EPAV DESK · ACCEPTABLE USE POLICY
Version 1.0 · Effective from 9 October 2026
Operator: NeriusCognitaren OÜ, registry code 17503018, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia
Abuse reports: abuse@epavdesk.com · Support: support@epavdesk.com
This policy is part of the EPAV Desk Terms of Service. It applies to you, your Agents, and anyone who uses EPAV Desk through your cabinet or your Site. A breach of this policy is a breach of the Terms. The lists below are examples; what matters is the purpose, so a use that breaks their spirit is also not allowed.
1. General rules
Use EPAV Desk to communicate with your own customers and the people who contact you, lawfully and in good faith. You are responsible for what your Site publishes and sends, including the answers of the AI assistant drawn from your knowledge base.
2. Unlawful and harmful content
Do not use EPAV Desk to publish, send or store content, or to offer goods or services, that:
- is illegal where you operate or where your Visitors are, including fraud, scams, phishing and the sale of illegal goods;
- sexually exploits or endangers children, in any form;
- promotes terrorism or violence, or incites hatred or discrimination;
- harasses, threatens or defames anyone;
- infringes copyright, trademarks, privacy or other rights of others;
- contains malware, or links meant to deceive people into revealing credentials or payment data.
3. Spam and unwanted messages
- Do not send messages to people who have not asked to hear from you, through any channel: email, WhatsApp, Telegram or proactive messages in the chat.
- Follow the law on electronic marketing and the rules of each channel. In WhatsApp, follow the WhatsApp Business Messaging Policy: get opt-in, use approved templates outside the 24-hour reply window, and give people a clear way to reach a human.
- Do not use bought or harvested contact lists.
- Do not use the EPAV mailbox for anything other than notifications to your Agents. Do not act in a way that gets our sending domains or addresses blocklisted; one sender's spam harms every customer.
4. Personal and sensitive data
- Have a lawful basis for the personal data you collect through EPAV Desk, and tell your Visitors how you use it.
- Do not ask Visitors for full payment card numbers, card security codes, bank login details or passwords in a conversation. EPAV Desk is not designed to protect payment card data.
- Do not use EPAV Desk to collect health data, data on criminal convictions, government identity numbers or other special categories of personal data, unless you have assessed this and have a lawful basis. Visitors may write such data without being asked; delete what you do not need.
- Do not knowingly collect data of children without the consent required by law.
5. The AI assistant
- Do not hide or remove the notice that tells people they are chatting with an AI assistant, and do not configure or instruct the assistant to claim to be a human.
- Do not use the assistant to give professional legal, medical or financial advice, or to make decisions with legal or similarly significant effects on people, such as about credit, employment, insurance or access to essential services.
- Do not use EPAV Desk for purposes that the EU AI Act prohibits or classifies as high-risk.
- Do not use the assistant to spread disinformation, to influence elections or votes, or to impersonate a real person.
- Do not try to make the assistant ignore its instructions ("jailbreak" or prompt injection) in order to extract other customers' data, our system instructions or anything else it should not reveal, and do not use EPAV Desk to train or build a competing AI model.
6. The platform
- Do not probe, scan or test the security of EPAV Desk, other customers' Sites or our infrastructure without our written permission. If you find a vulnerability, report it to support@epavdesk.com and do not exploit it.
- Do not try to reach data of other customers, bypass authentication, rate limits or sending limits, or get around the limits of your plan by technical tricks.
- Do not overload EPAV Desk, for example with automated traffic far beyond normal use of a support service.
- Do not scrape our websites or reverse engineer EPAV's proprietary software, except as the law or an open-source licence allows.
- Do not resell or share access to EPAV Desk outside your company, except to serve your own clients as the DPA allows.
- Do not impersonate another person or business, or suggest that EPAV endorses you.
7. What we do if this policy is broken
- We may ask you for information and to fix the problem within a reasonable time.
- We may remove or disable specific content, or switch off a specific feature (for example the AI assistant or the EPAV mailbox) for your Site.
- We may suspend your Site or cabinet at once where there is a security threat, serious harm to people, a breach of the law, or a risk to other customers' service, as Section 15 of the Terms describes.
- We may end the contract for a material breach, as Section 10.7 of the Terms describes, without a refund.
We decide each case individually, by people, not by automated decisions. We tell you which rule was broken and why we acted, unless the law or the risk of further harm prevents it, and you can reply to support@epavdesk.com to contest our decision.
8. Reporting abuse
If you believe a Site running on EPAV Desk is used against this policy, or hosts illegal content, write to abuse@epavdesk.com. Please give the address of the Site or the exact content, explain why you believe it breaks the law or this policy, and give your email address for our reply. We may pass your report to our customer who runs the Site. We confirm receipt and tell you what we decided.
9. Changes
We may update this policy. We tell the owners of cabinets about material changes by email at least 15 days before they take effect, as Section 22 of the Terms describes.