2. Account responsibility
- Accounts are personal and not shareable.
- The user is responsible for all activity under their account.
- Suspected access must be reported immediately.
3. Human use and automation boundaries
- The service is designed for authorised human use, not automated extraction.
- Scripts or bots must not simulate human use inside the interface.
- Permitted automation runs through approved APIs and within their limits.
4. API rules
- Respect published rate and volume limits.
- Do not share access keys or store them in insecure environments.
- Do not use the API to bypass permissions, credit limits or plan restrictions.
- Use the API only for agreed purposes.
5. Scraping restrictions
- Scraping or automated copying of platform content or search results is prohibited.
- Bulk extraction without a permitting API agreement is prohibited.
- Republishing content or outputs as a competing service is prohibited.
6. Data export restrictions
- Export is limited to data the user is authorised to access.
- Export is subject to organisation controls and permission limits.
- Circumventing export controls or content protection is prohibited.
7. AI abuse restrictions
- Do not submit passwords, secrets or API keys.
- Do not submit personal data the user is not authorised to process.
- Do not use outputs to produce unlawful, misleading or harmful content.
- Do not use the service or its outputs to train competing models without written permission.
8. Connector credential restrictions
- Connect only accounts and systems the customer is authorised to connect.
- Prefer service accounts with least privilege.
- Never upload credentials inside files or conversations.
- Notify DATA if a connector credential may have been exposed.
9. Security testing rules
- No security testing or intrusion attempts without prior written authorisation and an agreed scope.
- Report discovered vulnerabilities to the security contact without exploiting or publishing them.
- No load or performance testing against production without prior coordination.
10. Suspension and enforcement
- Detection through monitoring, reports or audit logs.
- Restriction or suspension of access where there is a security risk or a clear violation.
- Notification of the organisation admin, unless a security or legal reason prevents it.
- Remediation and restoration of access once the cause is removed.
- Termination under the agreement for serious or repeated violations.
11. Appeal and contact
An organisation admin may appeal any suspension or restriction by contacting DATA at info@data.sa. Appeals are reviewed and answered under the approved operational policy.
Version history
- 1.014 August 2025Approved for publication.
