Acceptable Use Policy
The rules for acceptable and prohibited use of the Viktor service.
Last Updated: July 31, 2026
This Acceptable Use Policy forms part of, and is incorporated by reference into, the Viktor General Terms of Service. Capitalized terms used but not defined herein have the meanings given in the Definitions.
1. Acceptable Use
Customer shall not, and shall ensure that its Authorized Users do not, use the Service to:
(a) violate any applicable law, including export-control laws (such as the Export Control Reform Act of 2018, U.S. Export Administration Regulations and sanctions administered by the U.S. Office of Foreign Assets Control), anti-spam laws (including the CAN-SPAM Act of 2003), data-protection laws, or laws prohibiting unauthorized access to computer systems;
(b) infringe or misappropriate any intellectual property right, publicity right, privacy right, or other right of any third party;
(c) transmit malware, viruses, ransomware, or other malicious code, or perform denial-of-service attacks, scraping, or unauthorized penetration testing;
(d) generate, transmit, or facilitate spam, phishing, or other deceptive or fraudulent communications;
(e) generate or distribute content that is defamatory, harassing, threatening, hateful, obscene, or that exploits or endangers minors;
(f) circumvent rate limits, usage restrictions, security measures, or access controls;
(g) access or use the Service to build a competing product or to benchmark against Provider’s offering for the purpose of public publication of comparative claims;
(h) use the Service if Customer or any Authorized User is located in, ordinarily resident in, or organized under the laws of a country or territory subject to comprehensive U.S. sanctions, or is listed on any U.S. government denied-party list (including the OFAC Specially Designated Nationals and Blocked Persons List);
(i) impersonate any person or entity, or misrepresent Customer’s identity, affiliation, authority, or the origin of any communication;
(j) use the Service in any high-risk context where failure or misuse could reasonably result in death, personal injury, or severe physical, environmental, property, financial, regulatory, or reputational harm.
2. Investigation and Enforcement
Provider may, but is not obligated to, investigate suspected violations of this Acceptable Use Policy and may remove content or suspend access in accordance with this Acceptable Use Policy and Section 10 of the General Terms. Action taken by Provider under this Section gives rise to no claim by Customer.
3. Prohibited Data Categories
The Service is not designed, certified, or intended to process Regulated Data. Customer shall not submit to the Service:
(a) protected health information (“PHI”) as defined under the Health Insurance Portability and Accountability Act (“HIPAA”) or equivalent health-data regulation;
(b) payment-card data subject to PCI DSS;
(c) non-public personal financial information subject to the Gramm-Leach-Bliley Act (“GLBA”) or equivalent financial-privacy law;
(d) special categories of personal data as defined under GDPR Article 9 (including health, biometric, racial or ethnic origin, religious belief, and criminal-conviction data);
(e) data of children under sixteen (16) years;
(f) data subject to export-control restrictions, including the U.S. Export Administration Regulations and the International Traffic in Arms Regulations (ITAR);
(g) any other data subject to sector-specific legal requirements imposing safeguards not expressly provided in the General Terms, the Product Terms, or the DPA
(collectively, “Regulated Data”).
Customer assumes full liability for any regulatory exposure arising from breach of this Section 3, including penalties, claims, and remediation costs. If Customer requires the Service to process Regulated Data, the Parties must execute a separate written addendum (such as a HIPAA Business Associate Agreement) before any such data is submitted. Provider may suspend or terminate the Service immediately upon discovery of Regulated Data without cure period.