LegalAcceptable Use

Acceptable Use Policy

What responsible use of Riskscape data and APIs looks like - restricted data, prohibited conduct and how we enforce the rules.

Contents
Effective date
Last updated

This Acceptable Use Policy (AUP) protects Riskscape, our customers, data subjects, data partners, and the reliability of the Services. It applies to every user, API request, integration, upload, download, query, and use of Riskscape data or output. It forms part of the Terms of Service.

1. Lawful and authorised use

You may use the Services only for lawful, authorised purposes within your plan, order, documentation, and data licence. You must obtain all notices, consents, licences, permissions, and lawful grounds required for Customer Data and your use of output.

You may not use the Services to violate POPIA, consumer-protection, credit, insurance, intellectual-property, privacy, anti-discrimination, cybersecurity, sanctions, export-control, or other applicable laws or third-party rights.

2. Restricted data

Do not submit or expose through the Services:

  • full payment-card details, CVVs, bank credentials, EFT PINs, one-time passwords, or private cryptographic keys;
  • passwords or live authentication credentials for another service;
  • health, biometric, precise active-tracking, children's, or other special or highly sensitive personal information;
  • government identifiers combined with information that creates a material identity-theft or privacy risk; or
  • unlawfully obtained, confidential, or proprietary data.

This restriction does not apply where a particular Service and written agreement expressly authorise the data type and appropriate security, lawful-processing, and data-handling requirements are in place. If restricted data is submitted accidentally, stop processing, secure the exposure, and notify info@riskscape.pro immediately.

3. Prohibited conduct

You must not:

  • introduce malware, ransomware, malicious code, destructive content, or hidden access mechanisms;
  • probe, scan, test, exploit, or bypass security or authentication without our prior written authorisation;
  • access another customer's account, data, keys, or systems;
  • intercept traffic, forge requests, impersonate another person, or misrepresent authority;
  • share credentials outside authorised users or publish API keys in client-side code or public repositories;
  • evade quotas, rate limits, usage meters, billing, access controls, or plan restrictions;
  • overload, disrupt, degrade, or interfere with the Services or another user's use;
  • scrape or extract data outside documented APIs and download functions;
  • reverse engineer, decompile, discover, copy, or reconstruct non-public source code, models, scoring logic, datasets, or security mechanisms, except to the limited extent law does not permit restriction;
  • re-identify, or attempt to re-identify, a person from aggregated, anonymised, pseudonymised, or de-identified information;
  • combine output with other data in a way that creates an unlawful or disproportionate surveillance or profiling capability;
  • resell, sublicense, redistribute, publish, or build a competing database, API, model, or service from Riskscape data unless a written licence permits it;
  • use the Services to send spam, phishing, deceptive communications, or unsolicited direct marketing;
  • use the Services to facilitate fraud, identity theft, stalking, harassment, discrimination, property crime, environmental harm, or physical harm; or
  • conceal a breach or give false information during a security, billing, or compliance investigation.

4. High-impact decisions

Riskscape output may assist decisions concerning property, lending, insurance, infrastructure, environment, and other significant matters. You must not use output as the sole basis for a decision that has legal or similarly significant effects on a person where law or fairness requires additional safeguards.

You are responsible for:

  • assessing whether the data is relevant, current, sufficiently accurate, and suitable for the use;
  • testing for inappropriate bias, proxy discrimination, and disparate impact;
  • using qualified human review and additional evidence where appropriate;
  • giving notices, reasons, access, correction, objection, or appeal rights where required; and
  • avoiding use for a prohibited or unfair discriminatory purpose.

5. API and platform integrity

Use documented authentication and supported integration methods. Respect rate limits, concurrency controls, pagination, caching rules, retry guidance, and reasonable-use limits.

Your integration should use secure secret storage, least-privilege access, encrypted transport, safe logging, input validation, timeouts, bounded retries, and monitoring. Do not log or expose API keys, restricted Customer Data, or complete sensitive responses unnecessarily.

If your use creates unusual load or risk, we may require a technical remediation plan, reduce limits temporarily, or move you to an appropriate capacity plan.

6. Data ownership and permitted sharing

Do not remove copyright, licence, source, confidence, date, or attribution notices. Preserve material limitations when sharing permitted conclusions or derived output.

You may share output only as allowed by your plan or order. Internal use does not authorise making raw data, bulk extracts, credentials, or a substitute data service available to affiliates, clients, contractors, or the public.

7. Security incidents and vulnerability reporting

Promptly report suspected credential exposure, unauthorised access, data leakage, or a vulnerability affecting Riskscape to info@riskscape.pro. Provide enough detail to investigate and avoid public disclosure until we have had a reasonable opportunity to address the issue.

Good-faith security research requires prior written authorisation defining scope, methods, timing, data handling, and disclosure. This AUP does not itself grant testing permission.

8. Enforcement

We may investigate suspected violations and preserve relevant evidence. We may rate-limit, block a request, remove content, rotate credentials, restrict a feature, suspend access, or terminate the affected Service where reasonably necessary.

Where practicable, we will notify you and allow a reasonable opportunity to remedy the violation. We may act immediately where delay could cause harm, compromise security, violate law or third-party rights, or threaten the Services. We may report unlawful conduct to affected parties or authorities where required or permitted by law.

You remain responsible for charges incurred before enforcement and for reasonable costs or losses recoverable under the Terms and applicable law.

9. Contact

Questions, permission requests, and incident reports: info@riskscape.pro

Riskscape (Pty) Ltd
Unit A-1002A, First Floor, Corobay, corner Aramist and Corobay Avenue, Menlyn, Pretoria, Gauteng, 0181, South Africa

Questions about this policy?

Talk to us about data licensing, processing agreements, security reviews or anything else in this document.