Este documento está disponible solo en inglés, y la versión en inglés es el texto vigente.
Acceptable Use Policy
Effective date: September 10, 2026
Last updated: September 10, 2026
This Acceptable Use Policy ("AUP") describes the rules governing your use of the Service operated by Esqase, Inc. ("Esqase," "we," "us," or "our"). This AUP is incorporated into and forms part of our Terms of Service. Capitalized terms used but not defined here, including "Service," have the meanings given in the Terms of Service. If this AUP conflicts with the Terms of Service, the Terms of Service control.
By accessing or using the Service, you agree to comply with this AUP.
1. Purpose
Esqase is a practice management platform designed specifically for law firms and legal professionals. The Service is intended to be used for lawful legal practice management activities. This AUP sets the boundaries for acceptable use to protect all users, protect Client Data, and maintain the integrity and availability of the Service.
2. Permitted Uses
You may use the Service to:
- Manage contacts, matters, tasks, documents, and billing for your legal practice.
- Communicate with your team through the Service's internal messaging feature, and with your clients and other contacts through the email composer, the communication logs, and the notifications sent by your Public-Facing Features.
- Collect client intake information via lead intake forms.
- Schedule consultations and events with clients.
- Send documents for eSignature and sign them electronically.
- Connect the third-party integrations offered in the Service (for example Gmail, Microsoft Outlook, Google Calendar, Outlook Calendar, Google Meet, Microsoft Teams, and Zoom), subject to each provider's own terms, as described in Section 10 of the Terms of Service.
- Access the Service programmatically through the Esqase Public API within documented rate limits and scopes.
3. Prohibited Activities
You must not use the Service to:
3.1 Unlawful Activities
- Violate any applicable law, regulation, court order, or professional rule.
- Engage in, facilitate, or promote any activity that is illegal in your jurisdiction or the jurisdiction of your clients.
- Process or store data in a manner that violates applicable data protection or privacy laws.
- Use, or permit the use of, the Service in violation of applicable export-control or economic-sanctions laws, or by or for the benefit of a person or entity located in a jurisdiction, or named on a restricted-party list, that those laws cover, as provided in Section 20 of the Terms of Service.
3.2 Harmful or Malicious Activity
- Upload, transmit, or store malware, viruses, Trojan horses, spyware, ransomware, or any other malicious code.
- Attempt to gain unauthorized access to the Service, another user's account, or any computer system or network.
- Conduct denial-of-service attacks, load or stress testing, network or vulnerability scanning, or penetration testing without prior written authorization from Esqase. Section 7 explains how to report a vulnerability and the conditions under which we treat good-faith security research as authorized.
- Interfere with or disrupt the integrity or performance of the Service or any data it contains.
3.3 Unauthorized Data Collection or Surveillance
- Collect, harvest, or scrape data from the Service or its users beyond what is authorized by the Terms of Service, this AUP, and our developer documentation.
- Use the Service to conduct covert surveillance of an individual, or to track an individual's location or activity, where doing so is unlawful or violates the rules of professional conduct that apply to you. This does not restrict lawful investigation, fact-gathering, or record-keeping carried out in the course of representing a client or evaluating a prospective engagement.
- Attempt to re-identify, de-anonymize, or link anonymized or pseudonymized data.
3.4 Misrepresentation and Fraud
- Impersonate another person or entity, or falsely claim an affiliation with any person or organization.
- Provide false or misleading information to Esqase or to your clients through the Service.
- Use the Service to commit fraud, money laundering, or any other financial crime.
3.5 Content Violations
- Upload or transmit content that: is defamatory, harassing, abusive, threatening, or incites violence; attacks or demeans a person or group on the basis of race, ethnicity, national origin, religion, sex, gender identity, sexual orientation, disability, age, or medical condition; infringes upon any third party's intellectual property rights; constitutes unsolicited commercial communications (spam); or violates any person's privacy or dignity.
- Use the Service to produce, store, or distribute child sexual abuse material (CSAM) or any content that sexualizes minors. Where Esqase obtains actual knowledge of apparent child sexual abuse material, online enticement of a child, or child sex trafficking, it reports and preserves that material as required by 18 U.S.C. 2258A.
- Upload, transmit, or publish an intimate visual depiction of an identifiable individual, including a computer-generated or digitally altered depiction, without that individual's consent. This does not restrict a Firm from holding such material in a matter file where it is evidence in, or otherwise necessary to, the representation, provided it is not published or shared through a Public-Facing Feature except as the representation requires.
3.6 Circumvention and Abuse
- Circumvent any usage limits, access controls, or security measures.
- Use the Service in a way that imposes an unreasonable or disproportionate load on our infrastructure.
- Create multiple accounts to circumvent account suspension, subscription limits, or other restrictions.
- Resell or sublicense access to the Service without explicit written authorization from Esqase. This does not restrict your use of features designed to give your clients and other External Users access, such as document sharing and payment pages, as provided in Section 4.5 of the Terms of Service.
- Share, publish, or transfer sign-in credentials, or allow more than one individual to use a single Account, as provided in Section 4.3 of the Terms of Service.
- Access the Service through automated means, or through an interface other than the user interfaces and the Esqase API we make available, including framing, mirroring, or scripted browsers.
- Remove, obscure, or alter any proprietary notice in the Service, or use the Esqase name, logo, or other marks without our prior written permission, including in a way that implies affiliation, endorsement, or partnership.
3.7 Conflict of Interest and Ethical Violations
- Use the Service in a manner that would violate the rules of professional conduct that apply to you, including the rules governing conflicts of interest, confidentiality, client funds and trust accounting, and legal advertising and solicitation.
- Configure or use the Service in a way that discloses privileged or confidential client information to a person not entitled to receive it, for example by sharing a matter, a document, or a Public-Facing Feature link with a recipient who should not have it. You are responsible for the sharing and permission settings you apply.
3.8 Bulk Messaging and Spam
- Send bulk unsolicited commercial messages through the Service, including through connected email accounts (such as Gmail or Outlook), system email, or intake and booking notifications.
- Send commercial email to recipients who have not consented to receive it and with whom you have no existing relationship.
- Continue messaging recipients who have unsubscribed or opted out.
- Use purchased, rented, or harvested recipient lists.
- Send messages in violation of applicable anti-spam, telemarketing, and electronic-marketing laws, including the U.S. CAN-SPAM Act (15 U.S.C. 7701 et seq.), the U.S. Telephone Consumer Protection Act where it applies to calls or text messages you send, and, where personal data is used for direct marketing, the consent requirements of applicable data protection law.
- Send commercial email that omits a valid physical postal address for the sender, a clear indication that the message is an advertisement, or a working way to opt out.
- Falsify or disguise the sender, the reply-to address, the routing information, or the subject line of any message sent through the Service.
4. Public-Facing Features
Public-Facing Features are the features described in Section 8 of the Terms of Service that let your clients and other External Users interact with your Firm, including booking pages, lead intake forms, shared document links, eSignature signing links, and payment pages. When you use them:
- Ensure that all communications are truthful, professional, and compliant with applicable legal advertising and solicitation rules.
- Obtain all required consents before collecting personal information from third parties.
- Set the audience, password, and permission options on each link deliberately. A link you make public can be opened by anyone who has it.
- Do not use these features to engage in any of the prohibited activities listed in Section 3, and do not configure them so that others can.
- For documents you send for signature, follow our eSignature Guidelines.
You are responsible for content that External Users submit through your Public-Facing Features, including files uploaded to your intake forms, to the extent it results from how you have configured and shared those features. If content submitted to your Firm through a Public-Facing Feature violates this AUP, tell us at legal@esqase.com and remove it.
5. API Usage
If you access the Service through the Esqase API at api.esqase.com, Section 9 (API Access) of the Terms of Service applies in full, and:
- Each request must stay within the scopes assigned to the key and the rate limits published in our developer documentation (currently 600 requests per 60 seconds per key).
- API keys must be kept confidential, must not be shared publicly or embedded in client-side code, and must be revoked promptly if compromised.
- Automated use of the API is permitted for integration and automation purposes within those limits. Use through a third-party tool that calls the Service on your behalf is your use, and this AUP applies to it.
- Systematic bulk export, scraping, or reproduction of Service data to build a competing product or service is prohibited.
6. Responsibility for Users of Your Account
You are responsible for ensuring that all Authorized Users under your Firm's account comply with this AUP. A violation by an Authorized User is treated as a violation by the Firm. You are also responsible for the use External Users make of the Service to the extent it results from how you configure and share your Public-Facing Features, as provided in Section 4.4 of the Terms of Service.
7. Reporting Violations and Security Issues
7.1 Reporting a Violation
If you become aware of a violation of this AUP, whether or not you are an Esqase customer, report it to us at legal@esqase.com with the subject line "AUP report." Include the address of the page, message, or link involved, what you observed, and how we can reach you. We investigate every report we receive and act as described in Section 8.
Copyright complaints follow the separate process in Section 12.3 of the Terms of Service.
7.2 Reporting a Security Vulnerability
Report a suspected vulnerability to legal@esqase.com with the subject line "Security disclosure." Include enough detail for us to reproduce the issue.
We will acknowledge your report within 5 business days, keep you informed while we investigate, and credit you if you would like us to. We ask that you give us 90 days from your report before disclosing publicly, and that you contact us if you believe a shorter period is warranted.
Testing must stay within these limits: use only accounts and data you own or have written permission to test; do not access, modify, or retain another Firm's data; stop as soon as you have confirmed the issue; do not run denial-of-service, load, or spam tests; and do not use social engineering or physical attacks. If you follow this section in good faith, Esqase will treat your testing as authorized for the purposes of Section 3.2, will not pursue legal action against you for it, and will say so if a third party asks. Esqase does not currently operate a paid bug bounty program.
8. Enforcement
8.1 No Duty to Monitor
Esqase does not review, pre-screen, or monitor User Content, and has no obligation to do so. Our right to investigate and act under this Section 8 does not create a duty to detect violations.
8.2 What We May Do
Where we reasonably believe this AUP has been violated, we may:
- Investigate. We start from account, log, and configuration data, and we access User Content only where it is necessary to assess or stop a violation or where the law requires it, consistent with Section 5.4 of the Terms of Service and our Data Processing Agreement. We limit that access to the smallest amount of content and the fewest people needed.
- Remove or disable the specific User Content or link that violates this AUP.
- Suspend or terminate access to the Service, in whole or in part, as provided in Sections 18.3 and 18.4 of the Terms of Service.
- Report violations to law enforcement or regulatory authorities where required, or where we reasonably believe it is necessary to prevent serious harm.
8.3 How We Act
We use good judgment and act proportionately. For a violation that does not require immediate action, we will give you notice and at least 14 days to cure before suspending access, as Section 18.3 of the Terms of Service provides. Where we reasonably believe there is a security emergency, illegal content, or conduct that harms or threatens the Service, other customers, or third parties, we may act immediately and without prior notice; we will notify you where practicable and restore access promptly once the issue is resolved.
8.4 Your Data During and After Enforcement
A suspension under this AUP does not delete your data. You may ask us to restore access once the violation is resolved, and you may request an export of your Firm's records while access is suspended. If we terminate your Subscription for a violation of this AUP, Section 18.5 of the Terms of Service governs retention and export, and fees already paid are not refunded, as provided in Section 4.3 of the Billing and Refund Policy.
9. Changes to This Policy
We may update this AUP from time to time. Continued use of the Service after a change takes effect constitutes your acceptance of the updated AUP. Material changes will be communicated in accordance with our Terms of Service.
10. Contact
Questions about this AUP, and reports under Section 7, go to:
Esqase, Inc.
2810 N Church St STE 89268
Wilmington, DE 19802, United States
legal@esqase.com