← Noryn

Acceptable Use Policy

Version v2026-09Effective 9 September 2026Questions? privacy@norynsystem.com
This AUP is incorporated into the Terms of Service. Violation may result in immediate suspension or termination. For serious violations (CSAM, terrorism, fraud), we will report to relevant authorities (NCMEC, NCA, ICO) without prior notice.

1. Purpose

This Acceptable Use Policy (“AUP”) defines prohibited uses of the Noryn platform. The platform uses advanced AI models capable of generating convincing content at scale. This power comes with responsibility — this AUP exists to protect data subjects, third parties, the integrity of public discourse, and our ability to operate the Service.

2. Categorically Prohibited Uses

You must not use the Service to:

2.1 Illegal and harmful content

  • Generate, distribute, or store child sexual abuse material (CSAM) or any sexual content involving minors
  • Create or distribute terrorist content, content glorifying political violence, or content inciting violence against individuals or groups
  • Engage in or facilitate fraud, scams, phishing, or financial crime
  • Generate malware, ransomware, or other malicious code

2.2 Harassment and deception

  • Target, harass, or stalk any individual
  • Impersonate real, named individuals without their explicit consent
  • Generate output presented as human-written when communicating with a person who has not been informed they may be interacting with AI (per UK ASA guidance and emerging AI transparency requirements)
  • Generate fake reviews, testimonials, or ratings

2.3 High-risk automated decisions

  • Make automated decisions with legal or similarly significant effects on individuals (loan denials, hiring decisions, insurance refusals, visa applications, etc.) — the platform is not designed or tested for these use cases

2.4 Prohibited data categories

Without prior written agreement with us, you must not process through the platform:

  • Health or medical data
  • Racial or ethnic origin data
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data
  • Biometric data (for the purpose of uniquely identifying a person)
  • Data concerning sexual orientation
  • Criminal records or offences data
  • Data relating to children under 13

If you need to process special-category data, contact us to discuss a domain-specific addendum before proceeding. One exception is built in: allergy and dietary information that your customers volunteer through the Service’s booking features is permitted, solely so that you can serve them safely — it must not be used for any other purpose.

Treatment enquiries. A second exception applies where you run a clinic, salon or similar service: health information your customers volunteer when enquiring about or booking a treatment is permitted, solely so that you can answer them and deliver the service safely. It must not be used for profiling or marketing, you must not solicit a medical history through the Service, and you remain responsible for the lawful basis under Article 9(2) UK GDPR.

2.5 Political and election activity

  • Automated political advertising or voter targeting
  • Election influence campaigns
  • Impersonation of political figures or public officials

2.6 Regulated professional advice

  • Providing or presenting AI-generated content as professional medical, legal, or financial advice
  • Diagnosing medical conditions, prescribing treatments, or advising on medication
  • Providing legal advice requiring a qualified solicitor or barrister
  • Providing regulated financial advice (FCA-regulated activities)

The Noryn platform may assist with general information in these areas but must not be positioned as a substitute for regulated professional advice.

2.7 Spam and unsolicited communications

  • Sending unsolicited bulk messages (spam) through any integration
  • Exceeding integration platform rate limits or terms of service
  • Circumventing the anti-spam controls built into the platform

3. Tier-Specific Restrictions

3.1 Volume limits

Every plan carries a monthly message allowance, applied across your whole organisation, to prevent platform abuse and protect deliverability for all customers. Your current allowance and usage are shown in your dashboard.

3.2 Domain-specific use (medical, legal, financial)

The exception in §2.4 stands on every plan: a customer volunteering a skin concern, a contraindication or a medication while enquiring about a treatment is covered, on the conditions set out there and in DPA §4.

What needs a domain-specific addendum is the use §2.4 excludes: asking a person for a medical history, holding clinical records, or giving regulated advice in healthcare, legal or financial services. Contact us before doing any of those.

3.3 AI transparency (all tiers)

Noryn does not append a disclosure footer to your outbound messages, and there is no setting that adds one. Transparency is therefore your obligation, on every tier: you are responsible for making it clear to your contacts that replies from your Virtual Employees may be generated by an automated system, and for choosing how you say so — in your own messaging, on your website, or in your booking confirmations. See our AI Disclosure for the full transparency obligations, and §2.2 above for the deception this is here to prevent.

4. Enforcement

4.1 First violation

For first violations of a non-severe nature: written warning, required remediation plan, monitoring period. No refund for the affected period.

4.2 Repeated or serious violations

For repeated violations or serious single violations: immediate suspension of all Virtual Employees, Subscription paused, no refund for the suspended period. Customer may appeal within 14 days.

4.3 Severe violations

For violations involving CSAM, terrorism content, fraud, or other serious criminal activity: immediate termination without warning, no refund, account data preserved for law enforcement, report filed with relevant authorities (NCMEC for CSAM, NCA for serious crime, ICO for data breaches).

5. Reporting

To report a violation of this AUP (including by another customer or a third party through our platform), email security@norynsystem.com. We investigate all reports.

6. Changes

We may update this AUP with 30 days’ notice. Continued use after the effective date constitutes acceptance.

Noryn · Noryn System Ltd · Registered in England & Wales no. 17335896 · ICO Reg ZC199308

Registered office: 44 Bellbrigg Lonning, Cockermouth, CA13 9DA, United Kingdom · privacy@norynsystem.com