Use Orvix only for legitimate, authorized business operations.
This Acceptable Use Policy applies whenever any person or organization accesses or uses an Orvix website, trial, workspace, client portal, API, automation, integration, file-storage function, support channel or related service. It forms part of the Orvix Terms of Service and Subscription Agreement.
Do not use Orvix in a way that threatens security, violates rights, disrupts service, extracts data without permission, bypasses controls or exposes Orvix, its customers or third parties to avoidable harm.
Users cannot engage in the following activities.
Security attacks and service disruption
You must not attack, disrupt, overload, disable or degrade Orvix Suite or any connected system. This includes denial-of-service activity, vulnerability probing, port scanning, penetration testing, traffic flooding, destructive requests or attempts to interfere with platform availability, except where Orvix has provided prior written authorization for a defined security test.
Malicious files, code and payloads
You must not upload, transmit, store, execute or distribute malware, ransomware, spyware, viruses, worms, trojans, exploit code, harmful macros, malicious links, corrupted files or any material intended to damage systems, steal credentials, obtain hidden access or compromise data.
Automation, API and resource abuse
You must not use bots, scripts, integrations, AI features, APIs or bulk actions to bypass rate limits, subscription limits, approval controls, user permissions or safeguards. Prohibited activity includes excessive automated requests, credential stuffing, spam actions, artificial activity, repetitive task creation and any automation that materially degrades the service or affects other customers.
Scraping, harvesting and unauthorized extraction
You must not crawl, scrape, harvest, index, copy, mirror, download in bulk or extract platform content, customer information, user details, pricing logic, interface elements or operational data through unsupported or unauthorized means. This includes using extracted material to build datasets, profiles, competing services or AI training resources. Public search-engine indexing that follows Orvix robots instructions and expressly authorized integrations are not prohibited.
Unauthorized access and credential misuse
You must not attempt to access another account, workspace, client portal, file, record, integration, database, administrative function or system without authorization. You must not share access outside approved users, impersonate another person, hijack sessions, escalate privileges, evade authentication or use credentials obtained without the account owner’s permission.
Illegal, fraudulent or harmful activity
You must not use Orvix Suite to violate applicable law, commit fraud, send unlawful or deceptive communications, infringe intellectual-property rights, violate privacy rights, unlawfully process personal data, harass others or manage content, campaigns or records that you are not legally authorized to control.
Circumvention and platform exploitation
You must not reverse engineer the service except where a non-waivable law expressly permits it, bypass subscription or add-on limits, avoid payment obligations, remove ownership notices, resell or sublicense access without written authorization, or use Orvix technology, confidential information or non-public interfaces to create or support a competing product.
Abuse of customer and client communications
You must not use workflows, notifications, approvals, client portals, email, WhatsApp links or integrations to distribute spam, phishing, misleading requests, unauthorized promotions or content that could reasonably expose recipients, customers or Orvix to security, legal or reputational harm.
Workspace owners are responsible for authorized users and configured integrations.
Customers must apply appropriate roles, remove access when it is no longer required, protect credentials, review automation permissions and ensure that employees, contractors, clients and invited users comply with this policy. A customer must promptly notify Orvix when it becomes aware of compromised credentials, unauthorized access or suspected misuse connected to its workspace.
Orvix may act to protect the platform and affected parties.
When Orvix reasonably believes that this policy has been violated, it may investigate, request information, restrict an integration, throttle activity, quarantine or remove harmful material, temporarily suspend access, terminate access for a material or repeated violation, preserve relevant records and take other proportionate protective measures. Where reasonable and legally permitted, Orvix may provide notice and an opportunity to remedy the violation. Urgent threats may require immediate action.
A trial, inactive subscription, failed payment or sales-led package does not create permission to bypass controls, access restricted features or test the security of Orvix.
Do not test Orvix security without written authorization.
Security research, vulnerability scanning, penetration testing and exploit validation are permitted only under a written authorization that identifies the approved systems, timing, methods and limits. A person who discovers a suspected vulnerability without performing additional intrusive testing should stop, avoid accessing or changing customer data, preserve confidentiality and report the issue to Orvix support.
Report security or abuse concerns promptly.
Reports should include the affected workspace or URL, the activity observed, relevant dates and any non-sensitive evidence that helps Orvix assess the issue. Do not send passwords, complete card details, API keys, webhook secrets or unlawfully obtained personal data by email or WhatsApp.
