Phase 0 · Pre-launch. Commercial activity has not commenced.
BreachDuty ← Back to site

Acceptable Use Policy

Effective Date: August 8, 2026 · Version 1.0

This Acceptable Use Policy ("AUP") governs your access to and use of the BreachDuty platform, web application, APIs, and related services (collectively, the "Service"), operated by Ellis Intelligence LLC, a Colorado limited liability company ("we", "us", "our"). By accessing or using the Service, you ("Customer", "you") agree to this AUP. This AUP is incorporated into and forms part of our Terms of Service, including its governing-law and dispute-resolution provisions.

If you violate this AUP, we may suspend or terminate your access without prior notice or refund and may pursue any other remedy available to us.

1. Permitted Use

You may use the Service only:

2. Account and Access

2.1 Account Security. You are responsible for maintaining the confidentiality of your account credentials. You must enable multi-factor authentication where the Service offers it. You must notify us immediately at [email protected] of any unauthorized account access.

2.2 No Sharing. Each user account is for a single individual. You may not share login credentials. Each seat used must correspond to a distinct natural person identified by name and email.

2.3 Workspace Isolation. Multi-tenant data isolation is a feature of the Service. You will not attempt to access data belonging to any other tenant, account, or workspace (that is, data belonging to any other customer of the Service or its users).

3. Prohibited Content

You will not upload, transmit, store, or generate through the Service any content that:

4. Prohibited Activities

You will not, and will not permit any third party to:

4.1 Service Integrity

4.2 Resale and Wrapping

Except where your subscription tier explicitly grants white-label or reseller rights (the White-label tier, per our Terms of Service §1.2):

4.3 AI and Output Use

4.4 Data Hygiene

4.5 Customer Responsibility; Indemnification

As between you and us, you are responsible for the lawfulness of the data you submit to the Service and of the instructions, configurations, and directions you give in using it, including every representation of lawful basis, authorization, or consent made in this AUP or in the BreachDuty Addendum. Violations of this AUP (including those representations) that give rise to a third-party claim against us are covered by the indemnification provisions of the Terms of Service, subject to the conditions and procedures stated there; where the DPA applies, this allocation does not excuse our own compliance with our obligations under the DPA.

5. Reporting and Cooperation

5.1 Reporting Violations. Report suspected AUP violations to [email protected]. Include the relevant account or tenant identifier, a description of the issue, and any supporting evidence.

5.2 Legal Requests. We will respond to lawful subpoenas, court orders, and government requests in compliance with applicable law. We will notify the affected Customer where lawful to do so.

5.3 Cooperation. You will cooperate reasonably with any investigation of suspected AUP violations involving your account.

6. Enforcement

6.1 Range of Actions. Depending on severity, we may take any one or more of the following actions in response to an AUP violation: issue a written warning; temporarily throttle, restrict, or suspend specific features of your account; suspend your account in full pending investigation; terminate your account immediately for material breach; refer the matter to law enforcement; or pursue civil remedies, including monetary damages and injunctive relief.

6.2 Material Breach — Immediate Action. The following constitute material breach permitting immediate suspension or termination without prior notice or refund: any activity prohibited under §3 (Prohibited Content) involving illegal content, malware, or regulated-data violations; any activity prohibited under §4.1 (Service Integrity) involving unauthorized access, vulnerability probing without authorization, or denial-of-service activity; use of the Service in violation of export-control law, sanctions law, or anti-bribery law; or repeated lower-severity violations after written warning.

6.3 Refund Policy on Termination for AUP Violation. No refund of pre-paid fees is owed for the billing period in which the violation occurred. Future billing periods are credited or refunded in accordance with the refund provisions of the Terms of Service.

6.4 Survival. Termination, suspension, or expiration of your account or subscription does not relieve you of obligations that by their nature should survive, including but not limited to: obligations of confidentiality; obligations regarding the return or destruction of data (as provided in the Terms of Service and the DPA); the representations in §4.5; and liability for AUP violations accruing before termination.

7. Modifications

We may update this AUP from time to time. Material changes will be communicated by written notice sent by email to the account's designated contacts (or by in-product notice) and, in addition, posted at breachduty.com/acceptable-use. Written notice is deemed given when sent; failure to read a properly sent notice does not extend any period. Each change takes effect on the effective date stated in the notice, and continued use of the Service after that effective date constitutes acceptance of the updated AUP.

8. Contact

Questions about this AUP: [email protected]
Security and abuse reports: [email protected]

Addendum — BreachDuty

BD1. Obligation Map — Not a Legal Determination. BreachDuty computes notification obligations and deadlines from statutes it cites and from facts you enter. It is not a legal determination, certification, or opinion, and it is not a substitute for your counsel's judgment. You will not represent to any regulator, attorney general, consumer, auditor, or insurer that BreachDuty has determined, certified, or opined on your obligations.

BD2. Scope — Atlas and Clock Only. The Service is scoped to the obligation map and the timing clock. It does not generate, assemble, or deliver breach-notification content.

BD3. Notice Origination and Delivery Are Yours; Heightened Responsibility. You and your counsel originate, draft, assemble, and deliver every notice through your own systems. The Service never transmits anything to a regulator, attorney general, or consumer, and you will not attempt to configure or integrate it to do so. Because a delivered notice reaches a regulator, attorney general, or consumer — a party outside your control once sent — you bear sole responsibility for its accuracy, completeness, and legal sufficiency. Our non-involvement in delivery does not shift that responsibility to us.

BD4. Accuracy of Inputs. You are responsible for the accuracy of the incident facts, data categories, and jurisdictional inputs you enter.

BreachDuty is a product of Ellis Intelligence LLC. This page is not legal advice. See also our Terms of Service and Privacy Policy. Questions about this document: [email protected].