Effective 2 September 2026 · Version 1.1 ·
Garuna Group — Enhanced Due Diligence (EDD)
Acceptable Use Policy
| Product | GARUNA GROUP — Enhanced Due Diligence ("EDD", the "Service") |
| Provider | Garuna Group ("Garuna", "we", "us") — Garuna Inc., a corporation incorporated under the laws of the Province of Ontario and operating as "Garuna Group", with registered office at 10 Thornmount Drive, Toronto, Ontario M1B 3J4, Canada |
| Governing law | Province of Ontario and the federal laws of Canada applicable therein |
| Effective date / Last updated | 2026-09-02 |
| Version | 1.2 |
| Contact | [email protected] (misuse reports / general); [email protected] (privacy/data protection); [email protected] (legal notices) |
This Acceptable Use Policy (the "AUP") is incorporated by reference into, and forms part of, the Terms of Service / Master Services Agreement (the "Terms") between Garuna and the Client. Capitalised terms not defined here have the meanings given in the Terms. In the event of a conflict, the Terms govern, save that the Data Processing Addendum (DPA) prevails on matters of personal-data processing.
1. Purpose & Scope
This AUP governs all access to and use of the Service by the Client and every Authorised User. It defines the purposes for which the Service may be used, the duties that attach to that use, and the uses that are strictly prohibited.
Early Access (membership-based). The Service is currently provided on an early-access basis, with all warranties limited accordingly and without prejudice to any warranty disclaimer, limitation of liability, or indemnity in the Terms. Access is account-gated (controlled by a garunagroup.com account login) and sold by monthly membership; every membership covers individual, entity and cryptocurrency searches. Every account holder warrants a documented lawful purpose for each query and that each search is conducted for a legitimate business, legal, or compliance purpose, and a holder who relies on a professional licence (for example under the Private Security and Investigative Services Act, 2005, or with the Law Society of Ontario) warrants that it is current. This is a warranty and account-gating control; the Service does not perform in-app verification of any licence number.
The AUP applies to:
- the Client (the organisation that signed the Terms) and each Authorised User (each analyst, investigator, employee, or contractor the Client authorises to operate the Service);
- every Sweep (one investigation of one Subject), every Report, and every export of a Report; and
- every Investigation Session an Authorised User establishes through the Service.
The Client is responsible for ensuring that each of its Authorised Users has read, understood, and complies with this AUP. The Client is accountable for all activity conducted under its account and credentials. Acceptance of the in-app acknowledgements at the pre-Sweep and Investigation Session gates does not narrow, replace, or supersede the obligations in this AUP.
A central fact frames everything below: the Subject is a third party, is not the user, and is generally unaware of the Sweep. That asymmetry — investigating a person or entity who does not know they are being investigated — is the reason the duties and prohibitions in this AUP exist and must be observed literally.
2. Permitted Purposes
The Service may be used only for lawful due diligence that the Client is independently entitled to carry out. Permitted purposes are limited to the following:
- KYC / KYB / AML — know-your-customer, know-your-business, and anti-money-laundering diligence on customers, counterparties, beneficial owners, and related parties, as part of the Client's own lawful compliance processes.
- Vendor, counterparty, and third-party risk — integrity, reputational, ownership, and sanctions-exposure assessment of suppliers, vendors, distributors, agents, partners, investees, acquisition targets, and other counterparties.
- Fraud and integrity investigations — detecting, investigating, or preventing fraud, misrepresentation, breach of agreement, or other unlawful or dishonest conduct affecting the Client or its stakeholders.
- Litigation support — lawful investigation in support of actual or contemplated legal proceedings, dispute resolution, asset tracing, or enforcement, consistent with applicable rules of court and professional conduct.
Any use outside these permitted purposes is a breach of this AUP. Permitted purpose is necessary but not sufficient: a use that falls within a permitted purpose is still prohibited if it engages any prohibition in §5 or breaches any duty in §3–§4.
2.1 Caution — employment and other eligibility decisions
The Service is not designed, marketed, or permitted as a hiring, screening, or eligibility tool, and pre-employment screening is not a permitted purpose where any consumer-reporting regime applies.
- You must not use the Service to make or inform any employment-eligibility decision — including hiring, promotion, retention, reassignment, or discipline of a candidate, employee, or contractor — where the use is, or would be treated as, a "consumer report" or an "employment purposes" use under the US Fair Credit Reporting Act (FCRA), the Ontario Consumer Reporting Act, or any other applicable consumer-reporting or credit-reporting legislation. Background research on a job candidate for an employment decision is the paradigm regulated use; Garuna is not a consumer reporting agency and the Service is not a consumer report (see §5.3).
- Any narrow residual use that touches an individual in an employment-adjacent context — for example, integrity, ethics, or reputational due diligence on a senior counterparty, principal, or beneficial owner that is not an eligibility determination governed by any consumer-reporting or FCRA regime — may be conducted only where the Client has obtained its own legal sign-off confirming that no such regime applies to the intended use. Absent that determination, the Service must not be used for it.
3. Lawful-Basis & Authorisation Duties
Garuna is the Processor / Service Provider in respect of Subject Personal Data; the Client is the Controller and selects every Subject. Before initiating any Sweep, the Client and the Authorised User must ensure that:
- Authority to investigate the specific Subject. You investigate only Subjects you are lawfully authorised to investigate. You must hold a lawful basis or authority to process the Subject's Personal Information for the chosen permitted purpose — for example, under PIPEDA's business-contact, investigation, fraud-prevention, or due-diligence provisions, and, for Subjects in the EU or UK, under GDPR / UK GDPR Article 6(1)(f) legitimate interests supported by a recorded balancing assessment (and with appropriate care if special-category data surfaces). Garuna processes only on the Client's Documented Instructions and does not warrant the Client's basis.
- A genuine, legitimate, case-specific purpose. Each Sweep must be tied to a real, articulable due-diligence need. Speculative, curiosity-driven, recreational, or fishing-expedition Sweeps are not permitted.
- Accurate Subject Inputs. Subject Inputs (legal name, jurisdiction, email, phone, alias/username, domain, context) must be accurate and submitted in good faith to identify the correct Subject and to support the identity-resolution and same-name-exclusion functions of the Service.
4. Data-Minimisation & Subject-Data Discipline
- Proportionality. Collection and use must be proportionate to the legitimate purpose. Do not run broader, deeper, or more identifier-rich Sweeps than the purpose requires, and do not enable Deep Mode or an Investigation Session where the case does not warrant it.
- No bulk or indiscriminate Sweeps. Do not run mass, automated, or indiscriminate Sweeps across populations of Subjects for whom you do not individually hold a lawful basis and a case-specific purpose.
- No basis-less profiling. Do not use the Service to assemble a standing dossier on a Subject beyond what the legitimate purpose requires, and do not retain or accumulate Reports to build profiles untethered from a current, lawful purpose.
- Subject is a third party. Treat all Subject data as the Personal Information of an unaware third party. The Service retains a Report only for a limited period (see the Privacy Policy) and keeps no standing, searchable database of Subjects; once you export a Report, you control that copy and are responsible for storing, securing, retaining, disposing of, and using it lawfully (see §6 of the Terms and the Privacy Policy).
- Identifier discipline for authenticated and account-discovery tooling. Where the case does not require it, do not submit a Subject email, phone, username, or domain that would cause the Service to query authenticated or account-discovery surfaces — including account-existence discovery tooling (open-source techniques that query target sites directly to test whether an email, phone, username, or domain corresponds to an account), or, where you have connected an authenticated account session, authenticated account lookup against a major email/account provider (Subject email → account surface). These techniques transmit the corresponding Subject identifier to many foreign third-party sites and, in the case of the authenticated lookup, to a major email/account provider. Submit only identifiers your lawful basis and purpose support.
- Output discipline. Subject the Output to human verification before acting on it. Do not make a solely-automated decision producing legal or similarly significant effects on the Subject without meaningful human review and independent verification. Do not represent the Output as a consumer report, or as legal, compliance, financial, or professional advice.
5. Prohibited Uses
You must not use the Service, a Sweep, a Report, an export, or any Output, in whole or in part, for any of the following. This list is illustrative, not exhaustive; anything substantially similar is equally prohibited.
5.1 Harm to individuals
- Stalking, harassment, doxxing, intimidation, coercion, or threats against any person, or facilitating any of these.
- Surveillance of an intimate partner, former partner, family member, or any person in a domestic or personal context — including monitoring, locating, tracking, or building a profile of a current, former, or prospective partner or household member. The Service is for organisational due diligence, not personal or relationship surveillance.
- Any use intended or reasonably likely to expose a Subject to physical, psychological, financial, or reputational harm outside a legitimate, lawful due-diligence purpose.
- Criminal harassment and non-consensual intimate images. Without limiting the foregoing, you must not use the Service, a Sweep, a Report, an export, or any Output to engage in, facilitate, or further criminal harassment within the meaning of section 264 of the Criminal Code (Canada) — including repeatedly following, communicating with, watching, or besetting a person, or engaging in threatening conduct, such that the person reasonably fears for their safety — or to publish, distribute, transmit, sell, make available, or otherwise deal with an intimate image of a person without their consent within the meaning of section 162.1 of the Criminal Code (Canada).
5.2 Discrimination & human-rights violations
- Targeting or selecting Subjects on the basis of a protected characteristic (such as race, ancestry, place of origin, colour, ethnic origin, citizenship, creed/religion, sex, sexual orientation, gender identity or expression, age, marital or family status, disability, or any characteristic protected under the Ontario Human Rights Code, the Canadian Human Rights Act, or other applicable anti-discrimination law), or using the Service to enable, support, or implement discrimination.
- Making, informing, or supporting any decision that violates human-rights or anti-discrimination law.
- Inferring, aggregating, or re-deriving protected characteristics about a Subject in order to profile, score, exclude, or otherwise treat the Subject in a prohibited way.
5.3 Consumer-reporting / eligibility misuse
- Using, treating, or relying upon the Output as a "consumer report", or using the Service for any FCRA-regulated eligibility decision (US credit, employment, insurance, housing/tenancy, or other eligibility). Garuna is not a consumer reporting agency and the Service is not a consumer report.
- Using the Output as a "consumer report" or for any decision governed by Canadian provincial consumer-reporting or credit-reporting legislation (for example, the Ontario Consumer Reporting Act).
- Using the Output to make eligibility determinations of the kind those regimes govern — including the employment-eligibility decisions described in §2.1 — whether or not the Client is itself subject to them.
- Using the Service or the Output to determine, or to inform the determination of, a Subject's eligibility for credit, employment, tenancy or housing, insurance, or any other benefit, licence, or service that is, or could be treated as, a consumer-reporting, credit-reporting, or "eligibility" purpose under the FCRA, the Ontario Consumer Reporting Act, or any comparable regime. No-adverse-action covenant. You covenant that you will not take, deny, or modify any adverse action against a Subject — including denying or revoking credit, employment, tenancy, insurance, or any benefit, licence, or service — in whole or in part on the basis of the Output.
5.4 Re-identification, aggregation & profiling abuse
- Combining the Output with other data to re-identify, de-anonymise, or aggregate information in order to build a profile for any prohibited purpose in this §5.
- Constructing or maintaining standing watchlists, scoring systems, or population-level datasets that are untethered from a current, case-specific, lawful due-diligence purpose.
5.5 Commercial redistribution
- Selling, licensing, sublicensing, syndicating, or redistributing raw Output, Reports, or exported data as a data product or data feed, or otherwise commercialising the Output as a standalone information service. Reports are intelligence to inform the Client's own lawful due diligence, not inventory for resale.
5.6 Authentication, scraping & platform abuse
- Attempting to crack, guess, bypass, defeat, or circumvent the authentication of any platform or website, or directing the Service to do so. At the credential layer, the Service never cracks, guesses, or bypasses authentication; an Investigation Session reuses only a session you created by signing in yourself, and you must not attempt to make it do otherwise. Note, however, that reuse of a logged-in session to read content a platform gates behind login — or to retrieve a Subject's profile photo or public engagement graph through that session — may still violate the platform's terms even though authentication is not bypassed. The Authorised User bears that risk (see §6).
- Scraping, harvesting, or collecting beyond what the Service performs in its ordinary operation — including driving the Service, or any account or session connected to it, to extract data in a manner that breaches a platform's terms or technical controls.
- Scraping, crawling, spidering, or data-mining the Service itself, its interfaces, or its sources, and using any Output, Report, or other data obtained from the Service to train, fine-tune, develop, evaluate, or improve any artificial-intelligence or machine-learning model, dataset, or system, whether by you or any third party.
- Using any account that is not your own or not duly authorised for an Investigation Session; sharing, pooling, or trafficking in credentials; or connecting an account you are not entitled to use.
- Accessing, using, submitting, or seeking to obtain private, confidential, stolen, leaked, hacked, or otherwise unlawfully obtained data; pretexting, social engineering, impersonation, or any other deceptive means to obtain information about or access to a Subject or any account; or otherwise circumventing or defeating authentication, access controls, or technical protection measures of any platform, system, or source.
5.7 Unlawful, infringing & malicious use
- Any use that is unlawful, that infringes intellectual-property, privacy, publicity, confidentiality, or contractual rights, or that breaches any applicable law, regulation, sanction, or court or regulatory order.
- Introducing malware, or using the Service to facilitate intrusion, exfiltration, or any malicious or fraudulent activity.
5.8 Service integrity & overload
- Overloading, flooding, or abusing the Service or its infrastructure — including excessive, automated, or high-volume request patterns that degrade availability or stability for others.
- Probing, scanning, reverse-engineering, or attempting to defeat the security, rate limits, access controls, or usage gates of the Service, or interfering with its operation.
- Circumventing or attempting to circumvent the in-product safeguards, including the identity-resolution / same-name-exclusion logic, the citation gate, the accuracy and sanctions banners, or the consent gates.
6. Platform-Terms Responsibility for Investigation Sessions
An Investigation Session is established when you sign in yourself to your own — or a duly authorised investigation ("burner") — account on a supported platform, through a real, visible browser login. The Service then reuses that logged-in session to read information about the Subject — for example, the Subject's public engagement graph (follows, likes, replies, boosts) on X and Instagram, and the Subject's authenticated profile photo on any connected platform (including LinkedIn). The supported platforms are X, Instagram, LinkedIn, Facebook, and Reddit. At the credential layer the Service never cracks, guesses, or bypasses authentication — it reuses only the session you established by signing in yourself.
Per-platform risk warning. Authenticated, automated, or session-reuse access — and the use of investigation or "burner" accounts — is restricted or outright prohibited by the terms of service of several supported platforms. LinkedIn and the Meta properties (Facebook and Instagram) are the most aggressive in prohibiting automated access and non-genuine accounts, and reuse of a logged-in session to read or retrieve gated content (including profile photos) may breach a platform's terms even though authentication is not bypassed. This risk rests with you, not Garuna.
For every Investigation Session, you acknowledge and agree that:
- You use only your own account, or an account you are duly authorised to use. You must not use a misappropriated, purchased, shared, or otherwise unauthorised account.
- You are solely responsible for compliance with the relevant platform's Terms of Service and other applicable terms, policies, and law, for whichever platform you actually connect (X, Instagram, LinkedIn, Facebook, or Reddit). Authenticated or session-reuse reads of a platform may breach that platform's terms; that risk and responsibility rest with you, not Garuna.
- You will not share or expose your credentials. For browser-session platforms, the Service holds the Session State (authentication cookies) in process memory only — it is never written to disk, never logged (only a cookie count is logged), and never serialised into a Report or export — and you may disconnect a Session at any time. Separately, where you authenticate the optional authenticated-lookup credential against a major email/account provider (the analyst's own credential, not Subject data), that credential is stored on disk in its own credential file for as long as the authenticated state persists; this is a distinct, persistent credential store and is described in the Privacy Policy. This privacy-protective handling does not transfer to you any authority you do not otherwise hold over the relevant account or platform.
This responsibility is allocated to the Client and the Authorised User and must be acknowledged at the in-app Investigation Session gate before any Session is used. The in-app acknowledgement covers whichever platform the Authorised User actually connects.
7. Reporting Misuse
If you become aware of any actual or suspected breach of this AUP — including credential compromise, unauthorised use of the Service, or use of the Output for a prohibited purpose — report it promptly to [email protected], or for privacy and data-protection concerns to [email protected].
8. Consequences of Breach
A breach of this AUP is a breach of the Terms. Without limiting any other right or remedy available to Garuna at law, in equity, or under the Terms, Garuna may:
- suspend or throttle any Authorised User's or the Client's access to the Service, immediately and without prior notice where Garuna reasonably considers the breach to be ongoing, serious, unlawful, or a threat to any person, to a third-party platform or source, or to the Service or its other clients;
- terminate the Client's access and the Terms in accordance with their terms;
- revoke or disconnect any Investigation Session, account, or credential involved; and
- report the conduct to the relevant platform, source, regulator, or law-enforcement authority where Garuna is required to do so by law or reasonably considers it necessary or appropriate.
The Client remains responsible for all use of the Service under its account and for the indemnities set out in the Terms, including in respect of unlawful use, breach of this AUP, absence of a lawful basis, and breach of any platform's Terms of Service. Reinstatement after a suspension is at Garuna's discretion and may be conditioned on remediation and assurances of compliance.
9. Changes to this AUP
Garuna may update this AUP from time to time. Material changes will be notified in accordance with the change and notice provisions of the Terms. Continued use of the Service after an update takes effect constitutes acceptance of the updated AUP. This AUP should be read together with the Terms, the Privacy Policy, the DPA, the Disclaimers & Legal Notices, and the Sub-processor List, each of which forms part of the same contractual stack.
Garuna Group — Enhanced Due Diligence (EDD) · Acceptable Use Policy · Version 1.2 · Effective 2026-09-02 · Governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. This AUP is incorporated into and forms part of the Terms of Service / Master Services Agreement.