Acceptable use policy
Last updated 6 October 2026
The short version
- This policy applies to everyone who uses a system Golden Dorado hosts, and to golden-dorado.com.
- Use the system for your company's lawful business. Do not break the law, attack the system, send spam through it, or put in data you have no right to hold.
- Keep payment card numbers, health records and government ID numbers out of the system unless your agreement allows them.
- Security testing needs our written permission first. Good-faith vulnerability reports are welcome.
- If something goes wrong, we respond in proportion, and usually that starts with a conversation.
1.Who this policy applies to
This policy applies to every client of Golden Dorado LLC, to the client's authorized users, and to anyone else who uses or accesses a system we host or the website golden-dorado.com. It forms part of our Terms of service and any signed agreement with a client.
Each client is responsible for making sure its authorized users know about this policy and follow it.
2.Prohibited content
Do not upload, store or send through a system we host any content that:
- is illegal, or helps someone carry out illegal activity;
- infringes anyone's copyright, trademark, trade secret, privacy or other rights;
- contains viruses, ransomware or other malicious code;
- harasses, threatens or defames anyone, or promotes violence or discrimination; or
- is data the client has no right to hold, for example personal information collected unlawfully, in breach of a contract or privacy notice, or without a consent the law requires.
3.Prohibited conduct
Do not use a system we host, or the website, to:
- Break the law, including fraud, deception or impersonation.
- Gain unauthorized access to any account, system or data, including another user's account or another client's environment.
- Probe, scan or test for vulnerabilities without our written permission (see Security testing).
- Interfere with the service, for example by overloading it, sending excessive automated requests, launching denial-of-service attacks, or disrupting other users.
- Send spam. The system's email and messaging features are for the client's own business messages, such as notifications, reminders and correspondence with its own customers. Do not use them for unsolicited bulk email or messages, or for any message that breaks anti-spam or telemarketing laws, and always honor opt-out requests.
- Harass anyone, including other users and our staff.
- Share sign-in credentials or one-time codes, or let anyone who is not an authorized user into an account.
- Get around limits, including usage limits, permissions, role restrictions, the audit trail or any security control.
- Build a competing product, or copy, reverse engineer or extract the software, its design or its data model for that or any other purpose not allowed by the signed agreement.
- Resell or share access with third parties, except as the signed agreement allows.
4.Regulated and sensitive data
Some kinds of data carry specific legal and contractual requirements. Unless the client's signed agreement expressly allows it and sets out how it will be protected, do not put any of the following into a system we host:
- Payment card numbers, security codes or other cardholder data. Take card payments through a payment processor instead.
- Health records or other health information about individuals.
- Government identification numbers for individuals, such as Social Security, driver's license or passport numbers.
If any of this data ends up in a system by mistake, tell us at support@golden-dorado.com and we will help remove it.
5.Security testing
Scanning, penetration testing, load testing or any other security testing of a system we host, or of our website, requires our written permission in advance. A client that wants a test, for example as part of a vendor review, should email security@golden-dorado.com so we can agree the scope, timing and environment together.
If you find a vulnerability, please report it under the vulnerability disclosure policy on our Trust and security page (also published at /.well-known/security.txt). We acknowledge reports within 2 business days. Good-faith research that follows that policy is welcome and is treated as authorized. In all cases, do not access, change or keep more data than you need to show the issue, do not disrupt the service, and give us reasonable time to fix the issue before sharing it.
6.Reporting a violation
If you believe someone is breaking this policy, email support@golden-dorado.com with what you saw, where and when. Send security issues to security@golden-dorado.com.
We read every report. If it concerns a client's system, we may share it with that client, since the client controls the content of its system.
7.Enforcement
We respond in proportion to the seriousness of the problem. Depending on the circumstances, we may:
- contact the client and ask for the problem to be fixed;
- remove or disable specific content, or a specific user's access;
- suspend access to a system, in whole or in part; or
- end the service under our Terms of service.
We normally work through the client's designated contact and give the client a chance to fix things first. We act immediately only when we need to prevent serious harm, stop a security threat or meet a legal requirement, and then we tell the client promptly. Suspension does not delete client data. We may report illegal activity to the authorities and respond to valid legal requests.
8.Changes to this policy
We may update this policy from time to time, and the date at the top of the page shows the latest version. We will tell clients about material changes before they take effect.
9.Contact
Golden Dorado LLC7252 N Central Ave
Phoenix, AZ 85020
support@golden-dorado.com
Security reports: security@golden-dorado.com