NoriaCRMSign in(opens in a new tab)

Legal

Acceptable Use Policy

What the service may not be used for, with the messaging rules spelled out.

Last updated 14 September 2026

This policy forms part of the Terms of Service. It applies to everyone who uses a workspace, and the customer holding the workspace is responsible for all of them.

Do not

Break the law with it. That includes the law where you are, where your contacts are, and where the service runs.

Put in data you have no right to. Do not upload a contact list you bought, scraped, or took from a former employer. Do not import personal data you have no lawful basis to process.

Use it against the people in it. No harassment, no threats, no discrimination, no deceiving somebody into a payment or a disclosure.

Attack the service. No probing for weaknesses without our written agreement, no attempting to reach another customer’s workspace, no interfering with anybody else’s use of it, no getting round a limit or a cap.

Misrepresent who you are. Do not send a message that hides its sender, imitates someone else, or invites a reply to a person it is not from.

Resell it. Do not provide the service to somebody outside your organisation, or use one seat for several people, unless we have agreed it in writing.

Use it to build a competing product, including by extracting the service’s output at scale to train a model.

Messaging, specifically

Messaging is where most of the risk lives, so these are separate.

Have a basis before you send. Each contact must have a lawful basis for the message you are about to send. For marketing that usually means consent that the person actually gave, to you, knowingly.

Record where consent came from. The service stores consent and withdrawal against each contact. Use it. A consent record you cannot explain the origin of is not a consent record.

Honour an opt out immediately, across every channel, not just the one they replied on. Do not message someone again because a different rep imported them again.

Follow the network’s rules, not just the law. WhatsApp messages are subject to the WhatsApp Business Messaging Policy and to Meta’s template approval. SMS is subject to the rules of the operators carrying it and to the sender ID you registered. Breaking these can get your number or sender ID blocked, which is between you and them.

Send at reasonable hours and at a reasonable frequency. Volume alone can turn a lawful campaign into a complaint.

Do not use messaging for one-time passwords, account recovery, or anything security critical for a third party’s system.

AI features, specifically

Check it before you act on it. AI output is a suggestion until a person accepts it. Do not configure a process, or instruct your team, so that suggestions are accepted without being read.

Do not put in what should not leave. Content sent for AI processing reaches the model providers on the sub-processors page. Do not paste credentials, special category data, or somebody else’s confidential material into a note in order to have AI work on it.

Do not use it to generate content that this policy forbids you to send.

Reporting abuse

If you believe a workspace is being used in breach of this policy, write to [email protected] with enough detail for us to find it.

What happens if you break it

Depending on what happened, we may ask you to fix it, limit a capability, suspend a user or the workspace, or end the agreement. Where the breach risks immediate harm to someone, or to the service, we may act first and tell you straight after.

Section 11 of the Terms of Service covers suspension, and section 15 covers who carries the cost of a claim arising from a breach of this policy.