Acceptable Use Policy — Schedule to the Subscription Agreement
1. Purpose
This Acceptable Use Policy ("AUP") defines the permitted and prohibited uses of the Titane Intelligence Services. It is incorporated by reference into the Subscription Agreement (MSA), and compliance with it is a contractual obligation of the Customer.
Failure to comply with the AUP may result in the immediate suspension of the Services or termination of the Agreement, in accordance with Article 8 of the MSA.
2. Prohibited uses — general
The Customer agrees not to use the Services for:
- a) any unlawful or fraudulent activity, or any activity contrary to public order and public morals;
- b) any activity infringing the rights of third parties, including intellectual property rights, image rights, personality rights, and trade secrets;
- c) any spam activity, unsolicited prospecting that does not comply with applicable regulations (in particular Article L. 34-5 of the French Postal and Electronic Communications Code regarding electronic prospecting), or abusive commercial communications;
- d) any activity intended to disrupt, degrade, overload, circumvent, or compromise the security of the Services;
- e) any reverse engineering, decompilation, or disassembly of the Titane Generic Models or of the Services infrastructure, except within the limits strictly permitted by law;
- f) any scraping, mass automated extraction, or circumvention of the technical limits of the Services or the API;
- g) any resale, sublicensing, rental, or making the Services available to third parties, except with Titane's prior written consent;
- h) any training of a competing Deep Learning model based on the outputs of the Services ("derived outputs"), including by distillation, prompt scraping, or any other equivalent method.
3. Restrictions on the data submitted
3.1 Pseudonymized architecture
In accordance with the pseudonymized architecture described in Article 6 of the DPA, the Customer agrees to transmit to Titane only Pseudonymized Identifiers (opaque tokens resulting from Customer-side encryption) and business data conforming to the categories set out in Schedule 1 of the DPA.
3.2 Expressly prohibited data
The Customer shall not, except with Titane's prior written consent and the implementation of appropriate supplementary measures, transmit:
- a) directly identifying data that is not encrypted (first name, last name, email address in clear text, phone number in clear text, postal address, banking data);
- b) special categories of data within the meaning of Article 9 of the GDPR (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic or biometric data; data concerning health; data concerning sex life or sexual orientation);
- c) data relating to criminal convictions and offenses (Article 10 of the GDPR);
- d) data of minors without the parental consent required by Article 8 of the GDPR and the French Data Protection Act.
3.3 Detection and consequences
Titane reserves the right to implement automated controls to detect the possible presence of prohibited data in incoming flows. In the event of detection, Titane may suspend the relevant ingestion, notify the Customer, and require immediate remediation.
4. Prohibited purposes of use
The Customer agrees not to use the Recommendations or the outputs of the Services for:
- a) any creditworthiness or credit-risk scoring, or any assessment for the purpose of lending, buy-now-pay-later (BNPL), or consumer credit;
- b) any other purpose listed in Annex III of Regulation (EU) 2024/1689 ("AI Act") that falls under high-risk systems, without first having implemented the compliance measures applicable to the Customer as a deployer;
- c) any automated individual decision-making producing legal effects or similarly significant effects on the data subjects, without substantial human intervention and without prior information to the data subjects in accordance with Article 22 of the GDPR;
- d) any manipulative or deceptive practice, or any practice that impairs the decision-making autonomy of the data subjects.
5. Zero Local Data Policy on Titane's side
Titane applies a Zero Local Data Policy: no Customer Data is stored on the workstations of Titane's staff. All access to Customer Data is carried out remotely via controlled environments (Remote SSH on AWS).
The Customer is encouraged to apply equivalent principles when its own teams access the Titane Account Space or use the Recommendations within its information system.
6. Account Security
The Customer agrees to:
- a) protect the confidentiality of its Account credentials and API keys;
- b) enable multi-factor authentication when offered by Titane;
- c) periodically rotate API keys exposed in the Customer's systems;
- d) notify Titane without delay at
security@titane-intelligence.com of any compromise or suspected compromise of credentials.
7. Consequences in the event of a breach
7.1 In the event of a breach of this AUP, Titane may:
- a) send the Customer a formal notice to cease, with a reasonable period to remediate;
- b) in the event of a serious breach or an imminent risk to security, compliance, or the rights of third parties, immediately suspend all or part of the Services without prior notice;
- c) terminate the Agreement in accordance with Article 8.3 of the MSA.
7.2 Suspension or termination for breach of the AUP does not give rise to any refund or compensation in favor of the Customer.
8. Reporting abuse
To report abusive use of the Services, write to contact@titane-intelligence.com or security@titane-intelligence.com, describing the alleged nature of the abuse and any information useful to the investigation.
Contact: contact@titane-intelligence.com
Version 1.0 — Last updated: May 18, 2026