Legal center

Privaata legal policy

Privaata Acceptable Use Policy

The conduct, content, security, automation, and platform-use rules that apply to all Privaata users.

Source document: Privaata Acceptable Use Policy.docx

Privaata Acceptable Use Policy

Effective Date: September 1, 2026 Last Updated: September 1, 2026

This Acceptable Use Policy (“Policy” or “AUP”) establishes rules governing the use of Privaata, a software-as-a-service privacy management platform operated by Kinfolk Technologies Limited (“Kinfolk Technologies,” “we,” “us,” or “our”).

This Policy applies to all Customers, administrators, authorized users and other persons who access or use Privaata.

By using Privaata, users agree to comply with this Policy, the Privaata Terms of Service and other applicable agreements.

1. Purpose

Privaata provides organizations with technology for managing privacy, data-protection and related governance activities.

Depending on the functionality available, Privaata may assist organizations with activities including:

Records of Processing Activities (“RoPAs”);

Data Protection Impact Assessments (“DPIAs”);

Data Subject Access Requests (“DSARs”);

privacy and data inventories;

data mapping;

incident and breach management;

vendor and third-party risk management;

policies and compliance records;

integrations with third-party systems;

AI-assisted privacy analysis;

regulatory-readiness activities;

audit records;

reporting; and

other privacy-management activities.

Because these capabilities may involve access to personal data, organizational systems and compliance records, users must exercise them responsibly and only with appropriate authority.

2. Compliance With Law

Users must not use Privaata to engage in, facilitate or conceal conduct that violates applicable laws, regulations, court orders or other legally binding requirements.

Users are responsible for understanding the laws applicable to their organization and use of Privaata.

The availability of a feature within Privaata does not mean that every possible use of that feature is lawful in every jurisdiction.

3. Authorization to Access and Process Data

Customers and users may only use Privaata to access, connect, scan, search, analyze, transfer or otherwise process information that they are authorized to access and process.

Users must not use Privaata to:

access another person’s or organization’s information without authorization;

connect a system they are not authorized to connect;

exceed permissions granted by their organization;

bypass internal authorization requirements;

search repositories they are not entitled to search; or

use legitimate credentials for an unauthorized purpose.

A user’s technical ability to access information does not necessarily establish lawful or organizational authority to access it.

4. Connected Systems and Integrations

Users may connect Privaata only to third-party systems for which they have appropriate authority.

This applies to systems such as email platforms, document repositories, collaboration systems, cloud services, databases and other connected applications.

Customers are responsible for ensuring that:

integrations are appropriately authorized;

requested permissions are appropriate;

administrators connecting systems have authority to do so;

connected data is processed for legitimate purposes; and

applicable legal and organizational requirements are satisfied.

Users must not intentionally exploit integrations to obtain information beyond their authorized scope.

5. Unauthorized Surveillance and Monitoring

Privaata must not be used for unlawful surveillance, stalking, tracking, monitoring or profiling of individuals.

This prohibition does not prevent legitimate organizational monitoring where the organization has appropriate authority, a lawful purpose and any notices, safeguards or other measures required by applicable law.

6. Misuse of DSAR Functionality

Privaata’s DSAR functionality must be used for legitimate privacy-management purposes.

Users must not use DSAR functionality to:

impersonate a data subject;

fabricate a request;

manufacture a false identity;

obtain information they are not authorized to access;

search unrelated records under the pretext of responding to a DSAR;

intentionally disclose information to an unauthorized person; or

circumvent appropriate identity-verification or access controls.

Organizations remain responsible for appropriately verifying requests and reviewing proposed disclosures before information is released.

7. Fabrication of Compliance Records

Users must not intentionally use Privaata to fabricate, falsify or materially misrepresent privacy or compliance evidence.

This includes intentionally creating false or misleading:

RoPAs;

DPIAs;

DSAR records;

consent records;

incident records;

breach records;

data inventories;

risk assessments;

vendor assessments;

audit evidence;

policies;

approvals;

remediation records;

training records; or

other compliance documentation.

Privaata must not be used to create the false appearance of compliance for the purpose of misleading a regulator, auditor, customer, data subject, business partner or other person.

8. Audit Logs and Evidence Integrity

Users must not improperly manipulate, falsify, circumvent, conceal or interfere with audit logs, security records or system-generated compliance evidence.

This does not prohibit legitimate administrative activities expressly supported by Privaata, including lawful correction, retention or deletion operations.

Where a record is legitimately corrected, the Customer should preserve appropriate accountability where required by law, policy or applicable functionality.

9. Artificial Intelligence

Privaata may provide AI-assisted functionality.

Users must not intentionally use Privaata’s AI functionality to:

facilitate unlawful activity;

perpetrate fraud or deception;

fabricate compliance evidence;

impersonate another person for fraudulent purposes;

harass or threaten individuals;

generate malicious software or instructions intended to compromise systems;

circumvent Privaata’s security controls;

intentionally create materially deceptive regulatory records; or

otherwise abuse the service.

AI-generated information must be appropriately reviewed by qualified human users before consequential privacy, legal, regulatory or organizational decisions are made.

10. No Misrepresentation of AI Outputs

Users must not knowingly represent an AI-generated recommendation, draft, assessment or analysis as having been independently verified by a human professional when it has not been.

Customers remain responsible for determining whether an AI-generated output is appropriate for their particular circumstances.

Privaata’s AI capabilities are decision-support tools and do not replace appropriate professional judgment.

11. Security Attacks and Malicious Activity

Users must not attempt to compromise Privaata, its infrastructure, another Customer’s workspace, or systems connected to the service.

Prohibited activity includes:

introducing malware;

unauthorized vulnerability exploitation;

credential attacks;

password attacks;

unauthorized privilege escalation;

denial-of-service attacks;

intentionally overwhelming infrastructure;

circumventing authentication;

bypassing access controls;

exploiting vulnerabilities to obtain unauthorized data;

interfering with another Customer’s use of Privaata; or

attempting to gain unauthorized administrative access.

12. Security Testing

Users may not conduct penetration testing, vulnerability exploitation, automated security scanning or similar testing against Privaata without appropriate authorization from Kinfolk Technologies.

This prohibition does not prevent legitimate security research or testing that Kinfolk Technologies has expressly authorized.

Persons who believe they have discovered a security vulnerability should report it responsibly rather than exploiting it.

Security reports may be submitted to:

security@kinfolktechnologies.com

13. Malware and Harmful Code

Users must not knowingly upload, transmit, execute or distribute malware or other harmful code through Privaata.

This includes viruses, ransomware, worms, destructive scripts, credential-stealing software and other code intended to compromise systems or data.

This restriction does not prohibit legitimate cybersecurity information being stored or processed for authorized defensive, incident-management or compliance purposes.

14. Reverse Engineering and Technical Circumvention

Except where applicable law provides a right that cannot lawfully be restricted, users must not:

reverse engineer Privaata;

attempt to obtain Privaata’s source code through unauthorized means;

reproduce substantial portions of the service;

circumvent licensing restrictions;

bypass plan limitations;

defeat AI usage controls;

evade storage or user limits;

circumvent rate limits;

disable security controls; or

otherwise defeat technical restrictions intended to protect the service.

15. Unauthorized Scraping and Automated Extraction

Users must not use bots, crawlers, scripts or automated tools to scrape, systematically extract or reproduce Privaata content or functionality except where the activity is expressly supported or authorized.

This restriction does not prohibit legitimate automation, APIs, integrations or other automated functionality that Privaata provides or expressly authorizes.

16. Excessive Automated Activity

Users must not generate automated activity that unreasonably degrades, disrupts or overloads Privaata or its infrastructure.

Kinfolk Technologies may apply reasonable technical measures such as rate limits, usage controls and temporary restrictions to protect service reliability.

Legitimate integrations and supported automation remain permitted within applicable technical and subscription limits.

17. Account and Credential Misuse

Users must not:

share individual account credentials with unauthorized persons;

sell or rent user accounts;

impersonate another authorized user;

misrepresent their authority within an organization;

deliberately access another Customer’s workspace;

obtain credentials through deceptive means; or

assist another person in circumventing account controls.

Each user should access Privaata using their own authorized account where individual accounts are provided.

18. Sensitive Personal Data

Privaata does not impose a blanket prohibition on sensitive personal data, because legitimate privacy-management activities may require organizations to process such information.

However, Customers should process sensitive personal data through Privaata only when:

reasonably necessary;

appropriately authorized;

supported by an appropriate lawful basis or other legal authority where required; and

subject to appropriate organizational and technical safeguards.

Customers should avoid placing unnecessary sensitive information into Privaata merely because the platform technically permits it.

19. Children’s Data

Privaata does not impose a blanket prohibition on Customer processing of personal data relating to children or minors.

Organizations such as schools, healthcare providers, religious organizations or other legitimate entities may have lawful reasons to manage privacy obligations involving minors.

Where children’s data is processed, the Customer is responsible for ensuring that it has appropriate authority, lawful basis, notices, permissions, safeguards or consent where applicable.

This provision does not change the separate rule that individuals under 18 should not independently create Privaata accounts.

20. Harassment, Abuse and Unlawful Harm

Privaata must not be used to intentionally:

threaten;

stalk;

harass;

intimidate;

unlawfully discriminate against;

defraud;

exploit; or

otherwise unlawfully harm another person.

This restriction does not prohibit legitimate investigations, disciplinary processes, compliance activities or legal proceedings conducted with appropriate authority.

21. Intellectual Property and Third-Party Rights

Users must not use Privaata to knowingly infringe or misappropriate another person’s:

copyright;

trademark;

trade secret;

database right;

confidential information;

contractual rights; or

other intellectual-property or proprietary rights.

Customers are responsible for ensuring that they have appropriate rights to content they upload or process through the service.

22. Resale and Commercial Exploitation

Customers may not resell, sublicense, rent, lease or commercially provide third parties with access to Privaata unless Kinfolk Technologies has expressly authorized the arrangement.

This restriction does not prevent an authorized consultant, service provider, managed-service provider, reseller or other partner from using or providing Privaata where expressly permitted under an applicable agreement.

23. Subscription and Usage Circumvention

Users must not deliberately manipulate Privaata to avoid legitimate subscription charges or usage limitations.

Examples include:

creating multiple accounts to improperly obtain repeated free trials;

circumventing AI usage allowances;

artificially dividing usage between accounts to avoid plan limits;

bypassing user limits;

manipulating billing mechanisms;

circumventing feature restrictions; or

exploiting technical defects to obtain paid functionality without authorization.

24. Free Trial Abuse

Privaata’s free trial is intended to allow eligible prospective Customers to evaluate the service.

Users must not repeatedly create accounts, identities, organizations or payment arrangements for the purpose of obtaining unauthorized consecutive free trials.

Kinfolk Technologies may restrict trial eligibility where it reasonably identifies abuse.

25. Payment and Fraud

Users must not use stolen, fraudulent or unauthorized payment credentials to purchase Privaata.

Users must not knowingly manipulate payment processes, transaction information or subscription records for fraudulent purposes.

Suspected payment fraud may result in immediate restriction or suspension and may be reported to appropriate payment providers or authorities where required or permitted by law.

26. Customer Responsibility for Authorized Users

Customers are responsible for appropriately administering users within their Privaata workspace.

Customers should:

grant access according to legitimate organizational roles;

remove access when it is no longer required;

periodically review permissions;

investigate suspected misuse;

protect administrative privileges; and

notify Kinfolk Technologies of relevant security concerns.

The Customer’s administrators are responsible for determining which individuals should be authorized to use the Customer’s workspace.

27. Investigating Suspected Violations

Kinfolk Technologies may investigate suspected violations of this Policy.

Where reasonably necessary, an investigation may involve reviewing relevant:

account information;

security information;

audit records;

usage metadata;

technical logs;

transaction information; and

other information reasonably necessary to understand the suspected violation.

Any such investigation will be conducted subject to applicable privacy, confidentiality and contractual obligations.

28. Enforcement

Kinfolk Technologies may take reasonable action where it determines that this Policy has been violated.

Depending on the nature and severity of the issue, actions may include:

contacting the Customer;

requesting additional information;

issuing a warning;

requiring corrective action;

limiting affected functionality;

temporarily restricting an account;

suspending access;

terminating access; or

taking other measures reasonably necessary to protect Privaata, Customers, data subjects or third parties.

29. Notice and Opportunity to Correct

For ordinary or remediable violations, Kinfolk Technologies will generally seek to provide reasonable notice and, where appropriate, an opportunity to correct the issue.

However, immediate action may be taken where reasonably necessary because of:

an active security threat;

unauthorized access;

fraud;

unlawful activity;

material risk to another Customer;

risk of significant data exposure;

malicious attacks;

payment fraud;

serious abuse of the platform; or

another circumstance requiring urgent intervention.

Kinfolk Technologies is not required to leave a harmful account active while awaiting remediation where immediate restriction is reasonably necessary.

30. Cooperation With Legal Requirements

Kinfolk Technologies may take action where necessary to comply with applicable law, a valid legal process, court order or lawful direction from a competent authority.

Nothing in this Policy requires Kinfolk Technologies to permit conduct that it reasonably believes would violate applicable law.

31. Reporting Misuse

Suspected misuse of Privaata or violations of this Policy may be reported to:

support@kinfolktechnologies.com

Security vulnerabilities, suspected attacks or security-related concerns may be reported to:

security@kinfolktechnologies.com

Privacy and personal-data concerns may be reported to:

privacy@kinfolktechnologies.com

Users should provide sufficient information to allow the matter to be investigated but should avoid sending passwords, complete payment-card information or other unnecessary sensitive credentials by email.

32. Changes to This Policy

Kinfolk Technologies may update this Policy as Privaata’s functionality, security requirements, legal obligations or risk environment evolves.

The “Last Updated” date identifies the current version.

Where required by applicable law or agreement, Kinfolk Technologies will provide reasonable notice of material changes.

Continued use following an effective update is subject to the applicable Terms of Service and mandatory legal rights.

33. Relationship With the Terms of Service

This Acceptable Use Policy forms part of the rules governing use of Privaata and should be read together with the Privaata Terms of Service.

A violation of this Policy may constitute a violation of the Terms of Service.

Where an enterprise agreement contains additional acceptable-use requirements, those requirements may also apply.

34. Contact Information

Kinfolk Technologies LimitedPrivaata18 Geranium PathMona HeightsKingston 6Jamaica

Telephone: (876) 298-4018General/Technical Support: support@kinfolktechnologies.comSecurity: security@kinfolktechnologies.comPrivacy: privacy@kinfolktechnologies.comBilling: billing@kinfolktechnologies.com

End of Acceptable Use Policy