BACI

ACCEPTABLE USE POLICY

Version 1.0 · Effective Date: 10 September 2026 · Last Updated: 10 September 2026

This Acceptable Use Policy ("AUP") establishes requirements governing acceptable use of BACI Services.

BACI provides business intelligence, artificial-intelligence, automation, discovery, analysis, forecasting, acquisition, conversion, growth, procurement, funding, investor, campaign, developer and related capabilities. Some Services may analyse information, generate intelligence, connect to external systems or perform Customer-authorised actions.

Those capabilities must not be used to cause unlawful harm, compromise systems, deceive others, violate rights, circumvent controls or delegate authority to BACI that the Customer does not lawfully possess.

1. SCOPE

This AUP applies to every person or entity that accesses or uses BACI Services, including Customers; Authorised Users; administrators; employees and contractors accessing BACI through a Customer; developers; agencies and advisers; technology partners; licensees; API users; persons accessing BACI through an integration; and third parties whom a Customer permits to access or use BACI where such access is authorised by the Agreement.

Customers are responsible for taking reasonable measures to ensure that persons using BACI through their Accounts, organisations, workspaces, credentials or authorised integrations comply with this AUP.

2. RELATIONSHIP TO THE BACI LEGAL FRAMEWORK

This AUP forms part of the BACI Legal Framework and is incorporated into the Agreement where applicable.

It should be read with applicable documents including the Terms of Service; Privacy Policy; Data Processing Addendum; Security Policy or Security Addendum; Responsible AI Policy; AI & Autonomous Systems Terms; Developer & API Terms; Platform & Intelligence Licensing Agreement; Government & Public Sector Schedule; and applicable Orders, Statements of Work and Supplemental Terms.

The order of precedence established by the applicable Agreement governs any conflict between documents.

This AUP supplements and does not replace restrictions contained elsewhere in the Agreement.

3. CUSTOMER RESPONSIBILITY

A Customer must use BACI only for lawful purposes; within the rights granted under the Agreement; within its purchased or authorised Capacity; through authorised Accounts, credentials and integrations; within applicable operating-mode authority; in compliance with Applicable Law; in compliance with applicable professional, regulatory and contractual obligations; and in a manner consistent with this AUP.

A Customer must not instruct, encourage, enable or knowingly permit another person to use BACI in a manner prohibited by this AUP.

4. UNLAWFUL ACTIVITY

BACI must not be used to commit, facilitate, materially assist or knowingly enable activity prohibited by Applicable Law.

This includes using BACI to commit fraud; steal money, property, credentials or information; facilitate corruption or bribery; evade sanctions or export controls; launder proceeds of unlawful activity; facilitate unlawful trafficking or exploitation; unlawfully obtain restricted goods or services; unlawfully interfere with elections or governmental processes; unlawfully evade taxes, regulatory requirements or legally binding restrictions; conceal unlawful conduct; generate or maintain records known to be materially false for an unlawful purpose; or materially assist another person in committing unlawful conduct.

A lawful business objective does not make an unlawful method acceptable.

5. FRAUD, DECEPTION AND IMPERSONATION

Users must not use BACI to impersonate another person or organisation without lawful authority; create materially deceptive identities for fraudulent purposes; conduct phishing or credential-harvesting activity; generate deceptive invoices, payment instructions or financial requests; misrepresent the origin of a communication where doing so is unlawful or fraudulent; fabricate evidence; knowingly falsify material business records; manipulate provenance information for fraudulent purposes; misrepresent BACI-generated intelligence as independently verified fact where the distinction is material; falsely represent that BACI, another organisation or a public authority endorses, approved or originated a communication; or use synthetic media or AI-generated content for unlawful deceptive impersonation.

Nothing in this section prohibits legitimate testing, simulation, fictional content, authorised security exercises or other lawful uses where the nature of the activity is appropriately controlled.

6. INTELLECTUAL PROPERTY AND PROPRIETARY RIGHTS

Users must not use BACI to knowingly infringe or misappropriate another person's copyright, trademark, patent, trade secret, database right, confidential information, publicity right, proprietary information or other legally protected right.

Customers are responsible for having appropriate rights to Inputs and Customer Data submitted to BACI.

A claim that material is publicly accessible does not by itself establish a right to reproduce, exploit or process that material.

7. PRIVACY AND PERSONAL DATA

Users must not use BACI to unlawfully obtain Personal Data; unlawfully disclose Personal Data; harvest credentials; unlawfully track or monitor individuals; circumvent legally required privacy choices; re-identify lawfully de-identified information where prohibited; create unlawful databases of Sensitive Personal Data; unlawfully infer protected characteristics; conduct unlawful surveillance; disclose another person's private information for harassment, intimidation or exploitation; or otherwise violate Applicable Data Protection Law.

Where a Customer uses BACI to process Personal Data, the Customer remains responsible for establishing its own lawful basis, notices, permissions and other controller obligations where applicable.

BACI's own responsibilities remain governed by Applicable Data Protection Law and the applicable BACI Legal Framework.

8. SECURITY AND UNAUTHORISED ACCESS

Users must not gain or attempt to gain unauthorised access to BACI or another system; probe, scan or test vulnerabilities without authorisation; conduct penetration testing against BACI without prior written authorisation; conduct material load, stress or denial-of-service testing without prior written authorisation; bypass authentication; compromise another Account; steal, disclose or misuse credentials; introduce malware or malicious code; deploy ransomware; operate command-and-control infrastructure through BACI; conduct denial-of-service attacks; interfere with security monitoring; disable or circumvent logging; circumvent tenant or organisational isolation; interfere with encryption or key-management controls; exploit vulnerabilities for purposes other than authorised security research; or materially impair the confidentiality, integrity or availability of BACI or another system.

Good-faith security research must be conducted only under an applicable BACI security-testing or vulnerability-disclosure programme where one is available.

9. CIRCUMVENTION OF BACI CONTROLS

Users must not intentionally circumvent or defeat BACI controls concerning authentication; authorisation; Capacity; rate limits; usage limits; payment; licensing; Account restrictions; security; tenant isolation; operating-mode restrictions; approval thresholds; Autonomous Action boundaries; model or system safeguards; geographic restrictions; regulatory restrictions; or functionality BACI has disabled or restricted.

Users must not create multiple Accounts, credentials, organisations, workspaces or technical pathways primarily to evade a restriction that would otherwise apply.

10. INTERFERENCE WITH BACI

Users must not use BACI in a manner that materially degrades Service performance; disrupts another Customer; exhausts shared resources outside permitted Capacity; compromises platform stability; interferes with network operation; generates abusive traffic; causes avoidable infrastructure harm; or prevents BACI from providing Services to others.

BACI may apply reasonable technical controls, throttling or Capacity enforcement to protect Service integrity.

11. REVERSE ENGINEERING AND EXTRACTION

Except to the extent expressly permitted by Applicable Law notwithstanding contractual restriction, or expressly authorised by BACI in writing, users must not reverse engineer BACI Technology; decompile or disassemble BACI software; attempt to discover BACI source code; extract non-public system prompts; extract model weights; obtain non-public algorithms; reconstruct BACI scoring systems; discover protected orchestration logic; systematically extract BACI taxonomies, ontologies or proprietary methodologies; reproduce BACI intelligence engines; bypass technical measures protecting BACI Technology; or use BACI Outputs or access to BACI primarily to create a substantially substitutable copy of protected BACI functionality in violation of the Agreement.

This section does not restrict rights that cannot lawfully be excluded.

12. SCRAPING, CRAWLING AND AUTOMATED ACCESS

Automated access to BACI is permitted only through functionality, APIs or other methods BACI authorises.

Users must not use bots, spiders, crawlers, scrapers or automated extraction systems to access BACI in a manner that circumvents an API; bypasses rate limits; extracts protected BACI Technology; materially burdens the Service; violates access controls; circumvents authentication; violates third-party rights; or violates the Agreement.

Where BACI provides an API for a particular automated use, Customers should use the authorised API rather than circumventing it through unauthorised automated extraction.

13. MALWARE AND MALICIOUS CODE

BACI must not be used to intentionally develop, deploy, distribute, control or materially facilitate malware; ransomware; spyware deployed without lawful authority; credential stealers; destructive code; malicious botnets; malicious remote-access tools; exploit kits intended for unlawful compromise; command-and-control systems; malicious persistence mechanisms; or code primarily designed to damage, disrupt or unlawfully access systems.

This section does not prohibit legitimate defensive cybersecurity analysis, malware analysis, authorised testing or security research conducted within lawful and appropriately controlled environments.

14. SPAM AND ABUSIVE COMMUNICATIONS

Users must not use BACI to send or materially facilitate unlawful unsolicited commercial communications; spam; phishing; fraudulent messages; unlawful automated calling or messaging; communications that violate legally valid opt-out requests; communications sent using unlawfully obtained contact information; or communications prohibited by applicable anti-spam, electronic-marketing or telecommunications laws.

Customers using BACI for acquisition, campaign, outreach or communications intelligence remain responsible for ensuring that actual communications comply with Applicable Law.

15. HARASSMENT, THREATS AND ABUSE

BACI must not be used to intentionally facilitate credible threats of unlawful violence; stalking; targeted harassment; extortion; blackmail; coercive abuse; doxxing for malicious purposes; non-consensual intimate imagery; sexual exploitation; or conduct intended to place an identifiable person in reasonable fear of serious unlawful harm.

This restriction does not prohibit legitimate investigation, safety analysis, legal work, journalism, research or threat assessment merely because such work concerns harmful conduct.

16. CHILD SEXUAL EXPLOITATION AND ABUSE

BACI must never be used to create, solicit, facilitate, distribute, store for unlawful purposes, promote or materially assist child sexual exploitation or abuse.

This prohibition includes real or synthetic child sexual abuse material and conduct facilitating sexual exploitation, trafficking or grooming of children.

BACI may take immediate action concerning suspected child sexual exploitation or abuse and may preserve or report information where required or permitted by Applicable Law.

17. HUMAN TRAFFICKING AND EXPLOITATION

BACI must not be used to knowingly facilitate human trafficking; forced labour; sexual exploitation; slavery; involuntary servitude; unlawful recruitment for exploitative purposes; or commercial activity knowingly dependent upon such conduct.

18. DISCRIMINATION AND PROTECTED CHARACTERISTICS

Users must not use BACI to make or materially facilitate decisions that unlawfully discriminate against individuals based upon legally protected characteristics.

Where BACI is used in employment, housing, lending, insurance, education, public benefits or another regulated decision context, Customers are responsible for determining whether the proposed use is lawful and whether human review, testing, notices, explanations, impact assessments or other safeguards are required.

BACI functionality must not be used to circumvent anti-discrimination law.

19. HIGH-CONSEQUENCE DECISIONS

BACI Intelligence must not be used as the sole basis for a decision producing legal or similarly significant effects upon an individual where Applicable Law prohibits that use or requires meaningful human review.

High-consequence contexts may include employment; credit; lending; insurance; housing; education admissions; healthcare; public benefits; law enforcement; immigration; criminal justice; and other legally significant decisions.

Where BACI supports a permitted high-consequence use, the Customer must apply oversight and verification proportionate to the foreseeable consequences.

Additional restrictions may be imposed through the Responsible AI Policy, AI & Autonomous Systems Terms, Government & Public Sector Schedule or applicable Supplemental Terms.

20. SAFETY-CRITICAL USE

Unless BACI expressly agrees in writing that a particular Service is designed and authorised for the relevant safety-critical purpose, Customers must not rely upon BACI as the sole operational control for an activity where failure could reasonably be expected to cause death; serious bodily injury; catastrophic physical damage; catastrophic environmental harm; or loss of essential life-sustaining functionality.

This restriction does not prohibit the use of BACI for business intelligence, planning, research, administrative support or decision support concerning a safety-sensitive industry where BACI is not acting as the sole safety-critical control.

21. PROFESSIONAL ADVICE

Unless expressly identified otherwise, BACI Intelligence is not a substitute for regulated professional judgment.

Users must not represent BACI as a licensed lawyer, accountant, investment adviser, medical practitioner or other regulated professional where BACI does not hold that status.

Where professional review is legally required, the Customer must obtain that review.

22. FINANCIAL AND INVESTMENT ACTIVITY

BACI may provide funding, investor, market, commercial, forecasting and opportunity intelligence.

Users must not use BACI to commit securities fraud; conduct unlawful market manipulation; trade unlawfully on material non-public information; misrepresent investment performance; create fraudulent investment opportunities; conduct unlawful fundraising; evade financial regulation; or provide regulated financial services without required authorisation.

BACI Intelligence concerning investors, funding or markets does not itself constitute a guarantee of funding, investment performance or transaction completion.

23. PROCUREMENT, BIDS AND GRANTS

BACI may identify, analyse or assist with procurement opportunities, tenders, bids, grants and related processes.

Users must not use BACI to submit knowingly false eligibility information; fabricate qualifications; create false certifications; falsify past performance; collude unlawfully with competing bidders; manipulate a tender process; bribe or improperly influence procurement personnel; circumvent procurement rules; misrepresent required registrations or licences; submit fabricated evidence; or obtain protected procurement information unlawfully.

BACI may assist with discovery, analysis, preparation and decision support, but the Customer remains responsible for the truthfulness and legal sufficiency of submissions made in its name.

24. INVESTOR, FUNDER AND BUSINESS-MATCHING INTELLIGENCE

Users must not use BACI's investor, funder, partner, acquisition or business-matching capabilities to fraudulently solicit funds; misrepresent identity or authority; unlawfully disclose confidential opportunities; circumvent legally required securities restrictions; misuse private contact information; falsely claim endorsement or qualification by BACI; unlawfully discriminate in access to opportunities; or use confidential matching information outside the permissions under which it was provided.

Where BACI provides blind, consent-based or restricted matching functionality, users must respect the applicable disclosure and participation controls.

25. COMPETITIVE INTELLIGENCE

BACI may lawfully analyse markets, competitors and commercial information.

Users must not use BACI to steal trade secrets; induce unlawful breach of confidentiality; obtain protected competitor credentials; unlawfully access private competitor systems; engage in industrial espionage; unlawfully intercept communications; or circumvent technical restrictions protecting non-public information.

Lawful competitive research and analysis remain permitted.

26. AUTONOMOUS ACTIONS

Customers using Autonomous functionality must configure and maintain appropriate authority boundaries.

A Customer must not authorise BACI to perform an Autonomous Action that the Customer itself lacks legal or contractual authority to perform.

Authority boundaries may include spending limits; financial limits; approval thresholds; markets; jurisdictions; channels; connected systems; authorised actions; user permissions; frequency; volume; objectives; and other operational constraints.

Customers must not intentionally configure Autonomous functionality to circumvent law, internal controls, regulatory obligations or required human approval.

Autonomy does not remove governance.

27. CONNECTED SYSTEMS

A BACI integration does not grant a Customer rights in the connected system beyond those the Customer already possesses.

Users must not use BACI integrations to exceed permissions granted by a connected service; access another person's Account without authority; bypass third-party access controls; extract information in violation of Applicable Law; perform prohibited actions through another platform; or circumvent restrictions that would apply if the Customer acted directly.

The technical ability of an integration to perform an action does not establish legal authority to perform that action.

28. API USE

Developers and API users must protect API credentials; use credentials only for authorised purposes; comply with rate and Capacity limits; implement reasonable security; prevent unauthorised credential sharing; comply with applicable Developer & API Terms; and promptly address known compromise of credentials.

Users must not sell or transfer API credentials without authorisation; expose secret credentials publicly; rotate identities to evade restrictions; circumvent metering; falsify usage information; or use the API to conduct activity prohibited elsewhere in this AUP.

29. DATA AND INTELLIGENCE MANIPULATION

Users must not intentionally manipulate BACI systems for the purpose of corrupting intelligence; poisoning shared data systems; falsifying provenance; manipulating scoring systems through fraudulent inputs; fabricating signals intended to mislead other Customers; causing BACI to produce knowingly deceptive intelligence for fraudulent purposes; or undermining the integrity of BACI's intelligence infrastructure.

Legitimate testing, scenario analysis, simulation and Customer-specific modelling are permitted where appropriately identified and controlled.

30. AI SAFEGUARD CIRCUMVENTION

Users must not intentionally circumvent AI safeguards for the primary purpose of obtaining functionality or content prohibited by this AUP or Applicable Law.

Security research, red-team testing, evaluation and other legitimate testing authorised by BACI or conducted under an applicable programme are not prohibited merely because they test the effectiveness of safeguards.

31. MODEL AND SYSTEM EXTRACTION

Users must not systematically query, probe or otherwise use BACI for the primary purpose of extracting protected model weights; reconstructing non-public system prompts; reproducing protected decision logic; extracting proprietary datasets; replicating proprietary BACI intelligence engines; discovering protected security controls for malicious purposes; or creating an unauthorised substitute for protected BACI Technology.

This section does not prevent legitimate use of BACI Outputs in accordance with the Customer's licence.

32. CONTENT AND OUTPUT RESPONSIBILITY

Customers are responsible for determining whether their Inputs and intended uses of Outputs are lawful and appropriate.

BACI's generation of an Output does not establish that the Output is accurate; the Output is lawful for every purpose; the Output is non-infringing; the Customer possesses all rights required for its intended use; a regulator has approved the Output; a professional has verified it; or the Output may lawfully be used without human review.

Customers must apply review proportionate to the significance and foreseeable consequences of the use.

33. RESTRICTED AND REGULATED DATA

Customers must not place data into BACI where Applicable Law prohibits the processing; the Customer lacks authority to disclose it; BACI has expressly stated that the relevant environment is not authorised for that category of data; or a specialised contractual or technical environment is legally required but has not been established.

This may include classified government information, specially controlled defence information, regulated health information, payment-card data or other specially regulated information where BACI has not expressly agreed to support the applicable regulatory requirements.

34. SANCTIONS AND EXPORT CONTROLS

Users must not access or use BACI in violation of applicable economic sanctions; trade sanctions; export-control laws; import restrictions; embargoes; or restrictions concerning prohibited persons or territories.

Users must not use BACI to circumvent such restrictions through intermediaries, false identities, routing arrangements or other evasive mechanisms.

35. CORRUPTION AND IMPROPER PAYMENTS

BACI must not be used to facilitate bribery; kickbacks; unlawful facilitation payments; corrupt procurement; improper payments to public officials; concealed unlawful commissions; or falsification of records intended to conceal corrupt payments.

36. PUBLIC-SECTOR USE

Government and public-sector Customers may be subject to additional requirements under the Government & Public Sector Schedule.

Unless expressly authorised under an applicable government agreement, Customers must not use ordinary BACI environments for classified information; information subject to specialised governmental hosting requirements; activities requiring a government accreditation BACI has not obtained; or functions for which BACI has expressly stated the Service is not authorised.

Public-sector Customers remain responsible for applicable requirements concerning due process, transparency, records, procurement, accessibility, human oversight and administrative decision-making.

37. CAPACITY AND RESOURCE ABUSE

Customers must use BACI within applicable Capacity and technical limits.

BACI may reasonably throttle excessive usage; enforce rate limits; restrict abusive queries; prevent resource exhaustion; enforce plan limits; and require an appropriate Capacity upgrade where usage exceeds purchased entitlements.

BACI will not treat legitimate high-volume use within contracted Capacity as abuse merely because the Customer makes substantial use of the Service.

38. REPORTING SUSPECTED VIOLATIONS

Suspected violations of this AUP may be reported to security@bacihq.com.

Reports should contain sufficient information for BACI to identify and evaluate the alleged activity where reasonably possible.

BACI may request additional information necessary to investigate.

Knowingly submitting fraudulent abuse reports is itself prohibited.

39. INVESTIGATION

BACI may reasonably investigate suspected violations of this AUP.

An investigation may include reviewing relevant security information; reviewing Account and Usage Data; preserving relevant records; requesting information from the Customer; applying temporary safeguards; assessing affected systems; consulting service providers or professional advisers where appropriate; and cooperating with competent authorities where legally required.

BACI will conduct investigations subject to Applicable Law and applicable contractual obligations.

40. ENFORCEMENT PRINCIPLES

BACI may take reasonable and proportionate action where it reasonably determines that use of the Services violates this AUP, the Agreement or Applicable Law.

Depending upon the circumstances, action may include warning the Customer; requesting remediation; removing or restricting particular content where BACI has the technical and contractual authority to do so; restricting particular functionality; rotating or revoking compromised credentials; throttling abusive activity; disabling an integration; restricting an individual user; temporarily suspending affected functionality; temporarily suspending an Account; terminating access where permitted by the Agreement; or making a legally required report.

BACI will seek to tailor enforcement to the nature, severity, scope and persistence of the violation.

41. PROPORTIONATE SUSPENSION

Where reasonably practicable, BACI will limit a suspension to the users, credentials, integrations, functionality or Services reasonably necessary to address the relevant risk.

BACI need not suspend an entire Customer organisation where a narrower restriction reasonably addresses the issue.

This does not prevent broader immediate action where reasonably necessary to address an active security threat; material unlawful activity; child sexual exploitation or abuse; serious fraud; imminent harm; material platform disruption; sanctions or export-control requirements; compromise of Customer or BACI systems; or another circumstance requiring immediate action.

42. NOTICE AND OPPORTUNITY TO REMEDY

Where reasonably practicable and consistent with security and Applicable Law, BACI may provide notice and a reasonable opportunity to remedy an AUP violation before materially suspending Services.

Advance notice may not be provided where BACI reasonably determines that immediate action is necessary to protect security; prevent ongoing unlawful conduct; prevent material harm; comply with Applicable Law; protect another Customer; preserve evidence; prevent evasion of enforcement; or maintain Service integrity.

Where advance notice cannot reasonably be provided, BACI may provide notice afterwards where legally permitted and appropriate.

43. CUSTOMER COOPERATION

Customers must reasonably cooperate with BACI concerning material AUP violations associated with their Accounts.

Cooperation may include securing compromised credentials; disabling unauthorised users; correcting configurations; stopping prohibited activity; providing reasonably necessary information; preserving relevant evidence where legally required; and implementing reasonable remediation.

44. REPEAT OR EGREGIOUS VIOLATIONS

Repeated, deliberate or egregious violations may result in stronger enforcement, including termination where permitted by the Agreement.

BACI is not required to provide repeated remediation opportunities where a Customer intentionally resumes materially prohibited conduct after receiving notice.

45. EMERGENCIES AND IMMINENT HARM

Where BACI reasonably believes that use of the Services presents an imminent risk of death, serious bodily injury, serious exploitation, substantial cybersecurity harm or another emergency recognised by Applicable Law, BACI may take reasonable emergency measures.

Such measures may include temporary restriction, preservation of relevant information or disclosure to appropriate emergency or governmental authorities where legally permitted or required.

46. LAW-ENFORCEMENT AND REGULATORY COOPERATION

BACI may cooperate with competent law-enforcement, regulatory or judicial authorities where required by valid legal process or Applicable Law.

BACI will not treat an informal governmental request as unlimited authority to access Customer environments.

Governmental requests remain subject to the applicable provisions of the Terms, Privacy Policy and other BACI Legal Framework documents.

47. NO DUTY TO MONITOR EVERYTHING

Nothing in this AUP requires BACI to proactively monitor every Customer action, Input, Output or communication unless Applicable Law or an applicable agreement imposes such an obligation.

BACI's ability to detect or prevent a violation does not transfer responsibility for the Customer's conduct to BACI.

BACI may nevertheless use reasonable security, abuse-prevention and integrity systems to detect conduct that may threaten BACI, Customers or third parties.

48. GOOD-FAITH RESEARCH, JOURNALISM AND LEGITIMATE ANALYSIS

A use is not prohibited merely because it involves analysis of crime; violence; cybersecurity threats; extremism; fraud; abuse; sanctions; harmful organisations; dangerous products; controversial subjects; or other sensitive matters.

Legitimate research, journalism, compliance, threat intelligence, safety analysis, legal analysis, academic work and defensive security activity may be permitted where the activity itself is lawful and does not materially facilitate prohibited conduct.

Context, purpose and actual use matter.

49. BACI INTELLIGENCE IS NOT AN AUTHORISATION

The fact that BACI identifies an opportunity; provides information; produces an analysis; recommends an action; identifies a person or organisation; generates content; exposes functionality; or technically permits an action does not constitute legal, regulatory, contractual or professional authorisation for the Customer to act.

Customers remain responsible for determining whether they possess the authority required for their intended action.

50. CHANGES TO THIS AUP

BACI may update this AUP to reflect changes in BACI Services; technology; threat patterns; Applicable Law; regulatory requirements; artificial-intelligence capabilities; autonomous functionality; security requirements; or the BACI Legal Framework.

Each version will identify its effective date and last-updated date.

Where required by the Agreement or Applicable Law, BACI will provide appropriate notice of material changes.

51. INTERPRETATION

Examples in this AUP are illustrative and do not limit broader prohibitions stated in the relevant section.

A prohibition on directly performing an activity also prohibits knowingly using BACI to materially facilitate, instruct, automate or enable that prohibited activity where the context requires.

Nothing in this AUP requires BACI to permit activity prohibited by Applicable Law; restricts rights that cannot lawfully be restricted; authorises BACI to disregard its contractual obligations; eliminates a Customer's responsibility for its users; expands BACI's rights in Customer Data beyond the applicable Agreement; or changes the order of precedence established by the applicable Agreement.

Where Applicable Law imposes a mandatory requirement inconsistent with this AUP, the mandatory requirement controls to the extent of the inconsistency.

52. CONTACT

Questions concerning this AUP may be directed to BACI LLC through the applicable BACI contact channel.

Security concerns and suspected abuse may be reported to:

security@bacihq.com

BACI ACCEPTABLE USE POLICY — VERSION 1.0 Effective 10 September 2026

We're listening.