01
Scope and responsibility
This Acceptable Use Policy (“AUP”) applies to every user of Root Digit Services and is incorporated into the Terms of Service. Customer must ensure that its authorised users and anyone using its systems follow this AUP.
You are responsible for your data, code, prompts, models, configurations, targets, outputs and downstream use, including obtaining required permissions and maintaining human and technical controls appropriate to the risk.
02
Illegal, deceptive and harmful conduct
- Do not violate applicable law, sanctions, export controls, court orders, anti-bribery, anti-money-laundering or sector-specific obligations.
- Do not commit fraud, impersonation, deceptive trade practices, phishing, harassment, stalking, threats or unlawful discrimination.
- Do not infringe intellectual property, privacy, publicity, confidentiality or other rights.
- Do not create, solicit, distribute or facilitate child sexual abuse material, sexual exploitation of minors, non-consensual intimate imagery or content that unlawfully endangers a person.
- Do not use Services to facilitate trafficking, prohibited weapons, terrorism, organised crime or evasion of lawful controls.
03
Cybersecurity, testing and attack simulation
Security testing is permitted only against systems you own or are expressly authorised in writing to test, within the approved targets, methods, timing and limits. Evidence of authorisation must be retained.
- No unauthorised access, vulnerability scanning, credential attacks, exploitation, interception or data extraction.
- No malware, ransomware, botnet operation, credential theft, destructive payloads or persistence on third-party systems.
- No denial-of-service activity, traffic amplification or attempts to exhaust resources except within an approved isolated test environment.
- No bypass of authentication, authorisation, rate limits, safety systems or usage controls.
Controlled high-capacity products
04
Network, platform and resource integrity
- No unsolicited bulk communication, spam, phishing, unlawful scraping or automated account creation.
- No cryptocurrency mining, open proxy, relay, anonymisation or distributed-compute workload unless expressly included in the purchased scope.
- No activity that materially degrades shared performance, evades quotas or shifts prohibited workloads across multiple accounts.
- No reverse engineering or benchmarking publication where prohibited by contract, except rights that applicable law does not permit us to restrict.
05
AI, data and automated systems
Users of AI or automated systems must have lawful rights to input data, evaluate material outputs, document appropriate limitations, provide disclosures required by law and maintain meaningful human oversight for consequential decisions.
- No unlawful profiling, social scoring, biometric categorisation, emotion inference or surveillance.
- No deceptive synthetic media, election interference, coordinated inauthentic behaviour or impersonation intended to cause harm.
- No solely automated high-impact decision in employment, credit, insurance, housing, education, healthcare or legal services without the controls and review required by law.
- No attempt to extract protected model weights, system prompts, private training data or another customer’s data.
06
Physical, financial and safety-critical uses
Robotics, autonomous vehicles, drones, industrial control, healthcare, financial forecasting and other high-impact systems require qualified human ownership, applicable approvals, operating limits, test evidence and a safe fallback. Root Digit Services are not independently certified for a safety-critical use unless the signed agreement expressly identifies the certification and scope.
Do not deploy a system where a plausible failure could cause death, serious injury, unlawful financial loss or critical-infrastructure disruption without documented hazard analysis, verification, validation, monitoring and emergency control appropriate to that use.
07
Content and data restrictions
Do not submit data you are not authorised to use. Do not place passwords, private keys, payment authentication data, government identifiers or highly sensitive personal data into a Service unless the contracted configuration expressly supports it.
Root Digit may remove or restrict content reasonably believed to violate this AUP, law or third-party rights. We do not assume an obligation to monitor all content and do not endorse user-generated output.
08
Investigation and enforcement
Root Digit may investigate credible suspected violations and preserve relevant records. Depending on severity, we may warn, require remediation, throttle, quarantine, suspend, terminate, block a target or account, and report conduct where legally required. We will limit action to what is reasonably necessary and provide notice where doing so would not increase risk or violate law.
Customers must cooperate with reasonable abuse investigations. Repeated, deliberate or severe violations may result in immediate termination without refund to the extent permitted by law and contract.
09
Reporting abuse and security issues
Report suspected service abuse through the legal enquiry route. Report a vulnerability in Root Digit systems through the security disclosure programme. Include affected system, timestamps, scope and non-sensitive evidence; do not exploit beyond what is needed to demonstrate the issue.
10
Changes to this policy
We may update this AUP to address new Services, threats, misuse patterns or legal requirements. Material changes affecting an active paid Service will be communicated through the client portal or another agreed channel. Urgent safety or security restrictions may apply immediately.
Questions, notices or rights requests
Use Root Digit’s structured enquiry form and select “Privacy, legal or rights request”. Do not include passwords, access keys, or confidential credentials.
Submit a legal enquiryRelated documents