Acceptable Use Policy
This Acceptable Use Policy (the “Policy”) sets the operational rules that bind the Customer, its Beneficiaries, and every Authorized User when accessing the Solution. It is incorporated by reference into the General Terms and Conditions at §4.2 and is binding on the same terms as the Agreement itself. Read together with the Data Processing Agreement and the Security policy, it defines the Solution’s instructions for use (as defined by Regulation 2024/1689 of the European Parliament and the Council of 13 June 2024 laying down harmonised rules on artificial intelligence, hereafter the “EU AI Act”).
1. Scope and definitions
This Policy binds the Customer, all Beneficiaries, and all Authorized Users as those terms are defined in the General Terms and Conditions (the “GTCs”). Capitalized terms used here without further definition have the meaning given to them in the Agreement.
Any breach of this Policy is a material breach of the Agreement and may trigger the remedies described in Section 8 below, including suspension, deployment of the circuit-breaker under GTC §4.6, and termination under GTC §12.2.
2. Intended Purpose and Permitted use
The Solution’s intended purpose, within the meaning of the EU AI Act, is to (i) provide voice-based sales-coaching simulations, (ii) generate post-drill coaching feedback, and (iii) provide summarized performance reporting to the Customer’s management. Use that deviates from this intended purpose is not compliant with the Agreement and may entail the qualification of the Customer as “provider” under Article 25(1)(c) of the EU AI Act, per GTC §3.2.
More specifically, the Solution does not pursue the objective of assessing the social value, trustworthiness, or general desirability of individuals. Rather, the Solution generates simulated conversational interactions and provides feedback limited to predefined professional competencies and rehearsal metrics (e.g., communication effectiveness, objection handling, adherence to scripted sales methodologies, or product knowledge).
The scoring or performance indicators generated by the Solution are therefore limited in scope and context and should be understood solely as pedagogical indicators intended to support employee skills development.
In particular:
- the Solution is not intended to profile individuals based on their social behaviour across different contexts;
- the Solution does not aggregate behavioural or personal data originating from unrelated social environments;
- the Solution does not establish a generalised reputation, trustworthiness, or social score attributable to employees;
- any scores, ratings, or feedback generated by the Solution are limited to the assessment of performance within specific drill scenarios and do not constitute an evaluation of an individual’s overall professional aptitude, personality, trustworthiness, or social behaviour;
- Voice data is used only for speech interaction and communication coaching, emotional inference models are not deployed;
- the Solution is not designed to produce legal or similarly significant effects on employees; and
- The Solution is intended exclusively for the rehearsal of client conversations and the coaching of retail teams. Outputs generated by the Solution are informational only and must not be used as the sole or decisive basis for employment-related decisions, as further provided in Section 4 below.
3. Prohibited content
The Customer, its Beneficiaries, and Authorized Users will not submit to the Solution, generate through the Solution, or use the Solution to disseminate any of the following:
- Illegal content.
- Harassment, discrimination, hate speech, or content that incites violence against any individual or group, including on the basis of race, religion, gender, sexual orientation, disability, or any other protected characteristic.
- Sexual content, sexually suggestive content, or content of a personal-relationship nature outside the legitimate scope of client-conversation rehearsal.
- Content involving minors in any drill scenario other than fact-based product-knowledge questions appropriate to the Customer’s regulatory context.
- Real customer personal data introduced into the Solution as drill content without the prior, documented, explicit consent of the data subject. Synthetic or pseudonymized client personas must be used instead.
- Confidential Information of third parties that the Customer is not entitled to disclose to Prestance Lab under existing contractual or legal obligations.
- Attempts to misuse the Solution to extract competitive intelligence from simulated personas, bypass safety instructions, or elicit Outputs that would breach this Policy — including but not limited to prompt-injection techniques.
4. Prohibited use of Outputs — HR and automated decision-making
The Outputs of the Solution — including transcripts, scores, skill maps, coaching letters, and any derivative metric — must not be used:
- As the sole or principal basis for any human-resources decision, including but not limited to hiring, promotion, demotion, bonus or variable-pay calculation, performance review, role assignment, disciplinary action, access to professional opportunities or termination of employment;
- As the basis for any automated decision-making within the meaning of Article 22 of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) — in that regard, the Solution is designed to support human-led coaching processes and does not autonomously make decisions concerning employees;
- To infer the emotional state, mental health, mood, personality, or any similar data within the meaning of Article 5(1)(f) of the EU AI Act (Regulation (EU) 2024/1689), of any natural person.
The Customer is responsible for ensuring that all internal communications about the Solution’s Outputs — to managers, to HR, and to Authorized Users themselves — are consistent with these restrictions.
Customers remain solely responsible for ensuring that their use of the Solution and any decisions taken on the basis of its Outputs comply with all applicable laws and regulations, including employment, labour, anti-discrimination, data protection, and workplace monitoring laws.
5. Account security
- Authorized Users must keep their Login Credentials confidential and secure, as required by GTC §5.3.
- Each user account is personal to one Authorized User. Account sharing is prohibited. Where an account is fully reassigned to a different Authorized User, the previous user immediately loses access (GTC §5.3).
- Multi-factor authentication must be enabled wherever the Customer’s identity provider supports it.
- Suspected credential compromise must be reported to security@sparred.ai without undue delay.
6. Compliance with upstream sub-processor AUPs
The Solution relies on third-party artificial-intelligence and infrastructure sub-processors. The Customer, Beneficiaries and Authorized Users will comply with the acceptable-use policies of those sub-processors, which are incorporated into this Policy by reference:
- Google Generative AI Prohibited Use Policy (real-time voice provider)
- OpenAI Usage Policies
- Fireworks AI Terms of Service (see “Acceptable use”)
- Supabase Acceptable Use Policy
- LiveKit Acceptable Use Policy
- Fly.io Acceptable Use Policy
Where a sub-processor’s acceptable-use policy and this Policy address the same matter, the stricter restriction prevails.
7. Reporting violations
Suspected violations of this Policy must be reported to abuse@sparred.ai. Reports should include:
- the workspace identifier;
- the Authorized User identifier, where known;
- a description of the suspected violation; and
- relevant timestamps.
Prestance Lab will acknowledge receipt within 2 business days and will investigate in good faith. The Customer may be asked to assist with the investigation in respect of conduct attributable to its Beneficiaries or Authorized Users.
8. Consequences of breach
- Prestance Lab may suspend a Client, Beneficiary and/or an Authorized User’s access immediately upon an actual or suspected material breach of this Policy, pending investigation.
- Prestance Lab may deploy the circuit-breaker described in GTC §4.6 — interrupting and stopping the Solution where, acting reasonably, Prestance Lab considers it necessary to do so or to comply with the EU AI Act or any other applicable law. No compensation is due to the Customer where the circuit-breaker is deployed.
- The Customer remains responsible for the acts and omissions of its Beneficiaries and Authorized Users under the Agreement.
9. Updates to this Policy
In accordance with GTC §2.7, Prestance Lab may update this Policy from time to time. Material changes will be notified to active Customers at least 30 days in advance, unless the change is required by applicable law or is needed to address a material security risk, in which case it may take effect with shorter notice.
10. Contact
- AUP questions and abuse reports: abuse@sparred.ai
- Security incidents: security@sparred.ai
- Privacy and DPA matters: privacy@sparred.ai