divelai closed beta

divelai / legal / acceptable use

Acceptable use

Divelai is a privacy control. It should not become a tool for the opposite, so this policy sets out the small number of things it may not be used for.

You must not

  • Attempt to re-identify data belonging to another customer, or access a vault that is not yours
  • Use tokenisation to disguise data you are prohibited from processing or transferring at all
  • Present Divelai output as anonymised or de-identified without your own assessment supporting that
  • Probe, load-test, or attempt to circumvent the service outside the terms of the disclosure policy
  • Route unlawful content through the service, or use it to facilitate unlawful processing
  • Resell or provide the service to a third party without a written agreement covering it

A note on the second point

It matters most and is easiest to get wrong. Pseudonymisation reduces risk and supports a safeguards argument — it does not remove data from the scope of a transfer rule, and it does not turn a prohibited processing activity into a permitted one. If a transfer would be unlawful with the names in it, sanitizing the names does not, by itself, make it lawful. Ask your counsel, not your vendor.

If this policy is breached

We will contact you first in almost every case, because most breaches are misconfiguration rather than intent. Where there is an immediate risk to another customer's data or to the service, we may suspend the affected deployment before making contact, and will explain what happened as soon as we do.

Suspension terms, notice periods, and appeal route [CONFIRM — to be aligned with the counsel-reviewed terms]

Unsure whether your use case fits?

Ask before you build. We would rather answer an awkward question early.