Draft — not yet reviewed by a solicitor.
This acceptable use policy is a working template prepared for internal review. It has
not been settled by a qualified legal adviser and must
not be relied upon by customers, presented in a procurement pack, or referenced in a contract until it
has been. Placeholders marked TODO
must be completed before publication.
Queries: support@dijitul.uk
1. Application
This Acceptable Use Policy (“AUP”) forms part of the Terms of Service. It applies to you, to your personnel, and to any end user to whom you make the Service available directly or indirectly. You are responsible for their compliance as if it were your own.
This policy is not a complete list of everything we consider unacceptable. Where something is plainly harmful, unlawful or abusive but is not listed, we may still act on it.
2. Prohibited uses
You must not use the Service to:
- do anything unlawful under the laws of England and Wales, or under the laws of any jurisdiction in which you or your end users operate;
- generate or distribute child sexual abuse material, or any content that sexualises a minor;
- generate content that incites violence, terrorism, or hatred against a group with a protected characteristic;
- harass, stalk, threaten, defame or dox an individual;
- produce material designed to deceive — impersonating a real person or organisation, fabricating evidence, generating fake reviews or fake identity documents, or creating synthetic media of a real person without their consent;
- develop malware, ransomware, exploits, phishing content, or tooling whose primary purpose is to compromise systems or credentials;
- provide instructions for the synthesis or acquisition of weapons, explosives, or chemical, biological, radiological or nuclear materials;
- facilitate fraud, money laundering, or the evasion of sanctions or export controls;
- infringe intellectual property rights, or circumvent technical protection measures; or
- process personal data without a lawful basis, or in breach of the rights of the individuals concerned.
3. High-risk and regulated uses
The Service is a general-purpose text tool. Model outputs are generated statistically and may be wrong. You must not present an output as professional advice, and you must not deploy the Service as the sole decision-maker in a context that materially affects a person's rights, safety, health, finances, employment, immigration status or access to essential services.
Where you use the Service in a regulated activity — legal services, healthcare, financial advice, recruitment, education, the operation of critical infrastructure — meaningful human review must sit between the output and the affected person, and you remain responsible for compliance with the rules of your regulator.
TODO(legal): review against the UK's emerging AI assurance expectations and, where the customer base extends into the EU, the EU AI Act's obligations for deployers of high-risk systems.
4. Technical restrictions
You must not:
- attempt to circumvent metering, rate limits, quotas, allow-lists or residency controls;
- share an API key across organisations, or resell access without our written agreement;
- probe, scan or test the security of the Service without our prior written permission, save that good-faith vulnerability research reported under the process on the security page is welcome;
- use the Service to systematically extract model weights, replicate a model, or generate a training corpus for a competing model;
- run automated retries in a way that degrades the Service for others — respect
Retry-Afterand theX-RateLimit-*headers; or - submit deliberately malformed input intended to cause resource exhaustion.
5. Content you submit
You must have the right to submit the content you send, and to have it processed for the purpose you are using it for. Where you send personal data, you must have a lawful basis, and where you send special category data you must have an Article 9 condition.
PII redaction is available and is genuinely useful, but it is a mitigation, not a lawful basis and not a guarantee. Enabling it does not transfer your obligations as controller to us.
6. Upstream policies
Inference is performed on a third-party platform using third-party models. Your use must also comply with the acceptable use policies of Amazon Web Services and of the model provider. Where an upstream policy is stricter than this one, the stricter policy applies.
We decline to serve models whose terms are incompatible with the commitments we make about retention and operator access, even where a customer asks for them. The current exclusions are published on the data residency page.
7. Enforcement
Where we reasonably believe this policy has been breached, we may — proportionately to the seriousness of the breach — contact you for an explanation, throttle or suspend a key, suspend the account, or terminate the Terms. Where the breach presents an immediate risk of serious harm, or where we are legally required to act, we may suspend first and explain afterwards.
We do not monitor the content of prompts. Enforcement is triggered by reports, by metadata patterns indicating abuse, or by notification from an upstream provider — not by us reading your traffic.
Where we are legally obliged to report content to a competent authority, we will do so, and we will tell you unless we are prohibited from doing so.
8. Reporting abuse
Report suspected misuse of the Service to support@dijitul.uk with the subject line ABUSE. Include the approximate time, and the key prefix if you know it. TODO(legal): replace with a dedicated abuse@ address and publish target response times.
9. Changes
We may update this policy as the risks change or as upstream policies change. Material changes will be notified by email to account holders. Continued use after the effective date constitutes acceptance.
Questions about this document should go to support@dijitul.uk. Nothing on this page is legal advice, and it does not create any obligation on dijitul Ltd until a settled version has been executed.