HENRYEXCHANGE
How it worksTrustInsightsFor partnersCapabilitiesCommunicationsIntegrations
Join the Exchange
Legal/Acceptable Use Policy

CUSTOMER ACCEPTABLE USE POLICY

Effective Date: 24 August 2026
Version: 2

This Customer Acceptable Use Policy (AUP) forms part of the Terms of Service and must be read with the Privacy Policy, Service Level Agreement, applicable Product and Processing Schedule and Security and Incident Schedule. Capitalised terms not defined here have the meanings given in the Terms of Service.

Standard and Enterprise arrangements: The standard position described in this document applies unless a signed Enterprise Annex expressly varies an eligible, identified contractual matter. Where legally and operationally available, any enhanced or non-standard scope, service level, support, infrastructure, assurance, reporting, implementation or other commitment must be separately requested, assessed, approved and priced under the Enterprise Agreement. An Enterprise Annex cannot alter statutory rights or mandatory legal obligations.


1. Purpose and Application

1.1. This AUP helps protect the security, reliability and lawful use of the Service defined in the Terms of Service.

1.2. Responsibility for Authorised Users, administrators, contractors, API clients and credentials is governed by the Terms of Service Sections 1 and 3.

1.3. Use of the Service must comply with applicable law.

1.4. By affirmatively accepting the Agreement, the Tenant agrees that it and its Authorised Users may send and receive reasonable, relevant communications with Henry and approved participants through the selected channels for an authorised application, request or transaction. The Tenant must ensure that its Authorised Users understand and comply with these limits. That acceptance does not authorise unrelated solicitation or direct marketing, which remains subject to the Privacy Policy, the Terms of Service and applicable law.

2. Responsible Use Requirements

2.1. To protect all customers, their information and the Service, the Service may not be used to:

  • commit, facilitate or conceal unlawful, fraudulent, deceptive or harmful conduct, including money laundering, terrorism financing, phishing or identity theft;
  • create, upload, transmit or store content that is unlawful, defamatory, threatening, abusive, hateful, obscene, malicious, privacy-invasive or infringes another person's rights;
  • process personal information contrary to the Privacy Policy or applicable law;
  • access or use Henry Lead Data outside Henry's authorised workflow, purpose, channel, period or personnel, or sell, export, disclose or retain it except as expressly permitted by the Operator Agreement;
  • submit information prohibited by the Privacy Policy;
  • submit Children's Information, authentication secrets, payment-card security codes or another restricted data category unless the applicable Product and Processing Schedule expressly supports it and the required approval, lawful basis and safeguards are in place;
  • ingest, disclose or analyse legally privileged, health, biometric, criminal, identity-document, bank-credential, workplace-monitoring or other sensitive content without authority, source and field minimisation, required notice and an approved workflow;
  • attempt to re-identify De-identified Data, combine datasets to defeat a privacy control or single out a person or Tenant contrary to an approved purpose;
  • access or attempt to access another tenant's information, account, systems or communications, except for the specific participant conversation and minimum information expressly made available to the User through an authorised cross-Tenant workflow;
  • compromise, probe, scan, test, bypass or interfere with security, authentication, access control, rate limiting, monitoring, Tenant isolation or content-safety measures without Henry's prior written authorisation;
  • introduce malware or harmful code, intercept or forge communications, or gain unauthorised access;
  • damage, disable, overburden or impair the Service or another person's use of it;
  • scrape, crawl, harvest, mine or bulk-extract the Service except through an authorised API;
  • scrape, collect or enrich personal information from a source without documented authority and an applicable lawful basis;
  • conduct unlawful electronic direct marketing, ignore a suppression or opt-out instruction, send more than the legally permitted consent request to a non-customer, or conceal promotion as an operational message;
  • use an authorised participant or cross-Tenant conversation for unrelated solicitation, harassment, bulk messaging, spam, contact harvesting, an undisclosed purpose or communication after the relevant request, transaction, authority or consent has ended;
  • use Henry or an enabled participant identity to misrepresent the sender, responsible provider, authority, eligibility, approval, advice, terms or purpose of a communication;
  • use the Service for covert or disproportionate employee, customer, applicant or public surveillance, emotion inference, discriminatory profiling or tracking that a person could not reasonably expect;
  • use an output, match, score or recommendation as the sole or determinative basis for an unapproved credit, employment, insurance, housing, education, healthcare, legal or similarly consequential decision;
  • use the Service as if Henry were the lender, credit provider, insurer, underwriter, financial adviser or other regulated provider, or require Henry personnel or systems to make a regulated decision or representation without an approved Enterprise Annex and legal review;
  • copy, sell, license, sublicense, monetise, redistribute, white-label, rebrand or otherwise Externalise the Service or a Henry Output except under an Externalisation Commercial Annex;
  • provide a Henry Output as a standalone service or data product, incorporate it into a commercial API, platform, dashboard, data feed or software product, or provide bulk or recurring third-party access;
  • remove a Henry proprietary notice, conceal the source of a Henry Output or use multiple accounts, affiliates, contractors or recipients to avoid a usage, metering, attribution or commercial restriction;
  • reverse engineer, decompile, disassemble or otherwise attempt to discover the Service's source code, object code, internal operation, models, prompts, weights, parameters, algorithms, datasets, taxonomies, ontologies, mappings, non-public schemas or Proprietary Methodology;
  • use prompts, systematic queries, screenshots, exports, observations, timing, errors or other testing to infer, extract or replicate Henry's models, rules, schemas, methods, digital twins, scoring, matching, routing, enrichment or workflow logic;
  • scrape, crawl, harvest, mine or bulk-extract the Service or Henry Outputs, including through an authorised API used outside its documented purpose or rate;
  • use a Henry Output as training data, evaluation data, labels, ground truth, retrieval material or test material for another AI model, analytical product or software system;
  • train, fine-tune, test, validate, benchmark or improve another AI model, software system, dataset, analytical product, matching system, routing system or decision-support product using the Service or Henry Outputs;
  • build, commission, enable or assist a competing, substitute or functionally equivalent service by using Henry Technology, Henry Outputs or Proprietary Methodology, or recreate Henry's data structures, dashboards, digital twins, scoring systems, workflows, matching or routing methods;
  • allow a competitor, external technology vendor, developer, consultant or data provider to inspect, query, test, ingest, process or use the Service or a Henry Output without Henry's prior written approval;
  • share credentials or API access, load a Henry Output into another AI or analytical system, or conduct technical testing or benchmarking without Henry's prior written approval;
  • disclose non-public benchmarks, architecture, screenshots, demonstrations, performance results or technical descriptions outside the Tenant except for a legally mandatory disclosure or minimum necessary disclosure to an approved adviser, auditor or regulator under confidentiality and non-use duties;
  • file, support or procure an intellectual-property application derived from Henry Technology or Proprietary Methodology, challenge Henry's ownership of Henry Technology, Henry Outputs, Enriched Data, Proprietary Methodology, Improvements or Custom Development except through a bona fide dispute identifying pre-existing Tenant Materials or unchanged source Tenant Data, or assist another person to do so; or
  • circumvent a usage limit, rate limit, metering mechanism, attribution, access control, tenant boundary or commercial restriction.

2.2. A Tenant or User may not instruct, pressure or induce Henry personnel to bypass Henry's legal, privacy, security, product, technical or internal approval controls or to implement an unlawful, materially insecure, deceptive, unsupported or unapproved configuration. A customer instruction does not expand the contracted product boundary or create a non-standard commitment.

2.3. Section 2 protects Henry's legitimate proprietary interests and does not prohibit ordinary lawful competition developed independently without use of Henry Technology, Henry Outputs, Proprietary Methodology or Henry Confidential Information. It does not prevent a disclosure required by law, provided the Tenant follows the minimum-disclosure and notice process in the Terms where legally permitted.

3. AI Use

3.1. A User must not:

  • use prompt injection, jailbreaking or similar methods to defeat safeguards;
  • generate spam, phishing, fraud, discriminatory content, misleading communications or other harmful material;
  • intentionally submit content to obtain unlawful or harmful outputs;
  • bypass moderation, filtering or safety mechanisms; or
  • misrepresent an AI output as human-generated where that distinction is material.

3.2. AI-output review and automated-processing requirements are governed by the Terms of Service Sections 5 and 6 and the Privacy Policy Section 4.

3.3. Before an output is used in a consequential workflow, a suitably authorised human reviewer must be able to consider the source and material limitations, review contrary information, correct inputs, override the output and provide the affected person with the applicable challenge route. A Tenant must not suppress provenance, confidence, exception or review information needed for that purpose.

3.4. The Service is not designed for a use in which its interruption, error or output could reasonably be expected to cause death, serious bodily injury or severe physical or environmental damage. A Tenant must not use it for such a high-risk purpose unless a signed Enterprise Annex expressly identifies and varies this restriction and allocates the required human oversight, resilience and legal controls.

4. API and Resource Use

4.1. API use is subject to documented authentication, payload, rate and plan limits and must not circumvent metering or restrictions. API credential duties are governed by the Terms of Service Section 3.

4.2. To preserve reliable access for all customers, Henry may throttle malformed, excessive, abusive or service-degrading requests, even where a nominal rate limit has not been exceeded. Henry will ordinarily take a proportionate approach and may use the remedies in the Terms of Service Section 9 where appropriate.

4.3. Automated access is permitted only through a documented and authorised interface.

4.4. Webhooks are provided on a best-effort basis. The Tenant must implement appropriate retry, validation and error handling and must independently verify critical processes.

5. Reporting

5.1. Report suspected security issues and other AUP concerns to legal@henryai.co.za. Reports should include sufficient information for investigation but must not contain unnecessary personal information, passwords or secrets.

5.2. Henry reviews good-faith reports to help protect customers and the Service. Any monitoring or personal-information processing undertaken for an investigation is governed by the Privacy Policy.

5.3. Henry will not retaliate against a person who makes a good-faith report. Reports may be submitted anonymously where practicable.

5.4. A good-faith security researcher must request and receive written scope before testing a production system, another Tenant, personal information, social-engineering target or service availability. Testing within Henry's written authorisation, using the minimum necessary access and prompt confidential reporting, is authorised security testing and is not prohibited by Section 2. Unauthorised access, persistence, extraction, disruption, extortion, public disclosure before remediation or testing outside the authorised scope remains prohibited.

6. Enforcement

6.1. Henry's aim is to resolve concerns fairly and proportionately. Where safe and appropriate, its usual approach is to provide notice and a reasonable opportunity to remedy a concern before taking more serious action. Depending on the nature, severity, frequency, intent and likely impact of the conduct, Henry may issue a warning, require remediation, restrict functionality, throttle use or use the suspension and termination remedies in the Terms of Service Section 9.

6.2. Immediate action may be necessary to protect customers, affected persons or the Service from unlawful conduct, fraud, security risk, material harm, disruption or legal exposure.

6.3. A Tenant may request review of a restriction by providing the affected account or workflow, relevant authority and supporting evidence through legal@henryai.co.za. Henry will review whether the restriction remains necessary and proportionate and will restore access or correct the record promptly where the restriction was mistaken or its cause has been remedied.

6.4. The effect of suspension or termination on Fees, access and data export is governed by the Terms of Service Sections 8 and 9.

6.5. Further contractual and legal remedies are governed by the Terms of Service Sections 7 and 12.

7. Changes and Contact

7.1. Changes to this AUP and their acceptance are governed by the Terms of Service Section 11. Materially adverse changes ordinarily apply on renewal; urgent legal or security restrictions may apply earlier to the extent reasonably necessary.

7.2. Legal, privacy, PAIA and AUP questions, formal notices and security reports may be sent to the monitored address legal@henryai.co.za. Finance and support routing is stated in the Terms of Service Section 12.2.


END OF ACCEPTABLE USE POLICY

HENRYEXCHANGE

One marketplace connecting demand, data and partners across the South African motor industry.

Platform

  • How it works
  • Trust and controls
  • Insights
  • Partner roles
  • Capabilities
  • Communications
  • Integrations

Get started

  • Join the Exchange
  • See how your business fits
© 2026 Henry AI (Pty) Ltd. All rights reserved.
LegalPrivacy policyTerms of serviceAcceptable use policy