Acceptable Use Policy
Effective July 29, 2026 · last updated July 29, 2026
This policy forms part of the Terms of Service and applies to everyone who uses the platform. It is written to be read by the people actually using the software, not only by the people who signed the contract, because those are the people it constrains.
Who this applies to
This policy applies to the customer organization, to every user within it, and to anyone reaching the platform through a link a customer issues. A customer is responsible for its users' compliance, and for the conduct of external recipients it invites in.
Nothing here is intended to interfere with the ordinary business of running events. If a legitimate thing you need to do appears to be prohibited below, tell us and we will look at it. The policy exists to stop abuse, not to make the software awkward.
Prohibited use
You may not use the platform to:
- break any applicable law, or facilitate someone else doing so;
- infringe copyright, trade marks, database rights, privacy rights or confidentiality obligations;
- attempt to access another organization's data, another user's account, or any part of the system you have not been granted access to;
- probe, scan, disrupt, overload or degrade the platform or the infrastructure it runs on, including through denial-of-service traffic or excessive automated requests;
- reverse-engineer, decompile or attempt to derive the source code of the platform, or circumvent a license limit, plan restriction, permission check or rate limit;
- resell, sublicense or provide the platform to a third party as a service of your own;
- upload malware, or content designed to interfere with a system or exploit a vulnerability;
- impersonate another person or organization, or misrepresent your affiliation;
- store or transmit content that is harassing, defamatory, discriminatory, or that depicts or promotes the abuse or exploitation of any person;
- benchmark or publish comparative performance data about the platform without our written consent.
Data you upload
You must have the right to submit the data you submit, and the lawful basis and notices that data protection law requires for it. Two categories deserve specific attention because the platform makes them easy to collect:
- Dietary requirements and allergies are special category data concerning health. Collect them for catering and duty of care, with the attendee's explicit consent or another Article 9(2) condition, and do not repurpose them.
- Staff location at check-in. If you enable time tracking, tell your staff before you do, explain what is recorded and why, and comply with the consultation and notice obligations that apply to monitoring workers in your jurisdiction.
Do not use the platform as a repository for categories of data it was not built for: payment card numbers outside the billing flow, government identity documents beyond what a program genuinely requires, medical records, or credentials for other systems.
Email and messaging
The platform sends email on your behalf: invitations, proposals, advisories, digests. You may send only to people who have a genuine relationship with you or your program, and you must honor opt-outs and applicable marketing law.
Do not use the platform for unsolicited bulk email, cold marketing campaigns, or any list you did not build yourself. It is program communication infrastructure, not a mass-mailing tool, and abuse of it damages deliverability for every other customer on the same sending infrastructure.
Portals and shared links
Vendor, client, driver, photographer and guest portals reach real people who never agreed to anything with us. Treat those links accordingly: send them only to the intended recipient, revoke them when the engagement ends, apply a password where the content warrants it, and do not use a portal to expose one client's information to another. Client-facing surfaces are built to exclude your cost and margin structurally. Do not work around that and then treat the result as our problem.
AI features
Do not attempt to extract system instructions, bypass the assistant's permission checks, or use it to reach data your account is not entitled to. Do not use AI features to generate content that is unlawful, deceptive, or presented to a client as human-authored where that misrepresentation matters.
Check the output. Model output is a draft: proposals, costings, parsed manifests, transfer plans and research summaries need a competent person to verify them before they go to a client or drive a decision, and nothing about safety, immigration, insurance or money should rest on an unreviewed generation.
API and automated access
API access on the Enterprise plan uses scoped keys with per-key rate limits and auditing. Keep keys secret, scope each to the least it needs, rotate them when someone with access leaves, and revoke a key you believe is exposed. Do not share a key between systems, embed one in client-side code, or use automated access to circumvent a rate limit or plan allowance.
Do not scrape the platform's interface as a substitute for the API, and do not use automated access in a way that materially degrades service for others.
Security research
We welcome vulnerability reports and will not pursue action against research conducted in good faith under our disclosure policy. In good faith means: use only accounts and data you own or have permission to test; stop at proof of a vulnerability rather than pivoting deeper; never access, modify, exfiltrate or retain another organization's data; do not run denial-of-service or load tests; do not use social engineering or physical intrusion; and give us reasonable time to fix an issue before disclosing it.
Report to security@dmcpilot.com. We will acknowledge, keep you informed, and credit you if you would like.
How we enforce this
We do not monitor the content of your data, read your messages or inspect your documents to police this policy. Where a breach is reported to us or becomes apparent through normal operation, we investigate.
Our response is proportionate, and in this order wherever it is safe to be:
- we contact you and explain what we have found;
- we agree a remedy and a timeframe;
- we restrict the specific capability being abused;
- we suspend access;
- we terminate, in accordance with the Terms.
We will skip ahead only where there is an active security threat, a legal requirement, or a risk of serious harm to someone, and we will tell you what we did and why. We will not suspend a customer mid-program over a matter that could wait, because the people affected by that are travelers and event staff who did nothing wrong.
Reporting abuse
To report misuse of the platform, email legal@dmcpilot.com. For a security vulnerability, email security@dmcpilot.com. For a privacy concern, email privacy@dmcpilot.com. Tell us what you saw and where; we will confirm receipt and investigate.
Questions about this document: legal@dmcpilot.com. Privacy requests: privacy@dmcpilot.com. Security reports: security@dmcpilot.com.