Legal
Acceptable Use Policy
Last updated: August 27, 2026
This Acceptable Use Policy (the “Policy”) defines the acceptable and prohibited uses of Solvigo AB’s AI-powered services (the “Services”). It protects Solvigo, its clients, end users and the integrity of the Services, and supports compliance with applicable law, including the GDPR and the EU AI Act.
By accessing or using the Services, you agree to comply with this Policy. Violation may result in suspension or termination of access, and may be subject to legal action.
Where a separate service agreement exists between Solvigo and you or your organisation, that agreement governs liability, indemnification and remedies. This Policy sits alongside it and does not replace it.
1. Who this applies to
This Policy applies to everyone who accesses or uses the Services:
- Solvigo personnel and contractors
- Client organisations and their authorised users
- Third-party integrators and API consumers
- Any individual accessing the Services by any means
It covers all features of the Services, including AI models, data processing pipelines, APIs, dashboards and administrative tools.
2. Acceptable use
You may use the Services for lawful business purposes consistent with your service agreement. That includes:
- Using the AI-powered automation and workflow features as described in your service agreement
- Uploading, processing and managing data you are authorised to process and have a legal basis for
- Using APIs and integrations within the applicable rate limits and technical constraints
- Configuring roles, permissions and workspace settings within the scope of your service agreement
- Generating reports, analytics and outputs for legitimate business operations
3. Prohibited use
3.1 Illegal and harmful activity
- Any use that violates applicable local, national or international law
- Fraud, money laundering, terrorism financing or any other criminal activity
- Processing data in a way that violates a third party’s rights, including intellectual property and privacy rights
- Generating, distributing or storing content that is defamatory, obscene, threatening or otherwise unlawful
3.2 Service integrity and security
- Reverse-engineering, decompiling or disassembling any Service, or otherwise deriving its source code or underlying algorithms
- Introducing malware, viruses, worms, trojans or other malicious code
- Attempting unauthorised access to systems, networks, accounts or other users’ data
- Circumventing, disabling or interfering with security features, access controls or usage limits
- Running vulnerability scans, penetration tests or load tests without prior written approval from Solvigo
3.3 AI-specific restrictions
- Using AI features to generate content impersonating real individuals without their consent
- Training or fine-tuning external models on outputs or data derived from the Services without authorisation
- Using the Services to make fully automated decisions producing legal or similarly significant effects on individuals without appropriate human oversight, contrary to the EU AI Act
- Deliberately attempting to make AI components produce biased, discriminatory or harmful output
3.4 Resource misuse
- Exceeding applicable API rate limits, or degrading Service performance for other users
- Using automated scripts or bots in ways your service agreement does not sanction
- Reselling, sublicensing or redistributing Service access or outputs contrary to the service agreement
4. Data privacy and security
4.1 How we process data
Solvigo processes all data in accordance with the GDPR and applicable data protection law. How we handle personal data is described in our Privacy Policy.
4.2 Your obligations
You are responsible for:
- Ensuring you have a valid legal basis — consent, legitimate interest, contractual necessity — for processing personal data through the Services
- Not uploading special categories of personal data (GDPR art. 9) unless explicitly authorised under your service agreement and with appropriate safeguards in place
- Promptly notifying Solvigo of any suspected data breach or unauthorised access to data processed via the Services
- Complying with retention policies and deleting data no longer needed for the stated purpose
- Implementing appropriate security measures in your own environment, including strong credentials and secure access practices
4.3 Data residency and transfers
Solvigo processes customer data primarily within the European Economic Area. Where a sub-processor operates outside the EEA, we ensure appropriate safeguards under GDPR Chapter V, including standard contractual clauses or a European Commission adequacy decision.
Personal data belonging to a customer or its end users is not transferred to non-EEA sub-processors without the customer’s prior agreement, except where strictly necessary to provide the Services and covered by the safeguards above.
A current sub-processor list, with processing locations and applicable safeguards, is available to customers on request.
4.4 Encryption and access control
We use industry-standard encryption for data at rest (AES-256) and in transit (TLS 1.3). Access to client data is restricted on a need-to-know basis under role-based access control. Access to production systems is logged and subject to periodic review.
4.5 Retention and deletion
Client data is retained for the duration of the service agreement. On termination, Solvigo deletes or returns all client data within 30 days, unless retention is required by law.
4.6 Incident response
Solvigo maintains an incident response plan. On a confirmed personal data breach we notify the affected client without undue delay, within whatever timeframe the applicable data processing agreement specifies. Where a breach is likely to result in a risk to individuals, we notify the relevant supervisory authority within 72 hours as required under GDPR art. 33.
5. Monitoring and enforcement
Solvigo may monitor use of the Services to verify compliance with this Policy, through automated logging, usage analytics and security audits, and does so in accordance with applicable privacy and data protection law.
On identifying a violation we may:
- Issue a formal warning to the user or client organisation
- Temporarily suspend access to the relevant Services pending investigation
- Permanently terminate access
- Report the violation to law enforcement or regulators where required or appropriate
We make reasonable efforts to notify the client organisation before taking enforcement action, except where immediate action is necessary to protect the Services, other users, or to comply with a legal obligation.
6. Your account
You are responsible for keeping your credentials confidential and for all activity conducted through your account. Report any suspected unauthorised use to us promptly.
Client organisations are responsible for making their authorised users aware of this Policy and remain liable for their users’ actions on the Services.
7. Changes to this Policy
We may modify this Policy to reflect changes in our Services, legal requirements or business practices.
Material changes that affect your rights or obligations: we give at least 14 days’ notice, by email or a prominent notice in the platform, before they take effect.
Non-material changes such as clarifications or minor edits take effect on posting.
Continued use of the Services after the effective date constitutes acceptance of the updated Policy.
8. Governing law
This Policy is governed by the laws of Sweden. Disputes arising under or in connection with it are subject to the exclusive jurisdiction of the courts of Stockholm, Sweden.
9. Contact
Solvigo AB (org.nr 559529-3647)
Valhallavägen 140, 114 59 Stockholm, Sweden
For anything — general inquiries, privacy questions and data subject requests, security and violation reports — write to info@solvigo.ai.
