1. Scope
This policy forms part of the Terms of Service and applies to everyone who uses Priveloq Chat — account holders, administrators and guests in temporary rooms alike.
An organisation is responsible for use of its own workspace. Where an organisation's own policies are stricter than this one, those apply to its people as well.
2. What you must not do
Unlawful and harmful activity
- Break any law that applies to you or to us.
- Harass, bully, threaten, stalk or intimidate anybody, or incite anyone else to.
- Share material that sexually exploits or endangers a child, or any other content whose possession or distribution is itself unlawful.
- Promote or organise violence, terrorism, or the targeting of people on the basis of who they are.
- Use the Service to traffic in stolen data, credentials or unlawful goods.
Security and integrity
- Access, or try to access, any account, workspace, conversation, file or record you have not been given access to.
- Probe, scan or test the security of the Service, or of another organisation's deployment, without written authorisation. See section 4 for how to report something you find.
- Circumvent, disable or interfere with authentication, authorisation, rate limiting, audit logging, retention controls or any other security control.
- Upload, host, link to or transmit malware, ransomware, spyware or any other malicious code.
- Use the Service to conduct phishing, credential theft, fraud or impersonation of a person or organisation.
- Interfere with the operation of the Service, including through deliberate overload, denial of service, or abuse of an automated interface.
- Share your credentials, or use somebody else's, or misrepresent your identity or affiliation.
Other people's rights
- Infringe copyright, trade marks, patents, trade secrets or any other intellectual property right.
- Upload personal information about somebody else that you have no lawful basis to share, or publish private information about a person without their agreement.
- Record, capture or redistribute a conversation or a call in a way that breaks the law that applies to you or the expectations of the people in it.
Abuse of the Service
- Send unsolicited bulk messages, chain messages or other spam, in the product or through invitations.
- Use invitations or guest rooms to reach people who have not asked to hear from you.
- Resell, sublicense or provide the Service to a third party except as a written agreement with us allows.
- Use the Service to build a competing product, or to benchmark it for publication, without our written permission.
- Use it as general-purpose file storage or a content delivery network unrelated to communication and collaboration.
3. Your responsibilities
- Make sure you have the right to put into the Service whatever you put into it.
- Be careful who you send a guest room link to. Before it is redeemed, anybody holding it can become the guest.
- Keep your credentials and any second factor to yourself, and report a compromise promptly.
- Remember that the Service is not end-to-end encrypted. Do not put content into it whose confidentiality depends on the server being unable to read it.
4. Reporting abuse and security problems
If somebody is using Priveloq Chat in a way this policy forbids, tell us. If you are in an organisation's workspace, tell your administrator as well — they can usually act fastest.
Security vulnerabilities. We welcome reports made in good faith. Please report privately, give us a reasonable chance to fix the problem before you tell anybody else, and do not access, modify or keep anybody else's data while investigating. Testing against another organisation's deployment without their written authorisation is not acceptable use, whatever the motive.
Security reports: insight@priveloq.com
Anything else: hello@priveloq.com or the contact page.
5. What we do about breaches
Where this policy is breached we may, depending on how serious it is and on what is needed to protect the Service and other people:
- Contact you or your organisation's administrators about it.
- Remove or make unavailable the content concerned.
- Suspend or limit an account, a workspace or a feature.
- Terminate access, in line with the Terms of Service.
- Report the matter to the authorities where the law requires it, or where somebody's safety is at risk.
We aim to take the least disruptive action that resolves the problem, and to tell you why we acted and what would put it right — unless telling you would itself be unlawful or would make the harm worse. Urgent action to protect the Service or a person may be taken first and explained afterwards.
6. Changes
This policy is versioned, and its version and effective date are at the top of this page. We may update it as new kinds of abuse appear. Where a change materially affects you, we will ask you to accept the revised version.