Acceptable Use Policy

Firebird Solutions Limited · NZBN 9463794 · Auckland, New Zealand

Draft — pending final legal review. The effective date is set when this document is finalised. Feedback: [email protected].

Atamaia Acceptable Use Policy

Effective date: draft — effective date set on publication Version: 1.0

This Acceptable Use Policy ("AUP") forms part of the Atamaia Terms of Service. It applies to the hosted Atamaia service. Capitalised terms have the meaning given in the Terms.

We have kept this short and specific. The intent is not to police what you build — Atamaia exists to give AI systems memory and autonomy, and that is a broad remit. The intent is to protect other customers, our infrastructure, and people who did not choose to be in your data.


1. Legal and rights

You must not use the Hosted Service to:

  • break any applicable law, or facilitate anyone else doing so;
  • store or transmit content you have no right to store or transmit;
  • infringe copyright, trade marks, trade secrets, patents, privacy or publicity rights;
  • store personal information about other people without a lawful basis, or in breach of a notice or consent obligation you owe them;
  • store material that is defamatory, or that constitutes harassment or stalking of an identifiable person.

2. Prohibited content

You must not store or transmit:

  • child sexual abuse material, or any sexualised content involving minors — we report this to law enforcement and terminate immediately, without notice;
  • content that incites or facilitates violence, terrorism, or serious harm to people;
  • content designed to facilitate the creation of weapons capable of mass casualties;
  • malware, exploit kits, or code whose purpose is to compromise systems without authorisation;
  • content that facilitates fraud, phishing, or identity theft.

3. Regulated data

You must not store in the Hosted Service:

  • protected health information subject to HIPAA — we do not offer Business Associate Agreements;
  • full payment card numbers or cardholder data subject to PCI-DSS;
  • government-issued identity credentials — passport, driver licence or national ID numbers and images;
  • classified or export-controlled material.

This is a limitation of our current certification posture, not a judgement about your use case. Health information that is your own, or that you hold outside a HIPAA-covered relationship, is permitted — see Terms section 9.6.

4. Security and integrity

You must not:

  • attempt to access another tenant's data, or probe for a way to;
  • attempt to bypass authentication, authorisation, tenant isolation, rate limits or quotas;
  • reverse engineer the Hosted Service to build a competing service — this does not restrict your rights under the open-source licence in respect of the published source code;
  • conduct penetration testing or vulnerability scanning without our prior written consent — contact [email protected] and we will usually say yes and agree a window;
  • introduce malware into the Hosted Service, or use it to attack a third party;
  • share credentials or API keys with anyone outside your tenant, or resell access to your account.

Responsible disclosure. If you find a vulnerability, tell us at [email protected]. We will not pursue action against good-faith research that respects this policy, avoids other customers' data, and gives us reasonable time to fix the issue before disclosure.

5. Resource use

You must not:

  • generate load that materially degrades the service for others;
  • run agents in loops that consume resources without purpose;
  • circumvent quota enforcement, including by creating multiple accounts to obtain additional free quota;
  • use the Hosted Service primarily as bulk file storage, a CDN, a proxy, or a cryptocurrency mining or blockchain node host.

6. Agents and autonomous operation

Atamaia supports agents that act autonomously. You are responsible for what your agents do as if you had done it yourself. In particular you must:

  • constrain agent tool access appropriately for the environment it operates in;
  • not configure an agent to take actions that would breach this AUP if you took them directly;
  • not use agents to impersonate a real person in a way likely to deceive;
  • ensure that where an agent interacts with third parties, it does not misrepresent itself as human where that would be unlawful or deceptive in the relevant jurisdiction.

7. Misrepresentation

You must not represent a Self-Hosted Deployment as being operated, hosted, endorsed or supported by us, or use our names or logos in a way likely to mislead. See Terms section 15.


Enforcement

Where we believe this AUP has been breached, we may — proportionate to the seriousness and the risk:

  1. contact you and ask you to fix it;
  2. restrict or throttle specific functionality;
  3. suspend the affected account or API key;
  4. terminate the account;
  5. where legally required or where there is a risk to life, report to authorities.

We will tell you what we have done and why, and give you an opportunity to respond, except where the breach falls under section 2's first bullet, where we are legally prevented, or where notice would create a risk to someone's safety or to the integrity of an investigation.

If you think we got it wrong, reply to the notice or write to [email protected]. A human will look at it.

Report abuse: [email protected]