Acceptable Use Policy
Incorporated by reference into the Terms of Service and any Cloud Service Agreement. "Service" means the dvt platform, API, and MCP interface.
Version 1.0 · Effective July 30, 2026 · Data Viz Tool, Inc.
1. Prohibited uses
You may not use the Service to:
- Break the law — violate any applicable law or regulation, or infringe any third party's intellectual property, privacy, or other rights.
- Attack the Service — attempt to gain unauthorized access to any system, account, or data; probe or test the vulnerability of the Service except under our published responsible disclosure policy; circumvent authentication, rate limits, quotas, or licensing controls.
- Reach other tenants — attempt to access another organization's specifications, connections, credentials, or data.
- Degrade the Service — interfere with or disrupt the Service or its infrastructure, including denial-of-service, deliberate resource exhaustion, or evading documented rate limits.
- Distribute malicious code — upload or transmit malware, or content designed to damage or gain unauthorized access to any system.
- Misuse credentials — share API keys outside your organization, or use credentials you are not authorized to use.
- Upload prohibited data — see Section 2.
- Resell or provide a competing service — resell, sublicense, or provide the Service to third parties except as expressly permitted under a Cloud Service Agreement and Order Form, if you have one, or use the Service to build or operate a competing product.
- Reverse engineer — decompile or reverse engineer the Service, except where that restriction is unenforceable under applicable law.
2. Data restrictions
The Service is not designed or authorized for:
- Protected Health Information (PHI) under HIPAA. dvt does not execute Business Associate Agreements.
- Payment card data subject to PCI-DSS.
- Classified or export-controlled information under ITAR or EAR.
- Personal data of children under 13, or under 16 where GDPR Article 8 applies.
A specific warning about dashboard media. Images and branding assets uploaded to dashboards are stored in a bucket that is readable by anyone holding the object's unguessable URL. Do not upload confidential material as dashboard media.
Your warehouse data is a different matter: it stays in your warehouse, under your own access controls. Customers with a signed Cloud Service Agreement also have a Data Processing Addendum (DPA) available on request from their account contact.
3. AI agents and automated authoring
dvt is designed to be driven by AI agents through its API and MCP interface. That is a supported, intended use. You remain responsible for:
- Every action an agent takes under your credentials. Agent actions are attributed in the audit log, but attribution is not authorization — an API key acts with the authority you gave it.
- Scoping keys to the minimum a workload needs. Scopes can only narrow; use that.
- What agents send to third-party model providers. If you connect an external AI tool to dvt, the data that tool sees leaves dvt's control and is governed by that tool's terms, not ours.
Do not use the Service to generate content that is unlawful, or to make automated decisions with legal or similarly significant effects on individuals without appropriate human review.
4. Fair use of shared infrastructure
The Service does not meter queries, viewers, or authorship, and we intend to keep it that way. That model depends on customers not deliberately exploiting it.
We may contact you to discuss usage that materially degrades service for other customers. We will always contact you before taking any action, and we will not suspend a paying customer for usage volume without first attempting to resolve it.
5. Enforcement
If we believe your use violates this Policy, we will contact you and, where practical, give you a reasonable opportunity to remedy it.
We may suspend access without prior notice only where the violation poses an immediate threat to the security, integrity, or availability of the Service or to another customer's data. Any such suspension will be the narrowest scope and shortest duration necessary, and we will notify you promptly with the reason and what is required to restore access.
Repeated or uncured material violations may be grounds for termination under the Agreement.
6. Reporting
Report suspected violations or security issues to[email protected].
7. Changes
We may update this Policy. Material changes take effect 30 days after we notify you, except where a shorter period is required by law or to address a security threat. Continued use after the effective date constitutes acceptance.