Partner license agreement
The terms every partner accepts on the partner page before configuring the integration — pricing, billing, what we do and do not promise, Enable Banking's requirements, and how either side ends the relationship.
La documentazione per i partner è pubblicata in inglese.
Version 2026-09-11.2. This agreement is between Tatic ApS (CVR 42532940, Mejsevej 2, 8370 Hadsten, Denmark), operating open-banking.io ("we", "us"), and the company whose owner accepts it on the partner page ("you", "the partner"). It governs your use of the partner programme: the Connect flow, the partner API, your Enable Banking application and everything else under /app/partner. Accepting it on the partner page is the same as signing it. Your owner account, company name and the time of acceptance are recorded with the version you accepted.
It sits on top of the open-banking.io terms of service (linked from every page's footer), which continue to apply to your own account; where the two differ for partner matters, this agreement wins.
#1. What you get
A limited, non-exclusive, non-transferable right to offer bank account information to your own end users through open-banking.io, under your own brand, using the Connect flow and the partner API, for as long as this agreement runs. Nothing in it transfers any intellectual property; the service, its documentation and its code remain ours, and your application and brand remain yours. You may name open-banking.io as your provider, and we may name you as a partner; either side may ask the other to stop doing so in writing.
You may offer your application in the European Economic Area only. Bank connections from outside it are outside the licence we hold upstream.
#2. Price
You pay per activated account per month, at the per-account price shown on your partner page when you accept this agreement — EUR 2.00 unless we agreed a different price with you before you accepted. There is no minimum, no setup fee and no volume tier: every account costs the same. Prices are in euro and exclude VAT; VAT is added where the law requires it.
An activated account is a bank account that one of your end users has connected through your Connect client and whose bank consent is active on the first day of the month, or becomes active during it. An account connected during a month is charged for the remainder of that month, pro rata by day. An account that goes away during a month is not refunded for the days it was gone.
We may change the price on 30 days' written notice by email to your owner account; the new price applies from the first monthly charge after the notice period. If you do not accept the new price, close your partner account (section 8) before it takes effect; keeping accounts connected past that date is acceptance.
#3. Billing and the card on file
You must keep a valid payment card on the billing account of your owner login; accepting this agreement is only possible while a card is on file, and we may suspend your partner account if it lapses. Fees fall due on the first day of each month for the month ahead, plus the pro-rata fees for accounts added during the month. We may collect them from the card on file; otherwise you pay within 10 days of our invoice or written notice. If a fee is not paid after our notice, we may suspend your partner account, and after 30 days terminate this agreement. Suspension stops new bank connections; it does not stop the fees for accounts that stay connected.
#4. When an account stops costing money
An account is billed for every month in which its consent is active on the first day. Billing for an account stops when its connection is ended: by you, through POST /oauth/revoke carrying the connection's connection_id and eb_session_id (see revoking; a revoke of the token alone stops your reads but not the connection or its fee), or by revoking the Connect client, which ends the connections of every user left without a key; or by the bank, when the consent expires or your user revokes it at the bank. A user who revokes your application on open-banking.io stops your reads only: the connection stays, and so does its fee, until the consent expires at the bank — and since the revoked token can no longer close it, your only remaining lever is revoking the whole Connect client, which also ends every other user of that client left without a key. We never end a connection on your behalf. To stop paying for an account next month, end its connection before the month ends. You can only end a whole connection, not a single account within it; a user who wants to keep some accounts must reconnect with only those.
#5. What we do not promise
The service is provided as is. We give no service level, no uptime commitment and no guarantee of any kind, express or implied: not that it will be uninterrupted, timely, secure or error-free, not that the data a bank returns is accurate, complete or current, and not that any particular bank will be available or behave the way it did yesterday. Banks change their interfaces, their authentication and their limits without notice, and the data we relay is the data the bank gives us. Support is by email to [email protected], on a best-effort basis, with no response-time commitment.
Our total liability to you under this agreement, for whatever cause, is limited to 75 % of the fees you paid us in the twelve months before the event giving rise to the claim (or, in the first year, 75 % of the fees you paid so far). Neither of us is liable to the other for indirect or consequential loss, including lost profit, lost revenue, lost data or business interruption. Nothing here limits liability that cannot be limited by law, or liability for wilful misconduct or gross negligence.
#6. Enable Banking, KYC and what we disclose about you
The bank connections run on our licence with Enable Banking Oy, an Account Information Service Provider registered with the Finnish Financial Supervisory Authority. As a condition of that licence and of Enable Banking's approval of the partner programme, we disclose the identity of every partner to Enable Banking: we register a separate application for you under our account, named after your company, and its description carries your company name, your contact email (the email of your owner login), your company registration number and your country, and says that the application aggregates bank data via open-banking.io. We also register the privacy-policy URL, the terms-of-service URL and the data-protection contact address you gave us. Enable Banking may show that information to end users, and may verify it at any time.
You warrant that everything you gave us on your partner request is true, and you must keep it current: tell us in writing before you change your company details, the name we registered for you, your terms or privacy URLs, your data-protection contact, or the way your application uses bank data. We need two weeks to pass a significant change on. You must cooperate with any know-your-customer or anti-money-laundering check Enable Banking or we ask for, as often as it is asked for. If a check cannot be completed, if Enable Banking declines or restricts your application, or if information you gave us turns out to be false or out of date, we may suspend your partner account at once and terminate this agreement.
Every requirement Enable Banking or a bank places on us for your traffic is a requirement on you. Enable Banking applies shared request quotas across all of our applications; if your traffic endangers them, or a bank or Enable Banking asks us to, we may throttle or suspend your application until it is resolved.
#7. Your obligations
You are the data controller for your end users. You must publish terms of service and a privacy policy for your application, obtain each user's consent before starting a bank connection for them, and handle their data lawfully under the GDPR and PSD2. You must not use the service for anything unlawful, unethical or injurious, or to build a product that competes with open-banking.io; you must not reverse-engineer it, probe or interfere with it, scrape it, introduce malware into it, or falsify the origin of your requests; and you must not sublicense, resell or otherwise give a third party access to your partner account, your Connect client or the data of your users other than as your application is meant to. A breach of this section is a material breach.
Your Connect client secret, your decryption key and every token issued to your application are yours to protect. We hold only the public half of your decryption key: the data of your users is sealed to it, we cannot read it, and if you lose the private half nobody can recover that data. Report a suspected compromise to us at once and rotate the credential.
Each party keeps the other's non-public information confidential for the term of this agreement and one year after, uses it only for this agreement, and returns or destroys it on request or when it is no longer needed, except where the law or a regulator requires otherwise.
#8. Term, closure and termination
This agreement runs until one of us ends it. You can close your partner account at any time from the partner page: closing revokes your Connect clients and partner keys, ends every connection of your users on our side, deletes the data we held for them and deletes your partner account. It does not close the consents your users granted at their banks, which are sealed to your key; run POST /oauth/revoke for the users you want closed at the bank before you close. The charges already made stay due; nothing is billed after closure. Your owner login, its own bank connections and its billing history stay.
We may end this agreement on 30 days' written notice for any reason, and at once if you are in material breach of it, if you become insolvent, if Enable Banking or a bank requires us to, if our own licence upstream ends or changes so that we can no longer serve you, or if a requirement under section 6 is not met. Neither of us is liable for a delay or failure caused by something outside our reasonable control.
We are independent contractors; nothing here makes either of us the agent or partner of the other in the legal sense.
#9. Changes and the law
We may publish a new version of this agreement. Your partner page will ask you to accept it before you can change your configuration again; your running integration is not interrupted while you decide, and the version you last accepted continues to apply to it until you accept the new one or close your account. The commercial change that matters, the price, always comes with the 30 days' notice of section 2.
This agreement is governed by the laws of Denmark. Disputes go to the courts of Denmark, with the City Court of Aarhus as the venue of first instance.
Once accepted, getting started is the page that takes you through the rest of the setup.