Acceptable Use Policy
Last updated: 10 June 2026
This policy sets out what you may and may not do with the Data Protection Register. It forms part of our Terms of Service. The short version: use the service for its intended purpose, managing your organisation's data protection records, and do not put other customers, the service, or anyone's data at risk.
Use the service lawfully
- Do not use the service to break the law or to help anyone else break it.
- Do not store content in your records that you have no right to hold, including personal data you have no lawful basis to process.
- Do not upload content that is malicious (such as malware), or that infringes someone else's intellectual property or confidentiality.
Respect security and tenant isolation
- Do not attempt to access another organisation's workspace, records, or data, even if a flaw makes it technically possible. If you find such a flaw, report it to us and stop.
- Do not probe, scan, or test the service for vulnerabilities without our prior written permission.
- Do not attempt to bypass authentication, rate limits, or billing.
- Do not share account credentials. Each person using the service needs their own account.
Use the AI features fairly
- The AI drafting features exist to generate compliance documents from the information you capture. Do not use them as a general-purpose AI service or try to make them produce unrelated content.
- Do not attempt to extract the service's prompts or to make the AI ignore its instructions.
- Do not use automation to generate documents at a volume that has no plausible connection to your organisation's real compliance needs. We apply fair use limits to AI generation and may throttle accounts that exceed them.
Do not misrepresent the service
- Do not resell access to the service or offer it to third parties as your own product.
- Do not present generated documents as having been reviewed or endorsed by us. As the Terms of Service make clear, generated documents are drafts for your review, not legal advice.
Reporting problems
If you find a security vulnerability or see this policy being broken, tell us at hello@alethrikolabs.co.uk. We appreciate responsible disclosure and will not pursue good faith security research conducted within the rules above.
Enforcement
If an account breaches this policy we may, depending on severity: warn the organisation owner, throttle or disable specific features, suspend the account, or terminate it as described in the Terms of Service. For serious risks to the service or to other customers we may suspend first and explain afterwards. Where the law requires it, we may also report unlawful activity to the relevant authorities.
Contact
Questions about this policy: hello@alethrikolabs.co.uk