Legal · Effective September 26, 2026
Acceptable Use Policy
This Acceptable Use Policy describes what you may not do with CaptivaHQ, including its AI features and APIs. It applies to every customer, Authorized User and integration, and forms part of the Terms of Service. Capitalised terms have the meanings given there.
1. Illegal, harmful and infringing use
Do not use the Service to:
- break any law or regulation, or help anyone else do so;
- infringe intellectual-property, privacy, publicity or other rights;
- store, generate or distribute child sexual abuse material, which we report to the authorities;
- harass, threaten, defame, stalk or discriminate unlawfully against anyone;
- promote violence, terrorism or self-harm, or plan the manufacture of weapons;
- defraud, scam or deceive people, including phishing and impersonating a person or organisation.
2. Messaging and outreach
- Send email, SMS and calls only to people you have a lawful basis to contact, and follow the rules that apply — for example CAN-SPAM, the TCPA, GDPR and ePrivacy rules, and CASL.
- No unsolicited bulk messaging, purchased or scraped lists, or messages that hide who sent them.
- Honour opt-outs promptly. Do not use AI voice or AI-drafted messages to mislead a recipient into thinking they are dealing with a human where the law requires disclosure.
3. Data you may not put in
Unless we have agreed otherwise in writing, do not upload or connect:
- protected health information or other medical records;
- full payment card numbers, bank credentials or authentication secrets for third-party systems (other than through the integration screens built for them);
- government identity numbers beyond what a business process genuinely needs;
- personal data about children under 16;
- data subject to export controls, or classified information.
4. Security and integrity
- Do not probe, scan or test the vulnerability of the Service without our written permission. To report a vulnerability, email [email protected].
- Do not access another customer's data, or try to break tenant isolation.
- Do not upload malware, or use the Service to host or distribute it.
- Do not overload the Service, run denial-of-service attacks, or bypass rate limits, metering or credit checks.
- Do not share login credentials between people, or use automated means to create accounts or trials.
- Use the API and MCP only as documented, with your own keys, and keep keys secret.
5. AI features
In addition to the fair-use rules in Section 5 of the Terms, do not:
- use AI Features to make fully automated decisions that have legal or similarly significant effects on a person — such as hiring, firing, credit, housing, insurance or access to essential services — without meaningful human review;
- generate content that passes AI Output off as human-written where that would deceive people in a way that matters, or create deepfakes of real people;
- attempt to jailbreak models, extract system prompts, or plant instructions in records, emails or documents intended to manipulate an AI agent (prompt injection);
- use AI Output or the Service to train, fine-tune or distil a model, or to build a competing product;
- use AI Features for biometric identification, emotion recognition in the workplace, social scoring, or any other practice prohibited by the EU AI Act or similar law;
- run AI Features in unattended loops or at volumes out of proportion to your business, or enrich data about people you have no relationship with.
Our model providers' usage policies also apply to AI Features. We will not ask you to accept terms stricter than this policy without notice.
6. Enforcement
We may investigate suspected breaches, and may remove content, disable integrations or agents, throttle AI usage, suspend users or suspend the Workspace, as described in Section 5.5 of the Terms. Serious or repeated breaches may lead to termination without refund. Where the law requires, we report illegal content to the authorities. We act proportionately and, where practical, tell the Workspace administrator first.
7. Reporting abuse
If you see CaptivaHQ being used in breach of this policy, email [email protected] with as much detail as you can. Security issues go to [email protected].
Published for CaptivaHQ by United Technology Services Inc. · All documents: captivahq.com/legal. Questions: [email protected].