Ardaro Acceptable Use Policy
Effective version: 2026.08.13
Scope
This Acceptable Use Policy applies to every person and organization that accesses Ardaro, Customer Content, public portals, APIs, imports, file workflows, or integrations. It is incorporated into the Ardaro Terms of Service.
Customer is responsible for its users and for configuring roles, portals, integrations, and sharing controls appropriately.
Lawful and authorized use
You may use Ardaro only for lawful, authorized business purposes. You may not use the service to:
- Violate a law, regulation, court order, contract, privacy right, publicity right, intellectual-property right, or other legal right.
- Collect, upload, disclose, or process information without the required authority, notice, permission, or consent.
- Misrepresent identity, authority, license, insurance, permit, inspection, safety status, signature, approval, invoice, payment, or project record.
- Facilitate fraud, theft, deceptive trade practices, unlawful discrimination, harassment, threats, exploitation, or physical harm.
Security and service integrity
You may not:
- Access or attempt to access another tenant, account, session, file, token, portal, or resource without authorization.
- Probe, scan, test, exploit, or bypass authentication, tenant isolation, role controls, rate limits, billing controls, audit logging, upload controls, or other security measures, except under Ardaro's written vulnerability-reporting authorization.
- Introduce malware, ransomware, destructive code, credential dumps, malicious documents, or content intended to compromise a person, device, provider, or service.
- Interfere with availability, overload the service, automate abusive traffic, scrape protected content, or consume resources in a manner materially disproportionate to the subscribed use.
- Share an individual account, expose credentials, reuse a session outside its intended context, or conceal the origin of prohibited activity.
- Reverse engineer or copy protected service components except where applicable law does not permit that restriction.
Good-faith security reports should follow the current instructions in Ardaro's SECURITY.md. The current reporting address is support@getardaro.com with the subject "Security report." Do not access real customer data to prove a report.
Files, imports, and sensitive data
You may upload only files and records that are needed for authorized business operations and that you have the right to process. You may not upload:
- Complete payment-card numbers, card security codes, or magnetic-stripe data.
- Account passwords, private keys, reusable authentication secrets, or credential collections.
- Malware, executable payloads disguised as documents, or content designed to exploit a parser or recipient.
- Medical records, biometric templates, classified information, export-controlled technical data, or specially regulated data unless Ardaro has expressly agreed in writing to the specific use.
- Unlawful surveillance data, intimate imagery without consent, or content that exploits children.
Business records such as tax forms may contain sensitive identifiers. Minimize or redact those fields where operationally possible, restrict access, and do not use Ardaro as a general archive for unnecessary sensitive data.
File acceptance, extension checks, or anomaly flags do not prove that a file is safe, accurate, licensed, or lawful. Customer remains responsible for its content and recipients.
Communications and public workflows
You may not use email, lead intake, customer portals, collaborator links, payment links, or other public workflows for spam, phishing, credential collection, unlawful marketing, harassment, or deceptive impersonation.
You must contact only recipients whom you are authorized to contact, use accurate sender and business information, honor applicable opt-out or suppression requirements, and avoid including unnecessary sensitive information in messages or links.
Public links and signed capabilities must be shared only with intended recipients. You may not publish, index, resell, or harvest them.
Construction and field safety
You may not treat Ardaro estimates, takeoffs, Intelligence results, templates, checklists, schedules, or reports as a substitute for required professional judgment, engineering, code review, site inspection, safety planning, or legal compliance.
You may not use Ardaro to falsify inspections, conceal hazards, bypass permit or safety duties, or direct work that you know is unsafe or unlawful.
Third-party services and data
You must comply with applicable third-party terms and licenses when importing supplier data, connecting an integration, sending email, collecting payment, or exporting records. You may not use Ardaro to evade a third party's access controls, usage limits, or data restrictions.
Enforcement
Ardaro may investigate suspected violations and may remove or restrict content, limit a feature, suspend access, preserve relevant evidence, or terminate service when reasonably necessary to protect users, providers, Ardaro, or the public; comply with law; or address a material violation.
When circumstances permit, Ardaro will provide notice and a reasonable opportunity to cure. Ardaro may act without advance notice for an urgent security, safety, legal, or abuse risk. Enforcement decisions may consider severity, repetition, intent, harm, and remediation.
Customer may request review through Ardaro's authenticated support channel or at support@getardaro.com. Ardaro may require identity and authority verification. A review request does not require Ardaro to restore content or access while a material risk remains.
Contact
Questions, abuse reports, and review requests may be initiated at support@getardaro.com. Privacy questions and personal-information requests should be sent to privacy@getardaro.com. Do not include passwords, session credentials, tokens, private keys, or unnecessary Customer Content.