VATFIND LEGAL
Acceptable use policy
Rules for lawful business use of VATFind’s workspace, API, MCP, monitoring and company information.
Updated 8 September 2026
Scope and authorised access
This policy forms part of the service terms and applies to free and paid users, API and MCP clients, monitoring, uploads and connected integrations. Use only workspaces, accounts and credentials you are authorised to access. You are responsible for people and software acting under your credentials.
Prohibited activity
- Do not evade payment, daily limits, rate controls or suspension by rotating accounts, network addresses, credentials or identities.
- Do not access another workspace, guess private result or attachment links, steal credentials, exploit a vulnerability, introduce malware or disrupt the service.
- Do not submit unlawful material, unrelated personal records, government identity documents, personal banking details, special-category information or information about children through ordinary lookup or contact fields.
- Do not use company information to stalk, harass, discriminate unlawfully, deceive, commit fraud or undertake unlawful surveillance.
- Do not represent a company match, missing result, format check or company-record monitor as an official tax-authority decision. Do not falsify source evidence or present an old snapshot as a current response.
- Do not resell, publish a bulk database, sublicense or use data beyond the licence in your order. Do not remove notices that explain source, retrieval time or usage conditions.
- Do not use the service for decisions about a natural person’s eligibility for employment, insurance or consumer credit where that would require a regulated consumer-reporting service or permissions that VATFind has not expressly agreed to provide.
API, agents and monitoring
Use documented endpoints and supported request volumes. Keep secret keys on trusted systems, limit OAuth scopes, honour throttling and retry guidance, and revoke credentials promptly when exposed. Do not place secrets in URLs or metadata. Use sandbox credentials for routine integration tests.
Only connect a webhook or agent client that you control or have authority to use. Review what it will receive and how it handles the data. You remain responsible for an agent’s instructions, actions, interpretation and onward disclosures. Set monitoring cadence and credit budgets deliberately; a paused service or unavailable source does not mean a company passed or failed a check.
Enforcement and review
We may investigate suspected misuse and proportionately limit or suspend affected access. Where practicable, we will explain the issue and provide a chance to correct it. Serious security threats, illegal activity or legal requirements may require immediate action. Termination and billing remedies follow the service terms.
Contact us to report abuse or ask for a human review of a restriction. Include the relevant account or request reference and a concise explanation; avoid unnecessary personal data or exploit payloads.
For legal, privacy or support requests, click here with “VATFind” and the nature of your request in the subject, or use the support centre. Do not send passwords, API keys or full payment-card details.