Purpose and scope
This policy applies to every customer, administrator and authorised user of Nidus, including use of connected providers, imports, exports, integrations, AI-assisted features, automations and any work produced through Nidus professional services. The customer is responsible for its users' compliance with this policy.
Use Nidus only for legitimate business purposes and in accordance with the agreement, applicable law and the rights of others.
Accounts and security
Do not share account credentials, bypass access controls, create accounts for unauthorised people, or use another person's account. Keep credentials and connected-provider tokens secure, use permissions appropriate to each user's role, and tell Nidus promptly if you suspect unauthorised access or a security incident.
Do not probe, scan, test, interfere with or circumvent the security, availability, rate limits, authentication or operation of Nidus or another user’s data without express written authorisation for a defined security test.
Prohibited content and activity
Do not upload, generate, send, store, process or make available content that is unlawful, fraudulent, threatening, abusive, discriminatory, defamatory, obscene, infringing, deceptive or otherwise harmful. Do not use Nidus to impersonate another person or organisation, facilitate wrongdoing, infringe intellectual-property or privacy rights, or breach confidentiality.
Do not use Nidus to distribute malware, disrupt systems, perform unauthorised penetration testing, mine cryptocurrency, create excessive load, reverse engineer or copy the service except where law cannot exclude that right, or use Nidus to build or train a competing product from the service itself.
Marketing, outreach and payments
When using marketing, outreach, email, forms, audience, consent, suppression, invoicing or payment functions, the customer is responsible for the content, recipients, permissions, notices, consent, opt-outs, suppression lists, records and legal compliance for its communications and collections. The customer must not send spam, misleading messages, unlawful direct marketing, phishing, or communications that breach applicable electronic-marketing, privacy or consumer-protection laws.
The customer must not misuse connected payment services, present false invoices, collect payments without authority, or use Nidus to facilitate a prohibited or unlawful transaction.
AI and automation safeguards
Do not use AI or automation features to make solely automated decisions that have legal or similarly significant effects on people unless the customer has a lawful basis, appropriate safeguards and all required notices and rights processes. Only submit personal data, confidential information or third-party content that you are authorised to process. For providers the customer selects or appoints directly, the customer must assess the provider and transfer arrangements. Nidus remains responsible for assessing and lawfully appointing its own providers and subprocessors under the DPA.
A person with appropriate authority must review AI-assisted output and approve any external communication, financial action, material business decision or other action where error could cause harm.
Enforcement and reporting
Nidus may investigate suspected breaches and take proportionate action under the Service Terms. Where possible, we will describe the concern and allow it to be remedied. Immediate restriction may be necessary to address unlawful use or an urgent risk to people, data or the service.
Report suspected abuse or security issues to [email protected]. Do not include passwords, access tokens or sensitive customer records in your initial report. We will agree an appropriate way to receive any necessary detail.