Legal
Acceptable Use Policy
Last updated
Purpose
This policy defines the conduct expected of every account, API client, and end user of the Farshore Labs platform. It exists to protect customers, the integrity of the data and infrastructure, and third parties whose information is exposed by some services (e.g. sanctions lists, sovereignty controls). A material breach may lead to suspension or termination of the account without refund.
Prohibited conduct
You must not, and must not encourage or allow others to:
- Use the Services in any way that violates applicable law, including export controls, sanctions regimes (OFAC, EU, UK, UN), data protection law, or laws against unfair or deceptive practices.
- Use the Services to facilitate illegal activity directed at third parties: spamming, phishing, credential stuffing, scraping of personal data, or distribution of malware.
- Attempt to defeat or evade rate limits, quota enforcement, billing, or authentication (including sharing API keys across entities, rotating keys solely to reset quotas, or distributing account credentials).
- Probe, scan, or test the vulnerability of the platform without prior written authorisation, except as expressly permitted by the responsible-disclosure programme on the Security page.
- Interfere with the integrity or performance of the platform (e.g. denial-of-service, deliberate resource exhaustion, uploading payloads designed to crash a service).
- Republish, resell, or sublicense reference datasets returned by the Services without an explicit written agreement. Building a competing product on top of bulk-extracted Farshore responses is not permitted.
- Use the Services to make decisions that produce legal or similarly significant effects on natural persons in a way that relies solely on the Services without competent human review.
- Submit personal data of third parties without a lawful basis to do so. The sanctions-screening service is intended for risk-management screening of names you are already entitled to process.
Fair use of rate limits
Per-service monthly quotas are enforced server-side; the default limit is 20,000 calls per service per UTC month. Splitting a workload across multiple accounts or API keys for the same underlying user/organisation in order to multiply quota is a breach of this policy.
Sustained traffic above the quota, or short-window bursts that materially degrade the service for others, may be throttled, dropped, or charged at a metered overage rate that we will notify you of in advance.
Content you submit
You are responsible for the inputs you submit to the Services. Do not submit:
- Special categories of personal data (Article 9 GDPR — health, biometric, sexual orientation, religion, etc.) unless the service is explicitly documented to accept them.
- Payment card data, government-issued ID numbers, or other sensitive credentials. The Services are not designed to process them.
- Content that is illegal, infringing, defamatory, or otherwise tortious in the jurisdiction in which it is processed.
Reporting and enforcement
To report suspected abuse of the platform, email abuse@farshorelabs.com. We investigate every credible report. Where law permits we may notify the affected customer; where it does not (e.g. ongoing law-enforcement investigation), we will not.
Enforcement options range from a warning, to quota reduction, to immediate suspension of an offending API key, account, or subscription. We will use the minimum measure that protects the platform and other customers.