Acceptable Use Policy

  • Home /
  • Acceptable Use Policy

Acceptable Use Policy

Last updated: August 16, 2026

This Acceptable Use Policy (AUP) applies to Dureach websites, SaaS services, AI workflows, APIs, integrations, data services, trade-data products, support channels, and any feature that lets a user upload, generate, enrich, export, send, or act on information.

1. Lawful Use Required

You may use Dureach only for lawful business purposes. You are responsible for complying with laws that apply to your users, data, messages, jurisdictions, industry, and intended use.

2. Prohibited Uses

You may not use Dureach to:

  • Break the law, violate sanctions or export controls, or assist illegal activity.
  • Infringe intellectual property, privacy, publicity, contractual, or confidentiality rights.
  • Harass, threaten, defame, deceive, exploit, discriminate against, or harm a person or group.
  • Send malware, phishing, credential-harvesting content, harmful code, or security exploits.
  • Attempt unauthorized access to accounts, systems, networks, APIs, data, or integrations.
  • Interfere with service performance, rate limits, metering, security controls, or abuse-prevention systems.
  • Scrape, crawl, harvest, or extract data at scale except through authorized product features and licensed usage rights.
  • Generate or distribute content that enables violence, self-harm, sexual exploitation, child exploitation, human trafficking, fraud, or other severe harm.
  • Use the service for regulated decisions such as credit, employment, housing, insurance, lending, public benefits, immigration, law enforcement, or similar eligibility decisions.

3. Sensitive and Regulated Data

Unless a signed agreement expressly permits it, you may not upload or process:

  • Protected health information, medical records, or health inferences.
  • Payment-card data, bank credentials, financial account credentials, or credit eligibility data.
  • Government IDs, biometric identifiers, precise geolocation trails, children’s data, or criminal records.
  • Special-category data under privacy laws, such as racial or ethnic origin, political opinions, religion, union membership, genetic data, sex life, or sexual orientation.
  • Classified, export-controlled, or highly confidential government data.

4. Outreach, Messaging, and Communications

If you use Dureach for outreach, messaging, enrichment, campaign planning, or communication workflows, you must:

  • Have a lawful basis for contacting recipients.
  • Use accurate sender identity, subject lines, and business contact information.
  • Honor opt-outs, suppression lists, unsubscribe requests, and do-not-contact signals promptly.
  • Follow anti-spam, telemarketing, electronic communications, consent, and privacy laws that apply to your campaign.
  • Avoid deceptive personalization, impersonation, hidden tracking that violates law, or misleading claims.
  • Maintain domain, mailbox, API, and sending practices that do not harm third parties or service integrity.

Dureach may suspend or limit workflows that create excessive complaints, bounces, abuse reports, deliverability risk, or legal risk.

5. AI Workflow Rules

You are responsible for reviewing AI-generated outputs before use. You may not use Dureach to create or deploy autonomous workflows that make high-impact decisions without appropriate human review, legal basis, and controls.

You may not use AI outputs to impersonate people, fabricate endorsements, forge documents, bypass safety controls, or mislead recipients about whether they are interacting with a person or automated system where disclosure is required.

6. Data Product Rules

You may use Dureach data products only within your licensed scope. You may not resell, redistribute, publish, bulk-export, model-train, reidentify, combine for prohibited profiling, or use data to make regulated eligibility decisions unless your agreement expressly allows it.

Trade-data use is also governed by the Trade Data Licensing Terms.

7. Security Testing

You may not conduct penetration tests, vulnerability scans, load tests, denial-of-service tests, social engineering, or similar security testing against Dureach systems without prior written authorization.

Report security concerns to [email protected].

8. Enforcement

Dureach may investigate suspected violations and may remove content, throttle usage, suspend workflows, restrict exports, revoke API keys, suspend accounts, or terminate access where needed to protect users, recipients, third parties, Dureach, or service integrity.

Where practical, Dureach will provide notice and an opportunity to remediate. Immediate action may be taken for urgent legal, security, privacy, abuse, or service-risk issues.

9. Contact

Report abuse to [email protected]. For legal questions, contact [email protected].