Acceptable Use Policy
What this policy covers
This policy governs use of the ELECTE platform at platform.electe.net — the accounts, the data you put into it, the API, and the outputs it returns.
It applies to you as a customer, to every user you give access to, and to anyone who uses the platform through your account or your credentials. You are responsible for what happens under your account: if someone you gave access to breaks these rules, that is a breach by you.
It does not cover the public website, the newsletter, or our publications, which are governed by the website terms, the privacy policy and the cookie policy.
This policy forms part of the agreement under which you access the platform — the ELECTE Terms of Service you accept when you sign up, or the master services agreement if you have signed one with us. Where that agreement gives us rights to suspend or terminate, this policy explains how we use them. It creates no new ones and reduces none.
On the platform, you decide what data goes in and why, and we process it for you. The lawful basis for the data you upload is yours to hold, not ours.
What you may put into the platform
Do not upload, connect, or otherwise feed into the platform:
- Personal data you have no lawful basis to process. If you cannot say which basis you rely on, do not upload it.
- Personal data collected for a different purpose than the one you are now using it for, or in breach of the notice you gave the people concerned.
- Special category data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used to identify someone, and data about health, sex life, or sexual orientation — unless you hold the specific basis Article 9 requires. The same applies to data about criminal convictions and offences under Article 10.
- Confidential information belonging to someone else that you are not permitted to disclose.
- Malicious code, or files designed to disrupt, damage, or gain unauthorised access to any system.
If you upload data that turns out to be one of these, remove it and tell us.
What you may do with the outputs
The platform supports decisions. It does not make them. Outputs can be wrong, incomplete, or out of date, and you are responsible for checking them before you act.
Do not:
- Use an output as the sole basis for a decision that produces legal effects on a person, or that similarly significantly affects them. This includes hiring, dismissal, promotion, pay, discipline, credit, insurance, tenancy, and access to a service. A person with the competence and authority to reach a different conclusion must review the case and be able to override the output. Signing off on whatever the system produced is not review. This is what Article 22 GDPR requires.
- Attempt to re-identify individuals in anonymised or aggregated data, whether by combining outputs with other datasets, by singling out records, or by any other means.
- Build a profile of a person for a purpose you have not disclosed to them.
- Present outputs as legal, medical, financial, or other regulated professional advice, or as advice or a statement issued by ELECTE.
Do not deploy the platform in a way that would make you the deployer of a high-risk AI system under Annex III of the EU AI Act — recruitment and worker management, access to essential services, creditworthiness, education, law enforcement, migration, or the administration of justice — unless we have agreed it with you in writing in advance.
Building on the platform, or against it
Do not:
- Use the platform, its outputs, or anything derived from them to train, fine-tune, evaluate, or otherwise develop a machine learning model, or to build a product or service that competes with ours. This includes extracting outputs systematically in order to assemble a training or evaluation set.
- Benchmark the platform, run comparative tests, or publish performance or accuracy measurements about it, without our written permission first.
- Resell, sublicense, rent, or run the platform as a service for anyone outside your organisation, unless your agreement with us says you may.
Automated access, scraping, and limits
You may access the platform through our documented API, within the limits that apply to your plan. Those limits are set out in our API documentation, and we will confirm yours on request.
Do not:
- Scrape or crawl the platform, or extract data in bulk by any method other than the export and API features we provide.
- Drive the user interface with scripts, headless browsers, or undocumented endpoints in order to get around API limits.
- Open additional accounts, or rotate credentials, tokens, or IP addresses, to exceed a limit or to evade a suspension.
- Share credentials outside your organisation.
If you need higher limits, ask us at hello@electe.net rather than working around them.
Security and integrity
Do not:
- Probe, scan, or attempt to breach the platform, its infrastructure, or its authentication. See the next section for the one exception.
- Access, or try to access, another customer's data or account, or defeat the separation between tenants.
- Use crafted inputs, prompts, or files to extract another customer's data, our system configuration, credentials, or internal instructions.
- Interfere with the platform's availability for others, including denial-of-service attacks and load testing without our written permission.
- Use the platform's compute for anything unrelated to its purpose, including cryptocurrency mining.
- Store or distribute malware, phishing pages, or command-and-control infrastructure through the platform.
- Send spam or unsolicited bulk messages from the platform or using data taken out of it.
Keep your credentials secure, and tell us immediately if you believe an account has been compromised.
Unlawful and abusive use
Do not use the platform for anything unlawful under Italian or EU law, or under the law that applies to you. In particular, do not use it for content or conduct that:
- Infringes copyright, trade marks, trade secrets, or other intellectual property rights.
- Is defamatory, harassing, threatening, or promotes violence, terrorism, or discrimination against a protected group.
- Sexualises children in any way. We report this to the authorities where the law requires it, and we do so without notice to you.
- Monitors employees in a way the applicable labour law does not permit.
- Would put ELECTE in breach of EU restrictive measures, of Italian sanctions law, or of export-control rules, including on dual-use items. The representations you give us on sanctions and restricted parties are in the terms of service.
Security testing and reporting a vulnerability
Security testing is permitted only with our prior written authorisation, which we grant for a defined scope and a defined window. Ask at security@electe.net and tell us what you want to test and when. Testing outside an authorised scope and window is a breach of this policy, whoever is doing it.
If you discover a vulnerability, including by accident:
- Stop as soon as you have confirmed it. Do not access, copy, modify, or delete data beyond the minimum needed to demonstrate the problem.
- Do not use it to reach another customer's data.
- Tell us at security@electe.net with enough detail to reproduce it.
- Give us a reasonable period to fix it before you tell anyone else.
We will acknowledge your report within 72 hours and keep you informed while we work on it. We do not run a bug bounty and do not pay for reports.
If you follow this section in good faith, we will not pursue legal action against you, and we will not ask your employer or your host to. That undertaking covers research inside the limits above. It does not cover exfiltrating data, extortion, or testing after we have asked you to stop.
If you break these rules
Normally we work through three steps, in order.
1. Notice. We tell you what we have seen, what rule it touches, and what needs to change. You have 30 days from our notice to put it right, unless the conduct is one of those listed below as immediate.
2. Suspension. If it is not fixed in time, or if it recurs, we may suspend the account, individual users, or particular features, or disable specific content. We take the narrowest step that stops the problem.
3. Termination. For serious or repeated violations, we may terminate your access under the agreement.
We may go straight to suspension, without prior notice, where:
- There is a risk of harm to a person.
- There is a risk to the security, integrity, or availability of the platform, or to another customer's data.
- The content or conduct is manifestly unlawful.
- A law, a court, a regulator, or sanctions rules require us to act.
- Giving notice first would defeat the point, for example during an active attack.
Where we act without notice, we tell you as soon as we reasonably can, unless we are not permitted to. We may preserve and disclose information where the law requires it.
If you think we got it wrong, write to hello@electe.net and we will look at it again.
Termination for a violation does not change what happens to your data. You have the same 30 days to export it, we delete it from live systems within 90 days, and it persists in off-site backups for up to 30 further days before they are overwritten. Invoices and tax records are kept for 10 years, as Italian law requires. We do not withhold an export as leverage in a dispute.
Reporting abuse
If you believe someone is using the platform in breach of this policy, tell us at abuse@electe.net. Include what you saw, where, and when, and how we can reach you. We investigate reports we can act on, and do not disclose the reporter's identity to the account concerned unless the law requires it.
Privacy complaints and data subject requests go through the privacy policy. Vulnerabilities go through the section above.
By post: ELECTE S.R.L., Via Montenapoleone 8, 20121 Milano (MI), Italy.
Changes to this policy
We may update this policy. If a change is material, we will give notice through the platform or by email to your account administrators before it takes effect. Continued use after that date means you accept the updated policy.
This policy is governed by Italian law, in line with the terms of service.
Effective 22 August 2026, version 1.0.