1. Scope and precedence
This AUP governs portal access and conduct only. It does not create or vary a signed agreement; the stricter controlling signed agreement, Statement of Work, client instruction and versioned Approved Tools List prevail. Use the portal only for authorised MoniSa or client work and comply with applicable law.
2. Protect systems and report incidents
- No malware, destructive code, credential theft, denial-of-service activity or unauthorised scanning.
- No scraping, automated extraction, reverse engineering or bypass of rate limits/access controls without written permission.
- No credential sharing, impersonation or access outside the assigned role.
- No uploading executable files or disguising file types.
- Report any suspected security or personal-data incident within four hours of discovery, provide the full written report within 24 hours, answer an urgent incident question within four hours, revoke exposed access within four hours, and report discovery that an affected participant may be under 18 within four hours. Preserve evidence.
- Coordinate client, data-principal, regulator and third-party communications with MoniSa. Nothing here prohibits or penalises a statutory or regulatory report, supervisory-authority complaint, protected disclosure, request for legal advice, or preservation or production of evidence where the law protects or requires it.
3. Protect data, content and tools
- Upload only data needed for the task and that you are authorised to use.
- Do not place client names, project personal data or secrets in free-text profile fields or administrative messaging channels such as WhatsApp or Skype.
- Machine translation, generative AI, automated transcription and synthetic voice are prohibited by default. They may be used only when the controlling Statement of Work expressly permits the use and the tool appears on the versioned Approved Tools List. No automated tool is currently approved.
- Until a portal declaration field exists, state in writing to the assigned project manager with the delivery record either that no automated tool was used or identify every tool used. Follow any seven-day approved-tool change process only where the signed agreement provides one.
- No portal checkbox can authorise synthetic/AI voice use. That requires a separate, unbundled, personally signed opt-in that states the authorised purpose and use.
- Do not use project or participant data, voice, likeness, prompts, outputs, annotations or derived features to train, fine-tune, benchmark or evaluate a model without all required express project and participant permissions.
- Do not export bulk portal data or maintain shadow copies outside approved storage.
4. Enforcement and fair process
MoniSa may block content, rate-limit, suspend or terminate access proportionately and preserve evidence. Except for urgent containment required by security or law, a named human decision-maker must record the reason and supporting evidence, give notice before effect, provide a meaningful opportunity to make representations, and give a reasoned outcome. No adverse action may be taken merely for a good-faith payment query, refusing or withdrawing optional consent, or exercising a statutory right. Appeals may be sent to legal@monisaenterprise.com.