Draft — pending legal review. This document is a working draft and is not yet in force. Wording, placeholders in square brackets and commitments may change before publication.
Acceptable Use Policy
Last updated
Effective date: [effective date]
1. Scope
This Acceptable Use Policy is part of the Terms of Service and applies to every Customer, to the users of a Workspace, and to anyone who creates documents through a product built on the Service. Where a customer lets its own users generate documents, the customer is responsible for their behaviour.
Documents generated with the Service can be delivered through links that anyone with the address can open, which makes us a hosting service under the Digital Services Act. Sections 4 and 5 explain how to report content and how we respond.
2. Prohibited content and uses
2.1 Deception, impersonation and forgery
- Phishing of any kind, including documents, invoices or notices designed to make recipients reveal credentials, card details or other sensitive information.
- Impersonating a person, company, public authority or brand, including documents that copy the look, logos or letterhead of an organisation you are not authorised to represent.
- Forged or fraudulent documents intended to deceive, such as fake identity documents, passports, driving licences, diplomas, professional certificates, bank statements, pay slips, invoices or receipts.
- Falsifying validation output, for example presenting an invoice as conforming to a standard when it did not pass validation.
Issuing your own certificates, invoices or statements to your own recipients is a normal use of the Service. The rules above concern documents that misrepresent who issued them or what they prove. Clearly marked samples and test data are fine.
2.2 Malware, spam and link abuse
- Distributing malware, exploit code, or documents that link to malicious downloads or credential-harvesting pages.
- Sending or supporting unsolicited bulk messages, or using generated files, signed links or public file links in spam campaigns.
- Using file hosting, signed links or the image CDN as general-purpose file storage or as a download service for content unrelated to documents you generate.
- Sharing or publishing signed-link secrets, or manipulating link parameters to obtain renders you are not entitled to.
2.3 Illegal and harmful content
- Child sexual abuse material. We report it to the competent authorities as required by law and terminate the account immediately.
- Content that is illegal in the EU or in the country the content targets, including terrorist content, unlawful hate speech, incitement to violence and content that infringes intellectual property rights.
- Harassment, threats, doxxing or content created to intimidate a specific person.
- Content that unlawfully invades someone's privacy, including publishing personal data you have no right to publish.
2.4 Sanctions and export control
You may not use the Service if you are subject to EU, UN, UK or US sanctions, on behalf of a sanctioned party, or from a comprehensively sanctioned territory, and you may not use it to breach export control law.
2.5 Sensitive personal data
- Do not process special categories of personal data, such as health, biometric, genetic, religious, political or sexual-orientation data, or data on criminal convictions, unless you have a valid legal basis and appropriate safeguards, and you have configured retention and logging accordingly (see the DPA).
- Do not submit protected health information as defined by HIPAA. We do not offer a business associate agreement, so this data must stay out of the Service until we announce otherwise.
- Do not submit payment card numbers, government identity numbers or credentials in request data that is logged, when a redaction setting or zero-retention mode would avoid it.
2.6 Platform integrity
- Do not circumvent plan limits, quotas, monthly top-up limits or rate limits, for example by creating multiple accounts or workspaces to obtain extra free renders, or by sharing or reselling keys outside your organisation.
- Do not remove or obscure watermarks on test-mode output, and do not use test mode for production documents.
- Do not probe, scan or load-test the Service, attempt to escape the rendering sandbox, or exploit vulnerabilities, unless we have given written permission [through our vulnerability disclosure programme]. Report findings to security@dynamicdocumentapi.com.
- Do not interfere with the Service or other customers, for example through denial-of-service attacks, deliberately abusive templates, or attempts to reach data outside your workspace.
- Do not render URLs you are not authorised to access, bypass access controls or paywalls on third-party sites, or use rendered pages in breach of their terms or applicable law.
3. Your responsibilities
Keep your own acceptable-use rules for the people who use your product, act on complaints you receive, and keep a contact address we can reach. If we ask about suspected abuse in your workspace, respond within [five] business days. You are responsible for the rights in everything you submit, including fonts, images and trademarks, as set out in the Terms.
4. Reporting abuse or illegal content
Report abuse, illegal content or a document that breaches this policy to security@dynamicdocumentapi.com, or through the notice form at [abuse contact address or notice form URL]. Security vulnerabilities also go to security@dynamicdocumentapi.com.
To let us act quickly, a notice should contain:
- the exact address of the file, link or page concerned;
- an explanation of why the content is illegal or breaches this policy;
- your name and e-mail address, except for reports concerning child sexual abuse material or similar offences; and
- a statement that the information in the notice is accurate and complete to the best of your knowledge.
Notices with these elements are treated as giving us actual knowledge of the content. Our single point of contact for authorities and for users is [single point of contact for DSA notices], and notices may be submitted in [languages].
5. How we enforce this policy
We investigate reports without undue delay in a diligent, objective and non-arbitrary way. We also use automated signals to detect certain abuse, such as known child sexual abuse material on publicly reachable file domains and indicators of phishing or malware; anything flagged is reviewed by a person before we act on it.
Depending on the severity, we may:
- ask you to remove or correct the content;
- disable a specific file, link or template;
- restrict a feature, reduce limits or revoke API keys;
- suspend the workspace; or
- terminate the Agreement and, where the law requires, report the case to authorities.
We choose the least intrusive measure that is effective and consider whether the breach was repeated or deliberate.
Statement of reasons. When we restrict content, visibility or access, we inform the affected customer of the decision and the reasons, including what was restricted, the facts we relied on, whether automated means were used to detect the content, the legal or contractual ground, and how to contest the decision.
Complaints and redress. To contest a decision, reply to the notice or write to security@dynamicdocumentapi.com within [30] days with your reasons. We review the case and reply with the outcome. Judicial remedies and, where applicable, out-of-court dispute settlement remain available. We may deprioritise notices from senders who repeatedly submit manifestly unfounded reports.
Preservation and disclosure. We may preserve content and related logs where the law requires it, and we disclose information to authorities only where a valid legal basis exists.
6. Changes
We may update this policy as abuse patterns and the law develop. Material changes are announced as described in section 19 of the Terms. Urgent changes needed to prevent harm or comply with the law can take effect immediately.
Questions about this policy: support@dynamicdocumentapi.com. Reports: security@dynamicdocumentapi.com.