Legal
Acceptable Use & Messaging Compliance Policy
This Policy protects recipients, providers, customers, and Sendvelo from unlawful, abusive, deceptive, or insecure use. It applies to all Sendvelo software, accounts, licensing services, APIs, and support.
- Effective:
- October 1, 2026
- Last updated:
- October 1, 2026
1. Customer responsibility
Customers control their self-hosted installations, audiences, content, schedules, integrations, and provider accounts. They are responsible for ensuring each communication is lawful in the recipient's jurisdiction and permitted by the applicable provider.
Sendvelo's opt-in fields, suppression status, templates, tracking, and automation tools are technical aids only. They do not establish consent, determine legal basis, or guarantee compliance.
2. Consent, identification, and opt-out
- Use only contact data lawfully obtained for the specific channel and purpose.
- Maintain verifiable consent records where consent is required, including source, scope, date, and withdrawal.
- Identify the sender accurately and do not disguise origin, routing information, caller identity, or purpose.
- Provide legally required disclosures and a clear, functional opt-out or unsubscribe method.
- Honor withdrawals, STOP requests, suppression lists, complaints, and do-not-contact rules promptly across relevant systems.
- Apply any quiet hours, frequency limits, age restrictions, and special rules for automated or prerecorded communications.
3. Prohibited messaging practices
- unsolicited bulk messages, spam, snowshoeing, list bombing, or messaging purchased, scraped, harvested, or randomly generated contacts;
- phishing, impersonation, fraudulent offers, pyramid schemes, deceptive subject lines, or misleading sender information;
- malware, credential theft, harmful code, exploit delivery, or links intended to compromise a person or system;
- harassment, threats, hate, unlawful discrimination, sexual exploitation, or content that facilitates violence or abuse;
- messages that violate privacy, intellectual-property, publicity, confidentiality, sanctions, export, or consumer-protection laws;
- attempts to evade provider filters, complaint controls, rate limits, opt-outs, or enforcement; and
- use that creates excessive complaints, invalid destinations, carrier penalties, security risk, or material harm to service reputation.
4. Channel and provider rules
Customers must follow all applicable laws and industry requirements, including CAN-SPAM, the Telephone Consumer Protection Act, GDPR, UK GDPR, ePrivacy rules, Ghana's Data Protection Act, national do-not-call rules, carrier codes, and equivalent local requirements.
Customers must also follow the rules of their configured providers, including Meta's WhatsApp Business and template policies, Firebase requirements, email-provider acceptable-use policies, and SMS carrier registration or sender-ID rules. Provider approval of a template or sender does not prove legal compliance.
5. Data and security restrictions
- Do not upload or expose data that you lack authority to process.
- Do not collect passwords, payment-card data, government identifiers, health data, or other sensitive data through messages unless lawfully necessary and appropriately protected.
- Do not share provider secrets, API keys, license keys, or account credentials.
- Do not probe, scan, overload, disrupt, or obtain unauthorized access to Sendvelo, its license service, or another system.
- Do not use tenant-configured external endpoints for server-side request forgery, internal-network discovery, or unauthorized data extraction.
6. AI-assisted features
Customers must review AI-generated content before use and remain responsible for accuracy, rights clearance, recipient impact, and legal compliance. Do not represent generated content as professional advice or use it for unlawful profiling, discrimination, deception, or high-impact automated decisions without appropriate human review.
Do not submit secrets, regulated data, or unnecessary personal information to AI features. Optional AI services may send prompts and content to OpenRouter and selected model providers under the customer's configuration and those providers' terms.
7. License and platform abuse
You must not share license keys outside the licensed organization, operate unauthorized installations, manipulate installation identity or domains, tamper with signed licenses, automate brute-force activation attempts, redistribute release packages, or bypass account, download, API, rate-limit, or licensing controls.
8. Monitoring and enforcement
QASA does not routinely inspect customer-hosted campaigns. We may investigate information available through our accounts, licensing, commerce, download, or support services and reports from providers, recipients, authorities, or rights holders.
Depending on severity, we may request corrective action, restrict support or downloads, suspend an account or license service, revoke a license for material breach, preserve evidence, or report unlawful conduct. We may act immediately where necessary to prevent harm, fraud, security compromise, sanctions exposure, or legal liability.
9. Reporting abuse
Report suspected abuse to support@thesendvelo.com with the sender, message date, channel, relevant headers or screenshots, and why the communication appears unlawful or abusive. Do not send unnecessary personal information. Privacy concerns are handled under our Privacy Policy.
Questions about this document?
Contact support@thesendvelo.com. QASA Solutions is located at 5th Mankralo Link, Mataheko, Accra, Ghana.