Fair Use Policy
What reasonable use of the platform, the public API and the AI features looks like, and what happens if use goes well beyond it.
Last updated 2026-07-28
Draft - pending review by a qualified lawyer.
This document is not legal advice. Text in square brackets must be completed by the operating company. Statements about how the product behaves are drawn from the implementation and are accurate; the legal framing around them is not yet settled.
The principle
Treica is priced per workspace rather than per record or per request, because counting those would make normal compliance work stressful. This policy exists so that a small number of extreme users cannot degrade the service for everyone else. It is not a mechanism for charging you more without warning.
If your use is unusual because your business is unusual - a large group with many entities, a genuinely enormous register - talk to us. That is a pricing conversation, not an enforcement one.
What normal use looks like
| Area | Expected range | Why the limit exists |
|---|---|---|
| Public API requests | Up to [API RATE LIMIT] requests per minute per key, and [API DAILY LIMIT] per day | Protects database capacity shared by all customers |
| Bulk import | Files up to [IMPORT ROW LIMIT] rows per import | Keeps preview and commit responsive and reversible |
| Evidence storage | Up to [STORAGE ALLOWANCE] per workspace, individual files up to [FILE SIZE LIMIT] | Storage is a direct cost and unbounded uploads are not sustainable |
| AI actions (Premium) | Up to [AI ACTIONS PER MONTH] assisted actions per workspace per month; contract PDFs up to 20 MB | Model inference is metered and materially more expensive than storage or queries |
| Users | Up to [USER LIMIT] active users per workspace | Beyond this, group structure usually needs a different arrangement |
What is not fair use
- Automated polling of the API at a rate far above what your data changes, instead of using a sensible schedule.
- Using the AI features to process material unrelated to your ICT third-party governance - for example bulk document processing for another purpose.
- Sharing one workspace across separate legal groups that should each hold their own register, in order to avoid separate subscriptions.
- Sharing API keys or user accounts between people, which also defeats the audit trail you are relying on.
- Load testing, scanning or penetration testing without our prior written authorisation.
How we respond
Our first step is always to contact the workspace owner and explain what we are seeing. Where use is simply growing, we will discuss a plan that fits.
Where use threatens service stability we may apply rate limiting to the affected key or workspace, and will say so. We reserve suspension for cases that are abusive or that endanger the security or availability of the service for others, and we will state the reason.
We will not silently degrade your service or delete your data under this policy.
Security testing
We welcome responsible disclosure. If you believe you have found a vulnerability, contact [SECURITY CONTACT EMAIL] before testing further, and do not access data belonging to any other customer. We will acknowledge within [DISCLOSURE RESPONSE TIME].