Legal documents

Acceptable Use Policy

Last updated: October 5, 2026

Courtesy translation. The Portuguese version is the legally binding one.

This Policy defines what constitutes acceptable use of INGESTIA.IO. It details clause 3.2 of the Terms of Use, forms part of them, and is the basis for the measures described in section 6.

The general rule fits in one sentence: use the Platform to process data you have the right to process, within the limits of your Plan, without harming third parties or other customers' operations.

1. About the data you connect

It is not permitted to insert, connect or process:

  • data for which the customer has no legal basis, authorisation or right — the most common form of misuse on a data platform, and the one that triggers the indemnity in clause 13.1 of the Terms;
  • sensitive personal data, data of children or adolescents, biometric data, health records or information under a specific statutory duty of secrecy, without the prior assessment required by clause 4.6 of the Terms;
  • content obtained by intrusion, from a leak, by scraping in breach of a third party's terms, or a purchased contact list without a legal basis;
  • third-party data without authorisation, including access credentials that do not belong to the customer.

2. About the operation of the Platform

It is not permitted to:

  • circumvent limits, quotas or controls, including the per-query volume cap and rate limits per API key, per environment or per IP address;
  • create multiple environments to split consumption and escape the Plan;
  • share a credential, API key or published dashboard link so as to give third parties access the Plan does not cover;
  • resell, sublicense or offer the Platform as your own service without written authorisation;
  • use automation that generates load disproportionate to reasonable human use, degrading the service for other customers.

Rate limits and the per-query volume cap are technically enforced. Some announced limits are informational (clause 1.4 of the Terms) — and an informational limit does not authorise the use it describes as a ceiling.

3. About security

It is not permitted to:

  • exploit a vulnerability, attempt unauthorised access, escalate privilege or access another customer's environment;
  • introduce malicious code, or use the Platform to distribute it;
  • carry out penetration testing, scanning or load testing without prior written authorisation — requests to seguranca@ingestia.io;
  • reverse engineer to the extent prohibited by law, or attempt to extract models, system prompts or proprietary logic.

Anyone who finds a flaw in good faith should report it to seguranca@ingestia.io. INGESTIA does not treat a good-faith report as a breach of this Policy.

4. About artificial intelligence

It is not permitted to:

  • use the AI features to produce unlawful, discriminatory or misleading content, or content that infringes a third party's rights;
  • attempt, through a prompt or through inserted data, to make the model ignore system instructions, reveal content from another environment or perform an unauthorised action (prompt injection);
  • use an AI output as the sole basis for a decision affecting people's rights — credit, employment, housing, health, access to a service — without human review. The Terms already prohibit this in clause 5.3; here it is made explicit that it is a breach of acceptable use, not merely a recommendation;
  • present an AI output as if it were a determination by INGESTIA.

5. About communications

It is not permitted to use the Platform's channels — report e-mail, alerts, WhatsApp — to send unsolicited messages to people who have not consented, nor to circumvent an opt-out request. Opt-out is honoured before any send, and circumventing it is a breach.

6. What INGESTIA does in case of a breach

The measure is proportionate to the risk, and the usual order is this:

  1. Notice, with a period to cure, where the breach creates no immediate risk.
  2. Limitation of the feature involved — for example, suspending automated runs while keeping already published content readable.
  3. Suspension of access, where there is a risk to security, to other customers' operations, or unlawful use.
  4. Termination, for a serious or repeated breach, or one not cured within the period.

Immediate security risk, an order of a competent authority or manifestly unlawful use permit suspension without prior notice, communicated afterwards with the reason.

INGESTIA will preserve, as far as possible, reasonable access for data export during a suspension — except where doing so would aggravate the risk that prompted the measure.

7. What this Policy is not

It does not shift to the customer responsibility for a failure of the Platform, nor authorise INGESTIA to inspect the content of Customer Data outside documented instructions and what the DPA provides. Investigating a breach is not a licence to read business data: the enquiry uses the audit trail, telemetry and metadata, and access to content occurs only where indispensable, recorded, and strictly to the extent necessary.

8. Changes and contact

This Policy may be updated; a material change is communicated and takes effect on the date indicated. The version in force, with its date, is at /legal/uso-aceitavel.

Questions and authorisation requests: suporte@ingestia.io · Security: seguranca@ingestia.io