Version 1.0, effective 2026-07-27.
1. Introduction
This Fair Use Policy applies to all Client users, service accounts, and integrations accessing PrivateMind, whether via the webchat interface or the API.
Fair use limits are necessary to protect the integrity of the service and ensure a fair and equitable level of service to users.
Clients are expected to refrain from behavior that can reasonably be expected to cause service disruption.
2. Usage limits & Thresholds
2.1 Token Limits
- Free Tier: $10 per login per month
- Enterprise: Custom limits available
2.2 Usage Enforcement
Clients accept that by using PrivateMind, for purposes of monitoring compliance with the Fair Use Policy Options may monitor:
- Usage patterns and rate limit adherence
- Content quality and policy violations
- System load and resource allocation
- Suspicious or anomalous behavior
2.3 Commercial Restrictions
Clients shall not resell PrivateMind, or offer its AI-generated content as a service.
Clients shall not use PrivateMind for bulk generation of content to train competing models.
3. Security Requirements
3.1 Credential Hygiene
Multi-factor authentication (MFA) is required for webchat access. Where the Client connects via its own identity provider (SSO/SAML), enforcement of MFA is the Client's responsibility; where Options IT provides authentication directly, Options IT enforces it.
API keys must be kept secure and must never be embedded in client-side code, mobile applications, or any publicly accessible repository.
Clients are responsible for rotating API keys on a regular basis and immediately upon any suspected compromise. API key expiry can be set in PrivateMind.
Any suspected credential compromise must be reported to Options IT without undue delay via the incident reporting channel described in Section 3.4.
3.2 No Unauthorized Security Testing
Clients must not conduct penetration testing, vulnerability scanning, adversarial probing, jailbreak attempts, or prompt-injection attempts, or any attempts targeting other tenants, without Options IT's prior written authorization.
Attempts to extract model weights, training data, or system prompts, or to otherwise reverse-engineer the underlying model or infrastructure, are prohibited.
Good-faith security researchers may report vulnerabilities through Options IT's responsible disclosure channel; Options IT will not treat good-faith, coordinated disclosure as a breach of this clause.
3.3 Tenant Isolation and Monitoring
Client usage (webchat and API) is logged and monitored by Options IT for the purposes of security, abuse detection, and service integrity.
A privacy-safe description of what is logged, and for how long it is retained, is set out in Options IT's Privacy Notice / DPA.
Monitoring and logging for abuse-detection and security purposes is distinct from, and does not imply, use of client content to train or fine-tune models, see Section 5.3 for Options IT's model-training commitment.
Tenant environments are logically isolated; no client has access to another client's data, sessions, or logs.
3.4 Incident Reporting
Options IT to Client: Options IT will notify affected Clients of a confirmed security incident affecting the service without undue delay, and in any event within 48 hours of confirmation, consistent with applicable breach-notification norms.
Client to Options IT: Clients must notify Options IT without undue delay of any security incident on their side that may affect the service; including but not limited to leaked credentials, unauthorized access to their environment, or compromised integrations.
The incident reporting channel and contact details are: privatemindsupport@options-it.com.
4. Data Inputs
Unless agreed in writing as part of an Enterprise License, Clients are advised not to submit the following to PrivateMind via webchat or API:
- Special category personal data (e.g., health, biometric, or similarly sensitive data under UK/EU GDPR Article 9)
- Authentication credentials, secrets, private keys, or tokens
- Payment card or other regulated financial account data
- Source code, trade secrets, or confidential information belonging to a third party, unless the Client has the right to disclose it
Clients remain solely responsible for the content they submit and for ensuring it is permitted under their internal & external policy requirements.
5. Compliance & Data Protection
5.1 Controller / Processor Allocation
The allocation of data controller and data processor responsibilities between Options IT and the Client is set out in the DPA referenced in the Client's MSA. This FUP does not vary that allocation.
Clients remain responsible for ensuring they have a lawful basis for any personal data submitted to PrivateMind.
5.2 Encryption
Data is encrypted in transit via secure protocols and at rest (AES-256-GCM).
5.3 No Training on Client Data
Client prompts and outputs submitted through PrivateMind (webchat or API) are not used to train, fine-tune, or otherwise improve Options IT's or any third-party's models, except with the Client's prior written consent.
5.4 Sub-Processor and Infrastructure Transparency
Options IT will make available, on request or via its trust portal, a current list of sub-processors and underlying model/infrastructure providers used to deliver PrivateMind, including relevant data residency information.
Where personal data is transferred outside the UK/EEA, Options IT relies on appropriate safeguards (e.g., UK GDPR Standard Contractual Clauses / International Data Transfer Agreement) as set out in the DPA.
5.5 Regulated-Industry Responsibility
Clients remain solely responsible for their compliance with regulatory obligations in regards to any inputs submitted into PrivateMind or the reliance on any data produced by PrivateMind, including but not limited to those under FCA, SEC, MAS.
Clients should assess whether content generated via PrivateMind may constitute a business record for the purposes of their record-keeping obligations (e.g., SEC Rule 17a-4, MiFID II, FCA SYSC) and retain it accordingly.
Clients should independently confirm that reliance on AI-generated output is compatible with their industry and internal policy requirements before acting on it, particularly where regulatory guidance on generative AI outputs is still evolving.
5.6 EU AI Act Transparency
Consistent with Article 50(1) of the EU AI Act, users of PrivateMind's webchat are informed that they are interacting with an AI system. This disclosure is built into the product interface and reinforced here.
5.7 Sanctions and Export Control
Access to PrivateMind is not permitted from prohibited or sanctioned jurisdictions, or by sanctioned parties, in each case as determined under applicable export control and sanctions law.
5.8 Third Party Policy Compliance
Client agrees that it shall comply with all policies, procedures, and rules of any LLM available within PrivateMind.
6. Ethics & Responsible Use of AI
6.1 Prohibited Use Cases
PrivateMind must not be used to:
- Engage in, or facilitate, unlawful activity of any kind
- Impersonate other individuals or entities
- Generate malware, phishing content, or content designed to compromise the security of any system
- Create or spread disinformation, or engage in market manipulation or insider dealing
- Produce content facilitating self-harm, child sexual exploitation, or weapons (including chemical, biological, radiological, or nuclear) development
- Make, or materially inform, decisions with legal or similarly significant effect on individuals, such as credit, employment, or insurance decisions, without qualified human review
6.2 Mandatory Human Oversight
Outputs from PrivateMind are assistive and advisory in nature, not authoritative. The platform must not be used for fully automated decision-making without human review.
Outputs are not a substitute for professional legal, financial, investment, medical, or other regulated advice.
6.3 Known Limitations Disclosure
PrivateMind, like all AI systems, may produce inaccurate, incomplete, or fabricated ("hallucinated") output, may reflect bias, and has a knowledge cut-off date beyond which it lacks awareness of events.
Clients should independently verify outputs before relying on them for consequential decisions.
6.4 No Misrepresentation
Where legally or contextually required, Clients must disclose that content was generated or assisted by AI.
6.5 Reporting Harmful or Concerning Outputs
Clients may report harmful, biased, or otherwise concerning outputs through Options IT's feedback channel within PrivateMind itself or by emailing privatemindsupport@options-it.com.
Reports are reviewed as part of Options IT's ongoing AI governance and continuous improvement process.
6.6 Output Ownership and Intellectual Property
Ownership of outputs generated through Client use of PrivateMind, and allocation of risk relating to potential third-party IP infringement of outputs, is subject to the relevant jurisdiction of the Client. Clients are expected to take legal advice before relying on outputs for external or commercial publication.
7. Liability & Indemnity
The Client agrees to indemnify, defend, and hold harmless Options, its affiliates, officers, directors, employees, and agents from any IP Claims and related damages arising from:
- Client Input infringement: Client submitting material that violates third-party IP rights
- Unauthorized AI-Generated Content use: Client distribution or commercialization of output beyond the scope of the FUP
- Client modification infringement: Client creation of derivative works that infringe third-party rights
- Integration into products: Client incorporation AI-Generated Content into products causing IP claims
- Distribution to third parties: Client sharing output in ways that trigger third-party claims
- Violation of license terms: Client exceeding permitted use under their tier
- Failure to obtain permissions: Client does not clear rights where legally required
- Misrepresentation of authorship: Client falsely claiming original ownership of AI-Generated Content
8. Policy Updates
This policy is reviewed quarterly.
Major changes are announced 30 days in advance.
Minor updates take effect immediately.
Revision history
| Version | Effective | Changes |
|---|---|---|
| 1.0 | 2026-07-27 | Initial policy. |
Each revision carries an effective date.