Acceptable Use Policy
Version 1.0 — Effective 2026-09-22
This Acceptable Use Policy ("AUP") forms part of the Terms of Service between Apex Academy d.o.o. and each Customer. It applies to the Customer, its Authorised Users, and every agent, app, workflow, tool and page they build or publish on the Service. Capitalised terms have the meaning given in the Terms. If the Croatian and English versions differ, the Croatian version prevails.
1. Unlawful and harmful content
You must not use the Service to create, store, publish or transmit content that:
- is unlawful, including content that infringes intellectual-property, privacy or personality rights;
- sexually exploits or endangers children, in any form;
- incites violence, terrorism or hatred against people on the basis of a protected characteristic;
- is defamatory, harassing or threatening;
- is fraudulent or deceptive, including phishing pages, fake reviews, or impersonation of another person or organisation.
2. Prohibited AI practices
You must not use the Service for any practice prohibited by Article 5 of the EU AI Act, as listed in our EU AI Act statement. In addition, you must not:
- deploy an agent that hides its AI nature from people who interact with it, or disable the AI disclosure where that nature is not obvious from context;
- generate deep fakes or other synthetic audio, image or video of real people without clear labelling and a lawful basis;
- use AI output as the sole basis for decisions with legal or similarly significant effect on a person, without human review.
3. Personal data
- You must have a lawful basis for all personal data you put into the Service and must inform the people concerned as the GDPR requires.
- You must not submit special categories of personal data (GDPR Art. 9) or data on criminal convictions (Art. 10) unless agreed in writing as set out in clause 4 of the DPA.
- You must not use the Service to build profiles of people from data collected without their knowledge, or to track people covertly.
4. Messaging and outreach
- You must not send unsolicited commercial communications (spam) by email, SMS, WhatsApp or any other channel, or messages to people who have not consented where consent is required.
- You must comply with the policies of the channels you connect, including the WhatsApp Business and messaging-provider policies.
- Every outbound message must identify the sender and offer an easy way to opt out where the law requires it.
5. Security and system abuse
You must not, and must not use agents, tools or code on the Service to:
- access, probe or scan systems or accounts without authorisation, including other Instances and our infrastructure;
- carry out or support denial-of-service attacks, or distribute malware, ransomware or other malicious code;
- circumvent security measures, sandboxes, rate limits, usage limits or access controls of the Service;
- scrape or harvest websites or services in breach of their terms or technical access restrictions;
- mine cryptocurrency or run workloads unrelated to your business use of the Service on its compute resources.
Security testing of your own Instance requires our prior written agreement. Report vulnerabilities to legal@apexacademy.hr.
6. Use for other organisations
Building on or providing the Service for other organisations requires a Partner Agreement, as set out in clause 6 of the Terms.
7. Your responsibility
The Customer is responsible for the agents, apps and other resources it publishes and for how they behave towards its end users, including content produced by AI models and actions taken by tools it configures. The Customer must configure a way for end users to reach a human where agents cannot help adequately.
8. Enforcement
If we become aware of a breach of this AUP we will usually ask you to remedy it first. Where the breach causes or risks serious harm, we may immediately disable the resources concerned under clause 16 of the Terms. Serious or repeated breaches are a material breach of the Terms. We cooperate with competent authorities where the law requires it.
9. Reporting
Report suspected breaches of this AUP, including by agents or apps published on the Service, to legal@apexacademy.hr. We acknowledge reports within five working days.