virbe.
Legal documentVersion 1

Acceptable Use Policy

Effective November 16, 2026

This Acceptable Use Policy ("AUP") forms part of the Agreement between Virbe sp. z o.o. ("Virbe") and the Customer under the Terms of Service (https://virbe.ai/terms). Capitalised terms have the meanings given in the Terms. The AUP applies to the Customer, its Authorized Users and its Customer Agents. The Customer must pass on equivalent rules to End Users, through its own terms or notices, to the extent relevant.

1. General principles

1.1. Customer Agents must be lawful, honest about being AI and respectful of the rights of the people they interact with.

1.2. The Customer remains responsible for how its Customer Agents are configured and used, including the content of prompts, system instructions, Knowledge Base content and the Third-Party Services it connects.

1.3. In addition to this AUP, the Customer must comply with the usage policies of the providers of the AI models and engines its Customer Agents use, for example the policies of OpenAI, Microsoft (Azure OpenAI and Azure AI services), Anthropic, Google and ElevenLabs, as applicable. Links are provided in the Documentation.

2. Prohibited AI practices

The Customer must not use the Services for any practice prohibited by Article 5 of Regulation (EU) 2024/1689 (AI Act), including to:

  • (a) deploy subliminal, purposefully manipulative or deceptive techniques that materially distort a person's behaviour by impairing their ability to make an informed decision, in a way that causes or is reasonably likely to cause significant harm;
  • (b) exploit vulnerabilities of persons due to their age, disability or specific social or economic situation (for example, pressuring elderly persons or persons in financial difficulty into purchasing financial products) with the objective or effect of materially distorting their behaviour in a way that causes or is reasonably likely to cause significant harm;
  • (c) evaluate or classify persons based on their social behaviour or personal characteristics leading to detrimental or unfavourable treatment (social scoring);
  • (d) assess or predict the risk of a person committing a criminal offence based solely on profiling or personality traits;
  • (e) create or expand facial recognition databases through untargeted scraping of facial images;
  • (f) infer emotions of persons in the workplace or in educational institutions (except for medical or safety reasons where permitted by law);
  • (g) categorise persons based on biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation;
  • (h) carry out real-time remote biometric identification in publicly accessible spaces;
  • (i) generate or disseminate non-consensual intimate or sexually explicit images, audio or video of identifiable persons, or any child sexual abuse material.

3. Restricted (high-risk) uses

3.1. Unless expressly permitted in an Enterprise Agreement, the Customer must not use the Services, a Customer Agent or its Outputs as an AI system for any purpose listed in Annex III of the AI Act, in particular:

  • (a) recruitment or selection of persons, decisions on promotion or termination of work relationships, allocation of tasks based on personal traits, or monitoring and evaluating the performance and behaviour of workers;
  • (b) determining access to, admission to or assignment within education or vocational training, evaluating learning outcomes or monitoring students during tests;
  • (c) evaluating the creditworthiness of natural persons or establishing their credit score, or risk assessment and pricing in life and health insurance;
  • (d) evaluating eligibility for essential public assistance benefits and services, or evaluating and classifying emergency calls and dispatching emergency services;
  • (e) law enforcement, migration, asylum, border control, the administration of justice or democratic processes, including influencing the outcome of elections or the voting behaviour of persons;
  • (f) biometric identification of persons, or biometric categorisation of persons inferring the attributes listed in Article 9(1) GDPR; age-range and gender estimation used only for aggregated statistics in accordance with Section 6 is not a restricted use;
  • (g) any other use that would make the Services or a Customer Agent a high-risk AI system.

3.2. A Customer Agent may provide general information about the products or services listed above (for example, explaining loan products or the steps of a recruitment process), provided that it does not make, or materially influence, decisions about individual persons.

3.3. Customer Agents must not provide individualised legal, medical, financial, tax or other professional advice as a substitute for a qualified professional, unless the Customer ensures appropriate review by a qualified person and complies with the rules applicable to that profession.

4. Transparency and authenticity

The Customer must not:

  • (a) disable, hide or render ineffective the AI disclosure of the Widget, the Kiosk Application or voice channels, or tell End Users that they are talking to a human;
  • (b) remove, alter or tamper with watermarks, metadata or other markings identifying Outputs as AI-generated;
  • (c) use a Customer Agent to impersonate a real person, organisation or public authority, or to create the false impression of human interaction, endorsement or affiliation;
  • (d) use stock avatars or voices provided by Virbe to depict real persons, in political or election-related content, or in news or current-affairs content, without Virbe's prior written consent.

5. Voice, image and likeness

5.1. The Customer may create or use a custom avatar, voice clone or other digital replica of a real person (through Virbe or a Third-Party Service) only if:

  • (a) the person is an adult and has given free, specific, informed, documented and revocable consent to the creation and each intended use;
  • (b) the Customer holds the necessary rights under copyright, image and personality rights law;
  • (c) the replica is disclosed to End Users as artificially generated in accordance with Article 50(4) of the AI Act; and
  • (d) the Customer stops the use and deletes the related assets when consent is withdrawn.

5.2. Digital replicas of minors, of deceased persons (without authorisation of their heirs or rights holders), and of public figures or politicians without their express consent are prohibited.

6. Kiosk camera features

When the Customer enables camera-based features of the Kiosk Application (for example presence detection, age or gender estimation), it must:

  • (a) display clear notices before persons enter the camera's field of view, explaining that an AI system analyses camera images, for what purpose, and who the controller is;
  • (b) carry out a data protection impact assessment where required and document its legal basis;
  • (c) not use these features to identify persons, to infer emotions or sensitive characteristics, in relation to its own employees in the workplace, in educational institutions, or in places primarily intended for minors;
  • (d) not use the results to treat individual persons differently in ways that produce legal or similarly significant effects, or to exploit vulnerabilities related to age; and
  • (e) use the results only as aggregated statistics.

7. Content and conduct

The Customer must not use the Services to create, store, transmit or make available content or Customer Agents that:

  • (a) are illegal, or promote illegal activities, terrorism, violent extremism or hate based on protected characteristics;
  • (b) harass, threaten, bully, defame or discriminate against any person;
  • (c) contain sexually explicit material, or sexualise minors in any way;
  • (d) infringe intellectual property rights, trade secrets, privacy or personality rights;
  • (e) facilitate fraud, phishing, scams, identity theft, or the collection of passwords, payment card data or other credentials;
  • (f) provide instructions for creating weapons, explosives, or chemical, biological, radiological or nuclear threats, or facilitate self-harm;
  • (g) distribute malware, or attack, probe or overload any system or network;
  • (h) send spam or unsolicited commercial communications, or make automated calls or messages without the consent required by law;
  • (i) collect personal data of End Users covertly or beyond what is necessary and disclosed in the Customer's privacy notice; or
  • (j) target or knowingly collect data from children without appropriate safeguards and, where required, parental consent.

8. Security and integrity of the Services

The Customer must not:

  • (a) circumvent or test the security, rate limits, authentication, content filters or safety settings of the Services or of model providers, including through prompt injection or "jailbreaking" aimed at the Services, except as part of a security assessment agreed in advance with Virbe;
  • (b) access accounts, Customer Agents or data of other customers;
  • (c) use the Services to train, distil or build competing AI models or services, or extract models, prompts or Virbe Content in bulk;
  • (d) share credentials, Profile Secrets or Provider Credentials publicly or with unauthorised persons; or
  • (e) use automated means to access the Services other than through the documented APIs and within their limits.

9. Reporting and enforcement

9.1. Suspected violations of this AUP, illegal content and security vulnerabilities can be reported to [email protected] (content and conduct) and [email protected] (vulnerabilities).

9.2. Depending on the severity and recurrence of a violation, Virbe may: (a) ask the Customer to remedy it within a reasonable period; (b) remove or disable access to specific content or a Customer Agent; (c) suspend the Services in accordance with Section 15 of the Terms; or (d) terminate the Agreement in accordance with Section 18.3 of the Terms, with immediate effect where the breach cannot be remedied (for example a prohibited practice under Section 2, a digital replica without consent under Section 5, or content sexualising minors). Virbe informs the Customer of its decision and the reasons for it, and the Customer may contest it as described in Section 15.4 of the Terms.

9.3. Virbe may update this AUP in accordance with Section 20 of the Terms, including to reflect new legal requirements and the policies of model providers.