Home Legal AUP

Acceptable Use Policy

Version 1.0

The rules of the road for the Utilitarian platform: account security, permitted and prohibited conduct, CRM and email integration, API usage, and data handling.

This Acceptable Use Policy (“AUP”) is incorporated into and forms part of the Utilitarian Platform Terms of Service (“Terms”). It applies to all users of the Utilitarian platform, including administrators, managers, viewers, and any person accessing the platform through your account.

Capitalised terms not defined here have the meaning given in the Terms. References to “you” include your organisation and all users on your account.

1. Account Security

1.1 Credentials

You must keep your login credentials confidential and must not share them with anyone, including colleagues. Each person who needs access to the platform should have their own account, created through the invite system or self-registration.

1.2 Shared accounts

Shared or generic login accounts (such as “info@company.com” used by multiple people) are not permitted. Each account must correspond to one identifiable person.

1.3 Compromised credentials

If you believe your credentials have been compromised, you must reset your password immediately and notify Utilitarian at security@utilitarian.world. You are responsible for all activity on your account until you report the compromise.

1.4 Access management

Administrators are responsible for promptly removing access for users who leave your organisation or no longer require platform access. Utilitarian is not responsible for actions taken by former employees or contractors who retain access due to delayed deprovisioning.

2. Permitted Use

The platform is provided for the purpose of operating product take-back programmes, managing customer engagement, viewing programme data and reporting, and related commercial activities as described in the Terms. You may use the platform only for these purposes and in accordance with these rules.

3. Prohibited Conduct

You must not, and must not permit others to:

3.1 Unlawful or harmful use

  • Use the platform for any purpose that violates applicable law or regulation.
  • Use the platform to facilitate fraud, money laundering, or any other criminal activity.
  • Use the platform in a way that could harm Utilitarian, its infrastructure, other clients, or third parties.

3.2 Platform integrity

  • Attempt to reverse-engineer, decompile, disassemble, or extract source code from the platform.
  • Interfere with the security, integrity, availability, or performance of the platform.
  • Circumvent or attempt to circumvent access controls, authentication mechanisms, or usage limits.
  • Introduce malware, viruses, or other harmful code.
  • Probe, scan, or test the vulnerability of the platform without prior written authorisation from Utilitarian.

3.3 Data extraction and scraping

  • Use automated tools, scripts, bots, or scrapers to bulk-extract, copy, or harvest data from the platform, except through published and documented APIs.
  • Systematically download, cache, or store platform data for use outside the platform, except through authorised export features.
  • Attempt to access data belonging to other clients or users.

3.4 Content and uploads

  • Upload or transmit content that infringes third-party intellectual property rights.
  • Upload content that is unlawful, defamatory, obscene, or otherwise objectionable.
  • Deliberately upload prohibited content (such as images of people, identity documents, or sensitive personal information) that is designed to evade the platform’s screening and quarantine workflow.
  • Use the platform to process special category data (as defined in GDPR Article 9) except where this occurs incidentally through customer uploads and is handled through the screening and quarantine workflow described in the Terms.

3.5 Misrepresentation

  • Impersonate another person, organisation, or Utilitarian employee.
  • Misrepresent your identity, role, or authorisation level when accessing the platform or communicating with Utilitarian.
  • Create accounts using false or misleading information.

4. CRM and Email Integration

If your Service Order includes API or CRM integration (Tier 2 or Tier 3), the following rules apply to your use of customer data obtained through the platform:

4.1 Consent

You must only send marketing communications to customers who have provided valid, GDPR-compliant consent through the platform’s opt-in mechanism. The platform records consent at the point of capture. You must not add customers to marketing lists without this consent.

4.2 Anti-spam

You must not use email addresses captured through the platform to send unsolicited bulk email, unrelated marketing, or communications that do not relate to your take-back programme or retail relationship with the customer.

4.3 Unsubscribe obligations

You must honour unsubscribe requests promptly and in accordance with applicable law. Where the platform provides an unsubscribe mechanism, you must not circumvent it or re-add unsubscribed customers without fresh consent.

4.4 Data minimisation

You must only export or sync the minimum customer data necessary for your stated programme purpose. You must not use the platform as a general-purpose data harvesting tool.

5. API Usage

If your Service Order includes API access:

  • Rate limits. You must respect published rate limits. Sustained traffic above documented thresholds may be throttled or blocked without notice.
  • Authentication. API keys and tokens must be stored securely and must not be embedded in client-side code, shared publicly, or committed to public repositories.
  • Fair use. API access is for integration with your systems in support of your take-back programme. You must not use the API to build a competing product or service, or to provide platform functionality to third parties.

6. Dashboard and Reporting Data

6.1 Internal use

Data and reports accessed through the platform dashboard are for your internal business use. You may share reports within your organisation and with your professional advisors.

6.2 External sharing

You must not publicly disclose Utilitarian’s proprietary benchmarking data, anonymised industry insights, or platform performance metrics without prior written consent from Utilitarian. You may share your own programme data (such as your store-level results) at your discretion.

6.3 Brand access data

If you are a retailer providing brand access (Tier 3), you control which brands can view which data through your account settings. You are responsible for ensuring that the data you make accessible to brands is appropriate and that any data-sharing arrangements with brands comply with applicable law.

7. Multi-User and Role-Based Access

The platform supports multiple user roles (admin, manager, viewer). You must assign roles according to the principle of least privilege: users should have only the access they need for their function. Administrators are responsible for reviewing and managing user access regularly.

8. Enforcement

8.1 Investigation

Utilitarian may investigate any suspected violation of this AUP. You agree to cooperate with reasonable investigations, including providing information necessary to verify compliance.

8.2 Actions

If Utilitarian determines that you have violated this AUP, we may, at our discretion and depending on the severity and nature of the violation: (a) notify you and request that you remedy the violation within a specified period; (b) restrict specific features or functionality while the violation is being addressed; (c) suspend your account or specific user accounts pending investigation or remediation; or (d) terminate your account in accordance with the Terms, for serious or repeated violations.

8.3 Urgent action

Where a violation poses an immediate risk to the security, integrity, or availability of the platform, or to other clients, Utilitarian may take immediate action (including suspension) without prior notice. We will notify you as soon as reasonably practicable after taking such action.

8.4 No liability for enforcement

Utilitarian is not liable for any loss or damage arising from enforcement actions taken in good faith under this AUP. Enforcement of this AUP does not relieve you of your obligations under the Terms, including any payment obligations.

9. Reporting Violations

If you become aware of any violation of this AUP — by your own users, by another client, or by any third party — please report it to security@utilitarian.world. Reports may be made confidentially.

10. Changes to This Policy

Utilitarian may update this AUP from time to time to reflect changes in the platform, applicable law, or industry practice. We will notify you of material changes by email to your account admin address at least 30 days before the changes take effect. Continued use of the platform after the effective date constitutes acceptance of the updated AUP.

11. Contact

Europe: Utilitarian B.V., Schiedamse Vest 154, 3011 BH Rotterdam (KVK 97343927). legal@utilitarian.world

Australia: Utilitarian Pty Ltd, ABN 89 655 178 402. legal@utilitarian.world