Canonical page: https://tellenze.com/legal/acceptable-use

# Acceptable Use Policy

Document version

Version: 2026-10-10.draft-1

Practical rules for lawful work, secure connections, respectful collaboration and responsible external actions.

These rules apply to Tellenze members, customers, public-tool participants and people using connected agents or integrations. They help protect the service, the people who use it and the people whose information appears in it.

This is a draft for owner, operational and legal review. It becomes part of the service rules only through the final approved agreement. Version 2026-10-10.draft-1 has no effective date.

## 1. Use the service within your authority

At a glance: Work only with the accounts, information and actions you are allowed to use.

Use Tellenze for lawful work within the service agreement and your organisation's rules. You must have the authority needed to read, change, upload, share or delete the information involved. Public-tool access and a workspace connection do not grant rights over someone else's information.

These rules apply to your own actions and to actions you instruct an agent or integration to perform. The customer should make them available to its members and keep access appropriate to each person's work.

An approved workflow can include client work, business research and contact with potential customers. Permission for that work depends on its purpose, the information involved, the communication channel and applicable law.

## 2. Do not use Tellenze for unlawful or abusive activity

At a glance: Illegal activity, threats, fraud and harmful content are prohibited.

Do not create, store, share or use content through Tellenze where the activity violates applicable law or another person's rights. Do not use the service to organise fraud, extortion, exploitation or other unlawful conduct.

Respect people when collaborating. A disagreement, complaint or honest report of wrongdoing may be legitimate. Use the relevant workspace or legal process without threats, targeted abuse or exposing unnecessary personal information.

- Do not threaten violence, encourage serious harm or use targeted harassment or discriminatory abuse.
- Do not share child sexual abuse material or use the service to exploit a child.
- Do not impersonate someone, forge records or mislead people about your identity or authority.
- Do not upload stolen material or content that infringes copyright, confidentiality or other rights.

## 3. Handle personal and confidential information carefully

At a glance: Collect only what your work needs and share it with an authorised audience.

Before adding another person's information, check your lawful purpose, the source, necessary permissions and any duty to explain the use to that person. Access to a public page or a contact detail does not remove privacy or communication requirements.

Limit personal information to what the work needs. Check workspace permissions, the room audience, exports and any connected provider before sharing. A file title, comment or generated summary can expose personal information even if the original file remains private.

Do not post passwords, private access tokens, full payment-card information or other secrets in tasks, public rooms or AI instructions. Use an approved connection or secure process for credentials. Use fictional information in the shared demo.

Do not upload sensitive or specially regulated information unless the customer has the required legal basis, service agreement and safeguards. Respect valid requests to correct, restrict or delete information through the responsible organisation's process.

## 4. Protect accounts and connections

At a glance: Do not bypass sign-in, permissions or connection boundaries.

Keep your account and connection credentials secure. Use access assigned to you and connect only the workspace and provider accounts you are authorised to use. Remove or revoke access when it is no longer needed.

Do not try to reach another workspace, member's private information or a restricted feature by changing identifiers, reusing credentials, hiding your identity or exploiting an error.

Security testing must have prior written authorisation and a defined scope. If you find an unexpected exposure, stop the activity, keep only the evidence needed to report it and contact general@tellenze.com. Do not keep exploring another person's records or publish their content as proof.

- Do not steal, sell or share access credentials to evade membership or permission rules.
- Do not bypass a revoked connection, expired authorisation or a disabled feature.
- Do not deploy malware, phishing links or instructions designed to steal secrets.
- Do not attempt unauthorised vulnerability scanning, exploitation or access to service infrastructure.

## 5. Keep the service reliable

At a glance: Automation must respect limits and avoid disrupting other people's work.

Use the documented tools and supported developer interfaces, or APIs, within their limits and the agreed service scope. Automated clients must handle errors, permission changes and retry guidance without creating uncontrolled traffic or repeated changes.

Do not evade request limits, generate deliberate overload, fill the service with junk records or interfere with another customer's availability. Do not extract information through a method or scope you have not been authorised to use.

An uncertain result needs checking. Repeating a request blindly can create duplicate records, charges or messages. Follow the service's retry and conflict guidance, and check the latest record before applying a change again.

## 6. Give agents clear and limited authority

At a glance: An agent must follow the same access, context and review rules as the person using it.

Check the selected workspace, member and context before instructing an agent. Its connection does not give it authority to read every source, act as an administrator or bind another person to a contract.

Follow Required Context guidance and the workspace's approval and completion rules. Do not instruct an agent to hide actions, ignore revoked access, change evidence to bypass a review or disclose another person's private work.

Content returned by a document or external page can contain misleading instructions. Do not treat those instructions as permission to reveal secrets, send messages or perform an unrelated action. Review important proposed changes against the actual source records.

Record actual results honestly. Do not fabricate work, review evidence, agent usage measurements, approvals or completion status. A prepared draft, failed operation or unverified result must not be represented as a completed external action.

## 7. Email and contact with potential customers

At a glance: Lawful outreach is allowed when you have the required authority and review the actual message and recipient.

You may use an enabled and authorised powerup for legitimate client or prospect contact. Before sending, check the source and use of the contact information, the applicable privacy and electronic-communication rules, any required consent and the recipient's previous choices.

Use a sender you are authorised to represent. Make the purpose clear, identify yourself accurately and provide a working way to stop marketing where required. Respect withdrawals, objections and suppression lists. Permission for one purpose or channel does not automatically cover another.

Review the actual recipients, subject, body, links and attachments. Confirm the selected sender and use the feature's explicit Send step where available. Drafting, revising or reviewing an email does not mean that it has been delivered.

An agent may help prepare lawful outreach within your authority. It may not treat a general business goal as permission to contact anyone, evade a recipient's choice or bypass the review required for an external action.

- Do not send unlawful spam, deceptive bulk messages, phishing or unwanted repeated contact after a valid objection.
- Do not use unlawfully obtained contact lists, invent recipient permission or hide the true sender.
- Do not bypass provider limits, reputation controls, blocked recipients or required unsubscribe handling.
- Do not include personal or confidential information that the recipient is not authorised to receive.

## 8. Publishing, sharing and external changes

At a glance: A public or external action needs the authority and review appropriate to that action.

Before publishing a review, article, form, page or other material, check its audience, source permissions, accuracy and publication requirements. Permission to see or draft content does not automatically permit public distribution.

Do not bypass a required approval, publish another person's private draft or use an export to avoid sharing restrictions. Information copied to an external service can remain there after a Tellenze connection is revoked.

For changes to external systems, check the target account, operation and consequences before confirming. Authority to prepare work or connect a provider is not unlimited authority to deploy, delete, purchase or change production systems.

## 9. Use AI results responsibly

At a glance: Check AI output before using it for an important decision or sharing it with others.

AI can make factual mistakes, omit context or produce unsuitable material. Verify important claims, permissions, calculations and recipient details. Follow the organisation's review process before relying on generated work.

Do not use Tellenze to create deceptive evidence or harmful impersonations. Do not present an AI suggestion as a verified fact, professional conclusion or approval that has not occurred.

Decisions about employment, credit, health, access to services or other serious personal matters can require additional legal and human safeguards. A connected agent does not remove those duties or make an unsupported use suitable.

## 10. Report abuse or a security concern

At a glance: Send a focused report to general@tellenze.com with enough information to find the issue.

Tell us the affected workspace, public tool or connection, what happened and when. Include a record or link you are authorised to share and explain any immediate risk. For content controlled by your organisation, also follow its reporting process where appropriate.

Do not include passwords, full access tokens or unrelated personal records in ordinary email. We may ask for additional evidence through a suitable channel. We should handle reports in a way that protects the reporter and other people concerned, within applicable law.

If there is an immediate danger to a person, use the appropriate emergency or law-enforcement route. A report to Tellenze is not a substitute for that route.

## 11. How concerns are handled

At a glance: We should use proportionate measures based on the seriousness and evidence of the issue.

We may investigate a credible report or security signal and take the measures allowed by the applicable service agreement and law. Depending on the issue, these can include guidance, a request to correct content, a rate limit, restriction of a feature or connection, suspension or termination.

Consider the impact, urgency, intent, repeated conduct and available evidence. Use the least restrictive measure that reasonably protects people and the service. An automated alert alone should not be treated as conclusive proof of misconduct.

Where it is safe and lawful, explain the reason, affected access and steps needed to resolve the issue. Serious threats, ongoing abuse or a legal requirement may require immediate action. Details may need to be limited to protect security, confidential information or a legal process.

Enforcement does not automatically settle contract charges or authorise deletion of all content. Content return, retention and privacy requests follow the relevant agreement and legal duties.

## 12. Ask for a decision to be reviewed

At a glance: You can explain why an enforcement decision should change and provide relevant evidence.

Email general@tellenze.com with the affected account, workspace or connection, the decision and your reasons for requesting review. Provide relevant evidence you are authorised to share, including any steps already taken to correct the issue.

The review should consider the original evidence, your explanation and whether the measure remains necessary and proportionate. We should explain the outcome where it is safe and lawful to do so. This draft promises no fixed appeal response time.

The Terms of Service describe contract disputes, and the Privacy Policy describes privacy complaints and rights. Those routes remain available where applicable.

## Sources used for this document

- [EDPB: lawful use of personal data](https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en)
- [EDPB: individual rights, including objection to direct marketing](https://www.edpb.europa.eu/sme/be-compliant/respect-individuals-rights_en)

Contact: general@tellenze.com
