Using BrandKit responsibly
BrandKit is built to help businesses work faster, communicate clearly and manage important customer and production workflows. This Acceptable Use Policy explains the rules that help us keep the platform secure, reliable and useful for everyone.
This policy applies to every person and organisation that accesses or uses BrandKit, including account holders, Authorised Users, portal users, API users and anyone acting on their behalf.
It forms part of the BrandKit Customer Terms of Service. Capitalised terms not defined here have the meaning given in those Terms.
1. The simple rule
Use BrandKit lawfully, honestly and in a way that does not harm other people, other customers, BrandKit or the Services.
You are responsible for activity carried out through your Account, Workspace, integrations, portals, API credentials and Authorised Users.
2. Illegal, harmful or abusive activity
You must not use BrandKit to create, upload, store, send, display, process or facilitate content or activity that:
- breaks any applicable law or regulation;
- infringes another person's intellectual property, privacy, confidentiality or other rights;
- is fraudulent, deceptive, defamatory, threatening, harassing or unlawfully discriminatory;
- promotes or facilitates violence, exploitation, abuse or criminal activity;
- contains unlawful intimate, sexual or exploitative material;
- is intended to cause serious harm, intimidation or distress;
- misrepresents your identity, authority, organisation, products or services;
- facilitates phishing, impersonation, scams, credential theft or payment fraud; or
- would expose BrandKit, another customer or a third party to material legal or reputational harm.
BrandKit is a business platform, not a hiding place for bad behaviour. If an activity would be unlawful or seriously harmful outside BrandKit, it is not permitted inside BrandKit either.
3. Spam and electronic communications
BrandKit may include tools that help users draft, organise or send emails and other communications. You must use those tools responsibly.
You must not:
- send spam or bulk unsolicited commercial messages;
- send messages to people where you do not have a lawful basis or reasonable permission to contact them;
- use misleading sender names, subject lines, domains or contact details;
- hide the commercial nature or identity of the sender where disclosure is required;
- ignore valid unsubscribe, suppression or opt-out requests;
- purchase, scrape or use unlawfully obtained contact lists;
- use BrandKit to evade sending limits, provider controls or anti-spam safeguards; or
- send content that breaches the policies of Google, Microsoft, an email provider or another connected service.
You are responsible for complying with the anti-spam, privacy, marketing and consumer laws that apply to your communications, including maintaining appropriate consent, identification and unsubscribe processes.
BrandKit may apply sending limits, suppress messages or suspend communications functionality where we reasonably believe activity may constitute spam, harm delivery reputation or breach applicable law or provider rules.
4. Security and system integrity
You must not attempt to compromise, disrupt or misuse BrandKit or any connected system.
This includes:
- introducing malware, viruses, ransomware, malicious scripts or harmful code;
- attempting to gain unauthorised access to Accounts, Workspaces, systems, databases, credentials or Customer Data;
- bypassing authentication, permissions, role controls, plan limits, billing controls or tenant boundaries;
- testing, probing, scanning or exploiting security vulnerabilities without BrandKit's written permission;
- interfering with the availability, performance or integrity of the Services;
- using stolen, shared or improperly obtained credentials;
- attempting to access another customer's data or infer confidential information about another customer;
- disabling or evading logging, monitoring, abuse prevention or security controls; or
- helping another person carry out any prohibited security activity.
If you believe you have found a security issue, do not exploit it or access information beyond what is necessary to demonstrate the issue. Report it promptly to support@brandkitcrm.com.
5. Scraping, automation and API use
Reasonable use of BrandKit's documented APIs and authorised automation is permitted within the limits of your Subscription and any technical documentation.
You must not:
- scrape, crawl, harvest or systematically extract data through undocumented or unauthorised methods;
- use bots or automation to bypass user, usage, rate, storage or plan limits;
- place unreasonable load on BrandKit's systems or connected services;
- use automation that creates excessive records, messages, requests or background jobs;
- use API credentials outside the purpose and permissions for which they were issued;
- share API keys or secrets publicly or with unauthorised parties;
- interfere with another customer's use of the Services; or
- replicate a substantial part of BrandKit's data, interface or functionality through automated extraction.
BrandKit may apply technical limits, rate limits, fair-use controls or temporary restrictions where needed to protect reliability and service quality.
6. Reverse engineering and competing products
You must not, except where applicable law expressly permits:
- reverse engineer, decompile, disassemble or attempt to derive BrandKit source code;
- copy or reproduce non-public workflows, architecture, models or system designs;
- remove or obscure proprietary notices;
- use non-public access to BrandKit to build, train, benchmark or improve a directly competing product;
- provide access to BrandKit for competitive intelligence or unauthorised product testing; or
- use confidential BrandKit information outside the purpose for which it was provided.
This does not stop customers from using BrandKit normally, integrating through authorised APIs, or independently developing products without using BrandKit's non-public information.
7. Customer Data and third-party rights
You must have the necessary rights, permissions and lawful basis for information you submit to or process through BrandKit.
You must not:
- upload confidential information you are not authorised to disclose;
- process personal information unlawfully;
- submit another person's intellectual property without permission or another lawful basis;
- use Customer Data to harass, profile, discriminate against or unlawfully target individuals;
- upload information subject to legal or contractual restrictions that prevent BrandKit from processing it; or
- use BrandKit to obtain or combine data in a way that unlawfully identifies, tracks or monitors people.
You remain responsible for your own privacy notices, permissions, retention settings and compliance obligations.
8. Sensitive and high-risk data
BrandKit is designed for ordinary business information used in customer, quoting, production, inventory, artwork and communication workflows.
Unless BrandKit has expressly agreed in writing, you must not use the Services as the primary system for storing or processing:
- payment card numbers, card security codes or online banking credentials;
- passwords or authentication secrets belonging to third parties;
- government-issued identity documents where not reasonably required;
- medical records, clinical information or highly sensitive health data;
- biometric identifiers used for identity verification;
- information classified by a government or subject to national-security controls;
- data subject to specialist regulatory hosting requirements that BrandKit has not agreed to support; or
- information whose loss would create an unacceptable safety or legal risk.
Limited incidental appearance of sensitive information in a legitimate business communication may occur, but customers should minimise it and use appropriate safeguards.
9. Artificial intelligence
You must use BrandKit's AI-assisted features responsibly.
You must not use AI features to:
- create unlawful, fraudulent, deceptive or seriously harmful content;
- impersonate another person or falsely represent that an output was approved by them;
- generate phishing, malware, credential theft or security-evasion material;
- make automated decisions about people where human review or legal safeguards are required;
- submit information you do not have the right to process;
- attempt to extract system prompts, secrets, model credentials or another customer's information;
- circumvent AI safeguards or deliberately test harmful prompts at scale without permission; or
- present an AI-generated output as verified professional advice when it has not been appropriately reviewed.
AI outputs can be inaccurate or incomplete. You are responsible for reviewing them before use, especially where an output affects pricing, customers, compliance, safety or legal rights.
10. Portals, shared pages and public content
Customers may use BrandKit to create proposal portals, ordering portals, catalogues or other pages for their clients, employees or partners.
You are responsible for the content and access settings of pages you create.
You must not use BrandKit-hosted pages to:
- publish unlawful, deceptive, infringing or malicious content;
- collect personal information without suitable notice or authority;
- mislead users about who operates the page or how information will be used;
- host malware, phishing pages or deceptive payment requests;
- make a private portal public through careless or intentional access settings; or
- present BrandKit as endorsing your products, statements or business unless BrandKit has agreed.
12. Fair use and excessive consumption
Some BrandKit features may be described as unlimited. Unlimited does not mean use without reasonable operational boundaries.
Use must remain consistent with ordinary business purposes, the applicable Subscription and the needs of a shared cloud service.
BrandKit may contact you or apply proportionate limits where usage:
- is unusually high compared with similar customers;
- creates material infrastructure cost or performance issues;
- appears automated, abusive or unrelated to normal business use;
- risks disrupting the Services or a third-party provider;
- is designed to avoid purchasing an appropriate plan or add-on; or
- prevents BrandKit from providing a reliable service to others.
Where practical, we will discuss unusual legitimate requirements and offer an appropriate plan, technical approach or custom arrangement before restricting access.
13. Monitoring and investigation
BrandKit does not routinely inspect private Customer Data for unrelated purposes. We may, however, use automated systems and limited authorised review to:
- detect spam, malware, fraud, abuse and security threats;
- investigate suspected violations of this policy or the Terms;
- protect platform reliability and sending reputation;
- respond to a support request or customer instruction;
- comply with law or a valid legal request; or
- protect BrandKit, customers, users or third parties.
Access to Customer Data for these purposes is limited to what is reasonably necessary and is subject to confidentiality and access controls.
14. What happens if this policy is breached
We aim to respond proportionately. Depending on the seriousness, urgency and history of the issue, BrandKit may:
- contact you and ask you to stop or correct the activity;
- remove or restrict specific content, messages, integrations or functionality;
- apply technical limits or require a change in configuration;
- temporarily suspend an Authorised User, integration, Workspace or Subscription;
- terminate access in accordance with the Customer Terms of Service;
- preserve or disclose relevant information where legally required; or
- refer serious unlawful activity to an appropriate authority.
Where reasonable, we will provide notice and an opportunity to remedy the issue. We may act immediately where necessary to address a serious security threat, fraud, unlawful activity, harm to others or material risk to the Services.
A Customer remains responsible for fees and obligations incurred before suspension or termination.
15. Reporting concerns
If you believe BrandKit is being used in breach of this policy, or you discover a security issue, contact support@brandkitcrm.com.
Please include enough information for us to understand and assess the concern, but do not send passwords, private keys or unnecessary sensitive information.
16. Changes to this policy
We may update this policy as BrandKit, our features, applicable laws or abuse risks change.
If a change materially affects existing customers, we will provide reasonable notice through the Services, by email or through another appropriate method.
The date at the top shows when this policy was last updated.
17. Contact us
Have questions about acceptable use? Contact us at support@brandkitcrm.com.
BrandKit is operated by Snowball Effect Ventures Limited, New Zealand company number 6415354, NZBN 9429046333681.