Muntin

Terms of Service

Muntin

Last updated: 14 August 2026 · Version 1.0

1. These terms, and who they bind

These terms govern your use of Muntin, A payroll operations register for a company with more than one legal entity: every entity in one place, reconciled before the close, posted to the ERP over endpoints included in the price.. They form a contract between Muntin, of Muntin Systems GmbH, Katharinenstrasse 17, 04109 Leipzig, Germany (“Muntin”, “we”) and the company that signs up for the service (“Customer”, “you”).

The service is offered to businesses only. It is not offered to consumers, and by signing up you confirm you are acting for purposes within your trade or profession and that you are authorised to bind your company.

The person clicking through these terms is agreeing on behalf of the company, not personally. If you do not have that authority, do not proceed.

Order of precedence. Where documents conflict: (1) a signed order form or agreement between us, (2) the Data Processing Agreement, (3) these terms, (4) our Privacy Policy, (5) anything on our website.

2. What the service is

The entity register, the per-period ingestion of every entity's payroll register in whatever shape it arrives, the mapping of it onto one fixed row contract with the source file retained, the fixed set of cross-entity checks, the exceptions queue that blocks the lock, the journal posting per entity, the headcount and cost center webhooks, the immutable locked period record, the REST API and the sandbox. All of it is in the flat subscription; nothing on that list is a separate line.

3. What the service is expressly not

These limits are deliberate and are part of what you are buying. They are not defects.

Not a payroll engine. We do not calculate pay, compute statutory deductions, or file with any authority. Keka carries local statutory payroll for India, the US and its GCC markets inside the product and files from it, and that is a real capability we do not have and are not building. Every figure Muntin holds was calculated by your payroll system or your bureau, and we reconcile it rather than produce it.

Not an HR suite. No hiring or applicant tracking, no performance reviews or calibration, no learning, no helpdesk, no employee self-service, no shift roster. Your employees have no login here and no account. If you are buying a suite, we are not one and are not a step toward one.

Not on the money path. No payment file, no bank connection, no payment initiation, no payslip generated or delivered. We hold four digits of a bank account as a matching key and nothing else of it. Nothing we do can pay a person or fail to pay a person.

Not an audit, and not advice. The checks are a fixed, published list and they are mechanical. Passing them is not an assurance that a payroll is correct, lawful or complete, and no exception cleared in Muntin is a professional opinion about anything. We take no position on your entitlements, your classifications or your filings.

4. Your responsibilities, and how they affect the outcome

What the service delivers depends materially on things only you control. Read this section carefully; sections 9 and 10 follow from it.

The entity register is yours to state. You produce the list of registered entities, with registration numbers, incorporation dates, calendars and currencies. At most groups this list has never existed in one document, and building it is the slowest part of week one. We cannot infer an entity you do not tell us about.

The chart of accounts as it stands today. Finance supplies the cost center tree in its current state, not its last approved state. Every cost center check runs against what you gave us, so a stale tree produces exceptions that are ours to raise and yours to fix.

Getting the register out of each system, every period. The file has to arrive by the cutoff you set for that entity, whether that is an export, an SFTP drop or a spreadsheet a controller maintains. We will tell you loudly that an entity has not reported; we cannot fetch what is not sent.

Confirming the mapping and clearing the queue. A proposed column mapping is applied only after one of your operators confirms it, and an identity match below threshold stays unresolved until a person decides. A named person on your side has to clear the queue before every close. This is the habit the product depends on and it is the one most likely to slip in month two.

The ERP service user. You issue the credential we post journals with, scoped to journal posting and reading the chart of accounts. It is your IT team's task rather than HR's, and until it exists there is nowhere for the journal to land.

Lawful basis and consultation. You are the controller. Deciding that cross-entity reconciliation of employee payroll data is lawful for your group, and consulting your works council or equivalent where that is required, is yours. We will supply what your data protection officer needs to assess it, before you load a single file.

5. Getting started, and what is free

Thirty days on your own last three closed periods, with your real registers, without a card and without a call first.

The trial includes the full onboarding: the entity register build, the column mapping for every file shape you bring, and the three-period backfill and cross-entity match.

If the cross-entity check finds nothing across three periods, we will say so and tell you not to buy it. That is a real outcome for a group whose entities genuinely do not overlap.

Nothing posts to your ERP during the trial unless you ask for it. The journal is generated and shown, and it stays in Muntin until you connect a service user.

6. Fees and what is extra

One flat subscription. €1,290 per month for the company group, covering up to 2,500 employees on the register. Invoiced monthly in advance. The figure is published on the site and is the figure on the order form.

Entities, users and endpoints are not metered. Additional registered legal entities, at any point and in any number, cost nothing. So do users of every kind, operator or read-only, including your auditor and your implementation consultant. So do the REST API, the webhooks and the sandbox. None of these appears as a line on any quote we issue.

Onboarding is not charged. The entity register build, the column mapping for every file shape you bring, and the three-period backfill are part of the subscription. We do not sell implementation days and we do not have a partner who does.

Above the employee ceiling. Above 2,500 employees on the register we quote, and we will publish the basis of that quote before you ask for it. Crossing the ceiling mid-term does not trigger a retrospective charge; it triggers a conversation at renewal.

Price held, and how it can change. The price is held for 24 months from signature regardless of what you add. After that it can change once per year with 90 days' written notice, and a change gives you the right to end the subscription at the old price with no charge.

7. Delivery, availability and support

The period close. Registers ingest on arrival, checks run on every arrival across all entities, and the exceptions queue updates as they run. The period locks when the queue is empty and not before. There is no override, for you or for us.

The journal and the webhooks. On lock, a payroll journal per entity is posted to your ERP with entity and cost center on every line, and headcount and cost center webhooks fire to the endpoints you nominate. A failed delivery retries with backoff for 24 hours and then raises an exception rather than dropping silently.

The API. The same objects the interface shows are readable and writable over a documented REST API on the same account: entities, periods, rows, exceptions, locks and journals. It is in the base price, it is versioned, and a breaking version is announced 180 days ahead.

Availability, stated plainly. We publish a status page with incident history. We target the ingestion and check path being available through the month-end window and we do not offer a service credit, because a credit is not a remedy for a late close and we would rather not pretend otherwise. What we do commit to is that a period never locks on unresolved data, whatever else is degraded.

7.3 Support. Support is by email at [email protected], with a target first response of one business day. That is a target, not a guarantee.

8. The period, its lock and its corrections

A locked period is immutable. Mapped rows, source files, check results, clearances and timestamps do not change after lock. A journal posted into your ledger has to remain explainable years later, and it cannot be if the record behind it can be rewritten.

Corrections are new versions. A correction produces a new period version carrying the reason, the author and the date, and a reversing journal where one is needed. The superseded version stays readable and marked as superseded rather than removed.

The source file is kept beside the rows. Every file is retained exactly as received. Any figure in a posted journal can be traced back to the file it came from, the mapping that was applied, and the operator who confirmed that mapping.

Export, and life after the subscription. Every period record, its rows, its exceptions log and its source files export as CSV and JSON at any time, on demand, without asking us. The row contract and the export schema are published, so the archive stays readable after you stop paying for the software.

9. Warranties, and their limits

We warrant that we will provide the service with reasonable skill and care, and that we have the right to provide it.

We give no other warranty. To the fullest extent permitted by law we exclude all implied warranties, including merchantability, fitness for a particular purpose and non-infringement.

We warrant that mapped rows are a faithful representation of the source file we received, that the published checks run against every period, that a period cannot lock with an unresolved exception, and that a locked period record is not altered afterward. We do not warrant that a payroll register you supply is correct, complete, lawful or timely, that a proposed column mapping or identity match is right before an operator confirms it, or that our checks will catch an error of a kind they do not test for. The check list is published and it is finite.

10. Liability

10.1 Neither party limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or for anything else that cannot lawfully be limited.

10.2 Excluded losses. Neither party is liable for loss of profit, revenue, anticipated savings, business, goodwill or reputation, or for any indirect or consequential loss, however arising.

10.3 Specifically excluded. We are excluded from liability for the consequences of the things we deliberately do not do. We do not calculate pay, so we are not liable for an incorrect payroll figure produced by your payroll system or your bureau. We are not on the payment path, so we are not liable for a payment made, missed or misdirected. We do not compute or file statutory deductions, so we are not liable for a penalty, interest or assessment arising from a filing. And because a check list that is published is also a check list that is bounded, we are not liable for an error of a type outside it. Where a close is late because the exceptions queue was not cleared, that is the product working as specified and as bought.

10.4 Cap. Our aggregate liability is capped at the fees paid in the twelve months preceding the claim. Where a claim concerns a defective mapping or a wrong identity match that we applied, the practical remedy is a corrected period version with the reason recorded and a reversing journal where one is needed, delivered within five working days at no charge.

10.5 You acknowledge that the limits in sections 9 and 10 are a reasonable allocation of risk given the price and your responsibilities under section 4, and that we would not offer the service at this price without them.

11. Confidentiality and data

Your entity register is your confidential information and we treat it as the most sensitive thing we hold about your business, because it is a description of your corporate structure and your acquisitions. We will not disclose it to a payroll provider, a bureau or any other customer, and we publish no statistic drawn from it. Your payroll registers are your employees' personal data before they are anyone's confidential information, and are handled under Part B. Our confidential information is the column classifier, the shared column corpus, the check list implementation and the matching thresholds.

Processing of personal data is governed by our Privacy Policy and by the Data Processing Agreement between us, which is incorporated into these terms. Where the DPA and these terms conflict on personal data, the DPA governs.

12. Intellectual property

Your registers, your entity register, your mapped rows and your period records are yours. We license you nothing over your own data and we claim nothing in it.

What we license you is the software, the row contract, the published check list, the export schema and the API.

The row contract and the export schema are published under an open license and sit outside the paid subscription entirely, so an archive exported from Muntin stays readable by anything you build or buy next.

You may show anything the product produces to your auditor, your board, your works council, an advisor or a competing vendor. There is no clause here restricting publication of benchmarks, performance or quality information about Muntin, and there will not be one.

We claim no right in the shared column corpus over any cell value, because it contains none: it holds header strings and statistical fingerprints of columns, mapped to field names.

You may not use our name or logo publicly, and we may not use yours, without prior written consent.

13. Term and termination

13.1 The contract starts when you sign up and continues until either party ends it.

13.2 By you. Cancel at any time, effective at the end of the current billing month, subject to any minimum term stated in section 6.

13.3 By us. We may terminate on 30 days’ notice, or immediately if you materially breach these terms and do not cure within 14 days of notice, if you become insolvent, or if your use exposes us to legal risk.

13.4 What survives. On termination we stop delivering and stop billing. You keep everything already delivered to you, and your licence to it survives. We delete or return our working copies as set out in the DPA. Sections 9, 10, 11 and 12 survive.

14. Changes to these terms

We may update these terms. Material changes take effect 30 days after we notify you by email, and if you do not accept them you may terminate before they take effect. Continuing to use the service after that date means you accept them.

15. Contact

Muntin, Muntin Systems GmbH, Katharinenstrasse 17, 04109 Leipzig, Germany
[email protected]

← Back

Your request has been received.

Expect a message from Muntin. It goes to the address you gave.