Acceptable Use Policy
What you may and may not do with the DashAPI platform, its data, and its AI features.
Effective: August 1, 2026 | Last updated: August 1, 2026
support@dashapi.ai1. Scope
This Acceptable Use Policy (Policy) applies to everyone who uses the DashAPI platform, including account holders, users invited to an organisation, and any system acting under an API token you issue. It forms part of our Terms of Service; capitalised terms have the meaning given there.
You are responsible for the conduct of everyone you invite to your organisation and for anything done with credentials or tokens issued under your account.
2. The short version
- Only put data into the platform that you have the right to hold and process.
- Do not use the platform to harm, deceive, harass or unlawfully surveil anyone.
- Do not attack, probe or overload the platform, and do not try to reach another tenant's data.
- Review AI output before you act on it or send it to anyone.
- Send only messages the recipient has a lawful basis to receive, and honour every opt-out.
- Keep credentials, tokens and integration permissions tight and current.
3. Lawful use of data
The platform holds data about real people. Before you ingest, enrich or analyse it, you must have a lawful basis and have given any notice the law requires. Specifically, you must not:
- upload personal data you obtained unlawfully, or in breach of another provider's terms;
- ingest special-category data — health, biometric, genetic, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life or sexual orientation — unless a written agreement with us covers it and you have met the additional legal requirements;
- upload government identifiers, payment card numbers, or credentials belonging to others;
- record or transcribe a call, meeting or conversation without the consent of every participant where the law requires it — many jurisdictions require all-party consent, and obtaining it is your responsibility;
- use the platform to build or sell a data product from personal data you do not have the right to redistribute, including Enrichment Output;
- ignore a valid access, correction, deletion or objection request from an individual whose data you hold; or
- combine data in a way that reveals sensitive characteristics an individual has not agreed to disclose.
Where we act as your processor, our Data Processing Addendum sets out how we support you in meeting these obligations.
4. Prohibited content and conduct
Do not use the platform to create, store, send or process content that:
- is unlawful, defamatory, obscene, or promotes violence, discrimination or self-harm;
- harasses, threatens, stalks or intimidates any person;
- infringes intellectual property, privacy, publicity or confidentiality rights;
- impersonates a person or organisation, or misrepresents your affiliation or authority;
- facilitates fraud, phishing, money laundering, or the sale of illegal goods or services;
- constitutes unlawful surveillance, tracking or profiling of individuals; or
- is designed to manipulate an election, a market, or a legal or regulatory process.
5. Platform and security restrictions
You must not, and must not permit anyone else to:
- attempt to access another organisation's data, or any account, system or network without authorisation;
- probe, scan or test the vulnerability of the platform except under clause 12 of this Policy;
- circumvent authentication, tenant scoping, permissions, rate limits or usage allowances;
- reverse engineer, decompile or disassemble the platform, or attempt to extract its source code, models, prompts or system instructions;
- copy the platform's features to build a competing product, or run competitive benchmarking without our written consent;
- scrape or data mine the platform outside the documented API, or use bots or headless browsers against the web interface;
- introduce malware, or send content designed to disrupt or damage any system; or
- resell, sublicense or provide the platform as a service to third parties unless your agreement with us permits it.
6. Responsible use of AI features
AI output is probabilistic and can be confidently wrong. Treat it as decision support, never as an authoritative record. You must:
- review AI-generated content before sending it to a customer, publishing it, or acting on it;
- keep a human in the loop for any decision with legal, financial, employment, safety or health consequences for a person;
- disclose AI involvement where the law or your own obligations require it;
- scope agents narrowly — grant only the tools, data and permissions each agent actually needs; and
- monitor automated workflows you enable, and stop them if they behave unexpectedly.
You must not use AI features to:
- generate content intended to deceive a person about who or what they are dealing with;
- produce material that impersonates a real individual without their consent;
- score, rank or filter individuals for employment, credit, housing, insurance or similar decisions without independent human review and compliance with the laws that govern those decisions;
- attempt to extract training data, model weights, prompts or provider credentials; or
- bypass safety controls in an underlying model, or use the platform to attack a model provider.
7. Outbound communications
When you send email, campaigns, booking notifications or other messages through the platform, you are the sender and you are responsible for compliance with CAN-SPAM, CASL, the GDPR and ePrivacy rules, UK PECR, the TCPA and Do-Not-Call rules where telephone or SMS is involved, and any equivalent law that applies to your recipients. You must:
- have consent or another lawful basis for each recipient;
- identify yourself accurately, and never falsify headers, sender identity or the origin of a message;
- include a working unsubscribe mechanism where one is required, and process opt-outs promptly;
- maintain suppression lists and honour them across campaigns; and
- keep complaint and bounce rates within accepted industry norms.
We may throttle or disable sending immediately where sending patterns are abnormal, complaint rates are high, a delivery provider requires it, or we reasonably suspect a breach of this clause.
8. API, tokens and connectors
- Use the documented API and respect published rate limits; do not distribute load across accounts to evade them.
- Issue tokens with the narrowest scope that works, rotate them regularly, and revoke tokens you no longer use.
- Never embed a token in client-side code, a public repository, or a shared document.
- Grant connectors and external AI clients only the scopes required for the feature you want.
- Tell us immediately at support@dashapi.ai if a token or connected account may be compromised.
9. Fair use and capacity
Plans include usage allowances for storage, records, AI operations, messages and API calls. Use that places a disproportionate load on shared infrastructure, degrades service for other customers, or materially exceeds your allowance may be throttled, and we may ask you to move to a plan that fits. We will contact you before taking action unless the load is causing immediate harm.
10. Responsibilities of administrators
If you administer an organisation on the platform, you are responsible for:
- granting the least privilege each member needs, and removing access promptly when someone leaves;
- configuring workspace, team and client scoping so data reaches only those who should see it;
- telling your members that administrators can access their workspace data and usage analytics;
- setting retention appropriate to the data you hold; and
- responding to requests from individuals whose data your organisation controls.
11. Enforcement
We investigate suspected breaches of this Policy. Depending on severity we may warn you, throttle or disable a feature, suspend an account or organisation, remove content, or terminate under the Terms of Service. We may act immediately and without prior notice where there is a risk to security, to other customers, to third parties, or of continuing unlawful conduct, and we may report unlawful activity to the appropriate authorities.
We will tell you the reason for an enforcement action unless we are legally prohibited from doing so or doing so would compromise an investigation. Suspension does not relieve you of your obligation to pay Fees accrued.
12. Reporting abuse or vulnerabilities
Report abuse, suspected compromise, or a security vulnerability tosupport@dashapi.ai. Include enough detail to reproduce or verify the issue. Our Security Overview describes what we ask of researchers and what you can expect from us. Do not access, modify or exfiltrate data that is not yours while testing, and do not run denial-of-service tests.
13. Changes to this policy
We may update this Policy as the platform, the threat landscape and the law evolve. Material changes will be announced with a new "last updated" date and, where they meaningfully restrict how you may use the platform, at least 14 days' notice by email or in-product notice.
Other legal documents
- Terms of ServiceThe contract for using the DashAPI platform.
- Privacy PolicyWhat we collect, why, and the rights you have.
- Data Processing AddendumGDPR/UK GDPR terms for customer personal data.
- Sub-processorsThird parties that process data on our behalf.
- Security OverviewHow we protect data, and how to report a flaw.
- Cookie PolicyCookies and similar technologies on our sites.
- Website Terms of UseRules for browsing dashapi.ai itself.