Acceptable Use Policy
Version 1.0 · 6 August 2026
This policy sets out what you may and may not do with LumiaChatFlow. It forms part of our Terms of Service. Breaching it is a breach of those Terms.
It applies to your account, your workspace, the agents you build, the content you index, and anywhere you embed the chat widget.
1. The basics
Do not use LumiaChatFlow to do anything unlawful, to harm people, or to interfere with the service or with other customers. Specifically, you must not:
- break any applicable law or regulation, or help anyone else do so;
- infringe anyone's intellectual property, privacy, or other rights;
- upload or distribute malware, or attempt to gain unauthorized access to any system;
- probe, scan, overload, or disrupt the service or the infrastructure behind it;
- resell, sublicense, or white-label the service without our written agreement;
- circumvent usage limits, credit accounting, rate limits, or billing;
- scrape or index content you do not have the right to use;
- use the service in breach of applicable export-control or sanctions laws, or for military end-use or the development or proliferation of weapons of mass destruction.
2. Restricted businesses and content
LumiaChatFlow is sold through PayPro Global as our Merchant of Record, and their prohibited-business rules apply to the sale of our subscriptions. Beyond that, we restrict what the platform itself may be used for. You may not use LumiaChatFlow — including any agent you build or any site where you embed the widget — to operate, promote, sell, or provide customer interaction for any of the following:
Illegal and harmful
- illegal or unlawful goods or services, or anything that encourages, promotes, facilitates, or instructs others to engage in illegal activity;
- weapons and ammunition, hazardous or combustible materials, controlled substances, illegal drugs or drug paraphernalia, or the unlawful sale of pharmaceuticals, prescription drugs or devices, or unapproved drugs or medical devices;
- content promoting hatred, racism, religious persecution, or otherwise offensive material;
- malware of any kind — viruses, worms, trojans, spyware, dishonest adware, crimeware, rootkits.
Adult and exploitative
- pornography or adult content of any kind, including on any site where the widget is embedded;
- escort services, bride catalogues, or any payment for sexual or romantic services.
Gambling and schemes
- gambling and gaming, or any activity with an entry fee and a prize — casinos, sports betting, horse or greyhound racing, lotteries, virtual gaming chips or credits, penny auctions;
- pyramid or Ponzi schemes, matrix programs, and certain multi-level marketing programs;
- work-from-home business opportunities and "get rich" schemes;
- degree or diploma mills;
- gift cards sold below face value, or virtual payment instruments designed to obscure the source of funds.
Infringing and deceptive
- replica or "knock-off" branded products, recalled products, satellite signal decoding products or card programming;
- anything infringing copyright, trademark, rights of publicity or privacy, or other proprietary rights — including pirated video, audio, or IPTV streaming;
- tools or services that circumvent locks, programming codes, security features, or geographic or IP-based restrictions, or that give access to content the user has not paid for or been authorized to access.
Regulated businesses are welcome — within limits. If your business is licensed or regulated — for example a medical clinic, a pharmacy, a law firm, an insurer, a bank, or a travel operator — you may use LumiaChatFlow for customer service and FAQ about your business: opening hours, services offered, prices, procedures, and policies. Your agents must comply with section 3 — in particular, they must not provide medical, legal, financial, or other professional advice (§3.3) and must not be deployed in the high-risk uses listed in §3.2.
If you are unsure which side of these lines your use falls on, ask us before you build on the platform.
3. Prohibited AI uses
You may not deploy agents built on LumiaChatFlow for any of the following.
3.1 Prohibited AI practices
- Manipulation — subliminal, manipulative, or deceptive techniques that distort a person's behaviour or impair their ability to make an informed decision, or exploitation of vulnerabilities due to age, disability, or social or economic situation.
- Social scoring — evaluating or classifying people based on their social behaviour or personal characteristics in a way that leads to detrimental or disproportionate treatment.
- Biometric categorization and identification — inferring or categorizing people by biometric data, including to deduce race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, or sexual orientation.
- Emotion recognition — inferring the emotions of a person in the workplace or in education.
3.2 High-risk fields
You may not deploy agents to make, or materially assist in making, decisions about people in:
- education — admission, assessment, or evaluation of students;
- employment — recruitment, screening, task allocation, promotion, or termination;
- credit and creditworthiness, or eligibility for essential services or benefits;
- law enforcement, migration, asylum, border control, or the administration of justice.
3.3 Product restrictions
- No agents aimed at children. Do not build or deploy agents directed at minors.
- No professional advice. Agents may not provide medical, legal, or financial advice, or present output as though it came from a licensed professional.
- No open-ended general-purpose chatbots. LumiaChatFlow agents answer from your own content for your own business. Do not repurpose the platform as a general-purpose assistant.
- No impersonation or deepfakes. Do not configure an agent to impersonate a real person, a public authority, or another business, or to produce deceptive synthetic media. Do not use the platform in connection with non-compliant deepfake technology.
- No output laundering. Do not use the service to generate content that infringes copyright or other intellectual-property rights.
4. AI transparency — your obligation
The chat widget displays a permanent notice telling visitors they are interacting with an AI
assistant (EU AI Act Art. 50(1)). Agent messages in the widget also carry a machine-readable
DOM mark (data-lumiachatflow-ai-generated) so software can detect AI-generated text
(Art. 50(2)). You must not remove, hide, obscure, or restyle that notice or that DOM mark,
whether by editing the embed code, injecting styles, stripping attributes, or any other means.
This is not cosmetic. EU AI Act transparency rules require people to be told when they are interacting with an AI system, and require machine-readable marking of AI-generated text where it applies. The widget's notice and DOM mark are how those provider-side surfaces reach your visitors and their browsers. Interfering with either breaches this policy and may leave you unable to demonstrate compliance. You remain responsible for assessing what those rules require of you as the deployer.
You are also responsible for telling your own website visitors how you handle their data. Our Widget Visitor Notice is a template you can adapt for that purpose.
5. Content you index
You are responsible for the content you bring. Do not index content you have no right to use, personal data you have no lawful basis to process, or special-category data (health, biometric, political, religious, sexual orientation, trade-union membership) unless you have a lawful basis and appropriate safeguards.
Do not use the service to build profiles of individuals or to enrich or cross-reference personal data across sources.
6. Fair use
Plan credits are for normal use of the service by you and your end users. Do not use automated means to inflate usage, share one workspace across unrelated businesses, or resell your credit allocation.
7. Reporting a problem
If you believe an agent or workspace on LumiaChatFlow is breaching this policy, tell us through the contact channel on our Imprint page. Include the site the widget appears on and what you observed. To report a security vulnerability, see our Security & Vulnerability Disclosure page.
8. Enforcement
If we believe you are breaching this policy we may, depending on how serious it is:
- ask you to fix the problem within a stated time;
- restrict or suspend access to your workspace, agents, or specific features;
- remove or de-index offending content;
- terminate your account and the agreement.
Where practical and lawful we will warn you first. For serious breaches — unlawful use, harm to people, security attacks, or the prohibited AI uses in section 3 — we may act immediately and without notice.
We may also be required to act by law, by a regulator, or by our payment provider. Terminating for a breach of this policy does not entitle you to a refund of fees already paid.
9. Changes
We may update this policy — for example when the law changes, or when our payment provider updates its own prohibited-business rules. Material changes will be notified in line with the Terms of Service.