1. Purpose
This Acceptable Use Policy explains what is not allowed when using BossBack. It applies to customers, account users, integrations, and customer-facing BossBack experiences and forms part of the Terms of Service.
2. Use BossBack lawfully
Do not use BossBack to create, facilitate, promote, or materially assist unlawful activity, fraud, deception, harassment, threats, exploitation, or violations of another person’s rights. Do not impersonate another person or business or intentionally misrepresent AI output as verified human or professional judgment when that distinction matters.
3. Unsupported sensitive data
Unless BossBack expressly adds a supported workflow with appropriate controls, do not use BossBack to collect, store, or transmit:
- payment-card numbers or card security codes;
- Social Insurance Numbers, Social Security numbers, or similar national identifiers;
- government identity documents or copies of passports, driver’s licences, health cards, or immigration documents;
- banking credentials, financial-account passwords, private keys, authentication secrets, or one-time codes;
- medical records, protected health information, diagnosis or treatment information, or other highly sensitive health data;
- biometric templates used to identify a person;
- highly sensitive information about children; or
- other regulated or highly sensitive data BossBack has not expressly stated is supported.
Ordinary inquiry context is different. A visitor can ask whether a clinic offers a service, for example, but BossBack is not intended to become a repository for a patient’s medical record or diagnosis.
4. Regulated and high-impact judgment
BossBack may explain approved information about a business and its services. It must not be used as the sole decision-maker or authoritative professional adviser for diagnosis or treatment, legal advice, investment or individualized financial advice, employment decisions, credit, lending, insurance eligibility, housing decisions, or other high-impact determinations.
5. Harmful activity
Do not use BossBack to facilitate violence, self-harm, sexual exploitation, trafficking, dangerous wrongdoing, malicious cyber activity, or instructions intended to bypass security or cause physical, financial, or digital harm.
6. Spam and deceptive outreach
Do not use BossBack for unsolicited bulk communications, deceptive lead generation, scraping personal information for marketing, or circumventing consent, unsubscribe, or anti-spam requirements.
7. Protect the service
- Do not probe or test BossBack for vulnerabilities without written authorization. To report a suspected security vulnerability or security issue, contact [email protected].
- Do not bypass authentication, rate limits, safety controls, access restrictions, or usage limits.
- Do not introduce malware or code intended to disrupt or gain unauthorized access.
- Do not reverse engineer protected parts of the service except where applicable law expressly permits it.
- Do not use automated traffic in a way that degrades service for others.
- Do not access another customer’s account, Sources, conversations, data, or credentials without authorization.
8. Content and privacy rights
Only provide content you have the right and lawful authority to process. If BossBack is on your website, you are responsible for appropriate privacy notices and permissions for end users.
9. Enforcement
We may investigate suspected violations and limit, suspend, or terminate access when reasonably necessary to protect the service, providers, customers, end users, or the public. Where a problem appears correctable and there is no immediate safety or security concern, we will generally try to contact the customer before permanent termination.
10. Report misuse
To report suspected abuse or ask whether a proposed use is supported, contact [email protected].
