Acceptable Use Policy
The rules for acceptable and prohibited use of the Balt service, and prohibited data.
This Acceptable Use Policy forms an integral part of, and is incorporated by reference into, the Balt General Terms of Service. Capitalized terms not defined here have the meanings given in the Definitions.
A breach of this Policy constitutes a material breach of the Agreement and may result in immediate suspension of the Service under Section 10.2 of the General Terms.
1. Prohibited Uses
Customer and its Authorized Users shall not use the Service to:
- (a) violate applicable law, including export-control and international sanctions rules (European Union regulations, regimes administered by the U.S. Office of Foreign Assets Control), electronic direct marketing rules (article L. 34-5 of the French Postal and Electronic Communications Code and the GDPR), data protection law, or the provisions penalizing unauthorized access to automated data processing systems (articles 323-1 et seq. of the French Criminal Code);
- (b) infringe or misappropriate any intellectual property right, image right, privacy right, or other right of any third party;
- (c) carry out discriminatory practices prohibited in recruitment or employment, in particular those referred to in article L. 1132-1 of the French Labour Code and articles 225-1 et seq. of the French Criminal Code, nor use Outputs to select candidates on a prohibited ground;
- (d) transmit malware, viruses, or ransomware, perform denial-of-service attacks, carry out unauthorized bulk extraction, or conduct unauthorized penetration testing;
- (e) generate, transmit, or facilitate unsolicited communications, phishing attempts, or any deceptive or fraudulent communication;
- (f) generate or distribute content that is defamatory, abusive, harassing, threatening, hateful, or obscene, or that endangers minors;
- (g) circumvent rate limits, usage restrictions, security measures, or access controls of the Service;
- (h) access or use the Service to build a competing product, or to benchmark it for the purpose of publishing public comparative claims;
- (i) use the Service if Customer or any Authorized User is located in, ordinarily resident in, or organized under the laws of a country or territory subject to comprehensive sanctions, or is listed on a denied-party list, including the OFAC Specially Designated Nationals list or European Union asset-freeze lists;
- (j) impersonate any person or entity, or conceal or misrepresent the identity, affiliation, authority, or true origin of any communication, including by presenting a message generated by the Service as coming from a person who did not approve it;
- (k) use the Service in any high-risk context where failure or misuse could reasonably result in death, personal injury, or severe property, environmental, financial, regulatory, or reputational harm.
2. Meeting Recording and Transcription
The Service allows Balt to join an online meeting in order to record and transcribe it. This feature places specific obligations on Customer, which Customer undertakes to comply with.
- (a) Customer informs all participants in advance of the presence of the bot, of the recording and transcription, and of their purposes and retention period;
- (b) Customer obtains the required consents and allows any participant to object to the recording without adverse consequence;
- (c) Customer refrains from recording exchanges of a private nature within the meaning of article 226-1 of the French Criminal Code, or any meeting whose recording would be unlawful in a participant's jurisdiction;
- (d) Customer ensures that the recording and transcription rest on an appropriate legal basis and that data subjects are informed of their rights.
Triggering a recording is a High-Risk Action within the meaning of Section 3.3 of the Product Terms: it always requires explicit human approval and can never be pre-authorized. Customer remains solely responsible for the lawfulness of recordings made from its account.
3. Prohibited Data Categories
The Service is not designed, certified, or intended to process Regulated Data. Customer shall not submit to the Service:
- (a) health data, including data subject to sector-specific health regulation, and data requiring certified health-data hosting;
- (b) payment card data subject to PCI DSS, and full bank account details;
- (c) special categories of personal data within the meaning of Article 9 GDPR, namely data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data for the purpose of uniquely identifying a person, health data, and data concerning sex life or sexual orientation;
- (d) data relating to criminal convictions and offences within the meaning of Article 10 GDPR, including criminal record extracts;
- (e) data relating to persons under fifteen (15) years of age, the age of digital consent in France under article 7-1 of French law no. 78-17 of January 6, 1978;
- (f) data subject to export-control restrictions or to a classification regime;
- (g) any other data subject to sector-specific legal requirements imposing safeguards not expressly provided for in the Agreement or the DPA.
Customer assumes full regulatory exposure arising from a breach of this Section 3, including penalties, claims, and remediation costs. If Customer requires the Service to process Regulated Data, the Parties must first execute a separate written addendum before any such data is submitted. Provider may suspend or terminate the Service immediately, without cure period, upon discovery of Regulated Data.
This prohibition is neither intended nor construed to prevent Customer from processing data required for a recruitment process where legally required, such as disabled-worker status information, provided such processing takes place outside the Service.
4. Investigation and Enforcement
Provider may, but is not obligated to, investigate suspected violations of this Acceptable Use Policy, remove content, or suspend access in accordance with Section 10 of the General Terms. Action taken by Provider under this Section gives rise to no claim by Customer.
Customer shall promptly report to Provider, at legal@cobalt-ia.com, any breach of this Policy of which it becomes aware, including breaches committed by one of its Authorized Users.
The other documents of the agreement
- Definitions : The defined terms used across the Balt contractual documents.
- General Terms : The core contractual terms governing access to and use of the Balt service.
- Product Terms : Service description, AI functionality, autonomous actions, connected platforms and security.
- Usage Terms : How Credits, allocations, top-ups and accounts work.
- License Terms : The license granted to use the Balt service, and its restrictions.
To report abuse or ask a question, contact us at: legal@cobalt-ia.com
