Acceptable Use Policy
En vigueur le 2026-06-21 · 2026-06-21
hey ema — Acceptable Use Policy
1. Purpose and scope
This Acceptable Use Policy (AUP) sets out what is and is not acceptable use of Hey ema. It applies to:
- the Customer;
- the Customer's Authorised Users; and
- End Users to whom the Customer makes Hey ema available, in each case to the extent the Customer is responsible for them under the MSA.
A breach of this AUP is a material breach of the MSA. Hey ema may suspend access under MSA clause 11.4 and/or terminate under clause 11.2 if this AUP is breached. The Customer must impose AUP-equivalent obligations on its Authorised Users and End Users (see MSA clause 3.3 and the SaaS End User Terms of Use (H10)).
Emergency removal and suspension. Despite any cure period elsewhere, Hey ema may immediately remove, disable access to, or quarantine content, and/or suspend the relevant account or feature, where Hey ema reasonably believes content or conduct is unlawful (in particular child sexual abuse material), poses an imminent security, safety or legal risk, or is required to be removed by law or by a competent authority. Hey ema will act proportionately, limit the action to what is reasonably necessary, and notify the Customer promptly.
2. General principles
You must use Hey ema:
- (a) lawfully, ethically, and in accordance with the MSA, the DPA, the AI Addendum, and Applicable Laws;
- (b) with respect for other users, End Users, and the security and integrity of Hey ema and the systems it depends on;
- (c) only for the purposes set out in the MSA and the Customer's documented business purposes; and
- (d) in line with the Hey ema documentation and the API Terms (H15) for any programmatic or integration access.
3. Prohibited content
You must not submit to, or process through, Hey ema any content that:
- (a) is unlawful, infringing, defamatory, obscene, harassing, threatening, abusive, hateful, or that incites violence;
- (b) infringes a third party's IP Rights, privacy, or other rights;
- (c) constitutes child sexual abuse material or sexually exploits or endangers a minor;
- (d) promotes terrorism or violent extremism;
- (e) contains malware, viruses, ransomware, or other harmful code;
- (f) is intended to deceive, defraud, or impersonate any person; or
- (g) violates the privacy of any individual, including by submitting Personal Information you do not have a lawful basis to Process.
4. Prohibited conduct
Programmatic access to Hey ema is also governed by the API Terms of Use (H15). You must not:
- (a) attempt to gain unauthorised access to any part of Hey ema, any other customer's data, or any underlying infrastructure;
- (b) probe, scan, or test the vulnerability of Hey ema, except under a written authorisation from Hey ema (e.g. a coordinated vulnerability disclosure or bug bounty);
- (c) bypass or circumvent rate limits, access controls, authentication, billing, or other restrictions;
- (d) use Hey ema to send unsolicited bulk messages (spam) or in breach of the Spam Act 2003 (Cth), the GDPR e-privacy rules, the CAN-SPAM Act, or other anti-spam laws;
- (e) use Hey ema to send phishing or social-engineering attacks;
- (f) interfere with or disrupt the operation of Hey ema, its underlying networks or other users' use of Hey ema (including by denial-of-service attacks);
- (g) reverse engineer, decompile, or disassemble Hey ema, except to the extent permitted by Applicable Law;
- (h) use Hey ema to develop or train a product that competes with Hey ema;
- (i) use Hey ema to scrape, replicate, or build a competing dataset;
- (j) misrepresent your identity or your authority to act for the Customer;
- (k) remove or alter proprietary notices on Hey ema or its outputs;
- (l) violate any Applicable Law, including data protection, sanctions, anti-bribery, modern slavery, or export-control laws;
- (m) re-sell or redistribute access to Hey ema except as expressly permitted in the Order Form.
5. Restrictions on use of AI features
In addition to the AI Addendum, you must not use Hey ema's AI features:
- (a) to generate, target, or distribute content prohibited under §3;
- (b) to make solely-automated decisions producing legal or similarly significant effects on individuals, except where the AI Addendum and Applicable Law permit;
- (c) for any use prohibited by the EU AI Act or other AI Laws applicable to you;
- (d) for biometric categorisation or emotion-inference of individuals, except as expressly permitted by Applicable Law and disclosed to the affected individuals;
- (e) to generate intentional misinformation or content designed to deceive about a person's identity or actions (e.g. non-consensual deepfakes);
- (f) in a way that bypasses or undermines the safety features of Hey ema or any underlying Model Provider;
- (g) to attempt to extract another customer's data, prompts, or AI Outputs.
6. Security cooperation
You must:
- (a) keep credentials confidential and use multi-factor authentication where available;
- (b) promptly notify Hey ema if you become aware of a security incident affecting Hey ema (security@heyema.com);
- (c) cooperate with Hey ema in investigating suspected breaches of this AUP; and
- (d) not facilitate or encourage another person to breach this AUP.
7. Reporting violations
If you become aware of a violation of this AUP, please report it to abuse@heyema.com with as much detail as you can provide. Hey ema reserves discretion as to how to address violations, except that it will act on reports of unlawful content as described in §1 (Emergency removal and suspension).
Mandatory reporting. Hey ema may, and where required by law will, report child sexual abuse material and other unlawful content or conduct to the relevant authorities (including, as applicable, the Australian Federal Police / eSafety Commissioner and the US National Center for Missing & Exploited Children), and may preserve and disclose related data to the extent required or permitted by law.
8. Changes
Hey ema may update this AUP from time to time. The current version is available at the URL notified to the Customer. Material changes will be notified at least 30 days before they take effect, except where shorter notice is required by law or where a change is necessary to address a security or legal risk.