Last reviewed 2026-05-17. Served live at /legal/aup.
This Acceptable Use Policy ("AUP") applies to every user of the hosted eudr.dev instance, including API callers, dashboard users, and A2A peer agents. It supplements (does not replace) the Terms of Service and the Privacy Notice.
1. Permitted use
The service is intended for business operators preparing Due Diligence Statements under Regulation (EU) 2023/1115 ("EUDR"), downstream traders, regulatory auditors working on behalf of an operator, and agent-to-agent peers invoking the public A2A skills documented in /.well-known/agent-card.json.
You may use the service:
to compile, sign, verify, store, and submit Annex II DDS records,
to test the engine against synthetic or real scenarios,
to integrate the agent card into another A2A-compatible system,
to vendor satellite snapshots and risk assessments inside your internal compliance workflow.
This AUP applies to use of eudr.dev itself. The emem Earth-memory protocol on which the agent depends is open-source under its own licence.
2. Prohibited use
You may not, and you may not permit any third party to:
Misuse the regulation surface. Submit fictitious operator, supplier, or plot data with the intent to mislead a competent authority. Re-attest a non-negligible verdict as negligible without addressing the underlying finding. Falsify customs declarations linked from customs_declaration_ref.
Compromise security. Probe, scan, or test the vulnerability of the service without prior written authorisation. Bypass or attempt to bypass the trusted-proxy allowlist, the per-IP / per-email rate limits, the magic-link single-use guarantee, or the boot guard that refuses HTTPS deployment with the dev signing key. Reverse- engineer the agent identity, attempt to forge ed25519 receipts, or replay-attack the verifier.
Abuse the system. Send unsolicited bulk requests; sustain request rates that materially affect the service for other operators (above the rate-limit ceiling published in the agent card); cause the service to act as a proxy for traffic that has no EUDR purpose. Train AI / ML systems on the dashboard HTML or the agent card output without written permission.
Send infringing or unlawful content. Submit data you do not have the right to process — including personal data of natural- person operators or smallholders for which the Customer lacks a lawful basis under GDPR. Send malware, spam, defamatory content, or material that infringes third-party rights.
Misrepresent identity. Pose as another operator, supplier, producer, or regulator. Claim affiliation with the European Commission or any EU institution. Re-distribute the agent card with a forged signature.
Bypass payments. Use stolen card data; charge back without following the contact-first step in the Refund Policy; exploit the pay-on-pass model to probe pricing logic at scale.
Resell without permission. Operate a reseller layer that exposes eudr.dev to third parties under your brand without a written reseller agreement.
Violate export controls or sanctions. Use the service in or on behalf of a jurisdiction or natural person subject to EU, US, UK, or Indian sanctions. The Provider screens against EU Consolidated Financial Sanctions and equivalent lists; the operator is responsible for downstream compliance in its own supply chain.
3. Smallholder data
Plot polygons that identify a natural-person operator or smallholder are personal data under GDPR. The hosted instance forwards only geometry, HS code, country, and quantity to the emem.dev sub-processor — never operator or supplier identity. The Customer remains the controller; the Customer must have a lawful basis (in practice Art. 6(1)(c) GDPR read with Reg. 2023/1115 Arts. 8–12) and must satisfy Art. 13/14 transparency obligations to the data subject. The Provider cannot, and will not, verify the Customer's lawful basis on a per-record basis — but unlawful processing is a breach of this AUP.
4. Enforcement
A breach of this AUP may, at the Provider's discretion:
result in a warning with a reasonable remediation window for first-time, non-severe issues;
result in suspension of the offending account or API key without notice for severe or repeat issues (security, fraud, regulatory misuse, sanctions);
be reported to the relevant competent authority (Reg. 2023/1115 Art. 25 and Art. 27 set the framework) and to law enforcement where the breach is criminal;
be a material breach of the Terms of Service, triggering termination per Section 4 of those Terms.
The Provider will state the AUP clause invoked when taking action, and will give the Customer a reasonable opportunity to respond unless that opportunity would itself extend ongoing harm.
Termination for breach. A material breach of this AUP entitles the Provider to terminate the Customer's access to the hosted service immediately and without refund of any fees already paid, in addition to any other remedy under the Terms of Service. The Provider's decision to enforce is at its reasonable discretion; the Provider's failure to enforce a clause on a particular occasion is not a waiver of the clause.
5. Reporting AUP violations
If you observe behaviour on the hosted instance that you believe violates this AUP, email avijeet@vortx.ai with the URL or agent identifier, the time of observation, and a short description. Substantiated concerns about regulatory misuse may additionally be filed with the operator's national competent authority under Reg. 2023/1115 Art. 27.
6. Updates
We may update this AUP from time to time. Material changes will be announced via the Sub-processors change-notice channel; subscribers receive 30 days' notice before the change takes effect. Non-material changes (typos, link refreshes) take effect on publication.
7. Contact
AUP questions or violation reports: avijeet@vortx.ai.