Contractual terms

API Terms of Use

The conditions under which an EmCurso API key is granted and used. They apply from the moment the key is issued and for as long as it is used — nothing further needs signing.

Version
1.1
In force since
3 August 2026

These terms supplement the general EmCurso.PT Terms and Conditions, which continue to apply to anything not specifically covered here. Where the two contradict each other on API access, this document prevails.

The Portuguese version is the binding one. This English translation exists for comprehension; in the event of divergence, the Portuguese text prevails.

1.

Subject matter

What this document governs

  1. These terms govern access to and use of the programming interface made available at api.emcurso.pt (the “API”), operated by EmCurso.PT (the “provider”), by anyone holding a valid access key (the “holder”).

  2. The API gives access to information on civil-protection occurrences, weather warnings and forecasts, fire risk and history, traffic disruption and supporting geographic data, gathered from official and third-party sources identified in article 7.

  3. “Integration” means any system, application or process of the holder that makes requests to the API; “end user” means any person to whom the holder presents information obtained through it.

2.

Acceptance

How these terms come to bind

  1. The holder accepts these terms when submitting the access request, by expressly declaring so on the form, and reiterates that acceptance with every request made to the API using the key issued to them.

  2. Where a key is requested on behalf of an organisation, the person requesting it warrants that they have authority to bind it. The obligations in these terms fall on the organisation named in the request, not only on the individual who submitted it.

  3. Access is granted case by case and creates no vested right. The provider may refuse a request without being obliged to give reasons, in particular where the stated purpose is incompatible with article 6.

3.

Nature of the service

What the API is and is not

  1. EmCurso is a not-for-profit project. It is not a public authority, is not an official service and is not an emergency channel. The API is a technical means of access to information produced by other bodies, processed and normalised by the provider. In an emergency, the number to call is 112.

  2. The information may contain delays, gaps, duplicates or errors originating from the sources, and may be corrected or withdrawn by them without notice. The provider does not validate the substantive content of the data and does not assume the position of primary source.

  3. The provider does not warrant that the data is accurate, complete, current or free from error. Where the data comes from external sources, responsibility for its accuracy lies with the bodies that produce it, and the provider does not answer for errors, omissions, delays, alterations or unavailability attributable to those sources or to factors outside its control.

  4. The service is provided free of charge, as is and as available. There is no service-level agreement and no guarantee of continuous availability, minimum uptime, response time, continuity or uninterrupted operation, unless a specific written agreement provides otherwise.

  5. Access may be interrupted, in whole or in part, for scheduled or urgent maintenance, fault correction, infrastructure changes or protection of the platform's security. Where reasonably possible the provider announces scheduled interruptions in advance; urgent ones may occur without prior notice.

  6. Some endpoints rely on free third-party community infrastructure and are marked as such in the documentation. Over these the provider has no capacity control whatsoever, and heavy use is not permitted.

4.

Licence

What the key permits

  1. The provider grants the holder a non-exclusive, non-transferable, non-sublicensable, free and revocable licence to access the API and use the data obtained within the integration described in the access request.

  2. The licence covers presenting the data to end users, transforming it and combining it with the holder's own data, and caching it for as long as the integration needs.

  3. The licence is limited to the stated purpose. A material change of purpose, audience or expected volume must be notified to the provider before it is put into effect.

  4. A key is personal to the organisation it was issued to. A holder may hold several keys for distinct organisations or systems, but none may be assigned, shared or resold to third parties — whoever needs access requests their own.

  5. The licence confers no right over EmCurso's trade marks, name or visual identity beyond the attribution required by article 5.

5.

Obligations

What the holder undertakes to do

  1. State the origin of the data whenever it is displayed, naming the body that produced it and EmCurso as the route to it, visibly and next to the data. The accepted forms and the basis for this obligation are set out on the Best practices page, which forms an integral part of these terms.

  2. Indicate that the data is presented in processed form. The licence under which the public sources make it available requires stating that changes were made, and there are changes: natures are normalised, occurrences classified by category and enriched with geographic information. The attribution form given in the best practices satisfies this requirement.

  3. Not present the information as official, as validated by a public authority, or as the holder's own. In an emergency context, the end user must be able to tell whose information they are reading and reach the source to confirm it.

  4. Respect the key's quota limits and each endpoint's minimum refresh interval, easing off in response to the quota headers rather than reacting only to a 429.

  5. Send a User-Agent header on every request that identifies the integration and allows contact, keeping it consistent with the one registered on the key.

  6. Keep the key secret: out of version control, out of client applications and web pages, and in a secrets vault or environment variable, with the other security practices expected of anyone operating access credentials. The holder answers for requests made with their key, including those resulting from third-party access they allowed or failed to prevent.

  7. Restrict the key to the people and systems that need it for the integration, prevent third parties from gaining access to it and, on any suspicion of compromise, loss or improper disclosure, regenerate it immediately and report this to the provider without delay.

  8. Keep the email address and contact details associated with the key up to date. That is how breaking changes, incidents and decisions about access are communicated.

  9. Tolerate, in their integration, the introduction of new fields in responses without breaking. The structure is stable and incompatible changes are announced in advance, but adding a field is not an incompatible change.

6.

Prohibitions

What is not permitted

  1. Reselling the data, or creating paid subscriptions whose product is essentially the redistribution of this public emergency information. Charging for a service that uses it as one component among several is permitted; charging for access to it is not.

  2. Reserving for paying subscribers the information obtained through the API, or a version of it that is more complete, more detailed or more current than the one available in the free part of the holder's service. A paid subscription may add the holder's own data, features or analysis; what it may not add is better access to the information served by this API.

  3. Circumventing or attempting to circumvent the technical limits, in particular through multiple keys for the same system, rotation of source addresses, or distributing requests through third parties in order to exceed the allocated quota.

  4. Automatically harvesting data from the emcurso.pt website or from any other interface of the service — by scraping, crawling, spiders, headless browsers or equivalent techniques — where the aim is to bypass the API, its limits or its authentication, or to reconstitute the platform, or a substantial part of it, outside the channels provided for in these terms.

  5. Accessing or attempting to access private, undocumented or unauthorised endpoints, circumventing the authentication mechanisms, or carrying out brute-force attacks, fuzzing, enumeration, systematic probing or any other attempt to discover or exploit vulnerabilities and to reach non-public functionality. The same applies to reverse engineering the service for those ends, without prejudice to acts the law mandatorily permits. Such conduct is capable of constituting unlawful access or computer sabotage under the Portuguese Cybercrime Act.

  6. Using the information to identify, locate or profile specific people involved in an occurrence, or to draw conclusions from it about their health, financial situation or private life.

  7. Using the information for unlawful, fraudulent, discriminatory or harassing purposes, to hinder rescue operations, or to direct unsolicited communications at third parties on the basis of an occurrence affecting them.

  8. Systematically extracting the data set in order to build a database equivalent to the provider's, or reproducing a substantial part of it, in breach of the database maker's right.

  9. Presenting the information in a way that misleads the end user as to how current it is, in particular by omitting the moment it refers to where that moment matters to the decision being taken.

Reporting in good faith a vulnerability found without exploiting it, without degrading the service and without accessing third-party data does not breach this article. Send it to the contact given at the end of this document.

7.

Third parties

Data that is not ours

  1. Most of the data served by the API is produced by third parties and is subject to those third parties' regimes. ANEPC, IPMA and ICNF data is published under a Creative Commons Attribution 4.0 licence, which permits free re-use, including commercial, against the obligation to credit the source and to indicate any changes made. The provider transmits the data; it cannot grant rights over it that it does not hold, nor waive the conditions of those who licensed it.

  2. Traffic data is supplied to the provider under a commercial licence and is intended for display within the holder's integration. It may not be redistributed raw, resold, or stored to build a historical series of the holder's own.

  3. Data originating from OpenStreetMap is licensed under ODbL. Beyond attribution, that licence imposes its own conditions on anyone producing and distributing derived databases — conditions the holder must check for themselves before doing so.

  4. If a source changes its conditions, withdraws data or ceases to make it available, the provider adjusts or removes the corresponding endpoint. Such a change does not constitute a breach of these terms.

Third-party data and its regime

Data
Civil-protection occurrences
Source holder
ANEPC
Applicable regime
CC BY 4.0Free re-use, including commercial, with attribution
Data
Weather warnings and forecast, fire risk
Source holder
IPMA
Applicable regime
CC BY 4.0Free re-use, including commercial, with attribution
Data
Burnt area and causes (annual series)
Source holder
ICNF
Applicable regime
CC BY 4.0Free re-use with express indication of provenance and authorship
Data
Burnt-area perimeters
Source holder
EFFIS · Copernicus EMS
Applicable regime
Copernicus dataFree use, including commercial, with acknowledgement of source
Data
Satellite thermal hotspots
Source holder
NASA FIRMS
Applicable regime
LANCE/FIRMS termsFree use, including commercial, with acknowledgement of source
Data
Traffic
Source holder
TomTom
Applicable regime
Commercial licenceDisplay only, no raw redistribution
Data
Administrative boundaries, emergency facilities, routes
Source holder
OpenStreetMap
Applicable regime
ODbLAttribution, and share-alike for derived databases

A source's regime travels with its data. In receiving it through this API, the holder becomes subject to the conditions of the body that produced it, not only to ours.

8.

Personal data

Data protection

  1. To administer access, the provider processes the identification and contact details given in the request — name, email address, organisation and, where supplied, tax number — on the basis of performance of the contract these terms constitute.

  2. Every request made to the API is logged with the endpoint invoked, the method, the response code, the response time, the originating IP address, the User-Agent header and the timestamp. This logging rests on the provider's legitimate interest in securing the service, detecting abuse and supporting the holder technically.

  3. Retention periods, data-subject rights and how to exercise them are set out in the EmCurso.PT Privacy Policy, which applies in full to this processing.

  4. The data served by the API describes occurrences and is not intended to identify individuals. Even so, the combination of location, nature and time may, in specific cases, allow people involved to be indirectly identified.

  5. In processing that information within their integration, the holder acts as an autonomous and independent controller. There is no processor relationship and no joint controllership between the parties, and it falls to the holder to ensure compliance with the General Data Protection Regulation on their own account, in particular as to lawful basis, minimisation and informing data subjects.

  6. The holder undertakes to notify the provider, without undue delay, of any security breach involving the key or data obtained through it.

9.

Breach

Suspension and revocation of access

  1. The provider monitors usage patterns and flags consumption far above the refresh interval, keys used from many distinct addresses, and integrations with high error rates. Flagging is not a sanction: as a rule, the provider contacts the holder so it can be put right.

  2. Where there are reasonable indications of breach of these terms or of abusive use, the provider may examine the access logs referred to in article 8, look into the usage patterns concerned and ask the holder for explanations about the integration, the volume of requests and the destination of the data. The holder undertakes to reply within a reasonable time.

  3. Where the breach persists after contact, or where the prohibitions in article 6 have been violated, the provider may reduce the quota, restrict endpoints, or suspend or revoke the key.

  4. Suspension may be immediate and without prior notice where there is a risk to the security or availability of the service, where a source requires it, or, as a precaution, while an enquiry into abusive use is under way. In that case the provider informs the holder as soon as it is safe to do so.

  5. Keys that record no request for twelve consecutive months, and accounts that remain inactive for the same period, may be revoked for reasons of security and platform management. Where possible the provider gives notice by email beforehand; revocation for inactivity does not prevent the holder from requesting a new key.

  6. The holder may cease use at any time, simply by no longer using the key and asking for its revocation. Termination gives neither party any right to compensation.

  7. Once access ends, the holder may no longer make requests and must remove the EmCurso attribution from displays no longer fed by the API. Data already obtained may continue to be retained, but presenting it as current is no longer acceptable.

10.

Changes

To the service and to these terms

  1. The provider may change, add or discontinue endpoints for technical or legal reasons or because of source availability. Breaking changes are notified by email to key holders with notice reasonable in light of the nature of the change.

  2. The provider may likewise change rate limits, allocated quotas, anti-abuse policies, authentication mechanisms, technical access requirements and the set of available features, in particular to protect the stability, security or availability of the platform. Such changes are announced in advance where possible, but may be applied immediately and without prior notice where protection of the service requires it.

  3. The API may come to be made available in new versions, and earlier versions may be changed, discontinued or cease to be supported. The provider seeks, wherever reasonably possible, to keep the earlier version running through a transition period and to give notice before it ends, but guarantees neither permanent compatibility nor the indefinite maintenance of any version.

  4. These terms may be revised. The version in force is the one published on this page, identified by version number and date. Substantive changes are notified by email to key holders.

  5. Use of the key after a new version takes effect constitutes acceptance. Anyone who does not accept should cease use and request revocation of the key, at no cost.

11.

Liability

Warranties and limits

  1. The provider does not warrant the accuracy, completeness, currency or fitness of the data for any particular purpose, and is not liable for decisions taken on the basis of it, whether by the holder or by their end users.

  2. To the fullest extent permitted by law, the provider's liability for indirect damage, loss of profit, loss of data or business interruption arising from use of or inability to use the API is excluded.

  3. The limitations in the preceding paragraph do not apply to damage caused intentionally or by gross negligence, nor to any liability that the law does not permit to be excluded or limited.

  4. The holder is responsible for the use they make of the data in their integration, towards their end users and towards third parties, and holds the provider harmless against claims arising from that use or from breach of these terms.

12.

Force majeure

Circumstances beyond reasonable control

  1. The provider is not liable for failure to perform, or defective performance of, the obligations these terms place on it, nor for interruptions, delays, data loss or degradation of the service, where these result from circumstances beyond its reasonable control.

  2. Circumstances of that nature include, in particular: power or telecommunications failures; unavailability, failure or alteration of infrastructure or data-provider services, in particular Cloudflare, Supabase, Vercel, IPMA, ANEPC, ICNF, TomTom or other sources identified in article 7; urgent maintenance; cyber-attacks, including denial-of-service attacks; natural disasters, fires, floods or extreme weather; war, acts of terrorism or civil unrest; strikes; decisions of public authorities; and other unforeseeable or unavoidable events.

  3. Where such a circumstance arises, the obligations it affects are suspended for as long as it lasts. The provider seeks to restore the service as soon as possible and to inform key holders where the interruption is prolonged, without either party acquiring any right to compensation as a result.

13.

Ownership

Rights over the service and the data

  1. Source data belongs to the bodies that produce it. The provider claims no rights over it and merely makes it available under article 7.

  2. The selection, normalisation, enrichment and organisation of the data, the structure of the responses, the documentation, the code and the visual identity of the service belong to the provider and are protected by copyright and by the database maker's right.

  3. The licence in article 4 permits use of the data; it transfers ownership of none of these elements.

  4. All rights not expressly granted by these terms remain reserved to the provider and, as regards source data, to the bodies that produce it.

  5. Suggestions, bug reports, improvement proposals and other feedback the holder sends about the API or the platform may be used freely by the provider to improve them, with no obligation to compensate and without the holder thereby acquiring any right over the service. This does not extend to information the holder marks as confidential when sending it, nor to the data of their integration.

14.

Final provisions

Governing law and dispute resolution

  1. The invalidity or ineffectiveness of any clause does not affect the remainder, which stay in force; the affected clause is replaced by one approximating its effect so far as the law permits.

  2. The provider's forbearance in the face of a breach does not amount to waiver of the right to require performance later.

  3. These terms are governed by Portuguese law.

  4. Disputes arising from these terms fall to the courts of the district of Lisbon, with express waiver of any other, save where a mandatory rule of law determines otherwise, in particular in relations with consumers.

Legal framework

This table is informative and replaces neither reading the instruments themselves nor legal advice. It exists so the holder knows which framework they are operating in before integrating emergency data into a service of their own.

Matter
Personal data protection
Instrument
Regulamento (UE) 2016/679 · Lei n.º 58/2019
Relevance
Frames article 8 and any processing the holder carries out in their integration
Matter
Re-use of public-sector information
Instrument
Lei n.º 26/2016 · Lei n.º 68/2021 · Diretiva (UE) 2019/1024
Relevance
Defines re-use as use for commercial or non-commercial purposes, provides for authorisation by online open licence, and requires dynamic data to be made available through APIs
Matter
Databases
Instrument
Decreto-Lei n.º 122/2000
Relevance
Underpins the maker's right invoked in articles 6 and 13
Matter
Copyright
Instrument
Código do Direito de Autor e dos Direitos Conexos
Relevance
Protects the documentation, code and visual identity of the service
Matter
Information-society services
Instrument
Decreto-Lei n.º 7/2004
Relevance
Governs online provision of the service and the information to be given to the recipient
Matter
Cybercrime
Instrument
Lei n.º 109/2009
Relevance
Defines the unlawful access and computer sabotage referred to in article 6
Matter
Cyberspace security
Instrument
Lei n.º 46/2018
Relevance
Frames the duties to report security incidents
Matter
Civil protection
Instrument
Lei n.º 27/2006 (Lei de Bases da Proteção Civil)
Relevance
Defines the powers of the authorities whose information the API transmits, and why it does not replace them

Contact

Questions about these terms, requests for clarification, exercise of data-protection rights, and reporting of security incidents:

Get in touch

If you suspect a key has been exposed, regenerate it on the dashboard first and contact us afterwards. The message can wait; a key in circulation cannot.