Legal
Acceptable Use Policy
Draft — not yet in force. This text is a working draft awaiting review by qualified counsel. Passages marked like this depend on facts that are not yet fixed.
A document generator is only as trustworthy as the documents it produces. This policy says what you may not create with the Service and what happens if you do. It forms part of the Terms of Service: breaking it is a breach of contract and lets us suspend access.
1. Who this applies to
This policy applies to everyone who uses the Service, including the users, customers and systems you give access to. You are responsible for their use as if it were your own.
2. Documents you may not create
Do not use the Service to produce, store or distribute:
- Documents meant to deceive. Invoices, receipts, statements, payslips, bank documents, insurance papers, diplomas, certificates, licences, identity documents or official forms that are fabricated, altered or issued in someone else’s name in order to mislead a recipient. Mock-ups clearly marked as samples, and test data in your own systems, are fine.
- Impersonation. Material that presents itself as coming from a person, company or public body without their authorisation, including use of their name, logo, letterhead or branding.
- Phishing and fraud. Documents used to obtain credentials, payments or personal data under false pretences, or as part of a scheme to defraud.
- Malware. Files that embed or deliver malicious code, or that exploit weaknesses in PDF or image readers.
- Illegal content. Child sexual abuse material, content that incites violence or hatred, terrorist content, and anything else unlawful where you or your recipients are.
- Harassment. Material targeting a person with threats, defamation or the publication of private information.
- Spam. Bulk documents for unsolicited campaigns that breach marketing or anti-spam law.
3. Rendering other people’s web pages
The URL endpoints fetch a page and turn it into a file. That is powerful and easy to misuse, so:
- render only pages you are entitled to access and reproduce;
- do not supply cookies, headers or credentials that belong to someone else, and do not use the Service to reach accounts that are not yours;
- do not use the Service to get around paywalls, access controls, rate limits or terms of a third-party site;
- do not point the Service at private, internal or loopback addresses, or use it to probe networks that are not yours. We block this technically as well;
- respect copyright: a capture is a copy. Having a link is not the same as having the right to reproduce what it shows.
4. Data you may not send
Unless we have agreed otherwise with you in writing, do not send through the Service:
- special categories of personal data under Article 9 GDPR — health, biometric or genetic data, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sex life or sexual orientation;
- data relating to criminal convictions and offences;
- protected health information under HIPAA. We do not offer a Business Associate Agreement [TO CONFIRM: still true at launch];
- full payment card numbers or other cardholder data;
- government-issued identification numbers, except where they are an ordinary part of the document you are producing (a VAT number on an invoice, for example);
- material subject to export controls that you are not licensed to transfer.
If personal data of this kind reaches us by accident, tell us at privacy@dynamicdocumentapi.com so we can help you delete it.
5. Technical limits and abuse
Do not:
- work around plan limits, rate limits or quotas, for example by splitting one workload across several free workspaces;
- generate load whose purpose is to degrade the Service for others;
- attempt to break out of the rendering sandbox, to reach other customers’ data, or to access our infrastructure beyond the documented API;
- reverse engineer the Service, except where the law allows it;
- scan or test our systems without our written permission. Security research is welcome under our security page — talk to us first.
6. Reselling and white-labelling
You may build products on the Service and offer them to your own customers, including under your own brand. You may not resell raw API capacity as a competing document generation API, or present the Service itself as your own product. [TO CONFIRM: is that the line you want? A stricter or looser rule changes who may become a customer.]
7. How we enforce this
What we do depends on what we find. In most cases we contact you first and ask you to fix the problem. Where the violation is clear, serious, or ongoing — fraudulent documents, illegal content, an active attack — we may suspend the workspace or individual endpoints immediately, remove the file in question, and where the law requires it, report the matter to the competent authorities.
We tell you what we did and why, unless we are legally barred from doing so, and you can respond: write to legal@dynamicdocumentapi.com and we will review the decision. Repeated or deliberate violations end the agreement under section 12 of the Terms of Service.
We do not monitor the content of your documents as a matter of course, and we do not read Customer Content to look for violations. We act on reports, on abuse signals from our systems and on legal orders.
8. Reporting a violation
If you have received a document produced with the Service that breaks this policy, or you believe content hosted by us is unlawful, use the reporting page or write to abuse@dynamicdocumentapi.com. Tell us the file URL, what is wrong with it, and how to reach you. We confirm receipt and tell you the outcome. [TO CONFIRM: mailbox exists]
Change history
| Version | Date | Change |
|---|---|---|
| 0.1 | 23 September 2026 | First draft, pending legal review |