Scope
This policy applies to everyone using nexvraw.com and to every client engagement. It forms part of our Terms of Service. Where a client asks us to build or support something within the prohibitions below we will decline, and may terminate an existing engagement under the Terms.
Using this website
You may not:
- attempt unauthorised access to the site, its server or connected systems;
- probe, scan or test the vulnerability of our infrastructure without prior written permission;
- introduce malware or interfere with normal operation;
- use automated tools to place unreasonable load, or to scrape content at scale;
- harvest contact details for marketing;
- use our content to train machine-learning models without written permission;
- impersonate NEXVRA or misrepresent affiliation with us;
- submit false, misleading or abusive enquiries.
Security research
Good-faith research is welcome. Contact legal@nexvraw.com before testing. We will not pursue action against researchers who avoid accessing, modifying or exfiltrating data, avoid degrading service, give reasonable time to remediate before disclosure, and stay within the law.
Work we will not build or support
We decline engagements whose purpose or predominant use is:
Unlawful or harmful
- Anything violating applicable law where it will operate.
- Systems facilitating fraud, money laundering or sanctions evasion.
- Tools whose purpose is unauthorised access, denial-of-service, malware or ransomware distribution, or evading security detection for malicious ends.
- Credential-harvesting or phishing infrastructure.
Deceptive by design
- Dark patterns: subscriptions deliberately hard to cancel, costs hidden until checkout, consent flows engineered to produce a "yes".
- Fake reviews, engagement farms, or systems manufacturing the appearance of activity.
- Synthetic media intended to deceive about the words or actions of a real person.
- Misinformation or disinformation operations.
Abusive to people
- Stalkerware, covert location tracking, or monitoring individuals without knowledge and lawful basis.
- Systems designed to harass, threaten, defame or discriminate against people or protected groups.
- Child sexual abuse material, or any system facilitating exploitation or trafficking.
- Mass unsolicited messaging and spam infrastructure.
Data misuse
- Scraping or aggregating personal data without lawful basis or in breach of a platform's terms.
- Selling or brokering personal data collected without informed consent.
- Biometric identification or surveillance operating without the consent and lawful basis its jurisdiction requires.
Weapons and safety-critical
- Autonomous weapons systems and targeting software.
- Safety-critical control systems — medical devices, aviation, industrial safety instrumentation — where certification and specialist assurance are required and we are not the appropriately qualified vendor.
AI and automation specifically
We build AI systems and hold them to the same rules. Additionally we will not build:
- systems making consequential decisions about people — hiring, credit, housing, benefits, criminal justice — without human review, documented evaluation and a route of appeal;
- agents with unrestricted, unaudited access to production systems or funds;
- models trained on data the client has no right to use;
- tools impersonating a specific real person without that person's documented consent;
- AI features presented as human where disclosure is expected or legally required.
Every AI engagement includes agreed evaluation criteria, guardrails and defined human checkpoints. If we do not believe a system can meet a reliability bar appropriate to its consequences, we say so and decline rather than ship it.
Client obligations
Engaging us, you confirm that:
- the intended use complies with applicable law;
- you hold the rights and consents for all content, code and data you supply;
- you will obtain consents required for personal data you ask us to process;
- you will not use deliverables for any purpose prohibited by this policy;
- you hold the licences, permits or regulatory approvals your sector requires.
Handling a violation
On becoming aware of a breach we normally raise it and give an opportunity to correct. Depending on severity we may restrict site access, suspend work, terminate under our Terms, retain fees for work performed, or report the matter where law requires.
Where we terminate for a violation you remain liable for work performed to that date. Where we decline before work begins, all fees paid are refunded in full under our Refund Policy.
Reporting
To report misuse of this site, abuse of software we built, or a suspected violation, email legal@nexvraw.com with as much detail as possible. We review every report and respond within one business day.
Last updated September 10, 2026. NEXVRA may revise this document; the version at nexvraw.com/acceptable-use/ is always the one in force. Material changes affecting active engagements are notified by email at least 30 days before taking effect.
Questions: legal@nexvraw.com