Product Genius acceptable use policy
Version 1.0 — Effective
Published at https://productgenius.ai/legal/aup. A dated copy of each version is archived at https://productgenius.ai/legal/aup/[YYYY-MM-DD].
This Acceptable Use Policy (this “AUP”) applies to all use of the Product Genius platform and Services provided by Gamalon, Inc. d/b/a Product Genius (“Product Genius”). It is incorporated into the Product Genius Subscription Terms. Capitalized terms have the meanings given there or in the Data Processing Agreement (“DPA”).
1. Prohibited conduct
Customer will not, and will not permit any Authorized User or third party to, use the Services to:
1.1 violate any applicable law or regulation, or infringe or misappropriate any third party’s intellectual property, privacy, publicity, or other rights;
1.2 transmit, store, or distribute unlawful, defamatory, harassing, or fraudulent content, or content that promotes violence or unlawful discrimination;
1.3 transmit malicious code, or interfere with or disrupt the integrity, security, or performance of the Services, the systems of Product Genius or its Sub-processors, or the data of any other customer;
1.4 attempt to gain unauthorized access to the Services, to another customer’s data or account, or to any related system or network;
1.5 probe, scan, or test the vulnerability of the Services or circumvent any authentication, rate-limiting, or access control, except with Product Genius’s prior written authorization (see Section 4);
1.6 reverse engineer, decompile, or attempt to derive the source code, model weights, or underlying architecture of the Services, except to the extent that restriction is unenforceable under applicable law;
1.7 use the Services to build a competing product or service, or to conduct benchmarking for publication without Product Genius’s consent;
1.8 resell, sublicense, or provide the Services to any third party except as expressly permitted in the Subscription Terms;
1.9 use automated means to access the Services in a manner that exceeds the Volume Limits or that imposes an unreasonable load on the infrastructure; or
1.10 misrepresent the source or ownership of content served through the Services, or remove or obscure any proprietary notice.
2. Prohibited data
The Services are designed to personalize merchandising using pseudonymous behavioural and catalogue data. They are not designed to process sensitive data, and Product Genius does not require sensitive data to deliver personalization.
2.1 Customer will not configure the Services to transmit to Product Genius, and will use reasonable measures to prevent transmission of, any of the following:
- payment card data, including primary account numbers, within the scope of the PCI DSS;
- financial account numbers or credentials, or data within the scope of the Gramm-Leach-Bliley Act;
- protected health information within the scope of HIPAA, or other health or medical information about an identified individual;
- government-issued identifiers, including social security numbers, passport numbers, driver’s licence numbers, and national identification numbers;
- biometric or genetic identifiers;
- precise geolocation data;
- special categories of personal data under Article 9 of the GDPR, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation;
- personal data of individuals Customer knows or reasonably should know to be under the age of 16; and
- personal data of individuals in respect of whom Customer has received an applicable opt-out or deletion request, to the extent Customer is able to suppress or transmit that signal through its consent mechanism as contemplated by Section 5.11 of the Subscription Terms.
Paragraphs (h) and (i) are obligations of reasonable diligence, not strict liability. Product Genius recognizes that Customer cannot always verify a shopper’s age and does not expect Customer to guarantee it.
2.2 Health- and wellness-adjacent catalogues. Product Genius recognizes that a product catalogue can itself carry inference risk — for example, browsing behaviour across health, wellness, pregnancy, or similar categories may support inferences about an individual’s health. Customer is responsible for assessing this risk for its own catalogue and for providing any notices and obtaining any consents that applicable law requires. Where Customer’s catalogue presents this risk, the Parties will agree any additional safeguards in the Order Form, and Product Genius will engage in good faith on measures such as category exclusions, shortened retention, or restricted inference. Product Genius will not decline to discuss this; Section 2.1 is not intended to transfer the whole of this risk to Customer without engagement.
2.3 Inadvertent transmission. If either Party becomes aware that prohibited data has been transmitted to the Services, it will notify the other without undue delay. Product Genius will not use that data for any purpose and will delete it promptly in accordance with Section 4.6 of the DPA.
3. Enforcement
3.1 Product Genius may investigate suspected violations of this AUP and may require Customer’s reasonable cooperation.
3.2 Where Product Genius believes a violation has occurred, it will notify Customer and give a reasonable opportunity to remedy before taking action, except where an immediate threat to the security, integrity, or availability of the Services or to another customer’s data requires immediate action.
3.3 Product Genius may suspend the affected use in accordance with Section 6.4 of the Subscription Terms. Any suspension will be limited to the affected use and access will be restored promptly once the issue is resolved. Repeated or uncured material violations are a material breach under Section 12.3 of the Subscription Terms.
3.4 Product Genius will not suspend or terminate for a violation of this AUP as a means of resolving a commercial or billing dispute.
4. Security research and vulnerability reporting
Product Genius welcomes good-faith security research. Report suspected vulnerabilities to security@productgenius.io. Product Genius will not pursue action under Section 1.5 against a researcher who acts in good faith, avoids accessing or modifying data belonging to others, does not degrade the Services, and gives Product Genius reasonable time to remediate before disclosure.
5. Changes to this AUP
Product Genius may update this AUP prospectively, on the notice terms in Section 13.3 of the Subscription Terms. Dated archived versions are maintained at the URL in the header. Where a dated version is attached to an executed Order Form, that version governs for the Initial Term.
6. Questions
Questions about this AUP: legal@productgenius.io. Data protection questions: privacy@productgenius.io.