PLATFORM SECURITY, PROHIBITED CONDUCT AND ACCOUNT ENFORCEMENT POLICY
OCEANSKY ENTERPRISES PTY LTD · ABN 54 699 634 387
Effective date: 8 August 2026
1. Purpose and legal status
This Platform Security, Prohibited Conduct and Account Enforcement Policy (Policy) protects the Chance Lab website, applications, accounts, data, systems and related services (Service). It forms part of the legal terms governing the Service and must be read with the Terms of Use, Privacy Policy, Intellectual Property and Permitted Use Policy, AI-Assisted Features and Automated Analysis Statement and other documents incorporated by the Terms of Use.
Nothing in this Policy excludes, restricts or modifies a right or remedy that cannot lawfully be excluded, restricted or modified. Mandatory law prevails to the extent of any inconsistency.
2. User security responsibilities
Users must provide accurate registration information, protect passwords and authentication methods, use reasonable device and network security, keep contact details current and promptly report suspected unauthorised access. An account must not be shared, transferred, rented, sold or made available to another person unless Chance Lab expressly permits it.
Users are responsible for activity performed through their account to the extent caused or authorised by them, but this does not make a user responsible for loss caused by Chance Lab's own failure or for unauthorised activity the user could not reasonably prevent.
3. Access and identity controls
Chance Lab may use email verification, re-authentication, session controls, device or network signals, CAPTCHA, payment confirmation, age or identity checks and other proportionate controls. Access may be delayed or limited while information is verified or a material risk is investigated.
A user must not provide false identity or payment information, impersonate another person, create accounts to evade a restriction, use another person's credentials, or interfere with an authorised verification process.
4. Security abuse and unauthorised access
Users must not gain or attempt to gain unauthorised access to an account, system, administrative area, dataset, source code, credential, token or non-public function; test or exploit a vulnerability without prior written authorisation; introduce malware or harmful code; intercept traffic; defeat authentication; or disrupt availability, integrity or confidentiality.
Good-faith security concerns should be reported privately to the contact in section 16 with enough detail for reasonable investigation. Public disclosure, data access or testing is not authorised merely because a concern is reported.
5. Automated access, scraping and excessive use
Users must not use bots, crawlers, scripts, browser automation, scraping tools or other automated means to access, copy, query or monitor the Service except through an interface expressly authorised by Chance Lab. Users must not evade rate limits, rotate identities or networks to avoid controls, generate excessive traffic, burden infrastructure or reconstruct a protected database.
Chance Lab may set and adjust reasonable technical and usage limits by account, feature, plan, device, network or risk level. A temporary limit does not create an entitlement to a particular capacity or continuous availability.
6. Fraud, payment and commercial misuse
Users must not use stolen or unauthorised payment methods, initiate a dishonest chargeback, manipulate subscriptions or promotions, resell access, conceal a commercial intermediary, create artificial transactions, launder value, or use the Service to facilitate fraud, deception, unlawful gambling or another unlawful activity.
A genuine billing dispute or lawful exercise of a consumer right is not prohibited. Users should provide reasonably requested information so Chance Lab and its payment provider can investigate payment anomalies, refunds, reversals or disputed authority.
7. Harmful, unlawful and misleading conduct
Users must not upload, transmit or use the Service for material that is unlawful, infringing, malicious, deceptive, defamatory, threatening, harassing, discriminatory, privacy-invasive or likely to harm another person or system. The Service must not be used to facilitate underage lottery participation, evade self-exclusion or misrepresent an analysis as an official result, certain prediction or Chance Lab endorsement.
Users must not mislead others about account ownership, Plus status, affiliation, source, accuracy or authority, or use Service materials to solicit money on the basis of claimed guaranteed lottery outcomes.
8. Intellectual property and competitive misuse
Users must not copy protected interfaces or content, remove rights notices, reverse engineer protected methods, extract prompts or configurations, create a substitute database, white-label or resell the Service, or use protected materials or outputs to train, benchmark, fine-tune, validate or develop a competing model, product or service.
These restrictions apply only to the extent permitted by law and do not prevent conduct that mandatory law expressly permits and cannot lawfully be restricted, or conduct authorised in advance in writing by Chance Lab.
9. Monitoring, logging and detection
Chance Lab may use proportionate logging, rate monitoring, integrity checks, fraud signals, security analytics, content filters and manual review to operate and protect the Service, enforce legal terms and meet legal obligations. Relevant information is handled under the Privacy Policy and applicable law.
These controls reduce risk but cannot identify or prevent every misuse, attack, error or unauthorised act. Their use, or review of a particular incident, does not create a duty to continuously monitor every user, device, communication, output, third-party service or external activity.
10. Investigation and cooperation
Where reasonably necessary, Chance Lab may request information, preserve relevant records, review affected activity, restrict data or features, contact service providers, and refer suspected unlawful conduct or credible threats to an appropriate authority. Chance Lab may delay disclosure where notice would compromise security, evidence, another person's rights or a lawful investigation.
Users must not destroy relevant evidence, obstruct a reasonable investigation, retaliate against a reporter or knowingly submit a false security or abuse report. Chance Lab may reject repetitive, abusive or unsupported reports after reasonable assessment.
11. Proportionate enforcement measures
Depending on seriousness, urgency, recurrence and available evidence, Chance Lab may warn a user, require verification or credential reset, invalidate sessions, limit requests, remove or quarantine content, disable a feature, withhold activation pending payment confirmation, temporarily suspend access, terminate an account, block re-registration or take another reasonably necessary protective measure.
Chance Lab may act without advance notice where reasonably necessary to contain an active threat, prevent fraud or harm, protect another person or system, preserve evidence, comply with law or address a serious breach. Where appropriate and lawful, Chance Lab may later provide a general reason, but need not disclose confidential detection methods or information that would weaken security.
12. Account termination and continuing obligations
Termination ends the user's permission to access the Service but does not transfer ownership, erase accrued payment obligations, reverse a completed external transaction or prevent retention required for security, disputes, legal compliance or enforcement. Cancellation, refund and deletion requests remain governed by the applicable policies and law.
Provisions concerning intellectual property, confidentiality, evidence, accrued rights, responsibility, dispute handling and other terms intended by their nature to continue remain effective after restriction or termination.
13. Review and correction
A user who reasonably believes an enforcement action was based on a material mistake may contact Chance Lab using section 16, identify the account and action, and provide relevant information. Chance Lab may require identity or control verification before discussing account details.
Chance Lab will consider a sufficiently supported request within a reasonable period having regard to risk, complexity and legal constraints, but does not guarantee restoration or a particular outcome. It may maintain, vary or reverse an action and correct records where appropriate. Repetitive, abusive or bad-faith requests may be closed.
14. Security limitations and service changes
No online service is completely secure or continuously available. Chance Lab does not guarantee that controls will prevent every attack, interruption, unauthorised access, data loss or third-party failure. Users should maintain reasonable safeguards and not use the Service as the sole repository for information they must independently retain.
Chance Lab may modify controls, providers, architecture, access methods and enforcement procedures where reasonably necessary for security, law, integrity or operations. A material change to this Policy will be communicated as required by law and will not retrospectively remove an accrued mandatory right.
15. Liability and consumer rights
Nothing in this Policy excludes, restricts or modifies the Australian Consumer Law or another guarantee, right or remedy that cannot lawfully be excluded, restricted or modified. Where permitted by law, responsibility is limited to loss reasonably attributable to Chance Lab's own act or omission and is reduced to the extent the user or a third party caused or contributed to the loss.
To the maximum extent permitted by law, Chance Lab is not responsible for loss to the extent caused by prohibited conduct, credential sharing, an unauthorised tool, failure to follow a clear security instruction, false information, obstruction of investigation or an independent third-party act. Where permitted, a remedy for failure to comply with a service consumer guarantee may be limited to resupplying the relevant services or paying the reasonable cost of resupply.