Effective date: July 13, 2026 · Company: Mahlum Innovations LLC d/b/a Chronos
This Acceptable Use Policy ("AUP") is incorporated into the Chronos Terms of Service. Capitalized terms have the meanings given there. Where your firm has signed a Business Associate Agreement (BAA), the BAA governs PHI obligations in the event of conflict.
The Service is for licensed legal professionals and their supervised staff — attorneys, paralegals, legal nurses/consultants, and legal-operations personnel — acting for a law firm or legal organization, for lawful legal-practice purposes in the United States. You must be at least 18, provide accurate registration information, and use the Service only under an account your firm authorizes. Attorneys remain responsible for supervising nonlawyer staff use of the Service consistent with ABA Model Rules 5.1 and 5.3 and applicable state bar guidance.
The Service is not offered to consumers, members of the public, or individuals acting outside of a professional legal-practice context.
You may upload records and case data only where your firm has the legal authority to possess and process them for the matter at hand — e.g., under a client authorization, HIPAA-permitted disclosure, subpoena, or discovery order. Specifically, you must not:
Your firm — not Chronos — is responsible for client consents, HIPAA authorizations, and compliance with professional conduct rules governing its own use of client information, including obtaining any informed consent required by ABA Formal Opinion 512 (2024) and applicable state bar guidance.
You must not:
You must not resell, sublicense, white-label, time-share, or provide the Service (or output generated at volume) to third parties as a competing or rebranded chronology service without Chronos's prior written consent. Serving your firm's own clients with Chronos-assisted work product is permitted and expected.
You must not misrepresent Chronos's compliance posture to courts or clients — Chronos is HIPAA-aligned with a signed BAA on every account and operates a SOC 2 readiness program; we do not hold government "HIPAA certification" (no such certification exists) or a SOC 2 report unless and until one is issued.
You must not use the Service to:
How we act. We may investigate suspected violations (using audit logs and telemetry — we do not read case files except as necessary to provide the Service, investigate a security incident, or as required by law) and may throttle, suspend, or terminate access for violations.
Notice and cure. For material violations, we will notify the firm's admin and, where the violation is curable and poses no security or legal risk to other customers, allow 10 business days to cure before suspension.
Immediate suspension. We may suspend immediately, without prior notice, where reasonably necessary to protect PHI, other customers, or the Service — e.g., credential compromise, attempted cross-tenant access, security probing, or a legal requirement.
Effect on data. Suspension does not delete your data; retention and return of PHI continue to be governed by your BAA and the Terms. Uploading PHI without a signed BAA is a material breach and grounds for suspension.
Reporting. Report abuse or violations to legal@medchronosai.com.
We may update this AUP with 30 days' notice for material changes.
See also: Terms of Service · Privacy Policy · SLA · Security overview