aitonomy← Back to legal

Acceptable Use Policy

Effective 10 September 2026 · Version 1.1


This Acceptable Use Policy (the "AUP") sets out how the Aitonomy platform, the Service and the Services provided by Baby Elephant B.V., trading as Aitonomy ("Aitonomy"), may and may not be used. It forms part of the Agreement. Capitalised terms have the meaning given in the SaaS Terms and Conditions or the Services Terms and Conditions, as applicable.

The AUP supplements the use restrictions already in those Terms (in particular clause 5 of the SaaS Terms). Where the AUP and those clauses overlap, both apply.

1. General restrictions

The Customer, and its Users, will not use the platform, the Service or the Services to:

  1. act unlawfully or fraudulently, or for any purpose that infringes the rights of a third party, including intellectual property, privacy or confidentiality rights;
  2. introduce malicious code, or interfere with or circumvent the security, integrity, governance controls or guardrails of the platform or the Service;
  3. attempt to gain unauthorised access to any system, data or account, or to reverse engineer the platform except where mandatory law permits;
  4. conduct load or penetration testing without Aitonomy's prior written consent;
  5. resell, sublicense or make the Service available to a third party except as agreed in writing; or
  6. use the Service in a way that may damage or impair its availability for others.

2. Fair use and service protection

  1. The Customer uses the Service in line with fair use and the subscribed configuration set out in the Order Form. Aitonomy may apply reasonable rate, concurrency and volume limits, quotas and other technical safeguards to protect the Service and its availability for other customers.
  2. The Customer does not use the Service to extract, download, scrape, mirror or replicate data in bulk, or to build a copy of a connected source, other than through the export mechanism provided for in the Terms.
  3. Where the subscribed configuration provides interactive access to connected sources for Users, the Service is used for interactive use by those Users. It is not used for automated, unattended or high-volume retrieval; workloads of that kind require the configuration intended for them.

3. Data restrictions

  1. The Customer provides only data it is entitled to provide and process for the agreed purpose, and warrants it has the necessary legal basis.
  2. Special categories of personal data (Article 9 GDPR) and criminal-offence data (Article 10 GDPR) are provided only where the Order Form and the Data Processing Agreement expressly provide for them, with the safeguards recorded there. They are never processed in a Scan.
  3. The Customer does not provide data whose processing would breach a duty of confidentiality it owes to a third party, unless it is entitled to do so.

4. AI-specific restrictions

The following also apply:

  1. Human oversight. The Customer does not use an Agent to make a decision producing legal or similarly significant effects on an individual on a solely automated basis without appropriate human oversight. The Customer configures and maintains that oversight for its use, as set out in clause 5 of the SaaS Terms.
  2. Prohibited practices. The Service and the Services are not used for any practice prohibited under Article 5 of Regulation (EU) 2024/1689 (the AI Act), including social scoring, manipulative or exploitative techniques that cause harm, untargeted scraping of facial images to build recognition databases, emotion recognition in the workplace or education except where permitted, and biometric categorisation to infer sensitive characteristics.
  3. High-risk uses. Where a use would qualify as high-risk under the AI Act, the Customer applies the safeguards, documentation and human oversight required for that use before putting it into production, and remains the deployer responsible for its compliance.
  4. Unlawful or harmful content. The Service is not used to generate or distribute unlawful content, content that sexually exploits minors, targeted harassment, or deceptive content presented as authentic where that is unlawful.

5. Customer responsibility and enforcement

  1. The Customer is responsible for ensuring that its Users comply with this AUP.
  2. Where Aitonomy reasonably determines that use breaches this AUP or poses a security or legal risk, it may take proportionate measures, including suspending access, in accordance with clause 5 of the SaaS Terms or the equivalent provision of the Services Terms. Where practicable, Aitonomy gives prior notice and an opportunity to remedy.

6. Changes

Aitonomy may update this AUP. The version in force on the date of the Order Form applies for the duration of that Order Form's then-current term; material changes are notified in advance in the same way as for the SaaS Terms.

Baby Elephant B.V., trading as Aitonomy · Emmastraat 23, 2282 AM Rijswijk, The Netherlands · KvK 27299029

Baby Elephant B.V., trading as Aitonomy  ·  Emmastraat 23, 2282 AM Rijswijk, The Netherlands  ·  KvK 27299029 Version 1.1  ·  [DATE]