Version: 2026-08-05
This Acceptable Use Policy (“AUP”) applies to every use of the d5s service. Capitalised terms not defined here have the meanings in the applicable agreement.
1. General rule
You may use d5s only lawfully, safely, and within the authority granted by the relevant organisation, data owner, system owner, and third-party service. You are responsible for users, agents, credentials, tools, connectors, destinations, instructions, and approvals you configure.
2. Illegal, harmful, or abusive activity
You must not use the Service to:
- violate law, regulation, court order, sanctions, export controls, or another binding obligation;
- facilitate violence, exploitation, trafficking, abuse, harassment, credible threats, or material physical harm;
- create, solicit, store, or distribute child sexual abuse material or sexual content involving minors;
- unlawfully discriminate or deny rights, services, employment, housing, credit, insurance, education, or public benefits;
- defraud, extort, deceive, manipulate, or impersonate a person or organisation in a materially misleading way;
- infringe privacy, confidentiality, publicity, intellectual-property, database, trade-secret, or other rights;
- collect, infer, identify, monitor, or disclose personal data without required authority, notice, and legal basis;
- create or distribute illegal content, malware, ransomware, destructive code, phishing, spam, or credential-stealing material;
- facilitate illegal weapons, controlled substances, or other prohibited transactions; or
- evade a lawful investigation or destroy evidence unlawfully.
3. Systems, credentials, and security
You must not:
- access or test a system, account, network, model, data source, or credential without explicit authority;
- scan, probe, exploit, disrupt, overload, or bypass security controls outside an authorised and appropriately scoped security engagement;
- share, expose, acquire, or use credentials, tokens, secrets, or personal accounts without permission;
- introduce malicious code or instruct an agent to persist, propagate, conceal itself, or evade monitoring;
- interfere with service integrity, another customer's use, metering, rate limits, or isolation;
- reverse engineer or extract non-public models, prompts, source, or data except where mandatory law permits it;
- use automated access outside documented interfaces in a way that creates unreasonable load; or
- circumvent a suspension, plan limit, policy control, approval step, or other safeguard.
Good-faith security research requires prior written authorisation and an agreed scope. Report suspected vulnerabilities to security@d5s.tech.
4. Consequential and regulated uses
Do not allow the Service or its outputs to make a final decision with legal or similarly significant effects about a person without qualified human review, appropriate authority, documented criteria, testing, monitoring, and a lawful appeal or correction path.
This includes decisions concerning employment, worker management, credit, insurance, housing, education, essential services, legal rights, medical care, biometric identification, law enforcement, migration, and public benefits.
Do not use d5s as a safety-critical control where an error could directly cause death, serious injury, or catastrophic physical or environmental damage unless d5s has expressly agreed to the use and the complete system meets applicable certification and safety requirements.
The Service does not replace professional legal, medical, financial, security, or compliance judgment.
5. Content and communications
You must not use d5s to generate or distribute:
- unlawful hate, targeted harassment, credible threats, or non-consensual intimate content;
- materially deceptive synthetic media without appropriate disclosure where a reasonable person could be misled;
- unsolicited bulk communications, unlawful marketing, or messages sent without required consent;
- content falsely presented as an authorised statement of another person or organisation;
- instructions or claims you know are materially false in a context likely to cause substantial harm; or
- content that violates a third-party service's applicable rules.
You must clearly identify automated communications where law or context requires it and provide human escalation and opt-out mechanisms where appropriate. d5s identifies agent-sent messages as generated by an AI system. You must not remove, obscure, or misrepresent that identification.
6. Data handling
Use the minimum data necessary. Do not submit special-category, criminal-offence, children's, biometric-identification, precise-location, payment-card, patient, or similarly high-risk data unless your agreement expressly permits it and you have implemented required safeguards.
Respect workspace boundaries, data classifications, retention instructions, and deletion obligations. Do not connect a system or disclose output to a recipient unless you are authorised to do so.
7. Resource use
Do not use the Service for unauthorised cryptocurrency mining, denial-of-service activity, excessive automated account creation, resale contrary to the Agreement, or workloads that materially degrade the Service for others.
d5s may apply reasonable technical limits, rate controls, or usage safeguards consistent with the ordered plan.
8. Monitoring and enforcement
d5s may use proportionate automated and manual measures to detect abuse, security threats, and policy violations, subject to the Privacy Notice and DPA.
If d5s reasonably believes a violation or urgent risk exists, it may:
- request information or remediation;
- block specific content, tools, destinations, credentials, or activity;
- throttle or suspend the affected account, workspace, agent, or feature;
- preserve relevant evidence as permitted by law;
- notify an organisation administrator, affected party, provider, or authority where legally required or reasonably necessary to prevent serious harm; or
- terminate for a material or repeated violation under the Agreement.
Where safe and lawful, d5s will give notice, explain the general basis, limit action to the affected scope, and provide a reasonable opportunity to cure or appeal. It may act without advance notice for urgent security, safety, legal, or integrity reasons.
9. Reporting and appeal
Report suspected violations or appeal an enforcement decision at legal@d5s.tech. Security vulnerabilities should be sent to security@d5s.tech. Include enough information to identify the activity without sending unnecessary sensitive data.
10. Changes
d5s may update this AUP prospectively. Material changes affecting an active paid subscription follow the notice and versioning rules in the applicable agreement. Each published version remains available through its immutable URL, so you can identify the version in force when you accepted it.