Legal
Acceptable Use Policy
What you can and can't do with Autonomiqa.
Last updated: 4 October 2026
This Acceptable Use Policy ("AUP") is part of the Terms of Service between you and Autonomiqa.
Why this exists: Everything sent through Autonomiqa reaches real people, from your own accounts, on sending infrastructure shared with other customers. Misuse by one customer harms everyone else. We enforce this policy.
1. Your core responsibility
When you decide who to contact and why, you are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 and other applicable data protection laws. You are responsible for making sure every contact you process through Autonomiqa may lawfully be used for your outreach. When we process that data only on your instructions, we act as your Data Processor. Our own use of personal data is covered by our Privacy Policy.
2. Data you bring to the platform
You must have the right to use every contact record for outreach, whether you upload it or source it through our providers, and be able to show that right if asked. Only process the data you actually need for your outreach.
You must NOT upload, import or process:
- Unlicensed lists: contact data bought, rented or swapped without an outreach licence, or data resold against the original provider's terms. Data from your own paid subscription to a reputable business data provider is fine, if that provider's terms allow it.
- Scraped data obtained in breach of a website's terms or access controls
- Data from a former employer or any source you aren't contractually free to use
- Private individuals: every contact must be approached in their business role. A personal email or mobile is fine where it's genuinely that person's business contact (common for founders and consultants), but not to contact people about non-business matters.
- Sensitive data: health, biometric, genetic, religious, political, sexual orientation, trade union, caste or financial account information, unless we have agreed in writing
- Government ID numbers of any kind
- Data about anyone under 18
You must also honour any notices, consents, opt-outs and deletion requests that apply to the people concerned.
3. Outreach conduct
You must NOT use Autonomiqa to:
- Deceive: impersonate anyone; fake sender names, reply-to addresses or headers; use misleading subject lines; or invent a relationship, referral or mutual connection
- Ignore opt-outs: remove or hide unsubscribe links; re-contact anyone who has opted out; or re-add a suppressed contact under a different campaign, identifier or account
- Send prohibited content: bulk consumer marketing; political campaigning; unsolicited recruitment outreach; multi-level marketing; cryptocurrency, gambling, adult content or investment solicitation; or anything illegal
- Harass: contact anyone who has asked you to stop, continue a sequence after a clear refusal, or send threatening, abusive, defamatory or discriminatory messages
- Overwhelm: get around sending limits, run extra accounts to send more than your plan allows, or send at volumes that put shared deliverability at risk
4. Laws in the countries you contact
You are responsible for following the privacy and anti-spam laws of each country where your recipients are, not only Indian law. In particular:
- European Economic Area and United Kingdom (GDPR, UK GDPR, PECR):
- Only contact people in their professional role, about something relevant to their job.
- Be able to show that your legitimate interest in contacting them is not outweighed by their rights.
- Say who you are, and tell people how to object.
- Honour every objection straight away.
- Some countries (for example, Germany) set stricter rules for unsolicited email, so check before you send.
- United States (CAN-SPAM Act):
- Every commercial email must clearly identify you as the sender, include your valid physical postal address, and carry a working unsubscribe link.
- Unsubscribes must be honoured within 10 business days. Autonomiqa processes unsubscribes automatically. Do not remove or disable this.
- Canada (CASL) and Australia (Spam Act 2003): you generally need the recipient's consent before sending commercial electronic messages. That can be express consent, or consent implied by a qualifying existing business relationship or a published business address without a "no spam" notice.
- India (DPDP Act): process only the personal data you need, for the purpose you contacted the person for, and honour withdrawal and erasure requests.
If you are unsure whether you may contact someone, don't, or take local legal advice first. Our compliance warnings help, but they are not legal advice.
5. LinkedIn and email providers
- You stay bound by the terms of the accounts you connect. LinkedIn's User Agreement restricts automated activity, and using Autonomiqa's LinkedIn features is at your own risk.
- If LinkedIn or your email provider restricts, suspends or closes your account, that is your responsibility. We can't appeal on your behalf, and it is not grounds for a refund.
- You are responsible for your domain reputation, SPF/DKIM/DMARC setup and mailbox warm-up.
6. Technical conduct
You must NOT:
- Get around login, security controls, separation between customer accounts or rate limits
- Access another customer's data
- Probe, scan or test our security without written permission
- Reverse-engineer the platform or try to extract our models or prompts
- Scrape the platform, resell access without a written agreement, or upload malware
Protect the personal data you handle through Autonomiqa. If you learn of any unauthorised access to or loss of such data, tell us without delay at support@autonomiqa.co with the subject "Security". Security researchers acting in good faith should contact us at the same address before testing.
7. AI-generated content
- AI-written messages are drafts. Review them before they send.
- Don't give the AI personal data it doesn't need, or use it to infer sensitive information about anyone.
- Don't generate defamatory, discriminatory or deceptive content, or claims about your product you can't back up.
- Don't try to trick the AI into breaking this policy, or use its outputs or data from the platform to train another AI model unless you have a lawful basis to do so.
8. Enforcement
If we believe this policy has been broken, we may, depending on how serious it is, warn you, pause a campaign, pause sending, suspend your account or terminate it. We act without notice when there is an active risk to recipients, shared infrastructure or security, or a legal obligation. Termination for breach does not entitle you to a refund.
We may keep, access or disclose information where reasonably needed to comply with the law, investigate misuse, protect the platform or defend legal claims.
9. Reporting misuse
- Anyone can report suspected misuse to support@autonomiqa.co with the subject "Abuse report".
- Received a message and want it to stop? Use the unsubscribe link in the message, or write to us with the subject "Opt-out".
10. Retention and deletion
When we process data on your behalf, you're responsible for instructions on keeping or deleting it, and for helping us respond to requests from the people concerned. We may keep data where needed to comply with the law, resolve disputes, prevent abuse or defend legal claims, as explained in our Privacy Policy.
11. Changes to this policy
We may update this policy. Material changes take effect 15 days after we notify you. Continued use after that date means you accept the updated policy.
12. Contact
Autonomiqa
Email: support@autonomiqa.co