Skip to main content
All documentation

Contracts

A deal is where the goods are coordinated. A contract is where the two sides say, in writing and on the record, what they have agreed to.

Until now the platform had no such record. A deal reached "Agreed" because the broker moved it there, and nothing anywhere held a document, a signature or a date. Contracts close that gap: a versioned bilingual agreement, accepted by both sides, with a tamper-evident history you can check yourself.

OnlyTons is not a law firm. The shipped contract text is a structurally complete starting point โ€” parties, subject, price, delivery, quality, title and risk, force majeure, confidentiality, governing law โ€” and it has not been reviewed by a lawyer. Have your own adviser read it before you rely on it.

Two contracts, never one

This is the part that surprises people, and it follows directly from operator privacy: you never learn who is on the other side of your trade.

A contract names its parties. So OnlyTons does not write one document naming everybody. It writes one agreement per operator, and the portal is a party to each:

        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
        โ”‚   The portal        โ”‚
        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”˜
   contract 1  โ”‚       โ”‚  contract 2, 3, โ€ฆ
        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ” โ”Œโ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
        โ”‚  Buyer  โ”‚ โ”‚ Suppliers โ”‚
        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Your agreement names you and the portal. It does not name the operator on the matching agreement, and there is no screen anywhere that shows you theirs. The portal is the counterparty of record on both sides โ€” it buys from the supplier and sells to the buyer.

One consequence worth stating plainly: the portal is a principal in the trade, not a messenger. It carries the obligation on both legs. That is what makes it possible for you to buy or sell without knowing who is on the other side.

The life of a contract

StateWhat it means
DraftThe portal is preparing it. You cannot see it yet โ€” and that is deliberate: terms nobody has stood behind are not terms you should be reading.
Awaiting acceptanceIt has been issued to you. Read it and sign, or tell the portal you will not.
Signed by one partyOne of the two has accepted. It does not bind yet.
In forceBoth have accepted. This is the agreement.
SuspendedStill binding, but performance is paused โ€” by the portal, or automatically if a certification condition fails.
CompletedPerformance is done.
TerminatedEnded before completion.
SupersededAn amendment replaced it โ€” see below.
WithdrawnPulled back before it bound, by either side, with a reason.
ExpiredNobody signed inside the acceptance window (14 days by default).

An agreement binds only when both parties have accepted. Not when the portal issues it, not when you sign it โ€” when both have. Until then the state says exactly where it has got to.

A contract is never edited and never deleted. If something has to change, the portal issues a NEW contract that supersedes the old one, and both stay on the record. That is the whole point of having a contract rather than a note.

Reading and signing

Open Contracts in the sidebar. Each row is one agreement your organization is a party to.

Inside, you get:

  • The document, in English and Italian. Both are produced together from the same terms. A line at the top says which language version prevails if the two ever differ โ€” for the shipped templates, Italian.
  • A content fingerprint (a sha256: line at the bottom). It is the agreement's identity: change one character of the terms and it changes.
  • The history, and a Check this record button. See below.

To sign:

  1. Scroll to the end. The button stays disabled until you have. We record whether you reached the end, so it has to be true.
  2. Tick both boxes โ€” that you have read it, and that you are authorised to bind your organization.
  3. Press Accept and sign.

Only an account owner can sign. A member can read the agreement and cannot accept it. Signing binds your company; posting a listing does not, which is why this is the one action with a stricter rule than the rest of the platform.

If the agreement changes while you have it open, signing is refused and you are asked to reload and read it again. You can only accept the document you were actually shown.

A suspended or rejected organization can still sign or refuse. If a contract was issued to you before your account was suspended, you keep the ability to finish it or turn it down. Being suspended stops new market activity; it does not strand you inside an agreement the other side is still bound by.

If your organization is in the Blocked band, signing is refused โ€” see Reliability. If it is Restricted, your acceptance is recorded and the agreement waits for a person at the portal to look before it takes effect. You are told which of the two has happened.

What we record when you sign, and for how long

This matters, so it is on the screen before you press the button, not buried here:

WhatWhyHow long
The date and timeIt is the agreement's dateKept
Which account signed, and its roleWho bound the companyKept
The exact document you were shown (its fingerprint) and which language you readSo "I signed something else" is answerableKept
Whether you scrolled to the end, and the exact wording of the boxes you tickedThe wording changes over time; "they ticked box 2" is not a defenceKept
Your network (IP) address and your browserCorroborating evidence that it was youErased after six years

The last row is personal data and it has a clock on it. After six years those two fields are erased automatically and the record notes that they were โ€” so "we never collected it" and "we collected it and have erased it" stay distinguishable. The record of the acceptance itself is kept: erasing it would destroy the evidence that you agreed at all, which is the only thing it is for.

Checking the record yourself

Every entry in a contract's history is sealed to the one before it. Each carries a fingerprint computed from its own contents plus the previous entry's fingerprint, so changing or removing anything breaks every entry after it.

Press Check this record and the platform recomputes the whole chain in front of you. You get one of:

  • The record is intact: N entries, each one sealed to the one before it.
  • This record does not check out. โ€” with where it stops holding.

You can run this, not just the portal. A tamper-evidence check that only the party who could tamper is able to run is not evidence of anything.

What it does and does not prove. It proves the history has not been altered piecemeal โ€” no entry edited, none removed, none inserted. It does not prove the portal could not have rewritten the entire chain from some point forward, which would require full database access. Publishing the chain's head to an independent public record would close that too; that is a later module, and the platform does not claim it today.

For the broker

From a deal room, the Contract group panel shows every leg of that deal at once โ€” the buy leg and one sell leg per supplier โ€” with how far each has got. This is the only screen that shows every operator on a deal together, and it is broker-only for exactly that reason.

  • Prepare contracts creates the group from the deal. The deal needs an agreed price and at least one supply line first.
  • Issue to all parties renders every draft leg in both languages, seals the document, and tells each counterparty.

The portal signs every leg too. It is a party to each one.

Free text is checked before a contract is issued. If a special condition names another operator on the deal, or carries an email address, phone number, web address, VAT number or IBAN, issuing is REFUSED rather than flagged. A contract is the one document meant to be printed, filed and read by third parties; there is no reviewer between it and the counterparty.

Contract templates

The words come from a published template, not from the application's code. Each template carries a version and a checksum, and each contract records which version it was written from โ€” so an agreement signed under version 2 still reads as version 2 forever.

Anyone signed in can read the templates and their versions. The text you are asked to sign is not a secret.

A template is never edited once published; a change is a new version. Both languages must be complete and must refer to the same terms โ€” a clause whose English mentions a delivery date and whose Italian does not is rejected at publication, because that is two different contracts sharing a clause number.

Conditions the portal checks by itself

Every agreement carries conditions, and a document nobody checks is a document nobody keeps. The Conditions card on your contract shows what the portal checks automatically, what it found, and when it last looked. It runs when the agreement takes effect, every time the deal moves, and once a night.

ConditionWhat it looks atWhat it can do
CertificationYour certificates against the delivery windowSuspends the agreement if goods contracted as organic would move under a certificate that does not cover them
Delivery windowThe expected delivery date and where the deal has got toWarns before the date, and reports a late delivery afterwards
QuantityWhat has been allocated against what the contract saysTells the portal when the two drift apart
DocumentsThe documents this template requiresStops the agreement being marked completed until they exist
Price indexationThe published index a price clause points atRecomputes the price and warns โ€” it never rewrites the agreement
Payment termsThe delivery date plus the agreed periodComputes the due date and nothing more

Four things are worth saying plainly, because each one is a limit rather than a feature:

Only one condition can act on its own, and it pauses rather than ends. A lapsed organic certificate suspends the agreement โ€” because that is a regulatory problem for the buyer as much as the seller โ€” and suspension is reversible. Every other condition tells a person, who decides.

The portal cannot see payments. It computes when payment falls due and says so; it has no access to a bank and does not check whether anybody paid. The screen says this rather than leaving you to assume otherwise.

"Not enough data" is not a pass. If a published price index has not arrived, the portal says it does not know, rather than showing a green tick over a question it could not answer.

One condition is not shown to you, and that is deliberate. The quantity check compares what has been allocated across the whole deal against what your contract says. Watching that number close over time would tell you that another supplier joined your deal โ€” which is precisely what operator privacy exists to prevent. The portal sees it; you see the other five.

If something goes wrong: disputes

Disputes on your contract is where you tell the portal that something is wrong โ€” quality, quantity, delivery, documents, payment or certification.

  • It goes to the portal, which is the other party to your agreement. Nobody else sees it, and no other operator learns that you raised it.
  • Raising a dispute does not suspend the agreement. A dispute is a claim; a suspension is a finding. If it were automatic, either side could stop being bound simply by making an assertion nobody had assessed.
  • The portal closes it with an outcome โ€” upheld, rejected, settled, withdrawn, or replaced by an amendment โ€” and you are told which.
  • Nothing is deleted. A claim you later withdraw stays on the record as withdrawn.

While a dispute is open, your contract shows a Disputed badge beside its state. The two are separate on purpose: an agreement can be in force AND disputed, and collapsing them would hide the fact the dispute turns on.

Changing a signed agreement

If a term is wrong, the portal issues a corrected version that supersedes the old one. The old contract stays on the record as Superseded, with its whole history.

Every signature on the superseded version stops counting, and both sides sign again. This is the part people ask about, and the answer is deliberate: a signature is given to a specific set of words. Carrying it forward would mean the portal holding a record saying you accepted terms you were never shown. There is no "small change" exception, because nothing can tell a corrected typo from a changed price except the people signing.

When a deal is agreed, and when it is cancelled

Two things connect the paperwork to the pipeline:

  • A deal can be made to require its contracts. When the broker turns this on for a deal, it cannot move to "Agreed" until every party has signed. It is off by default โ€” whether a signature should be a precondition everywhere is a business decision that has not been taken.
  • A deal cannot be moved back out of "Agreed" while an agreement is in force. The broker can suspend it, end it, or cancel the deal โ€” but the pipeline is not allowed to say "we are still negotiating" while a signed contract says otherwise.
  • Cancelling a deal ends its paperwork in the same moment. An agreement that bound is terminated; one nobody had signed yet is withdrawn. You are never left holding a live document for a deal that no longer exists.

What is not here yet

  • PDF export. The agreement is print-optimised HTML; use your browser's print-to-PDF. A PDF's bytes carry a creation timestamp, so they could never carry a fingerprint anybody could re-check โ€” which is why the fingerprint is over the content, not over a file.
  • Penalties. The portal reports a breach; it does not compute or apply a penalty, and there are no payment rails behind one.
  • Partial deliveries. A deal has one delivery step, so "half arrived on time" cannot be recorded yet.
  • Publishing the record externally. See "Checking the record yourself" above.

See also