Fair Use Policy

What reasonable use of the platform, the public API and the AI features looks like, and what happens if use goes well beyond it.

Last updated 2026-07-28

Draft - pending review by a qualified lawyer.

This document is not legal advice. Text in square brackets must be completed by the operating company. Statements about how the product behaves are drawn from the implementation and are accurate; the legal framing around them is not yet settled.

The principle

Treica is priced per workspace rather than per record or per request, because counting those would make normal compliance work stressful. This policy exists so that a small number of extreme users cannot degrade the service for everyone else. It is not a mechanism for charging you more without warning.

If your use is unusual because your business is unusual - a large group with many entities, a genuinely enormous register - talk to us. That is a pricing conversation, not an enforcement one.

What normal use looks like

AreaExpected rangeWhy the limit exists
Public API requestsUp to [API RATE LIMIT] requests per minute per key, and [API DAILY LIMIT] per dayProtects database capacity shared by all customers
Bulk importFiles up to [IMPORT ROW LIMIT] rows per importKeeps preview and commit responsive and reversible
Evidence storageUp to [STORAGE ALLOWANCE] per workspace, individual files up to [FILE SIZE LIMIT]Storage is a direct cost and unbounded uploads are not sustainable
AI actions (Premium)Up to [AI ACTIONS PER MONTH] assisted actions per workspace per month; contract PDFs up to 20 MBModel inference is metered and materially more expensive than storage or queries
UsersUp to [USER LIMIT] active users per workspaceBeyond this, group structure usually needs a different arrangement

What is not fair use

  • Automated polling of the API at a rate far above what your data changes, instead of using a sensible schedule.
  • Using the AI features to process material unrelated to your ICT third-party governance - for example bulk document processing for another purpose.
  • Sharing one workspace across separate legal groups that should each hold their own register, in order to avoid separate subscriptions.
  • Sharing API keys or user accounts between people, which also defeats the audit trail you are relying on.
  • Load testing, scanning or penetration testing without our prior written authorisation.

How we respond

Our first step is always to contact the workspace owner and explain what we are seeing. Where use is simply growing, we will discuss a plan that fits.

Where use threatens service stability we may apply rate limiting to the affected key or workspace, and will say so. We reserve suspension for cases that are abusive or that endanger the security or availability of the service for others, and we will state the reason.

We will not silently degrade your service or delete your data under this policy.

Security testing

We welcome responsible disclosure. If you believe you have found a vulnerability, contact [SECURITY CONTACT EMAIL] before testing further, and do not access data belonging to any other customer. We will acknowledge within [DISCLOSURE RESPONSE TIME].