ARGYLL DATA DEVELOPMENT LTD
Acceptable Use Policy
Effective date: 26 July 2026
This Policy applies only to services supplied by Argyll Data Development Ltd (ADD). It governs access to and use of ADD’s Platform, Software, APIs, Models, infrastructure, developer tools and related services.
Introduction
This Acceptable Use Policy (the “Policy”) governs access to and use of the Platform, Software, APIs, Models, infrastructure and related services provided by Argyll Data Development Ltd (“ADD”, “we”, “us” or “our”).
This Policy forms part of the ADD Platform, Software and AI Services Terms and any applicable Order Form, Service Schedule, Service Level Agreement, Security Schedule or other commercial agreement that incorporates it.
By accessing or using ADD services, you agree to comply with this Policy. Where you access or use the services on behalf of a company, organisation, governmental body, educational institution or other legal entity, you confirm that you have authority to bind that entity to this Policy.
Where a Customer is subject to a separate written enterprise agreement, supply contract, Service Level Agreement or negotiated commercial arrangement, that agreement will prevail to the extent of any express conflict with this Policy.
1. Purpose and scope
This Policy establishes the rules and standards governing access to and use of:
· the Platform and Software;
· APIs and developer tooling;
· Models and AI-enabled services;
· ADD-operated or ADD-provided infrastructure;
· integrations, applications and automated systems;
· and related services provided by ADD.
The Policy is intended to:
· protect the security, integrity, availability and lawful operation of ADD services;
· prevent unlawful, harmful, abusive or disruptive activity;
· support responsible use of artificial intelligence technologies;
· and protect Customers, infrastructure providers, operational partners, licensors and third parties from misuse or operational risk.
It applies to all Customers, Authorised Users, developers and third parties accessing or using ADD services through Customer accounts, credentials, APIs, integrations or environments. Compliance with this Policy is a condition of access to and continued use of ADD services.
Nothing in this Policy limits any additional restriction, obligation or compliance requirement contained in applicable law, a commercial agreement, Service Level Agreement, Security Schedule, third-party licence term or operational policy made available by ADD.
2. Lawful and responsible use
ADD services may only be used for lawful, authorised and responsible purposes in compliance with applicable laws and regulations, this Policy, applicable agreements with ADD and relevant third-party licence or operational requirements.
Customers and Authorised Users must:
· act responsibly and in good faith when using ADD services;
· maintain appropriate human oversight over AI-generated outputs;
· implement appropriate governance, security and access controls;
· ensure that they have lawful rights to submit and process Customer Data;
· review and validate outputs before relying upon them;
· and ensure that use of ADD services does not create unlawful, harmful, deceptive, abusive, discriminatory or operationally unsafe outcomes.
The Customer is responsible for all activity conducted through its accounts, APIs, credentials, integrations and Authorised Users.
The Platform operates as an inference service. Customer prompts, submitted content and AI-generated outputs are not used for foundation-model training unless expressly agreed otherwise in writing.
Customers and Authorised Users must not use ADD services in a manner that:
· violates the rights of another person or organisation;
· compromises security or operational integrity;
· interferes with availability, capacity or performance;
· circumvents technical, usage or access restrictions;
· or exposes ADD, its infrastructure providers, licensors, Customers or third parties to material legal, regulatory, security or operational risk.
3. AI-specific usage restrictions
Customers and Authorised Users must not use the Platform, Software, Models, APIs or related services to generate, facilitate, support or automate:
· unlawful decision-making activities;
· unlawful discrimination or profiling;
· unlawful surveillance, monitoring, biometric identification or biometric analysis;
· deceptive content intended to defraud, impersonate, manipulate or unlawfully mislead individuals or organisations;
· malicious synthetic media, including unlawful deepfake content;
· disinformation campaigns or coordinated deceptive activity;
· malware, ransomware, exploit code, credential-theft tools or malicious cyber capabilities;
· harassment, abuse, intimidation or unlawful targeting of individuals or groups;
· unlawful collection, processing or exploitation of personal data;
· activities prohibited under applicable export-control or sanctions laws;
· or any activity likely to create material legal, ethical, operational, security or reputational risk.
Outputs generated through the Platform may be probabilistic, incomplete, inaccurate, inconsistent or dependent upon Model selection, prompts and operational conditions. Customers remain responsible for human review, evaluation, validation, compliance decisions and determining whether outputs are appropriate for downstream use.
Customers must not represent AI-generated outputs as human-generated where that representation would be unlawful or deceptive, nor represent outputs as guaranteed factual, authoritative, professionally certified or independently verified without appropriate review and validation.
ADD may apply Model-specific restrictions, usage limitations, safety controls, output filtering, operational safeguards or access restrictions where reasonably necessary for security, legal compliance, licensing, infrastructure protection, abuse prevention or operational integrity.
4. Security monitoring and abuse prevention
ADD may monitor the operation and use of its Platform, Software, APIs, infrastructure and related services where reasonably necessary to:
· maintain security and operational integrity;
· detect, prevent, investigate or mitigate abuse, fraud, unlawful activity or security incidents;
· enforce this Policy and applicable agreements;
· protect infrastructure, Models, Customers, licensors and third parties;
· and comply with legal or regulatory obligations.
Monitoring may include operational telemetry, usage analytics, authentication and access logging, API activity monitoring, infrastructure diagnostics, capacity and performance monitoring and automated abuse-detection systems.
Customer prompts and AI-generated outputs are not routinely reviewed by human personnel except where reasonably necessary for legal compliance, security, abuse prevention, technical support or operational integrity.
Customers and Authorised Users must not:
· interfere with monitoring or security controls;
· attempt to conceal abusive or unlawful activity;
· bypass security mechanisms, usage restrictions or operational safeguards;
· or engage in conduct likely to compromise the security, availability or integrity of ADD services or infrastructure.
ADD may investigate suspected violations, suspend or restrict access, apply temporary or permanent usage controls, rotate credentials, revoke access tokens, remove or disable access to content or integrations, and cooperate with infrastructure providers, licensors, regulators or law-enforcement authorities where required by law or reasonably necessary to protect security or operational integrity.
Where legally permitted and reasonably practicable, ADD will use commercially reasonable efforts to limit the scope of disclosure, protect confidential information and notify an affected Customer before disclosing Customer information to a governmental or regulatory authority.
5. Third-party Models and open-source components
ADD services may include, integrate with, provide access to or rely upon third-party Models, Open-Source Components, hosted infrastructure services, external APIs and technologies licensed or operated by third parties.
Customers and Authorised Users must comply with applicable third-party licence terms, open-source licence obligations, operational restrictions, Model-specific usage requirements and legal or regulatory limitations associated with those technologies.
Customers must not:
· use Models or Open-Source Components in breach of applicable licence terms;
· remove or alter attribution, copyright or licensing notices where required;
· misrepresent ownership of third-party or open-source technologies;
· or use ADD services in a manner that could cause ADD, a licensor, an infrastructure provider or another Customer to breach an applicable licensing obligation.
The availability of specific Models, APIs, Open-Source Components or Third-Party Services may change because of licensing requirements, legal or regulatory restrictions, infrastructure availability, security considerations, operational requirements or provider decisions.
ADD may add, remove, replace, suspend or restrict access to Models or Third-Party Services, apply operational safeguards or usage restrictions, or modify supported technologies where reasonably necessary for legal, operational, security, licensing or infrastructure reasons.
Nothing in this Policy grants Customers ownership of third-party Models, Open-Source Components, proprietary technologies or intellectual-property rights belonging to licensors or third parties. Nothing in this Policy limits rights expressly granted under an applicable open-source licence.
6. Reporting security issues and abuse
Customers and Authorised Users should promptly report suspected security vulnerabilities, unauthorised access, credential compromise, abusive or unlawful activity, operational security concerns or suspected violations of this Policy or an applicable agreement through the operational, support or security channels made available by ADD.
A person reporting a security issue must:
· act responsibly and in good faith;
· avoid activities likely to disrupt services, infrastructure, Models, Customers or third parties;
· avoid accessing, modifying or retaining data beyond what is reasonably necessary to demonstrate the issue;
· and comply with applicable laws, regulations and operational requirements.
Penetration testing, vulnerability scanning, exploit testing, Model-extraction testing and security research are prohibited unless expressly authorised in writing by ADD.
ADD may investigate a reported issue, cooperate with infrastructure providers, licensors, regulators or law-enforcement authorities where required, and take reasonable operational, technical or legal measures to protect its Platform, Software, infrastructure, Customers or third parties.
Submitting a report does not create any contractual entitlement, right to compensation or reward, or authority to continue testing or investigative activity unless expressly agreed by ADD in writing.
7. Enforcement
A breach of this Policy may result in investigation, warning, restriction, suspension or termination of access, depending on the nature, severity, recurrence and operational impact of the breach and the terms of the applicable agreement.
ADD may take immediate action where reasonably necessary to protect security, service availability, legal compliance, Customers, infrastructure providers, licensors or third parties. Any action taken under this Policy is without prejudice to ADD’s other contractual, statutory or common-law rights and remedies.
8. Changes to this Policy
ADD may update, modify, supplement, replace or revise this Policy where reasonably necessary to reflect changes in law or regulation, security requirements, operational practices, infrastructure, licensing obligations, technology, Model availability or capabilities, abuse-prevention requirements, or evolving industry standards and risk-management practices.
Updated versions may be published through the Platform, Customer portals, Documentation repositories, the ADD website or other appropriate communication channels. Continued access to or use of ADD services after the effective date of an updated Policy constitutes acceptance of the revised Policy, subject to any contrary provision in an applicable negotiated agreement.