Acceptable use policy
This Acceptable Use Policy sets the conduct and security requirements for individual users of Clinia products and services. It is designed to protect patients, users, customers, Clinia, and the integrity and availability of the Services.
- 1. Scope and relationship to the Agreement
This Acceptable Use Policy (the “AUP”) applies to each individual who accesses or uses the Services as an Authorized User on behalf of a Customer or who accesses Free Tier Services under the Free Tier Services Terms (each a “User”). It is a condition of access to the Services. For Authorized Users, it forms part of the Documentation under the Agreement between Clinia and the Customer. For Free Tier Services, it is incorporated only where referenced by the applicable Free Tier Services Terms.
The AUP does not grant a User any independent right to access or use the Services. A User may access and use the Services only within the scope approved by the Customer or permitted for the applicable Free Tier Services, and in accordance with the terms governing that access.
Capitalized terms not defined in this AUP have the meanings given in the applicable Agreement or Free Tier Services Terms. If this AUP conflicts with those terms, those terms control.
End Users do not become Authorized Users, obtain independent access rights, or enter into a direct contractual relationship with Clinia merely because this AUP is displayed or communicated to them. The Customer remains responsible for End Users as set out in the Agreement.
- 2. Responsible and authorized use
Users must:
• use the Services only for the Customer’s authorized business purposes or the permitted evaluation purposes of the applicable Free Tier Services, and only within the User’s assigned role, permissions, and legitimate need to know;
• follow the Agreement, applicable Documentation and Product Schedules, Applicable Laws, professional obligations, and the Customer’s policies and instructions;
• use reasonable care when entering prompts, queries, instructions, configurations, or other Customer Data and verify that the information is appropriate for the intended workflow;
• respect the rights, privacy, confidentiality, and intellectual property of patients, individuals, the Customer, Clinia, and third parties; and
• cooperate with reasonable steps taken by the Customer or Clinia to protect, investigate, restore, or secure the Services.
- 3. Accounts, credentials, and access
Users must protect all credentials, authentication mechanisms, access tokens, and keys associated with the Services. In particular, Users must not:
• share accounts or credentials, permit another person to use their identity, or use credentials assigned to another person;
• circumvent role-based access, authentication, multi-factor authentication, single sign-on, usage limits, or other access or security controls;
• access any account, workspace, system, feature, Customer Data, or Customer Environment without authorization; or
• continue to access the Services after the Customer withdraws or changes the User’s authorization or the User’s permitted Free Tier Services access ends.
Users must promptly report suspected loss, compromise, unauthorized disclosure, or unauthorized use of credentials or accounts through the Customer’s designated process and, where directed, to Clinia through the applicable support channel.
- 4. Data, privacy, and confidentiality
When using the Services on behalf of a Customer, Users may submit, access, use, retrieve, export, or disclose Customer Data only where authorized by the Customer and only for a permitted purpose. Users must:
• ensure they are authorized to handle the relevant information and follow the Customer’s privacy, security, confidentiality, records-management, and professional requirements;
• use only the information reasonably necessary for the authorized task;
• not access, disclose, copy, export, download, or store Customer Data outside approved workflows, systems, or locations;
• not submit information that the Customer does not have the right or legal authority to process through the Services; and
• not attempt to identify or re-identify an individual from data represented as de-identified, anonymized, or aggregated, or use such data to reconstruct Customer Data.
Free-tier, trial, evaluation, preview, demonstration, sandbox, beta, pilot, and proof-of-concept environments may be used only with synthetic or test data unless Clinia has expressly approved another use in writing and the required contractual and data-protection terms are in place. Users must not place real patient, clinical, personal, confidential, regulated, production, or other sensitive data in those environments without that approval.
Clinia’s collection and use of Usage Data and its derivation and use of Aggregated Data are governed by the Agreement and, where applicable, the DPA. This AUP does not expand or change those permissions.
- 5. Security and service integrity
Users must not:
• interfere with, disrupt, overload, degrade, or compromise the security, integrity, availability, or performance of the Services;
• introduce malware, malicious code, harmful instructions, destructive content, or other harmful technical activity;
• probe, scan, test, or attempt to exploit a vulnerability, or conduct penetration testing, vulnerability scanning, load testing, or similar testing, without Clinia’s prior written approval or express permission in an applicable Product Schedule;
• avoid, defeat, disable, or interfere with security, safety, monitoring, rate-limiting, or technical controls;
• access or attempt to access source code, underlying components, non-public systems, or data not intentionally made available to the User; or
• use the Services in a way that could reasonably create a material security, operational, compliance, or availability risk.
- 6. Intellectual property, extraction, and competitive use
Except where the Agreement expressly permits it, Users must not:
• copy, modify, distribute, sell, lease, sublicense, publish, or make the Services or Clinia Technology available to any third party;
• reverse engineer, decompile, disassemble, translate, or attempt to discover source code, algorithms, models, architecture, or underlying components of the Services, except where Applicable Laws do not permit that restriction;
• remove, obscure, or alter proprietary notices or markings in the Services or Documentation;
• use the Services to develop, train, or operate a product or service that competes with the Services, or for competitive benchmarking or analysis; or
• scrape, harvest, bulk extract, or use the Services, Clinia Technology, or Outputs to train or improve any artificial intelligence or machine learning model, except as expressly permitted under the Agreement, applicable Order Form, Documentation, or Product Schedule.
- 7. Unlawful, deceptive, and harmful use
Users must not use the Services or Outputs:
• in violation of Applicable Laws, the Agreement, Documentation, or an applicable Product Schedule;
• to infringe, misappropriate, or violate privacy, confidentiality, intellectual property, contractual, or other legal rights;
• in a fraudulent, deceptive, misleading, abusive, or malicious manner;
• to impersonate another person, misrepresent authority, conceal unauthorized activity, or falsify information;
• to generate, transmit, facilitate, or distribute unlawful, deceptive, or harmful content or activity;
• in violation of export controls, economic sanctions, anti-corruption requirements, or international trade restrictions; or
• in any manner that could reasonably create a material risk of harm to an individual, patient, healthcare operation, Clinia, another customer, or a third party.
- 8. Healthcare and AI use
The Services may support healthcare and health-related workflows, but they do not replace professional or clinical judgment. Outputs may be inaccurate, incomplete, inconsistent, or unsuitable for a particular purpose. Users are responsible for reviewing and evaluating Outputs before using or relying on them and for following the Customer’s clinical governance and human-review requirements.
Users must not use AI Features or Outputs:
• in violation of Applicable Laws;
• to generate or distribute unlawful, deceptive, or harmful content;
• as a basis for clinical decision-making;
• for emergency response, life-support, or autonomous clinical decision-making; or
• in a manner that could reasonably create a material risk of harm to individuals or healthcare operations.
Users must not make the Services available, directly or indirectly, to patients or other individuals acting in their capacity as recipients of care unless the applicable Order Form or Product Schedule expressly authorizes that access.
- 9. Third-party services and integrations
Users may connect, configure, or use a Third-Party Service with the Services only where authorized by the Customer and permitted by the Agreement and Documentation. Users must comply with the terms and security requirements applicable to the Third-Party Service and must not use an integration to bypass this AUP or any control in the Services.
- 10. Reporting concerns
Users must promptly report suspected unauthorized access, misuse, security vulnerabilities, privacy concerns, harmful Outputs, or other violations of this AUP through the Customer’s designated reporting process or the applicable Clinia support channel. Users must not publicly disclose or exploit a suspected vulnerability.
- 11. Enforcement
Clinia may investigate suspected violations and may suspend or limit access to affected Services, accounts, users, features, or components where reasonably necessary to address security, operational, legal, compliance, or misuse risks, protect Customer Data or third parties, or prevent unauthorized or unlawful use. Where reasonably practicable, Clinia will provide notice and an opportunity to resolve the issue in accordance with the Agreement.
The Customer may also restrict or revoke an Authorized User’s access. A violation of this AUP may constitute a breach of the Agreement by the Customer or a breach of the applicable Free Tier Services Terms by the User and may result in other action permitted under those terms or Applicable Laws.
- 12. Updates
Clinia may update this AUP from time to time as permitted under the applicable Agreement or Free Tier Services Terms. Material updates will be communicated in accordance with the applicable terms. Continued access to or use of the Services after an update becomes effective is subject to the updated AUP.