Trust

Acceptable use policy

Sanaf acts inside your business systems on your behalf, which makes the question of what it may be used for a real one rather than boilerplate. This policy is short on purpose: if you would not ask a member of staff to do it, do not ask Sanaf.

Last updated 2026-09-04.

Deceiving the people it talks to

  • Presenting Sanaf as a named human being to a customer who asks whether they are talking to a person.
  • Writing reviews, testimonials or references in the voice of a customer who did not write them.
  • Impersonating another company, its staff or its official communications.

Contacting people who did not ask to hear from you

  • Sending bulk unsolicited messages to lists you did not collect or do not have permission to use.
  • Continuing to contact someone after they have asked you to stop.
  • Evading a platform rate limit, filter or opt-out mechanism in order to keep sending.

Reaching systems or data you are not entitled to

  • Connecting an account you do not own or administer, or are not authorised to connect.
  • Using the browser to work around an access control rather than to work within one.
  • Extracting data from a service in breach of that service own terms.

Decisions that need a person and accountability

  • Making a final hiring, firing, lending, housing or insurance decision about a person without human review.
  • Giving medical, legal or financial advice to a third party as if it came from a qualified professional.
  • Acting as the sole safeguard in a situation where a mistake would cause someone physical or financial harm.

Harm, harassment and illegal activity

  • Generating or distributing material that harasses, threatens or targets a person or group.
  • Anything unlawful in the jurisdiction where the work is being done or received.
  • Building or operating anything intended to damage, disrupt or gain unauthorised access to another system.

Working around the product own safeguards

  • Instructing Sanaf to hide, falsify or omit entries from its own work log.
  • Configuring a job specifically to avoid an approval rule that would otherwise apply to that kind of action.
  • Sharing workspace credentials or API keys with people outside the workspace so they can bypass its rules.

What happens if this is broken

  • If we believe this policy is being broken, we will contact the workspace owner first and say what we have seen, unless the situation is urgent enough that waiting would cause harm.
  • We may suspend a job, a connection or a workspace to stop ongoing harm. We will say what we suspended and why.
  • Serious or repeated breaches end the account. Where the law requires it, we report to the relevant authority.
  • We do not read your work to police it. Enforcement starts from a report, a billing anomaly, or an abuse signal from one of the platforms we work in.

Reporting a violation

If you believe a Sanaf workspace is being used in breach of this policy, tell us at the contact address on this site with whatever detail you have. Reports from people outside the workspace are taken as seriously as reports from inside it, and you do not need to be a customer to send one.

See also security and the subprocessor list.