KIVEX Acceptable Use Policy
This policy (the “AUP”) forms part of the Contract and applies to the Customer, its Users, Agents, sources, integrations, APIs and content processed through KIVEX.
This is an English translation provided for convenience. In the event of any discrepancy between the Czech and English versions, the Czech version prevails.
Contents
1. Basic rule
KIVEX may be used only lawfully, securely, transparently and within the scope of the Customer's authorisation. The Customer is responsible for the conduct of its Users and for the configuration of its Agents.
2. Prohibited content and activities
Through the Service, the Customer must not, in particular:
- breach laws, decisions of public authorities, contractual obligations or the rights of third parties;
- disseminate unlawful, fraudulent, misleading, threatening or otherwise illegal content;
- engage in phishing, impersonation, social engineering or unauthorised collection of access credentials;
- distribute malware, malicious code or instructions intended for unauthorised access, sabotage or circumvention of security;
- upload or make available content, personal data, trade secrets or copyright works without the necessary rights;
- use the Service for harassment, unlawful discrimination or targeted harm to persons;
- generate or distribute child sexual abuse material, terrorist content or any other content whose possession or dissemination is prohibited;
- use the Service for spam, unsolicited communications or deceptive lead generation;
- conceal that an End User is communicating with AI, or present an Agent as a specific human being;
- remove or circumvent mandatory AI labels, security warnings or KIVEX transparency features.
3. Personal data and sensitive use
3.1. The standard Service is not designed for the targeted collection of special categories of personal data, data relating to criminal matters, full payment card details, passwords, private keys or other authentication secrets.
3.2. The Customer must not enable the processing of special categories of data or a high-risk use case without a prior assessment, the necessary legal basis and a written agreement with KIVEX.
3.3. The Customer must truthfully inform End Users about the controller, the purpose of processing, the involvement of KIVEX, voice features, retention and their rights.
3.4. Persistent identifiers, recognition of returning anonymous visitors and linking of visits across sessions may be enabled only after appropriate consent has been obtained, unless the use of the identifier is demonstrably strictly necessary for a specific feature expressly requested by the End User.
4. AI use
4.1. Prohibited use
The Customer must not use KIVEX for any activity prohibited by Regulation (EU) 2024/1689 or other applicable law. This includes, in particular, practices that are prohibited under applicable law and cannot be legitimised merely by introducing an internal process or obtaining KIVEX's consent.
The Customer further must not:
- use manipulative, subliminal or deceptive techniques in a manner prohibited by law;
- carry out impermissible social scoring, biometric categorisation or emotion recognition to the extent that such use is prohibited;
- create the false impression that an AI Output has been verified by a human where it has not;
- circumvent mandatory transparent AI labelling or other statutory safeguards.
4.2. Regulated and high-risk use
The standard KIVEX Service is not intended to be a stand-alone decision-making system producing legal or similarly significant effects on individuals. Without a prior written assessment with KIVEX, the Customer must not use the Service as the decisive or sole basis for decisions concerning, in particular, employment, credit, insurance, education, healthcare, housing or other similarly sensitive decisions, where such use is subject to specific regulatory obligations.
For such a use case, KIVEX may require additional information, human oversight, restrictions on features, technical measures or a separate agreement. This does not affect the Customer's responsibility to identify and comply with its own obligations under applicable law.
5. Technical misuse
The Customer must not:
- circumvent capacity, licensing, security or access restrictions;
- gain access to another party's Workspace, Agent, data or account;
- reverse engineer, decompile or attempt to obtain non-public source code, model weights or system instructions, except to the extent permitted by mandatory law;
- scrape non-public parts of the Service without authorisation or use the Service to train a competing model;
- carry out penetration, load or automated security testing without a prior written agreement on its scope;
- intentionally overload the Service, circumvent rate limits or disrupt the operation of other customers;
- publish an API key, token or access credentials;
- remove KIVEX branding beyond what is expressly permitted by the plan or an add-on;
- resell stand-alone access to KIVEX without a partner or reseller agreement.
6. Domains, integrations and sources
6.1. The Customer may install the widget only on a domain that it owns or administers or for which it has express authorisation.
6.2. The Customer must not import a third party's non-public website, documentation, database or account without that third party's authorisation.
6.3. Integrations must use the minimum permissions necessary. The Customer is responsible for the keys, accounts and systems that it connects.
7. Enforcement
7.1. Where there is reasonable suspicion of a breach, KIVEX may request information and remediation, restrict specific content or a feature, or suspend access.
7.2. KIVEX may intervene without prior notice in the event of an imminent security risk, manifestly unlawful content, an attack, fraud or impending harm.
7.3. The scope of the intervention will be proportionate to the risk. The Customer may request a review at [email protected], stating the relevant facts.
7.4. KIVEX may retain the evidence of a breach that is necessary to protect its rights, comply with a legal obligation or resolve an incident.
8. Reporting unlawful content
Report suspected unlawful content, infringement of intellectual property rights or misuse of the Service to [email protected]. Please include the identity of the person making the report, the Agent or URL concerned, a description of the breach and supporting information that allows the matter to be verified.
Operator: Jakub Macura, Company ID (IČO) 24359939, Drahanovice 143, 783 44, Czech Republic. Contact: [email protected].
All documents are listed in the legal documents overview.

