Acceptable Use Policy
Version 2026-08-10Effective 10 August 2026Updated 10 August 2026
- Product
- Calanai Connect
- Published by
- CALANAI HQ LLP
Acceptable Use Policy
1. Purpose and scope
This Acceptable Use Policy ("AUP") governs the use of Calanai Connect (the "Service"). It applies to every customer, every Authorised User, and every person who accesses the Service, and it is incorporated into our Terms of Service. Capitalised terms not defined here have the meaning given in the Terms of Service.
This AUP exists for three reasons: to keep the Service lawful, to protect the people who receive communications sent through it, and to preserve our standing — and yours — with the messaging platforms we depend on. A violation by one customer can result in restrictions affecting all customers.
We may update this AUP from time to time. Material changes will be notified in accordance with the Terms of Service.
2. You are responsible for what you send
You are solely responsible for all content and communications sent from your account, whether composed by a person, configured as an automated response, imported, or generated by automated features. You are equally responsible for the conduct of your Authorised Users.
3. Consent and communication preferences
This is the most frequently violated area, and the one most likely to result in enforcement action against your account.
You must:
- Obtain valid consent from every recipient before sending them communications that require consent under applicable law or under the policies of the relevant messaging platform. Consent must be freely given, specific, informed, and recorded through an affirmative action by the recipient.
- Identify yourself clearly. The recipient must know which business is contacting them, and must have understood at the point of opt-in that they would receive messages from that business on that channel.
- Keep evidence of consent, including its source, method, and date, and produce it on request.
- Honour opt-out requests promptly, however they are expressed — including plain-language requests made in conversation, not only formally-worded ones or button presses.
- Maintain accurate preference records and ensure that opted-out individuals are excluded from all subsequent non-essential communications.
- Respect frequency expectations. Do not send communications at a volume or cadence a reasonable recipient would consider excessive.
You must not:
- purchase, rent, scrape, or otherwise acquire contact lists and message them;
- message individuals who have not opted in, or who have opted out;
- transfer consent obtained by one business to another business, or across unrelated brands;
- use a consent obtained for one purpose to send communications of a materially different nature;
- obscure, disable, or make impractical any opt-out mechanism; or
- re-add an individual who has opted out without a fresh, documented opt-in.
4. Prohibited content
You must not send, store, or process content that:
- Is unlawful under any applicable law, or that facilitates unlawful activity;
- Is deceptive or fraudulent — including phishing, impersonation, false claims about identity, affiliation, price, availability, or outcome, fake urgency, and misleading offers;
- Harms or harasses — including content that is threatening, abusive, harassing, bullying, or that incites violence or self-harm;
- Is hateful or discriminatory — including content attacking or demeaning individuals or groups on the basis of race, ethnicity, national origin, caste, religion, sex, gender identity, sexual orientation, disability, age, or any other protected characteristic;
- Is sexually explicit, or sexualises minors in any way;
- Infringes intellectual property, including copyright, trademark, and trade secret rights, or misappropriates another's likeness or identity;
- Violates privacy — including disclosing another person's personal data without a lawful basis, or publishing private information without consent;
- Contains malicious code, or links to sites hosting malware, exploits, or deceptive downloads; or
- Is prohibited by an applicable messaging platform, including the categories restricted under the WhatsApp Commerce Policy and Business Messaging Policy.
5. Prohibited goods, services, and use cases
You must not use the Service in connection with:
- illegal drugs, controlled substances, or drug paraphernalia;
- tobacco, vaping, and nicotine products, and alcohol, except where expressly permitted by applicable law and the relevant platform's policy and subject to required age controls;
- weapons, ammunition, explosives, and related accessories;
- live animals, endangered species, and products derived from them;
- adult content, adult services, and sexual services;
- gambling, betting, lotteries, and games of chance, except where expressly licensed and permitted;
- unlicensed financial services, high-risk investment schemes, cryptocurrency promotion of a speculative or unlicensed nature, pyramid or multi-level marketing schemes, and get-rich-quick offers;
- predatory lending, unlicensed debt collection, and abusive collections practices;
- medical or health claims that are unapproved, unsubstantiated, or misleading, and prescription medicines offered without lawful authorisation;
- counterfeit, stolen, or otherwise illegally traded goods;
- forged documents, false identification, and academic or professional credential fraud; or
- any other category prohibited by applicable law or by a messaging platform on which the Service operates.
6. Data protection and privacy
You must:
- have a valid lawful basis for every processing activity you carry out through the Service;
- provide the privacy notices required of you under applicable law;
- collect only data that is relevant and necessary for your stated purpose;
- honour data subject rights requests you receive; and
- ensure any third-party system you connect to the Service is one you are authorised to connect.
You must not:
- process sensitive or special categories of personal data through the Service — including health, biometric, genetic, financial account credentials, precise location, caste, religion, political affiliation, sexual orientation, or trade union membership — without our prior written agreement and an appropriate lawful basis;
- direct communications at children, or process children's data, without the verifiable parental consent required by applicable law;
- use the Service to conduct surveillance, tracking, or profiling of individuals in a manner they would not reasonably expect;
- use data obtained through the Service for any purpose other than serving the individuals concerned — in particular, you must not resell, license, or otherwise commercially exploit End Customer data; or
- combine data obtained through the Service with external data sources in a way that violates applicable law or the individual's reasonable expectations.
7. Security and technical conduct
You must not:
- attempt to gain unauthorised access to the Service, other customers' accounts or data, or any underlying system or network;
- circumvent or attempt to circumvent authentication, authorisation, tenant separation, rate limits, quotas, or other technical controls;
- probe, scan, or test the vulnerability of the Service, or breach or attempt to breach its security, except under a written authorisation from us;
- introduce viruses, worms, malicious code, or any other harmful component;
- conduct denial-of-service attacks, or generate load intended or reasonably likely to degrade the Service for others;
- use automated means to access the Service in a manner that exceeds documented API limits or that we have not authorised;
- reverse engineer, decompile, or disassemble the Service, except to the extent this restriction is unenforceable under applicable law;
- share credentials between individuals, or permit access by anyone who is not an Authorised User; or
- misrepresent your identity or the origin of traffic, including by spoofing headers or falsifying sender information.
8. Commercial restrictions
You must not:
- resell, sublicense, rent, lease, or otherwise make the Service available to third parties, except under a written reseller or partner agreement with us;
- use the Service to build, train, or improve a competing product or service;
- publish benchmarks or performance comparisons of the Service without our prior written consent; or
- use the Service in a manner designed to circumvent usage-based fees or platform charges.
9. Automated features
Where you use automated or artificial intelligence features:
- you must review and test the automated behaviour you configure before deploying it to real recipients;
- you must not present automated output as professional, legal, medical, or financial advice;
- you must not configure automation to deceive recipients about whether they are interacting with an automated system, where disclosure is required by law;
- you must maintain a practical means for recipients to reach a person, and must respond when they ask for one; and
- you remain fully responsible for automated output sent from your account.
10. Reporting violations
If you become aware of a violation of this AUP — whether by you, one of your Authorised Users, or another party — report it to support@calanaihq.com.
To report a security vulnerability, contact security@calanaihq.com. We will not pursue action against good-faith security research conducted responsibly, carried out without accessing, modifying, or exfiltrating other parties' data, and reported to us promptly and privately.
11. Enforcement
We may investigate suspected violations and may take any action we consider appropriate and proportionate, including:
- issuing a warning and requiring remediation within a stated period;
- restricting or throttling specific features, message types, or volumes;
- removing or blocking specific content or communications;
- suspending affected Authorised Users or the account, in whole or in part;
- terminating the Agreement in accordance with the Terms of Service; and
- reporting the matter to a messaging platform, a regulator, or law enforcement where we are required to do so or where we consider it necessary.
Where practicable, and where the violation is capable of cure and does not present an immediate risk, we will notify you and provide a reasonable opportunity to remedy it before suspending access. Where a violation presents a risk of harm, legal exposure, or a threat to the Service or to our standing with a messaging platform, we may act immediately and notify you afterwards.
Enforcement action under this AUP does not entitle you to a refund and does not relieve you of your obligation to pay fees.
Our decision not to enforce a provision in any instance is not a waiver of our right to enforce it later.
12. Messaging platform policies
The Service operates on third-party messaging platforms, each of which imposes its own rules. Compliance with those rules is your responsibility, and they apply in addition to this AUP. Where a platform's rules are stricter than this AUP, the stricter rule applies. For WhatsApp, these include the WhatsApp Business Messaging Policy and the WhatsApp Commerce Policy.
13. Contact
| Purpose | Contact |
|---|---|
| Report abuse or an AUP violation | support@calanaihq.com |
| Report a security vulnerability | security@calanaihq.com |
| Questions about this policy | support@calanaihq.com |