Trust Centre · Policies · v1.0
Acceptable Use Policy
Last updated August 2026 · v1.0 · Changelog
Document control
This Policy is the Acceptable Use Policy referred to in Condition 2.1 of the VIXIO General Terms and Conditions. It forms part of the Trust Centre and is incorporated into, and forms part of, the Agreement.
| Contracting entity | Compliance Online Limited t/a VIXIO Regulatory Intelligence (Co. No. 05706431) |
|---|---|
| Registered address | 7th Floor, St Clare House, 30 Minories, London, EC3N 1DD (per Condition 19.2 of the General Terms and Conditions) |
| Governing law | England and Wales (Condition 26.1); Delaware, USA where the Customer is established in the United States (Condition 26.2) |
| Applies to | Customer, Customer Users and Third Party Users under an Order incorporating the General Terms and Conditions |
| General / legal enquiries | info@vixio.com |
| Data protection | dataprotection@vixio.com |
| Security / vulnerability disclosure | tech@vixio.com |
1. Purpose and Scope
1.1 This Acceptable Use Policy (“Policy”) sets out the rules governing use of the Services by Compliance Online Limited, trading as VIXIO (“VIXIO”, “we”, “us”, “our”). It applies to the Customer and all Users (being Customer Users and Third Party Users), as those terms are defined in the Order and the VIXIO General Terms and Conditions (together, the “Agreement”).
1.2 This Policy is the “Acceptable Use Policy” referred to in Condition 2.1 of the General Terms and Conditions and forms part of the Trust Centre, together with the Documentation, the DPA, the Security Policy and the Service Levels. It is incorporated into, and forms part of, the Agreement.
1.3 The Customer must ensure that its Users comply with this Policy and remains liable for any breach of the Agreement, including this Policy, by its Users or by any third party using a User's log-in details (Condition 3.1(c)).
1.4 In the event of any conflict or ambiguity between this Policy and the other parts of the Agreement, the order of precedence at Condition 1.3 of the General Terms and Conditions applies: Special Terms, then the General Terms and Conditions, then the schedules (including this Policy), then the Order.
2. Definitions
2.1 Capitalised terms used in this Policy and not otherwise defined have the meanings given to them in the General Terms and Conditions, including “Customer”, “Customer Users”, “Third Party Users”, “Users”, “Client Content”, “Service Data”, “Services”, “Tier”, “Third Party Integration”, “Documentation” and “Trust Centre”.
2.2 “AI Functionality” and “Outputs” have the meanings given in Condition 8 of the General Terms and Conditions: AI Functionality means the artificial intelligence and machine learning functionality used by the Services to process Client Content and third party materials, and Outputs means the content generated using that functionality.
2.3 “Automated Access” means any method of accessing the Services other than direct, manual use by a User through the standard interface, or an authorised Third Party Integration, including scripts, bots, crawlers, scrapers and unauthorised application programming interface (API) calls.
3. General Principles
When using the Services, you must:
- comply with all applicable laws (Condition 4.3);
- ensure the number of Users, and your and their usage, does not exceed the limitations of your Tier (Condition 3.1);
- keep login details confidential and not share them with any individual who has not been assigned their own login details (Condition 3.3); and
- co-operate with any reasonable security or other checks or requests for information made by VIXIO (Condition 4.6).
4. Use of the Services
4.1 You must not, and must ensure your Users do not, access, store, distribute or transmit using the Services (Condition 4.2):
- any Virus;
- any material that is unlawful, harmful, threatening, defamatory, obscene, infringing, harassing, or racially or ethnically offensive;
- any material that facilitates illegal activity, depicts sexually explicit images, or promotes unlawful violence;
- any material that is discriminatory based on race, gender, colour, religious belief, sexual orientation or disability; or
- any material that is otherwise illegal or causes damage or injury to any person or property.
4.2 You must not, and must ensure your Users do not (Condition 4.3):
- try to gain unauthorised access to the Services or any connected networks, servers or computer systems;
- reverse compile, disassemble, reverse engineer or otherwise reduce to human-perceivable form all or any part of the Services, except to the extent this restriction cannot be excluded by law;
- allow any employee of a third party, including a group company, to access the Services, other than as an authorised Third Party User;
- copy, download, scrape, store, publish, transmit, transfer, distribute, broadcast, circulate, sub-licence, bundle with other products, sell or otherwise use any portion of the Services or Service Data, other than sending Service Data to third parties as permitted under Condition 6; or
- use or access the Services to build or support, or assist a third party to build or support, products or services which compete with the Services.
4.3 We reserve the right, without liability, to disable your access to the Services if you breach Section 4.1 or 4.2 of this Policy.
5. Use of Service Data
5.1 You may use Service Data for your internal business purposes only. You may authorise Customer Users to share Service Data with a Third Party User on an individual basis, for your internal business purposes, provided such sharing is reasonable and proportionate. Widespread sharing, for example via an intranet or group email addresses, is not permitted unless otherwise agreed (Condition 6.1).
5.2 You must not, and must ensure your Users do not (Condition 6.2):
- download or store Service Data in any form other than its original form, or for any purpose other than as permitted under the Agreement;
- create a database or other collection or record, in electronic or hard copy form, by systematically downloading or storing Service Data, including bulk exports for future reference;
- create derivative works based on Service Data;
- use Service Data for any unlawful purpose;
- sub-licence, rent, lease, give access to, transfer or assign any rights in Service Data, except as permitted under Condition 6.1;
- alter or remove any copyright or other proprietary notices in Service Data;
- use Service Data to develop, offer for sale, or sell any product or service that competes with the Services; or
- input all or part of Service Data into any public large language model, machine learning model, foundation model, generative AI system, or other process commonly referred to as artificial intelligence, for any purpose including developing, improving, training, testing or supporting such a model or system, or to generate, synthesise or combine content.
5.3 The final restriction at Section 5.2 applies regardless of which Tier or Third Party Integration is used to access Service Data, and applies in addition to the AI Functionality provisions at Section 7 of this Policy.
6. Client Content
6.1 Where you upload or submit Client Content, you warrant that it will not (Condition 7.1):
- breach any law, statute or regulation, including data protection law;
- infringe the intellectual property or other legal rights of any person;
- be provided in breach of a legal duty owed to a third party, such as a contractual duty or duty of confidence;
- be deliberately or knowingly false, inaccurate or misleading; or
- give rise to any cause of action against VIXIO.
6.2 VIXIO does not actively monitor Client Content, but may delete Client Content it reasonably believes breaches Section 6.1 (Condition 7.2). VIXIO accepts no liability for Client Content and has no liability for errors or omissions in Service Data to the extent based on Client Content (Conditions 7.2 to 7.3).
7. AI Functionality Acceptable Use
7.1 What AI Functionality does
The Services use artificial intelligence and machine learning (“AI Functionality”) to process Client Content and third-party materials and generate Outputs (Condition 8.1). The models in use, and the governance applied to them, are set out in Responsible AI.
7.2 Ownership of Outputs
You exclusively own all right, title and interest, including intellectual property rights, in Client Content and in Outputs generated using AI Functionality (Condition 8.1).
7.3 Accuracy and human oversight
VIXIO takes reasonable steps to monitor, test and evaluate AI Functionality, including periodic human review and controlling the materials to which it can refer, to help reduce material errors, bias and hallucinations (Condition 8.2). Outputs may nonetheless contain inaccuracies, omissions or bias, and are not warranted to be accurate, complete or error-free. You are responsible for reviewing all Outputs for accuracy, appropriateness, fitness for your intended purpose, and compliance with legal and regulatory requirements. All use of Outputs is at your own risk (Condition 8.3).
7.4 No training on Client Content
VIXIO will not use Client Content to train, fine-tune or otherwise improve any large language model, except to the extent strictly necessary to provide the Services. VIXIO may use aggregated, de-identified data derived from your use of AI Functionality to operate, improve and develop the Services, provided this does not identify you and does not include Client Content in a form that could be reverse engineered to identify you. Third-party AI providers and sub-processors used to support AI Functionality are bound by written obligations no less protective than this Policy, including a prohibition on using Client Content for training, fine-tuning or model improvement (Conditions 8.4 to 8.5).
7.5 Acceptable use of Outputs
You may use Outputs for your internal business purposes, consistent with Section 5 of this Policy. You must independently verify Outputs before relying on them for any business, compliance or regulatory decision.
8. Third Party Integration and Automated Access
8.1 The Services permit Third Party Integration. Availability, scope and number of Third Party Integrations depend on your Tier (Condition 5.1). You are responsible for the configuration, operation, security and maintenance of any integrated third-party software, platform, application or system, and must comply with the technical specification and requirements for integrations and APIs set out in the Trust Centre (Condition 5.3).
8.2 Automated Access to the Services, other than through an authorised Third Party Integration or direct manual use through the standard interface, is prohibited. This includes the use of bots, scripts, crawlers or scraping tools, consistent with the restriction on copying, downloading and scraping Service Data at Condition 6.2(b).
8.3 Any authorised Third Party Integration or API access must not:
- circumvent or attempt to circumvent rate limits, authentication requirements or other access controls;
- be used to build, populate or maintain a product, service or database that competes with the Services; or
- impose an unreasonable or disproportionate load on VIXIO's infrastructure.
9. Account and Credential Security
9.1 You must ensure Users keep their login details confidential and do not share them with any third party, and must inform VIXIO immediately if you have reason to believe a User's login details have become known to an unauthorised individual, or that the Services are being used, or are likely to be used, in an unauthorised way (Condition 3.3).
9.2 Customer Users must not be employed by any third party, including any other Affiliate, without VIXIO's prior written consent. Where the Customer acquires a new Affiliate or business (an “Acquisition”), employees related to that Acquisition may not be authorised as Users without VIXIO's prior written consent, which may be subject to additional Fees even where usage remains within the same Tier (Conditions 3.4 to 3.5).
10. Audit and Enforcement
10.1 VIXIO may audit your use of the Services on at least 30 days' prior written notice, conducted within normal business hours at VIXIO's expense, no more than once in any 12-month period except where required by law, a regulator, or where VIXIO reasonably believes you are in breach of the Agreement (Condition 4.6).
10.2 Where an audit reveals that a password has been provided to an individual who is not a User, or that Fees have been underpaid, VIXIO may suspend your access to the Services without liability and/or require payment of any underpayment and, at its sole discretion, an amount equal to the benefit received by the individual who is not a User (Condition 4.7).
10.3 VIXIO may suspend or terminate a User's account without liability if it reasonably believes that User is in breach of the Agreement (Condition 3.2), and may suspend or terminate the Agreement for reasonably believed fraudulent use, misuse or abuse of the Services, or failure to pay undisputed Fees (Condition 12.3).
11. Reporting Violations
If you believe this Policy has been breached, or wish to report a security vulnerability, please contact us using the details below.
| General Policy concerns | info@vixio.com |
|---|---|
| Security vulnerabilities | tech@vixio.com · see the vulnerability disclosure commitments in Security |
| Data protection concerns | dataprotection@vixio.com |
12. Policy Governance
| Version | v1.0 (August 2026) |
|---|---|
| Owner | CPTO |
| Review cycle | Annually, or following a material change (for example new AI Functionality, integration, or automated access route) |
| Notice of material change | Not less than 30 days' prior written notice by email (Condition 10.1(b) of the General Terms and Conditions) |
| Related documents | Order; General Terms and Conditions; Documentation; DPA; Security Policy; Service Levels; Privacy Policy; Trust Centre |
