All legal documents

Acceptable Use Policy

The rules for using Perical, and what happens when they are broken.

Last updated: October 2026

01Purpose and Scope

This Acceptable Use Policy ("AUP") sets out the rules for using Perical. It applies to all users, including event organizers, guests, and administrators. By using the Platform you agree to comply with this AUP, the Terms of Service, and applicable law.

This AUP is intended to protect the Platform, its users, and the events that rely on it. It is not intended to prevent legitimate use, including responsible security research.

02Prohibited Activities

You may not use the Platform to:

  • engage in any unlawful activity;
  • access, or attempt to access, systems, accounts, or data you are not authorized to access;
  • steal, misuse, or facilitate the theft of credentials;
  • introduce or distribute malware, viruses, or other harmful code;
  • conduct or facilitate phishing or social engineering;
  • engage in fraud or deceptive practices;
  • abuse, harass, threaten, or harm other users;
  • impersonate another person or organization;
  • access the Platform through a VPN, proxy, or any other location-concealment service;
  • create or publish an event without completing the required organizer identity verification;
  • operate malicious automation, including credential-stuffing, brute-force attacks, or automated abuse;
  • scrape or harvest data where such activity is prohibited, disrupts the Platform, or collects user data without appropriate consent;
  • send spam, unsolicited bulk communications, or abusive messages;
  • exploit vulnerabilities in the Platform or its users; or
  • interfere with, disrupt, or overload the Platform's infrastructure, services, or users.

03Bypassing Security Controls

You may not bypass, disable, or circumvent authentication, rate limits, authorization, or other security controls on the Platform. You may not probe or test the Platform's security in a way that disrupts the service or affects other users, except as described under Responsible Security Research below.

04Organizer Identity Verification (DigiLocker)

To help prevent fraud, impersonation, and abuse, an organizer must verify their identity through DigiLocker (the Government of India's digital document service) before creating or publishing an event. An event cannot be created until this verification is completed.

Verification is required only for users who host or create events. It is not required to create a normal user account, RSVP, register for, or attend an event as a guest. The verification is used solely to confirm the organizer's identity and eligibility to host.

You may not attempt to bypass, falsify, or share the organizer verification requirement, or present another person's verified identity as your own. Doing so is a serious violation of this AUP and may result in suspension or termination.

05VPN and Anonymizing Services

The use of a virtual private network (VPN), proxy, Tor, or any other service that conceals or changes your location or network origin when accessing the Platform is strictly prohibited. This applies to all users and to every part of the Platform.

We detect the use of such services for security, fraud-prevention, and abuse-prevention purposes. Where we detect that an account is being accessed through a VPN or similar mechanism, we apply an automatic five (5) day account lock. During the lock, the account cannot sign in or use the Platform.

The lock is lifted automatically after five (5) days, after which the account is unbanned and normal access is restored, unless the conduct also warrants separate action under this AUP or the Terms of Service (for example, where the VPN use is combined with other abuse). Repeating the use of a VPN or concealment service may lead to further locks or to suspension or termination.

06Privacy and Data Protection

You may not collect, store, or process personal data of other users without an appropriate basis, nor use data obtained from the Platform for purposes unrelated to the service. Event organizers are responsible for the guest information they add and must have the necessary authority and consents.

07Content Standards

Content submitted to the Platform - including messages, event updates, event information, files, and check-ins - must be lawful and must not infringe third-party rights, including copyright and privacy rights. Content that violates this AUP or applicable law may be removed without notice.

08Rate Limits and API Use

The Platform applies rate limits to protect its services from abuse. You may not attempt to circumvent these limits, including by using multiple accounts, automated tools, or other means. Automated access must be limited to what the Platform reasonably permits and must not degrade service for other users.

09Responsible Security Research

We value the security community and permit responsible, good-faith security research that:

  • is limited to testing your own account or the Platform's public interfaces;
  • does not access or expose other users' data;
  • does not disrupt the availability of the Platform or its services;
  • does not exploit a vulnerability beyond what is necessary to demonstrate it; and
  • is reported promptly and in good faith to security@perical.in.

Responsible research conducted in this manner will not be treated as a violation of this AUP. Research that harms users, accesses data without authorization, or disrupts the service will be treated as prohibited activity.

10Vulnerability Reporting

If you discover a potential vulnerability, please report it to security@perical.in with enough detail for us to understand and reproduce it. Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it.

11Enforcement

Violations of this AUP may result in any of the following, depending on the severity and circumstances:

  • a warning;
  • removal of content;
  • an automatic five (5) day account lock where we detect use of a VPN or other location-concealment service, lifted automatically when the five-day period ends;
  • temporary restriction of access;
  • suspension or termination of accounts; or
  • reporting to relevant authorities where legally required or appropriate.

The five-day lock for VPN or location-concealment use is applied automatically and is lifted automatically at the end of the period; it does not require a manual review to be removed. Other enforcement actions are applied at our discretion based on the severity and circumstances, and they do not automatically expire.

We do not automatically report every violation to authorities; we report where the law requires it or where the circumstances warrant it.

12Reporting Violations

If you believe someone is violating this AUP, please report it to the platform administrators through the appropriate channels, or by contacting us at security@perical.in. We will review reports in good faith.

Questions about this document? Contact us at support@perical.in.