Qualsis Acceptable Use Policy
Version: 1.0.0
1. About this Policy
This Acceptable Use Policy (the "AUP") sets out the rules for using the Services offered by Qualsis, LLC ("Qualsis," "we," "us," or "our"). The AUP is part of the Qualsis Terms of Service available at https://qualsis.com/legal/terms (the "Terms") and applies to every Customer of Qualsis and every individual that uses our Services on a Customer's behalf ("End Users").
By using the Services, Customer and its End Users agree to follow the rules in this AUP. Material violations may result in suspension or termination of access as described in the Terms.
This AUP is intentionally written in plain English. This AUP identifies the prohibited uses currently applicable to the Services. Qualsis may take immediate action under the Terms against activity presenting a material security risk or involving unlawful conduct, but an unpublished restriction does not independently create a breach of this AUP. If you are not sure whether something is permitted, ask us at Contact Privacy before doing it.
2. Definitions
Capitalized terms used but not defined here have the meanings given in the Terms or the Data Processing Addendum (the "DPA"). For convenience:
- "Services" means Qualsis's products as described in the Terms, currently QortexOS and (when generally available) QoherenceAI.
- "Customer Data" means data Customer or its End Users upload, connect, generate, or transmit through the Services.
- "Output" means information, content, recommendations, forecasts, or other material the Services produce in response to Customer Data or Customer instructions.
- "Agent" in QoherenceAI means a software workflow or service that a Customer builds on the QoherenceAI platform to perform tasks.
3. General prohibitions
Customer and its End Users will not, and will not enable or assist any third party to:
3.1. Unlawful or harmful use
- Use the Services for any purpose that violates applicable law, regulation, court order, or government authority
- Use the Services to violate the legal rights of any person, including intellectual property rights, privacy rights, publicity rights, and contract rights
- Use the Services to threaten, harass, defame, stalk, harm, or discriminate against any person or group
3.2. Content prohibitions (Customer Data and Outputs)
Do not upload, transmit, or generate through the Services any content that:
- Is illegal where Customer operates or where the content is processed
- Infringes intellectual property rights (copyrights, trademarks, patents, trade secrets) or other rights of third parties
- Is fraudulent, deceptive, or misleading
- Is defamatory or libelous
- Is obscene, sexually explicit, or violent in a manner that is unlawful
- Promotes terrorism, mass violence, or violent extremism
- Constitutes prohibited material under applicable law (such as child sexual abuse material, which Qualsis will report to authorities consistent with applicable law)
3.3. Security and integrity
- Do not attempt to gain unauthorized access to any part of the Services, to any other Customer's data, or to any system or network connected to the Services
- Do not interfere with or disrupt the Services, including by introducing viruses, malware, ransomware, or other malicious code; by conducting denial-of-service attacks; or by overloading or impairing system performance
- Do not probe, scan, or test the vulnerability of the Services or any system or network connected to them, except as expressly permitted by Qualsis in writing under a coordinated disclosure or bug-bounty program
- Do not bypass, defeat, or circumvent any security feature, authentication, rate limit, or access control of the Services
- Do not impersonate any person or misrepresent your affiliation with Qualsis or any third party
3.4. Misuse of the Services
- Do not use the Services to develop, train, or improve a competing product or service.
- Do not reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, underlying algorithms, model weights, or non-public components of the Services, except to the extent applicable law permits those activities notwithstanding this prohibition. Where applicable law permits Qualsis to require it, Customer will first request reasonably available interoperability information from Qualsis before undertaking otherwise permitted decompilation.
- Do not resell, sublicense, white-label, or otherwise make the Services available to third parties without our prior written consent
- Do not use the Services in a way that creates excessive or unreasonable load on Qualsis's infrastructure
- Do not use the Services to send unsolicited bulk communications (spam) or to harvest contact information
3.5. Customer Data integrity
- Do not upload Customer Data that Customer is not authorized to upload (such as data subject to an obligation prohibiting disclosure to Qualsis)
- Do not upload Customer Data without having obtained all consents and lawful bases required under Applicable Data Protection Laws (as defined in the DPA)
- Do not upload Customer Data that you know or should reasonably know to contain malware, hidden tracking, or other harmful payloads
- Do not upload classified or controlled-unclassified information that is subject to export controls or other government-handling requirements, except where Customer has confirmed in advance with Qualsis that the Customer's subscription tier and the Services' actual data handling support the relevant requirements
3.6. Resale and sublicensing restrictions
- Do not resell access to the Services, sublicense the Services to a third party for that third party's own use, or use the Services to provide services to third parties under your own brand, except where expressly permitted by your subscription plan or your Order
- Do not provide access to the Services to any person except Customer's authorized End Users acting on Customer's behalf
4. AI-specific prohibitions and rules
The Services include features that use artificial intelligence and machine learning. Customer and its End Users must comply with the rules in this Section 4 when using those features.
4.1. Categorical AI prohibitions (incorporated by reference)
Use of AI Features in the Services is governed by the Qualsis Responsible AI Policy at https://qualsis.com/legal/trust/responsible-ai, which is incorporated by reference into this AUP. The Responsible AI Policy contains the binding categorical prohibitions on AI use, the responsibility framework for consequential decisions, and the QoherenceAI customer-builder governance obligations.
In summary (the Responsible AI Policy controls):
- No fully automated adverse decisions about persons in matters affecting employment, credit, housing, education, healthcare, government benefits, or legal status. Human review with override authority is required.
- No biometric identification, emotion detection, or social scoring of persons.
- No use on the personal data of children below the applicable minimum age, except where expressly supported by the Customer's subscription tier with appropriate consents and lawful bases.
- No deepfakes, impersonation, or intentional deception. Generated content that depicts or impersonates real persons requires their consent or another lawful basis; AI-generated public-interest content must be disclosed where applicable law requires it.
- No content that harms minors (including child sexual abuse material) - Qualsis will report such material to authorities.
- No harassment, harm, or unauthorized surveillance of persons or groups.
- No circumvention of safety mechanisms built into the AI Features or any upstream model (including jailbreaking, prompt injection, and adversarial prompting).
- No reverse engineering of AI Features, including model weight extraction or derivative-model creation through output scraping.
For QoherenceAI specifically (when generally available), the platform will enforce these prohibitions by architecture where feasible. Attempting to bypass platform-level safeguards is a material breach of this AUP and the Responsible AI Policy.
Each prohibition is binding subject only to the express qualifications stated in the applicable bullet, the Responsible AI Policy, or a written authorization expressly permitted by this AUP. No unwritten or implied exception applies. The full statement of each, including required scope, examples, and definitions, is in the Responsible AI Policy.
4.2. Training rights and data extraction
Customer will not use the Services to:
- Extract, scrape, or otherwise capture model weights, model architectures, or training data of the Services
- Generate or otherwise produce a derivative model, product, or service intended to replicate the Services' capabilities, except where Qualsis has expressly authorized that activity in writing.
- Train any artificial intelligence or machine learning model (Customer's own or any third party's) on Outputs of the Services in a manner that contravenes Customer's subscription terms or applicable third-party licenses
4.3. Treating Output as definitive
The Services produce forecasts, signals, recommendations, and analysis. Customer agrees that Outputs are intended to inform Customer's judgment, not to replace it. Customer remains responsible for any decisions made on the basis of Outputs. Qualsis does not warrant the accuracy, completeness, or fitness for any particular purpose of the Outputs, as set out in the Terms.
4.4. QoherenceAI customer-side governance (when available)
Customer's use of QoherenceAI to build, deploy, or operate AI agents creates additional obligations. When QoherenceAI is generally available, Customer using the platform agrees to:
- Maintain a documented internal governance process for the agents Customer builds, including specification of intended use, training data sources, evaluation methodology, and incident handling
- Apply the prohibitions in Sections 4.1 and 4.2 above to the agents Customer builds on QoherenceAI; do not build agents that violate these rules
- Comply with applicable AI regulations as the downstream deployer or provider (as the case may be) under the EU AI Act, similar foreign laws, and applicable US state and federal laws
- On Qualsis's reasonable request (no more than once annually unless a material incident has occurred), provide written attestation that Customer's deployed agents comply with this AUP
These obligations may be expanded or detailed in a separate QoherenceAI-specific addendum to the Terms before QoherenceAI's general availability.
5. Customer Data and lawful basis
Customer is responsible for ensuring that:
- Customer has all necessary rights to upload, connect, transmit, or generate Customer Data through the Services
- Customer has obtained all necessary consents and lawful bases under applicable data protection laws for the processing of personal data within Customer Data, including consent of Data Subjects where required
- Customer Data is accurate to the extent its accuracy is required by applicable law or by Customer's intended use
- Customer maintains the records of consents, notices, and lawful bases for Customer-directed processing. Qualsis acts as Processor for Customer Personal Data as described in the DPA; Qualsis may act as Controller for account, administrator, security, billing, and similar data as described in the Privacy Policy.
Customer's data protection obligations are described in more detail in the DPA at https://qualsis.com/legal/trust/dpa.
6. Security obligations
In addition to the general security prohibitions in Section 3.3, Customer will:
- Maintain reasonable security of Customer's own systems, accounts, and credentials used to access the Services
- Use multi-factor authentication where the Services support it, especially for administrator accounts
- Promptly revoke access for any End User who no longer needs it
- Promptly notify Qualsis of any actual or suspected compromise of Customer's account or credentials
- Cooperate with Qualsis's reasonable security requests, including in connection with an incident involving Customer's data
7. Compliance with law
Customer's use of the Services must comply with all applicable laws, including:
- Data protection laws (GDPR, UK GDPR, CCPA, other US state privacy laws, and similar laws of other jurisdictions)
- Industry-specific regulations applicable to Customer (such as HIPAA for healthcare data, FERPA for education data, GLBA for financial data, where applicable)
- Export control and sanctions laws (including U.S. OFAC sanctions and EU sanctions; Customer is responsible for not violating sanctions through use of the Services)
- AI-specific regulations as they come into effect (including the EU AI Act phased application, US state AI laws, and similar foreign laws)
- Employment and anti-discrimination laws (especially relevant if Customer uses QortexOS analytics or Outputs in any way that could inform employment decisions, even with human review in the loop)
Customer is responsible for determining the laws that apply to its specific use of the Services. The Services are not designed for, and Customer will not use the Services to handle, any data that the Customer's subscription tier does not support, such as classified information, controlled unclassified information requiring specific federal handling, or special categories of personal data that the Customer has not been authorized to process under the Customer's subscription tier.
8. Industry-specific use cases
Some Customers operate in regulated industries. For those Customers:
8.1. Healthcare
Customer must not upload PHI unless and until Qualsis expressly designates Customer's subscription plan as supporting PHI and the parties execute a BAA before processing begins. No BAA is offered during a beta or evaluation program, unless by exception or special request. Contact Privacy to ask about future availability.
8.2. Financial services
If Customer is subject to GLBA, SOX, FINRA, or similar financial-services regulations, Customer remains responsible for its own regulatory compliance. The Services are not certified for any specific financial-services regulatory framework. Customer should consult its compliance officer before using the Services for regulated activities.
8.3. Government customers
Government customers may have additional regulatory obligations applicable to their use of the Services. Section 16.9 of the Terms applies; contact us before signup to discuss any required terms.
8.4. Education
If Customer handles educational records subject to FERPA, similar state laws, or similar foreign laws, Customer is responsible for ensuring that its use of the Services complies with applicable educational privacy requirements. The Services are not designed for processing student data of minors.
9. Reporting violations
If Customer or anyone else becomes aware of activity that violates this AUP, contact Qualsis at Contact Privacy. Reports should include reasonable details about the suspected violation and contact information through which Qualsis can reach the reporting person.
We will investigate credible reports and take appropriate action, which may include working with Customer to address the issue, suspending or terminating the account of a violating party, or reporting illegal activity to law enforcement.
10. Consequences of violation
Material violations of this AUP may result in:
- Notice and an opportunity to cure (where the circumstances reasonably allow)
- Suspension of access to the Services as described in the Terms (typically with notice, but immediate suspension may be appropriate for severe violations affecting security or other Customers)
- Termination of the Customer's subscription as described in the Terms
- Liability under the Customer's indemnification obligations in the Terms
- Referral to law enforcement or other authorities for activity that constitutes a crime or other serious legal violation
- Recovery of fees, damages, or other remedies available to Qualsis under the Terms and applicable law
Where required by applicable law, or where reasonably necessary to prevent imminent material harm, Qualsis may notify affected persons or relevant authorities. Where legally permitted and reasonably practicable, Qualsis will notify Customer before making a notification relating to Customer Data or Customer's use of the Services.
11. Updates to this AUP
Material changes ordinarily take effect at Customer's next renewal. A material change may take effect during a current term where required by law or reasonably necessary to address a material security, safety, abuse, or regulatory risk, subject to the applicable notice, termination, and refund provisions in the Terms. The current AUP is published at https://qualsis.com/legal/trust/acceptable-use, and a change log of material updates is maintained at https://qualsis.com/legal/trust/aup-changelog.
Non-material changes (clarifications, formatting, addition of products or examples that do not change substantive obligations) take effect upon publication.
12. Relationship to other documents
For personal-data processing matters, the DPA and its order-of-precedence provision control. For all other matters, the order of precedence in Terms Section 16.1 applies. This AUP imposes additional restrictions on use of the Services; an additional restriction does not create a conflict merely because the Terms do not restate it.
If a term of this AUP is held invalid or unenforceable in a particular jurisdiction, the remaining terms remain in effect; the invalid term is replaced by an enforceable term that approximates the original as closely as possible.
13. Contact
For questions about this AUP, to ask about BAA availability, to report a violation, or to ask whether a contemplated use is permitted:
Email: Contact Privacy (data-protection matters); Contact Legal (contractual matters)
Postal mail:
Qualsis, LLC
3540 Toringdon Way, Suite 200
Charlotte, NC 28277
United States
Last updated: August 28, 2026 · Effective: August 24, 2026