Legal agreement
Terms of Service
These Terms of Service constitute a legally binding agreement between you and Shim Technologies. Please read them carefully before using our Service.
Effective Date: August 4, 2026
1. Acceptance of Terms
By creating an account, accessing, or using the Shim AI Gateway platform ("Service"), operated by Shim Technologies ("Company", "we", "us"), you ("User", "you", "Customer") agree to be legally bound by these Terms of Service ("Terms"), our Privacy Policy, and all applicable laws and regulations.
If you are entering into these Terms on behalf of a company or other legal entity, you represent that you have the authority to bind such entity to these Terms. If you do not have such authority, or if you do not agree with these Terms, you must not use the Service.
You must be at least 18 years of age to use this Service. By using the Service, you represent and warrant that you meet this age requirement.
2. Description of Service
Shim is a native AI gateway that provides:
- governed access to OpenAI through the Responses and Chat Completions APIs, Anthropic through the Messages API, and Google through the Gemini Developer API,
- tenant-configured PII detection and redaction,
- model admission, rate, quota, loop, and spend controls, and
- usage, cost, audit, and compliance evidence.
The Service acts as an intermediary layer. We do not provide AI model inference directly. AI responses are generated by the provider configured for the native route and remain subject to that provider's terms and policies. The Service does not automatically reroute requests between providers.
3. Account Responsibilities
- You are solely responsible for maintaining the confidentiality of your account credentials and API keys.
- You are fully responsible for all activities that occur under your account, including actions by employees, contractors, or third parties with access to your API keys.
- You must immediately notify us at support@getshim.tech of any unauthorized use of your account or any other breach of security.
- We will not be liable for any loss or damage arising from your failure to comply with this section.
4. Prohibited Uses
You agree not to use the Service to:
- Violate any applicable local, national, or international law or regulation.
- Transmit content that is unlawful, threatening, abusive, defamatory, obscene, or otherwise objectionable.
- Process data belonging to individuals who have not consented to such processing where consent is required by law.
- Attempt to reverse engineer, decompile, disassemble, or otherwise derive the source code of the Service.
- Attempt to bypass, disable, or circumvent any security, rate limiting, or access control mechanisms.
- Use automated systems (bots, scrapers) to access the Service in a manner that exceeds reasonable usage.
- Resell, sublicense, or redistribute access to the Service without prior written consent.
- Interfere with or disrupt the integrity or performance of the Service or its infrastructure.
- Use the Service to develop a competing product or benchmark against the Service without consent.
5. PII Detection & Data Processing Disclaimer
THIS SECTION CONTAINS CRITICAL LIMITATIONS ON OUR LIABILITY REGARDING PERSONAL DATA. READ CAREFULLY.
5.1 Nature of PII Detection
Shim provides automated PII (Personally Identifiable Information) detection and redaction as a supplementary security layer operating on a best-effort basis. The Service uses pattern matching, natural language processing, and machine learning techniques to identify PII. These technologies have inherent limitations.
5.2 No Guarantee of Detection
- No automated PII detection system can guarantee 100% accuracy or completeness across all data formats, languages, dialects, encoding schemes, or contextual variations.
- The Service may produce false negatives (failing to detect PII) or false positives (incorrectly flagging non-PII data).
- The Service may not detect PII that is obfuscated, encoded, embedded in images, misspelled, abbreviated, or expressed in unconventional formats.
- New or domain-specific PII categories may not be covered by existing detection patterns.
5.3 Data Controller Responsibilities
- As defined under GDPR Article 4(7) and KVKK Article 3, you are and remain the data controller for all personal data processed through the Service.
- Shim acts solely as a data processor on your behalf, as defined under GDPR Article 4(8) and KVKK Article 3.
- You are solely responsible for:
- obtaining all necessary consents from data subjects,
- ensuring lawful basis for processing,
- maintaining records of processing activities,
- conducting data protection impact assessments where required, and
- reporting data breaches to supervisory authorities as required by law.
- Shim's PII redaction does not relieve you of any obligation under GDPR, KVKK, HIPAA, CCPA, LGPD, or any other applicable data protection legislation.
5.4 Transient Data Processing
- Raw prompt content is processed in memory. We do not persist raw prompt or response bodies in durable request records.
- For OpenAI Responses continuations, encrypted PII restoration mappings may be stored in Redis, bound to the tenant and upstream response identifier, for a bounded period of up to 30 days. Missing, corrupt, or expired continuation state causes the request to fail explicitly.
- Operational facts such as timestamps, endpoint, model, status, token counts, cost, and policy outcomes are retained for usage, budget, audit, and compliance reporting. These records do not contain raw prompt or response bodies.
5.5 Explicit Waiver of PII Liability
BY USING THE SERVICE, YOU EXPRESSLY ACKNOWLEDGE AND AGREE THAT:
- Shim Technologies shall not be held liable for any personal data that passes through the system undetected or inadequately redacted.
- Shim Technologies shall not be liable for any direct, indirect, incidental, consequential, or punitive damages, regulatory fines, penalties, or sanctions arising from incomplete or inaccurate PII detection.
- You waive any and all claims against Shim Technologies relating to data breaches, privacy violations, or regulatory non-compliance resulting from the use of our PII detection features.
- You have independently assessed that Shim's PII protection level is suitable for your specific use case and regulatory requirements before processing production data.
5.6 Upstream Provider Processing
- Governed request data is transmitted to the provider configured for the native route: OpenAI, Anthropic, or Google. When PII protection is enabled, Shim sends the redacted payload.
- Each upstream provider has its own data handling, retention, privacy, and service policies. Shim is not responsible for how a provider processes, stores, or uses data it receives.
- BYOK (Bring Your Own Key) users are directly bound by their configured provider's applicable terms of service.
- You acknowledge that despite PII scrubbing, residual context in prompts may still indirectly identify individuals. This risk is inherent to LLM usage and is your responsibility to assess.
6. Access Tiers & Commercial Availability
- Developer access may be offered without a subscription charge, subject to the request, token, and spend controls configured for the account.
- Contact shim for plan availability and commercial approval. Plan activation is handled by an operator.
- Paid entitlements begin after SHIM receives confirmation of payment. Contact support for plan changes and cancellation.
- Enterprise deployment, support, service levels, quotas, and commercial commitments require a separate written order, statement of work, or agreement signed by the parties.
- Configured request-governance limits may reject requests, including with HTTP 429 responses. Account limits do not constitute a promise of reserved upstream-provider capacity.
7. Intellectual Property
- The Service, including its software, algorithms, architecture, documentation, and branding, is the exclusive intellectual property of Shim Technologies.
- You retain all ownership rights to your data, prompts, and content processed through the Service.
- We do not claim any ownership or license over content you transmit through the Service.
- You grant us a limited, non-exclusive license to process your data solely for the purpose of providing the Service (request governance, PII redaction, proxying, and usage accounting).
8. Disclaimer of Warranties
THE SERVICE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS WITHOUT WARRANTIES OF ANY KIND.
TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, Shim TECHNOLOGIES EXPRESSLY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING BUT NOT LIMITED TO:
- Implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
- Any warranty that the Service will be uninterrupted, timely, secure, or error-free.
- Any warranty regarding the accuracy, completeness, or reliability of PII detection.
- Any warranty regarding the accuracy or quality of AI model responses obtained through the Service.
- Any warranty that the Service will meet your specific requirements or expectations.
9. Limitation of Liability
TO THE MAXIMUM EXTENT PERMITTED BY LAW, IN NO EVENT SHALL Shim TECHNOLOGIES, ITS DIRECTORS, EMPLOYEES, PARTNERS, AGENTS, SUPPLIERS, OR AFFILIATES BE LIABLE FOR:
- Any indirect, incidental, special, consequential, exemplary, or punitive damages.
- Loss of profits, revenue, data, use, goodwill, or other intangible losses.
- Regulatory fines, penalties, or sanctions imposed on you by any authority.
- Damages arising from unauthorized access to or alteration of your transmissions or data.
- Damages arising from the conduct or content of any third party, including an upstream provider.
- Any failure or delay in PII detection or redaction functionality.
IN ALL CASES, OUR AGGREGATE LIABILITY SHALL NOT EXCEED THE TOTAL AMOUNT PAID BY YOU TO Shim TECHNOLOGIES IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM. THIS LIMITATION APPLIES REGARDLESS OF THE LEGAL THEORY ON WHICH THE CLAIM IS BASED.
10. Indemnification
You agree to indemnify, defend, and hold harmless Shim Technologies and its officers, directors, employees, agents, and affiliates from and against any and all claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or relating to:
- Your use of the Service or any violation of these Terms.
- Your violation of any applicable law, regulation, or third-party right, including data protection laws.
- Any claim that data you processed through the Service infringed upon the privacy rights of any third party.
- Your failure to obtain necessary consents from data subjects.
- Any regulatory investigation, fine, or penalty arising from your use of the Service.
- Any claim by an upstream provider relating to your use of its services through Shim.
11. Governing Law & Dispute Resolution
These Terms shall be governed by and construed in accordance with the laws of the Republic of Turkey, without regard to its conflict of law provisions.
Any dispute arising out of or in connection with these Terms, including any question regarding its existence, validity, or termination, shall first be attempted to be resolved through good-faith negotiation for a period of thirty (30) days.
If the dispute cannot be resolved through negotiation, it shall be subject to the exclusive jurisdiction of the Central Courts and Execution Offices of Istanbul (Istanbul Caglayan Adliyesi), Republic of Turkey.
Notwithstanding the foregoing, we reserve the right to seek injunctive or other equitable relief in any court of competent jurisdiction to prevent the actual or threatened infringement of our intellectual property rights.
12. Service Availability & Force Majeure
- We target high availability but do not guarantee uninterrupted, continuous, or secure access to the Service.
- The Service may be temporarily unavailable due to scheduled maintenance, emergency maintenance, infrastructure updates, or circumstances beyond our reasonable control.
- We shall not be liable for any delay or failure to perform our obligations where such delay or failure results from events beyond our reasonable control, including but not limited to: natural disasters, acts of government, pandemic, war, terrorism, power failures, internet disruptions, or third-party service outages (including upstream-provider outages).
13. Termination
- We may terminate or suspend your access to the Service immediately, without prior notice or liability, if you breach any provision of these Terms.
- We may terminate or suspend any account that has been inactive for more than 12 consecutive months.
- Upon termination:
- your right to use the Service ceases,
- Shim API keys associated with the terminated access are no longer accepted,
- encrypted OpenAI Responses continuation state remains subject to its bounded expiry policy, and
- operational usage records may be retained as required by law.
- Sections 5 (PII Disclaimer), 8 (Disclaimer of Warranties), 9 (Limitation of Liability), 10 (Indemnification), and 11 (Governing Law) shall survive termination.
14. Changes to Terms
We reserve the right to modify these Terms at any time. Material changes will be communicated via email to the address associated with your account at least 30 days before they take effect. Non-material changes (clarifications, formatting) may be made without notice. Continued use of the Service after the effective date of revised Terms constitutes your acceptance of those changes. If you do not agree with the revised Terms, you must discontinue use of the Service.
15. General Provisions
- Entire Agreement: These Terms, together with our Privacy Policy, constitute the entire agreement between you and Shim Technologies regarding the Service and supersede all prior agreements.
- Severability: If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
- No Waiver: Our failure to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.
- Assignment: You may not assign or transfer these Terms without our prior written consent. We may assign our rights and obligations without restriction.
- Notices: All legal notices to Shim Technologies should be sent to legal@getshim.tech.