This Policy forms part of the GateBud Master SaaS Agreement.
1. Purpose
This Acceptable Use Policy (Policy) sets out the rules for using the GateBud platform and Services. Its purpose is simple: to keep the Services safe, reliable, lawful and fair for everyone who uses them.
This Policy forms part of the GateBud Master SaaS Agreement (the Master Agreement). It protects GateBud's systems and infrastructure, protects other customers, and helps prevent illegal or abusive use. Capitalised terms used but not defined here have the meaning given in the Master Agreement.
Breaching this Policy is a breach of the Master Agreement, and may lead to the enforcement steps in section 8.
2. Scope
This Policy applies to everyone who accesses or uses the Services, including:
- Customers;
- administrators;
- the Customer's employees and contractors;
- authorised Users; and
- anyone else accessing the Services under, or with access provided through, a Customer account.
The Customer is responsible for ensuring that everyone using the Services under its account complies with this Policy. A breach by any of those people is treated as a breach by the Customer.
3. Permitted use
The Services may be used only:
- for legitimate business purposes;
- in accordance with all applicable laws (including New Zealand law); and
- in accordance with the Master Agreement, this Policy and the Documentation.
Anything outside this is not permitted.
4. Prohibited activities
The following activities are prohibited. The examples below are illustrative, not an exhaustive list.
4.1 Security
- Attempting to gain unauthorised access to the Services, other accounts, or the systems and networks used to provide the Services.
- Circumventing, disabling or interfering with any authentication or security measure.
- Port scanning, vulnerability scanning, or penetration testing of the Services without GateBud's prior written approval.
- Reverse-engineering, decompiling or disassembling the Services or underlying software, or attempting to extract or derive source code, except to the extent this restriction cannot be excluded by law.
- Attempting to bypass, remove or tamper with any licensing, usage or access controls.
4.2 Platform abuse
- Interfering with, degrading or disrupting the availability, integrity or performance of the Services.
- Making excessive or abusive automated requests, or using bots or scripts in a way that adversely affects the Services or other customers (except through interfaces GateBud makes available for that purpose).
- Carrying out, or participating in, any denial-of-service (DoS or DDoS) attack.
- Introducing or transmitting malware, viruses, worms, or other harmful code or scripts.
- Sharing login credentials, or allowing access by anyone who is not an authorised User.
- Creating fake, fraudulent or unauthorised accounts, or misrepresenting your identity or authority.
- Abusing any free trial, promotional or evaluation access (where offered), including by creating multiple accounts to avoid limits or fees.
4.3 Illegal activity
- Fraud, identity theft, or any other dishonest or deceptive conduct.
- Harassment, threats, bullying, or defamation.
- Storing, sharing or transmitting illegal content.
- Infringing any third party's intellectual property rights.
- Breaching privacy or data protection laws, including the Privacy Act 2020.
4.4 Content
Do not upload, store, share or distribute through the Services any content that:
- contains malware or other harmful code;
- is offensive, obscene, harassing, threatening or otherwise objectionable;
- is illegal, or promotes illegal activity;
- infringes the intellectual property, privacy or other rights of any third party; or
- is intended to disrupt, damage or overload the platform.
The Customer is responsible for the content and Customer Data it and its Users put into the Services.
5. Fair use
The Services are provided for normal business use. Customers must not consume system resources in a way that is excessive, or that negatively affects the experience, performance or availability of the Services for other customers.
GateBud may investigate unusual, unexpected or potentially abusive usage patterns, and may discuss reasonable adjustments with the Customer where usage materially exceeds normal business use.
6. Security responsibilities
To help keep the Services secure, the Customer and its Users must:
- protect their passwords and login credentials, and not share them;
- enable multi-factor authentication where it is available;
- remove or disable access for people who no longer need it, and keep user permissions up to date;
- keep the devices used to access the Services reasonably secure and up to date; and
- notify GateBud promptly if they suspect any unauthorised access to, or compromise of, their account, credentials or Customer Data.
7. Monitoring
GateBud may monitor activity on the platform where reasonably necessary to:
- maintain the security of the Services;
- prevent, detect and investigate abuse or breaches of this Policy;
- investigate incidents; and
- maintain the performance, integrity and availability of the Services.
GateBud does not routinely monitor the content of customers' business activities or Customer Data, and only accesses Customer Data as permitted by the Master Agreement, including for operational, support, security or legal reasons.
8. Enforcement
If GateBud reasonably believes this Policy has been breached, or that action is needed to protect the Services, other customers, or any person, GateBud may, using commercially reasonable judgement and proportionate to the issue:
- issue a warning and ask for the activity to stop;
- restrict or disable specific features or functionality;
- suspend access to all or part of the Services;
- remove or disable offending content or Customer Data where legally permitted; and
- terminate the account or the Master Agreement for serious, deliberate or repeated breaches, in accordance with the Master Agreement.
Where the risk allows, GateBud will aim to give notice and limit its action to what is reasonably necessary. Where there is an urgent security or legal risk, GateBud may act first and notify the Customer as soon as practicable.
9. Reporting
To report a security issue, suspected abuse, or a breach of this Policy, please contact:
- Security: security@gatebud.com
- Support: support@gatebud.com
GateBud takes reports seriously and will investigate credible reports of misuse.
10. Changes
GateBud may update this Policy from time to time to reflect new features, changing risks, or changes in law. Material changes will be communicated through reasonable customer communication channels, such as email or an in-product notice, in accordance with the variation provisions of the Master Agreement. The current version will always be available on request or through the Services.
11. Exclusions
Nothing in this Policy limits or reduces:
- the Master Agreement, which continues to apply in full;
- any applicable law; or
- any of GateBud's rights or remedies under the Master Agreement or at law.
If there is any inconsistency between this Policy and the body of the Master Agreement, the body of the Master Agreement prevails, except on the specific acceptable-use matters this Policy addresses.