← Home
PLEN

Acceptable Use Policy

The day-to-day rules for using the platform: what is allowed, what is not, how to report vulnerabilities, and what should not be pasted into the assistant.

Acceptable Use Policy

Document version: 1.0 Version date: 1 September 2026 Document effective from: 1 September 2026 Document address: https://guardiso.com/dozwolone-uzytkowanie

This Acceptable Use Policy sets out how the Guardiso Platform may be used and how it may not be used. The document forms an integral part of the Agreement and gives effect to the reference contained in Section 17 paragraph 3 of the Terms of Service for the Provision of Services by Electronic Means.

The Policy is made available free of charge, in a form that allows it to be downloaded, reproduced and stored.

The document has been written so that the Customer's procurement function and security function can assess the rules for using the Platform without reading the entire Terms of Service.


Contents

  1. What this document is for, who is bound by it and how it relates to the other documents
  2. Definitions
  3. What the Platform is for and what counts as use consistent with its intended purpose
  4. Prohibition on supplying unlawful content
  5. Data the Platform is not intended for
  6. Accounts, access and User identity
  7. Load on the infrastructure and automated retrieval of content
  8. Prohibition on circumventing security measures and on probing other parties' data
  9. Security testing of the Platform
  10. Vulnerability reporting by security researchers
  11. Use of artificial intelligence features
  12. Granting access to outside parties and running more than one company
  13. Content Library
  14. How Guardiso detects breaches and what it does not do in this respect
  15. Consequences of a breach and the procedure applied
  16. Reporting breaches of the Policy
  17. Amendments to the Policy and final provisions

§ 1. What this document is for, who is bound by it and how it relates to the other documents

  1. The Policy sets out the permitted manner of using the Platform. It supplements the Terms of Service and the End User Licence Agreement and does not replace either of those documents.

  2. The Policy is binding on:

    1. the Customer;
    2. every User using the Platform within the Customer's Organisation;
    3. every person to whom the Customer has granted access to the Organisation, in particular an external auditor, a certification body and an entity serviced by the Customer under the model described in Section 4 of the End User Licence Agreement.
  3. The Customer is liable for the acts and omissions of the persons listed in paragraph 2 points 2 and 3 as for its own acts. This principle follows from Section 17 paragraph 4 of the Terms of Service. The Customer makes those persons familiar with the content of the Policy before granting them access.

  4. Section 10, concerning vulnerability reporting, is also addressed to persons who are neither the Customer nor a User. In that respect the Policy constitutes a unilateral declaration by Guardiso, not a contractual provision, and binds Guardiso towards anyone who meets the conditions described in that Section.

  5. The order of precedence of the documents is set out in Section 23 of the Terms of Service. The Policy ranks below a separate written agreement and the Partner Agreement, the Data Processing Agreement, the Service Level Agreement, the Terms of Service, the End User Licence Agreement and the document "Service Exit and Data Portability Rules". Where the Policy extends the Customer's rights beyond a document of higher precedence, it remains effective to that extent.

  6. Capitalised terms that are not defined in Section 2 have the meaning given to them in the Terms of Service and in the End User Licence Agreement. This applies in particular to the terms: Service, Platform, Plan, Subscription, Organisation, Account, Account Owner, User, Customer, Protected Customer, Customer Data, Business Day, Content Library, Application Programming Interface, Access Key, Consultant and Consultant's Client.

  7. In relation to a Protected Customer, the provisions of the Policy apply subject to the mandatory provisions of consumer protection law. A provision less favourable to the Protected Customer than a statutory provision does not bind that Customer.


§ 2. Definitions

The terms used in the Policy have the following meanings:

  1. Artificial intelligence features — features of the Platform that make use of a language model, in particular Asystent Guardiso answering questions, the generation of document drafts, suggested answers to questionnaires, the preliminary assessment of controls and searching the knowledge base.

  2. Prompt — the content entered by the User in the field from which an artificial intelligence feature is launched, together with the material that the User has attached to that prompt.

  3. Security researcher — a person who examines the Platform for vulnerabilities and reports their findings to Guardiso, irrespective of whether that person is a Customer or a User.

  4. Vulnerability — a property of the Platform that makes it possible to circumvent its security measures, to obtain access to data without authorisation, to disrupt its operation or to bring about another effect inconsistent with the purpose of the security measure.

  5. Resource abuse — use of the Platform in a manner that loads its resources beyond the measure resulting from ordinary work on one's own documentation, in particular in the manner described in Section 7.

  6. Security address — security@guardiso.com. This address is used for reporting vulnerabilities, incidents and suspected unauthorised access.

  7. General address — kontakt@guardiso.com. This address is used for all other matters covered by the Policy, including complaints and reports of breaches of the Policy made by third parties.


§ 3. What the Platform is for and what counts as use consistent with its intended purpose

  1. The Platform serves to maintain the documentation of an information security management system and to maintain compliance with selected standards and regulations, for the purposes of the Customer's own organisation and for the purposes of the entities for which the Customer maintains paid-for Organisations.

  2. Use consistent with the intended purpose includes in particular:

    1. maintaining policies, procedures, risk registers, controls, evidence, incidents, suppliers and tasks;
    2. preparing internal documents and running their circulation and approval;
    3. using the artificial intelligence features for the purposes of one's own documentation, within the limits of Section 11;
    4. preparing materials for audit purposes and making them available to an external auditor and to a certification body;
    5. making documents available to counterparties and authorities, including through the trust portal;
    6. running more than one Organisation, within the limits of the paid-for Organisations, including Organisations of entities other than the Customer;
    7. using the Application Programming Interface within the limits of the permissions granted to the Access Key;
    8. downloading one's own data using the export features made available in the Platform.
  3. General principle. Everything is permitted that is not prohibited by the Policy, the Terms of Service, the End User Licence Agreement or a provision of law. The lists of prohibitions contained in the Policy are illustrative and do not create a presumption that conduct not listed in them is permitted where it infringes the law.

  4. If the Customer is in doubt whether the intended manner of using the Platform is permitted, it may ask at the general address before taking action. Guardiso replies on Business Days. Guardiso does not undertake to reply within any stated deadline, other than the deadlines resulting from the complaint procedure described in the Terms of Service.

  5. Obtaining from Guardiso a consent, given in writing or in documentary form, to a particular manner of use precludes Guardiso from later invoking a breach of the Policy in that respect, unless the Customer gave an untrue description of the intended action.


§ 4. Prohibition on supplying unlawful content

  1. The Customer and the User are prohibited from supplying content of an unlawful character. The prohibition follows from Article 8, paragraph 3, point 2, letter b of the Polish Act of 18 July 2002 on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną) and is repeated in Section 17 paragraph 1 of the Terms of Service.

  2. It is prohibited in particular to enter into the Platform:

    1. content infringing another party's copyright, related rights, database rights or industrial property rights;
    2. content infringing the personal interests (dobra osobiste) of natural or legal persons;
    3. content constituting another party's trade secret within the meaning of Article 11 paragraph 2 of the Polish Act of 16 April 1993 on Combating Unfair Competition (ustawa o zwalczaniu nieuczciwej konkurencji), where the Customer is not entitled to possess and use it;
    4. content inciting hatred, violence or discrimination;
    5. pornographic content involving a minor and other content the mere possession of which is prohibited;
    6. malicious software, code adapted to the commission of a prohibited act, and passwords, access codes and other data enabling unauthorised access to information stored in an IT system, referred to in Article 269b of the Polish Criminal Code (Kodeks karny);
    7. data obtained unlawfully, including data originating from a personal data breach or from a third party's data leak.
  3. The Platform is not a mailing channel. The Platform's features used to send messages, in particular User invitations, notifications and document circulation, may be used exclusively in relation to persons connected with the Customer's Organisation and persons performing tasks for the Customer. It is prohibited to use those features to send commercial information without the recipient's consent, to phish for information, to impersonate another person and to distribute bulk messages.

  4. Procedure after receiving a notice. Receipt of an official notice or of reliable information about the unlawful character of the stored data gives rise on Guardiso's part to the obligations resulting from Article 14 of the Act on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną). Where Guardiso receives reliable information, it notifies the Customer of its intention to disable access to such data before disabling it, stating the reason and the basis of the notice.

  5. Guardiso does not carry out any prior or automated review of the content entered by the Customer and is not obliged to check the stored data, in accordance with Article 15 of the Act on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną). Guardiso's course of action is described in Section 14.

  6. A Customer who establishes that it has entered unlawful content into the Platform removes it without undue delay and notifies Guardiso at the general address if the content may have been made available outside the Organisation.


§ 5. Data the Platform is not intended for

  1. Special categories of data. The Platform is not intended for the processing of special categories of data referred to in Article 9(1) of Regulation (EU) 2016/679 of the European Parliament and of the Council, nor of data relating to criminal convictions and offences referred to in Article 10 of that Regulation. This principle is identical to Section 2 paragraph 3 of the Data Processing Agreement. If the Customer enters such data in the content of documents, it does so at its own risk and informs Guardiso in advance, so that the parties can agree on additional protective measures.

  2. Data that must never be entered. The following must not be entered into the Platform:

    1. passwords, private keys, tokens and other authentication data for the systems of the Customer or of a third party — including in the content of evidence, screenshots and attachments;
    2. full payment card numbers, verification codes and payment transaction authentication data;
    3. classified information within the meaning of the Polish Act of 5 August 2010 on the Protection of Classified Information (ustawa o ochronie informacji niejawnych) — the Platform is not accredited for processing such information and does not meet the requirements laid down for IT systems processing such information.
  3. Information covered by legally protected secrecy. The Customer itself assesses whether transferring to the Platform information covered by professional secrecy or another legally protected secrecy requires consent, a release from that secrecy or a separate legal basis, and whether it has such a basis. Guardiso does not make that assessment for the Customer.

  4. Limiting the scope. Before uploading a document as evidence, the Customer removes or redacts the data that are not needed to demonstrate the circumstance to which the evidence relates.

  5. A breach of this Section does not change the roles of the parties in personal data protection. The Customer remains the controller of the entrusted data and Guardiso remains the processor, on the terms of the Data Processing Agreement. Guardiso may demand the deletion of data entered contrary to this Section.


§ 6. Accounts, access and User identity

  1. An Account is personal. An Account is set up for a designated natural person and for one person only. It is prohibited to share login credentials with another person and to use an Account set up for someone else.

  2. The reason for the principle in paragraph 1 is not a limit on the number of Users — the Plans do not limit the number of Users in an Organisation. The reason is accountability: the activity log in the Platform attributes every action to an Account, and a record attributed to a shared account ceases to be evidence of who performed the action and loses its value in audit proceedings.

  3. The email mailbox used for logging in is a means of authentication. The login link sent to that mailbox is authentication data and is subject to the same protection as a password. The Customer secures the Users' mailboxes and does not direct them to shared addresses accessible to an indeterminate group of persons.

  4. Access Keys for the Application Programming Interface are authentication data. The Customer is bound by the rules described in Section 6 of the End User Licence Agreement, in particular the prohibition on placing an Access Key in publicly available code and the obligation to revoke an Access Key without undue delay where its disclosure is suspected.

  5. Managing permissions. The Customer grants access to the Organisation solely to those persons who need it to perform tasks in that Organisation, to the extent necessary for that purpose, and withdraws access without undue delay from persons who have ceased to perform those tasks.

  6. Reporting suspected unauthorised access. The Customer notifies Guardiso at the security address without undue delay after forming a suspicion that an unauthorised person has gained access to the Account or to the Organisation.


§ 7. Load on the infrastructure and automated retrieval of content

  1. General prohibition. It is prohibited to use the Platform in a manner that threatens the continuity of its operation or the security of other Customers' data.

  2. Resource abuse includes in particular:

    1. carrying out load resilience testing and generating artificial traffic without Guardiso's prior consent referred to in Section 9;
    2. sending requests in a loop or at a frequency grossly departing from the frequency resulting from a human being working on documentation;
    3. launching artificial intelligence features on a mass scale for a purpose other than working on one's own documentation, in particular in order to generate a body of content for use outside the Platform;
    4. performing operations of a size grossly departing from normal use, in particular the one-off upload or download of files whose handling prevents other Customers from working;
    5. using the file storage space as a repository of materials unrelated to compliance documentation, in particular as a place for storing backups of the Customer's systems or an archive of recordings.
  3. Automated retrieval of the Platform's content is permitted exclusively by means of the export features and the Application Programming Interface, within the limits of the permissions granted to the Access Key. Retrieving content by other means, including by automated reading of the Platform's pages, is not permitted. This principle repeats Section 6 paragraph 7 of the End User Licence Agreement.

  4. Limits. Guardiso may introduce limits on the number of requests, the frequency of connections and the volume of data transferred, and may also temporarily restrict traffic that threatens the stability of the Platform or the security of other Customers' data. Where circumstances allow, Guardiso gives advance notice of the introduction of a limit. Traffic that threatens stability may be restricted without delay, with notice given after the fact.

  5. Prohibition on circumventing limits. It is prohibited to create additional Access Keys, Accounts or Organisations in order to circumvent a limit resulting from the Plan, from the Price List or from paragraph 4. This also applies to the artificial intelligence feature budget assigned to the Plan.

  6. Guardiso selects the least onerous measure capable of removing the threat. Restricting traffic takes precedence over suspending access, and suspending a single feature or Access Key takes precedence over suspending the entire Account.


§ 8. Prohibition on circumventing security measures and on probing other parties' data

  1. Prohibition on circumventing security measures. It is prohibited to circumvent, or attempt to circumvent, the Platform's security measures, in particular the authentication mechanisms, the permission controls, the separation of data between Organisations, the restrictions resulting from the Plan, the limits described in Section 7 and the watermarks and origin markings.

  2. Prohibition on probing other parties' data. Any attempt to obtain access to the data of an Organisation in which the User has not been granted a permission is prohibited, in particular by substituting an identifier in an address, by altering the content of a request sent to the Platform and by exploiting an identified error in the Platform.

  3. What to do if another party's data appear by accident. If a User sees the data of another Organisation without having taken any action aimed at obtaining them, the User is obliged to stop the activity without undue delay, not to copy or record those data, not to disclose them to anyone and to report the event at the security address, describing what was seen and in what circumstances. Guardiso draws no consequences against the Customer or the User in respect of an event handled in the manner described, and treats such a report as assistance in removing a vulnerability.

  4. Reverse engineering. The reconstruction of source code, decompilation and disassembly of the Platform are prohibited, subject to the rights resulting from Article 75 paragraph 2 point 2 and point 3 and paragraph 3 of the Polish Act of 4 February 1994 on Copyright and Related Rights (ustawa o prawie autorskim i prawach pokrewnych). The procedure for exercising those rights is described in Section 7 of the End User Licence Agreement.

  5. Consequences outside the Agreement. Guardiso informs that the actions described in paragraphs 1 and 2 may constitute the prohibited acts defined in Articles 267, 268, 268a, 269, 269a and 269b of the Polish Criminal Code (Kodeks karny). This information is of a purely cautionary nature. The terms on which Guardiso does not pursue claims and does not file a notification of a suspected offence against a security researcher are set out in Section 10.

  6. Prohibition on using the Platform against third parties. It is prohibited to use the Platform's features to probe, scan or attack third-party systems. The domain security assessment feature may be used exclusively in relation to domains for which entitlement has been demonstrated in the manner provided for in the Platform.

  7. It is prohibited to use the Platform to transmit malicious software and to store tools serving the commission of a prohibited act. The prohibition does not cover the storage, as evidence, of material originating from an incident handled by the Customer, provided that the material is described and secured in a manner that prevents it from being executed.


§ 9. Security testing of the Platform

  1. Prohibited without consent. It is prohibited to carry out security testing of the Platform, including penetration testing, vulnerability scanning and load resilience testing, without Guardiso's prior consent given in documentary form and specifying the scope, the timing and the manner of conducting the tests. This principle repeats Section 7 paragraph 5 of the End User Licence Agreement.

  2. A request for consent is to be addressed to the security address. The request states: the commissioning entity, the performing entity and the persons carrying out the test, the scope and methods, the planned time window, the addresses from which traffic will be generated, the contact details of a person available during the test, and an undertaking to keep the findings confidential.

  3. Handling of the request. Guardiso considers the request on Business Days and may make available for this purpose a separate test environment operating on synthetic data, segregated from the production environment. Guardiso does not undertake to grant consent or to make a test environment available within any stated deadline.

  4. Never on other Customers' data. A test may not be conducted on the production environment in a manner affecting the data of other Customers, irrespective of any consent granted.

  5. Prohibited irrespective of consent. The consent referred to in paragraph 1 never covers:

    1. denial-of-service attacks and tests consisting in resource exhaustion;
    2. social engineering against Guardiso, against its personnel and against its suppliers, including phishing attempts and impersonation;
    3. attempts to gain physical access to the infrastructure;
    4. tests directed at the systems of Guardiso's suppliers, who are subject to their own terms and their own vulnerability reporting rules;
    5. actions affecting the data of other Customers.
  6. What Guardiso does not do. Guardiso does not conduct periodic penetration testing of the Platform and does not declare any frequency of such testing. Tests are conducted on request and before significant changes. This information is consistent with Section 4 of the Service Level Agreement and with Part B of Annex No. 1 to the Data Processing Agreement.

  7. The result of a test carried out by the Customer or on its instruction constitutes Confidential Information of both parties. The Customer passes to Guardiso the findings concerning the Platform without undue delay after establishing them, under the procedure set out in Section 10.


§ 10. Vulnerability reporting by security researchers

  1. Address and procedure. A vulnerability is to be reported to the security address. Guardiso accepts reports from anyone, including from a person who is neither a Customer nor a User. The contact details are also published in the file specified by the RFC 9116 standard, at https://guardiso.com/.well-known/security.txt.

  2. Guardiso's undertaking. Towards a security researcher who has met the conditions described in paragraph 3, Guardiso:

    1. will not pursue claims for a breach of Sections 7, 8 and 9 of this Policy or for a breach of Section 7 of the End User Licence Agreement;
    2. will not file a notification of a suspected offence in connection with the reported research;
    3. will treat the research as having been undertaken with Guardiso's consent and, should the need arise, will present a statement to that effect to the competent authority;
    4. will not require the security researcher to refrain from publication on terms other than those described in paragraph 6.
  3. Conditions the fulfilment of which triggers the undertaking under paragraph 2. The security researcher:

    1. acted in good faith, with the aim of detecting and reporting a vulnerability, and not with the aim of obtaining a benefit from exploiting it;
    2. limited the action to the extent necessary to demonstrate the existence of the vulnerability and did not extend it after confirming the vulnerability;
    3. did not download, disclose, alter or delete another person's data, and where access to such data occurred unintentionally — stopped the activity without undue delay, reported this to Guardiso and deleted all copies held;
    4. did not disrupt the operation of the Platform, in particular did not conduct a denial-of-service attack, did not generate mass traffic and did not delete or modify any configuration;
    5. did not conduct social engineering against Guardiso's personnel or its suppliers and did not attempt to gain physical access to the infrastructure;
    6. reported the vulnerability without undue delay after establishing it, describing it in a manner that allows it to be reproduced;
    7. did not disclose the vulnerability publicly before the date resulting from paragraph 6;
    8. did not make the report, or the refraining from disclosure, conditional on payment;
    9. did not infringe provisions of law, in particular the provisions on the protection of personal data.
  4. What the undertaking under paragraph 2 does not cover — and we say so plainly. Guardiso's undertaking:

    1. does not release the security researcher from liability towards third parties — Guardiso cannot dispose of other parties' claims, in particular the claims of other Customers and of data subjects;
    2. does not preclude proceedings conducted ex officio by law enforcement authorities — Guardiso can only refrain from filing a notification and present the statement described in paragraph 2 point 3;
    3. does not cover research into the systems of Guardiso's suppliers, including the infrastructure supplier and the edge network supplier, who operate their own vulnerability reporting rules;
    4. does not cover actions taken after the report that go beyond the scope to which the report related.
  5. What Guardiso does after receiving a report. Guardiso confirms receipt of the report, assesses it, and informs the security researcher of its findings and of the removal of the vulnerability. All these activities are performed on Business Days. Guardiso does not operate a 24-hour on-call service and does not undertake to respond within any stated time or to remove a vulnerability by any stated deadline. Guardiso informs the security researcher if it considers that the reported property of the Platform is not a vulnerability, stating the reason.

  6. Coordinated disclosure. The security researcher may disclose the vulnerability publicly after it has been removed by Guardiso or after ninety days have elapsed from the report, if the vulnerability has not been removed by then and the parties have not agreed on a longer period. Guardiso undertakes not to require silence for an indefinite period. Agreeing on a longer period requires a reason to be stated.

  7. Scope outside research. Guardiso does not treat as a vulnerability the mere absence of a recommended practice, where it does not lead to a specific effect, nor vulnerabilities in third-party software used on the security researcher's side, in particular the browser.

  8. No bounty programme. Guardiso does not operate a bounty programme for vulnerability reports and does not pay remuneration for reports. Guardiso may thank a security researcher publicly, solely with that researcher's prior consent and in a form agreed with them.

  9. The security researcher's personal data are processed for the purpose of handling the report, on the terms described in the Privacy Policy. A report may be submitted without providing identifying data, save that Guardiso will then be unable to communicate information about the outcome.

  10. A vulnerability report is not a complaint within the meaning of the Terms of Service and does not trigger the deadlines of the complaint procedure. A Customer wishing to pursue claims connected with a vulnerability files a separate complaint at the general address.


§ 11. Use of artificial intelligence features

  1. How it works. Artificial intelligence features are launched upon a User's prompt. The content of the prompt and the fragment of the material to which the launched feature relates are transferred to the model provider indicated in the list of sub-processors. The scope of the data transferred is described in Section 7 of the Privacy Policy.

  2. What must not be entered in a prompt. A prompt must not contain:

    1. passwords, private keys, tokens, Access Keys or other authentication data — whether one's own or another party's;
    2. full payment card numbers, verification codes or payment transaction authentication data;
    3. special categories of data referred to in Article 9(1) of Regulation (EU) 2016/679, or data referred to in Article 10 of that Regulation;
    4. classified information;
    5. personal data that are not necessary to obtain an answer, and where they are necessary — to an extent wider than necessary; as far as possible the User replaces identifying data with a designation of a function or a role;
    6. data of third parties in respect of whom the Customer has no legal basis for processing or has not discharged its information obligation;
    7. information covered by legally protected secrecy, where the Customer has no basis for disclosing it to a processor outside its own organisation;
    8. unlawful content referred to in Section 4.
  3. A reservation that must be stated plainly. Guardiso does not automatically filter the content that a User enters in a prompt. If a User places there the data listed in paragraph 2, they will be transferred to the model provider together with the prompt. Responsibility for the content of a prompt rests with the Customer. This reservation is identical to Section 7 paragraph 4 of the Privacy Policy.

  4. Prohibition on circumventing the model's safeguards. It is prohibited to formulate prompts aimed at circumventing the safeguards of the model or of the Platform, in particular at obtaining content concerning another Customer, at disclosing the Platform's configuration, at generating unlawful content and at obtaining an answer going beyond the User's permissions in the Organisation.

  5. Prohibition on use inconsistent with the intended purpose. The artificial intelligence features must not be used:

    1. to generate content unrelated to the Customer's compliance documentation;
    2. as an intermediary in accessing a language model for the Customer's own applications or those of a third party;
    3. to train, fine-tune or evaluate artificial intelligence models;
    4. to build a product or service competing with the Platform.
  6. Obligation of human verification. Content generated by the model has the character of a suggestion and a draft. Before it is incorporated into the Customer's documentation it requires reading, correction and approval by a human being. These rules are described in Section 9 of the End User Licence Agreement and in Section 7 of the Privacy Policy. Guardiso does not warrant the correctness, completeness or currency of content generated by the model.

  7. Labelling. The Platform labels content generated by the model and interactions with artificial intelligence, thereby discharging the transparency obligations resulting from Article 50 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 on artificial intelligence. A Customer who passes on externally a document created from such content is itself responsible for informing the recipient, where such an obligation results from a provision of law binding on the Customer.

  8. Customer Data are not used to train models — neither by Guardiso nor by the model provider.


§ 12. Granting access to outside parties and running more than one company

  1. What is permitted. The Customer may grant access to the Organisation to an external auditor, a certification body or another third party performing a task for the Customer, within the scope of the features provided for that purpose in the Platform. The Customer may make documents produced in the Platform available to its counterparties, auditors and authorities. Details are set out in Section 5 of the End User Licence Agreement.

  2. Running more than one Organisation is permitted, including for entities other than the Customer, within the limits of the paid-for Organisations. The rules, including the fee for each additional Organisation, are set out in Section 4 of the End User Licence Agreement and in the Price List.

  3. What is not permitted without Guardiso's separate consent given in a Partner Agreement:

    1. selling, reselling, leasing or otherwise providing access to the Platform as a separate performance;
    2. presenting the Platform as one's own software or one's own service, including making it available under one's own domain or trade name;
    3. making one paid-for Organisation available to several entities in order to avoid the fee for further Organisations;
    4. offering access to the Platform as an element of one's own offering, where the recipient pays for access to the Platform itself rather than for a service performed using it.
  4. Providing one's own advisory, implementation and support services for consideration using the Platform, within the paid-for Organisations, is permitted. Paragraph 3 concerns exclusively dealings in access to the Platform as such.

  5. The Customer does not remove or alter the origin markings, rights notices and watermarks placed on materials downloaded from the Platform or made available through it.

  6. The Customer is responsible for the selection of the persons to whom it grants access and for the scope of that access.


§ 13. Content Library

  1. The Content Library is protected as a work, as a database and as a trade secret. The full rules for using it are set out in Section 8 of the End User Licence Agreement, which takes precedence over this Section.

  2. It is prohibited in particular:

    1. to extract and re-utilise the Content Library in whole or in a substantial part for a purpose other than working on one's own documentation or on the documentation of a paid-for Organisation;
    2. to extract it in a repeated and systematic manner, contrary to normal use of the Platform;
    3. to pass it on in unprocessed form — as a set of templates, a catalogue or mappings — to an entity other than the entity for which a paid-for Organisation is maintained;
    4. to use it to build a product or service competing with the Platform;
    5. to use it to train, fine-tune or evaluate artificial intelligence models;
    6. to publish it and make it publicly available, including in open repositories and document-sharing services.
  3. The right to extract and re-utilise an insubstantial part, evaluated qualitatively or quantitatively, of the Content Library, resulting from Article 7 of the Polish Act of 27 July 2001 on the Protection of Databases (ustawa o ochronie baz danych), remains unaffected.

  4. The prohibitions described in paragraph 2 continue to apply after the termination of the Agreement.


§ 14. How Guardiso detects breaches and what it does not do in this respect

  1. What Guardiso does. Guardiso maintains an activity log in the Platform containing the time, the Account, the action and the internet protocol address, records calls to the Application Programming Interface and monitors the load on the Platform.

  2. What Guardiso does not do — and we say so plainly:

    1. Guardiso does not read the content of the Customer's documents in search of breaches and does not carry out automated content review;
    2. Guardiso does not have standing access to Customer Data. Every access by Guardiso's personnel requires a request stating the scope, the time and the justification, and the Customer's consent; it is limited in time and visible to the Customer in the access log. The Customer may withdraw its consent at any time;
    3. Guardiso does not maintain an alert collection system or automated failure notification and does not operate a 24-hour on-call service. A breach may therefore be noticed with a delay, and the most frequent source of knowledge about an irregularity is a report from the Customer. This information is consistent with Section 4 of the Service Level Agreement.
  3. Guardiso is not obliged to check the stored data, in accordance with Article 15 of the Act on Providing Services by Electronic Means (ustawa o świadczeniu usług drogą elektroniczną).

  4. Inspection of Customer Data for the purpose of clarifying a breach requires an access request to be submitted and the Customer's consent to be obtained, under the procedure described in the Data Processing Agreement. An exception is the emergency procedure, permissible solely in the case of a genuine security incident, where delay would risk an infringement of the rights or freedoms of natural persons. Guardiso notifies the Customer of every such access without undue delay, and no later than within seven days, stating the reason, the scope and the time of access and the actions taken. This principle is set out in Section 5 paragraph 5 of the Data Processing Agreement, which takes precedence over this paragraph.

  5. Guardiso uses the findings made under the procedure in paragraph 4 exclusively to clarify the breach and to remedy it.


§ 15. Consequences of a breach and the procedure applied

  1. Principle of graduation. Guardiso applies measures in order from the least to the most onerous: a demand, a restriction of features or traffic, suspension of access, termination of the Agreement. Guardiso selects a measure proportionate to the gravity of the breach and to the threat it causes.

  2. Demand. Where a breach is established, Guardiso calls upon the Customer to cease the breach and to remedy its effects, stating what the breach consists in and what Guardiso demands. The deadline set in the demand is not shorter than seven days, and in matters covered by the End User Licence Agreement — not shorter than fourteen days.

  3. Suspension without a prior demand is permissible only where the breach:

    1. threatens the security of other Customers' data or the continuity of the Platform's operation;
    2. consists in an attempt to obtain access to the data of another Organisation;
    3. consists in mass extraction of the Content Library or in the circumvention of security measures described in Section 8;
    4. consists in granting access to unauthorised persons in a manner causing a real risk to data;
    5. is the subject of an official notice referred to in Section 4 paragraph 4.

    In such a case Guardiso notifies the Customer of the suspension and of its reason without undue delay, and no later than on the following Business Day.

  4. Measures narrower than suspension of the Account. Before Guardiso suspends access to the entire Account, it considers: restricting the number of requests, disabling a single Access Key, disabling a single feature and disabling access to specific content.

  5. Access to data. Before access is suspended, the Customer is given the opportunity to download Customer Data, unless the breach threatens the security of other Customers' data. In the latter case Guardiso makes the data available by another route, once the threat has ceased. The rules for releasing data are described in the document "Service Exit and Data Portability Rules".

  6. Access is restored without undue delay after the breach and its effects have been remedied, and no later than within two Business Days of Guardiso establishing that circumstance.

  7. Termination of the Agreement. Once the deadline set in the demand has expired without effect, Guardiso may terminate the Agreement with immediate effect, on the terms and for the reasons described in Section 22 paragraph 4 of the Terms of Service.

  8. Claims. A breach of the Policy does not give rise to an obligation to pay a contractual penalty — the Policy does not provide for contractual penalties. Guardiso is entitled to the claims described in Section 21 of the Terms of Service and in Section 15 paragraph 5 of the End User Licence Agreement, including the claim for payment of the fees for Organisations maintained without payment of the fee due.

  9. Challenging Guardiso's decision. The Customer may challenge the merits of a demand, a restriction, a suspension or a termination under the complaint procedure described in the Terms of Service. Filing a complaint does not suspend the effects of a suspension, unless Guardiso decides otherwise.

  10. Settlement for the period of suspension. Suspension of access on account of a breach of the Policy does not release the Customer from the Subscription fee. This provision does not apply to suspension on account of payment arrears — in that case no fee is charged for the period of suspension, in accordance with Section 13 paragraph 4 point 4 of the Terms of Service, which takes precedence over this paragraph. If a complaint is upheld, or if Guardiso itself establishes that the suspension was unfounded, the Customer is entitled to a reduction of the fee for the period of suspension and, if the fee has already been paid, to a refund of that part.

  11. In relation to a Protected Customer, the rights described in this Section are exercised subject to the mandatory provisions of consumer protection law.


§ 16. Reporting breaches of the Policy

  1. A breach of the Policy may be reported by anyone — a Customer, a User and a third party. Reports concerning security are to be addressed to the security address, all others to the general address.

  2. A report should state: what it concerns, what the breach consists in, when it was noticed and — if the reporting person wishes to receive information about the outcome — contact details.

  3. Guardiso confirms receipt of the report and informs the reporting person how it has been handled, to the extent that this does not infringe confidentiality towards the Customer to whom the report relates, or the provisions on the protection of personal data.

  4. Guardiso may refuse to consider further any manifestly unfounded reports and reports made in bad faith, in particular reports made in order to harm another Customer, informing the reporting person accordingly.

  5. A report of a breach of the Policy is not a complaint. A Customer pursuing its own claims files a separate complaint under the procedure set out in the Terms of Service.


§ 17. Amendments to the Policy and final provisions

  1. Amendments to the Policy are announced by Guardiso thirty days in advance, with notice given to the Customer by email to the address of the Account Owner and by a message in the Platform. The absence of an objection within that period means acceptance of the amendment. An objection entitles the Customer to terminate the Agreement with a refund of the fee for the unused part of the Billing Period.

  2. An amendment taking effect without delay. An amendment necessary on account of the security of the Platform, the removal of a vulnerability or alignment with a mandatory provision of law may take effect without delay, with notice given after the fact. Such an amendment may not extend the Customer's obligations beyond the scope resulting from the reason that justifies it.

  3. An amendment to the Policy does not affect rights acquired before the date on which it enters into force, nor the assessment of events that occurred earlier.

  4. The governing law is Polish law. The choice of Polish law does not deprive a Protected Customer resident in another Member State of the European Union of the protection resulting from the mandatory provisions of the law of the State of their residence.

  5. Disputes arising out of the Policy are resolved in accordance with the rules described in Section 27 of the Terms of Service, including the rules on out-of-court dispute resolution available to a Protected Customer.

  6. If any provision of the Policy proves to be invalid or ineffective, the remaining provisions remain in force. In place of an invalid provision, the relevant provision of law applies and, in the absence of such a provision, the provision closest to the intended economic purpose.

  7. The Policy is drawn up in the Polish language. Where a translation into another language is made available, the Polish version prevails in the event of a discrepancy.

  8. Version history:

VersionDateScope of change
1.01 September 2026First edition. Separation of the acceptable use rules from Section 17 of the Terms of Service into a stand-alone document, addition of the rules for using artificial intelligence features and of the vulnerability reporting rules together with a safe harbour for security researchers.