# Terms of service
Entur operates Norway's national public transport data platform. Our APIs and open data are freely available for anyone to build services and tools that benefit passengers and the broader transport ecosystem. Some services require a partner agreement with Entur.

These are the general terms that apply to all use of Entur's APIs and data. Where a separate partner agreement exists, that agreement may extend or supersede specific provisions of these terms. See [Getting started](/docs/getting-started) for an overview of the different service types.

## API terms

### Client identification

All API requests must include an `ET-Client-Name` header identifying your application, not you personally. This allows Entur to manage traffic fairly and keep services stable for everyone. Applications without this header will operate at lower rate limits and may be subject to restrictions if usage is unreasonable.

For the full header format, example values, and code samples, see [Getting started — Client identification](/docs/getting-started#client-identification-et-client-name).

### Fair use and rate limits

Entur's APIs apply rate limiting to ensure stability and fair usage across all consumers. Specific rate limit values are defined per service.

Consumers are expected to monitor their usage and adapt their traffic accordingly. If your application is throttled or blocked, the most likely cause is missing or invalid client identification.

### API versioning, deprecation, and beta

Entur is committed to backward-compatible API development wherever possible. When breaking changes are unavoidable, Entur will:

- Provide written advance notice to affected consumers.
- Maintain the previous version in parallel for a minimum of 12 months.
- Make significant changes available in test environments before production rollout.

APIs or features marked as beta are provided for early access and testing purposes. They may change or be withdrawn without the full deprecation notice period that applies to stable APIs.

### Permitted and prohibited use

The following uses are not permitted:

- Attempting to circumvent rate limiting or traffic shaping measures.
- Using fake or randomly generated values in the `ET-Client-Name` header.
- Impersonating traffic from another application or organisation.

Accordingly, Entur may suspend or terminate access to the APIs at its sole discretion, including but not limited to cases of misuse, excessive load, security risks, or breach of these terms.

## Data and licensing

Entur publishes Norway's national public transport data as open datasets and through its APIs. The following terms apply to all data obtained from Entur, whether downloaded from the [Open Data portal](/open-data) or received as API responses.

### Licence

Entur's open data is published under the [Norwegian Licence for Open Government Data (NLOD)](https://data.norge.no/nlod/en/2.0). NLOD permits free reuse for any purpose, including commercial use, subject to attribution requirements and the exceptions set out in the licence.

### Attribution for open data

All use of Entur's open datasets requires attribution as specified by NLOD. At minimum:

- State that the data originates from Entur.
- Link to the applicable licence.
- Indicate if you have modified the data.
- Do not present the attribution in a way that implies Entur endorses your product or service.

Default attribution text: _Inneholder data under Norsk lisens for offentlige data (NLOD) tilgjengeliggjort av Entur AS_.

### Disclaimer

Data is provided "as is". Entur gives no warranties regarding the accuracy, completeness, or availability of published datasets. The disclaimer in the NLOD licence applies.

## Privacy and personal data

When your application calls an Entur API, Entur logs standard request metadata including IP addresses, request paths, and the `ET-Client-Name` header value. Entur AS is the data controller for this processing. The data is used for operational purposes — monitoring, capacity planning, security, and abuse prevention. The legal basis for the processing is legitimate interests pursuant to Article 6(1)(f) GDPR.

The logs are retained for 14 months. Longer retention only occurs in the case of security or incident investigations.

When you call Entur's APIs to process personal data of your own end users, you act as an independent controller for that processing, and you are responsible for establishing a legal basis for the processing, providing information to the data subjects pursuant to Articles 13 and 14 GDPR, and fulfilling other relevant legal obligations. Entur does not act as your data processor, unless a separate data processor agreement is in place.

All data subjects can exercise their rights under Articles 15–21 GDPR by contacting Entur's data protection officer at personvernombud[at]entur.org.

For further details on how Entur handles personal data, see the [Entur Privacy Policy](https://om.entur.no/personvern/).

## Changes to terms of service

Entur may update these terms from time to time. Significant changes will be announced through the developer portal and where relevant. The revision date on this page reflects when the terms were last updated.
