← Documenti legali

Acceptable Use Policy (AUP)

CONSOO S.R.L.S. — hice Edition: English master (international) Last updated: 3 July 2026


1. Preamble, purpose and scope

1.1 Purpose

This Acceptable Use Policy (hereinafter the «AUP» or the «Policy») defines the permitted uses and, above all, the prohibited uses of the hice Service, provided by CONSOO S.R.L.S. (hereinafter «hice» or the «Provider»). Its purpose is to protect the security, integrity and availability of the Service, to safeguard other Customers and Users, the Data Subjects whose data is processed in the Service, and third parties, as well as to ensure that the Service is used in compliance with the law.

1.2 Nature and relationship with the Terms

This AUP forms an integral and substantial part of the General Terms of Service (condizioni-generali-servizio.md, hereinafter the «Terms»), which the Customer accepts upon subscribing to the Service. In the event of a conflict between this Policy and the Terms, the Terms shall prevail, it being understood that the two sources are to be interpreted in a complementary manner. Capitalized terms not otherwise defined in this Policy have the meaning ascribed to them in the Terms and in the shared glossary.

1.3 Personal scope

This AUP applies to all Customers and to all Authorized Users, regardless of the Plan subscribed to, including the Free Plan. It applies to the use of the Service in its entirety: web platform (https://app.hice.ai), mobile app, API, AI Features and Documentation.

1.4 Customer responsibility for Users

The Customer is responsible for the use of the Service by its Authorized Users and by third parties to whom it grants, even de facto, access to its Account or Tenant. Any breach of this AUP by an Authorized User shall be deemed, for the purposes of the contractual relationship, a breach attributable to the Customer. The Customer is required to bring this Policy to the attention of its Authorized Users and to ensure compliance with it.

1.5 General principle

The use of the Service must be lawful, fair and consistent with its intended purpose. The Service is a Professional Services Automation platform intended for the professional management of clients, candidates, projects, timesheets, expense reports, documents, mail, team communications and related functions. Any use that goes beyond such intended purpose, that causes harm to hice, to other Customers, to Users, to Data Subjects or to third parties, or that violates laws or regulations, is prohibited.


2. Prohibited uses — Content and third-party rights

It is prohibited to upload, enter, generate, transmit, publish, store or otherwise make available through the Service any Content or Customer Data that:

2.1 Unlawful content

  • is contrary to mandatory rules, public order or public morality, or that constitutes a criminal offence or a civil or administrative wrong under applicable law;
  • promotes, incites or facilitates unlawful activities, violence, terrorism, discrimination, hatred or acts contrary to human dignity.

2.2 Defamatory content or content harmful to the person

  • is defamatory, abusive, slanderous, denigratory, threatening or harassing;
  • harms the honor, reputation, image, personal identity or privacy of a natural or legal person.

2.3 Infringement of third-party rights

  • infringes third parties' intellectual or industrial property rights (copyright, trademarks, patents, trade secrets, databases);
  • infringes personality rights, image rights, privacy rights or any other third-party right;
  • is uploaded without holding all the rights, licenses, authorizations and consents required.

2.4 Content prohibited by law

  • has child-pornographic content or content otherwise connected with the exploitation of minors;
  • has obscene or sexually explicit content not pertinent to the professional purpose of the Service.

The Customer is and remains the owner and sole party responsible for the Customer Data and the Content entered into the Service and warrants their lawfulness, in accordance with the Terms and the related indemnification obligation.


3. Prohibited uses — Protection of personal data (legal basis)

This section is of central importance, given that the Service includes recruiting and management functions for candidates, employees, collaborators and contacts, and therefore the routine processing of personal data of third parties.

3.1 Prohibition on uploading without a legal basis

It is prohibited to upload, enter or have the Service process personal data of third parties — including, by way of example, data of candidates, employees, collaborators and contacts — in the absence of a valid legal basis under Article 6 (and, where applicable, Article 9) of EU Regulation 2016/679 («GDPR»), including, where required, the consent of the Data Subject.

3.2 Special categories of data

The Customer must not upload to the Service special categories of personal data (Article 9 GDPR — racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, data concerning health, sex life or sexual orientation), nor data relating to criminal convictions and offences (Article 10 GDPR), unless this is strictly necessary, lawful and supported by an appropriate legal basis and adequate safeguards, and except as may otherwise be provided in the Terms and in the DPA (dpa-trattamento-dati.md). The Service is not designed for the systematic processing of such categories of data.

3.3 Obligations of the Customer as Data Controller

The Customer acts as Data Controller of the Customer Data; hice acts as Data Processor on behalf of the Customer, under the terms of the DPA (dpa-trattamento-dati.md). The Customer is therefore required to:

  • have a legal basis for any processing of personal data of third parties carried out through the Service;
  • provide Data Subjects with the information notice required by Articles 13–14 GDPR (for this purpose, it may use the Customer information notice templates, modelli-informative-cliente.md);
  • comply with the principles of data minimization, purpose limitation and storage limitation, refraining from uploading data that exceeds the professional purposes for which the Service is used;
  • ensure the rights of Data Subjects and act upon the related requests.

3.4 Misuse of recruiting and matching functions

It is prohibited to use the candidate management functions and the candidate↔opportunity matching functions for unlawful or discriminatory purposes, to profile or select persons in violation of the rules protecting workers and candidates, or to process candidate data beyond the retention periods permitted by applicable law. The use of the AI Features in support of selection is further governed by Article 8 and by the AI Notice and algorithmic transparency (informativa-ai-trasparenza.md).


4. Prohibited uses — Security of the Service and systems

4.1 Malware and malicious code

It is prohibited to upload, transmit, distribute or introduce into the Service or through it malware or malicious code of any kind, including viruses, worms, trojans, ransomware, spyware, keyloggers, rootkits, logic bombs, scripts or any other element capable of damaging, altering, disrupting or compromising the operation of the Service, of hice's systems, of its sub-processors or of third-party systems.

4.2 Compromising security, integrity or availability

It is prohibited to carry out activities that compromise or endanger the security, integrity or availability of the Service or of the underlying infrastructure, including, by way of example and without limitation:

  • Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks, flooding, or the generation of anomalous or disproportionate loads;
  • activities that degrade the performance of the Service or impair its use by other Customers or Users;
  • alteration, tampering with or corruption of data, logs, audit records or components of the Service;
  • interference with the multi-tenant isolation mechanisms.

4.3 Unauthorized access and intrusion attempts

It is prohibited to:

  • access or attempt to access Accounts, Tenants, data, areas or functions of the Service for which one is not authorized, including the data of other Customers or Users;
  • carry out penetration testing, vulnerability scanning, fuzzing, port scanning or similar activities on the Service or on its infrastructure without the prior written authorization of hice;
  • use others' credentials, improperly share one's own credentials, steal or attempt to steal credentials, tokens or keys;
  • exploit or attempt to exploit vulnerabilities, errors or defects of the Service in order to obtain unauthorized access or functionality.

4.4 Unauthorized extraction and analysis

It is prohibited, without prejudice to the mandatory limits of law, to:

  • carry out scraping, harvesting, automated crawling or bulk extraction of data from the Service not made available by the official functions or by the authorized API;
  • carry out data mining or systematic extraction of Content or data of which one is not the owner or legitimate recipient;
  • carry out reverse engineering, decompilation or disassembly of the Service or of its software, except within the strict limits in which such activities are permitted by mandatory, non-derogable rules (in particular as regards interoperability under software legislation), and subject to, where required by law, notice to hice.

4.5 Circumvention of technical limits, quotas and security measures

It is prohibited to evade, disable, tamper with or circumvent:

  • technical limits, usage quotas, thresholds or restrictions associated with the Plan subscribed to;
  • security measures, access controls, authentication mechanisms, filters or protections of the Service;
  • detection, logging, monitoring or audit mechanisms.

5. Prohibited uses — Unsolicited communications (spam)

It is prohibited to use the Service, including the integrated email feature and the team chat, notification and calendar functions, to:

  • send spam, unsolicited commercial or promotional communications, unwanted bulk communications or chain messages;
  • send communications in violation of the rules protecting recipients, in particular as regards direct marketing and consent (Articles 6, 7 GDPR and the Privacy Code, Legislative Decree 196/2003 as amended);
  • carry out phishing, spoofing, social engineering or falsification of the identity of the sender or of the subject of communications;
  • distribute, through communications, malware, malicious links or Content prohibited under this AUP.

It is recalled that the integrated email feature operates, where configured, through the Customer's credentials with the email services chosen by the Customer («BYO» integrations); the sending of communications remains under the Customer's full responsibility, and the Customer is required to comply also with the terms of use of the email services chosen by it.


6. Prohibited uses — Unauthorized commercial exploitation

It is prohibited, unless otherwise authorized in writing by hice or unless otherwise provided in the Terms, to:

  • resell, sublicense, rent, lease, lend, distribute or otherwise make the Service or access to it available to third parties;
  • use the Service to provide services to third parties on a service bureau, time-sharing or equivalent basis, beyond the Customer's normal internal professional use and its relationships with its own clients within the scope of the intended purpose of the Service;
  • allow access to the Service to persons who are not Authorized Users;
  • use the Service, or the information and data obtained from it, to develop, train or improve a competing product or service.

7. Fair use, quotas and technical limits

7.1 Fair use principle

The Service is subject to a principle of fair and reasonable use. The Customer undertakes not to use the Service in a manner that, by volume, frequency or method, is disproportionate to normal professional use, such as to prejudice the performance of the Service or the experience of other Customers and Users.

7.2 Quotas and limits

The Service may provide for usage quotas, thresholds and limits, differentiated according to the Plan (in particular for the Free Plan), relating, by way of example, to the number of Users, volume of data and storage, frequency of API calls, volume of use of the AI Features, and number of communications. The applicable limits are set out in the Documentation, in the Economic Terms (condizioni-economiche.md) or, for the Free Plan, in the Free Plan and Beta Terms (termini-piano-gratuito-beta.md).

7.3 Proportionate measures in case of anomalous use

In the event of exceeding the quotas or of anomalous or disproportionate use of resources, hice may adopt proportionate technical measures (for example, temporary limitation of the frequency of requests — rate limiting — or limitation of functions), under the terms provided in the Terms, giving the Customer prior notice where possible. Such measures do not in themselves constitute a breach by hice.


8. Prohibited uses — AI Features

8.1 Prohibition of use for prohibited purposes

It is prohibited to use the AI Features of the Service (chat assistant, candidate matching, CV parsing, OCR) for purposes prohibited by this AUP, by the Terms or by law, including to generate unlawful, defamatory, deceptive or rights-infringing Content, or for activities that compromise the security of the Service.

8.2 Prohibition of decisions without human oversight

The outputs of the AI Features are in the nature of an aid to decision-making and are provided «as is», and may contain errors, inaccuracies or omissions («hallucinations»). It is prohibited to use the AI Features to make decisions without adequate human oversight and verification, in particular decisions that produce legal effects or that significantly affect persons.

Consistent with the human-in-the-loop (HITL) principle, the write actions suggested by the AI require human confirmation before being executed. With specific regard to recruiting, candidate matching is a tool to support human decision-making and does not replace the Customer's assessment: the Customer, as Data Controller and decision-maker (and, where applicable, deployer under EU Regulation 2024/1689 — «AI Act»), must ensure human oversight, inform Data Subjects and recognize the right to human intervention, to express one's point of view and to contest the outcome.

8.3 Reference to the AI Notice

The detailed rules on the AI Features, the models used and the allocation of responsibilities are contained in the AI Notice and algorithmic transparency (informativa-ai-trasparenza.md), which the Customer is required to observe. It is reiterated that hice does not use Customer Data to train its own base AI models.


9. Compliance with laws

The Customer and the Authorized Users undertake to use the Service in compliance with all applicable laws and regulations, including, by way of example and without limitation, those concerning the protection of personal data, intellectual property, labor law and personnel selection, electronic communications and marketing, IT security, export control and restrictive measures (sanctions), as well as the rules of any jurisdiction relevant to the Customer's business. Any use of the Service contrary to such rules is prohibited.


10. Reporting of abuse and vulnerabilities

10.1 Reporting obligation

The Customer and the Authorized Users are required to promptly report to hice any abuse, unauthorized use of the Service, Account compromise, suspected breach of this AUP, as well as any security vulnerability or anomaly of which they become aware, refraining in the meantime from exploiting it. Reports are to be sent to info@hice.ai.

10.2 Vulnerability disclosure

The procedures for responsible reporting of security vulnerabilities, the conditions of safe harbor for research conducted in good faith, the prohibition of destructive testing and the response times are governed by the Security and Vulnerability Disclosure Policy (interno-policy-sicurezza-e-vuln-disclosure.md) and by the related security.txt file. Security research conducted in compliance with that policy does not constitute a breach of this AUP.


11. Monitoring and ascertaining breaches

hice is not subject to any general obligation to monitor the Content and the Customer Data, under the applicable rules on information society services (Legislative Decree 70/2003 and EU Regulation 2022/2065 — «Digital Services Act», where applicable). hice nevertheless reserves the right, without assuming the obligation, to:

  • ascertain, including following a report, breaches of this AUP;
  • adopt the proportionate technical measures described in this Policy and in the Terms;
  • remove or make inaccessible Content that is manifestly unlawful or in breach of this AUP, within the limits and in the manner provided by law and by the Terms.

The processing of data in the course of such activities takes place in compliance with the Privacy Notice (informativa-privacy.md) and the DPA (dpa-trattamento-dati.md).


12. Consequences of breaches

12.1 Graduated measures

In the event of a breach, even a suspected one, of this AUP, hice may adopt, according to severity and proportionality, one or more of the following measures: warning and formal notice to comply; removal or blocking of the infringing Content; limitation or disabling of functions or of Users; application of technical limits; suspension of the Account or of access to the Service; termination of the contract.

12.2 Immediate suspension in case of risk

hice may suspend with immediate effect, in whole or in part and without notice, access to the Service where the breach entails an actual risk to the security, integrity or availability of the Service, to the data or to the rights of hice, of other Customers, Users, Data Subjects or third parties, or where there is a well-founded risk of legal liability. Where possible and compatible with the nature of the risk, hice shall give the Customer concurrent or subsequent notice thereof.

12.3 Termination

In the event of a serious or repeated breach of this AUP, hice may terminate the contract, under the terms and with the effects provided by the General Terms of Service (condizioni-generali-servizio.md), to which full reference is made for the rules on suspension and termination (conditions, procedures, notice periods where provided, and effects, including those on the data and on the cessation of access).

12.4 Reference to the Terms and preservation of rights

The consequences of breaches, including suspension and termination, are governed primarily by the General Terms of Service (condizioni-generali-servizio.md). The adoption of the measures referred to in this Article is without prejudice to any other right or remedy available to hice, including the right to compensation for damages and the operation of the Customer's indemnification provided by the Terms for breaches of this AUP and for the lawfulness of the data uploaded. It is understood that, even in the event of suspension or termination for a breach attributable to the Customer, hice's obligations regarding data processing and, where applicable, the return or deletion of Customer Data under the DPA (dpa-trattamento-dati.md) remain unaffected.

12.5 No liability of hice for the measures adopted

The measures adopted by hice in accordance with this AUP and the Terms in response to a breach by the Customer or a User do not constitute a breach by hice and do not give rise to any obligation of indemnity or compensation on the part of hice, without prejudice to the mandatory limits of law.


13. Cooperation with the authorities

hice may, within the limits and in the manner provided by law, cooperate with the competent judicial, police, supervisory and administrative authorities and act upon lawful orders, requests and measures of the authorities, including by retaining, communicating or making available data and information necessary to ascertain or suppress breaches of law or of this AUP. Such cooperation takes place in compliance with the rules on the protection of personal data, with the Privacy Notice (informativa-privacy.md) and, for Customer Data, with the DPA (dpa-trattamento-dati.md); where the law permits, hice shall inform the Customer of requests concerning Customer Data.


14. Changes to this Policy

hice may amend this AUP to adapt it to regulatory, technical or Service developments, under the terms provided by the General Terms of Service (condizioni-generali-servizio.md) for the amendment of the Terms, with the related notice procedures. The version in force is the one published with the indication of the effective date stated in the heading.


15. Contacts

For reports, requests and communications relating to this AUP:

  • CONSOO S.R.L.S. — hice
  • Registered office: Piazzetta Umberto Giordano 2, 20122 Milan (MI), Italy
  • VAT / Tax Code: IT13823860963
  • REA: MI-2745733
  • PEC: consoo@pec.it
  • Email: info@hice.ai
  • Privacy / data protection: info@hice.ai