Acceptable Use Policy
Last updated: August 31, 2026
1. Scope
This Acceptable Use Policy (“AUP”) applies to all use of websites, public catalogs, import tools, accounts, reports, APIs, MCP interfaces, bulk-access methods, and other services provided by Fintora Technologies Inc., d/b/a Tandom.ai (“Tandom.ai”). It forms part of the Tandom.ai Terms of Service. You are responsible for compliance by anyone using the Services through your account, credentials, application, agent, or systems.
2. Unlawful, Harmful, or Deceptive Use
You may not use the Services to:
- Violate applicable law, regulation, sanctions, export controls, court orders, or the rights of another person.
- Facilitate fraud, evasion of customs or trade-remedy obligations, false statements, counterfeit goods, money laundering, or other unlawful trade or commercial activity.
- Harass, threaten, discriminate against, defame, impersonate, or deceive another person or misrepresent your identity, affiliation, authority, product, origin, supplier, manufacturer, or transaction.
- Upload, transmit, or distribute malware, malicious code, unlawful content, or content that infringes privacy, confidentiality, intellectual-property, or other rights.
- Create a material risk of harm to people, property, systems, supply chains, or the operation of the Services.
3. Accounts, Authentication, and Access Controls
You may not:
- Access or attempt to access an account, credential, key, dataset, endpoint, function, or system without authorization.
- Share, sell, transfer, expose, or publish an account credential or API key except through an authorized team or delegation feature.
- Create or use multiple accounts, browser identities, keys, IP addresses, proxies, or automated clients to evade sign-in gates, free-use allowances, quotas, suspensions, or other controls.
- Falsify request metadata, identity, attribution, billing, usage, or security information.
4. Automated Access, Scraping, and Rate Limits
Automated access must use an API, MCP interface, feed, or bulk-access method that Tandom.ai makes available for that purpose. You must obey published and technically enforced request limits, concurrency limits, quotas, access scopes, robots instructions, and caching requirements.
You may not:
- Scrape, crawl, download, enumerate, or extract content at a volume or frequency that burdens the Services or substitutes for approved API, MCP, feed, or bulk access.
- Rotate identifiers, accounts, IP addresses, or infrastructure to bypass a rate limit, quota, access decision, or technical control.
- Use parallel, distributed, or recursive requests to exhaust resources, degrade availability, or obtain more access than an applicable plan or authorization permits.
- Ignore a retry interval, suspension, access-denied response, or instruction to reduce or stop automated activity.
5. Security and Service Integrity
Without prior written authorization, you may not:
- Probe, scan, test, or exploit vulnerabilities; bypass authentication or authorization; or conduct penetration, load, or denial-of-service testing against production systems.
- Reverse engineer, decompile, disassemble, or attempt to derive source code, non-public data structures, secrets, or internal implementation details, except to the limited extent a restriction is prohibited by law.
- Interfere with, disrupt, overload, or degrade the Services or another user's access.
- Defeat, disable, remove, or evade logging, abuse detection, metering, security, or privacy controls.
Report a suspected vulnerability privately to legal@tandom.ai. Do not access, alter, retain, or disclose data that is not yours.
6. Data, Privacy, and Confidential Information
You may not use the Services to:
- Collect, process, or disclose personal, confidential, controlled, or proprietary information without the rights, notices, consents, and safeguards required by law and contract.
- Attempt to re-identify aggregated or pseudonymized information or correlate it to a person, account, or organization without authorization.
- Submit payment-card data, government-identification numbers, medical information, account passwords, export-controlled data, or other highly sensitive information through a feature not expressly approved for that data.
- Use catalog or tool data to target, profile, or make decisions about a person in a manner that violates applicable law.
7. AI-Assisted Features
When using an AI-assisted feature, you may not:
- Attempt to extract system prompts, hidden instructions, secrets, credentials, private context, or another user's data.
- Use prompt injection, adversarial inputs, tool-call manipulation, or similar techniques to bypass safeguards or cause unauthorized actions.
- Represent an AI-generated result as an official government ruling, legal opinion, professional certification, or verified factual conclusion when it is not one.
- Use outputs without the independent review appropriate to the customs, sourcing, purchasing, safety, or commercial decision at issue.
8. Resale, Redistribution, and Competitive Use
Unless a separate written agreement permits it, you may not resell, sublicense, white-label, redistribute, publish, or make available a substantial portion of the Services, catalogs, datasets, reports, or outputs as a standalone data product, competing service, or service for third parties. You may not use non-public Service access or outputs to train or evaluate a competing model, dataset, calculator, or product. Ordinary internal business use and limited citation with attribution remain permitted, subject to these Terms and applicable law.
9. Enforcement
We may investigate suspected violations and preserve relevant records. Depending on the nature, severity, and urgency of the issue, we may limit traffic, require remediation, revoke keys, remove content, suspend or terminate access, notify affected parties or authorities, or take other appropriate action. We may act without advance notice when reasonably necessary to protect the Services, users, third parties, or legal compliance.
If you believe an enforcement action was made in error, contact us with the account, request, or incident details needed to review it. We do not guarantee restoration of access while a security, legal, payment, or abuse risk remains unresolved.
10. Reporting Abuse
Report suspected abuse, unauthorized use, or a security concern to legal@tandom.ai. Include relevant URLs, timestamps, request identifiers, and a clear description, but do not email passwords, API keys, unnecessary personal data, or exploit code.
11. Changes to This Policy
We may update this AUP as the Services, threats, or legal requirements change. We will post the revised policy here and update the “Last updated” date. Continued use after a revised AUP takes effect constitutes acceptance.