This policy applies to everyone who uses the Karsenics platform: client organizations and their staff and volunteers, and participants who register through it. It is incorporated by reference into the Master Services Agreement and the Platform Terms of Use. Breaking it is a breach of whichever of those applies to you.

1. Technical conduct

You will not:

  • probe, scan, or test the vulnerability of the platform or any connected system, or breach or attempt to breach any authentication or access control, without Karsenics' prior written authorization;
  • run load tests, stress tests, or high-concurrency simulations against the platform without Karsenics' prior written agreement on timing and scope;
  • reverse engineer, decompile, disassemble, or attempt to derive the source code of the platform, except to the extent that restriction is unenforceable under applicable law;
  • use bots, spiders, crawlers, scrapers, or any automated means to access, extract, or index platform pages or data, other than through features Karsenics provides for that purpose;
  • attempt to access another organization's tenant, another participant's record, or any data you were not given access to;
  • circumvent capacity limits, registration windows, inventory pools, pricing bands, sold-out states, or payment;
  • introduce malware, ransomware, or any harmful code;
  • interfere with, overload, or disrupt the platform, its infrastructure, or its email delivery;
  • misrepresent your identity or your affiliation with any person or organization; or
  • remove, obscure, or alter any proprietary notice.

Coordinated security testing is welcome. If you want to test the platform's security, email legal@karsenics.com first and we will scope it with you. Unauthorized testing is not research, it is an incident.

2. Content and data

You will not upload, submit, store, or transmit through the platform:

  • unlawful, infringing, defamatory, or fraudulent content;
  • content that harasses, threatens, or incites violence against any person or group;
  • sexually explicit content, or any content that sexualizes a minor;
  • personal data you have no lawful basis to provide, including data about other people collected without notice or consent;
  • government identification numbers, financial account numbers, or health or medical records. The platform is not designed to hold these and organizations must not configure custom questions that ask for them;
  • forged, altered, or knowingly expired certificates, permits, licences, or insurance documents;
  • another organization's confidential information; or
  • content that violates a third party's intellectual property, publicity, or privacy rights.

Organizations are responsible for the custom questions they add and for the content they publish on their registration pages.

3. Communications

You will not use the platform to send unsolicited commercial messages, to message anyone from whom you lack a lawful basis, or to message anyone who has opted out. The Messaging Compliance Addendum sets out the full obligations for organizations. Participants must not use platform messaging features to solicit other participants.

4. Commercial conduct

4.1 Eligibility. The platform is for nonprofit and civic organizations running their own community events. It is not for corporate, private, or for-profit events, or for events run on behalf of a commercial promoter or a political campaign committee.

4.2 No resale. Organizations will not resell, sublicense, or operate the platform as a service for another organization.

4.3 No fee evasion. Organizations will not restructure registrations, split transactions, route participants off-platform, or misclassify paid registrations as $0.00 in order to avoid the platform fee. A genuine in-kind space, comped participant, or community-rate placement recorded with an honest reason is exactly what the $0.00 category is for and is not fee evasion. Deliberately misrecording paid participation is.

4.4 No scalping. Participants will not resell a registration, booth, space, or lineup position without the organization's written permission.

5. Artificial intelligence features

Where the platform offers AI-assisted features, you will not use them to generate unlawful content, to impersonate a real person, or to produce content you then present as human-authored where doing so would be deceptive. You are responsible for reviewing anything an AI feature produces before you publish or send it. The Karsenics AI Governance and Acceptable Use Policy describes how those features handle data.

6. What happens if you break this

6.1 Karsenics may investigate, may require you to stop, and may remove offending content.

6.2 Karsenics may suspend or terminate access, and may terminate the Master Services Agreement under its termination-for-cause provisions.

6.3 Proportionality. Karsenics will use the least disruptive response that addresses the problem, will give notice where it safely can, and will not take a live event's registration pages down over a policy dispute that is not a security or legal emergency. An immediate, no-notice suspension is reserved for active security threats, ongoing unlawful activity, and legal compulsion.

6.4 Karsenics may report unlawful activity to law enforcement and will comply with valid legal process.

6.5 Nothing here limits any other remedy Karsenics has.

7. Reporting

Report abuse, security issues, or violations to legal@karsenics.com. Include what you saw, where, and when. We acknowledge reports within five business days, and security reports within one business day.

8. Changes

We may update this policy. Material changes are notified to organizations 30 days in advance under Section 13.9 of the Master Services Agreement.

Karsenics PBC · legal@karsenics.com · 3120 Southwest Fwy, Ste 101, PMB #803188, Houston, TX 77098-4520

© 2026 Karsenics PBC. All rights reserved.