Acceptable Use Policy
This Acceptable Use Policy (“AUP”) applies to every use of the bdx-mcp service, including every third-party AI client that you authorize to access BDX data on your behalf. By accepting this AUP, you confirm that you are authorized by your organization to connect BDX data to AI tools and that you agree to the responsibilities described below.
1. Your data-governance responsibility
You are responsible for ensuring that your use of BDX data with any AI client complies with:
- Your organization's internal data-governance, privacy, information-security, and acceptable-use policies;
- Any contractual obligations you have with building owners, tenants, or other parties whose facilities the BDX data describes;
- All applicable laws and regulations in the jurisdictions where your organization operates, including data-protection laws (e.g. GDPR, CCPA), sector-specific rules, and any export-control or sanctions regimes.
BuildingLogiX does not pre-clear AI clients for any particular regulatory regime, customer policy, or building-owner contract. Before connecting an AI client to your tenant, satisfy yourself that doing so is permitted under the rules that apply to you.
2. How AI clients use your data
When you authorize an MCP client, that client will issue queries to bdx-mcp on your behalf and receive responses that may include building names, addresses, equipment metadata, time-series readings, and other operational information from your BDX site. The AI client provider — not BuildingLogiX — controls:
- How long that data is retained in chat history or vector stores;
- Whether that data is used to train, fine-tune, or evaluate the provider's models;
- Whether that data is shared with sub-processors or used to generate analytics across the provider's customer base;
- What controls (enterprise tenancy, data-residency, zero-retention modes) are available to your organization.
Review the AI client provider's data-processing terms before you connect. Enterprise tiers of providers like Anthropic, OpenAI, Microsoft, and Google typically offer stronger contractual protections than free or consumer tiers — choose accordingly.
3. No endorsement of any AI client
The bdx-mcp setup guides list third-party AI clients that have been tested against the Service. Inclusion in those guides is a statement of technical compatibility only, not an endorsement of any provider's data, privacy, or security practices for your use case.
4. Prohibited conduct
You agree not to use the Service or any connected AI client to:
- Access BDX data belonging to a tenant or building you are not authorized to access;
- Attempt to bypass the Service's authentication, authorization, tier gating, or rate-limit controls;
- Probe, scan, or test the vulnerability of the Service or any system it connects to except under a written authorization from BuildingLogiX;
- Send abusive, unlawful, or otherwise prohibited content through any field, including tool arguments and free-text search inputs;
- Use the Service or its outputs in a way that could interfere with the safe operation of any building system or life-safety control;
- Resell, sublicense, or expose the Service to parties outside your organization without prior written permission.
5. Safety-critical use is out of scope
bdx-mcp is a read-oriented analytics interface. It is not a certified building-management or life-safety system. Do not rely on its outputs — or on any AI-generated interpretation of those outputs — as the sole basis for life-safety, regulatory compliance, or emergency-response decisions. Use the BuildingLogiX BDX control surfaces or your BMS for those decisions.
6. Reporting concerns
If you become aware of a violation of this AUP, a suspected security incident, or a data-handling concern with a connected AI client, report it promptly to technical.support@buildinglogix.net. We may suspend an AI-client registration or user pending investigation.
7. Updates
This AUP is part of the Terms of Service. When we make substantive changes we bump the policy version and require each active user to accept the updated documents on next sign-in.
Effective May 22, 2026.