Terms of service
Last updated 25 September 2026
These terms govern the use of rollout: the dashboard at app-staging.rollout.so, the API, widget and MCP server at api-staging.rollout.so, and everything else we offer under staging.rollout.so (together, “rollout”). By creating an account you accept them. The annex is our data processing agreement for the data about your users that rollout processes on your behalf.
1. Provider and scope
rollout is provided by mita flow GmbH, Kirchplatz 18, 94474 Vilshofen an der Donau, Germany (“we”; details in the imprint). Our contract is with the company or organisation for which you create or join a workspace (“customer”, “you”).
rollout is offered only to businesses within the meaning of § 14 BGB, not to consumers. By signing up you confirm that you are using rollout for your trade, business or profession. Your own terms and conditions don't apply, even if we don't object to them.
2. The service
rollout lets you write product announcements and publish them to an in-app feed in your product, a public changelog, and your email platform. What rollout can do at any time is described in the dashboard and in the documentation.
rollout is currently in early access. We develop it continuously and may add, change or remove features. We tell you in good time before we remove a feature you rely on, and at least 30 days before we discontinue rollout as a whole, so that you can take your content with you (section 10). We may set reasonable usage limits (for example on projects, users or requests) to keep rollout working for everyone.
3. Fees
During early access, rollout is free of charge. If we introduce paid plans, we will tell you in advance. A paid plan only applies to you if you expressly agree to it; your workspace is never moved to a paid plan automatically.
4. Accounts and workspaces
- Give accurate information when you sign up and keep it up to date.
- Keep sign-in details, API keys, signing secrets and secret keys confidential. You are responsible for what happens with them and with the accounts of the people you invite to your workspace, and for giving each person only the role they need.
- Tell us without delay at info@mitaflow.com if you suspect that an account or key has been misused.
5. Your content and your users
Your content (announcements, snippets, images and settings) remains yours. You grant us the rights we need to host, process, display and deliver it for the purpose of providing rollout to you, including publishing it through the channels you choose (in-app feed, public changelog, email).
You are responsible for:
- your content, including that it is lawful and that you have the rights to it (for example to images);
- the data about your users that you send to rollout, and having a legal basis for it; the annex governs how we process it;
- the emails sent from your email platform, including that recipients agreed to receive them. rollout prepares campaign drafts; you or your team send them.
6. Acceptable use
You may not use rollout to:
- publish unlawful content or content that infringes the rights of others;
- distribute malware, send spam, or deceive people (for example by impersonating someone);
- attack, overload or probe rollout, circumvent its limits or security, or access other customers' data. Security research needs our prior agreement in text form;
- copy or rebuild rollout by reverse engineering, except where the law expressly allows it.
If we have concrete indications of a breach, we may block affected content or access, taking your legitimate interests into account, and tell you about it. We lift the block once the reason no longer applies.
7. Third-party services
rollout connects to services you choose and contract with yourself, such as your email platform (Loops) or AI assistants you connect to the MCP server. Their own terms apply to them; we are not responsible for how they work or what they do with data you share with them. When you connect such a service, you instruct us to exchange data with it as needed for the connection.
8. Availability
During early access we don't promise a particular availability. We do our best to keep rollout running and to announce planned maintenance in advance.
9. Liability
Because rollout is free during early access, we are liable only for intent and gross negligence. This limitation does not apply to injury to life, body or health, to liability under the Product Liability Act (Produkthaftungsgesetz), to guarantees we have given, or to fraudulently concealed defects; there we are liable under the statutory provisions. Liability for data processing under Art. 82 GDPR remains unaffected.
Once you use a paid plan, the terms agreed for it govern liability instead of the first sentence above.
10. Term and termination
The contract runs for an indefinite period. You can end it at any time by deleting your workspace or asking us to. We can end it with 30 days' notice in text form. Either side may terminate for good cause without notice, for example after a serious breach of section 6.
Before the contract ends, you can ask us for a copy of your content in a common, machine-readable format (for example Markdown and JSON). We delete your workspace data within 30 days after the end, unless the law requires us to keep it longer.
11. Changes to these terms
We may change these terms for good reason, for example new features, a changed legal situation or the introduction of paid plans. We tell you about changes by email at least 30 days before they take effect. If you don't object in text form before then, the new terms apply; we point this out in our notice. If you object, the current terms continue to apply and either side may end the contract as of the date of the change. Fees always need your express agreement (section 3).
12. Final provisions
- German law applies, excluding the UN Convention on Contracts for the International Sale of Goods (CISG).
- If you are a merchant (Kaufmann), a legal entity under public law or a special fund under public law, the exclusive place of jurisdiction is Passau, Germany. We may also sue you at your general place of jurisdiction.
- Declarations under these terms can be made in text form (for example by email), unless stated otherwise.
- If a provision of these terms is invalid, the rest remains valid; the statutory provisions take its place.
Annex: Data processing agreement
This agreement under Art. 28 GDPR applies when rollout processes personal data on your behalf. You are the controller and we are your processor. It is part of the contract and runs as long as the contract does.
A1. Subject, nature and purpose
We process personal data only to provide rollout to you: storing the users and organisations you tell rollout about, deciding which announcements each user sees, keeping track of what they have read, and answering the requests of your product and your servers.
A2. Data and data subjects
- Data subjects: the users of your product (and the organisations they belong to) who use the in-app feed or whom you send to rollout's API.
- Data: user and organisation identifiers you choose; the attributes you send for targeting (for example plan or role); when a user was first and last seen; which announcements they have read; and, in our server logs, IP addresses and technical request data (section 2 of the privacy policy).
Don't send special categories of personal data (Art. 9 GDPR) to rollout; the service isn't designed for them.
A3. Instructions
We process the data only on your documented instructions: these terms, your settings in rollout, and your requests to the API, plus any further instructions in text form. We tell you without delay if we believe an instruction infringes data protection law. We don't use the data for our own purposes. Where EU or member state law requires us to process data otherwise, we tell you beforehand unless that law prohibits it.
A4. Confidentiality
Everyone at mita flow GmbH with access to the data is bound to confidentiality and processes it only on your instructions.
A5. Security
We take appropriate technical and organisational measures under Art. 32 GDPR, including:
- encryption of all connections (TLS) and of the stored data;
- separation of customers in the database by row-level security, in addition to checks in the application;
- access by role, keys that can be revoked and may expire, and secrets kept in a vault;
- server logs deleted after 30 days at the latest;
- regular review and improvement of these measures as rollout develops.
A6. Sub-processors
You authorise us to use these sub-processors for the data in A2:
- Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany: servers in Germany and Finland.
- BunnyWay d.o.o. (Slovenia): content delivery network and protection service in front of our API and websites; it passes requests through to our servers.
- Supabase, Inc. (USA): database and file storage, with the data stored in the EU (Frankfurt, Germany). Transfers based on the EU–US Data Privacy Framework or the EU standard contractual clauses.
We bind sub-processors to the same data protection obligations. We tell you by email at least 30 days before adding or replacing a sub-processor. You can object for good reason within that time; if we can't resolve it, you can end the contract as of the change.
A7. Assistance
We help you answer requests from data subjects (Art. 12–23 GDPR), for example by deleting a user and their read state through the dashboard or the API, and with your obligations under Art. 32–36 GDPR, as far as our processing is concerned.
A8. Data breaches
We notify you without undue delay once we become aware of a personal data breach affecting your data, with the information you need for your own notifications.
A9. Deletion at the end
When the contract ends, we delete the data within 30 days, unless the law requires us to keep it. Before then, you can ask us for a copy (section 10).
A10. Evidence and audits
We provide the information you need to verify compliance with this agreement. You may audit us, or have an auditor bound to confidentiality do so, with reasonable notice, during business hours and without disrupting our operations, usually no more than once a year unless there is a specific reason.