Platform Safety
Acceptable Use Policy
Rules that prevent spam, unsafe use, credential abuse, PHI leakage, and platform misuse.
Last updated May 31, 2026
Status: Draft for legal review Document key: acceptableUsePolicy Version: 2026-05-31
This Acceptable Use Policy applies to Happy Light AI customers, users, administrators, referral partners, and anyone accessing the platform.
1. No Illegal or Harmful Use
Users may not use Happy Light AI to violate law, regulation, professional obligations, privacy rights, telecom rules, platform rules, carrier rules, or payment processor rules.
2. No Spam or Abusive Communications
Users may not use the platform for spam, unsolicited robocalls, deceptive texts, harassment, threats, phishing, impersonation, or unlawful advertising.
3. No Unauthorized Access
Users may not attempt to bypass authentication, access another tenant's data, reveal credentials without authorization, reverse engineer the service, probe infrastructure, or interfere with security controls.
4. No Improper PHI Handling
Users should not enter patient information into public pages, referral pages, general contact forms, or non-secure channels. Clinic users may access patient information only where authorized by the clinic and necessary for their role.
5. No Misleading Healthcare Claims
Users may not represent that Happy Light AI provides clinical advice, diagnoses, prescriptions, emergency medical services, insurance verification, benefits confirmation, claim submission, or guaranteed treatment outcomes.
6. No Credential Misuse
Open Dental CustomerKeys, Secret Manager references, dashboard tokens, payment credentials, and phone provider credentials must be protected. Users may not share or store secrets outside approved workflows.
7. Resource Abuse
Users may not intentionally overload the platform, create artificial traffic, abuse call volume, scrape data, automate requests beyond documented limits, or attack infrastructure.
8. Enforcement
Happy Light Tech may suspend, restrict, or terminate access immediately if it detects violations, suspected fraud, security risk, patient safety risk, platform abuse, or payment risk.
