Acceptable Use Policy
Rules for using Dotless responsibly, lawfully, and without harming people or systems.
Last updated August 7, 2026
1. Scope
This Acceptable Use Policy (“AUP”) forms part of the Dotless Terms of Service. It applies to every user, workspace, integration, API request, prospecting action, email, published website, upload, and other use of the Service. Capitalised terms have the meanings in the Terms. Customer is responsible for its users, clients, recipients, and anyone using its credentials or integrations.
2. Lawful data and prospecting
You must not use Dotless to:
•
collect, upload, enrich, infer, buy, sell, disclose, or use personal data without the notices, rights, permissions, lawful basis, and source rights required by law and contract;
•
target or segment people using health, biometric, genetic, precise location, political, religious, union, sexual-life, criminal-record, government-identifier, financial-account, or other sensitive data without Dotless’s prior written approval and a demonstrably lawful basis;
•
collect private-account content, authentication credentials, payment-card data, passwords, children’s data, or data obtained through unauthorized access;
•
ignore an objection, opt-out, do-not-contact request, suppression list, deletion request, or restriction applicable to the campaign;
•
circumvent a source’s access controls, robots instructions, contractual restrictions, licence limits, or technical measures; or
•
represent data as verified, complete, current, or permission to contact when it is not.
Public availability does not by itself establish a lawful basis or a right to reuse information. You must keep reasonable source, legal-basis, and suppression evidence appropriate to your campaign and provide it to Dotless where reasonably requested to investigate abuse.
3. Communications and anti-spam
You must:
•
send only communications permitted by the recipient’s jurisdiction, relationship, and status, including rules applicable to sole traders and individual subscribers;
•
use accurate from, reply-to, routing, domain, and subject information and never impersonate another person or conceal the sender;
•
identify the responsible business, include a valid postal address and other legally required disclosures, and make commercial purpose clear where required;
•
provide a conspicuous, functioning, easy, and free unsubscribe or objection method whenever required, and honour it promptly and within every applicable deadline;
•
apply relevant suppression lists before every send and avoid re-uploading or re-enriching a suppressed address for renewed contact;
•
monitor bounces, complaints, blocklists, reputation, and provider limits and pause activity when warning signs arise; and
•
comply with GDPR, ePrivacy and electronic-communications rules, CAN-SPAM, CASL, PECR, and other applicable privacy and marketing laws.
You must not send spam, bulk unsolicited messages where consent is required, list-bombing, snowshoe spam, purchased-list campaigns without verified rights, phishing, advance-fee or investment fraud, deceptive offers, chain messages, harassment, threats, or malware. Dotless may impose recipient, domain, volume, speed, or reputation limits even if a plan is marketed without a fixed Dotless sending quota.
4. Harmful, deceptive, and illegal activity
You must not use the Service for content or conduct that:
•
is unlawful, fraudulent, defamatory, threatening, exploitative, discriminatory, or intended to facilitate violence or serious harm;
•
sexually exploits any person, involves non-consensual intimate content, or depicts sexual abuse of children;
•
facilitates trafficking, illegal weapons, controlled substances, sanctions evasion, money laundering, or evasion of law enforcement;
•
deceives people about material terms, identity, endorsements, scarcity, reviews, results, affiliation, or the nature of an AI-generated interaction;
•
infringes copyright, trademark, design, privacy, publicity, database, confidentiality, trade-secret, or other rights;
•
publishes another person’s sensitive or private information without authorization, commonly called doxxing; or
•
violates a court order, authority decision, professional obligation, or sector rule applicable to you.
5. Security and platform integrity
You must not:
•
introduce malware, destructive code, hidden miners, credential theft, spam traps, or content designed to compromise a device or account;
•
probe, scan, penetrate, overload, disrupt, or test the vulnerability of the Service without prior written authorization;
•
bypass authentication, access another tenant, intercept traffic, forge requests, or use leaked or unauthorized credentials;
•
circumvent quotas, billing, rate limits, account restrictions, abuse controls, suppression mechanisms, or provider safeguards;
•
create accounts or distribute activity to conceal identity, avoid enforcement, inflate metrics, or evade a suspension;
•
use undocumented automated access, scraping, crawling, or browser automation against Dotless except where mandatory law permits it; or
•
reverse engineer, copy, mirror, extract, benchmark, or use the Service to train or build a competing product as prohibited by the Terms.
6. Published websites and AI output
Before publishing, you must review generated text, code, images, claims, links, forms, cookies, and accessibility. Do not publish unsafe code, unlawful tracking, deceptive interfaces, impersonation, intellectual-property infringement, or content for which you lack rights. A Customer website must display accurate publisher and contact information and the legal notices, consent controls, and offer terms required for that business and audience.
Do not use AI features to make eligibility, employment, credit, housing, insurance, healthcare, legal, biometric, criminal-justice, or other high-impact decisions about a person without an independently lawful system, qualified review, transparency, testing, and meaningful human oversight. Do not present AI output as professional advice or verified fact without review.
7. Enforcement
Dotless may investigate suspected violations using proportionate account, delivery, security, and complaint information. Depending on severity and urgency, we may warn, require remediation, reduce rates, block content or recipients, disable integrations or publication, preserve evidence, suspend, or terminate access. We may act immediately to protect recipients, infrastructure, providers, or the public, and may report apparent criminal conduct or respond to lawful authority requests.
Where practical, we will explain the reason and allow an appeal or cure. We are not required to disclose information that would compromise security, another person’s rights, a confidential investigation, or a legal restriction. Repeated or deliberate violations may result in permanent termination without refund.
8. Reporting abuse
Report spam, phishing, unsafe content, or another AUP violation to support@dotless.co. Include the sender, relevant URL or message headers, date and time, and a description, but do not send passwords or unnecessary sensitive data. Intellectual-property claims should follow the Intellectual Property Policy; privacy requests should follow the Privacy Policy.
