Last updated: May 10, 2026
1. Why this policy exists
Cofactu offers unlimited OCR on the Pro, Business and Accounting firm plans and allows configuring an API rate limit of up to 50,000 req/h on the Business and Accounting firm plans. These conditions comfortably cover the real usage of any professional firm or small business that uses the product for its daily operations.
The word "unlimited" means that we do not apply a rigid monthly quota — not a right to infinite consumption. To keep the service sustainable and fast for everyone, we define below the thresholds we consider fair use.
2. Reference thresholds
OCR (data extraction from invoices / receipts)
- Accounting firm plan: unlimited OCR (fair use) with an anti-abuse ceiling of 500 OCRs / hour per organization. Equivalent to an accounting firm with ~250 active clients processing 200 invoices/client/month.
- Business plan: unlimited OCR (fair use).
- Pro plan: unlimited OCR (fair use, with an hourly anti-abuse ceiling).
- Free plan: 20 OCRs/month.
Public API
- Default: 1,000 req/hour per API key (configurable).
- Manual cap: up to 50,000 req/hour on the Business and Accounting firm plans.
- Reference monthly volume: 1,000,000 req/month per organization for legitimate integrations (ERP, ecommerce, reconciliation, catalog sync). Above that requires contacting sales to validate the use case.
3. What we consider abuse
We consider the following patterns, among others, to be unreasonable use:
- Running OCR on documents unrelated to the organization's tax operations (bulk data extraction from third parties' historical files, training proprietary models, etc.).
- Reprocessing the same set of documents repeatedly with no apparent change (misconfigured cron, duplicated pipeline).
- Sustained API consumption exceeding 10× the average of organizations on the same plan over 7 consecutive days.
- Sharing the account or API keys with third parties other than the plan owner.
4. What we do when thresholds are exceeded
- Detection: our telemetry dashboards review accounts with anomalous consumption daily. Occasional spikes do not trigger any action.
- Contact: if the pattern persists, we contact the account owner within 7 days to understand the case and, if appropriate, propose a plan suited to actual volume.
- Temporary limitation: if we receive no response or the pattern is clearly abusive, we may apply a stricter rate limit for a set period, always preserving essential operations (VeriFactu submission to AEAT, PDF downloads, access to history).
- Termination: as a last resort, in cases of repeated intentional abuse, Codificado SL reserves the right to terminate the contract with 30 days' notice, refunding the unused portion of the annual fee and facilitating full export of the client's data.
5. Guarantees for the client
- This policy is not applied automatically. Before any limitation, there is always human contact and conversation.
- Client data is never blocked — access to history and the ability to export remain in place at all times.
- If an organization legitimately exceeds the thresholds (an accounting firm growing to 500 clients, a high-volume API integration), we offer a tailored plan that covers the real case without overpaying.
- The figures in this policy are reviewed quarterly against real usage data. If your case is close to the threshold, write to us at hola@cofactu.com and we'll review it together.
6. Relationship with other terms
This policy complements the legal notice and the privacy policy. In case of conflict, the specific conditions signed in the organization's commercial contract prevail.
7. Contact
Any questions about this policy or your current consumption level: legal@cofactu.com.