Acceptable Use Policy
This Policy defines the data you may and may not collect through Emblem Studio, and the sign-up practices you must follow.
Last updated: 14 August 2026 · Version: 1.2-beta
This Policy is part of the Terms of Service. It applies to everyone who uses Emblem Studio's hosted Service. Breaching it is a breach of the Terms and can lead to suspension or termination. It governs the hosted Service; it does not add conditions to the GPL-licensed WordPress plugin (Terms §12).
1. The data you must not collect
You must not use the Service to collect, store, or transmit, and must not configure a form that asks for:
-
Special-category data — data about health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric data, or a person's sex life or sexual orientation. This includes data that becomes sensitive by context or inference. A dropdown option like "diabetes management," or an ordinary email box on a fertility clinic's site, creates health data even though no field is labelled "health." You are responsible for recognising this on your own site; we cannot detect it.
-
Children's data — you must not use the Service on a site or form directed to children, or to knowingly collect personal data from children below the age of digital consent in their country.
-
Financial account credentials — payment card numbers, bank account logins, or similar. Take payments through a proper payment provider, never through a lead form.
-
Government identifiers such as national identity, social-security, or passport numbers, wherever collecting them is prohibited or high-risk.
-
Data from purchased, rented, or scraped lists, or any data you did not collect yourself with a lawful basis.
If you submit prohibited data anyway, that is your breach, and our discovery process may apply: we document it, contact you, give a deadline, and if unresolved suspend the forms and then terminate.
2. Consent and honest sign-up practices
- Never pre-tick a consent box. Under the GDPR a pre-ticked box is not consent, and it invalidates the records collected that way. The Service will not render a pre-ticked consent control, and you must not attempt to create one.
- One consent, one purpose. Do not bundle "I accept the terms" and "I agree to receive marketing" into a single box — it invalidates both. Keep marketing consent separate, specific, and unticked.
- No deceptive patterns. Do not use confirmshaming, hidden or disguised close buttons, or interstitials that obstruct dismissal. EDPB guidance names these as deceptive design; a popup product is exactly where they appear. Your popups must be genuinely dismissible.
- Phone/SMS. If your form collects a phone number for calls or texts, provide the separate disclosure and consent those rules require.
3. What you must not do with the Service
- Break the law, or help anyone else break it.
- Send spam, or use captured leads in breach of anti-spam law (you may only contact people on a lawful basis — e.g. their consent or a valid soft opt-in).
- Resell, rent, or trade the leads you capture as if they were a list; the people who signed up gave their data to you for your stated purpose.
- Upload or distribute malware, or content that is illegal, infringing, defamatory, harassing, or that promotes violence or hatred.
- Infringe anyone's intellectual property or privacy.
- Impersonate any person or organisation, or misrepresent who is collecting the data.
- Attempt to breach, probe, overload, or reverse-engineer the Service or its security (SSRF, injection, scraping our APIs, circumventing rate limits or tenant isolation), or access another customer's data.
- Use the Service to build a public-facing directory of the personal data you collect, or otherwise expose your leads' data.
4. Using the AI features responsibly
- If you connect your own AI (Strategist / MCP), you are responsible for everything it does through your account, automated or not (Terms §6). Do not connect an agent you do not control, and do not disable the confirmation gates on destructive actions.
- Do not use any AI feature to generate unlawful, infringing, or deceptive content, or to attempt to extract another customer's data.
5. Technical fair use
- Do not use the Service in a way that degrades it for others — excessive automated requests, deliberate overloading, or using ingestion endpoints as a general-purpose data pipe unrelated to your own forms.
- Do not interfere with bot filtering or security features, or use the Service to disguise the origin of traffic.
6. If you see a problem, or we do
- Report abuse or illegal content to contact@emblemstudio.ai. We act on genuine reports.
- We may investigate suspected breaches and, where necessary to protect people or comply with law, suspend the specific forms, the feature, or the account. For breaches involving children's data or special-category data we follow a documented escalation process.
- We will not delete your data unilaterally as a first step — it is yours, and deleting it can destroy evidence that either of us behaved properly. We document, contact you, and give you a chance to fix it, except where immediate action is needed to stop serious or unlawful harm.
7. Changes
We may update this Policy as the Service and the law change; material changes are notified as set out in the Terms (§17).