Acceptable Use Policy (AUP)
CONSOO S.R.L.S. — hice Edition: English master (international) Last updated: 3 July 2026
1. Preamble, purpose and scope
1.1 Purpose
This Acceptable Use Policy (hereinafter the «AUP» or the «Policy») defines the permitted uses and, above all, the prohibited uses of the hice Service, provided by CONSOO S.R.L.S. (hereinafter «hice» or the «Provider»). Its purpose is to protect the security, integrity and availability of the Service, to safeguard other Customers and Users, the Data Subjects whose data is processed in the Service, and third parties, as well as to ensure that the Service is used in compliance with the law.
1.2 Nature and relationship with the Terms
This AUP forms an integral and substantial part of the General Terms of
Service (condizioni-generali-servizio.md, hereinafter the «Terms»), which
the Customer accepts upon subscribing to the Service. In the event of a conflict
between this Policy and the Terms, the Terms shall prevail, it being understood
that the two sources are to be interpreted in a complementary manner.
Capitalized terms not otherwise defined in this Policy have the meaning ascribed
to them in the Terms and in the shared glossary.
1.3 Personal scope
This AUP applies to all Customers and to all Authorized Users,
regardless of the Plan subscribed to, including the Free Plan. It applies to
the use of the Service in its entirety: web platform (https://app.hice.ai),
mobile app, API, AI Features and Documentation.
1.4 Customer responsibility for Users
The Customer is responsible for the use of the Service by its Authorized Users and by third parties to whom it grants, even de facto, access to its Account or Tenant. Any breach of this AUP by an Authorized User shall be deemed, for the purposes of the contractual relationship, a breach attributable to the Customer. The Customer is required to bring this Policy to the attention of its Authorized Users and to ensure compliance with it.
1.5 General principle
The use of the Service must be lawful, fair and consistent with its intended purpose. The Service is a Professional Services Automation platform intended for the professional management of clients, candidates, projects, timesheets, expense reports, documents, mail, team communications and related functions. Any use that goes beyond such intended purpose, that causes harm to hice, to other Customers, to Users, to Data Subjects or to third parties, or that violates laws or regulations, is prohibited.
2. Prohibited uses — Content and third-party rights
It is prohibited to upload, enter, generate, transmit, publish, store or otherwise make available through the Service any Content or Customer Data that:
2.1 Unlawful content
- is contrary to mandatory rules, public order or public morality, or that constitutes a criminal offence or a civil or administrative wrong under applicable law;
- promotes, incites or facilitates unlawful activities, violence, terrorism, discrimination, hatred or acts contrary to human dignity.
2.2 Defamatory content or content harmful to the person
- is defamatory, abusive, slanderous, denigratory, threatening or harassing;
- harms the honor, reputation, image, personal identity or privacy of a natural or legal person.
2.3 Infringement of third-party rights
- infringes third parties' intellectual or industrial property rights (copyright, trademarks, patents, trade secrets, databases);
- infringes personality rights, image rights, privacy rights or any other third-party right;
- is uploaded without holding all the rights, licenses, authorizations and consents required.
2.4 Content prohibited by law
- has child-pornographic content or content otherwise connected with the exploitation of minors;
- has obscene or sexually explicit content not pertinent to the professional purpose of the Service.
The Customer is and remains the owner and sole party responsible for the Customer Data and the Content entered into the Service and warrants their lawfulness, in accordance with the Terms and the related indemnification obligation.
3. Prohibited uses — Protection of personal data (legal basis)
This section is of central importance, given that the Service includes recruiting and management functions for candidates, employees, collaborators and contacts, and therefore the routine processing of personal data of third parties.
3.1 Prohibition on uploading without a legal basis
It is prohibited to upload, enter or have the Service process personal data of third parties — including, by way of example, data of candidates, employees, collaborators and contacts — in the absence of a valid legal basis under Article 6 (and, where applicable, Article 9) of EU Regulation 2016/679 («GDPR»), including, where required, the consent of the Data Subject.
3.2 Special categories of data
The Customer must not upload to the Service special categories of personal
data (Article 9 GDPR — racial or ethnic origin, political opinions, religious
or philosophical beliefs, trade union membership, genetic or biometric data,
data concerning health, sex life or sexual orientation), nor data relating to
criminal convictions and offences (Article 10 GDPR), unless this is strictly
necessary, lawful and supported by an appropriate legal basis and adequate
safeguards, and except as may otherwise be provided in the Terms and in the DPA
(dpa-trattamento-dati.md). The Service is not designed for the systematic
processing of such categories of data.
3.3 Obligations of the Customer as Data Controller
The Customer acts as Data Controller of the Customer Data; hice acts as
Data Processor on behalf of the Customer, under the terms of the DPA
(dpa-trattamento-dati.md). The Customer is therefore required to:
- have a legal basis for any processing of personal data of third parties carried out through the Service;
- provide Data Subjects with the information notice required by Articles
13–14 GDPR (for this purpose, it may use the Customer information notice
templates,
modelli-informative-cliente.md); - comply with the principles of data minimization, purpose limitation and storage limitation, refraining from uploading data that exceeds the professional purposes for which the Service is used;
- ensure the rights of Data Subjects and act upon the related requests.
3.4 Misuse of recruiting and matching functions
It is prohibited to use the candidate management functions and the
candidate↔opportunity matching functions for unlawful or discriminatory
purposes, to profile or select persons in violation of the rules protecting
workers and candidates, or to process candidate data beyond the retention
periods permitted by applicable law. The use of the AI Features in support of
selection is further governed by Article 8 and by the AI Notice and algorithmic
transparency (informativa-ai-trasparenza.md).
4. Prohibited uses — Security of the Service and systems
4.1 Malware and malicious code
It is prohibited to upload, transmit, distribute or introduce into the Service or through it malware or malicious code of any kind, including viruses, worms, trojans, ransomware, spyware, keyloggers, rootkits, logic bombs, scripts or any other element capable of damaging, altering, disrupting or compromising the operation of the Service, of hice's systems, of its sub-processors or of third-party systems.
4.2 Compromising security, integrity or availability
It is prohibited to carry out activities that compromise or endanger the security, integrity or availability of the Service or of the underlying infrastructure, including, by way of example and without limitation:
- Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks, flooding, or the generation of anomalous or disproportionate loads;
- activities that degrade the performance of the Service or impair its use by other Customers or Users;
- alteration, tampering with or corruption of data, logs, audit records or components of the Service;
- interference with the multi-tenant isolation mechanisms.
4.3 Unauthorized access and intrusion attempts
It is prohibited to:
- access or attempt to access Accounts, Tenants, data, areas or functions of the Service for which one is not authorized, including the data of other Customers or Users;
- carry out penetration testing, vulnerability scanning, fuzzing, port scanning or similar activities on the Service or on its infrastructure without the prior written authorization of hice;
- use others' credentials, improperly share one's own credentials, steal or attempt to steal credentials, tokens or keys;
- exploit or attempt to exploit vulnerabilities, errors or defects of the Service in order to obtain unauthorized access or functionality.
4.4 Unauthorized extraction and analysis
It is prohibited, without prejudice to the mandatory limits of law, to:
- carry out scraping, harvesting, automated crawling or bulk extraction of data from the Service not made available by the official functions or by the authorized API;
- carry out data mining or systematic extraction of Content or data of which one is not the owner or legitimate recipient;
- carry out reverse engineering, decompilation or disassembly of the Service or of its software, except within the strict limits in which such activities are permitted by mandatory, non-derogable rules (in particular as regards interoperability under software legislation), and subject to, where required by law, notice to hice.
4.5 Circumvention of technical limits, quotas and security measures
It is prohibited to evade, disable, tamper with or circumvent:
- technical limits, usage quotas, thresholds or restrictions associated with the Plan subscribed to;
- security measures, access controls, authentication mechanisms, filters or protections of the Service;
- detection, logging, monitoring or audit mechanisms.
5. Prohibited uses — Unsolicited communications (spam)
It is prohibited to use the Service, including the integrated email feature and the team chat, notification and calendar functions, to:
- send spam, unsolicited commercial or promotional communications, unwanted bulk communications or chain messages;
- send communications in violation of the rules protecting recipients, in particular as regards direct marketing and consent (Articles 6, 7 GDPR and the Privacy Code, Legislative Decree 196/2003 as amended);
- carry out phishing, spoofing, social engineering or falsification of the identity of the sender or of the subject of communications;
- distribute, through communications, malware, malicious links or Content prohibited under this AUP.
It is recalled that the integrated email feature operates, where configured, through the Customer's credentials with the email services chosen by the Customer («BYO» integrations); the sending of communications remains under the Customer's full responsibility, and the Customer is required to comply also with the terms of use of the email services chosen by it.
6. Prohibited uses — Unauthorized commercial exploitation
It is prohibited, unless otherwise authorized in writing by hice or unless otherwise provided in the Terms, to:
- resell, sublicense, rent, lease, lend, distribute or otherwise make the Service or access to it available to third parties;
- use the Service to provide services to third parties on a service bureau, time-sharing or equivalent basis, beyond the Customer's normal internal professional use and its relationships with its own clients within the scope of the intended purpose of the Service;
- allow access to the Service to persons who are not Authorized Users;
- use the Service, or the information and data obtained from it, to develop, train or improve a competing product or service.
7. Fair use, quotas and technical limits
7.1 Fair use principle
The Service is subject to a principle of fair and reasonable use. The Customer undertakes not to use the Service in a manner that, by volume, frequency or method, is disproportionate to normal professional use, such as to prejudice the performance of the Service or the experience of other Customers and Users.
7.2 Quotas and limits
The Service may provide for usage quotas, thresholds and limits,
differentiated according to the Plan (in particular for the Free Plan), relating,
by way of example, to the number of Users, volume of data and storage, frequency
of API calls, volume of use of the AI Features, and number of communications.
The applicable limits are set out in the Documentation, in the Economic Terms
(condizioni-economiche.md) or, for the Free Plan, in the Free Plan and Beta
Terms (termini-piano-gratuito-beta.md).
7.3 Proportionate measures in case of anomalous use
In the event of exceeding the quotas or of anomalous or disproportionate use of resources, hice may adopt proportionate technical measures (for example, temporary limitation of the frequency of requests — rate limiting — or limitation of functions), under the terms provided in the Terms, giving the Customer prior notice where possible. Such measures do not in themselves constitute a breach by hice.
8. Prohibited uses — AI Features
8.1 Prohibition of use for prohibited purposes
It is prohibited to use the AI Features of the Service (chat assistant, candidate matching, CV parsing, OCR) for purposes prohibited by this AUP, by the Terms or by law, including to generate unlawful, defamatory, deceptive or rights-infringing Content, or for activities that compromise the security of the Service.
8.2 Prohibition of decisions without human oversight
The outputs of the AI Features are in the nature of an aid to decision-making and are provided «as is», and may contain errors, inaccuracies or omissions («hallucinations»). It is prohibited to use the AI Features to make decisions without adequate human oversight and verification, in particular decisions that produce legal effects or that significantly affect persons.
Consistent with the human-in-the-loop (HITL) principle, the write actions suggested by the AI require human confirmation before being executed. With specific regard to recruiting, candidate matching is a tool to support human decision-making and does not replace the Customer's assessment: the Customer, as Data Controller and decision-maker (and, where applicable, deployer under EU Regulation 2024/1689 — «AI Act»), must ensure human oversight, inform Data Subjects and recognize the right to human intervention, to express one's point of view and to contest the outcome.
8.3 Reference to the AI Notice
The detailed rules on the AI Features, the models used and the allocation of
responsibilities are contained in the AI Notice and algorithmic transparency
(informativa-ai-trasparenza.md), which the Customer is required to observe. It
is reiterated that hice does not use Customer Data to train its own base AI
models.
9. Compliance with laws
The Customer and the Authorized Users undertake to use the Service in compliance with all applicable laws and regulations, including, by way of example and without limitation, those concerning the protection of personal data, intellectual property, labor law and personnel selection, electronic communications and marketing, IT security, export control and restrictive measures (sanctions), as well as the rules of any jurisdiction relevant to the Customer's business. Any use of the Service contrary to such rules is prohibited.
10. Reporting of abuse and vulnerabilities
10.1 Reporting obligation
The Customer and the Authorized Users are required to promptly report to hice any abuse, unauthorized use of the Service, Account compromise, suspected breach of this AUP, as well as any security vulnerability or anomaly of which they become aware, refraining in the meantime from exploiting it. Reports are to be sent to info@hice.ai.
10.2 Vulnerability disclosure
The procedures for responsible reporting of security vulnerabilities, the
conditions of safe harbor for research conducted in good faith, the prohibition
of destructive testing and the response times are governed by the Security and
Vulnerability Disclosure Policy
(interno-policy-sicurezza-e-vuln-disclosure.md) and by the related
security.txt file. Security research conducted in compliance with that policy
does not constitute a breach of this AUP.
11. Monitoring and ascertaining breaches
hice is not subject to any general obligation to monitor the Content and the Customer Data, under the applicable rules on information society services (Legislative Decree 70/2003 and EU Regulation 2022/2065 — «Digital Services Act», where applicable). hice nevertheless reserves the right, without assuming the obligation, to:
- ascertain, including following a report, breaches of this AUP;
- adopt the proportionate technical measures described in this Policy and in the Terms;
- remove or make inaccessible Content that is manifestly unlawful or in breach of this AUP, within the limits and in the manner provided by law and by the Terms.
The processing of data in the course of such activities takes place in compliance
with the Privacy Notice (informativa-privacy.md) and the DPA
(dpa-trattamento-dati.md).
12. Consequences of breaches
12.1 Graduated measures
In the event of a breach, even a suspected one, of this AUP, hice may adopt, according to severity and proportionality, one or more of the following measures: warning and formal notice to comply; removal or blocking of the infringing Content; limitation or disabling of functions or of Users; application of technical limits; suspension of the Account or of access to the Service; termination of the contract.
12.2 Immediate suspension in case of risk
hice may suspend with immediate effect, in whole or in part and without notice, access to the Service where the breach entails an actual risk to the security, integrity or availability of the Service, to the data or to the rights of hice, of other Customers, Users, Data Subjects or third parties, or where there is a well-founded risk of legal liability. Where possible and compatible with the nature of the risk, hice shall give the Customer concurrent or subsequent notice thereof.
12.3 Termination
In the event of a serious or repeated breach of this AUP, hice may terminate
the contract, under the terms and with the effects provided by the General Terms
of Service (condizioni-generali-servizio.md), to which full reference is made
for the rules on suspension and termination (conditions, procedures,
notice periods where provided, and effects, including those on the data and on
the cessation of access).
12.4 Reference to the Terms and preservation of rights
The consequences of breaches, including suspension and termination, are governed
primarily by the General Terms of Service
(condizioni-generali-servizio.md). The adoption of the measures referred to in
this Article is without prejudice to any other right or remedy available to hice,
including the right to compensation for damages and the operation of the
Customer's indemnification provided by the Terms for breaches of this AUP and
for the lawfulness of the data uploaded. It is understood that, even in the event
of suspension or termination for a breach attributable to the Customer, hice's
obligations regarding data processing and, where applicable, the return or
deletion of Customer Data under the DPA (dpa-trattamento-dati.md) remain
unaffected.
12.5 No liability of hice for the measures adopted
The measures adopted by hice in accordance with this AUP and the Terms in response to a breach by the Customer or a User do not constitute a breach by hice and do not give rise to any obligation of indemnity or compensation on the part of hice, without prejudice to the mandatory limits of law.
13. Cooperation with the authorities
hice may, within the limits and in the manner provided by law, cooperate with
the competent judicial, police, supervisory and administrative authorities
and act upon lawful orders, requests and measures of the authorities, including
by retaining, communicating or making available data and information necessary to
ascertain or suppress breaches of law or of this AUP. Such cooperation takes
place in compliance with the rules on the protection of personal data, with the
Privacy Notice (informativa-privacy.md) and, for Customer Data, with the DPA
(dpa-trattamento-dati.md); where the law permits, hice shall inform the
Customer of requests concerning Customer Data.
14. Changes to this Policy
hice may amend this AUP to adapt it to regulatory, technical or Service
developments, under the terms provided by the General Terms of Service
(condizioni-generali-servizio.md) for the amendment of the Terms, with the
related notice procedures. The version in force is the one published with the
indication of the effective date stated in the heading.
15. Contacts
For reports, requests and communications relating to this AUP:
- CONSOO S.R.L.S. — hice
- Registered office: Piazzetta Umberto Giordano 2, 20122 Milan (MI), Italy
- VAT / Tax Code: IT13823860963
- REA: MI-2745733
- PEC: consoo@pec.it
- Email: info@hice.ai
- Privacy / data protection: info@hice.ai