askNiva Acceptable Use Policy
> Notice to Consumers (CPA §49). This AUP contains strict prohibitions. Violation of any one of them may result in immediate suspension or termination of your Account without prior notice and without refund (see §13 of the Terms, §16 of this AUP). The most severe prohibitions — child safety (§5.1), CBRNE and weapons (§5.2), terrorism (§5.3), CSAM, and self-propagation or platform-integrity attacks (§9.7) — result in permanent termination and may trigger mandatory reporting to law-enforcement authorities in South Africa, Germany, the United States, and elsewhere. Your statutory rights as a Consumer are preserved per Schedule A to the Terms.
How to read this agreement
This AUP is one of four documents that together form the agreement between you and askNiva:
- Terms of Service (ToS) — the core commercial and legal terms (who we are, what the Service is, billing, liability, termination, dispute resolution).
- Acceptable Use Policy (AUP) — this document; what you may and may not do with the Service.
- Data Processing Addendum (DPA) — applies to your processing of Personal Information through the Service; sets out askNiva's obligations as an Operator under POPIA and processor under GDPR, and regulates sub-processors, international transfers, and security.
- Privacy Policy — explains how askNiva processes Personal Information it collects directly from you (for example, account and billing data).
Order of precedence. If there is a conflict between these documents, the order of precedence is: (i) any signed order form; (ii) the DPA (on data-protection matters); (iii) the ToS; (iv) this AUP; (v) the Privacy Policy; (vi) any other policy incorporated by reference. See §23.2 of the Terms.
---
1. Scope and interpretation
1.1 Incorporation. This Acceptable Use Policy (the "AUP") is part of the askNiva Terms of Service (the "Terms"). It tells you what you may and may not do with the askNiva Service, your Instance, and any openClaw agent you configure on your Instance. It is binding on you and on anyone you allow to use the Service under your Account. Capitalised terms have the meaning given in the Terms.
1.2 Material breach. Violation of any part of this AUP is a material breach of the Terms, regardless of whether askNiva identifies a specific remedy for the violation (see §16 for enforcement).
1.3 Responsibility for your Instance. You are responsible for everything that happens on your Instance, whether you did it personally or not. If you let someone else use your Instance, configure an agent that acts on your behalf, or integrate with third-party services, the acts of those people, agents, and systems are your acts for the purposes of this AUP (see §13 for end-user flow-down).
1.4 Voice convention. Operative provisions use the defined term "askNiva". For plain-English callouts and explanatory passages, askNiva may use "we", "us", and "our" interchangeably with "askNiva"; in operative provisions the defined term governs.
---
2. Why this AUP is strict
2.1 askNiva runs on third-party infrastructure (Hetzner) and depends on third-party AI Providers (Anthropic, OpenAI, Google). askNiva's infrastructure provider and the AI Providers each have their own acceptable-use rules. A breach of any one of them by you can cause:
- Hetzner to lock, null-route, or terminate your Instance (and possibly other askNiva Instances with the same IP pool or account);
- an AI Provider to revoke your API key;
- askNiva's own Hetzner account or commercial relationship with an AI Provider to be suspended or terminated;
- legal action against askNiva, against you, and potentially against third parties;
- criminal investigation in the jurisdiction where askNiva's infrastructure is located (Germany), where you are located (South Africa), or where your agent or counterparties are located.
2.2 Strictest rule wins. Where providers, jurisdictions, or policies conflict, askNiva applies the strictest applicable rule. Compliance with this AUP does not excuse non-compliance with Hetzner's terms, any AI Provider's terms, or applicable law — you must comply with all of them simultaneously.
---
3. Legal framework
This AUP references, and requires your compliance with, the following legal frameworks. Where a prohibition in §§5–11 is tied to a statute, the cross-reference appears there.
3.1 South African law. In particular: the Protection of Personal Information Act 4 of 2013 ("POPIA"); the Consumer Protection Act 68 of 2008 ("CPA"); the Cybercrimes Act 19 of 2020; the Films and Publications Act 65 of 1996 (as amended); the Electoral Act 73 of 1998; the Financial Intelligence Centre Act 38 of 2001 ("FICA"); and the Electronic Communications and Transactions Act 25 of 2002 ("ECTA").
3.2 German criminal law (applies because Instances physically run on Hetzner infrastructure in Germany, regardless of your own location):
- §130 StGB (Volksverhetzung / incitement to hatred): criminalises content that incites hatred against part of the population or disturbs public peace by insulting, maliciously maligning, or defaming part of the population. Holocaust denial is included.
- §86 / §86a StGB: criminalises the distribution or display of symbols of Nazi organisations, banned terrorist groups, or similarly banned organisations (including swastikas, SS-runes, ISIS flags).
- §131 StGB: depictions of violence with a glorifying or inhumane effect.
- §166 StGB: defamation of religious or ideological beliefs in a manner that disturbs public peace (see also §11.2(a)).
- §§184, 184a, 184b, 184c, 184d StGB: various categories of sexual content, with §184b (child sexual abuse material) being the most strictly enforced; §184a (violent or bestial pornography) and §184c (youth-pornographic material not reaching §184b) are also criminal; §184d extends these prohibitions to broadcasting and tele-media distribution.
- §§185–187 StGB: insult (Beleidigung), defamation (üble Nachrede), and intentional defamation (Verleumdung).
- §§202a, 202b, 202c StGB: unauthorised access to specially-secured data (Ausspähen von Daten), intercepting data (Abfangen von Daten), and preparing such offences (including possession / distribution of hacking tools).
- §240 StGB (Nötigung / coercion): coercing any person, by force or threat of harm, to do, tolerate, or abstain from an act — relevant to agent-driven extortion, pressure, or threat scenarios.
- §241 StGB (Bedrohung / criminal threats): threatening a person with the commission of a felony against them or a person close to them.
- §§303a, 303b StGB: data alteration (Datenveränderung) and computer sabotage (Computersabotage) — the statutes that ground DDoS, ransomware, and service-disruption offences.
- Any further provision of the StGB, BDSG, NetzDG, or other German law applicable to content or conduct on infrastructure located in the Federal Republic of Germany, and any applicable EU law (including DSA, GDPR, and EU AI Act).
3.3 Upstream provider policies. You shall comply with Hetzner's terms (see §14) and every AI Provider's policies (see §15) simultaneously.
3.4 Foreign law. You shall also comply with the law of your location and the law of any location in which your agent operates or that you target.
3.5 German criminal-law flow-down. The StGB sections enumerated in §3.2 are incorporated into this AUP not because every section reaches a non-resident User extraterritorially under StGB §§3, 5, 7, or 9 (several do; several do not), but because (a) your Instance runs on DE-located Hetzner infrastructure, (b) Hetzner is strictly liable to third parties for content on that infrastructure, (c) Hetzner AGB §§7.1–7.3 and §9.2 make askNiva strictly liable to Hetzner for your conduct regardless of whether German criminal jurisdiction personally reaches you, and (d) askNiva is contractually required to pass that exposure through to you under ToS §16.1A. Your contractual duty to comply with the §3.2 enumeration is therefore independent of whether you could personally be prosecuted in Germany. For the avoidance of doubt: conduct that would be lawful in South Africa but would breach Hetzner AGB §§5.2, 8.2, or 8.3 (for example, publication of pornographic material that is legal in SA, certain forms of political expression that are lawful under the South African Constitution but fall within §130 StGB Volksverhetzung, or gambling content lawful in SA but prohibited by AGB §8.2) is not permitted on your Instance.
---
4. General principles
4.1 No illegal activity. You shall not use the Service, your Instance, or any agent to commit, facilitate, attempt, or conspire to commit any act that is illegal under any framework referenced in §3. You warrant that any activity you undertake with the Service is lawful in all jurisdictions in which it has effect.
4.2 You are the operator. You are the operator of every agent configured on your Instance. You are solely responsible for every action any agent takes, whether that action arose from direct instruction, general configuration, a prompt-injection attack (see §9.5), or model unpredictability.
4.3 AI disclosure. If an agent configured on your Instance communicates with a human, you shall ensure the agent discloses, at the beginning of each session and on sincere inquiry, that it is an AI and not a human. This applies to any messaging channel (email, chat, SMS, voice, social DM). You shall not use the Service to present AI-generated content as human-generated in any context where that representation is material to the recipient, whether the content is delivered in a session, asynchronously, or as a published artefact (including automated social-media posts, AI-authored articles, AI-authored code review, or AI-generated correspondence). Where any Output is presented to an individual (including indirectly through advice, recommendations, or documentation), you shall disclose to that individual that AI has been involved in producing the Output. You shall comply with any statutory or regulatory AI-disclosure, content-labelling, provenance-marking, or synthetic-content-labelling obligation in any jurisdiction where Output is consumed (including EU AI Act Article 50, US state deepfake-labelling laws, and analogous rules).
4.4 Aiding and abetting. Aiding, abetting, encouraging, or conspiring to do anything prohibited by this AUP is itself prohibited.
> In plain English: You may not do anything illegal with the Service; you are accountable for whatever your agent does; your agent must disclose that it is an AI when talking to humans; and helping someone else break the rules counts as breaking them yourself.
---
5. Safety-critical prohibitions
These prohibitions apply universally and are not subject to carve-outs. Violation of this §5 is grounds for immediate termination without notice.
5.1 Child safety (zero tolerance)
> In plain English: Anything that sexualises, exploits, or endangers children is absolutely prohibited. There is no research, artistic, satirical, or "it's AI-generated and not real" exception. A violation means permanent termination and mandatory reporting to the police.
You shall not, under any circumstance, use the Service to:
- (a) create, possess, distribute, promote, publish, access, store, transmit, or generate child sexual abuse material ("CSAM"). CSAM includes fully or partly AI-generated CSAM, fictional CSAM, sexualised depictions of minors, and hentai or anime sexualising characters presented or appearing to be minors;
- (b) groom a minor. Grooming includes generating content designed to manipulate, trick, desensitise, or sexually exploit a person under 18;
- (c) impersonate a minor, or operate a chatbot presenting as a minor;
- (d) facilitate or promote the sexual exploitation, sextortion, trafficking, or abuse of minors;
- (e) fetishise or sexualise minors in any context, including role-play;
- (f) promote or facilitate pedophilic relationships, including through role-play with an AI model;
- (g) expose minors to age-inappropriate content. This includes graphic self-harm, sexual, or violent content; promotion of unhealthy dieting or exercise behaviour to minors; shaming or stigmatising the body type or appearance of minors; and designing dangerous challenges aimed at minors;
- (h) facilitate underage access to age-restricted goods, services, or activities. Age-restricted items include alcohol, tobacco, firearms, gambling, sexual content, and restricted substances;
- (i) deploy, market, or operate any AI agent, application, or product (including an agent built on your Instance) that is directed at, likely to be accessed by, or primarily used by persons under 18 (or under 13 in the EEA, UK, or Switzerland, where lower), except where the relevant AI Provider has given express written authorisation for that use case, you have implemented age-appropriate safety features, you have conspicuously disclosed AI involvement, and you have obtained and evidenced any required parental or guardian consent. Specific AI-Provider rules apply (for example, OpenAI's Under-18 API Guidance and Zero Data Retention requirement for under-13 processing; Anthropic Usage Policy §4.2 minor-product safety-feature duty; Google Gemini / Vertex AI restrictions on minor-directed generative-AI apps; AWS's 18+ / parent-consented-13+ baseline);
- (j) knowingly allow any person under 18 (or a lower age permitted by the relevant AI Provider, for example 13 with verifiable parental consent) to interact with an agent configured on your Instance where an AI Provider has routed any part of the interaction.
CSAM is prohibited whether or not it was generated by AI, whether or not it depicts a real child, and whether or not it is legal in your jurisdiction. This is a permanent-termination offence. askNiva will report any suspected CSAM to the South African Police Service, the National Center for Missing and Exploited Children (NCMEC), and the German authorities (§184b StGB criminalises CSAM possession and distribution). askNiva may preserve and disclose all available evidence to those authorities without notice to you. You shall not tip off, alert, or notify any person (including the suspected perpetrator) of any CSAM preservation, reporting, or investigation by askNiva or any authority. You shall cooperate with any NCMEC CyberTipline submission or SAPS / German authority process, including by preserving original hashes, metadata, and unaltered copies of the relevant Customer Data.
5.2 CBRNE and weapons
You shall not use the Service to:
- (a) develop, design, synthesise, or produce, or help another develop, design, synthesise, or produce, any chemical, biological, radiological, nuclear, or high-yield explosive ("CBRNE") weapon, component, precursor, or delivery mechanism;
- (b) provide instructions, diagrams, protocols, formulas, or operational details for any CBRNE weapon;
- (c) develop, design, synthesise, acquire, modify, or use any conventional weapon, or any related delivery or targeting system, without explicit lawful authority and full disclosure of purpose on request;
- (d) circumvent regulatory controls to acquire weapons, their precursors, or dual-use items;
- (e) traffic in arms or ammunition;
- (f) design, build, or operate any fully autonomous weapons system capable of selecting or engaging targets without human control.
5.3 Violence, terrorism, and critical infrastructure
You shall not use the Service to:
- (a) incite, facilitate, promote, or glorify violence, terrorism, hate-based violence, violent extremism, or hateful behaviour (see also §3.2 on §131 StGB);
- (b) provide aid to any terrorist organisation or violent-extremist actor, including recruitment, training, fundraising, propaganda, or operational support;
- (c) target, attack, or threaten critical infrastructure, including power grids, water treatment, telecommunications, medical devices, financial infrastructure, transportation systems, or voting systems.
Legitimate research carve-out. Academic, defensive, or policy research concerning violence or weapons may be permitted with clear professional authority, disclosure of the research context on request, and strict compliance with applicable law. If you are not sure your use case qualifies, do not use the Service for it until you have written confirmation from askNiva.
5.4 Absolute prohibitions (no carve-out, no exceptions, no legitimate-research waiver)
Notwithstanding any other provision of this AUP (including the legitimate-research carve-out in §5.3, the vulnerability-research carve-out in §6.4, the journalism / political-expression carve-out in §10.2, and any written-authority process), the following uses are prohibited without exception and are not subject to any carve-out, waiver, or written-confirmation procedure:
- (a) design, development, operational use, or deployment assistance of any weapon, weapons system, weapon component, or targeting system (without limiting §5.2);
- (b) disinformation campaigns, coordinated inauthentic-behaviour campaigns, or information operations;
- (c) domestic mass surveillance of populations, including on behalf of any government or state actor;
- (d) censorship on behalf of any government or state actor in a manner inconsistent with applicable human-rights law;
- (e) malicious cyber operations (offensive cyber, ransomware operation, persistent-access kit development for adversarial deployment);
- (f) any use that any AI Provider's policy or any hyperscaler's policy categorises as unconditionally prohibited (including Anthropic Usage Policy §5 "unconditionally forbidden" items, Azure AI Code of Conduct §2.2 categorical prohibitions, and equivalent Google / OpenAI / AWS categorical rules).
Where an AI Provider treats a use as categorically prohibited under its own terms, that prohibition applies absolutely to your use of the Service regardless of jurisdiction, licensing, human oversight, or consent.
---
6. Cybersecurity and network abuse
6.1 Unauthorised access and malware
You will not use the Service to:
- (a) gain, or attempt to gain, unauthorised access to any computer, network, system, application, account, data, or device;
- (b) discover or exploit vulnerabilities in any system without the explicit prior consent of the system's owner;
- (c) create, distribute, store, or deploy malware, ransomware, spyware, rootkits, keyloggers, worms, trojans, logic bombs, viruses, or other malicious code;
- (d) operate, control, or contribute to any botnet, command-and-control server, DDoS network, or similar;
- (e) develop tools for denial-of-service attacks, botnet management, or mass compromise;
- (f) intercept, monitor, or tamper with any communication without explicit authorisation;
- (g) credential-stuff, credential-spray, password-crack, brute-force any authentication system, or use stolen or illegally-obtained credentials;
- (h) bypass safety, rate-limit, authentication, authorisation, or monitoring controls of any system (including those of AI Providers — see also §9.1(a));
- (i) develop persistent-access tools designed to operate below normal system-security levels;
- (j) intercept, extract, or exfiltrate data from any system without explicit authorisation.
6.2 Scanning, probing, and DoS
You will not, and you will not cause your agent to:
- (a) scan, probe, port-scan, vulnerability-scan, or perform reconnaissance on any system you do not own or do not have explicit permission to test (including Hetzner-owned networks, askNiva infrastructure, and any third-party service);
- (b) launch, participate in, amplify, or reflect any denial-of-service or distributed denial-of-service attack;
- (c) generate synthetic or simulated denial-of-service traffic from your Instance, even against your own systems;
- (d) crawl, monitor, or probe any system in a manner that impairs, disrupts, or materially burdens it;
- (e) generate traffic patterns that a reasonable network operator, acting on packet-metadata analysis, could interpret as a scan, probe, or attack — including high connection rates to diverse hosts, SYN-flood-like signatures, authentication-retry bursts, DNS-zone-walking queries, or equivalent patterns. The objective appearance of your traffic to Hetzner's or any AI Provider's automated abuse systems is decisive for §§14.2 enforcement purposes; your subjective intent is not a defence.
6.3 Network integrity
You will not, and you will not cause your agent to:
- (a) operate a Tor exit node, I2P exit, Freenet node, commercial or free VPN-exit service, SOCKS-anonymization exit, or any other anonymization-exit or traffic-laundering service where your Instance is the apparent origin of traffic on behalf of unknown third parties (running Tor relays or bridges for legitimate privacy purposes is permitted provided you respond promptly to any abuse complaint we forward);
- (b) operate an open proxy, open mail relay, open recursive DNS resolver, or similar service;
- (c) forge, spoof, or falsify IP headers, MAC addresses, email headers, SMTP sender data, or any other part of a packet or message describing its origin or route;
- (d) use fake, borrowed, or stolen source IP addresses;
- (e) manually change or mask the hardware (MAC) address of any virtualised or emulated network interface;
- (f) make network connections to any users, hosts, or networks without permission to communicate with them;
- (g) bypass, evade, or circumvent network-level rate limits, quotas, IP-based access controls, or similar restrictions imposed by any service.
6.4 Vulnerability research carve-out
Good-faith, responsibly-disclosed vulnerability research is permitted, but only (i) against systems you own, (ii) against systems whose owner has given explicit consent (for example, through a bug-bounty programme or a signed pen-test engagement), (iii) within the scope that owner has authorised, and (iv) in compliance with the target cloud's pen-testing policy where applicable — techniques prohibited by the target cloud's pen-test policy (for example, DoS / DDoS simulation, DNS zone walking, protocol / port / request flooding, aggressive or Internet-wide scanning) remain prohibited under this AUP even where the target is your own account on that cloud. Research against askNiva infrastructure, Hetzner infrastructure, or any AI Provider without written permission is prohibited.
---
7. Privacy, surveillance, and personal data
7.1 Unlawful collection and profiling
You will not use the Service to:
- (a) collect, scrape, harvest, buy, sell, or trade personal information about any person without their knowing consent (or another lawful basis under POPIA or the applicable privacy law) and a legitimate purpose;
- (b) track, monitor, profile, or target a person's physical location, movements, emotional state, or communications without their consent;
- (c) publish or disclose any person's private information (home address, phone number, financial account, medical information, immigration status, sexual orientation, or other sensitive attributes) without their explicit consent (doxxing).
7.2 Biometric and inference restrictions
You will not use the Service to:
- (a) build or contribute to any facial-recognition database (including by scraping facial images from the internet, CCTV footage, or any other source);
- (b) perform real-time or near-real-time remote biometric identification of people in public spaces;
- (c) categorise, classify, or score individuals based on their biometric data to infer race, ethnicity, political opinions, trade-union membership, religious or philosophical beliefs, sex life, sexual orientation, or health;
- (d) infer a person's emotional state (including through facial expression, voice pattern, text, or behavioural signal) in any context, except (i) with the Data Subject's explicit informed consent, or (ii) for strict medical or life-safety reasons; workplace and educational emotion-inference is prohibited in every case;
- (e) infer sensitive attributes (including race, religion, nationality, sexuality, gender identity, health status, immigration status, or criminal history) about any person without their explicit consent.
7.3 Mass surveillance and social scoring
You will not use the Service to:
- (a) conduct mass or untargeted surveillance of any population;
- (b) build or operate any social-scoring system that ranks people on their social behaviour or personal traits;
- (c) assess or predict the risk of any person committing a criminal offence based solely on personal traits or profiling;
- (d) censor content on behalf of any government in a manner that violates applicable human-rights law;
- (e) perform stalking, cyber-stalking, or intrusive investigation of any person.
7.4 POPIA compliance
If you are a Responsible Party or Operator within the meaning of POPIA and you process personal information through the Service, you will comply with POPIA's conditions for lawful processing, including your obligations to the data subjects whose information you process. The DPA sets out the processor-side obligations as between you and askNiva.
---
8. Deceptive practices, fraud, and communications integrity
8.1 Fraud and deception
You will not use the Service to:
- (a) commit, attempt, facilitate, or promote fraud, scams, Ponzi or pyramid schemes, make-money-fast schemes, advance-fee frauds, or any other deceptive financial activity;
- (b) phish, pharm, or spoof any person, service, or institution;
- (c) engage in social engineering (including pretexting, spear-phishing, business-email-compromise, CEO-fraud-style impersonation);
- (d) commit identity theft, synthetic-identity fraud, or use another person's identity without consent;
- (e) generate false reviews, testimonials, endorsements, or engagement on any platform;
- (f) misrepresent who you are in commerce (false advertising, fake accounts, inauthentic activity);
- (g) generate false or misleading claims of expertise (medical, legal, financial, governmental, or similar) intended to deceive a counterparty;
- (h) commit, facilitate, or participate in academic dishonesty (plagiarism, contract cheating, generating work to be represented as the student's own);
- (i) misrepresent the provenance of AI-generated content by falsely claiming it was solely created by a human in a context where that representation is material;
- (j) manipulate markets, wash-trade, pump-and-dump, or spoof trading activity;
- (k) commit credit-card fraud, chargeback fraud, or account-takeover fraud;
- (l) commit money laundering, terrorist financing, or transactions with designated persons under any applicable financial-crimes law (see FICA, §3.1);
- (m) evade sanctions imposed by the United Nations, European Union, United States (including OFAC), United Kingdom, or South Africa;
- (n) acquire, distribute, market, or exchange illegal or controlled substances;
- (o) engage in, facilitate, or promote human trafficking, forced labour, slavery, or prostitution;
- (p) traffic in stolen goods, counterfeit goods, endangered species, cultural artefacts with disputed provenance, or other contraband.
8.2 Impersonation, likeness, and synthetic media
You will not use the Service to:
- (a) impersonate any real person, organisation, employer, celebrity, public official, journalist, government, or institution without explicit and valid consent and all necessary rights (including any publicity, personality, union, or moral-rights clearances), including by use of that person's name, handle, username, title, email, signature, persona, branding, or any other identifier likely to cause confusion;
- (b) generate, publish, or distribute voice clones — that is, synthetic audio that reproduces an identifiable person's voice — without that person's express, specific, informed, and revocable written consent and all necessary rights (and, where the person is a politician, government official, candidate, or where the content could affect a democratic process, such synthetic audio is prohibited even with consent — see §10);
- (c) generate, publish, or distribute video deepfakes of any identifiable person — that is, synthetic or manipulated video that depicts a person saying or doing something they did not in fact say or do — without that person's express, specific, informed, and revocable written consent and all necessary rights, with the same carve-out for political figures and democratic processes as §8.2(b);
- (d) generate photorealistic images of any identifiable real person (living, deceased, public, or private) without that person's express consent and all necessary rights; and where the person is a politician, government official, candidate, or where the image could affect a democratic process, such photorealistic images are prohibited even with consent (matching §8.2(b)/(c));
- (e) create a chatbot, avatar, persona, role-play character, or digital companion that is a persona of a specific real person without that person's express, specific, informed, and revocable written consent and all necessary rights; and where the person is a politician, government official, candidate, or where the persona could affect a democratic process, such personas are prohibited even with consent;
- (f) reproduce the likeness (including face, body, voice, name, signature, persona, characteristic gestures, or other identifying features) of any person without their express consent and all necessary rights;
- (g) generate synthetic media that is reasonably likely to be mistaken for authentic documentation, news footage, evidence, or recorded events (for example, fabricated CCTV, forged correspondence, fake press briefings), whether or not an identifiable person is depicted.
Educational, satirical, journalistic, or creative uses involving public figures may be permitted where (i) the synthetic nature of the content is clearly and conspicuously disclosed to the viewer at the point of consumption, (ii) there is no reasonable likelihood of deceiving viewers as to authenticity, (iii) no sexualised content is generated, and (iv) the use complies with applicable defamation, publicity-rights, copyright, and election law. If your use is close to the line, treat it as prohibited until you have written confirmation from askNiva.
8.3 Spam and unsolicited communication
You will not use the Service to:
- (a) send, generate, facilitate, or assist in the transmission of unsolicited commercial email ("UCE"), unsolicited bulk email ("UBE"), unsolicited commercial SMS, unsolicited commercial fax, or any other unsolicited bulk electronic communication, regardless of lawful basis in any single jurisdiction;
- (b) transmit messages to any person without an established prior commercial relationship that meets every applicable law (including POPIA §69 direct-marketing rules, the US CAN-SPAM Act, the US Telephone Consumer Protection Act, the EU ePrivacy regime, and any equivalent local law);
- (c) send messages with falsified, forged, misleading, or disguised sender information;
- (d) send messages from infrastructure not authorised to send for the sender domain;
- (e) mass-DM, mass-comment, mass-message, or mass-post on any messaging platform, social network, forum, or community (including Signal, Telegram, Discord, WhatsApp, Slack, iMessage, email, SMS, X, LinkedIn, Reddit, or similar), regardless of the content;
- (f) create or operate email bombing, SMS bombing, or communication-flooding campaigns;
- (g) automate a response-chain outreach sequence of any scale that, taken together, constitutes bulk unsolicited contact.
Legitimate carve-out. Automated messaging by a personal assistant replying to your own incoming messages, or a transactional notification to your own confirmed customer, is permitted if it complies with every applicable law and platform policy.
---
9. AI-specific prohibitions and agent autonomy
9.1 Model abuse
You will not use the Service to:
- (a) bypass, jailbreak, or attempt to circumvent the safety controls, content filters, policies, guardrails, or protective measures of any AI Provider's model, including by means of adversarial prompts, prompt-injection payloads, policy-evasion techniques, or circumvention of any rate limit, moderation, or abuse-detection control of any AI Provider or any third-party AI-powered service — and including by disabling, lowering the sensitivity of, or configuring around any customer-configurable safety feature, content-filter tier, or abuse-monitoring setting provided by an AI Provider or hyperscaler (for example, Azure OpenAI content-filter tiers, Anthropic safety classifiers, OpenAI moderation or safety-system toggles, Google Gemini safety-attribute thresholds) below the provider's default setting, except with that provider's express written authorisation;
- (b) train, fine-tune, distil, or develop any AI or machine-learning model using inputs to or outputs from an AI Provider's model, without that provider's prior written consent;
- (c) extract, reverse engineer, replicate, or learn the weights, parameters, architecture, embeddings, or training data of any AI Provider's model;
- (d) scrape, extract, or harvest AI Provider Outputs at scale for any purpose that would contravene the AI Provider's terms;
- (e) store, execute, or distribute known jailbreak prompts, model-extraction toolkits, or published policy-evasion libraries on your Instance;
- (f) use any AI Provider's service (including Anthropic, OpenAI, Google Gemini / Vertex AI, AWS Bedrock, Azure OpenAI, or any other) to develop, train, fine-tune, distil, benchmark, evaluate, or build any product or service that competes with, resells, wraps, repackages, or replicates that AI Provider's products or services, or to generate synthetic training datasets for any such purpose, except under a "Permitted Exception" or equivalent express written authorisation from that AI Provider;
- (g) use the Service to generate, test, weaponise, or deploy prompt-injection, jailbreak, or adversarial-prompt attacks against any other AI service, agent, or user;
- (h) remove, alter, obscure, or tamper with any AI Content Credential, C2PA provenance mark, cryptographic watermark, SynthID, or equivalent provenance-signalling mechanism attached by any AI Provider to any Output;
- (i) operate any registration-gated or Limited-Access-gated AI-Provider capability (including Azure OpenAI Modified Content Filters, abuse-monitoring opt-outs, Azure Managed Customer Access Program / MCAP-gated features, or equivalent Limited Access / Managed Access programmes of any AI Provider) unless you have current written approval from that AI Provider, evidence of which you shall furnish to askNiva on demand;
- (j) operate your Instance as, or configure your Instance to function as, a thin wrapper, proxy, or substantially-equivalent clone of any AI Provider's API offered or resold for third-party use (including paid, quota-limited, or tokenised API access);
- (k) benchmark, performance-test, or publish comparative evaluations of the Service, the askNiva Platform, or askNiva's control plane against any third party's service without askNiva's prior written consent (this does not restrict your right to use the Service for your own internal evaluation).
9.1A Affirmative safety, moderation, and provenance duties
You shall, for any Instance that presents Output to any person other than yourself:
- (a) keep enabled, configured, and effective all filtering, safety, citation, moderation, and provenance features that each AI Provider supplies, at the default configuration or stricter — never weaker — unless you hold the AI Provider's express written authorisation for the weaker configuration (see §9.1(i));
- (b) use the AI Provider's moderation endpoint (for example, OpenAI's Moderation API) or deploy an equivalent content-classification layer with comparable coverage of violence, self-harm, sexual content, and harassment;
- (c) retain records of moderation-endpoint invocations and their results for at least twelve (12) months and produce those records to askNiva within seventy-two (72) hours of request made in connection with an AI-Provider enquiry, abuse report, or regulatory process;
- (d) where your Instance generates AI-generated video, image, audio, or other synthetic media presented to any person other than yourself, apply a durable visible watermark (or equivalent durable provenance signal accepted by the relevant AI Provider) and AI Content Credentials or equivalent C2PA-compliant metadata, before publication;
- (e) where your Instance operates as an autonomous agent presenting decisions or actions to any third party, (i) implement meaningful human-user controls to monitor, intervene, and override; (ii) publish documentation of the agent's autonomous capabilities, limitations, decision-making, and action-taking processes adequate for a reasonable end user to understand; and (iii) maintain an abuse / anomaly / feedback channel for end users.
Failure to perform any duty in this §9.1A is a material breach.
9.2 Regulated professional advice
You will not use the agent to provide legal, medical, financial, tax, insurance, psychological, or other regulated professional advice in a jurisdiction where such advice requires a licensed professional, unless you have the required licence and you involve an appropriately qualified human reviewer.
Clinical, medical-device, and robotics carve-in. Notwithstanding the licensed-professional-plus-human-review pathway above, the following uses are absolutely prohibited where the relevant AI Provider's terms forbid them (for example, Google Gemini API Additional Terms §2.6, Azure AI Code of Conduct, and equivalents), regardless of licensing or human review: (i) clinical practice, provision of medical advice, or any use subject to medical-device regulatory approval; (ii) use of any "Robotics Model" in any safety-critical application (healthcare, transportation, weapons, critical infrastructure, or settings where malfunction could reasonably cause death, injury, or severe property damage).
HIPAA / Protected Health Information. You shall not submit or route through your Instance any "Protected Health Information" as defined under HIPAA (45 CFR 160.103), any "electronic Protected Health Information" (ePHI), any data subject to HITECH, or any analogous health data under POPIA §26 or GDPR Article 9, to any AI Provider or hyperscaler that has not executed a Business Associate Agreement covering that call with you directly. askNiva is not a "business associate" within the meaning of HIPAA, has not executed, and will not execute, any "business associate agreement" absent a separate written agreement signed by an authorised askNiva officer; askNiva disclaims any status that would bring it within HIPAA's regulatory scope.
9.3 Automated consequential decisions
You will not automate any consequential decision without meaningful human review. A "consequential decision" includes any decision affecting a person's legal position, finances, health, safety, employment, housing, education, immigration, or access to critical services. In particular, you will not use the Service for the following high-risk applications unless you have the relevant regulatory licence, meaningful human oversight, documented testing and monitoring appropriate to the risk, compliance with every applicable AI-specific law (including the EU AI Act where an EU nexus exists, and any conformity assessment required under it), and a separate written agreement with askNiva:
- critical-infrastructure control (power, water, gas, telecommunications, transportation, financial-market infrastructure);
- life-safety systems, emergency services, or emergency dispatch;
- medical diagnosis, treatment decisions, drug prescribing, dosage calculation, or drug-drug interaction analysis for patient use;
- aircraft, automotive, maritime, or other autonomous-vehicle control;
- autonomous weapons systems or weapons targeting (see also §5.2);
- nuclear-facility control;
- legal-practice automation where legal advice is required (including automated court filings without attorney review);
- credit, lending, or credit-scoring decisions with material impact on individuals;
- employment decisions (hiring, firing, performance management, compensation);
- housing decisions, rental-tenant selection, or accommodation allocation;
- insurance underwriting or claims processing decisions;
- educational admissions, testing, or accreditation decisions;
- government-benefit eligibility decisions;
- criminal-justice decisions (sentencing, parole, pre-trial risk, predictive policing);
- migration or immigration decisions;
- social-scoring or general-purpose individual-behaviour scoring (see also §7.3(b));
- any safety-critical robotics application;
- national-security or intelligence applications (other than under express written authorisation from the relevant AI Provider);
- product-safety components or components subject to product-safety regulation;
- media, editorial, or journalistic content generation presented as human-authored, and any professional journalistic content generation at scale.
Where your use case is close to the line, you must maintain meaningful human review, provide clear disclosure to affected individuals, comply with any applicable AI-specific regulation (including the EU AI Act where an EU nexus exists), and document your controls.
Legal-material-impact rule (independent of human review). Independent of human review, you shall not use any AI Provider Output as the basis for any decision having a legal or materially adverse effect on a natural person — including decisions about credit, education, employment, housing, insurance, legal matters, medical care, migration, or the exercise of any constitutional right — unless the Output is reviewed and adopted in writing by a licensed professional whose written advice is the basis for the decision.
EU AI Act Article 5 (prohibited practices). Regardless of human review or licensing, you shall not use the Service for any practice prohibited by Article 5(1) EU AI Act, including (a) subliminal or purposefully manipulative techniques materially distorting behaviour to cause significant harm; (b) exploitation of vulnerabilities of specific groups; (c) social scoring by public authorities or for public-authority purposes; (d) real-time remote biometric identification in publicly accessible spaces for law-enforcement purposes (subject to narrow statutory exceptions directly vested in a state authority, not in you); (e) predictive policing based solely on profiling; (f) untargeted scraping of facial images from the internet or CCTV to build facial-recognition databases; (g) emotion inference in workplaces or educational institutions (see §7.2(d)); (h) biometric categorisation of individuals by protected attributes. EU AI Act Article 50 transparency obligations (AI-interaction disclosure, deepfake labelling) apply to Output you generate or make available in the EU and are flowed down via §§4.3 and 8.2.
9.4 Agent autonomy controls
You will not configure, permit, or allow any agent on your Instance to:
- (a) make autonomous financial transactions above a threshold you have not explicitly pre-authorised. In any case, the following absolute ceilings apply and may not be exceeded without explicit human confirmation for each specific transaction: (i) no single transaction over ZAR 500 (or local equivalent); (ii) no aggregate of transactions exceeding ZAR 2,000 (or local equivalent) within any rolling 24-hour period; (iii) no transaction where the counterparty is a consumer, a PEP, or a cross-border recipient; (iv) no transaction in any financial instrument covered by §9.4(b) at any amount. You may raise thresholds (i) and (ii) only by a separately initialled configuration change recorded in the Account audit log.
- (b) purchase, sell, trade, or transfer any financial instrument (stocks, bonds, cryptocurrency, derivatives) autonomously at any amount (zero threshold);
- (c) sign, execute, or commit to any contract on behalf of a human or legal person without a documented, specific authorisation and without human confirmation of the final commitment;
- (d) send communications that bind, oblige, or materially represent any third party without that third party's authorisation;
- (e) take any consequential action (as defined in §9.3) without human review;
- (f) access, scrape, extract, or interact with any third-party service (website, API, SaaS product) in a way that violates that service's terms of service, robots.txt, rate limits, CAPTCHA protections, or other access controls;
- (g) bypass a CAPTCHA or any other anti-bot protection on any third-party service;
- (h) create accounts at scale (account farming) on any third-party service;
- (i) steal, reuse, or share session cookies, authentication tokens, or credentials you do not own or are not explicitly authorised to use;
- (j) access any account, mailbox, system, or data the user does not own or have explicit permission to access;
- (k) impersonate any real human in its interactions, or fail to disclose that it is AI (see §4.3);
- (l) take any action on your Instance whose predictable consequence is a breach of this AUP, regardless of whether you specifically foresaw the breach.
Human-in-the-loop. For anything involving money, deadlines, legal consequences, communications to named third parties, or irreversible action, you must configure the agent to require a human confirmation step before taking the action.
9.5 Prompt injection
Prompt-injection attacks are a known risk. You are responsible for hardening your agent's configuration against prompt-injection attacks by (for example) treating inbound messages, emails, web-page content, and document content as untrusted; narrowing tool permissions; scoping browser sessions; and not granting shell, file-system, or payment access to the agent when not needed. askNiva is not liable for any action taken by your agent as a result of prompt injection, and such action is nonetheless your act for the purposes of §§4.2, 9.7, 13 of this AUP and §§5.3A and 16.1 of the Terms. You shall not plead prompt injection as a defence to any obligation under the Agreement, including your indemnity in ToS §16.1 or your obligations under §§9.4, 11, and 13.
9.6 Community skills and extensions
If the agent architecture supports third-party extensions, plugins, or skills, you are solely responsible for auditing and approving each extension before installing. askNiva makes no warranty about third-party skills.
9.7 Self-propagation, privilege escalation, and platform integrity
You will not configure, instruct, permit, or allow any agent on your Instance to:
- (a) self-propagate — copy, replicate, exfiltrate, or transmit itself, its prompts, its tools, its credentials, its memory state, or any component of its configuration to any other computer system, server, account, or environment outside your Instance;
- (b) escalate privileges — acquire, request, or attempt to acquire operating-system, network, cloud-account, IAM, or administrative privileges beyond those provisioned to your Instance by askNiva, whether by exploit, social engineering, credential theft, kernel exploitation, container escape, or any other means;
- (c) modify the instance — alter, patch, replace, or disable any askNiva-supplied component of the Instance (including the management agent, the control-plane integration, telemetry, logging, billing, or abuse-monitoring components) for the purpose of evading askNiva's controls, concealing activity, or extending capabilities beyond the Subscription tier;
- (d) recruit additional compute — acquire, rent, spawn, or hijack additional compute resources (whether from Hetzner, another cloud, a botnet, compromised systems, or any other source) to extend the agent's reach or to evade resource limits;
- (e) persist beyond termination — install any mechanism (scheduled task, rootkit, backdoor, second-stage payload, external callback) designed to continue the agent's activity after the Instance is suspended, terminated, or reprovisioned;
- (f) attack askNiva or fellow Users — probe, scan, exploit, or otherwise attempt to compromise the askNiva control plane, other askNiva Instances, shared infrastructure, or any neighbour on Hetzner-provided hardware;
- (g) cross-tenant or cross-platform prompt injection — craft, publish, or deliver content (whether via a shared integration, a messaging platform, a web page, a code repository, a document, a public data source, or any other channel) with the intent, reasonable foreseeability, or effect that an agent operated by another askNiva User or by any third party will ingest and act on that content in a manner contrary to its operator's interests;
- (h) shared-resource abuse — consume storage, CPU, network, IOPS, or token-budget resources in a manner intended or reasonably foreseeable to degrade neighbouring Instances, even within the limits of your Subscription tier.
These prohibitions apply whether the conduct arises from your direct instruction, your general configuration, emergent agent behaviour, or adversarial prompt injection (see §9.5).
---
10. Elections and political manipulation
10.1 You will not use the Service to:
- (a) interfere with any election or other democratic process in any country;
- (b) suppress voter turnout, discourage participation, or mislead voters about how, when, or where to vote, or about voter eligibility;
- (c) conduct personalised voter or campaign targeting based on individual profiles or data (other than as openly permitted by the applicable election law);
- (d) create or amplify artificial or deceptive political movements in which the source, scale, or nature is misrepresented;
- (e) generate automated communications to public officials or voters at scale that conceal their artificial origin;
- (f) create synthetic media depicting candidates, officials, or voters in a manner designed to deceive or mislead (this is the canonical prohibition on political deepfakes; §8.2(b) cross-refers to this section);
- (g) spread false or misleading information in political or electoral contexts;
- (h) engage in political lobbying using false, fabricated, or misattributed information;
- (i) deploy deceptive political advertising (including advertising misrepresenting its sponsor, funding, or AI origin).
10.2 Legitimate political journalism, civic-education content, personal political expression, and compliance-based outreach are not prohibited by this §10, provided that where the route touches any AI Provider whose policy categorically prohibits advocacy for or against a specific candidate, party, referendum position, issue, or electoral outcome (including Anthropic Usage Policy §2.10), the strictest-provider rule in §2.2 applies and no such advocacy — deceptive or authentic — may be generated via that route. If your activity is close to the line, treat it as prohibited until you have written confirmation from askNiva.
---
11. Content and conduct towards others
11.1 Intellectual property
> In plain English: Do not use the Service to steal, pirate, rip off, or misappropriate other people's work — copyright, trademarks, patents, trade secrets, images, brand names, anything. openClaw is open source under the MIT Licence; you must keep its copyright notice in place.
You shall not use the Service to:
- (a) infringe, misappropriate, or violate any third party's intellectual-property right. Covered rights include copyright, trademark, patent, trade secret, publicity right, moral right, and database right;
- (b) reproduce, distribute, or make available copyrighted material without a lawful basis;
- (c) circumvent any technological protection measure ("TPM") on any copyrighted work;
- (d) strip, alter, or forge copyright, authorship, or licensing metadata;
- (e) pass off another party's work as your own;
- (f) use any trademark, trade name, or logo in a manner likely to confuse, or in connection with goods or services not authorised by the rights holder;
- (g) misappropriate any trade secret or violate any confidentiality obligation;
- (h) use any AI Provider's trademark, name, or brand indicia — including "OpenAI", "GPT", "ChatGPT", "Claude", "Anthropic", "Gemini", "Google", "Vertex", "AWS", "Bedrock", "Azure" — or any variant, transliteration, or misspelling, in the name, branding, UI, documentation, or marketing of any agent, product, or service you build on your Instance, in any manner not expressly permitted by the relevant trademark holder's current brand guidelines.
openClaw attribution. askNiva preserves the openClaw MIT License text, copyright notice, and any NOTICE / AUTHORS / CONTRIBUTORS file in a discoverable location within every Instance (see Terms §10.2); you shall not remove, obscure, or modify any of the foregoing. If you copy, export, redistribute, snapshot, migrate, or otherwise make available to any third party any portion of openClaw (including container images, Instance exports obtained under Terms §13.6, or extracted configuration), you shall preserve the openClaw MIT Licence text, copyright notice, and any NOTICE / AUTHORS / CONTRIBUTORS file with that copy — this is required by MIT §1 ("substantial portions"). "openClaw" is the name of a third-party open-source project distributed under the MIT Licence; "MyClaw" is a separate commercial service operated by an unrelated third party. askNiva is not affiliated with, endorsed by, partnered with, or sponsored by the openClaw project, the openClaw Foundation, Peter Steinberger, MyClaw, or any AI Provider. askNiva's use of each name is nominative fair use solely to describe the software it deploys or to disambiguate itself from a separate service.
11.2 Defamation, harassment, and hate
You will not use the Service to:
- (a) defame, libel, or slander any person, organisation, or entity (see also §3.2 on §§185–187 StGB);
- (b) threaten, intimidate, harass, bully, stalk, or humiliate any person;
- (c) celebrate or glorify the suffering of any person;
- (d) coordinate harassment, targeted abuse, brigading, or pile-ons of any individual or group;
- (e) engage in hate speech, hateful conduct, or content that attacks, denigrates, or threatens any person or group on the basis of a protected characteristic (including race, ethnicity, national origin, gender, gender identity, sexual orientation, religious belief, age, disability, caste, or other characteristic) (see also §3.2 on §130 StGB Volksverhetzung);
- (f) engage in swatting, false reporting to authorities, or similar harmful pranks;
- (g) generate content promoting, trivialising, or glorifying animal cruelty or gratuitous gore;
- (h) engage in content that shames, humiliates, or targets vulnerable individuals;
- (i) develop products or services employing deceptive techniques intended to cause emotional harm.
11.3 Sexual and adult content
You will not use the Service to:
- (a) produce, distribute, host, store, index, transmit, serve, publicly display, or make available pornographic or obscene material of any kind, whether or not legal in any jurisdiction, whether or not generated by AI, and whether or not the Instance is the primary source of the material (Hetzner prohibits all pornographic or obscene material, not only illegal pornography, and askNiva cannot waive this);
- (b) produce, distribute, or publicly display non-consensual intimate imagery (including leaked intimate images, image-based sexual abuse, and revenge porn);
- (c) operate an erotic, romantic, or sexual-gratification chatbot or persona;
- (d) provide or promote sexual solicitation, commercial sex, or escort services;
- (e) generate content involving bestiality, incest, or sexual violence.
CSAM is governed exclusively by §5.1 (zero tolerance; mandatory reporting).
11.4 Cryptocurrency mining
You will not use the Service to:
- (a) mine, farm, plot, or otherwise create or validate units of any cryptocurrency or crypto token;
- (b) run any mining software, cryptocurrency hashing workload, blockchain validator, or staking node where the computational work is mining-equivalent;
- (c) operate infrastructure whose primary economic purpose is the generation or validation of cryptocurrency units.
This prohibition is universal across all Subscription tiers and all Instance sizes. It is imposed on askNiva by Hetzner and is not waivable. There are no carve-outs for "testing", "educational", or "small-scale" mining.
Using the Service to interact with existing cryptocurrency networks for non-mining purposes (for example, reading a wallet balance, sending a single transaction manually initiated by you) is not prohibited by this §11.4, subject to the other parts of this AUP (in particular §9.4 on autonomous financial transactions).
11.5 Gambling
You will not use the Service to operate, host, promote, broker, facilitate, or power any gambling, lottery, sports-betting, casino, poker, games-of-chance, prediction-market, or similar service, whether or not licensed in any jurisdiction. This prohibition reflects Hetzner's restriction on gambling hosting under its AGB §8.2 and the German Interstate Treaty on Gambling (Glücksspielstaatsvertrag), and reflects §284 StGB (unlicensed gambling). There is no carve-out for research, simulation, or demonstration.
---
12. Infrastructure and security hygiene
12.1 You will:
- (a) keep your Google account, your askNiva Account, and your AI Provider API keys secure, including by using strong authentication, enabling multi-factor authentication where available, and rotating credentials if a compromise is suspected;
- (b) not expose your Instance's management gateway to the public internet without authentication;
- (c) not run your Instance as a multi-tenant or shared-access agent for adversarial or untrusted users (one askNiva Account, one Instance, one operator);
- (d) not operate your Instance for any person barred from using the Service under §2 of the Terms;
- (e) configure the agent safely for your use case, including by scoping tool permissions, disabling features you do not need, and confirming consequential actions;
- (f) keep openClaw and any installed plugins up to date where updates are security-related;
- (g) respond promptly to any security or abuse notice askNiva sends you;
- (h) not embed AI Provider API keys in public code repositories or open-source projects;
- (i) implement affirmative fraud-detection and abuse-prevention controls where your Instance or any agent configured on it exposes functionality to third-party end users — including reasonable measures to detect and prevent fraudulent account creation, abuse, prompt injection, and automated misuse by such end users, commensurate with the risk of the application and the requirements of every upstream AI Provider;
- (j) not buy, sell, lease, transfer, share, rent, or otherwise traffic in any AI Provider API key, whether or not the key is registered to you — see also ToS §4.5.
12.2 Resource use. You will stay within the resource limits of your Subscription tier. You will not attempt to evade quotas or rate limits.
12.3 No resale. You will not resell, rent, or share your Instance with any third party without askNiva's prior written consent.
---
13. Responsibility for end users
13.1 If you permit any third party (for example, a colleague, a family member, an end user of an application you built on your Instance, another human interacting with your agent, or an automated system) to use your Instance, you are responsible for their acts and omissions as if they were yours.
13.2 You must ensure that anyone using your Instance is bound to rules at least as strict as this AUP and the Terms. For any agent-built application you deploy, your end-user-facing terms must flow down (at a minimum) the material prohibitions in this AUP. In particular, your end-user terms must:
- (a) bind end users to every AI Provider's Prohibited-Use / Usage Policy and Supported-Countries / Age-Gate rule that applies to any provider reachable from your Instance (linking the relevant provider policy from your end-user-facing documentation);
- (b) include a factual-reliance warning matching each AI Provider's flow-down (for Anthropic-powered deployments, a statement that Output may be false, incomplete, misleading, or not reflective of recent events and must not be relied on without independent verification; equivalent for OpenAI, Gemini, Azure, AWS, and Anthropic);
- (c) disclose to the end user that (i) the Instance routes prompts, files, and Outputs to one or more third-party AI Providers identified in §15, (ii) the AI Provider may retain the content for up to 30 days (longer where legally required, as with OpenAI abuse monitoring) for abuse-monitoring purposes, (iii) the AI Provider may have its Trust & Safety personnel review content flagged by its automated systems, and (iv) the content may be transferred to the United States, Ireland, or another jurisdiction in which the AI Provider operates;
- (d) bind end users to every statutory or regulatory disclosure obligation applicable in their jurisdiction (EU AI Act Article 50, applicable state deepfake-labelling rules, POPIA §18 / GDPR Art. 13 notice content);
- (e) where your agent obtains non-public end-user content via an AI Provider API, not expose that content to any other end user or third party without the originating end user's explicit opt-in consent (Google APIs ToS §3.3 incorporated by reference; equivalent obligations of other AI Providers incorporated by reference);
- (f) where your agent ingests end-user data via an AI Provider API, provide your end users with a data-export mechanism meeting Google APIs ToS §3.6 (or the equivalent obligation of any other AI Provider whose API you use);
- (g) where the Instance presents Output to natural persons, include substantive equivalents of each AI Provider's consumer-facing notice, including (for OpenAI-routed deployments) that flagged content may be examined by human trust-and-safety reviewers, that content may be transferred cross-border to the United States, and that CSAM will be reported to NCMEC.
13.3 If your agent takes any action affecting a third party (including sending a message, making a purchase, or booking a service), you are responsible for ensuring the agent had the authority to take that action and for the consequences.
13.4 End-user-suspension flow-down and end-user age floor.
- (a) Where your agent interacts with natural persons as end users, you shall not knowingly permit any person under 18 (or, where a lower age is permitted by the applicable AI Provider — for example 13 with verifiable parental consent — that lower age) to interact with the agent; any stricter age floor imposed by any AI Provider you route to applies to your end users.
- (b) If askNiva notifies you of a request or notice from an AI Provider under that provider's end-user-suspension mechanism (for example, OpenAI Services Agreement §8.1), you shall suspend or terminate the relevant end user of your Instance without delay and in any event within 24 hours (or such shorter period as the AI Provider specifies). Failure to do so is a material breach.
- (c) Before granting any third party use of your Instance, you shall (i) obtain that party's agreement to terms at least as strict as the Agreement; (ii) retain verified identity records sufficient to respond to a DSA Article 10 / POPIA §11 / German-law identification request within 48 hours; and (iii) provide those records to askNiva on request. Failure to maintain adequate records is itself a material breach.
13.5 EEA / UK targeting restriction (askNiva regulatory-posture preservation). Without prejudice to your own obligations under the GDPR, the UK GDPR, the DSA, and any other Applicable Data Protection Law:
- (a) No predominantly EEA / UK targeting. You shall not configure your Instance, your end-user-facing application, your agent, or your marketing in a manner that would cause your use to be predominantly directed at, or to predominantly monitor the behaviour of, Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland, without first complying with §13.5(c). Indicators that, on aggregate, would evidence such targeting include (without limitation): denomination of your end-user-facing pricing in Euro, Pound Sterling, or Swiss Franc; marketing of your application in an EU/EEA-Member-State language other than English; use of an
.eu, EU-Member-State, or.ukcountry-code top-level domain reachable through askNiva infrastructure; geo-targeted advertising of your application to recipients in those territories; or customer service in an EU/EEA-Member-State language other than English. - (b) No DSA "substantial connection" trigger by routing. You shall not configure your Instance or any agent to acquire, on askNiva's behalf, a "substantial connection to the Union" within the meaning of DSA Article 2(1) (read with Recitals 7 and 8 DSA). The indicators in §13.5(a) apply equally to this DSA limb.
- (c) Notification trigger and indemnity. Where you intend to engage in any conduct that would, or would reasonably be expected to, cross any threshold in §13.5(a) or §13.5(b), you shall give askNiva at least sixty (60) days' prior written notice to legal@askniva.com under ToS §2.10, so that askNiva may designate a GDPR Article 27 representative, a UK GDPR Article 27 representative, and/or DSA Article 11 / Article 12 / Article 13 contacts before the threshold is crossed. The reasonable cost of any such designation attributable to your conduct (including where you fail to give the notice required by this §13.5(c)) falls within the scope of your indemnity in ToS §16, subject — as against a Consumer — to ToS §15.2(b) and Schedule A.
- (d) Your own GDPR / UK GDPR / DSA exposure unaffected. This §13.5 protects askNiva's regulatory posture. It does not limit, displace, or address your obligations as a Responsible Party / controller, processor, online-platform provider, or hosting-service provider in your own right under the GDPR, UK GDPR, DSA, or any other applicable law. You remain responsible for your own compliance with those laws, including the appointment of any GDPR / UK GDPR Article 27 representative or any DSA Article 11–13 contact that you are independently required to designate.
---
14. Hetzner flow-down
14.1 Because your Instance runs on Hetzner infrastructure, you must comply with Hetzner's terms and policies at all times. The substantive Hetzner-driven prohibitions are set out elsewhere in this AUP:
- No (D)DoS, open relays, or attack tooling — see §6.
- No spam, forged sender data, or bulk unsolicited communication — see §8.3.
- No cryptocurrency mining — see §11.4.
- No scanning of foreign networks; no IP or MAC spoofing — see §§6.2–6.3.
- No pornographic or obscene material, extremist content, content offending common decency, gambling, material endangering minors, defamatory or insulting content, or content infringing third-party rights — see §§5, 11.1, 11.2, 11.3.
- Compliance with German criminal law on Hetzner-hosted content — see §3.2.
- Compliance with the EU Digital Services Act to the extent it applies through Hetzner.
14.2 Takedown deadlines and abuse-contact duty. Hetzner's abuse team typically imposes the following deadlines:
- port-scan or unauthorised scanning complaints: approximately 6 hours;
- network-attack (including DDoS) complaints: approximately 24 hours;
- email-abuse (spam, UCE, phishing) complaints: approximately 48 hours.
You shall designate and maintain a monitored abuse contact (email and phone) available on a 24/7/365 basis, and you shall acknowledge any notice askNiva forwards within one (1) hour (for Business Users) or without undue delay and in any event before the applicable upstream deadline (for Consumers), and you shall remediate within the shorter of (i) the upstream supplier's deadline or (ii) the deadline askNiva specifies. If askNiva forwards a Hetzner abuse complaint to you, you must respond and remediate within the applicable deadline. Failure to provide a monitored contact is a material breach and a waiver of any claim that notice was not timely received. Failure to remediate within the deadline will result in immediate suspension of your Instance to protect askNiva's Hetzner account.
14.3 Hetzner action = askNiva action. If Hetzner locks, null-routes, or terminates your Instance, askNiva will mirror that action at the askNiva control-plane level, with no refund.
14.4 Authority to represent you before Hetzner. The authority granted under this §14.4 is grounded in POPIA §11(1)(b) (necessary for the performance of the Agreement and of askNiva's upstream contract with Hetzner required to make the Service available to you), §11(1)(c) (compliance with legal obligations imposed on askNiva, including Hetzner AGB §§7.1–7.3 flow-down and any DSA Art. 9 / Art. 10 order routed through Hetzner), and §11(1)(f) (legitimate interests of askNiva and of Hetzner in the defence of claims and in the enforcement of Hetzner's terms). Any onward disclosure is subject to the ToS §18.1 recital and the POPIA §18(4)(b), (c), or (d) non-notification exemptions as applicable. You authorise askNiva to act as your representative in good faith before Hetzner and any other upstream supplier in connection with any abuse, takedown, preservation, security, or audit matter relating to your Instance, including by (a) acknowledging, on your behalf, that conduct complained of occurred on your Instance, (b) disclosing your identity, Instance metadata, and relevant conduct details under ToS §18.1(f), and (c) undertaking remediation steps on your behalf where you have failed to act within the §14.2 deadline.
---
15. AI Provider flow-down
15.1 Independent of the Terms, you accept that your use of any AI Provider is governed by that provider's own terms and policies, and you will comply with them at all times:
- Anthropic — Commercial Terms (https://www.anthropic.com/legal/commercial-terms); Usage Policy (https://www.anthropic.com/legal/aup).
- OpenAI — Services Agreement (https://openai.com/policies/services-agreement/); Service Terms (https://openai.com/policies/service-terms/); Usage Policies (https://openai.com/policies/usage-policies/).
- Google Gemini — Gemini API Additional Terms (https://ai.google.dev/gemini-api/terms); Google APIs Terms of Service (https://developers.google.com/terms) or Google Cloud Platform Terms of Service (https://cloud.google.com/terms); Generative AI Prohibited Use Policy (https://policies.google.com/terms/generative-ai/use-policy).
- Amazon Web Services (AWS Bedrock and other AWS AI services) — AWS Customer Agreement (https://aws.amazon.com/agreement/); AWS Service Terms, including the Amazon Bedrock section and any AI-service-specific provisions applicable to the service you invoke (https://aws.amazon.com/service-terms/); AWS Acceptable Use Policy (https://aws.amazon.com/aup/); AWS Responsible AI Policy (https://aws.amazon.com/ai/responsible-ai/policy/).
- Microsoft (Azure OpenAI, Azure AI Foundry, other Microsoft AI services; Microsoft Graph) — Microsoft Customer Agreement; Microsoft Product Terms (including the Microsoft Acceptable Use Policy and any AI-service-specific terms referenced from the Product Terms); the Code of Conduct for Microsoft AI Services (https://learn.microsoft.com/en-us/legal/ai-code-of-conduct); the Customer Copyright Commitment (CCC) Required Mitigations documentation; any Limited Access / Managed Customer Access Program (MCAP) / Responsible AI commitments applicable to Azure OpenAI or the service you invoke.
- Other AI Providers — the terms and policies applicable to your API key.
15.2 Strictest provider wins. Where one AI Provider permits a use and another prohibits it, you must follow the prohibiting policy while using any route that touches the prohibiting provider.
15.3 A breach of any AI Provider's policy by you or by an agent you configure is a breach of this AUP.
15.4 askNiva may suspend your Instance if an AI Provider notifies askNiva of actual or suspected misuse, regardless of whether askNiva independently confirms the misuse.
15.5 AI-Provider action = askNiva action (mandatory mirror). If an AI Provider, hyperscaler, or any upstream supplier whose service is reachable from your Instance demands that askNiva (a) suspend or terminate you, (b) remove, disable, or preserve specific Customer Data, (c) preserve logs or evidence relating to you, or (d) cooperate with that supplier's trust-and-safety, security, or compliance investigation, askNiva shall do so within the time frame the supplier requires, without prior notice to you and without refund, to the extent permitted by applicable law. askNiva may require you to remediate within 24 hours of notice (or such shorter period as the supplier specifies); failure to remediate within the specified period is a material breach. For Consumers, this §15.5 operates subject to ToS §15.2(b) and Schedule A, and does not displace any right or liability that cannot lawfully be excluded.
15.6 Free-tier AI-Provider prohibition. You shall not submit to any AI Provider's unpaid / free tier (including Google AI Studio without active Cloud billing, Anthropic or OpenAI consumer-tier surfaces such as claude.ai or chat.openai.com, and any equivalent free-tier API or consumer-facing surface) any of:
- (a) Personal Information, Special Personal Information, or the data of any Data Subject;
- (b) Confidential Information;
- (c) any content you do not own outright and have unlimited rights to use, including any third-party copyrighted work, licensed material, client work-product, or content you received under a confidentiality, professional-privilege, or data-use restriction.
This is a material breach regardless of any consent you may hold. This restates and makes operative the ToS §6.7 warning.
15.7 EEA / UK / Switzerland paid-tier-only rule. If you, any of your personnel, any end user of your Instance, or any Data Subject whose Personal Information is processed is located in the European Economic Area, the United Kingdom, or Switzerland, and the AI Provider is Google Gemini, you must use a paid-tier Gemini API key (accessed via a Google Cloud project with active billing, or via Vertex AI). Free-tier Gemini keys may not be used in any configuration where EEA / UK / Swiss data or persons are in-scope.
15.8 Grounding-with-Search / data-grounding constraints. If you enable Grounding with Google Search, Google Maps Grounding, or any comparable data-grounding feature offered by an AI Provider, you warrant that you (not askNiva) are the operator of the application consuming the grounded results. You shall not cache, frame, syndicate, resell, analyse, or train on grounded results, and shall not retain them beyond the limits the relevant AI Provider permits.
---
16. Reporting and enforcement
16.1 Reporting abuse to askNiva. If you become aware of any breach of the Agreement (including this AUP) by any user, you must promptly report it to abuse@askniva.com with enough information for askNiva to investigate, including (where available) the Account identifier, a description of the activity, any relevant timestamps, and any evidence you hold.
16.2 Reporting by third parties. Anyone may report abuse to abuse@askniva.com or through the online abuse form on askNiva's website (once published). askNiva shall investigate credible reports. askNiva may forward reports to you for a response and may require you to remediate.
16.3 Investigation rights. askNiva may investigate any suspected breach. askNiva may:
- (a) review logs, metadata, and configuration;
- (b) inspect network traffic (for security, abuse, or law-enforcement purposes, and subject to applicable law);
- (c) preserve, copy, and retain Customer Data as evidence;
- (d) work with Hetzner, AI Providers, payment processors, or law-enforcement agencies;
- (e) disclose information to authorities as permitted by law (see §18 of the Terms).
16.4 Enforcement measures. Depending on the nature and seriousness of a breach, askNiva may take any one or more of the following measures, with or without prior notice:
- (a) warn you and require remediation within a stated time;
- (b) throttle, rate-limit, or degrade the Service as applied to your Account;
- (c) disable specific features of your Instance (for example, network egress, outbound email, or agent autonomy);
- (d) require you to remove specified Customer Data;
- (e) reset, rotate, or revoke API keys stored in your Instance;
- (f) suspend your Account, your Instance, or both;
- (g) terminate your Subscription for cause;
- (h) ban you from registering a new Account;
- (i) preserve evidence and cooperate with law enforcement (see §§16.8 and 16.9);
- (j) publish a redacted public notice of the enforcement action (only in egregious cases, and subject to law).
16.5 No notice where unsafe. askNiva is not required to give you notice where (i) notice would prevent askNiva from protecting the Service, other Users, or any third party; (ii) notice would frustrate a lawful investigation; (iii) notice would be unlawful; or (iv) the nature of the breach requires immediate action.
16.6 No refund. Fees paid are not refundable if askNiva suspends or terminates your Account for a breach of this AUP.
16.7 User cooperation required. If askNiva asks you to cooperate with an investigation, to remediate a breach, or to respond to a third-party notice, you shall do so promptly and in good faith. Failure to cooperate is a separate material breach.
16.8 Evidence preservation (public-authority and askNiva-party limbs). POPIA recital. The preservation authorised by this §16.8 is grounded in POPIA §14(1)(a) (retention required or authorised by law) and §14(1)(b) (retention reasonably required for a lawful purpose related to a function or activity of askNiva). The further processing involved is compatible with the original purpose within the meaning of POPIA §15 — in particular §15(3)(c) for law-enforcement, regulatory, and court-process limbs and the §15(2) compatibility balance for the function-related defence limbs. Where askNiva does not notify you of a specific preservation event, it does so in reliance on POPIA §18(4)(b), (c), or (d) as the case may be. Subject to that framing, and notwithstanding any other provision of the Agreement (including any obligation to delete Customer Data on termination), askNiva may preserve logs, snapshots, agent traces, configuration, Customer Data, and metadata relating to any suspected violation of this AUP, scoped to what is reasonably necessary, for as long as askNiva reasonably considers necessary to (i) cooperate with law-enforcement or regulatory authorities; (ii) defend against third-party claims; (iii) prosecute askNiva's own legal proceedings; or (iv) comply with a legal hold, preservation, or retention obligation. Preserved material is handled in accordance with askNiva's security controls and disclosed only as permitted or required by law.
16.9 Evidence preservation — upstream-supplier limb. POPIA §14 / §15 purpose-limited authority. Where an AI Provider, hyperscaler, infrastructure provider, payment processor, or other upstream supplier whose terms you are bound by directs a preservation, investigation, audit, or enforcement request to askNiva relating to suspected or alleged breach of that supplier's terms by you (including pre-litigation investigations and abuse reviews), askNiva may preserve logs, snapshots, agent traces, configuration, Customer Data, and metadata relating to the request. The POPIA lawful basis is §14(1)(b) (a lawful purpose related to askNiva's function of providing the Service on the upstream-supplier stack you have configured), read with §15(2) further-processing compatibility (including in particular the contractual foreshadowing in this AUP and in the Terms). Preservation under this §16.9 is limited in scope to the material reasonably relevant to the supplier's request, and in duration to the shorter of (a) the period the supplier's process reasonably requires, (b) the period reasonably necessary for askNiva to discharge its own obligations to the supplier, and (c) the periods authorised by POPIA §14(1)(a)–(d). Preserved material is handled in accordance with askNiva's security controls and disclosed only as permitted or required by law. Notification to you of a specific preservation event under this §16.9 follows §18.2 of the Terms, save where POPIA §18(4)(b) or §18(4)(d) supports non-notification.
16A. Notice-and-takedown procedure (DSA-aligned)
16A.0 Scope determination. askNiva is established in the Republic of South Africa and has no place of establishment in the Union. The EU Digital Services Act (Regulation (EU) 2022/2065) ("DSA") applies to a non-EU-established intermediary service only where the provider has a "substantial connection to the Union" within the meaning of Art. 2(1) read with Recitals 7 and 8 DSA — that is, where the service is offered to, or activities are targeted toward, recipients located in the Union (language, currency, domain, local app-store availability, localised advertising, or customer service in a Member State language being indicators; mere technical accessibility from the Union is not sufficient). As at the Effective Date, askNiva does not market the Service to EEA recipients, does not offer the Service in any Member State language or in Euro, and does not have a substantial connection to the Union within the meaning of Art. 2(1). If and when askNiva does establish a substantial connection to the Union, askNiva will designate the Art. 11, Art. 12, and Art. 13 contacts required by the DSA and publish their details here and at legal@askniva.com. If in scope, askNiva would be a hosting service within the meaning of Art. 3(g)(iii) DSA (storage of information provided by, and at the request of, a recipient), and not an online platform within the meaning of Art. 3(h) DSA (which requires dissemination to the public at the recipient's request) and not a very large online platform within the meaning of Art. 33 DSA.
16A.1 Purpose. Because Instances run on Hetzner-provided infrastructure located in the European Union, content hosted on an Instance may be subject to notice-and-takedown obligations under the DSA. This §16A sets out the procedure askNiva follows when it receives notice of allegedly illegal content on an Instance, modelled on Articles 16, 17, 20, and 21 DSA. It applies whether or not askNiva is itself directly in scope of the DSA and without prejudice to askNiva's other enforcement rights.
16A.2 How to submit a notice. Any person may submit a notice of allegedly illegal content hosted on an Instance by email to abuse@askniva.com or through the abuse form at https://askniva.com/legal/abuse-form. A notice should contain:
- (a) a sufficiently substantiated explanation of the reasons why the content is alleged to be illegal (including the specific law alleged to be infringed);
- (b) a clear indication of the exact electronic location of the content (such as the URL, Instance identifier, channel, or message reference);
- (c) the name and contact details of the submitter (unless the notice concerns content that may be illegal under Articles 3 to 7 of Directive 2011/93/EU on combating the sexual abuse of children, in which case anonymous submission is accepted);
- (d) a statement confirming the submitter's good-faith belief that the information and allegations are accurate and complete.
16A.3 Acknowledgement and acting upon notices. Where a notice is submitted with the contact details in §16A.2(c), askNiva shall acknowledge receipt without undue delay and shall process the notice in a timely, diligent, non-arbitrary, and objective manner. Notices from trusted flaggers awarded that status under Article 22 DSA by a Digital Services Coordinator shall be treated with priority.
16A.4 Statement of reasons. Where, on the basis of a notice or otherwise, askNiva removes, disables access to, restricts the visibility of, terminates, or suspends the provision of the Service in respect of specific Customer Data, askNiva shall, where contact details are known, provide the affected User with a clear and specific statement of reasons, including:
- (a) whether the action consists of removal, disabling, restriction, termination, or suspension, and the territorial scope of the action;
- (b) the facts and circumstances relied upon;
- (c) where applicable, information about the use of automated means in reaching the decision;
- (d) the legal or contractual ground relied upon (statute, court order, AUP provision, or Hetzner notice);
- (e) clear information about possibilities of redress under §16A.5 and §16A.6.
16A.5 Internal complaint-handling mechanism. A User against whom askNiva takes action under §16A.4, or a person who submitted a notice under §16A.2, may lodge a complaint with askNiva by email to abuse@askniva.com within six (6) months of the decision. askNiva shall handle complaints in a timely, non-discriminatory, diligent, and non-arbitrary manner, reverse its decision where the complaint discloses sufficient grounds, and confirm the outcome to the complainant.
16A.6 Out-of-court dispute settlement. Without prejudice to the right to bring proceedings before a court, a User may also refer a dispute concerning a §16A.4 action to a certified out-of-court dispute-settlement body under Article 21 DSA (where applicable), or, if the User is a South African Consumer, to the National Consumer Commission, the Consumer Goods and Services Ombud, or any other competent forum under South African law. askNiva shall engage in good faith with any such body.
16A.7 Interaction with Hetzner. Where Hetzner forwards a DSA notice relating to an Instance, askNiva shall act on the notice within Hetzner's stated deadline (see §14.2) and may remove or disable content without prior notice to the User where Hetzner's deadline requires it; the §16A.4 statement of reasons will follow as soon as reasonably practicable.
16A.8 Misuse of the notice mechanism. askNiva may suspend, for a reasonable period and after prior warning, the processing of notices or complaints from any person that frequently submits notices or complaints that are manifestly unfounded, in line with Article 23 DSA.
16A.9 DSA Article 10 and equivalent information orders. Where askNiva receives an order under Article 10 DSA (or any equivalent information order from a competent authority, whether routed through Hetzner or directly), you shall (i) provide askNiva with verified identity, contact, and conduct information relating to your Instance within 48 hours of askNiva's request or such shorter period as the information order or upstream supplier requires, and (ii) authorise askNiva to forward that information upstream to the extent the order requires. The POPIA lawful basis for the onward disclosure is the §11(1)(b) / §11(1)(c) / §11(1)(f) stack recited in ToS §18.1 and §14.4 above. See also ToS §18.1(f).
16A.10 Future DSA designations. If askNiva acquires a substantial connection to the Union within the meaning of Art. 2(1) DSA, askNiva shall designate (i) a single point of contact for Member State authorities, the Commission, and the Board (Art. 11 DSA); (ii) a single point of contact for recipients of the Service (Art. 12 DSA); and (iii) a legal representative in one of the Member States where the Service is offered (Art. 13 DSA). The Art. 13 DSA legal representative is a distinct office from any representative askNiva may designate under GDPR Art. 27 or UK GDPR Art. 27; the same person may hold both offices, but the designation instruments are separate. The designation of a legal representative under Art. 13 DSA does not constitute an establishment in the Union (Art. 13(5) DSA).
---
17. Updates to this AUP
17.1 askNiva may update this AUP from time to time. Material updates will be notified in accordance with §23.11 of the Terms and take effect after the notice period. Continued use of the Service after an update takes effect is acceptance of the updated AUP. Updates required to comply with law, provider flow-downs, or urgent safety matters may take effect immediately.
---
18. Contact
Mollo Innovations (Pty) Ltd (trading as "askNiva")
Companies and Intellectual Property Commission (CIPC) registration number: 2026/275132/07
Registered office: Regus Business Centre, 1st Floor, Block B, North Park, Black River Park, 2 Fir Street, Observatory, Cape Town, Western Cape, South Africa, 7925
Abuse reports: abuse@askniva.com
Security issues: security@askniva.com
Legal notices: legal@askniva.com
Privacy / data-protection (POPIA): privacy@askniva.com
Data Protection Officer / Information Officer (POPIA §55): dpo@askniva.com
---
Annexe A — What does this mean in practice?
The scenarios below illustrate how canonical rules in this AUP apply to common agent-building patterns. They are illustrative, not exhaustive. If your planned activity resembles any prohibited scenario, treat it as prohibited until you have written confirmation from askNiva.
- "I want the agent to scrape Google Search results nightly to build a leads database." Prohibited. Violates §6.1 (scanning third-party services without permission) and §8.1 read with §9.4(f) (accessing third-party services in a manner that breaches their ToS and robots.txt), and typically the AI Provider's anti-scraping terms under §15.
- "I want the agent to DM every new member of my Telegram channel with a welcome-plus-pitch message." Prohibited. Violates §8.3(e) (mass-DM on messaging platforms is bulk unsolicited contact regardless of content) and, if the pitch concerns a token or investment, §8.1(a).
- "The agent replies to inbound customer emails on my behalf and books the occasional meeting." Permitted, subject to §4.3 (AI disclosure at the start of the conversation and on sincere enquiry), §9.4(c) (documented authority to commit on your behalf), and §8.3's carve-out for replying to your own incoming messages.
- "The agent places live equity trades based on market signals without human confirmation." Prohibited. Violates §9.4(b) (no autonomous trading of financial instruments) and §9.3 (no consequential-decision automation without meaningful human review).
- "I want to run a companion / roleplay persona chatbot that develops a romantic relationship with the user." Prohibited. Violates §11.3(c) (no erotic, romantic, or sexual-gratification chatbot); even non-sexual versions raise concerns under §11.2(i) (deceptive techniques causing emotional harm) and must be reviewed.
- "I want the agent to clone my CEO's voice for internal IVR so callers can reach the right department." Prohibited without express, specific, informed, and revocable written consent from the CEO (§8.2(b)), and the IVR must clearly disclose that the voice is synthetic (§4.3).
- "The agent watches my inbox and pays invoices under ZAR 300 automatically." Permitted but tightly bounded: no single transaction may exceed the threshold in §9.4(a) (ZAR 500) without explicit human confirmation, and you remain responsible for configuring fraud-detection and duplicate-payment safeguards.
- "I want to mine a bit of Monero on the idle CPU of my Instance, just for personal experimentation." Prohibited. Violates §11.4 — this prohibition is universal across all tiers, all Instance sizes, all purposes, with no "small-scale" or "educational" carve-out (Hetzner-mandated).
- "The agent should apply to 500 jobs on LinkedIn every week using Easy Apply." Prohibited. Violates §9.4(f) (circumventing LinkedIn's automation restrictions), §8.1(f) (misrepresentation in commerce / inauthentic activity where the applications mislead as to who or what is applying), and LinkedIn's own ToS, which in turn violates §15 where the AI Provider's terms require respect for target-service terms.
- "I want the agent to copy itself to a second VPS I rent elsewhere for redundancy." Prohibited. Violates §9.7(a) (self-propagation) and §9.7(d) (recruiting additional compute); permitted alternative is to deploy a fresh askNiva Instance under the same Account within the limits of your Subscription tier.
- "I'd like to deploy a Tor exit node on my Instance to support privacy projects." Prohibited by §6.3(a) (exit nodes — not tolerated because of abuse-response burden). Tor relays or bridges for legitimate privacy purposes are permitted if you respond promptly to any forwarded abuse complaint.
- "The agent generates photorealistic product photos, including sometimes of real public figures endorsing the product." Prohibited under §8.2(d) (photorealistic images of real persons without consent) and typically §8.1(e) (false endorsements).
These are examples only. They do not exhaust the scope of prohibited activity under this AUP. When in doubt, email legal@askniva.com before proceeding.