Acceptable Use Policy
1. Scope
This Policy forms part of the ULOX Business Terms of Service and binds the Customer and all its Authorised Users. The Customer is responsible for communicating it within its organisation and ensuring compliance.
2. A necessary reminder
ULOX Business cannot monitor content: end-to-end encryption prevents it by design. That technical impossibility is not an authorisation. The Customer is fully responsible for the lawfulness of what its organisation stores and transmits, and the absence of monitoring does not preclude investigation or prosecution by the competent authorities.
3. Prohibited uses
It is strictly prohibited to use the Service to:
- Carry out activities unlawful under Spanish law, European Union law or the law of the Customer's or its users' country.
- Store, transmit or distribute child sexual abuse material, or any content harmful to minors.
- Promote terrorism, violence, genocide, hatred or discrimination on grounds of origin, ethnicity, religion, sex, sexual orientation, gender identity, disability or any other status.
- Infringe third-party intellectual or industrial property rights.
- Commit fraud, deception, identity theft, extortion or money laundering.
- Breach the secrecy of communications or the privacy of third parties, including covert monitoring of employees without the information and safeguards required by employment and data protection law.
- Distribute malware, intrusion tools or command-and-control infrastructure.
- Send unsolicited bulk communications through the Service's invitation or email features.
4. Responsible technical use
- Do not circumvent, disable or tamper with authentication, encryption, capacity limits or access control mechanisms.
- Do not reverse engineer the Service or attempt to extract cryptographic material, save with the Provider's written authorisation.
- Do not conduct penetration testing, scanning or denial-of-service attacks without a prior written agreement defining the scope.
- Do not share credentials between people: each Authorised User must have their own, and each Seat enables one person only.
- Do not use the Service as a public file distribution platform unrelated to the organisation's activity, or in a way that degrades service quality for other customers.
- Use the programming interfaces in accordance with their documentation and published usage limits.
5. Responsible vulnerability disclosure
If the Customer or any of its users discovers a vulnerability, it must report it to abuse@ulox.org without exploiting it beyond what is strictly necessary to demonstrate it, without accessing third-party data and without public disclosure until it has been fixed or a reasonable period agreed between the parties has elapsed. The Provider welcomes and acts on such reports and will take no action against anyone acting in good faith under this section.
6. Consequences of breach
In the event of a breach, and depending on its seriousness, the Provider may: require that it cease, suspend the Service in whole or in part, terminate the agreement under the Terms and, where appropriate, report the facts to the competent authorities.
Given the blind server model, the Provider's action will necessarily rest on external information available to it — authority requests, substantiated third-party reports or communications from the Customer itself — and will consist of measures affecting access and the account, never the content, which it cannot access.
The Customer shall indemnify and hold the Provider harmless against claims arising from breach of this Policy, on the terms of the Terms of Service.
7. Contact
- Abuse, security and compliance:
abuse@ulox.org - Legal matters:
legal@ulox.org
