Skip to main content

Lem Cloud Acceptable Use Policy

Version v1.4

Version date 2026-09-08. v1.4 recut integrating the hosted subscription checkout billing route; the TOTP second factor remains per-tenant optional under owner decisions of 2026-08-21; approved for execution at the v1.4 re-cut ceremony of 2026-09-08 (counsel posture carried from owner decision counsel-waiver-decision:2026-09-07-owner-risk-acceptance-v14). The reporting routes that are and are not live are stated in section 9, which controls; no dedicated abuse or authority email address is active.

1. Scope and Interpretation

1.1 This Acceptable Use Policy (the "AUP") forms part of the executed Agreement between Novus Point Limited ("Vendor") and the Customer and applies to the Workspace, Connected Accounts and every feature expressly activated in the Order Form. The Service is not supplied without an executed MSA and Order Form. The Agreement and the Order Form are executed in the manner provided in the Master Services Agreement, including by the Customer's recorded click acceptance of the delivered, versioned contract pack at first Workspace activation, evidenced by the tamper-evident acceptance record described there; references in this AUP to an executed or signed document are read accordingly. Capitalised terms not defined in this AUP have the meanings given in clause 1.1 of the Master Services Agreement. The single order of precedence is in clause 2.5 of that Agreement and is not restated or varied here.

1.2 The Customer is responsible for use of the Workspace by anyone the Customer permits to access it. Instructing the AI operator to do something the Customer may not do directly is itself a breach of this AUP.

2. No Unlawful Use

The Customer must not use the Service, or instruct the AI operator, to:

  • (a) create, store, request or distribute unlawful content, including child sexual abuse or exploitation material; terrorist content; credible threats, incitement or facilitation of violence; trafficking or exploitation; fraud, phishing, impersonation or unlawful goods/services; non-consensual intimate or sexually explicit content or deepfakes; malware; unlawful harassment, hate or defamation; or material infringing privacy, confidentiality or intellectual-property rights;
  • (b) obtain or generate instructions for unlawful activity, including fraud, unauthorised access to systems or data, or the creation of malicious software;
  • (c) violate export-control, sanctions, anti-money-laundering or data-protection law;
  • (d) access, collect or process data the Customer does not control or is not authorised to process, including scraping or accessing third-party accounts without authority;
  • (e) misrepresent AI Outputs as originating from a human where the law requires disclosure, or impersonate any person or organisation.

2A. Intended Purpose and Prohibited AI Uses

2A.1 The permitted intended purpose is administrative assistance for the Customer's ordinary internal business communications and records: reading, organising, summarising and drafting content, with human approval before external email/message sending. The Customer's sector, approved workflows, enabled tools and affected person categories must be recorded in the Order Form. A material change requires prior written review.

2A.2 The Customer must not use or modify the Service for any prohibited practice under Article 5 of the EU AI Act, including harmful manipulation or deception, exploitation of vulnerability, prohibited social scoring, prohibited individual criminal-risk prediction, untargeted scraping to build facial-recognition databases, prohibited emotion recognition, prohibited biometric categorisation or prohibited real-time remote biometric identification.

2A.3 Unless the Vendor has released a separately assessed and expressly contracted compliant feature, the Service must not be used to make or materially support decisions in high-risk domains listed in Annex III of the EU AI Act, including employment/recruitment or worker management, education admission/assessment, access to essential public/private services or creditworthiness, law enforcement, migration/border control, justice or democratic processes. It must not be used for medical diagnosis, emergency dispatch or as a substitute for regulated professional judgment.

2A.4 The Customer must not remove required AI disclosures, provenance information or human-oversight controls, change the system's intended purpose, fine-tune/rebrand it for a restricted use, or represent it as certified or approved by a regulator. The Vendor may keep a restricted use disabled while it assesses whether the change would create provider, deployer, high-risk or substantial-modification obligations.

3. No Unsolicited Commercial Messaging

3.1 The Service must not be used to send or prepare cold or unsolicited commercial marketing, whether individually or in bulk, through email, SMS, Telegram, WhatsApp, calendar invitations, voice or any other channel. Ordinary one-to-one operational communications with existing customers, suppliers, personnel and contacts remain permitted where lawful and expected.

3.2 Any permitted direct marketing requires a separately approved feature and documented lawful route for every recipient class and jurisdiction, including sender identification, consent or other permitted basis, suppression/objection handling, a free opt-out and connected-provider compliance. The UK Privacy and Electronic Communications Regulations, UK GDPR and equivalent recipient-jurisdiction rules remain the Customer's responsibility as Controller. Voice v1 may not be used for outbound calls or marketing.

3.3 The draft-approval gate does not sanitise unlawful sending: approving a prohibited message is a breach of this AUP by the Customer.

4. No Interference with the Platform or Tenant Isolation

The Customer must not:

  • (a) probe, scan, penetrate or test the vulnerability of the Service or its infrastructure except with the Vendor's prior written consent;
  • (b) attempt to access, or interfere with, any Workspace, container, data volume, network segment, secrets scope or backup other than the Customer's own — any attempt to breach per-tenant isolation is a material breach of the Agreement;
  • (c) circumvent authentication, rate limits, usage thresholds, approval gates or other technical controls;
  • (d) introduce malware, or use the Workspace to stage attacks, mine cryptocurrency, run unrelated workloads, or operate as an open proxy or relay;
  • (e) reverse engineer, decompile or extract the Product Layer, except to the extent such restriction cannot lawfully be applied.

5. No Resale or Shared Access

5.1 The Service is provisioned as one Workspace per Customer for the Customer's own internal business use. The Customer must not resell, sublicense, rent, share or otherwise make the Service or Workspace access available to any third party, operate the Workspace as a service bureau, or use one Workspace to serve multiple unrelated businesses or clients, in each case except as expressly agreed in the Order Form.

5.2 Activation/reset links, passwords, TOTP seeds and codes, recovery codes, sign-in messages and active sessions must be kept confidential in accordance with the Agreement and EULA and must not be shared outside the single authorised agent_user.

6. Fair Use of LLM and Model Resources

6.1 Where the Order Form states that model (LLM) usage is included in the recurring subscription fee, that inclusion is on a fair-use basis intended for a single operator's ordinary business workload. Where the Order Form records a customer-owned provider key or pass-through metering, model usage is charged as stated in the Order Form and clause 6.3 applies; the fair-use standard in this clause continues to apply to platform load in every case. Usage that materially exceeds ordinary single-operator patterns — including sustained automated high-volume prompting, load generation, benchmarking without consent, or use of the Workspace as a general-purpose model API — is outside fair use.

6.2 No numeric fair-use threshold applies unless stated in the executed Order Form. The Vendor may apply the minimum temporary limitation reasonably necessary (a) to address an immediate security or abuse risk or a hard provider limit, or (b) where usage materially and demonstrably exceeds the fair-use standard in clause 6.1; in each case the Vendor must notify the Customer without undue delay and must restore ordinary use when the ground ends. Any recurring numeric usage limit or overage charge must be stated in the Order Form before it binds the Customer.

6.3 Where the Customer supplies its own model-provider key, the Customer is responsible for its own provider limits, quotas and charges, and must not use the Vendor-billed model path to evade its own provider's limits (or vice versa).

6.4 The Customer must not attempt to extract model weights or systematically reconstruct training data, and must not use the Service, its AI Outputs, or any benchmark or evaluation of either, to develop, train or improve a competing model, product or service. Those restrictions apply whether or not the conduct also breaches the terms of any third party. Separately, and in addition, the Customer must comply with the usage terms of the model provider enabled for its Workspace as recorded in the Order Form, which the Vendor will make available to the Customer on request; a breach of those provider terms is also a breach of this AUP.

7. Voice Add-On Rules

Where the Customer has purchased and opted into the voice add-on:

  • (a) the Customer must not instruct the AI operator or configure the voice agent to record, intercept or monitor calls or conversations unlawfully, including recording without any consent or notice required by the law applicable to the call participants;
  • (b) where the Customer directs transcription, the Customer is responsible for giving call participants any legally required notice and obtaining any legally required consent; storage of Call audio is disabled in the v1 Voice Add-On (clause 6.4 of the Voice Add-On Addendum) and the Customer must not configure or request it;
  • (c) Voice v1 is inbound-only: the Customer must not use or configure it for outbound dialling, marketing, campaigns, robocalls, call transfer or emergency handling;
  • (d) the Customer must not use or configure the voice agent to clone, synthesise or imitate any real person's voice; cloned and third-party voices, voiceprints, speaker recognition, emotion inference and biometric identification or categorisation are disabled in Voice v1 and may be enabled only under a separately assessed release and express written agreement;
  • (e) voice usage is subject to the fair-use and temporary-limitation provisions of section 6 and to per-minute pass-through charges as stated in the Order Form.

The Vendor gives no advice on, and makes no representation about, the recording, interception, notice or consent requirements of any jurisdiction; those are the Customer's responsibility as Controller and are governed by the counsel-approved jurisdiction matrix referenced in clause 5.3 of the Voice Add-On Addendum.

8. Enforcement

8.1 If the Vendor reasonably believes this AUP has been breached, the Vendor may, proportionately to the breach: issue a warning; throttle or disable the affected feature (including model usage, outbound sending or the voice agent); and, where the breach creates a material legal, security or third-party harm, suspend the Service in accordance with clause 6.3 of the Master Services Agreement or terminate in accordance with clause 6.2 or clause 6.3 of that Agreement.

8.1A Unlawful content. In addition to clause 8.1, where the Vendor becomes aware, including through a report under clause 9, of content or activity in the Workspace that the Vendor reasonably believes to be unlawful or to breach clause 2, the Vendor may exercise the access, preservation, isolation, blocking, removal and reporting rights in clause 6.3B of the Master Services Agreement, subject to the notification, record-keeping and restoration duties stated in that clause. This clause creates no right wider than clause 6.3B of that Agreement and imposes no monitoring obligation on the Vendor.

8.2 Where legally and operationally practicable, the Vendor will give notice and a reasonable opportunity to cure before restriction. Urgent action may be taken without prior notice only to address an immediate legal, security or third-party harm. The decision notice will identify the relevant facts, contractual/legal basis, scope, duration, use of automation and route/deadline for review, except to the extent disclosure is prohibited or would materially compromise security or an investigation.

8.3 The Customer may request a free human review by a person not responsible for the original decision or, where no such person is reasonably available, by the Vendor's most senior available decision-maker on a fresh review of the evidence. The reviewer will consider the Customer's evidence and confirm, vary or reverse the measure with reasons within ten (10) Business Days of receiving the request, or within any shorter period required by applicable law or stated in the Order Form. This process does not create a statutory DSA/OSA appeal unless the Service is determined to fall within that regime.

8.4 Authority requests. Preservation and disclosure are separate acts. Before disclosure, the Vendor will verify, so far as reasonably possible, the requesting authority, jurisdiction, legal basis, scope and necessity; disclose only the minimum required; preserve the request and response record; and notify the Customer before disclosure where lawful and practicable. DPA and applicable-law restrictions continue to apply.

8.5 Customer duties on breach. The Customer shall (a) notify the Vendor without undue delay on becoming aware of any actual or suspected breach of this AUP or misuse of the Workspace; (b) provide reasonable cooperation and information for any Vendor investigation of such a breach or of a report under clause 9; and (c) at the Vendor's reasonable written request, preserve material relevant to that investigation pending its conclusion. This clause imposes obligations on the Customer only; it does not qualify, condition or reduce any right of the Vendor under clauses 8.1, 8.1A, 8.2, 8.3 or 8.4. Failure to comply with this clause is a breach of this AUP.

9. Reporting

Suspected abuse, security issues or AUP violations may be reported by the Customer or by an affected third party who has no support relationship with the Vendor. Until the dedicated abuse mailbox is live, a report may be sent by post to Novus Point Limited (company number 08146241) at its registered office as recorded on the Companies House register, marked for the attention of "Abuse and Security"; a Customer may in addition use the abuse / AUP reporting contact stated in its executed Order Form.

A dedicated abuse and security email address, and a separate legal and authority-request address, will be stated in this AUP only at approved publication, and in the effective public notice at that time. Each route is published only once it exists and delivers, a recorded inbound-delivery test and response test have been completed, a named primary decision owner, an independent reviewer and deputies are in place, and the restricted case register and escalation coverage described in the Vendor's abuse procedure are operating. No dedicated abuse or authority email address is active until the conditions above are met; until then the postal route above is the route for reports.

A report should identify the Workspace/message/content where possible, the concern and supporting information, and a contact for follow-up. The Vendor will assess reports it receives in accordance with its abuse procedure once that procedure is activated. No acknowledgement, response or resolution time applies unless separately activated in writing.

10. Changes

For an existing Customer, a contractual change to this AUP requires the bilateral written variation and signed supplemental-manifest process in clause 20.4 of the Master Services Agreement. Updating a website, notice, Documentation page or later source file does not amend the frozen AUP. The Vendor may deploy an urgent security restriction under clauses 3.5 and 6.3 of the Master Services Agreement without retrospectively reducing accrued rights. The Vendor may amend this AUP on not less than thirty (30) days' written notice where the amendment is required by applicable law or by a regulator, is required by the terms of an active provider, or is reasonably necessary to address a security or abuse risk. The amendment takes effect at the end of the notice period. If the amendment materially and adversely affects the Customer, the Customer may terminate the affected Order Form on written notice before that date and receive a pro-rata refund of prepaid unused recurring Fees. This right is the exception permitted by clause 20.4 of the Master Services Agreement.


Related documents: Terms of Service · Privacy Notice · Refund & Cancellation Policy · Service Level Agreement (sla.md) · Third-Party Notices (ship with the product).