Acceptable Use Policy

Last updated: October 2, 2026

ANNEX E — ACCEPTABLE USE POLICY

This Acceptable Use Policy (the “AUP”) is an annex to, and an integral part of, the Enastro General Terms and Conditions (the “Terms”) published at https://dev.enastro.com/legal/terms. Capitalised terms have the meanings given in the Terms.

1. Purpose and application

1.1 This AUP protects the integrity, security, availability and lawful operation of the Service, our other customers, our Model Providers and the persons whose conversations are processed through the Service, and enables us to comply with the obligations imposed on us by applicable law and by our own suppliers.

1.2 It applies to you, to each Member, and to every person who accesses or uses the Service through your Organization, through an API Key issued to it, or with your permission, including your personnel, contractors and affiliates. You are responsible for the compliance of each such person as if their acts and omissions were your own.

1.3 This AUP supplements and does not limit clause 8.2 of the Terms, the Software Licence Terms or the AI Terms. Conduct which breaches this AUP may also breach those provisions, and we may rely on any or all of them.

2. General standards

2.1 You shall use the Service only for your own lawful internal business purposes, in accordance with the Documentation, and only in respect of data and recordings which you are lawfully entitled to process.

2.2 You shall provide and maintain accurate registration, contact, VAT and billing information, and shall not impersonate any person or misrepresent your identity, your affiliation with any person or the origin of any data you submit.

2.3 You shall keep Member credentials and API Keys confidential, shall not share a Member account between several natural persons, shall not issue credentials to any person who is not authorised under the Terms, and shall revoke credentials promptly upon a Member’s departure or change of role.

2.4 You shall cooperate with any reasonable request by us to investigate a suspected breach of this AUP, to identify the source of prohibited conduct, or to contain a security or abuse incident.

3. Prohibited content

3.1 You shall not ingest into, submit to, generate through, store in or transmit by means of the Service any material which:

(a) you have no lawful right to process, or which you are prohibited from disclosing to a processor by contract, professional obligation, court order or applicable law;

(b) infringes the Intellectual Property Rights, trade secrets, rights of confidence, privacy or personality rights of any person;

(c) is unlawful, defamatory, obscene, harassing or discriminatory, or which promotes violence, terrorism, self-harm or hatred against any person or group;

(d) constitutes child sexual abuse material or any other content the possession or transmission of which is a criminal offence;

(e) contains any virus, worm, trojan, ransomware, exploit, malicious code or payload, or any material designed to interfere with the operation of the Service or to compromise our data or that of any other customer;

(f) consists of special categories of personal data within the meaning of Article 9 GDPR, or of data relating to criminal convictions and offences, submitted deliberately or systematically rather than arising incidentally in the course of a customer service conversation; or

(g) consists of payment card data, authentication credentials, government identification numbers or comparable material submitted deliberately, other than as may arise incidentally in the course of a customer service conversation.

3.2 We do not review, filter, moderate or verify the content of recordings, transcripts, prompts, Metrics or Outputs, are under no obligation to do so, and do not thereby assume responsibility for that content.

4. Prohibited uses

4.1 You shall not use, and shall not permit any person to use, the Service:

(a) to develop, train, fine-tune, evaluate, benchmark or improve any artificial intelligence or machine-learning model, or to develop, or assist any third party to develop, a product or service which competes with the Service;

(b) to extract, distil, replicate or reconstruct any model, prompt, response schema, weights, architecture or other component of, or accessed through, the Service, or to elicit its system instructions or configuration;

(c) to resell, rent, lease, sublicense, white-label, host, syndicate or otherwise commercially exploit the Service or any Output as a standalone artificial intelligence, transcription or analytics capability, save as expressly permitted in writing by us;

(d) in a manner which circumvents, defeats, disables or manipulates metering, quotas, rate limits, Seat counting, tenant scoping, authentication or any other technical or contractual control, including the enrolment of Organizations, Workspaces, Members or API Keys for the purpose of avoiding, reducing or deferring Fees;

(e) to gain or attempt to gain unauthorised access to the Service, to any other customer’s tenant or data, to our systems or to the systems of any Model Provider;

(f) to conduct any penetration test, vulnerability scan, load test, denial-of-service test or other security or performance assessment of the Service without our prior written consent, or to publish the results of any such test or of any benchmark or model comparison;

(g) by means other than the interfaces we provide or authorise, including by scraping, crawling, automated extraction or the use of undocumented endpoints;

(h) in any manner which imposes, or is likely to impose, an unreasonable or disproportionate load on the Service, degrades its performance, or interferes with the use of the Service by any other customer; or

(i) in breach of any export control, sanctions, anti-money-laundering or anti-corruption law, or for the benefit of any person subject to sanctions or established in an embargoed territory.

4.2 You shall not use the Service to send unsolicited commercial communications, to conduct automated outbound calling or messaging campaigns in breach of applicable law, or to process recordings obtained through any such campaign.

5. Recording, monitoring and workplace use

5.1 You shall ingest only recordings which were lawfully made and which you are lawfully entitled to transmit to us, and shall have given all notices, obtained all consents and established and documented all legal bases required under applicable law, including the law on the confidentiality of communications.

5.2 Where recordings concern conversations conducted by your employees, workers or contractors, you shall comply with clause 11.2 of the Terms, including the obligations to inform the persons concerned and, where required, to consult their representatives in advance.

5.3 You shall not use the Service or any Output:

(a) for the individual evaluation, ranking, scoring, disciplining or performance monitoring of natural persons in work-related relationships, or for any decision affecting the recruitment, promotion, remuneration, task allocation or termination of any such person;

(b) to infer the emotions of a natural person in the areas of the workplace or of education institutions;

(c) for the profiling of natural persons within the meaning of Article 4(4) GDPR;

(d) as the sole or determining basis for any decision producing legal effects concerning a natural person or similarly significantly affecting a natural person within the meaning of Article 22 GDPR; or

(e) for any use case listed in Annex III to the AI Act, or in any manner which would cause the AI System to be classified as a high-risk AI system.

5.4 You shall apply meaningful human review to any Output before acting upon it in relation to an identified or identifiable natural person, and shall not present any Output to a third party as verified, as human-generated or as a statement of SmartRep.

5.5 You shall not use the Service for covert surveillance, for the monitoring of natural persons who have not been informed as required by applicable law, or for any purpose which you have represented to those persons that you would not pursue.

6. Security and integrity

6.1 You shall maintain appropriate technical and organisational measures for the systems, Audio Sources, storage credentials, webhook secrets and API Keys which you use in connection with the Service, and shall apply the principle of least privilege to the access you grant.

6.2 You shall not disable, block or filter the transmission of telemetry or metering data, and shall not prevent the installation of updates designated as mandatory or security-related.

6.3 You shall notify us without undue delay of any actual or suspected unauthorised access to the Service or to your Organization, compromise of credentials or API Keys, breach of this AUP by any person, or circumvention of metering or access controls of which you become aware.

7. Fair use and capacity

7.1 Use of the Service is subject to the rate limits, quotas and capacity constraints published in the Documentation or notified by us, and to the capacity and rate limits imposed by Model Providers.

7.2 We may apply queuing, throttling, prioritisation or temporary limits where necessary to preserve the stability, availability or security of the Service, to comply with a restriction imposed by a Model Provider, or to address anomalous or excessive consumption. Measures taken under this section do not constitute unavailability, give rise to no service credit, and do not relieve you of your payment obligations.

7.3 Where your consumption materially exceeds the pattern reasonably to be expected from your plan, or is such as to affect other customers, we may require you to modify your configuration, may propose revised commercial terms and, failing agreement within thirty (30) calendar days, may act under section 8.

8. Enforcement

8.1 We may investigate any suspected breach of this AUP, including by examining metering records, access logs, Job configurations and, where strictly necessary and permitted by the Data Processing Agreement, Customer Data.

8.2 Where we reasonably believe that this AUP has been breached we may, in addition to any other right or remedy: (a) require you to cease the conduct and remedy its effects within a stated period; (b) restrict, throttle or disable the affected functionality, Job, model, Member account or API Key; (c) remove or render inaccessible the material concerned where retaining it would expose us to legal liability; (d) suspend the Service in accordance with clause 17.2 of the Terms; or (e) terminate in accordance with clause 17.3 of the Terms.

8.3 We shall, so far as reasonably practicable, limit any measure to what is necessary, give you prior notice and an opportunity to remedy, and inform you of the reasons. Where the conduct presents an imminent risk to the security, integrity or lawful operation of the Service, to us or to any third party, or where applicable law, a competent authority or a Model Provider so requires, we may act with immediate effect and give notice afterwards.

8.4 We shall have no liability for any measure taken in accordance with this section. Fees, including storage charges in respect of data still held, continue to accrue during any period of restriction or suspension and no service credit arises.

8.5 You shall reimburse our reasonable costs of investigating and remedying a breach of this AUP by you or by any person for whom you are responsible, and shall indemnify us in accordance with clause 16.1 of the Terms.

8.6 We may report to a competent authority any conduct which we reasonably believe to constitute a criminal offence, and may preserve and disclose the material reasonably necessary for that purpose, subject to the Data Processing Agreement.

9. Changes

9.1 We may update this AUP in accordance with Article 18 of the Terms. Changes required by applicable law, by a competent authority, by a Model Provider or for the security or integrity of the Service may be implemented with immediate effect upon notice.

9.2 Continued use of the Service after an update takes effect constitutes acceptance of the updated AUP.