Acceptable Use Policy
1.Introduction
This Acceptable Use Policy ("AUP") governs your use of services provided by HostingX Solutions LLC. By using our services, you agree to comply with this policy.
2.Permitted Use
FinOps AI analyses the cloud cost and usage data of the accounts you connect, produces findings and recommendations, and — where you approve them — executes remediation actions against those accounts. It is intended for legitimate business purposes including:
- Analysing and optimising cloud cost and usage across accounts you are authorised to manage
- Reviewing findings, plans and recommendations the service generates
- Approving and executing remediation actions against your own cloud accounts
- Kubernetes, SaaS and AI-spend cost visibility, tag governance and budgets
- Sustainability and carbon reporting on your own infrastructure
HostingX Solutions LLC also provides consultancy and managed platform services outside FinOps AI; this policy governs those too.
2A.Connected Cloud Accounts and Automated Changes
This is the part of the service that acts on your infrastructure, so it carries obligations the rest of this policy does not. You must:
- Connect only accounts you are entitled to connect. You represent that you are authorised by the account owner to grant the access you grant, and to permit the changes described below.
- Hold the authority to approve changes. Approving a remediation instructs us to modify resources in your cloud account. Only approve actions you are entitled to authorise.
- Not use the service to bypass your own change control. Where your organisation requires review, approval or a maintenance window for infrastructure changes, our approval workflow does not replace it.
- Configure automation deliberately. Where you enable higher levels of automation, you remain responsible for the actions taken under the settings you choose.
- Not connect accounts belonging to third parties without their authorisation, or use connected access to reach systems outside those accounts.
2B.AI Features
The service generates AI-written narratives and provides an in-product assistant. What you type into the assistant is transmitted to our AI provider verbatim, including anything you paste — see §7 of the Privacy Policy, which describes exactly what is sent. Accordingly, you must not:
- Paste credentials, access keys or secrets into the assistant.
- Submit special-category personal data (health, biometric, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sex life or sexual orientation) or children's data. The service is not designed to process it and we do not request it.
- Submit third-party confidential information you are not permitted to disclose to a subprocessor.
- Rely on AI-generated output as professional, legal, tax or accounting advice, or act on a recommendation without reviewing it.
- Attempt to extract another customer's data through the assistant, or to circumvent the access controls that scope it to your workspace.
3.Prohibited Activities
You may NOT use our services to:
- (a) Violate Laws: engage in illegal activities or violate applicable laws and regulations.
- (b) Security Violations: attempt to breach, probe, or test security measures; access unauthorized data.
- (c) Network Abuse: send spam, conduct DDoS attacks, or intentionally disrupt services.
- (d) Malicious Code: transmit viruses, malware, ransomware, or other harmful code.
- (e) Unauthorized Access: access systems, accounts, or data without explicit permission.
- (f) Resource Abuse: intentionally overload infrastructure, bypass rate limits, or consume excessive resources.
- (g) Data Violations: process unlawful, stolen, or illegally obtained data.
- (h) Intellectual Property: infringe copyrights, trademarks, or other IP rights.
- (i) Resale: re-sell or sublicense services without written agreement.
- (j) Interference: disrupt other clients' use of shared infrastructure.
4.Security Requirements
You must:
- Maintain secure authentication credentials (strong passwords, MFA)
- Protect API keys and access tokens
- Promptly report security incidents or vulnerabilities
- Follow security best practices for your infrastructure
- Keep all systems and dependencies up to date
5.Data Processing Responsibilities
For the cloud data we process on your behalf you are the controller and we are the processor — see §5 of the Privacy Policy, which sets out where that split falls. As controller, you represent and warrant that:
- You have legal rights to all data you provide, and to the data in the cloud accounts you connect
- Your data processing complies with applicable laws (GDPR, CCPA, and others as applicable)
- You have obtained any consents or given any notices your own processing requires
- You will not process special-category personal data through the service without appropriate safeguards — the service is not designed for it
- You will not place personal data into cloud resource names, tags or labels beyond what your own processing requires, since we ingest those and they reach our AI provider
6.Resource Usage
- Use resources reasonably and as documented
- Do not attempt to circumvent usage limits
- Contact us before unusual load testing or capacity planning
- Scale appropriately to avoid service disruption
7.Monitoring and Enforcement
We reserve the right to:
- Monitor usage for security, performance, and compliance
- Investigate suspected violations
- Suspend or terminate services for AUP violations
- Report illegal activities to law enforcement
- Preserve evidence for legal proceedings
8.Consequences of Violations
Violations may result in:
- Warning and required corrective action
- Temporary service suspension
- Permanent account termination
- Legal action and liability for damages
- Reporting to authorities
9.Reporting Violations
- Abuse / AUP violations
- abuse@hostingx.co.il
- Security vulnerabilities
- security@hostingx.co.il
10.Changes
This AUP forms part of the agreement described in §19.7 of the Terms of Service, and we update it on the same basis: revisions are posted with an updated date, and material changes take effect 15 days after notice to existing customers, per Terms §19.8. Continued use after that period constitutes acceptance.
11.Contact
- Questions about this policy
- legal@hostingx.co.il
- FinOps AI inbox
- hello@getfinops.cloud