PrytanPrytan
All legal documents

Terms for booking platforms

Version 2026-10-02. A lawyer is reviewing this document; any change is posted here with its date before it applies.

A draft for signature. Not in force, and not accepted by a click. These terms take effect between Prytan and a booking platform only when both have signed them. They are finalised with the lawyer when the first real partner appears.

These terms are between [Company name, kennitala, registered address, Iceland] ("Prytan", "we") and the booking platform that signs them ("the Platform", "you"). Contact: support@prytan.ai.

1. What this agreement is about

Prytan is a service through which people's AI assistants find independent businesses and book appointments with them. Prytan books through the booking system each business already uses.

You run a booking system. You build a connection to Prytan's published standard (the Standard, `prytan/1`, and its later versions). Once Prytan has approved it, the businesses that use your system (your Merchants) can connect to Prytan, and people's AI assistants can book with them through Prytan.

2. No fee to connect

  • For as long as this agreement is in force, Prytan charges the Platform no fee to connect, to be listed, or for bookings. Prytan's revenue comes from the businesses' own subscriptions.
  • Prytan does not pay you, and neither side charges the other a commission.
  • A change to this clause is never retroactive: it never applies to connections or bookings made before it.

3. What you guarantee

  1. Accurate, live availability. The free times you give Prytan are worked out live from your system on every call, and are true when given. You never return a time that is not free, in the past, or outside the business's own rules.
  2. Honouring bookings. A booking your system accepts through Prytan is an ordinary, confirmed booking in your system, kept and shown to the Merchant like any other.
  3. An honest, revocable Allow screen. Your Merchant Allow screen names Prytan, lists in plain words what Prytan may do, asks for nothing more, and says how to revoke. A Merchant can revoke Prytan's access in your product at any time, and revoking takes effect at once. The same applies to your customer Allow screen, if you offer customer accounts (clause 5).
  4. Your own terms permit it. You confirm that your customer terms, your Merchant terms and your privacy notice permit and describe access through Prytan. You are responsible for those documents.
  5. Change notices, if you declare them. If your capability declaration says you send change notices, you send a signed notice within a minute whenever a booking made through Prytan is moved or cancelled on your side.
  6. Declared means working. Every ability you declare works as the Standard says. You do not declare an ability you have not built.
  7. Least privilege. Prytan's access to your Merchants never includes a read of their customer lists.
  8. Security. You keep your interface on HTTPS, keep Prytan's tokens and the shared webhook secret confidential, and tell us without undue delay of any security incident affecting Prytan's access or bookings made through Prytan.
  9. Keeping the test kit passing. Your implementation keeps passing Prytan's conformance test kit for every ability you declare. You tell us before a change on your side that could break it.
  10. Your Merchants' consent. You connect a Merchant to Prytan only through that Merchant's own Allow.

4. What Prytan guarantees

  1. The person confirms first. Before any booking is sent to your system, the person confirms a plain summary of it (business, service, time, staff where chosen, price where known).
  2. The business's rules are respected. Prytan never bypasses a rule your system reports: prepayment, existing customers only, notice periods, the booking horizon, cancellation and change windows. Where a rule stops a booking, Prytan points the person to the business's own booking page.
  3. Neutral ranking, never paid. Prytan orders results by distance, then by name. No one can pay for a better place: not you, not another platform, not a business, not anyone. See how results are ordered.
  4. No payment through Prytan. Prytan does not take, hold or pass on money or card details. A service that needs prepayment is not booked through Prytan.
  5. Honest data. Prytan shows people what your system says, and nothing it does not know. An unknown value is shown as unknown, never guessed.
  6. Only its own bookings. Prytan reads back, moves and cancels only bookings it made, each by its own id. It never lists a Merchant's calendar and never stores another appointment or customer.
  7. Security. Prytan stores your tokens encrypted, uses them only as these terms allow, and deletes them when the Merchant disconnects or this agreement ends.

5. Acting on a customer's behalf (customer accounts)

This clause applies only if you offer the customer accounts extension of the Standard. In Prytan this feature is built and switched off until a platform supports it.

  1. Only after the person connects. Prytan acts in a person's account on your platform only after that person has connected their account through your own sign-in, and allowed it on your own customer Allow screen. Prytan never sees or stores the person's password.
  2. What Prytan may then do, and nothing else: see that customer's standing at a Merchant (whether they are a known customer, and which staff they may book); book in that customer's account, after the person confirms each booking; see, move and cancel bookings made through Prytan; and list the customer's bookings, only to show them to that person, at their request.
  3. The record. Prytan keeps a record of each connection: what the Allow screen showed, when, and which person. The legal basis for acting in the account is the person's contract with Prytan: they asked for exactly this.
  4. Disconnecting at any time, on either side. The person can disconnect in Prytan or in your product. Either takes effect at once. Prytan then deletes its copy of the customer's token.
  5. Only for that person. Prytan uses a customer's token only for that person's own requests. What it learns (their standing, their bookings) is never shown to anyone else, including the Merchant, another platform or another person.
  6. What you learn. You learn that this customer booked through Prytan. Prytan does not give you the person's bookings at other businesses or platforms, their preferences, or their Prytan account details.

6. Data roles

  • Separate controllers. You are the controller of your customers' accounts and your Merchants' data on your platform. Prytan is the controller of a person's Prytan account, and of collecting and sending the booking that person asked for. Neither is the other's processor, and we are not joint controllers.
  • A Merchant's customers. Prytan is the Merchant's processor only for what it keeps and shows for the Merchant (the booking record, notifications, reading back its own bookings), under Prytan's data-processing terms with the Merchant. You remain whatever your own agreement with the Merchant makes you.
  • Your privacy notice. Your privacy notice tells your customers that they may connect outside services such as Prytan, what is shared when they press Allow (their standing and their bookings), that Prytan is a separate controller, and how to disconnect.
  • Each side's own duties. Each side is responsible for its own legal basis, its own notices and the rights of the people concerned.
  • If the two of us ever decide purposes together, for example a shared sign-in, we agree the roles for that in writing first.

7. Data protection

  1. Encryption. Tokens, keys and secrets are encrypted at rest; all traffic between us is encrypted in transit.
  2. Minimal data. Each side sends the other only what the Standard needs. No customer lists, no payment details, no passwords.
  3. Breach notice. Each side tells the other of a personal-data breach affecting data exchanged under this agreement without undue delay, and in any case within 48 hours of learning of it, with what it knows.
  4. Sub-processors. Prytan's sub-processors are on its sub-processor list. Prytan tells you before adding one that would receive data from your system.
  5. Deletion. When this agreement ends, Prytan deletes your tokens at once and other data received from your system as its data-processing terms say.
  6. Help. Each side helps the other, at reasonable effort, to answer a person who exercises their data-protection rights.

8. Suspension

  1. Automatic hiding. Prytan checks every live connection automatically, every night. The thresholds are published with the Standard. Today: a connection that fails two checks in a row is hidden from AI assistants automatically. Your Merchants then answer "not bookable right now" with their own booking page, and nothing is invented. We email your technical contact at the moment of hiding. A hidden connection is checked again every hour and is restored automatically the first time it passes. This is not a breach by either side.
  2. Suspension for serious misuse. We may suspend your connection for serious misuse, including using it to mislead people, to book against a Merchant's rules, or to harvest data. Before a suspension that is not urgent, we tell you the reason in writing and give you 5 working days to respond. Where an urgent risk to people, Merchants or the service makes that impossible, we suspend first, give you the reason in writing at once, and review the suspension within 5 working days.
  3. You may pause your connection at any time by telling us. Your Merchants then answer "not bookable right now".

9. Branding

  1. Each side may use the other's name and logo to say, truthfully, that your system connects to Prytan (for example "Bookable through Prytan" or "Supported: [your system]").
  2. Neither side may suggest an endorsement, a ranking advantage or a partnership beyond this agreement.
  3. Each side follows the other's reasonable brand guidelines, and stops using the other's marks when this agreement ends.

10. Ending the agreement

  1. Either side may end this agreement with 30 days' written notice, for any reason.
  2. Either side may end it at once if the other is in serious breach and has not put it right within 14 days of written notice, or at once where the breach cannot be put right.
  3. When it ends, Prytan stops calling your system, takes your Merchants off its listings, and deletes your tokens. Bookings already made stay ordinary bookings in your system, and each side keeps its obligations under clauses 5.5, 7 and 11.
  4. The person always keeps the right to disconnect a customer account, and the Merchant always keeps the right to revoke, whatever this agreement says.

11. Liability

  1. Each side is responsible for its own part: you for your system's availability, its bookings and its data; Prytan for its service, the person's confirmation and its data.
  2. Neither side is liable to the other for indirect losses, such as lost bookings or lost profit.
  3. Since no money changes hands, each side's total liability to the other is capped at ISK 1,000,000 in any twelve months.
  4. The cap and the exclusion do not apply to loss caused by intent or gross negligence, to a breach of confidentiality, to claims an individual brings under data-protection law, or to anything the law does not allow to be limited.
  5. Mutual indemnity. Each side covers the other's reasonable loss and costs from a claim by a third party that is caused by its own breach of this agreement. Where an individual recovers the whole of a data-protection loss from one of us, that side may recover the other's share from the other.

[The amount of ISK 1,000,000 is proposed and under legal review.]

12. Changes to these terms and to the Standard

  1. We may change these terms with 30 days' written notice. If you do not accept a change, you may end the agreement before it applies.
  2. A new version of the Standard does not stop an approved implementation from working without notice. How long an older version stays supported is agreed when the new version is published.

13. Law and disputes

Icelandic law applies. Disputes go to the District Court of Reykjavík (Héraðsdómur Reykjavíkur).

Questions: support@prytan.ai. Report a bug.