DRAFT v1.0 — prepared for review by qualified counsel before publication. Replace bracketed placeholders.
Version: 1.0 Effective date: [EFFECTIVE DATE] Published at: flowagenci.com/legal/acceptable-use
This Acceptable Use Policy ("AUP") sets out the rules for using Flow (the "Service"), provided by [FLOWAGENCI LLC LEGAL NAME] ("FlowAgenci", "we"). It is part of the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
The AUP applies to:
- the Customer
- its Authorized Users
- its Portal Users
- anyone else who accesses the Service, including through public forms
The Customer is responsible for ensuring that its Authorized Users and Portal Users comply with this AUP.
1. Illegal, harmful or infringing content
You may not use the Service to store, share, send or display content that:
- is illegal, or promotes or facilitates illegal activity, in the jurisdictions where you or your recipients are located.
- infringes intellectual property or other rights. This includes uploading or distributing copyrighted material, trademarks, fonts, stock images or software that you do not have the rights to use. Agencies must hold appropriate licenses for the assets they deliver to their clients.
- is child sexual abuse material (CSAM) or sexualizes minors in any way. We have zero tolerance. We will remove such content, terminate the associated accounts immediately and report it to the competent authorities, including the U.S. National Center for Missing & Exploited Children (NCMEC).
- harasses, threatens, defames or intimidates any person, or incites violence or hatred against individuals or groups based on protected characteristics.
- violates the privacy of others. Examples are publishing someone's Personal Data without a lawful basis, or covertly collecting data about Portal Users or third parties.
- is deceptive or fraudulent. Examples are fake invoices, impersonation of another person or company, or fraudulent payment requests.
2. Malware, phishing and security abuse
You may not:
- upload or distribute malware, viruses, ransomware, spyware or any other malicious code. Files uploaded to the Service are scanned. Infected files are quarantined, and repeated uploads may lead to suspension.
- use the Service for phishing. Examples are Client Portals, forms, emails or documents designed to collect credentials, payment details or other sensitive information under false pretenses.
- attempt to gain unauthorized access to the Service, other Customers' organizations, accounts or data, or our infrastructure.
- probe, scan or test the vulnerability of the Service, or breach or circumvent any security or authentication measure, except as permitted under Section 6 (Responsible disclosure).
- interfere with or disrupt the Service. This includes denial-of-service attacks, flooding, overloading and exploiting bugs to degrade performance for others.
3. Spam and abuse of communications
The Service sends emails and notifications on your behalf, such as invitations, review requests, asset requests, documents, invoice notices and reminders. You may not:
- send spam or unsolicited bulk or marketing messages through the Service. The communication features are for transactional communication with your team and your existing or prospective clients about actual work.
- invite Portal Users or send documents to people who have no business relationship with you, or who have asked not to be contacted.
- bypass "do not contact" markings. You may not remove them in order to message people who have opted out, and you may not otherwise circumvent recipient preferences or unsubscribe mechanisms.
- use misleading sender names, subject lines or content, or use the Service to impersonate another agency or brand.
- abuse public forms. Examples are submitting automated or fraudulent entries to another Customer's forms, or using your own forms to harvest data unrelated to your services.
We may apply sending limits and pause outbound email for an organization when bounce or complaint rates indicate abuse.
4. Scraping, limits and reselling
You may not:
- scrape, crawl or harvest data from the Service or from other Customers' Client Portals by automated means, except through APIs and exports we provide for that purpose.
- circumvent Plan limits or technical limits. Examples are sharing a single seat among several people, creating multiple organizations or trials to avoid paying, or evading rate limits, storage quotas or file-size limits.
- use the Service primarily as general-purpose file hosting, a content delivery network or backup storage unrelated to your agency work.
- resell, sublicense or white-label the Service to third parties as a standalone product, or provide it as a service bureau, without a written agreement with us. Serving your own clients through your Client Portal is, of course, permitted.
- access the Service to build a competing product, or to benchmark it for publication without our consent.
5. Sensitive data
The Service is built for agency work. It is not designed to store the following categories of data, and you may not submit them except as incidental content within ordinary business documents:
- payment card numbers (the Service is not PCI DSS–certified for card storage)
- bank account passwords, online banking credentials or other authentication secrets
- government identification numbers, beyond the tax identifiers normally shown on business documents (such as a company's tax ID)
- health data, biometric data, and other special or sensitive categories of Personal Data
- data about children under the age of 16
If your work requires handling such data, contact us first at privacy@flowagenci.com.
6. Responsible disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, report it to security@flowagenci.com and follow these rules:
- Test only against your own account and organization, or against accounts for which you have explicit permission.
- Do not access, modify or delete data belonging to others. If you encounter such data, stop and report it.
- Do not use automated scanners that generate significant traffic, and do not carry out denial-of-service, social-engineering or physical attacks.
- Give us reasonable time to fix the issue before disclosing it publicly.
We will not pursue legal action against good-faith research that follows these rules.
7. Responsibility for Portal Users and Authorized Users
The Customer is responsible for the conduct of the people it invites to the Service:
- Authorized Users: the Customer's team members and guests.
- Portal Users: the Customer's clients and contacts.
If a Portal User or Authorized User violates this AUP, we may ask the Customer to take action, such as revoking that person's access. We may also restrict the person's access directly.
8. Enforcement
If we become aware of a violation, we may take any of the following actions, taking into account the severity and whether the conduct is repeated:
- Warning: notify the organization owner and ask for the issue to be corrected.
- Content removal: remove or disable access to the offending content. Files flagged as malicious are quarantined automatically.
- Restriction or suspension: temporarily limit features, such as outbound email or public forms, or suspend specific users or the whole organization, as described in the Terms.
- Termination: terminate the Subscription for severe or repeated violations, as described in the Terms.
- Reporting: report illegal activity to the competent authorities, and cooperate with lawful requests.
We try to give notice and an opportunity to fix the problem before suspending, unless the violation is severe, poses a security risk or involves illegal content.
9. Reporting abuse
To report a violation of this AUP, including spam or phishing sent through Flow, or content in a Client Portal, write to abuse@flowagenci.com. Include as much detail as possible, such as URLs, the sender, dates and screenshots. For security vulnerabilities, use security@flowagenci.com.
10. Changes
We may update this AUP from time to time. Material changes will be announced as described in the Terms. The current version is always available at flowagenci.com/legal/acceptable-use.