Draft — pending legal review. The final wording of this policy is being finalised with qualified counsel. The structure below reflects what the published policy will cover.
DRAFT — pending legal review. Not legal advice.
Acceptable Use Policy
This Acceptable Use Policy ("AUP" or "Policy") sets out the rules for accessing and using the services operated by VAMS BioInnovation Private Limited ("VAMS", "the Company", "we", "us", "our"), a private limited company with its registered office at Plot No. 59, A-12-4-1, Near Matha Towers, K P Nagar, Benz Circle, Vijayawada, Andhra Pradesh 520008, India. It applies to everyone who accesses or uses:
the public website and any marketing or informational pages;
the customer dashboard and account areas;
the professional portals made available to clinician, laboratory and partner users;
API access and any programmatic interfaces we provide; and
research workspaces and collaborative analytics environments.
We refer to all of the above collectively as the "Services". By accessing or using any part of the Services, you agree to this Policy. If you are using the Services on behalf of an organisation, you accept this Policy for that organisation and confirm you are authorised to do so.
This Policy supplements, and is read together with, our Terms of Service, Privacy Policy and any professional, API or research agreement that applies to you. Where a signed agreement conflicts with this Policy, the signed agreement prevails to the extent of the conflict.
1. Nature of the Services — important context
VAMS provides microbiome-related informational and wellness-oriented products and reports. Our outputs are educational and are intended to support general wellbeing and personal understanding. They are not a medical diagnosis and are not a substitute for professional medical advice, examination, diagnosis or treatment.
Because of this, a core requirement of acceptable use is that you must not present, market, label, or rely on VAMS outputs as diagnosing, treating, curing, mitigating, preventing or predicting any disease or medical condition, and you must not represent them as a regulated medical or diagnostic service. This obligation applies to all users and is reinforced throughout this Policy.
2. Permitted use
You may use the Services only for lawful purposes and only in the manner expressly permitted by this Policy and any agreement that applies to you. Subject to those terms, you may:
access the website to learn about our products and educational content;
use the dashboard to manage your account, submit an authorised sample, and view your own informational reports;
if you are an authorised professional user, use the professional portal in accordance with your professional agreement and the scope granted to you;
if you are granted API access, use the API within the documented scopes, quotas and rate limits; and
if you are granted a research workspace, use it solely for the approved, governed research purpose for which access was granted.
You are responsible for all activity that occurs under your account or credentials.
3. Prohibited conduct — all users
You must not, and must not permit or enable any other person to, do any of the following.
3.1 Unlawful use
Use the Services in any way that breaches any applicable law or regulation, infringes the rights of others, or is fraudulent, deceptive, harmful, harassing, threatening or otherwise objectionable.
3.2 Submitting samples or data without authorisation or consent
Submit any biological sample, personal data or health-related information relating to another person unless you have the lawful authority and the specific, informed, affirmative consent of that person (or of their parent or lawful guardian where applicable) to do so, and to have it processed for the relevant purpose. You must not submit samples or data obtained unlawfully, deceptively, or in breach of any duty of confidentiality.
3.3 Intellectual-property infringement
Copy, reproduce, republish, distribute, adapt or create derivative works from any part of the Services, our content, reports, software, trademarks or branding, except as expressly permitted in writing. You must not remove or obscure any proprietary notices.
3.4 Scraping and reverse-engineering
Use any automated means (including crawlers, scrapers, bots or harvesting tools) to access, extract, index or copy content or data from the Services except as we expressly authorise. You must not decompile, disassemble, reverse-engineer or otherwise attempt to derive the source code, underlying models, algorithms, scoring logic or trade secrets of the Services, except to the limited extent this restriction is prohibited by applicable law.
3.5 Security circumvention
Probe, scan, or test the vulnerability of any system or network, or breach or circumvent any authentication, access-control, security or usage-limit measure, without our prior written authorisation. You must not introduce malware, viruses or any harmful code, or attempt to gain unauthorised access to any account, system, data or environment.
3.6 Misuse of the API and rate limits
Exceed, evade or attempt to evade documented rate limits, quotas or scopes; use multiple accounts or keys to circumvent limits; overload, degrade or disrupt the Services or their infrastructure; or use the API in a manner inconsistent with its documentation.
3.7 Unauthorised resale
Resell, sublicense, rent, lease, or commercially redistribute the Services, API access, reports or outputs, or make them available to any third party as a service, except under a written agreement that expressly permits this.
3.8 Misrepresenting VAMS outputs as diagnostic or medical
Present, describe, market, label or use any VAMS report, score, result or output as a medical diagnosis, medical device output, clinical test result, or a service that diagnoses, treats, cures, mitigates, prevents or predicts any disease or medical condition. You must not imply that VAMS is a laboratory, accredited laboratory, healthcare provider, diagnostic provider or holder of any regulatory approval. Educational and wellness framing must be preserved in any onward communication of our outputs.
3.9 Other prohibited activity
Impersonate any person or entity or misrepresent your affiliation; interfere with any other user's use of the Services; use the Services to build a competing product; or use the Services in any way not permitted by this Policy or your applicable agreement.
4. Professional-portal and API obligations
If you access the dashboard, a professional portal or the API as a clinician, laboratory, researcher, partner or other credentialed user, the following additional obligations apply.
4.1 Credential and key security
Keep your login credentials, API keys, tokens and secrets confidential and secure.
Do not share, publish, embed in client-side code, or transmit API keys or credentials to any unauthorised person or system.
Use appropriate safeguards (including strong authentication where offered) and notify us promptly at legal@vamsbiome.com if you suspect any credential has been lost, compromised or used without authorisation.
4.2 Respect scopes, quotas and limits
Use only the scopes granted to your credentials and only for the purposes for which access was provided.
Stay within your assigned quotas and rate limits, and design integrations to handle throttling and errors gracefully.
Do not attempt to access data, endpoints or accounts outside your authorised scope.
4.3 Data-handling duties for clinician, laboratory and researcher users
Access, use and disclose personal data and health-related information only as necessary for the authorised purpose and only where you have a lawful basis and, where required, valid consent.
Handle all personal data consistent with India's Digital Personal Data Protection Act, 2023 and other applicable law, and with any data-processing terms in your agreement with us.
Apply appropriate technical and organisational security measures, restrict access on a need-to-know basis, and retain data only as long as lawfully necessary.
Do not combine, enrich or repurpose data obtained through the Services in a way that exceeds the consent given by the individual or the scope of your agreement.
Promptly report any actual or suspected personal-data breach affecting the Services to us at privacy@vamsbiome.com.
4.4 Communicating outputs to patients, clients and third parties
When you share VAMS outputs with patients, clients, study participants or others, you must preserve their informational and wellness-oriented character and must not present them as diagnostic, clinical or predictive of disease. You remain responsible for any clinical judgement, advice or decision you make; VAMS outputs do not constitute such advice.
5. Research-workspace rules
If you are granted access to a research workspace or collaborative analytics environment, the following rules apply in addition to the obligations above.
5.1 De-identification
Only work with data that has been de-identified or pseudonymised as required by the governing approval, and handle any identifiers or keys strictly in accordance with that approval. Do not introduce direct identifiers into the workspace except where expressly permitted and governed.
5.2 Governance and approved purpose
Use the workspace solely for the specific, approved research purpose and only under the applicable governance framework, ethics or institutional approval, and data-sharing terms. Do not export, copy, or transfer data out of the workspace except as expressly authorised, and do not grant access to any person who is not authorised and bound by equivalent obligations.
5.3 No re-identification
Do not attempt, directly or indirectly, to re-identify any individual from de-identified or pseudonymised data, to link datasets in order to re-identify individuals, or to contact any individual identified or inferred from the data. Any incidental re-identification must be reported immediately to us at privacy@vamsbiome.com and must not be acted upon or disclosed.
5.4 Consent and scope boundaries
Use data only within the scope of the consent obtained from participants. Optional research, longitudinal profiling, algorithm development, biobank retention and sharing with collaborators are each separate, consent-dependent purposes; do not treat access to a workspace as consent for any purpose beyond the one specifically approved.
6. Monitoring
We may monitor use of the Services to protect their security, integrity and availability, to enforce this Policy, and to comply with law. We are not obliged to monitor, but we may investigate suspected breaches and cooperate with law-enforcement and regulators where appropriate and lawful.
7. Consequences of breach
If we reasonably believe you have breached this Policy, or to protect the Services, other users, or any individual's data or safety, we may take any of the following actions, with or without notice depending on the seriousness and urgency:
issue a warning or require you to correct the breach;
apply rate limiting, throttling, or restrict specific features, scopes or endpoints;
suspend, disable or revoke credentials, API keys, or access to any portal or workspace;
suspend or terminate your account or your access to any or all of the Services;
remove or disable access to offending content or data; and
take any other action available to us under your agreement or at law, including referral to competent authorities.
We will act proportionately and, where reasonably practicable and lawful, will give you an opportunity to remedy a breach. Suspension or termination does not limit any other rights or remedies available to us. Nothing in this section excludes or limits any liability that cannot lawfully be excluded, including for fraud, wilful misconduct, statutory consumer remedies, or our personal-data-security obligations.
8. Reporting misuse or security issues
If you become aware of any misuse of the Services, unauthorised access, a suspected vulnerability, or any content or activity that breaches this Policy, please report it promptly to us at legal@vamsbiome.com. For personal-data or privacy concerns, you may also contact our privacy contact at privacy@vamsbiome.com. Please include enough detail for us to investigate. We ask that you do not exploit, publicly disclose, or further access any vulnerability before we have had a reasonable opportunity to respond.
9. Changes to this Policy
We may update this Policy from time to time to reflect changes in the Services, our practices, or applicable law. We will post the updated version with a revised effective date, and material changes will take effect as described in the Version and Change History below or as otherwise notified. Your continued use of the Services after an update takes effect constitutes acceptance of the updated Policy.
10. Governing law
This Policy is governed by the laws of Laws of India, including applicable laws of the State of Andhra Pradesh, including the applicable laws of India. Nothing in this Policy removes any statutory grievance mechanism, access to the Consumer Commissions or other competent regulators, or any right that cannot lawfully be excluded.
11. Contact
Questions about this Policy can be sent to legal@vamsbiome.com. Privacy-related queries can be sent to privacy@vamsbiome.com.
Version and Change History
Document name: Acceptable Use Policy
Version: 1.0
Effective date: 10 July 2026
Change history: v1.0 (10 July 2026) — Initial publication.