Effective version: 2026-05-02
Acceptable Use Policy
Conexion Platform — Community Intelligence LLC
Last Updated: 2026-05-02
DISCLAIMER: This document is a template and should be reviewed by qualified legal counsel before use with clients.
1. Purpose
This Acceptable Use Policy ("AUP") defines the acceptable and prohibited uses of the Conexion platform ("Platform"). This AUP is incorporated into the Terms of Service and applies to all Authorized Users.
2. Acceptable Uses
The Platform is designed for and may be used for:
- Managing nonprofit operations (programs, grants, participants, staff, finances)
- Tracking program outcomes and participant services
- Managing grant pipelines, applications, and reporting
- Storing and organizing organizational documents
- Generating reports and data visualizations
- Using AI-powered features for grant writing and data analysis
- Communicating with funders, partners, and stakeholders via integrated email
- Automating operational workflows
- Tracking compliance with regulatory requirements
3. Prohibited Uses
You and your Authorized Users may not:
3.1 Legal and Regulatory Violations
- Use the Platform in violation of any applicable federal, state, or local law
- Store data that you are not legally authorized to collect or process
- Use the Platform to circumvent regulatory requirements
- Enter, upload, or transmit Protected Health Information (PHI) as defined under HIPAA before a Business Associate Agreement has been executed between your organization and Community Intelligence LLC. PHI includes any individually identifiable health information — including health-related fields, clinical notes, treatment records, payment for healthcare, or documents containing such information. If you are uncertain whether specific data qualifies as PHI, contact your administrator and pause data entry until the BAA is in place.
3.2 Data Misuse
- Store data unrelated to your nonprofit operations
- Enter deliberately false or misleading data about individuals
- Use participant data for marketing, solicitation, or purposes unrelated to service delivery
- Share login credentials between multiple individuals
- Access data beyond your assigned role and permissions
- Attempt to access other organizations' data (in managed hosting environments)
3.3 Security Violations
- Attempt to reverse engineer, decompile, or disassemble the Platform
- Attempt to bypass security controls, authentication, or access restrictions
- Probe, scan, or test the vulnerability of the Platform without written authorization
- Upload files containing viruses, malware, or other harmful code
- Attempt to gain unauthorized access to Platform systems or infrastructure
- Share or expose API keys, tokens, or credentials
3.4 System Abuse
- Use automated scripts, bots, or tools to access the Platform (except through the documented API)
- Consume excessive system resources that degrade performance for others
- Use the Platform for cryptocurrency mining or other computational abuse
- Attempt to interfere with the Platform's operation or availability
3.5 Content Restrictions
- Store content that infringes on third-party intellectual property rights
- Store content that is defamatory, obscene, or promotes illegal activity
- Use AI features to generate content that is intentionally misleading to funders or regulators
4. AI Feature Usage
When using AI-powered features (grant writing assistant, data analysis), you agree to:
- Review all AI-generated content before submitting to funders or regulators
- Not rely solely on AI recommendations for compliance or regulatory decisions
- Avoid including specific participant PII in AI prompts when possible
- Understand that AI outputs may contain inaccuracies and require human verification
- Accept responsibility for all content you submit, regardless of whether AI assisted in its creation
5. Account Security
You are responsible for:
- Using strong, unique passwords for all user accounts
- Enabling multi-factor authentication when required by your organization's policy
- Reporting suspected security incidents to your administrator immediately
- Logging out of shared or public computers
- Not sharing authentication credentials or recovery codes
6. Enforcement
6.1 Violations
If we determine that you have violated this AUP, we may:
- Issue a written warning
- Temporarily suspend the violating user's access
- Temporarily suspend your organization's access
- Terminate the Agreement (for material or repeated violations)
6.2 Process
Before taking enforcement action (except in emergencies), we will:
- Notify your administrative contact of the violation
- Provide 5 business days to cure the violation (except for security threats)
- Work with you to resolve the issue
For imminent security threats, we may take immediate protective action and notify you afterward.
7. Reporting
To report a suspected violation of this AUP or a security concern:
Email: security@communityintelligence.io
8. Changes
We may update this AUP with 30 days notice. Continued use of the Platform after the notice period constitutes acceptance of the updated policy.