Third-Party Terms
What is inside the product that we did not write, the licences it comes under, and which of those obligations flow through to you.
These Third-Party Terms are incorporated into the Terms and Conditions. They describe third-party software, models and services embedded in or used to deliver the DECTIFY Platform.
1. How third-party licences interact with your agreement
Where a third-party component is licensed to you directly under its own terms, those terms govern that component, and to the extent of any conflict they prevail over the Terms and Conditions for that component alone. DECTIFY gives no warranty and accepts no liability in respect of a third-party component beyond what clause 11.2 of the Terms and Conditions requires of the Services as a whole.
Open source licences that grant you rights — to use, study, modify and redistribute — are not restricted by anything in our agreement. Where a licence entitles you to source code, we will provide it as that licence requires.
2. Component categories
| Category | Typical licences | Where it sits | Flows through to you? |
|---|---|---|---|
| Application libraries and frameworks | MIT, BSD, Apache 2.0 | Platform and edge software | Attribution only |
| Computer vision and numerical libraries | Apache 2.0, BSD, MPL 2.0 | Inference pipeline | Attribution; MPL source availability for modified files |
| Model architectures and pretrained weights | Apache 2.0, MIT, AGPL-3.0, bespoke research licences | Detection and recognition models | See section 3 |
| Copyleft components | GPL-2.0, GPL-3.0, LGPL | Operating system and edge tooling, kept at arm's length from linked application code | Source offer on request |
| Fonts and design assets | SIL OFL, commercial licences | Interface | No |
| Cloud and infrastructure services | Commercial terms | Hosting, storage, delivery | Via the Sub-processors list |
3. Model licences, and why we care about AGPL
AGPL-3.0 is the licence that most often catches computer-vision products. Several widely used detection frameworks — including some YOLO distributions — are AGPL-3.0. AGPL's section 13 extends the source-provision obligation to users who interact with the software over a network, which is exactly how a hosted platform is used. Treating an AGPL model framework as though it were MIT is the most common licensing error in this industry.
DECTIFY's position:
- Every model framework is licence-reviewed before adoption, and the licence is recorded in the model card alongside the performance data.
- Where an AGPL-licensed component is used in a network-facing service, we comply with section 13 by making the corresponding source of that component and our modifications to it available to users of that service. Request it from opensource@dectify.in and we will provide it at no charge.
- Where a commercial licence for such a framework is available and we hold one, we say so in the notices file rather than leaving you to guess which basis applies.
- Pretrained weights are treated as licensed artefacts in their own right. A permissive code licence does not imply a permissive weights licence, and we do not assume it does.
- Research-only or non-commercial weights are not shipped in a commercial product. Ever.
4. The notices file
A complete, machine-readable inventory of third-party components in each release — name, version, licence, and copyright notice — is published with that release and is available at [notices URL], and on request from opensource@dectify.in.
We generate it from the build rather than maintaining it by hand, so it reflects what actually shipped. A software bill of materials in SPDX or CycloneDX format is available to customers on request, and is provided as standard to government buyers.
5. Source code requests
For any component whose licence entitles you to source, write to opensource@dectify.in naming the product, the version and the component. We provide it within thirty (30) days, by download link, at no charge beyond any cost the licence permits us to recover. This offer is valid for as long as the licence requires and in any event for three (3) years from the date you received the binary.
6. Vulnerability management in the supply chain
- Dependencies are scanned continuously against public vulnerability databases, and on every build.
- Critical vulnerabilities in internet-facing components are remediated within forty-eight (48) hours of a fix being available; the full schedule is at Vulnerability Disclosure Policy.
- Where no fix exists, we mitigate — configuration, isolation, or removal of the component.
- Where a vulnerability in a third-party component affects Customer Data, our notification obligations run exactly as they would for our own code: 6 hours to CERT-In, 12 or 72 hours under the SOCI Act, 72 hours to affected customers.
- Unmaintained components are replaced rather than carried. A dependency with no upstream maintainer is a security defect.
7. Cloud and infrastructure providers
Hosting, storage, content delivery, email and analytics providers are listed with their locations and functions at Sub-processors. Each is bound by the obligations at Vendor Terms, including data protection, security and incident notification fast enough to let us meet our own statutory clocks.
8. Third-party marks
Marks belonging to third parties that appear in our documentation or interface are the property of their owners, used for identification only, and their appearance is not an endorsement of DECTIFY. See Intellectual Property and Trademark Notice s.7.
9. Contributing back
Where we fix a defect in an open source component we use, we offer the fix upstream. Where we publish our own open source, it is released under a permissive licence and listed at [open source page].
10. Reporting a licensing concern
If you believe DECTIFY is using a component contrary to its licence, write to opensource@dectify.in with the component and the basis for your concern. We acknowledge within three (3) business days, investigate, and either correct our compliance or explain why we consider it correct. We treat a licence compliance report the same way we treat a security report: as useful information, not as an accusation to be defended against.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India