Acceptable Use Policy

Last Updated: September 18, 2025

Introduction

This Acceptable Use Policy (“AUP”) sets standards for using FormaFlow services (“Service”) to protect users and platform integrity through clear guidelines and enforcement.

The AUP applies to all access and usage; it should be read alongside the Terms of Service and Privacy Policy for comprehensive coverage of obligations and data practices.

1. Scope & Responsibilities

This AUP governs use of the Service by all accounts and end users, requiring compliant, secure, and respectful behavior throughout creation, collection, and distribution of content.

Users must ensure their usage aligns with applicable laws, organizational policies, and platform rules, and must safeguard credentials and access methods to prevent misuse.

Why native disclosures?+

HTML details/summary provide accessible, keyboard‑operable toggles without custom JavaScript, improving scannability for dense policy content.

2. Prohibited Uses

The Service must not be used to create, collect, or distribute content or activities that violate law, platform rules, or rights of others.

  • Illegal activities in any applicable jurisdiction, including evasion of sanctions or regulatory controls.
  • Harmful or malicious content, malware distribution, or attempts to compromise devices or data.
  • Infringement on intellectual property or proprietary rights, including unauthorized copying or use.
  • Deceptive practices such as phishing, impersonation, or fraud to obtain information or advantage.
  • Abusive content including harassment, hate speech, or threats targeting protected characteristics.
  • Spam or unsolicited bulk messages, or misuse of communication channels for unauthorized advertising.
Examples and clarifications+
  • Mass scraping that bypasses rate limits or technical controls is prohibited.
  • Content that facilitates financial fraud or identity theft is prohibited.
  • Use of brand assets to impersonate official communications is prohibited.

3. Specific Prohibitions on Data Collection

Certain sensitive data types must not be collected without appropriate safeguards and compliance controls aligned to legal requirements and platform rules.

  • Financial account numbers such as credit card or bank account numbers.
  • Social Security Numbers or other national identity numbers and unique identifiers.
  • Passwords, authentication factors, or security answers for any service.
  • Protected Health Information subject to frameworks like HIPAA or similar regimes.

4. Security & System Integrity

Attempts to bypass security, probe infrastructure, disrupt availability, or degrade service for other users are strictly prohibited.

Users must promptly report suspected vulnerabilities or misuse and avoid exploiting any discovered issues, following responsible disclosure norms.

5. Fair Usage & Rate Limits

Automated usage must respect documented quotas and rate limits, and patterns that burden infrastructure or impair others’ access may be throttled or blocked.

Caching, pagination, and backoff strategies should be used where applicable to reduce load and preserve quality of service for all tenants.

6. Enforcement

Violations may be investigated, and access may be suspended or terminated; content may be removed, and law enforcement may be notified where required.

Enforcement actions may consider severity, intent, and history, with the goal of protecting users, data, and platform reliability while applying fair and consistent measures.

7. Reporting Violations & Appeals

Suspected violations or security concerns should be reported via the contact page with sufficient detail to aid investigation and remediation.

If access is limited due to an alleged violation, an appeal can be submitted with relevant context, which will be reviewed in a timely and impartial manner.

8. Changes to this AUP

This AUP may be updated periodically; material updates will be communicated with reasonable notice where appropriate, and continued use constitutes acceptance.

9. Contact

Questions about this AUP or reports of suspected violations can be sent via /contact.