Acceptable Use Policy
Effective
This Acceptable Use Policy ("AUP") applies to everyone who uses the Indacas Platform — Researchers, Participants, and anonymous respondents — and forms part of the Terms of Service.
Breaching this policy may lead to content removal, study suspension, account suspension or termination (see Terms of Service, Section 11), and, where the law requires, reports to authorities.
1. Lawful data collection only
You must not use the Platform to collect, store, or process personal data:
- without a lawful basis under UK GDPR (or the data protection law that applies to you);
- in breach of a duty of confidence, a contract, or a court order;
- that you obtained unlawfully elsewhere and are importing into a study.
2. Special-category and sensitive data
- Do not collect special-category data (health, genetic, biometric, sex life or orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership) or criminal-offence data unless you have an Article 9/10 condition (e.g. explicit consent or the research condition with its safeguards) and any ethics approval your study requires.
- Flag fields collecting such data as "sensitive" in-product.
- Do not attempt to infer special-category data from responses collected for other purposes.
3. Payment card and financial details
- Do not use the Platform to collect payment card details — card numbers, security codes, expiry dates — or bank account and sort code numbers, whether through survey questions, record fields, free-text answers or file uploads.
- Indacas is not PCI-DSS certified and is not built to hold this data. Use a payment provider for payments and participant reimbursements.
- This applies however the data arrives, including a Participant volunteering it in a free-text box. If you discover card data in a response, remove it from the response.
4. Honest research — no deception or phishing
- No surveys that impersonate another organisation, mimic login pages, or harvest credentials, payment details, or government identifiers.
- No misrepresenting who is running a study, its purpose, or what will happen to responses. Approved deception designs in research must have ethics approval and a debrief, and must never collect credentials or payment data.
- No fake prize draws, misleading incentives, or dark-pattern consent flows. Consent text shown in-product must accurately describe the study.
5. Children and vulnerable participants
- No collecting personal data from children under 16 without the safeguards the law requires — including parental/guardian consent where applicable — and appropriate ethics approval.
- No harvesting personally identifiable information of minors. Studies involving children must collect the minimum data necessary and must not be used to build contact lists of minors.
- Studies involving vulnerable adults must have appropriate safeguards and, where required, ethics approval.
6. Distribution and anti-spam
- Send study invitations only to people you have a lawful right to contact (existing consent, a legitimate research relationship, or another lawful basis under UK GDPR and PECR).
- No purchased, scraped, or harvested contact lists.
- Honour opt-outs promptly and do not re-invite people who have declined or withdrawn.
- Do not misrepresent the sender or subject of invitation emails, and do not use the Platform to send bulk unsolicited messages of any kind.
7. Prohibited content and conduct
You must not use the Platform to:
- host or distribute unlawful content, malware, or links to either;
- harass, threaten, or defame any person, or incite harm;
- infringe intellectual property or publish others' private information without authority;
- run any activity that is unlawful in England and Wales or in the place you operate from;
- resell or white-label the Platform without a written agreement with us.
8. Platform integrity and security testing
- No unauthorised access attempts, credential stuffing, token guessing (including manipulating response-token links to access others' responses), or circumvention of role-based access controls.
- No scraping the Platform, automated bulk account creation, or interference with other users' studies.
- No load testing or vulnerability scanning against the Platform without prior written permission from Indacas.
- Good-faith reports welcome: if you find a vulnerability, report it to [email protected] and give us reasonable time to fix it before disclosure. Do not access, alter, or exfiltrate other people's data while investigating — stop and report as soon as you can demonstrate the issue.
9. Fair use of shared resources
Do not impose unreasonable load on shared infrastructure (e.g. abusive API usage or automation far beyond normal research use). Plan limits are stated on your subscription and deliberately circumventing them is a breach of this policy.
10. Reporting misuse
Anyone — including Participants who believe a study is misusing their data — can report suspected AUP breaches to [email protected]. We review reports promptly; where the concern is about a Researcher's controllership of Research Data (rather than Platform misuse), we may also direct you to the Researcher and to the ICO.
11. Changes
We may update this AUP as the Platform and the law evolve; material changes will be notified as described in the Terms of Service.