Lawful and authorised use
You must use the Service lawfully and have authority for your data, content, domains, destinations and connected accounts. Provide required notices, obtain necessary consents and respect privacy, intellectual property, consumer, advertising and electronic-marketing laws. You remain responsible for your users and anyone acting for you as provided in the Terms.
Do not use the Service for fraud, phishing, impersonation, unlawful surveillance, harassment, exploitation, malware, unsolicited unlawful messaging or infringement. Do not disguise prohibited content or destinations to evade lawful review or platform rules. Legitimate bot or scanner filtering is permitted where lawful and not used for deception or evasion.
Protecting the Service
Do not gain unauthorised access, steal credentials, interfere with another tenant, introduce malicious code or disrupt the Service. Do not bypass access controls, security measures, disclosed usage limits or rate limits, or create deceptive traffic, accounts or events to manipulate billing, attribution or other users' results.
Do not scan or test security without our written permission, except where applicable law gives a right that cannot be restricted. Do not reverse engineer, decompile or extract the Service except to the extent a restriction is prohibited by law. Use documented interfaces and authorised integration methods; do not scrape or extract data you have no right to access.
Ordinary evaluation and benchmarking for your business are permitted. Obtain written consent before publishing tests of non-public features or using access to copy protected technology or confidential information. Nothing here restricts truthful statements, lawful comparisons or statutory rights that cannot be restricted.
Domains and hosted content
Connect only domains and websites you own or are authorised to control. Maintain required permissions and stop using a connection when that authority ends. You are responsible for DNS changes, destination pages, hosted material and permissions for content you submit.
We may request reasonable evidence of authority and restrict disputed or harmful connections under the Terms. We do not undertake to detect every unlawful destination, verify every ownership claim or approve your content by allowing it to remain available.
Data restrictions
Send only personal data reasonably needed for an authorised feature. Do not put passwords, authentication secrets, payment-card details, government identifiers, biometric identifiers, precise location data or other sensitive information into event fields, URLs, logs or uploaded content without our prior written approval and appropriate safeguards. Credentials required for your Dáva account or an authorised integration must be supplied only through the designated secure interface.
Health information and children's personal data require our prior written approval before submission or collection. The same applies to other legally sensitive categories, including racial or ethnic origin, religious or political beliefs, trade-union membership, genetic information, sex life or sexual orientation, and criminal-offence information. Approval does not replace any lawful basis, consent, contract or additional protection required by law.
A website operating in a regulated sector is not prohibited merely because of that sector if the implementation does not send restricted information and otherwise complies with this policy. For lawful adult content, gambling, alcohol or political activity, you must hold required permissions and apply legally required age, location and advertising controls.
New features and AI
These rules also apply to new features, integrations and any AI functionality we introduce. You must have rights to submitted inputs and use outputs lawfully. This policy does not itself authorise us or another provider to train models on customer personal data; the Terms, Privacy Policy, DPA and any valid additional arrangement govern data use.
Agency use and resale
Authorised agency use for clients is permitted under the Terms. Reselling access, white-labelling or sublicensing the Service requires a separate written agreement unless your plan or Order Form expressly permits it.
Enforcement and reporting
We may investigate reasonably suspected misuse, request information, restrict affected activity or suspend or terminate access as permitted by the Terms. We will act proportionately to the risk and give notice and an opportunity to address the issue where reasonably practicable, unless urgent action, security or law prevents it. Nothing here overrides a non-excludable right or remedy.
We may preserve relevant evidence and disclose it where reasonably necessary and lawful to protect the Service, address misuse or comply with legal obligations. This is not permission to use customer personal data outside the DPA or applicable law.
Report security concerns to [email protected] and other misuse to [email protected]. Changes to this policy follow the Terms' change provisions and do not retrospectively make previously permitted conduct a breach.