Trust Center
Acceptable Use Policy
Last updated: 8 September 2026
Introduction
This Acceptable Use Policy (“AUP”) governs your access to and use of the websites, software, applications, APIs, models, integrations, agents, Outputs, documentation, and related services provided by ASUME B.V. (“ASUME,” “we,” “us,” or “our”) (collectively, the “Service”).
This AUP forms part of the agreement between you and ASUME governing your use of the Service (the “Agreement”). Your obligations under this AUP are in addition to your obligations under the Terms of Service and any applicable Order Form or other agreement with ASUME.
The Service is intended solely for legitimate business and professional use. You are responsible for ensuring that your Users, Administrators, employees, contractors, agents, connected systems, integrations, and other persons acting through your Account or Workspace comply with this AUP.
Capitalised terms not defined in this AUP have the meanings given in the Agreement.
1. Scope and Application
1.1. Permitted Use
You may use the Service only for legitimate business and professional purposes permitted by the Agreement and in compliance with applicable law, this AUP, applicable Order Forms, documented usage limits, and other restrictions applicable to the Service.
1.2. Customer Responsibility
You are responsible for activity conducted through your Accounts, Workspaces, Users, Administrators, API keys, credentials, integrations, connected systems, Customer Data, Customer-Authorised Sources, Customer-Controlled Sources, Outputs, and other Service functionality under your control.
1.3. No Authorisation of Unlawful Conduct
ASUME’s provision of functionality, information, an Output, source access, API capability, integration, model, Agent, or other Service feature does not constitute authorisation to use that functionality in violation of applicable law or third-party rights. ASUME cannot authorise conduct that applicable law prohibits.
1.4. Precedence
If this AUP conflicts with another part of the Agreement concerning acceptable use of the Service, this AUP controls solely with respect to acceptable use unless a written agreement signed by ASUME expressly provides otherwise. The DPA controls with respect to Processor Personal Data to the extent provided in the DPA.
2. Illegal, Harmful, and Abusive Use
2.1. Illegal Activity
You must not use the Service to commit, facilitate, encourage, conceal, or materially support activity that violates applicable law, regulation, court order, sanctions requirement, contractual restriction binding on you, or legally enforceable third-party right.
2.2. Harm to Persons or Organisations
You must not use the Service to harass, threaten, stalk, intimidate, defame, unlawfully discriminate against, exploit, deceive, impersonate, or intentionally cause unlawful harm to a person or organisation.
2.3. Fraud and Deception
You must not use the Service to commit or facilitate fraud, identity theft, phishing, misrepresentation, deceptive commercial practices, fabricated evidence, fraudulent claims, fake endorsements, false source attribution, or other materially deceptive conduct.
2.4. Identity and Authority
You must not misrepresent your identity, organisation, authority, affiliation, ownership of a source, authority to grant access, or the origin or legal status of information provided to ASUME.
2.5. Unlawful Discrimination
You must not use the Service to make, facilitate, or materially support decisions or targeting practices that unlawfully discriminate against persons or protected groups.
3. Security and Service Integrity
3.1. Unauthorised Access
You must not attempt to gain unauthorised access to the Service, another Customer’s Account or Workspace, ASUME systems, data, networks, models, infrastructure, administrative functionality, credentials, or other protected resources.
3.2. Security Controls
You must not bypass, disable, weaken, evade, or interfere with authentication, authorisation, access controls, security controls, monitoring systems, usage restrictions, rate limits, billing mechanisms, plan limits, or other technical restrictions applied by ASUME.
3.3. Vulnerability Testing
You must not probe, scan, test, exploit, or attempt to exploit vulnerabilities in the Service or related infrastructure without ASUME’s prior written authorisation.
3.4. Malicious Code and Interference
You must not introduce malware, ransomware, spyware, viruses, worms, malicious code, destructive instructions, denial-of-service activity, or other functionality designed to damage, disrupt, degrade, compromise, or interfere with the Service, a Customer, a User, or a third-party system.
3.5. Unauthorised Automation
You must not use unauthorised bots, crawlers, scripts, automated clients, agents, or other automated means to access, probe, extract from, interfere with, or abuse the Service. This restriction does not prohibit use of APIs, integrations, agents, automated workflows, or other automation expressly made available or authorised by ASUME.
3.6. Credentials
You must not use stolen, leaked, shared, fraudulently obtained, or otherwise unauthorised credentials, API keys, tokens, accounts, certificates, or authentication mechanisms.
3.7. Protected System Information
You must not attempt to extract or obtain ASUME credentials, secrets, API keys, system prompts, hidden system instructions, model weights, private configurations, security controls, internal reasoning processes, or other non-public system information except to the extent mandatory law expressly permits a particular activity.
3.8. Security Reporting
Suspected vulnerabilities or security incidents relating to ASUME should be reported to security@asume.ai. Security research must not involve accessing, modifying, deleting, retaining, exporting, or disclosing information that the researcher is not authorised to access.
4. Data, Privacy, and Source Access
4.1. Personal Data
You must not submit, connect, obtain, disclose, combine, enrich, profile, export, or otherwise Process Personal Data through the Service in violation of Applicable Data Protection Law or without the rights, authority, lawful basis, notices, permissions, or safeguards required for your Processing.
4.2. Sensitive Personal Data
You must not submit or Process special-category Personal Data, criminal-offence data, children’s data, health data, biometric data, precise location data, government identifiers, payment-card information, or other highly sensitive or specially regulated Personal Data unless expressly permitted by the Agreement, expressly agreed by ASUME where required, and supported by an appropriate lawful basis and safeguards.
4.3. Unlawful Profiling and Surveillance
You must not use the Service for unlawful surveillance, tracking, monitoring, profiling, doxing, stalking, targeting, or enrichment of individuals, or to infer or target individuals based on sensitive characteristics where such Processing is prohibited or otherwise unlawful.
4.4. Re-Identification
You must not intentionally re-identify individuals from anonymous, anonymised, aggregated, or de-identified information unless legally permitted and expressly authorised by the party responsible for that information.
4.5. Customer Data and Confidential Information
You must not upload, connect, disclose, or otherwise make available information that you obtained unlawfully, are not authorised to disclose, is subject to confidentiality obligations you cannot satisfy, or contains third-party trade secrets or other protected confidential information that you are not authorised to Process through ASUME.
4.6. Customer-Authorised Sources
You must not instruct or enable ASUME to access a Customer-Authorised Source unless you are authorised to access that source and to permit ASUME and its authorised service providers to access and Process the relevant information.
4.7. Customer-Controlled Sources
You must not designate, verify, connect, submit, or represent a website, domain, database, API, repository, documentation portal, knowledge base, or other resource as a Customer-Controlled Source unless you own or control that source or otherwise possess sufficient authority to grant the permissions and licences associated with that designation.
4.8. False Source Authority
You must not provide credentials, API keys, access tokens, licences, accounts, permissions, certificates, or other access rights to ASUME that you are not authorised to provide. Deliberately misrepresenting ownership, control, or authority over a source may constitute a material and non-curable breach of the Agreement.
4.9. Public Source Data
You may use Public Source Data and Outputs only in accordance with the Agreement, applicable law, and applicable third-party rights. You must not intentionally use the Service to obtain, reconstruct, expose, or facilitate access to credentials, authentication secrets, protected Personal Data, trade secrets, confidential documents, restricted systems, or other information that you know or reasonably should know was unintentionally exposed, unlawfully obtained, leaked, or not intended to be publicly available.
4.10. Company Inference
Nothing in this AUP prohibits the ordinary use of ASUME to draw evidence-based inferences about companies, business capabilities, needs, constraints, priorities, opportunities, or other company-level characteristics supported by the Service. Such use remains subject to the Agreement, applicable law, third-party rights, and restrictions concerning individuals, confidential information, and unlawful downstream use.
5. AI, Outputs, and High-Impact Uses
5.1. Output Review
ASUME Outputs are intended for business decision support and may contain uncertainty, assumptions, errors, incomplete information, outdated information, or other limitations. You are responsible for reviewing and validating Outputs before material reliance.
5.2. Representation of Outputs
You must not knowingly present an inference, assumption, score, classification, recommendation, or other AI-assisted Output as independently verified fact where it has not been independently verified. You must not materially alter or omit evidence, uncertainty, source information, limitations, or context in a manner that makes an Output misleading.
5.3. False ASUME Endorsement
You must not state or imply that ASUME has independently audited, verified, certified, endorsed, approved, guaranteed, or legally cleared a company, person, recommendation, opportunity, classification, Output, Customer decision, or Customer communication unless ASUME expressly states so in writing.
5.4. Prohibited AI Practices
You must not use the Service to engage in any AI practice prohibited by applicable law. Where the EU Artificial Intelligence Act applies, this includes any practice prohibited under that legislation. ASUME cannot approve or waive a statutory prohibition.
5.5. Prohibited Individual Uses
You must not use the Service for unlawful social scoring, prohibited biometric identification or categorisation, prohibited emotion recognition, unlawful predictive policing, unlawful manipulation or exploitation of vulnerable persons, or other prohibited processing of individuals.
5.6. Restricted High-Impact Uses
Unless ASUME expressly agrees in writing to support the use case and the use is lawful and appropriately safeguarded, you must not use the Service to make or materially support decisions concerning identified individuals relating to employment, recruitment, promotion, termination, worker evaluation, credit, lending, insurance, housing, education, healthcare, access to essential services, public benefits, migration, asylum, border control, law enforcement, criminal justice, or another matter that may produce legal or similarly significant effects on an individual.
5.7. Solely Automated Decisions
You must not use an ASUME Output as the sole or determinative basis for a decision that produces legal or similarly significant effects on an individual unless the relevant use is expressly supported by ASUME, permitted under the Agreement, and compliant with all applicable legal requirements concerning lawful basis, transparency, human oversight, contestability, risk management, and other safeguards.
5.8. Professional Advice
You must not rely on ASUME as a substitute for qualified legal, financial, tax, regulatory, employment, medical, accounting, investment, or other professional advice where professional review is appropriate or legally required.
6. Sales, Marketing, Communications, and External Actions
6.1. Lawful Communications
You must not use the Service to send or facilitate spam, unlawful unsolicited communications, unlawful telemarketing, deceptive outreach, or communications that violate applicable direct-marketing, electronic-communications, privacy, consumer-protection, or anti-spam requirements.
6.2. Business Contact Data
Inclusion of professional or business contact information in the Service does not constitute a representation that you may lawfully contact that person for every purpose. You remain responsible for the lawful basis, notices, objections, consent requirements, suppression requirements, and other obligations applicable to your communications.
6.3. Deceptive Outreach
You must not use the Service to conceal your identity where disclosure is required, misrepresent your reason for contacting a person or organisation, fabricate a relationship, impersonate another person, or make materially false or misleading claims concerning ASUME, a company, product, opportunity, Customer, prospect, or other person.
6.4. Automated Outreach
You must not use ASUME to conduct high-volume or automated communications in a manner that violates applicable law, provider restrictions, documented ASUME limits, or applicable recipient rights.
6.5. Autonomous and External Actions
Where you enable an Agent or other Service functionality to generate, schedule, send, publish, modify, submit, or otherwise take external actions, you are responsible for configuring appropriate permissions, recipients, limits, targeting criteria, review processes, business rules, and safeguards. You must not use such functionality to perform an action that you are not authorised to perform.
6.6. Automated Disclosure
Where applicable law requires disclosure that a person is interacting with an automated or AI system, you are responsible for making that disclosure in connection with Customer-controlled communications or actions unless the Service expressly provides that disclosure on your behalf.
7. Intellectual Property, Competitive Use, and Resale
7.1. ASUME Materials
You must not copy, reproduce, modify, adapt, distribute, sublicense, rent, resell, publish, or otherwise commercially exploit ASUME Materials except as expressly permitted by the Agreement or mandatory law.
7.2. Reverse Engineering
Except to the extent mandatory law expressly permits it, you must not reverse engineer, decompile, disassemble, decode, or attempt to derive the source code, model weights, proprietary prompts, system instructions, algorithms, schemas, taxonomies, scoring logic, evidence structures, inference methods, or other protected technology underlying the Service.
7.3. Model and Product Extraction
You must not perform model extraction, model stealing, prompt extraction, systematic response harvesting, system-instruction extraction, membership-inference attacks, or other activity intended to replicate or derive protected characteristics of ASUME models, systems, datasets, or functionality.
7.4. Competitive Training and Development
You must not use systematic queries, APIs, Outputs, model responses, evaluation results, ASUME Materials, or other Service information to train, fine-tune, distil, imitate, replicate, or materially develop a company-understanding model, intelligence service, inference system, or other product competitive with ASUME, except where ASUME expressly agrees otherwise in writing.
7.5. Benchmarking
You must not publish a benchmark, comparative evaluation, or performance claim concerning ASUME that is materially misleading, omits material methodology or limitations, uses non-representative conditions, discloses ASUME Confidential Information, or cannot reasonably be reproduced. Nothing in this provision prohibits legitimate internal evaluation conducted in compliance with the Agreement.
7.6. Data Resale
You must not engage in Data Resale Activity except where expressly permitted by ASUME in writing. You must not use the Service to create or operate a standalone data broker, enrichment database, company-intelligence database, API, data feed, or other information product substantially consisting of information obtained through the Service.
7.7. Service Bureau and White-Label Use
You must not resell, sublicense, rent, white-label, or provide third parties direct access to the Service as your own product or service unless expressly permitted by ASUME. This restriction does not prohibit authorised Users, contractors, professional advisers, or service providers acting for Customer from using the Service for Customer’s Permitted Purpose in accordance with the Agreement.
8. APIs, Automation, Integrations, and Platform Usage
8.1. Authorised Interfaces
You may access the Service only through interfaces, APIs, integrations, agents, software, and other methods made available or expressly authorised by ASUME.
8.2. Usage Limits
You must comply with applicable rate limits, usage limits, Credits, plan restrictions, concurrency limits, technical specifications, and other documented controls. You must not distribute activity across Accounts, identities, credentials, Workspaces, IP addresses, or other means for the purpose of evading such restrictions.
8.3. Excessive Use
You must not use the Service in a manner that imposes unreasonable load, cost, security risk, degradation, or disruption on ASUME, other Customers, or third-party infrastructure. ASUME may throttle, restrict, queue, or suspend activity that materially exceeds agreed or reasonable usage.
8.4. Integrations
You must not connect a third-party service, API, account, data source, repository, communication system, or other integration unless you possess sufficient authority to make the connection and permit the resulting Processing. You must comply with applicable access permissions and restrictions and discontinue the integration when your authority ends.
8.5. Third-Party Access Restrictions
You must not use an ASUME integration or Customer-supplied access credential to bypass third-party authentication, permissions, account restrictions, contractual access limitations, or API restrictions where you are not authorised to do so.
8.6. Billing and Usage Circumvention
You must not evade or manipulate billing, Credits, usage measurement, plan restrictions, feature restrictions, or other commercial controls.
9. Third-Party Services and Provider Restrictions
9.1. Third-Party Services
Certain Service functionality may depend on third-party model providers, search services, retrieval providers, cloud providers, APIs, integrations, or other Third-Party Services.
9.2. Provider Requirements
Where a Third-Party Service requires particular usage restrictions to apply to users of that service, you must comply with those restrictions to the extent they are identified in the Service, Documentation, applicable Order Form, or otherwise reasonably communicated by ASUME.
9.3. Provider Enforcement
ASUME may restrict, suspend, replace, or disable access to a particular model, provider, feature, source, or integration where your use would violate applicable provider restrictions, threaten ASUME’s access to the provider, or otherwise create material legal, security, contractual, or operational risk.
9.4. No General Incorporation of Undisclosed Terms
Nothing in this Section makes undisclosed third-party terms binding on you merely because ASUME uses that third party. Where compliance with a provider-specific restriction is required from Customer, ASUME will identify or reasonably communicate the relevant restriction.
10. Sanctions and Restricted Uses
10.1. Sanctions and Export Controls
You must not access or use the Service in violation of applicable sanctions, export-control laws, trade restrictions, embargoes, or prohibited-end-use requirements.
10.2. Restricted Parties
You must not use the Service for or on behalf of a person or entity prohibited from receiving the Service under applicable sanctions or export-control law.
10.3. Restricted End Uses
You must not use the Service for prohibited weapons activity, unlawful military or intelligence activity, malicious cyber operations, unlawful surveillance, sanctions evasion, or other end uses prohibited by applicable law.
10.4. Geographic Restrictions
ASUME may restrict or disable access to the Service in jurisdictions where provision or use of the Service would create material legal, regulatory, security, sanctions, or export-control risk.
11. Enforcement
11.1. Investigation
ASUME may investigate suspected violations of this AUP and may use automated and manual controls to identify abuse, security threats, circumvention, prohibited use, or other activity presenting material legal, security, privacy, operational, contractual, or reputational risk.
11.2. Remedial Measures
If ASUME reasonably believes that you, your Users, or your organisation have violated this AUP, ASUME may request information or remediation, issue a warning, remove or restrict affected content or functionality, throttle usage, disable an integration or API key, restrict access to a model or provider, suspend access, terminate an Account or Agreement, preserve relevant records, or take other reasonable measures permitted by the Agreement and applicable law.
11.3. Immediate Action
ASUME may act immediately and without prior notice where reasonably necessary to prevent or limit material harm, unlawful activity, security compromise, infringement, fraud, regulatory risk, continued abuse, loss of access to a critical provider, or other urgent risk.
11.4. Serious Violations
Deliberate security attacks, credential abuse, deliberate misrepresentation of ownership or authority over a Customer-Controlled Source, systematic model extraction, material unlawful use, unauthorised Data Resale Activity, fraud, or deliberate circumvention of a prior suspension or restriction may be treated as material and non-curable breaches.
11.5. Notifications
ASUME may notify affected Customers, Users, third-party providers, rights holders, Data Subjects, regulators, authorities, or other appropriate recipients where required by law or reasonably necessary to address unlawful activity, security threats, infringement, fraud, or material harm.
11.6. No Waiver
ASUME’s decision not to enforce a provision in one instance does not waive ASUME’s right to enforce that provision or another provision later.
12. Changes and Contact
12.1. Updates
ASUME may update this AUP to reflect changes in law, regulation, technology, Service functionality, security risks, misuse patterns, provider requirements, or ASUME’s policies.
12.2. Material Changes
ASUME will provide notice of material changes in accordance with the Agreement where required or reasonably appropriate. Changes may become effective earlier where reasonably necessary to address law, security, provider restrictions, abuse, or other urgent circumstances.
12.3. Contact
Questions concerning this AUP or reports of suspected misuse may be sent to legal@asume.ai.
Security vulnerabilities, suspected Account compromise, or other security issues should be sent to security@asume.ai.
Full company and contact information for ASUME B.V. is available in our Legal Notice.