Acceptable Use Policy
Last updated: May 19, 2026
1. Scope
This Exact Match Authorized Use Policy (this "AUP") governs all access to and use of the Services and Output by all Users across all access channels and methods, including web access, APIs, MCP endpoints, integrations, automations, agents, trial access, demo access, sandbox access, freemium access, and free-credit access.
This AUP is incorporated into and forms part of the Agreement between Exact Match Marketing Inc. ("Exact Match") and Customer. By accessing or using the Services or Output, each User agrees to comply with this AUP. Customer is responsible for ensuring that all Users acting under or through Customer's account, credentials, systems, instructions, configuration, or authority comply with this AUP.
This AUP applies to paid and unpaid, production and non-production, human-initiated and machine-initiated, and direct and indirect access or use, regardless of geography. Any access to or use of the Services or Output that is not expressly permitted by the Agreement, including this AUP, is prohibited.
Exact Match may update this AUP from time to time in accordance with the Agreement. Continued access to or use of the Services or Output following the effective date of any update constitutes acceptance of the updated AUP by Customer and all other Users acting under or through Customer.
2. Definitions
Capitalized terms used but not defined in this AUP have the meanings given to them in the Exact Match Terms of Service.
3. Permitted Uses
3.1 Permitted Business Purposes. Subject to the terms of the Agreement, this AUP, and all applicable laws, Users may access and use the Services and Output solely for lawful, legitimate purposes in support of Customer's commercial operations. Permitted uses, subject to applicable law, the Agreement, and this AUP, include the following:
- Prospecting and Sales Development. Identifying, researching, and contacting individuals, business contacts, and organizations for legitimate marketing, sales, business development, partnership, and account-based outreach activities, in each case subject to applicable law, the Agreement, and this AUP.
- Ideal Customer Profile (ICP) Modeling. Defining, refining, scoring, and analyzing ICP criteria, commercially relevant attributes, and similar relevance signals to support the desired go-to-market strategy and prioritization.
- Audience Creation and Segmentation. Building, refining, and exporting audiences, cohorts, segments, and target lists for use in compliant marketing, sales, advertising, and lifecycle programs, subject to Sections 8 through 12 of this AUP.
- Data Enrichment. Enriching the applicable existing records, CRM data, and other lawfully held commercial data with contact, firmographic, demographic, and other attributes made available through the Services.
- Identity Resolution. Resolving, matching, deduplicating, and reconciling identifiers, contact records, and related commercial records to maintain accurate and current reference data within Customer's systems.
- Workflow and System Integration. Integrating the Services and Output into Customer's authorized internal workflows, CRM, marketing automation, sales engagement, data warehouse, analytics, and similar business systems used by Customer Users and Customer Agents in connection with the permitted uses described above.
- Analytics and Reporting. Performing internal analytics, reporting, and measurement on the performance of programs that incorporate the Services or Output, in each case for Customer's own business purposes.
3.2 Conditions on Permitted Uses. All access to and use of the Services and Output, including each of the permitted uses described in Section 3.1, must at all times: (a) comply with this AUP, the Agreement, and all applicable laws, rules, and regulations, including data protection, privacy, marketing, anti-discrimination, consumer protection, export control, and sanctions laws; (b) respect all rights of data subjects, including consumer rights requests, suppression signals, and opt-outs as described in Section 12; (c) be limited to the volumes, seats, credits, environments, and other usage parameters set forth in the applicable Order Form or as otherwise authorized in writing by Exact Match; and (d) be subject to the prohibitions, restrictions, and conditions set forth elsewhere in this AUP, including Sections 6 through 18.
3.3 Commercial Use Only. The Services and Output are intended to support lawful commercial prospecting, marketing, audience development, analytics, and related business purposes. Users must not use the Services or Output for personal, household, stalking, surveillance, harassment, eligibility, sensitive-topic, discriminatory, or otherwise prohibited purposes, except as expressly permitted under the Agreement and consistent with Sections 7 through 12 of this AUP.
4. User Inputs
4.1 Scope of User Inputs. This Section governs all User Inputs submitted to the Services by or on behalf of any User, including User Inputs submitted through the web interface, API, MCP, integrations, Customer Agents, Downstream Agents, or any other access channel.
4.2 Legal Basis and Rights to Submit. Customer represents, warrants, and covenants that, with respect to all User Inputs submitted by or on behalf of Customer, any Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent: (a) Customer has all necessary rights, title, consents, permissions, authorizations, and lawful bases required under applicable law to submit such User Inputs to the Services and to authorize Exact Match to process them as contemplated by the Agreement; (b) the submission and processing of such User Inputs does not and will not violate any applicable law, regulation, contract, privacy policy, notice, or third-party right; and (c) where applicable law requires notice to or consent from any data subject, such notice has been provided and such consent has been obtained prior to submission.
4.3 Ownership. As between Customer and Exact Match, Customer retains all right, title, and interest in and to User Inputs submitted by or on behalf of Customer, subject to the licenses granted under the Agreement and this AUP. Nothing in this Section transfers ownership of User Inputs to Exact Match.
4.4 Accuracy and Quality. Customer is responsible for the accuracy, completeness, lawfulness, and quality of all User Inputs. Exact Match is not obligated to verify, validate, correct, or supplement User Inputs and may rely on User Inputs as submitted in providing the Services and generating Output.
4.5 Prohibited User Inputs. No User may submit, and Customer shall ensure that no Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent submits, any User Input that:
- consists of or contains information regulated by the Fair Credit Reporting Act (15 U.S.C. § 1681 et seq.) or any analogous state or non-U.S. consumer reporting law, or that is intended to be used to make or facilitate FCRA-covered or eligibility decisions;
- consists of or contains protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA), substance use disorder records subject to 42 C.F.R. Part 2, genetic information, biometric identifiers, or other health, medical, or clinical data;
- consists of or contains payment card data subject to PCI DSS, financial account numbers, government-issued identification numbers (other than as expressly permitted by the Agreement), passwords, credentials, or other authentication data;
- consists of or contains information about minors known or reasonably believed to be under the age of eighteen (18), or information collected directly from children under thirteen (13);
- consists of or contains special categories of personal data under the GDPR (Article 9), sensitive personal information under the CCPA/CPRA, or analogous categories under other applicable privacy laws, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, sex life, or sexual orientation;
- is obtained, derived, scraped, or compiled in violation of applicable law, contract, terms of service, robots exclusion protocols, or third-party rights;
- contains malware, malicious code, or content designed to disrupt, damage, or gain unauthorized access to any system; or
- is otherwise unlawful, infringing, defamatory, harassing, or prohibited by the Agreement, this AUP, or applicable law.
4.6 Suppression and Opt-Out Inputs. Customer may submit suppression lists, opt-out lists, do-not-contact lists, and similar User Inputs solely for the purpose of honoring consumer rights, exclusion, and suppression obligations as contemplated by Section 12. Such User Inputs may not be used by Customer or any other User to target, profile, enrich, or re-engage the listed individuals.
4.7 Retention and Deletion. Exact Match will retain and delete User Inputs in accordance with the Agreement, the applicable data processing addendum (if any), and applicable law. Customer is responsible for maintaining its own records of User Inputs and for issuing deletion, correction, or access instructions as required to comply with consumer rights requests and applicable law.
4.8 Indemnity Acknowledgment. Customer acknowledges that User Inputs submitted in violation of this Section may give rise to indemnification obligations under the Agreement, in addition to Exact Match's enforcement rights under Section 18.
5. Customer Responsibility
5.1 Customer is responsible for all access to and use of the Services and Output under Customer's account, credentials, API keys, systems, instructions, configuration, authority, downstream offering, or commercial relationship, including all access and use by Customer Users, Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents. Customer is responsible for all User Inputs submitted by or on behalf of Customer or through Customer's account, systems, integrations, Customer Agents, downstream offerings, or authority. Any act or omission of a Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent will be deemed an act or omission of Customer.
5.2 Without limiting Section 5.1, Customer shall: (a) maintain the confidentiality and security of all account credentials, API keys, tokens, and other authentication materials issued to or used by Customer; (b) promptly disable or revoke access for any Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent that violates, or that Customer reasonably believes may violate, this AUP; and (c) maintain reasonable internal policies, controls, training, oversight, and monitoring to support compliance with this AUP across all access channels.
5.3 Customer shall promptly notify Exact Match in writing upon becoming aware of any actual or suspected (a) breach of this AUP by any User, (b) unauthorized access to or use of the Services, Output, or Customer's account, credentials, or API keys, or (c) loss, compromise, or misuse of any Output. Customer shall cooperate with Exact Match in investigating and remediating any such matter.
5.4 Customer's obligations under this Section 5 are in addition to, and do not limit, any other obligation of Customer under the Agreement. Exact Match's enforcement rights under Section 18 (Monitoring and Enforcement) may be exercised in accordance with the Agreement and this AUP.
6. General Prohibited Uses
6.1 General Prohibition. No User may access or use the Services, User Inputs, or Output for any purpose that is unlawful, deceptive, abusive, infringing, or otherwise inconsistent with the Agreement. This Section 6 sets out baseline prohibited uses; the more specific restrictions in Sections 7 through 17 apply in addition.
6.2 Unlawful Activity. Using the Services or Output in violation of any applicable federal, state, local, or foreign law, regulation, rule, order, or industry self-regulatory standard, or in furtherance of any unlawful, fraudulent, deceptive, or tortious activity.
6.3 Fraud and Misrepresentation. Using the Services or Output to engage in or facilitate fraud, identity theft, account takeover, phishing, smishing, vishing, pretexting, social engineering, impersonation, false or misleading statements, deceptive business practices, or any scheme intended to deceive or defraud any person or entity, including Exact Match.
6.4 Harassment, Threats, and Harm. Using the Services or Output to harass, stalk, threaten, intimidate, dox, defame, extort, blackmail, surveil, or otherwise harm any individual or group, or to facilitate violence, self-harm, exploitation, trafficking, or abuse.
6.5 Spam and Unsolicited Communications. Using the Services or Output to send, facilitate, or support unsolicited, bulk, deceptive, or unlawful commercial communications, including communications that violate the CAN-SPAM Act, TCPA, CASL, GDPR, ePrivacy Directive, or any other applicable communications, marketing, data privacy or consent law, or that violate Section 11 (Marketing, Outreach, and Communications) or Section 12 (Consumer Rights, Suppression, and Do-Not-Serve Controls) of this AUP.
6.6 Scraping and Unauthorized Data Extraction. Scraping, crawling, harvesting, spidering, mirroring, indexing, caching, bulk-downloading, screen-scraping, or otherwise extracting or collecting data from the Services or Output except through documented and authorized interfaces and only to the extent expressly authorized in the Agreement or documentation.
6.7 Infringement of Intellectual Property and Other Rights. Using the Services, User Inputs, or Output to infringe, misappropriate, or violate any patent, copyright, trademark, trade secret, publicity, privacy, contractual, moral, or other proprietary or legal right of any person or entity, or to remove, obscure, or alter any proprietary notices or attributions associated with the Services or Output.
6.8 Privacy Violations. Using the Services or Output to violate any individual's privacy rights, to combine Output with other data in a manner not permitted by applicable law, to re-identify de-identified or pseudonymized data except as expressly permitted, or to process personal data without a valid legal basis or required notice or consent.
6.9 Malware and Malicious Code. Uploading, transmitting, distributing, or introducing into the Services or Output any malicious, harmful, or disabling code, file, or program.
6.10 Security Circumvention. Circumventing, disabling, or interfering with any security, integrity, access-control, monitoring, usage-measurement, or billing feature of the Services, or attempting to gain unauthorized access to any account, system, network, data, or portion of the Services.
6.11 Service Interference. Interfering with, disrupting, degrading, overloading, probing, testing without authorization, or impairing the Services, related infrastructure, or any other User's access to or use of the Services.
6.12 Account and Credential Misuse. Sharing, selling, transferring, sublicensing, or otherwise making available authentication materials to any unauthorized person or system; creating accounts by automated means; creating accounts to evade limits, suspensions, terminations, or pricing; or using another User's account or credentials without authorization.
6.13 Misleading Attribution and Output Manipulation. Misrepresenting the source, accuracy, completeness, or provenance of Output; falsely attributing Output to a person or entity; or modifying Output in a manner intended to deceive recipients or regulators.
6.14 Prohibited Decisions and Sensitive Uses. Using the Services or Output for any purpose prohibited by Section 7 (FCRA, Eligibility, and Regulated Decisions), Section 8 (Anti-Discrimination), Section 9 (Sensitive Data and Sensitive Topics), Section 10 (Location Data and Sensitive Locations), or Section 17 (No Competitive Use or Unauthorized Model Training).
6.15 Weapons, Critical Infrastructure, and Catastrophic Harm. Using the Services or Output in connection with the development, design, manufacture, or deployment of weapons (including chemical, biological, radiological, nuclear, or cyber weapons), the operation of safety-critical systems without appropriate human oversight, or any activity reasonably likely to result in death, serious bodily injury, or significant damage to critical infrastructure.
6.16 Circumvention of This AUP. Engaging, encouraging, soliciting, or enabling any third party (including any Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent) to engage in any conduct that, if undertaken by Customer, would violate this AUP, or otherwise structuring activity to evade or frustrate the application of this AUP.
6.17 The categories of prohibited use set forth in this Section 6 are illustrative and non-exhaustive. Exact Match reserves the right to determine, in its reasonable discretion, whether any particular access to or use of the Services, User Inputs, or Output violates this AUP, and to take any action permitted under Section 18 (Monitoring and Enforcement) and the Agreement.
7. FCRA, Eligibility, and Regulated Decisions
7.1 No Use for FCRA-Covered or Eligibility Decisions. The Services and Output are intended solely for lawful commercial prospecting, marketing, audience development, identity resolution, enrichment, analytics, and related commercial purposes as described in the Agreement. No User may access, use, request, query, retrieve, export, transmit, integrate, or otherwise rely upon the Services or Output, in whole or in part, as a factor in establishing any consumer's eligibility for, or to make, inform, recommend, evaluate, support, or deny any decision regarding: (a) credit or the extension of credit; (b) employment, including hiring, retention, promotion, reassignment, compensation, background screening, gig or contractor engagement, or termination; (c) insurance underwriting, eligibility, pricing, or claims; (d) housing, tenancy, rental, mortgage, or real estate eligibility; (e) healthcare eligibility, treatment, coverage, or benefits; (f) education, including admissions, financial aid, scholarships, or academic standing; (g) government benefits, licensing, public assistance, or entitlements; (h) immigration or citizenship status; or (i) any other purpose that constitutes a "permissible purpose" under the Fair Credit Reporting Act, 15 U.S.C. § 1681 et seq. ("FCRA"), or that is regulated as an eligibility determination, adverse action, or consumer report under any analogous federal, state, provincial, or foreign law (collectively, "Regulated Decisions").
7.2 Not a Consumer Reporting Agency. Exact Match is not a "consumer reporting agency" as defined in the FCRA, and the Services and Output are not "consumer reports," "investigative consumer reports," or "consumer files" within the meaning of the FCRA or any analogous law. The Services and Output have not been collected, assembled, evaluated, or maintained for the purpose of furnishing consumer reports, and Exact Match makes no representations or warranties regarding the accuracy, completeness, currency, or suitability of the Services or Output for any Regulated Decision. Users may not represent, market, package, label, or otherwise hold out the Services or Output as a consumer report, background check, screening tool, eligibility tool, or FCRA-compliant service.
7.3 Prohibited Downstream and Derivative Uses. The prohibitions in this Section 7 apply to all direct, indirect, derivative, aggregated, enriched, modeled, scored, segmented, and inferred uses of the Services or Output. Without limiting the foregoing, no User may: (a) combine, append, enrich, or merge the Services or Output with other data for the purpose of producing a consumer report or making a Regulated Decision; (b) use the Services or Output to train, fine-tune, validate, score, rank, or operate any model, algorithm, or system that is used, designed, or marketed for Regulated Decisions; (c) provide the Services or Output to any Downstream Customer, Downstream User, or Downstream Agent that the Customer knows, or reasonably should know, will use them for a Regulated Decision; or (d) use the Services or Output to identify, profile, or differentiate consumers based on their likely eligibility for any product, benefit, or opportunity that is the subject of a Regulated Decision.
7.4 Customer Controls and Flow-Down. Customer shall implement reasonable contractual, technical, and operational controls to prevent any Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent from using the Services or Output for any Regulated Decision, including by incorporating the prohibitions of this Section 7 into Customer's agreements with Downstream Customers and into the configuration of any Customer Agent or Downstream Agent. Any act or omission in violation of this Section 7 by a Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent will be deemed an act or omission of Customer.
7.5 No Reliance; Allocation of Risk. Each User acknowledges and agrees that (a) the Services and Output are provided for permissible commercial purposes only and not for Regulated Decisions; (b) any use of the Services or Output for a Regulated Decision is a material breach of the Agreement and this AUP; and (c) Exact Match disclaims all liability arising from or related to any use of the Services or Output for any Regulated Decision, and the User engaging in or enabling such use shall be solely responsible for all resulting claims, damages, penalties, and liabilities.
8. Anti-Discrimination
8.1 Prohibition. No User may use, and Customer shall not permit any Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent to use, the Services, Output, or User Inputs to discriminate against, or to facilitate, enable, automate, or conceal discrimination against, any individual or group on the basis of any characteristic protected under applicable federal, state, provincial, local, or foreign law, including race, color, ethnicity, national origin, ancestry, citizenship or immigration status, religion or creed, sex, gender, gender identity or expression, sexual orientation, marital or familial status, pregnancy, age, disability, genetic information, military or veteran status, source of income, or any other characteristic protected by applicable law (collectively, "Protected Characteristics").
8.2 Prohibited Activities. Without limiting Section 8.1, no User may use the Services, Output, or User Inputs to:
- construct, define, score, rank, segment, include, or exclude audiences, cohorts, lists, or Ideal Customer Profile ("ICP") models on the basis of, or as a proxy for, any Protected Characteristic;
- target, deliver, suppress, or withhold advertising, marketing, employment, housing, credit, insurance, education, healthcare, financial services, public accommodations, government benefits, or other opportunities or communications in a manner that discriminates on the basis of any Protected Characteristic;
- infer, derive, append, or enrich attributes that classify individuals by Protected Characteristics, or use the Services or Output to reverse-engineer, predict, or assign such classifications;
- use the Services or Output as inputs to, or in connection with, any algorithm, model, scoring system, or automated decision-making process that produces discriminatory outcomes prohibited by applicable law; or
- circumvent, defeat, or attempt to circumvent or defeat any anti-discrimination controls, filters, suppression lists, or policy enforcement mechanisms implemented by Exact Match or required by applicable law.
8.3 Proxies and Indirect Discrimination. The prohibitions in this Section 8 apply equally to the use of facially neutral attributes, signals, geographic indicators, behavioral data, affinities, interests, language preferences, or other variables that operate as proxies for, or that produce a substantially disparate impact on, individuals or groups defined by Protected Characteristics, except where such use is expressly permitted by applicable law and conducted in accordance with the Agreement.
8.4 Advertising and Housing, Employment, and Credit Opportunities. Customer acknowledges that the Services are not designed, authorized, or intended for use in connection with advertising, targeting, exclusion, audience construction, eligibility, or decisioning relating to housing, employment, credit, insurance, or other opportunities subject to specialized anti-discrimination regimes. Any such use is prohibited unless and until expressly authorized in writing by Exact Match and, where applicable, consistent with Section 7 (FCRA, Eligibility, and Regulated Decisions).
8.5 Customer Compliance Obligations. Customer shall implement and maintain reasonable policies, controls, training, and oversight to ensure that all access to and use of the Services and Output by Customer Users, Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents complies with this Section 8 and with all applicable anti-discrimination, civil rights, fair lending, fair housing, equal employment, and consumer protection laws. Customer shall promptly investigate and remediate any suspected violation of this Section 8 and shall notify Exact Match in accordance with Section 19.
8.6 No Authorization. Nothing in the Agreement, this AUP, or any documentation, marketing material, or communication from Exact Match shall be construed as authorizing, endorsing, or warranting the use of the Services or Output for any purpose prohibited by this Section 8. Violation of this Section 8 constitutes a material breach of the Agreement and may result in immediate suspension or termination of access in accordance with Section 18.
9. Sensitive Data and Sensitive Topics
9.1 Restrictions on Sensitive Categories. The Services and Output are intended for lawful commercial prospecting, marketing, identity resolution, enrichment, and audience-related activities, and are not designed, validated, or authorized for use in connection with sensitive personal data categories or sensitive topics. No User may use, configure, structure, query, enrich, infer, derive, segment, label, tag, score, model, target, exclude, or construct audiences or Output based on, or in a manner that reveals or is reasonably likely to reveal, any of the following categories of information about any natural person:
- physical or mental health, medical conditions, diagnoses, treatments, prescriptions, disabilities, pregnancy, fertility, reproductive health, or use of medical or therapeutic services;
- sex life, sexual behavior, sexual orientation, gender identity, gender expression, or transgender or non-binary status;
- race, ethnicity, color, national origin, ancestry, tribal affiliation, or indigenous status;
- religion, religious beliefs, religious practices, or affiliation with any faith, congregation, or place of worship;
- political opinions, political party affiliation, political activity, voting behavior, or membership in any political organization or campaign;
- trade union or labor organization membership, activity, or participation;
- immigration or citizenship status, refugee or asylum status, visa status, or country of birth used as a proxy for any of the foregoing;
- criminal history, arrests, charges, convictions, incarceration, parole, probation, or involvement with the criminal or juvenile justice systems;
- financial distress, debt collection status, bankruptcy, credit standing, eligibility for public assistance, or receipt of government benefits;
- biometric or genetic data, including fingerprints, facial geometry, voiceprints, retinal scans, DNA, or other unique biological identifiers;
- precise geolocation data, as further restricted under Section 10 (Location Data and Sensitive Locations); and
- information concerning minors or children under the age of eighteen (18), or audiences or segments knowingly constructed to include such individuals.
9.2 Prohibition on Inference and Proxy Use. Users may not use the Services or Output to infer, derive, predict, or approximate any of the categories described in Section 9.1 through proxy variables, combinations of attributes, lookalike modeling, ICP modeling, audience expansion, enrichment, or any other technique. The prohibition in this Section 9 applies regardless of whether the underlying information is characterized as observed, inferred, modeled, probabilistic, or publicly available.
9.3 Sensitive Topics in User Inputs. No User may submit User Input to the Services that contains, references, or is intended to elicit Output relating to the categories described in Section 9.1, including by uploading lists, identifiers, prompts, instructions, configuration data, or files that are organized around, labeled by, or selected on the basis of any such category. Customer is responsible for ensuring that all User Inputs submitted by or on behalf of Customer, Customer Users, Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents comply with this Section 9.
9.4 Sensitive Use Cases. Users may not use the Services or Output to identify, profile, target, surveil, exclude, harass, intimidate, or take adverse action against any individual or group on the basis of any category described in Section 9.1, including in connection with advocacy, journalism, investigations, opposition research, enforcement activity, or any campaign, communication, or decision directed at such individuals or groups.
9.5 No Authorization by Consent. The restrictions in this Section 9 apply regardless of whether the affected individuals have provided notice or consent to the processing of sensitive categories of information. Consent does not authorize use of the Services or Output for any purpose otherwise prohibited under this AUP.
9.6 Interaction with Other Sections. The restrictions in this Section 9 are in addition to, and do not limit, the restrictions set forth in Sections 7 (FCRA, Eligibility, and Regulated Decisions), 8 (Anti-Discrimination), 10 (Location Data and Sensitive Locations), and 11 (Marketing, Outreach, and Communications). Where multiple provisions apply, the most restrictive provision controls. Exact Match may identify additional sensitive categories or topics from time to time by updating this AUP.
10. Location Data and Sensitive Locations
10.1 General Restriction on Location-Based Use. Users may use location-related attributes available through the Services (such as business address, headquarters location, office location, or jurisdiction of incorporation) solely for lawful purposes consistent with the Agreement, this AUP, and applicable law. Users shall not use the Services or Output to track, surveil, or monitor the real-time or historical physical movements, whereabouts, or presence of any individual natural person.
10.2 Prohibition on Sensitive-Location Targeting and Inference. No User, Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent may use the Services or Output to identify, infer, target, segment, score, exclude, profile, or construct audiences or cohorts based on an individual's actual, suspected, or inferred visit to, presence at, proximity to, residence near, or association with any Sensitive Location. "Sensitive Location" includes, without limitation:
- places of worship, religious institutions, and religious gatherings;
- medical, mental-health, reproductive-health, substance-use, or addiction-treatment facilities, clinics, hospitals, or pharmacies;
- domestic-violence shelters, homeless shelters, refugee or immigrant assistance centers, and other facilities serving vulnerable populations;
- schools, child-care facilities, playgrounds, and other locations primarily serving minors;
- correctional facilities, halfway houses, parole or probation offices, and immigration detention or enforcement facilities;
- union halls, labor-organizing locations, protests, demonstrations, marches, rallies, and other sites of political or civic expression;
- LGBTQ+ community centers, gender-affirming care providers, and similar identity-based facilities;
- military installations, classified facilities, and other restricted government sites; and
- any other location the use of which would reveal sensitive personal characteristics, beliefs, conditions, or activities of an individual.
10.3 Prohibition on Geofencing and Movement-Based Audiences. Users shall not use the Services or Output, alone or in combination with other data, to (a) construct geofences, mobility patterns, visit histories, dwell-time analyses, or co-location inferences relating to any natural person; (b) build audiences, segments, or lookalike models derived from visits to, or presence at, any Sensitive Location; or (c) re-identify, append to, or enrich any dataset of mobile-device identifiers, GPS coordinates, Wi-Fi or Bluetooth signals, or similar location signals associated with natural persons.
10.4 No Use Against Vulnerable Populations. Users shall not use location attributes to identify, target, exclude, or disadvantage individuals based on their location at or association with facilities serving vulnerable populations, including those described in Section 10.2. Use of location data in a manner that would facilitate stalking, harassment, intimidation, doxxing, or physical harm to any individual is strictly prohibited.
10.5 Compliance with Law. All location-based use of the Services and Output must comply with applicable privacy, consumer-protection, civil-rights, and location-data laws and regulations, including state laws restricting the sale or use of precise geolocation data and laws restricting use of location data near sensitive locations. Customer is responsible for ensuring that any User Inputs containing location data have been collected, used, and submitted in compliance with all applicable legal requirements, including any required notices and consents.
10.6 Downstream Flow-Down. Customer shall impose the restrictions set forth in this Section 10 on all Customer Users, Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents, and shall be responsible for any violation of this Section 10 by any of the foregoing in accordance with Section 5.
11. Marketing, Outreach, and Communications
11.1 General Compliance. Customer and all other Users shall ensure that any marketing, advertising, sales outreach, fundraising, or other communications conducted using the Services or Output comply with all applicable communications, marketing, telemarketing, privacy, consumer-protection, anti-spam, do-not-call, and platform rules (collectively, the "Communications Laws").
11.2 Consent and Legal Basis. Prior to initiating any marketing, outreach, or other communication using the Services or Output, the applicable User shall obtain, document, and maintain all consents, permissions, legal bases, and authorizations required under the Communications Laws for the relevant channel, jurisdiction, and recipient. Customer is responsible for maintaining records sufficient to demonstrate compliance.
11.3 Channel-Specific Requirements. Without limiting Section 11.1, Users shall:
- Email. Comply with CAN-SPAM, CASL, GDPR/ePrivacy, and analogous laws, including by ensuring accurate header, sender, and routing information; using non-deceptive subject lines; clearly identifying messages as commercial where required; including a valid physical postal address; providing a functional, conspicuous, and free unsubscribe mechanism; honoring opt-out requests within the timeframes required by law; and not sending to addresses harvested through prohibited means.
- Telephone and SMS. Comply with the TCPA, TSR, state mini-TCPA and telemarketing statutes, and applicable DNC requirements, including by obtaining prior express consent or prior express written consent where required; scrubbing against the Federal DNC registry, applicable state DNC registries, internal do-not-call lists, and reassigned-number databases; observing calling-time restrictions; providing required identification and disclosures; and honoring opt-out and STOP requests immediately.
- International Communications. Comply with GDPR, the ePrivacy Directive and national implementations, UK GDPR and PECR, CASL, and other non-U.S. Communications Laws, including consent, transparency, sender identification, unsubscribe, and record-keeping requirements applicable to electronic marketing.
- Other Channels. Comply with all applicable laws and platform terms governing direct mail, fax (including the Junk Fax Prevention Act), voicemail drops, ringless voicemail, push notifications, in-product messaging, social media outreach, and connected-TV or addressable advertising.
11.4 Disclosures and Identification. All marketing and outreach communications generated, enabled, or sent using the Services or Output shall accurately identify the sender, the commercial nature of the communication where required, and any other disclosures required by applicable Communications Laws, including disclosures of automated systems or artificial or prerecorded voices where mandated. No User shall use the Services or Output to send communications that misrepresent the identity of the sender, the source of any data, the purpose of the communication, or any material fact, or that impersonate Exact Match, any Customer, any Downstream Customer, or any third party.
11.5 No Reliance on Output as Consent. Output, including contact records, audiences, segments, and enrichments, does not itself constitute consent, opt-in, an established business relationship, or any other legal basis for contact. The presence of an individual or business contact in any Output does not authorize Users to communicate with that individual or contact, and Users remain solely responsible for determining and documenting the lawful basis for each communication.
11.6 Suppression and Opt-Out Integration. Users shall apply all applicable suppression, unsubscribe, do-not-contact, deletion, and opt-out signals before using Output for marketing or outreach. The detailed requirements set forth in Section 12 (Consumer Rights, Suppression, and Do-Not-Serve Controls) apply in addition to this Section 11.
11.7 Prohibited Outreach. Users shall not use the Services or Output to send or facilitate: (a) unsolicited bulk or commercial communications in violation of any Communications Law; (b) communications that are deceptive, fraudulent, harassing, threatening, defamatory, obscene, or otherwise unlawful; (c) communications promoting illegal goods or services, illegal gambling, illegal financial schemes, illegal pharmaceuticals, or other unlawful offerings; (d) communications targeting minors in violation of applicable law; (e) communications that exploit, induce, or facilitate any prohibited use under Sections 6 through 10 of this AUP; or (f) communications using spoofed, falsified, or misappropriated sender identifiers, originating numbers, or routing information.
11.8 Vendor and Platform Terms. Users shall comply with the terms, acceptable use policies, and sender-reputation requirements of any email service provider, telephony provider, SMS aggregator, marketing automation platform, advertising platform, CRM, or other third-party system used in connection with the Services or Output. Customer is responsible for ensuring that any Customer Agent, Downstream Customer, Downstream User, or Downstream Agent that originates, schedules, or transmits communications using the Services or Output adheres to the requirements of this Section 11.
11.9 Records and Cooperation. Users shall retain records of consents, opt-outs, suppression actions, campaign content, recipient lists, and channel-level compliance documentation for the periods required by applicable Communications Laws. Upon Exact Match's reasonable request in connection with a suspected violation of this AUP, Customer shall provide information sufficient to demonstrate compliance with this Section 11.
12. Consumer Rights, Suppression, and Do-Not-Serve Controls
12.1 Compliance with Consumer Rights Requests. Each User must comply with all applicable consumer privacy and data protection laws governing the rights of data subjects, including rights to access, correct, delete, restrict, port, opt out of sale or sharing, opt out of targeted advertising, opt out of profiling, and limit the use or disclosure of personal information. Customer is responsible for ensuring that all User Inputs submitted to the Services, and all uses of Output, comply with such rights as exercised by the individuals to whom the underlying personal information pertains.
12.2 Suppression Lists and Do-Not-Contact Signals. Users must maintain and honor, on an ongoing basis, all applicable suppression lists, do-not-contact lists, do-not-email lists, do-not-call lists (including the National Do Not Call Registry and any applicable state or jurisdictional equivalents), do-not-mail lists, do-not-sell-or-share lists, do-not-track signals, Global Privacy Control (GPC) signals, and any other opt-out, unsubscribe, or revocation signals received from or applicable to a data subject. Users must scrub Output against such suppression lists prior to any outreach, activation, enrichment, audience construction, or other use of Output, and must continue to scrub on a recurring basis to capture newly received opt-outs.
12.3 Deletion and Revocation Signals. Where a data subject exercises a right of deletion, withdrawal of consent, or revocation of a prior authorization, the User must promptly cease using the corresponding personal information for any purpose not permitted by law, suppress the individual from all Output, audiences, cohorts, segments, models, and other materials derived in whole or in part from the Services, and propagate the suppression to all integrated systems, Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents.
12.4 Prohibition on Re-Targeting. No User may use the Services or Output to re-identify, re-acquire, re-enrich, re-append, re-target, or otherwise re-engage any individual who has previously opted out, unsubscribed, requested deletion, requested suppression, or otherwise exercised a do-not-serve, do-not-contact, do-not-sell/share, or similar right with respect to that User, Customer, Downstream Customer, or any related campaign, brand, or affiliate. Users may not use the Services to circumvent, defeat, or work around a prior opt-out, including by re-acquiring identifiers through alternative match keys, identity resolution, or enrichment.
12.5 Operational Controls. Customer must implement and maintain reasonable administrative, technical, and organizational controls to (a) intake, log, and timely action consumer rights requests and suppression signals; (b) propagate suppression instructions across all systems and integrations through which the Services or Output are used, including Customer Agents, Downstream Customers, Downstream Users, and Downstream Agents; (c) prevent the re-introduction of suppressed individuals into Output, audiences, or outreach workflows; and (d) demonstrate compliance with this Section 12 upon Exact Match's reasonable request.
12.6 Flow-Down to Downstream Recipients. Customer must contractually require, and operationally enable, each Downstream Customer, Downstream User, and Downstream Agent to honor the obligations set forth in this Section 12 with respect to any Output or derivative thereof made available through Customer's product, service, platform, workflow, agent, application, integration, campaign, or other offering. Customer remains responsible under Section 5 for all acts and omissions of such Downstream Customers, Downstream Users, and Downstream Agents in connection with consumer rights, suppression, and do-not-serve controls.
12.7 Exact Match Suppression Instructions. Exact Match may, in its discretion, transmit suppression, deletion, or do-not-serve instructions to Users with respect to specific identifiers or individuals, including in response to consumer rights requests received by Exact Match. Users must implement such instructions promptly and in any event within the time periods required by applicable law, and must confirm implementation to Exact Match upon request.
12.8 No Interference with Consumer Rights. No User may use the Services or Output to interfere with, frustrate, or discourage the exercise of any consumer right, including by designing dark patterns, obscuring opt-out mechanisms, conditioning services on waiver of rights where prohibited by law, or charging unlawful fees for the exercise of rights.
13. API, MCP, Automation, and Agents
13.1 This Section 13 governs all programmatic, automated, and agentic access to the Services and Output, including access via application programming interfaces ("APIs"), Model Context Protocol ("MCP") endpoints, software development kits, integrations, scripts, workflows, bots, Customer Agents, and Downstream Agents. Programmatic access is a privilege extended subject to this AUP and the remainder of the Agreement, and may be conditioned, throttled, revoked, or terminated by Exact Match in its discretion.
13.2 Attribution and Identification. Each API or MCP request must accurately identify the originating Customer account and, where applicable, the Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent on whose behalf the request is made. Users shall not spoof, omit, or misrepresent identifying headers, user-agent strings, request metadata, or agent identifiers, and shall not route traffic through third parties for the purpose of obscuring the origin of requests.
13.3 Rate Limits and Quotas. Users shall comply with all rate limits, concurrency limits, query volume caps, export caps, and other quotas published by Exact Match or set forth in the applicable Order Form. Users shall not circumvent those limits, including through account, credential, IP address, or proxy rotation, parallelized requests, or excessive, repetitive, or wasteful agentic queries.
13.4 Permitted Automation. Customer Agents and Downstream Agents may access the Services solely for purposes permitted under Section 3 (Permitted Uses) and otherwise consistent with this AUP. Customer shall configure and supervise Customer Agents so they do not exceed their authorized scope, bypass service controls, take material consumer-facing actions without required human oversight, or operate in a manner that violates Sections 7 through 12, 16, or 17.
13.5 Agent Oversight and Human Accountability. Customer shall implement reasonable governance, oversight, and control mechanisms over all Customer Agents and Downstream Agents that access the Services or Output, including (a) clearly scoped instructions, tool permissions, and operating boundaries, (b) human-in-the-loop or human-on-the-loop review for material, irreversible, or consumer-facing actions, (c) the ability to pause, terminate, or revoke any agent that is malfunctioning, exceeding scope, or operating in violation of the Agreement, and (d) periodic review of agent behavior, prompts, tool calls, and Output usage.
13.6 Prompt Injection and Adversarial Inputs. Customer acknowledges that Customer Agents and Downstream Agents may be exposed to untrusted content, instructions, or data that could attempt to manipulate agent behavior ("prompt injection"). Customer shall implement reasonable safeguards against prompt injection and adversarial inputs and shall not configure or permit any Customer Agent or Downstream Agent to follow third-party instructions that would cause a violation of this AUP.
13.7 Logging and Records. Customer shall maintain, for a period of not less than twelve (12) months (or such longer period required by applicable law), logs sufficient to identify requests submitted through Customer's account, credentials, Customer Agents, or Downstream Agents, the associated User or agent, the User Inputs submitted, and the disposition of Output, including downstream activations and transfers. Customer shall make such logs available to Exact Match promptly upon reasonable request in connection with an investigation under Section 18.
13.8 Prohibited Agentic Behavior. Users shall not, and shall not permit any Customer Agent to, (a) self-replicate, self-deploy, or spawn additional agents or accounts without express authorization, (b) attempt to acquire, escalate, or persist credentials, sessions, or privileges beyond those expressly granted, (c) chain Output across accounts or tenants in a manner designed to evade entitlements or rate limits, (d) use the Services to autonomously transact, contract, or commit Customer or any third party in a manner inconsistent with the Agreement, or (e) use Output to autonomously train, fine-tune, evaluate, or improve any AI or machine-learning model except as expressly permitted under Section 17.
13.9 Integrations and MCP Clients. Any MCP client, integration, or third-party tool used to access the Services must be configured to comply with this AUP, preserve attribution and authentication metadata, not introduce unauthorized Users, and not expose Output to unauthorized parties or systems. Customer is responsible for all MCP clients and integrations operating under Customer's account, credentials, or authority.
13.10 Suspension of Programmatic Access. Without limiting Section 18, Exact Match may, at any time and without prior notice, throttle, suspend, restrict, or revoke API, MCP, or other programmatic access where Exact Match reasonably believes that an agent, integration, or other automated system is operating in violation of this AUP, threatens the Services, or poses risk to Exact Match, its other customers, or consumers.
14. Agencies, Resellers, and Downstream Use
14.1 Authorized Downstream Use. Any access to or use of the Services or Output by Downstream Customers, Downstream Users, or Downstream Agents through Customer's product, service, platform, workflow, agent, application, integration, campaign, or other offering remains subject to this AUP.
14.2 Downstream Compliance. Customer shall not permit any Downstream Customer, Downstream User, or Downstream Agent to access or use the Services or Output in a manner that violates this AUP or the Agreement.
14.3 Customer Responsibility for Unauthorized Third-Party Use. Customer shall promptly notify Exact Match of any actual or suspected unauthorized third-party access to or use of the Services or Output and shall cooperate with Exact Match in investigating and remediating the matter. Customer remains responsible for all access and use under Customer's account, credentials, systems, or authority in accordance with Section 5.
14.4 Suspension of Third-Party Access. Exact Match may restrict or suspend any third-party access to the Services or Output in accordance with Section 18 and the Agreement.
15. Trial, Demo, and Freemium Access
15.1 Application. This Section 15 applies to all Trial Access and to all Users who access or use the Services or Output through Trial Access. The restrictions in this Section 15 apply in addition to, and not in lieu of, all other provisions of this AUP and the Agreement.
15.2 Permitted Evaluation Purposes. Users may access and use the Services and Output through Trial Access solely for the internal, good-faith purpose of evaluating the Services for potential procurement by Customer. Any use of the Services or Output through Trial Access outside of internal evaluation, including for live commercial, production, marketing, outreach, sales activation, monetization, advertising, audience activation, enrichment of production records, downstream delivery, or any revenue-generating activity, is prohibited unless and until Customer has entered into a paid Order Form expressly authorizing such use.
15.3 Prohibited Production Use. Without limiting Section 15.2, no User may use Trial Access to: (a) deploy, embed, or integrate the Services or Output into any production system, customer-facing product, live workflow, marketing campaign, outbound communication, or commercial offering; (b) use the Services or Output to contact, target, enrich, score, segment, or otherwise process records of actual prospects, customers, or other data subjects for any purpose other than bona fide evaluation; or (c) rely on the Services or Output as a system of record or for any business-critical decision.
15.4 No Export, Retention, or Redistribution. No User may export, download, copy, transmit, sync, push, or otherwise extract Output through Trial Access except to the limited extent reasonably necessary to evaluate the Services. Users may not retain Output following the conclusion, expiration, or termination of Trial Access, and shall promptly delete all such Output upon Exact Match's request or upon expiration of the applicable access. No User may sell, license, sublicense, share, publish, disclose, or otherwise make available Output obtained through Trial Access to any Downstream Customer, Downstream User, Downstream Agent, or other third party.
15.5 No Account Multiplication or Circumvention. No User shall create, register, operate, or maintain multiple accounts, identities, email domains, payment instruments, or credentials, or use proxies, virtual machines, disposable email addresses, or other means, in order to obtain Trial Access in excess of what Exact Match has expressly authorized, or to circumvent any usage limits, rate limits, credit caps, evaluation periods, suppression rules, or other restrictions applicable to unpaid or limited access. Each Customer is limited to a single, good-faith trial or evaluation instance per organization unless otherwise expressly authorized in writing by Exact Match.
15.6 Limits and Throttling. Exact Match may impose, modify, or enforce at any time and in its sole discretion limits on Trial Access, including limits on query volume, record volume, export volume, API and MCP call rates, concurrent sessions, feature availability, data scope, retention periods, and duration of access. Users shall not attempt to exceed, evade, or circumvent any such limits.
15.7 No Agent or Automated Trial Use. Unless expressly authorized in writing by Exact Match, no User may access or use Trial Access through Customer Agents, Downstream Agents, or other programmatic, automated, or agentic means, or connect Trial Access to any API client, MCP client, automation, workflow, or integration that operates on production data or in a production environment.
15.8 No Competitive Evaluation. No User may access or use Trial Access for any purpose prohibited by Section 17 (No Competitive Use or Unauthorized Model Training), including benchmarking, competitive analysis, reverse engineering, model training, model evaluation, dataset construction, or development of a competing or substitute product or service.
15.9 Customer Responsibility for Trial Access. Customer is responsible for all access to and use of the Services and Output through Trial Access under Customer's account, credentials, systems, instructions, configuration, authority, downstream offering, or commercial relationship. Any breach of this Section 15 by a User associated with Customer will be deemed a breach by Customer.
16. Security, Circumvention, and Service Integrity
16.1 General Obligation. Each User must access and use the Services and Output in a manner that preserves the security, integrity, availability, performance, and proper functioning of the Services. Customer is responsible for maintaining the confidentiality and security of all credentials, API keys, tokens, secrets, certificates, session identifiers, and other authentication materials issued to or used by Customer, Customer Users, and Customer Agents, and for all activity occurring under such credentials.
16.2 Prohibited Conduct. Without limiting Section 6 (General Prohibited Uses), no User may, and Customer shall not permit any Customer User, Customer Agent, Downstream Customer, Downstream User, Downstream Agent, or other person or system to, engage in any of the following security, circumvention, or service-integrity conduct:
- circumvent, disable, bypass, defeat, or attempt to circumvent, disable, bypass, or defeat any authentication, access control, entitlement, license, rate limit, quota, throttle, query cap, paywall, watermark, audit log, security mechanism, technical protection measure, or usage restriction of the Services or Output;
- share, transfer, sell, sublicense, pool, rotate, multiplex, or otherwise make available any account, login, credential, API key, token, or other authentication material to or with any unauthorized person or system, or use any credential other than one validly issued to the accessing User;
- access or attempt to access any account, environment, tenant, dataset, Output, User Input, configuration, or portion of the Services that the User is not expressly authorized to access, including any non-public, internal, administrative, staging, beta, or test endpoint;
- probe, scan, test, or audit the vulnerability, configuration, or security of the Services, or any system or network connected to the Services, or breach or circumvent any security or authentication measure, except pursuant to a written authorization from Exact Match (such as a coordinated vulnerability disclosure or written penetration test scope);
- use scraping, crawling, harvesting, spidering, mirroring, indexing, caching, or other extraction methods to circumvent authentication, access controls, rate limits, field restrictions, export limits, usage restrictions, or other service-integrity controls;
- use any robot, bot, headless browser, scraper, automation tool, Customer Agent, Downstream Agent, or other non-human system to exceed documented rate limits, evade throttling, simulate human behavior to avoid usage controls, or otherwise impair service integrity;
- launch or participate in any denial-of-service, distributed denial-of-service, flooding, amplification, brute-force, credential-stuffing, enumeration, scraping at scale, or similar activity against the Services or any related infrastructure, or transmit any volume or pattern of requests intended or reasonably likely to impair the availability, performance, or stability of the Services;
- remove, obscure, alter, or falsify any proprietary notice, identifier, signature, watermark, audit marker, or usage-control marker contained in or applied to the Services or Output, or use reverse-engineering techniques to circumvent security, usage, attribution, watermarking, or audit controls, except to the extent such restriction is prohibited by applicable law;
- introduce, upload, transmit, or distribute through the Services any virus, worm, Trojan horse, ransomware, spyware, time bomb, logic bomb, backdoor, rootkit, malicious code, or other harmful component, or any User Input designed to exploit, attack, or compromise the Services or any other system;
- use prompt injection, indirect prompt injection, jailbreaking, system-prompt extraction, tool-use exploitation, or other adversarial techniques to manipulate the Services, any Customer Agent or Downstream Agent operating against the Services, or any safety, policy, or access control mechanism of the Services;
- forge, spoof, or misrepresent any header, identifier, source IP, user-agent, account attribution, or other metadata associated with access to the Services, or impersonate any other User, Exact Match employee, or third party;
- interfere with, disrupt, or degrade the Services, any other User's use of the Services, or any servers, networks, or systems connected to the Services, including by disabling, overloading, or impairing logging, monitoring, billing, or metering functionality; or
- attempt, assist, encourage, or solicit any of the foregoing.
16.3 Credential Misuse. No User may share, transfer, expose, or use any credential, API key, token, or other authentication material in a manner that permits unauthorized access to the Services or Output.
17. No Competitive Use or Unauthorized Model Training
17.1 No Competitive Use. No User may access or use the Services or Output, in whole or in part, to design, develop, market, offer, operate, or support any product, service, dataset, model, API, MCP server, agent, integration, or other offering that competes with, replicates, or is substantially similar to the Services or any feature, function, or component thereof, including B2B contact data, identity resolution, ICP modeling, audience creation, data enrichment, or related capabilities.
17.2 No Benchmarking or Comparative Analysis. No User may use the Services or Output to conduct benchmarking, performance testing, accuracy testing, coverage testing, match-rate testing, comparative analysis, competitive intelligence, or any similar evaluation of the Services against any other product or service, or to publish, disclose, or otherwise make available the results of any such activity, in each case without Exact Match's prior express written authorization.
17.3 No Unauthorized Model Training or Evaluation. No User may use, and Customer shall ensure that no Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent uses, the Services or Output to train, pre-train, fine-tune, distill, retrieve-augment, ground, calibrate, validate, evaluate, red-team, or otherwise develop or improve any artificial intelligence model, machine-learning model, large language model, foundation model, embedding model, classifier, ranker, generative system, or other algorithmic system, in each case without Exact Match's prior express written authorization. The foregoing prohibition applies regardless of whether the model or system is proprietary, third-party, or open source, and regardless of whether the Output is used directly, indirectly, in aggregated form, in derivative form, or as a reference, label, or ground-truth signal.
17.4 No Unauthorized Standalone Data Products. No User may use the Services or Output to create, compile, assemble, or derive any standalone database, data product, lookup table, embedding store, vector index, knowledge graph, training corpus, evaluation set, or other dataset for any purpose not expressly permitted by the Agreement.
17.5 No Reverse Engineering of Data Methods. No User may use the Services or Output to reverse engineer, recreate, infer, or otherwise discover Exact Match's data sources, data acquisition methods, identity resolution logic, matching algorithms, scoring methodologies, model weights, training data, or other proprietary methods or know-how underlying the Services.
17.6 No Facilitation. No User may direct, enable, assist, fund, or otherwise facilitate any third party in engaging in any activity prohibited by this Section 17, and Customer shall impose contractual restrictions on Downstream Customers, Downstream Users, and Downstream Agents that are at least as protective as this Section 17.
17.7 Authorization. Any authorization granted by Exact Match under this Section 17 must be in a signed writing from an authorized officer of Exact Match, must specifically reference this Section 17, and may be conditioned, limited, or revoked by Exact Match in its sole discretion. No course of dealing, silence, failure to enforce, or non-written communication shall constitute authorization for purposes of this Section 17.
18. Monitoring and Enforcement
18.1 Reservation of Rights. Exact Match reserves the right, but is not obligated, to monitor, audit, log, review, and investigate access to or use of the Services, Output, and User Inputs, including account activity, query patterns, API and MCP traffic, agentic behavior, export volumes, integrations, authentication events, metadata, and telemetry, in order to verify compliance with this AUP, the Agreement, and applicable law and to protect the Services, Exact Match, its Users, and third parties.
18.2 Monitoring Activities. Exact Match may use automated systems, manual review, or both, and may retain logs and records for the purposes set forth in this Section 18 and the Agreement.
18.3 Investigations. Exact Match may investigate any actual, suspected, or threatened violation of this AUP, any unlawful, fraudulent, abusive, or harmful activity, any security or service-integrity issue, and any complaint or report relating to use of the Services or Output.
18.4 Enforcement Actions. In addition to any other rights or remedies available under the Agreement, at law, or in equity, Exact Match may, in its sole discretion and with or without prior notice, take any one or more of the following actions in response to an actual, suspected, or threatened violation of this AUP, or as otherwise reasonably necessary to protect the Services, Exact Match, its Users, or third parties:
- suspend, throttle, rate-limit, restrict, degrade, or disable, in whole or in part, access to the Services, Output, API, MCP endpoints, integrations, or specific features or functionality;
- revoke, rotate, disable, or refuse to issue API keys, credentials, tokens, or other authentication materials;
- quarantine, restrict, delete, or refuse to process User Inputs, queries, prompts, audiences, exports, or Output;
- block, terminate, or refuse access to the Services by any Customer User, Customer Agent, Downstream Customer, Downstream User, Downstream Agent, Trial User, IP address, device, account, or system;
- require Customer to remediate the violation, provide written certifications of compliance, or implement additional controls, monitoring, logging, or oversight;
- require Customer to suspend or terminate access by, or its commercial relationship with, any Downstream Customer, Downstream User, or Downstream Agent.
18.5 Immediate Action. Exact Match may take immediate enforcement action, without prior notice or opportunity to cure, where, in Exact Match's reasonable judgment, the violation or activity (a) poses a risk to the security, integrity, performance, or availability of the Services; (b) involves unlawful, fraudulent, deceptive, or abusive conduct; (c) involves the unauthorized access, use, exfiltration, or disclosure of data; (d) violates Sections 6 (General Prohibited Uses), 7 (FCRA, Eligibility, and Regulated Decisions), 8 (Anti-Discrimination), 9 (Sensitive Data and Sensitive Topics), 10 (Location Data and Sensitive Locations), 16 (Security, Circumvention, and Service Integrity), or 17 (No Competitive Use or Unauthorized Model Training); (e) exposes Exact Match or any third party to potential liability, regulatory action, or reputational harm; or (f) involves use by an unauthorized Customer Agent, Downstream Agent, or other automated system.
19. Reporting Violations
19.1 Reporting Channel. Any User, Downstream Customer, Downstream User, regulator, or other person or entity who becomes aware of any actual, suspected, or threatened violation of this AUP, or of any unlawful, abusive, or unauthorized access to or use of the Services, Output, or User Inputs, is encouraged to report such matter promptly to Exact Match Marketing Inc. using the contact information set forth below.
19.2 Contact Information. Reports may be submitted to Exact Match Marketing Inc. at the following:
19.3 Information to Include. To enable Exact Match to investigate and respond efficiently, reports should include, to the extent reasonably available: (a) the identity of the reporter and a means of contact; (b) a description of the conduct or condition giving rise to the report; (c) the identity of the User, Customer, Customer User, Customer Agent, Downstream Customer, Downstream User, or Downstream Agent involved, if known; (d) the date(s), time(s), and access channel(s) implicated (including web, API, MCP, integration, agent, trial, demo, or downstream offering); (e) any relevant Output, User Inputs, logs, screenshots, URLs, request identifiers, or other supporting materials; and (f) any prior communications with Exact Match concerning the matter.
20. Relationship to Other Terms
Relationship to Agreement. This AUP is incorporated into and forms part of the Agreement. In the event of a conflict, the Agreement controls, except that any more restrictive limitation, prohibition, or compliance obligation in this AUP controls unless the applicable Order Form or data processing addendum expressly supersedes that provision by specific reference. Exact Match may update this AUP in accordance with the Agreement.