Acceptable Use Policy
Effective date: July 3, 2026 · Last updated: July 3, 2026
1. Purpose and scope
This Acceptable Use Policy (the "Policy") describes prohibited uses of the Brock Service. It supplements and is incorporated into the Terms of Service www.brocktransform.com/terms-of-service. Capitalised terms not defined here have the meaning given in the Terms. If this Policy conflicts with the Terms, the Terms control unless this Policy states otherwise.
This Policy applies to you and to every Authorized User you permit to access the Service. You are responsible for violations by your Authorized Users and by anyone using your account, whether or not authorised.
2. Acceptable use
You may use the Service only for its intended purpose: discovering, analysing, transforming, and exporting data you are authorised to migrate, in accordance with the Terms and applicable law.
3. Prohibited activities
You will not, and will not permit any Authorized User or third party to:
3.1 Security and integrity
- Access or attempt to access any account, organisation, or data that is not yours, or attempt to defeat the Service's tenant-isolation, access controls, or row-level security.
- Probe, scan, or test the vulnerability of the Service, or breach or circumvent any authentication or security measure, except under a security-testing arrangement we have authorised in writing.
- Reverse-engineer, decompile, or attempt to derive the source code, models, or underlying algorithms of the Service, except to the limited extent applicable law permits despite this restriction.
- Introduce malware, or any code intended to disrupt, damage, or gain unauthorised access to the Service or other customers' data.
3.2 Capacity and abuse
- Impose an unreasonable or disproportionate load on the Service, or exceed the volume or rate limits of your subscription tier.
- Use bots, scrapers, or automated means to access the Service other than through interfaces we provide and within documented limits.
- Interfere with any other customer's use of the Service.
3.3 Data and legality
- Connect, upload, or process data you do not have the right and lawful basis to process — including third-party data — or do so in violation of any privacy, data-protection, or other law.
- Use the Service to store, process, or transmit unlawful, infringing, or malicious content.
- Use the Service to falsify financial records, facilitate fraud, money laundering, or tax evasion, or otherwise to disguise the true nature of financial data.
- Connect or upload special-category personal data (such as health, biometric, genetic, or racial or ethnic origin data), sensitive personal information as defined by applicable US law (such as precise geolocation data), or other data the Service is not designed to handle. The Service is intended for business-records migration; financial account information (such as bank account numbers) is within scope but must be processed only with the rights and lawful basis required above.
- Connect, upload, or process data that is subject to specialised regulatory regimes the Service is not designed to support, including: Protected Health Information governed by HIPAA; cardholder data governed by PCI-DSS (such as full payment-card numbers, which should be handled only through our payment processor, not migrated through the Service); data governed by the Gramm-Leach-Bliley Act as a regulated financial institution; and government, defence, or export-controlled data (such as data subject to FedRAMP, CJIS, or ITAR). Brock is not a HIPAA business associate, is not a PCI-DSS service provider for your cardholder data, and does not accept the associated compliance obligations; do not use the Service in a manner that would require it to be.
3.4 AI Features
- Use AI Feature outputs as a substitute for required professional review, or rely on them without the verification the Terms require.
- Attempt to extract, copy, or reconstruct the underlying models or training data behind the AI Features.
3.5 Commercial restrictions
- Resell, sublicense, rent, or operate the Service as a service bureau or time-sharing offering for third parties, except that an Authorized User acting as an implementation consultant may use the Service to perform migrations for that consultant's own end clients, provided the consultant remains responsible under the Terms and this Policy and the consultant is enrolled to the appropriate Consultant plan tier.
- Use the Service to build or train a competing product, or to benchmark it for a competitor.
4. Your data representations
By connecting or uploading Customer Data, you represent that you have all necessary rights, consents, and lawful bases to do so, including for any third-party or end-client data, and that doing so does not violate any law or third-party right.
5. Monitoring
We may, but are not obligated to, monitor use of the Service to protect its security and integrity and to enforce this Policy. We design the Service to minimise our access to the contents of Customer Data; where access is necessary, it is limited to what is required for the stated purpose.
6. Reporting violations
If you become aware of a violation of this Policy, report it to admin@brocktransform.com.
7. Consequences of violation
Violations may result in, at our discretion and proportionate to the violation: a warning; throttling or limiting your access; suspension or termination of your account under the Terms; and, where appropriate, referral to and cooperation with law enforcement or regulators. We may act immediately and without prior notice where a violation poses a security risk to the Service or other customers.
8. Changes to this Policy
We may update this Policy. The current version is always posted at www.brocktransform.com/acceptable-use. Material changes will be notified as described in the Terms; continued use after the effective date constitutes acceptance.