Terms of Service
Effective 9 September 2026.
1. Agreement
These Terms of Service (“Terms”) govern access to and use of Velafa CMS and its API (together, the “Service”) operated by Keelan Vella, a sole trader based in Malta (“we”, “us”, “our”).
By creating an account, accepting an invite, or using the Service, you agree to these Terms. If you use the Service on behalf of an organisation, you confirm that you have authority to bind that organisation, and “you” includes that organisation.
2. Definitions
In these Terms:
- “Account” means the user credentials used to access the Service.
- “Customer Content” means content, media, form submissions, configuration, and other data you or your members submit to the Service.
- “Workspace” means a tenant workspace that holds sites, members, and billing context.
- “Site” means a project inside a workspace, including its locales, pages, collections, media, forms, environments, and versions.
- “API Credentials” means workspace API keys and personal access tokens issued by the Service.
3. Eligibility and accounts
You must be at least 16 years old and able to form a binding contract. You must provide accurate registration details and keep them current.
You are responsible for activity under your Account, including sessions on devices you use. Keep your password and API Credentials secret. Tell us promptly at the contact address below if you believe an Account or token has been compromised.
We may require email verification before you can use parts of the Service. Invites expire and may be revoked by a workspace owner or admin.
4. Workspaces, sites, and roles
The Service is multi-tenant. Each workspace has members with one of these roles: owner, admin, or editor. Owners and admins manage members, sites, and settings. Editors work with content within the permissions granted to them.
You decide who you invite. You are responsible for the Customer Content those members create and for removing access when someone should no longer have it.
A workspace may contain multiple sites. Environments belong to a site and may be pinned to a published content version. You are responsible for which version each environment serves.
5. Acceptable use
You must not use the Service to:
- Break the law or anyone else’s rights, including intellectual property and privacy rights
- Upload malware, or attempt to probe, scan, or disrupt the Service or other customers
- Circumvent authentication, rate limits, or access controls
- Send unsolicited bulk messages through forms or notification features
- Misrepresent your identity or the origin of content
- Resell the Service or share an Account except as these Terms allow
6. Customer Content
You retain ownership of Customer Content. You grant us a worldwide, non-exclusive licence to host, process, transmit, and display Customer Content solely to operate, secure, and improve the Service, including generating public artefacts such as sitemap.xml, llms.txt, and robots.txt for environments you configure.
You confirm that you have the rights needed to submit Customer Content and to grant that licence. We do not claim ownership of your sites or of content published through the Service.
Public read endpoints serve the Customer Content you choose to publish. You are responsible for what those endpoints expose.
7. API keys and personal access tokens
Workspace API keys (including live and test prefixes) and personal access tokens let software call the Service on your behalf. Treat them as secrets. Anyone who holds a credential can act within its scopes until you revoke it.
You are responsible for calls made with your API Credentials, including rate-limit impact and any content those calls create, change, or delete. Revoke credentials you no longer need. We may revoke credentials that we reasonably believe are leaked or abused.
8. Third-party integrations
The Service can connect to third-party products when you choose to, including Vercel, Google (Analytics and Search Console), Microsoft Bing Webmaster Tools, and Spotify. Those products have their own terms and privacy notices.
We store the tokens and configuration needed to keep a connection working. You can disconnect an integration from the console. We are not responsible for the availability or policies of third-party services.
9. Fees
The Service is provided free of charge during the current beta. If we introduce paid plans, we will give you notice before charges apply and will not bill you without an agreed plan.
You remain responsible for costs you incur with third parties you connect, such as hosting, domains, or advertising accounts.
10. Availability, beta, and support
The Service is offered as a beta. Features may change, and we do not guarantee uninterrupted availability, particular uptime, or that the Service will meet a specific purpose.
Support is provided on a reasonable-efforts basis through the contact address in these Terms. We may throttle or queue requests to protect the Service.
11. Suspension and termination
You may stop using the Service and close your Account at any time by contacting us. Workspace owners may remove sites and members.
We may suspend or terminate access if you breach these Terms, if we must do so by law, or if continued use would harm the Service or other customers. We will try to give notice where it is lawful and practical.
After termination we may delete Customer Content after a reasonable period, except where we must keep records for legal reasons. Export what you need before you close a workspace.
12. Data export and deletion
You may export Customer Content through the console and the API while your Account is active. After termination we will delete Customer Content from active systems when it is no longer needed to operate the Service or to meet a legal obligation.
Backups may retain residual copies for a limited time until they rotate. Session cookies and tokens stop working when we revoke the related session or credential.
13. Disclaimer of warranties
The Service is provided “as is” and “as available”. To the fullest extent permitted by the law of Malta, we disclaim implied warranties of merchantability, fitness for a particular purpose, and non-infringement.
We do not warrant that the Service will be error-free, that content will never be lost, or that third-party integrations will continue to work without change.
14. Limitation of liability
Nothing in these Terms limits liability that cannot be limited under the law of Malta, including liability for death or personal injury caused by negligence, or for fraud.
Subject to that, we are not liable for indirect, incidental, special, consequential, or punitive loss, or for lost profits, revenue, data, or goodwill, whether in contract, tort, or otherwise, even if we were told they were possible.
Our total liability for all claims arising out of the Service is limited to the greater of (a) the fees you paid us for the Service in the three months before the claim, and (b) one hundred euro (€100).
15. Indemnity
You will indemnify us against claims, damages, and reasonable costs arising from Customer Content, your use of API Credentials, or your breach of these Terms, except to the extent the claim is caused by our own breach or negligence.
16. Changes
We may change the Service and these Terms. For material changes we will post the updated Terms on this page and, where practical, notify Account holders. Continued use after the effective date of a change is acceptance of the updated Terms. If you do not agree, stop using the Service and contact us to close your Account.
17. Governing law
These Terms are governed by the laws of Malta. The courts of Malta have exclusive jurisdiction, without prejudice to any mandatory consumer rights you may have in your country of residence.
18. Contact
Questions about these Terms: Keelan Vella, Malta, keelan@velafa.digital. The Service is available at https://cms.velafa.digital.