Acceptable Use Policy — Comprehendly
Provider: UltraDigital Limited (“StepCare”, “Comprehendly”)
Effective date: 1 August 2026
Version: 1.0
This Acceptable Use Policy (AUP) is incorporated into the Terms of Service.
1. Purpose
The Service is intended for lawful, professional form completion and documentation. This AUP protects users, individuals whose data is processed, and platform integrity.
2. Prohibited uses
You must not, and must not permit users or partners to:
2.1 Law and rights
- Violate applicable law in New Zealand, Australia, or other relevant jurisdictions
- Infringe intellectual property, privacy, or publicity rights
- Harass, threaten, or discriminate unlawfully
2.2 Data and privacy
- Submit personal information without lawful basis or required notices
- Submit sensitive or health information beyond what is necessary for the form
- Sell, rent, or broker personal information from the Service
- Use the Service to build unrelated datasets for marketing or surveillance
2.3 AI, voice, and phone
- Use voice or phone capture covertly where required consent is not obtained
- Rely on AI outputs for clinical diagnosis, medication decisions, eligibility determinations, or statutory determinations without qualified human review
- Use prompt injection or abuse designed to exfiltrate other tenants’ data
- Send SMS or make calls without required consent, identification, or unsubscribe / opt-out mechanisms
2.4 Security
- Probe, scan, or test vulnerabilities without written permission
- Share secret API keys in public repositories or unapproved client bundles
- Circumvent usage caps, metering, or authentication
- Access another tenant’s data
2.5 Platform abuse
- Distribute malware, spam, or phishing via forms, embed, SMS, or phone
- Overload infrastructure
- Resell access without a written partner agreement
2.6 Content
- Upload unlawful, defamatory, or exploitative content (including child exploitation material — zero tolerance; report to authorities)
3. Customer responsibilities
You must:
- Configure roles and permissions using least privilege
- Maintain workforce policies on appropriate voice, AI, and outreach use
- Revoke access for departed staff promptly
- Investigate and report suspected breaches to security@stepcare.app
4. Monitoring and enforcement
We may monitor aggregate usage and security signals. We do not routinely review form content except for support, security, legal compliance, or as described in the DPA.
Enforcement: warning, suspension, termination, or legal action. We may report unlawful activity to authorities.
5. Reporting abuse
security@stepcare.app — include tenant name, timestamps, and description.
6. Changes
We may update this AUP with notice as described in the Terms.
End of Acceptable Use Policy