Nairo Acceptable Use Policy
Last updated: 24/06/2026
This Acceptable Use Policy (the “Policy”) governs access to and use of the Nairo platform, website, applications, APIs, artificial intelligence features, private MVP, and related services (collectively, the “Services”) provided by People Future S.L., operating under the commercial name Nairo (“Nairo”, “we”, “us”, or “our”).
This Policy applies to all customers, users, administrators, employees, contractors, partners, and any other person or entity accessing or using the Services.
This Policy is intended to protect Nairo, our customers, users, systems, infrastructure, and third parties from misuse of the Services.
Any capitalized terms not defined in this Policy shall have the meaning given to them in the applicable agreement between Nairo and the customer, including any Master Services Agreement, Product Terms, Order Form, pilot agreement, design partner agreement, or other written agreement governing the use of the Services.
Authorized Use
The Services may only be accessed and used:
- for lawful business purposes;
- in accordance with applicable laws and regulations;
- in accordance with the applicable customer agreement and this Policy; and
- by authorized users with valid credentials and appropriate permissions.
Users are responsible for maintaining the confidentiality and security of their account credentials and for all activities conducted through their accounts.
Users must provide accurate and complete information when registering for or accessing the Services and must promptly update any information that becomes inaccurate or outdated.
Customers are responsible for:
- managing user access and permissions within their organization;
- ensuring that their users comply with this Policy;
- maintaining appropriate internal controls and oversight regarding the use of the Services; and
- ensuring that any data, documents, prompts, or other information submitted to the Services may lawfully be processed through the Services.
Nairo reserves the right to suspend, restrict, or terminate access to the Services where reasonably necessary to protect the security, integrity, availability, or lawful operation of the Services.
Prohibited Content
Users may not use the Services to create, upload, store, process, transmit, generate, or distribute any content, data, prompts, materials, or information that:
- violates any applicable law, regulation, or third-party right;
- infringes, misappropriates, or violates intellectual property rights, confidentiality obligations, privacy rights, contractual obligations, or proprietary rights;
- contains unlawful, fraudulent, deceptive, defamatory, harassing, abusive, threatening, hateful, discriminatory, or excessively violent material;
- promotes terrorism, violent extremism, organized crime, human trafficking, exploitation, or unlawful activities;
- contains child sexual abuse material, exploitative sexual content, or other unlawful sexual content;
- contains malicious code, malware, viruses, ransomware, spyware, Trojan horses, worms, credential theft tools, or other harmful or disruptive software or components;
- is intended to interfere with, disrupt, damage, or gain unauthorized access to systems, infrastructure, networks, accounts, models, applications, or data;
- includes personal data, special category personal data, regulated data, or confidential information where the user does not have the legal right, authority, or authorization to process or disclose such information through the Services;
- violates professional, regulatory, compliance, contractual, or industry obligations applicable to the user or customer organization; or
- could reasonably be expected to cause harm to individuals, organizations, infrastructure, systems, public safety, or the lawful operation of the Services.
Prohibited Activities
Users may not, directly or indirectly:
- access or use the Services for any unlawful, unauthorized, fraudulent, deceptive, harmful, or abusive purpose;
- attempt to gain unauthorized access to the Services, accounts, systems, networks, models, data, environments, or infrastructure connected to the Services;
- interfere with or disrupt the integrity, security, performance, availability, or lawful operation of the Services or related infrastructure;
- reverse engineer, decompile, disassemble, copy, reproduce, benchmark, scrape, extract, or otherwise attempt to discover the underlying models, algorithms, source code, prompts, systems, configurations, safeguards, or proprietary components of the Services, except where expressly permitted by applicable law;
- use automated tools, bots, crawlers, scraping tools, or programmatic methods to extract data, outputs, or content from the Services without Nairo’s prior written authorization;
- use the Services to develop, train, improve, evaluate, or benchmark competing products, models, systems, or services;
- circumvent, disable, interfere with, or bypass security features, access controls, usage limitations, rate limits, model safeguards, or technical protections implemented by Nairo or its providers;
- use the Services to distribute spam, phishing attempts, malicious communications, unauthorized advertising, or unauthorized solicitation;
- impersonate another individual or entity or misrepresent affiliation, identity, authority, or origin of information;
- overload, stress test, probe, scan, or perform security testing against the Services without Nairo’s prior written approval;
- use the Services in a manner that could damage, disable, overburden, impair, or negatively affect the operation of the Services or other users’ access to the Services;
- use the Services to violate export control, sanctions, anti-money laundering, anti-bribery, anti-corruption, or similar legal obligations; or
- use the Services in violation of any applicable customer agreement, security requirement, internal organizational policy, or applicable law.
Artificial Intelligence and High-Risk Use Restrictions
Nairo provides AI-enabled features designed to support professional workflows, research, analysis, document review, operational efficiency, and knowledge management.
Users remain solely responsible for evaluating, reviewing, validating, and approving any outputs generated through the Services. For additional information about AI-generated outputs, see our AI disclaimer.
Users may not use the Services:
- as the sole basis for making decisions that may materially impact individuals, organizations, legal rights, financial outcomes, insurance coverage, underwriting determinations, claims outcomes, regulatory obligations, compliance determinations, or access to services without appropriate human review and oversight;
- for fully autonomous decision-making in regulated, high-risk, safety-critical, or legally significant contexts;
- to generate or distribute knowingly false, misleading, fraudulent, or deceptive information;
- to conduct unlawful surveillance, profiling, monitoring, or unauthorized collection of personal, confidential, or regulated information;
- to generate harmful, discriminatory, abusive, or exploitative content intended to harass, manipulate, exploit, or target individuals or groups;
- to test, bypass, evade, or exploit vulnerabilities in artificial intelligence systems, models, prompts, safety mechanisms, filters, or security controls;
- to make or support decisions prohibited by applicable artificial intelligence, privacy, financial services, insurance, employment, anti-discrimination, consumer protection, or professional regulations; or
- in any way that could reasonably create material legal, operational, cybersecurity, regulatory, financial, or reputational risk for Nairo, its customers, users, or third parties.
Nairo does not guarantee the accuracy, completeness, reliability, security, legality, suitability, or fitness for purpose of AI-generated outputs.
Users are responsible for independently reviewing outputs, verifying relevant sources where appropriate, and exercising appropriate professional judgment before relying on, distributing, publishing, or implementing any output.
Regulated and Professional Use
The Services are intended to support professional users and operational workflows. They are not a substitute for independent professional judgment, legal advice, regulatory advice, underwriting authority, compliance approval, financial advice, medical advice, or other specialized professional advice.
Customers and users are responsible for ensuring that their use of the Services is appropriate for their industry, jurisdiction, internal policies, authorization levels, and applicable regulatory obligations.
In regulated or professional contexts, including insurance, financial services, legal, compliance, employment, audit, risk, or claims-related workflows, users must maintain appropriate human review, governance, escalation, approval, and audit processes.
Security and Account Responsibilities
Users are responsible for maintaining the security and confidentiality of their accounts, credentials, devices, and access methods used in connection with the Services.
Users must:
- maintain appropriate password and authentication security practices;
- restrict unauthorized access to accounts, credentials, devices, workspaces, and customer environments;
- promptly notify Nairo of any suspected or actual unauthorized access, security incident, credential compromise, vulnerability, or misuse involving the Services; and
- use the Services in accordance with applicable security policies, customer requirements, and reasonable industry practices.
Customers are responsible for managing user access, permissions, and administrative controls within their organization, including:
- granting access only to authorized individuals;
- assigning appropriate roles and permissions;
- removing access for inactive, unauthorized, or departed users; and
- maintaining appropriate internal governance and oversight over the use of the Services.
Users may not share credentials, bypass authentication controls, or attempt to access resources, environments, workspaces, or information beyond the scope of their authorized access.
Nairo reserves the right to investigate suspected violations of this Policy and may suspend or restrict access to the Services where reasonably necessary to protect the security, integrity, availability, or lawful operation of the Services or related systems.
Sensitive Data and Customer Content
Users must not submit personal data, special category personal data, regulated data, confidential information, trade secrets, or third-party proprietary information to the Services unless they have the legal right, authority, and appropriate basis to do so.
Customers are responsible for ensuring that any information uploaded, submitted, or processed through the Services complies with applicable privacy, confidentiality, regulatory, contractual, and professional obligations. See our Privacy Notice for information about personal data processing.
Users should avoid submitting unnecessary sensitive information and should apply appropriate minimization, redaction, access control, and review practices where relevant.
Enforcement and Violations
Violations of this Policy may result in the suspension, restriction, or termination of access to the Services, in whole or in part, at Nairo’s discretion and in accordance with the applicable customer agreement and applicable law.
Nairo reserves the right to:
- investigate suspected violations of this Policy;
- monitor and review activity reasonably necessary to protect the Services, customers, users, infrastructure, and third parties;
- remove, restrict, or disable access to content or activities that violate this Policy or applicable law; and
- take appropriate technical, legal, or operational measures in response to misuse of the Services.
Where appropriate, Nairo may report unlawful activity or material violations of applicable law to relevant authorities or cooperate with law enforcement, regulators, affected third parties, or infrastructure providers.
Customers are responsible for ensuring that their users comply with this Policy. A violation committed by a user may be treated as a violation by the relevant customer organization.
Nairo’s rights and remedies under this Policy are cumulative and do not limit any additional rights or remedies available under applicable agreements or law.
Changes to this Policy
Nairo may update or modify this Policy from time to time to reflect changes in applicable laws, regulations, technology, security practices, business operations, or the Services.
When material changes are made, Nairo may provide notice through the Services, website, email communications, customer notifications, or other reasonable means where appropriate.
The “Last updated” date at the top of this Policy indicates when the latest version became effective.
Continued access to or use of the Services after an updated version of this Policy becomes effective constitutes acceptance of the revised Policy, unless otherwise specified in the applicable customer agreement.
Contact Information
If you have any questions regarding this Acceptable Use Policy or wish to report a suspected violation of this Policy, you may contact:
People Future S.L.
Commercial name: Nairo
Calle San Germán 10, 4G
28020 Madrid, Spain
Email: legal@nairobilabs.com
Website: https://nairobilabs.com
For information about cookies and similar technologies, see our Cookie Notice. For subprocessors and infrastructure providers, see our Subprocessors List.