Acceptable Use Policy
This policy applies to anyone who accesses or uses a product or service operated by Sifotech UK Ltd, whether under a paid contract, a free tier or a trial.
Applies to all Sifotech products · Version 1.0
1. Permitted use
You may use Sifotech products for lawful purposes consistent with the product documentation, your agreement with us and this policy. You are responsible for the activity of any account or credential issued to you and for ensuring that anyone you give access to also complies with this policy.
2. Prohibited content and activity
You must not use a Sifotech product to:
- upload, store, publish or transmit content that is unlawful under UK law, including content that infringes intellectual property rights, violates privacy, defames any person, or constitutes harassment or hate speech;
- upload child sexual abuse material or any content that sexually exploits children, or any content prohibited by the Online Safety Act 2023;
- upload or transmit malware, ransomware, worms or any code designed to disrupt, damage or gain unauthorised access to a system;
- send unsolicited bulk messages (spam) or otherwise contravene the Privacy and Electronic Communications Regulations (PECR);
- impersonate any person or entity, or misrepresent your affiliation with a person or entity;
- use the product to develop or operate a competing service by reverse engineering or scraping, except to the extent permitted by law;
- process special-category or other particularly sensitive personal data in a way that breaches UK GDPR;
- violate any applicable export-control, sanctions or anti-money- laundering law.
3. Security and integrity
You must not:
- attempt to access, probe or interfere with the product, our infrastructure or another customer’s data, except under our published security disclosure policy;
- circumvent or attempt to circumvent rate limits, authentication, billing controls or feature gates;
- use bots, scrapers or automation that materially exceeds normal human interaction levels, unless we have agreed in writing;
- share credentials, MFA codes or session tokens with anyone who is not authorised to use the account.
Suspected vulnerabilities should be reported responsibly via security.txt.
4. AI features and outputs
Where a Sifotech product offers AI-assisted features, you must not use them to generate content that breaches section 2, to attempt to extract our prompts or training data, or to mislead a recipient about whether content was AI-generated where the law requires disclosure (for example, in political advertising). AI outputs are not professional advice and should be reviewed for accuracy before being relied on.
5. Reporting abuse
To report a violation of this policy, content you believe is unlawful, or anything else of concern, contact hello@sifotech.co.uk. We aim to acknowledge abuse reports within one (1) working day.
6. Monitoring
We do not routinely monitor the content you submit to our products. We log operational metadata (such as authentication events, API requests and error rates) to operate, secure and support the service. We may inspect specific content in response to a substantiated abuse report, a legal order or a security investigation, in line with our privacy notice.
7. Enforcement
Where we identify a likely breach, we will, depending on severity: warn the account holder, remove or restrict the offending content, suspend specific features, rate-limit the account, or proceed directly to suspension or termination as set out in section 8.
8. Suspension and termination
We may suspend or terminate access to a product immediately and without notice where (a) a breach of this policy is reasonably suspected, (b) we are required to do so by law, or (c) continued access poses a security or stability risk. Where suspension is for an issue you can remedy, we will let you know how. Where permitted, we will provide a route to export your data.
9. Changes
We may update this policy from time to time. The current version and review date are shown in the footer below. Material changes will be flagged in-product for at least thirty (30) days where we have an account-level contact route.