Legal

Acceptable Use Policy

What may not be done with the platform — by people, by API keys, and by the agents our customers configure.

Last updated: 4 September 2026

This Acceptable Use Policy (“AUP”) forms part of the Customer Terms of Service. It applies to every user of SalexHub, and to every automated actor — API key, integration, workflow or AI agent — acting under a workspace.

You are responsible for compliance by everyone and everything acting under your workspace, including agents you grant autonomy to. “I did not press the button myself” is not a defence when you configured the actor that did.

1Content and conduct

Do not use the platform to store, send, publish or process content that:

  • is unlawful under any law applicable to you or to us, or that promotes unlawful activity;
  • infringes intellectual property, privacy, publicity or contractual rights of others;
  • sexually exploits or endangers children, or depicts non-consensual sexual conduct;
  • harasses, threatens, defames or incites violence or hatred against a person or group;
  • misrepresents its origin — impersonating a person or organisation, forging headers, or presenting AI output as the statement of someone who did not make it;
  • constitutes fraud, deceptive commercial practice, a pyramid or Ponzi scheme, or unlicensed financial or gambling activity; or
  • contains malware, exploit code or credentials obtained without authorisation.

2Messaging and outbound

Email and messaging carry the strictest rules, because their abuse harms every other customer's deliverability.

  • Send only to recipients from whom you have consent or with whom you have a lawful basis and a genuine business relationship, as required by the law of the recipient's country (including GDPR and ePrivacy rules, CAN-SPAM, CASL, and UAE telecommunications regulation).
  • Do not send to purchased, rented, scraped or harvested lists.
  • Identify yourself accurately: a real sender name, a working reply address, and your postal or business identity where the law requires it.
  • Include a working unsubscribe mechanism in marketing messages, honour opt-outs promptly, and never re-import a suppressed address to defeat a suppression.
  • Do not use the platform to relay mail for a third party, to send on behalf of a domain you are not authorised to use, or to evade the sending limits or authentication of another provider.
  • Do not use deceptive subject lines, hidden text, or pixel tracking in a jurisdiction where it requires a consent you do not have.

3Security and integrity

Do not:

  • attempt to gain unauthorised access to the platform, another workspace, another tenant's data, or any underlying infrastructure;
  • probe, scan or test the vulnerability of the platform except under the responsible-disclosure terms in the Security Overview;
  • interfere with service to any user — denial of service, flooding, resource exhaustion, or deliberately abusive query patterns;
  • circumvent authentication, rate limits, entitlement checks, usage metering, permission or field-level restrictions, or a deployment licence or watermark;
  • use the platform to scan, attack or send unsolicited traffic to third-party systems; or
  • introduce code intended to disrupt, damage or gain unauthorised access to any system.

4Use of the platform itself

Do not:

  • share a single user seat between individuals, or create accounts to evade limits, suspensions or pricing;
  • resell, sublicense or provide the platform to third parties except under the Partner Program Terms;
  • scrape the platform, or extract data other than through the export and API features provided;
  • use the platform to build a competing service, or to train a machine-learning model on the platform's behaviour, output or interface;
  • misrepresent your relationship with us, or use our name, marks or brand in a way that implies endorsement without our written consent; or
  • store, in workspace fields, categories of data the Customer Terms of Service exclude — such as payment card numbers, government identity numbers, or health data — without a written agreement with us.

5Automated agents

The platform lets you give agents real capability. With it come specific rules:

  • Do not configure an agent to do anything a person may not do under this policy. Autonomy does not create permission.
  • Do not use agents to generate messages at a volume, or with a personalisation, designed to disguise bulk unsolicited outreach as individual correspondence.
  • Do not deploy agents that impersonate a specific real person, or that deny being automated when asked directly, where the law or the context requires disclosure.
  • Do not use agents to make consequential decisions about individuals — employment, credit, housing, insurance, education or access to essential services — without meaningful human review.
  • Keep human approval enabled for irreversible actions unless you have assessed and accepted the risk of the actor you are authorising.
  • Do not attempt to use agents, prompts or connectors to extract another tenant's data, our system prompts, or credentials.

6Tracking, forms and embedded components

If you use our tracking snippet, forms, hosted pages or embedded components on your own website, you must:

  • publish your own privacy notice describing the processing, and obtain any consent your law requires before tracking or before setting anything on a visitor's device;
  • install them only on websites you own or are authorised to operate;
  • not use them to collect special-category data, credentials, or payment card data; and
  • not use them to track individuals across unrelated websites you do not operate.

7Reporting and enforcement

Report suspected abuse to start@salexhub.ai with the subject “Abuse”, including the workspace, the content and any headers or identifiers you have.

Where we identify a breach, we act proportionately: we usually contact the customer first and give an opportunity to fix it. Where the breach is severe, ongoing, unlawful, or risks harm to others or to the platform, we may suspend a feature, a user, an agent or the whole workspace immediately, remove or disable content, and — where we are legally required — report it to the authorities.

Repeated or wilful breach is a material breach of the Customer Terms of Service and grounds for termination without refund.

This policy is not exhaustive. Behaviour that damages the platform, its users, or third parties may be treated as a breach even where it is not listed, and we will explain our reasoning when we act.