failure to check a figure before relying on it, where the platform gave you what you needed to check it. Clause 2 explains what we produce and what remains yours to verify.

6.4 The cap

Our total liability to you, whether in contract, tort (including negligence), breach of statutory duty or otherwise, is limited to the greater of £50,000 and the total fees you have paid us in the twelve months before the claim — in aggregate for all claims arising in any twelve-month period.

This figure is provisional — see the notice at the top of this page. It is drafted to sit comfortably inside professional indemnity cover we have decided to buy but have not yet completed, and it will be confirmed, with a solicitor, before anyone converts to a paid subscription.

6.5 Tax penalties are inside the cap, not excluded

For the avoidance of doubt, penalties, interest and professional costs you incur because a figure the platform produced was wrong are within the cap in clause 6.4 and are not excluded by clause 6.3. That is deliberate: it is the loss this product could actually cause, and excluding it would leave clause 2's disclaimer doing all of the work.

6.6 Termination

Either of us may end this agreement on 30 days' written notice.

Either of us may end it immediately if the other commits a material breach that is not put right within 14 days of being asked, or becomes insolvent. We may suspend your access for non-payment after giving you notice and a reasonable chance to pay.

6.7 What happens on exit

Your data is yours and you can take it with you. Ask us at any time, and for 30 days after termination, and we will give you your workspace data in a machine-readable form. During early access we produce that by hand — there is no self-service export yet, and we would rather say so than promise a button that does not exist.

After that we will delete it in line with clause 3.1, except where we are required to keep records by law — in particular invoices and VAT records, which must be retained for six years. Records kept for that reason are kept for that reason only.

6.8 Governing law

This agreement is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.

7. Changes

We will give you reasonable notice of any change to these terms that materially affects you, and you may terminate if you do not accept it. Each published version carries its own version number and date, at the top of this page; the version you accepted when you applied is recorded against your application.


Annex A — Data processing schedule (UK GDPR Article 28)

This annex forms part of the agreement and records the processing we carry out for you as your processor. Where it conflicts with the body of the agreement, this annex governs the processing.

A.1 Subject matter, duration, nature and purpose

We process personal data in order to supply the platform: operating your workspace, producing your money documents, monitoring your machines, and — where you use it — discovering and contacting prospective venues. Processing lasts for the term of the agreement and the exit period in clause 6.7, after which clause 3.1 applies.

A.2 Types of personal data

CategoryExamples
Your peoplename, email address, role, authentication credentials (stored hashed or as public keys, never in plain text), audit records of actions taken
Your venue partnersbusiness and individual contact names, email addresses, telephone numbers, addresses, VAT registration numbers
Your venue partners' payment detailssort code and account number, and the account-holder name, used to produce self-billed invoices. Where a partner is a sole trader these are personal data about an individual
Prospectsbusiness names, addresses, published contact details, and assessments generated about a site
End consumersa pseudonymous per-card identifier supplied by the fridge manufacturer. We hold no name, contact detail or payment credential for any consumer

No special-category data (Article 9) is processed, and none should be uploaded.

A.3 Categories of data subject

Your staff and contractors; the individual contacts at your host venues and prospective venues; and, pseudonymously only, consumers who buy from your machines.

A.4 Our obligations

We will:

  • process personal data only on your documented instructions, of which this agreement is one, unless we are required to do otherwise by law — in which case we will tell you first unless the law forbids it;
  • ensure that anyone authorised to process it is bound by confidentiality;
  • take the security measures described in A.5;
  • observe A.6 before engaging any sub-processor;
  • assist you, so far as we reasonably can, in responding to data-subject requests;
  • assist you with your obligations under Articles 32 to 36, including security, breach notification and impact assessments;
  • notify you without undue delay on becoming aware of a personal data breach affecting your data;
  • at the end of the agreement, delete or return your personal data in accordance with clauses 3.1 and 6.7; and
  • make available the information reasonably needed to demonstrate compliance with this annex, and submit to audits on reasonable notice, no more than once a year unless a breach or a regulator requires otherwise.

A.5 Security measures

Access to your workspace is restricted to people you have invited, authenticated by passkey or password, with sessions revocable by us and by you. Data is segregated per operator at the database level and fails closed — a request carrying no operator context reads nothing rather than reading everything. Connections are encrypted in transit with verified certificates, and data is encrypted at rest. Your people's credentials are never stored recoverably — passwords are hashed and passkeys are held as public keys, so nobody here can read them. API credentials you give us for your own equipment are different, and it would be untrue to claim otherwise: those are stored encrypted and we decrypt them to talk to your provider on your behalf, which is the whole point of giving them to us. Actions taken in the platform are recorded in an audit log. Backups are retained for no more than 35 days.

A.6 Sub-processors

You give general authorisation for the sub-processors below. We will give you reasonable notice before adding or replacing one, and you may object; if we cannot resolve your objection you may terminate.

Sub-processorPurposeLocation
Amazon Web Serviceshosting, database, file storage, email, SMSUnited Kingdom (London region)
Anthropicreading uploaded supplier documents; assessing prospective venues; drafting proposalsUnited States
Googlevenue discovery and mappingUnited States

International transfers are not yet documented — this is the first of the two gaps named at the top of this page. Anthropic and Google operate in the United States, so uploaded supplier documents and prospect data leave the UK. The transfer terms required to cover that (the UK IDTA, or the EU standard contractual clauses with the UK Addendum, plus a transfer risk assessment) are being prepared and are not in place today.

Your fridge manufacturer is deliberately not listed. You supply your own API credentials, so that is your own supplier relationship and we act as your client rather than appointing a sub-processor on your behalf.

A.7 Where we are controller, not processor

We are controller for account, credential and audit data, and for our own security and billing records. Lead discovery is a boundary case we are still resolving: we call third-party APIs under our own keys, using your search terms, which may make us controller for that processing rather than your processor. We will say which it is once it is settled.

Questions

Write to solo@woosee.pro. A question about these terms during early access reaches a person, not a queue.

Ready to apply?

Two fields — your email and your business name. We read every application and reply by email.

Apply for early access