Acceptable Use Policy
- Version:
2.0.0- In force since:
- October 02, 2026
- Supersedes:
- 1.0.0 (August 29, 2026)
- Operated by:
- GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88
This Acceptable Use Policy (“AUP”) forms part of the Terms of Use and defines what is permitted on the Upuai Cloud platform, operated by GMB TECNOLOGIA LTDA (CNPJ 68.727.144/0001-88).
It applies to you, to the members of your workspace and to the end users of your applications. You are answerable for third-party use of the resources you provision.
Language. This is a courtesy translation. The Portuguese version at upuai.com.br/aup is the binding version; in case of divergence, it prevails.
1. Prohibited conduct
Unlawful activity. Using the Platform to commit, facilitate or promote a crime or unlawful act, including fraud, money laundering, unauthorized gambling and trade in prohibited goods or services.
Unlawful content. Storing, transmitting or making available child sexual abuse material, incitement to crime, violence or discrimination based on race, color, ethnicity, religion, national origin, gender, sexual orientation, gender identity or disability, and content that violates the honor, image or privacy of others.
Malicious software and deception. Distributing or hosting malware, ransomware, spyware, botnets or command-and-control tooling; operating phishing pages or pages impersonating a person, company, public body or financial institution; and distributing applications that install software without the user’s informed consent.
Messaging abuse. Sending unsolicited bulk messages by email, SMS or messaging apps; operating lists obtained without consent; forging headers or senders; and running open relays.
Network and third-party abuse. Originating denial-of-service attacks; scanning ports, enumerating or testing the security of third-party systems without the owner’s written authorization; intercepting others’ traffic; and attempting unauthorized access to any system, including other workspaces on the Platform or the infrastructure itself.
Resource abuse. Mining cryptocurrency or running proof-of-work without prior written authorization; circumventing your Plan’s limits, quotas or technical controls; maintaining or operating more than one free-plan account — directly or through an intermediary — to run services or obtain free resources beyond what is offered, a practice subject to termination of all accounts involved; and running workloads whose primary purpose is to consume capacity rather than deliver a service of your own.
Infringement. Hosting or distributing content that infringes third-party copyright, trademarks, patents or trade secrets.
Personal data. Processing personal data contrary to the LGPD, including collecting sensitive data without a legal basis or processing data of children and adolescents without observing article 14 of the LGPD.
2. Legitimate heavy use
Heavy workloads — batch processing, transcoding, model training and inference, indexing — are permitted within your Plan’s limits. If your workload requires capacity beyond your plan, talk to us first: we will size the resource rather than suspend the service.
3. Security of your application
You are responsible for keeping your dependencies updated, not exposing secrets in your repository or log output, restricting access to your databases and buckets, and correctly configuring authentication in your application.
A compromised application that begins originating abuse is subject to the measures in section 5, even where the compromise was not your fault. In that case we act to contain the abuse and notify you immediately, prioritizing restoration of service.
4. Security research
Security testing against your own resources on the Platform is permitted, provided it does not degrade shared infrastructure or affect other customers.
Testing against Upuai’s infrastructure requires prior authorization. If you identify a vulnerability in the Platform, report it to contato@upuai.com.br before any disclosure. We will not take action against anyone reporting in good faith, without exploiting beyond what is necessary to demonstrate the flaw and without accessing third-party data.
5. Enforcement
Where there is evidence of a violation, and depending on severity and urgency, we may: request clarification with a period to remedy; rate-limit or cap the resource involved; suspend the specific resource; suspend the workspace; and terminate the account.
We prefer the least restrictive measure and prior notice. We act without notice only where there is imminent risk to the Platform, to third parties or to other customers, or where the law or an order from a competent authority requires it — in which case we notify you as soon as possible, describing what was done and why.
Appeals. You may contest any measure by writing to contato@upuai.com.br. We will review and respond within 5 business days. Measures applied in error are reversed, and the corresponding period of unavailability is taken into account for SLA purposes.
6. Reporting abuse
To report abusive content or conduct hosted on the Platform, write to contato@upuai.com.br with the URL or IP address involved, a description of the abuse, the date and time with time zone, and any evidence you hold. We review every report.
7. Changes
Material changes to this Policy will be communicated 30 days in advance and follow the procedure in section 2 of the Terms of Use.
GMB TECNOLOGIA LTDA — CNPJ 68.727.144/0001-88 — Belo Horizonte/MG, Brazil.