Skip to content

Legal & policies

Acceptable use policy

Short, and mostly obvious. It exists so that when something goes wrong there is a written rule rather than an argument.

Last updated 18 August 2026

This policy applies to everyone who uses Pallara — institution staff, learners, and anyone accessing it through an API token. It forms part of the terms of service.

What Pallara is for

Administering, teaching and supporting learners at a tertiary or vocational education provider, and meeting that provider's regulatory reporting obligations. Everything below follows from that.

What is not permitted

  • Unlawful use — anything that breaches New Zealand law, including the Privacy Act 2020, the Harmful Digital Communications Act 2015 and the Copyright Act 1994.
  • Accessing data you are not entitled to — attempting to reach another institution's tenant, another learner's records, or records restricted from you.
  • Circumventing controls — probing, scanning or attempting to bypass authentication, permissions, rate limits or tenant isolation, other than as permitted under responsible disclosure.
  • Harmful content — uploading or sending malware, or material that is harassing, defamatory, or that incites harm.
  • Misusing communications — sending unsolicited commercial messages, or using the email or SMS features for anything other than communicating with your own learners, applicants and stakeholders. Your institution is responsible for compliance with the Unsolicited Electronic Messages Act 2007.
  • Misusing the AI features — attempting to extract another person's information through a model, using the tutor to complete assessed work in breach of your institution's academic integrity policy, or generating content that would breach this policy if uploaded.
  • Degrading the service — automated traffic beyond published limits, load testing without our written agreement, or anything that impairs the service for others.
  • Reselling or reverse engineering — reselling access, or copying, decompiling or reverse engineering the platform.

What we ask of institutions

  • Assign permissions on a least-privilege basis, and remove access when someone leaves.
  • Make sure staff and learners know what this policy requires.
  • Have the authority to provide the personal information you enter, and a lawful purpose for it.
  • Tell us promptly at [email protected] if you suspect an account has been compromised.

How we enforce it

Where we believe this policy has been breached we will normally contact the institution's administrators, describe the problem and give a reasonable period to fix it. We may suspend an individual account or a specific feature immediately where there is an active security risk, a legal requirement, or a risk of harm to a person — and we will tell you as soon as we have.

Persistent or serious breach is a material breach of the terms of service.

Reporting misuse

Security issues to [email protected]. Anything else to [email protected]. If content on the platform is harming someone, say so in the subject line and we will treat it as urgent.