Skip to content

Last Updated: 1 October 2026

Acceptable Use Policy (AUP)

Overview

This Policy sets the boundaries for lawful, secure and fair use of Ductio. It protects customer information, professional intelligence, individuals and service availability while permitting the legitimate business uses purchased in an Order. Sections 1 to 12 are the proposed public policy. 

1 Application and interpretation

1.1 This Acceptable Use Policy applies to DUCTIO LTD’s executive intelligence Services where the accepted Order or Customer Terms incorporates its identified version. It covers paid subscriptions, trials and enabled AI, integration, API and Voice functions. Permitted purposes include executive search, succession, leadership and board assessment, workforce planning and investment due diligence only within the purchased scope. Defined terms follow the Customer Terms and incorporated Data and Intelligence Licence Schedule.

1.2 The Customer must ensure its Authorised Users comply with this Policy and take reasonable steps to prevent misuse through accounts and integrations under its control. This does not make the Customer responsible for a breach caused by Ductio’s own failure to meet its contractual security obligations.

1.3 Mandatory international-transfer clauses prevail for their subject matter, followed by the DPA for personal-data processing and expressly agreed lawful Order variations identifying the provision varied. Product Specific Terms govern service-specific matters; the Product and Usage Schedule governs measurement and entitlements; the Data and Intelligence Licence Schedule governs licensed use and distribution; this Policy governs acceptable use and proportionate enforcement. The Customer Terms govern remaining commercial matters, including liability and termination. This Policy creates no additional payment, indemnity, liability or Customer Content ownership rights. Internal policies and privacy notices do not become customer warranties merely by being listed.

1.4 Each party must comply with law applicable to its actual role and activity, including UK GDPR and the Data Protection Act 2018 as amended, including the Data (Use and Access) Act 2025 to the extent in force; EU GDPR where applicable; the Equality Act 2010 and applicable EU and national equality law; applicable electronic-communications, copyright, database-right and computer-misuse law; and Regulation (EU) 2024/1689 on artificial intelligence as amended, to the extent applicable and in force. Contractual permission is neither a lawful basis nor regulatory approval.

2 Accounts credentials and seats

2.1 Each account and seat is for one named Authorised User. Do not share logins, passwords, authentication codes or session tokens, allow another person to act through your identity, or rotate one seat among several active users. Permitted reassignment requires removing the previous user’s access and does not restore consumed allowances.

2.2 Give accurate registration and eligibility information. Do not impersonate another person or organisation, misrepresent authority, sell account access, or permit unlicensed affiliates, clients or contractors to access the platform. Client recipients of permitted reports do not acquire platform access rights.

2.3 Use the security controls required by the Agreement, protect credentials and integration secrets, and revoke access when it is no longer authorised. Approved service accounts or API credentials must use the agreed technical mechanism and scope; they are not a means of sharing named-user access. Notify Ductio promptly of suspected compromise through the support route in section 11.

3 Scraping and bulk extraction

3.1 Do not scrape, crawl, harvest or systematically collect Ductio Intelligence through bots, scripts, browser automation, headless browsers, screen capture, OCR, manual repetition or coordinated users. A method is prohibited where its purpose or effect is to collect intelligence beyond the permitted assignment and authorised export scope, even if each individual request appears within a technical limit.

3.2 Automated access is permitted only through an expressly enabled API, integration or other method authorised in writing by Ductio, within its agreed purpose, permissions and limits. Do not access undocumented endpoints, enumerate record identifiers, intercept hidden responses, bypass download restrictions, or use third-party extraction tools to obtain information unavailable through your authorised service.

3.3 An authorised export remains subject to the Order, Product and Usage Schedule, Data and Intelligence Licence Schedule and material Source Conditions disclosed before supply. An allowance specifies quantity, not broader extraction rights. Ordinary browsing, accessibility tools and expressly permitted report or record exports remain allowed. Approved API, bulk and resale rights must each be expressly granted; an API is a delivery channel, not an automatic bulk licence. This Policy does not prohibit systematic delivery within a separately agreed lawful bulk licence.

4 Database reconstruction and unauthorised reuse

4.1 Unless an express separate licence grants the relevant rights, do not reconstruct all or a substantial part of Ductio’s or a source provider’s intelligence database, build a substitute directory or data service, or systematically combine repeated smaller extracts to achieve that result. This includes accumulation across Projects, accounts, workspaces, trials, users and usage periods. Do not use shortlists, screenshots or report files to disguise database delivery.

4.2 Standalone dataset supply, resale, sublicensing, recurring feeds, embedding intelligence in another commercial product, public distribution and substitute intelligence services require express written rights and applicable source permissions. Shared or general-purpose model training, fine-tuning, evaluation or a shared retrieval corpus also requires express permission. Secure external analysis solely for a permitted Assignment must be authorised in the licence record, with confidentiality, provider access, retention and training restrictions. Nothing restricts lawful independently sourced information, independent development, good-faith validation of Assignment results or mandatory legal rights.

4.3 Legitimate paid search, advisory and investment diligence work is permitted within the purchased scope. You may supply proportionate Assignment Reports, shortlists and permitted profile extracts to the identified Commissioning Client and its necessary personnel and professional advisers under the Data and Intelligence Licence Schedule. Before voluntary sharing, bind recipients in writing to the Assignment purpose, confidentiality, lawful retention, correction and deletion, and restrictions on onward distribution, reconstruction and resale. Keep reasonable delivery records and take reasonable steps to remedy known misuse. Charging for that professional Assignment is permitted. Longlists, white-label delivery, guest access and client portals require their recorded permissions; a footer alone does not replace binding recipient terms.

4.4 Preserve required source notices, provenance, assessment dates, confidence information and limitations, and distinguish Customer edits from Ductio analysis. The surviving Report licence permits only the scope specified in the Data and Intelligence Licence Schedule, including completion of the same Assignment and necessary audit, legal or professional records. It does not permit a new vacancy, different client, fresh research or unrelated reuse. Apply justified retention and correction controls; historical results must not be presented as current. Unused raw exports and API caches outside the surviving licence must leave active systems within the period in the accepted licence, normally 30 days. Hosted Customer Content return and deletion remain separate. Lawful rights disclosures, evidence preservation and mandatory legal exceptions remain permitted.

4.5 Source Conditions materially restricting use must be disclosed before affected supply. Unknown supplier terms do not create undisclosed Customer obligations. Necessary corrections and legal restrictions may affect supplied material under the Agreement, but an upstream commercial change does not automatically revoke every lawfully retained Report. Material loss of purchased rights, replacement options and applicable refunds follow the Customer Terms and Licence Schedule.

5 Allowances and fair service use

5.1 Do not bypass seat, Project, AI Run, storage, export, API, trial or Voice allowances, spending caps, rate controls or other agreed restrictions. Prohibited conduct includes creating duplicate accounts or trials, disguising separate assignments as one Project, cycling seats, splitting requests across identities, manipulating usage records or exploiting metering errors to obtain unpurchased service.

5.2 Do not deliberately generate excessive requests, repeated pointless executions, unusually large batches or other traffic intended to disrupt the Services or exhaust resources. Use storage for material relevant to the enabled Services, not as a general file repository. Report a discovered metering or access-control defect rather than exploit it.

5.3 Reaching an allowance, legitimately refining an Assignment or disputing metering is not itself misuse. The Product and Usage Schedule governs counting, reset periods, failure restoration and approved additions. A Ductio workflow failure producing no usable result is handled under that Schedule, not treated as abuse merely because a retry is needed. Trial exports and paid-client delivery require their recorded permissions. This Policy creates no undisclosed quotas, automatic upgrades, penalty or unapproved overage; technical controls must protect service stability without silently reducing purchased entitlement.

6 Lawful profiling privacy and confidentiality

6.1 Use personal information only for a lawful, specified and proportionate purchased purpose. Establish the required lawful basis, Articles 13 or 14 information, permissions, retention and rights processes and complete required impact assessments. Public availability, licensed supply or a contract with an employer does not itself establish a lawful basis for processing a candidate’s information. Document any claimed transparency exception. Customer uploads and customer-specific analysis remain within the DPA where Ductio acts as processor; independently sourced intelligence and onward distribution may involve separate controller duties.

6.2 Do not use the Services for unlawful surveillance, stalking, doxxing, intimidation, persecution, identity theft, exposing confidential personal details, or creating or sharing blacklists for an unlawful purpose. Do not combine datasets to evade an individual’s rights, identify people from anonymous information without lawful authority, or continue using information after a legally valid restriction or withdrawal has been communicated.

6.3 Do not infer or use special category information, criminal-offence information or sensitive personal circumstances for an unlawful purpose. Such data may be processed only where the enabled service expressly permits it and the required legal conditions, safeguards and documented arrangements are in place. A professional biography or association is not reliable proof of health, beliefs, political opinions or another sensitive attribute.

6.4 Do not upload or connect material without source rights and authority, including stolen data, unlawfully obtained CVs, confidential third-party material or access secrets. Minimise submitted information. Customer Personal Data must not be sold, shared with unrelated customers, used for shared-model training or converted into a shared intelligence database under this Policy. Ductio’s separately licensed independent intelligence business and Privacy Policy do not authorise such repurposing.

6.5 Apply valid correction, restriction, deletion and suppression notices to affected active copies and communicate them to known recipients where required. Preserve necessary historical evidence only where lawfully justified, clearly marked and excluded from operational reuse. Do not retaliate against an individual for exercising rights or avoid restrictions by reimporting a removed record.

6.6 Assess restricted international transfers, including relevant remote access, before onward sharing or connecting an external tool. Record actual roles, destinations and applicable safeguards. The processor DPA does not automatically authorise controller-to-controller disclosures or cover every client recipient.

7 Discrimination and consequential decisions

7.1 Do not use the Services to discriminate unlawfully in recruitment, selection, remuneration, promotion, dismissal, investment-related people decisions or access to opportunities. Do not use protected characteristics, sensitive attributes or proxies for them to produce unlawful exclusion or disadvantage. Lawful equality monitoring, reasonable adjustments and legally permitted positive action require their own valid basis and safeguards; they are not blanket permission for preferential or adverse treatment.

7.2 Use relevant professional criteria and examine identity matches, evidence, uncertainty, bias and inappropriate proxies. Do not invent evidence or present an AI score, inferred link, adverse media mention or generated allegation as a verified fact. Verify material findings before consequential use and offer required correction and challenge routes. Do not infer honesty, emotional stability, health, political beliefs or other sensitive traits from unsupported career, language, association or communications signals.

7.3 The standard Services provide decision support. Do not make final hiring, rejection, promotion, dismissal or other legally or similarly significant decisions solely by automated processing, including automatic exclusion before a reviewer considers the candidate. A competent reviewer must meaningfully assess relevant evidence before the decision takes effect and have authority to change it. Rubber-stamping is insufficient. This is a contractual restriction for the standard product, not a claim that every automated decision is unlawful. A separately proposed automated-decision service requires agreed lawful scope and safeguards before deployment.

7.4 Do not use the Services for prohibited AI practices under applicable law, including prohibited social scoring, harmful manipulation, unlawful sensitive-trait biometric categorisation or prohibited workplace emotion recognition. Ordinary professional performance analysis must remain relevant, proportionate and lawful; an unrelated social or behavioural score is not justified by labelling it executive intelligence. Ductio’s standard service does not authorise emotion recognition from biometric signals in workplace interviews or recordings.

7.5 Follow lawful intended-use instructions and fulfil AI obligations applicable to the actual provider, deployer or other role. Assign competent oversight, maintain required records and report material concerns. Human review does not itself remove an EU AI Act high-risk classification. Review a changed intended use or substantial modification before deployment; customer terms do not settle classification or transfer Ductio’s statutory responsibilities to the Customer.

7.6 The standard commercial platform is not an approved environment for classified information, government secrets, security-cleared workloads or mobilisation and targeting operations. Lawful defence, national-security and resilience research requires express purchased scope. Do not infer military status, beliefs or security clearance from uncertain professional associations. Specialised public-sector or regulated deployments require separate authority, intended-use review, source rights and safeguards before activation.

8 Security malicious content and interference

8.1 Do not upload or transmit malware, ransomware, malicious macros, phishing content or code intended to damage systems, steal information or compromise another account. Do not submit content or prompts designed to make an AI workflow reveal another customer’s information, disclose protected system instructions, execute unauthorised actions or defeat security safeguards.

8.2 Do not attempt unauthorised access, privilege escalation, credential attacks, tenant-boundary bypass, denial of service or interference with availability, integrity, logging or security controls. Do not conceal malicious traffic or exploit a known vulnerability. Security or load testing requires prior written agreement on scope and safeguards.

8.3 Do not reverse engineer protected components or extract proprietary model parameters, source code or confidential scoring logic except where expressly permitted or a mandatory legal right applies. Asking for available explanations of an Output, reporting an error or making a lawful rights request is permitted.

8.4 If you encounter a vulnerability or unintended access, stop the affected activity, avoid collecting further information and report sufficient details securely through section 11. Preserve only the minimum evidence necessary for the report and do not publicly disclose personal data or exploit instructions while the issue is investigated.

9 Integrations communications and Voice

9.1 Connect only authorised accounts, systems and data, with permissions within the agreed scope and applicable provider terms. Do not use integrations or agents to evade source restrictions, scrape another service unlawfully, send unlawful communications or act beyond approved recipients and authority. Business contact details do not give blanket marketing permission. Observe UK PECR and applicable EU and national rules, distinguish corporate and individual subscribers where relevant, identify the sender and honour applicable objections, opt-outs and suppression records. Lawful unsolicited business communications are not automatically prohibited.

9.2 Do not use Voice for harassment, fraud, unlawful marketing, deceptive caller identification, unlawful recording or transcription, or prohibited premium-rate or traffic-pumping activity. Provide required participant information and obtain consent where required. Do not activate recording, transcription, forwarding or other chargeable functions for another user without authority.

9.3 Voice and other chargeable functions remain off until an authorised user expressly enables the agreed function and accepts its activation record. Calling, recording, transcription and forwarding are separate permissions; one does not enable the others. Apply the agreed allowances and spending caps, participant transparency and retention controls. Do not bypass them or assume a stored payment method authorises additional charges. Voice is not an emergency-calling service.

10 Proportionate enforcement

10.1 Ductio may investigate credible indications of breach using proportionate security and usage records and only necessary, lawful content access. Limit access to authorised personnel, preserve confidentiality and apply the DPA and Privacy Policy. Do not repurpose investigation material for marketing or model training. Unusual usage alone is not conclusive; consider legitimate explanations, approved bulk rights, accidental errors and disputed metering. An allegation alone does not establish a proven breach.

10.2 Ductio will select action proportionate to the evidence, seriousness, intent, recurrence, harm and risk. Where appropriate, it will explain the concern, request clarification, warn the Customer and allow a reasonable opportunity to correct it. Measures may include revoking compromised credentials, blocking a harmful request, quarantining a malicious upload, restricting an export or integration, or temporarily suspending affected users or functions.

10.3 Immediate protective action without advance notice is permitted where reasonably necessary to contain a credible security threat, prevent serious harm, stop unlawful activity or comply with a binding legal requirement. Ductio will give notice and reasons as soon as reasonably practicable unless law or a substantiated security need prevents disclosure. Restrictions must be confined to affected access where practicable and reviewed while they remain in force.

10.4 Ductio may request relevant information and reasonable corrective measures, such as revoking access, removing prohibited material, securing compromised accounts or stopping unauthorised distribution. Removal of unlawful or malicious content must be necessary and proportionate. Ductio will preserve relevant evidence only for a justified period and will not demand unrelated confidential records or unrestricted access to the Customer’s systems.

10.5 Termination follows the accepted Customer Terms. Under Customer Terms v0.2, a remediable material breach requires written notice specifying the breach and a 30-day cure period; the period in the actually accepted terms controls. An irremediable material breach permits immediate termination only on an applicable contractual ground. A suspension may protect against continuing harm during a cure period but must remain necessary and proportionate. Minor or inadvertent misuse does not automatically justify whole-subscription termination or cancellation of every surviving Report licence.

10.6 Restore affected access promptly when restriction grounds are resolved and correct mistaken restrictions. The Customer may request review through section 11, submit evidence and propose remediation. A responsible reviewer will reconsider reasons, scope and resolution, separately from the initial decision-maker where practicable. Acknowledge a review request normally within five UK business days and provide an outcome or reasoned progress update normally within ten UK business days of receiving necessary information. If more time is reasonably needed, explain why and give the next update date. Consider urgent risks promptly. Review does not delay statutory rights or urgent court relief.

10.7 Suspension does not defeat contractual return of Customer Content or processor-held personal data. Provide a safe limited return route where full access presents risk; exhaustion of commercial export allowances does not block a contractual data return. Retention and deletion follow the DPA and Customer Terms. Lawfully delivered Reports retain the surviving licence unless it is ended for affected material on a valid contractual ground. Necessary legal evidence remains protected. Refunds, fees, liability and loss claims follow the Agreement and law; no automatic fine, forfeiture, punitive licence fee, retrospective charge or double recovery is created.

10.8 Ductio may make a legally required disclosure or a lawful, necessary and proportionate report to a relevant authority or affected provider. Any disclosure must respect confidentiality and data protection, be limited to what is justified, and be notified to the Customer where lawful and practicable. Suspected misuse does not authorise unrestricted sharing of Customer Content.

11 Reporting and review requests

11.1 Report suspected misuse, compromised credentials, vulnerabilities or enforcement concerns through the support or contact route at https://www.ductio.co.uk or the contractual contact identified in your Order. Formal notices follow the Customer Terms. Individual privacy requests follow the Privacy Policy.

11.2 Include the affected account or workspace, relevant request or Project identifiers, approximate time and a concise description where available. Do not send passwords, authentication tokens or unnecessary personal information. Ductio will provide an appropriate secure route if sensitive evidence is needed. A good-faith report or challenge is not itself a breach.

12 Versions and changes

12.1 The version incorporated into the accepted Agreement governs the committed term. A website update does not silently replace that version. Ductio will retain dated versions and make the applicable version available on request.

12.2 Changes follow the notice, renewal and mandatory-law provisions in the Customer Terms. Material changes during a committed term require agreement except narrowly necessary mandatory-law changes permitted there. Operational security measures may address an existing threat within the accepted Agreement, but must not create unapproved charges, unrelated data-use rights or undisclosed reductions in purchased entitlement.