Acceptable Use Policy (AUP)
Effective date: see the version banner at the top of this page. Last updated: see the version banner at the top of this page.
This Acceptable Use Policy ("AUP") describes what you may and may not do when using ItsSuite (the "Service"). It is part of the Terms of Service. By using the Service you agree to be bound by this AUP.
This AUP is in addition to Meta's WhatsApp Business Solution Terms, Commerce Policy, and Messaging Policy. Where any of those policies are stricter than this AUP, the stricter policy wins.
1. Permitted use
The Service is provided to help you operate a legitimate business that communicates with its own opted-in customers through WhatsApp. Everything below describes what falls outside that purpose.
2. Prohibited content
You must not use the Service to send, store, or generate content that:
- Is illegal in any jurisdiction where the sender, receiver, or Zilo operates;
- Promotes or facilitates illegal activity — including but not limited to fraud, money laundering, illegal gambling, illegal drugs, illegal firearms, sex trafficking, child sexual abuse material, or terrorism;
- Infringes intellectual-property or publicity rights of any third party — including unlicensed copyrighted material, counterfeit goods, and trademark misuse;
- Is defamatory, libellous, or knowingly false to the harm of any person;
- Promotes violence, hate, or discrimination based on race, religion, gender, national origin, sexual orientation, disability, or any other protected characteristic;
- Sexually exploits or abuses any person, with absolute zero tolerance for content involving minors;
- Constitutes harassment, bullying, doxxing, or stalking of any person;
- Contains malware, ransomware, phishing payloads, or links to such;
- Falls within Meta's published list of restricted goods and services — including but not limited to alcohol, tobacco, weapons, pharmaceuticals, supplements, gambling, dating, financial products, cryptocurrency, and adult content — unless you have the regulatory authorisation and the platform clearances Meta requires;
- Misrepresents your identity — impersonates another business, person, or government agency, or sends from a number whose registered display name you do not have the right to use.
3. Anti-spam and consent
You must obtain valid prior opt-in consent from each end customer before you send them any message through the Service. Consent must be:
- Specific to WhatsApp messaging from you, by name — not a buried catch-all "agree to be contacted";
- Recorded with timestamp, source, and the language shown to the customer, and retrievable on demand;
- Revocable on request — you must honour a customer's request to stop receiving messages by ceasing further outbound messages from the Service immediately. You must support recognised stop words (STOP, UNSUBSCRIBE, OPTOUT) in any flow that sends marketing content.
You must not:
- Purchase, scrape, harvest, or otherwise acquire phone-number lists without per-recipient opt-in;
- Send unsolicited marketing or promotional messages ("spam");
- Use the Service to send messages on behalf of a third party (a client of yours, an agency client, a different brand) without that third party having their own contractual relationship with us, OR the Agency Annexure if your plan permits this and you have signed it;
- Use the Service to send messages to recipients you do not have a pre-existing customer relationship with;
- Send the same approved template repeatedly to the same recipient in a way that would breach Meta's frequency rules.
A high opt-out rate, block rate, or quality-rating drop will trigger automatic throttling and may lead to suspension under clause 9.
4. Volume, rate and fair use
Plan ceilings apply to all paid features (contact count, conversation count, AI completions, broadcast recipients, knowledge-base documents, agency child workspaces, custom-domain count, and so on). Soft limits are warned and hard limits enforced.
Beyond plan ceilings, fair use applies:
- You must not generate disproportionate load on shared infrastructure with the intent of degrading the Service for others;
- You must not use the broadcast feature to send to thousands of recipients on a low-tier plan without first upgrading;
- You must respect Meta's per-WABA and per-template rate limits — they also apply to your sending and we will throttle to keep you within them.
We may throttle or pause individual workspaces that pose a stability risk, with notice where reasonable.
5. Artificial-intelligence usage
When you use AI features (AI reply, AI classify, AI translate, AI template draft, conversation summary, in-app assistant), you must not:
- Generate prohibited content (clause 2);
- Generate content designed to impersonate identifiable real individuals without their consent;
- Use AI output as the sole basis for decisions with legal or similarly significant effect on a data subject (credit, employment, insurance, regulated benefits) without independent human review;
- Bypass or attempt to bypass the upstream provider's safety guardrails through prompt injection or otherwise;
- Use the assistant or template drafter to generate marketing copy promoting prohibited goods or services from clause 2.
We monitor for AI-feature abuse in aggregate. Repeated violations trigger AI-feature suspension on the workspace.
6. Knowledge base — only data you own or have licence to use
You must only upload documents, URLs, or Q&A pairs to your knowledge base that:
- You own; or
- You have a written licence to use for the AI-grounding purpose; or
- Are made available under an open licence compatible with that use.
You must not configure URL crawls against domains you do not own or do not have permission to crawl. Our URL crawler enforces a public-IP safety filter (no private RFC1918, no metadata services, no loopback, no link-local), and rejects requests for non-HTTP(S) schemes.
7. Connection and credential hygiene
- Keep your WhatsApp access tokens, Meta app secrets, and ItsSuite API tokens confidential. Do not share them in chat, email, or version control. We allow you to rotate them on demand.
- Two-factor authentication is required for platform admins and is strongly recommended for all workspace members. Many destructive actions require a fresh 2FA challenge regardless of the always-on requirement.
- Tell us immediately at security@zilo.co.za if you suspect any credential is compromised. We will assist with rotation and audit.
8. Anti-tampering and integrity
You must not:
- Attempt to gain unauthorised access to any other tenant's workspace, data, or API tokens;
- Bypass rate limits, plan ceilings, or feature gates through any technical means;
- Reverse-engineer the React-based flow builder, the AI dispatcher, or any other component except to the limited extent law permits;
- Probe, scan, fuzz, or run unauthorised security testing against the Service. Coordinated vulnerability disclosure is welcome — email security@zilo.co.za with details. We commit to good-faith engagement with researchers who follow responsible-disclosure norms;
- Use the Service to mine cryptocurrency, run distributed compute, or otherwise consume resources for purposes unrelated to your customer communications.
9. Enforcement
If we believe you have violated this AUP we may, at our sole discretion and without prior notice:
- Pause your outbound sending;
- Cancel a queued or scheduled broadcast;
- Remove specific content (a template, a knowledge-base document, a flow) that we reasonably believe violates this AUP, Meta's policies, or applicable law;
- Suspend AI features on your workspace;
- Suspend the workspace entirely;
- Terminate your account in accordance with the Terms of Service;
- Notify the relevant authorities and / or Meta where we are required or reasonably believe we should.
Where reasonably practicable we will tell you what happened and how to remedy it. Some categories of violation (child sexual abuse material, serious threats of violence, planned fraud) bypass that step and are reported immediately.
10. Appeals
If you believe an enforcement action against you was incorrect, email appeals@zilo.co.za within 30 days of the action. We aim to respond within 5 business days. You may also exercise any rights you have under the Consumer Protection Act and POPIA.
11. Reporting violations
If you become aware of a violation of this AUP by another user — for example, you receive a spam message from a business that you suspect is using ItsSuite — email abuse@zilo.co.za with the wa_id of the sender, the date and time of the message, and any other detail that will help us investigate. We treat reports confidentially.
12. Modifications
This AUP may be updated when Meta updates its policies, when applicable law changes, or when we identify a new category of misuse to call out. Material changes are notified the same way as Terms updates (workspace banner + email to the workspace owner, 14 days in advance unless the update is required by law). Continued use after the effective date constitutes acceptance.
— end of Acceptable Use Policy —