Acceptable Use Policy (AUP)
Last updated: 3 June 2026
This Acceptable Use Policy (“AUP”) supplements the BookOS Terms of Service and governs all use of the BookOS platform, APIs, websites, and email/SMS infrastructure (“Service”). Violations may result in suspension, termination, or referral to law-enforcement authorities, in addition to any other remedies available under the Terms or applicable law.
1. Prohibited content
You may not use the Service to host, store, send, or facilitate access to:
- content that is illegal under EU or Member-State law, including any law applicable to you or your end customers;
- child sexual abuse material (CSAM) or any content that sexualises minors — reports required by EU Regulation 2022/2065 will be made to the relevant national authority and to EU CSAM-reporting hotlines;
- content that promotes, glorifies, or incites violence, terrorism, or self-harm;
- content that is defamatory, harassing, threatening, or that discloses another person’s private information without lawful basis (“doxxing”);
- content infringing copyright, trade marks, patents, trade secrets, or other intellectual property rights;
- malware, ransomware, phishing kits, exploit code targeting third parties, or cryptojacking payloads;
- content depicting the sale or promotion of regulated goods or services that you are not lawfully authorised to offer (e.g. prescription drugs, controlled substances, firearms, gambling without licence).
2. Prohibited activities
You may not use the Service to:
- send unsolicited bulk messages (spam) in any channel (email, SMS, push, in-product notifications), or violate the EU ePrivacy Directive (2002/58/EC), the Danish Marketing Practices Act, GDPR Articles 6/7, or any applicable anti-spam law (CAN-SPAM, CASL, etc.);
- send marketing messages to recipients who have not given valid, prior, opt-in consent (or who have withdrawn it), or fail to honour unsubscribe / opt-out requests within 10 business days;
- use the Service for SMS pumping, traffic-pumping, premium-rate-number abuse, A2P aggregator fraud, or to circumvent carrier filtering;
- impersonate another person or business, forge headers, or otherwise misrepresent the origin of messages;
- attempt to gain unauthorised access to the Service, other tenants, or other accounts, including by probing for vulnerabilities outside of our published vulnerability disclosure programme;
- reverse-engineer, decompile, scrape (including via automated agents not authorised by us), or circumvent rate limits, robots.txt, CAPTCHAs, or other technical access controls;
- run benchmarking or competitive-analysis tooling against the Service for the purpose of building a competing product;
- resell, sublicense, or white-label the Service outside the scope expressly permitted in your subscription plan;
- interfere with other customers’ use of the Service, including by generating disproportionate load that degrades shared infrastructure;
- use the Service to operate or support a high-risk AI system within the meaning of the EU AI Act (Regulation (EU) 2024/1689) without first agreeing additional safeguards with us in writing.
3. Email and SMS sending
BookOS provides transactional and marketing messaging via our sub-processors (see sub-processors). Detailed sending rules are set out in our Anti-spam policy. At minimum, you are responsible for:
- maintaining valid, demonstrable consent records for every recipient and message type;
- including clear sender identification, business address, and unsubscribe / opt-out instructions in every marketing message, as required by the Danish Marketing Practices Act § 10 and ePrivacy Directive Art. 13;
- respecting time-of-day restrictions imposed by national law (e.g. SMS marketing curfews);
- monitoring bounce, spam-complaint, and unsubscribe rates — BookOS may throttle or suspend sending from accounts that exceed industry-standard thresholds (typically >0.3% spam complaints or >5% hard bounces sustained).
4. Data you upload
- You warrant you have all rights, consents, and lawful bases required to upload, process, and share Customer Data through the Service.
- You must not upload special-category personal data under GDPR Art. 9 (health, biometric, ethnic, religious, sexual, trade-union, political) into free-text fields without first agreeing additional safeguards with us in writing. Notes about allergies, scalp conditions, or medical contraindications constitute health data — treat them accordingly.
- You must not upload children’s personal data (under age 13 in Denmark, under the age of digital consent in other Member States) without valid parental consent.
5. Sanctions, export controls, and anti-bribery
- You may not use the Service in, or for the benefit of users located in, any country or region subject to comprehensive EU, UK, US OFAC, or UN sanctions (currently including Cuba, Iran, North Korea, Syria, Russia, Belarus, and the non-government-controlled regions of Ukraine).
- You may not provide the Service to any individual or entity on the EU Consolidated Financial Sanctions List, the UK OFSI list, the US OFAC SDN list, or any equivalent restricted-party list.
- You will comply with applicable anti-bribery and anti-corruption laws including the UK Bribery Act 2010, the US Foreign Corrupt Practices Act, and the Danish Criminal Code §§ 144 and 299.
6. Reporting violations
Report suspected violations to abuse@bookos.io. For illegal content under the EU Digital Services Act, please follow the procedure on our DSA contact page. For security vulnerabilities, see our vulnerability-disclosure programme.
7. Enforcement
We investigate suspected violations and may, at our sole discretion: (a) request additional information; (b) remove or restrict access to specific content; (c) throttle, suspend, or terminate the affected account; (d) report the matter to competent authorities. We provide a statement of reasons and an avenue for appeal in accordance with Articles 17 and 20 of the Digital Services Act where applicable.
8. Changes
We may update this AUP. Material changes take effect 30 days after notice to registered billing contacts. Continued use after the effective date constitutes acceptance.
