Osprey Approach API Access and Use Terms

Effective from 27 September 2026. Published 26 August 2026.

This policy forms part of the Osprey Approach Software Licensing & Services Agreement between Pracctice Limited and the Customer (Schedule I). Capitalised terms have the meanings given in that Agreement. In the event of any conflict, the Agreement prevails.


1. Application and Grant

1.1 This Schedule applies to any application programming interface, webhook, software development kit or other programmatic interface made available by Pracctice in connection with the Software (API), and to all access to and use of an API by or on behalf of the Customer (API Access).

1.2 API Access is available only where and to the extent expressly enabled by Pracctice. Nothing in this Agreement obliges Pracctice to make any API, endpoint, method or capability available unless expressly stated in the Commercial Schedule.

1.3 Where API Access is enabled, Pracctice grants the Customer a personal, non-exclusive, non-transferable right to use the API for the Customer’s own internal business purposes, through the supported and documented endpoints and methods only, and in accordance with this Agreement, the Acceptable Use Policy and Pracctice’s published API documentation as amended from time to time.

1.4 API Access does not create any additional Licence, matter capacity, storage entitlement, functionality commitment or Service Level beyond those expressly provided in this Agreement.

2. Credentials and Attribution

2.1 API credentials issued to or generated for the Customer are for the Customer’s use only. The Customer is responsible for the security, confidentiality and proper use of its API credentials.

2.2 Any access, request, instruction, extraction or other activity carried out using the Customer’s API credentials is treated as carried out by the Customer, whether performed by the Customer, a User, a third party engaged by the Customer or any other person using those credentials.

2.3 The Customer must notify Pracctice promptly on becoming aware of any compromise, loss or unauthorised use of its API credentials. Pracctice may revoke, rotate or reissue credentials at any time where reasonably required for security or operational reasons.

3. Third-Party Access and Approval

3.1 No third-party software provider, developer, integrator or other third party may exercise API Access on the Customer’s behalf unless that third party has first been approved by Pracctice in writing (an Approved Third Party).

3.2 A request for approval must be made by the Customer and must identify the third party, the application or service concerned, and the nature, purpose and expected volume of the intended access. Pracctice may request further information reasonably required to assess the request.

3.3 Pracctice may grant or refuse approval at its discretion, and may grant approval subject to conditions, including conditions as to scope, endpoints, volume, purpose, security requirements or duration. Without limiting that discretion, Pracctice may refuse approval where it considers that:

  • the third party is, or is connected with or under common ownership or control with, a competitor of Pracctice;

  • the access would present a security, operational, legal or regulatory risk;

  • the access would breach or be likely to breach this Schedule or the Acceptable Use Policy; or

  • the volume, pattern or purpose of the intended access is inconsistent with the Customer’s own internal business use of the Software.

3.4 Pracctice may withdraw or vary an approval, or restrict or suspend an Approved Third Party’s access, where any ground in Section 3.3 applies or where a condition of approval is not met. Pracctice will give the Customer reasonable notice of a withdrawal except where immediate action is reasonably required for security, legal or regulatory reasons.

3.5 The Customer remains fully responsible for the access and use of the API by an Approved Third Party as if it were the Customer’s own, including compliance with this Schedule and any conditions of approval.

3.6 API Access exercised by or on behalf of a third party that is not an Approved Third Party is unauthorised, and Pracctice may block or suspend it without notice. Such access is a breach of this Schedule by the Customer where it occurs using the Customer’s credentials or with the Customer’s knowledge or authority.

3.7 A withdrawal, variation, restriction, suspension or block under this Section applies to the relevant third-party access only and does not of itself suspend the Customer’s own use of the Software.

3.8 Approval of a third party does not create any right, benefit or entitlement in favour of that third party under this Agreement, and Pracctice owes no obligation, support commitment or duty of care to any Approved Third Party.

4. Usage Limits

4.1 API Access does not create an entitlement to unlimited API usage.

4.2 Pracctice may impose, vary and enforce reasonable rate, volume, concurrency, frequency or other technical limits on API usage where necessary to manage service capacity, security, cost, fair use across customers or operational performance.

4.3 Pracctice may throttle, queue or reject API requests that exceed applicable limits or that materially affect the performance or stability of the Software or the Service provided to other customers.

5. Versioning, Modification and Deprecation

5.1 Pracctice may modify, version, supersede, suspend or withdraw any API, endpoint, method, data structure or capability.

5.2 Pracctice will give reasonable notice of a material deprecation or withdrawal of a generally available API capability, except where a change is required urgently for security, legal or regulatory reasons.

5.3 Pracctice is not obliged to maintain any API, version or endpoint indefinitely, and no obligation to maintain compatibility with the Customer’s or a third party’s systems, code or integrations arises under this Agreement.

6. Prohibited Use

6.1 The Customer must not, and must ensure that no person exercising API Access on its behalf:

  • use the API to circumvent, exceed or undermine Licence quantities, matter capacity limits, usage limits or any other commercial or technical control applicable under this Agreement;

  • carry out systematic, bulk or comprehensive extraction, replication, copying or downloading of the Customer’s database, document store or a substantial part of either, whether in one operation or by accumulation over time;

  • use the API to construct, populate or maintain a substitute, parallel or replacement copy of the Customer’s practice management data outside the Software, except through data feeds or exports expressly supported by Pracctice for that purpose;

  • use the API, or permit it to be used, to facilitate or effect migration of the Customer’s data to an alternative practice or case management system;

  • resell, sublicense or provide API Access or API-derived data as a service to any third party;

  • use the API or API-derived data to develop, train, improve or operate a product or service which competes with the Software;

  • conduct load, stress, penetration or performance testing against the API without Pracctice’s prior written agreement; or

  • access the API by any method other than the supported and documented endpoints and authentication mechanisms.

6.2 Ordinary operational integration traffic – the exchange of data reasonably required for the day-to-day operation of a permitted integration in the course of the Customer’s business – is not prohibited by Section 6.1.

6.3 The sole means of obtaining a full copy of the Customer’s database under this Agreement are the full Customer database backup available during the Term under Clause 6 and the End of Agreement Backup provided under Schedule C. The API is not a mechanism for full database export.

7. Data Extracted via the API

7.1 Data retrieved through the API from the Customer’s use of the Software remains Customer Data and remains the property of the Customer.

7.2 Once data has been retrieved through the API and has left the Software, its storage, security, accuracy, onward processing, disclosure and use are solely the Customer’s responsibility. Schedule G applies to Pracctice’s Processing of Customer Personal Data within the Software and Services and does not apply to data after it has been retrieved by or on behalf of the Customer.

7.3 The Customer is responsible for ensuring that its retrieval and onward use of data through the API, including retrieval by a third party on its behalf, complies with Data Protection Law and the Customer’s professional and regulatory obligations.

8. Availability and Warranty

8.1 Unless expressly stated otherwise in the Commercial Schedule, API availability is not included in the Platform Availability target in Schedule B.

8.2 Pracctice does not warrant that any API is uninterrupted, error-free or fit for the Customer’s or a third party’s particular integration, system or purpose.

9. Support

9.1 Support Services in relation to an API are limited to the operation of the API substantially in accordance with Pracctice’s published API documentation.

9.2 Investigation, debugging, modification or support of the Customer’s own code, configuration or systems, or of a third party’s application or integration, is not included and may be provided, where Pracctice agrees, as Additional Services.

10. Charges

10.1 Where API usage is subject to charges, metering or included usage allowances, those commercial particulars will be stated in the Commercial Schedule or otherwise agreed with the Customer.

10.2 Pracctice may introduce charges for API usage which is currently uncharged on reasonable written notice, provided that usage within any allowance stated in the Commercial Schedule remains within that allowance for the Term.

11. Suspension

11.1 Pracctice may suspend API Access, in whole or in part, where reasonably necessary to:

  • prevent or contain a security incident;

  • prevent material disruption to the Software or other customers;

  • prevent unlawful use;

  • address a breach or suspected breach of this Schedule;

  • block or suspend access by a third party that is not an Approved Third Party; or

  • give effect to a refusal, withdrawal, variation or restriction under Section 3.

11.2 Where reasonably practicable, suspension will be limited to the affected credentials, endpoint, third party or activity.

11.3 Suspension of API Access does not of itself suspend the Customer’s use of the Software and does not relieve the Customer of its payment obligations under this Agreement.

12. Relationship with the Agreement

12.1 This Schedule forms part of the Agreement and is incorporated into the Acceptable Use Policy by reference. A breach of this Schedule is also a breach of the Acceptable Use Policy.

12.2 In the event of any inconsistency or conflict between this Schedule and the Main Agreement, the Main Agreement shall prevail.

12.3 Nothing in this Schedule extends the functionality, availability, warranty or Service Level obligations otherwise undertaken by Pracctice under this Agreement.

AMENDMENT TO THESE API TERMS

Published 30 August 2026. Effective from 30 September 2026.

This amendment forms part of these API Terms from its effective date and is published by website posting in accordance with the Main Agreement. Until the effective date, the existing terms apply unchanged.

1. Purpose of customer API access and the Osprey Insights Database

Customer API access and the Osprey Insights Database are provided for operational use of the Software during the Term. They may not be used to assemble a substantially complete copy of the Customer’s data, to populate a replacement system, or to facilitate migration to another supplier. Data extraction for exit purposes is provided exclusively through the backup services described in the Main Agreement.

2. Access by plan

Advanced: no customer API access and no Power BI connections.

Premium: read-only customer API access is included, comprising one API key and up to 5,000 requests per calendar day on standard endpoints, subject to fair use. Bulk extraction is not permitted at any request volume.

Enterprise: API consumption parameters (allowances, keys, refresh frequency and workload scale) are as recorded in the Customer’s Commercial Schedule.

Integrations supplied by Pracctice (for example InfoTrack, DocuSign and Lexis Smart Forms) are not customer API access and are unaffected by this amendment.

3. Osprey Insights Database

The Osprey Insights Database contains client, matter and financial data only. Documents and files are excluded; bulk document supply is provided through the backup services described in the Main Agreement. The standard refresh cycle is overnight; increased refresh frequency is available only under an Enterprise arrangement. Standard provisioning supports typical reporting workloads; sustained excessive compute may require an Enterprise arrangement. An active Osprey Insights Database is required for Power BI connections and for intensive or bulk API consumption.

4. Artificial intelligence systems

Customer API access and the Osprey Insights Database may not be used to train, fine-tune, or ground artificial intelligence systems on the structure, schemas, or systematically extracted contents of the Software; to develop, derive, or operate functionality that replicates or substitutes for any part of the Software; or to operate an intermediary interface (including AI agents) through which users interact with Customer Data in place of the Software. Nothing in this clause restricts the Customer’s use of its own data, exported through the services provided for that purpose, outside these access channels. Using AI tools to analyse reports, dashboards and outputs produced from the Osprey Insights Database is operational use and is permitted.

5. Monitoring and general

Pracctice may monitor API and Osprey Insights Database consumption for capacity management and compliance with these terms. Any breach of this amendment is treated as a breach of these API Terms under the Main Agreement.