Rules governing Client's use of Deliverables and Consultiply IP. Incorporated into the Agreement by reference and updatable under Section 23 of the Agreement. Applies to every Deliverable, every item of Consultiply IP, and all Services under the governing MSA.
1. Prohibited uses
Client shall not, and shall not permit any person to, use any Deliverable, any Consultiply IP, or the Services to:
- act in breach of any applicable law or regulation;
- infringe or misappropriate the intellectual property, privacy or publicity rights of any person;
- make or materially determine a decision about an individual's employment, credit, housing, insurance, education, healthcare or access to a public benefit, without review of that decision by a named human being with authority to overturn it;
- disable, bypass or remove a human-approval step built into a Deliverable, or alter the allocation between automated action and human approval agreed at kickoff, otherwise than through the change-control process and with the approval of an Authorized Contact;
- present output generated by a Deliverable as having been authored by a person who did not author it, where doing so would mislead the recipient;
- rely on output generated by a Deliverable as the sole basis for legal, medical, tax, accounting or financial advice given to a third party, without review by an appropriately qualified professional;
- impersonate any person or organization, or generate material designed to be mistaken for the communication of a real person or organization;
- submit to a Deliverable any information belonging to a third party that Client does not have the right to submit;
- transmit or store material that is unlawful, defamatory, harassing, or that contains malicious code;
- attempt to gain unauthorized access to, probe or test any Consultiply system, or any third-party system, other than with express prior written authorization;
- reverse engineer, decompile or attempt to derive the structure or underlying methodology of any Consultiply IP, except to the extent that restriction is prohibited by applicable law;
- resell, sublicense or make any Deliverable or Consultiply IP available to a third party, or operate it as a service for a third party, except as the applicable SOW expressly permits; or
- use any Deliverable or Consultiply IP to build, train, benchmark or improve a product or service competitive with Consultiply.
2. Restricted data
Client shall not submit to any Deliverable or to the Services:
- protected health information subject to HIPAA, unless the parties have first executed a Business Associate Agreement;
- cardholder data subject to the Payment Card Industry Data Security Standard, in any circumstance;
- information subject to ITAR, EAR-controlled technical data, or classified information, in any circumstance;
- any other category of information subject to a specialized regulatory regime, unless the parties have first agreed in writing that it may be submitted and have put the required terms in place.
Where Client intends to use the Services in connection with any of these categories, Client shall tell Consultiply in advance so the parties can determine what is required.
3. Investigation and enforcement
Consultiply may investigate a suspected breach of this Policy; may suspend the affected Services to prevent, contain or remediate a breach, in accordance with Section 18 (Suspension) of the Agreement; and Client shall cooperate with any such investigation. A breach of this Policy is subject to the indemnity provision at Section 14 of the Agreement.
4. Reporting
A suspected breach may be reported to Consultiply at the legal notice address in the Agreement.