daat.red ← back to site

Acceptable Use Policy

Last updated: [effective date]

This Acceptable Use Policy ("AUP") governs the use of the daat.red service (the "Service"), operated by Red Code Company, s.r.o., IČO 22385151, Děčínská 552/1, Střížkov, 180 00 Prague 8, Czech Republic.

The AUP is incorporated into and forms part of the Terms of Service. Capitalised terms not defined here have the meaning given in the Terms of Service. This AUP applies to the Client, to every user of the Client's Account, and to anyone using an API Key issued to the Client.

We may update this AUP from time to time. Material changes will be notified in accordance with the Terms of Service.

1. General principles

The Service provides pre-authorization payment-data and identity-verification checks. It is intended to be used by businesses as one input into a genuine transaction-risk, fraud-prevention, onboarding or compliance decision relating to the Client's own customers and transactions. Any use that is inconsistent with that purpose, or that is unlawful, abusive, deceptive or harmful, is prohibited.

The Client must use the Service and the Results:

2. Prohibited uses — fraud, financial crime and circumvention

The Client must not use the Service, or any Result, to:

2.1 facilitate, enable, test or conceal payment fraud, card-testing, carding, account-takeover, identity theft, or any unauthorised transaction;

2.2 assist money laundering, terrorist financing, sanctions evasion, or any breach of anti-money-laundering, counter-terrorist-financing or sanctions law;

2.3 circumvent, defeat or test the controls of a card network, payment system, issuer, acquirer, bank or other institution, including fraud checks, authentication requirements, chargeback rules or transaction limits;

2.4 validate, enrich or "clean" stolen, illegally obtained or unlawfully compiled card data, personal data or credential lists;

2.5 determine whether stolen or leaked payment credentials are live or usable;

2.6 evade detection, blocking or enforcement by us, by a card network, or by a competent authority.

3. Prohibited uses — data protection and privacy

The Client must not:

3.1 perform a lookup for which it does not have a valid lawful basis, or for which the required notice or consent has not been given;

3.2 use name, email, IP or other enrichment data to build, enrich or trade consumer profiles that are not tied to a genuine transaction-risk decision about that individual's dealings with the Client;

3.3 use the Service for marketing, advertising, list-building, lead generation, credit scoring, insurance pricing, employment screening, tenant screening or similar profiling, unless expressly agreed with us in writing and supported by the Client's own lawful basis;

3.4 use email, IP or name data to track, surveil, locate, deanonymise or dox an individual, or to enable stalking, harassment or intimidation;

3.5 use the Email check or Email info methods to verify or grow mailing lists for unsolicited communications (spam), or in a way that breaches applicable electronic-communications or anti-spam law;

3.6 submit special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR), except to the extent inherent in the ordinary data elements the API accepts;

3.7 process the personal data of children through the Service without an appropriate lawful basis and safeguards;

3.8 combine the Results with other data in a way that produces a decision with legal or similarly significant effect on an individual that is taken solely by automated means without the safeguards required by Article 22 GDPR.

4. Prohibited uses — data extraction and competition

The Client must not:

4.1 carry out bulk or automated querying, harvesting, scraping or enumeration (for example iterating over BIN ranges, email addresses or IP ranges) beyond what is necessary to screen the Client's own genuine transactions and accounts;

4.2 cache, store or accumulate the Results beyond what is necessary for the Client's own decision-making and record-keeping, or in order to reduce legitimate API usage;

4.3 resell, sublicense, redistribute, publish or otherwise make available the Results, or provide access to the Service, to any third party;

4.4 use the Service or the Results to build, train, benchmark or improve a competing product or service, or to create an independent or derived dataset (for example a BIN database, an email-reputation database or an IP-intelligence database) for internal distribution or external supply;

4.5 use the Service on behalf of an undisclosed third party, or as a "white-label" service, without our prior written consent.

5. Prohibited uses — security and integrity of the Service

The Client must not:

5.1 probe, scan, penetration-test, load-test, fuzz or stress-test the Service, or attempt to discover or exploit vulnerabilities, without our prior written permission;

5.2 attempt to gain unauthorised access to the Service, other accounts, or the underlying systems, networks or data;

5.3 share, publish, sell or transfer API Keys, or embed them in client-side, public, mobile-distributed or otherwise exposed code;

5.4 interfere with or disrupt the Service, circumvent rate limits, quotas or authentication, or impose an unreasonable or disproportionately large load on the infrastructure;

5.5 introduce malware or malicious code, or use the Service to distribute it;

5.6 misrepresent identity or affiliation, forge headers, or falsify the origin of requests.

6. Prohibited uses — intellectual property and lawfulness

The Client must not use the Service or the Results to:

6.1 infringe the intellectual property, privacy, publicity, contractual or other rights of any person;

6.2 engage in any activity that is unlawful in the jurisdiction of the Client, of the relevant user, or of the data subject, or that would cause us to breach a law or a contractual obligation to a card network or payment system;

6.3 support any business or activity that we have notified the Client is not permitted on the Service.

7. Responsibility for users and third parties

The Client is responsible for all use of the Service under its Account and API Keys, and for ensuring that its personnel, contractors and any permitted users comply with this AUP. The Client must have appropriate internal controls, staff training and monitoring in place.

8. Monitoring and enforcement

8.1 We do not routinely monitor the content of individual API requests. We do monitor usage patterns, volumes and error rates for security, billing and abuse-prevention purposes.

8.2 If we reasonably believe that a use breaches this AUP, or that a use creates legal, security, reputational or regulatory risk for us, a card network or a payment system, we may, with or without prior notice depending on the severity and urgency:

8.3 We will use reasonable efforts to notify the Client of enforcement action and to limit action to what is necessary, except where notice is prohibited by law or would prejudice an investigation or the security of the Service.

8.4 Suspension or termination for an AUP breach does not entitle the Client to a refund of consumed Credits, and does not limit our other rights and remedies.

9. Reporting abuse

To report suspected misuse of the Service, a security concern, or a suspected compromise of an API Key, contact:

[abuse reporting mailbox — suggested abuse@daat.red]

For security-vulnerability reports: [security contact / disclosure policy — suggested security@daat.red].