A SERIOUS OR DELIBERATE BREACH MAY RESULT IN IMMEDIATE REFUSAL, RESTRICTION, SUSPENSION OR TERMINATION AND MAY BE REPORTED TO A PAYMENT PROVIDER, PLATFORM, REGULATOR OR LAW-ENFORCEMENT BODY WHERE LAWFUL AND APPROPRIATE.
Lawful and authorised use
The website, accounts, Digital Products and Services may be used only for lawful, authorised purposes and in accordance with the contract, documentation, usage limits and this Policy.
A Customer is responsible for the acts and omissions of persons using its accounts, credentials, Deliverables or systems with its authority.
Fraud and deceptive conduct
- (a)
fraud, scams, impersonation, phishing, account takeover or deceptive payment activity;
- (b)
fabricated identities, documents, reviews, testimonials, traffic, engagement or business claims;
- (c)
counterfeit goods, misleading offers, unauthorised resale or misrepresentation of origin; and
- (d)
attempts to evade verification, sanctions, payment-provider controls, platform rules or lawful restrictions.
Security abuse
- (a)
malware, ransomware, spyware, credential theft, botnets or malicious code;
- (b)
unauthorised access, privilege escalation, credential stuffing, password spraying or circumvention of controls;
- (c)
denial-of-service activity, destructive testing, load generation or interference with availability;
- (d)
unauthorised scanning, scraping, bulk extraction, reverse engineering or automated access beyond documented limits; and
- (e)
use of our Services to attack, compromise, monitor or disrupt another person, account, device, network or service.
Harmful and unlawful content
- (a)
content involving exploitation, threats, stalking, harassment, unlawful hate or incitement;
- (b)
child sexual abuse material, sexual exploitation or non-consensual intimate material;
- (c)
content that unlawfully defames, deceives, discriminates against or invades the rights of another person;
- (d)
instructions or materials intended to facilitate serious crime, fraud or harmful cyber activity; and
- (e)
content prohibited by law, a competent authority or a lawfully applicable payment or platform rule.
Intellectual property, privacy and confidentiality
A user must not upload, request, publish, distribute or exploit material that infringes copyright, trademark, patent, database rights, confidentiality, privacy, publicity or another third-party right.
A user must not provide personal data without a lawful basis, required transparency and appropriate authority, or request surveillance, profiling or monitoring that is unlawful or disproportionate.
Restricted business activities
A Customer must not use our Services for an unlawful or prohibited business model, sanctions evasion, illegal gambling, unlicensed regulated financial activity, unlawful weapons, controlled substances, counterfeit trade, prohibited surveillance or another activity that creates material legal or payment risk.
We may request evidence of licences, regulatory status, consents, rights, source of funds, lawful purpose or platform approval before accepting or continuing work.
Resource limits and technical controls
Users must comply with user, device, domain, environment, storage, bandwidth, API, processing, rate, licence and geographic limits stated in the Order or documentation.
A user must not bypass metering, licence checks, rate limits, access restrictions or technical safeguards.
Requested development or support work
A Customer must not instruct us to build, configure, host, automate or support a system intended for unlawful access, fraud, evasion, exploitation, prohibited surveillance, infringement or another prohibited purpose.
We may decline a feature, integration, content category or deployment route that in our reasonable view creates unacceptable legal, security, payment or reputational risk.
Security testing
Testing our systems requires prior written authorisation unless it is expressly permitted by the Security Vulnerability Disclosure Policy.
Social engineering, physical intrusion, denial of service, destructive testing and access to another person's data are never authorised by the mere existence of a public website or disclosure channel.
Monitoring and investigation
We may use proportionate technical and manual controls to detect fraud, abuse, security incidents, policy violations and excessive resource use.
Where a suspected breach is investigated, we may preserve relevant account, transaction, access, content and communications records in accordance with the Privacy Notice and applicable law.
Enforcement
We may refuse an Order, remove or restrict content, block a transaction, limit features, suspend access, terminate an account or require remedial action where this Policy is breached or a serious risk arises.
Where practical and safe, we will give notice and an opportunity to remedy. Immediate action may be taken for serious, deliberate, fraudulent, illegal or security-critical conduct.
Disclosure and reporting
We may disclose relevant records to a hosting provider, payment provider, platform, insurer, regulator, court or law-enforcement body where required by law or reasonably necessary and lawful to protect rights, users, systems or the public.
Reporting abuse
Suspected abuse should be reported to security@involvecsolutions.com or support@involvecsolutions.com with the relevant account, URL, dates, evidence and risk. Unnecessary sensitive information should not be included.