Legal Center
Here you will find the terms and policies governing your relationship with Whisperly when you subscribe to any Whisperly plan or engage Whisperly for consulting services, in addition to any specific terms agreed upon in writing.
Acceptable Use Policy
Last updated on 28th May 2026
Applicable to every User of the Whisperly Platform
This Acceptable Use Policy (the "Policy") sets out the rules that every User must follow when accessing or using the Whisperly platform operated by Lexelerate OÜ ("Lexelerate", "we", or "us"). It forms part of, and is incorporated by reference into, the agreement between Lexelerate and the organisation that has subscribed to the Platform (the "Customer"), together with the General Terms, SaaS Terms, Service Level Agreement, and Data Processing Agreement available at the Legal Center (https://whisperly.ai/legal-center).
In this Policy, "User" means any individual authorised by the Customer to access and use the Platform, whether an employee, officer, or contractor of the Customer, including any User who holds administrative rights (an "Admin"). "Platform" or "Whisperly" means the web-based software-as-a-service solution for data protection compliance, vendor assessment, and AI governance made available by Lexelerate at whisperly.ai. Capitalised terms not defined here have the meaning given in the General Terms.
By accessing or using the Platform, each User agrees to comply with this Policy. The Customer is responsible for ensuring that all of its Users are aware of and comply with this Policy, and a breach by any User is treated as a breach by the Customer. Where the User is acting within the scope of their engagement with the Customer, obligations expressed as the User's may also be enforced against the Customer.
1Account Registration and Security
Each User must:
- provide complete, accurate, and current information when an account is created, and keep that information up to date;
- use a genuine identity and not impersonate any other person or misrepresent any affiliation with a person or organisation;
- keep their login credentials confidential, use them only for their own access, and not share, transfer, or allow any other person to use their account;
- maintain the security of their account and any device used to access the Platform, and follow any authentication or security measures we require; and
- notify Lexelerate without undue delay at the contact address stated in the Order Form if they become aware of any actual or suspected unauthorised access to, or use of, an account or the Platform.
Each User is responsible for all activity that occurs under their account, whether or not authorised by them. Accounts are personal to the individual User and may not be used on a shared or generic basis by more than one person.
2Permitted Use
Users may access and use the Platform only for the Customer's internal compliance, data protection, vendor assessment, and AI governance purposes, in accordance with the agreement between Lexelerate and the Customer, this Policy, and applicable law. Any use of the Platform that is not expressly permitted is prohibited.
3Content and Data Entered into the Platform
Users are responsible for the text, documents, records, personal data, and other content they upload to, enter into, or generate within the Platform ("User Content"). Each User must:
- only upload or process User Content that the Customer is lawfully entitled to upload and process, and only where there is a valid legal basis for any personal data it contains;
- not upload or process personal data, special categories of personal data, or confidential information of any individual or organisation without the right and, where required, the authority to do so;
- not upload any content that infringes the intellectual property, privacy, or other rights of any third party, or that is unlawful, defamatory, discriminatory, obscene, or otherwise objectionable; and
- not rely on the Platform as the sole repository or backup for any User Content, the Customer remaining responsible for retaining its own records in accordance with the agreement.
Where the Customer including its Users process personal data of other individuals through the Platform, that processing is governed by the Data Processing Agreement available in the Legal Center. Lexelerate has no obligation to monitor User Content and does not do so, save as permitted under the agreement or required by law.
4Use of AI Features
The Platform includes features that use artificial intelligence, including the AI Assistant. When using these features, each User must:
- treat AI-generated output as informational support only, and not as legal advice or a substitute for the Customer's own professional judgement and compliance decisions;
- review and verify AI-generated output before relying on it, acknowledging that such output may be incomplete, inaccurate, or out of date;
- not enter into the AI features any data the User has no right to disclose, and not attempt to use the AI features to obtain personal data or confidential information the User is not authorised to access; and
- not attempt to circumvent, manipulate, or interfere with the safeguards, filters, or intended operation of the AI features, including by prompts designed to produce unlawful or harmful output.
5Prohibited Conduct
When using the Platform, Users must not, and must not attempt to, directly or indirectly:
- use the Platform in breach of any applicable law or regulation, or to facilitate any unlawful, fraudulent, or harmful activity;
- violate the privacy or data protection rights of any person, or carry out any unlawful processing of personal data through the Platform;
- upload, transmit, or introduce any virus, worm, malicious code, or other material that is designed to interfere with, damage, or gain unauthorised access to the Platform, its systems, or any data;
- tamper with, reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, underlying ideas, algorithms, models, or structure of the Platform, except to the extent this restriction is prohibited by applicable law;
- circumvent, disable, or interfere with any security, authentication, or access-control measure of the Platform, or attempt to gain access to any account, system, network, or data that the User is not authorised to access;
- probe, scan, or test the vulnerability of the Platform, or conduct any penetration testing or security assessment, without Lexelerate's prior written authorisation;
- impose an unreasonable or disproportionate load on the Platform or its infrastructure, or otherwise disrupt or degrade its integrity or performance;
- carry out web scraping or data scraping on or in connection with the Platform, or collect information through any bot, crawler, or software that simulates human activity;
- automate access to the Platform, including through any application programming interface, bot, or script, except through interfaces and methods that we expressly make available for that purpose;
- resell, sublicense, rent, lease, or otherwise make the Platform available to, or use it for the benefit of, any third party; or
- remove, obscure, or alter any proprietary, copyright, or trademark notice displayed on or within the Platform.
6No Competitive Use
Users must not access or use the Platform, or any feature, information, or functionality of it, in order to build, develop, or assist in building or developing any product or service that is the same as, similar to, or competitive with the Platform, nor to engage in competitive analysis or benchmarking, nor to copy or replicate any feature, idea, function, workflow, user interface, or graphic of the Platform.
7Third-Party Integrations and Services
Where a User connects a third-party service or integration to the Platform, the User is responsible for ensuring the Customer is authorised to use that service and to share the relevant data with it. Lexelerate is not responsible for any third-party service, and use of such services is at the Customer's own risk and subject to the third party's own terms.
8Responsibilities of Admin Users
A User who holds administrative rights is responsible for managing the Customer's account, including adding and removing Users, configuring access and permissions, and managing organisation settings. An Admin must exercise these rights only on behalf of, and as authorised by, the Customer, and must take reasonable steps to ensure that the Users they administer comply with this Policy.
9Monitoring, Suspension, and Consequences of Breach
9.1 Lexelerate may investigate any suspected breach of this Policy and may, where reasonably necessary to protect the Platform, its Users, or any third party, suspend or restrict a User's access to the Platform with or without prior notice. We will lift any such suspension once the relevant activity or condition has been resolved.
9.2 A breach of this Policy is a material breach of the agreement between Lexelerate and the Customer. Lexelerate reserves the right, acting reasonably, to suspend or terminate access, remove offending User Content, or take any other step available under the agreement or applicable law.
9.3 Users are fully responsible for all activity carried out under their accounts. The Customer remains responsible for the acts and omissions of its Users as if they were its own.
10Changes to this Policy
Lexelerate may update this Policy from time to time to reflect changes in the Platform, applicable law, or our practices. The current version is always available at the Legal Center (https://whisperly.ai/legal-center/acceptable-use). Continued use of the Platform after an updated Policy takes effect constitutes acceptance of the updated Policy.
11Contact
Questions about this Policy, or reports of suspected misuse or unauthorised access, should be sent to Lexelerate at the contact address stated in the Order Form.