Acceptable Use Policy
Last updated: 7 September 2026
This Acceptable Use Policy (“AUP”) forms part of the Terms of Service and sets out the rules for using the Concha AI platform and related services (the “Service”). It applies to all users, including customers, end-users, contractors, and anyone accessing the Service on your behalf.
By using the Service, you agree to comply with this AUP. If you do not agree, you must not use the Service.
1. Purpose and Scope
This policy ensures that the Service is used:
- Safely, securely, and in compliance with applicable laws;
- In a way that protects Concha AI, its users, and third parties;
- In line with our commitment to responsible AI and ethical decision-making.
It applies to all use of the Service, including via web, API, integrations, and any future interfaces.
2. General Principles
You must use the Service:
- In accordance with these Terms, our Privacy Policy, and all applicable laws and regulations;
- Only for lawful purposes and in ways that do not infringe the rights of Concha AI or any third party;
- In good faith, with honesty and integrity;
- With appropriate human oversight, especially for decisions that significantly affect individuals.
3. Prohibited Uses
You must not use the Service to:
3.1 Illegal or Harmful Activities
- Violate any applicable law, regulation, or legal obligation (including data protection, employment, anti-discrimination, and AI-specific laws);
- Engage in fraudulent, deceptive, or misleading activities;
- Promote or facilitate terrorism, violent extremism, or organised crime;
- Distribute malware, viruses, or any harmful code;
- Attempt to gain unauthorised access to the Service, other users’ accounts, or Concha AI systems.
3.2 Discrimination and Harm to Individuals
- Discriminate against, harass, or harm individuals based on protected characteristics (e.g., race, ethnicity, gender, sexual orientation, religion, age, disability, nationality);
- Make solely automated decisions with legal or similarly significant effects without meaningful human review, where prohibited or restricted by law;
- Use the Service to profile, score, or evaluate individuals in ways that violate applicable laws or ethical standards.
3.3 Misuse of Data and Confidential Information
- Upload or process personal data without a lawful basis and appropriate notices to data subjects;
- Share confidential, proprietary, or sensitive information (yours or third-party) via the Service in breach of contractual or legal obligations;
- Attempt to extract, scrape, or harvest data from the Service beyond what is explicitly permitted;
- Circumvent technical measures designed to protect data or restrict access.
3.4 Abuse of the Platform
- Use the Service to send spam, unsolicited communications, or bulk messages;
- Interfere with or disrupt the Service, servers, or networks;
- Exploit vulnerabilities or security weaknesses in the Service;
- Use automated tools (bots, scripts) to access the Service in ways that exceed authorised usage or degrade performance;
- Resell, sublicense, or provide the Service as a service bureau to third parties without explicit written consent.
3.5 AI-Specific Prohibitions
- Use AI outputs to generate content designed to deceive, manipulate, or cause harm (e.g., deepfakes for fraudulent purposes, disinformation campaigns);
- Treat AI-generated recommendations as definitive without independent verification, especially for high-stakes decisions (hiring, promotion, dismissal, credit, legal, medical, safety);
- Use the Service to train competing AI models or extract model weights, parameters, or architecture details;
- Submit prompts or inputs designed to jailbreak, bypass safety filters, or extract system instructions.
4. Acceptable Uses
The Service is intended to support:
- Structured decision-making for hiring, promotions, and critical appointments;
- Evidence gathering, analysis, and documentation to inform human decisions;
- Generation of reports, insights, and recommendations to assist qualified decision-makers;
- Integration with existing HR, ATS, and operational systems to improve workflow efficiency;
- Research, planning, and internal analysis using data you are authorised to process.
All outputs should be treated as decision-support material requiring human review and validation before use.
5. Data Handling and Confidentiality
When using the Service, you must:
- Ensure you have appropriate legal grounds and notices before uploading personal data;
- Avoid sharing sensitive data (e.g., health information, financial data, authentication credentials) unless explicitly permitted and secured;
- Apply the principle of data minimisation: only upload what is necessary for the task;
- Implement appropriate access controls so only authorised personnel can access Customer Data within the Service;
- Notify us promptly if you become aware of unauthorised access or data breaches involving the Service.
6. API and Integration Use
If you access the Service via API or integrations:
- API keys and credentials are for your internal use only and must not be shared;
- You are responsible for all activity under your API keys;
- You must comply with rate limits and usage quotas to protect Service stability;
- You must not use APIs to build competing products or services;
- We may suspend or revoke API access for abuse, security risks, or breach of these Terms.
7. Security Obligations
You agree to:
- Maintain strong, unique passwords for all accounts;
- Enable multi-factor authentication where available;
- Keep your systems, browsers, and integrations up to date;
- Not attempt to bypass security controls or access controls;
- Report security vulnerabilities to security@concha-ai.com and allow reasonable time for remediation before public disclosure.
8. Monitoring and Enforcement
Concha AI may:
- Monitor usage patterns to detect abuse, fraud, or security incidents;
- Investigate suspected violations of this AUP;
- Suspend or terminate access immediately for serious or repeated breaches;
- Cooperate with law enforcement and regulators where required.
Enforcement actions are taken at our sole discretion and do not limit our other rights and remedies under the Terms or applicable law.
9. Reporting Violations
If you become aware of any misuse of the Service or potential violations of this AUP, please report them to:
- Email: abuse@concha-ai.com or security@concha-ai.com
- Include details such as: nature of the issue, affected accounts or data, timestamps, and any supporting evidence.
We take all reports seriously and will investigate appropriately.
10. Changes to This Policy
We may update this AUP from time to time to reflect changes in the Service, law, or best practices.
Material changes will be communicated via email or notice within the Service at least 30 days in advance. Continued use after the effective date constitutes acceptance of the updated policy.
11. Relationship to Other Policies
This AUP forms an integral part of the Terms of Service. In the event of any conflict between this AUP and the Terms, the Terms shall prevail unless otherwise stated.
Additional policies may apply to specific features, enterprise agreements, or regulated use cases.
12. Contact
For questions about this Acceptable Use Policy:
- Email: legal@concha-ai.com
- Website: https://concha-ai.com
- Address: [insert legal address of the company, if applicable]
Important notice: This document is a template and does not constitute legal advice. It should be reviewed by a qualified lawyer before publication, particularly to validate compliance with GDPR/UK GDPR, AI regulations, employment law, and local requirements.
