Dataetic hands you credentials-level access to systems and AI agents that can act on them. This policy is the short list of things that would make that dangerous — for you, for us, or for someone else — and it is part of your agreement with us.
1Who this applies to
This Acceptable Use Policy (the Policy) forms part of our
Terms of Service and applies to everyone who uses the Dataetic
platform — you, your users, and anyone acting through your account or API keys. You are
responsible for their compliance as if it were your own.
Terms defined in the Terms of Service have the same meaning here. If you are unsure
whether something is permitted, ask us at
hello@dataetic.com
before you build it. We would much rather answer a question than enforce this Policy.
2Data you may connect
The platform reads from systems you own or are authorised to access. Before you connect
anything, you must have the right to connect it.
You must
- be authorised by the owner of each system you connect, and by your own organisation;
- have a lawful basis for processing any personal data the platform will touch, and have given whatever notice the individuals concerned are owed — that notice comes from you, not from us;
- honour any contractual restriction on the data, including a third-party licence that forbids exporting it to another platform;
- tell us in advance if a connection will carry data subject to a specific regime, so we can confirm the platform is configured for it.
You must not connect
- data you obtained unlawfully, or by scraping a service in breach of its terms;
- payment card data subject to PCI DSS, protected health information, government-issued identifiers, precise biometric data, or data about children, unless we have agreed to it with you in writing first;
- data whose export from its jurisdiction is restricted, unless the transfer is lawful and configured accordingly;
- material that infringes someone's intellectual property or contains their trade secrets without the right to use them.
During beta, keep regulated data out. The beta service carries no availability
commitment and is still changing. If your use case needs a regulated-data
configuration, talk to us and we will tell you honestly whether we are ready for it.
3Security and system integrity
This clause matters more here than on a typical platform, because Dataetic holds
credentials to production systems. Do not do anything that undermines that trust.
Access and credentials
- Do not use a credential you are not authorised to use, or connect a system you do not have permission to access.
- Do not use the platform to reach a system, network or account you would not be permitted to reach directly — the platform's access is not a way around a control that applies to you.
- Do not share account credentials or API keys outside your organisation, or use another customer's.
- Grant the narrowest access a connection needs, and revoke credentials when you remove a connection or when someone leaves.
The platform itself
- Do not attempt to gain unauthorised access to the platform, another customer's workspace or data, or any underlying infrastructure.
- Do not probe, scan or penetration-test the platform, or bypass or attempt to bypass any authentication, authorisation, quota or rate limit.
- Do not reverse engineer the platform, or attempt to extract its source code or model weights, beyond what the law expressly permits.
- Do not upload or transmit malware, or use the platform to store or distribute malicious code.
- Do not interfere with anyone else's use of the platform, including by deliberately degrading shared infrastructure.
Security research is welcome — coordinated. If you have found a vulnerability,
report it privately to
hello@dataetic.com and give us a
reasonable time to fix it. We will not pursue good-faith research that stays within a
scope agreed with us in writing, does not access another customer's data, does not
degrade the service, and is reported to us before it is reported anywhere else. Testing
without that agreement is a breach of this Policy.
4Resource use and fair sharing
The platform is shared infrastructure. Plan limits and rate limits exist so that one
workload cannot spoil the service for everyone.
- Do not circumvent a plan limit, quota or rate limit — by creating multiple accounts, rotating keys, sharding a workload across workspaces, or any other means.
- Do not run a workflow whose schedule or retry behaviour amounts to hammering the platform or a connected system, and put a sensible backoff on anything that retries.
- Do not use the platform for crypto mining, distributed computation unrelated to your data, or as general-purpose compute or file hosting.
- Do not resell or share your capacity with a third party, or operate the platform as a service of your own, unless we have agreed to it in writing.
- Do not automate the user interface to work around API limits.
If you have a legitimately heavy workload, tell us — we would rather size for it than
throttle you unexpectedly.
5Using the AI agents responsibly
Agents can query your data, generate transformations and take actions you authorise.
That is useful, and it is exactly why the following limits apply.
Do not use agents to
- make a decision with legal or similarly significant effects on a person — employment, credit, housing, insurance, education, benefits or law enforcement — without meaningful human review of each decision;
- infer or attempt to infer sensitive characteristics about individuals — health, sexuality, religion, political opinion, immigration status — from data that was not collected for that purpose;
- build a surveillance, tracking or scoring system directed at individuals without their knowledge, or any facial recognition or biometric identification capability;
- generate deceptive material at scale — disinformation, spam, fake reviews, impersonation of a real person or organisation, or content designed to manipulate a market;
- produce material that sexualises children, incites violence or self-harm, or facilitates a serious crime;
- develop a weapon, or produce operational guidance for a biological, chemical, radiological or nuclear one;
- circumvent a technical protection measure, generate exploit code for a system you are not authorised to test, or scrape a service in breach of its terms.
You must
- review output before relying on it. Agent output can be confidently wrong. Check it before it informs a decision, and always before it reaches a customer;
- disclose to the people you serve where an agent, rather than a person, produced something material to them;
- require human approval for consequential actions — anything that writes to, updates or deletes data in a production system, spends money, or communicates externally;
- test destructive operations against non-production data first;
- not attempt to circumvent the platform's safety controls, whether by prompt injection, jailbreaking, or embedding instructions in connected data to make an agent act outside its authorisation.
An agent's authority is your authority. When you give an agent write access to a
system, you have given it the ability to make changes you are accountable for. Scope it
the way you would scope a new employee's permissions on their first day.
6Prohibited content and conduct
You must not use the platform to store, process, transmit or generate anything that:
- is unlawful, or promotes or facilitates an unlawful act;
- infringes a copyright, trade mark, patent, trade secret, privacy or publicity right;
- is defamatory, harassing, threatening, or incites hatred or violence against a person or group;
- constitutes child sexual abuse material — we report this to the relevant authorities without notice and terminate the account immediately;
- is unsolicited bulk communication, or supports the sending of it;
- facilitates fraud, phishing, identity theft, money laundering or a pyramid scheme;
- misrepresents you as someone else, or falsely implies an endorsement or affiliation, including with Dataetic.
You must also not:
- use the platform in breach of export control or sanctions law, or from a sanctioned territory;
- use it to build a competing product, or publish a benchmark of it without our written consent;
- remove or obscure a proprietary notice, or use our name, logo or trade marks without permission.
7Respecting third-party services
Every connector talks to a service governed by your agreement with its provider, not
ours. You are responsible for staying inside those agreements.
- Respect each provider's terms of service, API terms and rate limits.
- Do not use a connector to extract data at a volume or frequency the provider prohibits, or to build a competing dataset where their terms forbid it.
- Do not use a connector to reach a service you are not authorised to access, or to evade an IP or geographic restriction it applies.
- Where a provider requires attribution or restricts redistribution, honour it in what you build.
If a provider tells us that your use of a connector breaches their terms, we may
suspend that connection.
8How we enforce this
We do not monitor the contents of your connected data, and this Policy is not a licence
for us to. We act on what we detect through operational signals — abuse detection, rate
limit patterns, security alerts — and on credible reports we receive.
What we may do
Depending on how serious and how urgent the problem is, we may:
- contact you and ask you to fix it within a stated period;
- apply a rate limit, or disable the specific workflow, agent, connection or user involved;
- suspend your account, in whole or in part;
- terminate your account under clause 12 of the Terms;
- preserve evidence and report the matter to law enforcement where the law requires it or someone is at risk.
Proportionality
We prefer the narrowest measure that solves the problem, and we prefer to speak to you
first. We will tell you what we did and why, and give you a route to respond. But where
there is a risk of serious or immediate harm — an active security incident, child
safety material, an ongoing attack on a third party — we may act first and explain
afterwards.
Enforcing this Policy does not entitle you to a refund of fees for a suspension caused
by your breach, and does not limit any other right or remedy we have.
9Reporting a violation
If you believe someone is using Dataetic in breach of this Policy, tell us. Include
what you observed, when, and anything that helps us identify the account. We treat
reports confidentially.
10Changes to this policy
The platform is in beta and its capabilities are growing, so this Policy will grow with
them. We will give you notice of a material change before it takes effect, as set out
in clause 16 of the Terms, and the effective date at the
top of this page always tells you which version applies. A change we make to address a
live security or legal risk may take effect immediately.