Acceptable Use Policy
This Acceptable Use Policy ("AUP") describes permitted and prohibited uses of the Pritect.ai, including all Services, features, content, and Documentation provided by the Service Provider. By using the Platform, Customer agree to comply with this AUP. Violation may result in suspension or termination of access.
1. Definitions
Capitalized terms used but not defined in this Acceptable Use Policy shall have the meanings given to them in the Master Service Agreement (the "MSA") between Customer and the Service Provider.
2. Permitted Uses
The Platform is designed for legitimate governance, risk, and compliance activities, including:
- •Managing Records of Processing Activities (RoPA) and related data protection documentation.
- •Conducting and documenting impact assessments (DPIA, TIA, LIA, PIA, Comprehensive AI Impact Assessments).
- •Managing supplier due diligence and third-party governance.
- •Tracking IT assets and their compliance attributes.
- •Conducting maturity assessments across data protection, cybersecurity, and AI governance domains.
- •Managing data subject requests and breach incidents.
- •Utilising AI-powered features for governance guidance and workflow assistance.
- •Training employees on compliance topics through the training module.
3. Prohibited Uses
Customer must not use the Platform to:
3.1 Content and Data Misuse
Customer must not use the Platform to:
- •Extract, copy, or redistribute risk libraries, assessment templates, or regulatory content for competitive purposes.
- •Upload content that violates third-party intellectual property rights.
- •Store personal data beyond what is necessary for legitimate compliance purposes.
- •Process special category data without appropriate legal basis and safeguards.
3.2 Security and Access
Customer must not use the Platform to:
- •Attempt to gain unauthorized access to the Platform, systems, or data, or to tenant environments other than Customer's own.
- •Circumvent, disable, or interfere with security features including MFA and SSO.
- •Share login credentials or authentication tokens with unauthorized parties.
- •Conduct vulnerability scanning, penetration testing, or security assessments without prior written authorization.
- •Introduce Malicious Code or any software designed to disrupt the Platform.
3.3 Compliance Abuse
Customer must not use the Platform to:
- •Use the Platform for unlawful, fraudulent, misleading, or unethical purposes, or generate fraudulent compliance records or falsify audit documentation.
- •Misuse the DSR portal to submit vexatious or illegitimate requests.
- •Misrepresent compliance status to regulators or auditors using Platform outputs.
- •Conduct benchmarking or comparative analysis intended for publication without WLC's prior written consent.
- •Resell, sublicense, lease, or otherwise make the Platform available to any third party, other than Customer's Affiliates and authorized Users acting within Customer's account, except as expressly permitted under the MSA.
- •Use the Platform or any WLC's confidential information to train artificial intelligence, machine learning, or similar models, except as expressly permitted by WLC in writing.
3.4 Technical Restrictions
Customer must not use the Platform to:
- •Reverse engineer, decompile, or disassemble any part of the Platform.
- •Use automated scripts, bots, or scrapers without authorization.
- •Exceed reasonable API rate limits or attempt to overload Platform infrastructure.
- •Interfere with other Tenants' use of the Platform.
3.5 Prohibited Multi-entity and Managed Service Use
The Platform is designed to support a legal entity and its Affiliates in managing their own governance, risk, and compliance activities. A consultant, data protection officer, or compliance professional engaged by Customer may use the Platform solely to manage compliance activities of Customer and its Affiliates within a single Tenant.
The Platform is not designed or licensed for use as a managed service or compliance office tool through which a single Customer Tenant is used to serve multiple separate, unrelated client organisations. Each independent legal entity, or group of legal entities under common control, that does not qualify as Customer or an Affiliate of Customer, is required to hold its own subscription to the Platform.
Accordingly, Customer must not:
- •Use a single Tenant to manage, administer, or process governance, risk, and compliance activities described in Section 2 above, on behalf of legal entities that are not Customer or its Affiliates.
- •Act as a compliance office, managed service provider, or intermediary by using Customer's Tenant to produce, maintain, or deliver Platform outputs for the benefit of legal entities that do not qualify as Affiliates of Customer.
- •Grant access to Customer's Tenant to individuals or users acting on behalf of, or for the primary benefit of, legal entities that are not Customer or its Affiliates.
- •Use a single subscription in a manner that circumvents the multi-entity use restriction set out in MSA Section 3.12.
For the avoidance of doubt, this Section 3.5 does not prohibit Customer from: (i) producing compliance outputs, reports, or assessments that reference or relate to third parties in the ordinary course of Customer's own compliance activities, where such references are incidental to Customer's own compliance programme; or (ii) using the Platform in connection with services provided under a separate written agreement with Service Provider expressly authorising such use, including where Customer is an authorised partner or reseller of Service Provider.
4. AI-Enabled Features
The Platform incorporates AI-powered features to assist with governance tasks. When using these features:
- •Human Review Required: All AI-generated outputs (risk summaries, control recommendations, governance guidance) must be reviewed and validated by qualified personnel before being actioned or relied upon.
- •No Legal Advice: AI-Supported Features do not constitute legal, regulatory, or professional advice.
- •Data Processing: Customer data processed by AI-Supported Features is not used to train underlying models. See our Privacy Notice for details.
- •Accuracy Limitations: AI outputs may contain errors or omissions. Users are responsible for verifying accuracy.
5. Multi-Tenant Environment
The Platform operates as a multi-tenant platform with strict data isolation between organizations. Customer must:
- •Only access data within their authorized Tenant.
- •Not attempt to discover or access other Tenants' data, configurations, or Users.
- •Report any suspected data isolation issues immediately to security@pritect.ai.
6. Data Responsibilities
- •Customer remains the data controller for Customer Personal Data processed through the Platform.
- •Customer is responsible for ensuring appropriate legal bases for processing.
- •Customer must maintain accurate and up-to-date records.
- •Customer must configure appropriate access controls within Customer's Tenant.
- •Customer must promptly report any data breaches affecting Platform data to the appropriate authorities.
7. Monitoring & Enforcement
We reserve the right to:
- •Monitor Platform usage for security and compliance purposes.
- •Investigate suspected violations of this AUP.
- •Suspend or terminate access for AUP violations.
- •Cooperate with law enforcement where legally required.
- •Modify this AUP with reasonable notice to Users.
8. Reporting Violations
If Customer becomes aware of any violation of this AUP, Customer must report it immediately to security@pritect.ai.
9. Updates to This Policy
We may update this AUP from time to time. Material changes will be communicated via the Platform or email. Continued use of the Platform following changes constitutes acceptance of the updated AUP.
10. Contact
For questions about this Acceptable Use Policy:
White Label Consultancy AS
Email: legal@pritect.ai
