DocAccessible

Legal & trust

Acceptable Use Policy

These rules protect customer documents, connected websites, recipients, infrastructure, and the availability of the DocAccessible service.

Effective July 18, 2026Version 2026-07-18

This policy is incorporated into the Terms of Service and applies to every account, workspace, API client, invited participant, and public or protected page.

1. Use content you are authorized to process

Upload, transform, scan, share, or publish a document only when you own it or have permission and a lawful basis to do so. Do not use DocAccessible to violate copyright, privacy, confidentiality, publicity, contractual, or other rights. Do not connect a website you do not control or have authority to monitor.

2. Prohibited content and conduct

You may not use the service to:

  • break any applicable law, regulation, sanctions rule, or court order;
  • upload malware, destructive code, credential theft, or files intended to evade security scanning;
  • exploit, probe, scan, or test the vulnerability of the service without written authorization;
  • bypass authentication, permissions, plan limits, rate limits, download limits, or file-validation controls;
  • access another customer's account, workspace, documents, cases, tokens, or private URLs;
  • send spam, phishing, deceptive notices, harassment, threats, or abusive content;
  • publish unlawful, defamatory, exploitative, or non-consensual intimate material;
  • process sexual-abuse material involving children or content that facilitates exploitation of a minor;
  • use hosted pages, redirects, links, or delivery routes to impersonate a person or organization;
  • scrape, resell, mirror, or reverse engineer the service except where law expressly permits;
  • place excessive or automated load on the service outside documented API use or agreed testing;
  • use output to make an automated high-impact decision about a person without the legally required review and safeguards; or
  • misrepresent automated output as a DocAccessible certification of WCAG, PDF/UA, ADA, or Section 508 conformance.

3. Sensitive and regulated data

Do not upload payment-card data, passwords, authentication secrets, private keys, or government identifiers unless the specific workflow and signed order expressly permit it. DocAccessible does not claim HIPAA BAA coverage, PCI DSS storage, classified-data authorization, or another regulated-data commitment unless confirmed in a signed agreement. Minimize personal and confidential information to what the document workflow actually requires.

4. API, webhook, and link security

Keep API keys, vendor tokens, intake URLs, protected-share passwords, and delivery links confidential. Use the narrowest permissions and expiry that fit the task. Webhook destinations must be public HTTPS endpoints you control; attempts to reach internal networks, metadata services, or unrelated systems are prohibited.

5. Monitoring and enforcement

We may investigate credible reports and use automated safeguards such as file validation, malware scanning, rate limits, token checks, and outbound URL restrictions. We may quarantine or remove content and limit or suspend access when reasonably necessary to stop abuse or protect data and availability. We will consider context, severity, repetition, customer cooperation, and legal requirements. Where practical, we will notify the workspace owner and allow a cure.

6. Reporting

Report abuse, security concerns, or unauthorized content using the contact form. Copyright complaints have a dedicated reporting process. Do not include exploit code, credentials, or sensitive files in the public form; we will arrange a protected follow-up route if needed.