Acceptable Use Policy

1. Purpose and Scope

This policy protects elyXion, Customers, users, and providers from unlawful, abusive, insecure, or disruptive use of Services, the Portal, integrations, support channels, and elyXion-managed infrastructure. The Customer must ensure its Authorised Users comply.

2. Lawful Use

Services may be used only for lawful business purposes and within the Agreement. Users must not violate privacy, cybersecurity, intellectual-property, communications, sanctions, export-control, employment, discrimination, or other applicable laws.

3. Prohibited Activity

Users must not:

  • gain or attempt unauthorised access to accounts, systems, data, networks, tenants, or facilities;
  • probe, scan, exploit, or test security except under written authorisation and the disclosure policy;
  • introduce malware, ransomware, destructive code, credential stealers, or concealed persistence;
  • send spam, phishing, fraudulent messages, or communications that misrepresent identity or authority;
  • host, share, or process unlawful, infringing, exploitative, discriminatory, or deliberately harmful content;
  • interfere with service availability, overload resources, evade limits, or circumvent security controls;
  • harvest data, scrape protected content, or monitor people without a lawful basis and required notice;
  • share credentials, defeat multi-factor authentication, or permit access by unauthorised persons;
  • use Services to develop or operate weapons, unlawful surveillance, or prohibited AI practices;
  • reverse engineer the Portal except where mandatory law permits it;
  • remove ownership, security, audit, or attribution notices; or
  • use elyXion or provider names, logos, or services to imply endorsement without permission.

4. Security Testing

Security testing of elyXion systems requires written permission or must remain strictly within the published Coordinated Vulnerability Disclosure scope. Customer-authorised testing of Customer systems must be coordinated to prevent disruption and false incident response.

5. Data and AI Use

Users must not submit personal, confidential, regulated, or export-controlled data to AI functionality unless the Customer has authorised the use case and appropriate safeguards are in place. AI must not be used for unlawful profiling, manipulation, discrimination, or autonomous high-impact decisions outside an approved design.

6. Resource Use

elyXion may apply reasonable technical limits to protect fairness, cost, availability, and security. Unusual consumption may be throttled, isolated, or charged where the Agreement permits.

7. Investigation and Enforcement

elyXion may investigate credible abuse, preserve relevant records, restrict features, block content, or suspend affected access. Emergency action may occur without notice where necessary to contain harm. Where practicable, elyXion will explain the issue and allow remediation.

8. Reporting

Suspected abuse should be reported to legal@elyxion.eu. Reports should include the affected service, time, evidence, and impact, without sharing unnecessary personal data.

9. Customer Responsibility

The Customer is responsible for user conduct, permissions, content, and use under its account. The Customer must cooperate in containment and remediation and may be liable for costs caused by intentional or negligent misuse, subject to the Agreement.

Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review