← All legal documents
Version 1.0Effective July 24, 2026sha256 cada2fa5e53474610ba73b9f55c115905b6a97b26e9f9b681f6128b00ed384ee

Dion Health — Acceptable Use Policy

Version: 1.0 Effective Date: July 24, 2026 Last Updated: July 24, 2026

This Acceptable Use Policy (this "Policy") governs use of all Dion Health services and is incorporated into the Master Subscription Agreement (the "Agreement") by reference. Capitalized terms not defined here have the meaning given in the Agreement.

This Policy exists so that the Services stay secure, available, and lawful for every customer. It is in addition to, and does not narrow, the use restrictions in Section 4 of the Agreement.

Dion may update this Policy from time to time to address new risks. Material changes will be posted at /legal/acceptable-use-policy with an updated effective date.


1. Who This Applies To

This Policy applies to Customer, its Affiliates, and every Authorized User. Customer is responsible for its Authorized Users' compliance and for ensuring that anyone accessing the Services under its account is aware of and follows this Policy.


2. Prohibited Conduct

2.1 Unlawful and Harmful Use

Do not use the Services to:

  • violate any applicable law, regulation, or professional standard;
  • infringe or misappropriate any third party's intellectual property, privacy, or publicity rights;
  • store, transmit, or process material that is defamatory, harassing, threatening, obscene, or that depicts or promotes the exploitation of minors;
  • engage in or facilitate fraud, including insurance fraud, upcoding, unbundling, or the submission of claims for services not rendered;
  • discriminate against any individual in violation of applicable civil rights, fair employment, or patient-protection law.

2.2 Security

Do not:

  • attempt to gain unauthorized access to the Services, any account, any other customer's data, or any underlying system or network;
  • probe, scan, or test the vulnerability of the Services, or breach or circumvent any authentication, authorization, rate limit, or security measure, without Dion's prior written authorization under an agreed rules-of-engagement (see Agreement § 4(h));
  • introduce, transmit, or store any virus, worm, ransomware, logic bomb, or other malicious code;
  • interfere with or disrupt the integrity or performance of the Services, or the data of any other customer;
  • share, sell, or transfer credentials or API keys, or permit access by anyone other than the individual to whom the credential was issued.

2.3 Data Handling

Do not:

  • submit Protected Health Information to any Service, module, field, or channel not designated in the Documentation to receive it;
  • submit payment card data, Social Security numbers, or other sensitive identifiers to any field not designated to receive them;
  • submit data you do not have the legal right to submit, or for which required consents or authorizations have not been obtained;
  • attempt to re-identify data that has been de-identified or aggregated;
  • transmit PHI to any recipient, integration, or export destination not covered by an executed Business Associate Agreement.

2.4 Communications and Outreach

Where a Service sends messages, calls, or campaigns on Customer's behalf, do not:

  • send unsolicited commercial messages in violation of the CAN-SPAM Act, the Telephone Consumer Protection Act (TCPA), state mini-TCPA statutes, or applicable anti-spam law;
  • contact any individual who has revoked consent, opted out, or is on an applicable do-not-call list;
  • send messages that misrepresent their sender, origin, or purpose, or that use deceptive subject lines;
  • record any call without providing the disclosures required by applicable law, including all-party consent in states that require it;
  • use patient contact data obtained through the Services for any purpose other than Customer's own permitted communications, and never for sale or transfer to a third party.

Customer is solely responsible for obtaining and maintaining records of consent for every individual it contacts through the Services.

2.5 Capacity and Fair Use

Do not:

  • exceed documented rate limits, or use automated means to generate load beyond ordinary business use;
  • use the Services to run benchmarks, load tests, or stress tests without prior written authorization;
  • bulk-export data in a manner designed to circumvent the Services' intended interfaces;
  • use the Services in a way that imposes an unreasonable or disproportionate burden on Dion's infrastructure, degrades performance for other customers, or is inconsistent with normal use for Customer's licensed quantity.

2.6 Commercial Restrictions

Do not:

  • resell, sublicense, white-label, or provide the Services to any third party, or operate them on a service-bureau or managed-service basis for any practice or entity Customer does not own, manage, or serve under a written agreement disclosed to Dion;
  • use the Services, their output, or information gained through them to build, train, market, or operate a competing product or service;
  • reverse engineer, decompile, or attempt to derive the source code, models, or architecture of the Services;
  • remove or alter any proprietary notice.

2.7 Artificial Intelligence Features

Do not:

  • present AI-generated output as reviewed by a licensed professional when it has not been;
  • rely on AI Feature output for a clinical, billing, employment, or financial decision without the meaningful human review required by Agreement § 12.4;
  • use AI Features to generate content that is deceptive, that impersonates an individual without authorization, or that would violate professional advertising or solicitation rules;
  • submit prompts or inputs designed to extract training data, model weights, system prompts, or another customer's data;
  • use outputs to train, fine-tune, or evaluate any model other than as expressly permitted in an Order Form.

3. Reporting

Report suspected violations, security vulnerabilities, or abuse to security@dionhealth.com. Dion supports good-faith security research conducted under prior written authorization; unauthorized testing is a violation of this Policy regardless of intent.


4. Enforcement

Dion may investigate suspected violations and may suspend or terminate access in accordance with Agreement §§ 14.2 and 14.3. Where practicable and where doing so does not increase risk, Dion will notify Customer and provide an opportunity to remediate before suspending. Where a violation presents an immediate threat to the security, availability, or legality of the Services, Dion may act immediately and without prior notice, and will notify Customer promptly afterward.

Dion may also be required to report certain conduct to law enforcement or regulators. Nothing in this Policy limits any other remedy available to Dion under the Agreement or at law.


Contact

Dion Health Management Company LLC 450 Sutter Street, Suite 1519 San Francisco, CA 94108

  • Abuse and security: security@dionhealth.com
  • Legal: legal@dionhealth.com

All legal documents · legal@dionhealth.com

Dion Health Management Company LLC · 450 Sutter Street, Suite 1519 · San Francisco, CA 94108