01
Scope and responsibility
This policy applies to every EngageMinty customer and authorised user. Customers are responsible for ensuring that employees, contractors and other account users comply with it.
It covers CRM accounts and the platform wallet; websites, funnels, forms and calendars; email, SMS, WhatsApp and telephone services; AI assistants, generated content and automated decisions; workflows and integrations; and files, content, imported contacts and other data stored or processed through the services.
The policy forms part of the Terms of Service. Helping another person evade these rules is also prohibited.
02
Illegal, deceptive and harmful activity
Services must not be used for unlawful activity or to encourage it; fraud, scams, impersonation or deception; harassment, threats, hate, exploitation or abuse; malware, phishing, credential theft or unauthorised access; infringement of intellectual-property, privacy or confidentiality rights; unlawfully regulated or prohibited products; human trafficking, sexual exploitation or child sexual abuse material; terrorism or violent extremism; evasion of sanctions, court orders or regulatory restrictions; or processing data without a lawful basis.
EngageMinty may investigate, restrict or immediately suspend activity where it reasonably believes there is a serious legal, security or safety risk.
03
Messaging, calls and contact lists
Cold marketing SMS is prohibited without documented SMS consent. Promotional WhatsApp messaging requires the appropriate WhatsApp opt-in. A service enquiry, application, booking or appointment does not automatically create marketing consent.
Lawful B2B email outreach may be permitted where applicable PECR and data-protection requirements are satisfied. Lawful B2B calls may be permitted only after required TPS/CTPS, consent and suppression screening.
Bought data is not automatically prohibited, but the customer must be able to evidence its source, collection method, permitted uses, required notices and suppression handling. Scraped data is prohibited where collection or use breaches law, privacy expectations, access restrictions or platform terms.
Senders must identify themselves accurately, provide working contact and opt-out routes, honour opt-outs promptly across relevant systems, avoid excessive frequency or harassment, and retain appropriate consent, lawful-basis, source and screening records for reasonable inspection.
04
AI services and automated decisions
AI services must not be used for deceptive impersonation; fraudulent reviews, testimonials, evidence or documents; unlawful discrimination or prohibited decisions; malware, phishing or credential theft; non-consensual sexual or intimate content; exploitation of children or vulnerable people; harmful deliberate falsehoods; circumvention of model safeguards or provider restrictions; or processing data the customer is not authorised to use.
Significant employment, credit, housing, insurance, healthcare or legal decisions require appropriate human review. AI output must not be presented as verified professional advice without qualified review. Customers must review consequential output and remain responsible for its accuracy, legality, approval and publication.
Ordinary creative work, drafting, research assistance, customer support and business automation remain permitted when they otherwise comply with this policy.
05
Security and platform integrity
Prohibited security activity includes unauthorised access; credential sharing outside authorised users; bypassing security, rate limits, usage limits or billing controls; vulnerability scanning or penetration testing without written authorisation; malware; interference with availability or other customers; abusive APIs or excessive automated requests; prohibited reverse engineering; unauthorised resale or sublicensing; accounts created to evade suspension; concealment of abusive traffic; cryptocurrency mining or similarly excessive computation; and failure to report suspected account compromise promptly.
EngageMinty may apply technical controls, rate limits, restrictions or immediate suspension where reasonably necessary to protect customers, providers or the platform.
06
Regulated and higher-risk activity
Regulated and higher-risk sectors are not automatically prohibited. Customers may use the services where the activity is lawful and complies with applicable licences, professional duties, age restrictions, disclosures and provider rules.
EngageMinty may request further information or written approval only where reasonably necessary because law or regulation requires safeguards, a provider restricts the activity, sensitive data or significant automated decisions are involved, or the proposed use creates a material security, safety or compliance risk.
EngageMinty may refuse the affected activity where requirements cannot reasonably be met. Approval does not certify the customer’s legal or regulatory compliance.
07
Sensitive data, credentials and payment information
Passwords, API secrets, private keys and production credentials must not be submitted through ordinary forms, chats or questionnaires. Only EngageMinty-approved secure access methods may be used.
Full payment-card details must not be collected through ordinary CRM fields and must use approved payment-provider components.
Identity documents, health information, criminal-record data and other sensitive information must not be stored unless the use is agreed and appropriate safeguards are active. Customers must collect only data reasonably necessary for the stated purpose, use role-appropriate access, remove access promptly when a user leaves and notify EngageMinty promptly of suspected loss, unauthorised access or disclosure. Test data should be anonymised or synthetic where reasonably possible.
08
Fair use and resource consumption
Unlimited and fair-use features are for genuine normal use by the subscribed business, not resale or shared service provision. Customers must not resell AI Credits, communications capacity, accounts or platform access without written agreement, or use one account or location for unrelated businesses where separate subscriptions are required.
Artificial traffic, automated credit consumption or activity designed mainly to increase supplier cost is prohibited. High-volume activity must use suitable plans, sufficient wallet funding and provider-approved limits.
EngageMinty may investigate unusual consumption, apply temporary limits or require migration to an appropriate plan. It should normally contact the customer before restricting legitimate heavy use unless immediate action is reasonably required for security, cost, provider compliance or platform stability. Fair use is not a hidden numeric cap and is assessed against genuine business activity and the subscribed service.
09
Investigations, evidence and disclosure
EngageMinty may investigate suspected violations and request relevant information or evidence. It may preserve relevant logs, content and account records and disclose reasonably necessary information to law enforcement, courts, regulators, emergency services, specialist reporting bodies, relevant hosting, communications or security providers, or professional advisers where legally required or reasonably necessary to investigate abuse, comply with a valid request, protect rights or prevent serious harm.
EngageMinty should assess the apparent validity and scope of official requests where appropriate, limit disclosure to what is reasonably necessary, document disclosures where appropriate, and notify the customer where legally permitted and operationally safe. Advance notice is not promised where it could prejudice an investigation, breach law or increase risk. Information handling also follows the Privacy Policy.
10
Enforcement and review
For a lower-risk or correctable issue, EngageMinty should normally notify the customer and allow a reasonable opportunity to correct it.
EngageMinty may immediately pause an affected workflow, communication channel, content item or account where reasonably necessary to prevent serious harm, unlawful activity, security compromise, provider action or material cost. Restrictions should be limited to the affected activity where reasonably practical. Serious, repeated or deliberate violations may lead to content removal, suspension or termination.
Customers remain responsible for usage charges incurred before activity is stopped. Evidence may be preserved and providers or authorities may be assisted under the investigation rules above.
Customers may request a review of an enforcement decision and provide relevant evidence. A review does not automatically restore access while risk remains. Service may be restored subject to corrective actions, safeguards or monitoring.
Questions or review requests may be sent to hello@engageminty.com.